Intel

USB 4 Will Support Thunderbolt and Double the Speed of USB 3.2 (engadget.com) 165

At a Taipei event earlier today, Intel revealed that USB 4 will once again utilize dual channels to achieve 40Gbps speeds, even on existing 40Gbps-certified USB-C cables. A report adds: Better yet, thanks to Intel finally offering Thunderbolt 3 to manufacturers with open licensing, USB 4 will be integrating this tech and thus effectively becoming the "new" Thunderbolt 3. In other words, USB 4 will pretty much be the mother of all wired connectivity options, and will be ready for more powerful PCIe plus DisplayPort devices. It is expected to take 18 months between the final spec of USB 4 being published in the second half of this year, and the first devices hitting the market, so don't expect to see USB 4-powered commercial devices until sometime in 2021.
Further reading, from last week: USB-IF Confusingly Merges USB 3.0 and USB 3.1 Under New USB 3.2 Branding.
Security

40% of Malicious URLs Were Found on Good Domains (helpnetsecurity.com) 75

Help Net Security shared an interesting statistic from the 2019 Webroot Threat Report. 40 percent of malicious URLs were found on good domains. Legitimate websites are frequently compromised to host malicious content.

To protect users, cybersecurity solutions need URL-level visibility or, when unavailable, domain-level metrics, that accurately represent the dangers.

The report also found that while Google was the single most impersonated brand in phishing, 77% of all phishing attacks impersonated financial institutions. (The good news? After 12 months of security awareness training, end users were 70% less likely to fall for phishing attacks.)

And Windows 10 devices were "at least twice as secure as those running Windows 7. Webroot has seen a relatively steady decline in malware on Windows 10 machines for both consumer and business."
Databases

Massive Database Leak Exposes China's 'Digital Surveillance State' (eff.org) 72

Long-time Slashdot reader retroworks shared this EFF article: Although relatively little news gets out of Xinjiang to the rest of the world, we've known for over a year that China has been testing facial-recognition tracking and alert systems across Xinjiang and mandating the collection of biometric data -- including DNA samples, voice samples, fingerprints, and iris scans -- from all residents between the ages of 12 and 65... Earlier this month, security researcher Victor Gevers found and disclosed an exposed database live-tracking the locations of about 2.6 million residents of Xinjiang, China, offering a window into what a digital surveillance state looks like in the 21st century...

Over a period of 24 hours, 6.7 million individual GPS coordinates were streamed to and collected by the database, linking individuals to various public camera streams and identification checkpoints associated with location tags such as "hotel," "mosque," and "police station." The GPS coordinates were all located within Xinjiang. This database is owned by the company SenseNets, a private AI company advertising facial recognition and crowd analysis technologies. A couple of days later, Gevers reported a second open database tracking the movement of millions of cars and pedestrians. Violations like jaywalking, speeding, and going through a red-light are detected, trigger the camera to take a photo, and ping a WeChat API, presumably to try and tie the event to an identity.

China may have a working surveillance program in Xinjiang, but it's a shockingly insecure security state. Anyone with an Internet connection had access to this massive honeypot of information... Even poorly-executed surveillance is massively expensive, and Beijing is no doubt telling the people of Xinjiang that these investments are being made in the name of their own security. But the truth, revealed only through security failures and careful security research, tells a different story: China's leaders seem to care little for the privacy, or the freedom, of millions of its citizens.

EFF also reports that a Chinese cybersecurity firm also recently discovered 468 exposed MongoDB servers on the internet, including databases containing detailed information about remote access consoles owned by China General Nuclear Power Group.

Meanwhile, ZDNet suggests that SenseNets may actually be "a government contractor, helping authorities track the Muslim minority, rather than a private company selling its product to another private entity. Otherwise, it would be hard to explain how SenseNets has access to ID card information and camera feeds from police stations and other government buildings."
Crime

Workplace Theft Is On the Rise (theatlantic.com) 328

rfengineer tipped us off to this story. The Atlantic reports: Your office is a den of thieves. Don't take my word for it: When a forensic-accounting firm surveyed workers in 2013, 52 percent admitted to stealing company property. And the thievery is getting worse. The Association of Certified Fraud Examiners reports that theft of "non-cash" property -- ranging from a single pencil in the supply closet to a pallet of them on the company loading dock -- jumped from 10.6 percent of corporate-theft losses in 2002 to 21 percent in 2018. Managers routinely order up to 20 percent more product than is necessary, just to account for sticky-fingered employees.

Some items -- scissors, notebooks, staplers -- are pilfered perennially; others vanish on a seasonal basis: The burn rate on tape spikes when holiday gifts need wrapping, and parents ransack the supply closet in August, to avoid the back-to-school rush at Target. After a new Apple gadget is released, some workers report that their company-issued iPhone is broken -- knowing that IT will furnish a replacement, no questions asked. What's behind this 9-to-5 crime wave? Mark R. Doyle, the president of the loss-prevention consultancy Jack L. Hayes International, points to a decrease in supervision, the ease of reselling purloined products online, and what he alleges is "a general decline in employee honesty."

The report advises companies that the best way to reduce fraud was with surprise audits and data monitoring.

Another interesting statistic? "Fraudsters" who'd been with their company for more than five years "stole twice as much."
Botnet

Qbot Malware Resurfaces In New Attack Against Businesses (csoonline.com) 120

itwbennett writes: Security researchers at Varonis have uncovered a new attack using a new version of the venerable Qbot malware that "creates scheduled tasks and adds entries to the system registry to achieve persistence," writes Lucian Constantin, reporting on the attack for CSO. "The malware then starts recording all keystrokes typed by users, steals credentials and authentication cookies saved inside browsers, and injects malicious code into other processes to search for and steal financial-related text strings." The researchers "found logs showing 2,726 unique victim IP addresses," writes Constantin, but because "computers inside an organization typically access the internet through a shared IP address, the researchers believe the number of individually infected systems to be much larger." The malware first appeared in 2009 and was found to be uploading 2GB of stolen confidential information to its FTP servers each week by April 2010 from private and public sector computers, including 1,100 on the NHS network in the UK. A modified version of the malware resurfaced in April 2016 that was believed to have infected more than 54,000 PCs in thousands of organizations around the world. As Varonis now reports, Qbot is making yet another comeback.
Cellphones

Comcast Set Mobile Pins To '0000,' Helping Attackers Steal Phone Numbers (arstechnica.com) 30

An anonymous reader quotes a report from Ars Technica: A bad security decision by Comcast on the company's mobile phone service made it easier for attackers to port victims' cell phone numbers to different carriers. Comcast in 2017 launched Xfinity Mobile, a cellular service that uses the Verizon Wireless network and Comcast Wi-Fi hotspots. Comcast has signed up 1.2 million mobile subscribers but took a shortcut in the system that lets users switch from Comcast to other carriers. To port a phone line from Comcast to another wireless carrier, a customer needs to know his or her Comcast mobile account number. Carriers generally use PINs to verify that a customer seeking to port a number actually owns the number. But Comcast reportedly set the PIN to 0000 for all its customers, and there was apparently no way for customers to change it. That means that an attacker who acquired a victim's Comcast account number could easily port the victim's phone number to another carrier. Comcast told Ars that "less than 30" customers were affected by the problem, that it has implemented a fix, and that the company will eventually roll out a real PIN-based system to further protect customers. But Comcast declined to describe the recent fix in any way, saying that information could help attackers. Comcast also did not say when its new PIN-based system will be ready. Here's what Comcast had to say about the changes it's made and will make: "We have also implemented a solution that provides additional safeguards around our porting process, and we're working aggressively towards a PIN-based solution. We are reaching out to impacted customers to apologize and work with them to address the issue. We take this very seriously, and our fraud detection and prevention methods, policies and procedures are continually being reviewed, tested and refined."
Microsoft

Microsoft Excel Can Now Turn Pictures of Tables Into Actual, Editable Tables (thurrott.com) 82

Microsoft has rolled out a new feature to Excel's Android app that makes it easy to capture data. From a report: Excel now lets you take pictures of a document/paper in real life, crop the picture, and turn that into an actual, editable data on Excel. After capturing the data, you can edit the data to make sure Excel's image recognition is 100% accurate, and make any changes if some of the scanned data were incorrect. The company says it will roll out this feature to Excel for iOS app soon.
Privacy

Elasticsearch Clusters Face Attacks From Multiple Hacker Groups (csoonline.com) 28

itwbennett writes: If you're running Elasticsearch 1.4.2 and lower, you should make sure your patches are up to date. That's because researchers from Cisco's Talos group have "detected an increase in attacks targeting unsecured Elasticsearch clusters." At least six different groups are responsible for the increase, each deploying different malware, but regardless of the method, the potential impact of a breach is huge because Elasticsearch is designed to work with big data and companies use it to process sensitive data. "Given the size and sensitivity of the data sets these clusters contain, the impact of a breach of this nature could be severe," the Talos researchers warned.
Television

Samsung is Loading McAfee Antivirus Software On Smart TVs (techspot.com) 160

Samsung is adding bloatware to its 2019 TVs because McAfee is paying them to do so. From a report: There is arguably no reason at all for Samsung to offer a third-party antivirus software for an operating system that is developed in house. Partnering with software vendors is fairly common practice for large hardware manufacturers. Laptop makers frequently preinstall bloatware in return for some sizable payouts and smartphone OEMs are no different. Samsung is now installing McAfee antivirus software on its 2019 TV lineup.

Samsung is claiming something to the effect of wanting to protect users from malware. On the surface that makes sense, but Samsung is running its very own Tizen OS on all of its TVs. Instead of adding more junk to a TV, why not just improve the OS? The answer though is very self explanatory. Samsung would not receive a payout from McAfee if it did not install the unneeded software.

Security

Serious Amazon Ring Vulnerability Leaves Audio, Video Feeds Open To Attack (betanews.com) 43

Mark Wilson shares a report from BetaNews: Security researchers from Dojo by Bullguard have discovered a vulnerability in Amazon's Ring doorbell that leaves it prone to man-in-the-middle attacks. As well as enabling a hacker to access audio and video feeds in a severe violation of both privacy and security, the vulnerability also means that an attacker could replace a feed with footage of their own. Revealing the security flaw at Mobile World Congress, Yossi Atias from Dojo, demonstrated how a feed could be hijacked and injected with counterfeit video. The vulnerability poses a number of risks. The ability to spy on audio and video feeds has obvious privacy implications, but it could also enable a hacker to monitor comings and goings to determine when a house will be empty. Using easily-available tools, it is possible to intercept Ring's RTP stream and extract a viewable MPEG video.
Chrome

Chrome Should Get 'Extremely Fast' at Loading a Whole Lot of Web Pages (cnet.com) 203

Chrome is going to get a big speed boost -- at least for web pages you've recently visited. CNET: With a feature called bfcache -- backward-forward cache -- Google's web browser will store a website's state as you navigate to a new page. If you then go back to that page, Chrome will reconstitute it rapidly instead of having to reconstruct it from scratch. Then, if you retrace your steps forward again, Chrome will likewise rapidly pull that web page out of its memory cache. The speed boost doesn't help when visiting new websites. But this kind of navigation is very common: Going back accounts for 19 percent of pages viewed on Chrome for Android and 10 percent on Chrome for personal computers, Google said. With bfcache, that becomes "extremely fast."
Security

Cryptocurrency Wallet App Coinomi Caught Sending User Passwords To Google's Spellchecker (zdnet.com) 75

An anonymous reader shares a report: Coinomi wallet app sends user passwords to Google's spellchecking service in clear text, exposing users' accounts and their funds to man-in-the-middle (MitM) attacks during which attackers can log passwords and later empty accounts. The issue came to light yesterday after an angry write-up by Oman-based programmer Warith Al Maawali who discovered it while investigating the mysterious theft of 90 percent of his funds. Al Maawali says that during the Coinomi wallet setup, when users select a password (passphrase), Coinomi app grabs the user's input inside the passphrase textbox and silently sends it to Google's Spellcheck API service. [...] Coinomi, which offers a multi-cryptocurrency wallet app for Android, iOS, Linux, Mac, and Windows, did not respond to a request for comment.
Desktops (Apple)

Thunderbolt Vulnerabilities Leave Computers Wide-Open, Researchers Find (itnews.com.au) 90

Bismillah writes: Researchers have published the results of exploring how vulnerable Thunderbolt is to DMA attacks, and the answer is "very." Be careful what you plug into that USB-C port. Yes, the set of vulnerabilities has a name: "Thunderclap." "Thunderbolt, which is available through USB-C ports on modern laptops, provides low-level direct memory access (DMA) at much higher privilege levels than regular universal serial bus peripherals," reports ITNews, citing a paper published from a team of researchers from the University of Cambridge, Rice University and SRI International. "This opens up laptops, desktops and servers with Thunderbolt input/output ports and PCI-Express connectors to attacks using malicious DMA-enabled peripherals. The main defense against the above attacks is the input-output memory management unit (IOMMU) that allows devices to access only the memory needed for the job to be done. Enabling the IOMMU to protect against DMA attacks comes at a high performance cost however. Most operating systems trade off security for performance gains, and disable the IOMMU by default."

"Apple's macOS uses the IOMMU, but even with the hardware defense enabled, the researchers were able to use a fake network card to read data traffic that is meant to be confined to the machine and never leave it," the report adds. "The network card was also able to run arbitrary programs at system administrator level on macOS and could read display contents from other Macs and keystrokes from a USB keyboard. Apple patched the vulnerability in macOS 10.12.4 that was released in 2016, but the researchers say the more general scope of such attacks remains relevant."
IT

USB-IF Confusingly Merges USB 3.0 and USB 3.1 Under New USB 3.2 Branding (macrumors.com) 131

The USB Implementers Forum (USB-IF), this week announced a rebranding of the USB 3.0 and USB 3.1 specifications, under the USB 3.2 specification. USB 3.0 and USB 3.1 will now be considered previous generations of the USB 3.2 specification. From a report: Going forward, USB 3.1 Gen 1 (transfer speeds up to 5Gb/s), which used to be USB 3.0 prior to a separate rebranding, will be called USB 3.2 Gen 1, while USB 3.1 Gen 2 (transfer speeds up to 10Gb/s) will now be known as USB 3.2 Gen 2. What used to be considered USB 3.2 will now be USB 3.2 Gen 2x2 because if offers twice the throughput speeds of USB 3.1 Gen 2, now USB 3.2 Gen 2. If the swap between USB 3.1 Gen 1 and Gen 2 to USB 3.2 wasn't confusing enough, each of these specifications also has a marketing term. The new USB 3.2 Gen 1 with transfer speeds up to 5Gb/s is SuperSpeed USB, while USB 3.2 Gen 2 with transfer speeds up to 10Gb/s is known as SuperSpeed USB 10Gbps. The USB 3.2 Gen 2x2 specification with transfer speeds up to 20Gb/s is known as SuperSpeed USB 20Gbps.
Security

Millions of Utility Customers' Passwords Stored In Plain Text (arstechnica.com) 81

schwit1 shares a report from Ars Technica: In September of 2018, an anonymous independent security researcher (who we'll call X) noticed that their power company's website was offering to email -- not reset! -- lost account passwords to forgetful users. Startled, X fed the online form the utility account number and the last four phone number digits it was asking for. Sure enough, a few minutes later the account password, in plain text, was sitting in X's inbox. This was frustrating and insecure, and it shouldn't have happened at all in 2018. But this turned out to be a flaw common to websites designed by the Atlanta firm SEDC. After finding SEDC's copyright notices in the footer of the local utility company's website, X began looking for more customer-facing sites designed by SEDC. X found and confirmed SEDC's footer -- and the same offer to email plain-text passwords -- in more than 80 utility company websites. Those companies service 15 million or so clients (estimated from GIS data and in some cases from PR brags on the utility sites themselves). But the real number of affected Americans could easily be several times that large: SEDC itself claims that more than 250 utility companies use its software.
EU

Vodafone CEO Says Banning Huawei Could Set Europe's 5G Rollout Back Another Two Years (cnbc.com) 120

The CEO of Vodafone, the world's second-largest mobile operator, warned excluding Huawei from Europe's 5G networks could be "hugely disruptive" to national infrastructure and consumers. CEO Nick Read said that it would be "very very expensive" for operators and consumers if companies were forced to swap their Huawei equipment in favor of competitors', adding it would delay Europe's 5G rollout by "probably two years." CNBC reports: Speaking at a press conference at Mobile World Congress in Barcelona Monday, Vodafone CEO Nick Read said banning Huawei from providing 5G infrastructure in Europe would hamper competition in the supply chain. China's Huawei, Finland's Nokia and Sweden's Ericsson are the three biggest providers of telecommunications equipment in the world, accounting for more than half of revenues in the market, according to research firm Dell'Oro Group. "If we concentrate it down to two players I think that's an unhealthy position not just for us as an industry but also for national infrastructure in the country," Read said.

"It structurally disadvantages Europe," he said "Of course the U.S. don't have that problem because they don't put Huawei equipment in." Vodafone's Read said governments need to take a "fact-based" approach to assessing security concerns with Huawei, adding he will not be meeting with any U.S. officials in Barcelona this week. "I would at this stage prefer to be working with governments and securities on a national basis and making sure we have a fact-based conversation," he said. Vodafone's Read said there is "high competition" among the three equipment providers but added Huawei has had "leading technology." In a roundtable with media on Sunday in Barcelona, Huawei's rotating chairman Guo Ping claimed the company is 12 months ahead of its competitors when it comes to 5G technology.
Huawei has been left out of the U.S. market with officials citing security concerns that its technology could enable spying from the Chinese government, accusations Huawei denies. The U.S., the UK and Germany are weighing possible bans on Huawei's 5G equipment citing security risks.
Security

Researchers Break Digital Signatures For Most Desktop PDF Viewers (zdnet.com) 28

An anonymous reader quotes a report from ZDNet: A team of academics from the Ruhr-University Bochum in Germany say they've managed to break the digital signing system and create fake signatures on 21 of 22 desktop PDF viewer apps and five out of seven online PDF digital signing services. This includes apps such as Adobe Acrobat Reader, Foxit Reader, and LibreOffice, and online services like DocuSign and Evotrust --just to name the most recognizable names. The five-person research team has been working since early October 2018 together with experts from Germany's Computer Emergency Response Team (BSI-CERT) to notify impacted services. The team went public with their findings over the weekend after all affected app makers and commercial companies finished patching their products. In research published today, the Ruhr-University Bochum team described three vulnerabilities that they found in the digital signing process used by several desktop and web-based PDF signing services. Summarized, they are:

1. Universal Signature Forgery (USF) -- vulnerability lets attackers trick the signature verification process into showing users a fake panel/message that the signature is valid.
2. Incremental Saving Attack (ISA) -- vulnerability lets attackers add extra content to an already signed PDF document via the "incremental saving (incremental update)" mechanism, but without breaking the already-existing signature.
3. Signature Wrapping (SWA) -- vulnerability is similar to ISA, but the malicious code also contains extra logic to fool the signature validation process into "wrapping" around the attacker's extra content, effectively digitally signing the incremental update.
Additional details about the three vulnerabilities are available in this PDF research paper [1, 2], this blog post, and this dedicated website.
Privacy

People Are Concerned About Their Privacy In Theory, Not Practice, Says New Study (fortune.com) 62

A new privacy survey from IBM's Institute for Business Value found that 81% of consumers say they've become more concerned about how companies use their data, while 87% think companies should be more heavily regulated on personal data management. Three-quarters of the people felt like they were less likely to trust companies with data and 89% said companies should be clearer about how their products use data. Given these findings, you'd think people would take actions in response to companies losing or misusing their data -- but they're not. Fortune reports: 71% said that they were willing to give up privacy to get access to what technology can offer. Only 45% have updated their privacy settings on products in response and 16% walked away from a company because of data misuse. It's already been clear that one reasons for big data leaks is because there is little financial risk to companies, as Motherboard reported. This new data suggests that companies have even less to worry about, as most people are willing to keep doing business with them.
Security

New Flaws In 4G, 5G Allow Attackers To Intercept Calls and Track Phone Locations (techcrunch.com) 46

An anonymous reader quotes a report from TechCrunch: A group of academics have found three new security flaws in 4G and 5G, which they say can be used to intercept phone calls and track the locations of cell phone users. The findings are said to be the first time vulnerabilities have affected both 4G and the incoming 5G standard, which promises faster speeds and better security, particularly against law enforcement use of cell site simulators, known as "stingrays." But the researchers say that their new attacks can defeat newer protections that were believed to make it more difficult to snoop on phone users. [Rafiul Hussain, one of the co-authors of the paper, along with Ninghui Li and Elisa Bertino at Purdue University, and Mitziu Echeverria and Omar Chowdhury at the University of Iowa are set to reveal their findings at the Network and Distributed System Security Symposium in San Diego on Tuesday.

The paper, seen by TechCrunch prior to the talk, details the attacks: the first is Torpedo, which exploits a weakness in the paging protocol that carriers use to notify a phone before a call or text message comes through. The researchers found that several phone calls placed and cancelled in a short period can trigger a paging message without alerting the target device to an incoming call, which an attacker can use to track a victim's location. Knowing the victim's paging occasion also lets an attacker hijack the paging channel and inject or deny paging messages, by spoofing messages like Amber alerts or blocking messages altogether, the researchers say. Torpedo opens the door to two other attacks: Piercer, which the researchers say allows an attacker to determine an international mobile subscriber identity (IMSI) on the 4G network; and the aptly named IMSI-Cracking attack, which can brute force an IMSI number in both 4G and 5G networks, where IMSI numbers are encrypted.
AT&T, Verizon, Sprint and T-Mobile are all affected by Torpedo, "and the attacks can be carried out with radio equipment costing as little as $200," the report adds. One U.S. network is reportedly vulnerable to the Piercer attack, but the researcher wouldn't name which one.
Australia

Australian Email Service FastMail Says It is Losing Customers and Facing Calls To Move Operations Outside of the Country Over Local Anti-Encryption Laws (itnews.com.au) 65

An anonymous reader shares a report: Email provider FastMail says it has lost customers and faces "regular" requests to shift its operations outside Australia following the passage of anti-encryption laws. The Victorian company, which offers ad-free email services to users in 150 countries, told a senate committee that the now-passed laws were starting to bite.

"The way in which [the laws] were introduced, debated, and ultimately passed ... creates a perception that Australia has changed - that we are no longer a country which respects the right to privacy," FastMail CEO Bron Gondwana said. "We have already seen an impact on our business caused by this perception. Our particular service is not materially affected as we already respond to warrants under the Telecommunications Act." "Still, we have seen existing customers leave, and potential customers go elsewhere, citing this bill as the reason for their choice. We are [also] regularly being asked by customers if we plan to move."

Slashdot Top Deals