Government

Cellebrite Says It Can Unlock Any iPhone For Cops (wired.com) 132

An anonymous reader quotes a report from Wired: On Friday afternoon, the Israeli forensics firm and law enforcement contractor Cellebrite publicly announced a new version of its product known as a Universal Forensic Extraction Device or UFED, one that it's calling UFED Premium. In marketing that update, it says that the tool can now unlock any iOS device cops can lay their hands on, including those running iOS 12.3, released just a month ago. Cellebrite claims UFED Premium can extract files from many recent Android phones as well, including the Samsung Galaxy S9. No other law enforcement contractor has made such broad claims about a single product, at least not publicly. The move signals not only another step in the cat and mouse game between smartphone makers and the government-sponsored firms that seek to defeat their security, but also a more unabashedly public phase of that security face-off. "Cellebrite is proud to introduce #UFED Premium! An exclusive solution for law enforcement to unlock and extract data from all iOS and high-end Android devices," the company wrote on its Twitter feed for the UFED product. On a linked web page, the company says the new tool can pull forensic data off any iOS device dating back to iOS 7, and Android devices not just from Samsung but Huawei, LG, and Xiaomi.
Firefox

Avast and AVG Are Causing Firefox Users To Lose Saved Passwords (betanews.com) 90

An anonymous reader shares a report: Firefox users are reporting that their saved passwords have been lost, with the problem seemingly caused by antivirus software rather than being an issue with Firefox itself. Antivirus software such as Avast and AVG appear to be corrupting the file in which Firefox stores passwords, rendering it unreadable. Thankfully, passwords can be recovered, but -- for the time being --- they will be corrupted again when you restart your computer.
Cloud

'The New Dropbox Sucks' (daringfireball.net) 135

Earlier this week, Dropbox introduced a new desktop application that brings a new look to the file-sharing service as well as new capabilities. With this release, Dropbox has changed the underlying structure of its desktop application to operate just like any other desktop application, rather than its previous incarnation, which was tied very closely to desktop file systems like Windows File Explorer or Apple's Finder. Dropbox adds: It's a single workspace to organize your content, connect your tools, and bring everyone together, wherever you are. The first thing you'll notice is an all-new Dropbox desktop app that we're introducing today through our early access program. It's more than an app, though -- it's a completely new experience. That all sounds great, until you attempt to use it. John Gruber, writing for Daring Fireball: I don't want any of this. All I want from Dropbox is a folder that syncs perfectly across my devices and allows sharing with friends and colleagues. That's it: a folder that syncs with sharing. And that's what Dropbox was. Now it's a monstrosity that embeds its own incredibly resource-heavy web browser engine. In a sense Steve Jobs was right -- the old Dropbox was a feature not a product. But it was a feature well-worth paying for, and which made millions of people very happy.
IT

Microsoft Edge Might Come To Linux (zdnet.com) 146

The Microsoft Edge developer team held an AMA (Ask Me Anything) session on Reddit this week where they revealed some of their plans on current and upcoming features. From a report: The biggest tease the company dropped was its apparent willingness to release an Edge version for Linux -- a move that was once considered inconceivable. "We don't have any technical blockers to keep us from creating Linux binaries, and it's definitely something we'd like to do down the road. That being said, there is still work to make them 'customer ready' (installer, updaters, user sync, bug fixes, etc.) and something we are proud to give to you, so we aren't quite ready to commit to the work just yet. Right now, we are super focused on bringing stable versions of Edge first to other versions of Windows (as well as macOS), and then releasing our Beta channels," Edge devs said.
Security

Lessons From 5 Years of Free Cybersecurity For At-Risk Groups (axios.com) 41

Cloudflare's Project Galileo, which offers free high-tier DDoS protection service to journalists, dissidents, civil liberties groups and other at-risk groups, turned 5 years old this week. From a report: The project currently serves over 600 accounts. An LGBT protection group in the Middle East, for example, does important work on a shoestring budget and cannot possibly afford to block the outsized number of attacks it could face from governments and even citizens. Project Galileo isn't the only commercial cybersecurity service offered to at-risk groups, but it is one of the first and the most successful. "Project Galileo originally started from a failure to live up to what was originally our mission to make a better internet," Cloudflare CEO Matthew Prince told Codebook. Further reading: Cloudflare's Five-Year Project to Protect Nonprofits Online (Wired).
Security

Yubico To Replace Vulnerable YubiKey FIPS Security Keys (zdnet.com) 19

Yubico said today it plans to replace certain hardware security keys because of a firmware flaw that reduces the randomness of cryptographic keys generated by its devices. From a report: Affected products include models part of the YubiKey FIPS Series, a line of YubiKey authentication keys certified for use on US government networks (and others) according to the US government's Federal Information Processing Standards (FIPS). According to a Yubico security advisory published today, YubiKey FIPS Series devices that run firmware version 4.4.2 and 4.4.4 contain a bug that keeps "some predictable content" inside the device's data buffer after the power-up operation.

This "predictable content" will influence the randomness of cryptographic keys generated on the device for a short period after the boot-up, until the "predictable content" is all used up, and true random data is present in the buffer. This means that for a short period after booting up YubiKey FIPS Series devices with the affected 4.4.2 and 4.4.4 versions will generate keys that can be either recovered partially, or in full, depending on the cryptographic algorithm the key is working with for a particular authentication operation.

HP

IT Pro Screwed Out of Unused Vacation Pay, Bonus By HPE Thanks To Outdated Law (theregister.co.uk) 229

Slashdot reader Meg Whitman shares a report from The Register: A "highly skilled IT professional" has lost his fight to be paid his unused vacation days as well as a non-trivial bonus, after a judge stuck to a law he admitted was outdated. Matthew White joined Hewlett-Packard in 2013 and left in July 2015, just months before the company split into HP and Hewlett Packard Enterprise (HPE). After quitting, he was stunned when the U.S. mega-corp, citing HPE's new policies, refused to hand over extra pay he felt was contractually due. Hewlett-Packard had enticed White with a sweet contract that offered a signing bonus, base salary, regular bonuses, and a benefits program. But after he quit, he was left without his unused vacation pay and a $10,000 bonus he felt he was entitled to. [...]

HPE decided that, under the law, White could only get hold of the relevant policies if he turned up, in person, to the company's official human resources headquarters -- which is on the other side of America in California, roughly 2,500 miles away. White felt this was ridiculous given that HP, sorry, HPE is not only a massive organization with HR people all over the United States, but that it was a technology company with countless employees working across the world, often at home, and that the policies are likely readily available in an internal cloud. The judge had some sympathy for that view. "This part of the statute may indeed need reworking for today's world where cloud-based digital records are replacing physical file folders located in a physical location, where employees work at home -- sometimes remotely from any head office or regional office -- and where worldwide companies like HP assign HP personnel for an entire country or region, or even outsource various HP responsibilities." Yet the judge still decided against the techie.

Privacy

Facebook Collected Device Data On 187,000 Users Using Banned Snooping (techcrunch.com) 45

Facebook obtained personal and sensitive device data on about 187,000 users of its now-defunct Research app, which Apple banned earlier this year after the app violated its rules. TechCrunch reports: The social media giant said in a letter to Sen. Richard Blumenthal's office -- which TechCrunch obtained -- that it collected data on 31,000 users in the U.S., including 4,300 teenagers. The rest of the collected data came from users in India. "We know that the provisioning profile for the Facebook Research app was created on April 19, 2017, but this does not necessarily correlate to the date that Facebook distributed the provisioning profile to end users," said Timothy Powderly, Apple's director of federal affairs, in his letter. Facebook said the app dated back to 2016.

These "research" apps relied on willing participants to download the app from outside the app store and use the Apple-issued developer certificates to install the apps. Then, the apps would install a root network certificate, allowing the app to collect all the data out of the device -- like web browsing histories, encrypted messages and mobile app activity -- potentially also including data from their friends -- for competitive analysis. In Facebook's case, the research app -- dubbed Project Atlas -- was a repackaged version of its Onavo VPN app, which Facebook was forced to remove from Apple's App Store last year for gathering too much device data. Just this week, Facebook relaunched its research app as Study, only available on Google Play and for users who have been approved through Facebook's research partner, Applause. Facebook said it would be more transparent about how it collects user data.

Security

Team of American Hackers and Emirati Spies Discussed Attacking The Intercept (theintercept.com) 49

The Intercept: Operatives at a controversial cybersecurity firm working for the United Arab Emirates government discussed targeting The Intercept and breaching the computers of its employees, according to two sources, including a member of the hacking team who said they were present at a meeting to plan for such an attack. The firm, DarkMatter, brought ex-National Security Agency hackers and other U.S. intelligence and military veterans together with Emirati analysts to compromise the computers of political dissidents at home and abroad, including American citizens, Reuters revealed in January. The news agency also reported that the FBI is investigating DarkMatter's use of American hacking expertise and the possibility that it was wielded against Americans.

The campaign against dissidents and critics of the Emirati government, code-named Project Raven, began in Baltimore. A 2016 Intercept article by reporter Jenna McLaughlin revealed how the Maryland-based computer security firm CyberPoint assembled a team of Americans for a contract to hone UAE's budding hacking and surveillance capabilities, leaving some recruits unsettled. Much of the CyberPoint team was later poached by DarkMatter, a firm with close ties to the Emirati government and headquartered just two floors from the Emirati equivalent of the NSA, the National Electronic Security Authority (which later became the Signals Intelligence Agency).

Security

Google Expands Android's Built-in Security Key To iOS Devices (zdnet.com) 39

An anonymous reader shares a report: In April, Google announced a groundbreaking technology that could allow Android users to use their smartphones as hardware security keys whenever logging into Google accounts on their laptops or work PCs. Initially, the technology was made available for Chrome OS, macOS, and Windows 10 devices. Today, Google announced it is expanding this technology to iOS as well. Today's news means that iPhone and iPad users can now use their (secondary) Android smartphones as a security key whenever logging into their Google accounts on an iOS device. The technology works basically the same, as Google explained in April, at the Cloud Next 2019 conference.
IT

Telegram's Description of DDoS Attack is the Best (cnet.com) 117

A distributed denial of service attack may sound like hacker talk, but there's a simple explanation behind it. Secure messaging app Telegram said it had to endure one Wednesday, and it gave an explanation that almost anyone could understand. From a report: Telegram tweeted Wednesday morning that it was dealing with a DDoS attack. The app was down for many users across the globe, according to DownDetector. The downtime period was just a little over an hour, and while it was going on, Telegram explained how a DDoS attack works.

"Imagine that an army of lemmings just jumped the queue at McDonald's in front of you -- and each is ordering a whopper," Telegram tweeted. "The server is busy telling the whopper lemmings they came to the wrong place -- but there are so many of them that the server can't even see you to try and take your order." The tweets then went on to describe how hackers accomplish a DDoS attack. "To generate these garbage requests, bad guys use 'botnets' made up of computers of unsuspecting users which were infected with malware at some point in the past. This makes a DDoS similar to the zombie apocalypse: one of the whopper lemmings just might be your grandpa," the company said in another tweet.

Security

The Biggest Data Breach Archive On the Internet Is For Sale (vice.com) 54

Troy Hunt, the owner and founder of the well-known and respected data breach notification website "Have I Been Pwned," announced today that he's actively looking for a buyer.

"To date, every line of code, every configuration and every breached record has been handled by me alone. There is no 'HIBP team,' there's one guy keeping the whole thing afloat," Hunt wrote. "It's time for HIBP to grow up. It's time to go from that one guy doing what he can in his available time to a better-resourced and better-funded structure that's able to do way more than what I ever could on my own." Motherboard reports: Over the years, Have I Been Pwned has become the repository for data breaches on the internet, a place where users can search for their email address and see whether they have been part of a data breach. It's now also a service where people can sign up to get notified whenever their accounts get breached. It's perhaps the most useful, free, cybersecurity service in the world. Hunt said he's already had informal conversations with some organizations that might be interested in buying the service. Hunt said he's engaged the financial consulting firm KPMG to look for a buyer.

In the post, Hunt shared some staggering numbers that explain just how big Have I Been Pwned has become: 8 billion breached records, nearly 3 million people subscribed to notifications, who have been emailed about a breach 7 million times, 150,000 unique visitors to the site on a normal day, 10 million on an abnormal day. Regardless of who buys the site, Hunt made a series of commitments on the future of Have I Been Pwned: searches should remain free for consumers, the platform should expand and grow, and, finally, he wants to stay involved in some capacity.

Security

'RAMBleed' Rowhammer Attack Can Now Steal Data, Not Just Alter It (zdnet.com) 45

A team of academics from the US, Austria, and Australia, has published new research today detailing yet another variation of the Rowhammer attack. From a report: The novelty in this new Rowhammer variety -- which the research team has named RAMBleed -- is that it can be used to steal information from a targeted device, as opposed to altering existing data or to elevate an attacker's privileges, like all previous Rowhammer attacks, have done in the past. [...] In a research paper [PDF] published today, academics unveiled RAMBleed, the first Rowhammer attack that can actively deduce and steal data from a RAM card. To do this, researchers had to come up and combine different techniques, which, when assembled, would permit a RAMBleed attack to take place.
Bug

WordPress.com VIP Platform Outage Reverts Sites To Default Themes (zdnet.com) 60

An anonymous reader shares a report: Web blog hosting platform WordPress.com is currently facing a significant technical issue that has resulted in premium blogs going down or reverting to using default themes. Impacted sites include major news outlets like BBC America, TechCrunch, 9to5Mac, 9to5Google, VentureBeat, DroneDJ, and Electrek; but also many companies that were using the WordPress.com's VIP offering to host corporate blogs, such as Facebook, the Wikimedia Foundation, and others. Automattic, the company behind the WordPress.com service has admitted to the technical issue in a series of tweets and a blog post from its engineering staff.
Security

Radiohead Release Hours of Hacked MiniDiscs To Benefit Extinction Rebellion (theguardian.com) 117

Radiohead have released a vast collection of unreleased tracks made during the sessions for 1997 album OK Computer, after a MiniDisc archive owned by frontman Thom Yorke was hacked last week by an unnamed person, who reportedly held the recordings to ransom for $150,000. From a report: The band have now made the 18 MiniDisc recordings, most of them around an hour in length, available on Bandcamp for $23. Proceeds will go to climate activists Extinction Rebellion. The band's guitarist Jonny Greenwood confirmed the hack, and said: âoeInstead of complaining -- much -- or ignoring it, we're releasing all 18 hours on Bandcamp in aid of Extinction Rebellion. Just for the next 18 days. So for $23 you can find out if we should have paid that ransom. Never intended for public consumption (though some clips did reach the cassette in the OK Computer reissue) it's only tangentially interesting. And very, very long. Not a phone download." Thom Yorke wrote of the 1.8 gigabyte collection: "It's not v interesting. There's a lot of it 0... as it's out there it may as well be out there until we all get bored and move on."
Privacy

US Customs and Border Protection Says Traveler Photos and License Plate Images Stolen In Data Breach (techcrunch.com) 79

An anonymous reader quotes a report from TechCrunch: U.S. Customs and Border Protection has confirmed a data breach has exposed the photos of travelers and vehicles traveling in and out of the United States. The photos were stolen from a subcontractor's network through a "malicious cyberattack," a CBP spokesperson told TechCrunch in an email. "CBP learned that a subcontractor, in violation of CBP policies and without CBP's authorization or knowledge, had transferred copies of license plate images and traveler images collected by CBP to the subcontractor's company network," said an agency statement. "Initial information indicates that the subcontractor violated mandatory security and privacy protocols outlined in their contract," the statement read. he agency first learned of the breach on May 31. When asked, a spokesperson for CBP didn't say how many photos were taken in the breach or if U.S. citizens were affected. The agency also didn't name the subcontractor. The database that the agency maintains includes traveler images, as well as passport and visa photos. Congress has been notified and the CBP said it is "closely monitoring" CBP-related work by the subcontractor.
Security

Top Voting Machine Maker Reverses Position on Election Security, Promises Paper Ballots (techcrunch.com) 184

Election Systems & Software has championed electronic voting machines in the US. Now it has had a change of heart about the need for paper records of votes. From a report: TechCrunch understands the decision was made around the time that four senior Democratic lawmakers demanded to know why ES&S, and two other major voting machine makers, were still selling decade-old machines known to contain security flaws. ES&S chief executive Tom Burt's op-ed said voting machines "must have physical paper records of votes" to prevent mistakes or tampering that could lead to improperly cast votes. Sen. Ron Wyden introduced a bill a year ago that would mandate voter-verified paper ballots for all election machines. The chief executive also called on Congress to pass legislation mandating a stronger election machine testing program. Burt's remarks are a sharp turnaround from the company's position just a year ago, in which the election systems maker drew ire from the security community for denouncing vulnerabilities found by hackers at the annual Defcon conference.
Cellphones

A Wave of SIM Swapping Attacks Targets Cryptocurrency Users (zdnet.com) 33

"Numerous members of the cryptocurrency community have been hit by SIM swapping attacks over the past week," ZDNet reported Monday, "in what appears to be a coordinated wave of attacks."

SIM swapping, also known as SIM jacking, is a type of ATO (account take over) attack during which a malicious threat actor uses various techniques (usually social engineering) to transfers a victim's phone number to their own SIM card. The purpose of this attack is so that hackers can reset passwords or receive 2FA verification codes and access protected accounts....

[D]espite a period of calm in the first half of the year, a rash of SIM swapping attacks have been reported in the second half of May, and especially over the past week... Some candidly admitted to losing funds, while others said the SIM swapping attacks were unsuccessful because they switched to using hardware security tokens to protect accounts, instead of the classic SMS-based 2FA system.

Bitcoin

How npm Stopped a Malicious Upstream Code Update From Stealing Cryptocurrency (zdnet.com) 40

"If you're a cryptocurrency startup, would you face a huge backlash by hacking your own customers to keep their funds safe if you know that a hacker is about to launch an attack and steal their funds?" asks ZDNet: This is exactly what happened yesterday when the Komodo Platform learned about a backdoor in one of its older wallet apps named Agama. Knowing they had little time to act, the Komodo team said it used the same backdoor to extract users' funds from all impacted wallets and move them to a safe location, out of the hacker's reach.

The tactic paid off, and 8 million Komodo coins and 96 bitcoins, worth nearly $13 million, were taken from users' vulnerable accounts before the hacker could get a chance to abuse the backdoor and steal users' funds... While initially, it did not make any sense for a library with a very limited feature-set to contain such an advanced functionality, after investigating the issue, npm staffers realized they were dealing with a supply-chain attack aimed at another app downstream, which was using the now-backdoored library... The npm team said the malicious code would work as intended and collect Agama wallet app seeds and passphrases, and upload the data to a remote server.

These malicious-payload updates are "becoming more and more popular," according to a post on the official npm blog (a point they later emphasized in a press release).

"After being notified by our internal security tooling of this threat we responded by notifying and coordinating with Komodo to protect their users as well as remove the malware from npm."
Botnet

Large 'GoldBrute' RDP Botnet Hunts For Exposed Servers With Weak Passwords (sans.edu) 16

The Internet Storm Center reports: RDP, the remote desktop protocol, made the news recently after Microsoft patched a critical remote code execution vulnerability (CVE-2019-0708). While the reporting around this "Bluekeep" vulnerability focused on patching vulnerable servers, exposing RDP to the Internet has never been a good idea. Botnets have been scanning for these servers and are using weak and reused passwords to gain access to them.

The latest example of such a botnet is an ongoing malicious campaign we are refering to as "GoldBrute". This botnet is currently brute forcing a list of about 1.5 million RDP servers exposed to the Internet... Each bot will only try one particular username and password per target. This is possibly a strategy to fly under the radar of security tools as each authentication attempt comes from different addresses.

Long-time Slashdot reader UnderAttack writes: Infected systems will retrieve target lists from the command and control server and attempt to brute force credentials against the list, while at the same time looking for more exposed servers. With all the attention spent on patching RDP servers for the recent "BlueKeep" vulnerability, users should also make sure to just not expose RDP in the first place. Even patched, it will still be susceptible to brute forcing.

Slashdot Top Deals