Chrome

Chrome Promises 'No More Mixed Messages About HTTPS ' (chromium.org) 46

"Today we're announcing that Chrome will gradually start ensuring that https:// pages can only load secure https:// subresources," promises an announcement on the Chromium blog.

It notes that Chrome users already make HTTPS connections for more than 90% of their browsing time, and "we're now turning our attention to making sure that HTTPS configurations across the web are secure and up-to-date." In a series of steps outlined below, we'll start blocking mixed content (insecure http:// subresources on https:// pages) by default. This change will improve user privacy and security on the web, and present a clearer browser security UX to users...

HTTPS pages commonly suffer from a problem called mixed content, where subresources on the page are loaded insecurely over http://. Browsers block many types of mixed content by default, like scripts and iframes, but images, audio, and video are still allowed to load, which threatens users' privacy and security. For example, an attacker could tamper with a mixed image of a stock chart to mislead investors, or inject a tracking cookie into a mixed resource load. Loading mixed content also leads to a confusing browser security UX, where the page is presented as neither secure nor insecure but somewhere in between. In a series of steps starting in Chrome 79, Chrome will gradually move to blocking all mixed content by default. To minimize breakage, we will autoupgrade mixed resources to https://, so sites will continue to work if their subresources are already available over https://. Users will be able to enable a setting to opt out of mixed content blocking on particular websites...

Starting in December of 2019, Chrome 79 will include a new setting to unblock mixed content on specific sites. "This setting will apply to mixed scripts, iframes, and other types of content that Chrome currently blocks by default..."

Then in Chrome 80, mixed audio and video resources will be autoupgraded to https://, and if they fail to load Chrome will block them by default.
OS X

macOS Systems Can Be Abused In DDoS Attacks (zdnet.com) 18

An anonymous reader writes: "DDoS-for-hire services, also known as DDoS booters, or DDoS stressors, are abusing macOS systems to launch DDoS attacks," reports ZDNet. "These attacks are leveraging macOS systems where the Apple Remote Desktop feature has been enabled, and the computer is accessible from the internet, without being located inside a local network, or protected by a firewall. More specifically, the attackers are leveraging the Apple Remote Management Service (ARMS) that is a part of the Apple Remote Desktop (ARD) feature. When users enable the Remote Desktop capability on their macOS systems, the ARMS service starts on port 3283 and listens for incoming commands meant for the remote Mac." Hackers have figured out a way to bounce traffic off these ports and carry out DDoS attacks with the help of internet connected Macs. Nearly 40,000 macOS systems are currently connected online and can be used to send out DDoS attacks.
Security

Microsoft: Iranian Hackers Targeted a 2020 Presidential Campaign (zdnet.com) 100

Microsoft disclosed today that Iranian state-sponsored hackers tried to hack into email accounts belonging to current and former US government officials, and members of a 2020 US presidential campaign. From a report: The attacks have taken place "in a 30-day period between August and September," Tom Burt, Corporate Vice President, Customer Security & Trust at Microsoft, said today. Microsoft's Threat Intelligence Center (MSTIC) linked the attacks to a group the company calls Phosphorous (other names are APT35, Charming Kitten, and the Ajax Security Team). The group has been linked to Iran's government in reports from multiple cyber-security vendors. Burt said the group operated in different stages. It first made more than 2,700 probes to identify consumer email accounts belonging to specific Microsoft customers. Once the group had a list of high-value targets, it went after 241 of those accounts, which included "accounts are associated with a U.S. presidential campaign, current and former US government officials, journalists covering global politics and prominent Iranians living outside Iran."
Botnet

Dutch Police Take Down Hornets' Nest of DDoS Botnets (zdnet.com) 17

Dutch police have taken down this week a bulletproof hosting provider that has sheltered tens of IoT botnets that have been responsible for hundreds of thousands of DDoS attacks around the world, ZDNet reports. From the report: Servers were seized, and two men were arrested yesterday at the offices of KV Solutions BV (KV hereinafter), a so-called bulletproof hosting provider, a term used to describe web hosting providers that ignore abuse reports and allow cybercrime operations to operate on their servers. For two years, the company has provided hosting infrastructure to internet criminals, and has been one of the most serious offender at that, hosting all sorts of badies, from phishing pages to vulnerability scanners, and from crypto-mining operations to malware repositories. But above all, the company has made a reputation in cyber-security circles for being a hotspot for DDoS botnets, with cyber-criminals renting KV servers to host their bot scanners, malware, and command-and-control (C&C) servers, knowing they'd be safe from "harm."
Encryption

Attorney General Bill Barr Will Ask Zuckerberg To Halt Plans For End-To-End Encryption Across Facebook's Apps (buzzfeednews.com) 191

Attorney General Bill Barr, along with officials from the United Kingdom and Australia, is set to publish an open letter to Facebook CEO Mark Zuckerberg asking the company to delay plans for end-to-end encryption across its messaging services until it can guarantee the added privacy does not reduce public safety. From a report: A draft of the letter, dated Oct. 4, is set to be released alongside the announcement of a new data-sharing agreement between law enforcement in the US and the UK; it was obtained by BuzzFeed News ahead of its publication. Signed by Barr, UK Home Secretary Priti Patel, acting US Homeland Security Secretary Kevin McAleenan, and Australian Minister for Home Affairs Peter Dutton, the letter raises concerns that Facebook's plan to build end-to-end encryption into its messaging apps will prevent law enforcement agencies from finding illegal activity conducted through Facebook, including child sexual exploitation, terrorism, and election meddling.

"Security enhancements to the virtual world should not make us more vulnerable in the physical world," the letter reads. "Companies should not deliberately design their systems to preclude any form of access to content, even for preventing or investigating the most serious crimes." The letter calls on Facebook to prioritize public safety in designing its encryption by enabling law enforcement to gain access to illegal content in a manageable format and by consulting with governments ahead of time to ensure the changes will allow this access. While the letter acknowledges that Facebook, which owns Facebook Messenger, WhatsApp, and Instagram, captures 99% of child exploitation and terrorism-related content through its own systems, it also notes that "mere numbers cannot capture the significance of the harm to children."

Government

Government Plans To Collect DNA From Detained Immigrants (nytimes.com) 232

An anonymous reader quotes a report from The New York Times: The Trump administration is moving to begin collecting DNA samples from hundreds of thousands of people booked into federal immigration custody each year for entry into a national criminal database, an immense expansion of the use of technology to enforce the nation's immigration laws. Senior officials at the Department of Homeland Security said Wednesday that the Justice Department was developing a federal regulation that would give immigration officers the authority to collect DNA in detention facilities that are holding more than 40,000 people.

The move would constitute a major expansion of the use of a database maintained by the F.B.I., which has been limited mainly to genetic data collected from people who have been arrested, charged or convicted in connection with serious crimes. Immigrant and privacy advocates said the move raised privacy concerns for an already vulnerable population that could face profiling or discrimination as a result of their personal data being shared among law enforcement authorities. The new rules would allow the government to collect DNA from children, as well as those who seek asylum at legal ports of entry and have not broken the law. They warned that United States citizens, who are sometimes accidentally booked into immigration custody, could also be forced to hand over their private genetic information.
Homeland security officials said the new initiative was permitted under the DNA Fingerprint Act of 2005. "Up until now, immigrant detainees have been exempt from the law, they said, because of an agreement between Eric H. Holder Jr. and Janet Napolitano, who served as attorney general and homeland security secretary, respectively, under President Barack Obama," reports The New York Times.

The new program "would provide a comprehensive DNA profile of individuals who are tested, as opposed to the more narrow test that was used only to determine parentage," the report says. "And unlike the testing under the pilot program, the results would be shared with other law enforcement agencies."
AMD

AMD Ryzen Pro 3000 Series Desktop CPUs Will Offer Full RAM Encryption (arstechnica.com) 53

An anonymous reader quotes a report from Ars Technica: Monday, AMD announced Ryzen Pro 3000 desktop CPUs would be available in Q4 2019. This of course raises the question, "What's a Ryzen Pro?" The business answer: Ryzen Pro 3000 is a line of CPUs specifically intended to power business-class desktop machines. The Pro line ranges from the humble dual-core Athlon Pro 300GE all the way through to Ryzen 9 Pro 3900, a 12-core/24-thread monster. The new parts will not be available for end-user retail purchase and are only available to OEMs seeking to build systems around them.

From a more technical perspective, the answer is that the Ryzen Pro line includes AMD Memory Guard, a transparent system memory encryption feature that appears to be equivalent to the AMD SME (Secure Memory Encryption) in Epyc server CPUs. Although AMD's own press materials don't directly relate the two technologies, their description of Memory Guard -- "a transparent memory encryption (OS and application independent DRAM encryption) providing a cryptographic AES encryption of system memory" -- matches Epyc's SME exactly. AMD Memory Guard is not, unfortunately, available in standard Ryzen 3000 desktop CPUs. If you want to build your own Ryzen PC with full memory encryption from scratch, you're out of luck for now.

Security

Hackers Put Porn Vids On Promo Screens Above Asics Store and Detroit Billboard (cnn.com) 56

dryriver shares a report from CNN: Sports brand Asics has issued an apology after "objectionable content" played on the screens above its store in Auckland, New Zealand. Pornographic videos were shown on promotional screens for hours outside an Asics store in Auckland, New Zealand on Sunday morning, the New Zealand Herald reported. The Japanese sportswear brand apologized Sunday, saying the material had been played above its central Auckland store due to a hack. "This morning an unknown person gained access to the screens above our Central Auckland store and some objectionable content was displayed on the screens," said the statement published on Asics New Zealand's Facebook page. Security officer Dwayne Hinagano told the New Zealand Herald that an explicit sex video played for hours and was seen by startled passers-by. "The video ran for a long time, maybe two hours from 8am until the shop staff arrived at about 10am. Some people were shocked, but others just stopped and watched," Hinagano told the news outlet, which also cited witnesses who said the video had been running since 1 a.m. Over the weekend, two hackers managed to upload a porn video to an interstate billboard outside Detroit. According to news reports, the pornography played for about 20 minutes before it was removed.

"Police in the suburb of Auburn Hills said in a statement that the unidentified pair, who appear to be young white men, were captured by video shortly before 11 p.m. Saturday breaking into a building at the base of the electronic billboard on Interstate 75," reports NBC News. "The building, which is surrounded by a six-foot fence and is unstaffed, houses the computer that controls the sign, a police official told NBC affiliate WDIV."
Security

Ransomware Forces 3 Hospitals To Turn Away All But the Most Critical Patients (arstechnica.com) 89

Ten hospitals -- three in Alabama and seven in Australia -- have been hit with paralyzing ransomware attacks that are affecting their ability to take new patients, it was widely reported on Tuesday. Ars Technica reports: All three hospitals that make up the DCH Health System in Alabama were closed to new patients on Tuesday as officials there coped with an attack that paralyzed the health network's computer system. The hospitals -- DCH Regional Medical Center in Tuscaloosa, Northport Medical Center, and Fayette Medical Center -- are turning away "all but the most critical new patients" at the time this post was going live. Local ambulances were being instructed to take patients to other hospitals when possible. Patients coming to DCH emergency rooms faced the possibility of being transferred to another hospital once they were stabilized.

"A criminal is limiting our ability to use our computer systems in exchange for an as-yet unknown payment," DCH representatives wrote in a release. "Our hospitals have implemented our emergency procedures to ensure safe and efficient operations in the event technology dependent on computers is not available." At least seven hospitals in Australia, meanwhile, were also feeling the effects of a ransomware attack that struck on Monday. The hospitals in Gippsland and southwest Victoria said they were rescheduling some patient services as they responded to a "cyber health incident."
According to news reports, hospital computer systems remained locked down at seven hospitals on Tuesday more than 24 hours after the attack struck. "An official said it would take weeks to secure and restore damaged networks," reports Ars Technica. "The official said there was no indication that patient records had been accessed."
Yahoo!

Former Yahoo Engineer Pleads Guilty To Hacking User Emails in Search For Porn (zdnet.com) 52

A former Yahoo software engineer pleaded guilty yesterday to hacking into the personal accounts of over 6,000 Yahoo users, in search of sexual images and videos. From a report: Reyes Daniel Ruiz, 34, of Tracy, California, worked for more than ten years for Yahoo!, where he served as a reliability engineer for the company's Yahoo! Mail service, among other roles. According to court documents, Ruiz used the access to Yahoo!'s internal network that his job provided to crack users' passwords and gain access to their email accounts. In total, he accessed about 6,000 accounts, most belonging to younger women, including personal friends and work colleagues. Once in, he searched and downloaded images and videos, which he stored at home on a hard drive. Ruiz also used access to the hacked Yahoo! email inboxes to compromise accounts at services like Apple iCloud, Facebook, Gmail, DropBox, and others, where the victims used the Yahoo! email address to register accounts. He did this by requesting password resets on the third-party sites, which he received inside the victim's Yahoo! inboxes. Ruiz then continued his search of personal images and videos on these new accounts.
Education

Over 500 US Schools Were Hit By Ransomware in 2019 (zdnet.com) 27

In the first nine months of the year, ransomware infections have hit over 500 US schools, according to a report published last week by cyber-security firm Armor. From a report: In total, the company said it found and tracked ransomware infections at 54 educational organizations like school districts and colleges, accounting for disruptions at over 500 schools. To make matters worse, the attacks seem to have picked up in the last two weeks, with 15 school districts (accounting for over 100 K-12 schools) getting hit at the worst time possible -- in the first weeks of the new school year. Of these 15 ransomware incidents, Armos said that five were caused by the Ryuk ransomware, one of today's most active ransomware strains/gangs. Overall, Connecticut saw ransomware infections hit seven school districts throughout 2019, making them the state whose educational institutions were compromised the most by ransomware attacks this year. But while Connecticut saw the most ransomware infections targeting school districts, it was Louisiana who handled the attacks the best when, in July, Governor John Bel Edwards declared a state of emergency in response to a wave of ransomware infections that hit three school districts. The governer's actions rallied multiple state and private incident response teams together and helped impacted school districts recover before the new school year, without paying the hackers' ransom demand.
Security

Legit-Looking iPhone Lightning Cables That Hack You Will Be Mass Produced and Sold (vice.com) 57

An anonymous reader quotes a report from Motherboard: Soon it may be easier to get your hands on a cable that looks just like a legitimate Apple lightning cable, but which actually lets you remotely take over a computer. The security researcher behind the recently developed tool announced over the weekend that the cable has been successfully made in a factory. MG is the creator of the O.MG Cable. It charges phones and transfers data in the same way an Apple cable does, but it also contains a wireless hotspot that a hacker can connect to. Once they've done that, a hacker can run commands on the computer, potentially rummaging through a victim's files, for instance.

After demoing the cable for Motherboard at the Def Con hacking conference this summer, MG said "It's like being able to sit at the keyboard and mouse of the victim but without actually being there." At the time, MG was selling the handmade cables at the conference for $200 each. Now that production process has been streamlined. This doesn't necessarily mean that factories are churning out O.MG Cables right now, but it shows that their manufacture can be fully outsourced, and MG doesn't have to make the cables by hand.

Windows

Windows 10 Users Fume: Microsoft, Where's Our 'Local Account' Option Gone? (zdnet.com) 217

New submitter xack shares a report: Microsoft has annoyed some of its 900 million Windows 10 device users after apparently removing the 'Use offline account' as part of its effort to herd users towards its cloud-based Microsoft Account. The offline local account is specific to one device, while the Microsoft Account can be used to log in to multiple devices and comes with the benefit of Microsoft's recent work on passwordless authentication with Windows Hello. The local account doesn't require an internet connection or an email address -- just a username and password that are stored on the PC. But Windows 10 users are annoyed that Microsoft has hidden the local account option when setting up a new PC or reinstalling Windows 10. A user on a popular Reddit thread notes that the local account option is now invisible if the device is connected to the internet. "Either run the setup without being connected to the internet, or type in a fake phone number a few times and it will give you the prompt to create a local account," Froggyowns suggested as a solution.
Microsoft

Microsoft Stops Trusting SSD Makers (tomshardware.com) 56

Windows ships with a full volume encryption tool called BitLocker. The feature used to trust any SSD that claimed to offer its own hardware-based encryption, but that changed in the KB4516071 update to Windows 10 released on September 24, which now assumes that connected SSDs don't actually encrypt anything. From a report: "SwiftOnSecurity" called attention to this change on September 26. The pseudonymous Twitter user then reminded everyone of a November 2018 report that revealed security flaws, such as the use of master passwords set by manufacturers, of self-encrypting drives. That meant people who purchased SSDs that were supposed to help keep their data secure might as well have purchased a drive that didn't handle its own encryption instead. Those people were actually worse off than anticipated because Microsoft set up BitLocker to leave these self-encrypting drives to their own devices. This was supposed to help with performance -- the drives could use their own hardware to encrypt their contents rather than using the CPU -- without compromising the drive's security. Now it seems the company will no longer trust SSD manufacturers to keep their customers safe by themselves. Here's the exact update Microsoft said it made in KB4516071: "Changes the default setting for BitLocker when encrypting a self-encrypting hard drive. Now, the default is to use software encryption for newly encrypted drives. For existing drives, the type of encryption will not change." People can also choose not to have BitLocker encrypt these drives, too, but the default setting assumes they don't want to take SSD manufacturers at their word.
Crime

Krebs Publishes 'Interview With the Guy Who Tried To Frame Me For Heroin Possession' (krebsonsecurity.com) 52

"In April 2013, I received via U.S. mail more than a gram of pure heroin as part of a scheme to get me arrested for drug possession," writes security reserch Brian Krebs. "But the plan failed and the Ukrainian mastermind behind it soon after was imprisoned for unrelated cybercrime offenses.

"That individual recently gave his first interview since finishing his jail time here in the states, and he's shared some select (if often abrasive and coarse) details on how he got into cybercrime and why... Vovnenko claims he never sent anything and that it was all done by members of his forum... "They sent all sorts of crazy shit. Forty or so guys would send. When I was already doing time, one of the dudes sent it...." In an interview published on the Russian-language security blog Krober.biz, Vovnenko said he began stealing early in life, and by 13 was already getting picked up for petty robberies and thefts... "After watching movies and reading books about hackers, I really wanted to become a sort of virtual bandit who robs banks without leaving home," Vovnenko recalled...

Around the same time Fly was taking bitcoin donations for a fund to purchase heroin on my behalf, he was also engaged to be married to a nice young woman. But Fly apparently did not fully trust his bride-to-be, so he had malware installed on her system that forwarded him copies of all email that she sent and received. But Fly would make at least two big operational security mistakes in this spying effort: First, he had his fiancée's messages forwarded to an email account he'd used for plenty of cybercriminal stuff related to his various "Fly" identities. Mistake number two was the password for his email account was the same as one of his cybercrime forum admin accounts. And unbeknownst to him at the time, that forum was hacked, with all email addresses and hashed passwords exposed.

Soon enough, investigators were reading Fly's email, including the messages forwarded from his wife's account that had details about their upcoming nuptials, such as shipping addresses for their wedding-related items and the full name of Fly's fiancée. It didn't take long to zero in on Fly's location in Naples. While it may sound unlikely that a guy so immeshed in the cybercrime space could make such rookie security mistakes, I have found that a great many cybercriminals actually have worse operational security than the average Internet user. I suspect this may be because the nature of their activities requires them to create vast numbers of single- or brief-use accounts, and in general they tend to re-use credentials across multiple sites, or else pick very poor passwords -- even for critical resources...

Towards the end, Fly says he's considering going back to school, and that he may even take up information security as a study. I wish him luck in that whatever that endeavor is as long as he can also avoid stealing from people.

Security

Linus Torvalds Approves New Kernel 'Lockdown' Feature (zdnet.com) 86

"After years of countless reviews, discussions, and code rewrites, Linus Torvalds approved on Saturday a new security feature for the Linux kernel, named 'lockdown'," reports ZDNet: The new feature will ship as a LSM (Linux Security Module) in the soon-to-be-released Linux kernel 5.4 branch, where it will be turned off by default; usage being optional due to the risk of breaking existing systems. The new feature's primary function will be to strengthen the divide between userland processes and kernel code by preventing even the root account from interacting with kernel code -- something that it's been able to do, by design, until now.

When enabled, the new "lockdown" feature will restrict some kernel functionality, even for the root user, making it harder for compromised root accounts to compromise the rest of the OS... "When enabled, various pieces of kernel functionality are restricted," said Linus Torvalds, Linux kernel creator, and the one who put the final stamp of approval on the module yesterday. This includes restricting access to kernel features that may allow arbitrary code execution via code supplied by userland processes; blocking processes from writing or reading /dev/mem and /dev/kmem memory; block access to opening /dev/port to prevent raw port access; enforcing kernel module signatures; and many more others, detailed here.

IT

Kickstarter Defends Firings As Not Anti-Union, But Strong Criticism Continues (currentaffairs.org) 97

"Kickstarter's CEO Aziz Hasan sent an email to staff Friday, explaining why the company fired two staff members and laid off another who played an instrumental role in organizing a union at the company..." reports Motherboard: Hasan insisted that the firings were related specifically to job performance issues, not union organizing. "We understood how these firings could be perceived, but it would be unfair to not hold these two employees to the same standards as the rest of our staff," he wrote. "It's worth noting that since March we've given raises to 14 people who have been public about their support for a union, and promoted three of them...."

In his letter, Hasan asserts that management believes a union would hurt the company and that union organizers have not made their complaints clear to the company. "The union framework is inherently adversarial," he writes. "That dynamic doesn't reflect who we are as a company, how we interact, how we make decisions, or where we need to go. We believe that in many ways it would set us back, and that the us vs. them binary already has."

If Kickstarter unionizes, it would be one of the first white collar tech unions in the United States.

The magazine Current Affairs has a different perspective: When the union organizers were fired, Current Affairs happened to be in the middle of a Kickstarter campaign. As a left publication, we were appalled, and didn't want to publicly support an anti-union company. So we got together with our colleagues at Protean Magazine, Pinko Magazine, the Nib, and the Baffler (all of whom had done Kickstarter campaigns in the past) and released a statement condemning the firings and expressing solidarity with the union. We invited other Kickstarter project creators to join us on the statement, which hundreds did, including well-known creators like Neil Gaiman, Anita Sarkeesian, Molly Crabapple, and Richard Herring. Collectively, the creators on our statement have raised millions of dollars on the platform (my estimate is $10 million, but I stopped counting around 5). We were united in (1) appreciating Kickstarter's staff and the great platform they have created and (2) being firmly opposed to the company's anti-union activities and supportive of the workers' rights...

As our campaign took off and started to attract press attention, I received a message from Kickstarter's chief communications officer. He asked me if I would like to talk on the phone so that he could address our concerns.... We did not resolve anything on the conversation, but he said the company was thinking through how to respond and he would be in touch. Saturday, Kickstarter offered its response. The communications officer emailed me, and said he would like to share a statement from the CEO with the project creators. The statement said that Kickstarter:

1. Stood by its decision to fire the organizers, and would be dispatching its lawyers to fight their claims.

2. Would not voluntarily recognize a union even if the vast majority of workers signed in support of one.

3. Would not pledge to remain neutral on unionization, and would continue to actively oppose the effort.

The statement was the most blatant slap in the face imaginable to both the workers and the project creators. It says, in essence: drop dead...

For Current Affairs, it means that we now have to cease using Kickstarter for our fundraising efforts. Who can possibly partner with a company that is actively and proudly trying to union-bust? Why should we give 5 percent of our supporters' money to a corporation that will use it to hire lawyers and P.R. professionals to keep its workers from exercising their rights?

Google

Google's DNS-Over-HTTPS Plans Scrutinized By US Congress (engadget.com) 130

Google's plans to implement DNS over HTTPS in Chrome are being investigated by a committee in the U.S. House of Representatives, while the Justice Department has "recently received complaints" about the practice, according to the Wall Street Journal.

An anonymous reader quotes Engadget: While Google says it's pushing for adoption of the technology to prevent spying and spoofing, House investigators are worried this would give the internet giant an unfair advantage by denying access to users' data. The House sent a letter on September 13th asking if Google would use data handled through the process for commercial purposes... Internet service providers are worried that they may be shut out of the data and won't know as much about their customers' traffic patterns. This could "foreclose competition in advertising and other industries," an alliance of ISPs told Congress in a September 19th letter...

Mozilla also wants to use the format to secure DNS in Firefox, and the company's Marshall Erwin told the WSJ that the antitrust gripes are "fundamentally misleading." ISPs are trying to undermine the standard simply because they want continued access to users' data, Erwin said. Unencrypted DNS helps them target ads by tracking your web habits, and it's harder to thwart DNS tracking than cookies and other typical approaches.

Education

Liberal Arts Majors Eventually Earn More Than STEM Majors (indstate.edu) 122

The conventional wisdom that liberal arts majors earn less than compsci majors may be true for the first job, but not necessarily for an entire career, reports the New York Times, in an article shared by jds91md (and republished by Indiana State's College of Arts and Sciences). "By age 40 the earnings of people who majored in fields like social science or history have caught up." This happens for two reasons. First, many of the latest technical skills that are in high demand today become obsolete when technology progresses. Older workers must learn these new skills on the fly, while younger workers may have learned them in school. Skill obsolescence and increased competition from younger graduates work together to lower the earnings advantage for STEM degree-holders as they age.

Second, although liberal arts majors start slow, they gradually catch up to their peers in STEM fields. This is by design. A liberal arts education fosters valuable "soft skills" like problem-solving, critical thinking and adaptability. Such skills are hard to quantify, and they don't create clean pathways to high-paying first jobs. But they have long-run value in a wide variety of careers.

Some other interesting stats from the article:
  • STEM salaries grew more slowly -- and the field experienced a higher exit rate. "Between the ages of 25 and 40, the share of STEM majors working in STEM jobs falls from 65 percent to 48 percent. Many of them shift into managerial positions, which pay well but do not always require specialized skills."
  • High-paying jobs in management, business and law raise the average salary of all social science/history majors.

China

China Hacks Airbus Suppliers For Commercial Secrets (ibtimes.com) 50

An anonymous reader quotes International Business Times: European aerospace giant Airbus has been hit by a series of attacks by hackers targeting its suppliers in search of commercial secrets, sources told AFP, adding they suspected a Chinese link. AFP spoke to seven security and industry sources, all of whom confirmed a spate of attacks in the past 12 months but asked for anonymity because of the sensitive nature of the information they were sharing...

Many state-backed and independent hackers are known to disguise their tracks, or they may leave clues intended to confuse investigators or lead them to blame someone else. But the sources said they suspected Chinese hackers were responsible, given their record of trying to steal sensitive commercial information and the fact that Beijing has just launched a plane designed to compete with Airbus and US rival Boeing.

State-owned plane-maker Comac has already launched manufacturing of its first mid-range airliner but has struggled to get it certified. Engines and avionics are "areas in which Chinese research and development is weak," one of the sources said.

Slashdot Top Deals