Security

Anonymous Hacks Epik Web Hosting (gizmodo.com) 61

ArchieBunker writes: Members of the hacktivist collective Anonymous claim to have hacked web registration company Epik, allegedly stealing 'a decade's worth of data,' including reams of information about its clients and their domains. Epik is controversial, having been known to host a variety of rightwing clients, including ones that previous web hosting providers, like GoDaddy, have dropped for various reasons. Its users have included conservative social media networks Parler and Gab, as well as conspiracy-theory-laden YouTube wannabe Bitchute and former President Trump fansite, The Donald. The company recently hosted prolifewhistleblower.com -- the website designed to help people snitch on Texas residents who want abortions -- but later forcibly removed the tip-collecting platform after determining that it had violated Epik's terms by nonconsensually collecting third-party information.
Microsoft

Microsoft Account Goes Passwordless (thurrott.com) 148

Anyone with a Microsoft account can now remove their password from the account entirely to enable better security. From a report: "For the past couple of years we've been saying that the future is passwordless, and today I am excited to announce the next step in that vision," Microsoft corporate vice president Vasu Jakkal writes in the announcement post. "Beginning today, you can now completely remove the password from your Microsoft account." As for the "why" of this change, Microsoft points to the fact that passwords are insecure and are the focus of over 18 billion attacks every year, or 579 attacks every second. Before you can go passwordless, you'll need the Microsoft Authenticator app on your smartphone. Then, you can use Windows Hello, a security key, or a verification code that's sent to an email address, your phone, or a compatible app or service like Outlook, OneDrive, Microsoft Family Safety, and more to sign-in, depending on the location.
Crime

SEC Charges App Annie With Securities Fraud in $10 Million Settlement (protocol.com) 10

The Securities and Exchange Commission announced Tuesday that it's charging App Annie, the mobile app data provider, with securities fraud, accusing the company of "engaging in deceptive practices" and misrepresenting the origins of its data. From a report: App Annie will pay a $10 million settlement, according to the announcement, although the company has not admitted to any of the SEC's findings. According to the SEC, the company, which sells estimates on app downloads, usage and revenue, assured app businesses that the performance data they shared with App Annie would only be used in an anonymized way and run through an algorithm to generate performance estimates. But the SEC accuses App Annie and its former CEO and Chairman Bertrand Schmitt of reneging on that promise and using actual performance data to tweak its estimate models between 2014 and 2018. Then, the SEC alleges, the company sold that confidential data to trading firms, and misled those customers into thinking that the data was compliant with federal securities laws.
Android

Facebook Unveils Superpack, a New Compression Technique (fb.com) 54

An anonymous reader writes: Facebook unveiled a new compression technique they call 'Superpack compression.' In a blog post written by software engineer Sapan Bhatia, they claim that their compression improves Android app size by 20% over the default Zip compression used by Android. The post gives an overview of the compression ideas. The basis of these ideas is called out to be a key insight in Kolmogorov Complexity, that any data can be represented in the form of programs that generate that data. Facebook's tool, Superpack, mines out such small programs and optimizes them using compiler techniques.
Businesses

The IT Talent Gap is Still Growing (venturebeat.com) 109

IT executives see the talent shortage as the most significant adoption barrier to 64% of emerging technologies, according to a new Gartner survey. From a report: Across compute infrastructure and platform services, network, security, digital workplace, IT automation, and storage and database, respondents cited a lack of qualified candidates as a leading factor impeding tech deployment at their companies. "The ongoing push toward remote work and the acceleration of hiring plans in 2021 has exacerbated IT talent scarcity, especially for sourcing skills that enable cloud and edge, automation, and continuous delivery," Gartner research VP Yinuo Geng said in a press release.

"As one example, of all the IT automation technologies profiled in the survey, only 20% of them have moved ahead in the adoption cycle since 2020. The issue of talent is to blame here." The talent gaps are particularly acute for IT automation and digital workplace solutions, according to the executives surveyed -- a reflection of the demand for these technologies. According to McKinsey, nearly half of executives say their embrace of automation has accelerated, while digital and technology adoption is taking place about 25 times faster than before the pandemic. For example, Brain Corp reported that the use of robots to clean retail stores in the U.S. rose 24% in Q2 2020 year-over-year, and IBM has seen a surge in new users of its AI-driven customer service platform Watson Assistant.

Security

Apple Patches a NSO Zero-Day Flaw Affecting All Devices (techcrunch.com) 29

Apple has released security updates for a newly discovered zero-day vulnerability that affects every iPhone, iPad, Mac and Apple Watch. Citizen Lab, which discovered the vulnerability and was credited with the find, urges users to immediately update their devices. From a report: The technology giant said iOS 14.8 for iPhones and iPads, as well as new updates for Apple Watch and macOS, will fix at least one vulnerability that it said "may have been actively exploited." Citizen Lab said it has now discovered new artifacts of the ForcedEntry vulnerability, details it first revealed in August as part of an investigation into the use of a zero-day vulnerability that was used to silently hack into iPhones belonging to at least one Bahraini activist.

Last month, Citizen Lab said the zero day flaw -- named as such since it gives companies zero days to roll out a fix -- took advantage of a flaw in Apple's iMessage, which was exploited to push the Pegasus spyware, developed by Israeli firm NSO Group, to the activist's phone. Pegasus gives its government customers near-complete access to a target's device, including their personal data, photos, messages and location.

Security

Technology Giant Olympus Hit by BlackMatter Ransomware (techcrunch.com) 15

Olympus said in a brief statement that it is "currently investigating a potential cybersecurity incident" affecting its European, Middle East and Africa computer network. From a report: "Upon detection of suspicious activity, we immediately mobilized a specialized response team including forensics experts, and we are currently working with the highest priority to resolve this issue. As part of the investigation, we have suspended data transfers in the affected systems and have informed the relevant external partners," the statement said. But according to a person with knowledge of the incident, Olympus is recovering from a ransomware attack that began in the early morning of September 8. The person shared details of the incident prior to Olympus acknowledging the incident on Saturday. A ransom note left behind on infected computers claimed to be from the BlackMatter ransomware group.

"Your network is encrypted, and not currently operational," it reads. "If you pay, we will provide you the programs for decryption." The ransom note also included a web address to a site accessible only through the Tor Browser that's known to be used by BlackMatter to communicate with its victims. Brett Callow, a ransomware expert and threat analyst at Emsisoft, told TechCrunch that the site in the ransom note is associated with the BlackMatter group.

Firefox

Mozilla Has Defeated Microsoft's Default Browser Protections in Windows (theverge.com) 140

Mozilla has quietly made it easier to switch to Firefox on Windows recently. From a reporrt: While Microsoft offers a method to switch default browsers on Windows 10, it's more cumbersome than the simple one-click process to switch to Edge. This one-click process isn't officially available for anyone other than Microsoft, and Mozilla appears to have grown tired of the situation. In version 91 of Firefox, released on August 10th, Mozilla has reverse engineered the way Microsoft sets Edge as default in Windows 10, and enabled Firefox to quickly make itself the default. Before this change, Firefox users would be sent to the Settings part of Windows 10 to then have to select Firefox as a default browser and ignore Microsoft's plea to keep Edge. Mozilla's reverse engineering means you can now set Firefox as the default from within the browser, and it does all the work in the background with no additional prompts. This circumvents Microsoft's anti-hijacking protections that the company built into Windows 10 to ensure malware couldn't hijack default apps. Microsoft tells us this is not supported in Windows.
Education

Personal Data About Millions of Children Stolen from Schools, Leaked onto the Darkweb (nbcnews.com) 32

Long-time Slashdot reader phalse phace quotes NBC News: Most don't have bank passwords. Few have credit scores yet. And still, parts of the internet are awash in the personal information of millions of schoolchildren.

The ongoing wave of ransomware attacks has cost companies and institutions billions of dollars and exposed personal information about everyone from hospital patients to police officers. It's also swept up school districts, meaning files from thousands of schools are currently visible on those hackers' sites.

NBC News collected and analyzed school files from those sites and found they're littered with personal information of children. In 2021, ransomware gangs published data from more than 1,200 American K-12 schools, according to a tally provided to NBC News by Brett Callow, a ransomware analyst at the cybersecurity company Emsisoft.

Some schools contacted about the leaks appeared unaware of the problem. And even after schools are able to resume operations following an attack, parents have little recourse when their children's information is leaked. Some of the data is personal, like medical conditions or family financial statuses. Other pieces of data, such as Social Security numbers or birthdays, are permanent indicators of who they are, and their theft can set up a child for a lifetime of potential identity theft.

Microsoft

Study of 61,000 Microsoft Employees Finds Remote Work Threatened Productivity and Innovation (geekwire.com) 140

"A new study finds that Microsoft's companywide shift to remote work has hurt communication and collaboration among different business groups inside the company, threatening employee productivity and long-term innovation," reports GeekWire: That's one of the key findings in a peer-reviewed study of more than 61,000 Microsoft employees, published Thursday morning by Microsoft researchers in the journal Nature Human Behaviour.... The researchers call it a warning sign for other companies, as well. "Without intervention, the effects we discovered have the potential to impact workers' ability to acquire and share new information across groups, and as a result, affect productivity and innovation," they write in an accompanying blog post. "In light of these findings, companies should be thoughtful about if and how they choose to adopt long-term work-from-home policies."

The Microsoft study says remote work has also changed the way employees communicate, causing them to rely more frequently than before on asynchronous communication, such as email and instant messages, and less frequently than before on synchronous communication, such as audio and video calls. "Based on previous research, we believe that the shift to less 'rich' communication media may have made it more difficult for workers to convey and process complex information," the Microsoft researchers write. The study is based on an analysis of anonymized data about emails, calls, meetings, and other work activities by Microsoft employees.

At about the same time, Microsoft published a blog post summarizing the results of its own surveys of Microsoft employees — an opt-in survey of a random sample of 2,500. Some highlights: - In a year when we sent 160,000 people home to work and remotely onboarded 25,000 new employees, the share of people who report feeling included at Microsoft is at an all-time high of 90%. According to surveys, employee confidence and support from our managers is also at an all-time high...

- Our ongoing research shows employees crave more in-person time with their team but wish to keep the flexibility of remote work...

And Microsoft's LinkedIn also surveyed more than 500 C-level executives in the U.S. and U.K., "to better understand how employers are thinking about navigating this new world of work." Top of mind for executives is the same thing on the minds of employees — flexibility. With 87% of people saying they would prefer to stay remote at least half the time, a majority of employers are adapting: 81% of leaders are changing their workplace policies to offer greater flexibility. Despite all the change, leaders feel like there are opportunities ahead — more than half (58%) are optimistic that flexibility will be good for both people and the business.
Botnet

Krebs Also Hit By Massive DDOS, Apparently Caused by Compromised Routers (krebsonsecurity.com) 31

"On Thursday evening, KrebsOnSecurity was the subject of a rather massive (and mercifully brief) distributed denial-of-service (DDoS) attack," the site reports.

Citing a new blog post from DDoS protection firm Qrator Labs, Krebs writes that "The assault came from 'Meris,' the same new botnet behind record-shattering attacks against Russian search giant Yandex this week and internet infrastructure firm Cloudflare earlier this summer." A titanic and ongoing DDoS that hit Russian Internet search giant Yandex last week is estimated to have been launched by roughly 250,000 malware-infected devices globally, sending 21.8 million bogus requests-per-second. While last night's Meris attack on this site was far smaller than the recent Cloudflare DDoS, it was far larger than the Mirai DDoS attack in 2016 that held KrebsOnSecurity offline for nearly four days. The traffic deluge from Thursday's attack on this site was more than four times what Mirai threw at this site five years ago. This latest attack involved more than two million requests-per-second. By comparison, the 2016 Mirai DDoS generated approximately 450,000 requests-per-second.

According to Qrator, which is working with Yandex on combating the attack, Meris appears to be made up of Internet routers produced by MikroTik. Qrator says the United States is home to the most number of MikroTik routers that are potentially vulnerable to compromise by Meris — with more than 42 percent of the world's MikroTik systems connected to the Internet (followed by China — 18.9 percent- and a long tail of one- and two-percent countries). It's not immediately clear which security vulnerabilities led to these estimated 250,000 MikroTik routers getting hacked by Meris. "The spectrum of RouterOS versions we see across this botnet varies from years old to recent," the company wrote. "The largest share belongs to the version of firmware previous to the current stable one."

Krebs writes that the biggest contributor to the IoT botnet problem remains "a plethora of companies white-labeling [cheap] IoT devices that were never designed with security in mind and are often shipped to the customer in default-insecure states...

"The good news is that over the past five years, large Internet infrastructure companies like Akamai, Cloudflare and Google (which protects this site with its Project Shield initiative) have heavily invested in ramping up their ability to withstand these outsized attacks..."

One year earlier, back in 2015, Krebs had answered questions from Slashdot's readers.
China

Indonesian Intelligence Agency Compromised in Suspected Chinese Hack (therecord.media) 26

Chinese hackers have breached the internal networks of at least ten Indonesian government ministries and agencies, including computers from Indonesia's primary intelligence service, the Badan Intelijen Negara (BIN). From a report: The intrusion, discovered by Insikt Group, the threat research division of Recorded Future, has been linked to Mustang Panda, a Chinese threat actor known for its cyber-espionage campaigns targeting the Southeast Asian region. Insikt researchers first discovered this campaign in April this year, when they detected PlugX malware command and control (C&C) servers, operated by the Mustang Panda group, communicating with hosts inside the networks of the Indonesian government. These communications were later traced back to at least March 2021. The intrusion point and delivery method of the malware are still unclear.
Security

Apple Pays Hackers Six Figures To Find Bugs in Its Software. Then It Sits On their Findings. (washingtonpost.com) 23

Lack of communication, confusion about payments and long delays have security researchers fed up with Apple's bug bounty program. The Washington Post: Hoping to discover hidden weaknesses, Apple for five years now has invited hackers to break into its services and its iconic phones and laptops, offering up to $1 million to learn of its most serious security flaws. [...] But many who are familiar with the program say Apple is slow to fix reported bugs and does not always pay hackers what they believe they're owed. Ultimately, they say, Apple's insular culture has hurt the program and created a blind spot on security. "It's a bug bounty program where the house always wins," said Katie Moussouris, CEO and founder of Luta Security, which worked with the Defense Department to set up its first bug bounty program. She said Apple's bad reputation in the security industry will lead to "less secure products for their customers and more cost down the line."

Apple said its program, launched in 2016, is a work in progress. Until 2019, the program was not officially opened to the public, although researchers say the program was never exclusive. [...] In interviews with more than two dozen security researchers, some of whom spoke on the condition of anonymity because of nondisclosure agreements, the approaches taken by Apple's rivals were held up for comparison. Facebook, Microsoft and Google publicize their programs and highlight security researchers who receive bounties in blog posts and leader boards. They hold conferences and provide resources to encourage a broad international audience to participate. And most of them pay more money each year than Apple, which is at times the world's most valuable company.

Microsoft paid $13.6 million in the 12-month period beginning July 2020. Google paid $6.7 million in 2020. Apple spent $3.7 million last year, Krstic said in his statement. He said that number is likely to increase this year. Payment amounts aren't the only measure of success, however. The best programs support open conversations between the hackers and the companies. Apple, already known for being tight-lipped, limits communication and feedback on why it chooses to pay or not pay for a bug, according to security researchers who have submitted bugs to the bounty program and a former employee who spoke on the condition of anonymity because of a nondisclosure agreement. Apple also has a massive backlog of bugs that it hasn't fixed, according to the former employee and a current employee, who also spoke on the condition of anonymity because of an NDA.

Businesses

Wide-Ranging SolarWinds Probe Sparks Fear in Corporate America (reuters.com) 22

A U.S. Securities and Exchange Commission investigation into the SolarWinds Russian hacking operation has dozens of corporate executives fearful information unearthed in the expanding probe will expose them to liability, Reuters reported Friday, citing six people familiar with the inquiry. From the report: The SEC is asking companies to turn over records into "any other" data breach or ransomware attack since October 2019 if they downloaded a bugged network-management software update from SolarWinds, which delivers products used across corporate America, according to details of the letters shared with Reuters. People familiar with the inquiry say the requests may reveal numerous unreported cyber incidents unrelated to the Russian espionage campaign, giving the SEC a rare level of insight into previously unknown incidents that the companies likely never intended to disclose.

"I've never seen anything like this," said a consultant who works with dozens of publicly traded companies that recently received the request. "What companies are concerned about is they don't know how the SEC will use this information. And most companies have had unreported breaches since then." The consultant spoke on condition of anonymity to discuss his experience. The requests are voluntary, and companies are obliged to disclose anything material to investors. But the fact the inquiries comes from the SEC's enforcement staff could raise the prospect of investigations and steep penalties if companies fail to disclose breaches or did not have the appropriate controls in place to deal with past attacks, four attorneys who regularly handle SEC cases said.
Further reading: What it was like inside Microsoft during the worst cyberattack in history.
Encryption

WhatsApp Will Finally Let Users Encrypt Their Chat Backups in the Cloud (techcrunch.com) 12

WhatsApp said on Friday it will give its two billion users the option to encrypt their chat backups to the cloud, taking a significant step to put a lid on one of the tricky ways private communication between individuals on the app can be compromised. From a report: The Facebook-owned service has end-to-end encrypted chats between users for more than a decade. But users have had no option but to store their chat backup to their cloud -- iCloud on iPhones and Google Drive on Android -- in an unencrypted format. [...] Now WhatsApp says it is patching this weak link in the system.

The company said it has devised a system to enable WhatsApp users on Android and iOS to lock their chat backups with encryption keys. WhatsApp says it will offer users two ways to encrypt their cloud backups, and the feature is optional. In the "coming weeks," users on WhatsApp will see an option to generate a 64-digit encryption key to lock their chat backups in the cloud. Users can store the encryption key offline or in a password manager of their choice, or they can create a password that backs up their encryption key in a cloud-based "backup key vault" that WhatsApp has developed.

Microsoft

Microsoft Suggests Those Divisive Windows 11 System Specs Deliver a 99.8% Crash-free Experience (pcgamer.com) 187

PCGamer reports: Microsoft continues to double down on its assertion that the Windows 11 system requirements are absolutely necessary, and this whole TPM 2.0 schtick is vital for the safety of you, your PC, and maybe even the world. Okay, I made that last bit up, but the big M is sticking to its guns and has released another video backing its decision on excluding a whole lot of hardware that was fine with Windows 10. The latest claim is that you're going to see fewer blue screens of death -- or maybe black screens of death -- because of the new system requirements, citing a "99.8% crash-free experience in the [Windows 11] preview." Look, there's still a part of us that feels at some point in the future, maybe the distant future, Microsoft will turn around and say 'You know, what? We don't mind what processor you use with Windows 11,' but for right now this is where we're at. You need a modern CPU for Windows 11 for security and reliability.

And maybe a little performance. "So the requirement for Intel 8th Gen and AMD Ryzen 2000-series, and newer, chipsets does definitely contribute to performance," states Microsoft VP Steve Dispensa in the recent video. "But the main rationale here is actually the balanced security with performance. Security is at the core of these requirements." He does point to differences in how Windows 11 prioritises apps running in the foreground window. With the system running at 90% CPU load, it's still possible to get a responsive experience opening and using foreground apps thanks to these prioritisations.

Security

Hacker Lawyer Jay Leiderman Is Dead at 50 (gizmodo.com) 79

Jay Leiderman, a California defense attorney known for his whistleblower advocacy and defense of political dissidents and hackers, was confirmed dead in Ventura County on Thursday. He was 50 years old. From a report: Dubbed the "Hacktivist's Advocate" by The Atlantic in 2012, Leiderman gained national attention for his pro-bono work for clients accused of crashing corporate and government websites, including members of the group Anonymous. They were rarely good cases.

Leiderman's hacking clients had a nagging habit of openly admitting to the things they were accused of doing. One spent a decade fleeing authorities in several countries, giving interviews, all the while on the lam. (The client was just captured in June.) Still, their causes struck a chord with the Queens-born attorney, who'd long held to a rebellious legal philosophy. After a city in California passed a law criminalizing homelessness, the same client knocked one of its websites offline for half an hour. Where the FBI saw a felony computer crime worth up to 15 years in prison, Leiderman saw a peaceful protest against an unjust law -- a protest, he noted, that caused no perceptible harm.

Security

Russia's Yandex Says It Repelled Biggest DDoS Attack in History (yahoo.com) 39

head_dunce writes: A cyber attack on Russian tech giant Yandex's servers in August and September was the largest known distributed denial-of-service (DDoS) attack in the history of the internet, the company said on Thursday. The DDoS attack, in which hackers try to flood a network with unusually high volumes of data traffic in order to paralyse it when it can no longer cope with the scale of data requested, began in August and reached a record level on Sept. 5. "Our experts did manage to repel a record attack of nearly 22 million requests per second (RPS). This is the biggest known attack in the history of the internet," Yandex said in a statement. The previous record was held by Cloudflare, which said last month that it had mitigated a 17.2 RPS DDoS attack.
Encryption

Web Creator Tim Berners-Lee Joins ProtonMail's Advisory Board (zdnet.com) 30

The inventor of the World Wide Web, Tim Berners-Lee, has joined the advisory board of hosted email service provider ProtonMail. From a report: In a statement, ProtonMail CEO and founder Andy Yen said the addition of Berners-Lee to the company's advisory board was aligned with its goal to "create an internet where people are in control of their information at all times. Our vision is to build an internet where privacy is the default by creating an ecosystem of services accessible to everyone, everywhere, every day," Yen said. Yen said the company already had a past relationship with Berners-Lee, explaining that the idea of ProtonMail was initially conceived at CERN, the European Organization for Nuclear Research, where the World Wide Web was created.

The addition of Berners-Lee comes almost immediately after ProtonMail received flak for giving a climate activist's IP address to French authorities to comply with a Swiss court order. Addressing the logging of the IP address in a blog post earlier this week, Yen said all companies have to comply with laws, such as court orders, if they operate within 15 miles of land. "No matter what service you use, unless it is based 15 miles offshore in international waters, the company will have to comply with the law," Yen said.

Bitcoin

County IT Supervisor Mined Bitcoin At the Office, Prosecutors Say (nytimes.com) 85

An anonymous reader quotes a report from The New York Times: A Long Island man was charged on Wednesday with using his position as an I.T. supervisor for Suffolk County to mine cryptocurrency from government offices, costing the county thousands of dollars in electricity. Prosecutors said that Christopher Naples, 42, of Mattituck, L.I., had hidden 46 specialized devices used to mine Bitcoin and other cryptocurrencies in six rooms in the Suffolk County Center in Riverhead, including underneath floorboards and inside an unused electrical panel. Mr. Naples was charged with public corruption, grand larceny, computer trespass and official misconduct. If convicted of the top charge, he could face up to 15 years in prison.

Mr. Naples had admitted that the devices belonged to him and that he had been operating them for at least several months before the district attorney's office was alerted to the scheme. Prosecutors said that at least 10 of Mr. Naples's machines had been running since February, costing Suffolk County more than $6,000. [...] [G]iven that 36 more machines had been discovered, it was likely that Mr. Naples had cost the county thousands more. [...] [O]ne room in which Mr. Naples had placed the devices had critically important computer servers and other equipment for the entire county, and that the temperature in that room in which the devices were placed had dropped 20 degrees shortly after they were disabled.

Slashdot Top Deals