Security

Apache Web Server Bug Grants Root Access On Shared Hosting Environments (zdnet.com) 85

An anonymous reader quotes a report from ZDNet: This week, the Apache Software Foundation has patched a severe vulnerability in the Apache (httpd) web server project that could --under certain circumstances-- allow rogue server scripts to execute code with root privileges and take over the underlying server. The vulnerability, tracked as CVE-2019-0211, affects Apache web server releases for Unix systems only, from 2.4.17 to 2.4.38, and was fixed this week with the release of version 2.4.39. According to the Apache team, less-privileged Apache child processes (such as CGI scripts) can execute malicious code with the privileges of the parent process. Because on most Unix systems Apache httpd runs under the root user, any threat actor who has planted a malicious CGI script on an Apache server can use CVE-2019-0211 to take over the underlying system running the Apache httpd process, and inherently control the entire machine.

"First of all, it is a LOCAL vulnerability, which means you need to have some kind of access to the server," Charles Fol, the security researcher who discovered this vulnerability told ZDNet in an interview yesterday. This means that attackers either have to register accounts with shared hosting providers or compromise existing accounts. Once this happens, the attacker only needs to upload a malicious CGI script through their rented/compromised server's control panel to take control of the hosting provider's server to plant malware or steal data from other customers who have data stored on the same machine. "The web hoster has total access to the server through the 'root' account. If one of the users successfully exploits the vulnerability I reported, he/she will get full access to the server, just like the web hoster," Fol said. "This implies read/write/delete any file/database of the other clients."

Operating Systems

Windows 10 Will No Longer Auto Install Feature Updates Twice a Year (windowscentral.com) 104

Microsoft has announced that starting with the Windows 10 May 2019 Update, which will hit general availability late next month, users will no longer be forced to install new Windows 10 feature updates as they become available. From a report: This comes after feedback from users who have had countless issues with updates breaking programs, losing files, and installing at inconvenient times. Microsoft has been working hard to improve Windows Update, and while the system is better than it was at launch in 2015, it's still not perfect. Now, users will have the option to not have to deal with feature updates when they are released.

What Microsoft is doing here is splitting Windows Update in two. The normal "check for updates" button will now only function for security and monthly patches. Feature updates now get their own area in Windows Update where the user can initiate the download and install process for the latest feature update available. If the user doesn't want to initiate that process, they don't have to. The user will be alerted that a new feature update is available every now and then, but at no point will the user be forced to install that update, as long as the version of Windows 10 they're currently running is still in support.

Microsoft

Microsoft Bounty Program Offers Larger Rewards For Bug Hunters (betanews.com) 18

Microsoft, which already offers one of the biggest bug bounty programs, said today it is increasing the payouts it makes and the time it takes to push the payments. From a report: A key change in policy is that Microsoft will no longer wait until a fix has been produced for a bug until making a payout -- now the only requirement is that a bug can be reproduced. This is thanks in part to a partnership with HackerOne. [...] The maximum bounty has increased from $15,000 to $50,000 for the Windows Insider Preview bounty and from $15K to $20K for the Microsoft Cloud Bounty.
China

MIT Cuts Funding Ties With Huawei, ZTE Citing US National Security Concerns (scmp.com) 102

Following similar moves by Stanford, University of California Berkeley and University of Minnesota, Massachusetts Institute of Technology announced that it is cutting ties with Huawei and ZTE, citing U.S. national security concerns. "At this time, based on this enhanced review, MIT is not accepting new engagements or renewing existing ones with Huawei and ZTE or their respective subsidiaries due to federal investigations regarding violations of sanction restrictions," Richard Lester, MIT's associate provost, and Maria Zuber, the school's vice-president for research, said in a letter to faculty on Wednesday. The South China Morning Post reports: MIT's move is part of a broader effort to strengthen its vetting of research partners, which may affect relationships with other entities in mainland China, Hong Kong, Russia and Saudi Arabia. "Most recently we have determined that engagements with certain countries -- currently China [including Hong Kong], Russia and Saudi Arabia -- merit additional faculty and administrative review beyond the usual evaluations that all international projects receive," the letter said.

The Protect Our Universities Act, introduced last month by Representative Jim Banks, an Indiana Republican, would establish a task force, led by the U.S. Department of Education, to maintain a list of "sensitive" research projects, including those financed by the defense and energy departments and U.S. intelligence agencies. The proposed body would monitor foreign student participation in those projects. Students with past or current Chinese citizenship would not be allowed access to the projects without a waiver from the director of national intelligence. The Act also calls for the intelligence director to create a list of foreign entities that "pose a threat of espionage with respect to sensitive research," and stipulates that Huawei and ZTE be included.

Security

Huawei Laptop 'Backdoor' Flaw Raises Concerns (bbc.com) 95

A flaw in Huawei Matebook laptops, found by Microsoft researchers, could have been used to take control of machines. From a report: The "sophisticated flaw" had probably been introduced at the manufacturing stage, one expert told BBC News. Huawei is under increasing scrutiny around the world over how closely it is tied to the Chinese government. The company, which denies any collusion with Beijing, corrected the flaw after it was notified about it in January. Prof Alan Woodward, a computer security expert based at Surrey University, told BBC News the flaw had the hallmarks of a "backdoor" created by the US's National Security Agency to spy on the computers of targets. That tool was leaked online and has been used by a wide variety of hackers, including those who are state-sponsored and criminal gangs. "It was introduced at the manufacture stage but the path by which it came to be there is unknown and the fact that it looks like an exploit that is linked to the NSA doesn't mean anything," Prof Woodward said.
Privacy

Kaspersky Lab Will Warn You If Your Phone is Infected With Stalkerware (cnet.com) 31

Kaspersky Lab said today it would start flagging stalkerware as malicious, and warn people through its Android app when stalkerware is installed on their phones. In 2018 Kaspersky Lab detected stalkerware on 58,487 mobile devices. From a report: Stalkerware is frequently used by stalkers and abusers to spy on people through their phones. It essentially turns victims' phones into surveillance devices, letting an attacker track a person's every step and listen in on every word. Stalkerware is quietly installed on people's devices, and then accesses personal data including GPS location, text messages, photos and microphone feeds. You don't have to be an expert to get your hands on it -- stalkerware is sold online, for as little as a few hundred dollars. Some purveyors offer subscription plans for $68 a month, according to Kaspersky Lab.

Kaspersky Lab said it was motivated to start flagging stalkerware apps after speaking with Eva Galperin, the Electronic Frontier Foundation's head of cybersecurity. "As a result, we now flag commercial spyware with a specific alert which warns users of the dangers stalkerware poses," Alexey Firsh, a security researcher at Kaspersky Lab, said in a statement. "We believe users have a right to know if such a program is installed on their device."

Security

Fake Cancerous Nodes in CT Scans, Created By Malware, Trick Radiologists (washingtonpost.com) 45

Researchers in Israel created malware to draw attention to serious security weaknesses in medical imaging equipment and networks. An anonymous reader shares a report: Researchers in Israel say they have developed malware to draw attention to serious security weaknesses in critical medical imaging equipment used for diagnosing conditions and the networks that transmit those images -- vulnerabilities that could have potentially life-altering consequences if unaddressed. The malware they created would let attackers automatically add realistic, malignant-seeming growths to CT or MRI scans before radiologists and doctors examine them. Or it could remove real cancerous nodules and lesions without detection, leading to misdiagnosis and possibly a failure to treat patients who need critical and timely care.

Yisroel Mirsky, Yuval Elovici and two others at the Ben-Gurion University Cyber Security Research Center in Israel who created the malware say that attackers could target a presidential candidate or other politicians to trick them into believing they have a serious illness and cause them to withdraw from a race to seek treatment. The research isn't theoretical. In a blind study the researchers conducted involving real CT lung scans, 70 of which were altered by their malware, they were able to trick three skilled radiologists into misdiagnosing conditions nearly every time. In the case of scans with fabricated cancerous nodules, the radiologists diagnosed cancer 99 percent of the time. In cases where the malware removed real cancerous nodules from scans, the radiologists said those patients were healthy 94 percent of the time.

Facebook

Millions of Facebook Records Found on Amazon Cloud Servers (bloomberg.com) 26

Researchers at UpGuard, a cybersecurity firm, found troves of Facebook user information hiding in plain sight, inadvertently posted publicly on Amazon.com's cloud computing servers. From a report: The discovery shows that a year after the Cambridge Analytica scandal exposed how unsecure and widely disseminated Facebook users' information is online, companies that control that information at every step still haven't done enough to seal up private data, Bloomberg News reports. In one instance, Mexico City-based media company Cultura Colectiva openly stored 540 million records on Facebook users, including identification numbers, comments, reactions and account names. That database was closed on Wednesday after Bloomberg alerted Facebook to the problem and Facebook contacted Amazon. Facebook shares pared their gains after the Bloomberg News report. UpGuard adds: The data sets vary in when they were last updated, the data points present, and the number of unique individuals in each. What ties them together is that they both contain data about Facebook users, describing their interests, relationships, and interactions, that were available to third party developers. As Facebook faces scrutiny over its data stewardship practices, they have made efforts to reduce third party access. But as these exposures show, the data genie cannot be put back in the bottle. Data about Facebook users has been spread far beyond the bounds of what Facebook can control today. Combine that plenitude of personal data with storage technologies that are often misconfigured for public access, and the result is a long tail of data about Facebook users that continues to leak.


Facebook

Facebook is Demanding Some Users Share the Password For Their Outside Email Account (thedailybeast.com) 194

An anonymous reader shares a report: Just two weeks after admitting it stored hundreds of millions of its users' own passwords insecurely, Facebook is demanding some users fork over the password for their outside email account as the price of admission to the social network. Facebook users are being interrupted by an interstitial demanding they provide the password for the email account they gave to Facebook when signing up. "To continue using Facebook, you'll need to confirm your email," the message demands. "Since you signed up with [email address], you can do that automatically ..." A form below the message asked for the users' "email password."

"That's beyond sketchy," security consultant Jake Williams told the Daily Beast. "They should not be taking your password or handling your password in the background. If that's what's required to sign up with Facebook, you're better off not being on Facebook." In a statement emailed to the Daily Beast after this story published, Facebook reiterated its claim it doesn't store the email passwords. But the company also announced it will end the practice altogether. "We understand the password verification option isn't the best way to go about this, so we are going to stop offering it," Facebook wrote. It's not clear how widely the new measure was deployed, but in its statement Facebook said users retain the option of bypassing the password demand and activating their account through more conventional means, such as "a code sent to their phone or a link sent to their email." Those options are presented to users who click on the words "Need help?" in one corner of the page.

Security

Researcher Prints 'PWNED!' On Hundreds of GPS Watches' Maps Due To Unfixed API (zdnet.com) 49

An anonymous reader quotes a report from ZDNet: A German security researcher has printed the word "PWNED!" on the tracking maps of hundreds of GPS watches after the watch vendor ignored vulnerability reports for more than a year, leaving thousands of GPS-tracking watches --some of which are used by children and the elderly-- open to attackers. Speaking at the Troopers 2019 security conference that was held in Heidelberg, Germany, at the end of March, security researcher Christopher Bleckmann-Dreher presented a series of vulnerabilities impacting over 20 models of GPS watches manufactured by Austrian company Vidimensio. The watch models all share a common backend API, which works as an intermediary and storage point between the GPS watches and associated mobile apps.

Back in December 2017, Dreher discovered flaws in the mechanism through which the GPS watches communicate with this backend API server. [...] Dreher's new warning comes as the number vulnerable Vidimensio GPS watches grew ten times since December 2017, despite the warning from German authorities to destroy and stop using children smartwatches with intrusive tracking and eavesdropping capabilities. According to the researcher, the number has grown from around 700 to 7,000, of which 3,000 have been active in the past month. To raise awareness to these still-unpatched devices, Dreher told ZDNet that he has now turned to an unconventional strategy. The researcher has been using one of the security flaws he discovered to insert fake GPS coordinates in people's location history. The researcher designed these fake GPS coordinates to look like the word "PWNED!" when displayed on the location history section map --displayed inside the mobile apps and the watches' web dashboard.

Firefox

Mozilla Will Run Two Experiments This Month With Firefox To Explore Ways To Fight Push Notification Permission Spam (zdnet.com) 98

Mozilla said this week that it intends to run two experiments over the course of this month to determine the most adequate way of dealing with push notification spam, a growing problem that is slowly deteriorating the web experience for everyone. From a report: The experiments will run in Firefox Nightly (v68) and Firefox Beta (v67). The Firefox Nightly experiment will run from April 1 to April 29. During this time, Mozilla said Firefox Nightly would only allow websites to show a push notification permission only after the user has clicked or pressed a key while on a website. All attempts to show a push notification permission request before a click or key press will be blocked by default. [...] In the last two weeks of the experiment, Firefox will show an icon in the URL bar, but with no visible popup on the page. Users can click this icon and accept any push notification permission requests if they wish so. Further reading: Mozilla and Scroll Partner To Test Alternative Funding Models for the Web.
The Internet

IT and Security Professionals Think Normal People Are Just the Worst (zdnet.com) 296

Two new studies reaffirm every computer dunce's worst fears: IT professionals blame the employees they're bound to help for their computer problems -- at least when it comes to security. From a report: One, courtesy of SaaS operations management platform BetterCloud, offers grim reading. 91 percent of the 500 IT and security professionals surveyed admitted they feel vulnerable to insider threats. Which only makes one wonder about the supreme (over-)confidence of the other 9 percent.

[...] Yet now I've been confronted with another survey. This one was performed by the Ponemon Institute at the behest of security-for-your-security company nCipher. Its sampling was depressingly large. 5,856 IT and security professionals from around the world were asked for their views of corporate IT security. They seemed to wail in unison at the lesser and more unwashed. Oh, an objective 30 percent insisted that external hackers were the biggest cause for concern. A teeth-gritting 54 percent, however, said the most extreme threat to corporate IT security came from employee mistakes.

Businesses

iPad Mini Makes Two Common Repairs 'Unnecessarily Difficult,' Says iFixit (cnet.com) 77

Apple has released the fifth-generation iPad Mini. So, of course, the repair experts at iFixit needed to tear it apart. From a report: The new 7.9 inch tablet, launched two weeks ago, sticks to its roots as a revamp of the iPad Mini 4, according to iFixit's teardown published Tuesday. One notable change is the battery connector design, which could prevent people trying to fix a device from accidentally killing the backlight during a repair, according to iFixit. The iFixit team calls this tweak "nifty!"

iFixit also noted that both the screen and battery are difficult to remove. The removal of the display, in particular, if not done carefully, could compromise the Touch ID technology. "Battery and screen replacements are the two most common repairs, and the iPad Mini makes both unnecessarily difficult," iFixit said. "The battery lacks pull-to-remove adhesive tabs, and the display requires a tricky removal of the home button if you want to keep Touch ID after your repair."

Encryption

Gmail Becomes First Major Email Provider To Support MTA-STS, TLS Reporting (zdnet.com) 25

Google announced today that Gmail has become the first major email provider to support two new security standards, namely MTA-STS and TLS Reporting. Both are extensions to the Simple Mail Transfer Protocol (SMTP), the protocol through which all emails are sent today. ZDNet reports: The purpose of MTA-STS and TLS Reporting is to help email providers establish cryptographically secure connections between each other, with the main goal of thwarting SMTP man-in-the-middle attacks. The two new standards will prevent this by allowing legitimate email providers to create a secure channel for exchanging emails. For example, SMTP MTA Strict Transport Security (MTA-STS) works by allowing email server admins to set up an MTA-STS policy on their server. This policy allows a legitimate provider to request that external email servers verify the security of a SMTP connections before sending any emails. Minimum requirements, such as forcing external email servers to authenticate with a valid public certificate encrypted with TLS 1.2 or higher, can be enforced, depending on preferences, ensuring that emails sent to a company's server travel through an obligatory and properly encrypted channel -- or they don't arrive at all.

In addition, the TLS Reporting SMTP extension sets up a reporting mechanism through which a legitimate email server can request daily reports from other email servers about the success or failure of emails that have been sent to the legitimate server's domain. Both, when combined, will either prevent or help email server admins identify SMTP man-in-the-middle attacks against their email traffic.

Operating Systems

Windows 10 Makes Large Share Gains, While Windows 7 Declines Significantly (betanews.com) 122

An anonymous reader shared a report: It took quite some time for Windows 10 to overtake Windows 7, but it finally did it in December 2018, at least according to NetMarketShare's figures. In February however, Windows 10 actually lost share, while Windows 7 gained some, narrowing the gap between the two operating systems once more. In March though, roles were reversed, as Windows 10 made some big gains, and Windows 7 lost a sizable chunk of its share. In the month just gone, NetMarketShare shows Windows 10 going from 40.30 percent to 43.62 percent, a big gain of 3.32 percentage points. There is currently a gap of 7.11 percentage points between Windows 10 and Windows 7.
Security

Over 13K iSCSI Storage Clusters Left Exposed Online Without a Password (zdnet.com) 48

Over 13,000 iSCSI storage clusters are currently accessible via the internet after their respective owners forgot to enable authentication. From a report: This misconfiguration has the risk of causing serious harm to devices' owners, as cyber-criminal groups could access these internet-accessible hard drives (storage disk arrays and NAS devices) to replace legitimate files with malware, insert backdoors inside backups, or steal company information stored on the unprotected devices. [...] Over the weekend, penetration tester A Shadow tipped ZDNet about this hugely dangerous misconfiguration issue. The researcher found over 13,500 iSCSI clusters on Shodan, a search engine that indexes internet-connected devices. In an online conversation with ZDNet, the researcher described this iSCSI exposure as a "dangerous backdoor" that can allow cyber-criminals to plant ransomware-infected files on companies' networks, steal company data, or place backdoors inside backup archives that may get activated when a company restores one of these booby-trapped files.
Network

Cloudflare Says Its New VPN Service Won't Slow You Down (wired.com) 73

Cloudflare has announced that it's adding a VPN service to its 1.1.1.1 DNS resolver app. The 1.1.1.1 service, which first came to mobile back in November, currently attempts to speed up mobile data speeds by using Cloudflare's network to resolve DNS queries faster than your existing mobile network. From a report: "We wanted to build a VPN service that my dad would install on his phone," says Cloudflare CEO Matthew Prince. "If you tell him that it will make his connection more private and secure, he'd never do it. But if you tell him it will make his connection faster, make his phone's battery last longer, and make his connections more private, then it would be something he'd install."

Mobile phone users can begin signing up for the service, dubbed Warp, through Cloudflare's mobile app 1.1.1.1 on Monday; Cloudflare says it hopes the service is working Monday, but it might take a few days. Regardless, Warp is a sign of things to come for the rest of the internet. The technology that Cloudflare is betting will make Warp fast is a protocol invented by Google called QUIC, and it could one day make the rest of the internet faster and more reliable. QUIC is essentially a substitute for TCP, the venerable protocol now used for most internet connections. TCP, introduced in 1981, made reliable internet connections possible, says Jana Iyengar, who worked on QUIC for Google; Iyengar is now a distinguished engineer at the cloud computing company Fastly working to help finalize QUIC with the Internet Engineering Task Force standards body.

Facebook

Years of Mark Zuckerberg's Old Facebook Posts Have Vanished. The Company Says it 'Mistakenly Deleted' Them. (businessinsider.com) 118

Old Facebook posts by Mark Zuckerberg have disappeared -- obscuring details about core moments in Facebook's history. An anonymous reader shares a report: On multiple occassions, years-old public posts made by the 34-year-old billionaire chief executive that were previously public and reported on by news outlets at the time have since vanished, Business Insider has found. That includes all of the posts he made during 2007 and 2008. Reached for comment, a Facebook spokesperson said the posts were "mistakenly deleted" due to "technical errors." "A few years ago some of Mark's posts were mistakenly deleted due to technical errors. The work required to restore them would have been extensive and not guaranteed to be successful so we didn't do it," the spokesperson said in a statement.

"We agree people should be able to find information about past announcements and major company news, which is why for years we've shared and archived this information publicly - first on our blog and in recent years on our Newsroom." The total number of vanished posts could be significantly higher, as the very nature of the issue makes it extremely difficult to make a full accounting of what exactly what has gone missing over the years. The spokesperson said they didn't know how many posts in total were deleted.

Google

Gmail Turns 15, Gets Smart Compose Improvements and Email Scheduling (techcrunch.com) 56

Today, to celebrate its fifteenth birthday, the Gmail team announced a couple of a new and useful Gmail features, including improvements to Smart Compose and the ability to schedule emails to be sent in the future. From a report: Smart Compose, which tries to autocomplete your emails as you type them, will now be able to adapt to the way you write the greetings in your emails. If you prefer 'Hey' over 'Hi,' then Smart Compose will learn that. If you often fret over which subject to use for your emails, then there's some relief here for you, too, because Smart Compose can now suggest a subject line based on the content of your email. With this update, Smart Compose is now also available on all Android devices.
Government

In Massive Breach, Ex-NSA Contractor Pleads Guilty to Hoarding Highly Classified Secrets (usatoday.com) 82

"A former National Security Agency contractor on Thursday pleaded guilty to stealing secret defense information over two decades in what legal experts have described as the biggest breach of classified information in U.S. history."

Long-time Slashdot reader mencik quotes USA Today: In his plea deal in U.S. District Court in Baltimore, Harold Thomas Martin III admitted to removing highly classified digital and hard copy documents, then storing them in his home and car from the late 1990s through 2016. Prosecutors say there is no indication Martin ever shared the stolen secrets. His defense attorneys say he simply hoarded the information... One of his lawyers previously described Martin as a "compulsive hoarder" who took home work documents...

Martin, who held multiple security clearances while working at government agencies as a private contractor, said he knew stealing the documents risked the country's security. He pleaded guilty on Thursday to one felony count of willful retention of national defense information. He could be sentenced to nine years in prison.

Martin also told a federal judge that he'd been diagnosed with ADHD. "His actions were the product of mental illness," his federal defenders' statement said. "Not treason."

Slashdot Top Deals