Chrome

Google Chrome To Hide Notification Spam Starting February 2020 (zdnet.com) 50

Following in Mozilla's footsteps, Google announced today plans to hide notification popup prompts inside Chrome starting next month, February 2020. ZDNet reports: According to a blog post published today, Google plans to roll out a "quieter notification permission UI that reduces the interruptiveness of notification permission requests." The change is scheduled for Google Chrome 80, scheduled for release on February 4, next month.

Starting with Chrome 80 next month, Google's browser will also block most notification popups by default, and show an icon in the URL bar, similar to Firefox. When Chrome 80 launches next month, a new option will be added in the Chrome settings section that allows users to enroll in the new "quieter notification UI." Users can enable this option as soon as Chrome 80 is released, or they can wait for Google to enable it by default as the feature rolls out to the wider Chrome userbase in the following weeks. According to Google, the new feature works by hiding notification requests for Chrome users who regularly dismiss notification prompts. Furthermore, Chrome will also automatically block notification prompts on sites where users rarely accept notifications.

Mozilla

GitHub, Mozilla, and Cloudflare Appeal India To Be Transparent About Changes in Its Intermediary Liability Rules (techcrunch.com) 14

Microsoft's GitHub, Mozilla, and Cloudflare have urged India to be transparent about the amendments it is making to an upcoming law that could affect swathes of companies and the way more than half a billion people access information online. From a report: In December 2018, the Indian government proposed changes to its intermediary rules that would require any service that facilitates communication between two or more users and had more than 5 million users in India to set up a local office and have a senior executive in the nation who could be held responsible for any legal issues. The proposal also suggested that any of these services must be able to take down questionable content in within 24 hours and share the user data in within 72 hours of request. Technology giants such as Facebook, Google have so far enjoyed what is known as "safe harbor" laws. The laws, currently applicable in the U.S. under the Communications Decency Act and India through its 2000 Information Technology Act, say that tech platforms won't be held liable for the things their users share on the platform.

Several organizations have shared feedback and expressed concerned about the suggested changes in India's intermediary rules. In an open letter addressed to India's IT Minister Ravi Shankar Prasad on Tuesday, GitHub, Mozilla, and Cloudflare requested the Indian government to be more transparent about the final amendments it has drafted for the upcoming law. The Indian government has said previously that it would submit the final draft of the proposal to the nation's apex Supreme Court by January 15. But one of the concerning issues with the proposal is that nobody -- except for the government officials -- knows what is in the final draft.

Firefox

Firefox 72 Arrives With Fingerprinting Blocked By Default, Picture-in-Picture on macOS and Linux (venturebeat.com) 49

Mozilla today launched Firefox 72 for Windows, Mac, Linux, and Android. Firefox 72 includes fingerprinting scripts blocked by default, less annoying notifications, and Picture-in-Picture video on macOS and Linux. There isn't too much else here, as Mozilla has now transitioned Firefox releases to a four-week cadence (from six to eight weeks).
Security

Self-Sovereign ID Tech Is Being Advanced By Security Failures, Privacy Breaches (computerworld.com) 27

Lucas123 writes: There is a growing movement among fintech companies, banks, healthcare services, universities and others toward disintermediating the control of online user identities in favor of supporting end-user controlled decentralized digital wallets based on P2P blockchain. Self-sovereign identity (SSI) is a term used to describe the digital movement that recognizes an individual should own and control their identity without intervening administrative authorities. The wallets would carry encryption keys provided by third parties and could be used to digitally sign transactions or provide access to verifying information, everything from bank-issued credit lines to diplomas -- all of which are controlled by the user through public key infrastructure (PKI). The blockchain ledger and PKI technology is hidden behind user-friendly mobile applications. Currently, there are more proof-of-concept projects than production systems involving a small number of organizations. The pilots, being trialed in government, financial services, insurance, healthcare, energy and manufacturing, don't yet amount to an entire ecosystem, but they will grow over the next few years, according to Gartner.
United Kingdom

The UK Health System Tries Spending Millions To Reduce The Time Spent Logging In To Things (theguardian.com) 118

The UK's National Health System is getting £40m (about $52.3 million) to try reducing login times on its IT systems, "a move the government says could free up thousands of staffing hours a day as the saved seconds add up," according to the Guardian.

They note estimates that switching to a "single sign-on" system reduced login times from 105 seconds to just 10 at one hospital, ultimately saving them 130 staffing hours a day.

TheNinjaCoder shared their report: In a typical hospital, staff need to log in to as many as 15 systems when tending to a patient. As well as taking up time, the proliferation of logins requires staff either to remember multiple complex passwords or, more likely, compromise security by reusing the same one on every system. The health secretary, Matt Hancock, said: "It is frankly ridiculous how much time our doctors and nurses waste logging on to multiple systems. As I visit hospitals and GP practices around the country, I've lost count of the amount of times staff complain about this. It's no good in the 21st century having 20th-century technology at work.

"This investment is committed to driving forward the most basic frontline technology upgrades, so treatment can be delivered more effectively and we can keep pace with the growing demand on the NHS."

Security

Starbucks Devs Leave API Key in GitHub Public Repo (bleepingcomputer.com) 26

"One misstep from developers at Starbucks left exposed an API key that could be used by an attacker to access internal systems and manipulate the list of authorized users," reports Bleeping Computer: Vulnerability hunter Vinoth Kumar reported the oversight on October 17 and close to three weeks later Starbucks responded it demonstrated "significant information disclosure" and that it qualified for a bug bounty... Along with identifying the GitHub repository and specifying the file hosting the API key, Kumar also provided proof-of-concept (PoC) code demonstrating what an attacker could do with the key. Apart from listing systems and users, adversaries could also take control of the Amazon Web Services (AWS) account, execute commands on systems, and add or remove users with access to the internal systems.

Once Starbucks was content with the remediation steps taken, the company paid Kumar a $4,000 bounty for the disclosure, which is the maximum reward for critical vulnerabilities. Most bounties from Starbucks are between $250-$375. The company solved 834 reports since launching the bug bounty program in 2016, and 369 of them were reported in the past three months. For them, Starbucks spent $40,000.

Crime

'Police Tracked a Terror Suspect on WhatsApp -- Until His Phone Went Dark After a Warning From Facebook' (morningstar.com) 113

"A team of European law-enforcement officials was hot on the trail of a potential terror plot in October, fearing an attack during Christmas season, when their keyhole into a suspect's phone went dark," reports the Wall Street Journal: WhatsApp, Facebook Inc.'s popular messaging tool, had just notified about 1,400 users -- among them the suspected terrorist -- that their phones had been hacked by an "advanced cyber actor."

An elite surveillance team was using spyware from NSO Group, an Israeli company, to track the suspect, according to a law-enforcement official overseeing the investigation. A judge in the Western European country had authorized investigators to deploy all means available to get into the suspect's phone, for which the team used its government's existing contract with NSO. The country's use of NSO's spyware wasn't known to Facebook... WhatsApp's Oct. 29 message to users warned journalists, activists and government officials that their phones had been compromised, Facebook said. But it also had the unintended consequence of potentially jeopardizing multiple national-security investigations in Western Europe about which Facebook hadn't been alerted -- and about which government agencies can't formally complain, given their secret nature...

NSO has faced criticism for selling its products to government agencies in the Middle East, Mexico and India, which Facebook and human-rights research group Citizen Lab, among others, allege used them to spy on dissidents, religious leaders, journalists and political opponents. Among the 1,400 WhatsApp users notified in October, more than 100 fell into these categories, Citizen Lab said. The group, which is based at the University of Toronto's Munk School of Global Affairs and Public Policy, worked with Facebook on identifying these people... Citizen Lab has issued reports for several years linking NSO's spyware to governments with a history of human-rights abuses, and said that record should put NSO out of the running for government contracts from Western agencies, said Ronald Deibert, Citizen Lab's director. "What we have been trying to do with our research is to raise alarm bells...."

On the day WhatsApp sent its alert, the official overseeing the terror investigation in Western Europe said, he was stuck in traffic on his way to work when a call came in from Israel. "Have you seen the news? We've got a problem," he said he was told. WhatsApp was notifying suspects whom his team was tracking that their phones had been hacked. "No, that can't be right. Why would they do that?" the official said he asked his contact, thinking it a joke. The most immediate concern was a suspected terrorist investigators linked to Islamic State. They had received a tip he was part of a group plotting an attack around Christmas. Once they saw the suspect's phone receive WhatsApp's alert, the phone went dark, the official said. The sleuths soon lost access to the suspect's messages, the official said, indicating he had discarded or disabled the phone. "We only had that one phone," the official said.

Though that suspect was still under traditional surveillance, "He's not the only suspect we have to follow..." the official complained to the Wall Street Journal, adding that their counterparts in other Western European countries told him more than 10 other investigations "may have been" compromised by WhatsApp's alert.

The Journal also notes that tech companies "have come under growing pressure in the U.S. and Europe to give law enforcement a back door into encrypted messages. But they are also under fire for not doing enough to protect the privacy of their users and, in some jurisdictions, they have legal obligations to disclose security breaches."
The Military

Will Iran Launch a Cyberattack Against the U.S.? (msn.com) 174

"Iranian officials are likely considering a cyber-attack against the U.S. in the wake of an airstrike that killed one of its top military officials," reports Bloomberg: In a tweet after the airstrike on Thursday, Christopher Krebs, director of the U.S. Cybersecurity and Infrastructure Security Agency, repeated a warning from the summer about Iranian malicious cyber-attacks, and urged the public to brush up on Iranian tactics and to pay attention to critical systems, particularly industrial control infrastructure... John Hultquist, director of intelligence analysis at the cybersecurity firm FireEye Inc., said Iran has largely resisted carrying out attacks in the U.S. so far. But "given the gravity of this event, we are concerned any restraint they may have demonstrated could be replaced by a resolve to strike closer to home."

Iranian cyber-attacks have included U.S. universities and companies, operators of industrial control systems and banks. Iranian hackers tried to infiltrate the Trump campaign, and they have launched attacks against current and former U.S. government officials and journalists. The U.S., meanwhile, has employed cyberweapons to attack Iran's nuclear capabilities and computer systems used to plot attacks against oil tankers, according to the New York Times....

James Lewis, senior vice president at the Center for Strategic & International Studies, said Iranian retaliation may include the use of force, but the government is also likely asking hackers for a list of options. "Cyber-attacks may be tempting if they can find the right American target," Lewis said. "The Iranians are pretty capable and our defenses are uneven, so they could successfully attack poorly defensed targets in the U.S. There are thousands, but they would want something dramatic."

Mother Jones shares another perspective: There's little reason to think that Iran could pull off a truly spectacular attack, such as disabling major electric grids or other big utilities, said Robert M. Lee, an expert in industrial control systems security and the CEO of Dragos. "People should not be worried about large scale attacks and impacts that they can largely think about in movies and books like an electric grid going down." Instead, Iran might choose targets that are less prominent and less secure.

"The average citizen should not be concerned," he said, "but security teams at [U.S.] companies should be on a heightened sense of awareness."

Security

Google Disables All Xiaomi Device Integrations Pending Security Review (google.com) 17

New submitter jasonbuechler writes: Related to the Xiaomi post the other day, Google has entirely disabled Google Assistant/Home integration with Xiaomi devices pending further testing. Google issued the following statement:

Hi everyone,

Late night on January 1st, we were made aware of an issue where a Reddit user posted that their Nest Hub was able to access other people's Xiaomi camera feeds. We've been working with Xiaomi and we're comfortable that the issue was limited to their camera technology platform. While we worked on this issue with Xiaomi, we made the decision to disable all Xiaomi integrations on our devices. We understand this had a significant impact on users of Xiaomi devices but the security and privacy of our users is our priority and we felt this was the appropriate action.

We're re-enabling Xiaomi device integrations for everything but camera streaming after necessary testing has been completed. We will not reinstate camera functionality for Xiaomi devices until we are confident that the issue has been fully resolved. We'll keep you updated with information as more becomes available to share.
UPDATE: Speaking to Engadget, Xiaomi says that the issue occurred due to a cache update, which made the stills pop up if a user had that camera and that display under poor network conditions. According to the company, only 1,044 users had this setup with a "few" experiencing the poor network connection that would make it appear, and they have fixed the issue on their end. The full statement is available on Engadget's report.
Math

Why Some Rope Knots Hold Better Than Others (scitechdaily.com) 45

A reader shares a report from SciTechDaily: MIT mathematicians and engineers have developed a mathematical model that predicts how stable a knot is, based on several key properties, including the number of crossings involved and the direction in which the rope segments twist as the knot is pulled tight. "These subtle differences between knots critically determine whether a knot is strong or not," says Jorn Dunkel, associate professor of mathematics at MIT. "With this model, you should be able to look at two knots that are almost identical, and be able to say which is the better one." "Empirical knowledge refined over centuries has crystallized out what the best knots are," adds Mathias Kolle, the Rockwell International Career Development Associate Professor at MIT. "And now the model shows why."
[...]
In comparing the diagrams of knots of various strengths, the researchers were able to identify general "counting rules," or characteristics that determine a knot's stability. Basically, a knot is stronger if it has more strand crossings, as well as more "twist fluctuations" -- changes in the direction of rotation from one strand segment to another. For instance, if a fiber segment is rotated to the left at one crossing and rotated to the right at a neighboring crossing as a knot is pulled tight, this creates a twist fluctuation and thus opposing friction, which adds stability to a knot. If, however, the segment is rotated in the same direction at two neighboring crossing, there is no twist fluctuation, and the strand is more likely to rotate and slip, producing a weaker knot. They also found that a knot can be made stronger if it has more "circulations," which they define as a region in a knot where two parallel strands loop against each other in opposite directions, like a circular flow.

By taking into account these simple counting rules, the team was able to explain why a reef knot, for instance, is stronger than a granny knot. While the two are almost identical, the reef knot has a higher number of twist fluctuations, making it a more stable configuration. Likewise, the zeppelin knot, because of its slightly higher circulations and twist fluctuations, is stronger, though possibly harder to untie, than the Alpine butterfly -- a knot that is commonly used in climbing.
The findings have been published in the journal Science.
Security

Company Shuts Down Because of Ransomware, Leaves 300 Without Jobs Just Before Holidays (zdnet.com) 135

An Arkansas-based telemarketing firm sent home more than 300 employees and told them to find new jobs after IT recovery efforts didn't go according to plan following a ransomware incident that took place at the start of October 2019. From a report: Employees of Sherwood-based telemarketing firm The Heritage Company were notified of the decision just days before Christmas, via a letter sent by the company's CEO. Speaking with local media, employees said they had no idea the company had even suffered a ransomware attack, and the layoffs were unexpected, catching many off guard. "Unfortunately, approximately two months ago our Heritage servers were attacked by malicious software that basically 'held us hostage for ransom' and we were forced to pay the crooks to get the 'key' just to get our systems back up and running," wrote Sandra Franecke, the company's CEO, in the letter sent to employees. She goes on to say that data recovery efforts, initially estimated at one week, have not gone according to plan and the company had failed to recover full service by Christmas. Franecke said the company lost "hundreds of thousands of dollars" because of the incident and have been forced to "restructure different areas in the company." As a result of the botched ransomware recovery process, the company's leadership decided to suspend all services, leaving more than 300 employees without jobs.
Chrome

Chrome To Show Error Codes, Similar To Windows BSOD Screens (zdnet.com) 35

Google Chrome will get support for error codes, similar to the ones seen on Windows blue screen of death (BSOD) crash pages. From a report: The idea is to provide Chrome users with a code they can search online and find debugging help for various types of crashes. Work on this new feature started in November last year, and the error codes are already under testing in current Chrome Canary (v81) releases. The error codes will appear on the so-called "sad tab" page, also known as the "Aw, Snap!" page, which Chrome displays when a tab crashes.
IT

New USB Cable Kills Your Linux Laptop if Stolen in a Public Place (zdnet.com) 151

A software engineer has designed a so-called USB "kill cable" that works as a dead man's switch to shut down or wipe a Linux laptop when the device is stolen off your table or from your lap in public spaces like parks, malls, and internet cafes. From a report: The cable, named BusKill, was designed by Michael Altfield, a software engineer and Linux sysadmin from Orlando, Florida. The idea is to connect the BusKill cable to your Linux laptop on one end, and to your belt, on the other end. When someone yanks your laptop from your lap or table, the USB cable disconnects from the laptop and triggers a udev script that executes a series of preset operations.
Security

Xiaomi Camera Feed is Showing Random Homes on a Google Nest Hub, Including Still Images of Sleeping People (androidpolice.com) 82

An anonymous reader shares a report: So-called "smart" security cameras have had some pretty dumb security problems recently, but a recent report regarding a Xiaomi Mijia camera linked to a Google Home is especially disturbing. One Xiaomi Mijia camera owner is getting still images from other random peoples' homes when trying to stream content from his camera to a Google Nest Hub. The images include sills of people sleeping (even an infant in a cradle) inside their own homes. This issue was first reported by user /r/Dio-V on Reddit and affects his Xiaomi Mijia 1080p Smart IP Security Camera, which can be linked to a Google account for use with Google/Nest devices through Xiaomi's Mi Home app/service. It isn't clear when Dio-V's feed first began showing these still images into random homes or how long the camera was connected to his account before this started happening. He does state that both the Nest Hub and the camera were purchased new. The camera was noted as running firmware version 3.5.1_00.66.
Chrome

Chrome Extension Caught Stealing Crypto-Wallet Private Keys (zdnet.com) 28

A Google Chrome extension was caught injecting JavaScript code on web pages to steal passwords and private keys from cryptocurrency wallets and cryptocurrency portals. From a report: The extension is named Shitcoin Wallet (Chrome extension ID: ckkgmccefffnbbalkmbbgebbojjogffn), and was launched last month, on December 9. According to an introductory blog post, Shitcoin Wallet lets users manage Ether (ETH) coins, but also Ethereum ERC20-based tokens -- tokens usually issued for ICOs (initial coin offerings). Users can install the Chrome extension and manage ETH coins and ERC20 tokens from within their browser, or they can install a Windows desktop app, if they want to manage their funds from outside a browser's riskier environment. However, the wallet app wasn't what it promised to be. Yesterday, Harry Denley, Director of Security at the MyCrypto platform, discovered that the extension contained malicious code. According to Denley, the extension is dangerous to users in two ways. First, any funds (ETH coins and ERC0-based tokens) managed directly inside the extension are at risk.
China

Major US Companies Breached, Robbed, and Spied on by Chinese Hackers (foxbusiness.com) 118

Rob Barry and Dustin Volz, reporting for Wall Street Journal: The hackers seemed to be everywhere. In one of the largest-ever corporate espionage efforts, cyberattackers alleged to be working for China's intelligence services stole volumes of intellectual property, security clearance details and other records from scores of companies over the past several years. They got access to systems with prospecting secrets for mining company Rio Tinto, and sensitive medical research for electronics and health-care giant Philips NV. They came in through cloud service providers, where companies thought their data was safely stored. Once they got in, they could freely and anonymously hop from client to client, and defied investigators' attempts to kick them out for years. Cybersecurity investigators first identified aspects of the hack, called Cloud Hopper by the security researchers who first uncovered it, in 2016, and U.S. prosecutors charged two Chinese nationals for the global operation last December. The two men remain at large.

A Wall Street Journal investigation has found that the attack was much bigger than previously known. It goes far beyond the 14 unnamed companies listed in the indictment, stretching across at least a dozen cloud providers, including CGI Group, one of Canada's largest cloud companies; Tieto Oyj, a major Finnish IT services company; and International Business Machines. The Journal pieced together the hack and the sweeping counteroffensive by security firms and Western governments through interviews with more than a dozen people involved in the investigation, hundreds of pages of internal company and investigative documents, and technical data related to the intrusions. The Journal found that Hewlett Packard Enterprise was so overrun that the cloud company didn't see the hackers re-enter their clients' networks, even as the company gave customers the all-clear.

Encryption

ProtonMail Takes Aim at Google With an Encrypted Calendar (venturebeat.com) 33

Encrypted email provider ProtonMail has officially launched its new calendar in public beta. The move is part of the Swiss company's broader push to offer privacy-focused alternatives to Google's key products. From a report: ProtonMail has been talking about its plans to launch an encrypted calendar for a while. But starting from today, all ProtonMail users on a paid plan will be able to access ProtonCalendar, and it will be opened to everyone when it exits beta in 2020. "Our goal is to create and make widely accessible online products [that] serve users instead of exploiting them," said ProtonMail CEO Andy Yen. ProtonMail hasn't set out to reinvent the wheel in terms of the features and format of ProtonCalendar. It sports a clean interface with views by month and day, color-coded event types, and so on. It is also tied to a user's ProtonMail email account.
Microsoft

Microsoft Takes Down 50 Domains Operated by North Korean Hackers (zdnet.com) 45

Microsoft announced today that it successfully took down 50 web domains previously used by a North Korean government-backed hacking group. From a report: The OS maker said the 50 domains were used to launch cyberattacks by a group the company has been tracking as Thallium (also known as APT37). Microsoft said the Digital Crimes Unit (DCU) and the Microsoft Threat Intelligence Center (MSTIC) teams have been monitoring Thallium for months, tracking the group's activities, and mapping its infrastructure. On December 18, the Redmond-based company filed a lawsuit against Thallium in a Virginia court. Shortly after Christmas, US authorities granted Microsoft a court order, allowing the tech company to take over 50 domains that the North Korean hackers have been using as part of their attacks. The domains were used to send phishing emails and host phishing pages.
Security

Security Camera Startup Wyze Leaked Data on Millions of Customers (cnet.com) 36

An anonymous reader quotes CNET: Security camera startup Wyze has confirmed it suffered a data leak earlier this month that left the personal information for millions of its customers exposed on the internet. No passwords or financial information was exposed, but email addresses, Wi-Fi network IDs and body metrics for 2.4 million customers were left unprotected from Dec. 4 through Dec. 26, the company said Friday.

The data was accidentally left exposed when it was transferred to a new database to make the data easier to query, but a company employee failed to maintain previous security protocols during the process, Wyze co-founder Dongsheng Song wrote in a forum post. "We are still looking into this event to figure out why and how this happened," he wrote...

Among the data exposed in the Wyze leak was the height, weight, gender and other health information for about 140 beta users participating in testing of new hardware, Wyze said.

Privacy

CNET Releases '2019 Data Breach Hall of Shame' Dishonoring This Year's Biggest Data Breaches (cnet.com) 19

schwit1 quotes CNET's report on their newly-released "2019 Data Breach Hall of Shame." The biggest recurrent motif among the major data breaches of 2019 wasn't the black-hooded hacker in a dark room, digging into a screen full of green text. It was a faceless set of executives and security professionals under the fluorescent lights of an office somewhere, frantically dialing their attorneys and drafting public relations apologies after leaving the front doors of their servers unlocked in public.

The words "unsecured database" seemed to run on repeat through security journalism in 2019. Every month, another company was asking its customers to change their passwords and report any damage. Cloud-based storage companies like Amazon Web Services and ElasticSearch repeatedly saw their names surface in stories of negligent companies -- in the fields of health care, hospitality, government and elsewhere -- which left sensitive customer data unprotected in the open wilds of the internet, to be bought and sold by hackers who barely had to lift a finger to find it.

And it's not just manic media coverage. The total number of breaches was up 33% over last year, according to research from Risk Based Security, with medical services, retailers and public entities most affected. That's a whopping 5,183 data breaches for a total of 7.9 billion exposed records.

In November, the research firm called 2019 the "worst year on record" for breaches.

Slashdot Top Deals