IT

As Lockdowns End, Some Want to Continue Working From Inside Their Vans (msn.com) 81

During the lockdowns I edited dozens of Slashdot posts from the front-passenger seat of my car (using a cellphone for a mobile hotspot).

But according to CNBC, I wasn't the only person working from a vehicle... When Erica Horn received a work email in May 2020 saying her company would be fully remote for the next year, she knew right away it was time to live out her long-held dream of living out of a van... Horn is not alone. Many workers with jobs that let them work remotely during the pandemic left behind their sedentary housing situations and moved full-time into vans. These remote workers drive from location to location in their homes, working from internet hotspots in their vans and spending their free time in nature and exploring new places. As vaccines roll out and states start to open up, some workers are returning to their offices.

But many workers who've adopted the van life don't want to give it up...

Like overseas backpacking, van life appeals to those with a love for travel or the outdoors who have the privilege to work remotely and the budget to spend thousands of dollars buying and setting up their vans. They can shift the money from rent and car payments toward a lifestyle of endless travel... For some, working out of a van is less about travel and more of an alternative to leasing an office. Kenzo Fong, CEO of tech start-up Rock, began working out of his van in May 2020 after his children began doing their schoolwork at home during the pandemic. Fong still lives in his San Francisco home, but during the days, he gets into his van and picks a new location in the city...

Some van lifers only need a laptop. Others have more elaborate set ups complete with multiple monitors. But most carry at least two hot spots from different network providers so they can catch signal from at least one of the services as they hit new locations... Despite the challenges of life on the road, those who spoke with CNBC said they plan to continue their nomadic lifestyle until their companies stop allowing remote work or until they get burnt out. Horn said she originally planned to live on the road for at least a year, but that's now changed.

"At six months, I still feel like I'm just learning this, just getting the hang of it and just getting started," she said. "I could actually see myself doing it for closer to two years, and who knows, maybe longer."

Twitter

Intern's Email Goof at HBO Max Inspires Hundreds to Show Support on Twitter (cbsnews.com) 62

CBS News reports: A mysterious and puzzling email with the subject line of "Integration Test Email #1" landed in the boxes of some HBO Max subscribers on Thursday. Just hours later, the company said that the message was intended to be an empty test email, and "yes, it was the intern." The unnamed intern quickly became the new star of HBO Max on social media, as hundreds of encouraging messages poured in to reassure the intern that mistakes happen, in all phases of careers... And instead of subscribers responding with angry messages about an inconvenience, they used the opportunity to tell their own stories of work snafus...

One individual wrote about how they "once globally took down Spotify." It almost happened twice," they wrote. "...You managed to find something broken in the way integration tests are done. It's a good thing and will help improve things...."

"When I was 25 I made a PDF assigning each employee to the Muppet they reminded me of the most," another wrote. "I meant to send it to my work friend, but I accidentally sent it to the entire company. My supervisor (Beaker) wanted to fire me, but the owners (Bert & Ernie) intervened."

Dozens of news outlets, from the Huffington Post to media wire services, soon began covering the funny stories shared in support:
  • "Don't feel bad Integration Test Email #1 intern...when I was an intern once I accidentally powered off every device during a complicated laser experiment at MIT."
  • "In the first month of my new HR job with a major defense contractor, I sent out an email about shirt orders that included the division president and several corporate leaders. Title of email: Your Shit is in the HR Office..."

But my favorite reply of all?

"Dear intern, welcome to Systems Engineering."

Share your own thoughts and stories of support in the comments...


Bug

Peleton Patches Vulnerability In Camera That Allowed Spying on Riders (cnn.com) 20

McAfee has discovered a vulnerability "that allows hackers to access Peloton's bike screen," reports CNN, "and potentially spy on riders using its microphone and camera."

"However, the threat most likely affects only the $2,495 bike used in public spaces, such as in hotels or gyms, because the hacker needs to physically access the screen using a USB drive containing a malicious code." According to McAfee's Advanced Threat Research team, a hacker can discreetly control the stationary bike's screen remotely and interfere with its operating system. That means hackers could, for example, install apps that look like Netflix or Spotify and steal the users' log-in information. Perhaps more alarmingly, the cybersecurity team was able spy on users via the camera and microphone, which is normally used for video chats with other users.

"As a result, an unsuspecting gym-goer taking the Peloton Bike+ for a spin could be in danger of having their personal data compromised and their workout unknowingly watched," the report said. It also warned the hacker could configure this spyware at any point, including during the supply chain or delivery process, without the owner knowing... Peloton released a mandatory software update that fixes the issue to users earlier this month.

The security risk doesn't affect the lower-priced Peloton Bike because it uses a different type of touchscreen....

This report marks the second security concern for Peloton in two months. In May, the fitness firm released a security update that sealed a leak that was revealing personal account information, such as a user's age, city and weight.

Security

80% of Orgs That Paid the Ransom Were Hit Again, Report Finds (venturebeat.com) 91

Boston-headquartered security firm Cybereason's study has found that the majority of organizations that chose to pay ransom demands in the past were not immune to subsequent ransomware attacks, often by the same threat actors. From a report: In fact, 80% of organizations that paid the ransom were hit by a second attack, and almost half were hit by the same threat group. This study offers insight into the business impact of ransomware attacks across key industry verticals and reveals data that can be leveraged to improve ransomware defenses. For example, after an organization experienced a ransomware attack, the top two solutions implemented included security awareness training (48%) and security operations (48%). This research underscores that prevention is the best strategy for managing ransomware risk and ensuring your organization does not fall victim to a ransomware attack in the first place.
Security

Poland Says Recent Attacks on Local Politicians Originated from Russia (therecord.media) 22

The Polish government said that a recent wave of cyberattacks that have targeted the email accounts of local political figures originated from Russia. From a report: The attacks have targeted some of the most important Polish officials, ministers, and deputies from various political parties, said Jaroslaw Kaczynski, Poland's deputy prime minister, citing sources from the Polish Internal Security Agency and the Military Counterintelligence Service. "The analysis of our services and the special services of our allies allows for a clear statement that the cyber attack was carried out from the territory of the Russian Federation," Kaczynski said in a press release today. "Its scale and range are wide," the Polish official said. The announcement today comes after Polish local news outlets reported last week hackers broke into the email inbox of Michal Dworczyk, head of the Chancellery of the Polish Prime Minister's. Throughout the course of the last week, the hackers leaked emails and documents from Dworczyk's inbox on a Telegram channel, according to Polish online news outlet Onet. Other documents were also leaked through the Facebook account of Dworczyk's wife.
Google

Google Open-Sources Fully Homomorphic Encryption (FHE) Toolkit (therecord.media) 78

Google has open-sourced a collection of C++ libraries for implementing Fully Homomorphic Encryption (FHE) in modern applications. From a report: Fully homomorphic encryption, or simply homomorphic encryption, is a form of data encryption that allows users/applications to perform mathematical computations on encrypted data without decrypting it first, keeping the data's privacy intact. While the concept of homomorphic encryption has been around since 1978, when it was first described at a theoretical level, and 2009, when it was first implemented in practice, it has not been broadly adopted in software due to its complexity, advanced cryptography techniques, and lack of open-source code and public documentation. However, despite this, today, FHE is a hot technology in software design.

FHE allows software vendors to work on encrypted data without sharing the encryption/decryption keys with untrustworthy systems such as client-side apps or publicly-hosted web servers, where the keys could be stolen or intercepted by malware or malicious human operators. FHE allows developers to keep data secure, encrypted, and private, all at the same time, and Google hopes that developers will use its FHE libraries as the first step into adopting this new type of encryption technology within their applications.

Security

Police Bust Ransomware Gang in Ukraine (nbcnews.com) 68

Police in Ukraine said this week they arrested members of a major ransomware gang. From a report: The arrests mark the first time a law enforcement agency has announced a mass arrest of a prolific hacker group that had extorted Americans by either encrypting an organization's files or threatening to leak them to the public. The gang, known as Cl0p, has hacked a number of American targets, including the University of Miami, Florida, Stanford University, University of Maryland, and University of Colorado, demanding a payment to either keep their systems functional or to not publish material they were able to steal. The bust comes as ransomware has gone from a quietly pervasive cybersecurity problem to a broadly discussed national security issue, thanks to a series of high-profile attacks that have threatened to cripple some U.S. supply chains.

Ukraine's announcement coincided with President Joe Biden's meeting with Russian President Vladimir Putin in Geneva. Biden is expected to press Putin to take action against ransomware hackers who operate with impunity within Russia's borders. Ransomware has become a significant problem in the United States. Recent ransomware attacks briefly hobbled the Colonial Pipeline, shutting down the country's largest fuel pipeline for five days, and JBS, one of the country's largest meat suppliers. The majority of the most prolific ransomware gangs are believed to operate in Eastern Europe, and Russia in particular. Ukraine's cyber police announced they had arrested six people involved with Cl0p, and seized a number of computers, cars and about 5 million Ukrainian hryvnia ($185,000) in cash.

Encryption

Report Finds Phone Network Encryption Was Deliberately Weakened (vice.com) 83

A weakness in the algorithm used to encrypt cellphone data in the 1990s and 2000s allowed hackers to spy on some internet traffic, according to a new research paper. Motherboard: The paper has sent shockwaves through the encryption community because of what it implies: The researchers believe that the mathematical probability of the weakness being introduced on accident is extremely low. Thus, they speculate that a weakness was intentionally put into the algorithm. After the paper was published, the group that designed the algorithm confirmed this was the case. Researchers from several universities in Europe found that the encryption algorithm GEA-1, which was used in cellphones when the industry adopted GPRS standards in 2G networks, was intentionally designed to include a weakness that at least one cryptography expert sees as a backdoor. The researchers said they obtained two encryption algorithms, GEA-1 and GEA-2, which are proprietary and thus not public, "from a source." They then analyzed them and realized they were vulnerable to attacks that allowed for decryption of all traffic.

When trying to reverse-engineer the algorithm, the researchers wrote that (to simplify), they tried to design a similar encryption algorithm using a random number generator often used in cryptography and never came close to creating an encryption scheme as weak as the one actually used: "In a million tries we never even got close to such a weak instance," they wrote. "This implies that the weakness in GEA-1 is unlikely to occur by chance, indicating that the security level of 40 bits is due to export regulations." Researchers dubbed the attack "divide-and-conquer," and said it was "rather straightforward." In short, the attack allows someone who can intercept cellphone data traffic to recover the key used to encrypt the data and then decrypt all traffic. The weakness in GEA-1, the oldest algorithm developed in 1998, is that it provides only 40-bit security. That's what allows an attacker to get the key and decrypt all traffic, according to the researchers.

The Internet

Major Australian Banks, US Airlines Briefly Hit By Widespread Internet Outages (reuters.com) 21

Websites of dozens of financial institutions and airlines in Australia and the United States were briefly down on Thursday, in the second major blackout in just over a week caused by a glitch in an important piece of internet infrastructure. From a report: Server-related glitches at content delivery network provider Akamai had hampered services at Australian banks, while many U.S. airlines, including American Airlines and Southwest Airlines, also reported an hour-long outage. The disruption linked to technical issues at Akamai follows an outage at rival Fastly that affected a number of popular websites last week. The impacted platform is now up and running, an Akamai spokesperson said, adding that the company was "continuing to validate services." The outage was caused by a bug in Akamai's software that has since been fixed, and was not caused by a cyber-attack or vulnerability, the spokesperson added.
Privacy

Hackers Are Selling Data Stolen From Audi and Volkswagen (vice.com) 22

On Friday, Volkswagen disclosed a data breach that it said affected 3.3 million customers and interested buyers. On Monday, hackers put the data stolen from the car maker on sale on a notorious hacking forum. From a report: In the sales listing reviewed by Motherboard, a hacker that goes by 000 wrote that the data included email addresses and Vehicle Identification Numbers (VIN). The hacker also posted two samples of the data, which included full names, email addresses, mailing addresses, and phone numbers. The type of data seems to align with what Volkwagen admitted was stolen. In a website set up by a cybersecurity vendor on behalf of the car maker, Volkswagen said that "the majority" of affected data included: "first and last name, personal or business mailing address, email address, or phone number. In some instances, the data also included information about a vehicle purchased, leased, or inquired about, such as the Vehicle Identification Number (VIN), make, model, year, color and trim packages."

But for 90,000 victims, the data also included "more sensitive information relating to eligibility for a purchase, loan, or lease. Nearly all of the more sensitive data (over 95%) consists of driver's license numbers," according to the company, which added that the majority of data pertains to Audi customers and interested buyers in the US and Canada only. The company also said it believes the data was left unsecured by a vendor. (Audi is owned by the Volkswagen Group.) "There were also a very small number of dates of birth, Social Security or social insurance numbers, account or loan numbers, and tax identification numbers," the website read.

Businesses

The Global Chip Shortage is Creating a New Problem: More Fake Components (zdnet.com) 72

Industry analysts believe that the global chip shortage is creating the perfect environment for counterfeit semiconductors to enter the market. From a report: With demand looking unlikely to calm down, analyst firm Gartner estimates that the semiconductor shortage will last well into 2022, and has warned equipment manufacturers that wafer orders could come with up to 12 months of lead time in the coming months. For some companies, this will mean finding an alternative way of stocking up on chips or shutting down production lines. In other words, the current times are opening up a golden opportunity for electronic component counterfeiters and fraudsters to step in. "If next week, you need to get 5,000 parts or your line will shut down, you will be in a situation of distress purchase and you will put your guard down," Diganta Das, a researcher in counterfeit electronics at the Center for Advanced Life Cycle Engineering (CALCE), tells ZDNet. "You won't keep to your rules of verifying the vendor or going through test processes. This is likely to become a big problem."

As part of his research, Das regularly monitors counterfeit reporting databases like ERAI, and although it is too early to notice a surge, he is confident that the number of reports will start growing in the next six months as companies realize they have been sold illegal parts. The problem, of course, is unlikely to affect tech giants whose reliance on semiconductors is such that they have implemented robust supply chains, and will typically only purchase components directly from chip manufacturers. Those at risk rather include low-volume manufacturers whose supply chain for semiconductors is less established -- but it could include companies in sectors that are as critical as defense, healthcare and even automotive.

Transportation

Southwest Airlines Delays and Cancels Flights for a Third Day (nytimes.com) 22

Hundreds of Southwest Airlines flights were delayed or canceled again on Wednesday as the company sought to resolve disruptions from earlier in the week amid a pickup in summer travel. From a report: The headaches for Southwest, which is widely credited for pioneering the low-fare airline business model, began on Monday night, when a problem with a weather data supplier prevented the airline from safely flying planes. The issue was resolved within hours, but on Tuesday the airline suffered its own technological problems, resulting in half of its flights that day being delayed and many being canceled, according to FlightAware, a flight tracking service. Spillover from that episode caused Wednesday's problems, the airline said. About 10 percent of Southwest's flights were canceled and another 19 percent were delayed by midafternoon, according to FlightAware.

"While our technology issues from Tuesday have been resolved, we are still experiencing a small number of cancellations and delays across our network as we continue working to resume normal operations," Dan Landson, a Southwest spokesman, said in a statement. Southwest said on Tuesday that it was having problems with "network connectivity." Mr. Landson said that those troubles were unrelated to the weather data problems from Monday and that there was no indication the airline's computer systems had been breached or hacked. The flight disruptions came at a critical time for a company celebrating its 50th year.

IT

Southwest Airlines Cancels 500 Flights After Computer Glitch Grounds Fleet (reuters.com) 32

Southwest Airlines said on Tuesday it canceled about 500 flights and delayed hundreds of others after it was forced to temporarily halt operations over a computer issue -- the second time in 24 hours it had been forced to stop flights. From a report: The Federal Aviation Administration said it had issued a temporary nationwide groundstop at the request of Southwest Airlines to resolve a computer reservation issue. The groundstop lasted about 45 minutes, and ended at 2:30 p.m. EDT (1830 GMT), it said. Southwest said its operations were returning to normal. The issue was the result of "intermittent performance issues with our network connectivity." Southwest delayed nearly 1,300 flights on Tuesday, or 37% of its flights, according to flight tracker FlightAware.
Encryption

The Android Messages App Now Offers End-To-End Encryption (engadget.com) 55

Along with a string of new features across several areas of Android, Google is at last turning on end-to-end encryption (E2EE) for everyone in the Messages app. Beta testers have been able to use E2EE messaging since November. From a report: E2EE in Messages is only available in one-on-one conversations for the time being, not group chats. Both participants need to have RCS chat features enabled to use it. You'll know if a message you're about to send will be encrypted if you see a lock icon on the send button.
Privacy

Irish Police To Be Given Powers Over Passwords (bbc.com) 164

Irish police will have the power to compel people to provide passwords for electronic devices when carrying out a search warrant under new legislation. From a report: The change is part of the Garda Siochana Bill published by Irish Justice Minister Heather Humphreys on Monday. Gardai will also be required to make a written record of a stop and search. This will enable data to be collected so the effectiveness and use of the powers can be assessed. Special measures will be introduced for suspects who are children and suspects who may have impaired capacity. The bill will bring in longer detention periods for the investigation of multiple offences being investigated together, for a maximum of up to 48 hours. It will also allow for a week's detention for suspects in human trafficking offences, which are currently subject to a maximum of 24 hours detention.
Google

Google Will Let Enterprises Store Their Google Workspace Encryption Keys (techcrunch.com) 26

As ubiquitous as Google Docs has become in the last year alone, a major criticism often overlooked by the countless workplaces that use it is that it isn't end-to-end encrypted, allowing Google -- or any requesting government agency -- access to a company's files. But Google is finally addressing that key complaint with a round of updates that will let customers shield their data by storing their own encryption keys. From a report: Google Workspace, the company's enterprise offering that includes Google Docs, Slides and Sheets, is adding client-side encryption so that a company's data will be indecipherable to Google. Companies using Google Workspace can store their encryption keys with one of four partners for now: Flowcrypt, Futurex, Thales or Virtru, which are compatible with Google's specifications. The move is largely aimed at regulated industries -- like finance, healthcare and defense -- where intellectual property and sensitive data are subject to intense privacy and compliance rules.
Google

Google's AirTable Rival, Tables, Graduates From Beta (techcrunch.com) 20

Last fall, Google's in-house incubator Area 120 introduced a new work-tracking tool called Tables, an AirTable (a San Francisco-based startup that makes cloud-based spreadsheet collaboration software and is valued at $5.77 billion) rival that allows for tracking projects more efficiently using automation. Today, Google says Tables will officially "graduate" from Area 120 to become an official Google product by joining Google Cloud, which it expects to complete in the next year. From a report: The Tables project was started by long-time Google employee, now Tables' GM Tim Gleason, who spent 10 years at the company and many more before that in the tech industry. He said he was inspired to work on Tables because he always had a difficult time tracking projects, as teams shared notes and tasks across different documents, which quickly got out of date.

[...] Another factor that prompted Tables' adoption was how quickly people could be productive, thanks in part to its ability to integrate with existing data warehouses and other services. Currently, Tables supports Office 365, Microsoft Access, Google Sheets, Slack, Salesforce, Box and Dropbox, for example. Tables was one of only a few Area 120 projects to launch with a paid business model, along with ticket seller Fundo, conversational ads platform AdLingo and Google's recently launched Orion WiFi. During its beta, an individual could use Tables for free, with support for up to 100 tables and 1,000 rows. The paid plan was supposed to cost $10 per user per month, with support for up to 1,000 tables and 10,000 rows. This plan also included support for larger attachments, more actions and advanced history, sharing, forms, automation and views.

Security

G7 Calls on Russia To Crack Down on Ransomware Gangs (therecord.media) 58

In light of the recent wave of high-profile ransomware attacks that have caused havoc in the US and Europe, the member states of the G7 group have called on Russia and other countries to crack down on ransomware gangs operating within their borders. From a report: "We call on all states to urgently identify and disrupt ransomware criminal networks operating from within their borders, and hold those networks accountable for their actions," the G7 group said in a communique published on Sunday, at the end of a three-day conference held in Cornwall, UK. "In particular, we call on Russia [...] to identify, disrupt, and hold to account those within its borders who conduct ransomware attacks, abuse virtual currency to launder ransoms, and other cybercrimes," the G7 group added.

The joint statement was signed by the governments of Canada, France, Germany, Italy, Japan, the UK, and the US -- more commonly known as the Group of Seven (G7). It comes after a series of ransomware attacks that caused disruptions at hospitals during the COVID-19 pandemic, fuel outages on the US East Coast following the Colonial Pipeline attack, and beef supply issues across Australia and the US following the JBS Foods ransomware incident.

Security

Ransomware Attack Targeted Teamsters Union in 2019. But They Just Refused to Pay (nbcnews.com) 149

NBC reports that America's "Teamsters" labor union was hit by a ransomware attack demanding $2.5 million back in 2019.

"But unlike many of the companies hit by high-profile ransomware attacks in recent months, the union declined to pay, despite the FBI's advice to do so, three sources familiar with the previously unreported cyberattack told NBC News." Personal information for the millions of active and retired members was never compromised, according to a Teamsters spokesperson, who also said that only one of the union's two email systems was frozen along with other data. Teamsters officials alerted the FBI and asked for help in identifying the source of the attack. They were told that many similar hacks were happening and that the FBI would not be able to assist in pursuing the culprit.

The FBI advised the Teamsters to "just pay it," the first source said. "They said 'this is happening all over D.C. ... and we're not doing anything about it,'" a second source said.

Union officials in Washington were divided over whether to pay the ransom — going so far as to bargain the number down to $1.1 million, according to the sources — but eventually sided with their insurance company, which urged them not to pony up... The Teamsters decided to rebuild their systems, and 99 percent of their data has been restored from archival material — some of it from hard copies — according to the union's spokesperson.

The FBI's communications office did not reply to repeated requests for comment. The FBI's stance is to discourage ransomware payments.

NBC News draws a lesson from the fact that it took nearly two years for this story to emerge. "An unknown number of companies and organizations have been extorted without ever saying a word about it publicly."
Encryption

Why Quantum Computers Won't End Up Cracking Bitcoin Wallets (cnbc.com) 91

"Within a decade, quantum computers could be powerful enough to break the cryptographic security that protects cell phones, bank accounts, email addresses and — yes — bitcoin wallets," writes CNBC.

But fortunately, that would happen only if we do nothing in the meantime, they're told by Thorsten Groetker, former Utimaco CTO "and one of the top experts in the field of quantum computing." Crypto experts told CNBC they aren't all that worried about quantum hacking of bitcoin wallets for a couple of different reasons. Castle Island Ventures founding partner Nic Carter pointed out that quantum breaks would be gradual rather than sudden. "We would have plenty of forewarning if quantum computing was reaching the stage of maturity and sophistication at which it started to threaten our core cryptographic primitives," he said. "It wouldn't be something that happens overnight."

There is also the fact that the community knows that it is coming, and researchers are already in the process of building quantum-safe cryptography. "The National Institute of Science and Technology (NIST) has been working on a new standard for encryption for the future that's quantum-proof," said Fred Thiel, CEO of cryptocurrency mining specialist Marathon Digital Holdings. NIST is running that selection process now, picking the best candidates and standardizing them.

"It's a technical problem, and there's a technical solution for it," said Groetker. "There are new and secure algorithms for digital signatures. ... You will have years of time to migrate your funds from one account to another." Groetker said he expects the first standard quantum-safe crypto algorithm by 2024, which is still, as he put it, well before we'd see a quantum computer capable of breaking bitcoin's cryptography. Once a newly standardized post-quantum secure cryptography is built, Groetker said, the process of mass migration will begin. "Everyone who owns bitcoin or ethereum will transfer [their] funds from the digital identity that is secured with the old type of key, to a new wallet, or new account, that's secured with a new type of key, which is going to be secure," he said.

There will still be the problem of users who forget their password or died without sharing their key.

But in those scenarios, CNBC suggests, "an organization could lock down all accounts still using the old type of cryptography and give owners some way to access it."

Slashdot Top Deals