Iphone

Apple Says It Could Miss $9 Billion In iPhone Sales Due To Weak Demand (theverge.com) 332

An anonymous reader quotes a report from The Verge: Apple CEO Tim Cook published a letter to investors today warning of weaker than expected first-quarter earnings, citing "fewer iPhone upgrades than we had anticipated." The weakened demand came primarily from China, although Cook notes that "in some developed markets, iPhone upgrades also were not as strong as we thought they would be." In his letter, Cook offers several explanations for the lower earnings guidance: earlier launch timing of the iPhone XS and XS Max compared to the iPhone X, the strength of the US dollar, supply constraints due to the number of new products Apple released in the fall, and overall economic weakness in some markets. But the core issue remains simple: people just aren't buying as many new iPhones as Apple hoped. All in all, Apple's revised Q1 guidance forecast is dropping by up to $9 billion in revenue compared to its original estimate.
Television

Hackers Are Taking Over Chromecasts To Promote a YouTube Channel (theverge.com) 90

In what is being referred to as CastHack, hackers j3ws3r and HackerGiraffe are promoting Felix "PewDiePie" Kjellberg by forcing TVs to display a message encouraging people to subscribe to his YouTube channel. "The hack takes advantage of a router setting that makes smart devices, like Chromecasts and Google Homes, publicly viewable on the internet," reports The Verge. "The attackers are then able to gain control of the devices and broadcast videos on a connected TV." From the report: A website for the attack claims to count the number of TVs forced to show the PewDiePie message and currently says more than 3,000 have been affected. While it's not clear that this is an accurate number (it has reset several times), a number of people posted on Reddit that the video had appeared on their TV. Google tells The Verge it has received reports from people who had "an unauthorized video played on their TVs via a Chromecast device," but said the issue was the result of router settings. Both HackerGiraffe and Google told The Verge the best way for affected users to fix the issue is to turn off Universal Plug and Play (UPnP) on their routers. The two hackers said they were behind a hack in November that forced printers around the world to print out sheets of paper telling people to subscribe to PewDiePie.
Security

USB Type-C Authentication Program Launched (newatlas.com) 133

With the arrival of USB-C a few years back, plugging into laptops, tablets and smartphones became even easier than before. But there are potential security risks. The USB Type-C Authentication Program launched today aims to address such issues. From a report: The new protocol from the USB Implementers Forum (USB-IF) can be used to validate the authenticity of a cable, charger or hardware at the moment of connection, and stop attacks in their tracks. The USB-IF has chosen DigiCert to operate registrations and certificate authority services for the new specification, which makes use of 128-bit cryptographic-based authentication for certificate format, digital signing, hash and random number generation.

"USB Type-C Authentication gives OEMs the opportunity to use certificates that enable host systems to confirm the authenticity of a USB device or USB charger, including such product aspects as the descriptors, capabilities and certification status," said DigiCert in a press release. "This protects against potential damage from non-compliant USB chargers and the risks from maliciously embedded hardware or software in devices attempting to exploit a USB connection."

Security

First-Ever UEFI Rootkit Tied To Sednit APT (threatpost.com) 168

Researchers hunting cyber-espionage group Sednit (an APT also known as Sofacy, Fancy Bear and APT28) say they have discovered the first-ever instance of a rootkit targeting the Windows Unified Extensible Firmware Interface (UEFI) in successful attacks. From a report: The discussion of Sednit was part of the 35C3 conference, and a session given by Frederic Vachon, a malware researcher at ESET who published a technical write-up on his findings earlier this fall [PDF]. During his session, Vachon said that finding a rootkit targeting a system's UEFI is significant, given that rootkit malware programs can survive on the motherboard's flash memory, giving it both persistence and stealth.

"UEFI rootkits have been researched and discussed heavily in the past few years, but sparse evidence has been presented of real campaigns actively trying to compromise systems at this level," he said. The rootkit is named LoJax. The name is a nod to the underlying code, which is a modified version of Absolute Software's LoJack recovery software for laptops. The purpose of the legitimate LoJack software is to help victims of a stolen laptop be able to access their PC without tipping off the bad guys who stole it. It hides on a system's UEFI and stealthily beacons its whereabouts back to the owner for possible physical recovery of the laptop.

Security

Hackers Make a Fake Hand to Beat Vein Authentication (vice.com) 66

Devices and security systems are increasingly using biometric authentication to let users in and keep hackers out, be that fingerprint sensors or perhaps the iPhone's FaceID. Another method is so-called 'vein authentication,' which, as the name implies, involves a computer scanning the shape, size, and position of a users' veins under the skin of their hand. But hackers have found a workaround for that, too. From a report: On Thursday at the annual Chaos Communication Congress hacking conference in Leipzig, Germany, security researchers described how they created a fake hand out of wax to fool a vein sensor. "It makes you feel uneasy that the process is praised as a high-security system and then you modify a camera, take some cheap materials and hack it," Jan Krissler, who goes by the handle starbug, and who researched the vein authentication system along with Julian Albrecht, told Motherboard over email in German. Vein authentication works with systems that compare a user's placement of veins under their skin compared to a copy on record. According to a recent report from German news wire DPA, the BND, Germany's signals intelligence agency, uses vein authentication in its new headquarter building in Berlin.

One attraction of a vein based system over, say, a more traditional fingerprint system is that it may be typically harder for an attacker to learn how a user's veins are positioned under their skin, rather than lifting a fingerprint from a held object or high quality photograph, for example. But with that said, Krissler and Albrecht first took photos of their vein patterns. They used a converted SLR camera with the infrared filter removed; this allowed them to see the pattern of the veins under the skin.

Bug

Google is Working on a Fix For Laggy Tablet Mode on Chrome OS Devices (9to5google.com) 41

An anonymous reader shares a report: Chrome OS was originally a laptop platform, but slowly it's being reworked for tablet form factors. However, as that goes on, there have been some hiccups. Most recently, many have noted the poor performance of tablet mode especially on Chrome OS products like the Pixel Slate, but it seems a fix for that lag is incoming. If you tuned into any hands-on or review coverage of Google's Pixel Slate, you're likely familiar with the performance issues many have described. In tablet mode, Chrome OS has a lot of issues with lag. This is especially evident in the multitasking screen, and it seems that is the first thing Google is looking at to fix these problems. ChromeUnboxed notes a recent bug tracker which reveals how Google plans to start fixing Chrome OS tablet mode lag in the multitasking screen. Somewhat hilariously, it seems a big reason for the poor frame rates in the animations on this screen actually comes down to how the OS renders the rounded corners on this screen.
Science

Under Current Policies, Residential Batteries Increase Emissions In Most Cases (arstechnica.com) 182

schwit1 shares a report: Another year, another reason to take the promises of residential home batteries with a grain of salt. This month, a group of researchers from the University of California San Diego (UCSD) published a paper in Environmental Science and Technology reporting that there are very few cases in which operating a residential home battery reduces overall emissions -- assuming that households are economically rational and trying to minimize costs.

Of course, if the battery is only discharged during periods of peak emissions and only charged when fossil fuel use is low, then a household might reduce emissions. But across 16 representative regions, operating a battery this way ended up being costly. "There may be good reasons to decentralize the grid through ubiquitous installation of small RES [Residential Energy Storage], but cost-effective emissions control is not one of them at the moment," the researchers write.

News

Computer Virus Hits Newspapers Coast-to-Coast, Affects Printing (nbcnews.com) 57

A computer virus hit newspaper printing plants in Los Angeles and at Tribune Publishing newspapers across the country. From a report: Tribune Publishing said Saturday night that malware affected its ability to print newspapers across its chain of outlets, including the Chicago Tribune, the New York Daily News, the Baltimore Sun and the Orlando Sentinel. Many subscribers to the Los Angeles Times and San Diego Union-Tribune, which were previously owned by Tribune Publishing and still share some production technology with the company, stepped into a chilly sunny morning Saturday only to find empty doorsteps. The computer malware was detected Friday and "impacted some back-office systems which are primarily used to publish and produce newspapers across our properties," said Marisa Kollias, Tribune communications vice president, in a statement.
Advertising

How Much Internet Traffic Is Fake? Turns Out, a Lot of It, Actually. (nymag.com) 130

Long-time Slashdot reader AmiMoJo shared this article from New York magazine: In late November, the Justice Department unsealed indictments against eight people accused of fleecing advertisers of $36 million in two of the largest digital ad-fraud operations ever uncovered... Hucksters infected 1.7 million computers with malware that remotely directed traffic to "spoofed" websites.... [B]ots "faked clicks, mouse movements, and social network login information to masquerade as engaged human consumers." Some were sent to browse the internet to gather tracking cookies from other websites, just as a human visitor would have done through regular behavior. Fake people with fake cookies and fake social-media accounts, fake-moving their fake cursors, fake-clicking on fake websites -- the fraudsters had essentially created a simulacrum of the internet, where the only real things were the ads.

How much of the internet is fake? Studies generally suggest that, year after year, less than 60 percent of web traffic is human; some years, according to some researchers, a healthy majority of it is bot. For a period of time in 2013, the Times reported this year, a full half of YouTube traffic was "bots masquerading as people," a portion so high that employees feared an inflection point after which YouTube's systems for detecting fraudulent traffic would begin to regard bot traffic as real and human traffic as fake. They called this hypothetical event "the Inversion...."

[N]ot even Facebook, the world's greatest data-gathering organization, seems able to produce genuine figures. In October, small advertisers filed suit against the social-media giant, accusing it of covering up, for a year, its significant overstatements of the time users spent watching videos on the platform (by 60 to 80âpercent, Facebook says; by 150 to 900 percent, the plaintiffs say). According to an exhaustive list at MarketingLand, over the past two years Facebook has admitted to misreporting the reach of posts on Facebook Pages (in two different ways), the rate at which viewers complete ad videos, the average time spent reading its "Instant Articles," the amount of referral traffic from Facebook to external websites, the number of views that videos received via Facebook's mobile site, and the number of video views in Instant Articles.

On Twitter the author also shared a Twitter thread by the Washington Post's director of advertising technology, who shares his own complaints about the ecosystem of online advertising. "The problem isn't just that the internet is full of fakery and bullshit and bad numbers and malfunctioning metrics and bullshitters and fraudsters. The problem is that all the fake shit is layered on top of other fake shit and it just COMPOUNDS itself... Like you get fake users, who get autoplay videos which no one is really watching....

"That's not even counting the entire ad campaigns that are fake where the product is just a bullshit excuse to collect data on you."
Facebook

How Facebook Keeps Messenger From Crashing On New Year's Eve (ieee.org) 69

Wave723 quotes IEEE Spectrum: On New Year's Eve, millions of people will use Facebook's Messenger app to wish friends and family a 'Happy New Year!' If everything goes smoothly, those messages will reach recipients in fewer than 100 milliseconds, and life will go on. But if the service stalls or fails, a small team of software engineers based in the company's New York City office will have to answer for it.
The article says the team "tested and tweaked the app throughout the year and will soon face their biggest annual performance exam," since Messenger's 1.3 billion monthly active users send more messages on New Year's Eve than any other day of the year. Many of them hit "send" at the exact moment when their clock strikes midnight, "and people often try to resend messages that don't appear to make it through right away, which piles on more requests."

The solution appears to be load testing, re-directing traffic, message batching, and discarding "read receipts" and temporarily disabling other minor Facebook functions -- or, more generally, what their engineering manager describes as "graceful degradation."
Businesses

Vermont Will Give You $10K If You Move There and Work Remotely (fastcompany.com) 187

If you've been dreaming of moonlight in Vermont -- and getting a re-location subsidy -- "the time has come to make your maple-syrup-coated dreams a reality," reports Fast Company: [F]or those who relocate this year and can prove that they have full-time remote jobs, it's possible to get paid back for moving expenses, internet bills, or membership in a coworking space... The program offers up to $5,000 a year for two years. For the state, the program is one way to try to address its shrinking population. "We're the second-to-smallest state in the nation, and we're also getting older, so we really need to make sure there's more of a workforce here," says Joan Goldstein, commissioner of the Vermont Department of Economic Development, which is running the Remote Worker Grant Program. The entire state has a population of a little more than 600,000, roughly the size of Louisville, Kentucky.

Vermont also recognized that a growing number of Americans work remotely -- nearly two-thirds of companies today have remote workers, and one recent survey found that hiring managers think it will continue to become even more common -- and that many city dwellers elsewhere are struggling with rent on increasingly overpriced apartments... The median home value in Brattleboro, roughly two hours from Boston, is less than $200,000; a one-bedroom apartment a short walk from the local co-op (and a small coworking space) goes for $850 a month.

The budget for 2019 is $125,000, and will be given out "on a first come, first served basis."
Bug

EU Offers Big Bug Bounties On 14 Open Source Software Projects (juliareda.eu) 78

Julia Reda is a member of Germany's Pirate Party, a member of the European Parliament, and the Vice-President of The Greens-European Free Alliance.

Thursday her official web site announced: In 2014, security vulnerabilities were found in important Free Software projects. One of the issues was found in the Open Source encryption library OpenSSL.... The issue made lots of people realise how important Free and Open Source Software is for the integrity and reliability of the Internet and other infrastructure.... That is why my colleague Max Andersson and I started the Free and Open Source Software Audit project: FOSSA... In 2017, the project was extended for three more years. This time, we decided to go one step further and added the carrying out of Bug Bounties on important Free Software projects to the list of measures we wanted to put in place to increase the security of Free and Open Source Software...

In January the European Commission is launching 14 out of a total of 15 bug bounties on Free Software projects that the EU institutions rely on.

The bounties start at 25.000,00 € -- about $29,000 USD -- rising as high as 90.000,00 € ($103,000). "The amount of the bounty depends on the severity of the issue uncovered and the relative importance of the software," Reda writes.

Click through for a list of the software projects for which bug bounties will be offered.
Security

FTC Warns Netflix Users About Email Phishing Scam (deadline.com) 37

The Federal Trade Commission has sent out a flare to warn Netflix users that there are some grinches out there looking to take advantage of everyone's holiday bliss and vulnerability. From a report: In a post on the FTC's website, they warned us of scammers using household company names to dupe consumers. In a specific example, they cited a phishing email sent to a Netflix customer that claimed the user's account is on hold because Netflix is "having some trouble with your current billing information." The email invites the user to click on a link to update their payment method. The FTC sent the cautionary message out to all Netflix users so that they won't be victim to phishing.


Bitcoin

Users Report Losing Bitcoin in Clever Hack of Electrum Wallets (zdnet.com) 72

A hacker -- or potentially a group of hackers -- has made over 200 Bitcoin (circa $750,000 at today's exchange) using a clever attack on the infrastructure of the Electrum Bitcoin wallet over the last one week. From a report: The attack resulted in legitimate Electrum wallet apps showing a message on users' computers, urging them to download a malicious wallet update from an unauthorized GitHub repository. The attack began last week on Friday, December 21, and appears to have been temporarily stopped earlier today after GitHub admins took down the hacker's GitHub repository. Admins of the Electrum wallet expect a new attack to soon get underway, with either a new GitHub repo or a link to another download location altogether. This is because the vulnerability at the heart of this attack has remained unpatched, albeit Electrum wallet admins taking steps to mitigate its usability for the attacker.
Security

Hacker Steals Ten Years Worth of Data From San Diego School District (zdnet.com) 82

A hacker has stolen the personal details of over 500,000 San Diego Unified School District staff and students, the district revealed in a breach notice posted on its website Friday. From a report: The breach occurred because the attacker gained access to staff credentials via a tactic known as phishing -- sending authentic-looking emails that redirect users to fake login pages were attackers collect login credentials. The attack didn't go unnoticed. Some staff reported the funny-looking emails to IT staff, who investigated and eventually discovered the breach in October this year. District officials said the hacker had access to its network between January 2018 and November 1, 2018, but that he stole student and staff data going back to the 2008-2009 school year.
Microsoft

Microsoft's Emergency Internet Explorer Patch Renders Some Lenovo Laptops Unbootable (betanews.com) 165

Earlier this month, Microsoft issued an emergency patch for Internet Explorer to fix a zero-day vulnerability in the web browser. The problem affects versions of Internet Explorer from 9 to 11 across multiple versions of Windows, but it seems that the patch has been causing problems for many people. Specifically, people with some Lenovo laptop have found that after installing the KB4467691 patch they are unable to start Windows, reports BetaNews.
Security

Hot Tub Hack Reveals Washed-up Security Protection (bbc.com) 69

Thousands of hot tubs can be hacked and controlled remotely because of a hole in their online security, BBC Click has revealed. From a report: Researchers showed the TV programme how an attacker could make the tubs hotter or colder, or control the pumps and lights via a laptop or smartphone. Vulnerable tubs are designed to let their owners control them with an app. But third-party wi-fi databases mean hackers can home in on specific tubs by using their GPS location data. Balboa Water Group (BWG), which runs the affected system, has now pledged to introduce a more robust security system for owners and said the problem would be fixed by the end of February.

Pen Test Partners -- the UK security company that carried out the research -- warned that hot tubs were not the only household items at risk. Founder Ken Munro said that many Christmas gifts people would receive this year would connect to the internet and offer remote control through apps. "Manufacturers still are not taking security seriously enough, and until they do consumers have to be very vigilant," he said. "We recommend users reset any default passwords the device has immediately with a unique one of their own."

Iphone

iPhone Owners Irate After iOS Update Bricks Cellular Data (tomsguide.com) 154

According to several reports, iPhone users around the world who have upgraded to the latest version of iOS are finding that it cuts off mobile data services. From a report: One Twitter user @kevbruh says that "Apple update 12.1.1, I had no cellular data. I tried inserting my SIM card again, hard resetting my device, and tried resetting the network settings. Nothing happened and the problem persists." In addition to North America, similar issues are being reported in South America, Europe and Asia. Other iPhone owners are reporting that they can't make or receive calls and others are saying that they can't text or receive texts. [...] Many more iPhone users have come forward on Twitter claiming that they are having connectivity issues related to iOS 12.1.2. Apple is advising some to try to update their carrier settings using this guide.
Encryption

India Wants Tech Platforms To Break Encryption And Remove Content The Government Thinks Is 'Unlawful' (buzzfeednews.com) 108

India's government wants to make it mandatory for platforms like Facebook, WhatsApp, Twitter, and Google, to remove content it deems "unlawful" within 24 hours of notice, and create "automated tools" to "proactively identify and remove" such material. From a report: It also wants tech companies to build in a way to trace the source of the content, which would require platforms like WhatsApp to break end-to-end encryption. India's Ministry of Electronics and Information Technology (MeitY) published [PDF] the proposed rules on its website following a report on Monday by The Indian Express revealing the government's proposal to modify the country's primary IT law to work them in. The report comes days after India's government seemingly authorized 10 federal agencies to snoop into every computer in the country last week. The proposed measures have provoked concerns from privacy activists who claim they would threaten free speech and enable mass surveillance.

[...] If India does work these rules into its IT law, it would have precedent: Earlier this month, Australia passed a controversial encryption bill that would require technology companies to give law enforcement agencies access to encrypted communications, saying that it was essential to stop terrorists and criminals who rely on secure messaging apps to communicate.

United States

Huawei Had a Deal To Give Washington Redskins Fans Free Wi-Fi, Until the Government Stepped In (wsj.com) 113

Two years after a congressional report labeled Huawei a national-security threat, the Chinese firm unexpectedly scored a big-name ally in Washington. It was the Redskins, the capital's National Football League franchise. Huawei reached an agreement in 2014 to beam Wi-Fi through the suites at the team's FedEx Field, in exchange for advertising in the stadium and during broadcasts. From a report: It was a marketing coup for a company hankering to beef up its meager U.S. business and boost its image inside the Beltway. But the deal didn't last long. A government adviser read about the partnership. He knew the FedEx Field suites were a frequent haunt for lawmakers and senior officials across many agencies. So he triggered an unofficial federal complaint to the Redskins, who quietly tore up the deal. That previously unreported backroom maneuver is an example of a yearslong effort by U.S. officials, often working outside formal channels, to blacklist the Chinese technology giant. Washington has since intensified the campaign and taken it mainstream, with Congress and federal agencies working this year to snuff out Huawei's small U.S. business and curtail its much bigger overseas ambition. Further reading: Huawei Exceeds 200 Million Smartphone Shipments, Setting Company Record.

Slashdot Top Deals