IT

Ransomware Incident Leaves Some Johannesburg Residents Without Electricity (zdnet.com) 67

A ransomware infection at an electricity provider in the city of Johannesburg, South Africa's biggest city and financial capital, has left some of its residents without power. From a report: The ransomware infection impacted City Power -- a provider of pre-paid electric power for Johannesburg residents and local companies. The malware encrypted the company's database, internal network, web apps, and official website.
Bug

VLC Developer Debunks Reports of 'Critical Security Issue' In Open Source Media Player (portswigger.net) 80

New submitter Grindop53 shares a report: Widespread reports of a "critical security issue" that supposedly impacted users of VLC media player have been debunked as "completely bogus" by developers. Earlier this week, German computer emergency response team CERT-Bund -- part of the Federal Office for Information Security (BSI) -- pushed out an advisory warning network administrators and other users of a high-impact vulnerability in VLC. It seems that this advisory can be traced back to a ticket that was opened on VLC owner VideoLAN's public bug tracker more than four weeks ago. The alleged heap-based buffer overflow flaw was disclosed by a user named "topsec(zhangwy)," who stated that a malicious .mp4 file could be leveraged by an attacker to take control of VLC media player users' devices. The issue was flagged as high-risk on the CERT-Bund site, and the vulnerability was assigned a CVE entry (CVE-2019-13615).

However, according to VideoLAN president Jean-Baptiste Kempf, the exploit does not work on the latest VLC build. In fact, any potential issues relating to the vulnerability were patched more than a year ago. "There is no security issue in VLC," Kempf told The Daily Swig in a phone conversation this morning. "There is a security issue in a third-party library, and a fix was pushed [out] 18 months ago." When asked how or why this oversight generated so much attention, Kempf noted that the reporter of the supposed vulnerability did not approach VideoLAN through its security reporting email address. "The guy never contacted us," said Kempf, who remains a lead developer at the VLC project. "This is why you don't report security issues on a public bug tracker."
Kempf and his team were unable to replicate the issue in the latest version of VLC, leading many to believe that the bug reporter was working on a computer running an outdated version of Ubuntu. "If you report a security issue, at least update your Linux distribution," Kempf said.
Security

Don't Put Your Work Email on Your Personal Phone (medium.com) 192

Many of us have given up on the idea of carrying around a dedicated work phone. After all, why bother when you can get everything you need on your personal smartphone? Here's one reason: Your work account might be spying on you in the background. From a column: When you add a work email address to your phone, you'll likely be asked to install something called a Mobile Device Management (MDM) profile. Chances are, you'll blindly accept it. (What other choice do you have?) MDM is set up by your company's IT department to reach inside your phone in the background, allowing them to ensure your device is secure, know where it is, and remotely erase your data if the phone is stolen. From your company's perspective, there are obvious security reasons for installing an MDM on an employee's phone. But for employees, it's difficult to tell what these invisible profiles are collecting behind the scenes, as they provide people at your company with invisible control over your device. That's why when it comes to your phone, no matter how much you trust your IT department, it's a good idea to keep work and pleasure separate.

MDM profiles, paired with device management tools, allow companies to track employee phones in a single dashboard. They can mitigate security breaches or potential harm from a rogue employee; if you work for a law firm, say, and your boss worries you're leaking sensitive emails from your smartphone, they could remotely wipe your data. MDM profiles can also force you to use a long password on your device, rather than a simple PIN, among other policies.

Microsoft

Microsoft Reveals New Windows 10 Start Menu in Accidental Internal Leak (theverge.com) 147

Microsoft has accidentally released an internal-only version of Windows 10 to testers, revealing a new Start menu design. From a report: The software giant has distributed Windows 10 build 18947, meant for internal Xbox development, to Windows Insider testers using 32-bit devices. It's an internal-only build from the company's canary branch, and yet Microsoft has published it to all Windows 10 testers whether they're in release preview, fast ring, or even slow ring testing. Thankfully, it's only released to 32-bit systems, which aren't widely used, but it's an embarrassing mistake for Microsoft's Windows 10 testing efforts. This internal build appears to include a new Start menu design, that's very early in testing, without Microsoft's Live Tiles. It's something Microsoft is testing internally, but it's not clear whether Windows 10 will fully drop Live Tiles in the Start menu anytime soon.
Security

NSA Forms Cybersecurity Directorate Under More Assertive U.S. Effort (wsj.com) 24

The National Security Agency will create a cybersecurity directorate later this year as part of a wider effort to align the agency's offensive and defensive operations more closely, U.S. officials said. From a report: Anne Neuberger has been tapped to lead the new directorate, slated to become operational Oct. 1. The creation of the directorate and selection of Ms. Neuberger come during a broader fusion of NSA's offensive and defensive portfolios. The integration has been under way for several years but has expanded under Gen. Paul Nakasone, who has led the NSA and the U.S. Cyber Command since May 2018. The Trump administration has sought to be more aggressive and the NSA has adopted a strategy of "persistent engagement" in cyberspace against foreign adversaries including Russia, China and Iran. Much of those efforts, which are led offensively by Cyber Command but supported by intelligence collected by NSA, have focused on deterring election interference after Moscow, according to former special counsel Robert Mueller and the U.S. intelligence community, meddled in the 2016 presidential vote to boost the candidacy of Donald Trump. Russia has denied the allegations. Ms. Neuberger, 43 years old, is expected to be named formally to her new post Tuesday during a speech by Gen. Nakasone at the International Conference on Cyber Security at Fordham University. He is expected to provide public details on the cybersecurity directorate for the first time.
Encryption

AG Barr Says Consumers Should Accept Security Risks of Encryption Backdoors (techcrunch.com) 582

U.S. attorney general William Barr has said consumers should accept the risks that encryption backdoors pose to their personal cybersecurity to ensure law enforcement can access encrypted communications. From a report: In remarks, Barr said the "significance of the risk should be assessed based on its practical effect on consumer cybersecurity, as well as its relation to the net risks that offering the product poses for society." He suggested that the "residual risk of vulnerability resulting from incorporating a lawful access mechanism is materially greater than those already in the unmodified product. [...] Some argue that, to achieve at best a slight incremental improvement in security, it is worth imposing a massive cost on society in the form of degraded safety." The risk, he said, was acceptable because "we are talking about consumer products and services such as messaging, smart phones, e-mail, and voice and data applications," and "not talking about protecting the nation's nuclear launch codes."
Security

Hackers Stole 7.5TB of Secret Data From Russia's Intelligence Agency (fossbytes.com) 95

Hackers have reportedly stolen about 7.5 terabytes of data from a major Russian Federal Security Service (FSB) contractor, thus exposing the secret projects the agency was working on to de-anonymize Tor browsing, scrape data from social media, and cut off Russia's internet from the rest of the world. Fossbytes reports: Russia's FSB is the successor agency to the infamous KGB and is similar to the FBI and MI5; a major part of their work includes electronic surveillance in the country and overseas as well. The attack on FSB took place on July 13 when a hacking group that goes by the name 0v1ru$ breached SyTech, a major FSB contractor that works on several internet projects. The hackers defaced SyTech's homepage and left a smiling Yoba Face and other pictures to indicate the breach. 0v1ru$ passed on the stolen data to the larger hacking group Digital Revolution, which in turn shared the files with various media outlets and posted on Twitter. BBC Russia outlines the project data that was stolen and lists the major ones, including Nautilus, a project to scrap data on social media platforms; Nautilus-S, a project to de-anonymize Tor users by creating exit nodes that are controlled by the Russian government; and Nadezhda, a project attempting to create a "sovereign internet" that is isolated from the rest of the internet.
IT

DRAM Prices To Slide More Than 40% in 2019 Because Chip Makers Can't Forecast (theregister.co.uk) 81

The laws of botched supply and demand forecasting are coming home to roost for the semiconductor industry in 2019 with DRAM average sales price set to fall 42.1 per cent. From a report: The latest ladle of doom and gloom was poured onto the sector this morning by Gartner, days after IC Insights delivered its dark prognosis for chip makers. "A weaker pricing environment for memory and some other chip types combined with the US-China trade dispute and lower growth in major applications, including smartphones, servers and PCs is driving the global semiconductor market to its lowest growth level since 2009," said Gartner analyst Ben Lee. [...] The upshot of this is that global semiconductor revenues are expected to drop 9.6 per cent year-on-year to $475bn. This is down 3.4 per cent on Gartner's earlier forecast and likely could be revised again before the end of 2019 is upon us. Given the volumes of DRAM swilling around the supply chain that have forced down price, oversupply is on track to spill into the first and second quarters of the next calendar year.
IT

Slack's Desktop App Now Launches 33% Faster, Uses 50% Less Memory (venturebeat.com) 81

Slack today announced it's deploying an under-the-hood upgrade for its desktop app to boost performance for companies and teams using the app for workplace collaboration. From a report: The latest version of Slack for desktop and internet browsers is due out in the coming weeks and promises a 33% faster launch time, 10 times faster launch of VoIP calls, and roughly 50% less memory usage. The news comes a month after Slack became a public company, listed as WORK on the New York Stock Exchange. Slack product architect and lead of desktop client rewrite Johnny Rodgers said the upgrade takes advantage of changes to Slack's underlying technology, like modern JavaScript tools and techniques and the React UI framework.
Data Storage

Dropbox Brings Back Support For ZFS, XFS, Btrfs And eCryptFS On Linux (linuxuprising.com) 69

Speaking of Dropbox, the online storage cloud service has enabled support for ZFS and XFS on 64-bit Linux systems, and eCryptFS and Btrfs on all Linux systems. The move comes after it recently pulled support for all file storage systems on Linux except Ext4. From a report: Dropbox stopped supporting folder syncing to drives with filesystems it deemed "uncommon", which on Linux meant anything but Ext4, upsetting quite a few users. The reason cited for this was that "a supported file system is required as Dropbox relies on extended attributes (X-attrs) to identify files in the Dropbox folder and keep them in sync", which doesn't really make sense since there are many filesystems that support xattr (extended attributes) on Linux. After this change was announced, various workarounds started to appear online, including one that I posted on Linux Uprising. There was even a new unofficial, open source Dropbox client developed for this reason (which is also much lighter than the official client by the way). But this didn't last long though, as last week, the Dropbox 77.3.127 beta changelog says that Dropbox has added back support for ZFS (on 64-bit systems only), XFS (on 64bit systems only), Btrfs and eCryptFS.
Security

Equifax To Pay At Least $575M as Part of FTC Settlement (cnet.com) 58

Equifax has agreed to pay at least $575 million to the US Federal Trade Commission, the Consumer Financial Protection Bureau and all 50 states over its massive 2017 data breach. From a report: If that isn't enough to compensate people impacted by the breach, the credit reporting company could have to pay up to $700 million -- a figure we got hints about on Friday. The settlement includes $300 million for a fund providing affected consumers with credit monitoring services and for those who bought credit or identity monitoring services in the wake of the breach. If that doesn't cover the losses, Equifax will add up to $125 million to the fund. It's also agreed to pay $175 million to 48 states, the District of Columbia and Puerto Rico, as well as $100 million in civil penalties to the CFPB. Hackers stole the personal information -- including Social Security numbers and home addresses -- of nearly 148 million Americans from Equifax's servers in a data breach that ran from May and July 2017. A December 2018 House Oversight Committee report called the breach "entirely preventable," saying Equifax didn't take action to prevent it and wasn't prepared for the aftermath.
Google

Google Settles Age Descrimination Lawsuit (forbes.com) 120

Long-time Slashdot reader sfcat quotes Forbes: Almost a decade ago, courts sounded a clear warning bell that Google's culture was tainted by illegal and pervasive age discrimination. Inexplicably, Google didn't listen.

And so the Los Angeles Times recently reported that Google has agreed to pay $11 million to settle a federal lawsuit alleging Google engaged in a systemic practice of discriminating on the basis of age in hiring. Some 227 plaintiffs will collect an average of $35,000 each.

Google actually agreed to settle the case in December but the final settlement agreement was presented to a federal judge on Friday. The lawsuit was filed by Cheryl Fillekes, a software engineer who was interviewed by Google four times from 2007 to 2014, starting when she was 47, but was never hired.

The lawsuit alleged Google hired younger workers based on "cultural fit."

In the settlement Google also agrees to train its managers about age bias and create an "age diversity in recruiting" committee. Forbes points out that the median age for all Google employees in 2017 was 30, "a decade younger than the median age of U.S. workers."

"On its web page, Google says its mission is to 'organize the world's information and make it universally accessible and useful.' But for some reason Google has failed as a company to organize and use the information that age discrimination is illegal."
IT

Atlassian Changes Annual Performance Reviews To Stop Rewarding 'Brilliant Jerks' (businessinsider.com.au) 432

Australia-based Atlassian"has implemented a new performance review strategy designed to give their workers a better evaluation of how they're performing," reports Business Insider, adding that Atlassian's global head of talent said the company wants to measure contributions to a larger team effort. "We want people to get rewarded for what they delivered." In 2018 it soft-launched a strategy where most of its performance review process will have nothing to do with the skills in an employee's job, but more to do with how well they are living with the company values. Now, the strategy is being rolled out permanently and will be tied to employee bonuses... "We want to be able to evaluate a whole person and encourage them to bring their full self to work and not just focus on skills itself, but really focus on the way they do their work," said Bek Chee, Atlassian's global head of talent. She added that while workforces have changed over the past 30 years, performance reviews, for the most part, have stayed the same...

With this performance review system, Atlassian aims to throw out the idea of the "brilliant jerk", which Chee describes as someone who is technically-talented, but perhaps at the expense of others. Instead it is focusing on how an employee demonstrates the company values, how they complete their roles and how they contribute to their team. "We really want to enforce the way that values get lived, the way that people impact the team and the way that they also contribute within their role.

Programming

GitLab Survey Finds Positive Results For Both DevOps and Working Remotely (gitlab.com) 34

GitLab's CEO and co-founder says there was one big takeaway from their recent "2019 Global Developer Report: DevSecOps": that early adopters of a strong Devops model experience greater security. "Security teams in a longstanding DevOps environment reported they are three times more likely to discover bugs before code is merged," according to the GitLab blog, "and 90% more likely to test between 91% and 100% of code than teams who encounter early-stage DevOps."

But after polling over 4,000 software professionals, the survey also found positive results from another workplace arrangement, which they report under the headline "Remote work works." According to our survey respondents, working remotely leads to greater collaboration, better documentation, and transparency.

In fact, developers in a mostly remote environment are 23% more likely to have good insight into what colleagues are working on and rate the maturity of their organization's security practices 29% higher than those who work in a traditional office environment.

Programming

Is There Tension Between Developers and Security Professionals? (zdnet.com) 146

"Everyone knows security needs to be baked into the development lifecycle, but that doesn't mean it is," writes ZDNet, reporting on a new survey they say showed that "long-standing friction between security and development teams remain."

The results came from GitLab's "2019 Global Developer Report: DevSecOps" survey of over 4,000 software professionals. Nearly half of security pros surveyed, 49%, said they struggle to get developers to make remediation of vulnerabilities a priority. Worse still, 68% of security professionals feel fewer than half of developers can spot security vulnerabilities later in the life cycle. Roughly half of security professionals said they most often found bugs after code is merged in a test environment.

At the same time, nearly 70% of developers said that while they are expected to write secure code, they get little guidance or help. One disgruntled programmer said, "It's a mess, no standardization, most of my work has never had a security scan." Another problem is it seems many companies don't take security seriously enough. Nearly 44% of those surveyed reported that they're not judged on their security vulnerabilities.

ZDNet also cites Linus Torvalds' remarks on the Linux kernel mailing list in 2017, complaining about how security people celebrate when code is hardened against an invalid access. "[F]rom a developer standpoint, things really are not done. Not even close. From a developer standpoint, the bad access was just a symptom, and it needs to be reported, and debugged, and fixed, so that the bug actually gets corrected. So from a developer standpoint, the end point of hardening is just the starting point, and when you think you're done, we're really only getting started."

Torvalds then pointed out that the user community also has a third set of entirely different expectations, adding that "the number one rule of kernel development is that 'we don't break users'. Because without users, your program is pointless, and all the development work you've done over decades is pointless... and security is pointless too, in the end." Juggling the interest of users and developers, Torvalds suggests security people should adopt "do no harm" as their mantra, and "when adding hardening features, the first step should *ALWAYS* be 'just report it'. Not killing things, not even stopping the access. Report it. Nothing else."
Security

Microsoft Warns of Political Cyberattacks, Announces Free Vote-Verification Software (nbcnews.com) 67

"Microsoft on Wednesday announced that it would give away software designed to improve the security of American voting machines," reports NBC News.

Microsoft also said its AccountGuard service has already spotted 781 cyberattacks by foreign adversaries targeting political organizations -- 95% of which were located in the U.S. The company said it was rolling out the free, open-source software product called ElectionGuard, which it said uses encryption to "enable a new era of secure, verifiable voting." The company is working with election machine vendors and local governments to deploy the system in a pilot program for the 2020 election. The system uses an encrypted tracking code to allow a voter to verify that his or her vote has been recorded and has not been tampered with, Microsoft said in a blog post...

Edward Perez, an election security expert with the independent Open Source Election Technology Institute, said Microsoft's move signals that voting systems, long a technology backwater, are finally receiving attention from the county's leading technical minds. "We think that it's good when a technology provider as significant as Microsoft is stepping into something as nationally important as election security," Perez told NBC News. "ElectionGuard does provide verification and it can help to detect attacks. It's important to note that detection is different from prevention."

Microsoft also said its notified nearly 10,000 customers that they've been targeted or compromised by nation-state cyberattacks, according to the article -- mostly from Russia, Iran, and North Korea.

"While many of these attacks are unrelated to the democratic process," Microsoft said in a blog post, "this data demonstrates the significant extent to which nation-states continue to rely on cyberattacks as a tool to gain intelligence, influence geopolitics, or achieve other objectives."
Privacy

Is Russia Trying to Deanonymize Tor Traffic? (zdnet.com) 85

A contractor for Russia's intelligence agency suffered a breach, revealing projects they were pursuing -- including one to deanonymize Tor traffic.

An anonymous reader shared this report from ZDNet: The breach took place last weekend, on July 13, when a group of hackers going by the name of 0v1ru$ hacked into SyTech's Active Directory server from where they gained access to the company's entire IT network, including a JIRA instance. Hackers stole 7.5TB of data from the contractor's network, and they defaced the company's website with a "yoba face," an emoji popular with Russian users that stands for "trolling..." Per the different reports in Russian media, the files indicate that SyTech had worked since 2009 on a multitude of projects.
In February ZDNet reported that Russia disconnected itself from the rest of the internet in a test -- and suggests today that it was a real-world test of one of these leaked "secret projects" from the Russian intelligence agency. But the other projects include:
  • Nautilus-S - a project for deanonymizing Tor traffic with the help of rogue Tor servers.
  • Nautilus - a project for collecting data about social media users (such as Facebook, MySpace, and LinkedIn).
  • Reward - a project to covertly penetrate P2P networks, like the one used for torrents.
  • Mentor - a project to monitor and search email communications on the servers of Russian companies.
  • Tax-3 - a project for the creation of a closed intranet to store the information of highly-sensitive state figures, judges, and local administration officials, separate from the rest of the state's IT networks.

ZDNet also reports that the Tor-deanonymizing project, started in 2012, "appears to have been tested in the real world," citing a 2014 paper which found 18 malicious Tor exit nodes located in Russia.

Each of those hostile Russian exit nodes used version 0.2.2.37 of Tor -- the same one described in these leaked files.


Security

QuickBooks Cloud Hosting Firm iNSYNQ Hit In Ransomware Attack (krebsonsecurity.com) 30

Cloud hosting provider iNSYNQ says it was hit with a ransomware attack that shut down its network and left customers unable to access their accounting data for the past three days. "Unfortunately for iNSYNQ, the company appears to be turning a deaf ear to the increasingly anxious cries from its users for more information about the incident," reports Krebs On Security." From the report: Gig Harbor, Wash.-based iNSYNQ specializes in providing cloud-based QuickBooks accounting software and services. In a statement posted to its status page, iNSYNQ said it experienced a ransomware attack on July 16, and took its network offline in a bid to contain the spread of the malware. "The attack impacted data belonging to certain iNSYNQ clients, rendering such data inaccessible,"; the company said. "As soon as iNSYNQ discovered the attack, iNSYNQ took steps to contain it. This included turning off some servers in the iNSYNQ environment." iNSYNQ said it has engaged outside cybersecurity assistance and to determine whether any customer data was accessed without authorization, but that so far it has no estimate for when those files might be available again to customers.
Security

My Browser, the Spy: How Extensions Slurped Up Browsing Histories From 4M Users (arstechnica.com) 43

Dan Goodin, reporting for ArsTechnica: When we use browsers to make medical appointments, share tax returns with accountants, or access corporate intranets, we usually trust that the pages we access will remain private. DataSpii, a newly documented privacy issue in which millions of people's browsing histories have been collected and exposed, shows just how much about us is revealed when that assumption is turned on its head. DataSpii begins with browser extensions -- available mostly for Chrome but in more limited cases for Firefox as well -- that, by Google's account, had as many as 4.1 million users. These extensions collected the URLs, webpage titles, and in some cases the embedded hyperlinks of every page that the browser user visited. Most of these collected Web histories were then published by a fee-based service called Nacho Analytics, which markets itself as "God mode for the Internet" and uses the tag line "See Anyone's Analytics Account."

Web histories may not sound especially sensitive, but a subset of the published links led to pages that are not protected by passwords -- but only by a hard-to-guess sequence of characters (called tokens) included in the URL. Thus, the published links could allow viewers to access the content at these pages. (Security practitioners have long discouraged the publishing of sensitive information on pages that aren't password protected, but the practice remains widespread.)
Further reading: More on DataSpii: How extensions hide their data grabs -- and how they're discovered.
Security

A Rust-Based TLS Library Outperformed OpenSSL in Almost Every Category (zdnet.com) 213

A tiny and relatively unknown TLS library written in Rust, an up-and-coming programming language, outperformed the industry-standard OpenSSL in almost every major category. From a report: The findings are the result of a recent four-part series of benchmarks carried out by Joseph Birr-Pixton, the developer behind the Rustls library. The findings showed that Rustls was 10% faster when setting up and negotiating a new server connection, and between 20 and 40% faster when setting up a client connection. But while handshake speeds for new TLS connections are important, most TLS traffic relies on resuming previously negotiated handshakes. Here, too, Rustls outperformed the aging OpenSSL, being between 10 and 20% in resuming a connection on the server-side, and being between 30 and 70% quicker to resume a client connection. Furthermore, Rustls also fared better in sheer bulk performance -- or the speed at which data is transferred over the TLS connection. Birr-Pixton said Rustls could send data 15% faster than OpenSSL, and receive it 5% faster as well.

Slashdot Top Deals