IT

The New WikiLeaks (newrepublic.com) 57

How the transparency collective DDoSecrets eclipsed Julian Assange. From a report: Whereas WikiLeaks cultivated an anti-imperialist mystique centered on the cultish figure of Assange, DDoSecrets professes something more modest: an unvarnished commitment to providing information useful to journalists and concerned citizens. As the DDoSecrets website puts it, data must fulfill two criteria: "Is it in the public interest?" and "Can a prima facie case be made for the veracity of its contents?" If it passes that test -- and the group, which now has approximately 10 members along with an advisory board and volunteer contributors, decides collectively that they can protect their sources -- then they publish the archive, sometimes as an easily downloadable torrent, other times through its slightly more difficult to reach onion site, which requires using the Tor browser. While many archives are published for a wide audience, others are withheld and only offered to journalists upon request; and in some cases, the organization will write about data it receives without publishing its contents.

At its best, the work of DDoSecrets reveals the limits of official transparency, of authorized government leaks and incrementalist beat reporting and FOIA requests that yield pages of useless redactions. Nowhere is this more visible than with BlueLeaks. "Reading the unredacted, hacked documents gives a very different picture than the selections you get from an open records officer," said Brendan McQuade, author of Pacifying the Homeland, a book about the modern surveillance state. Based on BlueLeaks information, he wrote articles that exposed police malfeasance and brought attention to a federal whistleblower suit against the Maine Information and Analysis Center, or MIAC. Maine's state house later voted to close the site (although the bill never cleared the Senate). To McQuade, and to the members of DDoSecrets, hacked data provides what official channels cannot: truth and the potential for accountability.

Security

Cloudflare Says It Mitigated a Record-Breaking 17.2 Million HTTP RPS DDoS Attack (therecord.media) 10

Internet infrastructure company Cloudflare disclosed today that it mitigated the largest volumetric distributed denial of service attack that was recorded to date. From a report: The attack, which took place last month, targeted one of Cloudflare's customers in the financial industry. Cloudflare said that a threat actor used a botnet of more than 20,000 infected devices to flung HTTP requests at the customer's network in order to consume and crash server resources.

Called a volumetric DDoS, these are different from classic bandwidth DDoS attacks where threat actors try to exhaust and clog up the victim's internet connection bandwidth. Instead, attackers focus on sending as many junk HTTP requests to a victim's server in order to take up precious server CPU and RAM and prevent legitimate users from using targeted sites. Cloudflare said this attack peaked at 17.2 million HTTP requests/second (rps), a figure that the company described as almost three times larger than any previous volumetric DDoS attack that was ever reported in the public domain.

Google

Google Calendar Will Let You Record Where You're Working To Help Organize Office Meetings (theverge.com) 27

Google is adding an option to its Calendar service to let you show where you're working on any given day of the week, the company has announced. From a report: The feature will start rolling out from August 30th for users on select Google Workspace plans, and will be accessible via Calendar's settings menu alongside its existing working hours options, as well as on the weekly calendar view below where it shows each day's dates. Available work locations include "Office," "Home," "Unspecified," or "Somewhere else."

According to Google, the option is being added so it's "easier to plan in-person collaboration or set expectations in a hybrid workplace." It follows a surge in the popularity of home and hybrid working due to the pandemic. This has meant employees increasingly have to keep track not just of people's working hours, but also their location, when planning in-person meetings and other events. Google Calendar's new feature should help here.

Security

T-Mobile Says At Least 47 Million Current and Former Customers Affected by Hack (techcrunch.com) 51

T-Mobile has confirmed that millions of current and former customers had their information stolen in a data breach, following reports of a hack over the weekend. From a report: In a statement, T-Mobile, which has more than 100 million customers, said its preliminary analysis shows 7.8 million current postpaid T-Mobile customers had information taken in the data breach. The carrier said that some personal data was also taken, including customer names, dates of birth, Social Security numbers and driver's license information for a "subset" of current and former postpay customers and prospective T-Mobile customers. The company also said that 40 million records of former and prospective customers was taken, but that "no phone numbers, account numbers, PINs, passwords, or financial information were compromised." But the company warned that approximately 850,000 active T-Mobile customer names, phone numbers and account PINs were in fact compromised, and that customer names, phone numbers and account PINs were exposed.
Privacy

Apple's NeuralHash Algorithm Has Been Reverse-Engineered (schneier.com) 86

An anonymous reader writes: Apple's NeuralHash algorithm (PDF) -- the one it's using for client-side scanning on the iPhone -- has been reverse-engineered.

Turns out it was already in iOS 14.3, and someone noticed:

Early tests show that it can tolerate image resizing and compression, but not cropping or rotations. We also have the first collision: two images that hash to the same value. The next step is to generate innocuous images that NeuralHash classifies as prohibited content.

This was a bad idea from the start, and Apple never seemed to consider the adversarial context of the system as a whole, and not just the cryptography.

Windows

Updated App from Apple Brings iCloud Passwords To Windows (arstechnica.com) 10

Apple has released a new version of iCloud for Windows, numbered 12.5. The update adds the ability to access and manage passwords saved in iCloud from a Windows machine, a feature that users have long requested. From a report: Apple has been gradually adding more support for iCloud passwords on non-Apple platforms with mixed results. The company released a Chrome extension that synced iCloud passwords with Chrome. But like this new iCloud Passwords app, it did the bare minimum and not much else. Still, this addition is welcome for users who primarily live in the Apple ecosystem (and thus use Apple's iCloud password locker) but who sometimes have to use Windows. For example, some folks use an iPhone or a Mac most of the time but have a Windows PC that is only used to play games that can't be played on the Mac.
Blackberry

BlackBerry Resisted Announcing Major Flaw in Software Powering Cars, Hospital Equipment (politico.com) 40

A flaw in software made by BlackBerry has left two hundred million cars, along with critical hospital and factory equipment, vulnerable to hackers -- and the company opted to keep it secret for months. Politico: On Tuesday, BlackBerry announced that old but still widely used versions of one of its flagship products, an operating system called QNX, contain a vulnerability that could let hackers cripple devices that use it. But other companies affected by the same flaw, dubbed BadAlloc, went public with that news in May. Two people familiar with discussions between BlackBerry and federal cybersecurity officials, including one government employee, say the company initially denied that BadAlloc impacted its products at all and later resisted making a public announcement, even though it couldn't identify all of the customers using the software.

The back-and-forth between BlackBerry and the government highlights a major difficulty in fending off cyberattacks on increasingly internet-connected devices ranging from robotic vacuum cleaners to wastewater-plant management systems. When companies such as BlackBerry sell their software to equipment manufacturers, they rarely provide detailed records of the code that goes into the software -- leaving hardware makers, their customers and the government in the dark about where the biggest risks lie. BlackBerry may be best known for making old-school smartphones beloved for their manual keyboards, but in recent years it has become a major supplier of software for industrial equipment, including QNX, which powers everything from factory machinery and medical devices to rail equipment and components on the International Space Station.

Security

Healthcare Provider Expected To Lose $106.8 Million Following Ransomware Attack (therecord.media) 45

An anonymous reader quotes a report from The Record: Scripps Health, a California-based nonprofit healthcare provider that runs five hospitals and 19 outpatient facilities, said it expects to lose an estimated $106.8 million following a ransomware attack that hit the organization in May 2021. The bulk of the losses, representing $91.6 million, came from lost revenues during the four weeks the organization needed to recover from the May ransomware attack. Scripps also lost $21.1 million in costs associated with response and recovery. While the company said it recovered $5.9 million through its insurance policy, the healthcare provider said it expects to lose an estimated $106.8 million by the end of the year. The losses stemming from the ransomware attack do not include potential losses due to litigation.

Following the attack, several patient groups also filed class-action lawsuits against the organization for failing to protect their data after the organization revealed that the hackers also stole data on roughly 150,000 patients before they encrypted the healthcare provider's servers. The attack, while it did not get the same national coverage in the US as the ones on Colonial Pipeline, JBS Foods, and Kaseya, was one of the most impactful of the year, with Scripps being unable to access its web portal, patient medical records, and provide some patient services for four weeks, during which time staff had to redirect patients to other hospitals, which eventually resulted in the $91.6 million in lost revenue.

Security

Critical Bug Impacting Millions of IoT Devices Lets Hackers Spy On You (bleepingcomputer.com) 42

An anonymous reader quotes a report from BleepingComputer: Security researchers are sounding the alarm on a critical vulnerability affecting tens of millions of devices worldwide connected via ThroughTek's Kalay IoT cloud platform. The security issue impacts products from various manufacturers providing video and surveillance solutions as well as home automation IoT systems that use the Kalay network for easy connectin and communication with a corresponding app. A remote attacker could leverage the bug to gain access to the live audio and video streams, or to take control of the vulnerable device. Researchers at Mandiant's Red Team discovered the vulnerability at the end of 2020 and worked with the U.S. Cybersecurity and Infrastructure Security Agency and ThroughTek to coordinate the disclosure and create mitigation options.

Tracked as CVE-2021-28372, the issue is a device impersonation vulnerability that received a severity score of 9.6 out of 10. It affects the Kalay protocol that is implemented as a software development kit (SDK) that is built into mobile and desktop applications. Mandiant's Jake Valletta, Erik Barzdukas, and Dillon Franke looked at ThroughTek's Kalay protocol and found that registering a device on the Kalay network required only the device's unique identifier (UID). Following this lead, the researchers discovered that a Kalay client, such as a mobile app, usually receives the UID from a web API hosted by the vendor of the IoT device. An attacker with the UID of a target system could register on the Kalay network a device they control and receive all client connection attempts. This would allow them to obtain the login credentials that provide remote access to the victim device audio-video data. The researchers say that this type of access combined with vulnerabilities in device-implemented RPC (remote procedure call) interface can lead to complete device compromise. By the latest data from ThroughTek, its Kalay platform has more than 83 million active devices and manages over 1 billion connections every month.
The best way to protect yourself from this vulnerability is to keep your device software and applications updated to the latest version, as well as create complex, unique login passwords. The report also recommends you avoid connecting to IoT devices from an untrusted network.
Security

Firewalls and Middleboxes Can Be Weaponized For Gigantic DDoS Attacks (therecord.media) 65

An anonymous reader writes: In an award-winning paper last week, academics said they discovered a way to abuse the TCP protocol, firewalls, and other network middleboxes to launch giant distributed denial of service (DDoS) attacks against any target on the internet.

Authored by computer scientists from the University of Maryland and the University of Colorado Boulder, the research is the first of its kind to describe a method to carry out DDoS reflective amplification attacks via the TCP protocol, previously thought to be unusable for such operations. Making matters worse, researchers said the amplification factor for these TCP-based attacks is also far larger than UDP protocols, making TCP protocol abuse one of the most dangerous forms of carrying out a DDoS attack known to date and very likely to be abused in the future.

Books

The Mysterious Figure Stealing Books Before Their Release (vulture.com) 19

For years, a mysterious figure has been stealing books before their release. Is it espionage? Revenge? Or a complete waste of time? Vulture: On the spectrum of cyberattacks, this one wasn't very complex. There was no malicious software or actual hacking involved. Some of the earliest victims used Gmail accounts for work, which were easy and free to spoof. Registering an alternate domain and setting up an email server was only slightly more involved, and the possibilities were endless: t's became f's (@wwnorfon.com), q's replaced g's (@wylieaqency.com), r's and n's cornbined to make m's (@penguinrandornhouse.com). The domains suggested someone who liked to play with words as much as code. Books became bocks, unless the company was Dutch, in which case boek was Anglicized to book.

What did seem sophisticated was the thief's knowledge of the business. The culprit wrote like someone in publishing, abbreviating to "MS" for manuscript and "WEL" for world English-language rights, while exchanging insider chatter, telling one victim that a publisher was pitching a book as a comp to Pachinko and expressing surprise to another that a novel had recently sold for a shocking amount. The thief sent messages in the wake of announcements on Publishers Marketplace, a subscription website that tracks deals, but they also asked about books that the thief's marks didn't even know existed. The mimicry wasn't always perfect -- an assistant at the talent agency WME realized her boss was being impersonated because she would never say "please" or "thank you" -- but the impression was good enough.

What's more, the thief seemed to have a strong grasp of the rarefied world of international publishing. The first emails, in the fall of 2016, traveled almost exclusively among the small group of people who handle the flow of manuscripts between countries, including a foreign-rights manager in Greece, an editor in Spain, and an agent selling international writers in the Chinese market. In the attempted "Millennium" heist, only a few dozen people in the world knew the book was being shared with foreign publishers and that Mork and Altrov Berg controlled access to it.

Google

The Google Pixel 6 Won't Ship With a Charger (theverge.com) 96

Google is the latest manufacturer to bid farewell to the in-box charging brick, saying it expects the Pixel 5A will be the last phone to include one. That means the Pixel 6 and Pixel 6 Pro won't include one when they arrive this fall. From a report: The company says that most people already have a USB-C charging brick, so there's no longer a need to include one with its phones. Apple and Samsung made similar arguments when they announced they would no longer be offering an in-box charger. That may be true, but it's likely that the cost savings of not including a charger played a big role in those decisions.
Security

Chinese Espionage Tool Exploits Vulnerabilities In 58 Widely Used Websites (therecord.media) 23

A security researcher has discovered a web attack framework developed by a suspected Chinese government hacking group and used to exploit vulnerabilities in 58 popular websites to collect data on possible Chinese dissidents. From a report: Fifty-seven of the sites are popular Chinese portals, while the last is the site for US newspaper, the New York Times. In addition, the tool also abused legitimate browser features in attempts to collect user keystrokes, a large swath of operating system details, geolocation data, and even webcam snapshots of a target's face -- although many of these capabilities weren't as silent as the exploits targeting third-party websites, since they also tended to trigger a browser notification prompt.

Named Tetris, the tool was found secretly uploaded on two websites with a Chinese readership. "The sites both appear to be independent newsblogs," said a security researcher going online under the pseudonym of Imp0rtp3, who analyzed the Tetris attack framework for the first time in a blog post earlier this month. "Both [sites] are focused on China, one site [is focused on China's] actions against Taiwan and Hong-Kong written in Chinese and still updated and the other about general atrocities done by the Chinese government, written in Swedish and last updated [in] 2016," the researcher said. According to Imp0rtp3, users who landed on these two websites were first greeted by Jetriz, the first of Tetris' two components, which would gather and read basic information about a visitor's browser.

Privacy

Stop Using Zoom, Hamburg's DPA Warns State Government (techcrunch.com) 25

Hamburg's state government has been formally warned against using Zoom over data protection concerns. From a report: The German state's data protection agency (DPA) took the step of issuing a public warning yesterday, writing in a press release that the Senate Chancellory's use of the popular videoconferencing tool violates the European Union's General Data Protection Regulation (GDPR) since user data is transferred to the US for processing. The DPA's concern follows a landmark ruling (Schrems II) by Europe's top court last summer which invalidated a flagship data transfer arrangement between the EU and the US (Privacy Shield), finding US surveillance law to be incompatible with EU privacy rights.

The fallout from Schrems II has been slow to manifest -- beyond an instant blanket of legal uncertainty. However a number of European DPAs are now investigating the use of US-based digital services because of the data transfer issue, and in some instances publicly warning against the use of mainstream US tools like Facebook and Zoom because user data cannot be adequately safeguarded when it's taken over the pond. German agencies are among the most proactive in this respect. But the EU's data protection supervisor is also investigating the bloc's use of cloud services from US giants Amazon and Microsoft over the same data transfer concern.

Bug

Linux Glibc Security Fix Created a Nastier Linux Bug (zdnet.com) 74

A fix that was made in early June to the GNU C Library (glibc) introduced a new and nastier problem. Steven J. Vaughan-Nichols writes via ZDNet: The first problem wasn't that bad. As Siddhesh Poyarekar, a Red Hat principal software engineer wrote, "In order to mount a minimal attack using this flaw, an attacker needs many pre-requisites to be able to even crash a program using this mq_notify bug." Still, it needed patching and so it was fixed. Alas, the fix contained an even nastier bug. While checking the patch, Nikita Popov, a member of the CloudLinux TuxCare Team, found the problem. It turns out that it is possible to cause a situation where a segmentation fault could be triggered within the library. This can lead to any application using the library crashing. This, of course, would cause a Denial-of-Service (DoS) issue. This problem, unlike the earlier one, would be much easier to trigger. Whoops.

Red Hat gives the problem in its Common Vulnerability Scoring System (CVSS) a score of 7.5, which is "high." An attack using it would be easy to build and requires no privileges to be made. In short, it's bad news. Popov himself thinks "every Linux application including interpreters of other languages (python, PHP) is linked with glibc. It's the second important thing after the kernel itself, so the impact is quite high." [...] The good news is both the vulnerability and code fix have been submitted to the glibc development team. It has already been incorporated into upstream glibc.

In addition, a new test has been submitted to glibc's automated test suite to pick up this situation and prevent it from happening in the future. The bottom line is sometimes changed in unrelated code paths can lead to behaviors changing elsewhere without the programmer realizing what's going on. This test will catch this situation. The Linux distributors are still working out the best way to deploy the fix. In the meantime, if you want to be extra careful -- and I think you should be -- you should upgrade to the newest stable version of glibc 2.34 or higher.

Communications

T-Mobile Confirms It Was Hacked (vice.com) 20

T-Mobile confirmed hackers gained access to the telecom giant's systems in an announcement published Monday. Joseph Cox, reporting at Motherboard: The move comes after Motherboard reported that T-Mobile was investigating a post on an underground forum offering for sale Social Security Numbers and other private data. The forum post at the time didn't name T-Mobile, but the seller told Motherboard the data came from T-Mobile servers.

We have determined that unauthorized access to some T-Mobile data occurred, however we have not yet determined that there is any personal customer data involved," T-Mobile wrote in its new announcement. "This investigation will take some time but we are working with the highest degree of urgency. Until we have completed this assessment we cannot confirm the reported number of records affected or the validity of statements made by others," the announcement added.

Security

Secret Terrorist Watchlist With 2 Million Records Exposed Online (bleepingcomputer.com) 87

A secret terrorist watchlist with 1.9 million records, including classified "no-fly" records was exposed on the internet. The list was left accessible on an Elasticsearch cluster that had no password on it. BleepingComputer reports: July this year, Security Discovery researcher Bob Diachenko came across a plethora of JSON records in an exposed Elasticsearch cluster that piqued his interest. The 1.9 million-strong recordset contained sensitive information on people, including their names, country citizenship, gender, date of birth, passport details, and no-fly status. The exposed server was indexed by search engines Censys and ZoomEye, indicating Diachenko may not have been the only person to come across the list.

The researcher discovered the exposed database on July 19th, interestingly, on a server with a Bahrain IP address, not a US one. However, the same day, he rushed to report the data leak to the U.S. Department of Homeland Security (DHS). "I discovered the exposed data on the same day and reported it to the DHS." "The exposed server was taken down about three weeks later, on August 9, 2021." "It's not clear why it took so long, and I don't know for sure whether any unauthorized parties accessed it," writes Diachenko in his report. The researcher considers this data leak to be serious, considering watchlists can list people who are suspected of an illicit activity but not necessarily charged with any crime. "In the wrong hands, this list could be used to oppress, harass, or persecute people on the list and their families." "It could cause any number of personal and professional problems for innocent people whose names are included in the list," says the researcher.

Security

Pearson To Pay $1 Million Fine for Misleading Investors About 2018 Data Breach (techcrunch.com) 15

Pearson, a London-based publishing and education giant that provides software to schools and universities has agreed to pay $1 million to settle charges that it misled investors about a 2018 data breach resulting in the theft of millions of student records. From a report: The U.S. Securities and Exchange Commission announced the settlement on Monday after the agency found that Pearson made "misleading statements and omissions" about its 2018 data breach, which saw millions of student usernames and scrambled passwords stolen, along with the administrator login credentials of 13,000 schools, district and university customer accounts.

The agency said that in Person's semi-annual review filed in July 2019, the company referred to the incident as a "hypothetical risk," even after the data breach had happened. Similarly, in a statement that same month, Pearson said the breach may include dates of birth and email addresses, when it knew that such records were stolen, according to the SEC. Pearson also said that it had "strict protections" in place when it actually took the company six months to patch the vulnerability after it was notified.

Security

T-Mobile is Investigating an Alleged Data Breach That Would Affect 100 Million Users (vice.com) 37

Slashdot reader lightbox32 shared this report from Motherboard: T-Mobile says it is investigating a forum post claiming to be selling a mountain of personal data. The forum post itself doesn't mention T-Mobile, but the seller told Motherboard they have obtained data related to over 100 million people, and that the data came from T-Mobile servers.

The data includes social security numbers, phone numbers, names, physical addresses, unique IMEI numbers, and driver licenses information, the seller said. Motherboard has seen samples of the data, and confirmed they contained accurate information on T-Mobile customers.

Mashable points out that "it's entirely possible that the seller is misrepresenting the scope of the breach and/or the contents of the information they claim to be selling.

"T-Mobile likely isn't going to say anything until there's a clearer sense of the risks its customers are actually facing."
IT

The Case Against Working Remotely Full-Time (msn.com) 189

A new article in Time magazine argues it's time to "follow the science" on working from home.

"The solution for the future is a structured hybrid model, acknowledging that working from home doesn't work long-term for most jobs, while still giving workers flexibility." (Alternate URL here.) One way to do that would be to allocate time slots — perhaps specific days — of in-office working for all employees to maintain workplace productivity and collaboration, while also allowing working from home to continue outside those hours... For some, remote work leads to increased productivity, as well as job satisfaction, particularly for those working in technical jobs that require minimal teamwork... But the science tells us that workers like them are in a minority and, however topical their case is, we should be cautious about applying such a drastic change across our economies.

Since before the pandemic began I have been assessing multi-disciplinary collaboration in a work-from-home environment for my PhD research at Imperial College, London. Individuals employed on creative projects in virtual teams reported feeling more like a 'worker', and less like a member of a family. One respondent said of employers: "They don't see how early you show up in front of your computer...They don't see how hard I'm working." But more damaging than the effects of working from home on individuals, is what it does to teams. Remote work often breaks the mechanisms that allow a team to work together creatively. Studies have found that the best creative work occurs when a team is in a state of flow, or focuses its collective attention on a single problem together, known as 'team flow'. But remote work makes it harder to keep everyone engaged in solving that problem.

In my study, many respondents said it was hard to gauge when a team member had zoned out during a Zoom call. There is currently no digital technology that can reliably create 'flow' remotely, and we shouldn't pretend there is. If it did exist, it wouldn't have taken the necessity of pandemic restrictions for us to work remotely — managers and employees would have already embraced it. There's other evidence that points to this problem. Utah-based virtual whiteboard app Lucidspark found that 75% of 1,000 respondents surveyed in September last year said collaboration was the thing that suffered most when working remotely.

"It is clear from my research that fully autonomous working from home across all industries is neither desirable nor sustainable," the article concludes.

"That's why we need to carve out a third way, where teams that thrive on collaboration are given mandatory times each week when everyone is expected to be in the office."

Slashdot Top Deals