Bug

A Code Glitch May Have Caused Errors In More Than 100 Published Studies (vice.com) 20

Scientists have uncovered a glitch in a piece of code that could have yielded incorrect results in over 100 published studies that cited the original paper. From a report: The glitch caused results of a common chemistry computation to vary depending on the operating system used, causing discrepancies among Mac, Windows, and Linux systems. The researchers published the revelation and a debugged version of the script, which amounts to roughly 1,000 lines of code, last week in the journal Organic Letters. "This simple glitch in the original script calls into question the conclusions of a significant number of papers on a wide range of topics in a way that cannot be easily resolved from published information because the operating system is rarely mentioned," the new paper reads. "Authors who used these scripts should certainly double-check their results and any relevant conclusions using the modified scripts in the [supplementary information]." Yuheng Luo, a graduate student at the University of Hawai'i at Manoa, discovered the glitch this summer when he was verifying the results of research conducted by chemistry professor Philip Williams on cyanobacteria. The aim of the project was to "try to find compounds that are effective against cancer," Williams said.
Security

Thoma Bravo To Buy Sophos For $3.9 Billion (zdnet.com) 15

Private equity firm Thoma Bravo said today it plans to buy UK-based cyber-security giant Sophos for $7.40 per share, for a total value of $3.9 billion, both companies announced today. From a report: The sale price represents a 37% premium on the Sophos market trading price, as recorded on Friday, at the end of the trading. The Sophos board of directors said they plan to "unanimously recommend" the acquisition offer to their shareholders. Before today's announcement, Thoma Bravo acquired a minority stake in McAfee last year and was rumored to be interested in buying the whole company. It is unclear how today's Sophos acquisition will impact plans to buy McAfee, but the two companies -- Sophos and McAfee -- are classic rivals on the cyber-security market and share a product portfolio, so the door seems to have closed on the McAfee deal.
Security

Planting Tiny Spy Chips in Hardware Can Cost as Little as $200 (wired.com) 37

An anonymous reader shares a report: More than a year has passed since Bloomberg Businessweek grabbed the lapels of the cybersecurity world with a bombshell claim: that Supermicro motherboards in servers used by major tech firms, including Apple and Amazon, had been stealthily implanted with a chip the size of a rice grain that allowed Chinese hackers to spy deep into those networks. Apple, Amazon, and Supermicro all vehemently denied the report. The NSA dismissed it as a false alarm. The Defcon hacker conference awarded it two Pwnie Awards, for "most overhyped bug" and "most epic fail." And no follow-up reporting has yet affirmed its central premise.

But even as the facts of that story remain unconfirmed, the security community has warned that the possibility of the supply chain attacks it describes is all too real. The NSA, after all, has been doing something like it for years, according to the leaks of whistle-blower Edward Snowden. Now researchers have gone further, showing just how easily and cheaply a tiny, tough-to-detect spy chip could be planted in a company's hardware supply chain. And one of them has demonstrated that it doesn't even require a state-sponsored spy agency to pull it off -- just a motivated hardware hacker with the right access and as little as $200 worth of equipment.

Security

Invisible Hardware Hacks Allowing Full Remote Access Cost Pennies (wired.com) 84

Long-time Slashdot reader Artem S. Tashkinov quotes Wired: More than a year has passed since Bloomberg Businessweek grabbed the lapels of the cybersecurity world with a bombshell claim: that Supermicro motherboards in servers used by major tech firms, including Apple and Amazon, had been stealthily implanted with a chip the size of a rice grain that allowed Chinese hackers to spy deep into those networks. Apple, Amazon, and Supermicro all vehemently denied the report. The NSA dismissed it as a false alarm. The Defcon hacker conference awarded it two Pwnie Awards, for "most overhyped bug" and "most epic fail." And no follow-up reporting has yet affirmed its central premise.

But even as the facts of that story remain unconfirmed, the security community has warned that the possibility of the supply chain attacks it describes is all too real. The NSA, after all, has been doing something like it for years, according to the leaks of whistle-blower Edward Snowden. Now researchers have gone further, showing just how easily and cheaply a tiny, tough-to-detect spy chip could be planted in a company's hardware supply chain. And one of them has demonstrated that it doesn't even require a state-sponsored spy agency to pull it off -- just a motivated hardware hacker with the right access and as little as $200 worth of equipment.

Crime

IRS Programmer Stole Identities, Funded A Two-Year Shopping Spree (qz.com) 91

A computer programmer at America's tax-collecting agency "stole multiple people's identities, and used them to open illicit credit cards to fund vacations and shop for shoes and other goods," write Quartz, citing a complaint unsealed last week in federal court.

An anonymous reader quotes their report: The complaint accuses the 35-year-old federal worker of racking up almost $70,000 in charges over the course of two years, illegally using "the true names, addresses, dates of birth, and Social Security numbers" of at least three people.

The US Treasury Department's Inspector General for Tax Administration, which oversees internal wrongdoing at the Internal Revenue Service (IRS), is investigating the crime, although the complaint doesn't specify how the employee obtained the information. The arrest, however, comes just months after the Government Accountability Office -- the federal government's auditor, essentially -- issued a report raising concerns about the security of taxpayer information held at the IRS. The report said that unaddressed shortcomings left taxpayer data "unnecessarily vulnerable to inappropriate and undetected use, modification, or disclosure," which could allow employees or outsiders to illegally access millions of people's personal information. An IRS call center employee in Atlanta pleaded guilty last year to illegally using taxpayer data to file fraudulent tax returns, ultimately collecting almost $6,000. In 2016, another IRS worker in Atlanta admitted to improperly accessing the personal information of two taxpayers, amassing close to half a million dollars from illicit tax refunds....

The IRS employee's alleged scheme took place between January 2016 and February 2018, according to court filings. Investigators say he used a fraudulently obtained American Express card to fly to Sacramento and Miami Beach. He also used the card for some 37 Uber rides, nine payments on his father's Amazon account totaling $1,200, various purchases at Lowe's, the Designer Shoe Warehouse, BJ's Wholesale Club, and a flooring outlet, as well as a $7,400 payment to a business he owned. The complaint says the employee, who works for the tax agency as a software developer, obtained a second fraudulent credit card, which he used to fly to Montego Bay, Jamaica. A third fraudulent card was used to travel to Iceland.

In a particularly brazen move, investigators say the suspect linked this card to a phony PayPal account he opened using his official IRS email address.

Two of the credit cards were delivered to his home address, while a third was sent to his parents' address, according to the article. "The phone numbers listed on the accounts also belonged to the suspect, and he accessed emails associated with the accounts from his home IP address."
Security

Ransomware Gang's Victim Cracks Their Server and Releases All Their Decryption Keys (zdnet.com) 55

"A user got his revenge on the ransomware gang who encrypted his files by hacking their server and releasing the decryption keys for all victims," writes ZDNet.

ccnafr shared their report: One of the gang's victims was Tobias Frömel, a German software developer. Frömel was one of the victims who paid the ransom demand so he could regain access to his files. However, after paying the ransom, Frömel also analyzed the ransomware, gained insight into how Muhstik operated, and then retrieved the crooks' database from their server. "I know it was not legal from me," the researcher wrote in a text file he published online on Pastebin earlier Monday, containing 2,858 decryption keys. "I'm not the bad guy here," Frömel added.

Besides releasing the decryption keys, the German developer also published a decrypter that all Muhstik victims can use to unlock their files. The decrypter is available on MEGA [VirusTotal scan], and usage instructions are avaiable on the Bleeping Computer forum.

In the meantime, Frömel has been busy notifying Muhstik victims on Twitter about the decrypter's availability, advising users against paying the ransom.

Media

Laser Cutters Sold On Amazon and Elsewhere Are Cheap, Fun -- and Dangerous (fastcompany.com) 81

harrymcc writes: Go to Amazon, Walmart.com, and eBay, and you can find an array of companies selling laser cutters and engravers for a few hundred dollars -- dramatically less than you'll pay for a brand name such as Glowforge. But these budget models lack the safety features required to keep lasers safe, and may even have ignored the required FDA paperwork to put them on the market. Over at Fast Company, Glenn Fleishman wrote about the dangers of these devices. When alerted of specific models, the ecommerce sites removed them -- but many others remain for sale.
Unix

Computer Historians Crack Passwords of Unix's Early Pioneers (boingboing.net) 60

JustAnotherOldGuy shares a report from Boing Boing: Early versions of the free/open Unix variant BSD came with password files that included hashed passwords for such Unix luminaries as Dennis Ritchie, Stephen R. Bourne, Eric Schmidt, Brian W. Kernighan and Stuart Feldman. Leah Neukirchen recovered an BSD version 3 source tree and revealed that she was able to crack many of the weak passwords used by the equally weak hashing algorithm from those bygone days.

Dennis MacAlistair Ritchie's was "dmac," Bourne's was "bourne," Schmidt's was "wendy!!!" (his wife's name), Feldman's was "axlotl," and Kernighan's was "/.,/.,." Four more passwords were cracked by Arthur Krewat: Ozalp Babaolu's was "12ucdort," Howard Katseff's was "graduat;," Tom London's was "..pnn521," Bob Fabry's was "561cml.." and Ken Thompson's was "p/q2-q4!" (chess notation for a common opening move). BSD 3 used Descrypt for password hashing, which limited passwords to eight characters, salted with 12 bits of entropy.

Security

Cisco Hit By an Internal Network Outage (techcrunch.com) 33

Not a great start to the day for Cisco employees, many of which are struggling in the face of an internal IT outage. From a report: The technology and networking giant confirmed in a tweet it was "aware of some disruption" to its IT systems and is "working" on restoring the network. Worse, the company's corporate blog also went kaput. For a period, Cisco's blog was displaying the default WordPress install page. But at the time of publication, the blog had been restored. Some customers were unable to login through Cisco's single sign-on.
OS X

Critical Remote Code Execution Flaw Fixed In Popular Terminal App For MacOS (csoonline.com) 15

itwbennett shares a report from CSO: iTerm2 users: It's time to upgrade. A security audit sponsored by the Mozilla Open Source Support Program uncovered a critical remote code execution (RCE) vulnerability in the popular open-source terminal app for macOS. ITerm2 is an open-source alternative to the built-in macOS Terminal app, which allows users to interact with the command-line shell. Terminal apps are commonly used by system administrators, developers and IT staff in general, including security teams, for a variety of tasks and day-to-day operations.

The iTerm2 app is a popular choice on macOS because it has features and allows customizations that the built-in Terminal doesn't, which is why the Mozilla Open Source Support Program (MOSS) decided to sponsor a code audit for it. The MOSS was created in the wake of the critical and wide-impact Heartbleed vulnerability in OpenSSL with the goal of sponsoring security audits for widely used open-source technologies. The flaw, which is now tracked as CVE-2019-9535, has existed in iTerm2 for the past seven years and is located in the tmux integration. Tmux is a terminal multiplexer that allows running multiple sessions in the same terminal window by splitting the terminal screen. The flaw was fixed in iTerm2 version 3.3.6, which was released today.

The Internet

Tor Project Removes 13.5% of Current Servers For Running EOL Versions (zdnet.com) 9

An anonymous reader writes: The Tor Project has removed from its network this week more than 800 servers that were running outdated and end-of-life (EOL) versions of the Tor software. The removed servers represent roughly 13.5% of the 6,000+ servers that currently comprise the Tor network and help anonymize traffic for users across the world. Roughly 750 of the removed servers represent Tor middle relays, and 62 are exit relays -- where users exit the Tor network onto the world wide web after having their true location hidden through the Tor network. The organization said it plans to release a Tor software update in November that will natively reject connections with EOL Tor server versions by default, without any intervention from the Tor Project staff. "Until then, we will reject around 800 obsolete relays using their fingerprints," the Tor Project said in a statement this week.
Encryption

Schneier Slams Australia's Encryption Laws and CyberCon Speaker Bans (zdnet.com) 51

Governments breaking encryption is bad, and "will get worse once breaking encryption means people can die," says one of the world's leading security experts. From a report: "Australia has some pretty draconian laws about forcing tech companies to break security," says cryptographer and computer security professional Bruce Schneier. He's referring to the controversial Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018, which came into force in December. "I actually don't like that, because stuff that you do flows downhill to the US. So stop doing that," he told the Australian Cybersecurity Conference, or CyberCon, in Melbourne on Wednesday. Schneier's argument against breaking encrypted communications is simple. "You have to make a choice. Either everyone gets to spy, or no one gets to spy. You can't have 'We get to spy, you don't.' That's not the way the tech works," he said. "As this tech becomes more critical to life, we simply have to believe, accept, that securing it is more important than leaving it insecure so you can eavesdrop on the bad guys."
Privacy

Senator Proposes Mandatory Labeling For Products With Mics, Cameras (congress.gov) 42

Senator Cory Gardner (R-Colo.) introduced a bill, dubbed the Protecting Privacy in our Homes Act, that would require tech companies to include a label on products disclosing the presence of internet-connected microphones or cameras. "The proposed law does not define what kind of labels would need to be appended but rather would order the Federal Trade Commission to put in place specific regulations 'under which each covered manufacturer shall be required to include on the packaging of each covered device manufactured by the covered manufacturer a notice that a camera or microphone is a component of the covered device,'" reports Ars Technica. From the report: "Consumers face a number of challenges when it comes to their privacy, but they shouldn't have a challenge figuring out if a device they buy has a camera or microphone embedded into it," Gardner said. "This legislation is about consumer information, consumer empowerment, and making sure we're doing everything we can to protect consumer privacy." Most products that ship with cameras or microphones included tout the inclusion of such recording devices as a selling point, which could make this kind of regulation feel redundant at best. That said, there's quite a difference between "most" and "all." A rule such as the regulation Gardner proposes would close the gap that, for example, led owners of Nest Secure devices to the unpleasant discovery earlier this year that the products had shipped with undisclosed microphones.
Security

D-Link Home Routers Open To Remote Takeover Will Remain Unpatched (threatpost.com) 92

D-Link won't patch a critical unauthenticated command-injection vulnerability in its routers that could allow an attacker to remotely take over the devices and execute code. Threatpost reports: The vulnerability (CVE-2019-16920) exists in the latest firmware for the DIR-655, DIR-866L, DIR-652 and DHP-1565 products, which are Wi-Fi routers for the home market. D-Link last week told Fortinet's FortiGuard Labs, which first discovered the issue in September, that all four of them are end-of-life and no longer sold or supported by the vendor (however, the models are still available as new via third-party sellers). The root cause of the vulnerability, according to Fortinet, is a lack of a sanity check for arbitrary commands that are executed by the native command-execution function. Fortinet describes this as a "typical security pitfall suffered by many firmware manufacturers." With no patch available, affected users should upgrade their devices as soon as possible.
Encryption

Thunderbird Announces OpenPGP Support (mozilla.org) 40

doconnor writes: On the Mozilla Thunderbird blog it was announced that for the future Thunderbird 78 release, planned for summer 2020, they will add built-in functionality for email encryption and digital signatures using the OpenPGP standard. This addresses a feature request opened on Bugzilla almost 20 years ago and has been one of the top voted bugs for most of that period.
United States

Bipartisan Senate Report Calls For Sweeping Effort To Prevent Russian Interference in 2020 Election (washingtonpost.com) 330

A bipartisan panel of U.S. senators Tuesday called for sweeping action by Congress, the White House and Silicon Valley to ensure social media sites aren't used to interfere in the coming presidential election, delivering a sobering assessment about the weaknesses that Russian operatives exploited in the 2016 campaign. From a report: The Senate Intelligence Committee, a Republican-led panel that has been investigating foreign electoral interference for more than two and a half years, said in blunt language that Russians worked to damage Democrat Hillary Clinton while bolstering Republican Donald Trump -- and made clear that fresh rounds of interference are likely ahead of the 2020 vote. "Russia is waging an information warfare campaign against the U.S. that didn't start and didn't end with the 2016 election," said Sen. Richard Burr (R-N.C.), the committee's chairman. "Their goal is broader: to sow societal discord and erode public confidence in the machinery of government. By flooding social media with false reports, conspiracy theories, and trolls, and by exploiting existing divisions, Russia is trying to breed distrust of our democratic institutions and our fellow Americans." Though the 85-page report itself had extensive redactions, in the visible sections lawmakers urged their peers in Congress to act, including through the potential adoption of new regulations that would make who bought an ad more transparent. The report also called on the White House and the executive branch to adopt a more forceful, public role, warning Americans about the ways in which dangerous misinformation can spread while creating new teams within the U.S. government to monitor for threats and share intelligence with industry.
Android

The Privacy Trade-Offs of Cheap Android Smartphones (fastcompany.com) 22

Fast Company highlights some of the "privacy nightmares" surrounding low-cost Android smartphones, which can be very attractive for those on a tight budget. One example is the MYA2 MyPhone: According to an analysis by the advocacy group Privacy International, a $17 Android smartphone called MYA2 MyPhone, which was launched in December 2017, has a host of privacy problems that make its owner vulnerable to hackers and to data-hungry tech companies. First, it comes with an outdated version of Android with known security vulnerabilities that can't be updated or patched. The MYA2 also has apps that can't be updated or deleted, and those apps contain multiple security and privacy flaws. One of those pre-installed apps that can't be removed, Facebook Lite, gets default permission to track everywhere you go, upload all your contacts, and read your phone's calendar. The fact that Facebook Lite can't be removed is especially worrying because the app suffered a major privacy snafu earlier this year when hundreds of millions of Facebook Lite users had their passwords exposed.

Philippines-based MyPhone said the specs of the MYA2 limited it to shipping the phone with Android 6.0, and since then it says it has "lost access and support to update the apps we have pre-installed" with the device. Given that the MYA2 phone, like many low-cost Android smartphones, runs outdated versions of the Android OS and can't be updated due to their hardware limitations, users of such phones are limited to relatively light privacy protections compared to what modern OSes, like Android 10, offer today. The MYA2 is just one example of how cheap smartphones leak personal information, provide few if any privacy protections, and are incredibly easy to hack compared to their more expensive counterparts.

Security

Hospitals That Are Turning Away Patients Reportedly Pay Ransomware Attackers 100

An anonymous reader quotes a report from Ars Technica: Three Alabama hospitals have paid a ransomware demand to the criminals who waged a crippling malware attack that's forcing the hospitals to turn away all but the most critical patients, the Tuscaloosa News reported. As reported last Tuesday, ransomware shut down the hospitals' computer systems and prevented staff from following many normal procedures. Officials have been diverting non-critical patients to nearby hospitals and have warned that emergency patients may also be relocated once they are stabilized. An updated posted on Saturday said the diversion procedure remained in place. All three hospitals are part of the DCH health system in Alabama. Over the weekend, the Tuscaloosa News said DCH officials made a payment to the people responsible for the ransomware attack. The report didn't say how much officials paid. Saturday's statement from DCH officials said they have obtained a decryption key but didn't say how they obtained it. The statement read in part: "In collaboration with law enforcement and independent IT security experts, we have begun a methodical process of system restoration. We have been using our own DCH backup files to rebuild certain system components, and we have obtained a decryption key from the attacker to restore access to locked systems.

We have successfully completed a test decryption of multiple servers, and we are now executing a sequential plan to decrypt, test, and bring systems online one-by-one. This will be a deliberate progression that will prioritize primary operating systems and essential functions for emergency care. DCH has thousands of computer devices in its network, so this process will take time.

We cannot provide a specific timetable at this time, but our teams continue to work around the clock to restore normal hospital operations, as we incrementally bring system components back online across our medical centers. This will require a time-intensive process to complete, as we will continue testing and confirming secure operations as we go."
Security

FBI Warns About Attacks That Bypass Multi-Factor Authentication (zdnet.com) 29

The US Federal Bureau of Investigation (FBI) last month sent a security advisory to private industry partners about the rising threat of attacks against organizations and their employees that can bypass multi-factor authentication (MFA) solutions. From a report: "The FBI has observed cyber actors circumventing multi-factor authentication through common social engineering and technical attacks," the FBI wrote in a Private Industry Notification (PIN) sent out on September 17. While nowadays there are multiple ways of bypassing MFA protections, the FBI alert specifically warned about SIM swapping, vulnerabilities in online pages handling MFA operations, and the use of transparent proxies like Muraen and NecroBrowser.
Chrome

Russian Malware 'Patches' Chrome and Firefox To Fingerprint TLS Traffic (zdnet.com) 13

An anonymous reader quotes ZDNet: A Russian cyber-espionage hacker group has been spotted using a novel technique that involves patching locally installed browsers like Chrome and Firefox in order to modify the browsers' internal components. The end goal of these modifications is to alter the way the two browsers set up HTTPS connections, and add a per-victim fingerprint for the TLS-encrypted web traffic that originates from the infected computers...

According to a Kaspersky report published this week, hackers are infecting victims with a remote access trojan named Reductor, through which they are modifying the two browsers. This process involves two steps. They first install their own digital certificates to each infected host. This would allow hackers to intercept any TLS traffic originating from the host. Second, they modify the Chrome and Firefox installation to patch their pseudo-random number generation (PRNG) functions. These functions are used when generating random numbers needed for the process of negotiating and establishing new TLS handshakes for HTTPS connections.

Turla hackers are using these tainted PRNG functions to add a small fingerprint at the start of every new TLS connection.

The attack is being attributed to Turla, "a well-known hacker group believed to operate under the protection of the Russian government," ZDNet reports. And though the remote-access trojan already grants full control over a victim's device, one theory is the modified browsers offer "a secondary surveillance mechanism" if that trojan was discovered and removed. Researchers believe the malware is installed during file transfers over HTTP connections, suggesting an ISP had been compromised, according to the article.

"A January 2018 report from fellow cyber-security firm ESET revealed that Turla had compromised at least four ISPs before, in Eastern Europe and the former Soviet space, also with the purpose of tainting downloads and adding malware to legitimate files."

Slashdot Top Deals