Security

Personal Data of All 6.5 Million Israeli Voters Is Exposed (nytimes.com) 28

A software flaw exposed the personal data of every eligible voter in Israel -- including full names, addresses and identity card numbers for 6.5 million people -- raising concerns about identity theft and electoral manipulation, three weeks before the country's national election. The New York Times reports: The security lapse was tied to a mobile app used by Prime Minister Benjamin Netanyahu and his Likud party to communicate with voters, offering news and information about the March 2 election. Until it was fixed, the flaw made it possible, without advanced technical skills, to view and download the government's entire voter registry, though it was unclear how many people did so. How the breach occurred remains uncertain, but Israel's Privacy Protection Authority, a unit of the Justice Ministry, said it was looking into the matter -- though it stopped short of announcing a full-fledged investigation. The app's maker, in a statement, played down the potential consequences, describing the leak as a "one-off incident that was immediately dealt with" and saying it had since bolstered the site's security. "Ran Bar-Zik, the programmer who revealed the breach, explained that visitors to the Elector app's website could right-click to 'view source,' an action that reveals the code behind a web page," the report adds.

"That page of code included the user names and passwords of site administrators with access to the voter registry, and using those credentials would allow anyone to view and download the information. Mr. Bar-Zik, a software developer for Verizon Media who wrote the Sunday article in Haaretz, said he chose the name and password of the Likud party administrator and logged in."

The flaw was first reported on Sunday by the newspaper Haaretz.
Government

South Korea's Government Explores Move From Windows To Linux Desktop (zdnet.com) 44

An anonymous reader quotes a report from ZDNet: In May 2019, South Korea's Interior Ministry announced plans to look into switching to the Linux desktop from Windows. It must have liked what it saw. According to the Korean news site Newsis, the South Korean Ministry of Strategy and Planning has announced the government is exploring moving most of its approximately 3.3 million Windows computers to Linux. The reason for this is simple. It's to reduce software licensing costs and the government's reliance on Windows. As Choi Jang-hyuk, the head of the Ministry of Strategy and Finance, said, "We will resolve our dependency on a single company while reducing the budget by introducing an open-source operating system."

How much? South Korean officials said it would cost 780 billion won (about $655 million) to move government PCs from Windows 7 to Windows 10. [...] Windows will still have a role to play for now on South Korean government computers. As the Aju Business Daily, a South Korean business news site, explained: Government officials currently use two physical, air-gapped PCs. One is external for internet use, and the other is internal for intranet tasks. Only the external one will use a Linux-based distro. Eventually, by 2026, most civil servants will use a single Windows-powered laptop. On that system, Windows will continue to be used for internal work, while Linux will be used as a virtual desktop via a Linux-powered cloud server. This looks to eventually end up as a Desktop-as-a-Service (DaaS) model.
The report notes that the Ministry of National Defense and National Police Agency are already using the Ubuntu Linux 18.04 LTS-based Harmonica OS 3.0.

"Meanwhile, the Korean Postal Service division is moving to TMaxOS," reports ZDNet. "The Debian Linux-based South Korean Gooroom Cloud OS is also being used by Defense and the Ministry of Public Administration and Security."
China

Justice Dept. Charges China-backed Hackers Over Equifax Breach (techcrunch.com) 54

U.S. prosecutors have charged four hackers said to be working for the Chinese military for the 2018 cyberattack at Equifax, which led to the theft of more than 147 million credit reports in a massive data breach. From a report: Attorney general William Barr accused the four members of the Chinese People's Liberation Army of hacking into the credit giant over a period of several months. The nine-charge indictment was announced Monday against Wu Zhiyong, Wang Qian, Xu Ke, and Liu Lei. "This is the largest theft of sensitive PII by state-sponsored hackers ever recorded," said FBI deputy director David Bowdich. Equifax revealed the data breach in September 2017, months after it discovered hackers had broken into its systems. An investigation showed the company failed to patch a web server it knew was vulnerable for weeks, which let hackers crash the servers and steal massive amounts of personal data.
Microsoft

Suspicion and Anger Towards Microsoft Rises After Windows 10 Search Failure (forbes.com) 173

Earlier this week, searching in Windows 10 was broken, "with a black bar showing where search results should be, even for those who tried to perform a local search of their files." Microsoft issued a fix and blamed the issue on a "third-party networking fiber provider".

But unfortunately, Microsoft's fix isn't working for everyone -- and that's just the beginning. Long-time Slashdot reader Futurepower(R) shares Forbes' report: Second, and more worryingly, Microsoft's explanation doesn't add up and it has prompted serious questions to be asked about how the operating system works and what personal data it is sharing. Popular Microsoft pundit Woody Leonard led the charge, writing: "If you believe that yesterday's worldwide crash of Windows 10 Search was caused by a bad third-party fiber provider, I have a bridge to sell you."

In an open letter to new Windows head Panos Panay, Susan 'Patch Lady' Bradley was similarly sceptical, noting that today "we all found out that our local search boxes are somehow dependent on some service working at Microsoft." She attacked the company for a lack of transparency and gave it a maximum 'Pinocchio score' for a lack of trust... Similarly, Engadget writer Richard Lawler revealed that users were now trying to hack the Windows 10 registry to disconnect their local file searches from Microsoft servers "and I can't say I blame them after this episode. Microsoft owes users a better explanation than this and should make sure it's impossible for offline features to get taken out when the cloud is having an issue."

In fact, Forbes writes that "the aforementioned Windows 10 registry hack appears to be the only 100% fix for this issue and it also disconnects Bing and Cortana online services from Windows 10 search."

And then on Saturday the Windows Latest blog also noticed that Microsoft's release notes for Windows 10 20H1 Build 19035 reveal that Microsoft is apparently now delaying the roll-out of a widely-anticipated "Optional Updates" option. "It appears that the new Optional updates experience will come out in October/November 2020, not this spring as previously planned."
Bug

Windows 7 Bug Prevents Users From Shutting Down Or Rebooting Computers (zdnet.com) 59

An anonymous reader writes: A weird bug of unknown origins has been hitting Windows 7 computers this week, according to multiple reports online. Windows 7 users have been reporting that they are receiving a popup message that reads "You don't have permission to shut down this computer" every time they attempt to shut down or reboot their systems...

Windows 7 reached official end of life (EOL) on January 14, 2020 and is not scheduled to receive new fixes. Last month, Microsoft made an exception to this rule when it provided a fix for a bug that broke wallpaper display for Windows 7 users. Seeing that rebooting or shutting down your computer is a more important OS feature than wallpaper support, Microsoft will most likely need to make a another exception and deliver a second post-EOL update pretty soon.

Crime

New Ransomware Targets Industrial Control Systems (arstechnica.com) 35

In recent months, researchers have caught ransomware "intentionally tampering with industrial control systems that dams, electric grids, and gas refineries rely on to keep equipment running safely," reports Ars Technica. According to researchers at the security firm Drago, the ransomware tries to kill 64 different processes, the names of which are all hard-coded within the malware.

Long-time Slashdot reader Garabito shared Ars Technica's report: It remains unclear precisely what effect the killing of those processes would have on the safety of operations inside infected facilities... Monday's report described Ekans' ICS targeting as minimal and crude because the malware simply kills various processes created by widely used ICS programs. That's a key differentiator from ICS-targeting malware discovered over the past few years with the ability to do much more serious damage. One example is Industroyer, the sophisticated malware that caused a power outage in Ukraine in December 2016 in a deliberate and well-executed attempt to leave households without electricity in one of the country's coldest months...

Another reason Dragos considers Ekans to be a "relatively primitive attack" is that the ransomware has no mechanism to spread. That makes Ekans much less of a threat than ransomware such as Ryuk, which quietly collects credentials for months on infected systems so it can eventually proliferate widely through almost all parts of a targeted network.

Facebook

Facebook's Twitter Account Gets Breached (nbcnews.com) 15

The Saudi-based group OurMine took over Facebook's Twitter account on Friday, then pointed Facebook's 13.4 million followers to their own web site, reports NBC News: "Well even Facebook is hackable but at least their security is better than Twitter," the hackers tweeted just before 7 p.m. They said businesses interested in improving online security should visit OurMine's website.

The tweet was quickly taken down. Facebook later tweeted that it had regained control of the account. OurMine said in an email that the tweet was up for about 15 minutes...

While OurMine is usually described as a group of hackers, it said its security services are "for profit." Its social media takeovers have received widespread attention... "We have no bad intentions and only care about the security and privacy of your accounts and network," it said on its website.

OurMine is the same group that took over the Twitter accounts of several American football teams in January, posting "We are here to show people that everything is hackable,"
United Kingdom

UK To Host Spyware Firm Accused of Aiding Human Rights Abuses (theguardian.com) 17

An anonymous reader quotes a report from The Guardian: The British government is helping a controversial Israeli spyware company to market its surveillance technologies at a secretive trade fair visited by repressive regimes, the Guardian can reveal. The government will host the NSO Group, which sells technology that has allegedly been used by autocratic regimes to spy on the private messages of journalists and human rights activists, at the closed Security and Policing trade fair in Hampshire next month. The NSO Group is due to be an exhibitor at the three-day fair, where police and security officials from abroad can browse commercial stalls selling surveillance and crowd-control equipment.

Around 60 foreign delegations are typically hosted by the British government to the fair. In the last four years they have included countries whose human rights records have been criticized such as Saudi Arabia, Egypt, the UAE, Oman, Qatar and Hong Kong. The identities of this year's delegations are not known as they are usually announced on the opening day of the fair. NSO has faced allegations that its technology is used to target human rights activists and reporters around the world. At least three UK residents are among those who are alleged to have been targeted using spyware sold by NSO. Among them is a prominent London-based satirist who is suing Saudi Arabia in the UK courts alleging that the Riyadh regime targeted him using malware developed by the firm.
The closed Security and Policing trade fair will take place on March 3 at the Farnborough airport exhibition center.
Security

Ransomware Installs Gigabyte Driver To Kill Antivirus Products (zdnet.com) 29

A ransomware gang is installing vulnerable GIGABYTE drivers on computers it wants to infect. From a report: The purpose of these drivers is to allow the hackers to disable security products so their ransomware strain can encrypt files without being detected or stopped. This new novel technique has been spotted in two ransomware incidents so far, according to UK cybersecurity firm Sophos. In both cases, the ransomware was RobbinHood, a strain of "big-game" ransomware that's usually employed in targeted attacks against selected, high-value targets. In a report published late last night, Sophos described this new technique as follows:
1. Ransomware gang gets a foothold on a victim's network.
2. Hackers install legitimate Gigabyte kernel driver GDRV.SYS.
3. Hackers exploit a vulnerability in this legitimate driver to gain kernel access.
4. Attackers use the kernel access to temporarily disable the Windows OS driver signature enforcement.
5. Hackers install a malicious kernel driver named RBNL.SYS.
6. Attackers use this driver to disable or stop antivirus and other security products running on an infected host.
7. Hackers execute the RobbinHood ransomware and encrypt the victim's files

Security

Anatomy of a Rental Phishing Scam (jeffreyladish.com) 94

Jeffrey Ladish writes: I was recently the (unsuccessful) target of a very well-crafted phishing scam. As part of a housing search a few weeks ago, I was trawling craigslist and zillow for rental opportunities in the SF bay area. I reached out to a beautiful looking rental place to inquire about a tour. Despite my experience as a security professional, I didn't realize this was a scam until about the third email! Below I will account the story in excessive detail including screenshots. [...] The phishing team -- and given the work involved and the level of polish I bet it was a team -- ran a pretty tight operation. Their English was perfect, their emails looked professional, and their phishing site looked identical the original Airbnb site. The email domain "engineers-hibernia-chevron [dot] ca" redirected to "hibernia [dot] ca" to add legitimacy for those who took the extra step of looking up the domain.

I'm even more impressed by their subtle psychological tricks. Each step of the way, they left out information which required me to ask for something if I wanted to proceed. It's a lot easier to be on your guard when others are asking you for things. When you're the one doing the asking, it's even harder to say something when things look strange, because you may already feel like you're being a burden on their time. For the initial ad, they left out the phone number so I had to ask. After they told me I could look at their airbnb site, I had to ask for a link. Then, after they sent me to search on Airbnb's site, I had to ask for the link again! That was deliberately planned! Throughout these interactions, they mentioned there were other people looking, maintaining a plausible sense of urgency. Finally, using Airbnb as the phishing site was clever, because it gave the impression of a trusted middleman. I was genuinely thrown off at first, because I couldn't figure out how they were planning to steal my financial information. If they had just asked for bank or credit card information early on, their game would have been easy to spot.

IT

Makers of Basecamp Announce Email Product 'Hey', Open Invites (hey.com) 45

Makers of productivity suite Basecamp have announced Hey, an email product they plan to release this spring. Basecamp founder and CEO, Jason Fried shared the vision for what they are calling a much-improved approach to email in an open letter today on the Hey website: You started getting stuff you didn't want from people you didn't know. You lost control over who could reach you. You were forced to inherit other people's bad communication habits. Then an avalanche of automated emails amplified the clutter. And Gmail, Outlook, Yahoo, Apple, and all the others just let it happen. Now email feels like a chore, rather than a joy. Something you fall behind on. Something you clear out, not cherish. Rather than delight in it, you deal with it. Your relationship with email changed, and you didn't have a say.

So good news, the magic's still there. It's just obscured -- buried under a mess of modern day bad habits and neglect. Some from people, some from machines, a lot from email systems. It deserves a dust off. A renovation. Modernized for the way we email today. With HEY, we've done just that. It's a redo, a rethink, a simplified, potent reintroduction of email. A fresh start, the way it should be. For web, iOS, and Android. HEY is our love letter to email, and we're sending it to you.
Over 12,000 people have requested early access to Hey since yesterday, said David Heinemeier Hansson, founder of Basecamp, and creator of Ruby on Rails.
Windows

New Keyboard Shortcut Manager PowerToy Lets Windows 10 Users Remap Their Keyboards (betanews.com) 59

Microsoft's PowerToys utilities have always proved popular, and the arrival of a Windows 10 version was met with huge excitement. New utilities have been released over the last few months, and now there is news of a new addition: Keyboard Shortcut Manager. From a report: Despite the name, Keyboard Shortcut Manager does much more than give you control over keyboard shortcuts. On top of this, the PowerToy can be used to remap keys -- something that will be welcomed by power users, developers and people switching from macOS or Linux to Windows. At the moment, Keyboard Shortcut Manager is still in development, and it's not quite clear when there will be a version to download. But judging by how quickly the existing PowerToys have moved from embryonic ideas into fully fledged products, it shouldn't be too long before an installable version appears. When it does, it could be known simply as Keyboard Manager.
Android

Google Fixes No-User-Interaction Bug In Android's Bluetooth Component (zdnet.com) 22

An anonymous reader quotes a report from ZDNet: Google has patched this week a critical security flaw in Android's Bluetooth component. If left unpatched, the vulnerability can be exploited without any user interaction and can even be used to create self-spreading Bluetooth worms. Researchers said that exploiting the bug requires no user interaction. All that is required is that the user has Bluetooth enabled on his device. However, while this requirement would have limited the attack surface in past years, it does not today since modern Android OS versions ship with Bluetooth enabled by default and many Android users use Bluetooth-based headphones meaning the Bluetooth service is likely to be enabled on many handsets. The bug can lead to remote code execution and the hijacking of a device. Fixes for the bug are available via the Android February 2020 Security Bulletin, which has been available for download starting this week. Android 9 and earlier are impacted.
Software

NASA Safety Panel Calls For Reviews After Second Starliner Software Problem (spacenews.com) 83

A second software problem during a CST-100 Starliner test flight is prompting a NASA safety panel to recommend a review of Boeing's software verification processes. Space News reports: That new software problem, not previously discussed by NASA or Boeing, was discussed during a Feb. 6 meeting of NASA's Aerospace Safety Advisory Panel that examined the December uncrewed test flight of Starliner that was cut short by a timer error. That anomaly was discovered during ground testing while the spacecraft was in orbit, panel member Paul Hill said. "While this anomaly was corrected in flight, if it had gone uncorrected, it would have led to erroneous thruster firings and uncontrolled motion during [service module] separation for deorbit, with the potential for a catastrophic spacecraft failure," he said.

The exact cause of the failure remains under investigation by Boeing and NASA, who are also still examining the timer failure previously reported. Those problems, Hill said, suggested broader issues with how Boeing develops and tests the software used by the spacecraft. "The panel has a larger concern with the rigor of Boeing's verification processes," he said. The panel called for reviews of Boeing's flight software integration and testing processes. "Further, with confidence at risk for a spacecraft that is intended to carry humans in space, the panel recommends an even broader Boeing assessment of, and corrective actions in, Boeing's [systems engineering and integration] processes and verification testing." The panel added that all those investigations and reviews be completed as "required input for a formal NASA review to determine flight readiness for either another uncrewed flight test or proceeding directly to a crewed test flight."

Security

The Iowa Caucuses App Could Have Been Hacked (propublica.org) 120

A security firm consulted by ProPublica found that the "IowaReporter" app used to count and report votes from individual precincts in the Iowa Democratic caucuses was vulnerable to hacking. From the report: The IowaReporterApp was so insecure that vote totals, passwords and other sensitive information could have been intercepted or even changed, according to officials at Massachusetts-based Veracode, a security firm that reviewed the software at ProPublica's request. Because of a lack of safeguards, transmissions to and from the phone were left largely unprotected. Chris Wysopal, Veracode's chief technology officer, said the problems were elementary. He called it a "poor decision" to release the software without first fixing them. "It is important for all mobile apps that deal with sensitive data to have adequate security testing, and have any vulnerabilities fixed before being released for use," he said.

There's no evidence that hackers intercepted or tampered with caucus results. An attack would have required some degree of sophistication, but it would have been much easier to pull off had a precinct worker used an open Wi-Fi hotspot to report votes instead of a cell data plan. The U.S. Department of Homeland Security offered to test the app for the Iowa Democratic Party, but the party never took the government up on it, according to a U.S. official familiar with the matter who was not authorized to speak publicly. The official said the party did participate in a dry run, known as a tabletop exercise. The party did not respond to requests for comment on this issue.
Gerard Niemira, Shadow's CEO, said in a statement to ProPublica that "we are committed to the security of our products, including the app used during the Iowa caucuses. While there were reporting delays, what was most important is that the data was accurate and the caucus reporting process remained secure throughout."

"Our app underwent multiple, rigorous tests by a third party, but we learned today that a researcher found a vulnerability in our app. As with all software, sometimes vulnerabilities are discovered after they are released." He added that no "hack or intrusion" occurred during the caucuses, and that "the integrity of the vote in Iowa was not compromised in any way." The app is not currently in use, he said.

NBC News is also reporting that the phone number used to report Iowa caucus results was posted on 4chan on Monday night "along with encouragement to 'clog the lines,' an indication that jammed phone lines that left some caucus managers on hold for hours may have in part been due to prank calls."
Privacy

Wacom Drawing Tablets Track the Name of Every Application That You Open (robertheaton.com) 73

Software engineer Robert Heaton writes: Last week I set up my tablet on my new laptop. As part of installing its drivers I was asked to accept Wacom's privacy policy. Being a mostly-normal person I never usually read privacy policies. Instead I vigorously hammer the "yes" button in an effort to reach the game, machine, or medical advice on the other side of the agreement as fast as possible. But Wacom's request made me pause. Why does a device that is essentially a mouse need a privacy policy? I wondered. Sensing skullduggery, I decided to make an exception to my anti-privacy-policy-policy and give this one a read.

In Wacom's defense (that's the only time you're going to see that phrase today), the document was short and clear, although as we'll see it wasn't entirely open about its more dubious intentions. In addition, despite its attempts to look like the kind of compulsory agreement that must be accepted in order to unlock the product behind it, as far as I can tell anyone with the presence of mind to decline it could do so with no adverse consequences. With that attempt at even-handedness out the way, let's get kicking. In section 3.1 of their privacy policy, Wacom wondered if it would be OK if they sent a few bits and bobs of data from my computer to Google Analytics, "[including] aggregate usage data, technical session information and information about [my] hardware device." The half of my heart that cares about privacy sank. The other half of my heart, the half that enjoys snooping on snoopers and figuring out what they're up to, leapt. It was a disjointed feeling, probably similar to how it feels to get mugged by your favorite TV magician.

Security

Academics Steal Data From Air-Gapped Systems Using Screen Brightness Variations (zdnet.com) 52

Academics from Israel have detailed and demoed a new method for stealing data from air-gapped computers. From a report: The method relies on making small tweaks to an LCD screen's brightness settings. The tweaks are imperceptible to the human eye, but can be detected and extracted from video feeds using algorithmical methods. This article describes this innovative new method of stealing data, but readers should be aware from the start that this attack is not something that regular users should worry about, and are highly unlikely to ever encounter it. Named BRIGHTNESS, the attack was designed for air-gapped setups -- where computers are kept on a separate network with no internet access. Air-gapped computers are often found in government systems that store top-secret documents or enterprise networks dedicated to storing non-public proprietary information.
Microsoft

Microsoft Says it Detects 77,000 Active Web Shells on a Daily Basis (zdnet.com) 19

In a blog post promoting the capabilities of its commercial security platform -- the Microsoft Defender ATP -- Microsoft said that on a daily basis the company's security team detects and tracks on average around 77,000 active web shells, spread across 46,000 infected servers. From a report: But while the Microsoft blog post goes on to promote Defender ATP's industry-recognized detection capabilities, the nugget in Microsoft's recent marketing material is the 77,000 and 46,000 daily statistics. These two numbers are staggering in terms of size, and especially the 77,000 figure, which is far far larger than any previous reports about web shell prevalence. For example, earlier this month GoDaddy's Sucuri reported on cleaning around 3,600 web shells from hacked websites during all last year, in 2019, a number dwarfed by Microsoft's daily detection count. Microsoft's numbers highlight the prevalence of these tools in the today's hackers' arsenals -- where web shells are considered a must for every threat actor, from lowly hacktivist groups defacing websites to state-sponsored cyber-espionage groups.
Security

The FBI Downloaded CIA's Hacking Tools Using Starbuck's WiFi (emptywheel.net) 38

An anonymous reader shares a report: One of the most interesting details from the yesterday's Joshua Schulte trial involved how the FBI obtained the Vault 7 and Vault 8 materials they entered into evidence yesterday. Because the FBI did not want to download the files onto an existing FBI computer (in part, out of malware concerns) and because they didn't want to use an FBI IP address, they got a new computer and downloaded all the files at Starbucks.
Security

Patch Your Philips Hue Lightbulbs To Stop Them From Getting Hacked -- And Potentially Everything Else On Your Network (fortune.com) 183

An anonymous reader shares a report: Four years ago, security researchers showed how a flying drone could hack an entire room full of Philips Hue smart light bulbs from outside a building, by setting off a virus-like chain reaction that jumped from bulb to bulb. Today, we're learning that vulnerability never got fully fixed -- and now, researchers have figured out a way to exploit that very same issue to potentially infiltrate your home or corporate network, unless you install a patch. That's the word from cybersecurity research firm Check Point Software, and the good news is you should already be safe from the worst part of the hack. If the Philips Hue Hub that controls your bulbs is connected to the internet, it should have automatically updated itself to version 1935144040 by now, which contains the patch you want. (Check Point informed Philips in November, and a patch was issued mid-January.)

Slashdot Top Deals