Privacy

Security Breach Exposes More Than One Million DNA Profiles On Major Genealogy Database (buzzfeednews.com) 28

An anonymous reader quotes a report from BuzzFeed News: On July 19, genealogy enthusiasts who use the website GEDmatch to upload their DNA information and find relatives to fill in their family trees got an unpleasant surprise. Suddenly, more than a million DNA profiles that had been hidden from cops using the site to find partial matches to crime scene DNA were available for police to search. The news has undermined efforts by Verogen, the forensic genetics company that purchased GEDmatch last December, to convince users that it would protect their privacy while pursuing a business based on using genetic genealogy to help solve violent crimes.

A second alarm came on July 21, when MyHeritage, a genealogy website based in Israel, announced that some of its users had been subjected to a phishing attack to obtain their log-in details for the site -- apparently targeting email addresses obtained in the attack on GEDmatch just two days before. In a statement emailed to BuzzFeed News and posted on Facebook, Verogen explained that the sudden unmasking of GEDmatch profiles that were supposed to be hidden from law enforcement was "orchestrated through a sophisticated attack on one of our servers via an existing user account." "As a result of this breach, all user permissions were reset, making all profiles visible to all users. This was the case for approximately 3 hours," the statement said. "During this time, users who did not opt in for law enforcement matching were available for law enforcement matching and, conversely, all law enforcement profiles were made visible to GEDmatch users." It's unclear whether any unauthorized profiles were searched by law enforcement.

IOS

Apple Will Start Sending Special Devices To iPhone Hackers (vice.com) 13

Apple has announced that it will send special devices that make it easier to find flaws and vulnerabilities in its mobile operating system iOS to iPhone hackers that apply and qualify for a program the company announced last year. From a report: The program might make some hackers less likely to engage in the underground market for stolen prototype iPhones hackers currently use to research iPhone security, and encourage them to share their findings with Apple. In a new website published on Wednesday, Apple wrote that the program "features an iPhone dedicated exclusively to security research, with unique code execution and containment policies." It's called the Security Research Device Program. Security researchers can apply for it starting today and Apple told Motherboard that if they qualify they will receive the devices soon. Apple doesn't have a goal in terms of how many of these devices it wants to send out, and all you need to qualify is having a public track record of security research, not only on iPhone but also on other popular devices and software like Android phones, Windows, or Linux.
Google

Gmail Is About To Start Testing Verification-Like Logos For Email (engadget.com) 44

One of the biggest announcements made in Google's recent announcement of security enhancements for G Suite services is that authenticated logos are coming for emails from participating companies. Engadget reports: Last year Google announced it joined the Brand Indicators for Message Identification (BIMI) group, which is pushing an email spec that adds brand logos to authenticated emails. In practice it seems a lot like the verified stamps that have proliferated across social media, but when you see them it won't be a blue check, it will be the logo of the company that sent the email (Example). Emails are authenticated using the existing DMARC system and then there's certification that applies the associated logo, which hopefully gives people trust an email came from the company or person it's claiming to represent. Google said it will kick off a pilot of the technology within Gmail "in the coming weeks," so don't be surprised when you see those kinds of indicators popping up in the existing avatar box.
Crime

'World's Most Wanted Man' Involveld In Bizarre Attempt To Buy Hacking Tools (vice.com) 27

An anonymous reader quotes a report from Motherboard: The fugitive executive of the embattled payment startup Wirecard was mentioned in a brazen and bizarre attempt to purchase hacking tools and surveillance technology from an Italian company in 2013, an investigation by Motherboard and the German weekly Der Spiegel found. Jan Marsalek, a 40-year-old Austrian who until recently was the chief operating officer of the rising fintech company Wirecard, seems to have taken a meeting with the infamous Italian surveillance technology provider Hacking Team in 2013. At the time, Marsalek is described as an official representative of the government of Grenada, a small Caribbean island of around 100,000 people, in a letter that bears the letterhead of the Grenada government. The documents were included in a cache published after Hacking Team was hacked in 2015. In recent days, Marsalek has been described as the 'world's most wanted man.'

It is unclear from the documents alone whether Marsalek played any role in the attempt to procure hacking tools, or whether his name was simply used. However, months before Marsalek appears to have contacted with Hacking Team, several websites with official sounding names such as StateOfGrenada.org were registered under the name of Jan Marsalek, as Der Spiegel reported last week. Some of the sites were registered with Marsalek's phone number and his Munich address at the time, and the servers were apparently operated from Germany. Wirecard provided digital payment services and was considered one of the most important companies in the financial tech industry. Wirecard offered a mobile payment app called Boon, which was essentially a virtual MasterCard card, it also offered a prepaid debit card called mycard2go, and worked with companies such as KLM, Rakuten, and Qatar Airways to manage their online transactions. The company suddenly collapsed in June after German regulators raided its headquarters as part of an investigation into fraudulent stock price manipulation and 1.9 billion euros that are missing from the company's books. Marsalek is now a fugitive and a key suspect in the German investigation. He reportedly fled to Belarus, and is now hiding in Russia under the protection of the FSB, according to German news reports. In the past, he was involved in other strange dealings: he bragged about an attempt to recruit 15,000 Libyan militiamen, and about a trip to Syria along with Russian military, according to the Financial Times.

Security

Ransomware Gang Demands $7.5 Million From Argentinian ISP (zdnet.com) 29

A ransomware gang has infected the internal network of Telecom Argentina, one of the country's largest internet service providers, and is now demanding $7.5 million as ransom to unlock encrypted files. From a report: The incident took place over the weekend, on Saturday, July 18, and is considered one of Argentina's biggest hacks. Sources inside the ISP said hackers caused extensive damage to the company's network after they managed to gain control over an internal Domain Admin, from where they spread and installed their ransomware payload to more than 18,000 workstations. The incident did not cause internet connectivity to go down for the ISP's customers, nor did it affect fixed telephony or cable TV services; however, many of Telecom Argentina's official websites have been down since Saturday. Since the attack's onset, multiple Telecom employees have now also taken to social media to share details about the incident, and how the ISP has been managing the crisis.
China

US Charges Two Chinese Spies For a Global Hacking Campaign That Targeted COVID-19 Research (techcrunch.com) 76

U.S. prosecutors have charged two Chinese nationals, said to be working for China's state intelligence bureau, for their alleged involvement in a massive global hacking operation that targeted hundreds of companies and governments for more than a decade. From a report: The 11-count indictment, unsealed Tuesday, alleges Li Xiaoyu, 34, and Dong Jiazhi, 33, stole terabytes of data from high-technology companies, around the world -- including the United States, the prosecutors said. More recently, the prosecutors accused the hackers of targeting the networks of over a dozen U.S. companies in Maryland, Massachusetts and California developing vaccines and treatments for COVID-19. The indictment comes just weeks after both the FBI and Homeland Security warned that China was actively trying to steal U.S. research data related to the coronavirus pandemic. The hackers were first discovered after they targeted a U.S. Department of Energy network in Hanford, Washington, the Justice Department said.
IT

Return and Enter Are Two Different Keys (daringfireball.net) 306

John Gruber, writing at DaringFireball: A New York Times mini crossword clue over the weekend was based on the notion that "Enter" is just a synonym for the Return key. It's not. They're two different keys that usually perform the same action, but not always. All keyboards have a dedicated Return key -- it's the big key you're thinking of above the right Shift key. On a Mac, the key code when you press Return is 36 [...].

A dedicated Enter key is generally only present on extended keyboards with a numeric keypad -- it's the key in the lower-right corner and is generally the only oversized key on the keyboard that is larger vertically, not horizontally. Its Mac key code is 76 [...]. Just look at such a keyboard: the Return key says "Return", and the Enter key says "Enter". If your keyboard doesn't have a dedicated Enter key, you can type the Enter key by pressing Fn-Return. That's why some Return keys have "Enter" printed in small type above the word "Return". If your keyboard has neither a dedicated Enter key nor an Fn modifier key, I don't think you can type Enter. [...]

Businesses

LinkedIn Cuts 960 Jobs as Pandemic Puts the Brakes on Corporate Hiring (reuters.com) 34

Microsoft's professional networking site LinkedIn said on Tuesday it would cut about 960 jobs, or 6% of its global workforce, as the coronavirus pandemic is having a sustained impact on demand for its recruitment products. From a report: California-based LinkedIn helps employers assess a candidate's suitability for a role and employees use the platform to find new job. Jobs will be cut across sales and hiring divisions of the group globally. Announcing the plan in a message posted on LinkedIn's website, Chief Executive Ryan Roslansky said the company would provide at least 10 weeks of severance pay as well as health insurance for a year for U.S. employees, and will hire for newly-created roles from laid-off staff. "I want you to know these are the only layoffs we are planning," Roslansky said in his message. Affected staff, who have not yet been told, would be able to keep company-issued cell phones, laptops, and recently purchased equipment to help them work from home while making career transitions, he said.
Encryption

Rare and Hardest To Crack Enigma Code Machine Sells For $437,000 (zdnet.com) 46

An anonymous reader writes: A rare 1944 four-rotor M4 Enigma cipher machine, considered one of the hardest challenges for the Allies to decrypt, has sold at a Christie's auction for $437,955. As noted by Christie's, the M4 Enigma has a special place in computing history as the Allied efforts to break its encryption led to the development of the first programmable computer, the one developed at Bletchley Park that was used to secretly break the M4, giving Allied forces visibility into German naval planning during the Battle of the Atlantic until its surrender in mid-1945.

The M4 Enigmas are considered rare because they were made in smaller numbers than three-rotor machines. After Germany capitulated, the country ordered troops to destroy remaining Enigmas in order to keep them from Allied forces. After the war Winston Churchill also ordered all remaining Enigmas destroyed to help preserve the secret of Allied decoding successes at Bletchley. The M4 Enigmas were made on the order of Admiral Karl Donitz, the commander of the German U-boat fleet, who had concerns over repeated Allied successes against his submarines. The M4 became available to the U-boat fleet in May 1941, preventing Allies from knowing where German's U-boats were positioned for almost a year until Turing and Joe Desch in Dayton, Ohio developed the computer that broke M4 encryption to decipher German messages. By mid-1943 the majority of M4 Enigma messages were being read by the Allies, but it was not until the 1970s that knowledge of the Allied successes against the Enigma was made public.
"Rival auction house Sotheby's sold an M4 Enigma last year for $800,000, which may have reached a higher selling price because it was one of one of 15 Enigma machines found in a bunker at Germany's key Northern European naval base in Trondheim, Norway, which Germany had occupied since 1940," adds ZDNet.
Privacy

Most Dedicated VPN IP-Addresses Are Not Anonymous (torrentfreak.com) 27

"Many VPN services advertise themselves as ideal tools to offer security, privacy, and anonymity. To ensure the latter, they often have no-logging policies to prevent individual users from being exposed," writes Ernesto Van der Sar via TorrentFreak. "However, this is not necessarily true for the small group that use dedicated or static IP-addresses." From the report: Today, most of the top providers pride themselves on their "no logging" policies. They go to extreme lengths to ensure that anonymity is taken seriously, and some have hired third-party auditors to back up this claim. While we have no reason to doubt these results, not all VPN subscriptions are perfectly anonymous. Even companies with no-log policies can keep records that can link VPN IP-addresses to user accounts. That is, when they also offer dedicated IP-addresses, which are different from regular VPN connections.

With a dedicated IP-address, which is often sold as an add-on, users get a unique IP-address as opposed to a shared one. This can be very convenient as it reduces annoying captchas and can bypass regular VPN blacklists. However, it comes at an anonymity cost. By connecting through a single IP-address, monitoring outfits can build up a profile of the user's online activity. The real anonymity tradeoff, however, is that the VPN provider knows the user's IP-address and can connect it to other account information it has on record. This sometimes includes an email address. This may not be a concern for most people, but it's certainly something to keep in mind for the small subset of subscribers that use a dedicated VPN IP-address.

Broadly speaking, we would say that the "no logs" policies of VPN providers don't apply to dedicated IPs. That conclusion is backed up by several VPN providers we reached out to, which include VPNArea, NordVPN, CyberGhost, and Torguard. These providers all have a no-logging policy for their regular VPN service, which relies on shared IP-addresses. However, they see dedicated IP-addresses as a separate and different service, which is treated differently anonymity-wise.

Microsoft

Microsoft Brings Procmon To Linux (betanews.com) 86

ProcMon for Linux is Microsoft's newest open-source Linux software. ProcMon is a rewritten and re-imagined version of its Processor Monitor found on Windows within their Sysinternals suite. From a report: Microsoft explains, "The Procmon is a Linux reimagining of the classic Procmon tool from the Sysinternals suite of tools for Windows. Procmon provides a convenient and efficient way for Linux developers to trace the syscall activity on the system."
IT

Samsung Blu-ray Players Reportedly Bricked By XML Parsing Error (theregister.com) 97

Hammeh writes: Since the middle of last month, thousands of Samsung customers found their older internet-connected Blu-ray players had stopped working. In the days that followed, complaints about devices caught in an endless startup boot loop began to appear on various internet discussion boards, and videos documenting the device failure appeared on YouTube. To fix the issue, Samsung eventually advised customers to return their inoperable video players for repairs. There is no software fix. "We are aware of the boot loop issue that appeared on certain 2015 Samsung Blu-Ray players and are offering free mail-in repairs to customers who have been impacted," a representative of the mega-manufacturer said in a Samsung forum post.

It was speculated by netizens and some media reports that a HTTPS certificate error was to blame. However, it's been suggested to The Register that the cause of the failure was an XML file downloaded by the network-connected devices from Samsung servers during periodic logging policy checks. This file, when fetched and saved to the device's flash storage and processed by the equipment, crashed the system software and force a reboot. Upon reboot, the player parsed the XML file again from its flash storage, crashed and rebooted again. And so on, and so on, and so on. Crucially, the XML file would be parsed before a new one could be fetched from the internet, so once the bad configuration file was fetched and stored by these particular Samsung Blu-ray players in the field, they were bricked.

IT

BadPower Attack Corrupts Fast Chargers To Melt or Set Your Device on Fire (zdnet.com) 121

Chinese security researchers said they can alter the firmware of fast chargers to cause damage to connected (charging) systems, such as melt the components, or even set devices on fire. A reader shares a report: The technique, named BadPower, was detailed last week in a report published by Xuanwu Lab, a research unit of Chinese tech giant Tencent. According to researchers, BadPower works by corrupting the firmware of fast chargers -- a new type of charger that was developed in the past few years to speed up charging times. A fast charger looks like any typical charger but works using special firmware. This firmware "talks" to a connected device and negotiates a charging speed, based on the device's capabilities. If a fast-charging feature is not supported, the fast charger delivers the standard 5V, but if the device can handle bigger inputs, the fast charger can deliver up to 12V, 20V, or even more, for faster charging speeds. The BadPower technique works by altering the default charging parameters to deliver more voltage than the receiving device can handle, which degrades and damages the receiver's components, as they heat up, bend, melt, or even burn.
Microsoft

What Happened When Microsoft Analyzed Its Own Remote Work Patterns? (hbr.org) 79

Harvard Business Review just published a new analysis by the director of Microsoft's Workplace Analytics team, a director on Microsoft's workplace intelligence team, and the editor of Microsoft Workplace Insights.

"Four months ago we realized that our company, like so many others, was undergoing an immediate and unplanned shift to remote work..."

"So, we launched an experiment to measure how the work patterns across our group were changing, using Workplace Analytics, which measures everyday work in Microsoft 365, and anonymous sentiment surveys..." [O]ur research revealed that workdays were lengthening — people were "on" four more hours a week, on average. Our survey shed light on one possible explanation: Employees said they were carving out pockets of personal time to care for children, grab some fresh air or exercise, and walk the dog. To accommodate these breaks, people were likely signing into work earlier and signing off later...

One data point stunned us: the rise of the 30-minute meeting... We had 22% more meetings of 30 minutes or less and 11% fewer meetings of more than one hour. This was surprising. In recent decades meetings have generally gotten longer, and research shows it has had a negative effect on employee productivity and happiness. Our flip to shorter meetings had come about organically, not from any management mandate. And according to our sentiment survey, the change was appreciated. Suddenly the specter of an hour-long meeting seemed to demand more scrutiny. (Does it really need to be that long? Is this a wise use of everyone's time?) This is one of the many ways that the remote-work period could have a long-term impact...

Our colleagues in China, who have already moved large parts of their workforces back to the office, are seeing that some of the habits that emerged during remote work, such as more reliance on instant messaging and longer workweeks, have continued even after the return.

Other interesting observations:
  • "Employees who had well-protected weekends suddenly have blurrier work-life boundaries. The 10% of employees who previously had the least weekend collaboration — less than 10 minutes — saw that amount triple within a month."
  • "Responding to the lack of natural touchpoints — grabbing lunch in the cafeteria, popping by someone's desk — employees found new ones. In our group, these ranged from group lunches to happy hours with themes such as 'pajama day' and 'meet my pet.' Overall, social meetings went up 10% in a month."
  • "Multitasking during meetings didn't spike even though people weren't in the same room..."

Mozilla

'Mozilla VPN' Launches in Six Countries (mozilla.org) 69

"Starting today, there's a VPN on the market from a company you trust," Mozilla announced Wednesday.

Mozilla VPN is now officially available for Windows and Android in six countries: the U.S., Canada, the U.K., Singapore, Malaysia, and New Zealand, and it'll be coming to even more countries later this year, reports the Verge: The service is available for $4.99 a month, and, like other VPNs, it's designed to make your web-browsing more private and secure. As part of the move, the service is being rebranded from Firefox Private Network to Mozilla VPN, a change that was announced last month.

Mozilla argues that its VPN service has a couple of advantages over its many competitors. It says it should offer a faster browsing experience in many cases because it's based on a protocol with less than a third of the lines of code of an average VPN service provider. The company is also banking on the reputation it's built up with its privacy-focused browser, and it adds that it only collects the information it needs to run a service and doesn't keep user data logs.

The VPN's launch follows beta trials in the US, which also included tests of a VPN built directly into the Firefox browser. Last month, Mozilla announced that it would be testing asking users to pay $2.99 a month for unlimited usage of the extension, which is designed to mask your traffic within the browser rather than at a system-wide level.

Programming

Are Whiteboard Coding Interviews Just Testing For Social Anxiety? (theregister.com) 196

An anonymous reader quotes The Register: People applying for software engineering positions at companies are often asked to solve problems on a whiteboard, under the watchful eye of an interviewer, as a way to assess technical problem solving skills. But recent research suggests that whiteboard technical tests — so daunting to job seekers that there are books on how to deal with them — often fail to assess technical skill, according to new research. Instead, they're all about pressure.

In a paper to be presented later this year at the ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering, researchers from North Carolina State University and Microsoft in the U.S. argue that whiteboard sessions test for stage fright rather than, y'know, coding competency... "A technical interview has an uncanny resemblance to the Trier Social Stress Test, a procedure used for decades by psychologists and is the best known 'gold standard' procedure for the sole purpose of reliably inducing stress." As a consequence, whiteboard interviews may fail to assess coder competency. Rather, the researchers argue, they measure how well job candidates handle anxiety....

In essence, social anxiety took otherwise qualified job candidates out of the running because of the circumstances of the interview.

Twitter

Many New Details Emerge About Twitter's Breach (nytimes.com) 32

The New York Times claims to have traced the origins of a Twitter security breach to "a teasing message between two hackers late Tuesday on the online messaging platform Discord." [The Times' article was also republished here by the Bangkok Post.] "yoo bro," wrote a user named "Kirk," according to a screenshot of the conversation shared with The New York Times. "i work at twitter / don't show this to anyone / seriously." He then demonstrated that he could take control of valuable Twitter accounts — the sort of thing that would require insider access to the company's computer network. The hacker who received the message, using the screen name "lol," decided over the next 24 hours that Kirk did not actually work for Twitter because he was too willing to damage the company. But Kirk did have access to Twitter's most sensitive tools, which allowed him to take control of almost any Twitter account...

[F]our people who participated in the scheme spoke with The Times and shared numerous logs and screen shots of the conversations they had on Tuesday and Wednesday, demonstrating their involvement both before and after the hack became public. The interviews indicate that the attack was not the work of a single country like Russia or a sophisticated group of hackers. Instead, it was done by a group of young people — one of whom says he lives at home with his mother — who got to know one another because of their obsession with owning early or unusual screen names, particularly one letter or number, like @y or @6... "lol" did not confirm his real-world identity, but said he lived on the West Coast and was in his 20s. "ever so anxious" said he was 19 and lived in the south of England...

The group began by selling access to highly-coveted Twitter handles for bitcoin, according to the Times, including the accounts @dark, @w, @l, @50 and @vague.

Brian Krebs had suggested tweets of Twitter's internal tools came from "notorious SIM swapper" PlugWalkJoe — but the Times spoke to the 21-year-old (real name: Joseph O'Connor) who says his only involvement was taking possession of the breached Twitter account @6. "I don't care. They can come arrest me. I would laugh at them. I haven't done anything." Mr. O'Connor said other hackers had informed him that Kirk got access to the Twitter credentials when he found a way into Twitter's internal Slack messaging channel and saw them posted there, along with a service that gave him access to the company's servers. People investigating the case said that was consistent with what they had learned so far.
Meanwhile, Twitter has said, "The attackers successfully manipulated a small number of employees and used their credentials to access Twitter's internal systems, including getting through our two-factor protections. As of now, we know that they accessed tools only available to our internal support teams."

But Mashable brings more bad news: In an update posted on Friday night, Twitter ran down what its internal investigation has discovered so far. One piece of previously unknown information: the hacker(s) downloaded the personal account data for up to eight of the accounts which they had access to.

I should make this clear up front: that data includes direct messages...

As rumors spread around the platform as to which eight accounts could have been targeted, Twitter released an additional clarification... "[T]o address some of the speculation: none of the eight were Verified accounts..." Twitter also says 130 Twitter accounts were targeted... The company said that hackers gained access to 45 of them via a password reset and, for a second time, reiterated that the passwords used on the accounts were not accessed.

An article shared by Slashdot reader kimmmos notes that one account that went untouched was that of U.S. president Donald Trump. The Verge reports "it could be because Twitter has implemented extra protections for his account." But responding to the other account breaches, "A Twitter spokesperson confirmed the company has been in touch with the FBI," reports CNN. "We're acutely aware of our responsibilities to the people who use our service and to society more generally," Twitter added in a blog post.

"We're embarrassed, we're disappointed, and more than anything, we're sorry."
Businesses

Could Working Remotely Kill Silicon Valley's Culture? (medium.com) 67

This week Medium's editor-at-large argued remote working could kill Silicon Valley in a new article on Medium's business site "Marker" — because working remotely could bring an end to those "serendipitous encounters" which lead to blockbuster products: Tech serendipity is the means to an end in Silicon Valley. "You bring together a density of entrepreneurs and capital with a belief in crazy ideas and a readiness to fund them, and you manufacture serendipity at higher rates than if it were evenly distributed," said Shaan Hathiramani, the CEO of Flockjay, a San Francisco education startup, who is among those wrestling with how to replicate the chance encounter. But in a future remote dispersion of workers that all but excludes the unexpected, face-to-face encounter, what will Silicon Valley lose...?

Dozens of startups and legacy companies are trying to solve the serendipity crisis. Among them are Gather, a Silicon Valley startup, and Hopin, a U.K. company, both of which see the answer in conference apps: You watch online talks, then — just as you would at a physical conference — you go onto a "coffee break," a virtual room where you can "bump into" just about anyone else at the event. You can also sign up to be paired with people with whom you might have similar interests. "It's like a coffee break at TED," said Paul Saffo, a futurist at Stanford. Last week, Microsoft released a new feature for its Teams conferencing app called "Together Mode," which uses A.I. to cut out the images of everyone in a call and assemble them in a virtual setting, such as a theater. The sensation is to remove some of the fake-togetherness of Zoom calls, which is a real advance for the typical work meeting...

If the past is instructive, the pandemic will pass and many daily routines will return. Hordes of people will return to the office, but large numbers won't. Some will pick up and move. At that point, today's effort to digitalize serendipity will pick up more urgency. Video conferencing and other software will get better, and some companies will claim their product fosters the unscripted moment in truly innovative ways, blind to demographics. The question is whether that solution will include a continued place for Silicon Valley.

Security

VPN With 'Strict No-Logs Policy' Exposed Millions of User Log Files (betanews.com) 86

New submitter kimmmos shares a report from BetaNews: An unprotected database belonging to the VPN service UFO VPN was exposed online for more than two weeks. Contained within the database were more than 20 million logs including user passwords stored in plain text. User of both UFO VPN free and paid services are affected by the data breach which was discovered by the security research team at Comparitech. Despite the Hong Kong-based VPN provider claiming to have a "strict no-logs policy" and that any data collected is anonymized, Comparitech says that "based on the contents of the database, users' information does not appear to be anonymous at all." A total of 894GB of data was exposed, and the API access records and user logs included: Account passwords in plain text; VPN session secrets and tokens; IP addresses of both user devices and the VPN servers they connected to; Connection timestamps; Geo-tags; Device and OS characteristics; and URLs that appear to be domains from which advertisements are injected into free users' web browsers. Comparitech notes that this runs counter to UFO VPN's privacy policy.
Communications

FCC: Phone Carriers That Profit From Robocalls Could Have All Calls Blocked (arstechnica.com) 55

"Bad-actor" phone companies that profit from robocalls could be blocked by more legitimate carriers under rules approved unanimously yesterday by the Federal Communications Commission. From a report: Under the change, the FCC said carriers can block calls "from bad-actor upstream voice service providers that pass illegal or unwanted calls along to other providers, when those upstream providers have been notified but fail to take action to stop these calls." Carriers that impose this type of blocking will get a safe harbor from liability "for the unintended or inadvertent blocking of wanted calls, thus eliminating a concern that kept some companies from implementing robust robocall blocking efforts."

This expanded level of blocking -- spurred by a new law in which Congress directed the FCC to expand safe harbors -- could be implemented by companies that sell phone service directly to consumers. That includes mobile carriers Verizon, AT&T, and T-Mobile, traditional landline companies, and VoIP providers. Carriers won't be able to block calls from just any provider. As Chairman Ajit Pai explained, the safe harbor will be available in cases when the "bad-actor" telecom has been notified by the FCC that it is carrying illegal traffic and "fails either to effectively mitigate such traffic or to implement effective measures to prevent customers from using its network to originate illegal calls."

Slashdot Top Deals