Communications

Comcast Details What the Coronavirus Has Done To Network Traffic (venturebeat.com) 56

Comcast said that internet traffic has risen 32% because of the coronavirus, but the company said it has the capacity to handle peak traffic demands in the U.S. From a report: Tony Werner, Comcast president of technology, said in a press briefing that the company normally adds capacity 12-18 months ahead of time, with typical plans targeting 45% a year increases in traffic. "First and foremost, I think it's important to know that the network is performing well," Werner said. "And people are able to -- both business and customers working from home -- do the things they need to do with a great deal of proficiency." He said the company engineers the networks for "peak traffic" and that traffic is up more than 32% overall as of last week. Some parts of the country are up 60%, including Seattle, San Francisco, and now Chicago. [...] Video conference calls using the voice-over-internet-protocol on Comcast are up 212% since March 1.
Security

Houseparty App Offers $1M Reward To Unmask Entity Behind Hacking Smear Campaign (zdnet.com) 18

Houseparty, a video conferencing desktop and mobile application, said it would pay a $1 million bounty to anyone who could unmask the entity behind what the company described as "a paid commercial smear campaign." From a report: The company's apparent anger comes after Houseparty has been at the center of media reports published yesterday by three British tabloids. The Sun, the Express, and Mirror Online reported on Monday on a large number of Houseparty users claiming they had social media accounts hacked and taken over after installing the video conferencing app on their smartphones. Users reported having Netflix, eBay, Instagram, Snapchat, and Spotify accounts taken over; however, very few were able to provide details about what really happened. Houseparty officials feel they're now being defamed unjustly in a game of dirty politics.
Microsoft

Microsoft's Chromium Edge is Getting Vertical Tabs, Smart Copy, and Password Monitor (venturebeat.com) 20

Microsoft today announced upcoming features for its Edge browser based on Google's Chromium open source project, the same browser Google's Chrome is based on. Consumer features like Vertical Tabs, Smart Copy, and Password Monitor are coming soon. Microsoft also shared a few updates for existing or already announced features like Collections, InPrivate mode, and Immersive Reader.
Businesses

Whatever Happened to Ashley Madison? Affairs in the Time of Coronavirus (venturebeat.com) 67

An anonymous reader quotes VentureBeat: Ashley Madison's tagline has taken on a new ring amid the COVID-19 pandemic — "Life's short. Have an affair." And the "married dating" site, used to conduct clandestine affairs, has found itself in the midst of a boom. Despite the fact that it's harder than ever to physically meet up with a fellow cheater, Ashley Madison is seeing a surge in users. Some are just looking to chat with someone other than a spouse, some are seeking emotional validation or the fantasy of pursuing a secret sex life...

The company became a household name in July 2015, when hackers stole data on 32 million cheating spouses. The leak of sensitive data led to spouses discovering that their significant others were cheating. Divorces, breakups, and suicides ensued. The hackers also exposed that Ashley Madison used bots posing as attractive young women to lure men into engaging more with the site. The company says it has since beefed up its security and rid itself of the bots. And now it's more than double the size it was at the time of the hack, with over 65 million members last year. During 2019, the company added 15,500 new members a day. More recently, in the midst of the COVID-19 pandemic, it has been adding 17,000 new members a day.

Its chief strategy officer tells them that after their massive data breach "we were signing up more than 100,000 people a day... [W]e also saw revenues jump during that small time frame." (And the site also acquired "a whole new security team...")

Interestingly, he also says Facebook won't allow them to buy ads, which seems especially anticompetitive since Facebook runs its own dating site. "They block us but let other dating platforms advertise... We have had multiple conversations with them, and no, it's a fruitless conversation, unfortunately... This is part of the problem with Facebook, in general, in that they get to pick and choose which companies are going to advertise on the second-largest, if not the largest, digital advertising platform in the world. We question the validity of that."
Networking

Cringely Predicts 2020 Will See 'the Death of IT' (cringely.com) 232

Long-time technology pundit Robert Cringely writes: IT — Information Technology — grew out of something we called MIS — Management Information Systems — but both meant a kid in a white shirt who brought you a new keyboard when yours broke. Well, the kid is now gone, sent home with everyone else, and that kid isn't coming back... ever. IT is near death, fading by the day. But don't blame COVID-19 because the death of IT was inevitable. This novel coronavirus just made it happen a little quicker...

Amazon has been replacing all of our keyboards for some time now, along with our mice and our failed cables, and even entire PCs. IT has been changing steadily from kids taking elevators up from the sub-basement to Amazon Prime trucks rolling-up to your mailbox. At the same time, our network providers have been working to limit their truck rolls entirely. Stop by the Comcast storefront to get your cable modem, because nobody is going to come to install it if you aren't the first person living there to have cable...

Secure Access Service Edge (SASE) extends both the network and a security model end-to-end over any network including 4G or 5G wireless. Some folks will run their applications in their end device, whether it is a PC, phone, tablet, whatever, and some will run their applications in the same cloud as SASE, in which case everything will be that much faster and more secure. That's end end-game if there is one — everything in the cloud with your device strictly for input and output, painting screens compressed with HTML5. It's the end of IT because your device will no longer contain anything so it can be simply replaced via Amazon if it is damaged or lost, with the IT kid in the white shirt becoming an Uber driver.

Since COVID-19 is trapping us in our homes it is forcing this transition to happen faster than it might have. But it was always going to happen.

The Internet

Dark Web Hosting Site Suffers Cyberattack, 7,600 Sites Down (zdnet.com) 48

It's the largest free web hosting provider for dark web services. But remember back in 2018 when its 6,500 sites all went down after attackers accessed its database and deleted all its accounts?

It happened again -- for the second time in 16 months. And this time, ZDNet reports, Daniel's Host won't be coming back online for several months: Almost 7,600 dark web portals have been taken offline following the hack, during which an attacker deleted the web hosting portal's entire database. This happened earlier this month, on March 10, at around 03:30 am UTC, according to a message posted on DH's now-defunct portal by Daniel Winzen, the German software developer behind the service.

Winzen said that an attacker accessed the DH backend and deleted all hosting-related databases. The attacker then deleted Winzen's database account and created a new one to use for future operations. Winzen discovered the hack the next morning, at which time most of the data was already lost.

The service doesn't keep backups by design.

In an email to ZDNet today, Winzen said he has yet to find out how the hacker breached the DH backend. However, since the dark web hosting service was more of a hobby, Winzen didn't look too much into it. "I am currently very busy with my day-to-day life and other projects, I decided to not spend too much time investigating," he told ZDNet...

Winzen said that users should consider the passwords for their DH accounts as "leaked" and change them if they used the same password for other accounts.

Winzen told ZDNet he still hopes to relaunch the service "at a later time" with "new features and improvements."

"Not having to administrate the services all the time will hopefully give me more time for actual development."
Software

Bosses Panic-Buy Spy Software To Keep Tabs On Remote Workers (bloomberg.com) 94

An anonymous reader quotes a report from Bloomberg: With so many people working remotely because of the coronavirus, surveillance software is flying off the virtual shelves. "Companies have been scrambling," said Brad Miller, CEO of surveillance-software maker InterGuard. "They're trying to allow their employees to work from home but trying to maintain a level of security and productivity." Along with InterGuard, software makers include Time Doctor, Teramind, VeriClock, innerActiv, ActivTrak and Hubstaff. All provide a combination of screen monitoring and productivity metrics, such as number of emails sent, to reassure managers that their charges are doing their jobs.

ActivTrak's inbound requests have tripled in recent weeks, according to CEO Rita Selvaggi. Teramind has seen a similar increase, said Eli Sutton, vice president of global operations. Jim Mazotas, innerActive's founder, said phones have been ringing off the hook. Managers using InterGuard's software can be notified if an employee does a combination of worrisome behaviors, such as printing both a confidential client list and a resume, an indication that someone is quitting and taking their book of business with them. "It's not because of lack of trust," Miller said, who compared the software to banks using security cameras. "It's because it's imprudent not to do it." The software can also be a way for employers to grant more flexibility to workers to fit their jobs around other parts of their lives. It may also let managers spot areas that are overstaffed or where they may need additional hands.
Sutton from software maker Teramind says employers worried about workers' every moves might have a bigger issue to deal with. "It's not about spying on the user," Sutton said. "If you hired them, you should trust them. If you don't, they have no reason to be part of the organization."

Have you been required to use surveillance software while working from home? If so, which software is your employer using?
Bug

Unpatched iOS Bug Blocks VPNs From Encrypting All Traffic (bleepingcomputer.com) 19

An anonymous reader quotes a report from Bleeping Computer: A currently unpatched security vulnerability affecting iOS 13.3.1 or later prevents virtual private network (VPNs) from encrypting all traffic and can lead to some Internet connections bypassing VPN encryption to expose users' data or leak their IP addresses. While connections made after connecting to a VPN on your iOS device are not affected by this bug, all previously established connections will remain outside the VPN's secure tunnel as ProtonVPN disclosed.

The bug is due to Apple's iOS not terminating all existing Internet connections when the user connects to a VPN and having them automatically reconnect to the destination servers after the VPN tunnel is established. "Most connections are short-lived and will eventually be re-established through the VPN tunnel on their own," ProtonVPN explains. "However, some are long-lasting and can remain open for minutes to hours outside the VPN tunnel." During the time the connections are outside of the VPN secure communication channels, this issue can lead to serious consequences. For instance, user data could be exposed to third parties if the connections are not encrypted themselves, and IP address leaks could potentially reveal the users' location or expose them and destination servers to attacks.
Until Apple provides a fix, the company recommends using Always-on VPN to mitigate this problem. "However, since this workaround uses device management, it cannot be used to mitigate the vulnerability for third-party VPN apps such as ProtonVPN," the report adds.
Security

'League' of Cybersecurity Professionals Band Together To Help Hospitals (nbcnews.com) 7

pgmrdlm writes: A growing group of cybersecurity professionals is volunteering their expertise to help hospitals fight off hackers while doctors and nurses fight the coronavirus. Calling themselves the CTI League -- Countering Threat Intelligence, and a nod to the superhero team the Justice League -- the group has swelled from a handful of professionals to 450 members worldwide in less than two weeks. "If some hospital gets attacked by some ransomware and wouldn't be able to pay, people will die because they wouldn't be able to get the medical services needed," said the group's founder, Ohad Zaidenberg.
Security

Rare BadUSB Attack Detected in the Wild Against US Hospitality Provider (zdnet.com) 38

A US hospitality provider has recently been the target of an incredibly rare BadUSB attack, ZDNet has learned from cyber-security firm Trustwave. From a report: The attack happened after the company received an envelope containing a fake BestBuy gift card, along with a USB thumb drive.The receiving company was told to plug the USB thumb drive into a computer to access a list of items the gift card could be used for. But in reality, the USB thumb drive was what security experts call a "BadUSB" -- a USB thumb drive that actually functions as a keyboard when connected to a computer, where it emulates keypresses to launch various automated attacks.
Microsoft

Microsoft Announces New 'Hardware-Enforced Stack Protection' Feature (zdnet.com) 36

Microsoft announced today a new security feature for the Windows operating system. From a report: Named "Hardware-enforced Stack Protection," this feature allows applications to use the local CPU hardware to protect their code while running inside the CPU's memory. As the feature's name suggests, its primary role is to protect the (memory) stack -- where an app's code is stored during execution. "Hardware-enforced Stack Protection" works by enforcing strict management of the memory stack through the use of a combination between (1) modern CPU hardware and (2) shadow stacks. The term shadow stacks is a new one and refers to a copies of a program's intended execution flow (also referred to as the code's execution order). The new "Hardware-enforced Stack Protection" feature plans to use the hardware-based security features in modern CPUs to keep a copy of the app's shadow stack (intended code execution flow) in a hardware-secured environment.
Data Storage

HPE Says Firmware Bug Will Brick Some SSDs Starting in October this Year (zdnet.com) 97

An anonymous reader writes: Hewlett Packard Enterprise (HPE) issued a security advisory last week warning customers about a bug in the firmware of some SAS SSDs (Serial-Attached SCSI solid-state drives) that will fail after reaching 40,000 hours of operation -- which is 4 years, 206 days, and 16 hours after the SSD has been put into operation. HPE says that based on when affected SSDs have been manufactured and sold, the earliest failures are expected to occur starting with October this year. The company has released firmware updates last week to address the issue. HPE warns that if companies fail to install the update, they risk losing both the SSD and the data. "After the SSD failure occurs, neither the SSD nor the data can be recovered," the company explained.
Security

Hackers Hijack Routers' DNS To Spread Malicious COVID-19 Apps (bleepingcomputer.com) 13

An anonymous reader quotes a report from Bleeping Computer: A new cyber attack is hijacking router's DNS settings so that web browsers display alerts for a fake COVID-19 information app from the World Health Organization that is the Oski information-stealing malware. For the past five days, people have been reporting their web browser would open on its own and display a message prompting them to download a 'COVID-19 Inform App' that was allegedly from the World Health Organization (WHO). After further research, it was determined that these alerts were being caused by an attack that changed the DNS servers configured on their home D-Link or Linksys routers to use DNS servers operated by the attackers. As most computers use the IP address and DNS information provided by their router, the malicious DNS servers were redirecting victims to malicious content under the attacker's control. "If your browser is randomly opening to a page promoting a COVID-19 information app, then you need to login to your router and make sure you configure it to automatically receive its DNS servers from your ISP," the report says. It also recommends you set a strong password for your router and to disable remote administration.

"Finally, if you downloaded and installed the COVID-19 app, you should immediately perform a scan on your computer for malware. Once clean, you should change all of the passwords for sites whose credentials are saved in your browser and you should change the passwords for any site that you visited since being infected."
Security

Elite Hackers Target WHO As Coronavirus Cyberattacks Spike 47

According to Reuters, elite hackers tried to break into the World Health Organization earlier this month. While the effort was unsuccessful, the agency said there's been a more than two-fold increase in cyberattacks as they battle to contain the coronavirus. From the report: The attempted break-in at the WHO was first flagged to Reuters by Alexander Urbelis, a cybersecurity expert and attorney with the New York-based Blackstone Law Group, which tracks suspicious internet domain registration activity. Urbelis said he picked up on the activity around March 13, when a group of hackers he'd been following activated a malicious site mimicking the WHO's internal email system. "I realized quite quickly that this was a live attack on the World Health Organization in the midst of a pandemic," he said.

Urbelis said he didn't know who was responsible, but two other sources briefed on the matter said they suspected an advanced group of hackers known as DarkHotel, which has been conducting cyber-espionage operations since at least 2007. When asked by Reuters about the incident, the WHO's Security Officer Flavio Aggio confirmed that the site spotted by Urbelis had been used in an attempt to steal passwords from multiple agency staffers. Cybersecurity firms including Romania's Bitdefender and Moscow-based Kaspersky said they have traced many of DarkHotel's operations to East Asia - an area that has been particularly affected by the coronavirus. Specific targets have included government employees and business executives in places such as China, North Korea, Japan, and the United States. Costin Raiu, head of global research and analysis at Kaspersky, could not confirm that DarkHotel was responsible for the WHO attack but said the same malicious web infrastructure had also been used to target other healthcare and humanitarian organizations in recent weeks.
Microsoft

Microsoft Says Hackers Are Attacking Windows Users With a New Unpatched Bug (techcrunch.com) 69

Microsoft says attackers are exploiting a previously undisclosed security vulnerability found in all supported versions of Windows, including Windows 10. From a report: But the software giant said there is currently no patch for the vulnerability. The security flaw, which Microsoft deems "critical" -- its highest severity rating -- is found in how Windows handles and renders fonts, according to the advisory posted Monday. The bug can be exploited by tricking a victim into opening a malicious document. Once the document is opened -- or viewed in Windows Preview -- an attacker can remotely run malware, such as ransomware, on a vulnerable device. The advisory said that Microsoft was aware of hackers launching "limited, targeted attacks," but did not say who was launching the attacks or at what scale.
Security

Hacker Selling Data of 538 Million Weibo Users (zdnet.com) 7

The personal details of more than 538 million users of Chinese social network Weibo are currently available for sale online, according to ads seen by ZDNet and corroborating reports from Chinese media. From the report: In ads posted on the dark web and other places, a hacker claims to have breached Weibo in mid-2019 and obtained a dump of the company's user database. The database allegedly contains the details for 538 million Weibo users. Personal details include the likes of real names, site usernames, gender, location, and -- for 172 million users -- phone numbers. Passwords were not included, which explains why the hacker is selling the Weibo data for only $250.
Microsoft

Microsoft Pauses Edge Releases Amid Coronavirus Outbreak (zdnet.com) 20

Microsoft has announced that it is pausing the rollout of Edge v81, citing the ongoing "global circumstances" surrounding the coronavirus outbreak. From a report: New Edge releases (or any other kind of software updates) usually entail security reviews and compatibility testing to ensure operating systems and internal web applications don't break. Due to the COVID-19 coronavirus outbreak, most system administrators are most likely busy handling the security of employees working from home and taking care of their families in these tough times. Microsoft said it does not want to put an extra strain on system administrators and other IT staff personnel by releasing a new Edge version at this particular time. Redmond's decision comes days after Google announced a similar measure for Chrome v81, postponing the v81 release indefinitely.
Education

Predicting a Post-Pandemic Future: Remote Working and Distance Learning? (politico.com) 165

This week Politico published predictions from 34 "big thinkers" about what the future will be like after the coronavirus pandemic. (An associate professor of government and politics at the University of Maryland argues that "The Reagan era is over. The widely accepted idea that government is inherently bad won't persist after coronavirus.")

Others predict a future with voting from mobile devices (and possibly higher voter turnout), and one author even predicts a society that accepts "restraints on mass consumer culture as a reasonable price to pay to defend ourselves against future contagions and climate disasters alike."

But several also predict the rise of telemedicine, including the editor-in-chief of Reason, who also argues that the epidemic "will sweep away many of the artificial barriers to moving more of our lives online." The resistance -- led by teachers' unions and the politicians beholden to them -- to allowing partial homeschooling or online learning for K-12 kids has been swept away by necessity. It will be near-impossible to put that genie back in the bottle in the fall, with many families finding that they prefer full or partial homeschooling or online homework. For many college students, returning to an expensive dorm room on a depopulated campus will not be appealing, forcing massive changes in a sector that has been ripe for innovation for a long time.

And while not every job can be done remotely, many people are learning that the difference between having to put on a tie and commute for an hour or working efficiently at home was always just the ability to download one or two apps plus permission from their boss. Once companies sort out their remote work dance steps, it will be harder -- and more expensive -- to deny employees those options. In other words, it turns out, an awful lot of meetings (and doctors' appointments and classes) really could have been an email. And now they will be.

Not everyone agrees. Author Sonia Shah argues that "The hype around online education will be abandoned, as a generation of young people forced into seclusion will reshape the culture around a contrarian appreciation for communal life."

But the president of Vassar College even wonders if the pandemic will be a boon to virtual reality, hoping for a program that helps self-isolated people socialize. "Imagine putting on glasses, and suddenly you are in a classroom or another communal setting, or even a positive psychology intervention."
Security

Forbes: Hack on Putin's Intelligence Agency Finds Weapon to Exploit IoT Vulnerabilities (forbes.com) 36

"Red faces in Red Square, again," writes a Forbes cybersecurity correspondent: Last July, I reported on the hacking of SyTech, an FSB contractor working on internet surveillance tech. Now, reports have emerged from Russia of another shocking security breach within the FSB ecosystem. This one has exposed "a new weapon ordered by the security service," one that can be used to execute cyber attacks on IoT devices. The goal of the so-called "Fronton Program" is to exploit IoT security vulnerabilities en masse — remember, these technologies are fundamentally less secure than other connected devices in homes and offices...

The security contractors highlight retained default "factory" passwords as the obvious weakness, one that is easy to exploit... The intent of the program is not to access the owners of those devices, but rather to herd them together into a botnet that can be used to attack much larger targets — think major U.S. and European internet platforms, or the infrastructure within entire countries, such as those bordering Russia.

But the article also notes that targetted devices for the exploits include cameras, adding that compromising such devices in foreign countries by a nation-state agency "carries other surveillance risks as well." It also points out that the FSB "is the successor to the KGB and reports directly to Russia's President Vladimir Putin," and its responsibilities include electronic intelligence gathering overseas.

"The fact that these kind of tools are being contracted out for development given the current geopolitical climate should give us all serious pause for thought."
Security

Are There Security Risks When Millions are Suddenly Working from Home? (cnn.com) 95

"The dramatic expansion of teleworking by U.S. schools, businesses and government agencies in response to the coronavirus is raising fresh questions about the capacity and security of the tools many Americans use to connect to vital workplace systems and data," reports CNN: As of last week the Air Force's virtual private networking software could only support 72,000 people at once, according to a federal contractor who was also not authorized to speak on the record, and telework briefing materials viewed by CNN. The Air Force employs over 145,000 in-house civilian workers, and over 130,000 full-time contractors.

As they increasingly log on from home, Americans are having to meld their personal technology with professional tools at unprecedented scale. For employers, the concern isn't just about capacity, but also about workers introducing new potential vulnerabilities into their routine — whether that's weak passwords on personal computers, poorly secured home WiFi routers, or a family member's device passing along a computer virus.

Long-time Slashdot reader Lauren Weinstein also worries about a world where "doctors switch to heavy use of video office visits, and in general more critical information than ever is suddenly being thrust onto the Internet..." For example, the U.S. federal government is suspending key aspects of medical privacy laws to permit use of "telemedicine" via commercial services that have never been certified to be in compliance with the strict security and privacy rules associated with HIPAA (Health Insurance Portability and Accountability Act).

The rush to provide more remote access to medical professionals is understandable, but we must also understand the risks of data breaches that once having occurred can never be reversed.

Slashdot Top Deals