Security

Saudis Gained Access to Amazon CEO's Phone, Says Bezos' Security Chief (thedailybeast.com) 118

"The security chief for Amazon chief executive Jeff Bezos said on Saturday that the Saudi government had access to Bezos' phone and gained private information from it," Reuters reports.

But in addition, the National Enquirer's lawyer "tried to get me to say there was no hacking," writes security specialist Gavin de Becker. I've recently seen things that have surprised even me, such as National Enquirer's parent company, AMI, being in league with a foreign nation that's been actively trying to harm American citizens and companies, including the owner of the Washington Post. You know him as Jeff Bezos; I know him as my client of 22 years... Why did AMI's people work so hard to identify a source, and insist to the New York Times and others that he was their sole source for everything? My best answer is contained in what happened next: AMI threatened to publish embarrassing photos of Jeff Bezos unless certain conditions were met. (These were photos that, for some reason, they had held back and not published in their first story on the Bezos affair, or any subsequent story.) While a brief summary of those terms has been made public before, others that I'm sharing are new -- and they reveal a great deal about what was motivating AMI.

An eight-page contract AMI sent for me and Bezos to sign would have required that I make a public statement, composed by them and then widely disseminated, saying that my investigation had concluded they hadn't relied upon "any form of electronic eavesdropping or hacking in their news-gathering process." Note here that I'd never publicly said anything about electronic eavesdropping or hacking -- and they wanted to be sure I couldn't.... An earlier set of their proposed terms included AMI making a statement "affirming that it undertook no electronic eavesdropping in connection with its reporting and has no knowledge of such conduct" -- but now they wanted me to say that for them. The contract further held that if Bezos or I were ever in our lives to "state, suggest or allude to" anything contrary to what AMI wanted said about electronic eavesdropping and hacking, then they could publish the embarrassing photos.

I'm writing this today because it's exactly what the Enquirer scheme was intended to prevent me from doing. Their contract also contained terms that would have inhibited both me and Bezos from initiating a report to law enforcement.

Things didn't work out as they hoped.

De Becker instead turned over his investigation's results to U.S. federal officials, then published today's essay warning the National Enquirer and its chairman have "evolved into trying to strong-arm an American citizen whom that country's leadership wanted harmed, compromised, and silenced." He also suggests it's in response to the "relentless" coverage by the Washington Post (which Bezos owns) of the murder of Saudi Arabian journalist and dissident Jamal Khashoggi.

"Experts with whom we consulted confirmed New York Times reports on the Saudi capability to 'collect vast amounts of previously inaccessible data from smartphones in the air without leaving a trace -- including phone calls, texts, emails.'"
IT

Are We Experiencing a Burnout Epidemic? (washingtonpost.com) 174

"Burnout is everywhere," reports the Washington Post.

"Caused in part by social media, the 24-hour news cycle and the pressure to check work email outside of office hours, it could hit you, too -- especially if you don't know how to nip it in the bud..." A recent report from Harvard and Massachusetts medical organizations declared physician burnout a public health crisis. It pointed out the problem not only harms doctors but also patients. "Burnout is associated with increasing medical errors," the paper said... Ninety-five percent of human resource leaders say burnout is sabotaging workplace retention, often because of overly heavy workloads, one [2017] survey found. Poor management contributes to the burnout epidemic. "Organizations typically reward employees who are putting in longer hours and replace workers who aren't taking on an increased workload, which is a systematic problem that causes burnout in the first place," says Dan Schawbel, research director of Future Workplace, the firm that conducted the survey along with Kronos

Part of the difficulty of pinpointing true burnout may be because burnout is a nonmedical term -- at least in the United States. The Diagnostic and Statistical Manual of Mental Disorders doesn't list it as an illness. But other countries including France, Denmark and Sweden, do recognize burnout syndrome and consider it to be a legitimate reason to take a sick day from work.... For those who suspect they might be on the road to burnout, there are practical tools to mitigate it. Among others: physical exercise, sleep and positive social connection (the real kind, not the Facebook kind).

The Post also ran a follow-up article which suggests that to fight burnout, companies need to set reasonable work hours -- and develop a culture encouraging breaks and vacations.
IT

The Dangers of Sharing Your Screen With Co-Workers (seattletimes.com) 132

"if you must goof off at work, then at the very least manage your notification settings so that your alerts are muted, and aren't broadcast on the big screen when you screen share in the boardroom," warns the New York Times -- offering several examples of what can go wrong.

An anonymous reader quotes their follow-up report: Whether it's happened to you or in front of you, many of us are familiar with the screen-share disaster: the accidental exposure of something private while projecting your screen before a group of colleagues.

The only surefire way to avoid this is to do as the lawyers recommend and keep your personal things on your personal devices and your work things on you work computer. Sonia Farber, a partner and founder of , acknowledges that may not be feasible for everyone. "But, to the extent that you can keep some separation of church and state, you should make every effort to do that," she said.

The Times offers a checklist for "how not to ruin your life (or just die of embarrassment) with a screen share" -- offering common-sense tips like managing desktop notifications and signing out of messaging apps before meetings. (And of course, not leaving open any tell-tale browser tabs.) But have Slashdot's readers seen (or experienced) any screen-sharing disasters in their own lives?

Share your stories in the comments. What are the dangers of sharing your screen with co-workers?
Cellphones

Phone Carrier Apps Can Help Fight Robocalls -- Sometimes, Even For Free (cnn.com) 69

Friday CNN reported on "what you can do right now to stop robocalls."

"Short of throwing your phone in the garbage, there's no way to avoid them altogether. But wireless providers and smartphone developers offer tools to filter out at least some unwanted calls." - Verizon's Call Filter app is free to download on iPhones and Android devices. The company announced Thursday the app will offer some free features -- including auto-blocking calls from known fraudsters, showing warning banners for suspicious calls, and a spam reporting tool. For $2.99 a month per line, the Call Filter app can use a phonebook feature to look up the names of unknown callers, and it can show a "risk meter" for spam calls.

- AT&T's Call Protect has similar free features and add-ons with a $3.99 per month subscription. (iOS and Android)

- T-Mobile phones come loaded with Scam ID, which warns customers about suspicious phone numbers. It's also free to activate Scam Block, which automatically rejects calls from those numbers. An additional app called Name ID offers premium caller identification for $4 per line monthly. (iOS and Android)

- Sprint's Premium Caller ID , which comes pre-installed, looks up unknown numbers and filters and blocks robocalls for $2.99 per line.

- Google's Pixel phones also give you the option to have your voice assistant answer suspicious calls for you. The phone can transcribe the conversation and lets you decide whether to answer.

Security

Casino Accused of Withholding Bug Bounty, Then Assaulting 'Ethical Hacker' (arstechnica.com) 65

An anonymous reader quotes Ars Technica: People who find security vulnerabilities commonly run into difficulties when reporting them to the responsible company. But it's less common for such situations to turn into tense trade-show confrontations -- and competing claims of assault and blackmail. Yet that's what happened when executives at Atrient -- a casino technology firm headquartered in West Bloomfield, Michigan -- stopped responding to two UK-based security researchers who had reported some alleged security flaws. The researchers thought they had reached an agreement regarding payment for their work, but nothing final ever materialized. On February 5, 2019, one of the researchers -- Dylan Wheeler, a 23-year-old Australian living in the UK -- stopped by Atrient's booth at a London conference to confront the company's chief operating officer.

What happened next is in dispute. Wheeler says that Atrient COO Jessie Gill got in a confrontation with him and yanked off his conference lanyard; Gill insists he did no such thing, and he accused Wheeler of attempted extortion.

The debacle culminated in legal threats and a lot of mudslinging, with live play-by-play commentary as it played out on Twitter.

Ars Technica calls the story "practically a case study in the problems that can arise with vulnerability research and disclosure," adding "the vast majority of companies have no clear mechanism for outsiders to share information about security gaps."

A security research director at Rapid7 joked his first reaction was "man, I wish a vendor would punch me for disclosure. Boy, that beats any bug bounty." But they later warned, "It's on us as an industry not only to train corporate America on how to take disclosure, but also we need to do a little more training for people who find these bugs -- especially today, in an era where bug outings are kind of normal now -- to not expect someone to be necessarily grateful when one shows up."
Privacy

Tesla Cars Keep More Data Than You Think (cnbc.com) 57

Tesla vehicles sent to the junk yard after a crash carry much more data than you'd think. According to CNBC, citing two security researchers, "Computers on Tesla vehicles keep everything that drivers have voluntarily stored on their cars, plus tons of other information generated by the vehicles including video, location and navigational data showing exactly what happened leading up to a crash." From the report: One researcher, who calls himself GreenTheOnly, describes himself as a "white hat hacker" and a Tesla enthusiast who drives a Model X. He has extracted this kind of data from the computers in a salvaged Tesla Model S, Model X and two Model 3 vehicles, while also making tens of thousands of dollars cashing in on Tesla bug bounties in recent years. Many other cars download and store data from users, particularly information from paired cellphones, such as contact information.

But the researchers' findings highlight how Tesla is full of contradictions on privacy and cybersecurity. On one hand, Tesla holds car-generated data closely, and has fought customers in court to refrain from giving up vehicle data. Owners must purchase $995 cables and download a software kit from Tesla to get limited information out of their cars via "event data recorders" there, should they need this for legal, insurance or other reasons. At the same time, crashed Teslas that are sent to salvage can yield unencrypted and personally revealing data to anyone who takes possession of the car's computer and knows how to extract it. The contrast raises questions about whether Tesla has clearly defined goals for data security, and who its existing rules are meant to protect.
A Tesla spokesperson said in a statement to CNBC: "Tesla already offers options that customers can use to protect personal data stored on their car, including a factory reset option for deleting personal data and restoring customized settings to factory defaults, and a Valet Mode for hiding personal data (among other functions) when giving their keys to a valet. That said, we are always committed to finding and improving upon the right balance between technical vehicle needs and the privacy of our customers."

The report serves as a reminder for Tesla owners to factory reset their cars before handing them off to a junk yard or other reseller because that other party may not reset your car for you. "Tesla sometimes uses an automotive auction company called Manheim to inspect, recondition and sell used cars," reports CNBC. "A former Manheim employee, who asked to remain anonymous, confirmed that employees do not wipe the cars' computers with a factory reset."

The researchers were able to obtain phonebooks "worth of contact information from drivers or passengers who had paired their devices, and calendar entries with descriptions of planned appointments, and e-mail addresses of those invited." The data also showed the drivers' last 73 navigation locations, as well as crash-related information. The Model 3 that one of the researchers bought for research purposes contained a video showing the car speeding out of the right lane into the trees off the left side of a dark two-lane route. "GPS and other vehicle data reveals that the accident happened in Orleans, Massachusetts, on Namequoit Road, at 11:15 pm on Aug 11, and was severe enough that airbags deployed," the report adds.
Security

Critical Magento SQL Injection Flaw Could Soon Be Targeted By Hackers (csoonline.com) 14

itwbennett writes: The popular e-commerce platform Magento has released 37 security issues affecting both the commercial and open-source versions, four of which are critical. "Of those, one SQL injection flaw is of particular concern for researchers because it can be exploited without authentication," writes Lucian Constantine for CSO. Researchers from Web security firm Sucuri "have already reverse-engineered the patch [for that flaw] and created a working proof-of-concept exploit for internal testing," says Constantin. "The SQL vulnerability is very easy to exploit, and we encourage every Magento site owner to update to these recently patched versions to protect their ecommerce websites," the researchers warn in a blog post. "Unauthenticated attacks, like the one seen in this particular SQL Injection vulnerability, are very serious because they can be automated -- making it easy for hackers to mount successful, widespread attacks against vulnerable websites," the Sucuri researchers warned. "The number of active installs, the ease of exploitation, and the effects of a successful attack are what makes this vulnerability particularly dangerous." Since the researchers were able to create a working proof-of-concept exploit, it's only a matter of time until hackers discover a way to use the exploit to plant payment card skimmers on sites that have yet to install the new patch.

UPDATE: Onilab, an official Magento development partner, has a blog post explaining how you can update your store to the latest version of Magento.
Intel

Intel Lays Off Hundreds of Tech Admins (oregonlive.com) 97

Intel has reportedly laid off a number of information technology workers at sites across the company this week. Sources say the layoffs are numbered in the hundreds, but Intel has declined to specify how many people lost their jobs or describe the rationale for the cutbacks. OregonLive reports: The cuts took place at sites across the company, including Oregon, Intel's largest site with 20,000 workers. Cuts also took place at other Intel facilities in the United States and at a large administrative facility in Costa Rica, according to people familiar with the layoffs. Though Intel forecasts flat sales in 2019, people inside the company said this week's layoffs don't appear to be strictly a cost-cutting move. Rather, they said the cuts appeared to reflect a broad change in the way Intel is approaching its internal technical systems.

Information technology (IT) professionals don't usually develop new technology but they play an essential role in managing a company's internal systems. Their work is particularly important at tech companies such as Intel, which depend on IT workers to keep systems secure and running smoothly. This week's layoffs appear to be Intel's biggest cutbacks since 2016, when the company eliminated 15,000 jobs across the company through layoffs, buyouts and early retirement offers.
"Changes in our workforce are driven by the needs and priorities of our business, which we continually evaluate. We are committed to treating all impacted employees with professionalism and respect," Intel said in a brief statement acknowledging the cuts to The Oregonian/OregonLive.

Intel isn't the only tech company laying off workers right now. A new report from The Mercury News reveals many Bay Area tech firms will be laying off about 1,200 jobs between now and Memorial Day. The layoffs are expected from SAP, Oracle America, PayPal, Instacart, Thin Film Electronics, and others.
Security

Toyota Security Breach Exposes Personal Info of 3.1 Million Clients (bleepingcomputer.com) 19

An anonymous reader quotes a report from BleepingComputer: The personal information of roughly 3.1 million Toyota customers may have been leaked following a security breach of multiple Toyota and Lexus sales subsidiaries, as detailed in a breach notification issued by the car maker today. As detailed in a press release published on Toyota'a global newsroom, unauthorized access was detected on the computing systems of Tokyo Sales Holdings, Tokyo Tokyo Motor, Tokyo Toyopet, Toyota Tokyo Corolla, Nets Toyota Tokyo, Lexus Koishikawa Sales, Jamil Shoji (Lexus Nerima), and Toyota West Tokyo Corolla. "It turned out that up to 3.1 million items of customer information may have been leaked outside the company. The information that may have been leaked this time does not include information on credit cards," says the data breach notification. Toyota has not yet confirmed if the attackers were able to exfiltrate any of the customer personal information exposed after the IT systems of its subsidiaries were breached. Toyota said in a statement: "We apologize to everyone who has been using Toyota and Lexus vehicles for the great concern. We take this situation seriously, and will thoroughly implement information security measures at dealers and the entire Toyota Group."
Security

Critical Magento SQL Injection Flaw Could Soon Be Targeted By Hackers (csoonline.com) 13

itwbennett writes: The popular e-commerce platform Magento has released 37 security issues affecting both the commercial and open-source versions, four of which are critical. 'Of those, one SQL injection flaw is of particular concern for researchers because it can be exploited without authentication,' writes Lucian Constantine for CSO. Researchers from Web security firm Sucuri 'have already reverse-engineered the patch [for that flaw] and created a working proof-of-concept exploit for internal testing' says Constantin. 'The SQL vulnerability is very easy to exploit, and we encourage every Magento site owner to update to these recently patched versions to protect their ecommerce websites,' the researchers warn in a blog post.
Android

Google: Play Protect Cut Harmful Android App Installs by 20% in 2018 (venturebeat.com) 26

Speaking of the state of Android apps' security, Google today published its annual Android Security & Privacy Year in Review, a comprehensive report that details the company's ongoing efforts to keep over two billion devices running Android mobile operating system secure. From a report: Google says that Google Play Protect, Android's AI-driven built-in defense mechanism, substantially cut down on the number of Potentially Harmful Applications (PHAs) in Google Play. Last year, only 0.08 percent of devices that used Google Play exclusively for app downloads were affected by PHAs, and even devices that installed apps from outside of Play -- 0.68 percent of which were affected by one or more PHAs, down from 0.80 percent in 2017 -- saw a 15 percent reduction in malware. In fact, Play Protect prevented 1.6 billion PHA installation attempts from outside of Google Play in 2018, Google says [PDF]. Installation attempts outside of Google Play fell by 20 percent from the previous year, and 73 percent of PHA installations were successfully stopped compared to 71 percent in 2017 and 59 percent in 2016. In all, 0.45 percent of Android devices running Play Protect installed PHAs in 2018 compared with 0.56 percent of devices in 2017, equating to a 20 percent year-over-year improvement.
Bug

macOS 10.14.4 Mail Client Has Broken Gmail Access For Some Users (apple.com) 48

New submitter _observer writes: Hundreds of users are unable to read their Gmail in Apple's Mail client since the upgrade to macOS 10.14.4, with few workaround available. This is impacting business and personal users, although not all Gmail accounts are impacted. The web client and other clients like Outlook still work -- it is only Apple's Mail client that is not playing along. Users say they are caught in a login loop. It appears that the issue was even found and reported in the 10.14.4 Beta, but not addressed when the update was released. No word from Apple about this. While I am somewhat sympathetic to the software engineers having bugs in code (I am an engineer, too), but this seems to be a big QA miss. Gmail is the most popular free email service and this is blocking a large number of users. This thread on the Apple Support forum is growing rapidly (24 pages and counting)
Security

Researchers Discover and Abuse New Undocumented Feature in Intel Chipsets (zdnet.com) 102

At the Black Hat Asia 2019 security conference, security researchers from Positive Technologies disclosed the existence of a previously unknown and undocumented feature in Intel chipsets. From a report: Called Intel Visualization of Internal Signals Architecture (Intel VISA), Positive Technologies researchers Maxim Goryachy and Mark Ermolov said this is a new utility included in modern Intel chipsets to help with testing and debugging on manufacturing lines. VISA is included with Platform Controller Hub (PCH) chipsets part of modern Intel CPUs and works like a full-fledged logic signal analyzer. According to the two researchers, VISA intercepts electronic signals sent from internal buses and peripherals (display, keyboard, and webcam) to the PCH -- and later the main CPU. Unauthorized access to the VISA feature would allow a threat actor to intercept data from the computer memory and create spyware that works at the lowest possible level. But despite its extremely intrusive nature, very little is known about this new technology.
Microsoft

As Windows 10 19H1 Update Approaches, Microsoft Says Version 1809 is Now Ready For 'Broad Deployment' (onmsft.com) 58

We're now very close to the next semi-annual update for Windows 10, but Microsoft has just announced today that the version 1809 released last Fall is now the recommended version for all users. From a report: This is a new milestone in the troubled history of this major release, as Microsoft had to pause its public rollout after discovering a serious file deletion bug in October. "Based on the data and the feedback we've received from consumers, OEMs, ISVs, partners, and commercial customers, Windows 10, version 1809 has transitioned to broad deployment," wrote John Wilcox, Windows as a service evangelist on the Windows IT Pro blog today. We're now a little more than four months removed from Microsoft's re-released Windows 10 version 1803, and Microsoft previously admitted that it would be more cautious during the public rollout. According to AdDuplex's latest survey on more than 100,000 Windows 10 PCS, only 26.4% of them were running the version 1809 in March.
Android

Researchers Find Google Play Store Apps Were Actually Government Malware (vice.com) 41

Security researchers have found a new kind of government malware that was hiding in plain sight within apps on Android's Play Store. And they appear to have uncovered a case of lawful intercept gone wrong. An anonymous reader writes: This new case once again highlights the limits of Google's filters that are intended to prevent malware from slipping onto the Play Store. In this case, more than 20 malicious apps went unnoticed by Google over the course of roughly two years. Motherboard has also learned of a new kind of Android malware on the Google Play store that was sold to the Italian government by a company that sells surveillance cameras but was not known to produce malware until now. Experts told Motherboard the operation may have ensnared innocent victims as the spyware appears to have been faulty and poorly targeted. Legal and law enforcement experts told Motherboard the spyware could be illegal. The spyware apps were discovered and studied in a joint investigation by researchers from Security Without Borders, a non-profit that often investigates threats against dissidents and human rights defenders, and Motherboard. The researchers published a detailed, technical report of their findings on Friday.
Crime

Security Researcher Pleads Guilty To Hacking Into Microsoft and Nintendo (theverge.com) 53

24-year-old security researcher Zammis Clark pleaded guilty today to hacking into Microsoft and Nintendo servers and stealing confidential information. Clark, known online as Slipstream or Raylee, "was charged on multiple counts of computer misuse offenses in a London Crown Court on Thursday, and pleaded guilty to hacking into Microsoft and Nintendo networks," reports The Verge. From the report: Prosecutors revealed that Clark had gained access to a Microsoft server on January 24th, 2017 using an internal username and password, and then uploaded a web shell to remotely access Microsoft's network freely for at least three weeks. Clark then uploaded multiple shells which allowed him to search through Microsoft's network, upload files, and download data. In total, around 43,000 files were stolen after Clark targeted Microsoft's internal Windows flighting servers. These servers contain confidential copies of pre-release versions of Windows, and are used to distribute early beta code to developers working on Windows. Clark targeted unique build numbers to gain information on pre-release versions of Windows in around 7,500 searches for unreleased products, codenames, and build numbers.

Clark then shared access to Microsoft's servers through an Internet Relay Chat (IRC) server chatroom, allowing other individuals to access and steal confidential information. Prosecutors say other hackers from France, Germany, the United Arab Emirates, and other countries were then able to access Microsoft's servers. Police found the stolen files on Clark's home computer after a joint investigation involving Microsoft's cyber team, the FBI, EUROPOL, and the NCA's National Cyber Crime Unit (NCCU). [...] The Microsoft intrusion ended when Clark uploaded malware onto Microsoft's network, and he was subsequently arrested in June, 2017. Clark was then bailed without any restrictions on his computer use, and went on to hack into Nintendo's internal network in March last year. Clark gained access through Virtual Private Networks (VPNs) and used similar software to hack into Nintendo's highly confidential game development servers. These servers store development code for unreleased games, and Clark was able to steal 2,365 usernames and passwords until Nintendo eventually discovered the breach in May 2018. Nintendo estimates the cost of damages between $913,000 and $1.8 million, and Microsoft previously provided the court with a vague estimate of around $2 million in damages.
26-year-old Thomas Hounsell, known in the Windows community for running the now discontinued BuildFeed website, appeared alongside Clark in court on Thursday for using Clark's Microsoft server breach to conduct more than 1,000 searches for products, codenames, and build numbers over a 17-day period, the report adds.
Encryption

Russia Orders Major VPN Providers To Block 'Banned' Sites (torrentfreak.com) 87

Russian authorities have ordered ten major VPN providers to begin blocking sites on the country's blacklist. "NordVPN, ExpressVPN, IPVanish and HideMyAss are among those affected," reports TorrentFreak. "TorGuard also received a notification and has pulled its services out of Russia with immediate effect." From the report: During the past few days, telecoms watch Roscomnadzor says it sent compliance notifications to 10 major VPN services with servers inside Russia -- NordVPN, ExpressVPN, TorGuard, IPVanish, VPN Unlimited, VyprVPN, Kaspersky Secure Connection, HideMyAss!, Hola VPN, and OpenVPN. The government agency is demanding that the affected services begin interfacing with the FGIS database, blocking the sites listed within. Several other local companies -- search giant Yandex, Sputnik, Mail.ru, and Rambler -- are already connected to the database and filtering as required.

"In accordance with paragraph 5 of Article 15.8 of the Federal Law No. 149-FZ of 27.07.2006 'On Information, Information Technology and on Protection of Information' hereby we are informing you about the necessity to get connected to the Federal state informational system of the blocked information sources and networks [FGIS] within thirty working days from the receipt [of this notice]," the notice reads. A notice received by TorGuard reveals that the provider was indeed given just under a month to comply. The notice also details the consequences for not doing so, i.e being placed on the blacklist with the rest of the banned sites so it cannot operate in Russia. The demand from Roscomnadzor sent to TorGuard and the other companies also requires that they hand over information to the authorities, including details of their operators and places of business. The notice itself states that for foreign entities, Russian authorities require the full entity name, country of residence, tax number and/or trade register number, postal and email address details, plus other information.

Security

Researchers Find 36 New Security Flaws In LTE Protocol (zdnet.com) 23

An anonymous reader quotes a report from ZDNet: A group of academics from South Korea have identified 36 new vulnerabilities in the Long-Term Evolution (LTE) standard used by thousands of mobile networks and hundreds of millions of users across the world. The vulnerabilities allow attackers to disrupt mobile base stations, block incoming calls to a device, disconnect users from a mobile network, send spoofed SMS messages, and eavesdrop and manipulate user data traffic. They were discovered by a four-person research team from the Korea Advanced Institute of Science and Technology Constitution (KAIST), and documented in a research paper they intend to present at the IEEE Symposium on Security and Privacy in late May 2019.

The Korean researchers said they found 51 LTE vulnerabilities, of which 36 are new, and 15 have been first identified by other research groups in the past. They discovered this sheer number of flaws by using a technique known as fuzzing --a code testing method that inputs a large quantity of random data into an application and analyzes the output for abnormalities, which, in turn, give developers a hint about the presence of possible bugs. The resulting vulnerabilities, see image below or this Google Docs sheet, were located in both the design and implementation of the LTE standard among the different carriers and device vendors. The KAIST team said it notified both the 3GPP (industry body behind LTE standard) and the GSMA (industry body that represents mobile operators), but also the corresponding baseband chipset vendors and network equipment vendors on whose hardware they performed the LTEFuzz tests.

Security

Huawei's Equipment Poses 'Significant' Security Risks, UK Says (cnbc.com) 131

The U.K. government warned on Thursday Huawei's telecommunications equipment raises "significant" security issues, posing a possible setback to the Chinese tech firm as it looks to build out 5G networks. From a report: In 46-page report evaluating Huawei's security risks, British officials stopped short of calling for a ban of Huawei's 5G telecommunications equipment. But the assessment cited "underlying defects" in the company's software engineering and cybersecurity processes, citing "significantly increased risk to U.K. operators." The findings give weight to warnings from U.S. officials who have argued Huawei's networking equipment could be used for espionage by the Chinese government. Huawei has repeatedly said it does not pose any risk and insists it would not share customer data with Beijing. In a statement Thursday, Huawei said it takes the U.K. government's findings "very seriously."
Crime

Office Depot and Support.com To Pay $35 Million To Settle FTC Allegations That They Charged Users Millions in 'Fake' Malware Cleanup Fees (theregister.co.uk) 56

Office Depot and Support.com have coughed up $35 million after they were accused of lying to people that their PCs were infected with malware in order to charge them cleanup fees. From a report: Late Wednesday, the pair of businesses settled a lawsuit brought against them by the US Federal Trade Commission, which alleged staff at the tech duo falsely claimed software nasties were lingering on customers' computers to make a fast buck. The lawsuit, filed in southern Florida, claimed the two companies, including Office Depot subsidiary OfficeMax, from 2009 until November 2016 misrepresented the state of consumers' computers by using a sales tool designed to convince people to pay for diagnostic and repair services.

"In numerous instances throughout this time period, Defendants used the PC Health Check Program to report to Office Depot Companies customers that the scan had found or identified 'Malware Symptoms' when it had not done so," the complaint stated. "Additionally, in numerous instances, the PC Health Check Program falsely reported to consumers that the program had found 'infections' on the consumer's computer." According to the watchdog's complaint, the PC Health Check Program was incapable of finding malware. Support.com allegedly programmed the software so that whenever an Office Depot Company employee checked any one of four checkboxes describing a generic concern, like slowness, before the scan started, the scan would automatically report the detection of malware symptoms, and for a time, infections.

Slashdot Top Deals