Security

Linux systemd Affected by Memory Corruption Vulnerabilities, No Patches Yet (bleepingcomputer.com) 306

Major Linux distributions are vulnerable to three bugs in systemd, a Linux initialization system and service manager in widespread use, California-based security company Qualys said late yesterday. From a report: The bugs exist in 'journald' service, tasked with collecting and storing log data, and they can be exploited to obtain root privileges on the target machine or to leak information. No patches exist at the moment. Discovered by researchers at Qualys, the flaws are two memory corruption vulnerabilities (stack buffer overflow - CVE-2018-16864, and allocation of memory without limits - CVE-2018-16865) and one out-of-bounds error (CVE-2018-16866). They were able to obtain local root shell on both x86 and x64 machines by exploiting CVE-2018-16865 and CVE-2018-16866. The exploit worked faster on the x86 platform, achieving its purpose in ten minutes; on x64, though, the exploit took 70 minutes to complete. Qualys is planning on publishing the proof-of-concept exploit code in the near future, but they did provide details on how they were able to take advantage of the flaws.
Windows

Windows 7 Users Who Installed January Update Report Network Issues; Some Say the Update Has Also Incorrectly Flagged Their OS License as 'Not Genuine' (itpro.co.uk) 131

Some Windows 7 admins are feeling the pain of Microsoft's latest updates in this week's Patch Tuesday releases. From a report: Users who've installed this Tuesday's KB4480970 cumulative January update have been complaining of network connectivity issues on those devices based on a network that uses the SMBv2 file sharing protocol. Microsoft released its update to fix several identified vulnerabilities, including a remote execution flaw in PowerShell and to add robustness against side-channel attacks like those targeting the Meltdown and Spectre flaws. But a number of users immediately complained of networking issues, with Microsoft confirming there are now three known problems with the January patch. The other issues comprise an authentication error, and a file-sharing issue affecting some user accounts. ZDNet adds: Regarding the 'Not Genuine' Windows 7 error, Microsoft confirms that "some users are reporting the KMS Activation error, 'Not Genuine', 0xc004f200 on Windows 7 devices". "We are aware of this incident and are presently investigating it. We will provide an update when available," writes Microsoft on both KB4480960 and KB4480970.
Encryption

The Feds Cracked El Chapo's Encrypted Comms Network By Flipping His System Admin (gizmodo.com) 111

With signs that the New York trial of notorious Mexican drug lord and alleged mass murderer Joaquin "El Chapo" Guzman is entering its end phase, prosecutors on Tuesday played copies of what they said were audio recordings of Guzman the FBI obtained "after they infiltrated his encrypted messaging system" with the help of Colombian and former cartel systems engineer Cristian Rodriguez, Reuters reported. Gizmodo reports: As has been previously reported by Vice, Colombian drug lord Jorge Cifuentes testified that Rodriguez had forgot to renew a license key critical to the communications network of Guzman's Sinaloa Cartel in September 2010, forcing cartel leaders to temporarily rely on conventional cell phones. Cifuentes told the court he considered Rodriguez "an irresponsible person" who had compromised their security, with a terse phone call played by prosecutors showing Cifuentes warned the subordinate he was in "charge of the system always working."

But on Tuesday it was revealed that the FBI had lured Rodriguez into a meeting with an agent posing as a potential customer much earlier, in February 2010, according to a report in the New York Times. Later, they flipped Rodriguez, having him transfer servers from Canada to the Netherlands in a move masked as an upgrade. During that process, Rodriguez slipped investigators the network's encryption keys. The communications system ran over Voice over Internet Protocol (VoIP), with only cartel members able to access it. Getting through its encryption gave authorities access to roughly 1,500 of Guzman's and other cartel members' calls from April 2011 to January 2012, the Times wrote, with FBI agents able to identify ones placed by the drug lord by "comparing the high-pitched, nasal voice on the calls with other recordings of the kingpin, including a video interview he gave to Rolling Stone in October 2015."

Government

Security Firm Kaspersky, Which Has Been Accused by US of Working With Russian Spies, Helped Catch an Alleged NSA Data Thief 85

An anonymous reader shares a report: The 2016 arrest of a former National Security Agency contractor charged with a massive theft of classified data began with an unlikely source: a tip from a Russian cybersecurity firm that the U.S. government has called a threat to the country. Moscow-based Kaspersky Lab turned Harold T. Martin III in to the NSA after receiving strange Twitter messages in 2016 from an account linked to him, according to two people with knowledge of the investigation. They spoke with POLITICO on condition of anonymity because they're not authorized to discuss the case.

The company's role in exposing Martin is a remarkable twist in an increasingly bizarre case that is believed to be the largest breach of classified material in U.S. history. It indicates that the government's own internal monitoring systems and investigators had little to do with catching Martin, who prosecutors say took home an estimated 50 terabytes of data from the NSA and other government offices over a two-decade period, including some of the NSA's most sophisticated and sensitive hacking tools. The revelation also introduces an ironic turn in the negative narrative the U.S. government has woven about the Russian company in recent years.
Security

New Tool Automates Phishing Attacks That Bypass 2FA (zdnet.com) 121

A new penetration testing tool published at the start of the year by a security researcher can automate phishing attacks with an ease never seen before and can even blow through login operations for accounts protected by two-factor authentication (2FA). From a report: Named Modlishka --the English pronunciation of the Polish word for mantis -- this new tool was created by Polish researcher Piotr Duszynski. Modlishka is what IT professionals call a reverse proxy, but modified for handling traffic meant for login pages and phishing operations. It sits between a user and a target website -- like Gmail, Yahoo, or ProtonMail. Phishing victims connect to the Modlishka server (hosting a phishing domain), and the reverse proxy component behind it makes requests to the site it wants to impersonate. The victim receives authentic content from the legitimate site --let's say for example Google -- but all traffic and all the victim's interactions with the legitimate site passes through and is recorded on the Modlishka server.
Android

Samsung Phone Users Perturbed To Find They Can't Delete Facebook (bloomberg.com) 315

An anonymous reader quotes a report from Bloomberg: Nick Winke, a photographer in the Pacific northwest, was perusing internet forums when he came across a complaint that alarmed him: On certain Samsung Electronics Co. smartphones, users aren't allowed to delete the Facebook app. Winke bought his Samsung Galaxy S8, an Android-based device that comes with Facebook's social network already installed, when it was introduced in 2017. He has used the Facebook app to connect with old friends and to share pictures of natural landscapes and his Siamese cat -- but he didn't want to be stuck with it. He tried to remove the program from his phone, but the chatter proved true -- it was undeletable. He found only an option to "disable," and he wasn't sure what that meant.

A Facebook spokesperson said the disabled version of the app acts like it's been deleted, so it doesn't continue collecting data or sending information back to Facebook. But there's rarely communication with the consumer about the process. The Menlo Park, California-based company said whether the app is deletable or not depends on various pre-install deals Facebook has made with phone manufacturers, operating systems and mobile operators around the world over the years, including Samsung. Facebook, the world's largest social network, wouldn't disclose the financial nature of the agreements, but said they're meant to give the consumer "the best" phone experience right after opening the box.

Canada

Canada's Bell Telecommunications Company Wants Permission To Gather, Track Customer Data (www.cbc.ca) 73

Bell Canada is asking customers for permission to track everything they do with their home and mobile phones, internet, television, apps or any other services they get through Bell or its affiliates. "In return, Bell says it will provide advertising and promotions that are more 'tailored' to their needs and preferences," reports CBC.ca. From the report: "Tailored marketing means Bell will be able to customize advertising based on participant account information and service usage patterns, similar to the ways that companies like Google and others have been doing for some time," the company says in recent notices to customers. If given permission, Bell will collect information about its customers' age, gender, billing addresses, and the specific tablet, television or other devices used to access Bell services. It will also collect the "number of messages sent and received, voice minutes, user data consumption and type of connectivity when downloading or streaming." "Bell's marketing partners will not receive the personal information of program participants; we just deliver the offers relevant to the program participants on their behalf," the company assures customers. Teresa Scassa, who teaches law at the University of Ottawa and holds the Canada Research Chair in Information Law and Policy, says Bell customers who opt into Bell's new program could be giving away commercially valuable personal information with little to no compensation for increased risks to their privacy and security. "Here's a company that's taking every shred of personal information about me, from all kinds of activities that I engage in, and they're monetizing it. What do I get in return? Better ads? Really? That's it? What about better prices?"

Toronto-based consultant Charlie Wilton, whose firm has advised Bell and Rogers in the past, says: "I mean, in a perfect world, they would give you discounts or they would give you points or things that consumers would more tangibly want, rather than just the elimination of a pain point -- which is what they're offering right now."
Microsoft

Windows 10 Will Reserve 7GB of Your Computer's Storage in its Next Major Release So That Big Updates Don't Fail (zdnet.com) 368

In the next major release of Windows 10, Microsoft will reserve 7GB of your device's storage to resolve a Windows 10 bug thrown up by Windows Update not checking whether a PC has enough storage space before launching after big updates. From a report: As Microsoft warned ahead of the Windows 10 October 2018 Update, systems that don't have enough space to install Microsoft's 'quality updates' or new versions of the OS will see an error message explaining there is insufficient storage space. That happens because Windows doesn't check if a device has enough space before initializing. Microsoft's current solution is for users to manually delete unnecessary temporary files and temporarily move important files like photos and videos to external storage devices to make enough space for the update. This problem is more acute for devices with little storage capacity, such as many of the cheap 32GB flash-drive PCs on the market today.
Bug

Monarch Butterfly Numbers Plummet 86 Percent In California (usatoday.com) 148

An anonymous reader quotes a report from USA Today: The number of monarch butterflies turning up at California's overwintering sites has dropped by about 86 percent compared to only a year ago, according to the Xerces Society, which organizes a yearly count of the iconic creatures. That's bad news for a species whose numbers have already declined an estimated 97 percent since the 1980s. Each year, monarchs in the western United States migrate from inland areas to California's coastline to spend the winter, usually between September and February. Results from the count so far show that the number of monarchs at 97 California overwintering sites has dropped from around 148,000 in 2017 to just over 20,400 this year. Counts for dozens of other sites are still being tabulated, but the outlook is troubling.

What's causing the dramatic drop-off is somewhat of a mystery. Experts believe the decline is spurred by a confluence of unfortunate factors, including late rainy-season storms across California last March, the effects of the state's yearslong drought and the seemingly relentless onslaught of wildfires that have burned acres upon acres of habitat and at times choked the air with toxic smoke. The Thomas Fire last year burned almost 300,000 acres, including areas important for monarch breeding and migration. More recently, the Woolsey Fire damaged at least four monarch butterfly overwintering sites in the Malibu area, according to Lara Drizd, a wildlife biologist with the U.S. Fish and Wildlife Service in Ventura.

Security

Companies Are Now Offering Seven Figures For Hacks That Allow Spies, Cops To Steal Chat App Messages (vice.com) 73

Zerodium, a startup that buys and sells hacking tools and exploits to governments around the world, announced on Monday price increases for almost everything they are looking for, such as iOS remote jailbreaks and Windows exploits. "It said it will now pay security researchers $1,000,000 for exploits in WhatsApp, iMessage, and SMS/MMS apps for all mobile operating systems," reports Motherboard. From the report: Compromising the whole iPhone, sometimes referred to as remote jailbreaking or rooting the phone, can cost $2 million or more, and usually involves a series of bugs and exploits. The price increase shows that mobile devices in general are getting more and more secure, and thus harder to hack. That means that it's becoming increasingly hard for hackers to break into iOS and Android devices. That makes the life of folks like spy agencies and police departments harder too. That's where Zerodium and other similar companies, such as Azimuth and Crowdfense, come in: they act as intermediaries between security researchers and government agencies looking for tools -- often called zero-days -- to break into targets. Before today, Zerodium was willing to pay $500,000 for WhatsApp and iMessage exploits, according to an archived version of the company's site. These new prices are in line with the market, according to Maor Shwartz, who used to run a company that acquired and sold exploits to government agencies.
Spam

Google Drive Has a Serious Spam Problem, But Google Says a Fix is Coming (howtogeek.com) 58

Google Drive has a pretty bad spam problem, and it seems Google doesn't care. Spammers can share files that automatically appear in your Drive, and there's no way to stop it. From a report: Google Drive's sharing system is the problem. Since it doesn't offer any sharing acceptance, all files and folders shared with your account are automatically available to you in Drive -- they just show up. To make matters worse, if you only have "View" permission, you can't remove yourself from the share. It's a mess. And to make matters even worse, this is far from a new problem, but Google still hasn't done anything to fix it.

Google got back to us with a statement saying that changes are coming to Drive's sharing features and they're"making it a priority." Here's the statement in full: "For the vast majority of users, the default sharing permissions in Drive work as intended. Unfortunately, this was not the case for this user and we sincerely apologize for her experience. In light of this issue, we are evaluating changes to our spam, abuse, and blocking features that will prevent this kind of activity from taking place on Drive. In the interim, users who are experiencing similar issues can remove themselves from the folder, and the folder should not reappear in either 'My Drive' or 'Shared with Me' unless they revisit it."

Microsoft

Ask Slashdot: Is LinkedIn Still Relevant? 201

LinkedIn had 590 million members -- though back in 2016 Microsoft conceded that less than 25% of the service's members were active. Yet CNBC recently shared estimates that 95% of recruiters are using LinkedIn to find candidates, and touted a new tool called "LinkedIn Hashtags" which lets companies highlight policies like "#dogfriendly" or "#freelunch".

But is LinkedIn really helpful for job-seekers? An anonymous Slashdot reader writes: I'm on unemployment and am looking for a new job, and I've been told "Oh, you need to be on LinkedIn if you want to be taken seriously!" So I go there, and it looks like Facebook or something, wants to scrape my email contacts, upload pictures, and so on.

Is LinkedIn really necessary, or is it just a ruse to get me to give them all sorts of personal information like all other social media sites?

"I'm also unemployed and looking for a job," adds another anonymous Slashdot reader, "and have all my crap on Linkedin and Indeed, and have been using them to apply left and right. If they aren't useful anymore I'm essentially sitting on my hands doing nothing." But Slashdot reader tomhath insists that LinkedIn "was never relevant. Their motto was that you didn't exist if you're not there -- but that was only their marketing hype, not reality."

Leave your own thoughts in the comments. Is LinkedIn still relevant?
Google

Researchers Fool ReCAPTCHA With Google's Own Speech-To-Text Service (vice.com) 31

Researchers at the University of Maryland have managed to trick Google's reCaptcha system by using Google's own speech-to-text service. "[The researchers] claim that their CAPTCHA-fooling method, unCaptcha, can fool Google's reCaptcha, one of the most popular CAPTCHA systems currently used by hundreds of thousands of websites, with a 90 percent success rate," reports Motherboard. From the report: The researchers originally developed UnCaptcha in 2017, which uses Google's own free speech-to-text service to trick the system into thinking a robot is a human. It's an oroborus of bots: According to their paper, UnCaptcha downloads the audio captcha, segments the audio into individual digit audio clips, uploads the segments to multiple other speech-to-text services (including Google's), then converts these services' responses to digits. After a little homophone guesswork, it then decides which speech-to-text output is closest to accurate, and uploads the answer to the CAPTCHA field. This old method returned an 85% success rate.

After the release of that version of unCaptcha, Google fixed some of the loopholes that made it work, including better browser automation detection and switching to spoken phrases, rather than digits. The researchers claim that their new method, updated in June, gets around these improvements and is even more accurate than before, at 90 percent.
"We have been in contact with the ReCaptcha team for over six months and they are fully aware of this attack," the researchers write. "The team has allowed us to release the code, despite its current success."
Privacy

Marriott Says Hackers Stole More Than 5 Million Passport Numbers (cnet.com) 71

Marriott has downsized its original estimate on a major data breach, but the number of people affected is still historic. The hotel group announced Friday that it now believes hackers accessed the records of up to 383 million guests, following an investigation it conducted with a forensics and analytics team. In November, it had reported an estimate of as many as 500 million guests. From a report: Even at that lower figure, the Marriott incident remains one of the largest personal data breaches in history, more than double that of Equifax, which exposed the personal data of 147.7 million American. Data breaches have become a common issue for massive companies that collect and store information on millions of people. In 2018, tech giants like Facebook and Reddit have fallen victim to data breaches. Hackers look for poor protection that they can bypass to steal valuable details like Social Security numbers, birth dates, email addresses and credit card numbers.
Privacy

Hundreds of German Lawmakers Targeted in Mass Cyber Attack (vice.com) 88

A stolen cache of personal information belonging to nearly 1,000 German politicians -- including outgoing Chancellor Angela Merkel -- has been leaked, according to a report published Thursday. From a report: The information includes everything from phone numbers and credit card details to private messages with family members, German media said. The hack has impacted national, regional and EU politicians from all major parties except for members of the far-right Alternative for Germany (Alternative fur Deutschland, or AfD) party. Journalists, musicians, comedians and activists were also targeted. There is currently no indication of who was behind the attack, but the hacker or hackers leaked information for more than a month on Twitter before the media picked it up.

The scale of the hack was first reported by RBB, leading Justice Minister Katarina Barley to call it a "serious attack" Friday morning. "The people behind this want to damage confidence in our democracy and institutions," Barley said. The federal office for information security (BSI) said Friday it was investigating, adding that government networks had not been affected.

Security

Security Researcher Cracks Google's Widevine DRM (L3 Only) (zdnet.com) 76

The L3 protection level of Google's Widevine DRM technology has been cracked by a British security researcher who can now decrypt content transferred via DRM-protected multimedia streams. ZDNet's Catalin Cimpanu notes that while this "sounds very cool," it's not likely to fuel a massive piracy wave because "the hack works only against Widevine L3 streams, and not L2 and L1, which are the ones that carry high-quality audio and video content." From the report: Google designed its Widevine DRM technology to work on three data protection levels --L1, L2, and L3-- each usable in various scenarios. According to Google's docs, the differences between the three protection levels is as follows:

L1 - all content processing and cryptography operations are handled inside a CPU that supports a Trusted Execution Environment (TEE).
L2 - only cryptography operations are handled inside a TEE.
L3 - content processing and cryptography operations are (intentionally) handled outside of a TEE, or the device doesn't support a TEE

"Soooo, after a few evenings of work, I've 100% broken Widevine L3 DRM," [British security researcher David Buchanan] said on Twitter. "Their Whitebox AES-128 implementation is vulnerable to the well-studied DFA attack, which can be used to recover the original key. Then you can decrypt the MPEG-CENC streams with plain old ffmpeg." Albeit Buchanan did not yet release any proof-of-concept code, it wouldn't help anyone if he did. In order to get the DRM-encrypted data blob that you want to decrypt, an attacker would still need "the right/permission" to receive the data blob in the first place. If a Netflix pirate would have this right (being an account holder), then he'd most likely (ab)use it to pirate a higher-quality version of the content, instead of bothering to decrypt low-res video and lo-fi audio. The only advantage is in regards to automating the pirating process, but as some users have pointed out, this isn't very appealing in today's tech scene where almost all devices are capable of playing HD multimedia [1, 2].

Encryption

OSNews Suffered 'Likely' Data Breach, Contemplated Going Offline Permanently (osnews.com) 77

hmckee writes: OSNews was offline for a few days for upgrades. It is now back up with a message that indicates they encountered a data breach and considered going offline for good due to maintenance and financial difficulties. "Our best guess is that someone was able to exploit a vulnerability in old, unmaintained code in the site's content management system, and made off with at least some user data, which may be as little as a few user records or, at worst, our entire database," writes Publisher David Adams. "Your email addresses were in there, and the encryption on the passwords wasn't up to modern standards (unsalted SHA1). [...] Other than potential spam, though, we're not aware of any other nefarious use of your data, we don't store much beyond email addresses and passwords..."

David goes on to cite poor advertising revenues and a lack of time for reasons to throw in the towel and go offline permanently.
AI

Video Services May Use AI To Crack Down on Password Sharing (variety.com) 99

An anonymous reader shares a report: Still using your ex-roommates cable credentials to watch "Game of Thrones?" That may soon be getting a lot harder, thanks to new efforts to crack down on password sharing for pay TV and online video services. One of these efforts, launched by London-based Synamedia ahead of next week's Consumer Electronics Show (CES), even uses artificial intelligence to uncover notorious password sharers. Credentials Sharing Insight, as the new service is being called, targets both casual password sharing as well as criminal enterprises looking to resell pay TV login information. However, the focus clearly is on friends and family taking their generosity a bit too far, explained Symanedia chief product officer Jean-Marc Racine in an interview with Variety this week.

[...] Most services have tried to curtail password sharing by limiting the number of simultaneous streams, with little else to go by to identify abuse. "Today, you are in the dark," he said. Synamedia's solution on the other hand digs through lots of data to cluster users based on their streaming behavior. This can include user's physical location (someone streaming from both coasts at the same time) as well as general usage patterns (someone streaming 24/7). The company can even take a look at the specific content streamed by a user to identify unusual patterns. Based on these clues, Synamedia trains models to score users on a scale of 1 to 10, indicating whether they are likely sharing their passwords or not.

Intel

The Elite Intel Team Still Fighting Meltdown and Spectre (wired.com) 100

Throughout 2018, researchers inside and outside Intel continued to find exploitable weaknesses related to Meltdown and Spectre class of "speculative execution" vulnerabilities. Fixing many of them takes not just software patches, but conceptually rethinking how processors are made. From a report: At the center of these efforts for Intel is STORM, the company's strategic offensive research and mitigation group, a team of hackers from around the world tasked with heading off next-generation security threats. Reacting to speculative execution vulnerabilities in particular has taken extensive collaboration among product development teams, legacy architecture groups, outreach and communications departments to coordinate response, and security-focused research groups at Intel. STORM has been at the heart of the technical side. "With Meltdown and Spectre we were very aggressive with how we approached this problem," says Dhinesh Manoharan, who heads Intel's offensive security research division, which includes STORM. "The amount of products that we needed to deal with and address and the pace in which we did this -- we set a really high bar."

Intel's offensive security research team comprises about 60 people who focus on proactive security testing and in-depth investigations. STORM is a subset, about a dozen people who specifically work on prototyping exploits to show their practical impact. They help shed light on how far a vulnerability really extends, while also pointing to potential mitigations. The strategy helped them catch as many variants as possible of the speculative execution vulnerabilities that emerged in a slow trickle throughout 2018. "Every time a new state of the art capability or attack is discovered we need to keep tracking it, doing work on it, and making sure that our technologies are still resilient," says Rodrigo Branco, who heads STORM. "It was no different for Spectre and Meltdown. The only difference in that case is the size, because it also affected other companies and the industry as a whole."

Security

Data of 2.4 Million Blur Password Manager Users Left Exposed Online (zdnet.com) 60

Abine, the company behind the Blur password manager and the DeleteMe online privacy protection service, revealed on Monday a data breach impacting nearly 2.4 million Blur users, ZDNet reports. From the report: The breach came to light last year, on December 13, when a security researcher contacted the company about a server that exposed a file containing sensitive information about Blur users, an Abine spokesperson told ZDNet via email. The company said it followed this initial report with an internal security audit to determine the size of the breach. The audit concluded last week, and the company made the data leak public on Monday in a post on its blog. The data that was available on the web included each user's email addresses, some users' first and last names, some users' password hints but only from our old MaskMe product, and each user's encrypted Blur password.

Slashdot Top Deals