Privacy

Cloud Database Removed After Exposing Details on 80 Million US Households (cnet.com) 51

The addresses and demographic details of more than 80 million US households were exposed on an unsecured database stored on the cloud, independent security researchers have found. From a report: The details listed included names, ages and genders as well as income levels and marital status. The researchers, led by Noam Rotem and Ran Locar, were unable to identify the owner of the database, which until Monday was online and required no password to access. Some of the information was coded, like gender, marital status and income level. Names, ages and addresses were not coded. The data didn't include payment information or Social Security numbers. The 80 million households affected make up well over half of the households in the US, according to Statista. "I wouldn't like my data to be exposed like this," Rotem said in an interview with CNET. "It should not be there." Rotem and his team verified the accuracy of some data in the cache but didn't download the data in order to minimize the invasion of privacy of those listed, he said.
Programming

Do Complex Systems Require Higher Safety Standards From Managers and Engineers? (techcrunch.com) 137

An anonymous reader quotes TechCrunch: Automotive emissions, nuclear power plants, airplanes, application platforms, and electrical grids all share one thing in common: they are very complex, highly coupled systems... Engineers have matched some of this growing complexity with more sophisticated tools, mostly derived from greater computing power and better modeling. But there are limits to how far the technical tools can help here given our limits of organizational behavior about complexity in these systems. Even if engineers are (potentially) acquiring more sophisticated tools, management itself most definitely is not.... One pattern that binds all of these engineering disasters together is that they all had whistleblowers who were aware of the looming danger before it happened. Someone, somewhere knew what was about to transpire, and couldn't hit the red button to stop the line...

Engineering managers probably have the most challenging role, since they both need to sell upwards and downwards within an organization in order to maintain safety standards. The pattern that I have gleaned from reading many reports on disasters over the years indicates that most safety breakdowns start right here. The eng manager starts to prioritize business concerns from their leadership over the safety of their own product. Resistance of these pecuniary impulses is not enough -- safety has to be the watchword for everyone...

Finally, for individual contributors and employees, the key is to always be observant, to be thinking about safety and security while conducting engineering work, and to bring up any concerns early and often. Safety requires tenacity. And if the organization you are working for is sufficiently corrupt, then frankly, it might be incumbent on you to pull that proverbial red button and whistleblow to stop the madness.... [T]he demise of the ethical engineer doesn't have to be a fait accompli.

Security

Is Cyberwarfare War? Insurers Balk At Paying For Some Cyberattacks (thebulletin.org) 81

From the Bulletin of the Atomic Scientists: In an era of unceasing cyberattacks, including cases of state-sponsored hacking, insurance companies are beginning to re-interpret an old line in their contracts known as the "war exclusion." Stripping away the metaphorical connotation of the term "cyberwarfare," big insurers like Zurich Insurance have decided that state-sponsored attacks are basically just plain warfare.

This shift comes as the U.S. government is increasingly attributing state-sponsored cyberattacks to their alleged perpetrators, a development that some argue is a means of holding bad actors accountable. But the policy certainly doesn't seem to be doing any favors to the private sector.

The maker of Oreo cookies was hit by 2017's "NotPetya" attack, but its insurer refused to cover its $100 million in losses, citing an exclusion for "hostile or warlike action in time of peace or war...by any government or sovereign power." Oreo called their response "unprecedented," saying the war exclusion has always been applied only to "conventional armed conflict" -- and not to cyber-attacks.

Slashdot reader Lasrick argues that an insurance company win in court "could make cyberwar much more real -- and costly."
Android

Google Bans Developer With Half a Billion App Downloads From Play Store (buzzfeednews.com) 27

Google is banning app developer DO Global and removing their apps from the Google Play Store after it discovered the company was committing ad fraud. "As of today, 46 apps from DO Global, which is partly owned by internet giant Baidu, are gone from the Play store," reports BuzzFeed. "BuzzFeed News also found that DO Global apps no longer offer ad inventory for purchase via Google's AdMob network, suggesting the ban has also been extended to the internet giant's ad products." From the report: Prior to the app removals, DO Global had roughly 100 apps in the Play store with over 600 million installs. Their removal from the Play store marks one of the biggest bans, if not the biggest, Google has ever instituted against an app developer. DO Global was a subsidiary of Baidu until it was spun out last summer; Baidu retains a 34% stake. BuzzFeed News reported last week that at least six apps from DO included code that made them fraudulently click on ads even when a user was not using the app. The apps were also listed in the Play store under the generic developer names "Pic Tools Group" and "Photo Artist Studio," hosted their privacy policies on Tumblr, and did not disclose they were owned by DO. It's a violation of Play store policy to conceal ownership information, and to commit ad fraud. The ad fraud was detected by Check Point security, which responded to a request from BuzzFeed News to examine apps uncovered during its investigation.

Google removed those six apps, and claimed its internal systems had also flagged most of them for removal. Another 40 DO apps disappeared from the Play store this week, including 20 using the Do Global Games developer name, and 14 listed under Applecheer Studio. The apps listed different addresses and contact information in the store, making it difficult for the average user to see they were all owned by the same major developer.

Google

Google Gives Free Security Keys to Activists, But Not if You're in Iran or Syria (vice.com) 48

An anonymous reader shares a report: Go to an activist, technologist, or journalist gathering, and you may find a free pile of Google's security keys, dubbed Titan. These are small devices a Gmail user can plug into their computer via USB to make their account much harder to hack. The keys don't just work with Google accounts; Twitter and other large sites now support hardware security tokens too. But if you're an activist inside Iran, Sudan, Syria, Cuba, the region of Crimea, or North Korea, Google probably won't give you a Titan key. Google bars nonprofits and other groups from providing these tools, or promoting the availability of any Google product to activists in those countries, according to two independent sources familiar with Google's approach and a legal document viewed by Motherboard.
The Internet

Ask Slashdot: Would a Separate, Walled-Off 'SafeNet' Help Reduce Cybercrime? 284

dryriver writes: Imagine for a second that a second, smaller internet infrastructure is built parallel to, but separate from, the regular internet. Lets call this the SafeNet. The SafeNet, which does not allow anonymous use, is not intended for general purpose use like watching Youtube videos, downloading a Steam game, or going on Facebook. Rather, it is a safer, more policed mini-internet that you access through a purpose-built terminal device and use for security critical tasks like online banking, stock trading, medical data transfer and sending confidential business emails, text messages or documents or other things that you don't trust the general internet with.

For example, if you are buying a $250,000 home for your family, you would issue the payments and documents side of this via the SafeNet with a SafeNet terminal device, not over the internet, with a generic computing device. SafeNet requires every user to be government photo-ID registered -- you cannot use SafeNet anonymously like the internet. The network knows who you are, where you are, and you can't hide behind VPNs, proxies or other anonymizers on this network. SafeNet also has a police force that can be alerted if you are hacked, tricked or scammed in any way. Would an internet alternative -- a smaller, separate parallel network -- like this reduce Cybercrime? Again, you wouldn't use the SafeNet for everyday crap like ordering pizza, buying movie tickets, or arguing over something on an internet forum. SafeNet would be used in situations where you are concerned that hackers, cybercriminals or other malevolent agents could get hold of your personal data, steal money from you, impersonate you, or snoop into your confidential communications. Other uses would include letting minors communicate with each other in a controlled fashion without exposing them to the big bad internet itself. Basically, in many situations where you deem performing a task over the larger internet as risky or dangerous, you could perform that task over a SafeNet terminal instead. Shouldn't an "alternative internet" like this exist in some form by now?
Security

Microsoft Drops 60-Day Password Expiration Policy (bleepingcomputer.com) 75

Microsoft is dropping its 60-day password expiration policy starting with the Windows 10 May 2019 Update. "Once removed, the preset password expiration settings should be replaced by organizations with more modern and better password-security practices such as multi-factor authentication, detection of password-guessing attacks, detection of anomalous log on attempts, and the enforcement of banned passwords lists (such as Azure AD's password protection currently available in public preview)," reports Bleeping Computer. From the report: Microsoft's Aaron Margosis states that the password expiration mechanism which requires periodic password changes is in itself a flawed defense method given that, once a password is stolen, mitigation measures should be taken immediately instead of waiting for it to expire as per the set expiration policy. In addition, the soon to be removed policies are "a defense only against the probability that a password (or hash) will be stolen during its validity interval and will be used by an unauthorized entity."

The removal of the password-expiration policies without the addition of other password-oriented security configurations does not directly translate into a decrease in security but, instead, it simply stands as proof that security-conscious organizations need to implement extra measures to enforce their users' security. As Microsoft further detailed, "to try to avoid inevitable misunderstandings, we are talking here only about removing password-expiration policies -- we are not proposing changing requirements for minimum password length, history, or complexity."

Privacy

UK Minister: Huawei Leaks 'Unacceptable', Criminal Investigation Possible (reuters.com) 77

The UK Culture Secretary Jeremy Wright said on Thursday he could not rule out a criminal investigation over the "unacceptable" disclosure of confidential discussions on the role of China's Huawei in 5G network supply chains. From a report: Huawei, the world's biggest producer of telecoms equipment, is under intense scrutiny after the United States told allies not to use its technology because of fears it could be a vehicle for Chinese spying. Huawei has categorically denied this. Sources told Reuters on Wednesday Britain's National Security Council (NSC) had decided to bar Huawei from all core parts of the country's 5G network and restrict its access to non-core parts. The leak of information from a meeting of the NSC, first reported in national newspapers, has sparked anger in parliament because the committee's discussion are supposed to be secret. "We cannot exclude the possibility of a criminal investigation here," Wright said, speaking in response to an urgent question on Huawei in parliament. "I do not think that the motivation for this leak matters in the slightest. This was unacceptable and it is corrosive to the ability to deliver good government."
Security

GoDaddy Removes a Massive Network of Bogus Sales Sites (axios.com) 67

GoDaddy removed a cluster of more than 15,000 fraudulent websites discovered by a researcher at Palo Alto Networks' Unit 42 analysis team. From a report: The scam, which sold products like weight loss pills, used breached websites to add legitimacy to its sales and involved using fake celebrity endorsements. Jeff White, the researcher at Unit 42, started researching the network of sites more than 2 years ago when he noticed spam messages that looked visually similar and used similar language. The products were sold on commission as part of an affiliate marketing program and used low initial pricing and tiny print to get people signed up for costly subscriptions. The sales took place on hacked GoDaddy websites, where hackers had set up subdomains on legitimate websites.
United Kingdom

UK To Let Huawei Firm Help Build 5G Network (bbc.co.uk) 64

AmiMoJo writes: The UK government has given Chinese telecoms giant Huawei the go-ahead to supply equipment for the UK 5G data network. The company will help build some "non-core" parts such as antennas. But the plans have concerned the home, defense and foreign secretaries. The U.S. also wants its allies in the "Five Eyes" intelligence grouping -- the UK, Canada, Australia and New Zealand -- to exclude Huawei. Huawei said it was "pleased that the UK is continuing to take an evidence-based approach to its work," adding it would continue to work cooperatively with the government and the industry.
Android

Security Flaw Lets Attackers Recover Private Keys From Qualcomm Chips (zdnet.com) 44

Devices using Qualcomm chipsets, and especially smartphones and tablets, are vulnerable to a new security bug that can let attackers retrieve private data and encryption keys that are stored in a secure area of the chipset known as the Qualcomm Secure Execution Environment (QSEE). From a report: Qualcomm has deployed patches for this bug (CVE-2018-11976) earlier this month; however, knowing the sad state of Android OS updates, this will most likely leave many smartphones and tablets vulnerable for years to come. The vulnerability impacts how the Qualcomm chips (used in hundreds of millions of Android devices) handles data processed inside the QSEE.
Microsoft

Microsoft Blocks Windows 10 May 2019 Update on PCs That Use USB Storage or SD Cards (zdnet.com) 140

Microsoft has published a support document today warning Windows 10 users that the impending May 2019 Update may not install on their systems if they use external USB storage devices or SD cards. From a report: The OS maker cited problems with "inappropriate drive reassignment" as the main reason for blocking the May 2019 Update. "Inappropriate drive reassignment can occur on eligible computers that have an external USB device or SD memory card attached during the installation of the May 2019 update," the company said. "For this reason, these computers are currently blocked from receiving the May 2019 Update."
Android

Malicious Lifestyle Apps Found On Google Play, 30 Million Installs Recorded (zdnet.com) 31

A total of 50 malicious apps have managed to bypass Google's security checks and land on the Google Play store, leading to millions of installs on Android devices. ZDNet reports: Now, the cybersecurity team from Avast have found a further 50 apps relating to lifestyle services which masquerade as legitimate software but are actually adware, and these malicious apps have been downloaded a total of 30 million times. On Tuesday, Avast published a report on the discovery, in which the apps are linked to each other through third-party libraries that "bypass the background service restrictions present in newer Android versions."

"Although the bypassing itself is not explicitly forbidden on the Play Store, Avast detects it as Android:Agent-SEB [PUP], because apps using these libraries waste the user's battery and make the device slower," the researchers say. "The applications use the libraries to continuously display more and more ads to the user, going against Play Store rules." Each app displays full-blown ads to users, and in some cases, will also attempt to lure viewers to install additional adware-laden applications. The malicious apps include Pro Piczoo, Photo Blur Studio, Mov-tracker, Magic Cut Out, and Pro Photo Eraser. Installation rates range from one million to one thousand.

Upgrades

Record Number of Consumers Waiting To Upgrade Their Cellphones (bloomberg.com) 191

An anonymous reader quotes a report from Bloomberg: Wireless customers are hanging on to their old phones longer than ever. That's the message from Verizon, which said its upgrade rate fell to a record low last quarter -- a harbinger of tough times ahead for the iPhone and other devices. Faced with $1,000 price tags on moderately improved phones, consumers may be waiting to hear more about new 5G networks before committing to new models. The faster, more advanced services won't roll out in earnest until 2020. "Incremental changes from one model the the next, hasn't been that great, and it hasn't been enough of an incentive," Verizon Chief Financial Officer Matt Ellis said in an interview Tuesday after the company reported fewer-than-expected new customers for the first quarter. He expects replacement rates to be down for the year.
Security

ShadowHammer Targets Multiple Companies, ASUS Was Just One of Them (bleepingcomputer.com) 48

ASUS was not the only company targeted by supply-chain attacksduring the ShadowHammer hacking operation as discovered by Kaspersky, with at least six other organizations having been infiltrated by the attackers. From a report: As further found out by Kaspersky's security researchers, ASUS' supply chain was successfully compromised by trojanizing one of the company's notebook software updaters named ASUS Live Updater which eventually was downloaded and installed on the computers of tens of thousands of customers according to experts' estimations. The tampered with binaries were signed using a legitimate certificate which helped the attackers avoid breaking the digital signature and having the malicious updater flagged.

Among the similarities, they discovered that the ASUS samples and the newly found ones were both using very similar algorithms to calculate API function hashes, while the IPHLPAPI.dll was heavily used within all malware samples for various reasons. As in the ASUS case, the samples were using digitally signed binaries from three other Asian vendors: Electronics Extreme, authors of the zombie survival game called Infestation: Survivor Stories. Innovative Extremist, a company that provides Web and IT infrastructure services but also used to work in game development. Zepetto, the South Korean company that developed the video game Point Blank. Besides these three Asian gaming companies, Kaspersky was also able to find three other organizations which were successfully compromised, "another video gaming company, a conglomerate holding company and a pharmaceutical company, all in South Korea."

The Internet

The New Microsoft Edge Sometimes Impersonates Other Browsers (bleepingcomputer.com) 88

AmiMoJo writes: The new Chromium-based Microsoft Edge will impersonate other browsers depending on the site being visited. This is may be done for compatibility reasons, like properly rendering pages or how video will be streamed and played back. When the new Microsoft Edge starts, it will connect to config.edge.skype.com and download a JSON configuration for the browser. One section of the JSON configuration file is called EdgeDomainActions and is a series of rules that specify what browser Microsoft Edge should impersonate when visiting a particular site.
Security

WiFi Finder, a Popular Hotspot Finder App, Exposed 2 Million Wi-Fi Network Passwords (techcrunch.com) 31

A popular hotspot finder app for Android exposed the Wi-Fi network passwords for more than two million networks. From a report: The app, downloaded by thousands of users, allowed anyone to search for Wi-Fi networks in their nearby area. The app allows the user to upload Wi-Fi network passwords from their devices to its database for others to use. That database of more than two million network passwords, however, was left exposed and unprotected, allowing anyone to access and download the contents in bulk. Sanyam Jain, a security researcher and a member of the GDI Foundation, found the database and reported the findings to TechCrunch. We spent more than two weeks trying to contact the developer, believed to be based in China, to no avail. Eventually we contacted the host, DigitalOcean, which took down the database within a day of reaching out. "We notified the user and have taken the [server] hosting the exposed database offline," a spokesperson told TechCrunch.
Security

More Than 23 Million People Use the Password '123456' (ncsc.gov.uk) 155

Bearhouse shares a new study from the UK's "National Cyber Security Centre," which advises the public on computer security, about the world's most-frequently cracked passwords. It's probably no surprise to the Slashdot readership: people use bad passwords. A recent study of publicly-available "hacked" accounts -- by the UK National Cyber Security Centre -- reveals "123456" was top, followed by the much more secure "123456789" and hard-to-guess "qwerty". If you're a soccer (football) fan, then try "Liverpool" or "Chelsea" -- they'll work in more than half a million cases. Finally, for musicians, Metallica gets beaten down by 50cent, 140k to 190k respectively.
The most common fictional names used as passwords were "superman" (333,139 users), "naruto" (242,749), "tigger" (237,290), "pokemon" (226,947), and "batman" (203,116).

The organization recommends instead choosing three random words as a password -- and also checking "password blacklists" that show passwords that have already been found in past data breaches. (Developers and sysadmins are also advised to implement these checks as part of their rules for which user passwords will be allowed.) The organization also released a file from the "Have I Been Pwned" site containing the top 100,000 passwords.

So what are the top ten most-frequently used passwords?
  • 123456
  • 123456789
  • qwerty
  • password
  • 111111
  • 12345678
  • abc123
  • 1234567
  • password1
  • 12345

Security

Hacker Dumps Thousands of Sensitive Mexican Embassy Documents Online (techcrunch.com) 35

An anonymous reader quotes a report from TechCrunch: A hacker stole thousands of documents from Mexico's embassy in Guatemala and posted them online. The hacker, who goes by the online handle @0x55Taylor, tweeted a link to the data earlier this week. The data is no longer available for download after the cloud host pulled the data offline, but the hacker shared the document dump with TechCrunch to verify its contents. The hacker told TechCrunch in a message: "A vulnerable server in Guatemala related to the Mexican embassy was compromised and I downloaded all the documents and databases." He said he contacted Mexican officials but he was ignored.

More than 4,800 documents were stolen, most of which related to the inner workings of the Mexican embassy in the Guatemalan capital, including its consular activities, such as recognizing births and deaths, dealing with Mexican citizens who have been incarcerated or jailed and the issuing of travel documents. We found more than a thousand highly sensitive identity documents of primarily Mexican citizens and diplomats -- including scans of passports, visas, birth certificates and more -- but also some Guatemalan citizens. Several documents contained scans of the front and back of payment cards. The stolen data also included dozens of letters granting diplomatic rights, privileges and immunities to embassy staff.

Bitcoin

West Virginia Will Allow 'Blockchain Voting' In the 2020 Election (technologyreview.com) 89

Military voters stationed overseas will be able to cast their votes for the 2020 presidential election via a mobile app that uses a private blockchain. MIT Technology Review reports: Donald Kersey, West Virginia's elections director, tells the cryto news website LongHash that he believes the app, created by a startup called Voatz, can enhance participation by overseas voters. Turnout among this group is very low, in part because the process of receiving a ballot and securely returning it on time is often not straightforward. This is the rationale behind the decision by a number of states to allow overseas military voters to return their ballots via e-mail. West Virginia apparently is of the mind that Voatz's private blockchain will make this kind of online voting more secure. The state first piloted the program during the 2018 midterms.

Though Kersey admits there's no telling for certain whether the app can be compromised, West Virginia is undeterred, especially given the "really good response rate" officials saw during the midterms last year. "We are not saying mobile voting is the best solution to the problem, we are not saying that blockchain technology is the best solution to storage of security data," Kersey tells LongHash. "What we are saying though is that it's better than what we have."

Slashdot Top Deals