Social Networks

Attackers Can Now Remotely Deactivate WhatsApp on Your Phone (forbes.com) 52

"Using just your phone number, a remote attacker can easily deactivate WhatsApp on your phone and then stop you getting back in," reports a new article in Forbes. "Even two-factor authentication will not stop this..."

The attacker triggers a 12-hour freeze on new verification codes being sent to your phone — then simply reports that same phone number as a lost/stolen phone needing deactivation. There are apparently no follow-up questions, and "an automated process has been triggered, without your knowledge, and your account will now be deactivated," Forbes writes.

The phone can't be reactivated without one of those verification codes blocked by that 12-hour freeze (which the attacker can renew for another 12-hour window, until the next day WhatsApp blocks those reactivating codes indefinitely). "There is no sophistication to this attack — that's the real issue here and WhatsApp should address it immediately..." Forbes complains. This shouldn't happen. It shouldn't be possible. Not with a platform used by 2 billion people. Not this easily. When researchers, Luis Márquez Carpintero and Ernesto Canales Pereña, warned they could kill WhatsApp on my phone, blocking me from my own account using just my phone number, I was doubtful. But they were right...

Despite its vast user base, WhatsApp is creaking at the seams. Its architecture has fallen behind its rivals, missing key features such as multi-device access and fully encrypted backups. As the world's most popular messenger focuses on mandating new terms of service to enable Facebook's latest money-making schemes, these much-needed advancements remain "in development...."

Reached for comment, WhatsApp told Forbes that any victims of the attack should contact their support team — adding that such an attack would "violate our terms of service."

But Forbes adds "your other option would be to follow Mark Zuckerberg's reported example and start to use Signal..." Unfortunately, playing down the seriousness of security risks has become the in-house style at Facebook. Back in 2019, I reported on a vulnerability that allowed private user phone numbers to be pulled from Facebook databases at scale using automated bots. That hack was acknowledged by Facebook but dismissed as an "unlikely problem." Some 533 million users might now disagree.
United Kingdom

In Serious Incident, Software Glitch Miscalculates the Weight of Three UK Flights (theguardian.com) 93

A software mistake caused a flight on Tui airlines "to take off heavier than expected," according to The Guardian, citing an investigation by the UK's Air Accidents Investigation Branch An update to the airline's reservation system while its planes were grounded due to the coronavirus pandemic led to 38 passengers on the flight being allocated a child's "standard weight" of 35kg [77 pounds] as opposed to the adult figure of 69kg [152 pounds]. This caused the load sheet — produced for the captain to calculate what inputs are needed for take-off — to state that the Boeing 737 was more than 1,200kg lighter [2,645 pounds] than it actually was.

Investigators described the glitch as "a simple flaw" in an IT system. It was programmed in an unnamed foreign country where the title "Miss" is used for a child and "Ms" for an adult female.

Despite the issue, the thrust used for the departure from Birmingham on 21 July 2020 was only "marginally less" than it should have been, and the "safe operation of the aircraft was not compromised", the AAIB said.

They're still classifying it as a "serious incident" — and also note that because of the same software glitch, two more UK flights also took off on the same day with inaccurate load sheets.
Encryption

Customs and Border Protection Paid $700,000 To Encrypted App Wickr (vice.com) 16

An anonymous reader quotes a report from Motherboard: U.S. Customs and Border Protection (CBP), part of the Department of Homeland Security, recently paid encrypted messaging platform Wickr over $700,000, Motherboard has found. The news highlights the value of end-to-end encryption to law enforcement, while other federal law enforcement agencies routinely lambast the technology for what they say results in visibility on criminals' activities "going dark."

The contract is related to "Wickr licenses and support," dates from September 2020, and totals at $714,600, according to public procurement records. Wickr is likely most well known for its free consumer app, which lets users send encrypted messages to one another, as well as make encrypted video and audio calls. The app also offers an auto-burn feature, where messages are deleted from a users' device after a certain period of time, with the company claiming these messages "can never be uncovered," according to its website. Wickr also offers various paid products to private companies and government agencies. Wickr Pro and Wickr Enterprise are marketed towards businesses; Wickr RAM is geared specifically for the military. [...] It is not clear which specific Wickr product CBP paid for.
A CBP spokesperson told Motherboard in a statement that "The Federal Acquisition Regulations (FAR) and other laws prohibit the unauthorized use and disclosure of proprietary information from federal government contract actions. All publicly available information on this contract has been made available at the link you have provided. Any other information is considered proprietary to the awardee (WICKR) and shall not be divulged outside of the Government."
Security

Critical Zoom Vulnerability Triggers Remote Code Execution Without User Input (zdnet.com) 14

An anonymous reader quotes a report from ZDNet: A zero-day vulnerability in Zoom which can be used to launch remote code execution (RCE) attacks has been disclosed by researchers. The researchers from Computest demonstrated a three-bug attack chain that caused an RCE on a target machine, and all without any form of user interaction. As Zoom has not yet had time to patch the critical security issue, the specific technical details of the vulnerability are being kept under wraps. However, an animation of the attack in action demonstrates how an attacker was able to open the calculator program of a machine running Zoom following its exploit. As noted by Malwarebytes, the attack works on both Windows and Mac versions of Zoom, but it has not -- yet -- been tested on iOS or Android. The browser version of the videoconferencing software is not impacted. Computest researchers Daan Keuper and Thijs Alkemade earned themselves $200,000 for this Zoom discovery, as it was part of the Pwn2Own contest.

In a statement to Tom's Guide, Zoom thanked the Computest researchers and said the company was "working to mitigate this issue with respect to Zoom Chat." In-session Zoom Meetings and Zoom Video Webinars are not affected. "The attack must also originate from an accepted external contact or be a part of the target's same organizational account," Zoom added. "As a best practice, Zoom recommends that all users only accept contact requests from individuals they know and trust."
Android

APKPure App Contained Malicious Adware, Say Researchers (techcrunch.com) 31

Security researchers say APKPure, a widely popular app for installing older or discontinued Android apps from outside of Google's app store, contained malicious adware that flooded the victim's device with unwanted ads. From a report: Kaspersky Lab said that it alerted APKPure on Thursday that its most recent app version, 3.17.18, contained malicious code that siphoned off data from a victim's device without their knowledge, and pushed ads to the device's lock screen and in the background to generate fraudulent revenue for the adware operators. But the researchers said that the malicious code had the capacity to download other malware, potentially putting affected victims at further risk.
Google

W3C Slaps Down Google's Proposal To Treat Multiple Domains as Same Origin (theregister.com) 40

A Google proposal which enables a web browser to treat a group of domains as one for privacy and security reasons has been opposed by the W3C Technical Architecture Group (TAG). From a report: Google's First Party Sets (FPS) relates to the way web browsers determine whether a cookie or other resource comes from the same site to which the user has navigated or from another site. The browser is likely to treat these differently, an obvious example being the plan to block third-party cookies. The proposal suggests that where multiple domains owned by the same entity -- such as google.com, google.co.uk, and youtube.com -- they could be grouped into sets which "allow related domain names to declare themselves as the same first-party." The idea allows for sites to declare their own sets by means of a manifest in a known location. It also states that "the browser vendor could maintain a list of domains which meet its UA [User Agent] policy, and ship it in the browser."

In February 2019, Google software engineer Mike West requested a TAG review and feedback on the proposal was published yesterday. "It has been reviewed by the TAG and represents a consensus view," the document says. According to the TAG, "the architectural plank of the origin has remained relatively steady" over the last 10 years, despite major changes in web technology. It added: "We are concerned that this proposal weakens the concept of origin without considering the full implications of this action." The group identified some vagueness in the proposal, such as whether FPS applies to permissions such as access to microphone and camera. A Google Chrome engineering manager has stated: "No, we are not proposing to change the scope for permissions. The current scope for FPS is only to be treated as a privacy boundary where browsers impose cross-site tracking limitations." But the TAG reckons that the precise scope of FPS should be laid out in the proposal. A second concern is over the suggestion that browser vendors would ship their own lists. "This could lead to more application developers targeting specific browsers and writing web apps that only work (or are limited to) those browsers, which is not a desirable outcome," said the TAG.

Businesses

Wix and Their Dirty Tricks (ma.tt) 60

Matt Mullenweg, co-founder of the open-source blogging platform WordPress, writes: Wix, the website builder company you may remember from stealing WordPress code and lying about it, has now decided the best way to gain relevance is attacking the open source WordPress community in a bizarre set of ads. They can't even come up with original concepts for attack ads, and have tried to rip-off of Apple's Mac vs PC ads, but tastelessly personify the WordPress community as an absent, drunken father in a therapy session.

I have a lot of empathy for whoever was forced to work on these ads, including the actors, it must have felt bad working on something that's like Encyclopedia Britannica attacking Wikipedia. WordPress is a global movement of hundreds of thousands of volunteers and community members, coming together to make the web a better place. The code, and everything you put into it, belongs to you, and its open source license ensures that you're in complete control, now and forever. WordPress is free, and also gives you freedom. So if we're comparing website builders to abusive relationships, Wix is one that locks you in the basement and doesn't let you leave. I'm surprised consumer protection agencies haven't gone after them.

Wix is a for-profit company with a valuation that peaked at around 20 billion dollars, and whose business model is getting customers to pay more and more every year and making it difficult to leave or get a refund. (Don't take my word for it, look at their investor presentations.) They are so insecure that they are also the only website creator I'm aware of that doesn't allow you to export your content, so they're like a roach motel where you can check in but never check out. Once you buy into their proprietary stack you're locked in, which even their support documentation admits.

Privacy

Hackers Scraped Data from 500 Million LinkedIn Users -- and Have Posted it For Sale Online (businessinsider.com) 33

Data from 500 million LinkedIn users has been scraped and is for sale online, according to a report from Cyber News. A LinkedIn spokesperson confirmed to Insider that there is a dataset of public information that was scraped from the platform. From a report: "While we're still investigating this issue, the posted dataset appears to include publicly viewable information that was scraped from LinkedIn combined with data aggregated from other websites or companies," a LinkedIn spokesperson told Insider in a statement. "Scraping our members' data from LinkedIn violates our terms of service and we are constantly working to protect our members and their data." LinkedIn has 740 million users, according to its website, so the reported data scraping of 500 million users means about two-thirds of the platform's user base could be affected. The data includes account IDs, full names, email addresses, phone numbers, workplace information, genders, and links to other social media accounts.
Australia

Australian Minister's Phone Hacked as Report Reveals Hong Kong Link (bloomberg.com) 37

A second senior Australian government minister has revealed his mobile phone was hacked through the Telegram messaging app, with a media report saying the phishing scam was aimed at revealing contact details of pro-democracy activists in Hong Kong. From a report: Health Minister Greg Hunt's office said in an emailed statement on Thursday that "a cyber security attempt to impersonate the minister has been referred to the Australian Federal Police and investigations are underway." That follows Monday's statement by Finance Minister Simon Birmingham that he had been targeted. The Australian newspaper reported late Wednesday that the details of pro-democracy Hong Kongers were provided to someone impersonating Birmingham, with one of the recipients being asked: "Do you have any contacts in Hong Kong?" The person handed over details of Hong Kongers without realizing they were speaking to a cyber-hacker, the paper said, citing the person who it didn't identify.
Security

Polish Blogger Sued After Revealing Security Issue In Encrypted Messenger (therecord.media) 25

An anonymous reader quotes a report from The Record: The company behind the UseCrypt Messenger encrypted instant messaging application filed a lawsuit last month against a Polish security researcher for publishing an article that exposed a vulnerability in the app's user invite mechanism. The lawsuit targets Tomasz Zieliski, the editor of Informatyk Zakadowy, a Polish blog dedicated to IT topics, and denounces one of the site's articles, published in October 2020. The article describes how Zielinski found that in some cases, when UseCrypt Messenger users wanted to invite a friend to the app, the application used an insecure domain (autofwd.com) to send out user invitations. Zielinski found that besides running on an insecure HTTP connection, the AutoFWD.com website was also vulnerable to SQL injection and cross-site scripting (XSS) vulnerabilities that would have allowed anyone to hijack the site and then read or tamper with UseCrypt invitations. But while the authors of the AutoFWD.com website admitted to the security weaknesses in their service and shut down their website, Zieliski received a firm rebuttal of his research from V440 SA, the legal entity behind the UseCrypt Messenger.

In a message the company sent Zieliski a day after his blog post went live, they claimed his research contained "false information." In a message the company sent Zieliski a day after his blog post went live, they claimed his research contained "false information." V440 SA said their app did not use the AutoFWD.com service to handle user invitations but instead relied on an in-house solution hosted on the get.usecryptmessenger.com domain. But in a subsequent update, Zieliski claims that the UseCrypt team was lying and that, in reality, they silently patched their app to remove the AutoFWD.com from its user invite mechanism after his research was posted online and were merely trying to dismiss his findings, even after he notified them in advance of his research.
To make matters worse, V440 SA had reportedly filed criminal complaints against not only Zielinksi's blog but also against Niebezpiecznik and Zaufana Trzecia Strona, two other Polish IT security blogs, claiming that the three were working as part of an "organized criminal group."

"Requests to remove articles, requests for apologies and other letters from law firms addressed to our editors will not make us stop being interested in a certain issue," the editors of the Polish blogs said in a joint statement. It's currently unknown if there is actually a criminal investigation underway against the three sites or if this is just an intimidation tactic.
Facebook

Facebook Does Not Plan To Notify Half-Billion Users Affected by Data Leak (reuters.com) 22

Facebook did not notify the more than 530 million users whose details were obtained through the misuse of a feature before 2019 and recently made public in a database, and does not currently have plans to do so, a company spokesman said on Wednesday. Reuters: Business Insider reported last week that phone numbers and other details from user profiles were available in a public database. Facebook said in a blog post on Tuesday that "malicious actors" had obtained the data prior to September 2019 by "scraping" profiles using a vulnerability in the platform's tool for synching contacts. The Facebook spokesman said the social media company was not confident it had full visibility on which users would need to be notified. He said it also took into account that users could not fix the issue and that the data was publicly available in deciding not to notify users. Facebook has said it plugged the hole after identifying the problem at the time. Further reading: Facebook Says It's Your Fault That Hackers Got Half a Billion User Phone Numbers.
IT

Gazelle Brings Back Its Phone Trade-in Program Two Months After Discontinuing It (theverge.com) 3

Trade-in provider Gazelle exited the online trade-in business back in February, and now the company says it's changing its mind. From a report: Gazelle is back to accepting online trade-ins of iPhones, Samsung phones, Google Pixel devices, and iPads and other tablets on its website, the company confirms to The Verge. The program resumed accepting new offers on April 5th, a Gazelle representative clarified. "Earlier this year, we announced that we will no longer be offering our trade-in option on Gazelle. After careful consideration, including feedback from customers like you, we have decided to keep Gazelle Trade-In going. Today, we are happy to say, 'We're back, baby!'" reads an email Gazelle sent to prospective customers. "Gazelle Trade-In is a pioneer of the electronics trade-in space and we are happy to continue building on our legacy by offering a simple process and immediate payouts for those unwanted devices." Gazelle emerged as one of the leading trade-in providers of the smartphone era. But its business model didn't fare as well when the US mobile phone business underwent major shifts away from two-year contracts and outright device purchases and toward phone leasing and carrier and device maker trade-in programs like Apple's.
Java

Microsoft Previews Its Open Source Java Distribution, Microsoft Build of OpenJDK (betanews.com) 145

Mark Wilson writes: Microsoft has launched a preview version of its own distribution of Java, making it available for Windows, macOS and Linux. The company has named the release Microsoft Build of OpenJDK, and describes it as its "new way to collaborate and contribute to the Java ecosystem". The company has made available Microsoft Build of OpenJDK binaries for Java 11, which are based on OpenJDK source code. Microsoft says it is looking to broaden and deepen its support for Java, "one of the most important programming languages used today".
Facebook

Facebook Says It's Your Fault That Hackers Got Half a Billion User Phone Numbers (vice.com) 65

A database containing the phone numbers of more than half a billion Facebook users is being freely traded online, and Facebook is trying to pin the blame on everyone but themselves. From a report: A blog post titled "The Facts on News Reports About Facebook Data," published Tuesday evening, is designed to silence the growing criticism the company is facing for failing to protect the phone numbers and other personal information of 533 million users after a database containing that information was shared for free in low level hacking forums over the weekend, as first reported by Business Insider. Facebook initially dismissed the reports as irrelevant, claiming the data was leaked years ago and so the fact it had all been collected into one uber database containing one in every 15 people on the planet -- and was now being given away for free -- didn't really matter.

So instead of apologizing for failing to keep users' data secure, Facebook's product management director Mike Clark began his blog post by making a semantic point about how the data was leaked. "It is important to understand that malicious actors obtained this data not through hacking our systems but by scraping it from our platform prior to September 2019," Clark wrote. This is the identical excuse given in 2018, when it was revealed that Facebook had given Cambridge Analytica the data of 87 million users without their permission, for use in political ads. Clark goes on to explain that the people who collected this data -- sorry, "scraped" this data -- did so by using a feature designed to help new users find their friends on the platform.

Security

Cyberware Attack Shuts Down Vehicle Emissions Testing In Georgia and Seven Other States (wsbtv.com) 48

Georgia is waiving vehicle emissions checks because a cyberware attack has halted all emission testing across Georgia and seven other states. Slashdot reader McGruber shares a report from WSB-TV, an ABC-affiliated television station licensed to Atlanta: The CEO of Applus Technologies, whose software runs the system, apologized during the emergency meeting Monday. The outages are delivering a huge blow to small business owners. "All of the sudden, we were doing emissions testing just like normal and the system just kind of shut down," said James Baxter, who owns BP Car Care Tire Pros. "We haven't been able to do emissions since." Baxter said before the cyberattack, his full service automobile shop conducted more than 100 vehicle emissions tests per day. "Emissions is $25. You can imagine the revenue loss. We have employees that are out of work because of this," he said. Last week, Georgia's Department of Revenue issued a press release that omitted mention of the attack.

The Georgia Department of Revenue said its automated systems have been offline since March 31. According to the report, officials aren't sure when the system will go back online. It's also unclear if the hackers were able to access any personal information.
Privacy

Congress Says Foreign Intel Services Could Abuse Ad Networks For Spying (vice.com) 30

An anonymous reader quotes a report from Motherboard: A group of bipartisan lawmakers, including the chairman of the intelligence committee, have asked ad networks such as Google and Twitter what foreign companies they provide user data to, over concerns that foreign intelligence agencies could be leveraging them to harvest sensitive information on U.S. users, including their location. "This information would be a goldmine for foreign intelligence services that could exploit it to inform and supercharge hacking, blackmail, and influence campaigns," a letter signed by Senators Ron Wyden, Mark Warner, Kirsten Gillibrand, Sherrod Brown, Elizabeth Warren, and Bill Cassidy, reads. The lawmakers sent the letter last week to AT&T, Verizon, Google, Twitter, and a number of other companies that maintain advertisement platforms.

The concerns center around the process of so-called real-time bidding, and the flow of "bidstream" data. Before an advertisement is displayed inside of an app or a browsing session, different companies bid to get their ad into that slot. As part of that process, participating companies obtain sensitive data on the user, even if they don't win the ad placement. "Few Americans realize that some auction participants are siphoning off and storing 'bidstream' data to compile exhaustive dossiers about them. In turn, these dossiers are being openly sold to anyone with a credit card, including to hedge funds, political campaigns, and even to governments," the letter continued. [...] The letter asked the ad companies to name the foreign-headquartered or foreign-majority owned firms that they have provided bidstream data from users in the U.S. to in the past three years. The other companies the lawmakers sent the letter to were Index Exchange, Magnite, OpenX, and PubMatic.
Mark Tallman, assistant professor at the Department of Emergency Management and Homeland Security at the Massachusetts Maritime Academy, told Motherboard in an email that "It's difficult to imagine any policy solution or technical sorcery that can fully 'secure' consumers' private data such that applications and platforms can collect it, and the publishing and advertising industries can access it, while guaranteeing that cybercriminals and foreign intelligence agencies will never get it. Our adversaries already know that they can buy (or steal) data from our marketplace that they could only dream of collecting on such a broad swath of Americans twenty years ago."
Security

European Institutions Were Targeted in a Cyber-Attack Last Week (bloomberg.com) 6

A range of European Union institutions including the European Commission were hit by a significant cyber-attack last week. From a report: A spokesperson for the commission said that a number of EU bodies "experienced an IT security incident in their IT infrastructure." The spokesperson said forensic analysis of the incident is still in its initial phase and that it's too early to provide any conclusive information about the nature of the attack. "We are working closely with CERT-EU, the Computer Emergency Response Team for all EU institutions, bodies and agencies and the vendor of the affected IT solution," the spokesperson said. "Thus far, no major information breach was detected." The attack was serious enough for senior officials at the commission to be alerted, according to a person familiar with the matter. The same person said the incident was bigger than the usual attacks that regularly hit the EU. Another EU official said that staff had recently been warned about potential phishing attempts. Western institutions have uncovered at least two serious cyber-attacks recently.
Microsoft

Microsoft is Now Submerging Servers Into Liquid Baths (theverge.com) 82

Microsoft is starting to submerge its servers in liquid to improve their performance and energy efficiency. A rack of servers is now being used for production loads in what looks like a liquid bath. From a report: This immersion process has existed in the industry for a few years now, but Microsoft claims it's "the first cloud provider that is running two-phase immersion cooling in a production environment." The cooling works by completely submerging server racks in a specially designed non-conductive fluid. The fluorocarbon-based liquid works by removing heat as it directly hits components and the fluid reaches a lower boiling point (122 degrees Fahrenheit or 50 degrees Celsius) to condense and fall back into the bath as a raining liquid. This creates a closed-loop cooling system, reducing costs as no energy is needed to move the liquid around the tank, and no chiller is needed for the condenser either. "It's essentially a bath tub," explains Christian Belady, vice president of Microsoft's data center advanced development group, in an interview with The Verge. "The rack will lie down inside that bath tub, and what you'll see is boiling just like you'd see boiling in your pot. The boiling in your pot is at 100 degrees Celsius, and in this case it's at 50 degrees Celsius."
Facebook

Irish Regulator Probes 'Old' Facebook Data Dump (bbc.com) 13

A data leak involving personal details of hundreds of millions of Facebook users is being reviewed by Ireland's Data Protection Commission (DPC). The BBC reports: The database is believed to contain a mix of Facebook profile names, phone numbers, locations and other facts about more than 530 million people. Facebook says the data is "old," from a previously-reported leak in 2019. But the Irish DPC said it will work with Facebook, to make sure that is the case.

Ireland's regulator is critical to such investigations, as Facebook's European headquarters is in Dublin, making it an important regulator for the EU. The most recent data dump appears to contain the entire compromised database from the previous leak, which Facebook said it found and fixed more than a year and a half ago. But the dataset has now been published for free in a hacking forum, making it much more widely available. It covers 533 million people in 106 countries, according to researchers who have viewed the data. That includes 11 million Facebook users in the UK and more than 30 million Americans.
The DPC's deputy commissioner Graham Doyle said the recent data dump "appears to be" from the previous leak -- and that the data-scraping behind it had happened before the EU's GDPR privacy legislation was in effect.

"However, following this weekend's media reporting we are examining the matter to establish whether the dataset referred to is indeed the same as that reported in 2019," he added.
IT

Yahoo Answers, a Repository for Stupid Questions, Is Shutting Down (vice.com) 94

After 16 years of asinine questions and dubious answers, Yahoo Answers is shutting down next month. From a report: The company announced that starting April 20, users won't be able to post new questions or answer other people's questions; on May 4, the site will become inaccessible, and will redirect to the Yahoo homepage. Users who've posted questions and answers in the past can download their data via request before June 30, 2021, here. "While Yahoo Answered was once a key part of Yahoo's products and services, it has become less popular over the years as the needs of our members have changed," an announcement that went out to users, as spotted by the good people of the r/DataHoarder subreddit, said.

Slashdot Top Deals