Privacy

3 TB of Private Webcam/Home Security Video Leaked on Porn Sites (inputmag.com) 44

schwit1 quotes Input: A hacking group that has yet to identify itself found and stole more than 3 TB of private video from around the world — mainly collected from Singapore — and shared it on porn sites, according to reports from local media like The New Paper. While some of the footage was indeed pornographic in nature, other videos are more mundane.

More than 50,000 private IP-based cameras were accessed by hackers to amass the collection. Some were explicitly tagged with locations in Singapore, The New Paper reports, while others revealed their location as Singapore based on context clues such as book titles and home layout. Many show people (sometimes with their faces censored) in "various stages of undress or compromising positions...."

It's looking like poor security is the culprit. Clement Lee, a solutions architect for multinational software company Check Point Software Technologies, told The New Paper that the hacking of IP cameras is often due to "poor password management." IP cameras make it easy to access your video feeds from anywhere — which means it's also easy for hackers to access them from anywhere, once they've figured out your password...

The unfortunate fact of the matter is that internet-connected devices are inherently susceptible to hacking. Add lax encryption and lazy users to the mix and you have a recipe for disaster.

Google

Google's Internal Data Suggests Employees Feel Less Productive At Home (theinformation.com) 85

The Information reports: Google's engineering directors are grappling with a worrisome trend: internal data that indicate productivity during the coronavirus shutdowns deteriorated among engineers, particularly newly hired ones.

One internal survey viewed by The Information found that in the three months ended in June, only 31% of the company's engineers polled felt they had been highly productive, down 8 percentage points from a record high in the March quarter. That decline and more recent data on engineers' coding output from the third quarter caused its head of engineering productivity, Michael Bachman, last week to email senior Google managers and executives, drawing attention to the data. He said the findings are "still relevant for all teams across the company," not just engineers.

Inside.com's developer newsletter supplies some context: The news comes as reports reveal Microsoft's CEO Satya Nadella is tired of working from home, while Stanford economics professor Nicholas Bloom adds he believes remote work is, for many, a "productivity disaster" that he fears will hurt innovation.

However, these statements contradict a recent report unveiled during the September DevOpsWorld 2020 conference examining the impact of Covid-19 on software development, where many reported an increase in productivity.

Earth

Make Remote Work Permanent? No Way, Say Bay Area Leaders (msn.com) 169

Last month a regional government agency in the San Francisco Bay Area voted "to move forward" with a proposal to eventually require people at large, office-based companies to work from home three days a week "as a way to slash greenhouse gas emissions from car commutes," according to NBC News.

But today local newspapers report "Bay Area leaders are already saying, no way." [Shorter, non-paywalled article here.] The Metropolitan Transportation Commission is drawing heavy fire from lawmakers, the business commmunity and transit supporters for a proposal that would require big companies to have their employees work from home at least 60 percent of the time by 2035.

The proposal is aimed at reducing vehicle commuters and greenhouse gas emissions, but Bay Area politicians and business leaders say it would encourage Silicon Valley companies to pick up and leave. "This will spur a flight of large employers from the Bay Area," said San Jose Mayor Sam Liccardo, comparing the idea to paving lanes directly from Silicon Valley to Texas. After recovering from the pandemic-caused recession, Liccardo said, "we're going to miss those jobs." Liccardo and San Francisco Mayor London Breed this week urged MTC leaders to find a better solution to hit the region's long-term clean air goals...

Rebecca Saltzman, a BART director, is introducing a resolution asking MTC to re-examine the requirement, which was added late in the process. It would drive down transit use with no clear proof it would reduce greenhouse gases, she said. "We know we would lose riders," she said. Bay Area lawmakers said a work-from-home mandate would hurt small businesses located around large employers, drain vitality from downtowns and diminish transit use. The requirements would also fall heavily on low-wage workers who typically must report to work to cook, clean, build or serve customers. San Jose and San Francisco both have tech giants — Google and Salesforce — spending billions of dollars to design and develop new campuses with a higher density of homes and apartments near transit. A work-from-home mandate could disrupt those plans, Liccardo said.

"I'm concerned about a parade of unintended consequences," he said. "This undermines the incentives to live near work."

Security

How Ransomware Puts Your Hospital At Risk (deccanherald.com) 35

nickwinlund77 quotes a New York Times opinion piece: In March, several cybercrime groups rushed to reassure people that they wouldn't target hospitals and other health care facilities during the Covid-19 pandemic. The operators of several prominent strains of ransomware all announced they would not target hospitals, and some of them even promised to decrypt the data of health care organizations for free if one was accidentally infected by their malware. But any cybersecurity strategy that relies on the moral compunctions of criminals is doomed to fail, particularly when it comes to protecting the notoriously vulnerable computer systems of hospitals.

So it's no surprise that Universal Health Services was hit by ransomware late last month, affecting many of its more than 400 health care facilities across the United States and Britain. Or that clinical trials for a Covid-19 vaccine have been held up by a similar ransomware attack disclosed in early October. Or that loose-knit coalitions of volunteers all over the world are working around the clock to try to protect the computer systems of hospitals that are already straining under the demands of providing patient care during a global pandemic.

In the midst of the Covid-19 pandemic, the potential consequences of these cyberattacks are terrifying. Hospitals that have lost access to their databases or had their networks infected by ransomware may not be able to admit patients in need of care or may take longer to provide those patients with the treatment they need, if they switch to relying on paper records...

Every hospital and clinic should be re-evaluating their computer networks right now and ramping up the protections they have in place to prevent their services from being interrupted by malware or their sensitive patient data from being stolen.

Google

Google Says it Mitigated a 2.54 Tbps DDoS Attack in 2017, Largest Known To Date (zdnet.com) 15

The Google Cloud team revealed today a previously undisclosed DDoS attack that targeted Google service back in September 2017 and which clocked at 2.54 Tbps, making it the largest DDoS attack recorded to date. From a report: In a separate report published at the same time, the Google Threat Threat Analysis Group (TAG), the Google security team that analyzes high-end threat groups, said the attack was carried out by a state-sponsored threat actor. TAG researchers said the attack came from China, having originated from within the network of four Chinese internet service providers (ASNs 4134, 4837, 58453, and 9394). Damian Menscher, a Security Reliability Engineer for Google Cloud, said the 2.54 Tbps peak was "the culmination of a six-month campaign" that utilized multiple methods of attacks to hammer Google's server infrastructure.
Microsoft

You Can Now Install Microsoft Windows Calculator on Linux (betanews.com) 102

An anonymous reader shares a report: Earlier, Microsoft released the source for Windows Calculator. And now, that calculator app has been ported to Linux by Uno Platform. Best of all, it's insanely easy to install as it is packaged in Snap format. "The good folks in the Uno Platform community have ported the open-source Windows Calculator to Linux. And they've done it quicker than Microsoft could bring their browser to Linux. The calculator is published in the snapstore and can be downloaded right away," explains Rhys Davies, Product Manager, Canonical.
IT

British Airways Fined $26 Million Over Data Breach (bbc.com) 13

British Airways has been fined $26m by the Information Commissioner's Office (ICO) for a data breach which affected more than 400,000 customers. From a report: The breach took place in 2018 and affected both personal and credit card data. The fine is considerably smaller than the $236m that the ICO originally said it intended to issue back in 2019. It said "the economic impact of Covid-19" had been taken into account. However, it is still the largest penalty issued by the ICO to date. The incident took place when BA's systems were compromised by its attackers, and then modified to harvest customers' details as they were input. It was two months before BA was made aware of it by a security researcher, and then notified the ICO.
Technology

Coinbase's New 'Direction' Is Censorship, Leaked Audio Reveals (vice.com) 188

An anonymous reader shares a report: Brian Armstrong, CEO of cryptocurrency exchange Coinbase, revealed in a late September blog post that the company would prohibit employees from debating political or social issues, deeming this a "distraction" from the company's mission. Armstrong doubled down on his position during a virtual all-hands held on October 1, billed as an "AMA" (for "ask me anything"), from which Motherboard obtained audio. The AMA was meant to further explain the company's new "apolitical" direction for those who might consider accepting a severance package that was offered to any employee who felt "uncomfortable." Executives also explained when and where dissent would be appropriate, and explained why they required employees to delete specific political Slack messages. This, at a company that works with cryptocurrencies intended to replace government banking systems in order to create a more free world. During the meeting, Armstrong claimed there is a "silent majority" at Coinbase that agreed with his decision but feared reprisal from colleagues. Armstrong and Coinbase leadership, however, failed to soothe fears that this policy would police employees if they voiced opinions that did not align with Armstrong or this "silent majority."

One former Coinbase employee who left the company after the AMA and to whom Motherboard provided anonymity due to fear of industry reprisal said that these assurances were insufficient and workers feared surveillance and censorship. These fears are not unfounded. Emile Choi, Coinbase's chief operating officer, explained that at least two employees were asked to delete Slack posts, and that HR head L.J. Brock "proactively reached out to employees to explain why their posts would be taken down. He had a very productive conversation with both of them and they understood the context," she said. One employee asked if Coinbase leadership thought that this was "taking away employee power to start a discussion except with 300 character questions" in an AMA format. "It seems like Coinbase is stunting internal discussion." Choi said that the entire executive team was aligned on Armstrong's post and policy, and that the new "culture is focused on what unites us and what we face in the world, which is building toward our mission," Choi said. "The goal was not intended to be harsh, it wasn't intended to land in a way where people felt they were being policed."

Privacy

Robinhood Estimates Hackers Infiltrated Almost 2,000 Accounts (bloomberg.com) 19

An anonymous reader quotes a report from Bloomberg: Almost 2,000 Robinhood Markets accounts were compromised in a recent hacking spree that siphoned off customer funds, a sign that the attacks were more widespread than was previously known. A person with knowledge of an internal review, who asked not to be identified because the findings aren't public, provided the estimated figure. When Bloomberg first reported on the hacking spree last week, the popular online brokerage disclosed few details. It said "a limited number" of customers had been struck by cyber-criminals who gained access by breaching personal email accounts outside of Robinhood, an assertion that some of the victims acknowledge and others reject.

The attacks unleashed a torrent of complaints on social media, where investors recounted futile attempts to call the brokerage, which doesn't have a customer service phone number. Robinhood, which has more than 13 million customer accounts, is now considering whether to add a phone number along with other tools, the person said. This week, Robinhood sent push notifications to users suggesting they enable two-factor authentication on their accounts. It also plans to send customers more advice on security, according to the statement. Several victims said they found no sign of criminals compromising their email accounts. And some said their brokerage accounts were accessed even though they had set up two-factor authentication.

Security

Ubisoft, Crytek Data Posted on Ransomware Gang's Site (zdnet.com) 2

A ransomware gang going by the of Egregor has leaked data it claims to have obtained from the internal networks of two of today's largest gaming companies -- Ubisoft and Crytek. An anonymous reader writes: Data allegedly taken from each company has been published on the ransomware gang's dark web portal on Tuesday. Details about how the Egregor gang obtained the data remain unclear. Ransomware gangs like Egregor regularly breach companies, steal their data, encrypt files, and ask for a ransom to decrypt the locked data. However, in many incidents, ransomware gangs are also get caught and kicked out of networks during the data exfiltration process, and files are never encrypted. Nevertheless, they still extort companies, asking victims for money to not leak sensitive files. Usually, when negotiations break down, ransomware gangs post a partial leak of the stolen files on so-called leak sites. On Tuesday, leaks for both Crytek and Ubisoft were posted on the Egregor portal at the same time, with threats from the ransomware crew to leak more files in the coming days.
Security

Google and Intel Warn of High-Severity Bluetooth Security Bug In Linux (arstechnica.com) 41

An anonymous reader quotes a report from Ars Technica: Google and Intel are warning of a high-severity Bluetooth flaw in all but the most recent version of the Linux Kernel. While a Google researcher said the bug allows seamless code execution by attackers within Bluetooth range, Intel is characterizing the flaw as providing an escalation of privileges or the disclosure of information. The flaw resides in BlueZ, the software stack that by default implements all Bluetooth core protocols and layers for Linux. Besides Linux laptops, it's used in many consumer or industrial Internet-of-things devices. It works with Linux versions 2.4.6 and later. So far, little is known about BleedingTooth, the name given by Google engineer Andy Nguyen, who said that a blog post will be published "soon." A Twitter thread and a YouTube video provide the most detail and give the impression that the bug provides a reliable way for nearby attackers to execute malicious code of their choice on vulnerable Linux devices that use BlueZ for Bluetooth.

Intel, meanwhile, has issued this bare-bones advisory that categorizes the flaw as privilege-escalation or information-disclosure vulnerability. The advisory assigned a severity score of 8.3 out of a possible 10 to CVE-2020-12351, one of three distinct bugs that comprise BleedingTooth. "Potential security vulnerabilities in BlueZ may allow escalation of privilege or information disclosure," the advisory states. "BlueZ is releasing Linux kernel fixes to address these potential vulnerabilities." Intel, which is a primary contributor to the BlueZ open source project, said that the most effective way to patch the vulnerabilities is to update to Linux kernel version 5.9, which was published on Sunday. Those who can't upgrade to version 5.9 can install a series of kernel patches the advisory links to. Maintainers of BlueZ didn't immediately respond to emails asking for additional details about this vulnerability.
Ars Technica points out that since BleedingTooth requires proximity to a vulnerable device, there's not much reason for people to worry about this vulnerability. "It also requires highly specialized knowledge and works on only a tiny fraction of the world's Bluetooth devices," it adds.
Privacy

Florida Could Become First State To Offer Digital Driver's Licenses (wesh.com) 55

According to WESH Orlando, Florida residents next year will be able to apply for new mobile driver's licenses that can be easily accessed on a smartphone, tablet, or other device. They will be valid as a traditional license. From the report: The service will be provided by the company Thales, which designs and builds electrical systems and provides services for the aerospace, defense, transportation and security markets. "The State of Florida will be the first state in the United States to provide mobile Driver Licenses with leading-edge security mechanisms, fully compliant with rigorous national and international standards.," a statement from Thales said.

According to Thales, a digital license will work the same way as a traditional one. People would open the app and present it to verify your age, check in at TSA or interact with law enforcement. As of now, though, Thales states on their website, "It will be up to each state and local law enforcement agency to determine what procedure and methods work best within their existing protocol." It's unclear exactly when Florida will begin offering the mobile licenses.

Transportation

Split-Second 'Phantom' Images Can Fool Tesla's Autopilot (wired.com) 84

An anonymous reader quotes a report from Wired: Researchers at Israel's Ben Gurion University of the Negev have spent the last two years experimenting with "phantom" images to trick semi-autonomous driving systems. They previously revealed that they could use split-second light projections on roads to successfully trick Tesla's driver-assistance systems into automatically stopping without warning when its camera sees spoofed images of road signs or pedestrians. In new research, they've found they can pull off the same trick with just a few frames of a road sign injected on a billboard's video. And they warn that if hackers hijacked an internet-connected billboard to carry out the trick, it could be used to cause traffic jams or even road accidents while leaving little evidence behind.

In this latest set of experiments, the researchers injected frames of a phantom stop sign on digital billboards, simulating what they describe as a scenario in which someone hacked into a roadside billboard to alter its video. They also upgraded to Tesla's most recent version of Autopilot known as HW3. They found that they could again trick a Tesla or cause the same Mobileye device to give the driver mistaken alerts with just a few frames of altered video. The researchers found that an image that appeared for 0.42 seconds would reliably trick the Tesla, while one that appeared for just an eighth of a second would fool the Mobileye device. They also experimented with finding spots in a video frame that would attract the least notice from a human eye, going so far as to develop their own algorithm for identifying key blocks of pixels in an image so that a half-second phantom road sign could be slipped into the "uninteresting" portions. And while they tested their technique on a TV-sized billboard screen on a small road, they say it could easily be adapted to a digital highway billboard, where it could cause much more widespread mayhem.
"Autopilot is a driver assistance feature that is intended for use only with a fully attentive driver who has their hands on the wheel and is prepared to take over at any time," reads Tesla's response. The Ben Gurion researchers counter that Autopilot is used very differently in practice. "As we know, people use this feature as an autopilot and do not keep 100 percent attention on the road while using it," writes Mirsky in an email. "Therefore, we must try to mitigate this threat to keep people safe, regardless of [Tesla's] warnings."
Encryption

Zoom To Roll Out End-to-End Encrypted (E2EE) Calls (zdnet.com) 31

Video conferencing platform Zoom announced today plans to roll out end-to-end encryption (E2EE) capabilities starting next week. From a report: E2EE will allow Zoom users to generate individual encryption keys that will be used to encrypt voice or video calls between them and other conference participants. These keys will be stored locally and will not be shared with Zoom servers, meaning the software company won't be able to access or intercept any ongoing E2EE meetings. Support for E2EE calls will first be part of Zoom clients to be released next week. To use the new feature, users must update theri clients next week and enable support for E2EE calls at the account level. This green shield will contain a lock if E2EE is active. If the lock is absent, Zoom will use its default AES 256-bit GCM encryption scheme, which the company uses to secure current communications, but which the company can also intercept. Further reading: Zoom Adds Ability To Open Apps Like Dropbox And Slack, Event-Hosting Tools As Part Of Push Beyond Video Meetings.
IOS

Apple Is Poaching From Google's iPhone Hacking Team (vice.com) 18

Apple has poached a key member of Google's Project Zero, a hacking team at Google that has found dozens of critical vulnerabilities in Apple's iOS and other critical Apple software. From a report: Last year, Apple and Google fought over a series of vulnerabilities that Project Zero discovered in iOS, with Apple suggesting that Google was overselling the vulnerabilities. About a year later, Brandon Azad announced on Twitter at the beginning of October that he was leaving Google's elite team of hackers to join Apple. "My teammates at Project Zero have been among the kindest and smartest people I've met, and I've learned so much from them," Azad wrote. "I'll really miss working alongside everyone on the team. Thank you all for these wonderful experiences, and keep on hacking!" Azad has been widely considered one of the best iPhone hackers who didn't work for Apple, being named by Apple in countless security advisories, and presenting highly technical findings on Apple's products at major cybersecurity conferences around the world. Last year, Motherboard profiled Project Zero and revealed that Apple had been trying to poach a colleague of Azad, Ian Beer.
Businesses

Finnish Startup Unveils Machine That Takes Office-Air CO2 and Converts It Into Fuel (arstechnica.com) 114

Over a video call, Finnish start-up Soletair Power showed Ars Technica their machine that converts office-air carbon dioxide into fuel. Scott K. Johnson reports: The value proposition for the first part of the device is pretty straightforward. Carbon dioxide accumulates in buildings full of people, and higher CO2 concentrations may impact your ability to think clearly. The usual way to manage that is to introduce more outside air (which may need to be heated/cooled). Another could be to selectively filter out CO2. This device could do the latter for you. That CO2 could simply be vented outside or used to produce an unwieldy amount of seltzer. Instead, what makes Soletair's idea more interesting is that the rest of its device turns the CO2 into fuel. The configuration the company demonstrated makes methane but could be swapped for a liquid fuel process. Depending on the source of the energy running the machines, these fuels could be carbon-neutral since the carbon comes from the air. Whether it's economically viable is another question.

The CO2 capture technique they're using is a scaled-down version of those designed for combustion power plants. Air goes through a chamber full of small granules that contain amines -- compounds that bind with CO2 molecules. Periodically, the granules are cycled through a heating step. The temperature only needs to rise to shy of 120C, Soletair's Petri Laakso and Cyril Bajamundi told Ars, so steam from the local heat system and/or an electric heating element is sufficient. This makes the amine granules release the CO2 they're holding, which accumulates in a storage tank. The granules are then ready to absorb more CO2. The other two-thirds of the machine, which measures about 2 meters tall, 5 meters long, and 1 meter wide, deal with turning that CO2 into a usable fuel. First, there's an electrolyzer that splits water to make hydrogen gas. Then hydrogen is combined with CO2 in a methanation reactor to produce pure methane gas.

Cloud

Amazon's Latest Gimmicks Are Pushing the Limits of Privacy (wired.com) 49

At the end of September, Amazon debuted two especially futuristic products within five days of each other: a small autonomous surveillance drone, called Ring Always Home Cam, and a palm recognition scanner, called Amazon One. "Both products aim to make security and authentication more convenient -- but for privacy-conscious consumers, they also raise red flags," reports Wired. From the report: Amazon's latest data-hungry innovations are not launching in a vacuum. The company also owns Ring, whose smart doorbells have had myriad security issues and have been widely criticized for bringing unprecedented surveillance to traditionally semi-private spaces. Meanwhile, the biometric data that Amazon Go will collect is particularly sensitive, because unlike a password you can't simply change it if a hacker steals it or it gets unintentionally exposed. Amazon has a strong record for maintaining the security of its massive cloud infrastructure, but there have been lapses across the sprawling business. The stakes are already phenomenally high; the more data the company holds the more risk it takes on. "Amazon has a major genomics cloud platform, so maybe they hold your DNA and now they're going to have your palm as well? Plus all of these devices inside your house. And your purchase history on Prime. That's a lot of information. That's a lot of personal information," says Nina Alli, executive director of Defcon's Biohacking Village and a health care security researcher. "When you give away this data you're giving a company the ability to access and manage you, not the other way around."
[...]
Additionally, while companies like Apple and Samsung have brought biometric fingerprint and face scanners to the masses by making sure the data never leaves the device, Amazon One takes the opposite approach. Kumar writes that "palm images are never stored" on Amazon One itself. Instead they are encrypted and sent to a special high security area of Amazon's cloud to be converted into "palm signatures" based on the unique and distinctive features of a user's hand. Then the service compares that signature to the one on file in each user's account and returns a match or no match answer back down to the device. It makes sense that Amazon doesn't want to store databases of people's palm data locally on publicly accessible machines that could be manipulated. But the system could perhaps have been set up to generate a palm signature locally, delete the image of a person's hand, and send only the encrypted signature on for analysis. The fact that all of those palm images will be going for cloud processing creates a single point of failure.
"I'm worried that people could read your palm vein pattern in other ways and construct an analog. It's only a matter of time," says Joseph Lorenzo Hall, a longtime security and privacy researcher and a senior vice president at the nonprofit Internet Society. "Both the home drone and the palm payment are going to rely heavily on the cloud and on the security provided by that cloud storage. That's worrying because it means all the risks -- rogue employees, government data requests, data breach, secondary uses -- associated with data collection on the server-side could be possible. I'm much more comfortable having a biometric template stored locally rather than on a server where it might be exfiltrated."

An Amazon spokesperson told WIRED, "We are confident that the cloud is highly secure. In addition, Amazon One palm data is stored separately from other personal identifiers, and is uniquely encrypted with its own keys in a secure zone in the cloud."
Privacy

How Many Americans Still Secretly Use Their Ex's Passwords (zdnet.com) 42

A recent survey by British Virgin Islands-based VPN service provider ExpressVPN asked 1,506 American adults in an exclusive (non-married) relationship to find out their password sharing habits across social media platforms. ZDNet reports on the findings: The survey showed that couples share a variety of passwords with each other, and they most commonly share within the first six months of dating. The most commonly shared passwords between couples are for video streaming (78%), mobile devices (64%), and music streaming (58%). Almost half (47%) of Americans in a relationship share social media passwords and 38% share their personal email passwords. Most services, apart from social media and mobile device accounts (which are shared most with family), are more commonly shared with a significant other than family or friends. Respondents said that sharing passwords is most indicative of trust (70%), commitment (63%), intimacy (54%), marriage-material (51%), affection (48%), and vulnerability (47%). Among those sharing video streaming services, Netflix (86%), Hulu (57%), and Amazon Prime Video (52%) are shared most with a significant other. Millennials and Generation Z are also more likely to share passwords with their significant others across all platforms, as compared to older folks. Among people who do not share passwords with anyone, the most common objection is that the same username and password combination is often used for additional accounts.

Among respondents, men are more guilty than women of still secretly using an ex's login information/password post-break up. Over one in four (26%) currently use their ex's game streaming services account and online news subscriptions (26%). A quarter (25%) access their ex's photo sharing program, and food/grocery delivery sites. Almost one in four (23%) currently access social media accounts, mobile wallets, music, and video streaming services and one in five access their ex's personal email accounts. One in four 25% of respondents confess to currently tracking an ex's real-time location and 30% confess to secretly logging in to an ex's social media account at least once, with 23% admitting to still doing so currently. It is not surprising that over one in three (36%) of respondents indicate regret in sharing passwords with a significant other, either during the relationship or after a breakup -- with men feeling more regretful than women (40% vs. 32%).

Security

Backdoor In Kids' Smartwatch Makes It Possible For Someone To Covertly Take Pictures, Record Audio (theregister.com) 16

The Xplora 4 smartwatch, made by Chinese outfit Qihoo 360 Technology Co, and marketed to children under the Xplora brand in the US and Europe, can covertly take photos and record audio when activated by an encrypted SMS message, says Norwegian security firm Mnemonic. The Register reports: This backdoor is not a bug, the finders insist, but a deliberate, hidden feature. Around 350,000 watches have been sold so far, Xplora says. Exploiting this security hole is non-trivial, we note, though it does reveal the kind of remotely accessible stuff left in the firmware of today's gizmos. "The backdoor itself is not a vulnerability," said infosec pros Harrison Sand and Erlend Leiknes in a report on Monday. "It is a feature set developed with intent, with function names that include remote snapshot, send location, and wiretap. The backdoor is activated by sending SMS commands to the watch."

The researchers suggest these smartwatches could be used to capture photos covertly from its built-in camera, to track the wearer's location, and to conduct wiretapping via the built-in mic. They have not claimed any such surveillance has actually been done. The watches are marketed as a child's first phone, we're told, and thus contain a SIM card for connectivity (with an associated phone number). Parents can track the whereabouts of their offspring by using an app that finds the wearer of the watch. Xplora contends the security issue is just unused code from a prototype and has now been patched. But the company's smartwatches were among those cited by Mnemonic and Norwegian Consumer Council in 2017 for assorted security and privacy concerns.

With the appropriate Android intent, an incoming encrypted SMS message received by the Qihoo SMS app could be directed through the command dispatcher in the Persistent Connection Service to trigger an application command, like a remote memory snapshot. Exploiting this backdoor requires knowing the phone number of the target device and its factory-set encryption key. This data is available to those to Qihoo and Xplora, according to the researchers, and can be pulled off the device physically using specialist tools. This basically means ordinary folks aren't going to be hacked, either by the manufacturer under orders from Beijing or opportunistic miscreants attacking gizmos in the wild, though it is an issue for persons of interest. It also highlights the kind of code left lingering in mass-market devices.

Microsoft

Microsoft Releases Update for Windows 10 To Prevent Swollen Laptop Batteries (betanews.com) 72

Mark Wilson writes: Microsoft has teamed up with HP to work on a fix for a problem affecting various HP Business Notebooks. The flaw not only causes a reduction in performance and battery life, but can also lead to swollen batteries. The problem lies with the HP Battery Health Manager, and the update from Microsoft and HP is rolling out to enable a new charging algorithm to help alleviate the issue. Writing about the update, Microsoft says: "Microsoft is working with HP to distribute a solution to help address a configuration setting issue within HP Battery Health Manager on select HP Business Notebooks that can affect battery life and performance. This update does not require a restart to take effect."

Slashdot Top Deals