Privacy

Zoom Misses Its Own Deadline To Publish Its First Transparency Report (techcrunch.com) 5

How many government demands for user data has Zoom received? We won't know until "later this year," an updated Zoom blog post now says. From a report: The video conferencing giant previously said it would release the number of government demands it has received by June 30. But the company said it's missed that target and has given no firm new date for releasing the figures. It comes amid heightened scrutiny of the service after a number of security issues and privacy concerns came to light following a massive spike in its user base, thanks to millions working from home because of the coronavirus pandemic.

In a blog post today reflecting on the company's turnaround efforts, chief executive Eric Yuan said the company has "made significant progress defining the framework and approach for a transparency report that details information related to requests Zoom receives for data, records or content. We look forward to providing the fiscal [second quarter] data in our first report later this year," he said. Transparency reports offer rare insights into the number of demands or requests a company gets from the government for user data. These reports are not mandatory, but are important to understand the scale and scope of government surveillance.

Communications

FCC Declares Huawei, ZTE 'National Security Threats' (techcrunch.com) 74

The Federal Communication Commission has declared Chinese telecom giants Huawei and ZTE "national security threats," a move that will formally ban U.S. telecom companies from using federal funds to buy and install Huawei and ZTE equipment. From a report: FCC chairman Ajit Pai said that the "weight of evidence" supported the decision to ban the technology giants. Federal agencies and lawmakers have long claimed that the tech giants are subject to Chinese law, which "obligates them to cooperate with the country's intelligence services," Pai said. "We cannot and will not allow the Chinese Communist Party to exploit network vulnerabilities and compromise our critical communications infrastructure," the FCC said in a separate statement. Huawei and ZTE have repeatedly rejected the claims. The order, published by the FCC on Tuesday, said the designation takes immediate effect, but it's not immediately clear how the designation changes the status quo. In November of last year, the FCC announced that companies deemed a national security threat would be ineligible to receive any money from the Universal Service Fund. The $8.5B USF is the FCC's main way of purchasing and subsidizing equipment and services to improve connectivity across the country.
Android

Google Removes 25 Android Apps Caught Stealing Facebook Credentials (zdnet.com) 33

Google has removed this month 25 Android apps from the Google Play Store that were caught stealing Facebook credentials. From a report: Before being taken down, the 25 apps were collectively downloaded more than 2.34 million times. The malicious apps were developed by the same threat group and despite offering different features, under the hood, all the apps worked the same. According to a report from French cyber-security firm Evina shared with ZDNet today, the apps posed as step counters, image editors, video editors, wallpaper apps, flashlight applications, file managers, and mobile games. The apps offered a legitimate functionality, but they also contained malicious code. Evina researchers say the apps contained code that detected what app a user recently opened and had in the phone's foreground. If the app was Facebook, the malicious app would overlay a web browser window on top of the official Facebook app and load a fake Facebook login page (see image below: blue bar = actual Facebook app, black bar = phishing page).
Security

An Embattled Group of Hackers Picks Up the WikiLeaks Mantle (arstechnica.com) 74

An anonymous reader quotes a report from Ars Technica: For the past year, WikiLeaks founder Julian Assange has sat in a London jail awaiting extradition to the US. This week, the US Justice Department piled on yet more hacking conspiracy allegations against him, all related to his decade-plus at the helm of an organization that exposed reams of government and corporate secrets to the public. But in Assange's absence, another group has picked up where WikiLeaks left off -- and is also picking new fights.

For roughly the past year and a half, a small group of activists known as Distributed Denial of Secrets, or DDoSecrets, has quietly but steadily released a stream of hacked and leaked documents, from Russian oligarchs' emails to the stolen communications of Chilean military leaders to shell company databases. Late last week, the group unleashed its most high-profile leak yet: BlueLeaks, a 269-gigabyte collection of more than a million police files provided to DDoSecrets by a source aligned with the hacktivist group Anonymous, spanning emails, audio files, and interagency memos largely pulled from law enforcement "fusion centers," which serve as intelligence-sharing hubs. According to DDoSecrets, it represents the largest-ever release of hacked US police data. It may put DDoSecrets on the map as the heir to WikiLeaks' mission -- or at least the one it adhered to in its earlier, more idealistic years -- and the inheritor of its never-ending battles against critics and censors. "Our role is to archive and publish leaked and hacked data of potential public interest," writes the group's cofounder, Emma Best, a longtime transparency activist, in a text message interview with WIRED. "We want to inspire people to come forward, and release accurate information regardless of its source."

Security

A Hacker Gang is Wiping Lenovo NAS Devices and Asking for Ransoms (zdnet.com) 36

A hacker group going by the name of 'Cl0ud SecuritY' is breaking into old LenovoEMC (formerly Iomega) network-attached storage (NAS) devices, wiping files, and leaving ransom notes behind asking owners to pay between $200 and $275 to get their data back. From a report: Attacks have been happening for at least a month, according to entries on BitcoinAbuse, a web portal where users can report Bitcoin addresses abused in ransomware, extortions, cybercrime, and other online scams. Attacks appear to have targeted only LenovoEMC/Iomega NAS devices that are exposing their management interface on the internet without a password. ZDNet was able to identify around 1,000 such devices using a Shodan search.
Security

Apple Strong-Arms Entire CA Industry Into One-Year Certificate Lifespans (zdnet.com) 159

A decision that Apple unilaterally took in February 2020 has reverberated across the browser landscape and has effectively strong-armed the Certificate Authority industry into bitterly accepting a new default lifespan of 398 days for TLS certificates. From a report: Following Apple's initial announcement, Mozilla and Google have stated similar intentions to implement the same rule in their browsers. Starting with September 1, 2020, browsers and devices from Apple, Google, and Mozilla will show errors for new TLS certificates that have a lifespan greater than 398 days. The move is an important one because it not only changes how a core part of the internet works -- TLS certificates -- but also because it breaks away from normal industry practices and the cooperation between browsers and CAs. Known as the CA/B Forum, this is an informal group made up of Certificate Authorities (CAs), the companies that issue TLS certificates used to support HTTPS traffic, and browser makers. Since 2005, this group has been making the rules on how TLS certificates should be issued and how browsers are supposed to manage and validate them.
Privacy

Apple Declined To Implement 16 Web APIs in Safari Due To Privacy Concerns (zdnet.com) 120

Apple said last week that it declined to implement 16 new web technologies (Web APIs) in Safari because they posed a threat to user privacy by opening new avenues for user fingerprinting. Technologies that Apple declined to include in Safari because of user fingerprinting concerns include: Web Bluetooth - Allows websites to connect to nearby Bluetooth LE devices.
Web MIDI API - Allows websites to enumerate, manipulate and access MIDI devices.
Magnetometer API - Allows websites to access data about the local magnetic field around a user, as detected by the device's primary magnetometer sensor.
Web NFC API - Allows websites to communicate with NFC tags through a device's NFC reader.
Device Memory API - Allows websites to receive the approximate amount of device memory in gigabytes.
Network Information API - Provides information about the connection a device is using to communicate with the network and provides a means for scripts to be notified if the connection type changes.

Battery Status API - Allows websites to receive information about the battery status of the hosting device. Web Bluetooth Scanning - Allows websites to scan for nearby Bluetooth LE devices.
Ambient Light Sensor - Lets websites get the current light level or illuminance of the ambient light around the hosting device via the device's native sensors.
[...]
The vast majority of these APIs are only implemented in Chromium-based browsers, and very few on Mozilla's platform. Apple claims that the 16 Web APIs above would allow online advertisers and data analytics firms to create scripts that fingerprint users and their devices.

China

Chinese Bank Required Two Western Companies to Use Tax Software With a Hidden Backdoor (zdnet.com) 93

A Chinese bank required at least two western companies to install malware-laced tax software, according to a new report from the cyber-security firm Trustwave.

"The two companies are a UK-based technology/software vendor and a major financial institution, both of which had recently opened offices in China," reports ZDNet: "Discussions with our client revealed that [the malware] was part of their bank's required tax software," Trustwave said Thursday... Trustwave, who was providing cyber-security services for the UK software vendor, said it identified the malware after observing suspicious network requests originating from its customer's network... Trustwave said the software worked as advertised, allowing its customer to pay local taxes, but that it also installed a hidden backdoor. The security firm says this backdoor, which Trustwave codenamed GoldenSpy and said it ran with SYSTEM-level access, allowed a remote attacker to connect to the infected system and run Windows commands, or upload and install other software...

GoldenSpy installs two identical versions of itself, both as persistent autostart services. If either stops running, it will respawn its counterpart... The Intelligent Tax software's uninstall feature will not uninstall GoldenSpy. It leaves GoldenSpy running as an open backdoor into the environment, even after the tax software is fully removed. GoldenSpy is not downloaded and installed until a full two hours after the tax software installation process is completed. When it finally downloads and installs, it does so silently, with no notification on the system.

Privacy

Journalist's Phone Hacked: All He Had To Do Was Visit a Website. Any Website. (thestar.com) 123

The iPhone that Moroccan journalist Omar Radi used to contact his sources also allowed his government to spy on him (and at least two other journalists), reports the Toronto Star, citing new research from Amnesty International.

A Slashdot reader shares their report: Their government could read every email, text and website visited; listen to every phone call and watch every video conference; download calendar entries, monitor GPS coordinates, and even turn on the camera and microphone to see and hear where the phone was at any moment.

Yet Radi was trained in encryption and cyber security. He hadn't clicked on any suspicious links and didn't have any missed calls on WhatsApp — both well-documented ways a cell phone can be hacked. Instead, a report published Monday by Amnesty International shows Radi was targeted by a new and frighteningly stealthy technique. All he had to do was visit one website. Any website.

Forensic evidence gathered by Amnesty International on Radi's phone shows that it was infected by "network injection," a fully automated method where an attacker intercepts a cellular signal when it makes a request to visit a website. In milliseconds, the web browser is diverted to a malicious site and spyware code is downloaded that allows remote access to everything on the phone. The browser then redirects to the intended website and the user is none the wiser.

Two more human rights advocates in Morocco have been targeted by the same malware, the article reports.
Security

Bots Still Trying To Reach Cyberbunker 2.0 Addresses 9 Months After Raid (sans.edu) 13

Long-time Slashdot reader UnderAttack writes: In September last year, German police raided what was known as "Cyberbunker 2.0", a former cold war nuclear bunker turned into a "bulletproof" hosting facility. A student of the internet security-training company SANS Technology Institute analyzed traffic reaching out for the former Cyberbunker's IP address space.

Over two weeks, thousands of bots called "home" still looking for a command and control server. They also observed a number of phishing sites, as well as an odd ad network still directing users to the Cyberbunker's IPs. You can find the summary here.

Microsoft

Microsoft Removes Manual Deferrals From Windows Update By IT Pros 'To Prevent Confusion' (zdnet.com) 115

Microsoft is removing the ability for business users to defer manually Windows 10 feature updates using Windows Update settings starting with the Windows 10 2004/May Update. Microsoft seemingly made this change public with a change in its Windows 10 2004 for IT Pros documentation on June 23. From a report: Microsoft officials say this change is happening in the name of reducing confusion. Here's the explanation from the Microsoft page (which I saw thanks to WindowsTimes.com), and which I had heard about from a reader last week. (Last week, I assumed this was a bug, but now it seems like it's actually a "feature.") "Last year, we changed update installation policies for Windows 10 to only target devices running a feature update version that is nearing the end of service. As a result, many devices are only updating once a year. To enable all devices to make the most of this policy change, and to prevent confusion, we have removed deferrals from the Windows Update settings Advanced Options page starting on Windows 10, version 2004."
Encryption

Apple, Microsoft, Facebook, Google, Twitter, and Other Major Tech Companies Decry Republican Bill Seeking To Break Encryption (medianama.com) 66

In response to the Lawful Access to Encrypted Data (LAED) Act proposed by three Republican senators, Big Tech companies have registered their opposition through their Reform Government Surveillance coalition. From a report: They said that building encryption backdoors would jeopardize the sensitive data of billions of users and "leave all Americans, businesses, and government agencies dangerously exposed to cyber threats from criminals and foreign adversaries." They also pointed out that as the pandemic has forced everyone to rely on the internet "in critical ways," digital security is paramount and strong encryption is the way forward. The coalition's members are Apple, Microsoft, Facebook, Google, Twitter, Snap, Verizon Media, Dropbox, and Microsoft-owned LinkedIn. The coalition was established in December 2013, a few months after documents about the United States' PRISM data collection program were leaked.
Security

Apple Adds Support for Encrypted DNS (DoH and DoT) (zdnet.com) 16

In a presentation at its developer conference this week, Apple announced that the upcoming versions of its iOS and macOS operating systems will support the ability to handle encrypted DNS communications. From a report: Apple said that iOS 14 and macOS 11, set to be released this fall, will support both the DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT) protocols. Normal DNS (Domain Name System) traffic takes place in clear text and has been used by internet service providers and others to track users in the past, usually to create profiles to sell to online advertisers. But DoH and DoT allow a desktop, phone, or individual app to make DNS queries and receive DNS responses in an encrypted format, a feature that prevents third-parties and malicious threat actors from tracking a user's DNS queries and inferring the target's web traffic destinations and patterns.
Businesses

Apple Makes Another Acquisition: IT Startup Fleetsmith (arstechnica.com) 13

An anonymous reader quotes a report from Ars Technica: Apple has acquired device-management startup Fleetsmith. The technology and personnel that will join Apple as part of the acquisition could help Apple expand upon device enrollment and introduce better ways to set up new devices like iPads and Macs within organizations. Fleetsmith's proposition to customers (and Apple) seems perfectly tailored to our times: the company offers a way for organizations to equip remote workers' (or workers otherwise not located in the central office) devices and have those devices automatically registered and set up for enterprise use as soon as they're first turned on. After that, Fleetsmith automatically ensures devices get needed software updates. It also provides IT managers with a dashboard for managing the fleet.

If you've used Jamf, a more widespread competitor, you get the general idea. But Fleetsmith already had a special focus on Apple devices, it has an Apple-like design sensibility, and it was likely a much cheaper option for Apple than Jamf, to boot. Jamf appears to be on a different path, with a $3 billion IPO planned. Speaking of money, though, neither Apple nor Fleetsmith has revealed the purchase price. Fleetsmith did publish a blog post about the acquisition, though.
While the blog post notes that Fleetsmith will continue business as usual and serve both new and existing customers, Seth Goldin from Freethink Media claims that's not the full story. "Apple has completely eliminated core functionality from the app with absolutely no notice," says Goldin in a series of tweets, noting there are "hundreds of users" on the MacAdmins Slack workspace that are "totally outraged because Apple has pulled the rug out from under them."
Mozilla

Comcast Becomes the First ISP To Join Mozilla's TRR Program (neowin.net) 85

Comcast has joined Cloudflare and NextDNS in partnering with Mozilla's Trusted Recursive Resolver program, which aims to make DNS more trusted and secure. Neowin reports: Commenting on the move, Firefox CTO Eric Rescorla, said: "Comcast has moved quickly to adopt DNS encryption technology and we're excited to have them join the TRR program. Bringing ISPs into the TRR program helps us protect user privacy online without disrupting existing user experiences. We hope this sets a precedent for further cooperation between browsers and ISPs."

With its TRR program, Mozilla said that encrypting DNS data with DoH is just the first step in securing DNS. It said that the second step requires companies handling the data to have appropriate rules in place for handling it. Mozilla believes these rules include limiting data collection and retention, ensuring transparency about any retained data, and limiting the use of the resolver to block access or modify content.
Ars Technica notes that joining Mozilla's program means that Comcast agreed that it won't "retain, sell, or transfer to any third party (except as may be required by law) any personal information, IP addresses, or other user identifiers, or user query patterns from the DNS queries sent from the Firefox browser," along with other requirements.

When the change happens, it'll be automatic for users unless they've chosen a different DoH provider or disabled DoH altogether. Comcast told Ars yesterday that "Firefox users on Xfinity should automatically default to Xfinity resolvers under Mozilla's Trusted Recursive Resolver program, unless they have manually chosen a different resolver, or if DoH is disabled. The precise mechanism is still being tested and the companies plan to document it soon in an IETF [Internet Engineering Task Force] Draft."
Privacy

Safari 14 Will Let You Log in To Websites With Your Face or Finger (cnet.com) 42

With Safari on iOS 14, MacOS Big Sur and iPadOS 14, you'll be able to log in to websites using Apple's Face ID and Touch ID biometric authentication. That's a powerful endorsement for technology called FIDO -- Fast Identity Online -- that's paving the way to a future without passwords. From a report: Apple disclosed the biometric authentication support in Safari on Wednesday at WWDC, its annual developers conference. "It's both much faster and more secure," Apple Safari programmer Jiewen Tan said during one of the WWDC video sessions Apple offered after the coronavirus pandemic pushed the conference online. The change is a big boost for browser technology called Web Authentication, aka WebAuthn, developed by the FIDO consortium allies. Apple's not the first supporter -- it's already in Mozilla Firefox, Google Chrome and Microsoft Edge, and works with Windows Hello facial recognition and Android fingerprint authentication.
The Internet

The US-China Battle Over the Internet Goes Under the Sea (wired.com) 72

Last week, Washington strongly objected to a new project from Facebook and Google. It's too risky and offers "unprecedented opportunities" for Chinese government espionage, the Justice Department declared. The project, however, wasn't about online speech or contact tracing, but concerned an issue that would seem far less politically charged: building an undersea internet cable from the United States to Hong Kong. From a report: On June 17, Team Telecom -- the executive branch group charged with reviewing foreign telecoms for security risks (and recently in the news for escalating and apparently insufficient inspections) -- recommended the Federal Communications Commission stop the Hong Kong connection. It may seem odd for American officials to fret over undersea cable networks; rarely does your chosen crime show's protagonist kick a door in because someone is laying telecommunications fiber.

But geopolitical influence-projection on the internet isn't just about hacking other countries' intelligence databases. While not nearly as flashy, the development and maintenance of undersea cables, the landing points anchoring them above ground, and other physical internet infrastructure are a growing arm of cyber statecraft and source of security risk. This cable is just one element in a broader geopolitical contest. Facebook and Google joined the project, dubbed the Pacific Light Cable Network, back in 2016. Teaming up with New Jersey-based telecom TE SubCom and Pacific Light Data Communication Company, a Hong Kong subsidiary of the Chinese firm Dr. Peng Telecom & Media Group, the US giants jumped on a project already months underway: building a massive undersea internet cable -- the submarine-depth metal tubes hauling internet traffic from one land mass to another -- connecting the US, Hong Kong, Taiwan, and the Philippines.

To the US government, the Taiwan and Philippines part was up to scratch. Undersea cables have visible benefits, such as bolstering digital connections between regions and facilitating all forms of communication that follow. And for this 8,000-mile-long fiber-optic snake, connecting dispersed areas of the world was exactly the point. The stakeholders wrote as much in a December 2017 filing to the US government, noting this would be the first undersea cable moving internet traffic directly between Hong Kong and the United States, at speeds of 120 terabytes per second. But the government had security worries about the Chinese-owned Hong Kong subsidiary behind the effort, as well as the proposed line to Hong Kong itself. Google, Facebook, and their partners had already laid thousands of miles of cable and spent millions of dollars last August when word broke of the Justice Department's opposition to the project. Officials thought Beijing could physically access the cable for espionage -- in this case by capturing internet traffic.

Intel

Former Intel Engineer Claims Skylake QA Drove Apple Away (pcgamer.com) 252

UnknowingFool writes: A former Intel engineer has put forth information that the QA process around Skylake was so terrible that it may have finally driven Apple to use their own processors in upcoming Macs. Not to say that Apple would not have eventually made this move, but Francois Piednoel says Skylake was abnormally bad with Apple finding the largest amount of bugs inside the architecture rivaling Intel itself. That led Apple to reconsider staying on the architecture and hastening their plans to migrate to their own chips. "The quality assurance of Skylake was more than a problem," says Piednoel. "It was abnormally bad. We were getting way too much citing for little things inside Skylake. Basically our buddies at Apple became the number one filer of problems in the architecture. And that went really, really bad. When your customer starts finding almost as much bugs as you found yourself, you're not leading into the right place."

"For me this is the inflection point," added Piednoel. "This is where the Apple guys who were always contemplating to switch, they went and looked at it and said: 'Well, we've probably got to do it.' Basically the bad quality assurance of Skylake is responsible for them to actually go away from the platform."

Apple made the switch official at its developer conference on Monday, announcing that it will introduce Macs featuring Apple-designed, ARM-based processors later this year.
Safari

Safari 14 Removes Flash, Gets Support for Breach Alerts, HTTP/3, and WebP (zdnet.com) 54

Safari 14, scheduled to be released later this fall with iOS 14 and macOS 11, is a release that is packed choke-full with features. From a report: The biggest and most important of the new additions is support for WebExtensions, a technology for creating browser extensions. What this means for Safari users is that starting this fall, they'll see a huge influx of new Safari extensions as add-on developers are expected to port their existing Chrome and Firefox extensions to work on Apple's browser as well. Apple said that, for now, WebExtensions will only be available for Safari on macOS.

Safari 14 is also an end of an era, as this will be the first version of Safari that won't support Adobe Flash Player content. But while old stuff is being removed, new stuff is also being added. One of the new technologies added to Safari is support for HTTP/3, a new web standard that will make loading websites faster and safer. Another important addition in Safari is support for WebP, a lightweight image format that has been gaining widespread adoption across the internet. The format, created by Google, serves as an alternative to the older JPEG format, and Safari has been the last browser to add support for it. [...] But Safari hasn't been lagging behind other browsers just in terms of HTTP/3 and WebP support. Apple has also added support for another cool feature, namely breach alerts, already present in both Chrome and Firefox. Starting this fall, Apple says that Safari 14 will scan a user's locally-stored passwords and show a prompt if one or more of the user's credentials are present in publicly available lists of breached accounts.

Republicans

Republicans Push Bill Requiring Tech Companies To Help Access Encrypted Data (cnet.com) 182

New submitter feross shares a report: A group of Senate Republicans is looking to force tech companies to comply with "lawful access" to encrypted information, potentially jeopardizing the technology's security features. On Tuesday, Republican lawmakers introduced the Lawful Access to Encrypted Data Act, which calls for an end to "warrant-proof" encryption that's disrupted criminal investigations. The bill was proposed by Sen. Lindsey Graham, chairman of the Senate Judiciary committee, along with Sens. Tom Cotton and Marsha Blackburn. If passed, the act would require tech companies to help investigators access encrypted data if that assistance would help carry out a warrant. Lawmakers and the US Justice Department have long battled with tech companies over encryption, which is used to encode data.

The Justice Department argues that encryption prevents investigators from getting necessary evidence from suspects' devices and has requested that tech giants provide "lawful access." That could come in many ways, such as providing a key to unlock encryption that's only available for police requests. The FBI made a similar request to Apple in 2016 when it wanted to get data from a dead terrorist's iPhone in a San Bernardino, California, shooting case. Giving access specifically to government agencies when requested is often referred to as an "encryption backdoor," something tech experts and privacy advocates have long argued endangers more people than it helps.

Slashdot Top Deals