Security

Most Cyber-Security Reports Only Focus On the Cool Threats (zdnet.com) 27

The vast majority of reports published by the cyber-security industry focus on high-end economic espionage and state-sponsored hacking topics, ignoring threats to civil society and creating a distorted view of the actual cyber threat landscape that later influences policy-makers and academic work. From a report: In an article published in the Journal of Information Technology & Politics, a team of academics made up of some of today's biggest names in cyber-security and internet research fields analyzed 700 cyber-security reports published over the last decade, between 2009 and 2019. "The reports we collected were derived from two types of sources: first, commercial threat intelligence vendors (629 reports), and second, independent research centers (71 reports)," academics said. In addition, the team also examined helpline data from AccessNow, a digital rights advocacy group, in order to understand the true digital threats, as reported by the end-users themselves.
China

China To Launch Initiative To Set Global Data-Security Rules (reuters.com) 81

China is launching an initiative to set global standards on data security, countering U.S. efforts to persuade countries to ringfence their networks from Chinese technology, the Wall Street Journal reported on Monday. Reuters: Under its "Global Initiative on Data Security," China would call on all countries to handle data security in a "comprehensive, objective and evidence-based manner," the Journal said, citing a draft that it had reviewed. The initiative would urge countries to oppose "mass surveillance against other states" and call on tech companies not to install "backdoors in their products and services to illegally obtain users' data, control or manipulate users' systems and devices."
Social Networks

On Twitter Usernames With Lots of Numbers (tinysubversions.com) 49

Darius Kazemi: There's a common belief that Twitter accounts with usernames like @jsmith12345678 must be bots, or trolls, or otherwise nefarious actors. The thing is, since at least as far back as December 2017, the Twitter signup process has not allowed you to choose your own username! It instead gives you a name based on your first and last name, plus eight numbers on the end. You aren't prompted to pick a more distinctive username after that, and you can change it but you need to figure out how to do it yourself. (The December 2017 date was confirmed to me privately by someone who works at Twitter Design.) This means that when you see a reply from someone with a username with a bunch of numbers in it, it's actually pretty likely that the user is simply someone who joined Twitter after December 2017 and either doesn't care to change their username, or doesn't know that they can change it, or doesn't know how to change it. In other words, it's probably a user who isn't very technically savvy.
Privacy

Apple Opens Up -- Slightly -- on Hong Kong's National Security Law (techcrunch.com) 22

An anonymous reader shares a report: After Beijing unilaterally imposed a new national security law on Hong Kong on July 1, many saw the move as an effort by Beijing to crack down on dissent and protests in the semi-autonomous region. Soon after, a number of tech giants -- including Microsoft, Twitter and Google -- said they would stop processing requests for user data from Hong Kong authorities, fearing that the requested data could end up in the hands of Beijing. But Apple was noticeably absent from the list. Instead, Apple said it was "assessing" the new law. When reached by TechCrunch, Apple did not say how many requests for user data it had received from Hong Kong authorities since the new national security law went into effect. But the company reiterated that it doesn't receive requests for user content directly from Hong Kong. Instead, it relies on a long-established so-called mutual legal assistance treaty, allowing U.S. authorities to first review requests from foreign governments. Apple said it stores iCloud data for Hong Kong users in the United States, so any requests by Hong Kong authorities for user content has to be first approved by the Justice Department, and a warrant has to be issued by a U.S. federal judge before the data can be handed over to Hong Kong.
Transportation

How a White-Hat Hacker Once Gained Control of Tesla's Entire Fleet (electrek.co) 42

"A few years ago, a hacker managed to exploit vulnerabilities in Tesla's servers to gain access and control over the automaker's entire fleet," remembers Electrek (in a story shared by long-time Slashdot reader AmiMoJo).

Tesla enthusiast Jason Hughes had already received a $5,000 bug bounty for reporting a vulnerability, but "knowing that their network wasn't the most secure, to say the least, he decided to go hunting for more bug bounties." After some poking around, he managed to find a bunch of small vulnerabilities. The hacker told Electrek, "I realized a few of these things could be chained together, the official term is a bug chain, to gain more access to other things on their network. Eventually, I managed to access a sort of repository of server images on their network, one of which was 'Mothership'." Mothership is the name of Tesla's home server used to communicate with its customer fleet.

Any kind of remote commands or diagnostic information from the car to Tesla goes through "Mothership." After downloading and dissecting the data found in the repository, Hughes started using his car's VPN connection to poke at Mothership. He eventually landed on a developer network connection. That's when he found a bug in Mothership itself that enabled him to authenticate as if it was coming from any car in Tesla's fleet.

All he needed was a vehicle's VIN number, and he had access to all of those through Tesla's "tesladex" database thanks to his complete control of Mothership, and he could get information about any car in the fleet and even send commands to those cars.

Last week Hughes released an annotated version of the bug report he'd submitted to Tesla. "Hughes couldn't really send Tesla cars driving around everywhere..." reports Electrek, "but he could 'Summon' them..." Telsa gave him a special $50,000 bug report reward — several times higher than their usual maximum — and "used the information provided by Hughes to secure its network."

Electrek calls it "a good example of the importance of whitehat hackers."
Space

Trump Administration Issues Directive Aimed At Enhancing Cybersecurity In Space (theverge.com) 42

An anonymous reader quotes a report from The Verge: Today, the Trump administration released its fifth Space Policy Directive, this one designed to come up with a list of best practices for the space industry on how to protect their spacecraft from cyber threats. The goal is to encourage the government and space industry to create their space vehicles with cybersecurity plans in place, incorporating tools like encryption software and other protections when designing, building, and operating their vehicles. [...] To combat these threats, Space Policy Directive 5 lays out guidelines that companies should try to adhere to as they launch satellites and other vehicles to space. The administration is recommending operators use various types of software to ensure that the data they receive from their spacecraft is encrypted. The directive also encourages companies to use trusted supply chains and oversee the safety of their ground systems -- the facilities they use to send signals and retrieve data from their spacecraft. The report also recommends protecting against jamming and spoofing of satellites. "Sometimes the jamming can be fairly crude; other cases, some of the spoofing can be fairly sophisticated if somebody's trying to get on board," one official said. "So there's a whole range of things that you need to look at kind of end-to-end."

Ultimately, the directive says that government agencies should work with commercial companies to further refine what these best cybersecurity practices should be, especially since many in the space industry already implement these strategies when building and launching vehicles. [...] SPD-5 is the latest policy directive from the Trump administration designed to shape the U.S. space agenda. Trump's first directive instructed NASA to send humans back to the Moon, while other directives have focused on coming up with a way to oversee space traffic and streamlining regulations for space licenses.

Security

A Single Text Is All It Took To Unleash Code-Execution Worm In Cisco Jabber (arstechnica.com) 12

Until Wednesday, a single text message sent through Cisco's Jabber collaboration application was all it took to touch off a self-replicating attack that would spread malware from one Windows user to another, researchers who developed the exploit said. Ars Technica reports: The wormable attack was the result of several flaws, which Cisco patched on Wednesday, in the Chromium Embedded Framework that forms the foundation of the Jabber client. A filter that's designed to block potentially malicious content in incoming messages failed to scrutinize code that invoked a programming interface known as "onanimationstart." But even then, the filter still blocked content that contained , an HTML tag that had to be included in a malicious payload. To bypass that protection, the researchers used code that was tailored to a built-in animation component called spinner-grow. With that, the researchers were able to achieve a cross-site scripting exploit that injected a malicious payload directly into the internals of the browser built into Jabber.

A security sandbox built into the Chromium Embedded Framework, or CEF, would normally store the payload in a container that's isolated from sensitive parts of the app. To work around this constraint, the researchers abused the window.CallCppFunction, which is designed to open files sent by other Cisco Jabber users. By manipulating a function parameter that accepts files, the researchers were able to break out of the sandbox. "Since Cisco Jabber supports file transfers, an attacker can initiate a file transfer containing a malicious .exe file and force the victim to accept it using an XSS attack," researchers from security firm Watchcom Security wrote in a post. "The attacker can then trigger a call to window.CallCppFunction, causing the malicious file to be executed on the victim's machine." Accordingly, CVE-2020-3495, the designation assigned to the Cisco Jabber vulnerability, has a severity rating of 9.9 out of a maximum 10 based on the Common Vulnerability Scoring System. Cisco's advisory has more details here.

The Internet

The Terrorist Group is Defeated and Routed. But Its Backup Plan Survives (wired.co.uk) 27

The terrorist group is defeated and routed. But its backup plan survives. From a report: It all began on October 27, 2019. Rumour was, Abu Bakr al Baghdadi, the leader of Isis, was dead. Nothing was confirmed, but already the jihadist world online was thrumming with excitement and trepidation. "I was walking through an airport," Moustafa Ayad tells me. "Jet-lagged out of my mind." A deputy director of the counter-extremism think tank Institute of Strategic Dialogue (ISD), Ayad tries to stay on top of the constant struggles and skirmishes, retreats and resurgences between Isis and their many enemies online. That day, as he scrolled through his phone, a blitz of Isis propaganda stared back at him. The digital Jihad was raising a dirge to Baghdadi on Twitter. Flitting from account to pro-Isis account, Ayad noticed something strange. Some accounts carried short, discreet links, not within their tweets, but nestled in their biographies. He clicked.

The link, he realised, was not quite like any other he'd ever followed before. On his phone, Ayad saw folder after folder of meticulously catalogued terrorist content. "I thought it was a joke," Ayad says. "Some kind of scam." In the echoing marbled expanse of Dubai International Airport, on public Wi-Fi, in a Starbucks queue, he had stumbled upon a gigantic, sprawling cache of Isis material. He clicked on a PowerPoint presentation, one of countless now in front of him. "Al Qaeda Airlines", it said: a case study of the mechanics of hijacking planes, making your own chloroform, and the cell structure needed to organise a coordinated terrorist attack. Just then, a dim tannoy announced his flight. Over the weeks that followed, Ayad and his colleagues at the ISD began their journey through the cache. At first glance, the cache looks like a bunch of files on DropBox -- its colour palette an on-brand Isis black-and-white, with a roster of ordinary folders. But the first thing you notice is the size. Its 4,000 folders hold over a terabyte and a half of multimedia multilingual content, spanning Arabic, English, German, French, Spanish, Russian, Bangla, Turkish, and Pashto. "It's a blueprint for terrorism, complete with footnotes" Ayad tells me. "It's everything anyone with an inclination for violence would need to carry out an attack."

The cache's content is a blend of the official products of Isis itself with those of often more obscure precursors, such as the Tawhid wal-Jihad Group, who fought coalition forces in Iraq, and the umbrella organisation of other insurgent groups, Majlis Shura al-Mujahidin. A small amount of it -- just a few per cent by size -- captures in screeds and sermons the ideas of key ideologues of Isis itself. The key personality in the "Fatwas over the Airwaves" folder, for instance, is Turki al Banali, a Bahraini cleric-turned-recruiter who in each episode desperately gives the core concepts of Salafi Jihadism an Isis-friendly spin. Much of the stash, however, simply portrays daily life within Isis, back when the terrorist group still controlled a chunk of territory sitting astride Syria and Iraq. There are school curricula covering the six core subjects that, some estimates believe, were once taught to 130,000 children: English, PE, Arabic, Koranic Studies, Geography & History and a subject called "'ideology", a course of indoctrination in Isis's party lines expounding on the death and destruction awaiting all those who strayed outside of them. It is a mix of the banal and the horrifying -- conjugating verbs and killing the infidels, where early readers learn that "S is for sniper" and "G is for grenade".

Firefox

Firefox Will Add a New Drive-by-Download Protection (zdnet.com) 31

Mozilla will add a new security feature to Firefox in October that will make it harder for malicious web pages to initiate automatic downloads and plant malware-laced files on a user's computer. From a report: Called a drive-by download, this type of attack has been around for two decades and usually takes place when users visit a website that contains malicious code placed there by an attacker. The role of the malicious code is to abuse legitimate features in browsers and web standards to initiate an automatic file download or download prompt, in the hopes of tricking the user into running a malicious file. There are multiple forms of drive-by downloads, depending on the browser feature attackers decide to use. Browsers like Chrome, Firefox, and Internet Explorer have, across the years, gradually deployed various forms of protections against automatic drive-by downloads, but 100% protection can't be fully achieved because browser makers can't fully block legitimate web features and also because of the shifting landscape of web attacks, with attackers always finding a new hole to poke at.
Crime

Former IT Director Gets Jail Time For Selling Government's Cisco Gear On eBay (zdnet.com) 66

An anonymous reader quotes a report from ZDNet: A South Carolina man was sentenced this week to two years in federal prison for taking government-owned networking equipment and selling it on eBay. The man, Terry Shawn Petrill, 48, of Myrtle Beach, worked as the IT Security Director for Horry County in South Carolina, the Department of Justice said in a press release on Tuesday. According to court documents, "beginning on June 11, 2015, through August 23, 2018, Petrill ordered forty-one Cisco 3850 switches that were to be installed on the Horry County network."

US authorities said that through the years, when the switches would arrive, Petrill would take custody of the devices and tell fellow IT staffers that he would handle the installation alone. However, investigators said that "Petrill did not install the switches on the network and instead sold them to third parties and kept the proceeds for himself." FBI agents who investigated the case said they tracked nine of the 41 missing Cisco switches to ads on eBay, while the location of the rest remains unknown. Nonetheless, this was enough to file charges against Petrill, which authorities arrested and indicted in November 2019. Besides prison time, Petrill was also ordered to pay restitution in the amount of $345,265.57 to the Horry County Government.

Security

European ISPs Report Mysterious Wave of DDoS Attacks (zdnet.com) 8

More than a dozen internet service providers (ISPs) across Europe have reported DDoS attacks that targeted their DNS infrastructure. From a report: The list of ISPs that suffered attacks over the past week includes Belgium's EDP, France's Bouygues Telecom, FDN, K-net, SFR, and the Netherlands' Caiway, Delta, FreedomNet, Online.nl, Signet, and Tweak.nl. Attacks lasted no longer than a day and were all eventually mitigated, but ISP services were down while the DDoS was active. NBIP, a non-profit founded by Dutch ISPs to collectively fight DDoS attacks and government wiretapping attempts, provided ZDNet with additional insights into the past week's incidents. "Multiple attacks were aimed towards routers and DNS infrastructure of Benelux based ISPs," a spokesperson said. "Most of [the attacks] were DNS amplification and LDAP-type of attacks." "Some of the attacks took longer than 4 hours and hit close to 300Gbit/s in volume," NBIB said. The DDoS attacks against European ISPs all took place starting with August 28, a day after ZDNet exposed a criminal gang engaging in DDoS extortion against financial institutions across the world, with victims like MoneyGram, YesBank India, Worldpay, PayPal, Braintree, and Venmo.
Security

The FBI Botches Its DNC Hack Warning In 2016 -- But Says It Won't Next Time (wired.com) 90

An anonymous reader quotes a report from Wired: On April 28, 2016, an IT tech staffer for the Democratic National Committee named Yared Tamene made a sickening discovery: A notorious Russian hacker group known as Fancy Bear had penetrated a DNC server "at the heart of the network," as he would later tell the US Senate's Select Committee on Intelligence. By this point the intruders already had the ability, he said, to delete, alter, or steal data from the network at will. And somehow this breach had come as a terrible surprise -- despite an FBI agent's warning to Tamene of potential Russian hacking over a series of phone calls that had begun fully nine months earlier. The FBI agent's warnings had "never used alarming language," Tamene would tell the Senate committee, and never reached higher than the DNC's IT director, who dismissed them after a cursory search of the network for signs of foul play. That miscommunication would result in the success of the Kremlin-sponsored hack-and-leak operation that would ultimately contribute to the election of Donald Trump.

Four years later, the FBI and the community of incident response security professionals who often work with the bureau's agents says the FBI has significantly changed how it communicates with hacking victims -- the better to avoid another DNC-style debacle. In interviews with WIRED, FBI officials never explicitly admitted to a failure in the case of the DNC's botched notification. But they and their private sector counterparts nonetheless described a bureau that has revamped its practices to warn hacking targets faster, and at a higher level of the targeted organization -- especially in cases that might involve the upcoming election or the scourge of ransomware costing companies millions of dollars across the globe.

In December of last year, for instance, the FBI announced a new formal policy of immediately notifying state government officials when the bureau identifies a threat to election infrastructure they control. But the improvements go beyond warnings to state officials, says Mike Herrington, the section chief of the FBI's cyber division. "I see a key change in practice and emphasis, getting our special agents in charge keyed up to gain the full cooperation of potential victims," says Herrington, who says he's personally notified dozens of victims of hacking incidents over his career. Those "special agents in charge" are higher-ranking than the typical field agents who have notified victims in the past, notes Steven Kelly, the FBI's chief of cyber policy. Kelly says that those special agents have also been instructed to aim their warnings further up the victim's org chart. "We want them to be reaching out to the C-suite level, to senior executives," says Kelly. "To make sure they're aware of what's going on and that they're putting the right amount of calories into addressing the issues so that these things don't get ignored or buried."

United States

CISA Orders Agencies To Set Up Vulnerability Disclosure Programs (cyberscoop.com) 4

Out of scores of federal civilian agencies, only a handful of them have official programs to work with outside security researchers to find and fix software bugs -- a process that is commonplace in the private sector. From a report: Now, to put an end to the feet-dragging, the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency is giving agencies six months to set up the programs, known as vulnerability disclosure policies (VDPs). CISA on Wednesday issued a directive requiring agencies to establish VDPs that foreswear legal action against researchers who act in good faith, allow participants to submit vulnerability reports anonymously and cover at least one internet-accessible system or service. It's the latest sign that federal officials are warming to white-hat hackers from various walks of life. "We believe that better security of government computer systems can only be realized when the people are given the opportunity to help," CISA Assistant Director Bryan S. Ware said in announcing the directive. The White House echoed that language in a memo to agencies backing the VDP initiative and setting deadlines for agencies to act.
Businesses

Leaked Salary Spreadsheet Reveals Microsoft Employee Earnings for a Second Year (medium.com) 44

An anonymous reader shares a report: Over the course of August 2020, more than 300 Microsoft employees shared their salaries, bonuses, and stock awards in a Google spreadsheet to continue their push for fairer compensation. "You are legally protected to share this info, and you should share it so your coworkers can determine if they're being underpaid; however, you should still exercise caution," the Google Form to submit information reads. Sharing compensation data has become an annual tradition at Microsoft during this time of year, when full-time employees are notified of any raises or bonuses. Last year, more than 400 employees similarly shared their salaries, OneZero reported. The employees who respond to each year's survey are mainly based in Redmond, Microsoft's Washington headquarters. By the last day of August 2020, 310 employees had added their data to the spreadsheet. Microsoft employs more than 150,000 employees around the world.

Employees shared their previous base salary, any cash bonuses, other bonuses paid out in stock, and merit-based increases in salary. This year's spreadsheet also included two new questions: one asking whether the employee was a person of color, and another asking whether the employee felt marginalized or at risk of being marginalized due to their gender or gender identity. Microsoft's latest diversity report showed the company was mainly white and male, especially at the highest levels. At Microsoft, like most tech companies, seniority and compensation is based on a person's level. At Microsoft, the levels start at 59 and go beyond 80. Microsoft's senior positions start at level 63, according to the crowdsourced tech compensation website Levels.fyi.

Privacy

Private Intel Firm Buys Location Data to Track People to their 'Doorstep' (vice.com) 20

A threat intelligence firm called HYAS, a private company that tries to prevent or investigates hacks against its clients, is buying location data harvested from ordinary apps installed on peoples' phones around the world, and using it to unmask hackers. The company is a business, not a law enforcement agency, and claims to be able to track people to their "doorstep." From a report: The news highlights the complex supply chain and sale of location data, traveling from apps whose users are in some cases unaware that the software is selling their location, through to data brokers, and finally to end clients who use the data itself. The news also shows that while some location firms repeatedly reassure the public that their data is focused on the high level, aggregated, pseudonymous tracking of groups of people, some companies do buy and use location data from a largely unregulated market explicitly for the purpose of identifying specific individuals. HYAS' location data comes from X-Mode, a company that started with an app named "Drunk Mode," designed to prevent college students from making drunk phone calls and has since pivoted to selling user data from a wide swath of apps. Apps that mention X-Mode in their privacy policies include Perfect365, a beauty app, and other innocuous looking apps such as an MP3 file converter. "As a TI [threat intelligence] tool it's incredible, but ethically it stinks," a source in the threat intelligence industry who received a demo of HYAS' product told Motherboard.
Twitter

Twitter Hack May Have Had Another Mastermind: A 16-Year-Old (nytimes.com) 34

When authorities arrested Graham Ivan Clark, who they said was the "mastermind" of the recent Twitter hack that ensnared Kanye West, Bill Gates and others, one detail that stood out was his age: He was only 17. Now authorities have homed in on another person who appears to have played an equal, if not more significant role, in the July 15 attack, New York Times reported Tuesday, citing four people involved in the investigation who declined to be identified because the inquiry was ongoing. They said the person was at least partly responsible for planning the breach and carrying out some of its most sensitive and complicated elements.His age? Just 16, public records show. From the report: On Tuesday, federal agents served the teenager with a search warrant and scoured the Massachusetts home where he lives with his parents, said one of the people involved in the operation. A spokesman for the FBI confirmed a search warrant had been executed at the address. The search warrant and other documents in the case are under seal and federal agents may decide not to charge the youth with a crime. If he is ultimately arrested, the case is likely to be handed over to Massachusetts authorities, who have more leverage than federal prosecutors in charging minors as adults. (The New York Times is not naming the teenager at this point because of his age and because he has not been charged.)
It's funny.  Laugh.

An innocent Typo Led To a Giant 212-Story Obelisk in Microsoft Flight Simulator (theverge.com) 51

Kelerei writes: Microsoft Flight Simulator players spotted a giant mountain-high obelisk in Australia last month. While Flight Simulator has done a great job at recreating the real world, this unusually huge structure doesn't exist in real life. Players have now discovered that its existence stems from a simple typo. University student Nathan Wright made an edit to OpenStreetMap data for part of his degree work last year, adding more than two hundred stories to a building that's actually just two stories. Wright meant to type 2, but instead he typed 212 in the data section for floors. "I think it's so funny as it was the first time I was using OpenStreetMap," says Wright in an email to The Verge. "I was using it for a university task and had to add data for class. I didn't think I would have to see it again." His university work is now internet famous, especially with the Microsoft Flight Simulator community. The typo made its way into Microsoft's Bing Maps data, which Asobo Studio, the developers behind Microsoft Flight Simulator, uses to map out the world in the game. Flight Simulator uses Azure-powered procedural generation technology, combined with Bing Maps data, to recreate virtual buildings like this 212-story obelisk.
Network

Trump Administration Forces Facebook and Google To Drop Hong Kong Cable (arstechnica.com) 56

An anonymous reader quotes a report from Ars Technica: Google and Facebook have withdrawn plans to build an undersea cable between the United States and Hong Kong after the Trump administration raised national security concerns about the proposal. On Thursday, the companies submitted a revised plan that bypasses Hong Kong but includes links to Taiwan and the Philippines that were part of the original proposal. One of the original project's partners, Hong Kong company Pacific Light Data Communication, has been dropped.

Federal law requires a license from the Federal Communications Commission to build an undersea cable connecting the United States with a foreign country. When Google and Facebook submitted their application for an undersea cable connecting the US to Hong Kong, Taiwan, and the Philippines, a committee of federal agencies led by the Justice Department recommended against approving the connection to Hong Kong, citing the "current national security environment." The Trump administration cited "the [People's Republic of China] government's sustained efforts to acquire the sensitive personal data of millions of U.S. persons" as a reason to deny the application. The proposed cable's "high capacity and low latency would encourage U.S. communications traffic crossing the Pacific to detour through Hong Kong before reaching intended destinations in other parts of the Asia Pacific region," the government argued.

Crime

FBI Worried Ring and Other Doorbell Cameras Could Tip Owners Off To Police Searches (theverge.com) 128

FBI documents warned that owners of Amazon's Ring and similar video doorbells can use the systems -- which collect video footage sometimes used to investigate crimes -- in order to watch police instead. The Verge reports: The Intercept spotted the files in the BlueLeaks data trove aggregated from law enforcement agencies. One 2019 analysis describes numerous ways police and the FBI could use Ring surveillance footage, but it also cites "new challenges" involving sensor- and camera-equipped smart home devices. Specifically, they can offer an early warning when officers are approaching a house to search it; give away officer locations in a standoff; or let the owner capture pictures of law enforcement, "presenting a risk to their present and future safety."

These are partly hypothetical concerns. The standoff issue, for instance, was noted in a report about motion-activated panoramic cameras. But the FBI points to a 2017 incident where agents approached the home of someone with a video doorbell, seeking to search the premises. The resident wasn't home but saw them approach by watching a remote video feed, then preemptively contacted his neighbor and landlord about the FBI's approach. He may also have "been able to covertly monitor law enforcement activity" with the camera. This isn't necessarily more information than a security camera would capture. But doorbells like the Ring or Google Nest Hello are pitched as more mainstream devices, and they've also created controversy around police use of the footage.

Security

Apple Mistakenly Approved a Widely Used Malware To Run on Macs (techcrunch.com) 44

Apple has some of the strictest rules to prevent malicious software from landing in its app store, even if on occasion a bad app slips through the net. But last year Apple took its toughest approach yet by requiring developers to submit their apps for security checks in order to run on millions of Macs unhindered. From a report: The process, which Apple calls "notarization," scans an app for security issues and malicious content. If approved, the Mac's in-built security screening software, Gatekeeper, allows the app to run. Apps that don't pass the security sniff test are denied, and are blocked from running. But security researchers say they have found the first Mac malware inadvertently notarized by Apple. Peter Dantini, working with Patrick Wardle, a well-known Mac security researcher, found a malware campaign disguised as an Adobe Flash installer. These campaigns are common and have been around for years -- even if Flash is rarely used these days -- and most run unnotarized code, which Macs block immediately when opened. But Dantini and Wardle found that one malicious Flash installer had code notarized by Apple and would run on Macs. Wardle confirmed that Apple had approved code used by the popular Shlayer malware, which security firm Kaspersky said is the "most common threat" that Macs faced in 2019.

Slashdot Top Deals