Twitter

Twitter Names Famed Hacker 'Mudge' as Head of Security (reuters.com) 14

Social media giant Twitter, under increased threat of regulation and plagued by serious security breaches, is appointing one of the world's best-regarded hackers to tackle everything from engineering missteps to misinformation. From a report: The company on Monday named Peiter Zatko, widely known by his hacker handle Mudge, to the new position of head of security, giving him a broad mandate to recommend changes in structure and practices. Zatko answers to CEO Jack Dorsey and is expected to take over management of key security functions after a 45- to 60-day review. In an exclusive interview, Zatko said he will examine "information security, site integrity, physical security, platform integrity -- which starts to touch on abuse and manipulation of the platform -- and engineering." Zatko most recently oversaw security at the electronic payments unicorn Stripe. Before that, he worked on special projects at Google and oversaw handing out grants for projects on cybersecurity at the Pentagon's famed Defense Advanced Research and Projects Agency (DARPA).
Google

Ok Google: Please Publish Your DKIM Secret Keys 108

Matthew Green, a cryptographer and professor at Johns Hopkins University, writes: The Internet is a dangerous place in the best of times. Sometimes Internet engineers find ways to mitigate the worst of these threats, and sometimes they fail. Every now and then, however, a major Internet company finds a solution that actually makes the situation worse for just about everyone. Today I want to talk about one of those cases, and how a big company like Google might be able to lead the way in fixing it. This post is about the situation with Domain Keys Identified Mail (DKIM), a harmless little spam protocol that has somehow become a monster. My request is simple and can be summarized as follows: Dear Google: would you mind rotating and publishing your DKIM secret keys on a periodic basis? This would make the entire Internet quite a bit more secure, by removing a strong incentive for criminals to steal and leak emails. The fix would cost you basically nothing, and would remove a powerful tool from hands of thieves.
IT

GitHub Reinstates YouTube-dl Library After EFF Intervention (zdnet.com) 47

GitHub has reinstated today the youtube-dl open-source project, a Python library that lets users download the source audio and video files behind YouTube videos. From a report: GitHub, a code-hosting repository, had previously removed the library from its portal after it received a controversial DMCA takedown request from the Recording Industry Association of America (RIAA) on October 23. In a DMCA takedown letter, RIAA argued that the library was being used to "circumvent the technological protection measures used by authorized streaming services such as YouTube" and to allow users to "reproduce and distribute music videos and sound recordings [...] without authorization." RIAA also noted that the project's source code "expressly suggests its use to copy and/or distribute the following copyrighted works." More specifically, RIAA used Section 1201 of the Digital Millennium Copyright Act (DMCA) to claim that the youtube-dl library was breaking copyright by providing a tool to circumvent copyrighted material -- even if the youtube-dl library didn't contain copyright-infringing code itself.

But in a blog post today, GitHub said the library did not actually break Section 1201 of the DMCA, citing a letter it received from Electronic Frontier Foundation lawyers, who to take up the youtube-dl project's case. In the letter, the EFF team explained that Google does not have any technical measures in place to prevent the download of its videos -- all of which need to be made freely available to all kinds of apps, browsers, smart TVs, and more. Hence, EFF lawyers argued that the library could never be taken down under Section 1201 of the DMCA since the library doesn't actually circumvent any sort of copyright protection system in the first place.

Privacy

Apple Responds To Gatekeeper Issue With Upcoming Fixes (techcrunch.com) 54

Apple has updated a documentation page detailing the company's next steps to prevent last week's Gatekeeper bug from happening again. The company plans to implement the fixes over the next year. From a report: Apple had a difficult launch day last week. The company released macOS Big Sur, a major update for macOS. Apple then suffered from server-side issues. Third-party apps failed to launch as your Mac couldn't check the developer certificate of the app. That feature, called Gatekeeper, makes sure that you didn't download a malware app that disguises itself as a legit app. If the certificate doesn't match, macOS prevents the app launch. Many have been concerned about the privacy implications of the security feature. Does Apple log every app you launch on your Mac to gain competitive insights on app usage? It turns out it's easy to answer that question as the server doesn't mandate encryption. Jacopo Jannone intercepted an unencrypted network request and found out that Apple is not secretly spying on you. Gatekeeper really does what it says it does. "We have never combined data from these checks with information about Apple users or their devices. We do not use data from these checks to learn what individual users are launching or running on their devices," the company wrote.
United States

Data Breach Exposes 27 Million Texas Driver's License Records (thehill.com) 34

"A software company that provides services for insurance groups disclosed this week that about 27.7 million Texas driver's license records were exposed in a data breach earlier this year," reports The Hill: The company, Vertafore, said in a statement posted on a website set up to address the breach that the data was exposed between March and August and affected licenses issued before February 2019. Exposed data included driver's license numbers, addresses, dates of birth and vehicle registration history, according to the company. The group said that no Social Security numbers or financial account information were compromised.

The breach happened after three files were accessed by an unauthorized user after the files were "inadvertently stored in an unsecured external storage service," Vertafore said in its statement....

Vertafore said that it is providing a year of free credit monitoring and identity restoration services to all Texas residents whose driver's license data was exposed... Vertafore emphasized in disclosing the breach that it was taking steps to enhance employee cybersecurity and privacy training, reinforcing security procedures and policies, and further enhancing the security of its systems.

Cloud

Credit Card Numbers For Millions of Hotel Guests Exposed By Misconfigured Cloud Database (threatpost.com) 46

"A widely used hotel reservation platform has exposed 10 million files related to guests at various hotels around the world, thanks to a misconfigured Amazon Web Services S3 bucket," reports Threatpost.

"The records include sensitive data, including credit-card details." Prestige Software's "Cloud Hospitality" is used by hotels to integrate their reservation systems with online booking websites like Expedia and Booking.com. The incident has affected 24.4 GB worth of data in total, according to the security team at Website Planet, which uncovered the bucket.

Many of the records contain data for multiple hotel guests that were grouped together on a single reservation; thus, the number of people exposed is likely well over the 10 million, researchers said. Some of the records go back to 2013, the team determined — but the bucket was still "live" and in use when it was discovered this month. "The company was storing years of credit-card data from hotel guests and travel agents without any protection in place, putting millions of people at risk of fraud and online attacks," according to the firm, in a recent notice on the issue. "The S3 bucket contained over 180,000 records from August 2020 alone...."

The records contain a raft of information, Website Planet said, including full names, email addresses, national ID numbers and phone numbers of hotel guests; card numbers, cardholder names, CVVs and expiration dates; and reservation details, such as the total cost of hotel reservations, reservation number, dates of a stay, special requests made by guests, number of people, guest names and more. The exposure affects a wide number of platforms, with data related to reservations made through Amadeus, Booking.com, Expedia, Hotels.com, Hotelbeds, Omnibees, Sabre and more....

A too-large percentage of cloud databases containing highly sensitive information are publicly available, an analysis in September found. The study from Comparitch showed that 6 percent of all Google Cloud buckets are misconfigured and left open to the public internet, for anyone to access their contents.

Security

Is There a Better Way to Create Secure Passwords? (cnet.com) 143

"Forget all the rules about uppercase and lowercase letters, numbers and symbols; your password just needs to be at least 12 characters, and it needs to pass a real-time strength test" developed by the passwords research group in Carnegie Mellon's CyLab Security and Privacy Institute (according to the Lab's web site).

CNET reports: After a user has created a password of at least 10 characters, the meter will start giving suggestions, such as breaking up common words with slashes or random letters, to make your password stronger...

One of the problems with many passwords is that they tick all the security checks but are still easy to guess because most of us follow the same patterns, the lab found. Numbers? You'll likely add a "1" at the end. Capital letters? You'll probably make it the first one in the password. And special characters? Frequently exclamation marks...

In an experiment, users created passwords on a system that simply required them to enter 10 characters. Then the system rated the passwords with the lab's password strength meter and gave tailored suggestions for stronger passwords. Test subjects were able to come up with secure passwords that they could recall up to five days later. It worked better than showing users preset lists of rules or simply banning known bad passwords (I'm looking at you "StarWars")...

Lorrie Cranor, director of the CyLab Usable Security and Privacy Laboratory at CMU, says the best way to create and remember secure passwords is to use a password manager. Those aren't widely adopted, and they come with some trade-offs. Nonetheless, they allow you to create a random, unique password for each account, and they remember your passwords for you.

GNOME

Ubuntu Patches Bug That Tricked Gnome Desktop Into Giving Root Access (arstechnica.com) 25

"Ubuntu developers have fixed a series of vulnerabilities that made it easy for standard users to gain coveted root privileges," reports Ars Technica: "This blog post is about an astonishingly straightforward way to escalate privileges on Ubuntu," Kevin Backhouse, a researcher at GitHub, wrote in a post published on Tuesday. "With a few simple commands in the terminal, and a few mouse clicks, a standard user can create an administrator account for themselves."

The first series of commands triggered a denial-of-service bug in a daemon called accountsservice, which as its name suggests is used to manage user accounts on the computer... With the help of a few extra commands, Backhouse was able to set a timer that gave him just enough time to log out of the account before accountsservice crashed. When done correctly, Ubuntu would restart and open a window that allowed the user to create a new account that — you guessed it — had root privileges...

The second bug involved in the hack resided in the GNOME display manager, which among other things manages user sessions and the login screen. The display manager, which is often abbreviated as gdm3, also triggers the initial setup of the OS when it detects no users currently exist. "How does gdm3 check how many users there are on the system?" Backhouse asked rhetorically. "You probably already guessed it: by asking accounts-daemon! So what happens if accounts-daemon is unresponsive....?"

The vulnerabilities could be triggered only when someone had physical access to, and a valid account on, a vulnerable machine. It worked only on desktop versions of Ubuntu.

"This bug is now tracked as CVE-2020-16125 and rated with a high severity score of 7.2 out of 10. It affects Ubuntu 20.10, Ubuntu 20.04, and Ubuntu 18.04..." reports Bleeping Computer.

They add that the GitHub security research who discovered the bugs "reported them to Ubuntu and GNOME maintainers on October 17, and fixes are available in the latest code."
Security

Election Was Most Secure In American History, US Officials Say (bloomberg.com) 423

"The Nov. 3rd election was the most secure in American history," state and federal election officials said in a statement Thursday. "There is no evidence that any voting system deleted or lost votes, changed votes, or was in any way compromised." Bloomberg reports: The statement acknowledged the "many unfounded claims and opportunities for misinformation about the process of our elections" and urged Americans to turn to election administrators and officials for accurate information. The statement was signed by officials from the Elections Infrastructure Government Coordinating Council, which shares information among state, local and federal officials, and the Election Infrastructure Sector Coordinating Council, which includes election infrastructure owners and operators.

Among the 10 signatories were Benjamin Hovland, who chairs the U.S. Election Assistance Commission, and Bob Kolasky, the assistant director of the Cybersecurity and Infrastructure Security Agency, part of the Department of Homeland Security. Key officials at the cybersecurity agency, including its head, Christopher Krebs, are stepping down or expecting to get fired as Trump refuses to concede. Krebs, who has enjoyed bipartisan support for his role in helping run secure U.S. elections in 2018 and 2020, has told associates he expects to be dismissed, according to three people familiar with internal discussions. His departure would follow the resignation of Bryan Ware, assistant director for cybersecurity at CISA, who resigned on Thursday morning after about two years at the agency. In addition, Valerie Boyd, the assistant secretary for international affairs at the Department of Homeland Security, which oversees CISA, has also left, according to two other people. Krebs and Ware are both Trump appointees.

Microsoft

Microsoft: Russian, North Korean Cyberattacks Target COVID-19 Vaccine Efforts (axios.com) 28

Microsoft said Friday it has detected at least seven attacks on companies working to develop a COVID-19 vaccine or treatments. From a report: The company said attacks by three nation-state actors -- two from North Korea and one from Russia -- have targeted companies in Canada, France, India, South Korea and the United States. "Two global issues will help shape people's memories of this time in history -- COVID-19 and the increased use of the internet by malign actors to disrupt society," Microsoft deputy general counsel Tom Burt said in a blog post. "It's disturbing that these challenges have now merged as cyberattacks are being used to disrupt health care organizations fighting the pandemic." Attackers have used a range of approaches including phishing schemes and brute force to get needed passwords, with one group tied to North Korea posing as the World Health Organization in its spear-phishing effort. Microsoft said its built-in security protections stopped a majority of the attacks. "We've notified all organizations targeted, and where attacks have been successful, we've offered help," Burt said.
Security

Security Holes Opened Back Door To TCL Android Smart TVs (securityledger.com) 55

chicksdaddy shares a report from The Security Ledger: Millions of Android smart television sets from the Chinese vendor TCL Technology Group Corporation contained gaping software security holes that researchers say could have allowed remote attackers to take control of the devices, steal data or even control cameras and microphones to surveil the set's owners. The security holes appear to have been patched by the manufacturer in early November. However the manner in which the holes were closed is raising further alarm among the researchers about whether the China-based firm is able to access and control deployed television sets without the owner's knowledge or permission, according to a report published on Monday by two security researchers.

The report describes two serious software security holes affecting TCL brand television sets. First, a vulnerability in the software that runs TCL Android Smart TVs allowed an attacker on the adjacent network to browse and download sensitive files over an insecure web server running on port 7989. That flaw, CVE-2020-27403, would allow an unprivileged remote attacker on the adjacent network to download most system files from the TV set up to and including images, personal data and security tokens for connected applications. The flaw could lead to serious critical information disclosure, the researchers warned. Second, the researchers found a vulnerability in the TCL software that allowed a local unprivileged attacker to read from and write to critical vendor resource directories within the TV's Android file system, including the vendor upgrades folder. That flaw was assigned the identifier CVE-2020-28055.

The researchers, John Jackson, an application security engineer for Shutter Stock, and the independent researcher known by the handle "Sick Codes," said the flaws amount to a "back door" on any TCL Android smart television. "Anybody on an adjacent network can browse the TV's file system and download any file they want," said Sick Codes in an interview via the Signal platform. That would include everything from image files to small databases associated with installed applications, location data or security tokens for smart TV apps like Gmail. If the TCL TV set was exposed to the public Internet, anyone on the Internet could connect to it remotely, he said, noting that he had located a handful of such TCL Android smart TVs using the Shodan search engine.

Privacy

Six Reasons Why Google Maps Is the Creepiest App On Your Phone (vice.com) 121

VICE has highlighted six reasons why Google Maps is the creepiest app on your phone. An anonymous reader shares an excerpt from the report: 1. Google Maps Wants Your Search History: Google's "Web & App Activity" settings describe how the company collects data, such as user location, to create a faster and "more personalized" experience. In plain English, this means that every single place you've looked up in the app -- whether it's a strip club, a kebab shop or your moped-riding drug dealer's location -- is saved and integrated into Google's search engine algorithm for a period of 18 months. Google knows you probably find this creepy. That's why the company uses so-called "dark patterns" -- user interfaces crafted to coax us into choosing options we might not otherwise, for example by highlighting an option with certain fonts or brighter colors.

2. Google Maps Limits Its Features If You Don't Share Your Search History: If you open your Google Maps app, you'll see a circle in the top right corner that signifies you're logged in with your Google account. That's not necessary, and you can simply log out. Of course, the log out button is slightly hidden, but can be found like this: click on the circle > Settings > scroll down > Log out of Google Maps. Unfortunately, Google Maps won't let you save frequently visited places if you're not logged into your Google account. If you choose not to log in, when you click on the search bar you get a "Tired of typing?" button, suggesting you sign in, and coaxing you towards more data collection.

3. Google Maps Can Snitch On You: Another problematic feature is the "Google Maps Timeline," which "shows an estimate of places you may have been and routes you may have taken based on your Location History." With this feature, you can look at your personal travel routes on Google Maps, including the means of transport you probably used, such as a car or a bike. The obvious downside is that your every move is known to Google, and to anyone with access to your account. And that's not just hackers -- Google may also share data with government agencies such as the police. [...] If your "Location History" is on, your phone "saves where you go with your devices, even when you aren't using a specific Google service," as is explained in more detail on this page. This feature is useful if you lose your phone, but also turns it into a bonafide tracking device.

4. Google Maps Wants to Know Your Habits: Google Maps often asks users to share a quick public rating. "How was Berlin Burger? Help others know what to expect," suggests the app after you've picked up your dinner. This feels like a casual, lighthearted question and relies on the positive feeling we get when we help others. But all this info is collected in your Google profile, making it easier for someone to figure out if you're visiting a place briefly and occasionally (like on holiday) or if you live nearby.

5. Google Maps Doesn't Like It When You're Offline: Remember GPS navigation? It might have been clunky and slow, but it's a good reminder that you don't need to be connected to the internet to be directed. In fact, other apps offer offline navigation. On Google, you can download maps, but offline navigation is only available for cars. It seems fairly unlikely the tech giant can't figure out how to direct pedestrians and cyclists without internet.

6. Google Makes It Seem Like This Is All for Your Own Good: "Providing useful, meaningful experiences is at the core of what Google does," the company says on its website, adding that knowing your location is important for this reason. They say they use this data for all kinds of useful things, like "security" and "language settings" -- and, of course, selling ads. Google also sells advertisers the possibility to evaluate how well their campaigns reached their target (that's you!) and how often people visited their physical shops "in an anonymized and aggregated manner". But only if you opt in (or you forget to opt out).

Security

DNS Cache Poisoning, the Internet Attack From 2008, Is Back From the Dead (arstechnica.com) 22

An anonymous reader quotes a report from Ars Technica : In 2008, researcher Dan Kaminsky revealed one of the more severe Internet security threats ever: a weakness in the domain name system that made it possible for attackers to send users en masse to imposter sites instead of the real ones belonging to Google, Bank of America, or anyone else. With industrywide coordination, thousands of DNS providers around the world installed a fix that averted this doomsday scenario. Now, Kaminsky's DNS cache poisoning attack is back. Researchers on Wednesday presented a new technique that can once again cause DNS resolvers to return maliciously spoofed IP addresses instead of the site that rightfully corresponds to a domain name.

On Wednesday, researchers from Tsinghua University and the University of California, Riverside presented a technique that, once again, makes cache poisoning feasible. Their method exploits a side channel that identifies the port number used in a lookup request. Once the attackers know the number, they once again stand a high chance of successfully guessing the transaction ID. The side channel in this case is the rate limit for ICMP, the abbreviation for the Internet Control Message Protocol. To conserve bandwidth and computing resources, servers will respond to only a set number of requests from other servers. After that, servers will provide no response at all. Until recently, Linux always set this limit to 1,000 per second. To exploit this side channel, the new spoofing technique floods a DNS resolver with a high number of responses that are spoofed so they appear to come from the name server of the domain they want to impersonate. Each response is sent over a different port.

When an attacker sends a response over the wrong port, the server will send a response that the port is unreachable, which drains the global rate limit by one. When the attacker sends a request over the right port, the server will give no response at all, which doesn't change the rate limit counter. If the attacker probes 1,000 different ports with spoofed responses in one second and all of them are closed, the entire rate limit will be drained completely. If, on the other hand, one out of the 1,000 ports is open, then the limit will be drained to 999. Subsequently, the attacker can use its own non-spoofed IP address to measure the remaining rate limit. And if the server responds with one ICMP message, the attacker knows one of the previously probed 1,000 ports must be open and can further narrow down to the exact port number.
Linux kernel developers responded by introducing a change that causes the rate limit to randomly fluctuate between 500 and 2,000 per second, preventing the new technique from working. Cloudflare also introduced a fix where its DNS service will fall back to TCP, "which is much more difficult to spoof," reports Ars.

The researchers' press release is available here.
Security

Report: Swiss Government Long in Dark Over CIA Front Company (axios.com) 25

The Swiss intelligence service has known since at least 1993 that Switzerland-based encryption device maker Crypto AG was actually a front for the CIA and its German counterpart, according to a new report released by the Swiss Parliament, but Swiss leaders were in the dark until last year. From a report: Switzerland's intra-governmental information gap is unlikely to be welcome news in Europe, which already looks warily upon the U.S.' expansive surveillance practices. Still, Crypto AG provided information of incalculable value to U.S. policymakers over many decades. Crypto AG was controlled from 1970 on by the CIA and the West German BND intelligence agency. It sold encryption devices -- often employed in diplomatic communications -- that were used by over 120 countries through the 2000s.
Microsoft

Microsoft Urges Users To Stop Using Phone-Based Multi-Factor Authentication (zdnet.com) 164

Microsoft is urging users to abandon telephone-based multi-factor authentication (MFA) solutions like one-time codes sent via SMS and voice calls and instead replace them with newer MFA technologies, like app-based authenticators and security keys. From a report: The warning comes from Alex Weinert, Director of Identity Security at Microsoft. For the past year, Weinert has been advocating on Microsoft's behalf, urging users to embrace and enable MFA for their online accounts. Citing internal Microsoft statistics, Weinert said in a blog post last year that users who enabled multi-factor authentication (MFA) ended up blocking around 99.9% of automated attacks against their Microsoft accounts. But in a follow-up blog post today, Weinert says that if users have to choose between multiple MFA solutions, they should stay away from telephone-based MFA. The Microsoft exec cites several known security issues, not with MFA, but with the state of the telephone networks today. Weinert says that both SMS and voice calls are transmitted in cleartext and can be easily intercepted by determined attackers, using techniques and tools like software-defined-radios, FEMTO cells, or SS7 intercept services.
Chrome

Chrome To Block Tab-Nabbing Attacks (zdnet.com) 27

Google will deploy a new security feature in Chrome next year to prevent tab-nabbing, a type of web attack that allows newly opened tabs to hijack the original tab from where they were opened. From a report: The new feature is scheduled to go live with Chrome 88, to be released in January 2021. While the term "tab-nabbing" refers to a broad class of tab hijacking attacks [see OWASP, Wikipedia], Google is addressing a particular scenario. This scenario refers to situations when users click on a link, and the link opens in a new tab (via the "target=_blank" attribute). These new tabs have access to the original page that opened the new link. Via the JavaScript "window.opener" function, the newly opened tabs can modify the original page and redirect users to malicious sites. This type of attack has powered quite a few phishing campaigns across the years. To mitigate this threat, browser makers like Apple, Google, and Mozilla have created the rel="noopener" attribute.
Spam

Body Found In Canada Identified As Neo-Nazi Spam King (krebsonsecurity.com) 90

An anonymous reader quotes a report from Krebs On Security: The body of a man found shot inside a burned out vehicle in Canada three years ago has been identified as that of Davis Wolfgang Hawke, a prolific spammer and neo-Nazi who led a failed anti-government march on Washington, D.C. in 1999, according to news reports. Homicide detectives said they originally thought the man found June 14, 2017 in a torched SUV on a logging road in Squamish, British Columbia was a local rock climber known to others in the area as a politically progressive vegan named Jesse James.

But according to a report from CTV News, at a press conference late last month authorities said new DNA evidence linked to a missing persons investigation has confirmed the man's true identity as Davis Wolfgang Hawke. A key subject of the book Spam Kings by Brian McWilliams, Hawke was a Jewish-born American who'd legally changed his name from Andrew Britt Greenbaum. For many years, Hawke was a big time purveyor of spam emails hawking pornography and male enhancement supplements, such as herbal Viagra.

In 2005, AOL won a $12.8 million lawsuit against him for relentlessly spamming its users. More recently, Hawke's Jesse James identity penned a book called Psychology of Seduction, which claimed to merge the "shady world of the pickup artist with modern science, unraveling the mystery of attraction using evolutionary biology and examining seduction through the lens of social and evolutionary psychology." The book's "about the author" page said James was a "disruptive technology pioneer" who was into rock climbing and was a resident of Squamish. It also claimed James held a PhD in theoretical physics from Stanford, and that he was an officer in the Israeli Defense Force.

Data Storage

SSDs Are Primed To Get Bigger and Faster With Micron's New NAND Memory Tech (pcworld.com) 48

Micron has announced it's shipping 176-layer TLC NAND flash memory to customers, a move that portends larger, faster and even cheaper SSD drives for all. From a report: The company said its 5th-gen 3D NAND memory should put its density about 40 percent higher than its nearest competitors, which are using 128-layer NAND. Micron said read and write latencies are reduced by 35 percent compared to its 96-layer NAND, and by 25 percent compared its 128-layer NAND. Micron isn't the only NAND memory manufacturer that has 176 layers, but it is the first to start volume shipments. The Micron NAND is TLC, or three-bits per cell, and is said to have 33 percent faster transfer rates, as well as a 35 percent improvement in read and write latencies. And because it's TLC NAND instead of QLC, the new memory should offer better drive endurance, too. The 176-layer design comes from stacking two 88-layer stacks together, which isn't a new thing for Micron. You might think that's a trick, but the end result is still the same: far better density for larger drives. Micron said the new 176-layer NAND is about as thick as one-fifth of a sheet of printer paper, and works out to be as thick its previous 64-layer NAND despite having more than twice as many layers. In the end, this will lead to larger SSDs and potentially cheaper ones, too.
The Internet

Net Applications Will No Longer Track the Browser Wars (venturebeat.com) 34

Emil Protalinski, reporting for VentureBeat: For more than a decade, I've used Net Applications' NetMarketShare tool to track the desktop browser and operating system markets. The monthly reports have been critical in gauging which browsers and new versions of operating systems are gaining or losing market share. Last week, Net Applications released its final NetMarketShare report. The loss could not come at a worse time. After Chrome cemented its spot as the world's de facto browser, there hasn't been a lot of movement. But that might be about to change. Chrome's creator, Google, is facing the biggest U.S. antitrust case in a generation. Mozilla, which depends on Google for almost all its revenue, is rightly worried about becoming "collateral damage."

[...] So why is Net Applications killing off NetMarketShare? Don't act surprised when I tell you the undisputed market leader has something to do with it. In January, Google proposed deprecating the User-Agent string (used to identify which browser and operating system is being used) as part of its war on fingerprinting. Net Applications says the change will break NetMarketShare's device detection technology and "cause inaccuracies for a long period of time." Add the ongoing problem of filtering out bots to prevent skewing of the result, and Net Applications decided it was best to throw in the towel after 14 years. Net Applications provided its reports based on data captured from 100 million sessions each month over thousands of websites.

Security

Compal, the Second-Largest Laptop Manufacturer in the World, Hit By Ransomware (zdnet.com) 25

Compal, a Taiwanese electronics company that builds laptops for some of the world's largest computer brands, suffered a ransomware attack over the weekend. From a report: Responsible for the breach is believed to be the DoppelPaymer ransomware gang, according to a screenshot of the ransom note shared by Compal employees with Yahoo Taiwan reporters. According to Taiwanese media, the incident was discovered on Sunday morning and is believed to have impacted around 30% of Compal's computer fleet. Employees arriving at work were greeted by a memo from Compal's IT staff, asking workers to check the status of their workstations and back up important files on systems that were not impacted.

Slashdot Top Deals