Network

Long the Anonymous Cogs in Corporate America's Back Office, Work-From-Home Crises Have Put the IT Department in the Spotlight (bloomberg.com) 76

In ordinary times, they moved among us largely unnoticed. Now we can't get enough of them. The Covid-19 pandemic has thrust once-anonymous IT support workers into a new role: corporate saviors. From a report: As millions of employees make the transition from well-maintained office equipment to jury-rigged kitchen table setups, information technology departments have been called upon to keep companies online and connected. Requests range in size and scale, from replacing employees' $5 mouses, to speeding up networks, to keeping multimillion-dollar data centers up and running. For many departments, the result has been virtually unprecedented workloads. On March 12, Qualcomm told all staff to prepare to start working remotely in three days. Vice president of IT infrastructure, Zeeshan Sabir, and his team then worked about 72 hours straight trying to prepare a lot of laptops for secure, remote access and get other corporate systems ready. "I just saw heroics," he said. "I didn't see a blip of complaint from anyone."

[...] The way most IT departments are set up has meant many directors have been juggling major issues alongside relatively minor ones. At Bay Area transit agency SamTrans, IT manager Edward Kelly got help from AT&T to quickly increase the speed of connections to the agency's networks once its 200 employees made the switch to remote work. At the same time, Kelly's team of five was flooded by calls from employees who'd forgotten their computer password and guessed wrong too many times. He said he's also hoping people learn to use the "reply-all" button on group emails more sparingly. As many employees' home computers infuriate them, tensions can run high, said Jennifer Reed, a consultant at IT outsourcing firm Viqtor Davis North America.

Businesses

CFOs Looking To Make Remote Work, Telecommuting More Permanent Following COVID-19, Says Gartner Study (zdnet.com) 104

An anonymous reader quotes a report from ZDNet: The new normal telecommuting may be a bit more permanent than realized, as 74% of CFOs say they expect to move previously on-site employees remote post-COVID-19, according to a Gartner survey. The survey, which had 317 CFO respondents on March 30, highlighted how remote work may become more of the norm as companies look to cut commercial real estate costs. Gartner found that almost a quarter of respondents said they will move at least 20% of their on-site employees to remote work permanently. The research firm is taking the pulse of the COVID-19 CXO shifts in a series of surveys.

Among the key shifts from CFOs and enterprises as they manage cash via COVID-19 shutdowns:
- 81% of CFOs plan to exceed their contractual obligations to hourly workers and to fund that they are using remote work to offer flexible schedules and maintain operations.
- 90% of CFOs said their accounting close operations will be able to run effectively without disruptions off-site.
- 20% of CFOs said they are cutting their on-premise technology spending with 12% planning the same move.
- 13% of CFOs have already cut real estate expenses with another 9% planning cuts in the months to come.

Privacy

Easy-To-Pick 'Smart' Locks Gush Personal Data, FTC Finds (arstechnica.com) 59

An anonymous reader quotes a report from Ars Technica: A padlock -- whether it uses a combination, a key, or "smart" tech -- has exactly one job: to keep your stuff safe so other people can't get it. Tapplock, Inc., based in Canada, produces such a product. The company's locks unlock with a fingerprint or an app connected by Bluetooth to your phone. Unfortunately, the Federal Trade Commission said, the locks are full of both digital and physical vulnerabilities that leave users' stuff, and data, at risk. The FTC's complaint (PDF) against Tapplock, released Monday, basically alleges that the company misrepresented itself, because it marketed its products as secure and tested when they were neither. A product -- any product -- simply being kind of crappy doesn't necessarily fall under the FTC's purview. Saying untrue things about your product in your advertisement or privacy policy, however, will make the commission very unhappy with you indeed.

The lock may be built with "7mm reinforced stainless steel shackles, strengthened by double-layered lock design with anti-shim and anti-pry technologies," as Tapplock's website promises, but according to the FTC, perhaps it should have considered anti-screwdriver technologies. As it turns out, a researcher was able to unlock the lock "within a matter of seconds" by unscrewing the back panel. Oops. The complaint also pointed to several "reasonably foreseeable" software vulnerabilities that the FTC alleges Tapplock could have avoided if the company "had implemented simple, low-cost steps."

One vulnerability security researchers identified allowed a user to bypass the account authentication process entirely in order to gain full access to the account of literally any Tapplock user, including their personal information. And how could this happen? "A researcher who logged in with a valid user credential could then access another user's account without being re-directed back to the login page, thereby allowing the researcher to circumvent Respondent's authentication procedures altogether," the complaint explains. A second vulnerability allowed researchers the ability to access and unlock any lock they could get close enough to with a working Bluetooth connection. That's because Tapplock "failed to encrypt the Bluetooth communication between the lock and the app," leaving the data wide open for the researchers to discover and replicate. The third vulnerability outlined in the complaint also has to do with a failure to secure communication data. That app that allows "unlimited" connections? The primary owner can of course add and revoke authorized users from the lock. But someone whose access was revoked could still access the lock because the vulnerability allowed for sniffing out the relevant data packets.
As part of the settlement, the FTC is requiring Tapplock to create a security program for its products. "That program is required to include training for employees; timely disclosure of 'covered incidents,' including both loss of personal information and also unauthorized access to systems; actual penetration testing of the network; and several other elements, including annual review," reports Ars Technica.
Businesses

It's a 'Cold War Every Day' Inside Apple's IS&T Group (buzzfeednews.com) 45

An anonymous reader shares an excerpt from a report via BuzzFeed News: A group inside Apple called Information Systems & Technology, or IS&T, builds much of the company's internal technology tools -- from servers and data infrastructure to retail and corporate sales software -- and operates in a state of tumult. IS&T is made up largely of contractors hired by rival consulting companies, and its dysfunction has led to a rolling state of war. "It's a huge contractor org that handles a crazy amount of infrastructure for the company," one ex-employee who worked closely with IS&T told me. "That whole organization is a Game of Thrones nightmare." Interviews with multiple former IS&T employees and its internal clients paint a picture of a division in turmoil, where infighting regularly prevents the creation of useful software, and whose contract workers are treated as disposable parts.

"There's a Cold War going on every single day," Archana Sabapathy, a former IS&T contractor who did two stints in the division, told me. Sabapathy's first stint at IS&T lasted more than three years, the second only a day. Inside the division, she said, contracting companies such as Wipro, Infosys, and Accenture are constantly fighting to fill roles and win projects, which are handed out largely on the basis of how cheaply they can staff up to Apple's needs. "They're just fighting for the roles," Sabapathy told me. "That's all they care about, not the work, not the deliverables, the effort they put in, or even talent. They're not looking for any of those aspects." IS&T is thus filled with vendor tribalism, where loyalty to one's contracting company trumps all. "Making a friendship is -- like you wouldn't even think about that," Sabapathy told me, speaking of cross-vendor relationships. "It's not the traditional American way of working anymore. You build relationships when you come to work because you spend most of your time here -- that's not there."
"Sabapathy told [BuzzFeed's Alex Kantrowitz] Apple employees' expectations for their IS&T contractors were unrealistic given that they saw the sum total they were paying the consulting companies ($150 to $120 an hour, she said) but the contractors themselves were making much less ($40 to $55 an hour) after the companies took their cut," writes Kantrowitz. "The approach leaves Apple with lesser contractors but the same high demands, a recipe for disappointment."

In closing, Kantrowitz suggests if Apple wants to become inventive again, "it will need to give its employees more time to develop new ideas." He adds: "IS&T could therefore become a division of strength at Apple one day, building tools that minimize work that supports existing products while making room for those ideas. But until Apple gives the division a hard look, its employees will be stuck spending their time reworking broken internal software, and wishing they were inventing instead."
Businesses

WeWork Sues SoftBank In Intensifying Crisis Over Canceled $3 Billion Tender Offer (techcrunch.com) 17

Just days after SoftBank announced that it would not consummate its $3 billion tender offer for WeWork shares that would have bought out some of the equity held by the company's co-founder Adam Neumann along with venture capital firms like Benchmark and many individual company employees, the company is now retaliating, suing SoftBank over alleged breach of contract and breach of fiduciary duty. TechCrunch reports: In a press statement this morning, the Special Committee of WeWork's board said that it "regrets the fact that SoftBank continues to put its own interests ahead of those of WeWork's minority stockholders." WeWork's Special Committee argues that SoftBank already received the benefits of the contract it signed last year, which included board control provisions. It's demanding that SoftBank either complete the transaction, or offer cash to cover damages related to its scuttling of the deal. Under the terms of the tender offer proposed in November last year, SoftBank would buy upwards of $3 billion in shares from existing shareholders with the transaction closing at the beginning of April. As part of the terms of that contract, the co-working company and SoftBank agreed to a set of performance milestones that WeWork agreed to meet in exchange for the secondary liquidity. Such terms are customary in most financial transactions.

SoftBank in its statement last week said that WeWork failed to meet a number of those performance requirements, and said that it was within its rights under the tender offer contract to walk away from the deal. WeWork's financials have been rocked by the global pandemic of novel coronavirus, which has seen the company's co-working facilities mostly closed worldwide as part of public health mandates for social distancing. Given the disagreement between the parties, a lawsuit was all but inevitable.

Google

Google Backs Apple's SMS OTP Standard Proposal 40

Google is now backing a standard proposed by Apple engineers in January to create a default format for one-time passcodes (OTP) sent via SMS to users during the two-factor authentication (2FA) process. From a report: The standard, proposed by Apple engineers working on the Safari WebKit project, has now reached the status of official Web Platform Incubator Community Group (WICG) specification draft. "We've moved 'Origin-bound one-time codes delivered via SMS' to @wicg_, where we're working on a shared spec with our collaborators at Google. Please take a look! Updated explainer, and specification," wrote Apple's Ricky Mondello. The proposal aims to fix some issues with the current state of SMS 2FA/OTP codes, all of which have different formats, unique per the websites sending the codes.
Television

Samsung's Older Smart TVs Are Losing Remote Control App Support (engadget.com) 66

Samsung is killing its Smart View app for Android and iOS, which serves as a remote control for its older smart TVs. From a report: The company has updated the application's descriptions to announce that it will no longer be supported starting on October 5th. Android Police first spotted the changes and noted that, in addition to its capability as a remote control, Smart View can also beam music and media to the company's TVs. It's unclear how Samsung defines "older" -- hence which all models will be impacted.
Microsoft

Microsoft Announces IPE, a New Code Integrity Feature for Linux (zdnet.com) 89

Microsoft has revealed details about a new project it has been working on for Linux kernel. From a report: Named Integrity Policy Enforcement -- or IPE -- the project is a Linux security module (LSM). LSMs are optional add-ons for the Linux kernel that enable additional security features. According to a documentation page published on Monday, IPE is Microsoft's attempt to solve the code integrity problem for Linux -- an operating system the company broadly uses in its Azure cloud service. On Linux systems where IPE is enabled, system administrators can create a list of binaries that are allowed to execute and then add the verification attributes the kernel needs to check for each binary before allowing it to run. If binaries have been altered by an attacker, IPE can block the execution of the malicious code.
Firefox

Firefox 75 Arrives With Revamped Address Bar; Mozilla To Stick With 2020 Schedule (venturebeat.com) 43

An anonymous reader writes: Mozilla today launched Firefox 75 for Windows, Mac, and Linux. Firefox 75 includes a revamped address bar with significant search improvements, a few performance tweaks, and a handful of developer features. You can download Firefox 75 for desktop now from Firefox.com, and all existing users should be able to upgrade to it automatically. According to Mozilla, Firefox has about 250 million active users, making it a major platform for web developers to consider.

When the coronavirus crisis took hold, millions found themselves spending more time in their browsers as they learn and work from home. But the crisis is also impacting software developers. Google was forced to pause its Chrome releases, which typically arrive every six weeks. Ultimately, Chrome 81 was delayed, Chrome 82 is being skipped altogether, and Chrome 83 has been moved up a few weeks. Microsoft has followed suit with Edge's release schedule, consistent with Google's open source Chromium project, which both Chrome and Edge are based on. Mozilla wants to make clear it is not in the same boat. The company took an indirect jab at Google and Microsoft today, saying: "We've built empathy into our systems for handling difficult or unexpected circumstances. These strengths are what allow us to continue to make progress where some of our competitors have had to slow down or stop work."

Microsoft

Microsoft Buys Corp.com So Bad Guys Can't (krebsonsecurity.com) 76

Brian Krebs: In February, KrebsOnSecurity told the story of a private citizen auctioning off the dangerous domain corp.com for the starting price of $1.7 million. Domain experts called corp.com dangerous because years of testing showed whoever wields it would have access to an unending stream of passwords, email and other sensitive data from hundreds of thousands of Microsoft Windows PCs at major companies around the globe. This week, Microsoft agreed to buy the domain in a bid to keep it out of the hands of those who might abuse its awesome power.
Communications

Russian Telco Hijacked Internet Traffic of Google, AWS, Cloudflare, and Others (zdnet.com) 45

Last week, traffic meant for more than 200 of the world's largest content delivery networks (CDNs) and cloud hosting providers was suspiciously redirected through Rostelecom, Russia's state-owned telecommunications provider. From a report: The incident affected more than 8,800 internet traffic routes from 200+ networks, and lasted for about an hour. Impacted companies are a who's who in the cloud and CDN market, including big names such as Google, Amazon, Facebook, Akamai, Cloudflare, GoDaddy, Digital Ocean, Joyent, LeaseWeb, Hetzner, and Linode.
IT

uTorrent is the Most Used BitTorrent Client By Far (torrentfreak.com) 60

Ernesto, writing for TorrentFreak: With help from iknowwhatyoudownload we looked at over 25 million logged BitTorrent connections on a single day last week. This reveals that more than two-thirds (68.6%) of these were using uTorrent's desktop version. The vast majority of these users were updated to the most recent 3.5.5 release, but dozens of older versions are in use as well. Although no longer officially supported, there are also hundreds of thousands of people who still use uTorrent for Mac.

The most popular Mac client, however, appears to be Transmission. This is a notable change compared to a decade ago when its market share was much lower. Although Transmission also has a beta Windows release, that userbase is believed to be relatively small. Below is an overview of all software with at least 0.1% market share -- which translates to roughly 25,000 logged connections.

Education

US Schools Are Banning Zoom and Switching To Microsoft Teams (betanews.com) 121

After many schools adopted Zoom to conduct online lessons during the coronavirus lockdown, concerns about security and privacy have led to a ban on the video conferencing software across the U.S. BetaNews reports: The chancellor of New York City's Department of Education Richard A Carranza sent an email to school principals telling them to "cease using Zoom as soon as possible." And he is not alone; schools in other parts of the country have taken similar action, and educators are now being trained to use Microsoft Teams as this has been suggested as a suitable alternative, partly because it is compliant with FERPA (Family Educational Rights and Privacy Act).

Documents seen by Chalkbeat show that principals in NYC have been told: "Based on the DOE's review of those documented concerns, the DOE will no longer permit the use of Zoom at this time." The Washington Post quotes Danielle Filson, spokesperson for the NYC Education Department, as saying: "Providing a safe and secure remote learning experience for our students is essential, and upon further review of security concerns, schools should move away from using Zoom as soon as possible. There are many new components to remote learning, and we are making real-time decisions in the best interest of our staff and student. We will support staff and students in transitioning to different platforms such as Microsoft Teams that have the same capabilities with appropriate security measures in place."
Clark County Public Schools in Nevada, as well as schools in Utah, Washington State and beyond are looking into Zoom alternatives.
The Almighty Buck

PayPal and Venmo Are Letting SIM Swappers Hijack Accounts (vice.com) 42

An anonymous reader quotes a report from Motherboard: Several major apps and websites, such as Paypal and Venmo have a flaw that lets hackers easily take over users' accounts once they have taken control of the victim's phone number. Earlier this year, researchers at Princeton University found 17 major companies, among them Amazon, Paypal, Venmo, Blizzard, Adobe, eBay, Snapchat, and Yahoo, allowed users to reset their passwords via text message sent to a phone number associated with their accounts. This means that if a hacker takes control of a victim's cellphone number via a common and tragically easy to perform hack known as SIM swapping, they can then hack into the victim's online accounts with these apps and websites.

Last week, two months after their initial outreach to the companies to report this flaw in their authentication mechanisms, the Princeton researchers checked again to see if the companies had fixed the problem. Some, including Adobe, Blizzard, Ebay, Microsoft, and Snapchat, have plugged the hole. Others have yet to do it. Paypal and Venmo, given that they are apps that allow users to exchange money and are linked to bank accounts or credit cards, may be the most glaring examples. Motherboard verified this week that it's possible to reset passwords on Paypal and Venmo via text message.
Fear not, there is a solution. "The easiest way to make it impossible for SIM swappers to take over your accounts after they hijack your number is to unlink your phone number with those accounts, and use a VoIP number -- such as Google Voice, Skype, or another -- instead," reports Motherboard. "Google Voice numbers, given that they're not actually linked to a real SIM card, are much harder to hijack."
Bug

Some Users Experiencing System Crashes on macOS 10.15.4, Especially During Large File Transfers (macrumors.com) 58

A sizeable number of Mac users are experiencing occasional system crashes after updating to macOS Catalina version 10.15.4, released a few weeks ago. From a report: The crashing issue appears to be most prominent when users attempt to make large file transfers. In a forum post, SoftRAID described the issue as a bug and said that it is working with Apple engineers on a fix for macOS 10.15.5, or a workaround. "SoftRAID said the issue extends to Apple-formatted disks: There is a serious issue with 10.15.4. It shows up in different scenarios, even on Apple disks but is more likely when there are lots of IO threads. We think it is a threading issue. So while SoftRAID volumes are hit the hardest (it's now hard to copy more than 30GB of data at a time), all systems are impacted by this. In our bug report to Apple, we used a method to reproduce the problem with ONLY Apple formatted disks. Takes longer to reproduce, but that is more likely to get a faster fix to the user base."
Businesses

What It's Like To Attend a Conference -- in Person -- in the Age of Covid-19? (fastcompany.com) 35

What happens when no one shows up for a tech conference?

Fast Company's technology editor harrymcc writes: From Apple to Microsoft to Google, major tech companies have responded to the coronavirus crisis by either canceling their 2020 conference or making them purely virtual. But one well-established event — Vancouver's CanSecWest — went ahead earlier this month, with streaming as an option but not mandatory. Only three attendees showed up in the flesh. But so did security reporter Seth Rosenblatt, who wrote about the eerie experience for Fast Company.
They were outnumbed by the six staffers at the event -- "there to run the online component" -- but the article notes that the conference's organizer and founder promised all attendees "infrared body temperature checks, on-site coronavirus testing, ample supplies of disposable face masks and hand sanitizer, and restrictions on physical contact and interaction..."

"Empty hallways and escalators echoed with every footstep, and it smelled empty, the ventilation system circulating unused air. At the conference registration desk, I was offered a disposable surgical face mask and gloves."
China

Attack Campaign Hits Thousands of MS-SQL Servers For Two Years (csoonline.com) 33

"In December, security researchers noticed an uptick in brute-force attacks against publicly exposed Microsoft SQL servers," reports CSOnline.

"It turns out the attacks go as far back as May 2018 and infect on average a couple thousand database servers every day with remote access Trojans and cryptominers."

Slashdot reader itwbennett writes: While the primary goal of the attack seems to be cryptocurrency mining, "what makes these database servers appealing for attackers apart from their valuable CPU power is the huge amount of data they hold," say researchers from Guardicore who investigated the attacks. The researchers also note that most machines (60%) stay infected only briefly, but "almost 20% of all breached servers remained infected for more than a week and even longer than two weeks," and 10% become reinfected...

[T]he attackers aggressively remove malware from competitors from targeted machines.

Many of the infected machines are located in America, India, South Korea, and Turkey, according to the article, which adds that the researchers traced the campaign back to China.

"The scans and attacks originate from Chinese IP addresses -- likely associated with infected and hijacked machines -- and the command-and-control servers are also hosted in China and use Chinese language for their web-based management interfaces."
Chrome

U.S. Government: Update Chrome 80 Now, Multiple Security Concerns Confirmed (forbes.com) 54

Part of America's Department of Homeland Security, the Cybersecurity and Infrastructure Security Agency (CISA) "has advised users to update Google Chrome as new high-rated security vulnerabilities have been found," reports Forbes: In an April 1 posting, CISA confirmed that Google Chrome version 80.0.3987.162 "addresses vulnerabilities that an attacker could exploit to take control of an affected system," be that Windows, Mac or Linux. It went on to state that it "encourages" users and administrators to apply the update. It's not just CISA that is warning about the need to update Google Chrome. The Center for Internet Security (CIS) is a non-profit entity that works to safeguard both private and public organizations against cyber threats. In a multi-state information sharing and analysis center (MS-ISAC) advisory, it has also warned of multiple vulnerabilities in Google Chrome.

The most severe of these could allow an attacker to achieve arbitrary code execution within the context of the browser... All it would take for an attacker to exploit the vulnerabilities is to get the user to visit, by way of a phishing attack or even redirection from a compromised site, a maliciously crafted web page.

Beside three high-rated vulnerabilities, Forbes reports that "a further five security vulnerabilities were discovered by the Google internal security team using a combination of internal audits and fuzzing."
IBM

Not Just 'The Death of IT'. Cringely Also Predicts Layoffs For Many IT Contractors (cringely.com) 78

Last week long-time tech pundit Robert Cringely predicted "the death of IT" in 2020 due to the widespread adoption of SD-WAN and SASE.

Now he's predicting "an even bigger bloodbath as IT employees at all levels are let go forever," including IT consultants and contractors. My IT labor death scenario now extends to process experts (generally consultants) being replaced with automation. In a software-defined network, whether that's SD-WAN or SASE, so much of what used to be getting discreet boxes to talk with one another over the network becomes a simple database adjustment. The objective, in case anyone forgets (as IT, itself, often does) is the improvement of the end-user experience, in this case through an automated process. With SD-WAN, for example, there are over 3,000 available Quality of Service metrics. You can say that Office 365 is a critical metric as just one example. Write a script to that effect into the SD-WAN database, deploy it globally with a keyclick and you are done...

It's slowly dawning on IBM [and its competitors] that they have to get rid of all those process experts and replace them with a few subject matter experts. Here's the big lesson: with SD-WAN and SASE the process no longer matters, so knowing the process (beyond a few silverbacks kept on just in case the world really does end) isn't good for business.

Cringely predicts the downgrading of corporate bonds will also put pressure on IBM and its competitors, perhaps ultimately leading to a sale or spin-off at IBM. "Either they sell the parts that don't make money, which is to say everything except Red Hat and mainframes, or they sell the whole darned thing, which is what I expect to happen."

With that he predicts thousands of layoffs or furloughs — and while the bond market puts IBM in a bigger bind, "this could apply in varying degrees to any IBM competitors."
Security

A Hacker Found a Way To Take Over Any Apple Webcam (wired.com) 52

An anonymous reader quotes a report from Wired: Apple has a well-earned reputation for security, but in recent years its Safari browser has had its share of missteps. This week, a security researcher publicly shared new findings about vulnerabilities that would have allowed an attacker to exploit three Safari bugs in succession and take over a target's webcam and microphone on iOS and macOS devices. Apple patched the vulnerabilities in January and March updates. But before the fixes, all a victim would have needed to do is click one malicious link and an attacker would have been able to spy on them remotely.

The bugs Pickren found all stem from seemingly minor oversights. For example, he discovered that Safari's list of the permissions a user has granted to websites treated all sorts of URL variations as being part of the same site, like https://www.example.com, http://example.com and fake://example.com. By "wiggling around," as Pickren puts it, he was able to generate specially crafted URLs that could work with scripts embedded in a malicious site to launch the bait-and-switch that would trick Safari. A hacker who tricked a victim into clicking their malicious link would be able to quietly launch the target's webcam and microphone to capture video, take photos, or record audio. And the attack would work on iPhones, iPads, and Macs alike. None of the flaws are in Apple's microphone and webcam protections themselves, or even in Safari's defenses that keep malicious sites from accessing the sensors. Instead, the attack surmounts all of these barriers just by generating a convincing disguise.

Slashdot Top Deals