Security

NSA's Guide For Choosing a Safe Text Chat and Video Conferencing Service (zdnet.com) 73

The US National Security Agency (NSA) published last week a security assessment of today's most popular video conferencing, text chatting, and collaboration tools. From a report: The guidance contains a list of security criteria that the NSA hopes companies take into consideration when selecting which telework tool/service they want to deploy in their environments. The NSA document is not only meant for US government and military entities but the private sector as well. The idea behind the NSA's initiative is to give military, public, and private organizations an overview of all of a tools' features, so IT staff don't make wrong decisions, expecting that a tool provides certain features that are not actually living up to the reality. Per the NSA's document, the assessed criteria answers to basic questions like:

Does the service implement end-to-end (E2E) encryption?
Does the E2E encryption use strong, well-known, testable encryption standards?
Is multi-factor authentication (MFA) available?
Can users see and control who connects to collaboration sessions?
Does the tool's vendor share data with third parties or affiliates?
Do users have the ability to securely delete data from the service and its repositories as needed (both on client and server-side)?
Is the tool's source code public (e.g. open source)?
Is the service FedRAMP approved for official US government use?

Chrome

Google Announces Chrome Web Store Crackdown For August 2020 (zdnet.com) 15

Google announced this week new rules for the Chrome Web Store in an attempt to cut down the number of shady Chrome extensions submitted and listed on the site. From a report: Starting August 27, Google says it intends to enforce a new set of rules, which will result in a large number of extensions being delisted. These rules are meant to crack down on a series of practices extension developers have been recently employing to flood the Web Store with shady extensions or boost install counts for low-quality content. They include:
1. Developers cannot submit duplicate extensions anymore. (e.g. Wallpaper extensions that have different names but provide the user with the same wallpapers when installed.)
2. Extensions are not allowed to use "keyword spam" techniques to flood metadata fields with multiple terms and have the extension listed across multiple categories to improve the extension's visibility in search results.
3. Developers are not allowed to use misleading, improperly formatted, non-descriptive, irrelevant, excessive, or inappropriate metadata. Extension metadata needs to be accurate, and Google intends to be strict about it.
4. Developers are now forbidden from inflating product ratings, reviews, or install counts by illegitimate means, such as fraudulent or paid downloads, reviews, and ratings.

Microsoft

Microsoft's Visual Studio Online Code Editor is Now Visual Studio Codespaces and Gets a Price Drop (techcrunch.com) 24

About a year ago, Microsoft launched Visual Studio Online, its online code editor based on the popular Visual Studio Code project. It')s basically a full code editor and hosted environment that lives in your browser. Today, the company announced that it is changing the name of this service to Visual Studio Codespaces. It's also dropping the price of the service by more than 50% and giving developers the option to run it on relatively low-performance virtual machines that will start at $0.08 per hour. In today's announcement, Microsoft's Scott Hanselman points out that the company learned that most developers who used Visual Studio Online thought of it as being much more than simply an editor in the browser.
IT

This Tech Conference Is Being Held on an Animal Crossing Island (vice.com) 42

As our lives have become a seemingly endless series of work meetings on Zoom and FaceTime or WhatsApp catch-ups with friends, we're all getting a bit sick of seeing people's faces enclosed in a cold, almost lifeless, digital frame. A tech worker from New York had a different idea for his tech conference, which he announced, in all seriousness, on April Fools' Day. The free conference is called Deserted Island DevOps and is happening on Thursday, entirely inside Animal Crossing, the Nintendo Switch hit game released in the midst of the Coronavirus pandemic. From a report: Speakers are doing their talks on an island in Animal Crossing specifically built for the conference, and attendees can follow along in the game, on Twitch, or Zoom, as a fallback option. Other than the unusual, and incredibly colorful and fun setting, the conference is very much like any other conference. The speakers' avatars are standing behind a podium, their slides are being displayed next to them, and attendees sit in the audience. Crucially, the conference isn't about Animal Crossing, it's kind of a standard software development type conference. It just happens to be happening inside a video game.
IT

Raspberry Pi Gains a New 12.3-Megapixel Camera and Interchangeable Lenses (betanews.com) 66

The Raspberry Pi can be used for all sorts of maker projects, and the foundation has offered camera modules for it since 2013, adding vision-related functionality. The first module was a modest 5-megapixel affair that was eventually replaced by an 8-megapixel Sony sensor four years ago. Today, sees the arrival of a new much higher 12.3 megapixel quality camera, and a range of interchangeable lenses. From a report: The new camera is compatible with all Raspberry Pi models -- from Pi 1 Model B onwards -- with the exception of early Pi Zero boards. The camera is available to buy from today for $50.
Software

Half of Americans Won't Trust Contact-Tracing Apps, New Poll Finds (arstechnica.com) 221

Before life can safely return to normalcy, we'll need an enormous increase in our ability to perform contact tracing -- identifying and contacting everyone who's been in contact with a person infected with COVID-19 so that they in turn can hunker down in quarantine and avoid infecting others. But, as Ars Technica reports, there are two huge problems with the massive contact-tracing platform that Google and Apple are working on. "First, billions of phones won't be able to use the tech," reports Ars. "And second: even among those who could, a solid half of Americans would refuse to because they don't trust insurers or tech companies with their health data." From the report: The 82 percent of US adults who have smartphones are exactly split on the issue, according to poll data released today by The Washington Post and University of Maryland. Half of the poll respondents said they probably or definitely would use a contact-tracing app, and the remaining half said they probably or definitely would not. While a majority of respondents (57 percent) expressed a reasonable amount of trust in public health agencies, less than half (47 percent) said they trust health insurance firms, and only 43 percent said they trust tech firms such as Google or Apple. Overall, the poll indicates that only 41 percent of American adults have both the technological capacity and the will to use a contact-tracing app. That's a problem, as research suggests that digital tracing would have to reach about 60 percent of the population to be most effective.
Iphone

Apple Will Make It Easier To Unlock Your iPhone While Wearing a Face Mask (techcrunch.com) 65

Face ID was a great idea -- until large swathes of the world were forced to wear face masks, rendering it largely useless. Apple has apparently heard our pain. From a report: Users are reporting a subtle new feature in the latest developer version of iOS 13.5 that will make it easier to unlock your iPhone without having to take off your protective face mask. Videos shared on Twitter by Robert Petersen and Guilherme Rambo show that Apple devices with Face ID will jump to the backup passcode-entry screen if it detects a mask. That's not only helpful if you're unlocking your phone dozens of times a day -- which we all do -- but it's also helping to keep people safe by not forcing users to take off their masks and potentially exposing themselves to the virus.
Windows

Canon's New Software Will Turn Select EOS, PowerShot Cameras Into Webcams for Windows 10 PCs (dpreview.com) 78

An anonymous reader shares a report: As more and more people desire higher-quality video communication over internet while working from home due to the COVID-19 pandemic, the demand for webcams has increased dramatically, triggering incredibly high prices, sometimes three to four times over MSRP. And that's if you can find one at all. To help bridge a growing gap, Canon has announced the release of the EOS Webcam Utility Beta, a program for that will, with a single USB cable, turn compatible Canon EOS interchangeable lens cameras (ILCs) and PowerShot cameras into dedicated webcams on PCs running the 64-bit version of Windows 10. "In unprecedented times, it's imperative for Canon to provide our customers with useful, simple and accessible solutions to assist them in whatever imaging needs they have," said Tatsuro Kano, executive vice president of the Canon U.S.A., Inc. Imaging Technologies & Communications Group in the press release.
Google

How Spies Snuck Malware Into the Google Play Store -- Again and Again (wired.com) 34

Google's Play Store for Android apps has never had a reputation for the strictest protections from malware. Shady adware and even banking trojans have managed over the years to repeatedly defy Google's security checks. Now security researchers have found what appears to be a more rare form of Android abuse: state-sponsored spies who repeatedly slipped their targeted hacking tools into the Play Store and onto victims' phones. From a report: At a remote virtual version of its annual Security Analyst Summit, researchers from the Russian security firm Kaspersky today plan to present research about a hacking campaign they call PhantomLance, in which spies hid malware in the Play Store to target users in Vietnam, Bangladesh, Indonesia, and India. Unlike most of the shady apps found in Play Store malware, Kaspersky's researchers say, PhantomLance's hackers apparently smuggled in data-stealing apps with the aim of infecting only some hundreds of users; the spy campaign likely sent links to the malicious apps to those targets via phishing emails. "In this case, the attackers used Google Play as a trusted source," says Kaspersky researcher Alexey Firsh. "You can deliver a link to this app, and the victim will trust it because it's Google Play."

Kaspersky says it has tied the PhantomLance campaign to the hacker group OceanLotus, also known as APT32, widely believed to be working on behalf of the Vietnamese government. That suggests the PhantomLance campaign likely mixed spying on Vietnam's Southeast Asian neighbors with domestic surveillance of Vietnamese citizens. Security firm FireEye, for instance, has linked OceanLotus to previous operations that targeted Vietnamese dissidents and bloggers. FireEye also recently spotted the group targeting China's Ministry of Emergency Management as well as the government of the Chinese province of Wuhan, apparently searching for information related to Covid-19.

Privacy

Number-Plate Cam Site Had No Password, Spills 8.6 Million Logs of UK Road Journeys (theregister.co.uk) 48

The Register reports that Sheffield City Council's automatic number-plate recognition (ANPR) system exposed to the internet 8.6 million records of road journeys made by thousands of people. From the report: The ANPR camera system's internal management dashboard could be accessed by simply entering its IP address into a web browser. No login details or authentication of any sort was needed to view and search the live system -- which logs where and when vehicles, identified by their number plates, travel through Sheffield's road network. Britain's Surveillance Camera Commissioner Tony Porter described the security lapse as "both astonishing and worrying," and demanded a full probe into the snafu. He told us: "As chair of the National ANPR Independent Advisory Group, I will be requesting a report into this incident. I will focus on the comprehensive national standards that exist and look towards any emerging compliance issues or failure thereof."

The unsecured management dashboard could have been used by anyone who found it to reconstruct a particular vehicle's journey, or series of journeys, from its number plate, right down to the minute with ease. A malicious person could have renamed the cameras or altered key metadata shown to operators, such as a camera's location, direction, and unique identifying number. A total of 8,616,198 records of vehicle movements, by time, location, and number plate, could be searched through the dashboard last week, The Register understands. This number constantly grew as more and more number plates were captured by the 100 live cameras feeding the system, and locations of vehicles were logged along with timestamps. The dashboard was taken offline within a few hours of The Register alerting officials.

Bug

Newly Discovered macOS Image Capture Bug Can Fill Up Hard Drives With Empty Data (macrumors.com) 25

An anonymous reader quotes a report from MacRumors: A bug has been discovered in Apple's macOS Image Capture app that needlessly eats up potentially gigabytes of storage space when transferring photos from an iPhone or iPad to a Mac. Discovered by the developers of media asset management app NeoFinder and shared in a blog post called "Another macOS bug in Image Capture," the issue occurs when Apple's Mac tool converts HEIF photos taken by iOS to more standard JPG files. This process happens when users uncheck the "Keep Originals" option in Image Capture's settings, which converts the HEIC files to JPG when copied to Mac. However, the app also inexplicably adds 1.5MBs of empty data to every single file in the process.

It's worth noting that the bug only occurs when transferring photos from Apple devices, not when importing photos from digital cameras using Image Capture. NeoFinder's team says it has notified Apple of the bug, and the developers suggest anyone plagued by the issue can try using a new beta version of the third-party utility Graphic Converter, which includes an option to remove the unwanted empty data from the JPEG files.

Windows

You Can Now Manage Windows 10 Devices Through G Suite (zdnet.com) 55

Google has announced the general availability of a long-awaited feature -- the ability to manage Windows 10 devices through G Suite. From a report: Until today, companies that used G Suite to manage corporate endpoints could only enroll Android, iOS, Chrome, and Jamboard devices. Once enrolled in a G Suite enterprise plan, system administrators at these companies would have full control over the enrolled devices, to ensure that company data was safeguarded from sloppy employees. G Suite admins could enforce security policies related to login operations, file storage, encryption, and other features. Starting this week, the same features are now also available for working with Windows 10 devices, Google announced in a blog post. These include the ability to, among other things: Log into Windows 10 systems using a Google account, control Windows 10 update rules, and change Windows 10 settings remotely.
Android

Android OEM Patch Rates Have Improved, With Nokia and Google Leading the Charge (zdnet.com) 30

Security updates are reaching Android users faster and more reliably than in previous years. In research published this month, German cyber-security firm SRLabs said the Android patch gap has gone down from 44 days in 2018 to 38 days today. From a report: The term Android patch delay, or patch gap, refers to the time from when Google formally publishes a security update on its website, and until a smartphone vendor (OEMs, or original equipment manufacturers) integrates the patch into its firmware. SRLabs says it collected information on patches delays using its SnoopSnitch security scanner app installed on more than 500,000 Android smartphones. While the company reported that the patch delay has gone down by 15% in the last two years, the patch gap varied wildly across smartphone vendors, with some better than others at integrating the Google-provided security patches into their customized Android OS versions. Researchers said Google, Nokia, and Sony were the fastest at integrating the monthly Android Android security updates into their customized customized Android OS releases, while Xiaomi, HTC, and Vivo were the vendors lagging behind the most.
Crime

Parolees Are Being Forced To Download Telmate's Guardian App That Listens and Records Every Move (gizmodo.com) 228

XXongo writes: Monitoring parolees released from prison by an app on their smartphone sounds like a good idea, right? The phone has facial recognition and biometric ID, and a GPS system that knows where it is. But what if the app doesn't work? In a story on Gizmodo, the [Telmate Guardian] app's coding is "sloppy" and "irresponsible" and its default privacy settings are wildly invasive, asking for "excessive permissions" to access device data. And the app isn't even accurate on recognizing parolees, nor on knowing location, with one parolee noting that the app set off the high-pitched warning alarm and sent a notification to her parole officers telling him that she was not at home multiple times in the middle of the night, when she was in fact at home and in bed. The device also serves as a covert surveillance bug, with built-in potential to covertly record ambient audio from the phone, even in standby mode -- a feature which is not even legal in many states. "But there's nothing you can do," according to one parolee. "If you don't accept it, then you go back to prison. You're considered their property. That's how they see it."
Medicine

NHS Rejects Apple-Google Coronavirus App Plan (bbc.com) 36

The UK's coronavirus contact-tracing app is set to use a different model to the one proposed by Apple and Google, despite concerns raised about privacy and performance. From a report: The NHS says it has a way to make the software work "sufficiently well" on iPhones without users having to keep it active and on-screen. That limitation has posed problems for similar apps in other countries. Experts from GCHQ's National Cyber Security Centre have aided the effort. NCSC indicated that its involvement has been limited to an advisory role. "Engineers have met several core challenges for the app to meet public health needs and support detection of contact events sufficiently well, including when the app is in the background, without excessively affecting battery life," said a spokeswoman for NHSX, the health service's digital innovation unit.
Security

Hackers Are Exploiting a Sophos Firewall Zero-day (zdnet.com) 12

Cyber-security firm Sophos has published an emergency security update to patch a zero-day vulnerability in its XG enterprise firewall product that was being abused in the wild by hackers. From a report: Sophos said it first learned of the zero-day on late Wednesday, April 22, after it received a report from one of its customers. The customer reported seeing "a suspicious field value visible in the management interface." After investigating the report, Sophos determined this was an active attack and not an error in its product. "The attack used a previously unknown SQL injection vulnerability to gain access to exposed XG devices," Sophos said in a security advisory today. Hackers targeted Sophos XG Firewall devices that had their administration (HTTPS service) or the User Portal control panel exposed on the internet. Sophos said the hackers used the SQL injection vulnerability to download a payload on the device. This payload then stole files from the XG Firewall.
Mozilla

Firefox Raises Its Bug Bounties to $10,000 (mozilla.org) 5

"We're updating our bug bounty policy and payouts to make it more appealing to researchers and reflect the more hardened security stance we adopted after moving to a multi-process, sandboxed architecture," reports the Mozilla security blog: Besides rewarding duplicate submissions, we're clarifying our payout criteria and raising the payouts for higher impact bugs. Now, sandbox escapes and related bugs will be eligible for a baseline $8,000, with a high quality report up to $10,000. Additionally, proxy bypass bugs are eligible for a baseline of $3,000, with a high quality report up to $5,000...

Additionally, we'll be publishing more posts about how to get started testing Firefox — which is something we began by talking about the HTML Sanitization we rely on to prevent UXSS. By following the instructions there you can immediately start trying to bypass our sanitizer using your existing Firefox installation in less than a minute...

Lastly, we would like to let you know that we have cross-posted this to our new Attack & Defense blog. This new blog is a vehicle for tailored content specifically for engineers, security researchers, and Firefox bug bounty participants.

They point out that Firefox has one of the world's oldest bug bounty programs, dating back to 2004 -- and it's still going strong. "From 2017-2019, we paid out $965,750 to researchers across 348 bugs, making the average payout $2,775 — but as you can see in the graph below, our most common payout was actually $4,000!"
IT

Ventilator Companies Finally Make the Life Saving Devices Easier to Repair (vice.com) 32

America needs ventilators. The coronavirus has spread far enough that Donald Trump used the Defense Production Act on April 2 to make it easier to produce more. There's also broken ventilators on the market that could work with some repairs, but manufacturers spent weeks making it hard to get basic information needed for technicians to repair the machines. From a report: U.S. PIRG and other groups had been pressuring the manufacturers to release the ventilator information for weeks. On April 14, the States Treasurer of Pennsylvania, Delaware, Illinois, Rhode Island, and Colorado called on the manufacturers to release the documents in an open letter. Now, ventilator manufacturers GE, Fisher & Paykal, and Medtronic have made it easier to access the repair manuals and other service information hospitals need to repair broken ventilators. GE opened a web portal where people can download the repair information for its Carescape R860 and Engstrom ventilators. GE typically requires a 4-day in-person training class to learn to repair ventilators but is making the information available to the public "to help navigate this crisis and ensure ventilators are maintained as quickly as possible to get these vital systems back into patient care."

Medtronic, who makes a number of ventilators, has posted a portal to register for the design and repair information of its ventilators. Meaning that the savvy user could do more than repair a broken machine -- they may be able to build a whole new ventilator. But it's not enough, according to Kyle Wiens of iFixit, a company that advocates for the right-to-repair and teaches people how to fix their own stuff. "Medtronic only released the manual for the PB560, which they don't sell in the U.S," Wiens told Motherboard in a Twitter DM. "We don't have the manual for the PB980, their flagship model and the one used by our hospitals in San Luis Obispo."

Nintendo

Nearly 160,000 Nintendo Accounts Compromised In Massive Hack (digitaltrends.com) 12

Nintendo has confirmed that about 160,000 Nintendo Network ID accounts have been compromised since the beginning of April. Digital Trends reports: The Japan-based video game company says login ID and password information of these profiles were obtained "illegally by some means other than our service" and in response, it's freezing the ability to log into a Nintendo account through Nintendo Network ID (NNID). Nintendo began looking into a potential breach after several players reported suspicious logins and fraudulent transactions for digital items like Fortnite VBucks through linked PayPal accounts earlier this month. Nintendo's investigation revealed intruders may have accessed personal data such as nicknames, dates of birth, country of residence, and email addresses.

Plus, for users who used the same password for an NNID and Nintendo account, it's warning that their "balance and registered credit card/PayPal may be illegally used at My Nintendo Store or Nintendo eShop." In addition to halting Nintendo Network ID (NNID) logins, Nintendo is reaching out to affected customers via email and resetting their passwords. It's also recommending enabling two-factor authentication to everyone. Despite this, Nintendo is asking users who have discovered fraudulent transactions in their accounts to contact the company so it can cancel the purchases and possibly for initiating refunds.

Privacy

Apple and Google Pledge To Shut Down Coronavirus Tracker When Pandemic Ends (theverge.com) 63

An anonymous reader quotes a report from The Verge: On Friday, Apple and Google revised their ambitious automatic contact-tracing proposal, just two weeks after the system was first announced. An Apple representative said the changes were the result of feedback both companies had received about the specifications and how they might be improved. The companies also released a "Frequently Asked Questions" page, which rehashes much of the information already made public. On a call accompanying the announcement, representatives from each company pledged for the first time to disable the service after the outbreak had been sufficiently contained. Such a decision would have to be made on a region-by-region basis, and it's unclear how public health authorities would reach such a determination. However, the engineers stated definitively that the APIs were not intended to be maintained indefinitely.

Under the new encryption specification, daily tracing keys will now be randomly generated rather than mathematically derived from a user's private key. Crucially, the daily tracing key is shared with the central database if a user decides to report their positive diagnosis. As part of the change, the daily key is now referred to as the "temporary tracing key," and the long-term tracing key included in the original specification is no longer present. The new encryption specification also establishes specific protections around the metadata associated with the system's Bluetooth transmissions. Along with the random codes, devices will also broadcast their base power level (used in calculating proximity) and which version of the tool they are running. The companies are also changing the language they use to describe the project. The protocols were initially announced as a contact-tracing system, it is now referred to as an "exposure notification" system. The companies say the name change reflects that the new system should be "in service of broader contact tracing efforts by public health authorities."

Slashdot Top Deals