Chrome

Google Chrome Will Soon Start Blocking Insecure Downloads (theverge.com) 139

"Google has revealed plans to initially warn Chrome users about 'insecure' downloads and eventually block them outright," reports The Verge. The warnings will begin in April: "Today we're announcing that Chrome will gradually ensure that secure (HTTPS) pages only download secure files," Joe DeBlasio of the Chrome security team wrote in a blog post. "Insecurely-downloaded files are a risk to users' security and privacy. For instance, insecurely-downloaded programs can be swapped out for malware by attackers, and eavesdroppers can read users' insecurely-downloaded bank statements."

Beginning with Chrome 82, due for release in April, Chrome will warn users if they're about to download mixed content executables from a secure website. Then, when version 83 is released, those executable downloads will be blocked and the warning will be applied to archive files. PDFs and .doc files will get the warning in Chrome 84, with audio, images, text, and video files displaying it by version 85. Finally, all mixed content downloads — a non-secure file coming from a secure site — will be blocked as of the release of Chrome 86. Right now, Google is estimating an October release for that build of the popular web browsing.

Windows

Warning: Microsoft Pulls Windows 10 Security Update After Reports of Serious Bugs (forbes.com) 103

Slashdot reader golden_donkey quotes Forbes: Are you booting up your Windows 10 machine and discovering you can't log in to your profile? It appears you're not alone. Reports are increasing across Twitter and Microsoft forums that following the most recent Patch Tuesday update (KB4532693), users are complaining that their profiles and desktop files are missing, and that custom icons and wallpaper have all been reset to their default state...

The KB4532693 update is allegedly causing much more serious headaches for some users. A newer report by Windows Latest cites multiple users in their comments section complaining that the data is nowhere to be found and allegedly not recoverable.

Microsoft has now "yanked KB4524244 from its update servers..." reports ZDNet, "after acknowledging reports of 'an issue affecting a sub-set of devices.'" Microsoft says customers who have successfully installed the update don't need to take any further steps. Those who have configured PCs to defer installation of updates by at least four days should also be unaffected.

For those who are experiencing issues related to this update, Microsoft recommends uninstalling the update.

Forbes also shared a video "on a related note." Its title? "How To Choose A Linux Distro That's Right For You..."
Encryption

Signal Is Finally Bringing Its Secure Messaging To the Masses (wired.com) 79

An anonymous reader quotes a report from Wired: [Cryptographer and coder known as Moxie Marlinspike] has always talked about making encrypted communications easy enough for anyone to use. The difference, today, is that Signal is finally reaching that mass audience it was always been intended for -- not just the privacy diehards, activists, and cybersecurity nerds that formed its core user base for years -- thanks in part to a concerted effort to make the app more accessible and appealing to the mainstream. That new phase in Signal's evolution began two years ago this month. That's when WhatsApp cofounder Brian Acton, a few months removed from leaving the app he built amid post-acquisition clashes with Facebook management, injected $50 million into Marlinspike's end-to-end encrypted messaging project. Acton also joined the newly created Signal Foundation as executive chairman. The pairing up made sense; WhatsApp had used Signal's open source protocol to encrypt all WhatsApp communications end-to-end by default, and Acton had grown disaffected with what he saw as Facebook's attempts to erode WhatsApp's privacy.

Since then, Marlinspike's nonprofit has put Acton's millions -- and his experience building an app with billions of users -- to work. After years of scraping by with just three overworked full-time staffers, the Signal Foundation now has 20 employees. For years a bare-bones texting and calling app, Signal has increasingly become a fully featured, mainstream communications platform. With its new coding muscle, it has rolled out features at a breakneck speed: In just the last three months, Signal has added support for iPad, ephemeral images and video designed to disappear after a single viewing, downloadable customizable "stickers," and emoji reactions. More significantly, it announced plans to roll out a new system for group messaging, and an experimental method for storing encrypted contacts in the cloud. Many of those features might sound trivial. They certainly aren't the sort that appealed to Signal's earliest core users. Instead, they're what Acton calls "enrichment features." They're designed to attract normal people who want a messaging app as multifunctional as WhatsApp, iMessage, or Facebook Messenger but still value Signal's widely trusted security and the fact that it collects virtually no user data.
Wired explains how adding simple-sounding enhancements can require significant feats of security engineering to fit within Signal's privacy constraints. Adding downloadable customizable stickers, for example, "required designing a system where every sticker 'pack' is encrypted with a 'pack key,'" reports Wired. "That key is itself encrypted and shared from one user to another when someone wants to install new stickers on their phone, so that Signal's server can never see decrypted stickers or even identify the Signal user who created or sent them."

For Signal's new group messaging, Signal partnered with Microsoft Research to invent a novel form of "anonymous credentials" that let a server gatekeep who belongs in a group, but without ever learning the members' identities.
Security

US Cyber Command, DHS, and FBI Expose New North Korean Malware (zdnet.com) 14

US Cyber Command, the Department of Homeland Security, and the Federal Bureau of Investigations have exposed today a new North Korean hacking operation. Authorities have published security advisories detailing six new malware families that are currently being used by North Korean hackers. From a report: According to the Twitter account of the Cyber National Mission Force (CNMF), a subordinate unit of US Cyber Command, the malware is being distributed via a North Korean phishing campaign. US Cyber Command believes the malware is used to provide North Korean hackers with remote access to infected systems in order to steal funds that are later transfered back to North Korea, as a way to avoid economical sanctions. The North Korean government has a long history of using hackers to steal funds from banks and cryptocurrency exchanges in order to evade economic sanctions and raise funds for its nuclear weapons and missile programs. In September 2019, the US Department of the Treasury imposed sanctions on the Pyongyang regime for the use of this exact tactic.
Power

Developer Finds USB Chargers Have as Much Processing Power as the Apollo 11 Guidance Computers (gizmodo.com) 110

An anonymous reader shares a report: It comes as no surprise that the guidance computers aboard the Apollo 11 spacecraft were impossibly primitive compared to the pocket computers we all carry around 50 years later. But on his website, an Apple developer analyzed the tech specs even further and found that even something as simple as a modern USB charger is packed with more processing power. Forrest Heller, a software developer who formerly worked on Occipital's Structure 3D scanner accessory for mobile devices, but who now works for Apple, broke down the numbers when it comes to the processing power, memory, and storage capacity of Google's 18W Pixel charger, Huawei's 40W SuperCharge, the Anker PowerPort Atom PD 2 charger, and the Apollo 11 guidance computer, also referred to as the AGC. It's not easy to directly compare those modern devices with the 50-year-old AGC, which was custom developed by NASA for controlling and automating the guidance and navigation systems aboard the Apollo 11 spacecraft.

In a time when computers were the size of giant rooms, the AGC was contained in a box just a few feet in length because it was one of the first computers to be made with integrated circuits. Instead of plopping in an off the shelf processor, NASA's engineers designed and built the AGC with somewhere around 5,600 electronic gates that were capable of performing nearly 40,000 simple mathematical calculations every second. While we measure processor speeds in gigahertz these days, the AGC chugged along at 1.024 MHz. By comparison, the Anker PowerPort Atom PD 2 USB-C charger includes a Cypress CYPD4225 processor running at 48 MHz with the twice the RAM of the AGC, and almost twice the storage space for software instructions.

Democrats

Nevada Democrats To Use iPads Loaded With Google Forms To Track Caucus (cnet.com) 145

An anonymous reader quotes a report from CNET: Nevada's Democratic Party said Thursday it plans to use iPads loaded with survey app Google Forms to calculate voting results in next week's caucuses. The system is an effort to avoid a repeat of the Iowa caucus chaos. The app will be loaded onto 2,000 iPads purchased by the party and distributed to precinct chairs, according to a memo signed by party Executive Director Alana Mounce seen by the Associated Press Thursday. Google's app will calculate and submit results electronically, while a second step will rely on submissions also being made by phone. Nevada's caucuses will be held on Feb. 22.
Chrome

500 Chrome Extensions Secretly Uploaded Private Data From Millions of Users (arstechnica.com) 26

More than 500 browser extensions downloaded millions of times from Google's Chrome Web Store surreptitiously uploaded private browsing data to attacker-controlled servers, researchers said on Thursday. Ars Technica reports: The extensions were part of a long-running malvertising and ad-fraud scheme that was discovered by independent researcher Jamila Kaya. She and researchers from Cisco-owned Duo Security eventually identified 71 Chrome Web Store extensions that had more than 1.7 million installations. After the researchers privately reported their findings to Google, the company identified more than 430 additional extensions. Google has since removed all known extensions. "In the case reported here, the Chrome extension creators had specifically made extensions that obfuscated the underlying advertising functionality from users," Kaya and Duo Security Jacob Rickerd wrote in a report. "This was done in order to connect the browser clients to a command and control architecture, exfiltrate private browsing data without the users' knowledge, expose the user to risk of exploit through advertising streams, and attempt to evade the Chrome Web Store's fraud detection mechanisms."

The extensions were mostly presented as tools that provided various promotion- and advertising-as-a service utilities. In fact, they engaged in ad fraud and malvertising by shuffling infected browsers through a maze of sketchy domains. Each plugin first connected to a domain that used the same name as the plugin (e.g.: Mapstrek[.]com or ArcadeYum[.]com) to check for instructions on whether to uninstall themselves. The plugins then redirected browsers to one of a handful of hard-coded control servers to receive additional instructions, locations to upload data, advertisement feed lists, and domains for future redirects. Infected browsers then uploaded user data, updated plugin configurations, and flowed through a stream of site redirections.
The researchers say the campaign dates back to at least January 2019, but it's possible that the operators were active "as early as 2017."
Bug

Car 'Splatometer' Tests Reveal Huge Decline In Number of Insects 130

An anonymous reader quotes a report from The Guardian: Two scientific studies of the number of insects splattered by cars have revealed a huge decline in abundance at European sites in two decades. The survey of insects hitting car windscreens in rural Denmark used data collected every summer from 1997 to 2017 and found an 80% decline in abundance. It also found a parallel decline in the number of swallows and martins, birds that live on insects.

The second survey, in the UK county of Kent in 2019, examined splats in a grid placed over car registration plates, known as a "splatometer." This revealed 50% fewer impacts than in 2004. The research included vintage cars up to 70 years old to see if their less aerodynamic shape meant they killed more bugs, but it found that modern cars actually hit slightly more insects. [...] The stream research, published in the journal Conservation Biology, analyzed weekly data from 1969 to 2010 on a stream in a German nature reserve, where the only major human impact is climate change. "Overall, water temperature increased by 1.88C and discharge patterns changed significantly. These changes were accompanied by an 81.6% decline in insect abundance," the scientists reported. "Our results indicate that climate change has already altered [wildlife] communities severely, even in protected areas."
Android

An Old Android Virus is Reinstalling Itself Even After Factory Resets (inputmag.com) 58

A particularly persistent malware infection has been spreading amongst Android phones -- and removing it only seems to bring it back with a vengeance. From a report: The Trojan xHelper, which Malwarebytes first wrote about last year, is reportedly re-spawning on devices where it's already been removed. If virus-removal software doesn't take care of a nasty infection, a hard reset will usually do the trick. But users report that even a full factory reset of an infected device doesn't wipe xHelper out completely. Within an hour the malware is usually back and ready to wreak havoc. Here's how to remove it.
Security

MIT Researchers Disclose Vulnerabilities in Voatz Mobile Voting Election App (zdnet.com) 38

Academics from MIT's computer science laboratory have published a security audit today of Voatz, a mobile app used for online voting during the 2018 US midterm elections and scheduled to be used again in the upcoming 2020 presidential election. From a report: MIT academics claim they identified bugs that could allow hackers to "alter, stop, or expose how an individual user has voted." "We additionally find that Voatz has a number of privacy issues stemming from their use of third party services for crucial app functionality," the research team said in a technical paper released today. "Our findings serve as a concrete illustration of the common wisdom against Internet voting, and of the importance of transparency to the legitimacy of elections," researchers added. MIT academics urge states to continue using paper ballots rather than mobile apps that transmit votes over the internet. They say the current paper ballot voting system is designed to be transparent, and allow citizens and political parties to observe the voting process. "Voatz's app and infrastructure were completely closed-source," said James Koppel, one of the MIT academics.
Desktops (Apple)

Apple's Mac Computers Now Outpace Windows In Malware (vox.com) 97

According to cybersecurity software company Malwarebytes' latest State of Malware report, the amount of malware on Macs is outpacing PCs for the first time ever. Recode reports: Windows machines still dominate the market share and tend to have more security vulnerabilities, which has for years made them the bigger and easier target for hackers. But as Apple's computers have grown in popularity, hackers appear to be focusing more of their attention on the versions of macOS that power them. Malwarebytes said there was a 400 percent increase in threats on Mac devices from 2018 to 2019, and found an average of 11 threats per Mac devices, which about twice the 5.8 average on Windows.

Now, this isn't quite as bad as it may appear. First of all, as Malwarebytes notes, the increase in threats could be attributable to an increase in Mac devices running its software. That makes the per-device statistic a better barometer. In 2018, there were 4.8 threats per Mac device, which means the per-device number has more than doubled. That's not great, but it's not as bad as that 400 percent increase. Also, the report says, the types of threats differ between operating systems. While Windows devices were more prone to "traditional"; malware, the top 10 Mac threats were adware and what are known as "potentially unwanted programs."

Businesses

Average Tenure of a CISO is Just 26 Months Due To High Stress and Burnout (zdnet.com) 44

Chief Information Security Officers (CISOs, or CSOs) across the industry are reporting high levels of stress. From a report: Many say the heightened stress levels has led to mental and physical health issues, relationship problems, medication and alcohol abuse, and in some cases, an eventual burnout, resulting in an average 26-month tenure before CISOs find new employment. The numbers, reported by Nominet, represent a growing issue that's been commonly acknowledged, but mostly ignored across the information security (infosec) community, but one that is slowly starting to rear its ugly head as once-ignored infosec roles are becoming more prominent inside today's companies. [...] The survey's results paint a gloomy picture about one of today's most in-demand jobs. According to the numbers: 88% of CISOs reported being "moderately or tremendously stressed." 48% of CISOs said work stress has had a detrimental impact on their mental health. 40% of CISOs said that their stress levels had affected their relationships with their partners or children. 32% said that their job stress levels had repercussions on their marriage or romantic relationships.
Businesses

Data Protection Authority Investigates Avast for Selling Users' Browsing History (vice.com) 13

The Czech data protection authority has announced an investigation into antivirus company Avast, which was harvesting the browsing history of over 100 million users and then selling products based on that data to a slew of different companies including Google, Microsoft, and Home Depot. From a report: "On the basis of the information revealed describing the practices of Avast Software s.r.o., which was supposed to sell data on the activities of anti-virus users through its 'Jumpshot division' the Office initiated a preliminary investigation of the case," a statement from the Czech national data protection authority on its website reads. Under the European General Protection Regulation (GDPR) and national laws, the Czech Republic, like other EU states, has a data protection authority to enforce things like mishandling of personal data. With GDPR, companies can be fined for data abuses. "At the moment we are collecting information on the whole case. There is a suspicion of a serious and extensive breach of the protection of users' personal data. Based on the findings, further steps will be taken and general public will be informed in due time," added Ms Ivana Janu, President of the Czech Office for Personal Data Protection, in the statement. Avast is a Czech company.
Security

Trump Signs Order To Test Vulnerabilities of US Infrastructure To GPS Outage (reuters.com) 165

U.S. President Donald Trump on Wednesday signed an executive order directing U.S. agencies to test the vulnerabilities of critical infrastructure systems in the event of a disruption or manipulation of global positioning system services (GPS). From a report: GPS is critical to a variety of purposes ranging from electrical power grids, weather forecasting, traffic signals, smartphone applications and vehicle navigation systems. The order said "disruption or manipulation of these services has the potential to adversely affect the national and economic security of the United States."
Botnet

One of the Most Destructive Botnets Can Now Spread To Nearby Wi-Fi Networks (arstechnica.com) 28

The sophistication of the Emotet malware's code base and its regularly evolving methods for tricking targets into clicking on malicious links has allowed it to spread widely. "Now, Emotet is adopting yet another way to spread: using already compromised devices to infect devices connected to nearby Wi-Fi networks," reports Ars Technica. From the report: Last month, Emotet operators were caught using an updated version that uses infected devices to enumerate all nearby Wi-Fi networks. It uses a programming interface called wlanAPI to profile the SSID, signal strength, and use of WPA or other encryption methods for password-protecting access. Then, the malware uses one of two password lists to guess commonly used default username and password combinations. After successfully gaining access to a new Wi-Fi network, the infected device enumerates all non-hidden devices that are connected to it. Using a second password list, the malware then tries to guess credentials for each user connected to the drive. In the event that no connected users are infected, the malware tries to guess the password for the administrator of the shared resource.

"With this newly discovered loader-type used by Emotet, a new threat vector is introduced to Emotet's capabilities," researchers from security firm Binary Defense wrote in a recently published post. "Previously thought to only spread through malspam and infected networks, Emotet can use this loader-type to spread through nearby wireless networks if the networks use insecure passwords." The Binary Defense post said the new Wi-Fi spreader has a timestamp of April 2018 and was first submitted to the VirusTotal malware search engine a month later. While the module was created almost two years ago, Binary Defense didn't observe it being used in the wild until last month.

Microsoft

Microsoft Promises Windows 10X Updates Will Take 'Less Than 90 Seconds' (theverge.com) 76

Microsoft is revealing more about its Windows 10X operating system today, which is designed for new dual-screen devices. From a report: The software giant has re-engineered this special variant of Windows 10 to install and update the operating system a lot faster. This will allow Windows 10X to download an OS update and simply switch to it at reboot, all within less than 90 seconds. That's a big difference from what we're used to with Windows 10 today, which involves the OS downloading an update and then applying it and rebooting. This takes minutes even on high-end systems currently, but Microsoft has developed a special state separation in Windows 10X to improve this radically.
Communications

Huawei Can Covertly Access Telecom Networks, US Officials Say (wsj.com) 133

U.S. officials say Huawei can covertly access mobile-phone networks around the world through "back doors" designed for use by law enforcement [Editor's note: the link may be paywalled; an alternative source was not immediately available.], as Washington tries to persuade allies to exclude the Chinese company from their networks. From a report: Intelligence shows Huawei has had this secret capability for more than a decade, U.S. officials said. Huawei rejected the allegations. The U.S. kept the intelligence highly classified until late last year, when American officials provided details to allies including the U.K. and Germany, according to officials from the three countries. That was a tactical turnabout by the U.S., which in the past had argued that it didn't need to produce hard evidence of the threat it says Huawei poses to nations' security. When telecom-equipment makers build and sell hardware such as switching gear, base stations and antennae to carriers -- who assemble the networks that enable mobile communication and computing -- they are required by law to build into their hardware ways for authorities to access the networks for lawful purposes. They are also required to build equipment in such a way that the manufacturer can't get access without the consent of the network operator. Only law-enforcement officials or authorized officials at each carrier are allowed into these "lawful interception interfaces," generally with the carrier's permission. Such access is governed by laws and protocols specific to each country. U.S. officials say Huawei has built equipment that secretly preserves the manufacturer's ability to access networks through these interfaces without the carriers' knowledge.
Chrome

Microsoft Will No Longer Force Bing By Default For Office 365 ProPlus Customers (windowscentral.com) 38

Microsoft will no longer forcibly make Bing the default search engine in Chrome for Office 365 ProPlus customers. A tech community post from Microsoft announced the change. From a report: Microsoft states that people will have the choice to opt-in to have the Microsoft Search in Bing browser extension installed. Microsoft was going to install the Microsoft Search Bing extension onto any system with Office 365 ProPlus that didn't already have Bing set as the default search engine. This would have effectively forced Bing onto Office 365 ProPlus customers. The move set off waves of backlash around the web, which caused Microsoft to change its plans.
United States

The CIA Secretly Bought a Company That Sold Encryption Devices Across the World. Then, Its Spies Read Everything. (washingtonpost.com) 277

Greg Miller, reporting for Washington Post: For more than half a century, governments all over the world trusted a single company to keep the communications of their spies, soldiers and diplomats secret. The company, Crypto AG, got its first break with a contract to build code-making machines for U.S. troops during World War II. Flush with cash, it became a dominant maker of encryption devices for decades, navigating waves of technology from mechanical gears to electronic circuits and, finally, silicon chips and software. The Swiss firm made millions of dollars selling equipment to more than 120 countries well into the 21st century. Its clients included Iran, military juntas in Latin America, nuclear rivals India and Pakistan, and even the Vatican.

But what none of its customers ever knew was that Crypto AG was secretly owned by the CIA in a highly classified partnership with West German intelligence. These spy agencies rigged the company's devices so they could easily break the codes that countries used to send encrypted messages. The decades-long arrangement, among the most closely guarded secrets of the Cold War, is laid bare in a classified, comprehensive CIA history of the operation obtained by The Washington Post and ZDF, a German public broadcaster, in a joint reporting project. The account identifies the CIA officers who ran the program and the company executives entrusted to execute it. It traces the origin of the venture as well as the internal conflicts that nearly derailed it. It describes how the United States and its allies exploited other nations' gullibility for years, taking their money and stealing their secrets. The operation, known first by the code name "Thesaurus" and later "Rubicon," ranks among the most audacious in CIA history.

IBM

IBM Picks Slack Over Microsoft Teams For Its 350,000 Employees (theverge.com) 68

According to Business Insider, IBM has chosen Slack over rival Microsoft Teams for its more than 350,000 employees. From a report: It's a big test for Slack, but it has been one the pair has been working toward in recent years. Internal teams at IBM reportedly started using the chat app as far back as 2014, and this has grown over time. "Going wall to wall in IBM -- it's basically the maximum scale that there is, so we now know that Slack will work for literally the largest organizations in the world," says Slack CEO Stewart Butterfield in an interview with Business Insider.

While this new rollout makes IBM Slack's biggest customer to date, it has been the company's biggest customer for years according to Slack. "IBM has been Slack's largest customer for several years and has expanded its usage of Slack over that time," reveals an SEC filing from Slack, which appears to downplay the news.

Slashdot Top Deals