United States

CenturyLink Outage Led To a 3.5% Drop in Global Web Traffic (zdnet.com) 27

US internet service provider CenturyLink has suffered a major technical outage on Sunday after a misconfiguration in one of its data centers created havoc all over the internet. From a report Due to the technical nature of the outage -- involving both firewall and BGP routing -- the error spread outward from CenturyLink's network and also impacted other internet service providers, ending up causing connectivity problems for many more other companies. The list of tech giants who had services go down today because of the CenturyLink outage includes big names like Amazon, Twitter, Microsoft (Xbox Live), EA, Blizzard, Steam, Discord, Reddit, Hulu, Duo Security, Imperva, NameCheap, OpenDNS, and many more. Cloudflare, which was also severely impacted today, said CenturyLink's outward-propagating issue led to a 3.5% drop in global internet traffic, which would make this one of the biggest internet outages ever recorded.
Programming

Psychology Today: How Programmers Can Avoid Burnout (psychologytoday.com) 61

An anonymous reader quotes Psychology Today: While software development jobs sound great right out of the gate, technology roles don't always offer a great career path. The entry-level salary is fantastic, and the job is fun. But five years on, the average developer reaches a senior role, and there aren't many more rungs on the technology career ladder. An article from 1998 in the New York Times reported that six years after finishing college, only 57 percent of computer science graduates were working as programmers. After 20 years, the figure dropped to 19 percent. In contrast, the figures for civil engineering were 61 percent and 52 percent...

It's not just about the money — it's at least as much about the control you have over what you do. And software developers these days have little say in what apps they build. "More than anything, what bothered me is the feeling that my work doesn't matter one way or another," said one of my friends before he quit his programming job. He continued, "You get into software thinking you'll build cool things, but instead, it's about jumping through hoops for business school people with bad ideas."

Rapid changes in technology make programming one of the fastest-moving careers. Avoiding burnout is the only way to have a long and sustainable career in tech. Veteran software developers often recommend to:

- Work at a place where you can grow. Constantly learning new things is a requirement in tech, but it's only sustainable if you can do it as part of the job.

- Build transferable skills. Many developers find it interesting to invest in learning leadership skills and explore technical management roles — those don't change as often as programming languages do.

- Have creative outlets and create a space to focus on yourself, to switch off and relax. Make sure you move enough, eat well, and spend quality time with friends and family.

Of course, there's always the nuclear option: make your money and get out.

Security

'Unusually Large Number' of Breached SendGrid Accounts Are Sending Spams and Scams (krebsonsecurity.com) 13

Krebs on Security reports: Email service provider Sendgrid is grappling with an unusually large number of customer accounts whose passwords have been cracked, sold to spammers, and abused for sending phishing and email malware attacks. Sendgrid's parent company Twilio says it is working on a plan to require multi-factor authentication for all of its customers, but that solution may not come fast enough for organizations having trouble dealing with the fallout in the meantime...

[A] large number of organizations allow email from Sendgrid's systems to sail through their spam-filtering systems. To make matters worse, links included in emails sent through Sendgrid are obfuscated (mainly for tracking deliverability and other metrics), so it is not immediately clear to recipients where on the Internet they will be taken when they click...

Rob McEwen is CEO of Invaluement.com, an anti-spam firm whose data on junk email trends are used to improve the spam-blocking technologies deployed by several Fortune 100 companies. McEwen said no other email service provider has come close to generating the volume of spam that's been emanating from Sendgrid accounts lately. "As far as the nasty criminal phishes and viruses, I think there's not even a close second in terms of how bad it's been with Sendgrid over the past few months," he said...

Neil Schwartzman, executive director of the anti-spam group CAUCE, said Sendgrid's two-factor authentication plans are long overdue, noting that the company bought Authy back in 2015. "Single-factor authentication for a company like this in 2020 is just ludicrous given the potential damage and malicious content we're seeing," Schwartzman said... Schwartzman said if Twilio doesn't act quickly enough to fix the problem on its end, the major email providers of the world (think Google, Microsoft and Apple) — and their various machine-learning anti-spam algorithms — may do it for them.

Krebs found an online cybercriminal selling access to more than 400 compromised Sendgrid accounts. "Accounts that can send up to 40,000 emails a month go for $15, whereas those capable of blasting 10 million missives a month sell for $400."
Spam

Elon Musk Shows Neuralink Brain Link Working In a Pig (cnet.com) 87

With a pig named Gertrude, Elon Musk demonstrated his startup Neuralink's technology to build a digital link between brains and computers. A wireless link from the Neuralink device showed the pig's activity activity as it snuffled around a pen on stage Friday night. CNET reports: The demonstration shows the the technology to be significantly closer to delivering on Musk's radical ambitions than during a 2019 product debut, when Neuralink only showed photos of a rat with a Neuralink connected via a USB-C port. It's still far from reality, but Musk said the US Food and Drug Administration in July granted approval for "breakthrough device" testing. Musk also showed a second-generation device that's more compact and that fits into a small cavity hollowed out of a hole in a skull. "It's like a Fitbit in your skull with tiny wires," Musk said of the device. It communicates with brain cells with 1,024 thin electrodes that penetrate within brain cell.
Windows

Microsoft Tests Fix For Bug That Defrags SSD Drives Too Often (bleepingcomputer.com) 95

An anonymous reader shares a report: Windows 10 May 2020 Update, otherwise known as version 2004, was released in May with at least ten known issues. Microsoft later expanded the list of the problems and acknowledged that this feature update is also plagued with a bug that breaks Drive Optimize tool. After upgrading to Windows 10 version 2004, users observed that Optimize Drives (also known as defragmentation tool) is not correctly recording the last time a drive has been optimized. As a result, when you open the tool, you will see that your SSD drive says it 'Needs Optimization' even though you've manually optimized the drives already or automatic maintenance was run this morning. Since the last optimizations times are forgotten, Windows 10's built-in maintenance tool started defragging an SSD drive much more often when you restart Windows. With Windows 10 Build 19042.487 (20H2) for Insiders, Microsoft has finally resolved all problems with the Optimize Drives (also known as defragmentation tool).
Intel

Intel Slips, and a High-Profile Supercomputer Is Delayed (nytimes.com) 77

The chip maker was selected for an Energy Department project meant to show American tech independence. But problems at Intel have thrown a wrench into the effort. From a report: When it selected Intel to help build a $500 million supercomputer last year, the Energy Department bet that computer chips made in the United States could help counter a technology challenge from China. Officials at the department's Argonne National Laboratory predicted that the machine, called Aurora and scheduled to be installed at facilities near Chicago in 2021, would be the first U.S. system to reach a technical pinnacle known as exascale computing. Intel pledged to supply three kinds of chips for the system from its factories in Oregon, Arizona and New Mexico. But a technology delay by the Silicon Valley giant has thrown a wrench into that plan, the latest sign of headwinds facing government and industry efforts to reverse America's dependence on foreign-made semiconductors. It was also an indication of the challenges ahead for U.S. hopes to regain a lead in critical semiconductor manufacturing technology.

Intel, which supplies electronic brains for most personal computers and web services, has long driven miniaturization advances that make electronic devices smaller, faster and cheaper. But Robert Swan, its chief executive, warned last month that the next production advance would be 12 months late and suggested that some chips for Aurora might be made outside Intel factories. Intel's problems make it close to impossible that Aurora will be installed on schedule, researchers and analysts said. And shifting a key component to foreign factories would undermine company and government hopes of an all-American design. "That is part of the story they were trying to sell," said Jack Dongarra, a computer scientist at the University of Tennessee who tracks supercomputer installations around the world. "Now they stumbled."

AI

Visa Unveils More Powerful AI Tool That Approves or Denies Card Transactions (wsj.com) 50

Visa said it has developed a more advanced artificial intelligence system that can approve or decline credit and debit transactions on behalf of banks whose own networks are down. From a report: The decision to approve or deny a transaction typically is made by the bank. But bank networks can crash because of natural disasters, buggy software or other reasons. Visa said its backup system will be available to banks who sign up for the service starting in October. The technology is "an incredible first step in helping us reduce the impact of an outage," said Rajat Taneja, president of technology for Visa. The financial services company is the largest U.S. card network, as measured both by the number of cards in circulation and by transactions. The new service reflects the growing use of AI in banking. Banks are expected to spend $7.1 billion on AI in 2020, growing to $14.5 billion by 2024, on initiatives such as fraud analysis and investigation, according to market research firm International Data Corp. The service, Smarter Stand-In Processing, uses a branch of AI called deep learning that roughly mimics neurons in the human brain and is an underlying technology powering self-driving cars, voice-enabled digital assistants and facial recognition.
The Internet

A Quarter of the Alexa Top 10K Websites Are Using Browser Fingerprinting Scripts (zdnet.com) 13

An anonymous reader quotes a report from ZDNet: A browser fingerprinting script is a piece of JavaScript code that runs inside a web page and works by testing for the presence of certain browser features. In an academic paper published earlier this month, a team of academics from the University of Iowa, Mozilla, and the University of California, Davis, has analyzed how popular browser fingerprinting scripts are used today by website operators. Using a machine learning toolkit they developed themselves and named FP-Inspector, the research team scanned and analyzed the top 100,000 most popular websites on the internet, according to the Alexa web traffic ranking.

"We find that browser fingerprinting is now present on more than 10% of the top-100K websites and over a quarter of the top-10K websites," the research team said. However, the research team also points out that despite the large number of websites that are currently using browser fingerprinting, not all scripts are used for tracking. Some fingerprinting scripts are also used for fraud detection since automated bots tend to have the same or similar fingerprints, and fingerprinting scripts are a reliable method of detecting automated behavior. Additional details about the team's research can be found in a paper named "Fingerprinting the Fingerprinters: Learning to Detect Browser Fingerprinting Behaviors," set to be presented at the IEEE Symposium on Security and Privacy, next year, in May 2021.
If you're concerned about the findings, you can block fingerprinting scripts by enabling anti-fingerprinting protections in your respective browser settings or by installing an ad blocker extension.
Security

New Zealand Stock Exchange Halted by Cyber-Attack (bbc.com) 22

The New Zealand stock exchange was knocked offline two days in a row due to a cyber-attack. From a report NZX said it had first been hit by a distributed denial of service (DDoS) attack from abroad, on Tuesday. The exchange said the attack had "impacted NZX network connectivity" and it had decided to halt trading in cash markets just before 16:00 local time. Trading halted briefly for a second time, on Wednesday, but was back up and running before the end of the day. A DDoS attack is a relatively simple type of cyber-attack, in which a large array of computers all try to connect to an online service at once, overwhelming its capacity. They often use devices compromised by malware the owners do not know are part of the attack. Genuine traders may have had problems carrying out their business. But it does not mean any financial or personal information was accessed.
United States

Russian Arrested For Trying To Recruit an Insider and Hack a Nevada Company (zdnet.com) 30

The US Department of Justice announced charges today against a Russian citizen who traveled to the US in order to recruit and convince an employee of a Nevada company to install malware on their employer's network in exchange for $1,000,000. From a report: According to court documents unsealed today, Egor Igorevich Kriuchkov, a 27-year-old Russian, was identified as a member of a larger criminal gang who planned to use the malware to gain access to the company's network, steal sensitive documents, and then extort the victim company for a large ransom payment. To mask the theft of corporate data, Kriuchkov told the employee that other members of his gang would launch DDoS attacks to keep the company's security team distracted.

Kriuchkov and his co-conspirators' plans were, however, upended, when the employee they wanted to recruit reported the incident to the FBI. FBI agents kept Kriuchkov under observation during his stay in the US, and eventually arrested the Russian national on Saturday after they had gathered all the evidence they needed to prosecute.

Network

A Chrome Feature is Creating Enormous Load on Global Root DNS Servers (arstechnica.com) 26

An anonymous reader shares a report: The Chromium browser -- open source, upstream parent to both Google Chrome and the new Microsoft Edge -- is getting some serious negative attention for a well-intentioned feature that checks to see if a user's ISP is "hijacking" non-existent domain results. The Intranet Redirect Detector, which makes spurious queries for random "domains" statistically unlikely to exist, is responsible for roughly half of the total traffic the world's root DNS servers receive. Verisign engineer Matt Thomas wrote a lengthy APNIC blog post outlining the problem and defining its scope. DNS, or the Domain Name System, is how computers translate relatively memorable domain names like arstechnica.com into far less memorable IP addresses, like 3.128.236.93.

Without DNS, the Internet couldn't exist in a human-usable form -- which means unnecessary load on its top-level infrastructure is a real problem. Loading a single modern webpage can require a dizzying number of DNS lookups. When we analyzed ESPN's front page, we counted 93 separate domain names -- from a.espncdn.com to z.motads.com -- which needed to be performed in order to fully load the page! In order to keep the load manageable for a lookup system that must service the entire world, DNS is designed as a many-stage hierarchy. At the top of this pyramid are the root servers -- each top-level domain, such as .com, has its own family of servers that are the ultimate authority for every domain beneath it. One step above those are the actual root servers, a.root-servers.net through m.root-servers.net.

Botnet

A New Botnet Is Covertly Targeting Millions of Servers (wired.com) 27

An anonymous reader quotes a report from Wired: FritzFrog has been used to try and infiltrate government agencies, banks, telecom companies, and universities across the US and Europe. Researchers have found what they believe is a previously undiscovered botnet that uses unusually advanced measures to covertly target millions of servers around the world. The botnet uses proprietary software written from scratch to infect servers and corral them into a peer-to-peer network, researchers from security firm Guardicore Labs reported on Wednesday. Peer-to-peer (P2P) botnets distribute their administration among many infected nodes rather than relying on a control server to send commands and receive pilfered data. With no centralized server, the botnets are generally harder to spot and more difficult to shut down.

The botnet, which Guardicore Labs researchers have named FritzFrog, has a host of other advanced features, including: In-memory payloads that never touch the disks of infected servers; At least 20 versions of the software binary since January; A sole focus on infecting secure shell, or SSH, servers that network administrators use to manage machines; The ability to backdoor infected servers; and A list of login credential combinations used to suss out weak login passwords that's more "extensive" than those in previously seen botnets. Taken together, the attributes indicate an above-average operator who has invested considerable resources to build a botnet that's effective, difficult to detect, and resilient to takedowns. The new code base -- combined with rapidly evolving versions and payloads that run only in memory -- make it hard for antivirus and other end-point protection to detect the malware.

The botnet has so far succeeded in infecting 500 servers belonging to "well-known universities in the US and Europe, and a railway company."Once installed, the malicious payload can execute 30 commands, including those that run scripts and download databases, logs, or files. To evade firewalls and endpoint protection, attackers pipe commands over SSH to a netcat client on the infected machine. Netcat then connects to a "malware server." (Mention of this server suggests that the FritzFrog peer-to-peer structure may not be absolute. Or it's possible that the "malware server" is hosted on one of the infected machines, and not on a dedicated server. Guardicore Labs researchers weren't immediately available to clarify.)

Chrome

Chrome 85 Arrives With Tab Management, 10% Faster Page Loads, and PDF Improvements (venturebeat.com) 62

Google today launched Chrome 85 for Windows, Mac, Linux, Android, and iOS. Chrome 85 brings tab management changes, 10% faster page loads, PDF improvements, and a slew of developer features. From a report: Google is promising under-the-hood performance improvements with Chrome 85. You can expect two types of speed gains: Profile Guided Optimization, which delivers up to 10% faster page loads, and Tab Throttling, which helps reduce the impact of idle background tabs. The latter, however, is coming to the Beta channel meaning it's not yet ready. Profile Guided Optimization is a compiler optimization technique where the most performance-critical parts of the code can run faster. Profile Guided Optimization prioritizes the most common tasks using real usage scenarios that match the workflows of Chrome users around the world.
Privacy

Bridgefy, the Messenger Promoted For Mass Protests, Is a Privacy Disaster (arstechnica.com) 80

Bridgefy, a popular messaging app for conversing with one another when internet connections are heavily congested or completely shut down, is a privacy disaster that can allow moderately-skilled hackers to take a host of nefarious actions against users, according to a paper published on Monday. The findings come after the company has for months touted the app as a safe and reliable way for activists to communicate in large gatherings. Ars Technica reports: By using Bluetooth and mesh network routing, Bridgefy lets users within a few hundred meters -- and much further as long as there are intermediary nodes -- to send and receive both direct and group texts with no reliance on the Internet at all. Bridgefy cofounder and CEO Jorge Rios has said he originally envisioned the app as a way for people to communicate in rural areas or other places where Internet connections were scarce. And with the past year's upswell of large protests around the world -- often in places with hostile or authoritarian governments -- company representatives began telling journalists that the app's use of end-to-end encryption (reiterated here, here, and here) protected activists against governments and counter protesters trying to intercept texts or shut down communications.

[R]esearchers said that the app's design for use at concerts, sports events, or during natural disasters makes it woefully unsuitable for more threatening settings such as mass protests. They wrote: "Though it is advertised as 'safe' and 'private' and its creators claimed it was secured by end-to-end encryption, none of aforementioned use cases can be considered as taking place in adversarial environments such as situations of civil unrest where attempts to subvert the application's security are not merely possible, but to be expected, and where such attacks can have harsh consequences for its users. Despite this, the Bridgefy developers advertise the app for such scenarios and media reports suggest the application is indeed relied upon."

The researchers are: Martin R. Albrecht, Jorge Blasco, Rikke Bjerg Jensen, and Lenka Marekova from Royal Holloway, University of London. After reverse engineering the app, they devised a series of devastating attacks that allow hackers -- in many cases with only modest resources and moderate skill levels -- to take a host of nefarious actions against users. The attacks allow for: deanonymizing users; building social graphs of users' interactions, both in real time and after the fact; decrypting and reading direct messages; impersonating users to anyone else on the network; completely shutting down the network; and performing active man-in-the-middle attacks, which allow an adversary not only to read messages, but to tamper with them as well.
"The key shortcoming that makes many of these attacks possible is that Bridgefy offers no means of cryptographic authentication, which one person uses to prove she's who she claims to be," the report adds. "Instead, the app relies on a user ID that's transmitted in plaintext to identify each person. Attackers can exploit this by sniffing the ID over the air and using it to spoof another user."

The app also uses PKCS #1, an outdated way of encoding and formatting messages so that they can be encrypted with the RSA cryptographic algorithm. "This encoding method, which was deprecated in 1998, allows attackers to perform what's known as a padding oracle attack to derive contents of an encrypted message," reports Ars.
Security

Chinese-Made Smartphones Are Secretly Stealing Money From People Around the World (buzzfeednews.com) 55

An anonymous reader quotes a report from BuzzFeed News: When Mxolosi saw a Tecno W2 smartphone in a store in Johannesburg, South Africa, he was attracted to its looks and functionality. But what really drew him in was the price, roughly $30 -- far less than comparable models from Samsung, Nokia, or Huawei, Africa's other top brands. It was another sale for Transsion, the Chinese company that makes Tecno and other low-priced smartphones, as well as basic handsets, for the developing world. Since releasing its first smartphone in 2014, the upstart has grown to become Africa's top handset seller, beating out longtime market leaders Samsung and Nokia. But its success can come at a price. Mxolosi, an unemployed 41-year-old, became frustrated with his Tecno W2. Pop-up ads interrupted his calls and chats. He'd wake up to find his prepaid data mysteriously used up and messages about paid subscriptions to apps he'd never asked for.

He thought it might be his fault, but according to an investigation by Secure-D, a mobile security service, and BuzzFeed News, software embedded in his phone right out of the box was draining his data while trying to steal his money. Mxolosi's Tecno W2 was infected with xHelper and Triada, malware that secretly downloaded apps and attempted to subscribe him to paid services without his knowledge. Secure-D's system, which mobile carriers use to protect their networks and customers against fraudulent transactions, blocked 844,000 transactions connected to preinstalled malware on Transsion phones between March and December 2019. Secure-D Managing Director Geoffrey Cleaves told BuzzFeed News that Mxolosi's data was used up by the malware as it attempted to subscribe him to paid services. Along with South Africa, Tecno W2 phones in Ethiopia, Cameroon, Egypt, Ghana, Indonesia, and Myanmar were infected.

IT

Zoom Outage Halts Classes, Meetings (axios.com) 46

Videoconferencing software Zoom experienced a widespread outage Monday morning with many users unable to join or launch video meetings. From a report: Why it matters: During the coronavirus pandemic, Zoom has become the go-to solution for many businesses and schools trying to function remotely. What they're saying: "We have identified the issue causing users to be unable to start and join Zoom Meetings and Webinars and are working on a fix for this issue," Zoom said in a statement to Axios. "We sincerely apologize for any inconvenience." The issue has been resolved.
Bitcoin

Is Blockchain 'the Amazing Solution for Almost Nothing'? (thecorrespondent.com) 155

Long-time Slashdot reader leathered shares an investigation from the Correspondent about blockchain -- and " what's so terribly revolutionary about it? What problem does it solve...? I can tell you upfront, it's a bizarre journey to nowhere. I've never seen so much incomprehensible jargon to describe so little... And I've never seen so many people searching so hard for a problem to go with their solution...." [Y]ou can't do much with bitcoin. But blockchain, on the other hand: it's the technology behind bitcoin, which makes it cool. Blockchain generalises the bitcoin pitch: let's not just get rid of banks, but also the land registry, voting machines, insurance companies, Facebook, Uber, Amazon, the Lung Foundation, the porn industry and government and businesses in general. They are superfluous, thanks to the blockchain. Power to the users...!

The only thing is that there's a huge gap between promise and reality. It seems that blockchain sounds best in a PowerPoint slide. Most blockchain projects don't make it past a press release, an inventory by Bloomberg showed... Out of over 86,000 blockchain projects that had been launched, 92% had been abandoned by the end of 2017, according to consultancy firm Deloitte. Why are they deciding to stop? Enlightened — and thus former — blockchain developer Mark van Cuijk explained: "You could also use a forklift to put a six-pack of beer on your kitchen counter. But it's just not very efficient...."

[I]nformation and communications technology is like the rest of the world — a big old mess. And that's something that we — outsiders, laypeople, non-tech geeks — simply refuse to accept. Councillors and managers think that problems — however large and fundamental they are — evaporate instantaneously thanks to technology they've heard about in a fancy PowerPoint presentation. How will it work? Who cares! Don't try to understand it, just reap the benefits!

This is the market for magic, and that market is big. Whether it's about blockchain, big data, cloud computing, AI or other buzzwords...

Maybe this is blockchain's greatest merit: it's an awareness campaign, albeit an expensive one. "Back-office management" isn't an item on the agenda in board meetings, but "blockchain" and "innovation" are... Yes, it took a few wild, unmet promises, but the result is that administrators are now interested in the boring subjects that help make the world run a bit more efficiently — nothing spectacular, just a bit better.

Windows

Microsoft Removes Registry Tweak That Allowed Users To Permanently Disable Windows Defender (pcgamer.com) 126

An anonymous reader quotes a report from PC Gamer: A recent update to Windows 10 took away the ability for consumers to permanently disable Defender, the built-in antivirus software, no matter what the reason. However, Defender should voluntarily step aside if it detects the installation of a third-party AV program (emphasis on should). Before the update, if a user wanted to disable Defender on a permanent basis, they could edit a registry key called DisableAntiSpyware. That is no longer the case.

"DisableAntiSpyware is intended to be used by OEMs and IT Pros to disable Microsoft Defender Antivirus and deploy another antivirus product during deployment. This is a legacy setting that is no longer necessary as Microsoft Defender antivirus automatically turns itself off when it detects another antivirus program. This setting is not intended for consumer devices, and we've decided to remove this registry key," Microsoft explains in a support document.

Security

'DiceKeys' Creates a Master Password For Life With One Roll (wired.com) 98

Stuart Schechter, a computer scientist at the University of California, Berkeley, is launching DiceKeys, a simple kit for physically generating a single super-secure key that can serve as the basis for creating all the most important passwords in your life for years or even decades to come. Wired reports: With little more than a plastic contraption that looks a bit like a Boggle set and an accompanying web app to scan the resulting dice roll, DiceKeys creates a highly random, mathematically unguessable key. You can then use that key to derive master passwords for password managers, as the seed to create a U2F key for two-factor authentication, or even as the secret key for cryptocurrency wallets. Perhaps most importantly, the box of dice is designed to serve as a permanent, offline key to regenerate that master password, crypto key, or U2F token if it gets lost, forgotten, or broken.

Schechter intends for most DiceKeys users to only ever roll their set once. After shaking the keys in a bag, the user dumps them into their plastic box, then snaps the lid closed to permanently lock them into place. The user then scans the dice box with the DiceKeys app -- currently a web app hosted at DiceKeys.app -- that accesses their laptop, phone, or iPad camera. That app generates a cryptographic key based on the dice, checking the barcode-like symbols on the faces to ensure it interpreted the dice's characters and orientation correctly. Despite the current version of the DiceKeys app being hosted on the web, Schechter says that it's designed so that no data ever leaves the user's device. Thanks to the different numbers and letters on each key face as well as the dices' orientations, the resulting arrangement has around 196 bits of entropy, Schechter says, meaning there are 296 different possibilities for how the dice could be positioned. Schechter estimates that's roughly as many possibilities as there are atoms in four or five thousand solar systems.

Security

Former Uber Exec Charged With Paying 'Hush Money' To Conceal Massive Breach (npr.org) 13

Federal prosecutors have charged Uber's former chief security officer with covering up a massive 2016 data breach by arranging a $100,000 payoff to the hackers responsible for the attack. The personal data of 57 million Uber passengers and drivers was stolen in the hack. NPR reports: Prosecutors are charging the former executive Joe Sullivan with obstructing justice and concealing a felony for the alleged cover-up. Sullivan "engaged in a scheme to withhold and conceal" the breach from regulators and failed to report it to law enforcement or the public, according to a complaint filed in federal court in California on Thursday.

"Sullivan is being charged with a corporate cover-up and Sullivan is being charged with the payment of hush money to conceal something that should have been revealed," David Anderson, U.S. attorney for the Northern District of California, told NPR. Sullivan not only allegedly hid the breach from authorities, but also concealed it from many other Uber employees, including top management -- with one exception. According to the complaint, Uber's CEO at the time, Travis Kalanick, knew about the incident and about the steps Sullivan took to allegedly cover it up, including making the $100,000 payout under Uber's "bug bounty" program. Kalanick has not been charged and wouldn't comment for this story.

Like many tech companies, Uber pays so-called "white hat" hackers to test its systems for vulnerabilities. But the payment Uber made in this case was much larger than any bug bounty it had paid before, the complaint said, noting the company's program "had a nominal cap of $10,000." Uber required the hackers to sign nondisclosure agreements, also not standard practice for a bug bounty, the complaint alleged. Those agreements falsely said that the hackers did not take or store any data. "The problem is that this hush money payment was not a bug bounty," Anderson said. "We allege that this entire course of conduct reflects [Sullivan's] consciousness of guilt and desperation to conceal."

Slashdot Top Deals