Security

Serious Flaw That Lurked In Sudo For 9 Years Hands Over Root Privileges (arstechnica.com) 96

An anonymous reader quotes a report from Ars Technica: Sudo, a utility found in dozens of Unix-like operating systems, has received a patch for a potentially serious bug that allows unprivileged users to easily obtain unfettered root privileges on vulnerable systems. The vulnerability, tracked as CVE-2019-18634, is the result of a stack-based buffer-overflow bug found in versions 1.7.1 through 1.8.25p1. It can be triggered only when either an administrator or a downstream OS, such as Linux Mint and Elementary OS, has enabled an option known as pwfeedback. With pwfeedback turned on, the vulnerability can be exploited even by users who aren't listed in sudoers, a file that contains rules that users must follow when using the sudo command.

"Exploiting the bug does not require sudo permissions, merely that pwfeedback be enabled," an advisory published by sudo developers said. "The bug can be reproduced by passing a large input to sudo via a pipe when it prompts for a password." The advisory lists two flaws that lead to the vulnerability. The first: pwfeedback isn't ignored as it should be when reading from something other than a terminal. As a result, the saved version of a line erase character remains at its initialized value of 0. The second contributor is that the code that erases the line of asterisks doesn't properly reset the buffer position if there is an error writing data. Instead, the code resets only the remaining buffer length. As a result, input can write past the end of the buffers. Systems with unidirectional pipe allow an attempt to write to the read end of the pipe to result in a write error. Because the remaining buffer length isn't reset correctly when write errors result from line erasures, the stack buffer can be overflowed.
The report notes the vulnerability was introduced in 2009 and remained active until 2018, with the release of 1.8.26b1. "Systems or software using a vulnerable version should move to version 1.8.31 as soon as practical," reports Ars. "Those who can't update right away can prevent exploits by making sure pwfeedback is disabled."
Privacy

Amazon's Ring Doorbell Update Allows Opt Out of All Police Video Requests (mashable.com) 74

Amazon's Ring doorbell has rolled out a new update that lets users add and remove shared users on an account, restrict third-party access, view two-factor authentication settings, and (perhaps, most importantly) opt out of all video request notifications from law enforcement. Mashable reports: Uncovered in reporting by Motherboard and Gizmodo in 2019, the scale of Amazon's Neighbor Portal program is much larger than originally believed -- and its various affiliations with law enforcement has raised alarming ethical questions. In the new update, users will be able to see an "Active Law Enforcement Map" clarifying which local institutions are part of the Neighbor Portal network. They will also be able to disable requests for video from officials, whether or not they have received one in the past. (This feature was available previously, but an account had to have received one request for the opt-out option to appear.)

That said, Ring is suggesting users allow video request notifications -- citing specific instances where such evidence helped solve criminal cases. According to Ring's official press release, the control center update will be made available to all Android and iOS users within "the next few days." Per the same release, this is the first of numerous security and privacy updates planned for the system.

Democrats

Iowa Caucus Debacle is One of the Most Stunning Tech Failures Ever (cnbc.com) 439

The Iowa caucus debacle represents one of the most stunning failures of information security ever. From a column: This failure was delivered by the same Iowa Democratic Party officials who have said for the last four years they were "ramping up" their technology capabilities, convening seemingly endless security task forces to ensure foreign powers did not disenfranchise voters, and collaborating with federal agencies like the Department of Homeland Security to make sure everyone was in the loop on voting security. Voters will be paying close attention to how party leaders ensure that votes going forward have clear contingency plans in place, not just to protect against hackers, but from all types of technology failures, including applications that might not work.

Iowa officials counting the results coming in Monday from the caucusing app reported irregularities that required them to switch from the app to counting votes manually. Party officials said the "underlying data" put into the app was fine, but it is unclear as of yet how they know this or even what they consider "underlying data." "Last night, more than 1,600 precinct caucuses gathered across the state of Iowa and at satellite caucuses around the world," the Iowa Democratic Party said in a statement Tuesday. "As precinct caucus results started coming in, the IDP ran them through an accuracy and quality check. It became clear that there were inconsistencies with the reports. The underlying cause of these inconsistencies was not immediately clear, and required investigation, which took time."

Chrome

Google Cuts Chrome 'Patch Gap' in Half, From 33 Days To 15 (zdnet.com) 10

Google security engineers said last week they have successfully cut down the "patch gap" in Google Chrome from 33 days to only 15 days. From a report: The term "patch gap" refers to the time it takes from when a security bug is fixed in an open source library to when the same fix lands in software that uses that particular library. In today's software landscape where many apps rely on open source components, the "patch gap" is considered a major security risk. The reason is because when a security bug is fixed in an open source library, details about that bug become public, primarily due to the public nature and openness of most open source projects. Hackers can then use details about these security flaws to craft exploits and launch attacks against software that relies on the vulnerable component, before the software maker has a chance to release a patch. If the software maker is on a fixed release schedule, with updates coming out every few weeks or months, the patch gap can provide hackers with an attack window that most software projects can't deal with.
Google

Google May Have Shared Your Videos With Strangers (betanews.com) 17

If you used Google Takeout to download an archive of your Google Photos content, there's a chance that someone else may have ended up with your videos. From a report: The company has admitted that for a few days in November last year, "some videos in Google Photos were exported to unrelated users' archives." This means that not only could your videos have ended up on a stranger's computer, but also that you may have received random videos belonging to someone else. Google is not making much of the "technical issue" which it says has now been resolved. But the company apologizes for the "inconvenience" that may have been caused for people downloading their Google Photos archive between November 21 and 25, 2019.
Nintendo

FBI Catches Hacker That Stole Nintendo's Secrets For Years (arstechnica.com) 31

An anonymous reader quotes a report from Ars Technica: A 21-year-old California man has pleaded guilty to hacking Nintendo's servers multiple times since 2016, using phishing techniques to gain early access to information about the company's plans. Ryan S. Hernandez, who went by RyanRocks online, worked with an unnamed associate to phish employee login credentials for proprietary Nintendo servers, according to an indictment filed in Washington state federal court in December and unsealed over the weekend. Hernandez used that unauthorized access to "download thousands of files, including proprietary developer tools and non-public information" about upcoming Nintendo products and "access pirated and unreleased video games."

That information (and discussion of Nintendo's internal server vulnerabilities) was leaked to the public via Twitter, Discord, and a chat room called "Ryan's Underground Hangout," prosecutors said. At one point, "RyanRocks" drew at least a little infamy in the Nintendo hacking community for allegedly leaking a Nintendo Software Development Kit that had a piece of hidden Remote Access Tool malware added to it. FBI agents confronted Hernandez about his hacking in 2017, according to a prosecution press release, and secured a promise from Hernandez "to stop any further malicious activity." But the hacking continued in 2018 and 2019, according to the indictment, until a June 2019 FBI raid that obtained hard drives with thousands of proprietary Nintendo files. The seized hard drives also included sexually explicit images of minors in a folder labeled "BAD STUFF," according to prosecutors. Hernandez has agreed to pay almost $260,000 to Nintendo as part of a plea agreement. Prosecutors are recommending a jail term of three years for Hernandez's crimes when sentencing is decided in April.

Security

Elon Musk Announces AI Party/Hackathon At His Home With Tesla AI/Autopilot Team 52

Rei writes: On Twitter yesterday evening, Elon Musk announced an upcoming AI party/hackathon to be held at his house, and that invites will be going out soon. Asked whether a person needs to have a Ph.D to attend, Musk replied no: "All that matters is a deep understanding of AI & ability to implement NNs in a way that is actually useful (latter point is what's truly hard). Don't care if you even graduated high school." The hackathon appears to be Musk's latest attempt to accumulate AI talent. Last fall, Tesla acquired AI startup DeepScale in order to bring its engineers into its team, while days ago Musk posted an AI job ad on his Twitter page.
United States

West Virginia Poised To Allow Smartphone Voting For Disabled Voters (arstechnica.com) 47

An anonymous reader quotes a report from Ars Technica: West Virginia's legislature last week passed legislation allowing disabled voters to cast votes by smartphone, sending the bill to the desk of Governor Jim Justice. Justice is expected to sign the legislation, according to NBC. It's a decision that alarms many computer security experts, who say that the Internet and smartphones are too vulnerable to hackers.

The legislation would require every county in the state to offer smartphone voting. It doesn't specify any particular voting method, but the state has recently been experimenting with software called Voatz that tries to use a blockchain to help secure elections. West Virginia performed a small-scale pilot project with Voatz in the 2018 election, allowing about 150 overseas voters to vote using the technology. A fundamental problem with online voting, experts say, is that modern computing devices have a huge "attack surface." Even if the voting app itself is completely secure, there might still be vulnerabilities in the user's operating system, network, or the servers used to register users and collect votes. And to swing an election, a hacker doesn't need to change anyone's votes -- just preventing some of a candidate's voters from voting can be sufficient to swing a close election. But West Virginia officials have pressed forward, arguing that it's too difficult for some disabled voters to get to a physical polling place to cast votes.
Washington is also considering smartphone voting. The King Conservation District, a district of 1.2 million voters encompassing Greater Seattle, may have the option to cast votes online using a smartphone.
Microsoft

Microsoft Teams Went Down After Microsoft Forgot To Renew a Critical Certificate (theverge.com) 72

An anonymous reader quotes a report from The Verge: Microsoft Teams went down this morning for nearly three hours after Microsoft forgot to renew a critical security certificate. Users of Microsoft's Slack competitor were met with error messages attempting to sign into the service on Monday morning, with the app noting it had failed to establish an HTTPS connection to Microsoft's servers. Microsoft confirmed the Teams service was down just after 9AM ET today, and then later revealed the source of the issue. "We've determined that an authentication certificate has expired causing users to have issues using the service," explains Microsoft's outage notification. Microsoft then started rolling the fix out at 11:20AM ET, and by 12PM ET the service was restored for most affected users.
Firefox

Firefox Now Shows What Telemetry Data It's Collecting About You (zdnet.com) 34

There is now a special page in the Firefox browser where users can see what telemetry data Mozilla is collecting from their browser. From a report: Accessible by typing about:telemetry in the browser's URL address bar, this new section is a recent addition to Firefox. The page shows deeply technical information about browser settings, installed add-ons, OS/hardware information, browser session details, and running processes. The information is what you'd expect a software vendor to collect about users in order to fix bugs and keep a statistical track of its userbase. A Firefox engineer told ZDNet the page was primarily created for selfish reasons, in order to help engineers debug Firefox test installs. However, it was allowed to ship to the stable branch also as a PR move, to put users' minds at ease about what type of data the browser maker collects from its users.
Google

'Hack' Creates Fake Google Maps Traffic Jams With 99 Cell Phones (bleepingcomputer.com) 92

A German artist illustrated [video] how it is possible to create a virtual traffic jam in Google Maps by walking around the streets of Berlin with 99 cell phones. Qbertino shares a report: Google Maps utilizes GPS and location data from mobile devices to determine if there is traffic congestion on a particular street. The app will then redirect users to less trafficked streets to avoid traffic. Using a hand cart filled with 99 active cell phones connected to Google Maps, artist Simon Weckert showed how he could create fake traffic jams in Google Maps simply by walking around the streets of Berlin. As he would be walking, rather than driving, Google Maps would perceive it to be a traffic jam due to a large number of devices reporting the same slow speed. Google's response to the matter, via blog 9to5Google: Speaking with 9to5Google, a spokesperson from Google has responded to this situation to clarify a few things. In normal usage, Google does use a large number of devices running Maps in a single place as proof of a traffic jam, something this rare and very specific case took advantage of. In the statement below, though, the company does hint that it might use cases like this to further improve how Maps handles traffic data. "Whether via car or cart or camel, we love seeing creative uses of Google Maps as it helps us make maps work better over time."
Security

Only Three of the Top 100 International Airports Pass Basic Security Checks (zdnet.com) 39

Only three of the world's Top 100 international airports pass basic security checks, according to a report published last week by cyber-security firm ImmuniWeb. From a report: The three are the Amsterdam Schiphol Airport in the Netherlands, the Helsinki Vantaa Airport in Finland, and the Dublin International Airport in Ireland. According to ImmuniWeb, these three "may serve a laudable example not just to the aviation industry but to all other industries as well." The three are the only airports that passed a long list of security tests that involved checks of their public websites, official mobile applications, and searches for leaks of sensitive airport or passenger data in places like cloud services, public code repositories, or the dark web.
Wireless Networking

Researchers Find Some LoRaWAN Networks Vulnerable to Cyber-Attacks (zdnet.com) 6

Slashdot reader JustAnotherOldGuy quotes ZDNet: Security experts have published a report Tuesday warning that the new and fast-rising LoRaWAN technology is vulnerable to cyberattacks and misconfigurations, despite claims of improved security rooted in the protocol's use of two layers of encryption.

LoRaWAN stands for "Long Range Wide Area Network." It is a radio-based technology that works on top of the proprietary LoRa protocol. LoRaWAN takes the LoRa protocol and allows devices spread across a large geographical area to wirelessly connect to the internet via radio waves...

But broadcasting data from devices via radio waves is not a secure approach. However, the protocol's creators anticipated this issue. Since its first version, LoRaWAN has used two layers of 128-bit encryption to secure the data being broadcast from devices — with one encryption key being used to authenticate the device against the network server and the other against a company's backend application. In a 27-page report published Tuesday, security researchers from IOActive say the protocol is prone to misconfigurations and design choices that make it susceptible to hacking and cyber-attacks. The company lists several scenarios it found plausible during its analysis of this fast-rising protocol.

Some examples:
  • "Encryption keys can be extracted from devices by reverse engineering the firmware of devices that ship with a LoRaWAN module."
  • "Many devices come with a tag displaying a QR code and/or text with the device's identifier, security keys, or more."

Bug

OpenBSD Mail Server Bug Allowed Remotely Executing Shell Commands As Root (zdnet.com) 39

This week a remotely-exploitable vulnerability (granting root privileges) was discovered in OpenSMTPD (OpenBSD's implementation of server-side SMTP).

ZDNet notes that the library's "portable" version "has also been incorporated into other OSes, such as FreeBSD, NetBSD, and some Linux distros, such as Debian, Fedora, Alpine Linux, and more." To exploit this issue, an attacker must craft and send malformed SMTP messages to a vulnerable server... OpenSMTPD developers have confirmed the vulnerability and released a patch earlier Wednesday -- OpenSMTPD version 6.6.2p1...

The good news is that the bug was introduced in the OpenSMTPD code in May 2018 and that many distros may still use older library versions, not affected by this issue. For example, only in-dev Debian releases are affected by this issue, but not Debian stable branches, which ship with older OpenSMTPD versions.

Technical details and proof of concept exploit code are available in the Qualys CVE-2020-7247 security advisory.

Hackaday has a more detailed description of the vulnerability, while the Register looks at the buggy C code.

Interestingly, Qualys researchers exploited this vulnerability using a technique from the Morris Worm of 1988.
Cloud

Move Over, Silicon Valley: St. Louis, Atlanta, Small Cities Gaining Tech Jobs (dice.com) 72

Slashdot reader SpaceForceCommander shared Dice's new annual report on America's tech industry salaries based on a survey of over 12,800 "technologists": Columbus and St. Louis enjoyed double-digit year-over-year growth in salaries (14.2 percent and 13.6 percent, respectively), and other cities such as Denver [7 percent] and Atlanta [10 percent] also experienced an ideal mix of growth and high salaries. These up-and-comers benefitted from the presence of key employers such as Amazon and IBM; in addition, a lower cost of living and plentiful amenities have made them increasingly attractive to technologists, even those coming from well-established tech hubs such as Silicon Valley.

Silicon Valley remains a world of high salaries — but the cost of living in the Bay Area remains extraordinarily high, which chews into that higher-than-average paycheck. And that's before we factor in issues such as grinding commutes. In Seattle, New York City (also known as "Silicon Alley"), and other well-established tech hubs, costs are similarly high, which only makes up-and-coming tech hubs more potentially attractive to technologists.

Silicon Valley is still #1 on Dice's ranking of average annual salaries (at $123,826), followed by Seattle, San Diego, Boston, Baltimore, Portland, Denver, and then New York. (And while St. Louis ranks #9, Columbus is #17.)

But the average annual tech-industry salary rose just 1.3 percent last year, according to the survey, with Dice arguing that what made salaries vary was supply and demand. They then ranked the highest-paying skills, starting with Apache Kafka (with average reported salaries of $134,557), followed by HANA (High performance ANalytic Appliance), Cloudera, and MapReduce: Newer skills don't necessarily draw higher salaries; with many older skills, the number of proficient technologists is relatively low, which means employers are willing to pay more in order to secure their services. (That's a key reason why the handful of technologists who still know their way around an ancient mainframe can score six-figure salaries from companies that haven't given up decades-old hardware....) In the case of programming languages such as Swift, which enjoyed significant year-over-year growth and high salaries, a large number of technologists might have mastered it — but the market is huge and white-hot, ensuring that compensation will only rise.
Encryption

Linus Torvalds Pulls WireGuard VPN into Linux 5.6 Kernel Source Tree (techradar.com) 51

"The WireGuard VPN protocol will be included into the next Linux kernel as Linus Torvalds has merged it into his source tree for version 5.6," reports TechRadar:
While there are many popular VPN protocols such as OpenVPN, WireGuard has made a name for itself by being easy to configure and deploy as SSH... The WireGuard protocol is a project from security researcher and kernel developer Jason Donenfeld who created it as an alternative to both IPsec and OpenVPN. Since the protocol consists of around just 4,000 lines of code as opposed to the 100,000 lines of code that make up OpenVPN, it is much easier for security experts to review and audit for vulnerabilities.

While WireGuard was initially released for the Linux kernel, the protocol is now cross-platform and can be deployed on Windows, macOS, BSD, iOS and Android.

Ars Technica notes that with Linus having merged WireGuard into the source tree, "the likelihood that it will disappear between now and 5.6's final release (expected sometime in May or early June) is vanishingly small." WireGuard's Jason Donenfeld is also contributing AVX crypto optimizations to the kernel outside the WireGuard project itself. Specifically, Donenfeld has optimized the Poly1305 cipher to take advantage of instruction sets present in modern CPUs. Poly1305 is used for WireGuard's own message authentication but can be used outside the project as well — for example, chacha20-poly1305 is one of the highest-performing SSH ciphers, particularly on CPUs without AES-NI hardware acceleration.

Other interesting features new to the 5.6 kernel will include USB4 support, multipath TCP, AMD and Intel power management improvements, and more.

Social Networks

Social Media Boosting Service Exposed Thousands of Instagram Passwords (techcrunch.com) 11

An anonymous reader quotes a report from TechCrunch: A social media boosting startup, which bills itself as a service to increase a user's Instagram followers, has exposed thousands of Instagram account passwords. The company, Social Captain, says it helps thousands of users to grow their Instagram follower counts by connecting their accounts to its platform. Users are asked to enter their Instagram username and password into the platform to get started. But TechCrunch learned this week Social Captain was storing the passwords of linked Instagram accounts in unencrypted plaintext. Any user who viewed the web page source code on their Social Captain profile page could see their Instagram username and password in plain sight, so long as they had connected their account to the platform.

Making matters worse, a website bug allowed anyone access to any Social Captain user's profile without having to log in -- simply plugging in a user's unique account ID into the company's web address would grant access to their Social Captain account -- and their Instagram login credentials. Because the user account IDs were for the most part sequential, it was possible to access any user's account and view their Instagram password and other account information with relative ease.
The security researcher who reported the vulnerability provided a spreadsheet of about 10,000 scraped user accounts to TechCrunch.

"The spreadsheet contained about 4,700 complete sets of Instagram usernames and passwords," the report says. "The rest of the records contained just the user's name and their email address."
Encryption

A New Bill Could Punish Web Platforms For Using End-To-End Encryption (theverge.com) 93

Lindsey Graham (R-SC) is working on a bill that would reduce legal protections for apps and websites, potentially jeopardizing online encryption. The Verge reports: The draft bill would form a "National Commission on Online Child Exploitation Prevention" to establish rules for finding and removing child exploitation content. If companies don't follow these rules, they could lose some protection under Section 230 of the Communications Decency Act, which largely shields companies from liability over users' posts. Reports from Bloomberg and The Information say that Sen. Lindsey Graham (R-SC) is behind the bill, currently dubbed the Eliminating Abusive and Rampant Neglect of Interactive Technologies (or EARN IT) Act. It would amend Section 230 to make companies liable for state prosecution and civil lawsuits over child abuse and exploitation-related material, unless they follow the committee's best practices. They wouldn't lose Section 230 protections for other content like defamation and threats.

The bill doesn't lay out specific rules. But the committee -- which would be chaired by the Attorney General -- is likely to limit how companies encrypt users' data. Large web companies have moved toward end-to-end encryption (which keeps data encrypted for anyone outside a conversation, including the companies themselves) in recent years. Facebook has added end-to-end encryption to apps like Messenger and Whatsapp, for example, and it's reportedly pushing it for other services as well. U.S. Attorney General William Barr has condemned the move, saying it would prevent law enforcement from finding criminals, but Facebook isn't required to comply. Under the EARN IT Act, though, a committee could require Facebook and other companies to add a backdoor for law enforcement.

Encryption

This Sculpture Holds a Decades-Old C.I.A. Mystery. And Now, Another Clue. (nytimes.com) 20

The creator of one of the world's most famous mysteries is giving obsessive fans a new clue. From a report: Kryptos, a sculpture in a courtyard at the headquarters of the Central Intelligence Agency in Langley, Va., holds an encrypted message that has not fully yielded to attempts to crack it. It's been nearly 30 years since its tall scroll of copper with thousands of punched-through letters was set in place. Three of the four passages of the sculpture have been decrypted (the first, though unacknowledged at the time, was solved by a team from the National Security Agency). But after nearly three decades, one brief passage remains uncracked. And that has been a source of delight and consternation to thousands of people around the world. The sculptor, Jim Sanborn, has been hounded for decades by codebreaking enthusiasts. And he has twice provided clues to move the community of would-be solvers along, once in 2010 and again in 2014. Now he is offering another clue. The last one, he says. It is a word: "NORTHEAST."

Why do people care so much about a puzzle cut into a sheet of copper in a courtyard after so much time? It's not just that the piece itself has a kind of brooding, powerful beauty, or the fact that it has been referred to in novels by the thriller writer Dan Brown. It is something deeper, something that involves the nature of the human mind, said Craig Bauer, a professor of mathematics at York College of Pennsylvania and a former scholar in residence at the N.S.A.'s Center for Cryptologic History. "We have many problems that are difficult to resolve -- intimidating, perhaps even scary," he said. "It gives people great pleasure to pick up on one that they think they have a chance of solving." [...] Why now? Did we mention Mr. Sanborn is 74? Holding on to one of the world's most enticing secrets can be stressful. Some would-be codebreakers have appeared at his home. Many felt they had solved the puzzle, and wanted to check with Mr. Sanborn. Sometimes forcefully. Sometimes, in person.
NPR spoke with Sanborn (4-min).
Security

Public Wi-Fi is a Lot Safer Than You Think (eff.org) 80

Jacob Hoffman-Andrews, writing for EFF: If you follow security on the Internet, you may have seen articles warning you to "beware of public Wi-Fi networks" in cafes, airports, hotels, and other public places. But now, due to the widespread deployment of HTTPS encryption on most popular websites, advice to avoid public Wi-Fi is mostly out of date and applicable to a lot fewer people than it once was. The advice stems from the early days of the Internet, when most communication was not encrypted. At that time, if someone could snoop on your network communications -- for instance by sniffing packets from unencrypted Wi-Fi or by being the NSA -- they could read your email. Starting in 2010 that all changed. Eric Butler released Firesheep, an easy-to-use demonstration of "sniffing" insecure HTTP to take over people's accounts. Site owners started to take note and realized they needed to implement HTTPS (the more secure, encrypted version of HTTP) for every page on their site. The timing was good: earlier that year, Google had turned on HTTPS by default for all Gmail users and reported that the costs to do so were quite low. Hardware and software had advanced to the point where encrypting web browsing was easy and cheap.

However, practical deployment of HTTPS across the whole web took a long time. One big obstacle was the difficulty for webmasters and site administrators of buying and installing a certificate (a small file required in order to set up HTTPS). EFF helped launch Let's Encrypt, which makes certificates available for free, and we wrote Certbot, the easiest way to get a free certificate from Let's Encrypt and install it. Meanwhile, lots of site owners were changing their software and HTML in order to make the switch to HTTPS. There's been tremendous progress, and now 92% of web page loads from the United States use HTTPS. In other countries the percentage is somewhat lower -- 80% in India, for example -- but HTTPS still protects the large majority of pages visited. [...] What about the risk of governments scooping up signals from "open" public Wi-Fi that has no password? Governments that surveill people on the Internet often do it by listening in on upstream data, at the core routers of broadband providers and mobile phone companies. If that's the case, it means the same information is commonly visible to the government whether they sniff it from the air or from the wires.

Slashdot Top Deals