Security

When Myspace Was King, Employees Abused a Tool Called 'Overlord' To Spy on Users (vice.com) 45

During the social network's heyday, multiple Myspace employees abused an internal company tool to spy on users, in some cases including ex-partners, Motherboard reported on Monday. From the report: Named 'Overlord,' the tool allowed employees to see users' passwords and their messages, two former employees said. While the tool was originally designed to help moderate the platform and allow MySpace to comply with law enforcement requests, multiple sources said the tool was used for illegitimate purposes by employees who accessed Myspace user data without authorization to do so. "It was basically an entire backdoor to the Myspace platform," one of the former employees said of Overlord. (Motherboard granted five former Myspace employees anonymity to discuss internal Myspace incidents.) The abuse happened about a decade ago, closer to the height of the platform's popularity, according to multiple sources. In fall 2006, the platform signed up its 100 millionth user. Around this time, Myspace was the second most popular website in the U.S., and ranked higher than Google search. Further reading: MySpace Has Reportedly Lost All Photos, Videos and Songs Uploaded Over 12 Years Due To Data Corruption During a Server Migration Project (March, 2019).
United States

US Launches Cyber-Attack Aimed At Iranian Rocket and Missile Systems (zdnet.com) 141

The US has responded to a recent rise in Iranian cyber-activity and the shooting of an unarmed drone last week by launching cyber-attacks against Iran's military IT systems. From a report: The cyber-attacks were carried out by US Cyber Command with the direct approval of US President Donald Trump, the Associated Press reported on Sunday, citing two inside sources, and confirming the report through a third Pentagon official. US Cyber Command targeted the Iran military's computer systems used to control some of the country's rocket and missile launchers. The systems are managed by Iran's Islamic Revolutionary Guard Corps (IRGC), a branch of Iran's Armed Forces, which the US Presidency designated as a terrorist organization last year. The AP reported that the US cyber-attacks were the second go-to measure after President Trump backed off from launching a military strike against Iranian military and radar bases last week, on Thursday.
Microsoft

Microsoft's New Windows Terminal Is Now Available (howtogeek.com) 115

You can now download a preview version of the new Windows Terminal app from the Store on Windows 10. From a report: Microsoft released this application on the evening of June 21 after a listing showed up earlier that day. After downloading the Windows Terminal app from the Store, you can take advantage of all the new features-- including tabs, finally! You can combine tabs from the traditional Command Prompt, Linux Bash instances, and PowerShell in the same window. It's a deeply customizable environment, too.
IOS

Apple Releases First Public Betas of macOS Catalina, iOS 13 and iPadOS 61

Apple today seeded the first beta versions of upcoming macOS Catalina update, iOS 13 update, and iPadOS update to its public beta testing group, giving non-developers a chance to try out the software ahead of their fall public release. Beta testers who have signed up for Apple's beta testing program will be able to download the macOS Catalina beta through the Software Update mechanism in System Preferences after installing the proper profile. Those who want to be a part of Apple's beta testing program can sign up to participate through the beta testing website, which gives users access to iOS, macOS, and tvOS betas. Similarly, beta testers who have signed up for Apple's beta testing program will receive the iOS 13 beta update over-the-air after installing the proper certificate on an iOS device. New features in macOS Catalina update includes: macOS Catalina eliminates the iTunes app, which has been a key Mac feature since 2001. In Catalina, iTunes has been replaced by Music, Podcasts, and TV apps. The new apps can do everything that iTunes can do, so Mac users aren't going to be losing any functionality, and device management capabilities are now handled by the Finder app. macOS Catalina has a useful new Sidecar feature, designed to turn the iPad into a secondary display for the Mac. For those with an Apple Watch set up to unlock the Mac, there's now an option to approve security prompts in Catalina by tapping on the side button of the watch. Macs with a T2 chip in them also support Activation Lock, making them useless to thieves much as it does on the iPhone. There's a new Find My app that lets you track your lost devices, and previously, this functionality was only available via iCloud on the Mac. There's even a new option to find your devices even when they're offline by leveraging Bluetooth connections to other nearby devices, something that's particularly handy on the Mac because it doesn't have a cellular connection. For developers, a "Project Catalyst" feature lets apps designed for the iPad be ported over to the Mac with just a few clicks in Xcode and some minor tweaks. Apple's ultimate goal with Project Catalyst is to bring more apps to the Mac.
Communications

Dutch Telephone Outage Takes Out Nation's Emergency Number (go.com) 24

A major telephone outage hit the Netherlands on Monday, taking down the country's emergency number and leaving many businesses and municipalities unreachable by phone. From a report: Police sent officers onto the streets so that people could approach them for emergency help and issued an alternative emergency phone number an hour after the outage began around 4 p.m. (1400 GMT). "We're appealing to everybody who wants to report an emergency and needs help to ... go onto the street. Police officers with walkie-talkies are taking to the streets as much as possible so they can be spoken to," police spokeswoman Suzanne van de Graaf told national broadcaster NOS. Telecom provider KPN reported on its website that the nationwide outage affected both landlines and mobile services. It said work was underway to find a solution.
IT

USB Inventor Regrets Making Them So Difficult To Plug in Correctly (mashable.com) 289

An anonymous reader shares a report: While plugging plug a mouse, a phone, or a thumb drive into your computer, you try to stick the USB into its slot, only to find it stopping prematurely. You flip it around, but it still won't go in. So you flip it back to the original position and it slides in without a hitch. We've all been there, and the inventor of the USB sees our pain. Ajay Bhatt, the leader behind the IBM team that gave us the USB in the mid-'90s, revealed in an interview with NPR Friday that he is well aware of the annoyances the public has with USB, or Universal Serial Bus, but there's a reason it's designed the way it is.

"The biggest annoyance is reversibility," Bhatt told NPR. For outsiders, it seems like designing the USB so it can be reversible would be an easy fix to everyone's problems, so no matter which way you stick it in it's a success. Bhatt told NPR that would have doubled the cost of the technology, requiring double the wires and circuits. Another option that the Intel team floated was a round design, but that would have been even more difficult to plug in correctly. Although the rectangle design we all know was ultimately chosen and adopted by pretty much every hardware manufacturer since Apple first put USB ports into its computers in 1998, Bhatt acknowledges that there may have been a better way. "In hindsight, based on all the experiences that we all had, of course it was not as easy as it should be," Bhatt said.

Education

Amazonians Visit High Schools To Inspect the Amazon Future Engineer Troops (washingtonian.com) 92

theodp writes: Amazon Future Engineer students across the country are graduating from high school," reports the Amazon Day One blog, "and to celebrate, Amazonians visited select classrooms to meet some of the students and to check out their impressive computer science progress and end of year projects [TV coverage of an 'Amazon graduation'].

Amazon Future Engineer "is a four-part, childhood-to-career program aimed at inspiring and educating 10 million students from underrepresented and underserved communities each year to try computer science and coding. Amazon strives to achieve this by inspiring millions of children through coding camps and Code.org's Hour of Code program, funding computer science courses in high schools across the country, providing 100 students with four-year college scholarships in computer science, and offering Amazon internships to scholarship recipients."

The importance of CS education to Amazon is highlighted in a new Washingtonian story, The Real Story of How Virginia Won Amazon's HQ2, which reports, "Northern Virginia's ultimate proposal was centered around an effort to provide Amazon -- or any other tech firm that wanted to come -- with all the educated workers it needed, now and in the future. [Virginia Economic Development Partnership CEO Stephen] Moret's team proposed increasing tech education from kindergarten through 12th grade, expanding university offerings to produce up to 17,500 new bachelor's degrees in computer science and related fields, and building a tech campus that could produce the same number of master's degrees."

And in a recent Brookings Institution fireside chat, Moret noted, "we analyzed substantially all of the LinkedIn profiles of HQ1 — the Seattle workforce... And if you look at the tech occupations — that was the space they were the most concerned about — literally half of all the people at Amazon Seattle headquarters that are working in some kind of tech occupation, half of them have at least one degree in computer science. So, that was a really big data point for us; and that really shaped a lot of how we built our package.

Security

The Threat Actor You Can't Detect: Cognitive Bias (securityledger.com) 88

Long-time Slashdot reader chicksdaddy shares news of a recent report from cybersecurity company Forcepoint's X-Lab, examining how cybersecurity decision-making is affected by six common biases: For instance, Forcepoint found that older generations are typically characterized by information security professionals as "riskier users based on their supposed lack of familiarity with new technologies." However, studies have found the opposite to be true: younger people are far more likely to engage in risky behavior like sharing their passwords to streaming services. The presumption that older workers pose more of a risk than younger workers is an example of so-called "aggregate bias," in which subjects make inferences about an individual based on a population trend. Biases like this misinform security professionals by directing their focus to individual users based on their supposed group membership. In turn, analysts wrongly direct their focus to the wrong individuals as sources of security issues.

Availability bias may influence cybersecurity analysts' decision-making in favor of hot topics in the news, which ultimately cloud other information they may know but are not so frequently exposed to; leading them to make less well-rounded decisions. People encounter "confirmation bias" most frequently during research. By neglecting the bigger picture, assumptions are made and research is specifically tailored to confirm those assumptions. When looking for issues, analysts can often find themselves looking for confirmation of what they already believe to be the cause as opposed to searching for all possible causes.

The fundamental attribution error also plays a significant role in misleading security analysts, Forcepoint found. This is manifested when information security analysts or software developers place blame on users being inept instead of considering that their technology may be faulty or that internal factors contributed to a security lapse.

The report also cites what it calls the framing effect. "Security problems are often aggressively worded, and use negative framing strategies to emphasize the potential for loss."
Education

America's NSA Challenges Students With A Codebreaking Competition, Then Recruits Them (federalnewsnetwork.com) 51

This year America's National Security Agency (NSA) is once again "developing a cyber challenge and daring more than 330 schools and 2,600 students to solve it," writes Federal News Network.

Slashdot reader eatvegetables shares their report: Kathy Hutson, the senior strategist for industry and academic engagement at the NSA, said the Codebreaker Challenge has become one of the best ways to attract the next generation of talent to the federal government... NSA launched the Codebreaker Challenge in 2013 as a way to further connect with students and professors, who are focused on technology and cyber issues. Over the last six years, the annual initiative has become a much-anticipated challenge with professors making it a part of their classes and students testing their mettle against NSA's cyber experts...

The initiative provides students, professors and anyone else who is interested "with a hands-on opportunity to develop their reverse-engineering /low-level code analysis skills while working on a realistic problem set centered around the NSA's mission," said Eric Bryant, a technical director in the crypto analysis organization at the NSA. The 2018 challenge focused on ransomware and blockchain, requiring participants to solve eight separate, but related challenges... Bryant said a group of NSA cyber experts develop the challenge each year on top of their regular duties. He said they try to focus on areas that are either up-and-coming or current cyber threats and attack vectors. For the 2019 Codebreaker Challenge, Bryant said it likely will focus on mobile security threats, probably using an Android operating system...

Bryant said he reaches out to all of the students who solve the challenge and NSA sends them letters of recognition and a memento for participating. "We reach out to these students to figure out what year they are in, how could they come here to do internships or hire them full-time, so we are definitely on that from a hiring and recruitment perspective," Hutson said.
The NSA keeps a leaderboard ranking the participating colleges. (Last year Oregon State had over 100 students participating.)

The 2018 challenge is still online, Bryant says, "and there are people who are working and submitting solutions."
Microsoft

Microsoft Puts Slack On Internal List of 'Prohibited and Discouraged' Software (geekwire.com) 139

PolygamousRanchKid shares a report: GeekWire obtained an internal Microsoft list of prohibited and discouraged technology -- software and online services that the company doesn't want its employees using as part of their day-to-day work. We first picked up on rumblings of the prohibition from Microsoft employees who were surprised that they couldn't use Slack at work, before tracking down the list and verifying its authenticity. While the list references the competitive nature of these services in some situations, the primary criteria for landing in the "prohibited" category are related to IT security and safeguarding company secrets.

Slack is on the "prohibited" category of the internal Microsoft list, along with tools such as the Grammarly grammar checker and Kaspersky security software. Services in the "discouraged" category include Amazon Web Services, Google Docs, PagerDuty and even the cloud version of GitHub, the popular software development hub and community acquired by Microsoft last year for $7.5 billion...

"It's not just the risk that Google will try to find trade secrets from data stored on their servers," said Christopher Budd, who has worked in security technology for 20 years, including past roles in Microsoft security and privacy communications. "When you're at Microsoft, you're at risk of state sponsored industrial espionage."

The article notes that in the past Microsoft adopted an even harsher stance to employees using competing products. "At a company meeting during his tenure as CEO, Steve Ballmer once famously snatched an iPhone from an employee and pretended to stomp on it..."

But GeekWire also argues that Microsoft's prohibiting of a popular chat tool "can have implications in a competitive recruiting environment."
The Military

Iran Steps Up Cyberattacks Against America (marketwatch.com) 216

An anonymous reader quotes MarketWatch: Iran has increased its offensive cyberattacks against the U.S. government and critical infrastructure as tensions have grown between the two nations, cybersecurity firms say.

In recent weeks, hackers believed to be working for the Iranian government have targeted U.S. government agencies, as well as sectors of the economy, including oil and gas, sending waves of spear-phishing emails, according to representatives of cybersecurity companies CrowdStrike and FireEye, which regularly track such activity. It was not known if any of the hackers managed to gain access to the targeted networks...

"Both sides are desperate to know what the other side is thinking," said John Hultquist, director of intelligence analysis at FireEye. "You can absolutely expect the regime to be leveraging every tool they have available to reduce the uncertainty about what's going to happen next, about what the U.S.'s next move will be...."

According to the article, one of the phishing emails "appeared to come from the Executive Office of the President and seemed to be trying to recruit people for an economic adviser position.

"Another email was more generic and appeared to include details on updating Microsoft Outlook's global address book."
IT

Will Hot-Desking Kill Your Company? (forbes.com) 280

"If you hate your company, its employees and the shareholders then go ahead and introduce the latest management fad: Hot-desking," writes Forbes contributor Simon Constable. "It's a better way to destroy the firm than inviting Russian hackers to rob you blind.

"The bigger the company, the faster the damage will occur with hot-desking."

Hot-desking is a working arrangement where employees have no assigned desk. Each morning you get a workstation based on that old standby, first-come-first-served. If you show up at 5:30 a.m. then you'll likely have your pick. Later than 9 a.m., then probably you'll get what's left even if that means working apart from your colleagues. The theory behind this idea is that it provides companies with increased flexibility in managing office space. With some exceptions, the drawbacks vastly outweigh any benefits.

I know this having witnessed decades in corporate jobs, including a role at one employer that implemented such idiocy. It sends the message that employees don't matter. Employers frequently say their employees are their biggest asset. But when the company can't even be bothered to let you have a permanent desk, then the opposite message is sent.

He cites other more specific problems -- like the fact that no one can easily find anyone, making it harder to hold quick impromptu discussions or ask for help. And it also becomes harder to explain to employees why they can't just work from home.

The article concedes hot-desking "probably works just fine" for small companies with just a handful of employees. But "the bigger the firm the larger the inefficiency that is caused. A company of 50 people might see only minor problems from hot-desking, while one of 50,000 will likely see massive dysfunction throughout the institution..."

"If you see a public company introducing hot desks as a way to add flexibility or save money across the board, then be afraid for investors. Why? Because the profits quickly suffer in a dysfunctional company."
The Internet

Should Slack-Like Chat Clients Replace Email? (indiatimes.com) 164

This week the New York Times' Style section asked an interesting question. "Slack wants to replace email. Is that what we want?" The company says it has 88,000 paying customers -- a sliver of a sliver of the world's desk-and-phone-bound office workers, and fewer than work full time at, for example, Google's parent company, Alphabet. Speaking of Google, the company has a Slack alternative of its own, called Hangouts Chat, as does Facebook, in Workplace. Microsoft has Teams, which is bundled with its Office software and which the company says is being used by more than 500,000 organizations. This multifront attack on email is just beginning, but a wartime narrative already dominates: The universally despised office culture of replies and forwards and mass CCs and "looping in" and "circling back" is on its way out, and it's going to be replaced by chat apps. So what happens if they actually win...?

For the right office, it's a huge relief to chat. "I know for the engineering team it's a game-changer," said Shannon Todesca, an employee at CarGurus, an automotive shopping site. "It's used to keep track of code pushes," she said, as well as system errors. Workers also report dentist appointments and sick days to the #ooo (out of office) channel, preventing inboxes from getting clogged, or an early heads-up from getting lost. At Automattic, which runs Wordpress.com and a handful of smaller internet services, Slack is the glue that binds a fully remote "virtual office" of nearly 1,000 employees living in dozens of countries and working on vastly different products...

Rank-and-file employees were more likely to share concerns about the new era of office chat... Most common were mixed feelings, often related to privacy and productivity. "We've had to consciously discuss using Slack less often," said Lacey Berrien, who works at marketing startup Drift. "I had our IT team check a few weeks ago, and we were up to over 950 Slack channels," she said, "and that doesn't count the private ones...." I have also spent the last 10 years at companies where work chat was the norm and observed the arrival of Slack with both relief and suspicion. Finally, a better work chat app. Then: Oh god, this is really how people are going to work, now?

I remember using chat logs to trace back the discussions that led to buggy programs. (Though obviously you can do the same thing with archived emails.) So I'd be interested to hear how Slashdot's readers would answer the question.

Should Slack-like chat clients replace email?
NASA

NASA Hacked Because of Unauthorized Raspberry Pi Connected To Its Network 134

An anonymous reader quotes a report from ZDNet: A report published this week by the NASA Office of Inspector General reveals that in April 2018 hackers breached the agency's network and stole approximately 500 MB of data related to Mars missions. The point of entry was a Raspberry Pi device that was connected to the IT network of the NASA Jet Propulsion Laboratory (JPL) without authorization or going through the proper security review. NASA described the hackers as an "advanced persistent threat," a term generally used for nation-state hacking groups.
Security

Emergency Presidential Alert Texts Could Be Faked, Researchers Say (cnet.com) 36

Fake presidential alerts could be sent to tens of thousands of phones, according to a report out of the University of Colorado Boulder. From a report: Researchers say they found a backdoor that let them mimic alerts and blast fake messages to people confined to a small area, such as a city block or a sports stadium. The researchers developed software mimicking the presidential alert format and then used commercially available wireless transmitters to send the messages to phones within their radius. The team had a success rate of hitting 90% of all phones in the area it tested.
Operating Systems

Millions of Dell PCs Vulnerable To Flaw In Pre-Installed Software (threatpost.com) 30

secwatcher shares a report from Threatpost: Millions of PCs made by Dell and other OEMs are vulnerable to a flaw stemming from a component in pre-installed SupportAssist software. The flaw could enable a remote attacker to completely takeover affected devices. The high-severity vulnerability (CVE-2019-12280) stems from a component in SupportAssist, a proactive monitoring software pre-installed on PCs with automatic failure detection and notifications for Dell devices. That component is made by a company called PC-Doctor, which develops hardware-diagnostic software for various PC and laptop original equipment manufacturers (OEMs). A patch has been issued by PC-Doctor that fixes impacted devices. Impacted customers can find the latest version of SupportAssist here (for single PC users) or here (for IT managers).
Canada

Desjardins Data Breach Affecting 2.9 Million Members Caused By Employee Who's Since Been Fired (straight.com) 27

Freshly Exhumed shares a report from The Georgia Straight: The Quebec-based Desjardins Group has admitted to being victimized by one of the largest data breaches in Canadian history. Laval police informed the financial-services giant that personal information of more than 2.9 million members has been shared with people outside of the organization. This includes 2.7 million people and 173,000 businesses. "This situation is the outcome of unauthorized and illegal use of our internal data by an employee who has since been fired," Desjardins said in a statement. "In light of these events, and given the circumstances, additional security measures were put in place on all accounts." Desjardins, which is the largest federation of credit unions in North America, will be informing people by letters if they've been affected. The leaked data included first and last names, birthdates, social insurance numbers, addresses, phone numbers, email addresses, and details about banking habits. However, passwords, security questions, and PINs were not disclosed.
Books

Prisons Are Banning Books That Teach Prisoners How To Code (vice.com) 193

An anonymous reader quotes a report from Motherboard: The Oregon Department of Corrections has banned prisoners from reading a number of books related to technology and programming, citing concerns about security. According to public records obtained by the Salem Reporter, the Oregon Department of Corrections has banned dozens of books related to programming and technology as they come through the mail room, ensuring that they don't get to the hands of prisoners. At least in official department code, there is no blanket ban on technology-related books. Instead, each book is individually evaluated to assess potential threats. Many programming-related books are cited as "material that threatens," often including the subject matter ("computer programming") as justification. The Oregon Department of Corrections (DOC) worries that prisoners could use the tools mentioned in some of the programming-related books to compromise their systems. But what's odd is the scope of the ban. Justin Seitz's Black Hat Python book failed the prison's security test since it's geared towards hacking, but so did the book Windows 10 for Dummies, Microsoft Excel 16 for Dummies which simply teaches proficiency in Excel and Windows 10.

Officials at the DOC argue that knowledge of even these basic programs can pose a threat to prisons. "Not only do we have to think about classic prison escape and riot efforts like digging holes, jumping fences and starting fires, modernity requires that we also protect our prisons and the public against data system breaches and malware," DOC spokesperson Jennifer Black said in an emailed statement. "It is a balancing act we are actively trying to achieve."
Security

WeTransfer Shared Its Users' Files With the Wrong People (betanews.com) 24

WeTransfer, a popular online service to transfer and share files, has informed some of its customers of a security incident that resulted in it sharing emails with download links to wrong recipients. BetaNews reports: In the email to customers, WeTransfer said: "We are writing to let you know about a security incident in which a number of WeTransfer service emails were sent to the wrong people. This happened on June 16th and 17th. Our team has been working tirelessly to correct and contain this situation and find out how it happened. We have learned that a transfer you sent or received was also delivered to some people it was not meant to go to. Our records show those files have been accessed, but almost certainly by the intended recipient. Nevertheless, as a precaution we blocked the link to prevent further downloads.
Security

Gmail Confidential Mode is Neither Secure Nor Private (protonmail.com) 67

Even though Google launched confidential mode over a year ago, people are still confused about what it does. Is it actually secure or private? Is it encrypted? From a report: When you turn it on, does it prevent Google from reading your messages? The answer to these questions is 'no.' In fact, the decision to call it "confidential" suggests a level of security and privacy that doesn't exist in Gmail confidential mode. Gmail's confidential mode does not mean your messages are end-to-end encrypted. Google can still read them. Expiring messages aren't erased for good, and the recipient can always take a screenshot of your message.

Gmail's confidential mode does not make emails private because Google can always read them. When you send an email with confidential mode turned on, Google keeps the email contents on its servers. Other Gmail users can read the email in their inbox, but outside users only receive an email notifying them that a sender "has sent you an email via Gmail confidential mode" along with a link to a page on google.com.

Slashdot Top Deals