IT

Ask Slashdot: What Kind of Keyboard Do You Use With Your Computer and Why? 363

An anonymous reader writes: Hello all. I am looking to buy a good mechanical keyboard for my everyday usage — programming and writing. I see some good offers on certain keyboards -- thanks to Black Friday deals. Just this week, Razer launched what looks like a good mechanical keyboard for people who are looking for a budget gear. One of the issues I have come across looking for a good keyboard is how most of them are designed for Windows OS by default. (I know you can customize keys, but.)

Slashdot has run keyboard discussion posts in the past -- the best laptop with best keyboard, greatest keyboard ever made, and quest to find a good keyboard , but I don't see any recent story on this. I was curious to know what kind of keyboard you use and why did you choose the one you have?
Privacy

Amazon Has Emailed an Unspecified Number of Customers To Inform Them That Their Names and Addresses Were Disclosed by the Website, Blames 'Technical Error' (betanews.com) 31

If you have received a strange email from Amazon today, you're not alone. A number of customers on Wednesday received an email from the company in which it notes that it "inadvertently disclosed your name and email address due to a technical error." The company confirmed to BetaNews that the emails are genuine, but did not discuss the nature and severity of the technical error and how many customers are impacted. The technical error impacted customers in the United States as well as United Kingdom. It remains unclear if customers elsewhere were affected too. In a statement, the company said, "We have fixed the issue and informed customers who may have been impacted."
Wireless Networking

Using Airport and Hotel Wi-Fi Is Much Safer Than It Used To Be (wired.com) 60

As you travel this holiday season, bouncing from airport to airplane to hotel, you'll likely find yourself facing a familiar quandary: Do I really trust this random public Wi-Fi network? As recently as a couple of years ago, the answer was almost certainly a resounding no. But in the year of our lord 2018? Friend, go for it. Wired: This advice comes with plenty of qualifiers. If you're planning to commit crimes online at the Holiday Inn Express, or to visit websites that you'd rather people not know you frequented, you need to take precautionary steps that we'll get to in a minute. Likewise, if you're a high-value target of a sophisticated nation state, stay off of public Wi-Fi at all costs. But for the rest of us? You're probably OK. That's not because hotel and airport Wi-Fi networks have necessarily gotten that much more secure. The web itself has.

"A lot of the former risks, the reasons we used to warn people, those things are gone now," says Chet Wisniewski, principle researcher at security firm Sophos. "It used to be because almost nothing on the internet was encrypted. You could sit there and sniff everything. Or someone could set up a rogue access point and pretend to be Hilton, and then you would connect to them instead of the hotel." In those Wild West days, in other words, signing onto a shared Wi-Fi network exposed you to myriad attacks, from hackers tracking your every move online, to so-called man-in-the-middle efforts that tricked you into entering your passwords, credit card information, or more on phony websites. A cheap, easy to use device called a Wi-Fi Pineapple makes those attacks simple to pull off. All of that's still technically possible. But a critical internet evolution has made those efforts much less effective: the advent of HTTPS.

Microsoft

Microsoft Now Lets You Log Into Outlook, Skype, Xbox Live With No Password (cnet.com) 60

You and 800 million other people now can use hardware authentication keys -- and no password at all -- to log on to Microsoft accounts used for Outlook, Office 365, OneDrive, Skype and Xbox Live. From a report: Microsoft is using a technology called FIDO2, which employs hardware keys for the no-password logon, the company said Tuesday. New versions of Microsoft's Windows 10 operating system and Edge web browser support the technology. The hardware authentication keys plug into laptop USB ports or, for phones, use Bluetooth or NFC wireless communications to help prove who you are. Initially, they worked in combination with a password for dual-factor authentication, but FIDO2 and a related browser technology called WebAuthn expands beyond that to let the company ditch the password altogether.

Microsoft's no-password logon offers three options: the hardware key combined with Windows Hello face recognition technology or fingerprint ID; the hardware key combined with a PIN code; or a phone running the Microsoft Authenticator app. It works with Outlook.com, Office 365, Skype, OneDrive, Cortana, Microsoft Edge, Xbox Live on the PC, Mixer, the Microsoft Store, Bing and the MSN portal site.

Microsoft

Microsoft Pulls Some Non-Security Updates For Microsoft Office 2010, 2013 and 2016 That It Released Earlier This Month (betanews.com) 58

Mark Wilson, writing for BetaNews: Having released a series of updates for Office 2010, 2013 and 2016 as part of this month's Patch Tuesday, Microsoft has now pulled two of them and advised sysadmins to uninstall the updates if they have already been installed. In both instances -- KB4461522 and KB2863821 -- Microsoft says that the problematic updates can lead to application crashes. While this is not as serious a problem as, say, data loss, it does little to quieten the fears that have been voiced about the quality control Microsoft has over its updates.
The Courts

Russia Wants DNC Hack Lawsuit Thrown Out, Citing International Conventions (zdnet.com) 267

An anonymous reader quotes a report from ZDNet: The Russian Federation has responded to a lawsuit filed by the Democratic National Committee and has requested the overseeing court to throw out the lawsuit altogether. The lawsuit, filed by the DNC in April 2018, names a slew of figures as defendants, such as the Russian state, Russia's military intelligence service GRU, the hacker known as Guccifer 2.0, WikiLeaks and its founder Julian Assange, and several members of the Trump campaign, such as Donald Trump, Jr., Paul Manafort, Roger Stone, Jared Kushner, and George Papadopoulos. According to an 87-page indictment, the DNC accused Russia and the other defendants of carrying out the hacking of DNC servers in 2016 and then leaking data online via the WikiLeaks portal in an orchestrated manner for the benefit of the Trump presidential campaign.

The lawsuit, which has its own Wikipedia page and was likened to a lawsuit the DNC filed against Nixon after the Watergate scandal, seeks damages, but also for the court to issue a declaration about the defendants' conspiracy. But in a letter sent to a New York court, presented by the Russian Embassy in the U.S. and signed by a representative of the Russian Ministry of Justice, the Russian Federation wants the lawsuit thrown out. In the 12-page letter, the Russian Federation argues that the U.S. Foreign Sovereign Immunities Act ("FSIA") grants Russia immunity.
"The FSIA provides that foreign sovereign States enjoy absolute jurisdictional immunity from suit unless a plaintiff can demonstrate that one of the FSIA's enumerated 'exceptions' applies'," the letter argues. "The DNC's allegations regarding a purported 'military attack' by 'Russia's military intelligence agency' do not fall within any of the FSIA's enumerated exceptions to the Russian Federation's sovereign immunity."

"Any alleged 'military attack' is a quintessential sovereign act that does not fall within any exception to the FSIA or the customary international law of foreign sovereign immunity. The Russian Federation's sovereign immunity with respect to claims based upon such allegations is absolute."
Microsoft

Office 365 Users in Europe, Asia, and Americas Who Have Enabled Multi-Factor Authentication (MFA) Are Impacted by an Outage (theregister.co.uk) 72

New submitter neo00 writes: Office 365 users in Europe, Asia, and Americas are impacted by a wide-spread outage causing users who have Multi-Factor Authentication (MFA) enabled by default policy to be unable to login to Office 365 and other services reliant on Azure Active Directory. According to The Register: "Microsoft confirmed that there were problems from 04:39 UTC with a subset of customers in Europe and Asia-Pacific experiencing 'difficulties signing into Azure resources' such as the, er, little used Azure Active Directory, when Multi-Factor Authentication (MFA) is enabled. Six hours later, and the problems are continuing."

The Office 365 health status page has reported that: "Affected users may be unable to sign in using MFA" and Azure's own status page confirmed that there are "issues connecting to Azure resources" thanks to the borked MFA."

Official Azure status updates are published here.


Privacy

AWS Rolls Out New Security Feature To Prevent Accidental S3 Data Leaks (zdnet.com) 32

Amazon's Web Services division rolled out new security features to AWS account owners last week that are meant to prevent accidental data exposures caused by the misconfiguration of S3 data storage buckets. From a report: Starting today, AWS account owners will have access to four new options inside their S3 dashboards under the "Public access settings for this account" section. These four new options allow the account owner to set a default access setting for all of an account's S3 buckets. These new account-level settings will override any existing or newly created bucket-level ACLs (access control lists) and policies. Account owners will have the ability to apply these new settings for S3 buckets that will be created from now onwards, to apply the new setting retroactively, or both.
Businesses

GitLab's Secret To Success? All Its 350 Employees Work Remotely (inc.com) 106

Inc. magazine explains a unique feature of GitLab. "Every employee of the San Francisco-based startup, which offers tools for software developers, works from home." Three years ago, that was nine people. Today, GitLab's 350 employees across 45 countries use video calls and Slack chats to stay constantly connected.... GitLab meetings and presentations are uploaded to YouTube. Its employee handbook -- over 1,000 pages long when printed -- is publicly available online as a resource, so employees can get questions answered without waking up co-workers in a different time zone.

The biggest advantage to an all-remote team is obvious: Your hiring pool is gigantic, and you don't need to convince top talent to move for you. GitLab's percentage of quality job applications is similar to other companies -- its dramatic number of recent hires is due to how many applications it receives, 13,000 in the second quarter of 2018 alone. On the other hand, maintaining a culture is really difficult. "To be honest, I was definitely a bit concerned," says Dave Munichiello, a general partner at Alphabet's venture capital arm, GV, which invested in GitLab in 2017. "What happens when the all-hands meeting isn't a bunch of folks hanging around the water cooler listening to the CEO articulate the vision and the mission?"

GitLab's leaders constantly think about it. Co-founder and CEO Sid Sijbrandij even hired away Netflix's vice president of talent, Barbie Brewer, to serve as chief people officer. Virtual coffee breaks, where employees talk about their lives outside GitLab, are built into everyone's schedules. Senior leaders hold office hours in video chat rooms that anyone can join. When GitLab meets its monthly goals, everyone gets a free dinner. "What we've learned from GitLab," Munichiello says, "is that when you have a leadership team that's as committed to remote-only as they are, and as communicative and transparent as they are, and as insistent on documentation as they are, it can work."

Security

Hacker Says They Compromised ProtonMail; ProtonMail Calls BS (bleepingcomputer.com) 55

A hacker going by the name AmFearLiathMor is claiming to have hacked ProtonMail and stolen "significant" amounts of data. They have posted a ransom demand to an anonymous Pastebin but it reads like a prank, as it states that the alleged hackers have access to underwater drone activity and treaty violations in Antarctica. Lawrence Abrams writes via BleepingComputer: According to the message, a hacker going by the name AmFearLiathMor makes quite a few interesting claims such as hacking ProtonMail's services and stealing user's email, that ProtonMail is sending their user's decrypted data to American servers, and that ProtonMail is abusing the lack of Subresource Integrity (SRI) use to purposely and maliciously steal their user's passwords. After reading the Pastebin message (archive.is link), which is shown in its entirety below minus some alleged keys, and seeing the amount of claims, the first thing that came to mind was a corporate version of the sextortion scams that have been running rampant lately. As I kept reading it, though, it just felt like a joke. ProtonMail posted on Twitter that this is a hoax and that there is no evidence that anything states is true. The encrypted email service provided a statement to BleepingComputer: "We believe this extortion attempt is a hoax, and we have seen zero evidence to suggest otherwise. Not a single claim made is true and many of the claims are unsound from a technical standpoint. We are aware of a small number of ProtonMail accounts that have been compromised as a result of those individual users falling for phishing attempts. However, there is zero evidence of a breach of our infrastructure."
Blackberry

BlackBerry Buys Cybersecurity Firm Cylance For $1.4 Billion (securityweek.com) 34

wiredmikey shares a report from SecurityWeek: BlackBerry on Friday announced that it has agreed to acquire endpoint security firm Cylance for $1.4 billion in cash. "We plan on immediately expanding the capabilities across BlackBerry's 'chip-to-edge' portfolio, including QNX, our safety-certified embedded OS that is deployed in more than 120 million vehicles, robot dogs, medical devices, and more," a BlackBerry company spokesperson told SecurityWeek. "Over time, we plan to integrate Cylance technology with our Spark platform, which is at the center of our strategy to ensure data flowing between endpoints (in a car, business, or smart city) is secured, private, and trusted." Cylance has raised roughly $300 million in funding [prior being acquired]. BlackBerry describes the "Spark platform" as a secure chip-to-edge communications platform "designed for ultra-security and industry-specific safety-certifications, such as ISO 26262 in automobiles."
Security

Lock-Screen Bypass Bug Quietly Patched In Handsets (threatpost.com) 21

secwatcher shares a report from Threatpost: A design flaw affecting all in-display fingerprint sensors -- that left over a half-dozen cellphone models vulnerable to a trivial lock-screen bypass attack -- has been quietly patched. The flaw was tied to a bug in the popular in-display fingerprint reader technology used for user authentication. In-display fingerprint reader technology is widely considered an up-and-coming feature to be used in a number of flagship model phones introduced in 2019 by top OEM phone makers, according to Tencent's Xuanwu Lab which is credited for first identifying the flaw earlier this year. Impacted are all phones tested in the first half of 2018 that had in-display fingerprint sensors. That includes current models of Huawei Technologies' Porsche Design Mate RS and Mate 20 Pro model phones. Researchers said that many more cellphone manufacturers are impacted by the issue. The most popular phone in the U.S. that is impacted by this vulnerability is the OnePlus 6T. "[A]ll an attacker needs to carry out the attack is an opaque reflective material such as aluminum foil," reports Threatpost. "By placing the reflective material over a residual fingerprint on the phone's display the capacitance fingerprint imaging mechanism can be tricked into authenticating a fingerprint."
Security

MiSafes' Child-Tracking Smartwatches Are 'Easy To Hack' (bbc.com) 29

The location-tracking "MiSafe" smartwatch may not be as safe as the name proclaims. According to security researchers from Pen Test Partners, the watches are easy to hack as they do not encrypt the data they use or secure each child's account. The researchers found that they could track children's movements, surreptitiously listen in to their activities and make spoof calls to the watches that appeared to be from parents. The BBC reports: The MiSafes watch was first released in 2015. It uses a global positioning system (GPS) sensor and a 2G mobile data connection to let parents see where their child is, via a smartphone app. In addition, parents can create a "safe zone" and receive an alert if the child leaves the area. The adult can also listen in to what their offspring is doing at any time and trigger two-way calls.

Pen Test Partner's Ken Munro and Alan Monie learned of the product's existence when a friend bought one for his son earlier this year. Out of curiosity, they probed its security measures and found that easy-to-find PC software could be used to mimic the app's communications. This software could be used to change the assigned ID number, which was all it took to get access to others' accounts. This made it possible to see personal information used to register the product, including: a photo of the child; their name, gender and date of birth; their height and weight; the parents' phone numbers; and the phone number assigned to the watch's Sim card.

United States

Trump Signs Bill That Creates the Cybersecurity and Infrastructure Security Agency (zdnet.com) 72

An anonymous reader quotes a report from ZDNet: U.S. President Donald Trump signed today a bill into law, approving the creation of the Cybersecurity and Infrastructure Security Agency (CISA). The bill, known as the CISA Act, reorganizes and rebrands the National Protection and Programs Directorate (NPPD), a program inside the Department of Homeland Security (DHS), as CISA, a standalone federal agency in charge of overseeing civilian and federal cybersecurity programs. The NPPD, which was first established in 2007, has already been handling almost all of the DHS' cyber-related issues and projects.

As part of the DHS, the NPPD was the government entity in charge of physical and cyber-security of federal networks and critical infrastructure, and oversaw the Federal Protective Service (FPS), the Office of Biometric Identity Management (OBIM), the Office of Cyber and Infrastructure Analysis (OCIA), the Office of Cybersecurity & Communications (OC&C), and the Office of Infrastructure Protection (OIP). As CISA, the agency's prerogatives will remain the same, and nothing is expected to change in day-to-day operations, but as a federal agency, CISA will now benefit from an increased budget and more authority in imposing its directives.
"Elevating the cybersecurity mission within the Department of Homeland Security, streamlining our operations, and giving NPPD a name that reflects what it actually does will help better secure the nation's critical infrastructure and cyber platforms," said NPPD Under Secretary Christopher Krebs. "The changes will also improve the Department's ability to engage with industry and government stakeholders and recruit top cybersecurity talent."
Security

Most ATMs Can Be Hacked in Under 20 Minutes (zdnet.com) 78

An extensive testing session carried out by bank security experts at Positive Technologies has revealed that most ATMs can be hacked in under 20 minutes, and even less, in certain types of attacks. From a report: Experts tested ATMs from NCR, Diebold Nixdorf, and GRGBanking, and detailed their findings in a 22-page report published this week. The attacks they tried are the typical types of exploits and tricks used by cyber-criminals seeking to obtain money from the ATM safe or to copy the details of users' bank cards (also known as skimming). Experts said that 85 percent of the ATMs they tested allowed an attacker access to the network. The research team did this by either unplugging and tapping into Ethernet cables, or by spoofing wireless connections or devices to which the ATM usually connected to. Researchers said that 27 percent of the tested ATMs were vulnerable to having their processing center communications spoofed, while 58 percent of tested ATMs had vulnerabilities in their network components or services that could be exploited to control the ATM remotely.
Privacy

A Leaky Database of SMS Text Messages Exposed Password Resets and Two-Factor Codes (techcrunch.com) 37

A database which contained millions of text messages used to authenticate users signing into websites was left exposed to the internet without a password. From the report: The exposed server belongs to Voxox (formerly Telcentris), a San Diego, Calif.-based communications company. The server wasn't protected with a password, allowing anyone who knew where to look to peek in and snoop on a near-real-time stream of text messages. For Sebastien Kaul, a Berlin-based security researcher, it didn't take long to find. Although Kaul found the exposed server on Shodan, a search engine for publicly available devices and databases, it was also attached to to one of Voxox's own subdomains. Worse, the database -- running on Amazon's Elasticsearch -- was configured with a Kibana front-end, making the data within easily readable, browsable and searchable for names, cell numbers and the contents of the text messages themselves.
The Internet

'The Internet Needs More Friction' (vice.com) 155

Justin Kosslyn, who leads product management at Jigsaw, a unit within Alphabet that builds technology to address global security challenges, writes: The Internet's lack of friction made it great, but now our devotion to minimizing friction is perhaps the internet's weakest link for security. Friction -- delays and hurdles to speed and growth -- can be a win-win-win for users, companies, and security. It is time to abandon our groupthink bias against friction as a design principle. Highways have speed limits and drugs require prescriptions -- rules that limit how fast you can drive a vehicle or access a controlled substance -- yet digital information moves limitlessly. The same design philosophy that accelerated the flow of correspondence, news, and commerce also accelerates the flow of phishing, ransomware, and disinformation.

In the old days, it took time and work to steal secrets, blackmail people, and meddle across borders. Then came the internet. From the beginning, it was designed as a frictionless communication platform across countries, companies, and computers. Reducing friction is generally considered a good thing: it saves time and effort, and in many genuine ways makes our world smaller. There are also often financial incentives: more engagement, more ads, more dollars. But the internet's lack of friction has been a boon to the dark side, too. Now, in a matter of hours a "bad actor" can steal corporate secrets or use ransomware to blackmail thousands of people. Governments can influence foreign populations remotely and at relatively low cost. Whether the threat is malware, phishing, or disinformation, they all exploit high-velocity networks of computers and people.

Businesses

Remote Workers Can Get a Cushy Apartment, Free Office Space, and $10K If They Move To Tulsa (nextgov.com) 190

Tulsa, Oklahoma is offering full-time remote workers in the U.S. free office space, a subsidized furnished apartment, and $10,000 cash if you move there and stay for at least one year. The city wants to attract so-called "digital nomads," who would, presumably, start paying taxes, launch businesses, and otherwise contribute to the economy of wherever they're drawn to. Nextgov reports: Tulsa Remote is one of several revitalization projects in the region funded by the George Kaiser Family Foundation. The Tulsa-based philanthropic organization was started by George B. Kaiser, an oil and banking billionaire who has signed on to Warren Buffett and Bill and Melinda Gates' "Giving Pledge," whose wealthy signees promise to give away at least half their fortunes to charity.

The organization has budgeted for 20 new remote workers in the program's first year, says Ken Levit, GKFF's executive director. Applicants must be at least 18, eligible to work in the U.S., already working full-time for an employer based outside the boundaries of Tulsa County, and prepared to move to Tulsa within six months. Applications opened Tuesday at the website TulsaRemote.com; the city hopes to settle the first new residents within the next three months, Levit said.

Security

Why Sleep Apnea Patients Rely On a Lone, DRM-Breaking CPAP Machine Hacker (vice.com) 154

Jason Koebler writes: "SleepyHead" is a free, open-source, and definitely not FDA-approved piece of software for sleep apnea patients that is the product of thousands of hours of hacking and development by a lone Australian developer named Mark Watkins, who has helped thousands of sleep apnea patients take back control of their treatment from overburdened and underinvested doctors. The software gives patients access to the sleep data that is already being generated by their CPAP machines but generally remains inaccessible, hidden by DRM and proprietary data formats that can only be read by authorized users (doctors) on proprietary pieces of software that patients often can't buy or download. SleepyHead and community-run forums like CPAPtalk.com and ApneaBoard.com have allowed patients to circumvent medical device manufacturers, who would prefer that the software not exist at all. Medical device manufacturers fought in 2015 to prevent an exemption to the Digital Millennium Copyright Act to legalize hacking by patients who wanted to access their own data, but an exemption was granted, legalizing SleepyHead and software like it.
Security

The F-35's Greatest Vulnerability Isn't Enemy Weapons. It's Being Hacked. (popularmechanics.com) 137

schwit1 shares a report: Every F-35 squadron, no matter the country, has a 13-server ALIS package that is connected to the worldwide ALIS network. Individual jets send logistical data back to their nation's Central Point of Entry, which then passes it on to Lockheed's central server hub in Fort Worth, Texas. In fact, ALIS sends back so much data that some countries are worried it could give away too much information about their F-35 operations. Another networking system is the Joint Reprogramming Enterprise, or JRE. The JRE maintains a shared library of potential adversary sensors and weapon systems that is distributed to the worldwide F-35 fleet. For example, the JRE will seek out and share information on enemy radar and electronic warfare signals so that individual air forces will not have to track down the information themselves. This allows countries with the F-35 to tailor the mission around anticipated threats -- and fly one step ahead of them.

Although the networks have serious cybersecurity protections, they will undoubtedly be targets for hackers in times of peace, and war. Hackers might try to bring down the networks entirely, snarling the worldwide logistics system and even endangering the ability of individual aircraft to get much-needed spare parts. Alternately, it might be possible to compromise the integrity of the ALIS data -- by, say, reporting a worldwide shortage of F-35 engines. Hackers could conceivably introduce bad data in the JRE that could compromise the safety of a mission, shortening the range of a weapon system so that a pilot thinks she is safely outside the engagement zone when she is most certainly not. Even the F-35 simulators that train pilots could conceivably leak data to an adversary. Flight simulators are programmed to mirror flying a real aircraft as much as possible, so data retrieved from a simulator will closely follow the data from a real F-35.

Slashdot Top Deals