Facebook

NSO Employees Take Legal Action Against Facebook For Banning Their Accounts (vice.com) 53

On Tuesday, lawyers representing current and former employees of Israeli surveillance contractor NSO Group took legal action against Facebook to try and get their accounts reinstated after being banned by the social media giant. Motherboard reports: Last month, Facebook itself sued NSO in California for leveraging a vulnerability in the WhatsApp chat program that NSO Group clients used to hack targets. As part of that, Facebook also banned the personal Facebook and Instagram accounts of multiple current and former NSO employees. The new lawsuit argues that Facebook violated its own terms of service by blocking the NSO employees, and it used personal information they shared with Facebook in order to identify them, in violation of an Israeli privacy law. As relief, the lawyers ask the court to make Facebook lift the ban on the accounts. The lawsuit was first reported in Israeli media.

"It appears that Facebook used the [NSO employees'] personal data...in order to identify them as NSO employees (or former employees), in service of imposing 'collective punishment' on them, in the form of blocking their personal accounts," the lawsuit reads in Hebrew. The lawsuit argues that the personal data used to identify them as NSO employees belonged to the individuals, and not Facebook. The legal action says that the NSO employees were banned without warning even though they are "private people, who make private use of the social networks, whose only 'sin' was any association with NSO, as employees or former employees." The lawsuit includes a screenshot of an email Facebook allegedly sent to someone who had their account suspended.
Facebook told Motherboard in a statement on Tuesday, "In October we filed a legal complaint which attributed a sophisticated cyber attack to the NSO Group and its employees that was directed at WhatsApp and its users in violation of our terms of service and U.S. law. Such actions warranted disabling relevant accounts and continue to be necessary for security reasons, including preventing additional attacks."
Security

Amazon's Ring Planned Neighborhood 'Watch Lists' Built On Facial Recognition (theintercept.com) 68

An anonymous reader quotes a report from The Intercept: Ring, Amazon's crimefighting surveillance camera division, has crafted plans to use facial recognition software and its ever-expanding network of home security cameras to create AI-enabled neighborhood "watch lists," according to internal documents reviewed by The Intercept. The planning materials envision a seamless system whereby a Ring owner would be automatically alerted when an individual deemed "suspicious" was captured in their camera's frame, something described as a "suspicious activity prompt."

It's unclear who would have access to these neighborhood watch lists, if implemented, or how exactly they would be compiled, but the documents refer repeatedly to law enforcement, and Ring has forged partnerships with police departments throughout the U.S., raising the possibility that the lists could be used to aid local authorities. The documents indicate that the lists would be available in Ring's Neighbors app, through which Ring camera owners discuss potential porch and garage security threats with others nearby. [...] Mohammad Tajsar, an attorney with the American Civil Liberties Union of Southern California, expressed concern over Ring's willingness to plan the use of facial recognition watch lists, fearing that "giving police departments and consumers access to 'watch listing' capabilities on Ring devices encourages the creation of a digital redline in local neighborhoods, where cops in tandem with skeptical homeowners let machines create lists of undesirables unworthy of entrance into well-to-do areas."
When reached for comment, Ring spokesperson Yassi Shahmiri said that "the features described are not in development or in use and Ring does not use facial recognition technology."

Amazon also told Massachusetts Sen. Edward Markey earlier this month that facial recognition has been a "contemplated but unreleased feature" for Ring, but would only be added with "thoughtful design including privacy, security and user control."
Security

Some Fortinet Products Shipped With Hardcoded Encryption Keys (zdnet.com) 21

Fortinet, a vendor of cyber-security products, took between 10 and 18 months to remove a hardcoded encryption key from three products that were exposing customer data to passive interception. From a report: The hardcoded encryption key was found inside the FortiOS for FortiGate firewalls and the FortiClient endpoint protection software (antivirus) for Mac and Windows. These three products used a weak encryption cipher (XOR) and hardcoded cryptographic keys to communicate with various FortiGate cloud services. The hardcoded keys were used to encrypt user traffic for the FortiGuard Web Filter feature, FortiGuard AntiSpam feature, and FortiGuard AntiVirus feature. A threat actor in a position to observe a user or a company's traffic would have been able to take the hardcoded encryption keys and decrypt this weakly encrypted data stream.
Data Storage

Some HPE SSDs Fail After 3 Years and 9 Months, Company Warns (hpe.com) 113

New submitter AllHail writes: HPE SAS solid state drives are affected by a firmware problem which causes these drives to stop working after 32768 power-on hours (3 years and 9 months). If these drives are not flashed with updated firmware before the failure, the drives and the data on them become unrecoverable at that time. If several of these drives are installed and operated together in a RAID, they are going to fail almost simultaneously. Patch or assume the risk of failure, says Hewlett Packard Enterprise.
Social Networks

Facebook and Twitter Users' Data Exposed Due To Third-Party SDK Bug (thurrott.com) 10

Facebook and Twitter announced on Monday that the companies were notified about malicious software development kits (SDKs) that allowed certain apps to collect users' data from the apps without their permission. Paul Thurrott reports: The main culprits here are One Audience and Mobiburn, developers of the malicious SDKs that apparently paid developers to use the SDKs and secretly collect users data. Twitter noted that the issue isn't due to a vulnerability in its software. The breach was caused by "the lack of isolation between SDKs within an application," according to the company. The company also said that the malicious SDKs could allow apps to access personal information like your email, username, and your last tweet without your permission. "We have evidence that this SDK was used to access people's personal data for at least some Twitter account holders using Android, however, we have no evidence that the iOS version of this malicious SDK targeted people who use Twitter for iOS," the company said. The two social networks said that they will notify the affected users about the breach.
United States

US Tech Sector Skews Younger Than the Workforce As a Whole, Study Finds (wsj.com) 118

An anonymous reader quotes a report from The Wall Street Journal: Older information-technology professionals are being passed over by employers, even as IT job openings soar to record highs and employers say recruiting tech talent is a challenge. The IT workforce in the U.S. skews young: Workers aged 22 to 44 account for 61% of the IT sector, but only 49% of the workforce across all occupations, according to 2019 data compiled by IT trade group CompTIA. On the other side, workers aged 45 and older represent 38% of all IT employees at U.S. companies, while the comparable figure for all occupations is 44%, CompTIA said. The largest gap occurs among workers ages 35 to 44. They make up 29% of the IT workforce, but just 21% of the overall national workforce, said Tim Herbert, CompTIA's senior vice president for research and market intelligence. One problem is that some older IT workers who get too comfortable with their skills risk falling behind, says Michael Solomon, an advisory firm for senior technology job seekers. Another issue is cost.

"By the time many tech workers are in their 50s and 60s, they often have top-level compensation packages," the report says. "The age imbalance between IT and the overall U.S. workforce began roughly a decade ago and has grown over the years, researchers have found."
Operating Systems

Zorin OS 15 Lite Linux Distro Can Rejuvenate Your Aging Windows PC (betanews.com) 69

An anonymous reader writes: Called "Zorin OS 15 Lite," it is not only lightweight, but thanks to the Xfce desktop environment and integrated Flatpak support, it should be quite familiar to those switching from Windows. In fact, the developers are intentionally targeting existing Windows 7 users, as Microsoft's operating system will be unsupported beginning January 2020. Zorin OS 15 Lite, in comparison, is based on Ubuntu 18.04 LTS and supported until 2023! It even comes with the very modern Linux kernel 5.0. "With Zorin OS 15 Lite, we've condensed the full Zorin OS experience into a streamlined operating system, designed to run fast on computers as old as 15 years. With version 15, we've gone the extra mile to make the XFCE 4.14-based desktop feel familiar and user-friendly to new users, especially those moving away from Windows 7 leading up to the end of its support in January 2020. By pairing the most advanced and efficient software with a user-friendly experience, we've made it possible for anyone to extend the lifespan of their computers for years to come," explains the Zorin OS developers.
Chrome

Chrome, Microsoft Edge and Safari Cracked In China's White-Hat Hacker Competition (ibtimes.com) 17

An anonymous reader quotes the International Business Times: At the recent Tianfu cup held in Chengdu, China, Chinese China's top white-hat hackers have converged to test zero-days against top software available in the market today. During the first day of the event, Chinese security researchers were able to break into major browsers such as Safari, Microsoft Edge, and Google Chrome.

Since March 2018, the Chinese government has officially discouraged security researchers from joining hacking competitions outside the county. The recent Tianfu Cup is the venue for hackers to showcase their skills and even earn six-figure bounties for successful exploits. Former Pwn2Own winner Team 360 Vulcan took home $382,500 for successfully hacking the old version of Office 365, Microsoft Edge, Adobe PDF Reader, VMWare Workstation, and gemu+ Ubuntu during the two days event, reports ZDNet... Search engine giant Google has a representative in the event with some members of the Google Chrome security team present on site. Organizers plan to submit a report of all bugs uncovered during the event to all vendors when the competition concludes, says ZDNet.

Programming

What Tech Skills Do Employers Want? SQL, Java, Python, and AWS (ieee.org) 121

"What tech skills do U.S. employers want? Researchers at job search site Indeed took a deep dive into its database to answer that question," reports IEEE Spectrum: [A]t least for now, expertise in SQL came out on top of the list of most highly sought after skills, followed by Java. Python and Amazon Web Services (AWS) are coming on fast, and, should trends continue, may take over the lead in the next year or two...

Indeed's team considered U.S. English-language jobs posted on the site between September 2014 and September 2019; those postings encompassed 571 tech skills. Over that period, Docker, the enterprise container platform, sits at number 20 on the list today, but that is the result of a dramatic climb over that five-year period. Demand for proficiency in that platform-as-a-service grew more than 4000 percent, from a barely registering share of 0.1 percent of job post mentions in 2014 to 5.1 percent today. Azure jumped more than 1000 percent during that period, from 0.6 percent to 6.9 percent; and the general category of machine learning climbed 439 percent, closely followed by AWS at 418 percent.

Indeed's researchers note that the big jumps in demand for engineers skilled in Python stems from the boom in data scientist and engineer jobs, which disproportionately use Python.

"Python" has overtaken "Linux" in just the last two years, while in the same period "AWS" overtook C++, C, C# and .net.
Microsoft

Slack's Response to New Microsoft Teams Ad? 'Ok Boomer' (msn.com) 260

An anonymous reader quotes Business Insider: Slack tweeted a video on Thursday comparing a Slack ad and a Microsoft ad, showing the similarities between them and implying the Microsoft ad copied Slack's concept. The video was captioned "ok boomer," a phrase that has turned into a meme for millennials and Gen Z to voice their gripes with the baby boomer generation... Slack is leaning into its status as the young, hip startup by calling out its older, more established competition: Microsoft...

On Tuesday, Microsoft announced that Teams hit 20 million daily users, while Slack most recently announced just 12 million users. Slack's stock took a dive after the announcement. Although it has fewer users, Slack points to its user engagement, saying that users enjoy using the app. Slack CEO Stewart Butterfield said that Microsoft sees the company as an "existential threat."

The Verge notes that "a lot of businesses will opt for Teams simply because it's bundled as part of Office 365."

And ZDNet reports that a partner at one of Slack's early investors even tweeted an image showing Google Trends' top five rising queries for Microsoft Teams. #1 is "how to stop Microsoft teams," and also include "how to turn off Microsoft teams," "how to get rid of Microsoft teams", and "Microsoft teams keeps reinstalling."
Security

New Linux/Windows Malware Allows Arbitrary Execution of Shell Commands (bleepingcomputer.com) 80

"Researchers have discovered a new multi-platform backdoor that infects Windows and Linux systems allowing the attackers to run malicious code and binaries on the compromised machines," reports Bleeping Computer: The malware dubbed ACBackdoor is developed by a threat group with experience in developing malicious tools for the Linux platform based on the higher complexity of the Linux variant as Intezer security researcher Ignacio Sanmillan found. "ACBackdoor provides arbitrary execution of shell commands, arbitrary binary execution, persistence, and update capabilities," the Intezer researcher found.

Both variants share the same command and control (C2) server but the infection vectors they use to infect their victims are different: the Windows version is being pushed through malvertising with the help of the Fallout Exploit Kit while the Linux payload is dropped via a yet unknown delivery system... Besides infecting victims via an unknown vector, the Linux malicious binary is detected by only one of the anti-malware scanning engines on VirusTotal at the time this article was published, while the Windows one is detected by 37 out of 70 engines. The Linux binary is also more complex and has extra malicious capabilities, although it shares a similar control flow and logic with the Windows version...

ACBackdoor can receive the info, run, execute, and update commands from the C2 server, allowing its operators to run shell commands, to execute a binary, and to update the malware on the infected system.

The article warns that the Linux version will disguise itself as the Ubuntu UpdateNotifier utility, renaming its process as the Linux kernel thread [kworker/u8:7-ev].
Security

OnePlus Notifies Customers of Data Breach Impacting Users of Its Online Store 7

OnePlus has sent out an email informing recent OnePlus customers of a security issue. "This 'Security Notification' from OnePlus informs customers that an 'unauthorized party' was able to access order information from the company's online store," reports 9to5Google. "OnePlus says that payment information as well as account details were not accessed, but names, addresses, emails, and phone numbers 'may' have been exposed. The company says it will continue to investigate the matter, but obviously this is no small issue." From the report: Speaking to Droid-Life, OnePlus says that they took "immediate steps to stop the intruder and reinforce security," and that they are currently "working with the relevant authorities to further investigate this incident." OnePlus didn't explain what went wrong, but they are apparently working to start a bug bounty program by the end of this year.

This isn't the first time the company's store has fallen victim to a security issue like this. In early 2018, OnePlus customers found evidence of credit card fraud stemming from the Store that triggered OnePlus to shut down credit card payments temporarily. Just a day later, OnePlus' investigation into the matter revealed that 40,000 credit card numbers had been exposed.
OnePlus has a thread on its forums with more details about the breach.
Privacy

1.2 Billion Records Found Exposed Online in a Single Server (wired.com) 17

JustAnotherOldGuy writes: For well over a decade, identity thieves, phishers, and other online scammers have created a black market of stolen and aggregated consumer data that they used to break into people's accounts, steal their money, or impersonate them. In October, dark web researcher Vinny Troia found one such trove sitting exposed and easily accessible on an unsecured server, comprising 4 terabytes of personal information -- about 1.2 billion records in all. While the collection is impressive for its sheer volume, the data doesn't include sensitive information like passwords, credit card numbers, or Social Security numbers. It does, though, contain profiles of hundreds of millions of people that include home and cell phone numbers, associated social media profiles like Facebook, Twitter, LinkedIn, and Github, work histories seemingly scraped from LinkedIn, almost 50 million unique phone numbers, and 622 million unique email addresses. "It's bad that someone had this whole thing wide open," Troia says. "This is the first time I've seen all these social media profiles collected and merged with user profile information into a single database on this scale. From the perspective of an attacker, if the goal is to impersonate people or hijack their accounts, you have names, phone numbers, and associated account URLs. That's a lot of information in one place to get you started."
China

Microsoft Gets Export License To Sell To Huawei 14

hackingbear writes: Microsoft has been granted a license to export [mass market] software to Huawei once again. The software giant was caught up in a long line of US-based technology companies that have been forced to comply with President Trump's executive order to crack down on Chinese tech companies. It's not immediately clear what "mass-market" refers to, but Microsoft sells Windows and Office licenses to Huawei. It's likely that Microsoft is at least able to sell Windows licenses to Huawei once again, which will help with Huawei's server solutions and its Windows-powered laptops. Microsoft is part of a number of US companies that are starting to get licenses to supply goods to Huawei once again. Huawei has been anticipating a fight with the US and prepared and succeed in replacing American (electronic) technologies with its own home-grown replacement for almost two decades after Motorola foolishly rejected the chance of acquiring Huawei, China's most successful hi-tech company worth at least $100 billion today, over a bargaining price of $7.5 billion. "When this decision was made, I told them [Huawei executives], if we continued to work in this sector, we would definitely be in a race against the US in 10 years. We had to prepare", said then Huawei founder Ren Zhengfei after the merger fell through. However, software ecosystems, i.e. Windows and Android, remain Huawei's Achilles' heel.
Security

Twitter Will Finally Let Users Disable SMS as Default 2FA Method (zdnet.com) 9

Twitter says users will finally be able to disable SMS-based two-factor authentication (2FA) for their accounts, and use an alternative method only, such as a mobile one-time code (OTP) authenticator app or a hardware security key. Until this week, this was impossible. From a report: If users wanted to use 2FA for their Twitter account, they had to register a phone number and enable the SMS-based 2FA method, even if they wished it or not. Users who wanted to use an OTP mobile authenticator app or a hardware security key, had to enable the SMS-based 2FA first, and they couldn't disable it. Even if the user chose to use a security key, the SMS-based 2FA method was still active, and exposed the account to attacks known as SIM swaps. Hackers who knew a user's password would perform a SIM swap to temporarily hijack a user's phone number, bypass SMS-based 2FA, and then take over that user's account.
The Courts

Pennsylvania Supreme Court Rules Police Can't Force You To Tell Them Your Password (eff.org) 73

An anonymous reader quotes a report from the Electronic Frontier Foundation: The Pennsylvania Supreme Court issued a forceful opinion today holding that the Fifth Amendment to the U.S. Constitution protects individuals from being forced to disclose the passcode to their devices to the police. In a 4-3 decision in Commonwealth v. Davis, the court found that disclosing a password is "testimony" protected by the Fifth Amendment's privilege against self-incrimination. EFF filed an amicus brief in Davis, and we were gratified that the court's opinion closely parallels our arguments. The Fifth Amendment privilege prohibits the government from coercing a confession or forcing a suspect to lead police to incriminating evidence. We argue that unlocking and decrypting a smartphone or computer is the modern equivalent of these forms of self-incrimination.

Crucially, the court held that the narrow "foregone conclusion exception" to the Fifth Amendment does not apply to disclosing passcodes. As described in our brief, this exception applies only when an individual is forced to comply with a subpoena for business records and only when complying with the subpoena does not reveal the "contents of his mind," as the U.S. Supreme Court put it. The Pennsylvania Supreme Court agreed with EFF. It wrote: "Requiring the Commonwealth to do the heavy lifting, indeed, to shoulder the entire load, in building and bringing a criminal case without a defendant's assistance may be inconvenient and even difficult; yet, to apply the foregone conclusion rationale in these circumstances would allow the exception to swallow the constitutional privilege. Nevertheless, this constitutional right is firmly grounded in the "realization that the privilege, while sometimes a shelter to the guilty, is often a protection to the innocent."

Communications

T-Mobile Reveals Data Breach Affecting Prepaid Customers (tmonews.com) 15

T-Mobile says it has suffered a data breach affecting some prepaid customers. No financial data, social security numbers, or passwords were accessed, but information associated with users' prepaid wireless accounts was obtained, including names, billing addresses, phone numbers, account numbers, rate plans, and features that users have added to their accounts. TmoNews reports: T-Mobile is in the process of notifying all customers that've been affected by this data breach. If you got a notification, you should update the PIN on your T-Mobile account. T-Mo does say that it's possible that some affected customers may not be notified because their contact info isn't up-to-date, so if that's the case with you, you can contact T-Mobile support for more info by dialing 611 from your T-Mo phone or 1-800-TMOBILE from any phone. There's no word yet on exactly how many customers were affected by this security issue, but some Reddit users have chimed in to say that they've been alerted to the breach by T-Mobile. "We take the security of your information very seriously and have a number of safeguards in place to protect your personal information from unauthorized access," T-Mobile says. "We truly regret that this incident occurred and apologize for any inconvenience this has caused you."
Google

Google Will Pay Bug Hunters Up To $1.5M if They Can Hack Its Titan M Chip (zdnet.com) 21

Google announced today that it is willing to dish out bug bounty cash rewards of up to $1.5 million if security researchers find and report bugs in the Android operating system that can also compromise its new Titan M security chip. From a report: Launched last year, the Titan M chip is currently part of Google Pixel 3 and Pixel 4 devices. It's a separate chip that's included in both phones and is dedicated solely to processing sensitive data and processes, like Verified Boot, on-device disk encryption, lock screen protections, secure transactions, and more. Google says that if researchers manage to find "a full chain remote code execution exploit with persistence" that also compromises data protected by Titan M, they are willing to pay up to $1 million to the bug hunter who finds it. If the exploit chain works against a preview version of the Android OS, the reward can go up to $1.5 million.
Privacy

Senators Press Amazon For Answers On Ring's Sloppy Security Practices (theintercept.com) 12

New submitter BeerF writes: This past year has been chock full of uncomfortable revelations about Ring, the surveillance social network and home security hardware company acquired by Amazon for a reported $800 million, including reports of potentially disastrous internal security practices, an apparent disregard for user privacy, and wave after wave of detail on secret partnerships with local police. Today, in a letter addressed to Amazon CEO Jeff Bezos, five Democratic senators are asking for an explanation, citing potential threats to U.S. national security.

Much of the letter focuses on allegations that Ring's Ukrainian office, where it conducts much of its research and development operation, allowed employees across the company to access customer video data whether they had any real need to or not. In January, The Intercept reported that this loose security atmosphere at Ring meant "if [someone] knew a reporter or competitor's email address, [they] could view all their cameras," per one source, who also recalled Ring engineers casually spying on and "teasing each other about who they brought home" after dates. "If hackers or foreign agents were to gain access to this data," the letter states, "it would not only threaten the privacy and safety of the impacted Americans; it could also threaten U.S. national security."

Security

Password Data For About 2.2 Million Users of Currency, Gaming Sites Dumped Online (arstechnica.com) 25

Password data and other personal information belonging to as many as 2.2 million users of two websites -- one a cryptocurrency wallet service and the other a gaming bot provider -- have been posted online, according to Troy Hunt, the security researcher behind the Have I Been Pwned breach notification service. Ars Technica reports: One haul includes personal information for as many as 1.4 million accounts from the GateHub cryptocurrency wallet service. The other contains data for about 800,000 accounts on RuneScape bot provider EpicBot. The databases include registered email addresses and passwords that were cryptographically hashed with bcrypt, a function that's among the hardest to crack.

The person posting the 3.72GB Gatehub database said it also includes two-factor authentication keys, mnemonic phrases, and wallet hashes, although GateHub officials said an investigation suggested wallet hashes were not accessed. The EpicBot database, meanwhile, purportedly included usernames and IP addresses. Hunt said he selected a representative sample of accounts from both databases to verify the authenticity of the data. All of the email addresses he checked were registered to accounts of the two sites. [...] While there were 2.2 million unique addresses in the two dumps, it's possible that corresponding password hashes or other data isn't included with each one.

Slashdot Top Deals