Businesses

Slack Partners With Amazon To Take On Microsoft Teams (theverge.com) 29

Slack is partnering with Amazon in a multi-year agreement that means all Amazon employees will start to use Slack. The Verge reports: The deal comes just as Slack faces increased competition from Microsoft Teams, and it will also see Slack migrate its voice and video calling features over to Amazon's Chime platform alongside a broader adoption of Amazon Web Services (AWS). Amazon's roll out of Slack to all of its employees is a big part of the deal, thanks to an enterprise-wide agreement. It's not immediately clear how many of Amazon's 840,000 employees will be using Slack, though. Up until today, Slack's biggest customer has been IBM, which is rolling out Slack to its 350,000 employees.

While Slack has long used AWS to power parts of its chat app, it's now committing to using Amazon's cloud services as its preferred partner for storage, compute, database, security, analytics, machine learning, and future collaboration features. The deal means it's unlikely we'll see Slack turn to Microsoft's Azure cloud services or Google Cloud to power parts of its service in the foreseeable future. [...] Slack and Amazon are also promising better product integration and interoperability for features like AWS Chatbot, a service that pushes out Slack channel alerts for AWS instances. In the coming months, Slack and AWS will improve its Amazon AppFlow integration to support bi-directional transfer of data between AWS services and Slack channels.

Privacy

Incognito Mode Detection Still Works in Chrome Despite Promise To Fix (zdnet.com) 40

Websites are still capable of detecting when a visitor is using Chrome's incognito (private browsing) mode, despite Google's efforts last year to disrupt the practice. From a report: It is still possible to detect incognito mode in Chrome, and all the other Chromium-based browsers, such as Edge, Opera, Vivaldi, and Brave, all of which share the core of Chrome's codebase. Furthermore, developers have taken the scripts shared last year and have expanded support to non-Chrome browsers, such as Firefox and Safari, allowing sites to block users in incognito mode across the board. Currently, there is no deadline for a new Chrome update to block incognito mode detections, however, today, Google might be interested more than ever in fixing this issue.
IT

Dropbox is Working On Its Own Password Manager (androidpolice.com) 22

AndroidPolice: Dropbox just unceremoniously dumped a brand new app on the Play Store with no fanfare or formal announcement. The new Dropbox Passwords app, according to its listing, is a password manager available exclusively in an invite-only private beta for some Dropbox customers. Based on screenshots and description, the app seems pretty barebones -- or "minimal," depending on your tastes. Dropbox seems to intentionally avoid calling it a "password manager," though its functionality otherwise appears about the same as other solutions. Like other password managers, Dropbox Password can generate passwords for new accounts as required and sync them remotely so you can access all your passwords on multiple devices. It also uses zero-knowledge encryption to store those passwords remotely.
Encryption

Signal Launches Face-Blurring Tool as US Protesters Embrace Encrypted Messaging (venturebeat.com) 117

Law enforcement officials across the U.S. have already revealed that they will leverage facial recognition technology to retroactively target protesters following the killing of George Floyd, with police asking the public for footage and photos. Against this backdrop, Signal is introducing a new feature that can automatically obfuscate faces shared within the encrypted messaging app, as the company says it's "working hard to keep up with the increased traffic" from protesters. From a report: Moving forward, Signal users will be able to activate a feature in the main photo editing toolbox that will automatically blur all faces it identifies in an image. As with many automated computer vision tools, Signal doesn't claim that its face-blurring smarts are 100% effective. It may not identify all faces in a photo, which is why users can manually obscure faces by drawing the blur brush across each face with their finger.
Security

Anti-Racism Sites Hit By Wave of Cyberattacks (bbc.com) 248

An anonymous reader quotes a report from the BBC: Cyber-attacks against anti-racism organizations shot up in the wake of the death of George Floyd, a leading provider of protection services says. Cloudflare, which blocks attacks designed to knock websites offline, says advocacy groups in general saw attacks increase 1,120-fold. Mr Floyd's death, in police custody, has sparked nationwide civil unrest in the US. Government and military websites also saw a notable increase in attacks. Cloudflare says that after Mr Floyd's death and the ensuing violent clashes between police and protesters, it saw a noticeable jump in the amount of requests it blocked -- an extra 19 billion (17%) from the corresponding weekend the previous month. That equates to an extra 110,000 blocked requests every second, it said.

The problem was particularly acute for certain types of organizations. One single website belonging to an unnamed advocacy group dealt with 20,000 requests a second. Anti-racism groups which belong to Cloudflare's free program for at-risk organizations saw a large surge in the past week, from near-zero to more than 120 million blocked requests. Attacks on government and military websites were also up — by 1.8 and 3.8 times respectively.

United Kingdom

UK Willing To Admit Nearly 3 Million From Hong Kong If China Adopts Security Law (npr.org) 283

schwit1 shares news that UK Prime Minister Boris Johnson said he would be willing to allow more than 2.8 million people from Hong Kong to live and work in the country if China implements a controversial proposed national security law on the former British colony. The law could take effect as soon as this month, and would expand mainland China's control over Hong Kong. NPR reports: Johnson wrote in a column that appeared in The Times of London that the law would infringe on the "one country, two systems" agreement China reached with Britain in 1997 when Britain ceded control of the territory. He added that the law "would curtail [Hong Kong's] freedoms and dramatically erode its autonomy."

If China were to implement the law, Johnson wrote, Britain is prepared to take in around 350,000 people from Hong Kong who already have British National (Overseas) passports and 2.5 million who would be eligible to apply for them. He also noted that the U.K. would be making "one of the biggest changes in our visa system in history." It would allow Hong Kongers with these passports to come to the U.K. for a renewable period of a year. The current system allows them to come without a visa for up to six months. The potential new system would include a right to work and, potentially, a path to citizenship. Johnson did not elaborate in the column about how the 2.5 million people eligible for a British passport would be able to attain one, or how arrivals from Hong Kong would attain citizenship.
"Many people in Hong Kong fear that their way of life -- which China pledged to uphold -- is under threat," Johnson wrote. "If China proceeds to justify their fears, then Britain could not in good conscience shrug our shoulders and walk away... I still hope that China will remember that responsibilities go hand in glove with strength and leadership."

The law would authorize mainland China to prevent "secession, subversion, terrorism and foreign interference" in the semi-autonomous city. "One part that has got people worried is the suggestion that China could set up its own institutions in Hong Kong responsible for security," reports the BBC.

"Hong Kong was handed back to China from British control in 1997, but under a unique agreement -- a mini-constitution called the Basic Law and a so-called 'one country, two systems' principle," the report adds. "They are supposed to protect certain freedoms for Hong Kong: freedom of assembly and speech, an independent judiciary and some democratic rights -- freedoms that no other part of mainland China has." People in Hong Kong believe the law will result in a loss of these freedoms and could see Beijing punish people for criticizing the country, as happens in mainland China.
Android

New Cold Boot Attack Affects Seven Years of LG Android Smartphones (zdnet.com) 10

South Korean phone manufacturer LG has released a security update last month to fix a vulnerability that impacts its Android smartphones sold over the past seven years. From a report: The vulnerability, tracked under the identifier of CVE-2020-12753, impacts the bootloader component that ships with LG smartphones. In March this year, US software engineer Max Thomas discovered a vulnerability in the bootloader component that had been added to LG smartphones starting with the LG Nexus 5 series. In a technical breakdown of the vulnerability published on Tuesday, Thomas says the bootloader component's graphics package contains a bug that lets attackers sneak in their own code to run alongside the bootloader's graphics under certain conditions, such as when the battery dies out and when the device is in the bootloader's Download Mode. Thomas says that threat actors who perfectly time an attack can gain the ability to run their own custom code, which could allow them to take over the bootloader, and inherently the entire device.
Microsoft

Microsoft's New Edge Browser Now Rolling Out via Windows Update (theverge.com) 29

Microsoft is starting to roll out its new Edge browser through Windows Update. The new Chromium-based version of Edge launched in January, but Windows users had to specifically download it. From a report: A Microsoft support article notes that it's now available on Windows Update, meaning it will soon arrive on the more than 1 billion Windows 10 devices in use. It appears that Edge will be automatically installed through Windows Update on Windows 10 version 1803 and higher. That covers the vast majority of versions of Windows 10 that are currently supported, meaning it should start showing up in Windows Update for everyone soon. As always, this is a gradual rollout, so you might not see it immediately on Windows Update just yet.
Privacy

Zoom Won't Encrypt Free Calls Because it Wants To Comply With Law Enforcement (thenextweb.com) 70

If you're a free Zoom user, and waiting for the company to roll out end-to-end encryption for better protection of your calls, you're out of luck. From a report: Free calls won't be encrypted, and law enforcement will be able to access your information in case of 'misuse' of the platform. Zoom CEO Eric Yuan today said that the video conferencing app's upcoming end-to-end encryption feature will be available to only paid users.
Security

Hackers Plan To Use Stolen Cryptocurrency Exchange Data for SIM Swapping (vice.com) 10

Hackers who obtained personal data on users of Canadian cryptocurrency exchange Coinsquare say they plan to use the information to perform so-called SIM swapping attacks, according to one of the hackers. Motherboard: The news shows hackers' continued interest in trying to leverage security issues with telecom-based forms of authentication. In a SIM swapping attack, a hacker takes control of a target's phone number, which then gives them the ability to request password resets for some websites or a victim's two-factor authentication code. Often, SIM swappers will use these techniques to steal cryptocurrency. The breach also signals the continued risk of insider access, with Coinsquare telling Motherboard a former employee was responsible for stealing the data. "The original intent was to sell it [the data] but we figured we would make more money by SIM swapping the accounts," a pseudonymous hacker who provided the Coinsquare data to Motherboard said in an online chat.
Firefox

Firefox 77 Arrives With Faster JavaScript Debugging and Optional Permissions (venturebeat.com) 30

An anonymous reader writes: Mozilla today launched Firefox 77 for Windows, Mac, and Linux. Firefox 77 includes faster JavaScript debugging, optional permissions for extensions, and Pocket recommendations in the U.K. You can download Firefox 77 for desktop now from Firefox.com, and all existing users should be able to upgrade to it automatically. According to Mozilla, Firefox has about 250 million active users, making it a major platform for web developers to consider. [...] Other than Pocket recommendations arriving in the U.K. (they've been in Canada, Germany, and the U.S. since April 2018), this is primarily a developer release. Firefox's Debugger is now better at handling large web apps with all their bundling, live reloading, and dependencies. Mozilla is promising performance improvements that speed up pausing and stepping, as well as cutting down on memory usage over time. Source maps should also see performance boosts -- some inline source maps load 10 times faster -- and improved reliability for many configurations. The debugger will now also respect the currently selected stack when stepping, which is useful when you've stepped into a function call or paused in a library method further down in the stack.
Security

Setting This Image As Wallpaper Could Soft-Brick Your Phone (androidauthority.com) 42

Well-known leaker Universe Ice on Twitter, along with dozens of other users, have discovered that simply setting an image as wallpaper on your phone could cause it to crash and become unable to boot. Android Authority reports: Based on user reports, many models from Samsung and Google are affected, while we've also seen some reports from users of OnePlus, Nokia, and Xiaomi devices (it's not clear if these latter devices ran stock software or custom ROMs). From our own testing and looking at user reports, Huawei devices seem to be less exposed to the wallpaper crash issue. There are a few solutions, depending on how hard the phone is hit. Some users were able to change the wallpaper in the short interval between crashes. Others had success deleting the wallpaper using the recovery tool TWRP. But in most cases, the only solution was to reset the phone to factory settings, losing any data that's not backed up.

The issue affects up-to-date phones running Android 10, but as it turns out, it's not actually new. Users have been reporting similar problems for a couple of years, and just last month Android Police reported on what appears to be a closely related issue specifically impacting Pixel phones running the Google Wallpapers app. [...] An issue with a very similar description has been reported in Google's Android issue tracker back in 2018. At the time, Google developers said they were unable to reproduce the issue and closed it out (Hat tip: inverimus on Reddit).

Security

After a Breach, Users Rarely Change Their Passwords, Study Finds (zdnet.com) 47

Only around a third of users usually change their passwords following a data breach announcement, according to a recent study published by academics from the Carnegie Mellon University's Security and Privacy Institute (CyLab). From a report: The study, presented earlier this month at the IEEE 2020 Workshop on Technology and Consumer Protection, was not based on survey data, but on actual browser traffic. Academics analyzed real-world web traffic collected with the help of the university's Security Behavior Observatory (SBO), an opt-in research group where users sign up and share their full browser history for the sole purpose of academic research. The research team's dataset included information collected from the home computers of 249 participants.

The data was collected between January 2017 and December 2018 and included not only web traffic, passwords used to log into websites and stored inside the browser. Based on their analysis of the data, academics said that of the 249 users, only 63 had accounts on breached domains that publicly announced a data breach during the collection interval. CyLab researchers said that of the 63 users, only 21 (33%) visited the breached sites to change their passwords, and that of these 21, only 15 users changed passwords within three months after the data breach announcement.

Security

George Floyd: Anonymous Hackers Reemerge Amid US Unrest (bbc.com) 187

An anonymous reader quotes a report from the BBC: As the United States deals with widespread civil unrest across dozens of cities, "hacktivist" group Anonymous has returned from the shadows. The hacker collective was once a regular fixture in the news, targeting those it accused of injustice with cyber-attacks. After years of relative quiet, it appears to have re-emerged in the wake of violent protests in Minneapolis over the death of George Floyd, promising to expose the "many crimes" of the city's police to the world. However, it's not easy to pin down what, if anything, is genuinely the mysterious group's work.

Various forms of cyber-attack are being attributed to Anonymous in relation to the George Floyd protests. First, the Minneapolis police department website was temporarily taken offline over the weekend in a suspected Distributed Denial of Service (DDoS) attack. This is an unsophisticated but effective form of cyber-attack that floods a server with data until it can't keep up and stops working -- in the same way that shopping websites can go offline when too many people flood it to snap up high-demand products. A database of email addresses and passwords claiming to be hacked from the police department's system is also in circulation, and being linked to Anonymous. However, there is no evidence that the police servers have been hacked and one researcher, Troy Hunt, says the credentials are likely to have been compiled from older data breaches.

A page on the website of a minor United Nations agency has been turned into a memorial for Mr Floyd, replacing its contents with the message "Rest in Power, George Floyd", along with an Anonymous logo. On Twitter, unverified posts have also gone viral, apparently showing police radios playing music and preventing communication. However, experts suggest it is unlikely to be a hack, and could instead be the result of a stolen piece of hardware being commandeered by protesters on the scene -- if the videos are genuine in the first place. Anonymous activists are also circulating years-old accusations against President Trump, taken from documents in a civil court case that was voluntarily dismissed by the accuser before it went to trial.

Microsoft

Samsung Rolls Out Access Upgrade Plan For New Galaxy Devices (theverge.com) 14

Samsung is rolling out Samsung Access, a monthly premium upgrade program in the US for users who purchase new Galaxy S20, Galaxy S20 Plus, or Galaxy S20 Ultra phones, the company announced in a blog post. From a report: Unlike its legacy upgrade program, Samsung Access provides additional benefits, including a Premium Care membership, and a premium Microsoft 365 subscription, which includes Word, Excel, Outlook, PowerPoint, and Skype, along with 1TB of OneDrive cloud storage. Another big difference between the new Access plan and the legacy upgrade plan: if you already have a Samsung device, you can't trade it in to join the new Access plan. The standard upgrade plan allows you to trade in an existing device and put any remaining balance toward a new one. Pricing for a minimum three-month subscription to Samsung Access will cost $37 per month for the S20, $42 per month for the S20 Plus, and $48 per month for the S20 Ultra.
Microsoft

Microsoft Now Credits Maker of Package Manager it 'Copied' -- But Offers No Apology (zdnet.com) 67

Microsoft has now admitted it failed to give due credit to Canadian developer Keivan Beigi for his role in the new WinGet Windows 10 package manager. From a report: Last week, Beigi, who built the open-source AppGet package manager for Windows, accused Microsoft of copying his work for WinGet without acknowledging his product's influence. Beigi says Microsoft copied large parts of AppGet to deliver WinGet, the Windows package manager announced at Microsoft Build 2020. Last week, he detailed his discussions with a senior manager at Microsoft named Andrew who approached him in July 2019 with an invitation to meet and discuss "how we can make your life easier building AppGet".

Andrew Clinick, a group program manager on the team responsible for how apps install on Windows, has now admitted Microsoft failed to give Beigi proper credit for AppGet's influence on WinGet. "Our goal is to provide a great product to our customers and community where everyone can contribute and receive recognition," wrote Clinick. "The last thing that we want to do is alienate anyone in the process. That is why we are building it on GitHub in the open where everyone can contribute. "Over the past couple of days we've listened and learned from our community and clearly we did not live up to this goal. More specifically, we failed to live up to this with Keivan and AppGet. This was the last thing that we wanted."

Bug

Finding Serious 'Sign In with Apple' Hole Earns Security Researcher a $100,000 Bug Bounty (forbes.com) 21

An anonymous reader quotes Forbes: When Apple announced Sign in with Apple at the June 2019 worldwide developers conference, it called it a "more private way to simply and quickly sign into apps and websites." The idea was, and still is, a good one: replace social logins that can be used to collect personal data with a secure authentication system backed by Apple's promise not to profile users or their app activity... Unsurprisingly, it has been pushed as being a more privacy-oriented option than using your Facebook or Google account.

Fast forward to April 2020, and a security researcher from Delhi uncovered a critical Sign in with Apple vulnerability that could allow an attacker to potentially take over an account with just an email ID. A critical vulnerability that was deemed important enough that Apple paid him $100,000 through its bug bounty program by way of a reward. With the vulnerability already now patched by Apple on the server-side, Bhavuk Jain published his disclosure of the security shocker on May 30.

It applied "only to third-party apps which used Sign in with Apple without taking any further security measures," the article points out , adding that the researcher who found it "said Apple carried out an internal investigation and determined that no account compromises or misuse had occurred before the vulnerability was fixed."

But they also quote an SME application security lead at ImmersiveLabs who said he "would have expected better testing around this from a company such as Apple, especially when it is trying to set itself a reputation as privacy-focused."
Security

Zoom's New, Stronger Encryption May Only Protect Paying Clients (newsweek.com) 21

"Zoom plans to strengthen the encryption of its service for paying customers," reports Newsweek, "but the upgrade will not be available to users of its free service." Zoom security consultant Alex Stamos later confirmed the details of the reported move in an interview with Reuters, which first reported the changes on Friday. But he also told the news outlet that Zoom's plans could still change. "The CEO is looking at different arguments," Stamos said.

"The current plan is paid customers plus enterprise accounts where the company knows who they are." In the wake of privacy concerns, he added that Zoom was making significant efforts to upgrade safety and trust on its platform. In an emailed statement to Newsweek, a Zoom spokesperson said: "Zoom's approach to end-to-end encryption is very much a work in progress — everything from our draft cryptographic design, which was just published last week, to our continued discussions around which customers it would apply to." The tech company's plans to boost the encryption of video calls on its platform have been revealed a month after it was reported that half a million Zoom account credentials were being sold on the Dark Web.

Zoom's increased usage during lockdowns brought increase scrutiny, reports CNET, which "revealed several Zoom security problems and the fact that an earlier Zoom boast of end-to-end encryption was baseless."
Open Source

GitHub Warns Java Developers of New Malware Poisoning NetBeans Projects (zdnet.com) 45

GitHub issued a security alert Thursday warning about new malware spreading on its site via boobytrapped Java projects, ZDNet reports: The malware, which GitHub's security team has named Octopus Scanner, has been found in projects managed using the Apache NetBeans IDE (integrated development environment), a tool used to write and compile Java applications. GitHub said it found 26 repositories uploaded on its site that contained the Octopus Scanner malware, following a tip it received from a security researcher on March 9.
But the article adds GitHub "believes that many more projects have been infected during the past two years." GitHub says that when other users would download any of the 26 projects, the malware would behave like a self-spreading virus and infect their local computers. It would scan the victim's workstation for a local NetBeans IDE installation, and proceed to burrow into the developer's other Java projects. The malware, which can run on Windows, macOS, and Linux, would then download a remote access trojan (RAT) as the final step of its infection, allowing the Octopus Scanner operator to rummage through an infected victim's computer, looking for sensitive information.

GitHub says the Octopus Scanner campaign has been going on for years, with the oldest sample of the malware being uploaded on the VirusTotal web scanner in August 2018, time during which the malware operated unimpeded.

United States

2018 'Hacking Attempt' Claimed By Georgia Was A Security Test They'd Requested Themselves (ajc.com) 50

An anonymous reader quotes the Atlanta Journal-Constitution: It was a stunning accusation: Two days before the 2018 election for Georgia governor, Republican Brian Kemp used his power as secretary of state to open an investigation into what he called a "failed hacking attempt" of voter registration systems involving the Democratic Party. But newly released case files from the Georgia Bureau of Investigation reveal that there was no such hacking attempt.

The evidence from the closed investigation indicates that Kemp's office mistook planned security tests and a warning about potential election security holes for malicious hacking.

Kemp then wrongly accused his political opponents just before Election Day — a high-profile salvo that drew national media attention in one of the most closely watched races of 2018... The internet activity that Kemp's staff described as hacking attempts were actually scans by the U.S. Department of Homeland Security (DHS) that the secretary of state's office had agreed to, according to the Georgia Bureau of Investigation. Kemp's chief information officer signed off on the DHS scans three months beforehand.

The Atlanta Journal-Constitution also reports that the Democratic party's only role was apparently forwarding an email about vulnerabilities to two cybersecurity professors at Georgia Tech, who then alerted authorities: Richard Wright, a Georgia Tech graduate and Democratic voter who works for a software company...found that he could look up other voters' information by modifying the web address on the site, a flaw confirmed by ProPublica and Georgia Public Broadcasting before it was fixed....An election security vendor for the state, Fortalice Solutions, later concluded, however, that there was no evidence that voter information had been accessed, manipulated or changed by bad actors...

While publicly denying Wright's claims about vulnerabilities, behind the scenes, Kemp's staff was working to correct them.... The secretary of state's firewall hadn't been set up to block access to the locations identified by Wright, according to a Georgia Bureau of Investigation agent's report. Election officials then "set up safeguards to restrict access to the vulnerable areas" on the last two days before the 2018 general election... This type of weakness, called broken access control, is one of the 10 most critical web application security risks, according to the Open Web Application Security Project, an organization that works to improve software security.

In 2016 Kemp also accused the Department of Homeland Security of trying to breach his office's firewall.

But a later investigation revealed the activity Kemp cited "was the result of normal and automatic computer message exchanges," apparently caused by someone cutting and pasting data into a Microsoft Excel document.

Slashdot Top Deals