Television

All 201 Episodes of 'The Office' Are Now Playing Out Over Slack (theverge.com) 32

An anonymous reader writes: If you take out The Office's physical interactions between characters and try to tell the same jokes over Slack, does The Office still work? It's a question that creative collective MSCHF set to find out, recreating all 201 episodes of the series over Slack. Viewers will join a live Slack, where different channels are dedicated to various departments, including accounting, warehouse, and a general office room. Viewers are requested to avoid posting in the "company" channels, but are encouraged to pop in and out of channels to keep up with the episodes as they don't all play in one. Since it is a live Slack, inappropriate messages and images do pop up, but the MSCHF team has a number of moderators working to keep it as troll-free as possible, a representative told The Verge. It could take roughly two to three weeks for each episode to "air" over Slack, so settle in.
Businesses

Newton Mail is Being Resurrected Again, This Time by Superfans (inputmag.com) 14

Newton Mail, a subscription-based email client with an impressively large fanbase, is being reincarnated by new owners: long-time fans Maitrik Kataria and Justin Mitchell. From a report: After Newton's owner Essential announced it would be shutting down in February -- for the second time, Kataria and Mitchell reached out to the company to figure out how they could save their favorite email client. And somehow they've done it. Newton, which was originally produced under the name CloudMagic, has been shut down and given new life more times than most companies are afforded. CloudMagic rebranded as Newton in 2016 and did pretty well for itself -- by the time it first shut down in the summer of 2018, the service had more than 40,000 paid subscribers. The purchase of Newton Mail by Kataria and Mitchell brings the mail client back to its roots as a company free of venture capital funding. Newton will need to bank on its long-standing fan base's willingness to pay subscription fees for a mail client if it wants to survive. Otherwise, history is doomed to repeat itself once again.
Bug

Thunderbolt Bug Lets Hackers Steal Your Data in 'Five Minutes' (thenextweb.com) 92

A new set of flaws discovered in the Intel Thunderbolt port has put millions of machines at risk of local hacking. This new research by Eindhoven University's Bjorn Ruytenberg suggests that if a hacker gains access to a machine for just five minutes, they could bypass login methods to gain full data access. From a report: Thunderbolt ports are present in machines with Windows, Linux, and macOS. So, that covers a lot of computers. Ruytenberg said all Thunderbolt versions and systems shipped between 2011 to 2020 are affected and no software patch can fix these vulnerabilities. So, Intel would need to redesign silicon in order to fix these flaws. There's not much you can do here. However, with open-source software called Thunderspy, developed by Ruytenberg and their team, you can check if you're affected by the Thunderbolt bug.
Intel

Microsoft and Intel Project Converts Malware Into Images Before Analyzing It (zdnet.com) 45

Microsoft and Intel have collaborated on a new research project that explores a new approach to detecting and classifying malware. From a report: Called STAMINA (STAtic Malware-as-Image Network Analysis), the project relies on a new technique that converts malware samples into grayscale images and then scans the image for textural and structural patterns specific to malware samples. The Intel-Microsoft research team said the entire process followed a few simple steps. The first consisted of taking an input file and converting its binary form into a stream of raw pixel data. Researchers then took this one-dimensional (1D) pixel stream and converted it into a 2D photo so that normal image analysis algorithms can analyze it.
Stats

Even After the Pandemic, 43% Say They'll Want to Work Remotely More Often (cnbc.com) 64

Long-time Slashdot reader gollum123 quotes CNBC: Nearly 43% of full-time American employees say they want to work remotely more often even after the economy has reopened, according to a survey released by business publishing company getAbstract. Of the more than 1,200 employees surveyed between April 16 and April 17, nearly 20% said their employer is actively discussing how they can make remote work more of an option in the future...

Andrew Savikas, chief strategy officer at getAbstract, says one of the biggest reasons why employees prefer to work remotely is because they get to save time on their daily commute. On average, Americans spent roughly 27 minutes on their one-way commute to work in 2018, according to the Census Bureau. This equates to over 200 hours spent commuting per year... "People like having that time back," Savikas says, while adding that employees also like the flexibility of working remotely because they can "structure the day how they want."

According to a joint CNBC/Change Research survey of more than 5,000 voters in swing states, 47% said the time they would normally spend on commuting has now been used to spend more time with their family. The survey, which gathered responses between April 17 and April 18, also found that employees have been spending the time they save on their commute to sleep more, focus on various hobbies and get more work done.

Security

Man Sues Teenager's 'Crew of Evil Computer Geniuses' Over Crypto Heist (bloomberg.com) 66

Cryptocurrency investor Michael Terpin sued AT&T over a SIM card attack in 2018 that lost him control over $23 million.

Now Bloomberg reports that he's suing the "15-year-old hacker and his crew of 'evil computer geniuses'" behind the attack. (Alternate source) Terpin, the founder and chief executive officer of blockchain advisory firm Transform Group, is suing Ellis Pinsky, now 18, for $71 million under a federal racketeering law that allows for triple damages. "Pinsky and his other cohorts are in fact evil computer geniuses with sociopathic traits who heartlessly ruin their innocent victims' lives and gleefully boast of their multi-million-dollar heists," Terpin said in his complaint filed Thursday in federal court in Manhattan.

Pinsky, of Irvington, New York, couldn't be reached for comment....

According to Terpin. Pinsky's ring identifies people with large cryptocurrency holdings and gains control of their phones by bribing or fooling employees of their wireless carriers. The hackers are then able to intercept authentication messages, gain information and drain the victims' cryptocurrency accounts.

Pinsky has boasted to friends that, starting at age 13, he stole more than $100 million worth of cryptocurrency, hundreds of thousands of dollars of which has been converted into cash stored in his bedroom, the lawsuit alleges. Terpin also claims that, after confronting Pinsky about his alleged role in the theft, the teenager sent him cryptocurrency, cash and a watch with a combined value of $2 million. He claims this was an admission by Pinsky that he had stolen from Terpin.

Cloud

Belkin Criticized For Its Upcoming Bricking of NetCams (forbes.com) 88

A Forbes contributor notes that Belkin abruptly announced the end-of-life for its Wemo NetCams, which will discontinued on May 29 2020. But that's just the beginning... Unlike many other end-of-life announcements which simply render products ineligible for support or upgrades, Belkin is literally pulling the plug on its Cloud service, rendering its NetCam range of home security cameras as useless beige bricks...

The question of how Belkin are deliberately bricking their products needs to be called out. When the NetCam was released, users had the option to use the Wemo software (which was lousy) or connect to the cameras using ffmpeg with their favourite NVS platform or even with VLC or equivalent. However, in a firmware update a few years back — Belkin disabled this capability. While workarounds do exist, such as the one published by Vladimir Sobolev in 2018, the whole premise of buying a Belkin product is for ease of use and simplicity. Belkin claim to design 'people inspired products'. All customers of Belkin need to look carefully at these words and see how they match up with their deeds?

How many other Belkin products might be switched off on a whim?

The criticism can be applied to cloud-enabled products as a whole, but in the main — vendors understand that to alienate customers by bricking their possessions is not a viable long term strategy to maintain trust...

Forthcoming European legislation forcing technology companies to make their products easier to repair should go some way to address these concerns.

The article points out that even Microsoft gave Windows 7 users five years of warnings about its 2020 end-of-life.

And it also complains property owners now face two difficult choices: "Either leaving their property with no security system and zero surveillance capability, or breaking the quarantine orders in order to install new equipment."
Open Source

Do Working-From-Home Developers Risk Burning Out? (infoworld.com) 77

"Software developers, like everyone else, have had to transition to a work-from-home world," writes InfoWorld. For the users of GitHub, the COVID-19 pandemic has meant changes in work cadence and collaboration, along with an increased risk of burnout, a GitHub study of usage patterns on the Microsoft-owned code sharing site has found." In an "Octoverse spotlight" analysis published May 6, 2020, GitHub compared the first three months of 2020 with the first three months of 2019... GitHub said its analysis shows that developers have been resilient to the change wrought by COVID-19, with activity holding consistent or increasing through the crisis.
But their analysis also found:
  • Developers are working longer, by "up to an hour per day," seven days a week.
  • Slightly more pushes, pull requests, reviewed pull requests, and commented issues.
  • More collaboration on open source projects, and less time to merge pull requests into open source projects.

Security

In-Person DEF CON 28 Event Is Canceled (theregister.co.uk) 23

Annual Las Vegas hacker gathering DEF CON has officially called off its physical conference for this year due to the coronavirus pandemic. The Register reports: In what was pretty much a foregone conclusion, the organizing team today said the in-person event would not be held in 2020. It had been slated to take place in August. This comes after the more formal Black Hat USA event, usually scheduled to run the same week as DEF CON in Sin City, was shelved as an in-person shindig, due to the COVID-19 coronavirus pandemic forcing everyone to stay home where possible. Both shows will tentatively take place as web streaming affairs this summer. For DEF CON 28, this means a 'Safe Mode' online gathering, with video streams and a Discord server, between August 6 and 9. "Even if a vaccine were to be discovered tomorrow it would not be soon enough to test, manufacture, distribute and administer in time for people to safely to travel by August," explained Jeff "The Dark Tangent" Moss.

"Too many states have stayed open or are reopening, people partied for far too long, and the lack of federal coordination gives me no hope that things will get back to normal this year. I also worry that the conferences that postponed to later this year will be caught up in the 'second wave' after restrictions start to ease and they will end up having to cancel. Because of this, postponing for DEF CON was not an option."
Security

Cognizant Expects To Lose Between $50 Million and $70 Million Following Ransomware Attack (zdnet.com) 20

IT services provider Cognizant said in an earnings call this week that a ransomware incident that took place last month in April 2020 will negatively impact its Q2 revenue. ZDNet reports: "While we anticipate that the revenue impact related to this issue will be largely resolved by the middle of the quarter, we do anticipate the revenue and corresponding margin impact to be in the range of $50 million to $70 million for the quarter," said Karen McLoughlin, Cognizant Chief Financial Officer in an earnings call yesterday. McLoughlin also expects the incident to incur additional and unforeseen legal, consulting, and other costs associated with the investigation, service restoration, and remediation of the breach. The Cognizant CFO says the company has now fully recovered from the ransomware infection and restored the majority of its services.

Speaking on the ransomware attack, Cognizant CEO Brian Humphries said the incident only impacted its internal network, but not customer systems. More precisely, Humphries said the ransomware incident impacted (1) Cognizant's select system supporting employees' work from home setups and (2) the provisioning of laptops that Cognizant was using to support its work from home capabilities during the COVID-19 pandemic. Humphries said staff moved quickly to take down all impacted systems, which impacted Cognizant's billing system for a period of time. Some customer services were taken down as a precaution.

Bug

Oil Crash Busted Broker's Computers and Inflicted Big Losses (bloomberg.com) 87

An anonymous reader quotes a report from Bloomberg: Syed Shah usually buys and sells stocks and currencies through his Interactive Brokers account, but he couldn't resist trying his hand at some oil trading on April 20, the day prices plunged below zero for the first time ever. The day trader, working from his house in a Toronto suburb, figured he couldn't lose as he spent $2,400 snapping up crude at $3.30 a barrel, and then 50 cents. Then came what looked like the deal of a lifetime: buying 212 futures contracts on West Texas Intermediate for an astonishing penny each. What he didn't know was oil's first trip into negative pricing had broken Interactive Brokers Group Inc. Its software couldn't cope with that pesky minus sign, even though it was always technically possible -- though this was an outlandish idea before the pandemic -- for the crude market to go upside down. Crude was actually around negative $3.70 a barrel when Shah's screen had it at 1 cent. Interactive Brokers never displayed a subzero price to him as oil kept diving to end the day at minus $37.63 a barrel. At midnight, Shah got the devastating news: he owed Interactive Brokers $9 million. He'd started the day with $77,000 in his account.

To be clear, investors who were long those oil contracts had a brutal day, regardless of what brokerage they had their account in. What set Interactive Brokers apart, though, is that its customers were flying blind, unable to see that prices had turned negative, or in other cases locked into their investments and blocked from trading. Compounding the problem, and a big reason why Shah lost an unbelievable amount in a few hours, is that the negative numbers also blew up the model Interactive Brokers used to calculate the amount of margin -- aka collateral -- that customers needed to secure their accounts.
"It's a $113 million mistake on our part," said Thomas Peterffy, the chairman and founder of Interactive Brokers, in an interview Wednesday.

Customers will be made whole, Peterffy said. "We will rebate from our own funds to our customers who were locked in with a long position during the time the price was negative any losses they suffered below zero."
Security

Cognizant Expects To Lose Between $50M and $70M Following Ransomware Attack (zdnet.com) 9

IT services provider Cognizant said in an earnings call this week that a ransomware incident that took place last month in April 2020 will negatively impact its Q2 revenue. From a report: "While we anticipate that the revenue impact related to this issue will be largely resolved by the middle of the quarter, we do anticipate the revenue and corresponding margin impact to be in the range of $50 million to $70 million for the quarter," said Karen McLoughlin, Cognizant Chief Financial Officer in an earnings call yesterday. McLoughlin also expects the incident to incur additional and unforeseen legal, consulting, and other costs associated with the investigation, service restoration, and remediation of the breach. The Cognizant CFO says the company has now fully recovered from the ransomware infection and restored the majority of its services.
Cloud

Microsoft VP Asks AWS To 'Stand Down' On JEDI Cloud Protests (crn.com) 74

A Microsoft executive urged Amazon Web Services to "stand down on its litigation" opposing the award of the military's lucrative JEDI commercial cloud transformation contract, arguing the ongoing legal and administrative challenges are keeping the best tools out of the hands of U.S. warfighters. From a report: The statement from Frank Shaw, Microsoft's corporate vice president for communications, came in response to Amazon's latest attempt to compel a re-evaluation of the potentially $10 billion contract won by Microsoft -- a protest filed Monday directly with the Pentagon. The Defense Department's "decision to source a Joint Enterprise Defense Infrastructure (JEDI) contract to deliver the latest advancements in enterprise cloud could be a great step forward," Shaw said. "But only if Amazon gets out of the way." Shaw repeated Microsoft's now-common refrain against AWS: the cloud market leader bid too high, and it is now looking for a "re-do." "This latest filing -- filed with the DoD this time -- is another example of Amazon trying to bog down JEDI in complaints, litigation and other delays designed to force a do-over to rescue its failed bid," he said.
Bug

How a Facebook Bug Took Down Your Favorite iOS Apps (wired.com) 65

An anonymous reader quotes a report from Wired: A little after 6 pm ET on Wednesday, the system started blinking red for iOS developer Clay Jones. Like many devs, Jones uses a Google product called Crashlytics to keep tabs on when his app stops working. Out of nowhere, it registered tens of thousands of crashes. It also pointed to the cause: a chunk of code that Jones' app incorporates to let people log in with their Facebook accounts. By 6:30 pm, Jones had filed a bug report about the flaw in Facebook's software development kit on GitHub, the code repository. He wasn't alone. According to widespread reports and the web monitoring service Down Detector, prominent iOS apps like TikTok, Spotify, Pinterest, Venmo, and more experienced issues on Wednesday. Many users found that they crashed whenever they tried to open the apps, whether or not they used Facebook to log in.

"Yesterday, a new release of Facebook included a change that triggered crashes in some apps using the Facebook iOS SDK for some users. We identified the issue quickly and resolved it," Facebook said in a statement. That change was quite small, given its outsized impact. "It was something like a server value -- which was supposed to provide a dictionary of things -- was changed to providing a simple YES/NO instead, without warning," says iOS developer Steven Troughton-Smith. "A change that simple can break an app that isn't prepared for it."

"Pretty much all these apps -- Pinterest, Spotify, a lot of the big ones -- use the Facebook SDK for the login button," says Jones. "You'll see 'Login With Facebook.' Everyone has it, super common, great for sign-up rates because it's just a one-click thing." And lots of apps that don't use Login With Facebook still use the SDK, which is why the issue Wednesday was so widespread. [...] The good news is that Facebook did fix the issue with haste, as far as these things go. Jones says it took about two hours for things to return to normal.

Security

Hackers Target WHO By Posing As Think Tank, Broadcaster (bloomberg.com) 15

An anonymous reader quotes a report from Bloomberg: The messages began arriving in World Health Organization employees' inboxes in early April, seemingly innocuous emails about the coronavirus from news organizations and researchers. But a close examination revealed that they contained malicious links, and some security experts have traced the emails to a hacking group in Iran believed to be sponsored by the government. The hacking effort, which began on April 3, was an attempt to steal passwords and possibly install malware on WHO computers, according to three people familiar with the matter, who requested anonymity because they aren't authorized to talk to the news media. The incident was one of several suspected state-sponsored hacks targeting WHO officials in recent weeks, the people said.

Two of the messages sent to the WHO, which were reviewed by Bloomberg News, were designed to look like coronavirus newsletters from the British Broadcasting Corporation. A third message was tailored to look like an interview request from the American Foreign Policy Council, a conservative think tank based in Washington. It encouraged recipients to click on what looked to be a shortened Google link, which diverted to a malicious domain. Ohad Zaidenberg, lead cyber intelligence researcher at Clearsky Cyber Security, reviewed the messages for Bloomberg News, and said he believed they were sent by a group of state-sponsored Iranian hackers known as "Charming Kitten," which has been active since 2014 and previously targeted Iranian dissidents, academics, journalists and human rights activists.
Flavio Aggio, the WHO's chief information security officer, confirmed the "very clever attacks" but said they'd so far been unsuccessful. "We are dealing with an information war and a cyberwar at the same time," he added.
Security

Microsoft's GitHub Account Allegedly Hacked, 500GB Stolen (bleepingcomputer.com) 43

A hacker claims to have stolen over 500GB of data from Microsoft's private GitHub repositories, BleepingComputer reports. From the report: This evening, a hacker going by the name Shiny Hunters contacted BleepingComputer to tell us they had hacked into the Microsoft GitHub account, gaining full access to the software giant's 'Private' repositories. The individual told us that they then downloaded 500GB of private projects and initially planned on selling it, but has now decided to leak it for free. Based on the file stamps in the leaked files, the breach may have occurred on March 28th, 2020.
Google

Google Authenticator's First Android Update in Years Lets You Move Your Account Between Devices (theverge.com) 27

Google Authenticator, the company's code-based authentication app, has received its first update in three years, updating the app's interface for larger screens with more modern aspect ratios and delivering one of the platform's most-needed features. From a report: The Android version was last updated on August 22nd, 2017, while the iOS one was updated around a year ago to adjust it for iPhone X screens. Now, for the first time, Authenticator users will be able to easily transfer their account from one device to another without needing to manually transfer each code or disable and reenable two-factor authentication (2FA) on each account. The update introduces this feature through an import / export tool that lets you choose which accounts to include and transfer using a single QR code scan. It's a feature that competitor Authy has provided for quite some time, so it's refreshing to see it come to Authenticator, even if it's years late.
Businesses

Zoom Acquires Keybase To Get End-to-End Encryption Expertise (techcrunch.com) 59

Zoom announced this morning that it has acquired Keybase, a startup with encryption expertise. From a report: Keybase, which has been building encryption products for several years including secure file sharing and collaboration tools, should give Zoom some security credibility as it goes through pandemic demand growing pains. The company has faced a number of security issues in the last couple of months as demand as soared and exposed some security weaknesses in the platform. As the company has moved to address these issues, having a team of encryption experts on staff should help the company build a more secure product. In a blog post announcing the deal, CEO Eric Yuan said they acquired Keybase to give customers a higher level of security, something that's increasingly important to enterprise customers as more operations are relying on the platform, working from home during the pandemic.
Security

Wink Smart Home Users Have One Week To Subscribe Or Be Shut Off (engadget.com) 140

Stephenmg writes: The smart home hub Wink, which was purchased by Will.i.am in 2017, is giving users until May 13th to opt into a subscription for $4.99 per month. If users do not opt-in, the hub becomes a brick. "Long term costs and recent economic events" prompted the move, according to Wink, and the company didn't want to sell user data to offset the costs of running services for free.
Security

Details of 44 Million Pakistani Mobile Users Leaked Online, Part of Bigger 115 Million Cache (zdnet.com) 11

An anonymous reader quotes a report from ZDNet: The details of 44 million Pakistani mobile subscribers have leaked online this week, ZDNet has learned. The leak comes after a hacker tried to sell a package containing 115 million Pakistani mobile user records last month for a price of $2.1 million in bitcoin. Data contains names, phone numbers, national IDs, and home addresses among others, and is believed to have originated from Jazz, a local mobile provider. According to our analysis of the leaked files, the data contained both personally-identifiable and telephony-related information. This includes the likes of: Customer full names; Home addresses (city, region, street name); National identification (CNIC) numbers; Mobile phone numbers; Landline numbers; and Dates of subscription.

Based on the dates of subscription, the oldest entries in the leaked files are from late 2013, suggesting that hackers either got their hands on an older backup file, or the breach took place in 2013, and only now surfaced online. The vast majority of entries in the leaked files contained mobile phone numbers belonging to Jazz (formerly Mobilink), a Pakistani mobile operator. However, ZDNet also identified phone numbers that appeared to belong to other mobile operators. [...] The incident is already under investigation in Pakistan, where the Pakistan Telecommunication Authority (PTA) and the Federal Investigation Agency (FIA) are looking into the matter since last month when the hacker first tried to sell the entire 115 million batch on a hacker forum.

Slashdot Top Deals