The Almighty Buck

'Evil Mobile Emulator Farms' Used To Steal Millions From US and EU Banks (arstechnica.com) 59

An anonymous reader quotes a report from Ars Technica: Researchers from IBM Trusteer say they've uncovered a massive fraud operation that used a network of mobile device emulators to drain millions of dollars from online bank accounts in a matter of days. The scale of the operation was unlike anything the researchers have seen before. In one case, crooks used about 20 emulators to mimic more than 16,000 phones belonging to customers whose mobile bank accounts had been compromised. In a separate case, a single emulator was able to spoof more than 8,100 devices.

The thieves then entered usernames and passwords into banking apps running on the emulators and initiated fraudulent money orders that siphoned funds out of the compromised accounts. Emulators are used by legitimate developers and researchers to test how apps run on a variety of different mobile devices. To bypass protections banks use to block such attacks, the crooks used device identifiers corresponding to each compromised account holder and spoofed GPS locations the device was known to use. The device IDs were likely obtained from the holders' hacked devices, although in some cases, the fraudsters gave the appearance they were customers who were accessing their accounts from new phones. The attackers were also able to bypass multi-factor authentication by accessing SMS messages.

Security

Up To 3 Million Devices Infected By Malware-Laced Chrome and Edge Add-Ons (arstechnica.com) 17

As many as 3 million people have been infected by Chrome and Edge browser extensions that steal personal data and redirect users to ad or phishing sites, a security firm said on Wednesday. Ars Technica reports: In all, researchers from Prague-based Avast said they found 28 extensions for the Google Chrome and Microsoft Edge browsers that contained malware. The add-ons billed themselves as a way to download pictures, videos, or other content from sites including Facebook, Instagram, Vimeo, and Spotify. At the time this post went live, some, but not all, of the malicious extensions remained available for download from Google and Microsoft. Avast researchers found malicious code in the JavaScript-based extensions that allows them to download malware onto an infected computer.

In a post, the researchers wrote: "Users have also reported that these extensions are manipulating their internet experience and redirecting them to other websites. Anytime a user clicks on a link, the extensions send information about the click to the attacker's control server, which can optionally send a command to redirect the victim from the real link target to a new hijacked URL before later redirecting them to the actual website they wanted to visit. User's privacy is compromised by this procedure since a log of all clicks is being sent to these third party intermediary websites. The actors also exfiltrate and collect the user's birth dates, email addresses, and device information, including first sign in time, last login time, name of the device, operating system, used browser and its version, even IP addresses (which could be used to find the approximate geographical location history of the user)."

The researchers don't yet know if the extensions came with the malicious code preinstalled or if the developers waited for the extensions to gain a critical mass of users and only then pushed a malicious update. It's also possible that legitimate developers created the add-ons and then unknowingly sold them to someone who intended to use them maliciously. [...] The list Avast provides in its blog post includes links to download locations for both Chrome and Edge. Anyone who has downloaded one of these add-ons should remove it immediately and run a virus scan.

Twitter

Dutch Prosecutors Find a Hacker Did Successfully Log Into Donald Trump's Twitter Account (bbc.com) 96

Dutch prosecutors have found a hacker did successfully log in to Donald Trump's Twitter account by guessing his password -- "MAGA2020!" From a report: But they will not be punishing Victor Gevers, who was acting "ethically." Mr Gevers shared what he said were screenshots of the inside of Mr Trump's account on 22 October, during the final stages of the US presidential election. But at the time, the White House denied it had been hacked and Twitter said it had no evidence of it. Mr Gevers said he was very happy with the outcome. "This is not just about my work but all volunteers who look for vulnerabilities in the internet," he said. The well respected cyber-security researcher said he had been conducting a semi-regular sweep of the Twitter accounts of high-profile US election candidates, on 16 October, when he had guessed President Trump's password.
Security

SolarWinds Hides List of High-Profile Customers After Devastating Hack (theverge.com) 58

SolarWinds has removed a list of high-profile clients from its website in the wake of a massive breach, "suggesting the company may be trying to obscure its clients in an effort to protect them from bad publicity," reports The Verge. From the report: The list of vulnerable companies is much smaller than SolarWinds' overall client list, so simply appearing on the list doesn't mean a company has been affected. SolarWinds claims that only 33,000 companies use the Orion product, compared to its total client base of 330,000. Out of that 33,000, the company estimates that fewer than 18,000 were directly impacted by a malicious update, and the list of directly targeted companies is likely even smaller. Still, there is much about the attack that remains unknown, and it is possible that additional compromises have yet to be discovered.

SolarWinds' overall client list includes a broad range of sensitive organizations. Before its removal, the page boasted a broad range of clients, including more than 425 of the companies listed on the Fortune 500 as well as the top 10 telecom operators in the United States. In an article on Monday, The New York Times cited a number of organizations as vulnerable that are not cited on the public client page, including Boeing and Los Alamos National Laboratory. Other organizations have been cagey about their own exposure, even within the federal government. Several news outlets have reported that the breach affected the Department of Homeland Security, but the department has not made any official statement regarding its exposure.

Security

Microsoft and Industry Partners Seize Key Domain Used In SolarWinds Hack (zdnet.com) 18

An anonymous reader quotes a report from ZDNet: Microsoft and a coalition of tech companies have intervened today to seize and sinkhole a domain that played a central role in the SolarWinds hack, ZDNet has learned from sources familiar with the matter. The domain in question is avsvmcloud[.]com, which served as command and control (C&C) server for malware delivered to around 18,000 SolarWinds customers via a trojanized update for the company's Orion app. SolarWinds Orion updates versions 2019.4 through 2020.2.1, released between March 2020 and June 2020, contained a strain of malware named SUNBURST (also known as Solorigate). Once installed on a computer, the malware would sit dormant for 12 to 14 days and then ping a subdomain of avsvmcloud[.]com.

According to analysis from security firm FireEye, the C&C domain would reply with a DNS response that contained a CNAME field with information on another domain from where the SUNBURST malware would obtain further instructions and additional payloads to execute on an infected company's network. Earlier today, a coalition of tech companies seized and sinkholed avsvmcloud[.]com, transferring the domain into Microsoft's possession. Sources familiar with today's actions described the takedown as "protective work" done to prevent the threat actor behind the SolarWinds hack from delivering new orders to infected computers.

Security

Academics Turn RAM Into Wi-Fi Cards To Steal Data From Air-Gapped Systems (zdnet.com) 105

Academics from an Israeli university have published new research today detailing a technique to convert a RAM card into an impromptu wireless emitter and transmit sensitive data from inside a non-networked air-gapped computer that has no Wi-Fi card. From a report: Named AIR-FI, the technique is the work of Mordechai Guri, the head of R&D at the Ben-Gurion University of the Negev, in Israel. Over the last half-decade, Guri has led tens of research projects that investigated stealing data through unconventional methods from air-gapped systems. [...] At the core of the AIR-FI technique is the fact that any electronic component generates electromagnetic waves as electric current passes through. Since Wi-Fi signals are radio waves and radio is basically electromagnetic waves, Guri argues that malicious code planted on an air-gapped system by attackers could manipulate the electrical current inside the RAM card in order to generate electromagnetic waves with the frequency consistent with the normal Wi-Fi signal spectrum (2,400 GHz). In his research paper, titled "AIR-FI: Generating Covert WiFi Signals from Air-Gapped Computers," Guri shows that perfectly timed read-write operations to a computer's RAM card can make the card's memory bus emit electromagnetic waves consistent with a weak Wi-Fi signal. This signal can then be picked up by anything with a Wi-Fi antenna in the proximity of an air-gapped system, such as smartphones, laptops, IoT devices, smartwatches, and more. Guri says he tested the technique with different air-gapped computer rigs where the Wi-Fi card was removed and was able to leak data at speeds of up to 100 b/s to devices up to several meters away.
Cloud

AWS Introduces New Chaos Engineering as a Service Offering (techcrunch.com) 20

When large companies like Netflix or Amazon want to test the resilience of their systems, they use chaos engineering tools designed to help them simulate worst-case scenarios and find potential issues before they even happen. Today at AWS re:Invent, Amazon CTO Werner Vogels introduced the company's Chaos Engineering as a Service offering called AWS Fault Injection Simulator. From a report: The name may lack a certain marketing panache, but Vogels said that the service is designed to help bring this capability to all companies. "We believe that chaos engineering is for everyone, not just shops running at Amazon or Netflix scale. And that's why today I'm excited to pre-announce a new service built to simplify the process of running chaos experiments in the cloud," Vogels said. As he explained, the goal of chaos engineering is to understand how your application responds to issues by injecting failures into your application, usually running these experiments against production systems. AWS Fault Injection Simulator offers a fully managed service to run these experiments on applications running on AWS hardware.
Security

Hackers at Center of Sprawling Spy Campaign Turned SolarWinds' Dominance Against It (reuters.com) 49

An anonymous reader shares a report: On an earnings call two months ago, SolarWinds Chief Executive Kevin Thompson touted how far the company had gone during his 11 years at the helm. There was not a database or an IT deployment model out there to which his Austin, Texas-based company did not provide some level of monitoring or management, he told analysts on the Oct. 27 call. "We don't think anyone else in the market is really even close in terms of the breadth of coverage we have," he said. "We manage everyone's network gear." Now that dominance has become a liability -- an example of how the workhorse software that helps glue organizations together can turn toxic when it is subverted by sophisticated hackers. On Monday, SolarWinds confirmed that Orion -- its flagship network management software -- had served as the unwitting conduit for a sprawling international cyberespionage operation. The hackers inserted malicious code into Orion software updates pushed out to nearly 18,000 customers.

[...] Cybersecurity experts across government and private industry are still struggling to understand the scope of the damage, which some are already calling one of the most consequential breaches in recent memory. [...] Experts are reviewing their notes to find old examples of substandard security at the company. Security researcher Vinoth Kumar told Reuters that, last year, he alerted the company that anyone could access SolarWinds' update server by using the password "solarwinds123" "This could have been done by any attacker, easily," Kumar said. Others -- including Kyle Hanslovan, the cofounder of Maryland-based cybersecurity company Huntress -- noticed that, even days after SolarWinds realized their software had been compromised, the malicious updates were still available for download.

Security

SolarWinds Says 18,000 Customers Were Impacted by Recent Hack (zdnet.com) 23

IT software provider SolarWinds downplayed a recent security breach in documents filed with the US Securities and Exchange Commission on Monday. From a report: SolarWinds disclosed on Sunday that a nation-state hacker group breached its network and inserted malware in updates for Orion, a software application for IT inventory management and monitoring. Orion app versions 2019.4 through 2020.2.1, released between March 2020 and June 2020, were tainted with malware, SolarWinds said in a security advisory. The trojanized Orion update allowed attackers to deploy additional and highly stealthy malware on the networks of SolarWinds customers.

But while initial news reports on Sunday suggested that all of SolarWinds' customers were impacted, in SEC documents filed today, SolarWinds said that of its 300,000 total customers, only 33,000 were using Orion, a software platform for IT inventory management and monitoring, and that fewer than 18,000 are believed to have installed the malware-laced update. The company said it notified all its 33,000 Orion customers on Sunday, even if they didn't install the trojanized Orion update, with information about the hack and mitigation steps they could take.

Google

'Google is Getting Left Behind Due To Horrible UI/UX' (danielmiessler.com) 269

Daniel Miessler, a widely respected infosec professional in San Francisco, writes about design and user experience choices Google has made across its services in recent years: I've been writing for probably a decade about how bad Google's GUI is for Google Analytics, Google Apps, and countless of their other properties -- not to mention their multiple social media network attempts, like Google+ and Wave. Back then it was super annoying, but kind of ok. They're a hardcore engineering group, and their backend services are without equal. But lately it's just becoming too much.

1. Even Gmail is a cesspool at this point. Nobody would ever design a webmail interface like that, starting from scratch.
2. What happened to Google Docs? Why does it not look and behave more like Notion, or Quip, or any of the other alternatives that made progress in the last 5-10 years?
3. What college course do I take to manage a Google Analytics property?
4. Google just rolled out Google Analytics 4 -- I think -- and the internet is full of people asking the same question I am. "Is this a real rollout?"

[...] My questions are simple:
1. How the hell is this possible? I get it 10 years ago. But then they came out with the new design language. Materialize, or whatever it was. Cool story, and cool visuals. But it's not about the graphics, it's about the experience.
2. How can you be sitting on billions of dollars and be unable to hire product managers that can create usable interfaces?
3. How can you run Gmail on an interface that's tangibly worse than anything else out there?
4. How can you let Google Docs get completely obsoleted by startups?

I've heard people say that Google has become the new Microsoft, or the new Oracle, but damn -- at least Microsoft is innovating. At least Oracle has a sailing team, or whatever else they do. I'm being emotional at this point.

Google, you are made out of money. Fix your fucking interfaces. Focus on the experience. Focus on simplicity. And use navigation language that's similar across your various properties, so that I'll know what to do whether I'm managing my Apps account, or my domains, or my Analytics. You guys are awesome at so many things. Make the commitment to fix how we interact with them.

Encryption

Israeli Spy Tech Firm Says It Can Break Into Signal App (haaretz.com) 87

Last Thursday, Israeli phone-hacking firm Cellebrite said in a blog post that it can now break into Signal, an encrypted app considered safe from external snooping. Haaretz reports: Cellebrite's flagship product is the UFED (Universal Forensic Extraction Device), a system that allows authorities to unlock and access the data of any phone in their possession. Another product it offers is the Physical Analyzer, which helps organize and process data lifted from the phone. Last Thursday, the company announced that the analyzer has now been updated with a new capability, developed by the firm, that allows clients to decode information and data from Signal. Signal, owned by the Signal Technology Foundation, uses a special open source encryption system called Signal Protocol, which was thought to make it nigh-on impossible for a third party to break into a conversation or access data being shared on the platform. It does so by employing what's called "end-to-end encryption."

According to Cellebrite's announcement last week, "Law enforcement agencies are seeing a rapid rise in the adoption of highly encrypted apps like Signal, which incorporate capabilities like image blurring to stop police from reviewing data. "Criminals are using this application to communicate, send attachments, and making [sic] illegal deals that they want to keep discrete [sic] and out of sight from law enforcement," the blog post added. Despite support for the app's encryption capabilities, Cellebrite noted that "Signal is an encrypted communication application designed to keep sent messages and attachments as safe as possible from 3rd-party programs.

"Cellebrite Physical Analyzer now allows lawful access to Signal app data. At Cellebrite, we work tirelessly to empower investigators in the public and private sector to find new ways to accelerate justice, protect communities, and save lives." In an earlier, now deleted, version of the blog post, the company went as far as to say: "Decrypting Signal messages and attachments was not an easy task. It required extensive research on many different fronts to create new capabilities from scratch. At Cellebrite, however, finding new ways to help those who make our world a safer place is what we're dedicated to doing every day." The initial post, which was stored on the Internet Archive, also included a detailed explanation of how Cellebrite "cracked the code" by reviewing Signal's own open source protocol and using it against it. The company noted in the deleted blog post that "because [Signal] encrypts virtually all its metadata to protect its users, efforts have been put forward by legal authorities to require developers of encrypted software to enable a 'backdoor' that makes it possible for them to access people's data. Until such agreements are reached, Cellebrite continues to work diligently with law enforcement to enable agencies to decrypt and decode data from the Signal app."

Businesses

Vista Acquires IT Education Platform Pluralsight for $3.5B (techcrunch.com) 9

The hectic M&A cycle we have seen throughout 2020 continued this weekend when Vista Equity Partners announced it was acquiring Pluralsight for $3.5 billion. From a report: That comes out to $20.26 per share. The company stock closed on Friday at $18.50 per share on a market cap of over $2.7 billion. With Pluralsight, Vista gets an online training company that helps educate IT professionals, including developers, operations, data and security, with a suite of online courses. As the pandemic has taken hold, it has breathed new life into edtech, but even before that, there was a market for upskilling IT Pros online. This trend certainly didn't escape Monti Saroya, co-head of the Vista Flagship Fund and senior managing director at Vista. "We have seen firsthand that the demand for skilled software engineers continues to outstrip supply, and we expect this trend to persist as we move into a hybrid online-offline world across all industries and interactions, with business leaders recognizing that technological innovation is critical to business success," he said in a statement.
United States

Suspected Russian Hackers Breached Department of Homeland Security (reuters.com) 55

Reuters: A team of sophisticated hackers believed to be working for the Russian government won access to internal communications at the U.S. Department of Homeland Security, according to people familiar with the matter. The breach was part of the campaign reported Sunday that penetrated the U.S. departments of Treasury and Commerce.
Bug

'Cyberpunk 2077' Players Are Fixing Parts of the Game Before CD Projekt (vice.com) 79

Cyberpunk 2077 is here in all its glory and pain. On some machines, it's a visual spectacle pushing the limits of current technology and delivering on the promise of Deus Ex, but open world. On other machines, including last-gen consoles, it's a unoptimized and barely playable nightmare. Developer CD Projekt Red has said it's working to improve the game, but fans already have a number of fixes, particularly if you're using an AMD CPU. From a report: Fans aren't waiting for the developer however and over the weekend AMD CPU users discovered that a few small tweaks could improve performance on their PCs. Some players reported performance gains of as much as 60 percent. Cyberpunk 2077 seems to be a CPU intensive game and, at release, it isn't properly optimized for AMD chips. "If you run the game on an AMD CPU and check your usage in task manager, it seems to utilise 4 (logical, 2 physical) cores in frequent bursts up to 100% usage, whereas the rest of the physical cores sit around 40-60%, and their logical counterparts remain idle," Redditor BramblexD explained in a post on the /r/AMD subreddit. Basically, Cyberpunk 2077 is only utilizing a portion of any AMD chips power.

Digital Foundry, a YouTube channel that does in-depth technical analysis of video games, noticed the AMD issue as well. "It really looks like Cyberpunk is not properly using the hyperthreads on Ryzen CPUs," Digital Foundry said in a recent video. To fix this issue, the community has developed three separate solutions. One involves altering the game's executable with a hex editor, the other involves editing a config file, and a third is an unofficial patch built by the community. All three do the same thing -- unleash the power of AMDs processors. "Holy shit are you a wizard or something? The game is finally playable now!" One redditor said of the hex editing technique. "With this tweak my CPU usage went from 50% to ~75% and my frametime is so much more stable now."

Google

Google Services Including Gmail, YouTube Suffer Major Outage (bloomberg.com) 104

Services from Alphabet's Google experienced widespread outages around the world, preventing people from accessing Gmail, YouTube and other services. From a report: Errors ranged from "something went wrong" on YouTube, to "there was an error. Please try again later," when attempting to log into the company's mail product from about 6:30 a.m. in New York. Google tools were failing to load for users in the U.S., the U.K. and across Europe, but began functioning again for many people after about an hour. Google confirmed there was an outage for the majority of its services according to a Workspace Status Dashboard, which monitors the health of its products, but just before 8:00 a.m. it said functionality was restored to the "vast majority" of users. "We will continue to work toward restoring service for the remaining affected users," it wrote in a post on its service status page. It hasn't said what caused the problems.
Government

Russia Breached Update Server Used by 300,000 Organizations, Including the NSA (seattletimes.com) 115

Sunday Reuters reported that "a sophisticated hacking group" backed by "a foreign government" has stolen information from America's Treasury Department, and also from "a U.S. agency responsible for deciding policy around the internet and telecommunications."

The Washington Post has since attributed the breach to "Russian government hackers," and discovered it's "part of a global espionage campaign that stretches back months, according to people familiar with the matter." Officials were scrambling over the weekend to assess the extent of the intrusions and implement effective countermeasures, but initial signs suggested the breach was long-running and significant, the people familiar with the matter said. The Russian hackers, known by the nicknames APT29 or Cozy Bear, are part of that nation's foreign intelligence service and breached email systems in some cases, said the people familiar with the intrusions, who spoke on the condition of anonymity because of the sensitivity of the matter. The same Russian group hacked the State Department and the White House email servers during the Obama administration... [The Washington Post has also reported this is the group responsible for the FireEye breach. -Ed]

All of the organizations were breached through the update server of a network management system called SolarWinds, according to four people familiar with the matter. The company said Sunday in a statement that monitoring products it released in March and June of this year may have been surreptitiously weaponized with in a "highly-sophisticated, targeted...attack by a nation state." The scale of the Russian espionage operation is potentially vast and appears to be large, said several individuals familiar with the matter. "This is looking very, very bad," said one person. SolarWinds products are used by more than 300,000 organizations across the world. They include all five branches of the U.S. military, the Pentagon, State Department, Justice Department, NASA, the Executive Office of the President and the National Security Agency, the world's top electronic spy agency, according to the firm's website. SolarWinds is also used by the top 10 U.S. telecommunications companies...

APT29 compromised the SolarWinds server that sends updates so that any time a customer checks in to request an update, the Russians could hitch a ride on that update to get into a victim's system, according to a person familiar with the matter. "Monday may be a bad day for lots of security teams," tweeted Dmitri Alperovitch, a cybersecurity expert and founder of the Silverado Policy Accelerator think tank.

Reuters described the breach as "so serious it led to a National Security Council meeting at the White House."
Games

Do Games Made Under Crunch Conditions Deserve 'Best Direction' Awards? (kotaku.com) 146

The annual Game Awards ceremony awarded this year's "Best Direction" award to Naughty Dog studio's The Last of Us Part II — provoking a strong reaction from Kotaku's staff writer.

"I think it's pretty obvious that no game that required its developers to crunch, like The Last of Us Part II did, should be given a Best Direction award." It's no secret that Naughty Dog subjected its workers to unbelievable levels of crunch to get The Last of Us Part II out the door, but that's hardly an innovation when it comes to Naughty Dog or game development in general. Over the years, the studio has seen constant employee turnover as developers crunch on games like The Last of Us and Uncharted, burn out, and throw in the towel. Relentless overtime, missed weekends, long stretches of time without seeing your family — these things take a toll on even the most passionate artist.

"This can't be something that's continuing over and over for each game, because it is unsustainable," one The Last of Us Part II developer told Kotaku earlier this year. "At a certain point you realize, 'I can't keep doing this. I'm getting older. I can't stay and work all night.'"

Let's be clear: the existence of crunch indicates a failure in leadership. It's up to game directors and producers to ensure workloads are being managed properly and goals are being met. If workers are being forced to crunch, explicitly or otherwise, it means the managers themselves have fallen short somewhere, either in straining the limits of their existing staff, fostering an environment where overtime is an implied (if unspoken) requirement, or both. And as ambitious as The Last of Us Part II director Neil Druckmann and his projects may be, "questionable experiments in the realm of pushing human limits" are not required to make a great game...

I feel like the industry, now more than ever, is willing to discuss the dangers of crunch culture and solutions to eradicate it. But lavishing praise on the way The Last of Us Part II was directed feels like a tacit endorsement of crunch and only serves to push that conversation to the backburner again. A popular online statement, first coined by Fanbyte podcast producer Jordan Mallory, says, "I want shorter games with worse graphics made by people who are paid more to work less and I'm not kidding." The message from all those who share it is clear: No game, not even industry darling The Last of Us Part II, is worth destroying lives to create.

United States

US Treasury Department Breached by 'Hackers Backed By Foreign Government' (usnews.com) 64

Reuters reports that "a sophisticated hacking group" backed by "a foreign government" has stolen information from America's Treasury Department, and also from "a U.S. agency responsible for deciding policy around the internet and telecommunications." There is concern within the U.S. intelligence community that the hackers who targeted the Treasury Department and the Commerce Department's National Telecommunications and Information Administration used a similar tool to break into other government agencies, according to three people briefed on the matter.

The hack is so serious it led to a National Security Council meeting at the White House on Saturday, said one of the people familiar with the matter.

Businesses

'Will Remote Work Kill Innovation?' Ask Silicon Valley Experts (mercurynews.com) 110

Remote work "is here to stay," argues a new article in Silicon Valley's newspaper The Mercury News (also re-published in the East Bay Times). But they've also asked industry professionals around Silicon Valley whether this will hurt our ability to innovate.

Software engineer/entrepreneur Joyce Park (who's worked in Silicon Valley over 20 years): "Fast feedback is what we're all about in this town. That's what's gone away... If you have a dumb idea or people hate your idea then you don't have to spend more time fleshing it out, and that means you don't have to spend more time defending it. When you're trying to do really innovative work, it takes so many meetings. Zoom meetings are different than normal meetings because they're much more performative. Most engineers aren't really in the putting-on-a-show business... Pretty is the death of innovation."

Park also worries about young tech workers, who represent the future of innovation and aren't in offices absorbing knowledge. "Who's going to mentor them, who's going to make them successful? A lot of the craft is just seeing problems and seeing how they were successfully or unsuccessfully solved."

Tarun Wadhwa, who's taught new innovation methods at Carnegie Mellon University's Silicon Valley outpost, most recently this spring: "The sparks wouldn't fly," Wadhwa said. "The students were just as brilliant as they've always been but the class wasn't as able to help them advance that brilliance as it once was." What was missing, Wadhwa suspects, was the free-flowing, back-and-forth-and-sideways exchange of ideas that happens in person, especially during extra-curricular gatherings such as when students from different teams and different backgrounds go out for coffee together after class...
Another perspective from a long-time Silicon Valley veteran: Mike Strasser, whose mechanical engineering career and current employment as general manager of Campbell med-tech startup Imperative Care straddle the hardware and software worlds, believes a reduced ability to develop a rapport with colleagues when working apart poses problems across both sectors. However, the problem is worse in hardware, where teams can't pass a prototype around a table, and easier in software, especially with collaboration apps supplementing video meetings.

The move to remote work has forced technologists to find new solutions, Strasser noted, such as relatively inexpensive 3D printers that can make prototypes at home.

Bay Area venture capitalist Peter Rojas, a partner at Betaworks Ventures: "We have this historic opportunity to reorganize working life and to rethink where people live and where they work...." Successful companies will be those that can nurture talent and build a strong culture while taking advantage of the opportunities remote work presents, he said. "This idea that you can only get a sense of a person in person, I think we're really getting away from that now," Rojas said.

He said his firm has money in more than 100 companies — including one that makes video-conferencing collaboration software — and none appear hurt by the shift to remote. "Everybody adjusted," he said, "and figured out how to get their stuff done."

Open Source

Open Source Developers Say Securing Their Code Is 'Insufferably Boring' and 'Soul-Withering' (techrepublic.com) 150

"A new survey of the free and open-source software (FOSS) community conducted by the Linux Foundation suggests that contributors spend less than 3% of their time on security issues and have little desire to increase this," reports TechRepublic: Moreover, responses indicated that many respondents had little interest in increasing time and effort on security. One respondent commented that they "find the enterprise of security a soul-withering chore and a subject best left for the lawyers and process freaks," while another said: "I find security an insufferably boring procedural hindrance."

The researchers concluded that a new approach to the security and auditing of FOSS would be needed to improve security practices, while limiting the burden on contributors. Some of the most requested tools from contributors were bug and security fixes, free security audits, and simplified ways to add security-related tools to their continuous integration (CI) pipelines.

"There is a clear need to dedicate more effort to the security of FOSS, but the burden should not fall solely on contributors," read the report. "Developers generally do not want to become security auditors; they want to receive the results of audits..."

The researchers continued: "One way to improve a rewrite's security is to switch from memory-unsafe languages (such as C or C++ ) into memory-safe languages (such as nearly all other languages)," researchers said. "This would eliminate entire classes of vulnerabilities such as buffer overflows and double-frees."

Also interesting: money "scored very low in developers' motivations for contributing to open-source projects, as did a desire for recognition amongst peers," according to TechRepublic.

"Instead, developers said they were purely interested in finding features, fixes and solutions to the open-source projects they were working on. Other top motivations included were enjoyment and a desire to contribute back to the FOSS projects that they used."

Slashdot Top Deals