Iphone

iPhone Owners Irate After iOS Update Bricks Cellular Data (tomsguide.com) 154

According to several reports, iPhone users around the world who have upgraded to the latest version of iOS are finding that it cuts off mobile data services. From a report: One Twitter user @kevbruh says that "Apple update 12.1.1, I had no cellular data. I tried inserting my SIM card again, hard resetting my device, and tried resetting the network settings. Nothing happened and the problem persists." In addition to North America, similar issues are being reported in South America, Europe and Asia. Other iPhone owners are reporting that they can't make or receive calls and others are saying that they can't text or receive texts. [...] Many more iPhone users have come forward on Twitter claiming that they are having connectivity issues related to iOS 12.1.2. Apple is advising some to try to update their carrier settings using this guide.
Encryption

India Wants Tech Platforms To Break Encryption And Remove Content The Government Thinks Is 'Unlawful' (buzzfeednews.com) 108

India's government wants to make it mandatory for platforms like Facebook, WhatsApp, Twitter, and Google, to remove content it deems "unlawful" within 24 hours of notice, and create "automated tools" to "proactively identify and remove" such material. From a report: It also wants tech companies to build in a way to trace the source of the content, which would require platforms like WhatsApp to break end-to-end encryption. India's Ministry of Electronics and Information Technology (MeitY) published [PDF] the proposed rules on its website following a report on Monday by The Indian Express revealing the government's proposal to modify the country's primary IT law to work them in. The report comes days after India's government seemingly authorized 10 federal agencies to snoop into every computer in the country last week. The proposed measures have provoked concerns from privacy activists who claim they would threaten free speech and enable mass surveillance.

[...] If India does work these rules into its IT law, it would have precedent: Earlier this month, Australia passed a controversial encryption bill that would require technology companies to give law enforcement agencies access to encrypted communications, saying that it was essential to stop terrorists and criminals who rely on secure messaging apps to communicate.

United States

Huawei Had a Deal To Give Washington Redskins Fans Free Wi-Fi, Until the Government Stepped In (wsj.com) 113

Two years after a congressional report labeled Huawei a national-security threat, the Chinese firm unexpectedly scored a big-name ally in Washington. It was the Redskins, the capital's National Football League franchise. Huawei reached an agreement in 2014 to beam Wi-Fi through the suites at the team's FedEx Field, in exchange for advertising in the stadium and during broadcasts. From a report: It was a marketing coup for a company hankering to beef up its meager U.S. business and boost its image inside the Beltway. But the deal didn't last long. A government adviser read about the partnership. He knew the FedEx Field suites were a frequent haunt for lawmakers and senior officials across many agencies. So he triggered an unofficial federal complaint to the Redskins, who quietly tore up the deal. That previously unreported backroom maneuver is an example of a yearslong effort by U.S. officials, often working outside formal channels, to blacklist the Chinese technology giant. Washington has since intensified the campaign and taken it mainstream, with Congress and federal agencies working this year to snuff out Huawei's small U.S. business and curtail its much bigger overseas ambition. Further reading: Huawei Exceeds 200 Million Smartphone Shipments, Setting Company Record.
Network

NVIDIA 'GeForce NOW Recommended Routers' Program Helps Gamers Choose Networking Gear (betanews.com) 126

NVIDIA has launched the "GeForce NOW Recommended Routers" program to help gamers choose the best router for them. From a report: "The GeForce NOW game-streaming service has transformed where and how you can enjoy your favorite high-performance games. We've rolled out enhancements during its beta period to improve the quality of service from our data centers to your home. With our recommended routers, in-home network congestion becomes a thing of the past, helping to keep your gameplay silky smooth," says NVIDIA. The gaming company also says, "The latest generation of routers allows you to configure settings to prioritize GeForce NOW before all other data. But we wanted to make it even easier. Recommended routers are certified as factory-enabled with a GeForce NOW quality of service (QoS) profile. It's automatically enabled when you're gaming with GeForce NOW."
Google

Chrome OS To Block USB Access While the Screen is Locked (zdnet.com) 91

Google will add a new security feature to Chrome OS, the company's web-based operating system that powers its Chromebooks devices, it announced this week. From a report: The new feature, named USBGuard, will block access to the USB port access while the device's screen is locked. According to a Chrome OS source code commit spotted by Chrome Story earlier this week, the new feature is currently available in Chrome OS Canary builds and is expected to land in the stable branch of Chrome OS soon. Once this happens, users can enable it by modifying the following Chrome OS flag: chrome://flags/#enable-usbguard . The way this security feature is meant to work is by preventing the operating system from reading or executing any code when a USB-based device is plugged in, and the screen is locked.
Government

Kansas is Trying to Unload $10M in Unused Computer Equipment (apnews.com) 117

An anonymous reader quotes the Associated Press: Kansas Governor Jeff Colyer's administration is seeking a way to donate or sell at a steep discount as much as $10 million in unused computer equipment that has been stored in a state office building since 2016. The state still owes $2 million on the equipment, which it bought in 2016 as part of a failed plan to develop a centralized storage system, call Kansas GovCloud, for computer information. That idea was canceled by state IT officials who said it was too expensive. Instead, the state contracts with an outside company to store data on remote servers.

Attempts to sell the equipment failed to attract bidders, leading to discussions about finding someone to take the equipment before its value dropped to the level of scrap metal, The Topeka Capital-Journal reported. Sen. Tom Holland, D-Baldwin City, said the state allocated $17 million, including $10 million for the equipment, before dropping the storage idea. Selling it for pennies on the dollar or donating it to someone has merit, he said. "The point is, equipment after a while just becomes obsolete. If somebody can use it, great. If you can get some money out of it, fine," Holland said.

Bitcoin

Tim May, Father of 'Crypto Anarchy,' Is Dead At 67 (reason.com) 60

Tim May, co-founder of the influential Cypherpunks mailing list and a significant influence on both bitcoin and WikiLeaks, passed away in mid-December at his home in Corralitos, California. The news was announced last Saturday on a Facebook post written by his friend Lucky Green. Long-time Slashdot reader SonicSpike quotes Reason: In his influential 1988 essay, "The Crypto Anarchist Manifesto," May predicted that advances in computer technology would eventually allow "individuals and groups to communicate and interact with each other" anonymously and without government intrusion. "These developments will alter completely the nature of government regulation [and] the ability to tax and control economic interactions," he wrote... Running 497 words, it was his most influential piece of writing... May became convinced that public-key cryptography combined with networked computing would break apart social power structures...

In September 1992, May and his friends Eric Hughes and Hugh Daniels came up with the idea of setting up an online mailing list to discuss their ideas. Within a few days of its launch, a hundred people had signed up for the Cypherpunks mailing list. (The group's name was coined by Hughes' girlfriend as a play on the "cyberpunk" genre of fiction.) By 1997, it averaged 30 messages daily with about 2,000 subscribers. May was its most prolific contributor. May and Hughes, along with free speech activist John Gilmore, wore masks on the cover of the second issue of Wired magazine accompanying a profile by journalist Steven Levy, who described the Cypherpunks as "more a gathering of those who share a predilection for codes, a passion for privacy, and the gumption to do something about it...."

WikiLeaks founder Julian Assange was an active reader and participant on the list, contributing his first posts in 1995 under the name "Proff."

The article notes that May "recently expressed disgust with the current state of the cryptocurrency community, citing its overpriced conferences and the advent of 'bitcoin exchanges that have draconian rules about KYC, AML, passports, freezes on accounts and laws about reporting 'suspicious activity' to the local secret police.'"

In his last published interview he told CoinDesk "I think Satoshi would barf."
Security

Sneaky Mac Malware Went Undetected By AV Providers For Four Month (arstechnica.com) 28

Four months after a mysterious group was outed for a digital espionage operation that used novel techniques to target Mac users, its macOS malware samples continued to go undetected by most antivirus providers, a security researcher reported on Thursday. Ars Technica reports: Windshift is what researchers refer to as an APT -- short for "advanced persistent threat" -- that surveils individuals in the Middle East. The group operated in the shadows for two years until August, when Taha Karim, a researcher at security firm DarkMatter, profiled it at the Hack in the Box conference in Singapore. Slides, a brief description, and a report from Forbes are here, here and here, respectively.

On Thursday, Mac security expert Patrick Wardle published an analysis of Meeting_Agenda.zip, a file Karim had said installed the rare Mac malware. To Wardle's surprise, results from VirusTotal at the time showed that only two antivirus providers -- Kaspersky and ZoneAlarm -- detected the file as malicious. Wardle then used a feature that searched VirusTotal for related malicious files and found four more. Three of them weren't detected by any AV providers, while one was detected by only two providers. The reason the findings were so surprising is that Apple had already revoked the cryptographic certificate the developers used to digitally sign their malware. That meant Apple knew of the malware. In fairness, the control servers the malware contacts are no longer available on the Internet. That means any infected computers aren't in danger of being surveilled. Also in fairness, the number of detections has slowly risen in the day since Wardle published his analysis.

Privacy

ACLU To Feds: Your 'Hacking Presents a Unique Threat To Individual Privacy' (arstechnica.com) 67

The American Civil Liberties Union, along with Privacy International, a similar organization based in the United Kingdom, have now sued 11 federal agencies, demanding records about how those agencies engage in what is often called "lawful hacking." From a report: The activist groups filed Freedom of Information Act requests to the FBI, the Drug Enforcement Agency, and nine others. None responded in a substantive way. "Law enforcement use of hacking presents a unique threat to individual privacy," the ACLU argues in its lawsuit, which was filed Friday in federal court in New York state. "Hacking can be used to obtain volumes of personal information about individuals that would never previously have been available to law enforcement."
Australia

Australia, Canada, Japan, New Zealand and UK Accuse China of APT10 Hacking Spree (zdnet.com) 61

A day after the US Department of Justice charged two Chinese nationals for being members of a state-sponsored hacking group and accused the Chinese government of orchestrating a string of hacks around the world, five other governments have stepped in with similar accusations. From a report: Australia, Canada, Japan, New Zealand, and the UK have published official statements today formally blaming China of hacking their government agencies and local companies. All statements are in regards to the supposed involvement of the Chinese Ministry of State Security (MSS) in supporting the activity of a hacking group known as APT10. In a DOJ indictment yesterday, the US says this group hacked companies in 12 countries, and later breached cloud service providers, wormed through their infrastructure, and hacked even more companies. US officials said the primary purpose of these hacks was to steal trade secrets and intellectual property that the Chinese government later passed to local Chinese companies, helping create an unfair advantage for local firms on the global market.
Privacy

India To Intercept, Monitor, and Decrypt Citizens' Computers (venturebeat.com) 108

Several readers have shared a report: The Indian government has authorized 10 central agencies to intercept, monitor, and decrypt data on any computer, sending a shock wave through citizens and privacy watchdogs. Narendra Modi's government late Thursday broadened the scope of Section 69 of the nation's IT Act, 2000 to require a subscriber, service provider, or any person in charge of a computer to "extend all facilities and technical assistance to the agencies." Failure to comply with the agencies could result in seven years of imprisonment and an unspecified fine. In a clarification posted today, the Ministry of Home Affairs said each case of interception, monitoring, and decryption is to be approved by the competent authority, which is the Union Home Secretary.

Explaining the rationale behind the order, India's IT minister, Ravi Shankar Prasad, said that the measure was undertaken in the interests of national security. He added that some form of "tapping" has already been going on in the country for a number of years and that the new order would help bring structure to that process. "Always remember one thing," he said in a televised interview. "Even in the case of a particular individual, the interception order shall not be effective unless affirmed by the Home Secretary."

The Internet Freedom Foundation, a nonprofit organization that protects the online rights of citizens in India, cautioned that the order goes beyond telephone tapping. It includes looking at content streams and might even involve breaking encryption in some cases. "Imagine your search queries on Google over [a number of] years being demanded -- mixed with your WhatsApp metadata, who you talk to, when, and how much [and add] layers of data streams from emails + Facebook," it said. "To us this order is unconstitutional and in breach of the telephone tapping guidelines, the Privacy Judgement and the Aadhaar Judgement," it asserted.

The Internet

Microsoft Issues Emergency Fix For Internet Explorer Zero Day (bleepingcomputer.com) 39

An anonymous reader quotes a report from Bleeping Computer: Microsoft has released an out-of-band security update that fixes an actively exploited vulnerability in Internet Explorer. This vulnerability has been assigned ID CVE-2018-8653 and was discovered by Google's Threat Analysis Group when they saw the vulnerability being used in targeted attacks. According to Microsoft's security bulletin this is vulnerability in how the Internet Explorer scripting engine handles objects in memory. Attackers can use this vulnerability to corrupt memory in such a way that attackers could execute code under the security privileges of the logged in user. This vulnerability can also be used to launch attacks through specially crafted web sites that utilize the exploit code. This means that attackers can utilize this feature in exploit kits or by compromising legitimate sites and adding code that exploits the vulnerability.

"A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer," states Microsoft's advisory. "The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights."

Android

Two Android Apps Used In Combat By US Troops Contained Severe Vulnerabilities (zdnet.com) 54

According to a Navy Inspector General report, U.S. military troops used two Android apps that contained severe vulnerabilities in live combat scenarios. "The two apps are named KILSWITCH (Kinetic Integrated Low-Cost Software Integrated Tactical Combat Handheld) and APASS (Android Precision Assault Strike Suite)," reports ZDNet. From the report: Both apps work by showing satellite imagery of surroundings, including objectives, mission goals, nearby enemy and friendly forces. The two apps work as a modern-day replacement for radios and paper maps and allow troops to use a real-time messaging client to coordinate with other military branches, and even call in air-strike support with a few simple screen taps, according to a DARPA press release and accompanying YouTube video. The apps have been under development since 2012 and starting 2015, they have been made generally available to all U.S. troops via a public app store managed by the National Geospatial-Intelligence Agency. But according to a Navy Inspector General report from March that was made public today, both apps contained vulnerabilities that could have allowed enemy forces access to troops' information.

The heavily redacted report doesn't detail the nature of the two vulnerabilities, but it does point out that the Navy had failed to control the distribution of these two applications, and later failed to act in warning troops of the danger they were in for almost a year. The report says that the two apps, KILSWITCH and APASS, were never meant or approved to be deployed in live combat zones. But the two apps, because of their flashy features and easier to use interface, became wildly popular among U.S. troops, but also other military branches, including foreign allied forces.

Security

FBI Shuts Down 15 DDoS-For-Hire Sites (techcrunch.com) 49

The FBI has shut down the domains of 15 high-profile distributed denial-of-service (DDoS) websites. "Several seizure warrants granted by a California federal judge went into effect Thursday, removing several of these 'border' or 'stresser' sites off the internet 'as part of coordinated law enforcement action taken against illegal DDoS-for-hire services,'" reports TechCrunch. "The orders were granted under federal seizure laws, and the domains were replaced with a federal notice." From the report: Prosecutors have charged three men, Matthew Gatrel and Juan Martinez in California and David Bukoski in Alaska, with operating the sites, according to affidavits filed in three U.S. federal courts, which were unsealed Thursday. The FBI had assistance from the U.K.'s National Crime Agency and the Dutch national police, and the Justice Department named several companies, including Cloudflare, Flashpoint and Google, for providing authorities with additional assistance. In all, several sites were knocked offline -- including downthem.org, netstress.org, quantumstress.net, vbooter.org and defcon.pro and more -- which allowed would-be attackers to sign up to rent time and servers to launch large-scale bandwidth attacks against systems and servers.
Security

China Hacked HPE, IBM and Then Attacked Clients, Report Finds (reuters.com) 59

An anonymous reader quotes a report from Reuters: Hackers working on behalf of China's Ministry of State Security breached the networks of Hewlett Packard Enterprise and IBM, then used the access to hack into their clients' computers, according to five sources familiar with the attacks. The attacks were part of a Chinese campaign known as Cloudhopper, which the United States and Britain on Thursday said infected technology service providers in order to steal secrets from their clients. While cybersecurity firms and government agencies have issued multiple warnings about the Cloudhopper threat since 2017, they have not disclosed the identity of technology companies whose networks were compromised. IBM said it had no evidence that sensitive corporate data had been compromised. HPE said it could not comment on the Cloudhopper campaign.

Cloudhopper targeted managed service providers (MSPs) to access client networks and steal corporate secrets from companies around the globe, according to a U.S. federal indictment of two Chinese nationals unsealed on Thursday. Prosecutors did not identify any of the MSPs that were breached. Cloudhopper, which has been targeting technology services providers for several years, infiltrated the networks of HPE and IBM multiple times in breaches that lasted for weeks and months. Reuters was unable to confirm the names of other breached technology firms or identify any affected clients.
Both IBM and HPE provided statements but declined to comment on the specific claims made by the sources. "The security of HPE customer data is our top priority," HPE said. "We are unable to comment on the specific details described in the indictment, but HPE's managed services provider business moved to DXC Technology in connection with HPE's divestiture of its Enterprise Services business in 2017."

"IBM has taken extensive counter measures worldwide as part of its continuous efforts to protect itself and its clients against constantly evolving threats," the company said in an emailed statement. "We take responsible stewardship of client data very seriously and have no evidence that sensitive IBM or client data has been compromised."
Communications

Facebook's WhatsApp Has an Encrypted Child Porn Problem (techcrunch.com) 156

Videos and pictures of children being subjected to sexual abuse are being openly shared on Facebook's WhatsApp on a vast scale, with the encrypted messaging service failing to curb the problem despite banning thousands of accounts every day. From a report: Without the necessary number of human moderators, the disturbing content is slipping by WhatsApp's automated systems. A report reviewed by TechCrunch from two Israeli NGOs details how third-party apps for discovering WhatsApp groups include "Adult" sections that offer invite links to join rings of users trading images of child exploitation. TechCrunch has reviewed materials showing many of these groups are currently active.

TechCrunch's investigation shows that Facebook could do more to police WhatsApp and remove this kind of content. Even without technical solutions that would require a weakening of encryption, WhatsApp's moderators should have been able to find these groups and put a stop to them. Groups with names like "child porn only no adv" and "child porn xvideos" found on the group discovery app "Group Links For Whats" by Lisa Studio don't even attempt to hide their nature.

Better manual investigation of these group discovery apps and WhatsApp itself should have immediately led these groups to be deleted and their members banned. While Facebook doubled its moderation staff from 10,000 to 20,000 in 2018 to crack down on election interference, bullying, and other policy violations, that staff does not moderate WhatsApp content. With just 300 employees, WhatsApp runs semi-independently, and the company confirms it handles its own moderation efforts. That's proving inadequate for policing at 1.5 billion user community.
It's a similar problem that WhatsApp, used by more than a billion users, is facing in developing markets where its service is being used to spread false information.
United States

US Slams China For Corporate Cyber Espionage, Indicts Two Spies (reuters.com) 54

U.S. authorities on Thursday unveiled indictments against two Chinese nationals linked to China's government who took part in a cyber spying campaign that hacked a range of American government agencies and corporations and violated a 2015 pact, escalating tensions between the two nations. From a report: The U.S. Justice Department charged Zhu Hua and Zhang Jianguo in computer hacking attacks on the U.S. Navy, the space agency NASA and businesses in numerous sectors. The defendants hacked computers to steal intellectual property and confidential business and technological data, according to the indictment. U.S. and British authorities on Thursday also condemned China for violating 2015 agreements to curb cyber espionage for business purposes, slamming Chinese efforts to steal other countries' trade secrets and technologies and to compromise government computers.
Debian

Debian's Anti-Harassment Team Is Removing A Package Over Its Name (phoronix.com) 521

quantic_oscillation7 shares a report: The latest notes from the Debian anti-harassment team on Wednesday caught my attention when reading, "We were requested to advice on the appropriateness of a certain package in the Debian archive. Our decision resulted in the package pending removal from the archive." Curiosity got the best of me... What package was deemed too inappropriate for the Debian archive?

When digging further, the package raised to the Debian Anti-Harassment Team was "Weboob." Weboob is short for "Web Outside of Browsers" as it's an open-source collection of software to script and automate the parsing/scraping/gathering-via-API of web data so that it can be consumed by different modules/applications. Weboob.org describes itself as "Weboob is a collection of applications able to interact with websites, without requiring the user to open them in a browser. It also provides well-defined APIs to talk to websites lacking one."

Weboob is Python-based and offers Qt-based user interfaces for accessing these different modules for reading data from different web-sites outside of any conventional web browser. Those interested can learn more about the software at Weboob.org. But, yes, the name is juvenile and likely inappropriate in most professional/corporate environments.

Microsoft

Microsoft Announces Project Mu, an Open-Source Release of the UEFI Core (betanews.com) 121

Mark Wilson writes: Microsoft has a new open source project -- Project Mu. This is the company's open-source release of the Unified Extensible Firmware Interface (UEFI) core which is currently used by Surface devices and Hyper-V. With the project, Microsoft hopes to make it easier to build scalable and serviceable firmware, and it embraces the idea of Firmware as a Service (FaaS). This allows for fast and efficient updating of firmware after release, with both security patches and performance-enhancing updates.

FaaS is something that Microsoft has already enabled on Surface, but the company realized that TianoCore -- the existing open-source implementation of UEFI -- was not optimized for rapid servicing. This is where Project Mu can help, the company says. "Mu is built around the idea that shipping and maintaining a UEFI product is an ongoing collaboration between numerous partners. For too long the industry has built products using a 'forking' model combined with copy/paste/rename and with each new product the maintenance burden grows to such a level that updates are near impossible due to cost and risk," the company said.

Crime

US Treasury Sanctions 16 Russians For Hacking, Election Meddling (engadget.com) 129

An anonymous reader quotes a report from Engadget: The Treasury Department has leveled sanctions against 16 current and former GRU intelligence officers (some of whom were targeted in earlier indictments) for their involvement in multiple campaigns against the U.S., including the Democratic National Committee hacks, World Anti-Doping Agency hacks and election meddling efforts. The targets include Elena Khusyaynova, the primary accountant for the Project Lakhta influence campaign that included the Internet Research Agency. The sanctions also target associated entities like the Federal News Agency.

As with the indictments, the sanctions will only have a limited effect. The measure blocks all property and interests from these people that might be in U.S. jurisdictions, and Americans are "generally prohibited" from conducting transactions with them. The targets live in Russia, though, and it's doubtful that they'll travel to countries where the sanctions will hit them. This is more a symbolic gesture than one intended to curb Russian hacks and manipulation attempts.

Slashdot Top Deals