IOS

Apple Agrees To Notify iPhone Users If iOS Updates Will Affect Performance, UK Watchdog Says (cnbc.com) 42

A UK watchdog group said on Wednesday that Apple has agreed to clearly notify consumers if future iOS software updates slow down or change the performance of an iPhone. CNBC reports: The U.K. Competition and Markets Authority investigated the issue after Apple said in early 2018 that it had deliberately slowed down processor speeds through a software update on some iPhones to extend battery life. Public pressure stemming from the revelation forced Apple to provide discounted $29 battery replacements that were cited by the company as one reason iPhone sales last holiday quarter were slower than expected. That program has ended.

"To ensure compliance with consumer law Apple has formally agreed to improve the information it provides to people about the battery health of their phones and the impact performance management software may have on their phones," the U.K. government said on its website. The CMA said that Apple is legally required to tell consumers about the software and battery health, something the company was already doing through software on the iPhone as well as a letter on its website.

Cellphones

Phones Can Now Tell Who Is Carrying Them From Their Users' Gaits (economist.com) 94

PolygamousRanchKid shares an excerpt from a report via The Economist: Most online fraud involves identity theft, which is why businesses that operate on the web have a keen interest in distinguishing impersonators from genuine customers. Passwords help. But many can be guessed or are jotted down imprudently. Newer phones, tablets, and laptop and desktop computers often have beefed-up security with fingerprint and facial recognition. But these can be spoofed. To overcome these shortcomings the next level of security is likely to identify people using things which are harder to copy, such as the way they walk. Many online security services already use a system called device fingerprinting. This employs software to note things like the model type of a gadget employed by a particular user; its hardware configuration; its operating system; the apps which have been downloaded onto it; and other features, including sometimes the Wi-Fi networks it regularly connects through and devices like headsets it plugs into.

LexisNexis Risk Solutions, an American analytics firm, has catalogued more than 4 billion phones, tablets and other computers in this way for banks and other clients. Roughly 7% of them have been used for shenanigans of some sort. But device fingerprinting is becoming less useful. Apple, Google and other makers of equipment and operating systems have been steadily restricting the range of attributes that can be observed remotely. That is why a new approach, behavioral biometrics, is gaining ground. It relies on the wealth of measurements made by today's devices. These include data from accelerometers and gyroscopic sensors, that reveal how people hold their phones when using them, how they carry them and even the way they walk. Touchscreens, keyboards and mice can be monitored to show the distinctive ways in which someone's fingers and hands move. Sensors can detect whether a phone has been set down on a hard surface such as a table or dropped lightly on a soft one such as a bed. If the hour is appropriate, this action could be used to assume when a user has retired for the night. These traits can then be used to determine whether someone attempting to make a transaction is likely to be the device's habitual user.
If used wisely, the report says behavioral biometrics could be used to authenticate account-holders without badgering them for additional passwords or security questions; it could even be used for unlocking the doors of a vehicle once the gait of the driver, as measured by his phone, is recognized, for example.

"Used unwisely, however, the system could become yet another electronic spy, permitting complete strangers to monitor your actions, from the moment you reach for your phone in the morning, to when you fling it on the floor at night," the report adds.
Security

Millions of Golfers Land In Privacy Hazard After Cloud Misconfig (nbcnews.com) 29

Millions of golfer records from the Game Golf app, including GPS details from courses played, usernames and passwords, and even Facebook login data, were all exposed for anyone with an internet browser to see -- a veritable hole-in-one for a cyberattacker looking to build profiles for potential victims, to be used in follow-on social-engineering attacks. Threatpost reports: Security Discovery researcher Bob Diachenko recently ran across an Elastic database that was not password-protected and thus visible in any browser. Further inspection showed that it belongs to Game Golf, which is a family of apps developed by San Francisco-based Game Your Game Inc. Game Golf comes as a free app, as a paid pro version with coaching tools and also bundled with a wearable. It's a straightforward analyzer for those that like to hit the links -- tracking courses played, GPS data for specific shots, various player stats and so on -- plus there's a messaging and community function, and an optional "caddy" feature. It's popular, too: It has 50,000+ installs on Google Play.

Unfortunately, Game Golf landed its users in a sand trap of privacy concerns by not securing the database: Security Discovery senior security researcher Jeremiah Fowler said that the bucket included all of the aforementioned analyzer information, plus profile data like usernames and hashed passwords, emails, gender, and Facebook IDs and authorization tokens. In all, the exposure consisted of millions of records, including details on "134 million rounds of golf, 4.9 million user notifications and 19.2 million records in a folder called 'activity feed,'" Fowler said. The database also contained network information for the company: IP addresses, ports, pathways and storage info that "cybercriminals could exploit to access deeper into the network," according to Fowler, writing in a post on Tuesday. No word on whether malicious players took a swing at the data, as it were, but the sheer breadth of the information that the app gathers is concerning, Fowler noted.

Security

Hackers Are Holding Baltimore's Government Computers Hostage (gizmodo.com) 172

On May 7, hackers infected about 10,000 of Baltimore city government's computers with an aggressive form of ransomware called RobbinHood, and insisted the city pay 13 bitcoin (then $76,280, today $102,310) to cut the computers loose. The hackers claimed the price would go up every day after four days, and after the tenth day, the affected files would be lost forever. From a report: "We won't talk more, all we know is MONEY!" the ransom note read. "Hurry up! Tik Tak, Tik Tak, Tik Tak!" But the city has not paid. In the two weeks since, Baltimore citizens have not had access to many city services. The city payment services and email systems are still offline. A May 7 Baltimore Sun report stated the Robbinhood ransomware used in this attack encrypts files with a "file-locking" virus so the hackers can hold the files hostage. Among the departments that have had issues with their email and phone systems are the Department of Public Works, the Department of Transportation, and the Baltimore Police Department.

According to the Wall Street Journal, Baltimore Health Department's epidemiologists aren't able to use the network that allows them to alert citizens of certain which types of drugs are causing recent overdoses. Many services have resumed through phone, and vital emergency systems like 911 and 311 reportedly continued to function. The ransomware froze the system the city uses for executing home sales, which reportedly hurt the local market, but the city began implementing a manual workaround earlier this week.

IOS

Android and iOS Devices Impacted By New Sensor Calibration Attack (zdnet.com) 59

A new device fingerprinting technique can track Android and iOS devices across the Internet by using factory-set sensor calibration details that any app or website can obtain without special permissions. From a report: This new technique -- called a calibration fingerprinting attack, or SensorID -- works by using calibration details from gyroscope and magnetometer sensors on iOS; and calibration details from accelerometer, gyroscope, and magnetometer sensors on Android devices. According to a team of academics from the University of Cambridge in the UK, SensorID impacts iOS devices more than Android smartphones. The reason is that Apple likes to calibrate iPhone and iPad sensors on its factory line, a process that only a few Android vendors are using to improve the accuracy of their smartphones' sensors. "Our approach works by carefully analysing the data from sensors which are accessible without any special permissions to both websites and apps," the research team said in a research paper published yesterday. "Our analysis infers the per-device factory calibration data which manufacturers embed into the firmware of the smartphone to compensate for systematic manufacturing errors [in their devices' sensors]," researchers said. This calibration data can then be used as a fingerprint, producing a unique identifier that advertising or analytics firms can use to track a user as they navigate across the internet.
Security

Google Says Some G Suite User Passwords Were Stored In Plaintext Since 2005 (techcrunch.com) 35

Google says a small number of its enterprise customers mistakenly had their passwords stored on its systems in plaintext. The exact number was not disclosed. "We recently notified a subset of our enterprise G Suite customers that some passwords were stored in our encrypted internal systems unhashed," said Google vice president of engineering Suzanne Frey.

Slashdot reader pegdhcp appears to be one of the users impacted by this security lapse: I am sharing a message that I received from G Suite, redacted. They are having some serious problem... If you missed the message or somehow tend to ignore sometimes extremely frequent and unnecessary G Suite messages like I do, this one can be important depending on your settings. [You can read the full email message (with redactions) below:]
Microsoft

Microsoft Kicks Off the Rollout of the Windows 10 May Update 1903 (zdnet.com) 77

It's technically "late May." So it's not too surprising that Microsoft's promised late May rollout of the Windows 10 May 2019 Update (also known as 1903) is kicking off today, May 21. From a report: As of today, mainstream consumer and business users who want to manually download and install the May feature update may do so. The May 2019 Update/1903 is available on WSUS, Windows Update for Business as of today. Users who aren't already on Windows 10 1809 (either because they weren't "offered" it or didn't proactively grab it) will be able to just skip over 1809 and go straight to 1903, since Windows 10 feature updates are cumulative.

There are a quite a number of new features in the May 2019 Update/1903. Microsoft is providing users -- including Home users -- with more control over how and when Windows 10 feature updates will install with this release. Microsoft is adding the ability for Home users to pause updates for up to 35 days.

AMD

Intel Performance Hit 5x Harder Than AMD After Spectre, Meltdown Patches (extremetech.com) 170

Phoronix has conducted a series of tests to show just how much the Spectre and Meltdown patches have impacted the raw performance of Intel and AMD CPUs. While the patches have resulted in performance decreases across the board, ranging from virtually nothing to significant depending on the application, it appears that Intel received the short end of the stick as its CPUs have been hit five times harder than AMD, according to ExtremeTech. From the report: The collective impact of enabling all patches is not a positive for Intel. While the impacts vary tremendously from virtually nothing to significant on an application-by-application level, the collective whack is about 15-16 percent on all Intel CPUs without Hyper-Threading disabled. Disabling increases the overall performance impact to 20 percent (for the 7980XE), 24.8 percent (8700K) and 20.5 percent (6800K).

The AMD CPUs are not tested with HT disabled, because disabling SMT isn't a required fix for the situation on AMD chips, but the cumulative impact of the decline is much smaller. AMD loses ~3 percent with all fixes enabled. The impact of these changes is enough to change the relative performance weighting between the tested solutions. With no fixes applied, across its entire test suite, the CPU performance ranking is (from fastest to slowest): 7980XE (288), 8700K (271), 2990WX (245), 2700X (219), 6800K. (200). With the full suite of mitigations enabled, the CPU performance ranking is (from fastest to slowest): 2990WX (238), 7980XE (231), 2700X (213), 8700K (204), 6800K (159).
In closing, ExtremeTech writes: "AMD, in other words, now leads the aggregate performance metrics, moving from 3rd and 4th to 1st and 3rd. This isn't the same as winning every test, and since the degree to which each test responds to these changes varies, you can't claim that the 2990WX is now across-the-board faster than the 7980XE in the Phoronix benchmark suite. It isn't. But the cumulative impact of these patches could result in more tests where Intel and AMD switch rankings as a result of performance impacts that only hit one vendor."
Security

Email Addresses and Passwords Leaked For 113,000 Users Of Account Hijacking Forum (krebsonsecurity.com) 36

"Ogusers.com -- a forum popular among people involved in hijacking online accounts and conducting SIM swapping attacks to seize control over victims' phone numbers -- has itself been hacked," reports security researcher Brian Krebs, "exposing the email addresses, hashed passwords, IP addresses and private messages for nearly 113,000 forum users." On May 12, the administrator of OGusers explained an outage to forum members by saying a hard drive failure had erased several months' worth of private messages, forum posts and prestige points, and that he'd restored a backup from January 2019. Little did the administrators of OGusers know at the time, but that May 12 incident coincided with the theft of the forum's user database, and the wiping of forum hard drives. On May 16, the administrator of rival hacking community RaidForums announced he'd uploaded the OGusers database for anyone to download for free...

"The website owner has acknowledged data corruption but not a breach so I guess I'm the first to tell you the truth. According to his statement he didn't have any recent backups so I guess I will provide one on this thread lmfao."

Some users of the hijacking forum complained that their email addresses had started getting phishing emails -- and that the forum's owner had since altered the forum's functionality so user's couldn't delete their accounts.

"It's difficult not to admit feeling a bit of schadenfreude in response to this event..." writes Krebs, adding "federal and state law enforcement investigators going after SIM swappers are likely to have a field day with this database, and my guess is this leak will fuel even more arrests and charges for those involved."
Bug

Salesforce Triggers 15-Hour Shutdown After Faulty Script Starts Granting View/Modify Access (zdnet.com) 29

Friday Salesforce "was forced to shut down large chunks of its infrastructure," ZDNet reports, calling it one of the company's biggest outages ever: At the heart of the outage was a change the company made to its production environment that broke access permission settings across organizations and gave employees access to all of their company's files. According to reports on Reddit, users didn't just get read access, but they also received write permissions, making it easy for malicious employees to steal or tamper with a company's data...

Salesforce said the script only impacted customers of Salesforce Pardot -- a business-to-business (B2B) marketing-focused CRM. However, out of an abundance of caution, the company decided to take down all other Salesforce services, for both current and former Pardot customers. "As a result, customers who were not affected may have also experienced service disruption, including customers using Marketing Cloud integrations," Salesforce said.

A status update at Salesforce.com reports that the final duration of the service disruption was 15 hours and 8 minutes.
Programming

Are Trendy Developers Ignoring Tradeoffs and Over-Engineering Workplaces? (github.io) 211

An anonymous reader shares an article titled "Does IT Run on Java 8?"

"After more than ten years in tech, in a range of different environments, from Fortune 500 companies, to startups, I've finally come to realize that most businesss and developers simply don't revolve around whatever's trending on Hacker News," argues one Python/R/Spark data scientist: Most developers -- and companies -- are part of what [programmer] Scott Hanselman dubbed a while ago as the 99%... "They don't read a lot of blogs, they never write blogs, they don't go to user groups, they don't tweet or facebook, and you don't often see them at large conferences. Lots of technologies don't iterate at this speed, nor should they.

"Embedded developers are still doing their thing in C and C++. Both are deeply mature and well understood languages that don't require a lot of churn or panic on the social networks. Where are the dark matter developers? Probably getting work done. Maybe using ASP.NET 1.1 at a local municipality or small office. Maybe working at a bottling plant in Mexico in VB6. Perhaps they are writing PHP calendar applications at a large chip manufacturer."

While some companies are using Spark and Druid and Airflow, some are still using Coldfusion... Or telnet... Or Microsoft TFS... There are reasons updates are not made. In some cases, it's a matter of national security (like at NASA). In others, people get used to what they know. In some cases, the old tech is better... In some cases, it's both a matter of security, AND IT is not a priority. This is the reason many government agencies return data in PDF formats, or in XML... For all of this variety of reasons and more, the majority of companies that are at the pinnacle of succes in America are quietly running Windows Server 2012 behind the scenes.

And, not only are they running Java on Windows 2012, they're also not doing machine learning, or AI, or any of the sexy buzzwords you hear about. Most business rules are still just that: hardcoded case statements decided by the business, passed down to analysts, and done in Excel sheets, half because of bureacracy and intraction, and sometimes, because you just don't need machine learning. Finally, the third piece of this is the "dark matter" effect. Most developers are simply not talking about the mundane work they're doing. Who wants to share their C# code moving fractions of a cent transactions between banking systems when everyone is doing Tensorflow.js?

In a footnote to his essay, Hanselman had added that his examples weren't hypothetical. "These people and companies all exist, I've met them and spoken to them at length." (And the article includes several tweets from real-world developers, including one which claims Tesla's infotainment firmware and backend services were all run in a single-location datacenter "on the worst VMware deployment known to man.")

But the data scientist ultimately asks if our online filter bubbles are exposing us to "tech-forward biases" that are "overenthusiastic about the promises of new technology without talking about tradeoffs," leading us into over-engineered platforms "that our companies don't need, and that most other developers that pick up our work can't relate to, or can even work with...

"For better or worse, the world runs on Excel, Java 8, and Sharepoint, and I think it's important for us as technology professionals to remember and be empathetic of that."
Security

Severe Linux Kernel Flaw Found In RDS (sophos.com) 90

jwhyche (Slashdot reader #6,192) shared this article from Sophos: Linux systems running kernels prior to 5.0.8 require patching after news emerged of a high-severity flaw that could be remotely exploited.

According to the NIST advisory, CVE-2019-1181 is a race condition affecting the kernel's rds_tcp_kill_sock in net/rds/tcp.c "leading to a use-after-free, related to net namespace cleanup." The RDS bit refers to systems running the Reliable Datagram Sockets (RDS) for the TCP module, which means only systems that run applications using this are affected.

The attention-grabbing part is that this opens unpatched systems to remote compromise and denial of service without the need for system privileges or user interaction. On the other hand, the attack complexity is described as 'high', and any such attack would need to be launched from the local network.

Encryption

New John the Ripper Cracks Passwords On FPGAs 58

Long-time Slashdot reader solardiz has long bring an advocate for bringing security to open environments. Wednesday he contacted Slashdot to share this update about a piece of software he's authored called John the Ripper: John the Ripper is the oldest still evolving password cracker program (and Open Source project), first released in 1996. John the Ripper 1.9.0-jumbo-1, which has just been announced with a lengthy list of changes, is the first release to include FPGA support (in addition to CPU, GPU, and Xeon Phi). This is a long-awaited (or long-delayed) major release, encompassing 4.5 years of development and 6000+ commits by 80+ contributors. From the announcement:

"Added FPGA support for 7 hash types for ZTEX 1.15y boards [...] we support: bcrypt, descrypt (including its bigcrypt extension), sha512crypt & Drupal7, sha256crypt, md5crypt (including its Apache apr1 and AIX smd5 variations) & phpass. As far as we're aware, several of these are implemented on FPGA for the very first time. For bcrypt, our ~119k c/s at cost 5 in ~27W greatly outperforms latest high-end GPUs per board, per dollar, and per Watt. [...] We also support multi-board clusters (tested [...] for up to 16 boards, thus 64 FPGAs, [...] on a Raspberry Pi 2 host)."
Security

Slack Patches Vulnerability In Windows Client That Could Be Used To Hijack Files (arstechnica.com) 24

An anonymous reader quotes a report from Ars Technica: On May 17, researchers at Tenable revealed that they had discovered a vulnerability in the Windows version of the desktop application for Slack, the widely used collaboration service. The vulnerability, in Slack Desktop version 3.3.7 for Windows, could have been used to change the destination of a file download from a Slack conversation to a remote file share owned by an attacker. This would allow the attacker to not only steal the files that were downloaded by a targeted user, but also allow the attacker to alter the files and add malware to them. When victims opened the files, they would get a potentially nasty surprise. Tenable reported the vulnerability to Slack via HackerOne. Slack has issued an update to the Windows desktop client that closes the vulnerability. Once the attacker had changed the default download location, "the attacker could have not only stolen the document, but even inserted malicious code in it so that when opened by victim after download (through the Slack application), their machine would have been infected," writes Tenable's David Wells in a blog post.
Security

A Large Chunk of Ethereum Clients Remain Unpatched (zdnet.com) 16

The Ethereum ecosystem is no different than the Windows or IoT landscape, where security flaws remain unpatched for long periods of time, despite the availability of public patches. From a report: In a report shared with ZDNet today, security researchers from SRLabs revealed that a large chunk of the Ethereum client software that runs on Ethereum nodes has yet to receive a patch for a critical security flaw the company discovered earlier this year. "According to our collected data, only two thirds of nodes have been patched so far," said Karsten Nohl, one of the researchers. The vulnerability is a denial of service (DoS) vulnerability in the Parity client that can be used to run Ethereum nodes. Per SRLabs, the vulnerability allows an attacker to remotely crash Ethereum nodes (that run Parity) by sending malformed packets. The issue was fixed with the release of the Parity Ethereum client v2.2.10, in mid-February this year, a few days after it was reported. While most DoS flaws are considered "low impact" for most products, this is not the case in the cryptocurrency world.
Security

Amazon Updates Alexa To Guard Your House and Listen For Broken Glass, Smoke Alarm (techcrunch.com) 69

Amazon is rolling out an update to Alexa that will turn the company's line of smart home products into home security devices while the user is out. Called "Alexa Guard," the feature will have your smart speakers listen for key sounds, including breaking glass and smoke and carbon monoxide alarms. If the Echo hears the noise, it will send you an alert, coupled with an audio recording of the noise. TechCrunch reports: It's an interesting new addition and one that leverages the sometimes controversial fact that the device's mics are designed to always be listening. Amazon points out that it worked with licensed contractors to break hundreds of different glass windows with different instruments in order to create a wide range of different sounds for Alexa to listen for.

The new feature works with different smart home devices, as well. Users with Ring or ADT pro monitoring can set it up to forward alerts to their providers. Users with Away Lighting setup, meanwhile, can use the alert to flip on lights in order to make it look like you're still around. The app is rolling out as a free addition to all Echo owners in the U.S.

Cloud

Hackers Abuse ASUS Cloud Service To Install Backdoor On Users' PCs (arstechnica.com) 20

An anonymous reader quotes a report from Ars Technica: ASUS' update mechanism has once again been abused to install malware that backdoors PCs, researchers from Eset reported earlier this week. The researchers, who continue to investigate the incident, said they believe the attacks are the result of router-level man-in-the-middle attacks that exploit insecure HTTP connections between end users and ASUS servers, along with incomplete code-signing to validate the authenticity of received files before they're executed. Plead, as the malware is known, is the work of espionage hackers Trend Micro calls the BlackTech Group, which targets government agencies and private organizations in Asia. Last year, the group used legitimate code-signing certificates stolen from router-maker D-Link to cryptographically authenticate itself as trustworthy. Before that, the BlackTech Group used spear-phishing emails and vulnerable routers to serve as command-and-control servers for its malware.

Late last month, Eset researchers noticed the BlackTech Group was using a new and unusual method to sneak Plead onto targets' computers. The backdoor arrived in a file named ASUS Webstorage Upate.exe included in an update from ASUS. An analysis showed infections were being created and executed by AsusWSPanel.exe, which is a legitimate Windows process belonging to, and digitally signed by, ASUS WebStorage. As the name suggests, ASUS WebStorage is a cloud service the computer-maker offers for storing files. Eset published its findings on Tuesday. [...] In all, Eset has counted about 20 computers receiving the malicious ASUS update, but that number includes only company customers. "The real number is probably higher if we consider targets that are not our users," Anton Cherepanov, a senior malware researcher at Eset, told Ars. Once the file is executed, it downloads an image from a different server that contains an encrypted executable file hidden inside. Once decrypted, the malicious executable gets dropped into the Windows Start Menu folder, where it's loaded each time the user logs in.
In a blog post, ASUS reported a "WebStorage security incident" that reads: "ASUS Cloud first learned of an incident in late April 2019, when we were contacted by a customer with a security concern. Upon learning of the incident, ASUS Cloud took immediate action to mitigate the attack by shutting down the ASUS WebStorage update server and halting the issuance of all ASUS WebStorage update notifications, thereby effectively stopping the attack.

In response to this attack, ASUS Cloud has revamped the host architecture of the update server and has implemented security measures aimed at strengthening data protection. This will prevent similar attacks in the future. Nevertheless, ASUS Cloud strongly recommends that users of ASUS WebStorage services immediately run a complete virus scan to ensure the integrity of your personal data."
Microsoft

Microsoft Launches Decentralized Identity Tool on Bitcoin Blockchain (coindesk.com) 38

Microsoft is launching the first decentralized infrastructure implementation by a major tech company that is built directly on the bitcoin blockchain. From a report: The open source project, called Ion, deals with the underlying mechanics of how networks talk to each other. For example, if you log onto Airbnb using Facebook, a protocol deals with the software that sends the personal information from your social profile to that external service provider. In this case, Ion handles the decentralized identifiers, which control the ability to prove you own the keys to this data.

Christopher Allen, a crypto veteran and the co-founder of the World Wide Web Consortium (W3C) working group for decentralized identity (DID) solutions, told CoinDesk that Microsoft's move could impact the entire tech industry. "A lot of enterprise infrastructures use Microsoft products," Allen said. "So if they integrate this into any of their infrastructure products, they'll have access to DID." Indeed, Yorke Rhodes, a program manager on Microsoft's blockchain engineering team, told CoinDesk that Microsoft's team has been working for a year on a key signing and validation software that relies on public networks, like bitcoin or ethereum, yet can handle far greater throughput than the underlying blockchain itself.

Security

Hackers Can Fake Radio Signals To Hijack Aircraft Landing Systems, Warn Researchers (computing.co.uk) 63

Hackers could hijack the systems used to guide planes by compromising and spoofing the radio signals that are used during landing. From a report: That's according to a team of researchers at Northeastern University in Boston, who have detailed their research in a recently published white paper. "Modern aircraft heavily rely on several wireless technologies for communications, control, and navigation. Researchers demonstrated vulnerabilities in many aviation systems," said the academics. "However, the resilience of the aircraft landing systems to adversarial wireless attacks have not yet been studied in the open literature, despite their criticality and the increasing availability of low-cost software-defined radio (SDR) platforms." After analysing the instrument system waveforms, the researchers found that hackers can spoof such radio signals using commercially available tools. With them, attackers are able to cause last-minute go-around decisions and even make the plane miss its landing zone in low-visibility scenarios.
Communications

Trump Signs Executive Order Barring US Companies From Using Huawei Gear (reuters.com) 249

schwit1 shares a report from Reuters: President Donald Trump on Wednesday signed an executive order declaring a national emergency and barring U.S. companies from using telecommunications equipment made by firms posing a national security risk, paving the way for a ban on doing business with China's Huawei. The executive order invokes the International Emergency Economic Powers Act, which gives the president the authority to regulate commerce in response to a national emergency that threatens the United States. The order directs the Commerce Department, working with other government agencies, to draw up a plan for enforcement within 150 days. The order, which has been under review for more than a year, is aimed at protecting the supply chain from "foreign adversaries to the nation's information and communications technology and services supply chain," said Commerce Secretary Wilbur Ross.

Slashdot Top Deals