Security

Apple's T2 Security Chip Has an Unfixable Flaw (wired.com) 81

A recently released tool is letting anyone exploit an unusual Mac vulnerability to bypass Apple's trusted T2 security chip and gain deep system access. The flaw is one researchers have also been using for more than a year to jailbreak older models of iPhones. But the fact that the T2 chip is vulnerable in the same way creates a new host of potential threats. Worst of all, while Apple may be able to slow down potential hackers, the flaw is ultimately unfixable in every Mac that has a T2 inside. From a report: In general, the jailbreak community haven't paid as much attention to macOS and OS X as it has iOS, because they don't have the same restrictions and walled gardens that are built into Apple's mobile ecosystem. But the T2 chip, launched in 2017, created some limitations and mysteries. Apple added the chip as a trusted mechanism for securing high-value features like encrypted data storage, Touch ID, and Activation Lock, which works with Apple's "Find My" services. But the T2 also contains a vulnerability, known as Checkm8, that jailbreakers have already been exploiting in Apple's A5 through A11 (2011 to 2017) mobile chipsets. Now Checkra1n, the same group that developed the tool for iOS, has released support for T2 bypass.

On Macs, the jailbreak allows researchers to probe the T2 chip and explore its security features. It can even be used to run Linux on the T2 or play Doom on a MacBook Pro's Touch Bar. The jailbreak could also be weaponized by malicious hackers, though, to disable macOS security features like System Integrity Protection and Secure Boot and install malware. Combined with another T2 vulnerability that was publicly disclosed in July by the Chinese security research and jailbreaking group Pangu Team, the jailbreak could also potentially be used to obtain FileVault encryption keys and to decrypt user data. The vulnerability is unpatchable, because the flaw is in low-level, unchangeable code for hardware. "The T2 is meant to be this little secure black box in Macs -- a computer inside your computer, handling things like Lost Mode enforcement, integrity checking, and other privileged duties," says Will Strafach, a longtime iOS researcher and creator of the Guardian Firewall app for iOS. "So the significance is that this chip was supposed to be harder to compromise -- but now it's been done."

Encryption

Five Eyes Governments, India, and Japan Make New Call For Encryption Backdoors (zdnet.com) 129

Members of the intelligence-sharing alliance Five Eyes, along with government representatives for Japan and India, have published a statement over the weekend calling on tech companies to come up with a solution for law enforcement to access end-to-end encrypted communications. From a report: The statement is the alliance's latest effort to get tech companies to agree to encryption backdoors. The Five Eyes alliance, comprised of the US, the UK, Canada, Australia, and New Zealand, have made similar calls to tech giants in 2018 and 2019, respectively. Just like before, government officials claim tech companies have put themselves in a corner by incorporating end-to-end encryption (E2EE) into their products. If properly implemented, E2EE lets users have secure conversations -- may them be chat, audio, or video -- without sharing the encryption key with the tech companies. Representatives from the seven governments argue that the way E2EE encryption is currently supported on today's major tech platforms prohibits law enforcement from investigating crime rings, but also the tech platforms themselves from enforcing their own terms of service. Signatories argue that "particular implementations of encryption technology" are currently posing challenges to law enforcement investigations, as the tech platforms themselves can't access some communications and provide needed data to investigators.
Security

America's 'Cyber Command' Is Trying to Disrupt the World's Largest Botnet (krebsonsecurity.com) 37

The Washington Post reports: In recent weeks, the U.S. military has mounted an operation to temporarily disrupt what is described as the world's largest botnet — one used also to drop ransomware, which officials say is one of the top threats to the 2020 election.

U.S. Cyber Command's campaign against the Trickbot botnet, an army of at least 1 million hijacked computers run by Russian-speaking criminals, is not expected to permanently dismantle the network, said four U.S. officials, who spoke on the condition of anonymity because of the matter's sensitivity. But it is one way to distract them at least for a while as they seek to restore operations.

U.S. Cyber Command also "stuffed millions of bogus records about new victims into the Trickbot database — apparently to confuse or stymie the botnet's operators," reports security researcher Brian Krebs: Alex Holden, chief information security officer and president of Milwaukee-based Hold Security, has been monitoring Trickbot activity before and after the 10-day operation. Holden said while the attack on Trickbot appears to have cut its operators off from a large number of victim computers, the bad guys still have passwords, financial data and reams of other sensitive information stolen from more than 2.7 million systems around the world. Holden said the Trickbot operators have begun rebuilding their botnet, and continue to engage in deploying ransomware at new targets. "They are running normally and their ransomware operations are pretty much back in full swing," Holden said. "They are not slowing down because they still have a great deal of stolen data."

Holden added that since news of the disruption first broke a week ago, the Russian-speaking cybercriminals behind Trickbot have been discussing how to recoup their losses, and have been toying with the idea of massively increasing the amount of money demanded from future ransomware victims.

Wireless Networking

America's FBI Warns of Security Risks in Using Hotel Wi-Fi (ic3.gov) 88

"Most users don't seem to realize the severity of the risks they're subjecting themselves to while using hotel Wi-Fi networks," writes Windows Report, noting that America's FBI "issued a Public Service Announcement concerning the risks of using hotel Wi-Fi networks while teleworking." Apparently, more and more U.S. hotels started advertising room reservations during the daytime for those who seek a distraction-free environment. This comes as a blessing for teleworkers who can't seem to focus on their work environment while at home. On the other hand...there are a few quite serious risks you may expose yourself to while using Wi-Fi networks in hotels:

- Traffic monitoring: Your network activity could be exposed to a malicious third-party

- Evil Twin attacks: Cloning the hotel network, misleading clients to connect to the fake one instead

- Man-In-The-Middle attacks: Intercepting and stealing sensitive information from one's device

- Compromising work" Facilitating cybercriminals to steal work credentials or other similar resources

- Digital identity theft

- Ransomware

Among other things, the FBI points out: Guests generally have minimal visibility into both the physical location of wireless access points within the hotel and the age of networking equipment. Old, outdated equipment is significantly more likely to possess vulnerabilities that criminal actors can exploit. Even if a hotel is using modern equipment, the guest has no way of knowing how frequently the hotel is updating the firmware of that equipment or whether the hotel has changed the equipment's default passwords. The hotel guest must take each of these factors into consideration when choosing whether to telework on a hotel network.
Or, as Slashdot reader SmartAboutThings puts it, "Using hotel Wi-Fi, in general, is not safe at all, and if you have no other choice, then you might as well give VPN services a try."

Or, just don't use the hotel's wifi (using your cellphone as a mobile hotspot instead).
Chrome

Chrome Changes How Its Cache System Works To Improve Privacy (zdnet.com) 21

Google has changed how a core component of the Chrome browser works in order to add additional privacy protections for its users. From a report: Known as the HTTP Cache or the Shared Cache, this Chrome component works by saving copies of resources loaded on a web page, such as images, CSS files, and JavaScript files. The idea is that when a user revisits the same site or visits another website where the same files are used, Chrome will load them from its internal cache, rather than waste time re-downloading each file all over again.

[...] With Chrome 86, released earlier this week, Google has rolled out important changes to this mechanism. Known as "cache partitioning," this feature works by changing how resources are saved in the HTTP cache based on two additional factors. From now on, a resource's storage key will contain three items, instead of one: The top-level site domain (http://a.example), the resource's current frame (http://c.example), and the resource's URL (https://x.example/doge.png). By adding additional keys to the cache pre-load checking process, Chrome has effectively blocked all the past attacks against its cache mechanism, as most website components will only have access to their own resources and won't be able to check resources they have not created themselves.

Security

Computers Aboard Airliners Vulnerable to Hacking, Watchdog Says (bloomberg.com) 29

Airliners carry a variety of computer systems that could become vulnerable to hackers and U.S. regulators haven't imposed adequate counter measures, a government watchdog report concluded. From a report: The Federal Aviation Administration hasn't prioritized cyber risks, developed a cybersecurity training program or conducted testing of potentially vulnerable systems, the Government Accountability Office said in a report issued Friday. "Until FAA strengthens its oversight program, based on assessed risks, it may not be able to ensure it is providing sufficient oversight to guard against evolving cybersecurity risks facing avionics systems in commercial airplane," the GAO report said. Commercial aircraft carry increasingly sophisticated computer systems, including wireless networks, seat-back entertainment, position broadcasts and devices that automatically transmit data to the ground.
Security

Apple Pays $288,000 To White-Hat Hackers Who Had Run of Company's Network (arstechnica.com) 24

An anonymous reader quotes a report from Ars Technica: For months, Apple's corporate network was at risk of hacks that could have stolen sensitive data from potentially millions of its customers and executed malicious code on their phones and computers, a security researcher said on Thursday. Sam Curry, a 20-year-old researcher who specializes in website security, said that, in total, he and his team found 55 vulnerabilities. He rated 11 of them critical because they allowed him to take control of core Apple infrastructure and from there steal private emails, iCloud data, and other private information.

Apple promptly fixed the vulnerabilities after Curry reported them over a three-month span, often within hours of his initial advisory. The company has so far processed about half of the vulnerabilities and committed to paying $288,500 for them. Once Apple processes the remainder, Curry said, the total payout might surpass $500,000. "If the issues were used by an attacker, Apple would've faced massive information disclosure and integrity loss," Curry said in an online chat a few hours after posting a 9,200-word writeup titled We Hacked Apple for 3 Months: Here's What We Found. "For instance, attackers would have access to the internal tools used for managing user information and additionally be able to change the systems around to work as the hackers intend."
An Apple representative issued a statement that said: "At Apple, we vigilantly protect our networks and have dedicated teams of information security professionals that work to detect and respond to threats. As soon as the researchers alerted us to the issues they detail in their report, we immediately fixed the vulnerabilities and took steps to prevent future issues of this kind. Based on our logs, the researchers were the first to discover the vulnerabilities so we feel confident no user data was misused. We value our collaboration with security researchers to help keep our users safe and have credited the team for their assistance and will reward them from the Apple Security Bounty program."
Security

Ransom Gangs Increasingly Outsource Their Work (krebsonsecurity.com) 7

Brian Krebs writes via KrebsOnSecurity.com: There's an old adage in information security: "Every company gets penetration tested, whether or not they pay someone for the pleasure." Many organizations that do hire professionals to test their network security posture unfortunately tend to focus on fixing vulnerabilities hackers could use to break in. But judging from the proliferation of help-wanted ads for offensive pentesters in the cybercrime underground, today's attackers have exactly zero trouble gaining that initial intrusion: The real challenge seems to be hiring enough people to help everyone profit from the access already gained.

One of the most common ways such access is monetized these days is through ransomware, which holds a victim's data and/or computers hostage unless and until an extortion payment is made. But in most cases, there is a yawning gap of days, weeks or months between the initial intrusion and the deployment of ransomware within a victim organization. That's because it usually takes time and a good deal of effort for intruders to get from a single infected PC to seizing control over enough resources within the victim organization where it makes sense to launch the ransomware.

This includes pivoting from or converting a single compromised Microsoft Windows user account to an administrator account with greater privileges on the target network; the ability to sidestep and/or disable any security software; and gaining the access needed to disrupt or corrupt any data backup systems the victim firm may have. Each day, millions of malware-laced emails are blasted out containing booby-trapped attachments. If the attachment is opened, the malicious document proceeds to quietly download additional malware and hacking tools to the victim machine. From there, the infected system will report home to a malware control server operated by the spammers who sent the missive. At that point, control over the victim machine may be transferred or sold multiple times between different cybercriminals who specialize in exploiting such access. These folks are very often contractors who work with established ransomware groups, and who are paid a set percentage of any eventual ransom payments made by a victim company.

IT

Microsoft Edge Gets Free 24-Hour Video Calls, Screenshot Tool, and Shopping Features (venturebeat.com) 37

Microsoft today announced a slew of new features coming to its Chromium Edge browser. From a report: There are PDF improvements, a built-in screenshot tool, support for more themes, and new shopping features in time for the holiday season. But the most notable addition is the one powered by Skype because for better or for worse, 2020 is the year of video calling. When Zoom usage exploded this year, Microsoft tried to save face by making it easier to join Skype calls -- the company dropping account sign-up requirements and expanded the number of supported users. Microsoft is now bringing that functionality to Edge's new tab page with a dedicated Meet Now button (not to be confused with Google Meet). [...] Microsoft claims "Edge is the best browser for shopping this holiday." To make the case, Edge is getting a feature called price comparison that compares the price of a product you're searching for across other retailers. If you add a product to a collection, you can then click "compare price to other retailers" to see a list of prices of that item across other retailers.
Facebook

Facebook Just Forced Its Most Powerful Critics Offline (vice.com) 180

Facebook is using its vast legal muscle to silence one of its most prominent critics. The Real Facebook Oversight Board, a group established last month in response to the tech giant's failure to get its actual Oversight Board up and running before the presidential election, was forced offline on Wednesday night after Facebook wrote to the internet service provider demanding the group's website -- realfacebookoversight.org -- be taken offline. From a report: The group is made up of dozens of prominent academics, activists, lawyers, and journalists whose goal is to hold Facebook accountable in the run-up to the election next month. Facebook's own Oversight Board, which was announced 13 months ago, will not meet for the first time until later this month, and won't consider any issues related to the election. In a letter sent to one of the founders of the RFOB, journalist Carole Cadwalladr, the ISP SupportNation said the website was being taken offline after Facebook complained that the site was involved in "phishing."
Microsoft

Microsoft App Store Playbook Swipes at Apple, Google (axios.com) 39

In a not-so-subtle dig at Apple and Google, Microsoft today announced a series of "principles" for its Windows 10 App Store -- including letting users choose their own payment system for in-app purchases -- that it says should serve as a model for other app stores. From a report: The move comes as antitrust regulators in the U.S. and around the world are spotlighting how both Apple and Google manage their mobile platforms and as some developers charge them with running their app stores unfairly. In addition to offering developers the option to use an alternative payment mechanism for in-app purchases, Microsoft pledged that it will, among other things: allow competing app stores; hold its own apps to the same standards as those of other companies; allow app makers to decide what they do and don't want to sell within their app; and allow any developer in its store "as long as it meets objective standards and requirements, including those for security, privacy, quality, content, and digital safety."
Google

Google Accounts Get Security Boost With New Critical Alerts System (cnet.com) 19

Google on Wednesday unveiled a pair of online products designed to better protect the security and privacy of Google users' information. From a report: The company said it will soon introduce a redesigned critical alert to warn Google Account users when a serious security threat is detected, such as a suspected hack. Unlike alerts that arrive in your email or on your phone, the new alert will automatically be displayed in the Google app you're using. To provide an additional layer of reassurance, Google says the new alert is spoof-proof, so you don't have to worry about whether the alert is legitimate. Google is also rolling out a new feature for Google Assistant called Guest mode that will allow you to use the voice-activated AI without your interactions being saved to your Google account. A simple voice command turns the feature on and off.
Businesses

Trump Administration Announces Overhaul of H-1B Visa Program (mercurynews.com) 181

An anonymous reader quotes a report from The Mercury News: The administration of President Donald Trump on Tuesday moved to impose major new limits on use of the controversial H-1B visa, intended for jobs requiring specialized skills and widely used by Silicon Valley technology firms. The new rules are expected to reduce the pool of skilled labor and raise costs for tech companies and other employers. Critics say that could force companies to move some operations outside the U.S.

The announced changes involve new rules from both Homeland Security and the U.S. Department of Labor. Homeland Security said its rule, effective 60 days after it's published in the federal register, would "combat the use of H-1B workers to serve as a low-cost replacement for otherwise qualified American workers." The Homeland Security rule would fulfill a long-running Trump administration promise to revise the definition of which "specialty occupations" are eligible for the visa, according to a draft copy released late Tuesday. Also revised would be definitions of "worksite," "third-party worksite" and "U.S. employer," as well as clarifying how the government will determine whether an "employer-employee" relationship exists. Placements of H-1B workers at third-party sites -- as staffing companies do -- would last a maximum of a year.

The Labor Department's draft rule suggests visa approvals will require specific degrees for job types. If that change is made, it could lead to qualified applications being rejected, [said Sean Randolph, senior director of the Bay Area Council's Economic Institute.] While there are problems around wages paid to less-skilled H-1B holders, including those hired out to big tech firms by staffing companies, "it would be a mistake to tar and feather the entire system with that because what I've seen about how our tech companies here use the H-1Bs, they're very selective, and they're for important niche positions that otherwise a company would have a hard time filling," Randolph said.

Patents

Cisco Ordered To Cough Up $2 Billion Plus Royalties After Ripping Off Biz's Cybersecurity Patents (theregister.com) 31

Cisco has been hit with a massive $1.9 billion patent-infringement bill for copying cybersecurity tech from Centripetal Networks and pushing the company out of lucrative government contracts. The Register reports: The network switch maker infringed four patents, a Virginia court decided on Monday, but since the infringement was "willful and egregious," the judge multiplied the $756 million owed by 2.5 to a total fine of $1,889,521,362.50. With interest, Cisco faces a hefty $1,903,239,287.50 bill "payable in a lump sum due on the judgment date," the court said. The four patents are: US 9,203,806, 9,560,176, 9,686,193, and 9,917,856.

That's not all: the court also imposed [PDF] a royalty of ten per cent of some of Cisco's products for the next three years, and five per cent for three years after that. That royalty must be at least $168 million and no more than $300 million for the first three years, and between $84 million and $150 million for the next three, the judge said. Even though the sums are massive, they are far from ruinous, and represent about three months of profit for Cisco. The networking giant also has a massive cash pile of roughly $30 billion that the total bill will barely eat into.

As for the tech itself, Centripetal Networks, based in Virginia, developed a network protection system that was in part funded by the US government. The patented parts of it deal with speed and scalability issues, and allowed for live updates and automated workflows. It outlined the technology to Cisco after the company had signed a non-disclosure agreement. But then Cisco simply stole the functionality and incorporated it into its own products in 2017. Centripetal sued [PDF] the following year. "The fact that Cisco released products with Centripetal's functionality within a year of these meetings goes beyond mere coincidence," said District Judge Henry Morgan in his judgment. He noted that Cisco had "continually gathered information from Centripetal as if it intended to buy the technology from Centripetal," but then "appropriated the information gained in these meetings to learn about Centripetal's patented functionality and embedded it into its own products."

Security

Cellmate: Male Chastity Gadget Hack Could Lock Users In (bbc.com) 126

A security flaw in a hi-tech chastity belt for men made it possible for hackers to remotely lock all the devices in use simultaneously. The BBC reports: Qiui's Cellmate Chastity Cage is sold online for about $190 and is marketed as a way for owners to give a partner control over access to their body. Pen Test Partners believe about 40,000 devices have been sold based on the number of IDs that have been granted by its Guangdong-based creator. The cage wirelessly connects to a smartphone via a Bluetooth signal, which is used to trigger the device's lock-and-clamp mechanism. But to achieve this, the software relies on sending commands to a computer server used by the manufacturer.

The security researchers said they discovered a way to fool the server into disclosing the registered name of each device owner, among other personal details, as well as the co-ordinates of every location from where the app had been used. In addition, they said, they could reveal a unique code that had been assigned to each device. These could be used to make the server ignore app requests to unlock any of the identified chastity toys, they added, leaving wearers locked in.

The sex toy's app has been fixed by its Chinese developer after a team of UK security professionals flagged the bug. They have also published a workaround. This could be useful to anyone still using the old version of the app who finds themselves locked in as a result of an attacker making use of the revelation. Any other attempt to cut through the device's plastic body poses a risk of harm.

Chrome

Chrome 86 Brings Password Protections For Android and iOS, VP9 For MacOS Big Sur (venturebeat.com) 16

An anonymous reader writes: Google today launched Chrome 86 for Windows, Mac, Linux, Android, and iOS. Chrome 86 brings password protections for Android and iOS, VP9 for macOS Big Sur, autoupgrades for insecure forms, focus indicator improvements, and a slew of developer features. You can update to the latest version now using Chrome's built-in updater or download it directly from google.com/chrome.

With over 1 billion users, Chrome is both a browser and a major platform that web developers must consider. In fact, with Chrome's regular additions and changes, developers have to stay on top of everything available -- as well as what has been deprecated or removed. Chrome 86, for example, deprecates support for FTP URLs, starting with 1% of users and ramping up to 100% by Chrome 88.

Microsoft

Microsoft Says Iranian Hackers Are Exploiting the Zerologon Vulnerability (zdnet.com) 29

Microsoft said on Monday that Iranian state-sponsored hackers are currently exploiting the Zerologon vulnerability in real-world hacking campaigns. From a report: Successful attacks would allow hackers to take over servers known as domain controllers (DC) that are the centerpieces of most enterprise networks and enable intruders to gain full control over their targets. The Iranian attacks were detected by Microsoft's Threat Intelligence Center (MSTIC) and have been going on for at least two weeks, the company said today in a short tweet. MSTIC linked the attacks to a group of Iranian hackers that the company tracks as MERCURY, but who are more widely known under their monicker of MuddyWatter. The group is believed to be a contractor for the Iranian government working under orders from the Islamic Revolutionary Guard Corps, Iran's primary intelligence and military service.
Transportation

Tesla Hacker Reveals What Driver-Facing Camera Is Looking For (electrek.co) 71

An anonymous reader quotes a report from Electrek: A Tesla hacker has revealed what Tesla's driver-facing camera in Model 3 and Model Y is looking for -- hinting at driver monitoring feature. When Tesla launched the Model 3, it equipped the vehicle with a standard cabin-facing camera located in the rearview mirror. At the time, the automaker said that the camera wasn't active and it would be used in the future. CEO Elon Musk said that it would be used to prevent people from vandalizing cars when they are being driven automatically on Tesla's upcoming self-driving robotaxi network. For almost 3 years, the camera was not used in the Model 3 and Model Y vehicles until earlier this year when Tesla activated the camera for the first time.

Now Tesla hacker 'green', known for revealing many features in Tesla's software, has discovered what events the automaker is trying to detect with the driver-facing camera: BLINDED; DARK; EYES_CLOSED; EYES_DOWN; EYES_NOMINAL; EYES_UP; HEAD_DOWN; HEAD_TRUNC; LOOKING_LEFT; LOOKING_RIGHT; PHONE_USE; SUNGLASSES_EYES_LIKELY_NOMINAL; and SUNGLASSES_LIKELY_EYES_DOWN. Tesla's only active driver monitoring feature when Autopilot is engaged is detecting if torque is being applied to the wheel. Several other driver-assist systems, like GM's Supercruise, are using cabin-facing cameras to make sure drivers are looking at the road.
Tesla started collecting images and clips for research purposes, but only with consent from the drivers: "Help Tesla continue to develop safer vehicles by sharing camera data from your vehicle. This update will allow you to enable the built-in cabin camera above the rearview mirror. If enabled, Tesla will automatically capture images and a short video clip just prior to a collision or safety event to help engineers develop safety features and enhancements in the future. As usual, you can adjust your data sharing preferences by tapping Controls > Safety &Security > DATA Sharing > Camera Analytics."
Microsoft

MS Excel Data Files Exceeding the Maximum Size Resulted in Nearly 16,000 Covid-19 Cases Go Unreported in England (bbc.com) 142

rastos1 shares a report: The health secretary has said a technical glitch that saw nearly 16,000 Covid-19 cases go unreported in England "should never have happened." The error meant that although those who tested positive were told about their results, their close contacts were not traced. By Monday afternoon, around half of those who tested positive had yet to be asked about their close contacts. Labour said the missing results were "putting lives at risk." Experts advise that ideally contacts should be tracked down within 48 hours. The technical error was caused by some Microsoft Excel data files exceeding the maximum size after they were sent from NHS Test and Trace to Public Health England. It meant 15,841 cases between 25 September and 2 October were left out of the UK daily case figures. PHE said the error itself, discovered overnight on Friday, has been fixed, and outstanding cases had been passed on to tracers by 01:00 BST on Saturday. But Health Secretary Matt Hancock told MPs the incident as a whole had not yet been resolved - with only 51% of those whose positive results were caught up in the glitch now reached by contact tracers.
Iphone

Battery Drain Problems After iPhone Upgrade? Apple Suggests Complete Data Wipe (forbes.com) 64

Apple has confirmed several problems including "increased battery drain" for some users who upgraded their iPhone to iOS 14. But ZDNet warns Apple's proposed solution "sounds pretty drastic."

Forbes reports: In an official post, Apple reveals seven significant data and battery-related problems with iOS 14 and watchOS 7, and the company states the only fix is to "erase all content and settings from your iPhone".

Breaking these down, Apple classifies six as related to its Activity, Health and Fitness apps as well as the broader problem of "Increased battery drain on your iPhone or Apple Watch." The latter will not be a surprise to anyone who has seen the growing number of complaints directed at the company's @AppleSupport Twitter account since iOS 14 was released...

On the plus side, Apple's belief that these problems can be fixed without an iOS update is good news. That said, a complete data wipe is also the nuclear option, so Apple is not messing around... I would also be amazed if iOS 14.0.2 is not being fast tracked as we speak.

Slashdot Top Deals