IT

Linus Torvalds Shares His Tips On Working Remotely (zdnet.com) 76

Linus Torvalds tells ZDNet what he's learned about working remotely: Torvalds admits that when he started, "I worried about missing human interaction -- not just talking to people in the office and hallways, but going out to lunch etc. It turns out I never really missed it."

Of course, just saying "'don't be social' isn't much of a great tip, is it?" Nor, as many extroverts are now finding out, is working from home necessarily at all comfortable. So, Torvalds suggests that you take "advantage of the 'real' upside of working from home: flexibility... Torvalds says, "if you make your new life a '9-5, but from home' kind of thing, I think you're just going to hate your home, yourself and your life. All the downsides, none of the upsides...." He believes that instead of using "video conferencing instead to recreate exactly what we used to do before, you should" try to really change how you work. Use asynchronous communication models: messaging, email, shared calendars, whatever.

Torvalds also recommends carefully tracking the things that you need to do, but argues that if you're spending hours in online meetings from home instead of hours in real-world meetings, "you've just taken the worst part of office life, and brought it home, and made it even worse..."

And the article also includes some tips from James Bottomley, an IBM Research Distinguished Engineer and senior Linux kernel developer who works closely with Torvald. For videoconferencing Bottomley uses NextCloud Talk and Zoom, which he calls a "horrible proprietary app" -- but notes that it does have binaries for every Linux distro.
Security

Hackers Breach FSB Contractor and Leak Details About IoT Hacking Project (zdnet.com) 11

Russian hacker group Digital Revolution claims to have breached a contractor for the FSB -- Russia's national intelligence service -- and discovered details about a project intended for hacking Internet of Things (IoT) devices. From a report: The group published this week 12 technical documents, diagrams, and code fragments for a project called "Fronton." ZDNet has not seen the documents first hand since they are still password-protected; however, the hackers provided the files to BBC Russia earlier this week. According to screenshots shared by the hacker group, which ZDNet asked security researchers to analyze, and based on BBC Russia's report from earlier this week, we believe the Fronton project describes the basics of building an IoT botnet. The technical Fronton documents were put together following a procurement order placed by one of the FSB's internal departments, unit No. 64829, which is also known as the FSB Information Security Center.
Security

Windows, Ubuntu, macOS, VirtualBox Fall at Pwn2Own Hacking Contest (zdnet.com) 26

The 2020 spring edition of the Pwn2Own hacking contest has come to a close today. This year's winner is Team Fluoroacetate -- made up of security researchers Amat Cama and Richard Zhu -- who won the contest after accumulating nine points across the two-day competition, which was just enough to extend their dominance and win their fourth tournament in a row. From a report: But this year's edition was a notable event for another reason. While the spring edition of the Pwn2Own hacking contest takes place at the CanSecWest cyber-security conference, held each spring in Vancouver, Canada, this year was different. Due to the ongoing coronavirus (COVID-19) outbreak and travel restrictions imposed in many countries around the globe, many security researchers couldn't attend or weren't willing to travel to Vancouver and potentially put their health at risk. Instead, this year's Pwn2Own edition has become the first-ever hacking contest that has been hosted in a virtual setting. Participants sent exploits to Pwn2Own organizers in advance, who ran the code during a live stream with all participants present. During the competition's two-day schedule, six teams managed to hack apps and operating systems like Windows, macOS, Ubuntu, Safari, Adobe Reader, and Oracle VirtualBox. All bugs exploited during the contest were immediately reported to their respective companies.
Technology

Magic Leap Wants Workers To Use Its Headsets While They're Stuck At Home (theverge.com) 12

Mixed reality startup Magic Leap is trying to tempt potential buyers with a package for people stuck working from home. The Verge reports: The "Collaboration Package" is a 45-day trial of four Magic Leap headsets, plus access to Spatial, a virtual collaboration program. It costs $5,000, with the option to extend the license or send the headsets back afterward. Spatial creates avatars of users based on photos, then lets them hold meetings with these avatars and virtual screens. It isn't exclusive to Magic Leap or mixed reality headsets; the software also works across computers and phones. But headsets can (in some ways) more realistically simulate sharing a room with a distant colleague.
Security

IT Security Report Finds 97 Percent Have Suspicious Network Activity 46

According to a 13-page study from IT security vendor Positive Technologies, a whopping 97% of surveyed companies with at least 1,000 employees show evidence of suspicious activity in their network traffic and that 81% of the companies were being subject to malicious activity. TechRepublic reports: "In one in every three companies, there were traces of scans of its internal network, which could potentially mean that hackers are gathering intelligence inside the infrastructure. This includes network scans, multiple failed attempts to connect to hosts, and traces of collecting intelligence on active network sessions on a specific host or in the entire domain." Another alarming statistic from the research showed that 94% of the participating companies in the study suffered from noncompliance with their corporate security policies within their IT infrastructure systems, leaving them more vulnerable to successful cyberattacks, according to the report. Noncompliance with IT security policies "has a direct impact on security deterioration, by practically opening the door for the hackers to exploit," the report continued.

Also worrisome is that 81% of the participating companies are transmitting their sensitive data in clear text, or text that is not encrypted or meant to be encrypted, according to the research. By using only risky clear text, companies can enable potential hackers to search their network traffic for logins and passwords which are moving between and across corporate networks. Meanwhile, some 67% of the companies allow the use of remote access software, such as RAdmin, TeamViewer, and Ammyy Admin, which can also be compromised by attackers to move along the network while remaining undetected by security tools, the report states. In addition, workers in 44% of the companies use BitTorrent for data transfer, which dramatically can increase the risk of malware infection. Ultimately, 92% of these network security threats were detected inside the perimeters of the companies that were surveyed, according to the report, which reveals the depth of the problems and the need for constant internal network monitoring.
Firefox

Firefox To Remove Support For the FTP Protocol (zdnet.com) 146

Mozilla has announced plans to remove support for the FTP protocol from Firefox. Going forward, users won't be able to download files via the FTP protocol and view the content of FTP links/folders inside the Firefox browser. From a report: "We're doing this for security reasons," said Michal Novotny, a software engineer at the Mozilla Corporation, the company behind the Firefox browser. "FTP is an insecure protocol and there are no reasons to prefer it over HTTPS for downloading resources," he said. "Also, a part of the FTP code is very old, unsafe and hard to maintain and we found a lot of security bugs in it in the past." Novotny says Mozilla plans to disable support for the FTP protocol with the release of Firefox 77, scheduled for release in June this year.
Businesses

Microsoft Teams Passes 44 Million Daily Active Users, Thanks in Part To Coronavirus (venturebeat.com) 44

Microsoft Teams, which launched worldwide in March 2017, passed 32 million daily active users (DAUs) this month. From a report: A week later, thanks in part to COVID-19, usage had spiked to 44 million DAUs. That's up from 20 million daily active users in November, a 60-110% jump in just four months. Microsoft used the product's three-year anniversary to share the new figures and announce new Teams features targeting "underserved professionals, including firstline and health care workers." Teams is the company's Office 365 chat-based collaboration tool that competes with Slack (12 million DAUs as of October), Facebook's Workplace (3 million paid users as of October), and Google's Hangouts Chat (no user number shared). It's also Microsoft's fastest-growing business app ever. But the company has been criticized for how it calculates its DAU figure, so today it shared its methodology.
Facebook

Facebook Bug Caused Legitimate News Articles About the Coronavirus To Be Marked As Spam 31

McGruber shares a report from Business Insider: Facebook is blocking users from posting some legitimate news articles about the coronavirus in what appears to be a bug in its spam filters. On Tuesday, multiple Facebook users reported on Twitter that they found themselves unable to post articles from certain news outlets including Business Insider, BuzzFeed, The Atlantic, and the Times of Israel. It's not clear exactly what has gone wrong, and Facebook did not respond to a request for comment.

Alex Stamos, an outspoken former Facebook security exec, speculated that it might be caused by Facebook's shift to automated software after it sent its human content moderators home. "It looks like an anti-spam rule at FB is going haywire," he wrote on Twitter. "Facebook sent home content moderators yesterday, who generally can't [work from home] due to privacy commitments the company has made. We might be seeing the start of the machine learning going nuts with less human oversight.
In a tweet, VP of Integrity Guy Rosen said: "We're on this -- this is a bug in an anti-spam system, unrelated to any changes in our content moderator workforce. We're in the process of fixing and bringing all these posts back."
Medicine

Slashdot Asks: How are YOU Handling the Coronavirus? (theatlantic.com) 425

This week saw dramatic responses to the coronavirus pandemic. At least two different U.S. states have ordered all bars and restaurants to close, according to the AP, while "officials elsewhere in the country said they were considering similar restrictions." America's Center for Disease Control is now urging the entire country to "cancel or postpone in-person events that consist of 50 people or more." At least two more states have postponed their presidential primary elections -- and lots of people now seem to be avoiding movie theatres.

Meanwhile, earlier this week GitLab released its first "Remote Work Report," arguing that "it's undeniable that the future of work will be remote."

But what are you doing? Are you working remotely? (And is the rest of your company?) Are you buying groceries during off-peak hours? Staying home to watch Frozen 2?

We're all in this together -- so let's hear about the experiences of Slashdot readers. Share your own stories in the comments.

How are you handling the coronavirus?
Crime

Live Coronavirus Map Used to Spread Malware (krebsonsecurity.com) 19

Malware distributors "have started disseminating real-time, accurate information about global infection rates tied to the Coronavirus/COVID-19 pandemic in a bid to infect computers with malicious software," reports security researcher Brian Krebs: In one scheme, an interactive dashboard of Coronavirus infections and deaths produced by Johns Hopkins University is being used in malicious Web sites (and possibly spam emails) to spread password-stealing malware. Late last month, a member of several Russian language cybercrime forums began selling a digital Coronavirus infection kit that uses the Hopkins interactive map as part of a Java-based malware deployment scheme.

The kit costs $200 if the buyer already has a Java code signing certificate, and $700 if the buyer wishes to just use the seller's certificate. "It loads [a] fully working online map of Corona Virus infected areas and other data," the seller explains. "Map is resizable, interactive, and has real time data from World Health Organization and other sources. Users will think that PreLoader is actually a map, so they will open it and will spread it to their friends and it goes viral...!" The sales thread claims the customer's payload can be bundled with the Java-based map into a filename that most Webmail providers allow in sent messages... The seller says the user/victim has to have Java installed for the map and exploit to work, but that it will work even on fully patched versions of Java...

It's unclear how many takers this seller has had, but earlier this week security experts began warning of new malicious Web sites being stood up that used interactive versions of the same map to distract visitors while the sites tried to foist the password-stealing AZORult malware.

Security

Data of Millions of eBay and Amazon Shoppers Exposed (sophos.com) 39

An anonymous reader quotes the "Naked Security" blog of anti-virus company Sophos: Researchers have discovered another big database containing millions of European customer records left unsecured on Amazon Web Services (AWS) for anyone to find using a search engine. A total of eight million records were involved, collected via marketplace and payment system APIs belonging to companies including Amazon, eBay, Shopify, PayPal, and Stripe.

Discovered by Comparitech's noted breach hunter Bob Diachenko, the AWS instance containing the MongoDB database became visible on 3 February, where it remained indexable by search engines for five days. Data in the records included names, shipping addresses, email addresses, phone numbers, items purchased, payments, order IDs, links to Stripe and Shopify invoices, and partially redacted credit cards...

A total of eight million records were involved, collected via marketplace and payment system APIs belonging to companies including Amazon, eBay, Shopify, PayPal, and Stripe.

The article calls it "simply the latest example of how easy it is to leave sensitive data sitting in an unsecured state on cloud storage platforms." They cite two more high-profile databases that Comparitech found exposed on Elasticsearch just in 2020:
IBM

IBM and AT&T Tell Employees To Work From Home (kimt.com) 49

Slashdot reader Willy English quotes CNBC: AT&T is asking all of its employees who have the ability to work remotely to do so until further notice, as the coronavirus spreads across the globe.

The company will be announcing new procedures and safeguards for employees who can't work from home, AT&T CEO Randall Stephenson said in a note sent to employees Friday. AT&T is one of the largest employers in the United States, and has 245,000 global employees.

Meanwhile, a local U.S. news station reports: IBM is encouraging all employees in the United States to work from home through the end of March, if possible.

In an email sent to employees and provided to KIMT, the technology company says the recommendation is in response to the global coronavirus pandemic.

Programming

Study Finds High Demand for Go and AR/VR Programmers, While Python Remains Favorite Language (hired.com) 75

The tech jobs marketplace at Hired.com crunched their data on more than 400,000 interview requests and job offers over the last year to produce their annual "State of Software Engineers" report. Among its surprising insights: software engineers with more than 10 years of experience get 20% fewere interview requests than engineers with 4 to 10 years of experience.

Other insights: Demand for AR/VR talent is up by 1400%, mirroring blockchain's 517% demand growth last year... In large U.S. tech hubs AR/VR engineer salaries range from $135k - $150k... 46% of software engineers rank AR/VR as one of the top 3 technologies they'd like to learn in 2020... If you work in AR/VR, you may want to move to San Francisco, where they pay $150k/year on average.
The next-highest growth in demand came for "gaming engineers" and "computer vision engineers" -- with both positions seeing a 146% increase in demand over 2018. The next-highest demand growth was for "search engineers" (increasing 137%) and for "machine learning engineers" (increasing 89%). Demand for "blockchain engineers" increased by just 9%.

But they also report that demand for frontend and backend engineers "grew steadily by 17%, which shows that all companies -- not just Silicon Valley tech giants -- are evolving into being tech companies..." The worldwide process of digital transformation, while something of a buzzword, reflects a critical truth: every company is now a technology company. Whether the company is Bank of America, Alaska Airlines, Sainsbury's, or Tesla, investment in top software engineering talent isn't a future ambition, it's a matter of survival.
And the #1 most-desired coding skill was Go (for the second year in a row), "garnering an average of 9.2 interview requests for every Go-skilled candidate..." But there may be a larger trend. All told, the number of interview requests across all languages remained nearly constant year-over-year, with only minor fluctuations in average requests, and zero change in how each language ranked against others. This could suggest that supply for these skills has not yet caught up with demand...

According to Robert Half, 67% of IT managers plan to expand their teams in areas such as security, cloud computing and business intelligence, but 89% reported challenges in recruiting that talent. Those challenges in hiring are even greater for roles related to machine learning, artificial intelligence, and blockchain.

Their analysis concludes the most in-demand programming languages are Go, Scala, Ruby, TypeScript, Kotlin, Objective C, JavaScript, Swift, PHP, Java, HTML, and then Python -- though Python, JavaScript, and Java are engineers' favorite coding languages, "largely because of their useful and well-maintained libraries and packages..."

"Ruby, PHP and Objective C are ranked the least favorite (and least fun) languages for software engineers."
Privacy

900 Million Secrets From 8 Years of 'Whisper' App Were Left Exposed Online (washingtonpost.com) 32

Long-time Slashdot reader AmiMoJo shares a startling report from the Washington Post: Whisper, the secret-sharing app that called itself the "safest place on the Internet," left years of users' most intimate confessions exposed on the Web tied to their age, location and other details, raising alarm among cybersecurity researchers that users could have been unmasked or blackmailed.

The data exposure, discovered by independent researchers and shown to The Washington Post, allowed anyone to access all of the location data and other information tied to anonymous "whispers" posted to the popular social app, which has claimed hundreds of millions of users. The records were viewable on a non-password-protected database open to the public Web. A Post reporter was able to freely browse and search through the records, many of which involved children: A search of users who had listed their age as 15 returned 1.3 million results.

The cybersecurity consultants Matthew Porter and Dan Ehrlich, who lead the advisory group Twelve Security, said they were able to access nearly 900 million user records from the app's release in 2012 to the present day. The researchers alerted federal law-enforcement officials and the company to the exposure.

Shortly after researchers and The Post contacted the company on Monday, access to the data was removed.

Medicine

You Can Now Take Up To 12 Ounces of Hand Sanitizer Through Airport Security 128

The Transportation Security Administration (TSA) will now allow passengers to bring on board hand sanitizer containers up to 12 ounces in size, which is much larger than the standard 3.4 ounces (100 milliliters) previously allowed. The Verge reports: There are some caveats, though. The updated policy only applies to hand sanitizer. And larger containers will be subject to additional screening by TSA agents, which will likely lead to increased wait times. So ask yourself before heading out to the airport: how much sanitizer do you really need? Airports are said to be stocking up on disinfectants and other cleaning equipment. Passengers are likely to see hand sanitizer stations everywhere at airports reflecting this new reality, so no worries for those who don't feel like lugging a huge bottle of the stuff on the plane with them.
Programming

Microsoft Plots the End of Visual Basic (thurrott.com) 66

Microsoft said this week that it will support Visual Basic on .NET 5.0 but will no longer add new features or evolve the language. From a report: "Starting with .NET 5, Visual Basic will support Class Library, Console, Windows Forms, WPF, Worker Service, [and] ASP.NET Core Web API ... to provide a good path forward for the existing VB customer who want [sic] to migrate their applications to .NET Core," the .NET team wrote in a post to the Microsoft DevBlogs. "Going forward, we do not plan to evolve Visual Basic as a language ... The future of Visual Basic ... will focus on stability, the application types listed above, and compatibility between the .NET Core and .NET Framework versions of Visual Basic."

When Microsoft released the .NET version of Visual Basic, originally called Visual Basic .NET, alongside C# at the beginning of the .NET era, the two languages were evolved together and had roughly identical feature sets. But this changed over time, with professional developers adopting C# and many fans of classic VB simply giving up on the more complex but powerful .NET versions of the environment. Today, virtually all of Microsoft's relevant developer documentation is in C# only, with VB source code examples ever harder to find.

Censorship

ProtonMail Could Reroute Connections Through Google To Circumvent Censorship (venturebeat.com) 9

Proton Technologies, the company behind encrypted email provider ProtonMail, has announced plans to circumvent censorship by routing connections to its servers through third-party infrastructure, which may include Google -- a company that ProtonMail has long been critical of over its privacy practices. From a report: Proton, which was founded out of Switzerland in 2013 by academic researchers working on particle physics projects at CERN, promises ProtonMail users full privacy via client-side encryption, meaning that nobody can intercept and read their emails -- it has frequently positioned itself as the antithesis of Gmail, which serves as a vital cog in Google's advertising wheel. ProtonMail, on the other hand, has emerged as a prominent privacy-focused alternative, used by companies and individuals -- including White House staffers and activists -- wishing to sidestep snoopers.

Thus, ProtonMail has faced its fair share of censorship, with the likes of Turkey, Belarus, and Russia all blocking the service in recent times. This is something that Proton is now pushing harder to counter with its new backup solution. The new tool, which will be deployed over the next few weeks in the ProtonMail desktop and mobile apps, is designed to sidestep any blocks imposed by network administrators, internet service providers (ISPs), or governments.

Security

Czech Hospital Hit By Cyber-Attack While in the Midst of a COVID-19 Outbreak (zdnet.com) 31

The Brno University Hospital in the city of Brno, Czech Republic, has been hit by a cyber-attack right in the middle of a COVID-19 outbreak that is picking up steam in the small central European country. From a report: Hospital officials have not revealed the nature of the security breach; however, the incident was deemed severe enough to postpone urgent surgical interventions, and re-route new acute patients to nearby St. Anne's University Hospital, local media reported. The hospital was forced to shut down its entire IT network during the incident, and two other of the hospital's branches, the Children's Hospital and the Maternity Hospital, were also impacted. The Czech National Cyber Security Center (NCSC) tweeted today that "the incident was resolved on the spot," together with the hospital's IT staff and members of Czech police (NCOZ). The incident was considered a severe one and treated with the utmost urgency because the Brno University Hospital is one of the Czech Republic's biggest COVID-19 testing laboratories.
Security

Modern RAM Used For Computers, Smartphones Still Vulnerable To Rowhammer Attacks (zdnet.com) 13

An anonymous reader quotes a report from ZDNet: According to new research published today, modern RAM cards are still vulnerable to Rowhammer attacks despite extensive mitigations that have been deployed by manufacturers over the past six years. These mitigations, collectively referred to as Target Row Refresh (TRR), are a combination of software and hardware fixes that have been slowly added to the design of modern RAM cards after 2014 when academics disclosed the first-ever Rowhammer attack. But in a new research paper titled today and titled "TRRespass: Exploiting the Many Sides of Target Row Refresh," a team of academics from universities in the Netherlands and Switzerland said they developed a generic tool named TRRespass that can be used to upgrade the old Rowhammer attacks to work on the new-and-improved TRR-protected RAM cards. The new upgraded attacks work on both DIMM and LPDDR4 memory types, and can be used to retrieve encryption keys from memory, or escalate an attacker's access right to sudo/SYSTEM-level.
Microsoft

Microsoft Patches SMBv3 Wormable Bug That Leaked Earlier this Week (zdnet.com) 12

Microsoft today released a patch for a vulnerability in the SMBv3 protocol that accidentally leaked online earlier this week during the March 2020 Patch Tuesday preamble. From a report: The fix is available as KB4551762, an update for Windows 10, versions 1903 and 1909, and Windows Server 2019, versions 1903 and 1909. The update fixes CVE-2020-0796, a vulnerability in Server Message Block, a protocol for sharing files, printers, and other resources on local networks and the Internet. The bug allows attackers to connect to remote systems where the SMB service is enabled and run malicious code with SYSTEM privileges, allowing for remote takeovers of vulnerable systems. Earlier this week, due to what looks like a miscommunication between Microsoft and some antivirus vendors, details about this bug leaked online.

Slashdot Top Deals