Education

Should Retraining Programs for Laid-Off Retail Workers Include Computer Programming? 233

Appearing on ABC, former Chicago Mayor and Obama White House Chief of Staff Rahm Emanuel on Friday volunteered some suggestions for an economic recovery plan that America's next president could implement. "One of the things we've got to do to rebuild, mainly on infrastructure," he begins, before switching to additional ideas for also offering a more promising future to laid-off retail workers by trying to train them for better jobs. "There's going to be people like at JCPenney and other retail — those jobs aren't coming back. Give them the tools..."

One such possible job he offered as an example? Computer programming. "Six months, you're going to become a computer coder. We'll pay for it.... we need to give them a lifeline to what's the next chapter." He believes lots of people would be interested. Although before any of that, Rahm stressed, "The first part of the stimulus is creating a floor so the economy doesn't sink any more. You can't get an economy growing if states and companies are laying people off."

While computer programming was apparently meant as just one example of possible jobs training programs, this appears to have been twisted into claims that Rahm Emanuel believes millions of laid off retail workers should become computer programmers.

Long-time Slashdot reader theodp does point out that Emanuel has held a long-standing faith in the potential of computer science education. ("Before leaving office, Emanuel worked to make Computer Science a high school graduation requirement beginning with the Class of 2020, although the Chicago Public Schools waived the requirement this year, citing the pandemic.") But is that also one possible solution for older generations who didn't receive computer science training in high school?

What do Slashdot's readers think? Leave your own thoughts in the comments. Should the retraining programs offered to laid-off retail workers include computer programming?
Android

On Older Versions of Android, Many Let's Encrypt-Secured Sites May Stop Working in 2021 (letsencrypt.org) 45

This year Let's Encrypt announced that it's issued a billion certificates, and it's been estimated they've made certs for almost 30% of web domains. But Friday they posted that "The DST Root X3 root certificate that we relied on to get us off the ground is going to expire — on September 1, 2021. Fortunately, we're ready to stand on our own, and rely solely on our own root certificate."

"However, this does introduce some compatibility woes." Some software that hasn't been updated since 2016 (approximately when our root was accepted to many root programs) still doesn't trust our root certificate, ISRG Root X1. Most notably, this includes versions of Android prior to 7.1.1. That means those older versions of Android will no longer trust certificates issued by Let's Encrypt.

Android has a long-standing and well known issue with operating system updates. There are lots of Android devices in the world running out-of-date operating systems. The causes are complex and hard to fix: for each phone, the core Android operating system is commonly modified by both the manufacturer and a mobile carrier before an end-user receives it. When there's an update to Android, both the manufacturer and the mobile carrier have to incorporate those changes into their customized version before sending it out. Often manufacturers decide that's not worth the effort. The result is bad for the people who buy these devices: many are stuck on operating systems that are years out of date.

Currently, 66.2% of Android devices are running version 7.1 or above. The remaining 33.8% of Android devices will eventually start getting certificate errors when users visit sites that have a Let's Encrypt certificate. In our communications with large integrators, we have found that this represents around 1-5% of traffic to their sites. Hopefully these numbers will be lower by the time DST Root X3 expires next year, but the change may not be very significant.

Let's Encrypt engineer Jacob Hoffman-Andrews explains that "In the time between now and September 29 we plan to start serving certificates with the 'alternate' link relation 186 to allow Automatic Certificate Management Environment (ACME) clients to programmatically select a chain they prefer." But Friday's blog post explains that won't solve everything: There will be site owners that receive complaints from users and we are empathetic to that being not ideal. We're working hard to alert site owners so you can plan and prepare. We encourage site owners to deploy a temporary fix (switching to the alternate certificate chain) to keep your site working while you evaluate what you need for a long-term solution: whether you need to run a banner asking your Android users on older OSes to install Firefox, stop supporting older Android versions, drop back to HTTP for older Android versions, or switch to a CA that is installed on those older versions.
Gizmodo notes that Firefox will be unaffected "since it relies on its own certificate store that includes Let's Encrypt's root, though that wouldn't keep applications from breaking or ensure functionality beyond your browser." They describe Let's Encrypt as "the Mozilla-partnered nonprofit," and offers this succinct summary of the problem.

"One of the world's top certificate authorities warns that phones running versions of Android prior to 7.1.1 Nougat will be cut off from large portions of the secure web starting in 2021."
Security

Cyberattackers Now Also Make Linux Versions of Their Ransomware (zdnet.com) 77

"Security firm Kaspersky said Friday that it discovered a Linux version of the RansomEXX ransomware," reports ZDNet, "marking the first time a major Windows ransomware strain has been ported to Linux to aid in targeted intrusions." RansomEXX is a relatively new ransomware strain that was first spotted earlier this year in June. The ransomware has been used in attacks against the Texas Department of Transportation, Konica Minolta, U.S. government contractor Tyler Technologies, Montreal's public transportation system, and, most recently, against Brazil's court system (STJ)...

The RansomEXX gang creating a Linux version of their Windows ransomware is in tune with how many companies operate today, with many firms running internal systems on Linux, and not always on Windows Server. A Linux version makes perfect sense from an attacker's perspective; always looking to expand and touch as much core infrastructure as possible in their quest to cripple companies and demand higher ransoms. What we see from RansomEXX may soon turn out to be an industry-defining trend, with other big ransomware groups rolling out their Linux versions in the future as well.

And, this trend appears to have already begun. According to cyber-security firm Emsisoft, besides RansomEXX, the Mespinoza (Pysa) ransomware gang has also recently developed a Linux variant from their initial Windows version.

Security

Ransomware Gangs That Steal Your Data Don't Always Delete It (zdnet.com) 28

Ransomware gangs that steal a company's data and then get paid a ransom fee to delete it don't always follow through on their promise. From a report: The number of cases where something like this has happened has increased, according to a report published by Coveware this week and according to several incidents shared by security researchers with ZDNet researchers over the past few months. These incidents take place only for a certain category of ransomware attacks -- namely those carried out by "big-game hunters" or "human-operated" ransomware gangs. These two terms refer to incidents where a ransomware gang specifically targets enterprise or government networks, knowing that once infected, these victims can't afford prolonged downtimes and will likely agree to huge payouts. But since the fall of 2019, more and more ransomware gangs began stealing large troves of files from the hacked organizations before encrypting the victims' files. The idea was to threaten the victim to release its sensitive files online if the company wanted to restore its network from backups instead of paying for a decryption key to recover its files.
Printer

Why Do Printers Still Suck? (wired.com) 287

Just when we need them the most, with print shops locked down, online schooling in session, and everyone working from home, they fail to step up. From a column: Printers have been my enemy ever since I can remember. My first office job involved an evil printer that suffered daily paper jams. Tasked with fixing it, I suffered frequent burns and paper cuts. It had a door you had to close just so, or it would immediately break again with the dreaded phantom paper jam. It tormented me for months, completely indifferent to my cries. There isn't even any paper in it! More than two decades later, printers haven't improved at all. It feels like printer companies stopped innovating sometime in the '90s when sales stopped climbing. In fact, it's almost as if they've regressed. Manufacturers tempt with unbelievably cheap deals on printers and then nail you on expensive ink. To make sure they get their pound of flesh, they focus an inordinate effort on making sure printers only work with proprietary ink cartridges.

[...] Three years and a couple of printers later, sick of being gouged for ink cartridges that always seem to run out at the worst moment, I optimistically signed up for a printing subscription plan. The idea is you are charged a flat fee based on how many pages you print each month, and the printer automatically orders ink refills when it's running low. Reading this back, I can only cringe at my naivety. Things were fine for the first few weeks. Then I made the mistake of turning the printer off. It doesn't like to be turned off. It started emailing me, insisting that it needs to be turned on and connected to the internet so the subscription plan can work properly. Every time I turn it on, it prints an ink-heavy test page. It is incredibly good at printing test pages -- it just won't print the document you want. Things got worse when I made the mistake of changing my internet service provider. I forgot about the printer for a while. Then I suddenly needed it. I didn't have time to set up the Wi-Fi, so I plugged directly into the printer with a good old-fashioned cable. It refused to print. I refused to connect it to the internet, so it refused to print for me. To get it working again I had to completely uninstall everything related to the printer, update my drivers, install three separate programs, carry it to another room to plug directly into my desktop, carry it back again, hold down the correct button sequence at the stroke of midnight, spin around three times, and recite the printer incantation into a mirror. It's finally connected and working ... for now. But I know it's only a matter of time before it betrays me again.

Security

GitHub Denies Getting Hacked (zdnet.com) 10

GitHub has denied rumors today of getting hacked after a mysterious entity shared what they claimed to be the source code of the GitHub.com and GitHub Enterprise portals. From a report: The "supposed" source code was leaked via a commit to GitHub's DMCA section. The commit was also faked to look like it originated from GitHub CEO Nat Friedman. But in a message posted on YCombinator's Hacker News portal, Friedman denied that it was him and that GitHub got hacked in any way. Friedman said the "leaked source code" didn't cover all of GitHub's code but only the GitHub Enterprise Server product. This is a version of GitHub Enterprise that companies can run on their own on-premise servers in case they need to store source code locally for security reasons but still want to benefit from GitHub Enterprise features. Friedman said this source code had already leaked months before due to its own error when GitHub engineers accidentally "shipped an un-stripped/obfuscated tarball of our GitHub Enterprise Server source code to some customers."
Security

Configuration Snafu Exposes Passwords For Two Million Marijuana Growers (zdnet.com) 29

An anonymous reader quotes a report from ZDNet: GrowDiaries, an online community where marijuana growers can blog about their plants and interact with other farmers, has suffered a security breach in September this year. The breach occurred after the company left two Kibana apps exposed on the internet without administrative passwords. Kibana apps are normally used by a company's IT and development staff, as the app allows programmers to manage Elasticsearch databases via a simple web-based visual interface. Due to its native features, securing Kibana apps is just as important as securing the databases themselves.

But in a report published today on LinkedIn, Bob Diachenko, a security researcher known for discovering and reporting unsecured databases, said GrowDiaries failed to secure two of its Kibana apps, which appear to have been left exposed online without a password since September 22, 2020. Diachenko says these two Kibana apps granted attackers access to two sets of Elasticsearch databases, with one storing 1.4 million user records and the second holding more than two million user data points. The first exposed usernames, email addresses, and IP addresses, while the second database also exposed user articles posted on the GrowDiaries site and users' account passwords. While the passwords were stored in a hashed format, Diachenko said the format was MD5, a hashing function known to be insecure and crackable (allowing threat actors to determine the cleartext version of each password).
The company secured its infrastructure five days after Diachenko reported the exposed Kibana apps on October 10. It's unknown if someone else accessed the databases to download user data.
IT

Nikon Will Let You Use Its Cameras as High-End Webcams (engadget.com) 65

Nikon has at last released software that turns your fancy DSLR or mirrorless camera into a high-end webcam. From a report: Other major camera makers have rolled out similar tools in the last several months, as video calls became much more prevalent amid stay-at-home measures to combat COVID-19. The free Webcam Utility Software is available in beta for both Windows 10 and macOS. Along with video conference calls, Nikon suggests you can use a mirrorless camera or DLSR for livestreaming as well, just in case you've had designs on becoming a Twitch superstar.
Security

23,600 Hacked Databases Have Leaked From a Defunct 'Data Breach Index' Site (zdnet.com) 1

More than 23,000 hacked databases have been made available for download on several hacking forums and Telegram channels in what threat intel analysts are calling the biggest leak of its kind. From a report: The database collection is said to have originated from Cit0Day.in, a private service advertised on hacking forums to other cybercriminals. Cit0day operated by collecting hacked databases and then providing access to usernames, emails, addresses, and even cleartext passwords to other hackers for a daily or monthly fee. Cybercriminals would then use the site to identify possible passwords for targeted users and then attempt to breach their accounts at other, more high-profile sites. The idea behind the site isn't unique, and Cit0Day could be considered a reincarnation of similar "data breach index" services such as LeakedSource and WeLeakInfo, both taken down by authorities in 2018 and 2020, respectively.
Electronic Frontier Foundation

Police Will Pilot a Program To Live-Stream Amazon Ring Cameras (eff.org) 84

An anonymous reader quotes a report from the Electronic Frontier Foundation: This is not a drill. Red alert: The police surveillance center in Jackson, Mississippi, will be conducting a 45-day pilot program to live stream the Amazon Ring cameras of participating residents. Now, our worst fears have been confirmed. Police in Jackson, Mississippi, have started a pilot program that would allow Ring owners to patch the camera streams from their front doors directly to a police Real Time Crime Center. The footage from your front door includes you coming and going from your house, your neighbors taking out the trash, and the dog walkers and delivery people who do their jobs in your street. In Jackson, this footage can now be live streamed directly onto a dozen monitors scrutinized by police around the clock. Even if you refuse to allow your footage to be used that way, your neighbor's camera pointed at your house may still be transmitting directly to the police.

Only a few months ago, Jackson stood up for its residents, becoming the first city in the southern United States to ban police use of face recognition technology. Clearly, this is a city that understands invasive surveillance technology when it sees it, and knows when police have overstepped their ability to invade privacy. If police want to build a surveillance camera network, they should only do so in ways that are transparent and accountable, and ensure active resident participation in the process. If residents say "no" to spy cameras, then police must not deploy them. The choices you and your neighbors make as consumers should not be hijacked by police to roll out surveillance technologies. The decision making process must be left to communities.

Security

Google To GitHub: Time's Up -- This Unfixed 'High-Severity' Security Bug Affects Developers (zdnet.com) 32

Google Project Zero, the Google security team that finds bugs in all popular software, has disclosed what it classes a high-severity flaw on GitHub after the code-hosting site asked for a double extension on the normal 90-day disclosure deadline. From a report: The bug in GitHub's Actions feature -- a developer workflow automation tool -- has become one of the rare vulnerabilities that wasn't properly fixed before Google Project Zero's (GPZ) standard 90-day deadline expired. Over 95.8% of flaws are fixed within the deadline, according to Google's hackers. GPZ is known to be generally strict with its 90-day deadline, but it appears GitHub was a little lax in its responses as the deadline approached after Google gave it every chance to fix the bug. As detailed in a disclosure timeline by GPZ's Felix Wilhelm, the Google security team reported the issue to GitHub's security on July 21 and a disclosure date was set for October 18. According to Wilhelm, Actions' workflow commands are "highly vulnerable to injection attacks."
IBM

The Untimely Demise Of Workstations (deprogrammaticaipsum.com) 122

Graham Lee, writing at De Programmatica Ipsum: Last month's news that IBM would do a Hewlett-Packard and divide into two -- an IT consultancy and a buzzword compliance unit -- marks the end of "business as usual" for yet another of the great workstation companies. [...] In high-tech domains, an engineer could readily have a toolchest of suitable computers in the same way that a mechanic has different tools for their tasks. This one has an FPGA connected by both PCI-E and JTAG to allow for quick hardware prototyping. This one is connected to a high-throughput GPU for visualisations; that one to a high-capacity GPU for scientific simulations. The general purpose hardware vendors want us to believe that an okay-at-anything computer is the best for everything: you don't need a truck, so here's a car. But when you're hauling a ton of goods, you'll find it cheaper and more satisfying to shell out more for a truck. Okay-at-anything is good for nothing.
Security

WeWork Employees Used an Alarmingly Insecure Printer Password (techcrunch.com) 29

A shared user account used by WeWork employees to access printer settings and print jobs had an incredibly simple password -- so simple that a customer guessed it. From a report: Jake Elsley, who works at a WeWork in London, said he found the user account after a WeWork employee at his location mistakenly left the account logged in. WeWork customers like Elsley normally have an assigned seven-digit username and a four-digit passcode used for printing documents at WeWork locations. But the username for the account used by WeWork employees was just four-digits: "9999". Elsley told TechCrunch that he guessed the password because it was the same as the username. ("9999" is ranked as one of the most common passwords in use today, making it highly insecure.)

The "9999" account is used by and shared among WeWork community managers, who oversee day-to-day operations at each location, to print documents for visitors who don't have accounts to print on their own. The account cannot be used to access print jobs sent to other customer accounts. Elsley said that the "9999" account could not see the contents of documents beyond file names, but that logging in to the WeWork printing web portal could allow him to release other people's pending print jobs sent to the "9999" account to any other WeWork printer on the network.

Chrome

Chrome Will Soon Have Its Own Dedicated Certificate Root Store (zdnet.com) 56

Google has announced plans to run its own certificate root program/store for Chrome, in a major architectural shift for the company's web browser program. From a report: A "root program" or a "root store" is a list of root certificates that operating systems and applications use to verify the identity of a software program during its installation routine. Browsers like Chrome use root stores to check the validity of an HTTPS connection. They do this by looking at the website's TLS certificate and checking if the root certificate that was used to generate the TLS cert is included in the local root program/store. Since its launch in late 2009, Chrome was configured to use the "root store" of the underlying platform. For example, Chrome on Windows checked a site's TLS certificate against the Microsoft Trusted Root Program, the root store that ships with Windows; Chrome on macOS relied on the Apple Root Certificate Program; and so on. But in a wiki page, shared with ZDNet by one of our readers, Google announced plans to create its own root store, named the Chrome Root Program, that will ship with all versions of Chrome, on all platforms, except iOS.
Google

What It's Like To Get Locked Out of Google Indefinitely (businessinsider.com) 352

An anonymous reader shares a report: When he received the notification from Google he couldn't quite believe it. Cleroth, a game developer who asked not to use his real name, woke up to see a message that all his Google accounts were disabled due to "serious violation of Google policies." His first reaction was that something must have malfunctioned on his phone. Then he went to his computer and opened up Chrome, Google's internet browser. He was signed out. He tried to access Gmail, his main email account, which was also locked. "Everything was disconnected," he told Business Insider. Cleroth had some options he could pursue: One was the option to try and recover his Google data â" which gave him hope. But he didn't go too far into the process because there was also an option to appeal the ban. He sent in an appeal.

He received a response the next day: Google had determined he had broken their terms of service, though they didn't explain exactly what had happened, and his account wouldn't be reinstated. (Google has been approached for comment on this story.) Cleroth is one of a number of people who have seen their accounts suspended in the last few days and weeks. In response to a tweet explaining his fear at being locked out of his Google account after 15 years of use, others have posted about the impact of being barred from the company that runs most of the services we use in our day-to-day lives. "I've been using a Google account for personal and work purposes for years now. It had loads of various types of data in there," said Stephen Roughley, a software developer from Birkenhead, UK. "One day when I went to use it I found I couldn't log in." Roughley checked his backup email account and found a message there informing him his main account had been terminated for violating the terms of service. "It suggested that I had been given a warning and I searched and searched but couldn't find anything," added Roughley. "I then followed the link to recover my account but was given a message stating that my account was irrecoverable." Roughley lost data including emails, photos, documents and diagrams that he had developed for his work. "My account and all its data is gone," he said.

Stats

Millions of Americans Plan to Relocate Thanks to Telework, Survey Finds (npr.org) 129

NPR reports: An astonishing 14 million to 23 million Americans intend to relocate to a different city or region as a result of telework, according to a new study released by Upwork, a freelancing platform. The survey was conducted Oct. 1 to 15 among 20,490 Americans 18 and over.

The large migration is motivated by people no longer confined to the city where their job is located. The pandemic has shifted many companies' view on working from home...

Another study conducted by United Van Lines, a major household moving company, found that people wanted to relocate out of New York state at a higher rate than the national average. And, by the beginning of September, the requests to leave San Francisco had grown to more than double the U.S. average. The survey was conducted between March and August. Nationally, there is a 32% increase in moving interest compared with this time last year, the United Van Lines survey found.

Interestingly, currently San Francisco actually has the lowest positivity rate from coronavirus testing of any major metropolitan area in America — suggesting the migrations aren't motivated by a flight from the pandemic itself.

Instead Upwork's chief economist calls their data "an early indicator of the much larger impacts that remote work could have in increasing economic efficiency and spreading opportunity."
Crime

Therapy Patients Blackmailed For Cash After Clinic Data Breach (bbc.co.uk) 55

"Many patients of a large psychotherapy clinic in Finland have been contacted individually by a blackmailer, after their data was stolen," reports the BBC: The data appears to have included personal identification records and notes about what was discussed in therapy sessions.

Vastaamo is a nationwide practice with about 20 branches and thousands of patients. The clinic has advised those affected to contact the police. It said it believed the data had been stolen in November 2018, with a further potential breach in March 2019... About 300 records have already been published on the dark web, according to the Associated Press news agency.

On its website, the clinic calls the attack "a great crisis". It has set up a helpline and is offering all victims one free therapy session, the details of which will not be recorded.

According to the article, the blackmailer claims Vastaamo refused to pay the 40 bitcoin ransom — so they are instead blackmailing individual patients.

And one patient even complained that while his therapist took notes in a physical notebook, "he had not been told these would be uploaded to a server."
Music

RIAA Obtains Subpoenas Targeting 40 YouTube-Ripping Platforms and Pirate Sites (torrentfreak.com) 99

An anonymous reader shares a report: The RIAA is ramping up the pressure on a wide range of platforms allegedly involved in music piracy. Two DMCA subpoenas obtained against Cloudflare and Namecheap require the companies to hand over all information they hold on more than 40 torrent sites, streaming portals and YouTube-ripping services. Also included in the mix are several file-hosting platforms.
Windows

Google Discloses Windows Zero-Day Exploited in the Wild (zdnet.com) 32

Security researchers from Google have disclosed today a zero-day vulnerability in the Windows operating system that is currently under active exploitation. From a report: The zero-day is expected to be patched on November 10, which is the date of Microsoft's next Patch Tuesday, according to Ben Hawkes, team lead for Project Zero, Google's elite vulnerability research team. On Twitter, Hawkes said the Windows zero-day (tracked as CVE-2020-17087) was used as part of a two-punch attack, together with another a Chrome zero-day (tracked as CVE-2020-15999) that his team disclosed last week. The Chrome zero-day was used to allow attackers to run malicious code inside Chrome, while the Windows zero-day was the second part of this attack, allowing threat actors to escape Chrome's secure container and run code on the underlying operating system -- in what security experts call a sandbox escape.

Slashdot Top Deals