Bug

Division 2 Multiplayer and Single-Player Campaign Broken By Latest Update 27

Longtime Slashdot reader Andy Smith writes: Gamers enjoying the single-player campaign in The Division 2 have been bitten by a bug in the latest update that spawned a range of server connection issues. While you might expect this to affect only multiplayer games, The Division 2 controversially requires a continuous server connection for the single-player campaign to work. Since Tuesday, campaign players have reported being kicked out of the game and losing their items, skills, and mission progress. Not surprisingly, developer Massive has been inundated with complaints . The company said: "We are aware of the connectivity issues some players are experiencing. We are investigating and working on a solution."
Businesses

Firms That Promised High-Tech Ransomware Solutions Almost Always Just Pay the Hackers (propublica.org) 88

As ransomware attacks crippled businesses and law enforcement agencies, two U.S. data recovery firms claimed to offer an ethical way out. Instead, they typically paid the ransom and charged victims extra. From a report: Proven Data promised to help ransomware victims by unlocking their data with the "latest technology," according to company emails and former clients. Instead, it obtained decryption tools from cyberattackers by paying ransoms, according to Storfer and an FBI affidavit obtained by ProPublica. Another U.S. company, Florida-based MonsterCloud, also professes to use its own data recovery methods but instead pays ransoms, sometimes without informing victims such as local law enforcement agencies, ProPublica has found. The firms are alike in other ways. Both charge victims substantial fees on top of the ransom amounts. They also offer other services, such as sealing breaches to protect against future attacks. Both firms have used aliases for their workers, rather than real names, in communicating with victims.

The payments underscore the lack of other options for individuals and businesses devastated by ransomware, the failure of law enforcement to catch or deter the hackers, and the moral quandary of whether paying ransoms encourages extortion. Since some victims are public agencies or receive government funding, taxpayer money may end up in the hands of cybercriminals in countries hostile to the U.S. such as Russia and Iran.

Security

Google Recalls Its Bluetooth Titan Security Keys Because of a Security Bug (techcrunch.com) 21

Google today disclosed a security bug in its Bluetooth Titan Security Key that could allow an attacker in close physical proximity to circumvent the security the key is supposed to provide. From a report: The company says that the bug is due to a "misconfiguration in the Titan Security Keys' Bluetooth pairing protocols" and that even the faulty keys still protect against phishing attacks. Still, the company is providing a free replacement key to all existing users. The bug affects all Titan Bluetooth keys, which sell for $50 in a package that also includes a standard USB/NFC key, that have a "T1" or "T2" on the back.
Communications

FCC Announces Action and Legal Framework To Fight Robocalls (axios.com) 104

Federal Communications Commission Chairman Ajit Pai proposed a ruling Wednesday that would combat robocalls that spoof legitimate, in-service numbers and provide legal framework for phone carriers to carry out the action. From a report: The declaratory ruling will be voted on and, assuming it passes, be adopted by June 6, per the FCC. If enacted: Phone companies would be allowed to block calls for consumers by default. Consumers could "white list" their contacts and opt-in to only receive calls based on that list. Emergency and other vital calls would not be blocked. Through the notice of proposed rulemaking, the FCC will also seek comment on additional measures aimed at curbing robocalls.
Security

Scientists Help Artificial Intelligence Outsmart Hackers (sciencemag.org) 61

sciencehabit shares a report from Science Magazine: A hacked message in a streamed song makes Alexa send money to a foreign entity. A self-driving car crashes after a prankster strategically places stickers on a stop sign so the car misinterprets it as a speed limit sign. Fortunately these haven't happened yet, but hacks like this, sometimes called adversarial attacks, could become commonplace -- unless artificial intelligence (AI) finds a way to outsmart them. Now, researchers have found a new way to give AI a defensive edge. The work could not only protect the public. It also helps reveal why AI, notoriously difficult to understand, falls victim to such attacks in the first place. Because some AIs are too smart for their own good, spotting patterns in images that humans can't, they are vulnerable to those patterns and need to be trained with that in mind, the research suggests.

To identify this vulnerability, researchers created a special set of training data: images that look to us like one thing, but look to AI like another -- a picture of a dog, for example, that, on close examination by a computer, has catlike fur. Then the team mislabeled the pictures -- calling the dog picture an image of a cat, for example -- and trained an algorithm to learn the labels. Once the AI had learned to see dogs with subtle cat features as cats, they tested it by asking it to recognize fresh, unmodified images. Even though the AI had been trained in this odd way, it could correctly identify actual dogs, cats, and so on nearly half the time. In essence, it had learned to match the subtle features with labels, whatever the obvious features. The training experiment suggests AIs use two types of features: obvious, macro ones like ears and tails that people recognize, and micro ones that we can only guess at. It further suggests adversarial attacks aren't just confusing an AI with meaningless tweaks to an image. In those tweaks, the AI is smartly seeing traces of something else. An AI might see a stop sign as a speed limit sign, for example, because something about the stickers actually makes it subtly resemble a speed limit sign in a way that humans are too oblivious to comprehend.
Engineers could change the way they train AI to help outsmart adversarial attacks. When the researchers trained an algorithm on images without the subtle features, "their image recognition software was fooled by adversarial attacks only 50% of the time," reports Science Magazine. "That compares with a 95% rate of vulnerability when the AI was trained on images with both obvious and subtle patterns."
IOS

It's Almost Impossible To Tell If Your iPhone Has Been Hacked (vice.com) 124

An anonymous reader writes: A recent vulnerability in WhatsApp shows that there's little defenders can do to detect and analyze iPhone hacks. Some iOS security experts say this is yet another incident that shows iOS is so locked down it's hard -- if not impossible -- to figure out if your own iPhone has been hacked.

[...] "The simple reality is there are so many 0-day exploits for iOS," said Stefan Esser, a security researcher that specializes in iOS. "And the only reason why just a few attacks have been caught in the wild is that iOS phones by design hinder defenders to inspect the phones." As of today, there is no specific tool that an iPhone user can download to analyze their phone and figure out if it has been compromised. In 2016, Apple took down an app made by Esser that was specifically designed to detect malicious jailbreaks.

Security

'Hard-To-Fix' Cisco Flaw Puts Work Email At Risk (bbc.com) 47

An anonymous reader quotes a report from the BBC: Security researchers have discovered serious vulnerabilities affecting dozens of Cisco devices. The flaws allow hackers to deceive the part of the product hardware that checks whether software updates come from legitimate sources. Experts believe this could put emails sent within an organization at risk as they may use compromised routers. Messages sent externally constitute less of a risk, however, as they tend to be encrypted. The California-based firm said it is working on "software fixes" for all affected hardware.

"We've shown that we can quietly and persistently disable the Trust Anchor," Red Balloon chief executive Ang Cui, told Wired magazine. "That means we can make arbitrary changes to a Cisco router, and the Trust Anchor will still report that the device is trustworthy. Which is scary and bad, because this is in every important Cisco product. Everything." Security experts believe that the vulnerability could cause a major headache for Cisco, which has listed dozens of its products as vulnerable on its website. "We don't know how many devices could have been affected and it's unlikely Cisco can tell either," said Prof Alan Woodward, a computer security expert based at Surrey University. "It could cost Cisco a lot of money."
Security firm Red Balloon has set up a website with more details on the vulnerabilities, which they are calling "Thrangycat."
Microsoft

Microsoft Patches 'Wormable' Flaw in Windows XP, 7 and Windows 2003 (krebsonsecurity.com) 52

Microsoft today is taking the unusual step of releasing security updates for unsupported but still widely-used Windows operating systems like XP and Windows 2003, citing the discovery of a "wormable" flaw that the company says could be used to fuel a fast-moving malware threat like the WannaCry ransomware attacks of 2017. From a report: The vulnerability (CVE-2019-0708) resides in the "remote desktop services" component built into supported versions of Windows, including Windows 7, Windows Server 2008 R2, and Windows Server 2008. It also is present in computers powered by Windows XP and Windows 2003, operating systems for which Microsoft long ago stopped shipping security updates. Microsoft said the company has not yet observed any evidence of attacks against the dangerous security flaw, but that it is trying to head off a serious and imminent threat.
Intel

Intel CPUs Released in Last 8 Years Impacted by New Zombieload Side-Channel Attack (zdnet.com) 149

Academics have discovered a new class of vulnerabilities in Intel processors that can allow attackers to retrieve data being processed inside a CPU. From a report: The leading attack in this new vulnerability class is a security flaw named Zombieload, which is another side-channel attack in the same category as Meltdown, Spectre, and Foreshadow. Just like the first three, Zombieload is exploited by taking advantage of the speculative execution process, which is an optimization technique that Intel added to its CPUs to improve data processing speeds and performance. For more than a year, academics have been poking holes in various components of the speculative execution process, revealing ways to leak data from various CPU buffer zones and data processing operations. Meltdown, Spectre, and Foreshadow have shown how various CPU components leak data during the speculative execution process.

Today, an international team of academics -- including some of the people involved in the original Meltdown and Spectre research -- along with security researchers from Bitdefender have disclosed a new attack impacting the speculative execution process. This one is what researchers have named a Microarchitectural Data Sampling (MDS) attack, and targets a CPU's microarchitectural data structures, such as the load, store, and line fill buffers, which the CPU uses for fast reads/writes of data being processed inside the CPU. [...] In a research paper published today, academics say that all Intel CPUs released since 2011 are most likely vulnerable. Processors for desktops, laptops, and (cloud) servers are all impacted, researchers said on a special website they've set up with information about the Zombieload flaws.

Security

Israeli Firm Tied To Tool That Uses WhatsApp Flaw To Spy On Activists (bbc.com) 95

An anonymous reader quotes a report from The New York Times: An Israeli firm accused of supplying tools for spying on human-rights activists and journalists now faces claims that its technology can use a security hole in WhatsApp, the messaging app used by 1.5 billion people, to break into the digital communications of iPhone and Android phone users (Warning: source may be paywalled; alternative source). Security researchers said they had found so-called spyware -- designed to take advantage of the WhatsApp flaw -- that bears the characteristics of technology from the company, the NSO Group.

The spyware was used to break into the phone of a London lawyer who has been involved in lawsuits that accused the company of providing tools to hack the phones of Omar Abdulaziz, a Saudi dissident in Canada; a Qatari citizen; and a group of Mexican journalists and activists, the researchers said. There may have been other targets, they said. Digital attackers could use the vulnerability to insert malicious code and steal data from an Android phone or an iPhone simply by placing a WhatsApp call, even if the victim did not pick up the call. As WhatsApp's engineers examined the vulnerability, they concluded that it was similar to other tools from the NSO Group, because of its digital footprint.
WhatsApp engineers patched the vulnerability on Monday.

"WhatsApp encourages people to upgrade to the latest version of our app, as well as keep their mobile operating system up to date, to protect against potential targeted exploits designed to compromise information stored on mobile devices," the Facebook-owned company said in a statement.
Security

Boost Mobile Says Hackers Broke into Customer Accounts (techcrunch.com) 12

Boost Mobile is informing customers of a data breach nearly two months after it happened. "Boost.com experienced unauthorized online account activity in which an unauthorized person accessed your account through your Boost phone number and Boost.com PIN code," said the notification. "The Boost Mobile fraud team discovered the incident and was able to implement a permanent solution to prevent similar unauthorized account activity." TechCrunch reports: It's not known exactly how the hackers obtained customer PINs -- or how many Boost customers are affected. The company also notified the California attorney general, which companies are required to do if more than 500 people in the state are affected by the same security incident. Boost Mobile reportedly had 15 million customers in 2018.

The hackers used those phone numbers and account PINs to break into customer accounts using the company's website Boost.com, said the notification. These codes can be used to alter account settings. Hackers can automate account logins using lists of exposed usernames and passwords -- or in this case phone numbers and PIN codes -- in what's known as a credential stuffing attack. Boost said it has sent to affected customers a text with a temporary PIN.

Security

Academics Improve SHA-1 Collision Attack, Make It Actually Dangerous (zdnet.com) 69

An anonymous reader writes: "Attacks on the SHA-1 hashing algorithm just got a lot more dangerous last week with the discovery of the first-ever 'chosen-prefix collision attack,' a more practical version of the SHA-1 collision attack first carried out by Google two years ago," reports ZDNet. Google's original research allowed attackers to force duplicates for specific files, but this process was often at random. A new SHA-1 collision attack variation (a chosen-prefix attack) detailed last week allows attackers to choose what SHA-1-signed files or data streams they want to forge on demand, making SHA-1 an attack that is now practical in the real world, albeit at a price tag of $100,000 per collision.
Facebook

Facebook Sues Analytics Firm Rankwave Over Data Misuse (techcrunch.com) 11

Facebook revealed last Friday that it has filed a lawsuit alleging South Korean analytics firm Rankwave abused its developer platform's data, and has refused to cooperate with a mandatory compliance audit and request to delete the data. TechCrunch reports: Facebook's lawsuit centers around Rankwave offering to help businesses build a Facebook authorization step into their apps so they can pass all the user data to Rankwave, which then analyzes biographic and behavioral traits to supply user contact info and ad targeting assistance to the business. Rankwave also apparently misused data sucked in by its own consumer app for checking your social media "influencer score." That app could pull data about your Facebook activity such as location checkins, determine that you've checked into a baseball stadium, and then Rankwave could help its clients target you with ads for baseball tickets.

The use of a seemingly fun app to slurp up user data and repurpose it for other business goals is strikingly similar to how Cambridge Analytica's personality quiz app tempted millions of users to provide data about themselves and their friends. TechCrunch has attained a copy of the lawsuit that alleges that Rankwave misused Facebook data outside of the apps where it was collected, purposefully delayed responding to a cease-and-desist order, claimed it didn't violate Facebook policy, lied about not using its apps since 2018 when they were accessed in April 2019, and then refused to comply with a mandatory audit of its data practices. Facebook Platform data is not supposed to be repurposed for other business goals, only for the developer to improve their app's user experience.

Privacy

Twitter Bug Shared Location Data For Some iOS Users (zdnet.com) 9

Twitter today disclosed a bug in its platform that impacted the privacy of some its iOS app's users. From a report: "We have discovered that we were inadvertently collecting and sharing iOS location data with one of our trusted partners in certain circumstances," Twitter said. The company said the bug only occurred on its iOS app where users added a second Twitter account on their phones. If they allowed Twitter access to precise location data in one account, then that setting was applied to both accounts managed via the iOS app. This meant the app sent precise location data to Twitter, which then made it available to "a trusted partner during an advertising process known as real-time bidding," even for accounts users didn't agree to share such info.
Security

Ask Slashdot: Could We Fight Ransomware With 'Unencryptable' Folders? 437

CaptainDork writes: I'm a retired IT guy and ransomware was not a huge thing 3-5 years ago (at least few victims were self-reporting) and I'm very curious about protection schemes.

In my, now ancient, world we did not encrypt anything -- anywhere. Seems to me the trick would be to mark certain places as "unencryptable," similar to long-time attributes like "hidden," "system," "read-only," etc.

Do solutions exist that would mark local data folders and backup drives as "unencryptable," and if not, do you think it could be done? If so, how?

Leave your best thoughts and suggestions in the comments. Could we fight ransomware with 'unencryptable' folders?
Books

Is Big Tech Needlessly Ruining Entire Industries? (salon.com) 325

Salon tech editor Keith A. Spencer just published a new article describing what happens when "venture capital-backed entrepreneurs jackhammer their way into a new industry, 'tech'-ify it in some way, undermine the competition and declare their new way superior once the old is bankrupted." - Being a taxi driver was once a much-vaunted job, so much so that a taxi medallion was perceived of as a ticket to the middle class. Then came Uber and Lyft, who flooded the market for private transit and undercut the taxi industry by de-skilling the industry and paying their workers far, far less....

- Building devices to quantize as much fitness data as possible wasn't an example of capitalism fulfilling consumer desire -- no one, save a few data scientists, ever said, "I want to turn my leisure activities and exercise regime into spreadsheets" -- but the tech industry has been very effective at making us desire just that....

- The thing is, baristas and cashiers aren't things that we are all dying to get rid of... Silicon Valley is only trying to put baristas and cashiers out of business because human labor costs money; the difference between a $4 coffee from a robot and a $4 coffee from a human is that there are no labor costs in the former purchase, something that makes Silicon Valley go googly-eyed with dollar signs. The tech industry's vision of the future is of a world with less human interaction, less conversation, less humanity; and more surveillance and more monetization of our buying habits. No one wants this, but it's being forced upon us.

The article is adapted from Spencer's recent book, A People's History of Silicon Valley: How the Tech Industry Exploits Workers, Erodes Privacy and Undermines Democracy.

The article's title? "Silicon Valley makes everything worse: Four industries that Big Tech has ruined."
Programming

Software Executive Decries 'Toxic Certainty Syndrome' (glowforge.com) 217

Michael Natkin is the VP of software engineering at the 3D printer company Glowforge. In a recent post on the company blog, he argues that the tech industry has "glorified overconfidence" with its philosophy of "strong opinions, loosely held": The idea of strong opinions, loosely held is that you can make bombastic statements, and everyone should implicitly assume that you'll happily change your mind in a heartbeat if new data suggests you are wrong. It is supposed to lead to a collegial, competitive environment in which ideas get a vigorous defense, the best of them survive, and no one gets their feelings hurt in the process. On a certain kind of team, where everyone shares that ethos, and there is very little power differential, this can work well. I've had the pleasure of working on teams like that, and it is all kinds of fun...

Unfortunately, that ideal is seldom achieved. What really happens? The loudest, most bombastic engineer states their case with certainty, and that shuts down discussion. Other people either assume the loudmouth knows best, or don't want to stick out their neck and risk criticism and shame. This is especially true if the loudmouth is senior, or there is any other power differential... Even if someone does have the courage to push back, in practice the original speaker isn't likely to be holding their opinion as loosely as they think. Having stated their case, they are anchored to it and will look for evidence that confirms it and reject anything contradictory. It is a natural tendency to want to win the argument and be the smartest person in the room.

As a fix, he suggests adding a degree of uncertainty to statements -- which makes it easier for you to adjust them later while also explicitly encouraging feedback.

For example, in announcing the blog post on Twitter, Natkin wrote that "I'm about 60% sure it's useful."
GNU is Not Unix

GDB 8.3 Released (gnu.org) 38

"Release 8.3 of GDB, the GNU Debugger, is now available," according to an announcement on the info-gnu mailing list:

GDB is a source-level debugger for Ada, C, C++, Go, Rust, and many other languages. GDB can target (i.e., debug programs running on) more than a dozen different processor architectures, and GDB itself can run on most popular GNU/Linux, Unix and Microsoft Windows variants. GDB is free (libre) software. GDB 8.3 includes support for new native configurations (also available as a target configuration) for RISC-V GNU/Linux and RISC-V FreeBSD.

The announcement warns that Native Windows debugging "is only supported on Windows XP or later," and that "the Python API in GDB now requires Python 2.6 or later."
Microsoft

Russia-Linked Hackers Using Sophisticated Backdoor To Hijack Exchange Servers (securityweek.com) 40

wiredmikey quotes SecurityWeek: The Russia-linked threat group known as Turla has reportedly been using a sophisticated backdoor to hijack Microsoft Exchange mail servers, ESET reported... The malware, dubbed LightNeuron, allows the attackers to read and modify any email passing through the compromised mail server, create and send new emails, and block emails to prevent the intended recipients from receiving them. According to ESET, LightNeuron has been used by Turla — the group is also known as Waterbug, KRYPTON and Venomous Bear — since at least 2014 to target Microsoft Exchange servers. The cybersecurity firm has analyzed a Windows version of the malware, but evidence suggests a Linux version exists as well.
Security

MongoDB Database Containing Over 275 Million Personal Records Exposed and Hacked (bleepingcomputer.com) 47

"An unprotected and public-facing MongoDB database containing over 275 million records of personal information on Indian citizens has been discovered on search engine Shodan," writes Slashdot reader helpfulhecker.

BleepingComputer reports that the detailed personally identifiable information was exposed online for over two weeks: Security Discovery researcher Bob Diachenko discovered the publicly accessible MongoDB database hosted on Amazon AWS using Shodan, and as historical data provided by the platform showed, the huge cache of PII data was first indexed on April 23, 2019. As he found out after further investigation, the exposed data included information such as name, gender, date of birth, email, mobile phone number, education details, professional info (employer, employment history, skills, functional area), and current salary for each of the database records.

While the unprotected MongoDB database leaked the sensitive information of hundreds of millions of Indians, Diachenko did not find any information that would link it to a specific owner. Additionally, the names of the data collections stored within the database suggested that the entire cache of resumes was collected "as part of a massive scraping operation" for unknown purposes.

Two months ago Diachenko also helped uncover over 800 million exposed email addresses in another unprotected MongoDB database. And in January an investigation with TechCrunch also discovered millions of highly sensitive financial documents from tens of thousands of individuals who took out loans or mortgages.

The same month Diachenko also discovered an exposed 854 gigabyte MongoDB database filled with resumes from over 200 million job-seekers in China.

Slashdot Top Deals