Security

The Vatican Is Said To Be Hacked From China Before Talks With Beijing (nytimes.com) 55

An anonymous reader quotes a report from The New York Times: Chinese hackers infiltrated the Vatican's computer networks in the past three months , a private monitoring group has concluded, in an apparent espionage effort before the beginning of sensitive negotiations with Beijing. The attack was detected by Recorded Future, a firm based in Somerville, Mass. The Chinese Communist Party has been waging a broad campaign to tighten its grip on religious groups, in what government leaders have periodically referred to as an effort to "Sinicize religions" in the country.

China officially recognizes five religions, including Catholicism, but the authorities often suspect religious groups and worshipers of undermining the control of the Communist Party and the state, and of threatening the country's national security. Chinese hackers and state authorities have often used cyberattacks to try to gather information on groups of Buddhist Tibetans, Muslim Uighurs and Falun Gong practitioners outside China. But this appears to be the first time that hackers, presumed by cybersecurity experts at Recorded Future to be working for the Chinese state, have been publicly caught directly hacking into the Vatican and the Holy See's Study Mission to China, the Hong Kong-based group of de facto Vatican representatives who have played a role in negotiating the Catholic Church's status. The Vatican and Beijing are expected to start talks in September over control of the appointment of bishops and the status of houses of worship as part of a renewal of a provisional agreement signed in 2018 that revised the terms of the Catholic Church's operations in China.
One of the attacks, which began in early May, was hidden inside a document that appeared to be a legitimate letter from the Vatican to Msgr. Javier Corona Herrera, the chaplain who heads the study mission in Hong Kong," reports The New York Times.

"It was an artful deception: an electronic file that looked as if it was on the official stationery of Archbishop Edgar Pena Parra. The letter carried a message from Cardinal Pietro Parolin, the Vatican's secretary of state, the pope's second in command and an old China hand who has defended the deal. In his message, Cardinal Parolin expressed the pope's sadness about the death of a bishop. It is unclear whether the letter was fabricated or a real document that the attackers had obtained and then linked to malware that gave them access to the computers of the Hong Kong church offices and the Vatican's mail servers. Recorded Future concluded that the attack was most likely connected to negotiations over the extension of the 2018 agreement."
Security

Alcohol Delivery Service Drizly Confirms Data Breach (techcrunch.com) 15

An anonymous reader quotes a report from TechCrunch: Online alcohol delivery startup Drizly has told customers that it was hit by a data breach. In an email to customers obtained by TechCrunch, the company said that a hacker "obtained" some customer data. The hacker took customer email addresses, date-of-birth, hashed passwords, and in some cases delivery addresses, the email read. Some 2.4 million Drizly accounts are believed to have been stolen. TechCrunch obtained a portion of the data, including several accounts of Drizly staff members. We verified the data against public records. The portion of data we obtained also contains user phone numbers, IP addresses, and geolocation data associated with the user's billing address.

Drizly did not say when the hack occurred or how many accounts were affected, but did advise users to change their passwords. The company said that no financial data was taken in the breach. But a listing on a dark web marketplace from a well-known seller of stolen data claims otherwise. The listing, which we are not linking to, claims to have "fresh hacked" [sic] Drizly accounts. The data is on sale for $14, at the time of writing . The seller did not say when the breach took place, but the listing appears to have been posted on February 13. Although no sample of data was offered, the listing claims to have valid Drizly credit card numbers and users' order history.

Security

Election Officials Are Vulnerable To Exim Security Vulnerability, Report Shows (thehill.com) 41

whh3 writes: The Wall Street Journal has an "exclusive" scoop about a report detailing that several counties host their own mail servers using a version of Exim that is vulnerable to exploitation (Warning: source paywalled; alternative source), exposing electing officials to potential interference during the upcoming cycle. "[Cybersecurity vendor Area 1 Security Inc.] found that officials in six small jurisdictions in Michigan, Missouri, Maine and New Hampshire, for example, were using a buggy version of a free software product called Exim, which has been linked to online attacks conducted by the Russian intelligence service known as the GRU," reports The Wall Street Journal. The report itself is online here. "The report, compiled by cybersecurity group Area 1 Security, found that over 50 percent of election administrators have 'only rudimentary or non-standard technologies' to protect against malicious emails from cyber criminals, with less than 30 percent using basic security controls to halt phishing emails," adds The Hill. "The study also found that around 5 percent of election administrators use personal emails, which are seen as less secure than government emails."

The researchers wrote in the report: "The disparate approaches to cybersecurity by state, local and county officials is such that should a cybersecurity incident occur in one small town, whether in a 'battleground state' or not, even if statistically insignificant, could cause troubling ripple effects that erode confidence in results across the entire country." They noted that 90 percent of cyberattacks begin with a phishing email.
Security

Garmin Begins Recovery From Ransomware Attack (bbc.com) 19

An anonymous reader quotes a report from the BBC: The American GPS and fitness-tracker company Garmin is dealing with the aftermath of a ransomware attack, the BBC has confirmed. Owners of its products had been unable to use its services since Thursday. However, some of its online tools are now being provided in a "limited" state, according to its online dashboard. Garmin has said it was "the victim of a cyber-attack that encrypted some of our systems." But the statement it released avoided any reference to a ransom demand.

"Many of our online services were interrupted including website functions, customer support, customer-facing applications, and company communications," it said. "We have no indication that any customer data, including payment information from Garmin Pay, was accessed, lost or stolen." The firm added that it expected all its systems to return to normal operation within a few days, but warned that there might be a "backlog" of user data to process. It is not known if the firm paid the blackmailers, but a source told the BBC it was in the "final stage of recovery." Some customers have already reported that Garmin's services appear to be "partially" working again.

Windows

You Can Now Boot a Windows 95 PC Inside Minecraft and Play Doom On It (theverge.com) 84

If you've ever wanted to build a real and working Windows 95 PC inside Minecraft, now is the time. From a report: A new VM Computers mod has been created for Minecraft that allows players to order computer parts from a satellite orbiting around a Minecraft world and build a computer that actually boots Windows 95 and a variety of other operating systems. The mod uses VirtualBox, free and open-source virtual machine software, to run operating systems like Windows 95. Within Minecraft you simply place a PC case block and then use it to create virtual hard drives to install operating systems from ISO files. Naturally, the Minecraft community has been experimenting with the VM Computers mod, and someone has managed to get Doom running within Minecraft as a result.
Nintendo

Huge Apparent Leak Unearths Nintendo's Prototype History (arstechnica.com) 21

An anonymous reader quotes a report from Ars Technica: A massive leak of apparent Nintendo source code is giving gamers a rare, unauthorized look at Nintendo's development process dating back to the Super NES era. The massive trove of files, first posted to 4chan Friday and quickly dubbed the "Gigaleak" by the community, includes compilable code and assets for Super NES, Game Boy, and N64 games in the Mario, Mario Kart, Zelda, F-Zero, and Pokemon series. Hidden among that code is a bevy of pre-release art and sound files that have never seen the light of day, as well as fully playable prototype versions of some games. Modders and homebrew developers have been digging through the trove of data over the weekend and taking to Twitter and YouTube with their discoveries. Among the most interesting findings:

- A version of Super Mario 64 including data for a 3D model of Luigi (likely for the scrapped two-player mode). Players have inserted that model into the ROM to create video of Luigi running around. The leak also includes few unused test rooms for the game.
- A Yoshi's Island prototype featuring differences in the map screen, interface, music (and including the prefix "Super Mario Bros. 5" in Japanese). The prototype also features two apparently unused mini-games (No. 1, No. 2) and some unused test levels.
- Pokemon prototypes featuring early and unused sprite designs for many monsters.
- An original prototype named "Super Donkey" featuring a Rayman-style character in a Yoshi's Island-styled world [Update: A previous version of this post mischaracterized the music in this video. Ars regrets the error].
- Sprite data for Luigi giving an apparent middle finger and Bowser outside of his clown-copter in Super Mario World. The code also contains multiple early designs for Yoshi (some of which match art previously revealed in interviews with Nintendo developers) and a completely new map screen design (which also matches previously revealed screenshots).
- A version of Star Fox 2 with previously unseen characters.
- High-quality voice samples from Star Fox 64, F-Zero X and Super Mario 64 before they were compressed to fit on relatively small N64 cartridges.
- Graphics for a Pilotwings prototype called Dragonfly, previously seen only in grainy magazine screenshots.

Security

Hackers Stole GitHub and GitLab OAuth Tokens From Git Analytics Firm Waydev (zdnet.com) 28

Waydev, an analytics platform used by software companies, has disclosed a security breach that occurred earlier this month. From a report: The company says that hackers broke into its platform and stole GitHub and GitLab OAuth tokens from its internal database. Waydev, a San Francisco-based company, runs a platform that can be used to track software engineers' work output by analyzing Git-based codebases. To do this, Waydev runs a special app listed on the GitHub and GitLab app stores. When users install the app, Waydev receives an OAuth token that it can use to access its customers' GitHub or GitLab projects. Waydev stores this token in its database and uses it on a daily basis to generate analytical reports for its customers. Waydev CEO and co-founder Alex Circei told ZDNet today in a phone call that hackers used a blind SQL injection vulnerability to gain access to its database, from where they stole GitHub and GitLab OAuth tokens. The hackers then used some of these tokens to pivot to other companies' codebases and gain access to their source code projects.
Australia

Australian Regulator Says Google Misled Users Over Data Privacy Issues (reuters.com) 11

Australia's competition regulator on Monday accused Alphabet's Google of misleading consumers to get permission for use of their personal data for targeted advertising, seeking a fine "in the millions" and aiming to establish a precedent. From a report: The move comes as scrutiny grows worldwide over data privacy, with U.S. and European lawmakers recently focusing on how tech companies treat user data. In court documents, the Australian Competition and Consumer Commission (ACCC) accused Google of not explicitly getting consent or properly informing consumers of a 2016 move to combine personal information in Google accounts with browsing activities on non-Google websites. "This change ... was worth a lot of money to Google," said commission chairman Rod Sims. "We allege they've achieved it through misleading behaviour." The change allowed Google to link the browsing behaviour of millions of consumers with their names and identities, providing it with extreme market power, the regulator added. "We consider Google misled Australian consumers about what it planned to do with large amounts of their personal information, including internet activity on websites not connected to Google," Sims said.
Security

Digital Banking Site 'Dave' Admits Security Breach Impacting 7.5 Million Users (zdnet.com) 21

"Digital banking app and tech unicorn Dave.com confirmed today a security breach," reports ZDNet, "after a hacker published the details of 7,516,625 users on a public forum." In an email to ZDNet today, Dave said the security breach originated on the network of a former business partner, Waydev, an analytics platform used by engineering teams... The company said it has already plugged the hacker's point of entry and is in the process of notifying customers of the incident. Dave app passwords are also being reset after being exposed.

"As soon as Dave became aware of this incident, the company immediately initiated an investigation, which is ongoing, and is coordinating with law enforcement, including with the FBI around claims by a malicious party that it has 'cracked' some of these passwords and is attempting to sell Dave customer data," Dave said. The company also brought in cyber-security firm CrowdStrike to assist the investigation...

The data includes a wealth of information, such as real names, phone numbers, emails, birth dates, and home addresses.

Security

Vigilante Sabotages Malware Botnet By Replacing Payloads With Animated GIFs (zdnet.com) 16

An anonymous reader writes: An unknown vigilante hacker has been sabotaging the operations of the recently-revived Emotet botnet by replacing Emotet payloads with animated GIFs, effectively preventing victims from getting infected. The sabotage, which started on July 21, has grown from a simple joke to a serious issue impacting a large portion of the Emotet operation, reducing the biggest malware botnet today to a quarter of its daily capabilities.

Since the attack started, the vigilante has replaced Emotet payloads with this Blink 182 "WTF" GIF, a James Franco GIF, and the Hackerman GIF from the Kung Fury movie.

The article points out this is all possible because Emotet stashes its malware on Wordpress sites they've breached with web shells — all of which have the exact same password.
IT

Is Work Easier For 'Digital Nomads'? (forbes.com) 40

A digital nomad describes what no one ever warns you about after selling everything and then travelling to Singapore, Malaysia, Vietnam, and Thailand "before doing the Working Holiday Visa thing in Australia and New Zealand." It was the greatest solo travel adventure of my life and I loved it. That said, I've had some time to reflect on my experience and there are some things I wish I'd known before diving in headfirst... [I]n reality, you're working just as hard, only from a different place. You still have deadlines...and you still have to hound clients who take forever to pay you after your project is done.

Did I mention that this is all done in a completely different time zone from the people you're working with? This can also be tricky when it comes to conference calls but nothing you can't figure out and plan for.

While you may have given yourself a more beautiful backdrop to work with, you're still going to spend a decent amount of time behind your laptop wherever you go, though on the bright side, you will also have the opportunity to work alongside the locals, hear different accents, taste new and amazing food and check out your new surroundings whenever you're off, so it's all good...

I once spent six months living "on the road" as a digital nomad, which felt like a nice long extended trip (rather than settling for an exotic one-week vacation). But it'd be interesting to hear anecdotes from Slashdot's readers — so share your own thoughts and experiences in the comments.

And is work easier for digital nomads?
Databases

'Meow' Attack Has Now Wiped Nearly 4,000 Databases (arstechnica.com) 54

On Thursday long-time Slashdot reader PuceBaboon wrote: Ars Technica is reporting a new attack on unprotected databases which, to date, has deleted all content from over 1,000 ElasticSearch and MongoDB databases across the 'net, leaving the calling-card "meow" in its place.

Most people are likely to find this a lot less amusing than a kitty video, so if you have a database instance on a cloud machine, now would be a good time to verify that it is password protected by something other than the default, install password...

From the article: The attack first came to the attention of researcher Bob Diachenko on Tuesday, when he discovered a database that stored user details of the UFO VPN had been destroyed. UFO VPN had already been in the news that day because the world-readable database exposed a wealth of sensitive user information... Besides amounting to a serious privacy breach, the database was at odds with the Hong Kong-based UFO's promise to keep no logs. The VPN provider responded by moving the database to a different location but once again failed to secure it properly. Shortly after, the Meow attack wiped it out.
"Attacks have continued and are getting closer to 4,000," reports Bleeping Computer. "A new search on Saturday using Shodan shows that more than 3,800 databases have entry names matching a 'meow' attack. More than 97% of them are Elastic and MongoDB."
Encryption

State-of-the-Art Crypto Goes Post-Quantum (with Containerized TinySSH) (opensource.com) 40

emil (Slashdot reader #695) writes: The advent of quantum computing poses a well-recognized threat to RSA and other well-known asymmetric cryptosystems. It has been four years since NIST opened the post-quantum cryptography competition, and we are seeing extensive delays compared to AES.

A new and (hopefully) quantum-secure SSH key exchange, based on NTRU Prime, has been present in OpenSSH since January 2019, first implemented in TinySSH shortly before. This key exchange is marked by OpenSSH as experimental, and not enabled by default.

For those ready to evaluate NTRU Prime, or otherwise seeking an SSH server with "state-of-the-art crypto" (as described by TinySSH author Jan Mojí), a complete procedure for a Musl build and Busybox container deployment is presented, with additional focus on supplemental servers and key conversion.

Republicans

Trump Campaign Angry That Cell Carriers Blocked Company Texts To Voters (arstechnica.com) 103

An anonymous reader quotes a report from Ars Technica: President Trump's re-election campaign has accused Verizon, AT&T, and T-Mobile of "suppression of political speech" over the carriers' blocking of spam texts sent by the campaign. The fight was described Wednesday in an in-depth article by Business Insider and other reports. "The Trump campaign has been battling this month with the biggest US cellphone carriers over an effort to blast millions of cell users with texts meant to coax them to vote or donate," Business Insider wrote. "President Donald Trump's adviser and son-in-law, Jared Kushner, didn't appreciate it when AT&T, Verizon, and T-Mobile blocked mass campaign texts to voters. He called the companies to complain, setting off the legal wrangling."

When contacted by Ars, a Trump campaign spokesperson said that "any effort by the carriers to restrict the campaign from contacting its supporters is suppression of political speech. Plain and simple." The Trump campaign statement also said it "stands by the compliance of its texting programs" with the US Telephone Consumer Protection Act (TCPA) and Federal Communications Commission guidelines. Business Insider wrote that "the showdown got serious at the start of July when Trump's team sent a blast of texts to people who hadn't signed up for them," and "a third-party firm hired to screen such messages for the major cellphone companies blocked the texts." The article said that campaign lawyers and the carriers "are still fighting over what kinds of messages the campaign is allowed to send and what the companies have the power to stop." Politico wrote about the dispute on Monday. "People familiar with the chain of events said Verizon, T-Mobile and AT&T flagged potential regulatory problems with the peer-to-peer messaging operation, which differs from robo-texting in that texts are sent individually, as opposed to a mass blast," Politico wrote. "But within Trump's orbit, the episode has further fueled suspicions that big tech companies are looking to influence the election."
The Trump campaign has not explained why the texts are legal and shouldn't have been blocked. They also didn't say how many people they tried to send the texts to, or whether the texts were unsolicited or sent to people who had signed up for campaign communications.

Carriers "viewed the texts as a possible violation of federal anti-robocall laws and Federal Communications Commission rules that come with hefty fines," Business Insider reported, citing information provided by "two Republicans familiar with the effort." Trump "campaign operatives" contend that its texting "exists in a legal gray area that allows campaigns to blast cellphone users if the messages are sent manually," Business Insider also wrote.
IT

Indian IT Consultancies Struggle Against Technological Obsolescence (economist.com) 64

Few people outside their home country have heard of Tata Consultancy Services (TCS), Infosys, Wipro, HCL Technologies or Tech Mahindra, India's five biggest information technology (IT) consultancies. Yet even when enterprise software to manage marketing, production, inventory and the like comes from Oracle of America or Germany's SAP, it is often the Indian companies that install and maintain software for clients. But for all their tech nous, the Indian giants have also been unable to keep pace with technological change. The Economist (may be paywalled): Corporate software is becoming easier to use, reducing demand for their services. The lucrative legacy business of running mainframes is evaporating. Helping clients shift to the cloud makes money but not nearly as much. Despite some interesting pilot projects -- such as Tech Mahindra's use of artificial intelligence to tell apart 1,645 Indian languages or Infosys's covid-19 contact-tracing in Rhode Island -- the consultancies have not come up with a killer app, let alone powerful platforms like those of America's big tech firms.

Worse still, multinationals are increasingly reluctant to outsource their IT. Rather than hire the consultants, many are creating subsidiaries in India to do the job in-house -- sucking away both custom and workers from the consultancies. Before the pandemic India hosted more than 1,400 of these so-called "captive centres", employing a total of more than 1m people, according to an analysis by the Ken, an Indian news website; around 70% of them were owned by big American firms. Walmart Labs India, owned by the American supermarket chain, is reportedly on course to double its staff numbers to 7,000 in the next year or two. The popularity of such in-house operations has to do with the changing economics of technology. This once required armies of people, so spreading costs among many clients made sense. With falling prices of hardware and software, and more skilled workers around, a captive centre can pay for itself with just 50 employees, says Peter Bendor Samuel of the Everest Group, a research firm.

China

FBI Warns US Companies About Backdoors In Chinese Tax Software (zdnet.com) 36

An anonymous reader writes: The US Federal Bureau of Investigation has sent an alert on Thursday warning US companies about backdoor malware that is silently being installed on the networks of foreign companies operating in China via government-mandated tax software. The backdoors allow threat actors to execute unauthorized code, infiltrate networks, and steal proprietary data from branches operating in China. Making matters worse, the FBI says that all foreign companies are required by local Chinese laws to install this particular piece of software in order to handle value-added tax (VAT) payments to the Chinese tax authority. FBI officials said the backdoor malware was spotted in the VAT software of two Chinese tech companies -- namely Baiwang and Aisino. Unfortunately, these are the only government-authorized tax software service providers allowed to operate VAT software in China, officials said, suggesting that any foreign company operating in China was most likely affected by this issue.
Twitter

More Than 1,000 People at Twitter Had Ability To Aid Hack of Accounts (reuters.com) 29

More than a thousand Twitter employees and contractors as of earlier this year had access to internal tools that could change user account settings and hand control to others, Reuters is reporting citing two former employees said, making it hard to defend against the hacking that occurred last week. From the report: Twitter and the FBI are investigating the breach that allowed hackers to repeatedly tweet from verified accounts of the likes of Democratic presidential candidate Joe Biden, billionaire philanthropist Bill Gates, Tesla Chief Executive Elon Musk and former New York Mayor Mike Bloomberg. Twitter said on Saturday that the perpetrators "manipulated a small number of employees and used their credentials" to log into tools and turn over access to 45 accounts. here On Wednesday, it said that the hackers could have read direct messages to and from 36 accounts but did not identify the affected users.
Businesses

Who Still Needs the Office? US Companies Start Cutting Space (reuters.com) 158

An anonymous reader quotes a report from Reuters: Corporate America is downsizing its real estate footprint as companies allow more employees to work from home, a growing threat to the bottom line of owners of traditional office buildings and a sign that companies are looking for ways to cut costs as a result of the coronavirus pandemic. A Reuters analysis of quarterly earnings calls over the past week revealed more than 25 large companies plan to reduce their office space in the year ahead, a move designed to reduce the second-largest expense after payrolls at corporations.

Energy company Halliburton Co said it intends to close more than 100 facilities. Financial services company State Street Corp said it is going to nearly double the workers assigned to one office before adding additional space, based on the assumption that a significant portion of its workforce will continue to work from home even after a vaccine for COVID-19 emerges. Bedding company Sleep Number Corp plans to slow the growth of its total square footage as more consumers shop online. Analysts say the plans to cut back on real estate are likely the first wave of cost-cutting measures to hit office workers as companies try to maintain margins going into what may be a long recession. So far, the majority of the 14.7 million U.S. jobs lost during the pandemic have been in hard-hit areas such as restaurants, travel and retailers. Reductions in office spending could likely be followed by layoffs and investments in technology that should help improve productivity with a reduced workforce, said Bill McMahon, chief investment officer of active equity strategies at Charles Schwab.
According to Morgan Stanley, vacancy rates in New York will reach 10%-12% in the next two to five years from 8.7% now, while San Francisco will reach 7-9% from 5.8%.

"Green Street Advisors expects that office demand will be reduced by up to 15% as a result of work from home policies once the coronavirus pandemic is contained," adds Reuters. "That reduction in necessary space will most likely hurt real estate investment firms with large exposures in cities such as San Francisco and New York as workers are expected to be given more freedom by employers to live in lower-cost areas away from the coasts."
Security

Garmin Services and Production Go Down After Ransomware Attack (zdnet.com) 22

An anonymous reader quotes a report from ZDNet: Smartwatch and wearables maker Garmin has shut down several of its services today to deal with a ransomware attack that has encrypted its internal network and some production systems. The company is currently planning a multi-day maintenance window to deal with the attack's aftermath, which includes shutting down its official website, the Garmin Connect user data-syncing service, and even some production lines in Asia. In messages shared on its website and Twitter, Garmin said the same outage also impacted its call centers, leaving the company in the situation of being unable to answer calls, emails, and online chats sent by users. The incident didn't go unnoticed today and has caused lots of headaches for the company's customers, most of which rely on the Garmin Connect service to sync data about runs and bike rides to Garmin's servers, all of which have been down today. Some Garmin employees are attributing the incident to a new strain of ransomware that appeared earlier this year, called WastedLocker, though this has not yet been verified.
China

Popular Chinese-Made Drone Is Found To Have Security Weakness (nytimes.com) 60

Cybersecurity researchers revealed on Thursday a newfound vulnerability in an app that controls the world's most popular consumer drones, threatening to intensify the growing tensions between China and the United States. From a report: In two reports, the researchers contended that an app on Google's Android operating system that powers drones made by China-based Da Jiang Innovations, or DJI, collects large amounts of personal information that could be exploited by the Beijing government. Hundreds of thousands of customers across the world use the app to pilot their rotor-powered, camera-mounted aircraft. The world's largest maker of commercial drones, DJI has found itself increasingly in the cross hairs of the United States government, as have other successful Chinese companies. The Pentagon has banned the use of its drones, and in January the Interior Department decided to continue grounding its fleet of the company's drones over security fears. DJI said the decision was about politics, not software vulnerabilities.

For months, U.S. government officials have stepped up warnings about the Chinese government's potentially exploiting weaknesses in tech products to force companies there to give up information about American users. Chinese companies must comply with any government request to turn over data, according to American officials. "Every Chinese technology company is required by Chinese law to provide information they obtain, or information stored on their networks, to Chinese authorities if requested to do so," said William R. Evanina, director of the National Counterintelligence and Security Center. "All Americans should be concerned that their images, biometrics, locational and other data stored on Chinese apps must be turned over to China's state security apparatus." The drone vulnerability, said American officials, is the kind of security hole that worries Washington.

Slashdot Top Deals