Bug

Facebook Announces Time Bonus Payouts For Bug Hunters (nbcnews.com) 9

Facebook is adding a new perk to its bug bounty program that will pay bonus rewards to researchers based on the time it takes the social network to fix a vulnerability after it's found and reported by bug hunters. ZDNet reports: Essentially, Facebook is acknowledging that it's sometimes slow to reach a bounty decision and is using this bonus payment to encourage patience among the researchers in its bug bounty community. The Payout Time Bonus will reward reports that are paid more than 30 days from the time Facebook receives all the necessary information for a successful reproduction of the report and its impact, Facebook said. The bonuses will be paid on a sliding scale, with payouts made between 30-59 days receiving a 5% bonus; payouts made between 60-89 days receiving a 7.5% bonus; and payouts made after 90 days or more receiving a 10% bonus. Reports that require clarification from the researcher will have the payments adjusted accordingly.
Encryption

Amazon Rolls Out Encryption For Ring Doorbells (zdnet.com) 53

Starting today in the U.S. (and other countries in the not too distant future), you'll be able to encrypt the video footage captured via your Ring devices. ZDNet reports: This is done with Amazon's Video End-to-End Encryption (E2EE). If you decide to install this optional privacy feature, you'll need to install a new version of the Ring application on your smartphone. Once installed, it uses a Public Key Infrastructure (PKI) security system based on an RSA 2048-bit asymmetric account signing key pair. In English, the foundation is pretty darn secure.

Earlier, Ring already encrypted videos when they are uploaded to the cloud (in transit) and stored on Ring's servers (at rest). Law enforcement doesn't have automatic access to customer devices or videos. You choose whether or not to share footage with law enforcement. With E2EE, customer videos are further secured with an additional lock, which can only be unlocked by a key that is stored on the customer's enrolled mobile device, designed so that only the customer can decrypt and view recordings on their enrolled device. In addition, you'll need to opt into using E2EE. It doesn't turn on automatically with the software update. You'll also need to set a passphrase, which you must remember. AWS doesn't keep a copy. If you lose it, you're out of luck. [Just know that if you use E2EE, various features will be missing, such as sharing your videos, being able to view encrypted videos on Ring.com, the Windows desktop app, the Mac desktop app, or the Rapid Ring app, and the Event Timeline. E2EE also won't work with many Ring devices.]
ZDNet notes that while police can still ask for or demand your video and audio content, they won't be able to decrypt your E2EE end-to-end encrypted video "because the private keys required to decrypt the videos are only stored on customer's enrolled mobile devices."
Firefox

Firefox Says Its Revamped SmartBlock Won't Break Facebook Login Buttons Anymore (theverge.com) 32

Firefox 90 introduces the next version of SmartBlock, the browser's tracker blocking mechanism built into its private browsing and strict modes, which now has improvements designed to prevent buttons that let you log into websites using your Facebook account from breaking, Mozilla announced on Tuesday. From a report: SmartBlock was first introduced with Firefox 87 in March, and if you aren't familiar, here's Mozilla's description of how it works, from the company's blog: "SmartBlock intelligently fixes up web pages that are broken by our tracking protections, without compromising user privacy. SmartBlock does this by providing local stand-ins for blocked third-party tracking scripts. These stand-in scripts behave just enough like the original ones to make sure that the website works properly. They allow broken sites relying on the original scripts to load with their functionality intact." Sometimes, though, the feature would break Facebook login buttons. In a new blog post, Mozilla's Tom Wisniewski and Arthur Edelstein explain why this would happen, using an example of trying to log in to Etsy.
Security

Gmail Deploys Support BIMI Security Standard (therecord.media) 50

Google has rolled out support for the new Brand Indicators for Message Identification (BIMI) standard to all Gmail users as part of an effort to improve email-sender authenticity. From a report: The new standard is hard to comprehend for non-technical users, but it basically allows companies that have implemented email security standards like DMARC, DKIM, and SPF for their email domains to show "authenticated logos" inside email clients. Since all these security protocols rely on digital certificates and advanced cryptography, the verified logos will only appear for a company's real email domain and not for spoofed emails sent by scammers or cybercrime groups.
Security

Ransomware Gang REvil Vanishes From Web After Biden Warning (bloomberg.com) 71

The Russia-linked ransomware gang REvil has seemingly vanished from the dark web, where it maintains several pages documenting its activities including one called the "happy blog." From a report: It's not yet known if the sites were down temporarily or if the group -- or law enforcement -- took its websites offline. "It's too early too tell, but I've never seen ALL of their infrastructure offline like this," said Allan Liska, senior threat analyst at cybersecurity firm Recorded Future, in a text message. "I can't find any of their infrastructure online. Their extortion page is gone, all of their payment portals are offline, as is their chat function." Liska said the websites went offline around 1 a.m. Eastern time. The sudden outage comes just days after President Joe Biden said he pressed Russian President Vladimir Putin to act against hackers in his country blamed for recent ransomware attacks.
Windows

Windows 11 Will Support Rolling Back To Windows 10, but Not for Long (extremetech.com) 91

Microsoft took the wraps off Windows 11 recently, and we expect the new OS to arrive later this year. Upgrading to a new version of Windows is often a painful process, and in the past, you were stuck even if the new software ruined your workflow. It's different this time: Microsoft says you'll be able to go back to Windows 10 if you don't like Windows 11. You'll only have 10 days to decide, though. From a report: How will you know if Windows 11 is worth using? There's a preview program for Windows 11, but the preview builds are still missing some elements of the final release. You don't have to mess with the Insiders builds at all -- you can install the final version when it's available, and take it for a spin. This news comes by way of a PDF that Microsoft has provided to PC manufacturers. It's an FAQ format, and among the various redundant queries is this gem: "Can I go back to Windows 10 after I upgrade if I don't like Windows 11?" The answer is a resounding yes... for 10 days. You'll have that long to decide to roll back to Windows 10. Wait any longer, and you're locked into Windows 11 unless you reformat your system.
IT

The 'Worst' Keyboard Ever Made 101

Marcin Wichary, Design Manager at Figma, writes in his newsletter: At this point it's probably clear that every time I say "the worst keyboard ever made," I am being cheeky. These are not the worst keyboards ever made. There is no worst keyboard; the world of keyboards is just too complex for this to be possible. Even more importantly, though, I believe there is always something you can learn from a keyboard you don't like. Sure, the Ukrainian keyboard has an atrocious build quality, the TI calculator keypad is weird to press, and the abKey is far from a Revolution. But there are things in either of them that can surprise and delight.
Botnet

Trickbot Strikes Back (gizmodo.com) 6

A notorious group of cybercriminals whose operations were almost totally dismantled last year seems to be back in business -- in yet another example of the seemingly intractable nature of cybercrime. Gizmodo reports: The Russian-speaking group known as "Trickbot" (which is also the name of the malware that they're responsible for creating and distributing), has built up its infrastructure and seems to be preparing for some nefarious new campaign, The Daily Beast first reported. The group, which has been connected to ransomware attacks and widespread theft of financial information, is an outgrowth of an older, Russia-based cybercrime group called "Dyre." After Dyre was initially broken up by Russian authorities back in 2015, the remaining members regrouped, creating new malware tools and working to employ them in even more expansive criminal enterprises. Trickbot, which today operates out of numerous places in Eastern Europe -- including Russia, Ukraine, Belarus, and others -- is perhaps best known for running one of the world's largest botnets. Botnets are large networks of "zombie" devices -- computers that have been infected with special kinds of malware that allow them to be collectively controlled by a hacker, typically for malicious purposes. In Trickbot's case, the group has used its million-plus botnet for an assortment of sordid activities, including helping to launch ransomware attacks throughout the world.

Last fall, the Pentagon's Cyber Command attempted to debilitate Trickbot, fearing that hackers connected to the group might attempt to interfere with the 2020 presidential election. CYBERCOM launched a series of "coordinated attacks" against Trickbot's servers, ultimately succeeding in disrupting its operations. However, it was clear that federal officials did not expect their efforts to be a long-term deterrent, with anonymous sources telling the Washington Post that the action was "not expected to permanently dismantle the network." Around the same time, Microsoft launched its own campaign that was also targeted at dismantling the group. The company tracked and analyzed the servers that were involved in operating the botnet, subsequently garnering a court order that allowed them to disable the IP addresses connected to those servers. Microsoft's operation even involved working together with ISPs to reportedly go "door to door" in Latin America, where they helped to replace routers that had been compromised by the criminal group. However, as is often the case with cybercrime, few of the culprits behind the malware's distribution were ever tracked down or faced charges.

Indeed, a recent report from security firm Fortinet seems to show that the group has allegedly helped create a new strain of ransomware, dubbed "Diavol." On top of this, another report from BitDefender shows that the group has built back up its infrastructure and that it has recently been seen gearing up for new attacks and malicious activity, with the firm ultimately noting that "Trickbot shows no sign of slowing down."

Businesses

Microsoft Agrees To Acquire Cybersecurity Company RiskIQ (bloomberg.com) 9

Microsoft said it has agreed to acquire RiskIQ, a security software maker, as the tech giant tries to expand its products and better protect customers amid a rising tide of global cyberattacks. From a report: The company announced the deal Monday on its web site and didn't disclose terms. Bloomberg on Sunday reported the purchase, citing people familiar with the matter. Microsoft is paying more than $500 million in cash for the company, said one of the people, who declined to be named discussing confidential matters. San Francisco-based RiskIQ makes cloud software for detecting security threats, helping clients understand where and how they can be attacked on complex webs of corporate networks and devices. Its customers include Facebook, BMW, American Express and the U.S. Postal Service, according to the company's web site.
China

China's Great Firewall is Blocking Around 311K Domains, 41K by Accident (therecord.media) 33

In the largest study of its kind, a team of academics from four US and Canadian universities said they were able to determine the size of China's Great Firewall internet censorship capabilities. From a report: In a research project that lasted nine months, from April to December 2020, academics developed a system called GFWatch that accessed domains from inside and outside China's internet space and then measured how the Great Firewall (GFW) would tamper with the connection at the DNS level in order to prevent Chinese users from accessing a domain, or an external entity accessing Chinese internal sites.

Using GFWatch, researchers said they tested 534 million distinct domains, accessing around 411 million domains on a daily basis in order to record and then verify that the blocks were persistent. After nine months of compiling data, they found that China's Great Firewall currently blocks around 311,000 domains, with 270,000 blocks working as intended, while 41,000 domains appear to have been blocked by accident. The research team said these latter domains appear to have been blocked accidentally when Chinese authorities tried to block a shorter domain and used a broad DNS filtering regular expression (regex) that did not account for situations where that shorter domain was also part of a longer domain name, indirectly banning other sites. For example, researchers said that when Chinese authorities blocked access to reddit.com, they also accidentally blocked access to booksreddit.com, geareddit.com, and 1,087 other sites.

Businesses

Before Ransomware Attack, Kaseya Was Warned of 'Critical' Security Flaws, Ex-Employees Say (engadget.com) 22

"The giant ransomware attack against Kaseya might have been entirely avoidable," writes Engadget: Former staff talking to Bloomberg claim they warned executives of "critical" security flaws in Kaseya's products several times between 2017 and 2020, but that the company didn't truly address them... Employees reportedly complained that Kaseya was using old code, implemented poor encryption and even failed to routinely patch software. The company's Virtual System Administrator, the remote maintenance tool that fell prey to ransomware, was supposedly rife with enough problems that workers wanted the software replaced.

One employee claimed he was fired two weeks after sending executives a 40-page briefing on security problems. Others simply left in frustration with a seeming focus on new features and releases instead of fixing basic issues. Kaseya also laid off some employees in 2018 in favor of outsourcing work to Belarus, which some staff considered a security risk given local leaders' partnerships with the Russian government.

Kaseya has declined to comment...

The company's software was reportedly used to launch ransomware at least twice between 2018 and 2019, and it didn't significantly rethink its security strategy.

Engadget adds the Kaseya's software "was reportedly used to launch ransomware at least twice between 2018 and 2019, and it didn't significantly rethink its security strategy."
IT

Study: Older LinkedIn Users Get Fewer Job Offers, But a Younger Picture Helps (psychnewsdaily.com) 92

Slashdot reader tinkers writes: A new study has found that older job seekers on LinkedIn receive fewer job offers than younger ones. But using a profile photo with a younger appearance reduces this effect...

The study's authors say these results reconfirm why photographs are usually absent from traditional resumes or CVs. As such, they suggest that removing photos from LinkedIn might make job-seeking fairer. The lack of photos might cause recruiters to focus more on information that is more relevant to the job.

IT

More States are Trying to Attract Remote Workers (politico.com) 75

Remote-worker incentive programs are gradually expanding beyond Hawaii, Vermont, Indiana, and Tulsa, Oklahoma. Now Charleston, West Virginia is offering a $5,000 "relocation credit" to remote workers. And Ascend WV is offering $12,000 (with a year of free whitewater rafting, rock climbing and skiing...)

Politico discussed the strategies behind luring remote workers with former Intuit CEO Brad Smith (who helped launch the Ascend WV program) and Jim Justice, the state's billionaire governor: At a news conference in April, Justice announced the launch of the program alongside a bill signing of legislation that overhauls the state's corporate income tax law that he said would make West Virginia "the most attractive state in the nation for remote workers and for all businesses." A joyful Justice called West Virginians "frogs proud of their own pond" and labeled Ascend the No. 1 remote worker relocation program in the nation...

The idea is that West Virginia can become "the start-up state," Smith explains to me on a call from his home in Menlo Park, Calif. If you can incentivize ambitious, business minded folks to give overlooked West Virginia a chance, they'll fall in love with the place and stay for good, setting off a domino effect to jumpstart the state economy by creating new businesses and hiring locally, all while giving back to the state in tax dollars along the way and reversing the population decline. And the pool of remote workers is tenfold what it was before the pandemic now that employers everywhere are changing the way they view office work, which could mean high earners will consider a place with a low cost of living where their money can go further — like West Virginia.

A key selling point for Smith is that Ascend participants won't be competing for local jobs; they already have jobs elsewhere. Instead, they'll be spending their money locally, engaging with the community and seeing a place they never would have given a chance before, Smith says... "And their income is taxed in our state, which then creates tax funds to invest in infrastructure."

Prithwiraj Choudhury, a professor at Harvard Business School who studies remote work, believes programs like Ascend can have a positive long-term impact for host cities and will be a "game changer" for places like West Virginia. The Tulsa Remote program, operated by the George Kaiser Family Foundation, has shown payoff in both income tax revenue, projecting a boost of $1.4 million in 2020, and in community engagement; many of the 300-some participants continue to volunteer locally, according to Choudhury's research. Twenty-seven homes have been purchased by Tulsa Remote workers, according to the latest count. "Work from anywhere is here to stay, and people are going to relocate both permanently and for short durations," Choudhury said. "I think policy makers and politicians should view this as an opportunity for attracting tech workers and future entrepreneurs."

That focus on making outsiders happy, though, is at the root of the criticism of programs like Ascend.

Microsoft

Microsoft Gives Employees $1,500 Pandemic Bonus, GitHub Gives Days Off (theverge.com) 5

Long-time Slashdot reader AmiMoJo shared this report from the Verge: Microsoft is gifting its employees a $1,500 pandemic bonus. In an internal memo seen by The Verge, the software giant says this one-time bonus "is in recognition of the unique and challenging fiscal year that Microsoft just completed."

Microsoft's chief people officer, Kathleen Hogan, announced the gift to employees Thursday, and it will apply to all eligible employees in both the U.S. and internationally. Microsoft is gifting this bonus to all staff below corporate vice president level that started on or before March 31st, 2021, including part-time workers and those on hourly rates. Microsoft has 175,508 employees worldwide, but LinkedIn, GitHub, and ZeniMax employees are not eligible for the bonus, despite Microsoft owning these three separate companies. As a result, we understand it's a gift of around $200 million, or less than two days' worth of profit for Microsoft.

The article also notes similar gifts given to employees at Facebook, BT, and Vox Media, as well as Amazon's $300 holiday bonus to frontline workers.

And GitHub did do something special for its employees, according to the company's holiday FAQ: The pandemic brought unprecedented challenges, revolutionizing the way our customers and open source community build software. We have watched our employees step up...while also balancing the unique complexities of remote work, children, health, and more. We recognize that our employees are our greatest asset, so to give back to our employees who give so much, we will be taking company wide wellbeing days July 5-9, as well as six Fridays in July and August.

GitHub is committed to providing our customers with high-quality customer support and will have staff available to assist should an issue arise, however you may experience a delayed response during these dates.

To ensure a seamless developer experience, we recommend that you refrain from upgrading between June 28 and July 9.

Google

Some Google Workers Angered by 'Hypocritical' Remote Work Policies (cnet.com) 175

Slashdot reader nray shared this report from CNET: In May, CEO Sundar Pichai unveiled plans for a "hybrid" work environment that would require most employees to work from their offices at least three days a week beginning in September. Under the new structure, 20% of the company would work remotely. Another 20% could work from new locations. People who relocated would get salary adjustments based on the local market. The bulk of Google would pick up where it left off, working from the office. Google makes up almost all of Alphabet, a holding company that has more than 135,000 full-time employees...

The rancor intensified last week, when Urs Hölzle, one of the company's longest-tenured and most senior executives, announced plans to work remotely from New Zealand, according to an email he sent to employees that was viewed by CNET. Hölzle's plans angered rank-and-file workers, who consider it special treatment for company leadership, while lower-level employees have had to wade through a drawn-out and uncertain application process... Hölzle, Google's senior vice president of technical infrastructure, is a revered figure at the company. He was one of Google's first 10 employees and is credited with building the tech giant's IT foundation of servers and networks. But for some Googlers, his relocation email, which was sent on June 29 and hasn't been previously reported, illustrated the inequities of the company's system for deciding remote work... Two Google employees said Hölzle's situation encapsulated the company's "hypocritical" policies. Both complained that the relocation represented a double standard in which different rules apply to executives in senior ranks. While his approval came last year, Google employees now undergoing the remote work application process have been told decisions won't come until August, at the earliest. Approval for Hölzle's move came before the procedure was instituted.

News of Hölzle's relocation especially stung because he has been particularly vocal against remote work, employees said. De Vesine, the resigning Googler, said Hölzle had a policy of not letting people work remotely unless they were assigned to an office and that he wouldn't consider remote work for people who hadn't reached a certain level of seniority...

It's unclear if Hölzle's salary will be adjusted to the local market, as required for other employees relocating to a new place. The Google spokesman declined to comment on his compensation.

"While some tech companies, like Reddit, have said they'll pay employees San Francisco or New York City salaries wherever they work, Google has taken a hard line on making pay adjustments..." CNET reports.

They also point out that for 20 yerars Google "has set the tone for office culture in Silicon Valley... The impact of Google's remote work policies could ripple far and wide..."
Networking

SolarWinds and Kaseya Attacks Shake Faith In SaaS Model (channelinsider.com) 58

"First SolarWinds, now Kaseya. SaaS software heavily used by managed service providers (MSPs) has now been the target of two successful cyberattacks," writes Slashdot reader storagedude.

He shares a ChannelInsider article reporting the Kaseya ransomware attack compromised roughly 1,500 "downstream" businesses — and that now managed service providers "are reassessing their approaches to managing IT" after their own upstream vendors were breached: In many cases, rather than assuming the platforms that MSPs employ are secure, end customers will now require them to prove it via an audit of their software supply chains, says James Shank, Chief Architect of Community Services for Team Cymru, a provider of threat intelligence tools employed to conduct such audits. Shank, who also served on the Ransomware Task Force Committee set up by The Institute for Security and Technology, notes that MSPs should also assume attacks will only get worse before they get any better. "This is not the end or the middle," he says. "It's only the beginning."

Others, however, don't think there will be any widespread mandate to audit IT supply chains in the absence of any government requirement. Most organizations are simply not going to conduct or require extensive audits because of the time, effort, money and expertise required, says Mike Hamilton, chief information security officer (CISO) for Critical Insight, a provider of a managed detection and response platform.

"American companies are not going to do that unless someone holds their feet to the fire," he says.

The challenge that creates for MSPs and their customers is it may force them to continue to place too much trust in IT platforms provided to them by a vendor, says Chris Grove, technology evangelist for Nozomi Networks, a provider of security tools for monitoring networks. "These platforms are over-trusted," he says.

The decision many MSPs are specifically wrestling with is the degree to which they should continue to rely on IT service management (ITSM) platforms from an IT vendor that might be compromised by malware versus building and securing their own custom platform. The latter approach is not immune to malware but might be less of a target as cybercriminals increasingly focus their efforts on platforms that enable them to wreck greater downstream havoc. Alternatively, MSPs could switch to IT service management platforms provided by vendors that don't have enough market share to attract the attention of cybercriminals... Building an IT service management platform from scratch naturally requires a level of investment many MSPs lack the funding or expertise to make, notes Eldon Sprickerhoff, chief innovation officer for eSentire, a provider of a managed detection and response platform. "It's a difficult situation," he says.
BR> The article points out that few small- to medium-sized businesses can afford their own internal IT security team.

Slashdot reader storagedude then suggests "on-premises installed and managed software could get another look as a result of the attacks," while vendors who can prove high levels of security "could gain a market advantage."
Cellphones

Ask Slashdot: How Secure Is a Cellphone's eSIM? (pcmag.com) 41

A few months ago PC Magazine explained eSIMs: You almost certainly have a SIM card: a thumbnail-sized chip that sits in your mobile phone, telling it which carrier and what phone number you use. Now those SIMs are going digital (or "e") and moving your information to a reprogrammable, embedded chip.

A SIM card is a "subscriber identity module." Required in all GSM, LTE, and 5G devices, it's a chip that holds your customer ID and details of how your phone can connect to its mobile network... An eSIM takes the circuitry of a SIM, solders it directly to a device's board, and makes it remotely reprogrammable through software... There are some minor consumer downsides, though. With eSIMs, it's harder to switch one plan between devices — you can't just swap the physical card around — and they can make it harder for you to temporarily remove your SIM if you don't want to be tracked by a carrier.

Google's Pixels have had eSIMs since 2017, and Apple's iPhones have had them since 2018...

Now let's see how long-time Slashdot reader shanen feels about them: Shopping for a new smartphone due to premature battery swelling of a cheapie, but surprised to find out I can't just plug the SIM into a new phone. There ain't no SIM here, but rather the dying phone has an eSIM.... Quick research indicated it's only software, so my obvious question is "How secure can an eSIM be?" (The obvious search results also fail to produce "fresh" results.)

But the black hats have already had a couple of years to work on the problem, and it seems intrinsically difficult to do anything securely if you're only using software. My probably obsolete understanding is that part of the basis of SIM security is that you'd have to destroy the SIM to save its data, but is there an actual security expert in the house?

Related question based on my surprise. How would you even know if you're using an eSIM? Especially since it appears to be possible to use an eSIM on a phone with a SIM.

Share your own thoughts and opinions in the comments.

How secure is an eSIM?
Chrome

Google's Unfair Performance Advantage in Chrome (ctrl.blog) 37

An anonymous reader shares a post: Google Chrome for Android has a feature that gives Google Search an unfair advantage over its competition. Sure, it's the default search engine and that's a huge hurdle to overcome for any competitor. However, Chrome also reserves a performance-boosting feature for Google Search exclusively. I recently poked around in the Chromium project source code; the open-source foundation for Google's Chrome web browser. The Chromium project is co-developed by Google, and other corporate and individual contributors. The project is managed and controlled by Google, however. I was looking for something else when I stumbled upon a feature called PreconnectToSearch. When enabled, the feature preemptively opens and maintains a connection to the default search engine.

The preconnection feature resolves the domain name, and negotiates and sets up a secure connection to the server. All these things take time and they must happen before the search engine can receive the users' search queries. Preempting these steps can save a dozen seconds on a slow network connection or half a second on a fast connection. This optimization can yield a nice performance boost for Google's customers. Assuming the connection only requires a trivial amount of processing power and network bandwidth, of course. Setting up the connection early can be wasteful or slow down the loading of other pages if the user isn't going to search the web. There's just one small catch: Chromium checks the default search engine setting, and only enables the feature when it's set to Google Search. This preferential treatment means no other search engine can compete with Google Search on the time it takes to load search results. Every competitor must wait until the user has started to type a search query before Chrome will establish a connection.

Microsoft

Microsoft Pays Staff $1,500 for Work in Pandemic (bbc.com) 42

Microsoft is to give its non-executive staff a $1,500 bonus for their work during the pandemic. From a report: The company told the BBC it was a symbol of appreciation "during a uniquely challenging year." It added: "We are proud to recognise our employees with a one-time monetary gift." In the first quarter of 2021 Microsoft's profits rose 38% on the same period last year. The Verge reported that employees below vice-president level who joined no later than 31 March 2021 would receive the payment, including part-time workers. The big tech firms have done well during the pandemic and Microsoft is not the only firm to have made bonus payments to staff. In March 2020, Facebook gave employees a $1,000 bonus to help them with increased expenses caused by the pandemic, such as those associated with setting up a home office. Google made a similar $1,000 payment in May 2020. In December, Amazon gave front-line employees a $300 dollar bonus with part-time workers receiving $150.
Japan

Japanese Fax Fans Rally To Defence of Much-Maligned Machine (theguardian.com) 99

Ministers back down after hundreds of government offices insist banishing fax would be impossible. From a report: Most bureaucrats might be expected to welcome the chance to be freed from the tyranny of the fax machine. But in Japan, government plans to send the must-have item of 1980s office equipment the way of telex have in effect been scrapped after they encountered resistance from "faxophile" officials. A cabinet body that promotes administrative reform said in June it had decided to abolish the use of fax machines "as a rule" by the end of the month and switch to emails at ministries and agencies in the Tokyo district of Kasumigaseki, Japan's bureaucratic nerve centre. The move would enable more people to work from home, it said, citing concerns that too many people were still going to the office during the coronavirus pandemic to send and receive faxes. Exceptions would be made for disaster response and interactions with the public and businesses that had traditionally depended on faxes. Instead of embracing the digital age, however, hundreds of government offices mounted a defence of the much-maligned machine, insisting that banishing them would be "impossible," according to the Hokkaido Shimbun newspaper.

The backlash has forced the government to abandon its mission to turn officialdom into a digital-only operation, the newspaper said on Wednesday. Members of the resistance said there were concerns over the security of sensitive information and "anxiety over the communication environment" if, as the government had requested, they switched exclusively to email. Japanese ministries and agencies use faxes when handling highly confidential information, including court procedures and police work, and the Hokkaido Shimbun said there were fears that exclusively online communication would result in security lapses. "Although many ministries and agencies may have stopped using fax machines, I can't say with pride that we managed to get rid of most of them," an official at the cabinet body told the newspaper.

Slashdot Top Deals