Encryption

UK.gov Is Launching An Anti-Facebook Encryption Push (theregister.com) 33

The British government is preparing to launch a full-scale policy assault against Facebook as the company gears up to introduce end-to-end encryption across all of its services. The Register reports: Prominent in details briefed to the news media this week (including The Register) were accusations that Facebook harbours paedophiles, terrorists, and mobsters and that British police forces would effectively be blinded to the scale of criminality on the social networking platform, save for cases where crimes are reported. It's a difficult and nuanced topic made no simpler or easier by the fact that government officials seem hellbent on painting it in black and white.

Government and law enforcement officials who briefed the press on condition of anonymity earlier this week* sought to paint a picture of the internet going dark if Facebook's plans for end-to-end encryption (E2EE) went forward, in terms familiar to anyone who remembers how Western nation states defended themselves from public upset after former NSA sysadmin Edward Snowden's 2013 revelations of illegal mass surveillance. The US National Centre for Missing and Exploited Children (NCMEC) generates around 20 million reports of child sexual abuse material (CSAM) every year, of which 70 per cent would be "lost" if E2E encryption were put in place, claimed British officials.

The government's long-signaled push to deter Facebook from implementing E2EE comes, inevitably, at a significant cost to taxpayers: London ad agency M&C Saatchi has been hired at an undisclosed cost by the Home Office to tell the public that Facebook (and WhatsApp) harbours criminals. The ad campaign will run online, in newspapers and on radio stations with the aim of turning public opinion against E2EE -- and, presumably, driving home the message that encryption itself is something inherently bad. Other announcements due this week, from notoriously anti-encryption Home Secretary Priti Patel and intergovernmental meetings, will explicitly condemn Facebook's contemplated rollout of E2EE.

IT

The Verge's 'Infamous' PC Build Gets Fixed (kotaku.com) 51

Luke Plunkett, writing at Kotaku: Back in 2018, The Verge released a guide to building a new PC that was, well, from where I was sitting it was not ideal. From where some angry PC nerds were sitting, though, it was an outrage. How bad was the video? It has its own knowyourmeme page, that's how bad. The guide was full of glaring omissions and bizarre tips, from a strange obsession with power usage to the most liberal use of thermal paste you've ever seen. The original video guide was eventually removed by The Verge (though you can see it here, and the written portion remains online), with the site claiming that it didn't meet their "editorial standards." Things took a turn for the worse when folks' initial bemusement with the guide quickly morphed into outright harassment from others, with author Stefan Etienne receiving a ton of racial abuse and The Verge issuing takedown notices on a couple of videos critical of the situation.

Anyway, that was 2018. We're not here to drag up bad old content and the ramblings of internet shitheads, we're here for the redemptive arc in this tale. That comes in the form of this new Linus Tech Tips video, where the host gets Etienne on to "fix" his old build, going through the same basic overall process as the original, making some changes (or just adding some extra information) at stops along the way. Etienne is a great sport throughout (and interestingly claims that The Verge's editorial basically threw him under the bus with the video section of the guide). The pair go through the original guide point by point, not just explaining how they'd improve things in 2021, but also allowing Etienne to break down just what was going on during the creation of the video as well.
[H/T UnknowingFool.]
Security

Notorious Russian Ransomware Group 'REvil' Has Reappeared (bloomberg.com) 9

The infamous criminal ransomware group behind the JBS SA cyberattack has returned to the dark web after vanishing this summer. From a report: "REvil," short for "Ransomware-Evil," is among the most prolific cyber gangs to hold data for ransom. The group operates from Russia, according to cybersecurity firms and the U.S. government, and is accused of leading a flurry of attacks this year against companies and organizations, including JBS. The giant Brazilian meat supplier eventually paid an $11 million ransom. REvil runs a website called the "Happy Blog," where it publishes samples of data stolen before locking companies out of their own networks. The attackers then try to persuade targets to pay for a digital key to restore network access.

A portal REvil uses to negotiate with victims also came back online on Tuesday, according to Adam Meyers, vice president of intelligence at cybersecurity firm CrowdStrike, although the cybergang hasn't posted any new victims. Meyers says it appears the site was restored by the same actors running the portal before it went offline in June without explanation. "I would think this was a cool-off period," he said. "There was a lot of heat back in June/July. Maybe they rebuilt some infrastructure and invested in better operational security."

Security

McDonald's Leaks Password For Monopoly VIP Database To Winners (bleepingcomputer.com) 33

A bug in the McDonald's Monopoly VIP game in the United Kingdom caused the login names and passwords for the game's database to be sent to all winners. BleepingComputer reports: After skipping a year due to COVID-19, McDonald's UK launched their popular Monopoly VIP game on August 25th, where customers can enter codes found on purchase food items for a chance to win a prize. These prizes include 100,000 pounds in cash, an Ibiza villa or UK getaway holiday, Lay-Z Spa hot tubs, and more. Unfortunately, the game hit a snag over the weekend after a bug caused the user name and passwords for both the production and staging database servers to be in prize redemption emails sent to prize winners.

An unredacted screenshot of the email sent to prize winners was shared with BleepingComputer by Troy Hunt that shows an exception error, including sensitive information for the web application. This information included hostnames for Azure SQL databases and the databases' login names and passwords, as displayed in the redacted email below sent to a Monopoly VIP winner. The prize winner who shared the email with Troy Hunt said that the production server was firewalled off but that they could access the staging server using the included credentials. As these databases may have contained winning prize codes, it could have allowed an unscrupulous person to download unused game codes to claim the prizes. Luckily for McDonald's, the person responsibly disclosed the issue with McDonald's, and while they did not receive a response, they later found that the staging server's password was soon changed.

Education

Howard University Announces Ransomware Attack, Shuts Down Classes On Tuesday (zdnet.com) 52

An anonymous reader quotes a report from ZDNet: Howard University announced on Monday that it has been hit with a ransomware attack, forcing the school to shut down classes on Tuesday, according to a statement from the prominent HBCU. The school said that on September 3, members of their technology team noticed "unusual activity" on the university's network and shut it down in order to investigate the problem. They later confirmed it was a ransomware attack but did not say which group was behind the attack.

"The situation is still being investigated, but we are writing to provide an interim update and to share as much information as we safely and possibly can at this point in time, considering that our emails are often shared within a public domain," Howard University said in a statement. "ETS and its partners have been working diligently to fully address this incident and restore operations as quickly as possible; but please consider that remediation, after an incident of this kind, is a long haul -- not an overnight solution." The school has contacted law enforcement and is working with forensic experts on the issue. They claim there is "no evidence of personal information being accessed or exfiltrated" but noted that the investigation is ongoing. The school was forced to cancel all classes on Tuesday in order to address the issue and the campus is only open to essential employees. Even the campus Wi-Fi is down. They noted that some cloud applications will remain accessible to students and that they will continue to update students and faculty at 2pm each day.

"This is a moment in time for our campus when IT security will be at its tightest. We recognize that there has to be a balance between access and security; but at this point in time, the University's response will be from a position of heightened security," the school added. "This is a highly dynamic situation, and it is our priority to protect all sensitive personal, research and clinical data. We are in contact with the FBI and the D.C. city government, and we are installing additional safety measures to further protect the University's and your personal data from any criminal ciphering. You will receive additional communications from ETS over the course of the next few hours and continuing into the next few days, especially surrounding phishing attempts and how to protect your data online beyond the Howard University community."

Security

Ghostscript Zero-Day Allows Full Server Compromises (therecord.media) 40

Proof-of-concept exploit code was published online over the weekend for an unpatched Ghostscript vulnerability that puts all servers that rely on the component at risk of attacks. From a report: Published by Vietnamese security researcher Nguyen The Duc, the proof-of-concept code is available on GitHub and was confirmed to work by several of today's leading security researchers. Released back in 1988, Ghostscript is a small library that allows applications to process PDF documents and PostScript-based files. While its primary use is for desktop software, Ghostscript is also used server-side, where it is typically included with image conversion and file upload processing toolkits, such as the popular ImageMagick. The proof-of-concept code released by Nguyen on Sunday exploits this latter scenario, allowing an attacker to upload a malformed SVG file that escapes the image processing pipeline and runs malicious code on the underlying operating system. While Nguyen released the public exploit for this bug, he is not the one who discovered the vulnerability.
IT

Is Remote Working Leading to a Boom in Worker Surveillance? (theguardian.com) 91

A Guardian article begins with the story of how a digital surveillance platform called Sneek ruined the first week on the job for a remote worker named David: Every minute or so, the program would capture a live photo of David and his workmates via their company laptop webcams. The ever-changing headshots were splayed across the wall of a digital conference waiting room that everyone on the team could see. Clicking on a colleague's face would unilaterally pull them into a video call. If you were lucky enough to catch someone goofing off or picking their nose, you could forward the offending image to a team chat via Sneek's integration with the messaging platform Slack.

According to the Sneek co-founder Del Currie, the software is meant to replicate the office. "We know lots of people will find it an invasion of privacy, we 100% get that, and it's not the solution for those folks," Currie says. "But there's also lots of teams out there who are good friends and want to stay connected when they're working together." For David, though, Sneek was a dealbreaker. He quit after less than three weeks on the job. "I signed up to manage their digital marketing," he tells me, "not to livestream my living room."

Little did he realize that his experience was part of a wide-scale boom in worker surveillance- and one that's poised to become a standard feature of life on the job... One of the major players in the industry, ActivTrak, reports that during March 2020 alone, the firm scaled up from 50 client companies to 800. Over the course of the pandemic, the company has maintained that growth, today boasting 9,000 customers — or, as it claims, more than 250,000 individual users. Time Doctor, Teramind, and Hubstaff — which, together with ActivTrak, make up the bulk of the market — have all seen similar growth from prospective customers.

These software programs give bosses a mix of options for monitoring workers' online activity and assessing their productivity: from screenshotting employees' screens to logging their keystrokes and tracking their browsing.

Speaking to the Guardian, Juan Carloz, a digital researcher and privacy advocate with the University of Melbourne, shares a theory about why remote workers aren't pushing back against surveillance softare.

"Since, rightly or wrongly, [its] being framed as a trade-off for remote work, many are all too content to let it slide."
Security

Malware Found Preinstalled In Classic Push-button Phones Sold In Russia (therecord.media) 40

"A security researcher has discovered malicious code inside the firmware of four low-budget push-button mobile phones sold through Russian online stores," reports the Record: In a report published this week by a Russian security researcher named ValdikSS, push-button phones such as DEXP SD2810, Itel it2160, Irbis SF63, and F+ Flip 3 were caught subscribing users to premium SMS services and intercepting incoming SMS messages to prevent detection. ValdikSS, who set up a local 2G base station in order to intercept the phones' communications, said the devices also secretly notified a remote internet server when they were activated for the first time, even if the phones had no internet browser...

All the remote servers that received this activity were located in China, ValdikSS said, where all the devices were also manufactured before being re-sold on Russian online stores as low-budget alternatives to more popular push-button phone offerings, such as those from Nokia.

But who's responsible, the article ultimately asks. The third party supplying the firmware? The parties shipping the phones? The vendors selling the phone without detecting its malware? Or the government agencies lacking a mechanism for collecting reports of malware...
Security

In Novel Attack Technique, Salesforce Email Service Used For Phishing Campaign (esecurityplanet.com) 21

Slashdot reader storagedude writes: In a novel attack technique, Israeli security researchers discovered that cybercriminals were subscribing to Salesforce in order to use its email service to launch a phishing campaign and thus bypass corporate security defenses like whitelisting.

The researchers, from email security service provider Perception Point, said bad actors are sending phishing emails via the Salesforce email service by impersonating the Israel Postal Service in a campaign that has targeted multiple Israeli organizations.

In a blog post, security analysts Miri Slavoutsky and Shai Golderman wrote that this is the first time they had seen attackers abuse Salesforce services for malicious purposes.

"Mass Email gives users the option to send an individual, personalized email to each recipient, thus creating the perception of receiving a unique email, created especially for you," Slavoutsky and Golderman wrote. "Spoofing attempts of Salesforce are nothing new to us. Attackers spoof emails from Salesforce for credential theft, is a typical example. In this case, the attackers actually purchased and abused the service; knowing that most companies use this service as part of their business, and therefore have it whitelisted and even allowed in their SPF records."

Shlomi Levin, Perception Point's co-founder and CTO, told eSecurity Planet that given how whitelisting a trusted source can result in security breaches, "it is essential to employ a zero-trust attitude combined with a strong filtering mechanism to any content that enters the organization no matter the source: email, collaboration tools or Instant Messaging."

Stephen Banda, senior manager of security solutions at cybersecurity vendor Lookout, agreed with the researchers that it's a new approach by malicious actors.

"The practice of legitimately signing up for an email service with the full intention of using it for malice is an innovative strategy," Banda said. "This breach should be a warning to all service providers to conduct extensive due diligence into who is requesting access to their services so that this type of scam can be avoided in the future."

"There are ways to detect spoofing but in this case the emails look authentic and are also coming from where they say they are coming from," said Saumitra Das, CTO of cybersecurity firm Blue Hexagon. "This means that attackers have got through the first email firewall both from a threat intelligence signature perspective of blocking known bad sources and also in some sense the instinct of the user themselves to be suspicious of what something is. It is common for attacks to get through email security solutions, but then well-trained or savvy users are the next line of defense. This [use of a legitimate email service] increases the chances of those users also clicking on links or downloading attachments."

Encryption

America's NSA Isn't Sure Quantum Computers Will Ever Break Public Key Encryption (msn.com) 92

America's National Security Agency "isn't really sure when or even if quantum computers will be able to crack public key cryptography," writes TechRadar.

They report that the NSA "has expressed its reservations about the potential of quantum computing" in a new FAQ titled Quantum Computing and Post-Quantum Cryptography. "NSA does not know when or even if a quantum computer of sufficient size and power to exploit public key cryptography (a CRQC) will exist," said the security agency in response to whether it is worried about the potential of adversarial use of quantum computing. In the FAQ, the NSA describes a Cryptographically Relevant Quantum Computer (CRQC) as a quantum computer that's capable of actually attacking real world cryptographic systems, something that's currently infeasible.

While it agrees that such a computer would be "devastating" to the digital security infrastructure, it seems to suggest that it doesn't believe such a CRQC would ever materialize.

However, the growing research in quantum computing has moved the agency to also support the development of post-quantum cryptographic standards, along with plans for eventual transition to such standards.

Security

Banksy Was Warned About Website Flaw Before NFT Hack Scam (bbc.com) 29

Artist Banksy's team was warned his website had a security weakness seven days before a hacker scammed a fan out of $336,000. The BBC reports: On Tuesday a piece of art was advertised on Banksy's official website as the world-renowned graffiti artist's first NFT (non-fungible token). A British collector won the auction to buy it, before realizing it was a fake. A cyber-security expert warned Banksy that the website could be hacked, but was ignored. Sam Curry, a professional ethical hacker from the US and founder of security consultancy Palisade, said he first heard that the site could have a weakness on the social network Discord, last month.

"I was in a security forum and multiple people were posting links to the site. I'd clicked one and immediately saw it was vulnerable, so I reached out to Banksy's team via email as I wasn't sure if anyone else had. "They didn't respond over email, so I tried a few other ways to contact them including their Instagram, but never received a response." Mr Curry's disclosure, first reported by rekt.news was made initially by email on 25 August. The BBC was shown the email thread and has tried to contact Banksy's team several times, with no response.

Mr Curry says the website flaw -- which has now been fixed -- "allowed you to create arbitrary files on the website" and post your own pages and content. The new page, called 'Banksy.co.uk/NFT,' was deleted shortly after the auction, with Banksy's team saying: "Any Banksy NFT auctions are not affiliated with the artist in any shape or form." The British man who won the auction is a prominent NFT collector and Banksy fan known on Twitter as Pranksy. He said he felt "burned" when he was scammed out of nearly $340,000 in cryptocurrency coins, but was relieved when the hacker inexplicably returned most of the money to him by the end of the day.

China

Chinese Hackers Behind July 2021 SolarWinds Zero-day Attacks (therecord.media) 13

In mid-July this year, Texas-based software provider SolarWinds released an emergency security update to patch a zero-day in its Serv-U file transferring technology that was being exploited in the wild. From a report: At the time, SolarWinds did not share any details about the attacks and only said that it learned of the bug from Microsoft's security team. In a blog post on Thursday, Microsoft revealed more details about the July attacks. The company said the zero-day was the work of a new threat actor the company was tracking as DEV-0322, which Microsoft described as "a group operating out of China, based on observed victimology, tactics, and procedures." Microsoft said the group targeted SolarWinds Serv-U servers "by connecting to the open SSH port and sending a malformed pre-auth connection request," which allowed DEV-0322 operators to run malicious code on the targeted system and take over vulnerable devices. The OS maker did not go into details about what the intruders did once they breached a target. It is unclear if the hackers were interested in cyber-espionage and intelligence collection or if DEV-0322 was a run-of-the-mill crypto-mining gang.
Android

Pixel 3 and 3 XL Phones Are Getting Stuck In EDL Mode and Seemingly Bricked (androidpolice.com) 72

New submitter throx shares a report from Android Police: For months users of the three-year-old Pixel 3 series have been complaining of a common and dreadful problem: seemingly random shutdowns that completely lock their devices. The Pixel 3 and 3 XL have been plagued by the "EDL Mode" bug, which locks the device with no screen or button inputs and makes it more or less impossible to use. To date there's no clear solution to this problem, at least not one that's easily available to even advanced users.

Google's official support channels are aware of the issue, and that it seems to be accelerating in terms of users in the last few months. But since more or less every Pixel 3 and 3 XL sold is out of warranty at this point, options are limited. You can start an official support ticket with Google and pay for a repair, or (as one volunteer on the Google support forums suggests) take it into an authorized repair shop to see if their Qualcomm tools can get the phone to wake up. At the time of writing there doesn't seem to be any indication of a user-accessible fix for the EDL issues.

Security

Gift Card Gang Extracts Cash From 100K Inboxes Daily (krebsonsecurity.com) 10

Cybercrime and computer security reporter Brian Krebs tells the story of a cybercrime group that compromises up to 100,000 email inboxes per day, and apparently does little else with this access except siphon gift card and customer loyalty program data that can be resold online. From the report: The data in this story come from a trusted source in the security industry who has visibility into a network of hacked machines that fraudsters in just about every corner of the Internet are using to anonymize their malicious Web traffic. For the past three years, the source -- we'll call him "Bill" to preserve his requested anonymity -- has been watching one group of threat actors that is mass-testing millions of usernames and passwords against the world's major email providers each day. Bill said he's not sure where the passwords are coming from, but he assumes they are tied to various databases for compromised websites that get posted to password cracking and hacking forums on a regular basis. Bill said this criminal group averages between five and ten million email authentication attempts daily, and comes away with anywhere from 50,000 to 100,000 of working inbox credentials.

In about half the cases the credentials are being checked via "IMAP," which is an email standard used by email software clients like Mozilla's Thunderbird and Microsoft Outlook. With his visibility into the proxy network, Bill can see whether or not an authentication attempt succeeds based on the network response from the email provider (e.g. mail server responds "OK" = successful access). You might think that whoever is behind such a sprawling crime machine would use their access to blast out spam, or conduct targeted phishing attacks against each victim's contacts. But based on interactions that Bill has had with several large email providers so far, this crime gang merely uses custom, automated scripts that periodically log in and search each inbox for digital items of value that can easily be resold. And they seem particularly focused on stealing gift card data.

"Sometimes they'll log in as much as two to three times a week for months at a time," Bill said. "These guys are looking for low-hanging fruit -- basically cash in your inbox. Whether it's related to hotel or airline rewards or just Amazon gift cards, after they successfully log in to the account their scripts start pilfering inboxes looking for things that could be of value." According to Bill, the fraudsters aren't downloading all of their victims' emails: That would quickly add up to a monstrous amount of data. Rather, they're using automated systems to log in to each inbox and search for a variety of domains and other terms related to companies that maintain loyalty and points programs, and/or issue gift cards and handle their fulfillment. Why go after hotel or airline rewards? Because these accounts can all be cleaned out and deposited onto a gift card number that can be resold quickly online for 80 percent of its value.

Security

Seemingly Normal Lightning Cable Will Leak Everything You Type (vice.com) 51

An anonymous reader quotes a report from Motherboard: It looks like a Lightning cable, it works like a Lightning cable, and I can use it to connect my keyboard to my Mac. But it is actually a malicious cable that can record everything I type, including passwords, and wirelessly send that data to a hacker who could be more than a mile away. This is the new version of a series of penetration testing tools made by the security researcher known as MG. MG previously demoed an earlier version of the cables for Motherboard at the DEF CON hacking conference in 2019. Shortly after that, MG said he had successfully moved the cables into mass production, and cybersecurity vendor Hak5 started selling the cables. But the more recent cables come in new physical variations, including Lightning to USB-C, and include more capabilities for hackers to play with.

"There were people who said that Type C cables were safe from this type of implant because there isn't enough space. So, clearly, I had to prove that wrong. :)," MG told Motherboard in an online chat. The OMG Cables, as they're called, work by creating a Wi-Fi hotspot itself that a hacker can connect to from their own device. From here, an interface in an ordinary web browser lets the hacker start recording keystrokes. The malicious implant itself takes up around half the length of the plastic shell, MG said. MG said that the new cables now have geofencing features, where a user can trigger or block the device's payloads based on the physical location of the cable. "It pairs well with the self-destruct feature if an OMG Cable leaves the scope of your engagement and you do not want your payloads leaking or being accidentally run against random computers," he said. "We tested this out in downtown Oakland and were able to trigger payloads at over 1 mile," he added. He said that the Type C cables allow the same sort of attacks to be carried out against smartphones and tablets. Various other improvements include being able to change keyboard mappings, the ability to forge the identity of specific USB devices, such as pretending to be a device that leverages a particular vulnerability on a system.

Security

Juniper Breach Mystery Starts To Clear With New Details on Hackers and US Role (yahoo.com) 19

An anonymous reader shares a report: An anonymous reader Days before Christmas in 2015, Juniper Networks alerted users that it had been breached. In a brief statement, the company said it had discovered "unauthorized code" in one of its network security products, allowing hackers to decipher encrypted communications and gain high-level access to customers' computer systems. Further details were scant, but Juniper made clear the implications were serious: It urged users to download a software update "with the highest priority." More than five years later, the breach of Juniper's network remains an enduring mystery in computer security, an attack on America's software supply chain that potentially exposed highly sensitive customers including telecommunications companies and U.S. military agencies to years of spying before the company issued a patch.

Those intruders haven't yet been publicly identified, and if there were any victims other than Juniper, they haven't surfaced to date. But one crucial detail about the incident has long been known -- uncovered by independent researchers days after Juniper's alert in 2015 -- and continues to raise questions about the methods U.S. intelligence agencies use to monitor foreign adversaries. The Juniper product that was targeted, a popular firewall device called NetScreen, included an algorithm written by the National Security Agency. Security researchers have suggested that the algorithm contained an intentional flaw -- otherwise known as a backdoor -- that American spies could have used to eavesdrop on the communications of Juniper's overseas customers. NSA declined to address allegations about the algorithm.

Juniper's breach remains important -- and the subject of continued questions from Congress -- because it highlights the perils of governments inserting backdoors in technology products. "As government agencies and misguided politicians continue to push for backdoors into our personal devices, policymakers and the American people need a full understanding of how backdoors will be exploited by our adversaries," Senator Ron Wyden, a Democrat from Oregon, said in a statement to Bloomberg. He demanded answers in the last year from Juniper and from the NSA about the incident, in letters signed by 10 or more members of Congress.

Software

Car Owners' New Gripe: Lousy Wireless Service (axios.com) 84

The biggest frustration among new car owners is that they can't get their car and smartphone to talk to one another, a new J.D. Power study finds. From a report: Consumers want their digital lives to follow them seamlessly in the car, which is why Apple CarPlay and Android Auto have become so popular. But if the wireless connection is glitchy, such features don't work, leaving car owners unhappy. "Owners are caught in the middle when vehicle and phone technologies don't properly connect," says Dave Sargent, vice president of automotive quality at J.D. Power.

1 in 4 problems cited by car buyers in the first 90 days of ownership involves infotainment, according to the J.D. Power 2021 Initial Quality Study (IQS), released Tuesday. For the first time in a decade, voice recognition is not the top problem; instead, it's Apple CarPlay/Android Auto connectivity, which worsened significantly, especially for those trying to connect wirelessly. About one-third of new cars now come with a built-in WiFi hub, which may or may not be compatible with a phone's operating system.

Windows

Microsoft Will Release Windows 11 on October 5 (theverge.com) 83

Microsoft is announcing that Windows 11 will be released on October 5. The new operating system will be available as a free upgrade for eligible Windows 10 PCs, or on new hardware that ships with Windows 11 pre-loaded. From a report: The free upgrade to Windows 11 will start rolling out on October 5th, but like many Windows upgrades in the past, it will be available in phases. New eligible devices will be offered the upgrade first, and then Windows 11 will become available for more in-market devices in the weeks and months following October 5th. "Following the tremendous learnings from Windows 10, we want to make sure we're providing you with the best possible experience," explains Aaron Woodman, general manager of Windows marketing at Microsoft. "We expect all eligible devices to be offered the free upgrade to Windows 11 by mid-2022."
Microsoft

Microsoft is Threatening To Withhold Windows 11 Updates If Your CPU is Old (theverge.com) 226

Last week, media reported how Microsoft's Windows 11 won't technically leave millions of PCs behind -- the company told the press that it won't actually block you from installing Windows 11 on a PC with an older CPU, so long as you download and manually install an ISO file all by yourself. But it turns out even that technicality has a technicality. The Verge: Microsoft is now threatening to withhold Windows Updates from your copy of Windows 11 -- potentially even security updates -- if you take that route. We're not sure why the company didn't mention it in our original briefing, but Microsoft has since told The Verge that unsupported PCs won't be entitled to receive Windows Updates, and that even security and driver updates may be withheld.
Google

Should Google Cut Salaries For Its Remote Workers? (inc.com) 429

A columnist for Inc. writes that Google "may reduce the salaries of employees who choose to work at home full-time, based on the cost of living where they live, according to an internal calculator viewed by Reuters."

They also argue that Google's move is "likely to be a disaster." It may seem sensible, given that a salary that barely covers a San Francisco studio apartment might get you a mansion in, say, Topeka. That's the logic Google says it's using. "Our compensation packages have always been determined by location," a spokesperson told Reuters.

But cutting pay for existing employees who opt to work from home is a terrible idea and it shows a complete lack of emotional intelligence. If Google is smart, it will shelve this idea. So will Facebook, Twitter, the UK government, and any other company considering a similar move. Here's why:

1. A salary is about more than just paying the bills... In real life, a pay cut will feel like an insult to most employees, even if it has nothing to do with their performance or their value to the company. You're literally telling them that they're worth less. Is that the message you want them to hear?

2. Google is being greedy... Like other tech giants, it's thrived during the pandemic. Cutting people's salaries when your share price has more than doubled, your revenues are up 62 percent, and your profits are up even more seems like the pinnacle of corporate greed. Not a good look.

3. It will make Google even more unequal than it already is...

Slashdot Top Deals