Stats

'Silent Majority' of Americans Don't Want to Work Remotely Full-Time (yahoo.com) 277

"While workers who want to stay at home forever have been especially vocal about their demands, a silent majority of Americans do want to get back to the office, at least for a few days a week..." reports the New York Times. The article, shared by long-time Slashdot reader gollum123, cites the opinions of workers in a variety of industries. In a national survey of more than 950 workers, conducted in mid-August by Morning Consult on behalf of The New York Times, 31 percent said they would prefer to work from home full time. By comparison, 45 percent said they wanted to be in a workplace or an office full time. The remaining 24 percent said they wanted to split time between work and home... The data intelligence company's findings echoed recent internal surveys by employers like Google and Twitter, as well as outside surveys by firms like Eden Workplace. Among those craving the routines of office life and cubicle chatter: social butterflies, managers, new hires eager to meet colleagues, and people with noisy or crowded homes...

Certainly, some people have thrived in their new remote work lives. They saved time and money, and sometimes increased productivity. The degree to which employees have embraced permanent remote or hybrid work models has been "stunning" to company executives, said Tsedal Neeley, a Harvard Business School professor who has studied remote work for decades. But for others, Professor Neeley said, it has removed needed barriers between work and home life, increased a sense of isolation and led to burnout. "Some people just dislike the screen — their physicality and their proximity to others is a big part of what work looks like," she said.

In the Times' article, here's how one 23-year-old recent college graduate starting at Google described their own dilemma.

"If we don't get a really solid foundation at this company in our first six months, our first year, what foot does that leave us on for the rest of our time at the company?"
Education

Code.org Will Teach 'Cybersecurity Hygiene' to Millions of Students 29

Long-time Slashdot reader theodp writes: Mr. President," Code.org founder Hadi Partovi told President Joe Biden and tech CEOs from Microsoft, Amazon, Google, Apple, and IBM at Wednesday's Presidential Summit on Cybersecurity, "America's cybersecurity problem is an education problem. I loved [Microsoft CEO] Satya Nadella's wonderful analogy to the car industry, and like Satya said, we need standards for seatbelts in every car for sure. But if none of the drivers took a course in basic safety skills, our roads could never, ever be safe. That's the current state of affairs on the roads of the internet. Without proper education, we can't address our nation's weakest link. If you look around, every CEO is nodding their head because they know we need a plan to educate every American on basic cyber security hygiene, and also a plan to staff up our cyber defense workforce. This needs to start early, in K-12, and reach everybody."

A newly-released White House Fact Sheet announcing "Ambitious Initiatives to Bolster the Nation's Cybersecurity" notes that tech-bankrolled "Code.org announced it will teach cybersecurity concepts to over 3 million students across 35,000 classrooms over 3 years, to teach a diverse population of students how to stay safe online, and to build interest in cybersecurity as a potential career."
Security

How Microsoft, Google, Apple, and IBM Will Help the US Improve Its Cybersecurity (infosecurity-magazine.com) 19

Infosecurity magazine reports: Some of the world's biggest tech companies have committed tens of billions of dollars to improving supply chain security, closing industry skills gaps and driving security awareness among the public, according to the White House.

As reported by Infosecurity yesterday, the Biden administration welcomed the CEOs of Microsoft, Apple, Google, IBM and others to a meeting yesterday to discuss the "whole-of-nation" effort needed to address cybersecurity threats." The result of that encounter has been a series of commitments from these firms, including $10bn from Google over the next five years to expand zero trust and improve supply chain and open source security. The tech giant will apparently also help 100,000 Americans earn "digital skills certificates."

IBM said it would train 150,000 people in cyber skills over the coming three years and focus on improving the diversity of the security workforce, while Microsoft has committed $20bn over five years to drive security by design, and $150m for federal, local and state governments. Apple will establish a new program to improve supply chain security, including among its 9000 US suppliers, with multi-factor authentication (MFA), vulnerability remediation, event logging and incident response all playing a key role. Amazon is making MFA devices available to all AWS customers and rolling out the security training it offers employees to the general public.

Aside from these commitments, the White House announced the expansion of its Industrial Control Systems Cybersecurity Initiative, from the electricity sector to natural gas pipelines, and said the National Institute of Standards and Technology (NIST) would develop a new framework for supply chain security. In another potentially significant move, insurer Resilience said it would require policyholders to meet a threshold of cybersecurity best practice as a condition of receiving coverage — something experts have been demanding for some time across the industry.

NextGov.com also quotes the president's remarks about a cybersecurity executive order issued May 12th: "Because of that order, government will only buy tech products that meet certain cybersecurity standards, which will have a ripple effect across the software industry, in our view, ultimately improving security for all Americans,"
Communications

T-Mobile Says Hacker Used Specialized Tools, Brute Force (bloomberg.com) 20

T-Mobile said a cyberattack earlier this month that exposed millions of customer records was carried out using specialized tools to gain entry to the network, followed by brute force-style hacking techniques to access user data. From a report: "In short, this individual's intent was to break in and steal data, and they succeeded," Chief Executive Officer Mike Sievert said Friday in a statement, the company's fullest account yet of what happened. The company has hired cybersecurity provider Mandiant and consulting firm KPMG to improve its defenses, he said. The breach, the fourth that has compromised T-Mobile customer records in as many years, involved personal information including names, dates of birth, Social Security numbers and driver's license information. Sievert said the company is working with law enforcement and can't share further details of what happened. Further reading: T-Mobile Hacker Explains How He Breached Carrier's Security.
Security

Academics Bypass PINs for Mastercard and Maestro Contactless Payments (therecord.media) 10

A team of scientists from a Swiss university has discovered a way to bypass PIN codes on contactless cards from Mastercard and Maestro. From a report: The now-patched vulnerability would have allowed cybercriminals to use stolen Mastercard and Maestro cards to pay for expensive products without needing to provide PINs on contactless payments. Discovered by a team from the Department of Computer Science at the ETH Zurich university, the attack is extremely stealthy and could be easily deployed in a real-world scenario if new bugs in contactless payment protocols are discovered. The general idea behind the attack is for an attacker to interpose itself between the stolen card and a vendor's Point-of-Sale (PoS) terminal, in what security researchers would normally call a Man/Person/Meddler-in-the-Middle (MitM) scenario.

To achieve this, an attacker would require: a stolen card, two Android smartphones, a custom-made Android app that can tamper with a transaction's fields. The app is installed on both smartphones, which will act as emulators. One smartphone will be placed near the stolen card and act as a PoS emulator, tricking the card into initiating a transaction and sharing its details, while the second smartphone will act as a card emulator and be used by a crook to feed modified transaction details to a real-life PoS terminal inside a store.

The Internet

Why Are Hyperlinks Blue? (mozilla.org) 77

Elise Blanchard, writing on Mozilla blog: [...]

What happened in 1993 to suddenly make hyperlinks blue? No one knows, but I have some theories. I often hear that blue was chosen as the hyperlink color for color contrast. Well, even though the W3C wasn't created until 1994, and so the standards for which we judge web accessibility weren't yet defined, if we look at the contrast between black as a text color, and blue as a link color, there is a contrast ratio of 2.3:1, which would not pass as enough color contrast between the blue hyperlink and the black text. Instead, I like to imagine that Cello and Mosaic were both inspired by the same trends happening in user interface design at the time. My theory is that Windows 3.1 had just come out a few months before the beginning of both projects, and this interface was the first to use blue prominently as a selection color, paving the way for blue to be used as a hyperlink color.

Additionally, we know that Mosaic was inspired by ViolaWWW, and kept the same gray background and black text that they used for their interface. Reviewing Mosaic's release notes, we see in release 0.7 black text with underlines appearing as the preferred way of conveying hyperlinks, and we can infer that was still the case until something happened around mid April right before when blue hyperlinks made their appearance in release 0.13. In fact, conveying links as black text with underlines had been the standard since 1985 with Microsoft 1, which some once claimed Microsoft had stolen from Apple's Lisa's look and feel.

I think the real reason why we have blue hyperlinks is simply because color monitors were becoming more popular around this time. Mosaic as a product also became popular, and blue hyperlinks went along for the ride. Mosaic came out during an important time where support for color monitors was shifting; the standard was for hyperlinks to use black text with some sort of underline, hover state or border. Mosaic chose to use blue, and they chose to port their browser for multiple operating systems. This helped Mosaic become the standard browser for internet use, and helped solidify its user interface as the default language for interacting with the web.

Microsoft

Microsoft Warns Thousands of Cloud Customers of Exposed Databases (reuters.com) 43

Microsoft has warned thousands of its cloud computing customers, including some of the world's largest companies, that intruders could have the ability to read, change or even delete their main databases, according to a copy of the email and a cyber security researcher. From a report: The vulnerability is in Microsoft Azure's flagship Cosmos database. A research team at security company Wiz discovered it was able to access keys that control access to databases held by thousands of companies. Wiz Chief Technology Officer Ami Luttwak is a former chief technology officer at Microsoft's Cloud Security Group. Because Microsoft cannot change those keys by itself, it emailed the customers Thursday telling them to create new ones. Microsoft agreed to pay Wiz $40,000 for finding the flaw and reporting it, according to an email it sent to Wiz. Microsoft's email to customers said it has fixed the vulnerability and that there was no evidence the flaw had been exploited. "We have no indication that external entities outside the researcher (Wiz) had access to the primary read-write key," according to a copy of the email seen by Reuters.
Security

T-Mobile Hacker Explains How He Breached Carrier's Security (axios.com) 26

According to the Wall Street Journal, the person behind T-Mobile's recent security breach that affected more than 50 million customers is a 21-year-old named John Binns. " Binns said he broke through the T-mobile defenses after discovering an unprotected router exposed on the internet, after scanning the carrier's internet addresses for weak spots using a publicly available tool," reports Axios. From the report: "I was panicking because I had access to something big," he wrote in Telegram messages to the Journal. "Their security is awful." "Generating noise was one goal," Binns said. He declined to say whether he sold any of the information he stole, or whether he was paid for the hack.

Some of the information exposed in the breach included names, dates of birth, social security numbers and personal ID information. The breach is being investigated Seattle's FBI office, according to the Journal.

Security

China's Microsoft Hack May Have Had A Bigger Purpose Than Just Spying (npr.org) 43

An anonymous reader shares a report: Steven Adair hunts hackers for a living. Back in January, in a corner-of-his-eye, peripheral kind of way, he thought he saw one in his customer's networks -- a shadowy presence downloading emails. Adair is the founder of a cybersecurity company called Volexity, and he runs traps to corner intruders all the time. So he took a quick look at a server his client was using to run Microsoft Exchange and was stunned to "see requests that we're not expecting," he said. There were requests for access to specific email accounts, requests for confidential files. He followed all this requested information to a virtual server off-site. "The hair is almost rising on my arms right now when I think about it," Adair told NPR later. "This feeling of like, oh, crap this is not what should be going on." What Adair discovered was a massive hack into Microsoft Exchange -- one of the most popular email software programs in the world. For nearly three months, intruders helped themselves to everything from emails to calendars to contacts. Then they went wild and launched a second wave of attacks to sweep Exchange data from tens of thousands of unsuspecting victims. They hit mom-and-pop shops, dentist offices, school districts, local governments -- all in a brazen attempt to vacuum up information.

Both the White House and Microsoft have said unequivocally that Chinese government-backed hackers are to blame. NPR's months-long examination of the attack -- based on interviews with dozens of players from company officials to cyber forensics experts to U.S. intelligence officials -- found that stealing emails and intellectual property may only have been the beginning. Officials believe that the breach was in the service of something bigger: China's artificial intelligence ambitions. The Beijing leadership aims to lead the world in a technology that allows computers to perform tasks that traditionally required human intelligence -- such as finding patterns and recognizing speech or faces. "There is a long-term project underway," said Kiersten Todt, who was the executive director of the Obama administration's bipartisan commission on cybersecurity and now runs the Cyber Readiness Institute. "We don't know what the Chinese are building, but what we do know is that diversity of data, quality of data aggregation, accumulation of data is going to be critical to its success."

Bitcoin

Coinbase Slammed For Terrible Customer Service After Hackers Drain Accounts (cnbc.com) 57

An anonymous reader quotes a report from CNBC: Interviews with Coinbase customers around the country and a review of thousands of complaints reveal a pattern of account takeovers, where users see money suddenly vanish from their account, followed by poor customer service from Coinbase that made those users feel left hanging and angry. Making the issue even worse, cryptocurrency transactions cannot be reversed, according to the FBI. Experts say once criminals access an account, funds can be drained in minutes. Coinbase, which went public in April, has a market cap of about $65 billion, has more than 68 million users in 100-plus countries, more than 2,100 full-time employees and $223 billion in held assets, according to the company. While the cryptocurrency exchange company has grown rapidly, complaints have continued to arise. Since 2016, Coinbase users have filed more than 11,000 complaints against Coinbase with the Federal Trade Commission and Consumer Financial Protection Bureau, mostly related to customer service. Former employees told CNBC the company's customer service practices shifted over time, with representatives struggling to keep up with demand.

After a review of Coinbase's complaints, the Better Business Bureau in March determined the company has a "pattern of complaints from customers who state they are locked out of their accounts, even after providing required information or updates." The organization has received 1,128 complaints in the past three years, according to its website. BBB said it sent a letter to Coinbase in order to address the customers' complaints and receive feedback from any implemented improvements. The group has "not heard a response from this business, about the situation, pattern of complaints for the last three years," Alma Galvan, a marketing and communication manager with the organization, said in an email to CNBC.
In an email to CNBC, Coinbase said: "Over the years, we've consistently updated our customer support offerings to help us scale. In early 2020, we moved to email as our primary channel of support. Many of our customer inquiries require our agents to conduct a significant amount of research to resolve the issue. And, to avoid long wait times, communicating asynchronously via email was the preferred method. However, we recognize that customers want real-time support, and that's why we're rolling out phone support for ATOs this month and live messaging for all customers later this year."

Asked about the number of customer service complaints, the company said: "Over the past several years, our customer base grew exponentially. We grew from 43+ million users at the end of 2020 to 68+ million registered users, as of June 30, 2021. Through all this growth, some of our customers unfortunately experienced challenges and delays reaching our support team, which resulted in a negative impact for some of our customers. Improving our customer experience remains a top priority for Coinbase." They declined to disclose how many customers' accounts have been hacked or the total amount it has refunded customers as a result of the hacks.
Security

Hackers Release Data Trove From Belarus in Bid To Overthrow Lukashenko Regime (bloomberg.com) 56

Opponents of the Belarus government said they have pulled off an audacious hack that has compromised dozens of police and interior ministry databases as part of a broad effort to overthrow President Alexander Lukashenko's regime. From a report: The Belarusian Cyber Partisans, as the hackers call themselves, have in recent weeks released portions of a huge data trove they say includes some of the country's most secret police and government databases. The information contains lists of alleged police informants, personal information about top government officials and spies, video footage gathered from police drones and detention centers and secret recordings of phone calls from a government wiretapping system, according to interviews with the hackers and documents reviewed by Bloomberg News.

Among the pilfered documents are personal details about Lukashenko's inner circle and intelligence officers. In addition, there are mortality statistics indicating that thousands more people in Belarus died from Covid-19 than the government has publicly acknowledged, the documents suggest. In an interview and on social media, the hackers said they also sabotaged more than 240 surveillance cameras in Belarus and are preparing to shut down government computers with malicious software named X-App.

Television

Samsung Activates TV Block Function To Render All TV Sets That Were Looted and Stolen Useless (blogspot.com) 161

Samsung South Africa has announced that it has activated a TV Block Function on all Samsung TV sets stolen during the looting, violence and unrest in parts of KwaZulu-Natal and Gauteng during July that saw TV sets stolen from Samsung warehouses. From a report: Samsung has activated TV Block on all Samsung television sets looted from its Cato Ridge distribution centre in KwaZulu-Natal since 11 July. Samsung's television block technology is already pre-loaded on all Samsung TV products and the company says that all sets taken unlawfully and stolen from Samsung warehouses are being blocked, rendering them useless.

TV Block is a remote, security solution that detects if Samsung TV units have been unduly activated, and ensures that the television sets can only be used by the rightful owners with a valid proof of purchase. Samsung SA says that the aim of the technology is to mitigate against the creation of secondary markets linked to the sale of illegal goods, both in South Africa and beyond its borders.

Security

FBI Sends Its First-Ever Alert About a 'Ransomware Affiliate' (therecord.media) 8

The US Federal Bureau of Investigations has published its first-ever public advisory detailing the modus operandi of a "ransomware affiliate." From a report: A relatively new term, a ransomware affiliate refers to a person or group who rents access to Ransomware-as-a-Service (RaaS) platforms, orchestrates intrusions into corporate networks, encrypt files with the "rented ransomware," and then earn a commission from successful extortions. Going by the name of OnePercent Group, the FBI said today this threat actor has been active since at least November 2020.
Security

Hundreds of Thousands of Realtek-based Devices Under Attack from IoT Botnet (therecord.media) 13

A dangerous vulnerability in Realtek chipsets used in hundreds of thousands of smart devices from at least 65 vendors is currently under attack from a notorious DDoS botnet gang. From a report: The attacks started last week, according to a report from IoT security firm SAM, and began just three days after fellow security firm IoT Inspector published details about the vulnerability on its blog. Tracked as CVE-2021-35395, the vulnerability is part of four issues IoT Inspector researchers found in the software development kit (SDK) that ships with multiple Realtek chipsets (SoCs). These chips are manufactured by Realtek but are shipped to other companies, which then use them as the basic System-on-Chip (SoC) board for their own devices, with the Realtek SDK serving as a configurator and starting point for their own firmware. IoT Inspector said they found more than 200 different device models from at least 65 different vendors that had been built around these chips and were using the vulnerable SDK.
Security

38 Million Records Were Exposed Online -- Including Contact-Tracing Info (wired.com) 19

More than a thousand web apps mistakenly exposed 38 million records on the open internet, including data from a number of Covid-19 contact tracing platforms, vaccination sign-ups, job application portals, and employee databases. The data included a range of sensitive information, from people's phone numbers and home addresses to social security numbers and Covid-19 vaccination status. From a report: The incident affected major companies and organizations, including American Airlines, Ford, the transportation and logistics company J.B. Hunt, the Maryland Department of Health, the New York City Municipal Transportation Authority, and New York City public schools. And while the data exposures have since been addressed, they show how one bad configuration setting in a popular platform can have far-reaching consequences.

The exposed data was all stored in Microsoft's Power Apps portal service, a development platform that makes it easy to create web or mobile apps for external use. If you need to spin up a vaccine appointment sign-up site quickly during, say, a pandemic, Power Apps portals can generate both the public-facing site and the data management backend. Beginning in May, researchers from the security firm Upguard began investigating a large number of Power Apps portals that publicly exposed data that should have been private -- including in some Power Apps that Microsoft made for its own purposes. None of the data is known to have been compromised, but the finding is significant still, as it reveals an oversight in the design of Power Apps portals that has since been fixed. In addition to managing internal databases and offering a foundation to develop apps, the Power Apps platform also provides ready-made application programming interfaces to interact with that data. But the Upguard researchers realized that when enabling these APIs, the platform defaulted to making the corresponding data publicly accessible. Enabling privacy settings was a manual process. As a result, many customers misconfigured their apps by leaving the insecure default.

Firefox

Firefox Follows Chrome and Prepares To Block Insecure Downloads (therecord.media) 79

Mozilla developers are putting the finishing touches on a new feature that will block insecure file downloads in Firefox. From a report: Called mixed content downloaded blocking, the feature works by blocking files downloads initiated from an encrypted HTTPS page but which actually take place via an unencrypted HTTP channel. The idea behind this feature is to prevent Firefox users from getting misled by the URL bar and think they're downloading a file securely via HTTPS when, in reality, the file could be tampered with by third parties while in transit.
IT

If Remote Work Lasts Two Years, Will Employees Ever Return to Offices? (livemint.com) 230

"With the latest wave of return-to-office delays from Covid-19, some companies are considering a new possibility: Offices may be closed for nearly two years," reports the Wall Street Journal.

"That is raising concerns among executives that the longer people stay at home, the harder or more disruptive it could be to eventually bring them back." Many employees developed new routines during the pandemic, swapping commuting for exercise or blocking hours for uninterrupted work. Even staffers who once bristled at doing their jobs outside of an office have come to embrace the flexibility and productivity of at-home life over the past 18 months, many say. Surveys have shown that enthusiasm for remote work has only increased as the pandemic has stretched on. "If you have a little blip, people go back to the old way. Well, this ain't a blip," said Pat Gelsinger, chief executive officer of Intel Corp., whose company has benefited from the work-from-home boom. He predicts hybrid and remote work will remain the norm for months and years to come. "There is no going back...."

[W]hat many have concluded over time is that their companies can operate largely effectively while remote, executives and workers say... As more time passes until offices reopen, it could become difficult to convince existing employees to willingly upend their new lives and return to pre-pandemic schedules in offices, executives say.

Apple, Amazon, Facebook, and Lyft have now all postponed the return to their U.S. workplaces until 2022.
Iphone

'No Service' Bug Hits Some IOS 14.7.1 Users After Updating Their IPhones (zdnet.com) 26

"What seemed like a small update has, for some, turned into a huge headache," reports ZDNet: Over on Apple's support forum, there are several threads from users complaining that iOS 14.7.1 broke their iPhones, causing a "no service" problem where users are unable to connect to cell service. Ther">e are similar threads on Apple's developer forums as well.

While there doesn't seem to be a pattern to which phones are affected, I've seen reports of everything from the iPhone 6 to iPhone 12 affected, and the cause is clear — upgrading to iOS 14.7.1.

"Users are saying that restarting the phone, removing the SIM, and even resetting network settings didn't help," according to 9to5Mac (in an article shared by long-time Slashdot reader antdude).

Forbes reports the bug appears to happen when you lose your cellular connection and switch to WiFi calling, "so those living in areas with good reception may never see it. Of course, this scenario also helps to mask the scale of iPhones which might be affected." If you haven't upgraded to iOS 14.7.1 yet, this potentially crippling flaw could (understandably) put you off upgrading. The problem is that the release also contains a critical fix for a new zero-day security flaw...
Operating Systems

New Linux Syscall Enables Secret Memory Even the Kernel Can't Read (lwn.net) 131

RoccamOccam writes: After many months of development, the memfd_secret() system call was finally merged for the upcoming 5.14 release of Linux. There have been many changes during this feature's development, but its core purpose remains the same: allow a user-space process to create a range of memory that is inaccessible to anybody else -- kernel included. That memory can be used to store cryptographic keys or any other data that must not be exposed to others. Reportedly, it is even safe from processor vulnerabilities like Spectre because secret memory is uncached mapped.

Slashdot Top Deals