The Almighty Buck

Schwab Sues Former Client After Accidental Transfer of $1.2 Million (reuters.com) 198

An anonymous reader writes: Charles Schwab is suing one of its former customers after the retail brokerage allegedly sent more than $1.2 million to an account of the Louisiana woman and then could not get the money back. Schwab meant to send $82.56 to Kelyn Spadoni's Fidelity Brokerage Services account in February, but a computer glitch caused it to erroneously transfer more than $1.2 million, according to the lawsuit. Schwab tried to get the money back, but repeated calls and texts to Spadoni, who lives in a suburb of New Orleans, were not returned, the brokerage said in the lawsuit. "We are fully cooperating with authorities in an effort to resolve this issue," Schwab said in a statement on Tuesday. Fidelity declined comment. After receiving the money in her account, Spadoni transferred a quarter of the money to another account, after which she bought a house and a car using the funds, Jefferson Parish Sheriff's Office spokesman Captain Jason Rivarde said in an interview on Tuesday. "Obviously you are not planning to give the money back if you spent it," he said. When Spadoni signed up with Schwab in January, the agreement she signed included a section that said any overpayment of funds must be returned, said the lawsuit, filed March 30.
Earth

Google Earth Now Shows Decades of Climate Change in Seconds (bloomberg.com) 66

Google Earth has partnered with NASA, the U.S. Geological Survey, the EU's Copernicus Climate Change Service, and Carnegie Mellon University's CREATE Lab to bring users time-lapse images of the planet's surface -- 24 million satellite photos taken over 37 years. Together they offer photographic evidence of a planet changing faster than at any time in millennia. Shorelines creep in. Cities blossom. Trees fall. Water reservoirs shrink. Glaciers melt and fracture. From a report: "We can objectively see global warming with our own eyes," said Rebecca Moore, director of Google Earth. "We hope that this can ground everyone in an objective, common understanding of what's actually happening on the planet, and inspire action." Timelapse, the name of the new Google Earth feature, is the largest video on the planet, according to a statement from the company, requiring 2 million hours to process in cloud computers, and the equivalent of 530,000 high-resolution videos. The tool stitches together nearly 50 years of imagery from the U.S.'s Landsat program, which is run by NASA and the USGS. When combined with images from complementary European Sentinel-2 satellites, Landsat provides the equivalent of complete coverage of the Earth's surface every two days. Google Earth is expected to update Timelapse about once a year.
Businesses

Dell Announces Long-Awaited Spinoff of VMware (siliconangle.com) 27

Dell has announced the long-expected spinoff of VMware, the computing virtualization company it has majority-owned since it bought then-owner EMC Corp. in 2016. From a report: The computing giant said it will spin off its 81% equity ownership in VMware, creating two standalone companies when the move is completed in the fourth quarter of this year. That timing depends on conditions such as a favorable Internal Revenue Service opinion that the transaction qualifies for tax-free status for Dell shareholders. The idea is to simplify the companies' capital structures, since arguably investors have valued both companies' stocks lower than they might have because of the uncertainties related to the complex capital structures. Dell's shares rose about 9% in after-hours trading, while VMware's shares rose about 1.6% in late trading. Under the spinoff, which Dell had signaled last year, VMware will distribute a cash dividend of about $11.5 billion to $12 billion to shareholders, which of course include publicly held Dell itself. Chairman and Chief Executive Michael Dell, along with financial partner Silver Lake Partners, own 60% of Dell shares. Dell will get $9.3 billion to $9.7 billion of that dividend, which the company said will help it get more investment-grade ratings and enable it to pay down debt it has gradually been reducing since buying EMC.
Google

Google's FeedBurner Moves To a New Infrastructure But Loses Its Email Subscription Service (techcrunch.com) 6

Google today announced that it is moving FeedBurner to a new infrastructure but also deprecating its email subscription service. From a report: If you're an internet user of a certain age, chances are you used Google's FeedBurner to manage the RSS feeds of your personal blogs and early podcasts at some point. During the Web 2.0 era, it was the de facto standard for feed management and analytics, after all. Founded in 2004, with Dick Costolo as one of its co-founders (before he became Twitter's CEO in 2010), it was acquired by Google in 2007. Ever since, FeedBurner lingered in an odd kind of limbo. While Google had no qualms shutting down popular services like Google Reader in favor of its ill-fated social experiments like Google+, FeedBurner just kept burning feeds day in and day out, even as Google slowly deprecated some parts of the service, most notably its advertising integrations. [...] But in July, it is also shutting down some non-core features that don't directly involve feed management, most importantly the FeedBurner email subscription service that allowed you to get emailed alerts when a feed updates. Feed owners will be able to download their email subscriber lists (and will be able to do so after July, too).
Desktops (Apple)

Parallels 16.5 Can Virtualize ARM Windows Natively on M1 Macs With Up to 30% Faster Performance (macrumors.com) 60

Parallels today announced the release of Parallels Desktop 16.5 for Mac with full support for M1 Macs, allowing for the Windows 10 ARM Insider Preview and ARM-based Linux distributions to be run in a virtual machine at native speeds on M1 Macs. From a report: Parallels says running a Windows 10 ARM Insider Preview virtual machine natively on an M1 Mac results in up to 30 percent better performance compared to a 2019 model 15-inch MacBook Pro with an Intel Core i9 processor, 32GB of RAM, and Radeon Pro Vega 20 graphics. Parallels also indicates that on an M1 Mac, Parallels Desktop 16.5 uses 2.5x less energy than on the latest Intel-based MacBook Air. Microsoft does not yet offer a retail version of ARM-based Windows, with the Windows 10 ARM Insider Preview available on Microsoft's website for Windows Insider program members. The ability to run macOS Big Sur in a virtual machine is a feature that Parallels hopes to add support for in Parallels Desktop later this year as well.
Security

Sweden Drops Russian Hacking Investigation Due To Legal Complications (therecord.media) 12

The Swedish government dropped today its investigation into the 2017 hack of its sports authority, citing legal constraints that would have prevented prosecutors from charging the Russian hackers responsible for the intrusion, which officials claimed were mere pawns operating on behalf of a "foreign power." From a report: This marks the first time that such a legal clause is cited by prosecutors investigating cyber-espionage hacking groups. Today's statement from the Swedish Prosecution Authority also marks the first time that Swedish officials formally blamed the Russian government for the 2017 hack of the Swedish Sports Confederation (SSC). Citing a recently-concluded investigation from the Swedish Security Service, which also involved foreign intelligence services, Swedish prosecutors said that one of Russia's military hacker groups breached its sports body between December 2017 and May 2018 and stole medical records for Swedish athletes.
Power

Biden Rushes To Protect the Power Grid as Hacking Threats Grow (bloomberg.com) 109

A White House plan to rapidly shore up the security of the U.S. power grid will begin with a 100-day sprint, but take years more to transform utilities' ability to fight off hackers, Bloomberg reported Wednesday, citing a draft version of the plan confirmed by two people. From the report: The plan is the policy equivalent of a high-wire act: it provides incentives for electric companies to dramatically change the way they protect themselves against cyber-attacks while trying to avoid political tripwires that have stalled previous efforts, the details suggest. Among its core tenets, the Biden administration's so-called "action plan" will incentivize power utilities to install sophisticated new monitoring equipment to more quickly detect hackers, and to share that information widely with the U.S. government. It will ask utilities to identify critical sites which, if attacked, could have an outsized impact across the grid, according to a six-page draft of the plan, which was drawn up by the National Security Council and described in detail to Bloomberg News. And it will expand a partially classified Energy Department program to identify flaws in grid components that could be exploited by the country's cyber-adversaries, including Russia, Iran and China.
Businesses

'Master,' 'Slave' and the Fight Over Offensive Terms in Computing (nytimes.com) 570

Nearly a year after the Internet Engineering Task Force took up a plan to replace words that could be considered racist, the debate is still raging. The New York Times: What started as an earnest proposal has stalled as members of the task force have debated the history of slavery and the prevalence of racism in tech. Some companies and tech organizations have forged ahead anyway, raising the possibility that important technical terms will have different meanings to different people -- a troubling proposition for an engineering world that needs broad agreement so technologies work together. While the fight over terminology reflects the intractability of racial issues in society, it is also indicative of a peculiar organizational culture that relies on informal consensus to get things done.

The Internet Engineering Task Force eschews voting, and it often measures consensus by asking opposing factions of engineers to hum during meetings. The hums are then assessed by volume and ferocity. Vigorous humming, even from only a few people, could indicate strong disagreement, a sign that consensus has not yet been reached. The I.E.T.F. has created rigorous standards for the internet and for itself. Until 2016, it required the documents in which its standards are published to be precisely 72 characters wide and 58 lines long, a format adapted from the era when programmers punched their code into paper cards and fed them into early IBM computers. "We have big fights with each other, but our intent is always to reach consensus," said Vint Cerf, one of the founders of the task force and a vice president at Google. "I think that the spirit of the I.E.T.F. still is that, if we're going to do anything, let's try to do it one way so that we can have a uniform expectation that things will function."

Australia

Australia's NDIS Gets a Government App With Blockchain But No Ethics (zdnet.com) 47

An anonymous reader quotes a report from ZDNet: Good news, disabled Australians! You'll soon be getting an app that will implement a welfare compliance regime designed by the people who brought you robo-debt. But don't worry, it'll have blockchain. No, this isn't good news at all. What makes it worse is that it's clear the government wants to extend technology-driven compliance to all Australians, with an emphasis on cracking down on your mistakes, not theirs. Kathryn Campbell, Secretary of the Department of Social Services, says the long-term plan is to have one app for all Commonwealth government services. "One to rule the world," she said last month, apparently oblivious to how evil that sounds.

Senators are already worried that the disability app, intended to be used by participants in the National Disability Insurance Scheme (NDIS) to claim expenses against their support plan, will go the way of COVIDSafe: Millions of dollars spent on technology that doesn't really do the job. The intention was to fix a poor web experience, and allow claims to be made from a mobile device. But instead of simply creating a better website, in 2018, the Digital Transformation Agency (DTA) joined forces with CSIRO's Data61 and the Commonwealth Bank to trial blockchain-based smart money that would magically know whether the expense was legitimate or not. According to the CEO of the National Disability Insurance Agency (NDIA), Martin Hoffman, that pilot app has been "very popular and well-received," and the feedback has been "extremely positive." The app will be "fully available in the coming months, first on Google Play and then Apple's app store," he said.
"Given the horrendously complex NDIS environment, defective processes and vulnerable people, there needs to be considerable caution in the application of blockchain technology," wrote former NDIS Technology Authority chief Marie Johnson in a submission [PDF] to the Parliamentary Joint Standing Committee on the NDIS. "Blockchain in itself -- as with other technology innovations -- does not address fundamental design and human rights issues. Ethics is paramount. The involvement of the Commonwealth Bank itself raises further ethics issues, given the value of participant data; the size of the market; and the yet to be realized emarket honey pot of data, funds and services."

You can view the detailed "Making Money Smart: Empowering NDIS participants with Blockchain technologies" report here (PDF).
Security

NSA Helps Out Microsoft With Critical Exchange Server Vulnerability Disclosures (theregister.com) 23

April showers bring hours of patches as Microsoft delivers its Patch Tuesday fun-fest consisting of over a hundred CVEs, including four Exchange Server vulnerabilities reported to the company by the US National Security Agency (NSA). The Register reports: Forty-four different products and services are affected, mainly having to do with Azure, Exchange Server, Office, Visual Studio Code, and Windows. Among the vulnerabilities, four have been publicly disclosed and a fifth is being actively exploited. Nineteen of the CVEs have been designated critical. "This month's release includes a number of critical vulnerabilities that we recommend you prioritize, including updates to protect against new vulnerabilities in on-premise Exchange Servers," Microsoft said in its blog post. "These new vulnerabilities were reported by a security partner through standard coordinated vulnerability disclosure and found internally by Microsoft. We have not seen the vulnerabilities used in attacks against our customers.

Clicking through Microsoft's coy links to CVE-2021-28480 (9.8 severity), CVE-2021-28481 (9.8 severity), CVE-2021-28482 (8.8 severity), and CVE-2021-28483 (9.0 severity), you'll find the unspecified security partner is the NSA. Exchange Server 2013 CU23, Exchange Server 2016 CU19 and CU20, and Exchange Server 2019 CU8 and CU9 are affected by this set of problems. "NSA urges applying critical Microsoft patches released today, as exploitation of these #vulnerabilities could allow persistent access and control of enterprise networks," the signals intelligence agency said via Twitter.

Security

NAME:WRECK Vulnerabilities Impact Millions of Smart and Industrial Devices (therecord.media) 21

Catalin Cimpanu, reporting at Record: Security researchers have found a new set of vulnerabilities that impact hundreds of millions of servers, smart devices, and industrial equipment. Called NAME:WRECK, the vulnerabilities have been discovered by enterprise IoT security firm Forescout as part of its internal research program named Project Memoria -- which the company describes as "an initiative that aims at providing the cybersecurity community with the largest study on the security of TCP/IP stacks." Although never visible to end-users, TCP/IP stacks are libraries that vendors add to their firmware to support internet connectivity and other networking functions for their devices. These libraries are very small but, in most cases, underpin the most basic functions of a device, and any vulnerability here exposes users to remote attacks. The NAME:WRECK research is the fifth set of vulnerabilities impacting TCP/IP libraries that have been disclosed over the past three years, and the third set disclosed part of Project Memoria.
Bug

Counter Strike' Bug Allows Hackers To Take Over a PC With a Steam Invite (vice.com) 26

Hackers could take control of victims' computers just by tricking them into clicking on a Steam invite to play Counter Strike: Global Offensive, Motherboard reports, citing a bug filing review. From a report: A bug in the game engine used in Counter Strike: Global Offensive could be exploited by hackers to take full control of a target's machine. A security researcher alerted Valve about the bug in June of 2019. Valve is the maker of Source Engine, which is used by CS:GO, Team Fortress 2, and several other games. The researcher, who goes by the name Florian, said that while that the bug has been fixed in some games that use the Source engine, it is still present in CS:GO, and he demonstrated it in a call with Motherboard. Florian's correspondence with Valve occurred on HackerOne, the bug bounty platform used by the company to get reports about vulnerabilities. Valve admitted that it was being slow to respond, even though it classified the bug as "critical" in the thread with the researchers, which Motherboard reviewed. "I am honestly very disappointed because they straight up ignored me most of the time," Florian said in an online chat.
Security

Security Researcher Drops Chrome and Edge Exploit on Twitter (therecord.media) 17

An Indian security researcher has published today proof-of-concept exploit code for a recently discovered vulnerability impacting Google Chrome, Microsoft Edge, and other Chromium-based browsers like Opera and Brave. From a report: The researcher, Rajvardhan Agarwal, told The Record today that the exploit code is for a Chromium bug that was used during the Pwn2Own hacking contest that took place last week. During the contest, security researchers Bruno Keith (@bkth_) & Niklas Baumstark (@_niklasb) of Dataflow Security used a vulnerability to run malicious code inside Chrome and Edge, for which they received $100,000. Per contest rules, details about this bug were handed over to the Chrome security team so the bug could be patched as soon as possible. While details about the exact nature of the bug were never publicly disclosed, Agarwal told The Record he spotted the patches for this bug by looking at the source code commits to the V8 JavaScript engine, a component of the Chromium open-source browser project, which allowed him to recreate the Pwn2Own exploit, which he uploaded earlier today on GitHub, and shared on Twitter. However, while Chromium developers have patched the V8 bug last week, the patch has not yet been integrated into official releases of downstream Chromium-based browsers such as Chrome, Edge, and others, which are still vulnerable to attacks.
Microsoft

Microsoft Announces New Webcam and USB-C Speaker for the Work from Home Era (theverge.com) 48

Microsoft's long-awaited new webcam is finally here, alongside a number of accessories designed for the work from home era. From a report: Rumors of a new Microsoft webcam have been circulating for years, and the result is what Microsoft calls the Modern Webcam. It's a fairly basic and affordable 1080p webcam that will start shipping for $69.99 in June. The Microsoft Modern Webcam will support up to 1080p HDR output at 30fps and connects via USB-A, not USB-C. It's not the 4K webcam found on Microsoft's Surface Hub 2, and it doesn't include Windows Hello support either. It's really a simple webcam designed for students or workers to quickly add a better video calling option to an existing laptop or PC. Microsoft is also including a privacy shutter and LED indicator to let people easily see when the webcam is active. Microsoft is also launching a new USB-C speaker. The Modern USB-C Speaker is designed primarily for Microsoft Teams, and it even includes a button to launch a control panel for Teams with quick actions for meetings.
Privacy

Billions of Smartphone Owners Will Soon Be Authorizing Payments Using Facial Recognition (zdnet.com) 104

An anonymous reader quotes a report from ZDNet: The next few years will see billions of users regularly using facial recognition technology to secure payments made through their smartphone, tablets or smartwatches, according to new analysis carried out by Juniper Research. Smartphone owners are already used to staring at their screens to safely unlock their devices without having to dial in a secret code; now, facial recognition will increasingly be deployed to verify the identity of a user making a payment with their handset, whether that's via an app or directly in-store, in wallet mode.

In addition to facial features, Juniper Research's analysts predict that a host of biometrics will be used to authenticate mobile payments, including fingerprint, iris and voice recognition. Biometric capabilities will reach 95% of smartphones globally by 2025, according to the researchers; by that time, users' biological characteristics will be authenticating over $3 trillion-worth of payment transactions -- up from $404 billion in 2020. [...] "All you need for software-based facial recognition is a front-facing camera on the device and accompanying software," Nick Maynard, lead analyst at Juniper Research, tells ZDNet. "In a hardware-based system, there will be additional hardware layers that add additional security levels. It's increasingly important to differentiate because hardware-based systems are the more secure of the two." Maynard's research shows that between now and 2025, the number of handsets using hardware-based systems will grow by a dramatic 376% to reach 17% of smartphones. Juniper expects the number of smartphone owners using [software-based facial recognition systems] to secure payments to grow by 120% to 2025, to reach 1.4 billion devices -- that is, roughly 27% of smartphones globally.
"Hardware-based systems obviously have additional costs per device," adds Maynard, "but the reason it is growing well is really that Apple has been driving it forward. They've made the technology a part of their high-end devices, and shown that hardware-based facial recognition technology can be done and can be very secure."

"Software-based facial recognition is strong because it's very easy to deploy," Maynard continues, "but we are expecting a shift towards hardware-based systems as software becomes invalidated by fraudster approaches. Fraudster methods are always evolving, and the hardware needs to evolve with it."
Security

Your WhatsApp Account Can Be Suspended By Anyone Who Has Your Phone Number (androidpolice.com) 18

An anonymous reader writes: If you're a frequent user of WhatsApp, you may want to keep an eye on a disturbing hole discovered in its security this weekend. It's possible for an attacker to completely suspend your WhatsApp account, without any recourse for the individual user, and all they need is your phone number. At the time of writing there's no solution for this issue.

This newly-discovered flaw uses two separate vectors. The attacker installs WhatsApp on a new device and enters your number to activate the chat service. They can't verify it, because of course, the two-factor authentication system is sending the login prompts to your phone instead. After multiple repeated and failed attempts, your login is locked for 12 hours. Here's where the tricky part comes in: with your account locked, the attacker sends a support message to WhatsApp from their email address, claiming that their (your) phone has been lost or stolen, and that the account associated with your number needs to be deactivated. WhatsApp "verifies" this with a reply email, and suspends your account without any input on your end. The attacker can repeat the process several times in succession to create a semi-permanent lock on your account. The results are disturbing, but at the very least, this method can't be used to actually gain access to an account, merely to block access by its legitimate owner. Confidential text messages and contacts are not exposed.
The proof-of-concept attack was first reported by Forbes from security researchers Luis Marquez Carpintero and Ernesto Canales Perena. There's no indication that it's being used in the wild.
IT

Logitech Harmony Remote Controls Officially Discontinued (cepro.com) 77

CIStud writes: The rumors have persisted for some time, and now Logitech has officially confirmed it has discontinued its once-vaunted Harmony remote controls, including the line of Logitech Harmony Pro programmable remotes for custom installers. Logitech plans to continue maintaining the Harmony database and software. The discontinuation does not affect the operation or the warranty on any Harmony remotes being used by integrators' clients already in the field. Logitech also plans to continue to offer service and support for Harmony remotes. The company also points out that the decision does not affect a customer's ability to interface with the Harmony universal remotes via their Amazon Alexa or Google Assistant voice controls.
United States

Are Silicon Valley Tech Workers Now Swarming 'a Reluctant Austin'? (bloomberg.com) 222

Austin, Texas is America's fastest-growing major metro area, reports Bloomberg Businessweek, growing 30% from 2010 to 2019. But today a minimum wage worker hoping to afford a one-bedroom rental "would now need to work a 125-hour week."

And meanwhile, homeowner Matthew Congrove says he's now getting a half-dozen all-cash offers on his house every week. "In the boldest attempt, a stranger simply showed up at his home unannounced and asked to buy it..." Even Congrove — a software engineer who moved from Florida seven years ago — is most concerned about how the new wave of tech workers is affecting his adopted city's culture. Lately, he's seen more T-shirts bearing startup logos than band names. New condos have sprouted up where quirky bungalows once stood. And the commute time to his downtown office has tripled. "They just keep coming," Congrove says. "The fleece vests, the tech bros — that's definitely imported from California."

During the pandemic, Austin has welcomed more new residents from the Bay Area than from any other region outside Texas, according to records provided to Bloomberg by the U.S. Postal Service... Oracle late last year said it was moving its headquarters to Austin, and a stream of tech elites including prominent investor Jim Breyer and the chief executive officers of Dropbox and Splunk made plans to relocate. Elon Musk, the second-richest man in the world, is now a resident of Texas — though he hasn't said where — and Tesla Inc. is building a factory in Austin's outskirts, where Musk has said the company will need 10,000 people by 2022. He's also expanding the Austin area operations for Boring Co. and SpaceX, and has moved his personal foundation to the city's downtown.

For all his boosterism, even Musk recognizes the potential hazards of the influx he's helping spark. In a tweet on April 4, he called out the "urgent need to build more housing in greater Austin area!"

The region is facing the same boomtown dynamics that have plagued San Francisco for decades.... "There is a fairly broad-based concern that some of the things that aren't working in other areas are going to be brought here," says Dax Williamson, a managing director for Silicon Valley Bank who leads its technology banking practice for Central Texas. "If we price out the musicians we're going to find ourselves in a bad place." In a sign that may already be happening, Tesla recently selected a warehouse in southern Austin that served as music rehearsal space, with plans to transform it into a $2.5 million Tesla showroom this summer.

Hating California is a tradition in Texas, but Austin's growing pains aren't all California's fault. According to the Austin Chamber, more than half of newcomers from 2014 to 2018 came from other parts of the state, followed by just 8% from California and 3% from New York... Still, out-of-state arrivals from affluent cities tend to be richer than average existing residents and, as a consequence, have a greater impact on the local economy. "Probably 5 out of 10 of my clients are Californians, and others could say the same thing," says Susan Horton, president of the Austin Board of Realtors. "The majority are all tech people, and the last wave were all coming to work at Tesla."

The Military

Iran Nuclear Facility Suffers Blackout, Cyberattack Suspected (apnews.com) 117

While difficult negotiations continue over a deal to curtail Iran's nuclear ambitions, this morning Iran suddenly experienced a blackout at its underground Natanz atomic facility, the Associated Press reports: While there was no immediate claim of responsibility, suspicion fell immediately on Israel, where its media nearly uniformly reported a devastating cyberattack orchestrated by the country caused the blackout. Israeli Prime Minister Benjamin Netanyahu later Sunday night toasted his security chiefs, with the head of the Mossad, Yossi Cohen, at his side on the eve of his country's Independence Day... Netanyahu, who also met Sunday with U.S. Defense Secretary Lloyd Austin, has vowed to do everything in his power to stop the nuclear deal...

Natanz has been targeted by sabotage in the past. The Stuxnet computer virus, discovered in 2010 and widely believed to be a joint U.S.-Israeli creation, once disrupted and destroyed Iranian centrifuges at Natanz amid an earlier period of Western fears about Tehran's program. Natanz suffered a mysterious explosion at its advanced centrifuge assembly plant in July that authorities later described as sabotage. Iran now is rebuilding that facility deep inside a nearby mountain. Iran also blamed Israel for the November killing of a scientist who began the country's military nuclear program decades earlier.

Multiple Israeli media outlets reported Sunday that an Israeli cyberattack caused the blackout in Natanz. Public broadcaster Kan said the Mossad was behind the attack. Channel 12 TV cited "experts" as estimating the attack shut down entire sections of the facility. While the reports offered no sourcing for their information, Israeli media maintains a close relationship with the country's military and intelligence agencies...

On Tuesday, an Iranian cargo ship said to serve as a floating base for Iran's paramilitary Revolutionary Guard forces off the coast of Yemen was struck by an explosion, likely from a limpet mine. Iran has blamed Israel for the blast. That attack escalated a long-running shadow war in Mideast waterways targeting shipping in the region.

PHP

Git.PHP.net Not Compromised in Supply Chain Attack, but User Database Leak Possible (inside.com) 18

Inside.com's developer newsletter reports: The PHP team no longer believes the git.php.net server was compromised in a recent attack, which prompted PHP to move servers to GitHub and caused the team to temporarily put releases on hold until mid-April...

In an update offering further insight into the root cause of the late March attack, the team says because it's possible the master.php.net user database was exposed, master.php.net has been moved to main.php.net. The team also reset php.net passwords, and you can visit https://main.php.net/forgot.php to set a new password. In addition, git.php.net and svn.php.net are both read-only now.

Two malicious commits were pushed to the php-src repo from PHP founder Rasmus Lerdorf and PHP core developer Nikita Popov, Popov announced March 28. After an investigation, the PHP team reassured users these malicious commits never reached end-users. However, the team decided to move to GitHub after determining maintaining its own git infrastructure is "an unnecessary security risk."

"In 2019, the PHP team temporarily shut down its Git server after discovering that an attacker had maliciously replaced the official PHP Extension and Application Repository with a malicious one," reports CPO magazine. But this newer supply chain attack "targeted any server that uses PHP ZLib compression when sending data. Most servers use this functionality on almost all content except images and archives that are already size optimized." The supply chain attack would have turned PHP into a remote web shell through which the attackers could execute any command without authentication. This is because the malicious attackers would have the same privileges as the web server running PHP. The backdoor is triggered at the start of a request by checking if the request contains the word "zerodium." If this condition was met, PHP executes the code in the "User-Agentt" request header. The header closely resembles the PHP "User-Agent" request for checking for browser properties.

The rest of the request would thus be treated as a command that could be executed on a PHP server using the server's privileges. This would allow the hackers to run any arbitrary command without the need for further privileges...

PHP powers 80% of all websites. Thus, a successful supply chain attack exploiting the language could prove catastrophic.

Slashdot Top Deals