United States

High Housing Prices In Tech Cities Are Now Raising Home Prices In Other States (bloombergquint.com) 253

Tech cities and their high housing prices are apparently now driving up home prices in other states. An anonymous reader quotes Bloomberg: For some Californians, the state's punishing housing costs, high taxes, and constant threat of natural disaster have all become too much... In the second quarter, only 26 percent of homebuyers in the state could afford to purchase a median-price single-family house, which was almost $600,000, according to the California Association of Realtors... They're making their escape to areas such as Boise, Phoenix, and Reno, Nevada, fueling some of the biggest home-price gains in the country... Almost 143,000 more people left the state than arrived from elsewhere in the U.S. in 2016....

Boise is becoming an alternative to traditional havens for Californians such as Portland and Seattle that have also gotten too pricey, says Glenn Kelman, chief executive officer of Redfin Inc., a national real estate brokerage that recently opened a Boise outpost. About 29 percent of the Idaho capital's home-listing views are from Californians, according to Realtor.com... In Nevada, where Californians make up the largest share of arrivals, prices jumped 13 percent in August, the biggest increase for any state, according to CoreLogic Inc. data. It was followed closely by Idaho, with a 12 percent gain...

[Boise]'s been particularly attractive to Californians, who accounted for 85 percent of net domestic immigration to Idaho, according to Realtor.com's analysis of 2016 Census data... The median existing-home price in Boise's home of Ada County was $299,950 last month -- up almost 18 percent from a year earlier, but still about half California's. The influx is great news for people who already own homes in the area, says Danielle Hale, chief economist for Realtor.com. "But if you're a local aspiring to homeownership, it feels very much that Californians are bringing high prices with them."

Python

Twelve Malicious Python Libraries Found and Removed From PyPI (zdnet.com) 36

An anonymous reader writes: A software security engineer has identified 12 Python libraries uploaded on the official Python Package Index (PyPI) that contained malicious code. The 12 packages used typo-squatting in the hopes a user would install them by accident or carelessness when doing a "pip install" operation for a mistyped more popular package, like Django (ex: diango).

Eleven libraries would attempt to either collect data about each infected environment, obtain boot persistence, or even open a reverse shell on remote workstations. A twelfth package, named "colourama," was financially-motivated and hijacked an infected users' operating system clipboard, where it would scan every 500ms for a Bitcoin address-like string, which it would replace with the attacker's own Bitcoin address in an attempt to hijack Bitcoin payments/transfers made by an infected user.

54 users downloaded that package -- although all 12 malicious packages have since been taken down.

Four of the packages were misspellings of django -- diango, djago, dajngo, and djanga.
Security

Trivial Bug In X.Org Server Gives Root Permissions On Linux, BSD Systems (bleepingcomputer.com) 114

An anonymous reader quotes a report from Bleeping Computer: A vulnerability that is trivial to exploit allows privilege escalation to root level on Linux and BSD distributions using X.Org server, the open source implementation of the X Window System that offers the graphical environment. The flaw is now identified as CVE-2018-14665 (credited to security researcher Narendra Shinde). It has been present in xorg-server for two years, since version 1.19.0 and is exploitable by a limited user as long as the X server runs with elevated permissions.

An advisory on Thursday describes the problem as an "incorrect command-line parameter validation" that also allows an attacker to overwrite arbitrary files. Privilege escalation can be accomplished via the -modulepath argument by setting an insecure path to modules loaded by the X.org server. Arbitrary file overwrite is possible through the -logfile argument, because of improper verification when parsing the option. Apart from OpenBSD, other operating systems affected by the bug include Debian and Ubuntu, Fedora and its downstream distro Red Hat Enterprise Linux along with its community-supported counterpart CentOS.

China

Worried About Trump iPhone Eavesdroppers? China Recommends a Huawei (reuters.com) 109

China's foreign ministry has some suggestions for the Trump administration if it is worried about foreign eavesdropping on the U.S. president's iPhones: use a Huawei handset instead. Or just cut all forms of modern communication with the outside world. From a report: The riposte came after the New York Times reported that American intelligence reports indicated that Chinese and Russian spies often listen in on President Donald Trump when he uses his Apple cellphones to chat with old friends. Aides have repeatedly told him that his cellphone calls are not secure, but although the president has been persuaded to use his secure White House landline more often, he has refused to give up the phones, the Times said. Trump called the Times report incorrect on Thursday, and dismissed it as "long and boring." "I only use Government Phones, and have only one seldom used government cell phone. Story is soooo wrong!" Trump wrote on Twitter. In a later tweet, he said, "I rarely use a cellphone, & when I do it's government authorized. I like Hard Lines. Just more made up Fake News!"
Security

Cathay Pacific Data Breach Hits 9.4 Million People (zdnet.com) 20

An anonymous reader quotes a report from ZDNet: Hong Kong-based airline Cathay Pacific informed the Hong Kong stock exchange of a data breach late on Wednesday night that could affect 9.4 million people. In a notice, the airline said it would reach out to members of its Marco Polo Club, Asia Miles, and registered users. Otherwise, people who are worried about whether they have been hit should fill in an enquiry form. Cathay said that passenger details including name, nationality, date of birth, phone number, email address, passport number, identity card number, frequent flyer membership number, customer service remarks, and historical travel information could have been accessed. In its statement [PDF] to the exchange, Cathay said 860,000 passport numbers and approximately 245,000 Hong Kong identity card numbers were accessed. A small number of credit card numbers, 403 in total, were accessed, as well as 27 cards with no CVV. Don't worry, the airline is "offering ID monitoring services" and "free credit monitoring services" to those impacted...
Android

New Study Claims Data Harvesting Among Android Apps Is 'Out of Control' (techspot.com) 97

A new study from Oxford University revealed that almost 90 percent of free apps on the Google Play store share data with Alphabet. "The researchers, who analyzed 959,000 apps from the U.S. and UK Google Play stores, said data harvesting and sharing by mobile apps was now 'out of control,'" reports TechSpot. "'We find that most apps contain third party tracking, and the distribution of trackers is long-tailed with several highly dominant trackers accounting for a large portion of the coverage,' reads the report." From the report: It's revealed that most of the apps, 88.4 percent, could share data with companies owned by Google parent Alphabet. Next came a firm that's no stranger to data sharing controversies, Facebook (42.5 percent), followed by Twitter (33.8 percent), Verizon (26.27 percent), Microsoft (22.75 percent), and Amazon (17.91 percent). [I]nformation shared by these third-party apps can include age, gender, location, and information about a user's other installed apps. The data "enables construction of detailed profiles about individuals, which could include inferences about shopping habits, socio-economic class or likely political opinions."

Big firms then use the data for a variety of purposes, such as credit scoring and for targeting political messages, but its main use is often ad targeting. Not surprising, given that revenue from online advertising is now over $59 billion per year. According to the research, the average app transfers data to five tracker companies, which pass the data on to larger firms. The biggest culprits are news apps and those aimed at children, both of which tend to have the most third-party trackers associated with them.

Privacy

Thousands of Swedes Are Inserting Microchips Under Their Skin (npr.org) 193

An anonymous reader quotes a report from NPR: In Sweden, a country rich with technological advancement, thousands have had microchips inserted into their hands. The chips are designed to speed up users' daily routines and make their lives more convenient -- accessing their homes, offices and gyms is as easy as swiping their hands against digital readers. They also can be used to store emergency contact details, social media profiles or e-tickets for events and rail journeys within Sweden. Proponents of the tiny chips say they're safe and largely protected from hacking, but one scientist is raising privacy concerns around the kind of personal health data that might be stored on the devices.

Around the size of a grain of rice, the chips typically are inserted into the skin just above each user's thumb, using a syringe similar to that used for giving vaccinations. The procedure costs about $180. So many Swedes are lining up to get the microchips that the country's main chipping company says it can't keep up with the number of requests. More than 4,000 Swedes have adopted the technology, with one company, Biohax International, dominating the market. The chipping firm was started five years ago by Jowan Osterlund, a former professional body piercer. After spending the past two years working full time on the project, he is currently developing training materials so he can hire Swedish doctors and nurses to help take on some of his heavy workload.

Microsoft

New Windows Zero-Day Bug Helps Delete Any File, Exploit Available (bleepingcomputer.com) 74

An anonymous reader quotes a report from Bleeping Computer: Proof-of-concept code for a new zero-day vulnerability in Windows has been released by a security researcher before Microsoft was able to release a fix. The code exploits a vulnerability that allows deleting without permission any files on a machine, including system data, and it has the potential to lead to privilege escalation. The vulnerability could be used to delete application DLLs, thus forcing the programs to look for the missing libraries in other places. If the search reaches a location that grants write permission to the local user, the attacker could take advantage by providing a malicious DLL.

The problem is with Microsoft Data Sharing Service, present in Windows 10, Server 2016 and 2019 operating systems, which provides data brokering between applications. Will Dormann, a vulnerability analyst at CERT/CC, tested the exploit code successfully on a Windows 10 operating system running the latest security updates. Behind the discovery is a researcher using the online alias SandboxEscaper, also responsible for publicly sharing in late August another security bug in Windows Task Scheduler component.
Microsoft hasn't addressed the issue, but there is a temporary fix available through the oPatch platform. "A micropatch candidate was ready seven hours after the zero-day vulnerability announcement, and it blocked the exploit successfully," reports Bleeping Computer. "oPatch now delivers the stable version of the micropatch for fully updated Windows 10 1803.
Government

Apple Just Killed The 'GrayKey' iPhone Passcode Hack (forbes.com) 85

Apple's newest version of iOS has rendered the GrayKey hacking tech useless, a report said Wednesday. How Apple pulled it off wasn't immediately clear, but it would have a huge implication for the law enforcement agencies around the world that have relied on GrayKey to break into locked iPhones. Forbes reports: Apple has put up what may be an insurmountable wall. Multiple sources familiar with the GrayKey tech tell Forbes the device can no longer break the passcodes of any iPhone running iOS 12 or above. On those devices, GrayKey can only do what's called a "partial extraction," sources from the forensic community said. That means police using the tool can only draw out unencrypted files and some metadata, such as file sizes and folder structures.

Previously, GrayKey used "brute forcing" techniques to guess passcodes and had found a way to get around Apple's protections preventing such repeat guesses. But no more. And if it's impossible for GrayKey, which counts an ex-Apple security engineer among its founders, it's a safe assumption few can break iPhone passcodes. Police officer Captain John Sherwin of the Rochester Police Department in Minnesota said of the claim iOS 12 was preventing GrayKey from unlocking iPhones: "That's a fairly accurate assessment as to what we have experienced."

Android

Google Now Requires Partner OEMs To Offer Two Years of Security Updates To Popular Phones (theverge.com) 74

Confidential contracts obtained by news outlet The Verge show many Android smartphone vendors now have explicit obligations to keep their phones updated. From the report: A contract obtained by The Verge requires Android device makers to regularly install updates for any popular phone or tablet for at least two years. Google's contract with Android partners stipulates that they must provide "at least four security updates" within one year of the phone's launch. Security updates are mandated within the second year as well, though without a specified minimum number of releases.

David Kleidermacher, Google's head of Android security, referred to these terms earlier this year during a talk at Google I/O. Kleidermacher said that Google had added a provision into its agreements with partners to roll out "regular" security updates. But it wasn't clear which devices those would apply to, how often those updates would come, or for how long. The terms cover any device launched after January 31st, 2018 that's been activated by more than 100,000 users. Starting July 31st, the patching requirements were applied to 75 percent of a manufacturer's "security mandatory models." Starting on January 31st, 2019, Google will require that all security mandatory devices receive these updates.

Security

Russia Is Behind Cyberattack On Saudi Petrochemical Plant, Researchers Say (zdnet.com) 81

U.S. researchers from FireEye have linked a Russian research lab to a cyberattack on a Saudi petrochemical plant. The malware strain called Triton -- or Trisis -- "was designed to either shut down a production process or allow SIS-controlled machinery to work in an unsafe state," reports ZDNet, citing technical reports from FireEye, Dragos, and Symantec. From the report: The group behind the malware, which FireEye has been tracking under the codename of TEMP.Veles, nearly succeeded last year, when it almost caused an explosion at a Saudi petrochemical plant owned by Tasnee, a privately owned Saudi company, according to a New York Times report. The malware's origins were a mystery when FireEye first discovered Triton in 2017 and remained a mystery even after the New York Times report in March 2018.

But in a report published today, FireEye says that following further research into incidents where the Triton malware was deployed, it can now assess with "high confidence" that the Central Scientific Research Institute of Chemistry and Mechanics (CNIIHM), a government-owned technical research institution located in Moscow, was involved in these attacks. FireEye's report does not link the Triton malware itself to CNIIHM, but the secondary malware strains used by TEMP.Veles and deployed during the incidents where Triton was deployed. Clues in these secondary malware strains used to aid the deployment of the main Triton payloads contained enough artifacts that allowed researchers to identify their source.

Security

Yahoo To Pay $50 Million, Offer Credit Monitoring For Massive Security Breach (go.com) 36

Yahoo has agreed to pay $50 million in damages and provide two years of free credit-monitoring services to 200 million people whose email addresses and other personal information were stolen as part of the biggest security breach in history. "The restitution hinges on federal court approval of a settlement filed late Monday in a 2-year-old lawsuit seeking to hold Yahoo accountable for digital burglaries that occurred in 2013 and 2014, but weren't disclosed until 2016," reports ABC News. From the report: Claims for a portion of the $50 million fund can be submitted by any eligible Yahoo accountholder who suffered losses resulting from the security breach. The costs can include such things as identity theft, delayed tax refunds or other problems linked to having had personal information pilfered during the Yahoo break-ins. The fund will compensate Yahoo accountholders at a rate of $25 per hour for time spent dealing with issues triggered by the security breach, according to the preliminary settlement. Those with documented losses can ask for up to 15 hours of lost time, or $375. Those who can't document losses can file claims seeking up to five hours, or $125, for their time spent dealing with the breach. Yahoo accountholders who paid $20 to $50 annually for a premium email account will be eligible for a 25 percent refund.

The free credit monitoring service from AllClear could end up being the most valuable part of the settlement for most accountholders. The lawyers representing the accountholders pegged the retail value of AllClear's credit-monitoring service at $14.95 per month, or about $359 for two years -- but it's unlikely Yahoo will pay that rate. The settlement didn't disclose how much Yahoo had agreed to pay AllClear for covering affected accountholders.

Data Storage

An ISP Left Corporate Passwords, Keys, and All Its Data Exposed On the Internet (vice.com) 53

Security researchers at UpGuard discovered that a Washington-based ISP called Pocket iNet left 73 gigabytes of essential operational data publicly exposed in a misconfigured Amazon S3 storage bucket for months. "Said bucket, named 'pinapp2,' contained the 'keys to the kingdom,' according to the security firm, including internal network diagramming, network hardware configuration photos, details and inventory lists -- as well as lists of plain text passwords and AWS secret keys for Pocket iNet employees," reports Motherboard. From the report: Upguard says the firm contacted Pocket iNet on October 11 of this year, the same day the exposed bucket was discovered, but the ISP took an additional week before the data was adequately secured. "Seven days passed before Pocket iNet finally secured the exposure," noted the firm. "Due to the severity of this exposure, UpGuard expended significant effort during those seven days, repeatedly contacting Pocket iNet and relevant regulators, including using contact information found within the exposed dataset."

According to UpGuard, the list of plain text passwords was particularly problematic, given it provided root admin access to the ISP's firewalls, core routers and switches, servers, and wireless access points. "Documents containing long lists of administrative passwords may be convenient for operations, but they create single points of total risk, where the compromise of one document can have severe and extensive effects throughout the entire business," noted UpGuard. "If such documents must exist, they should be strongly encrypted and stored in a known secure location," said the firm. "Unfortunately, a single folder of PocketiNet's network operation historical data (non-customer) was publicly accessible to Amazon administrative users," the ISP said in a statement to Motherboard. "It has since been secured."

IBM

IBM Open Sources Mac@IBM Code (9to5mac.com) 91

PolygamousRanchKid shares a report from 9to5Mac: At the Jamf Nation User Conference, IBM has announced that it is open sourcing its Mac@IBM provisioning code. The code being open-sourced offers IT departments the ability to gather additional information about their employees during macOS setup and allows employees to customize their enrollment by selecting apps or bundles of apps to install.

Back in 2015, IBM discussed how it went from zero to 30,000 Macs in six months. In 2016, IBM said Apple products were cheaper to manage when you looked at the entire life cycle: "IBM is saving a minimum of $265 (up to $535 depending on model) per Mac compared to a PC, over a 4-year lifespan. While the upfront workstation investment is lower for PCs, the residual value for Mac is higher The program's success has improved IBM's ability to attract and retain top talent -- a key advantage in today's competitive market."

Apple

Multiple iCloud Services Experiencing Issues (macrumors.com) 31

Several iCloud services are experiencing problems this afternoon, users reported. While Apple PR has not issued a statement yet, the status page of Apple services reflect the issues, too. Citing people and the status page, news outlet MacRumors reports that Cloud Drive, iCloud Mail, iCloud Keychain, iCloud Contacts, iCloud Calendar, Mail Drop, Find My iPhone, and more services are performing "slower than normal" for some users.
Cloud

Amazon's Move Off Oracle Caused Prime Day Outage in One of its Biggest Warehouses, Internal Report Says (cnbc.com) 130

Amazon is learning how hard it can be to move off of Oracle's database software. From a report: On Prime Day, while the e-retailer was dealing with a major website glitch that slowed sales, the company was also dealing with a technical problem in Ohio at one of its biggest warehouses, leading to thousands of delayed package deliveries, according to an internal report obtained by CNBC. The problem was in large part due to Amazon's migration from Oracle's database to its own technology, the documents show. The outage underscores the challenge Amazon faces as it looks to move completely off Oracle's database by 2020, and how difficult it is to re-create that level of reliability. It also shows that Oracle's database is more efficient in some aspects than Amazon's rival software, a point that Oracle will likely emphasize during this week's annual OpenWorld conference in San Francisco.
Android

Google News App Bug Is Using Up Gigabytes of Background Data Without Users' Knowledge (theverge.com) 110

A bug in the Google News app for Android is reportedly causing the app to use up excessive amounts of background data, leading to overage charges. "According to dozens of posts on the Google News Help Forum, users have been experiencing this issue as early as June," reports The Verge. "The issue was verified and addressed by a Google News community manager in September, stating that the company was investigating and working toward a fix, but the issue is still ongoing." From the report: Verge reader Zach Dowdle emailed in with his experience, and screenshots of his app and Wi-Fi data usage: "The Google News app is randomly using a ridiculous amount of background data without users' knowledge. The app burned through over 12 gigs of data on my phone while I slept and my Wi-Fi had disconnected. It lead to $75 in overage charges."

According to several users, the app burned through mobile data despite having "Download via Wi-Fi" turned on in the settings. In some extreme cases, the Google News app used up to 24GB of data, leading to overage charges of up to $385, users reported. So far, the only solutions seem to be disabling background data, and deleting the app altogether.

China

AWS CEO Andy Jassy Follows Apple In Calling For Retraction of Chinese Spy Chip Story (cnbc.com) 111

An anonymous reader quotes a report from CNBC: Andy Jassy, the CEO of Amazon Web Services, followed Apple's lead in calling the for the retraction of Bloomberg's story about spy chips being embedded in servers. "They offered no proof, story kept changing, and showed no interest in our answers unless we could validate their theories," Jassy wrote in a tweet on Monday. "Reporters got played or took liberties. Bloomberg should retract."

Apple CEO Tim Cook told Buzzfeed on Friday that the scenario Bloomberg reported never happened and that the October story in Bloomberg Businessweek should be retracted. Bloomberg alleged data center hardware used by Apple and AWS, and provided by server company Super Micro, was under surveillance by the Chinese government, even though almost all the companies named in the report denied Bloomberg's claim. Bloomberg published a denial from AWS alongside its own report, and AWS refuted the report in a more strongly worded six-paragraph blog post entitled "Setting the Record Straight on Bloomberg Businessweek's Erroneous Article."
Further reading is available via The Washington Post.

"Sources tell the Erik Wemple Blog that the New York Times, the Wall Street Journal and The Post have each sunk resources into confirming the story, only to come up empty-handed," the Washington Post reports. "(The Post did run a story summarizing Bloomberg's findings, along with various denials and official skepticism.) It behooves such outlets to dispatch entire teams to search for corroboration: If, indeed, it's true that China has embarked on this sort of attack, there will be a long tail of implications. No self-respecting news organization will want to be left out of those stories. 'Unlike software, hardware leaves behind a good trail of evidence. If somebody decides to go down that path, it means that they don't care about the consequences,' Stathakopoulos says.'"
Privacy

Now Apps Can Track You Even After You Uninstall Them (bloomberg.com) 118

If it seems as though the app you deleted last week is suddenly popping up everywhere, it may not be mere coincidence. From a report: Companies that cater to app makers have found ways to game both iOS and Android, enabling them to figure out which users have uninstalled a given piece of software lately -- and making it easy to pelt the departed with ads aimed at winning them back. Adjust, AppsFlyer, MoEngage, Localytics, and CleverTap are among the companies that offer uninstall trackers, usually as part of a broader set of developer tools. Their customers include T-Mobile US, Spotify Technology, and Yelp. Critics say they're a fresh reason to reassess online privacy rights and limit what companies can do with user data. "Most tech companies are not giving people nuanced privacy choices, if they give them choices at all," says Jeremy Gillula, tech policy director at the Electronic Frontier Foundation, a privacy advocate.

Some providers say these tracking tools are meant to measure user reaction to app updates and other changes. Jude McColgan, chief executive officer of Boston's Localytics, says he hasn't seen clients use the technology to target former users with ads. Ehren Maedge, vice president for marketing and sales at MoEngage Inc. in San Francisco, says it's up to the app makers not to do so. "The dialogue is between our customers and their end users," he says. "If they violate users' trust, it's not going to go well for them." Adjust, AppsFlyer, and CleverTap didn't respond to requests for comment, nor did T-Mobile, Spotify, or Yelp.

Uninstall tracking exploits a core element of Apple's and Google's mobile operating systems: push notifications. Developers have always been able to use so-called silent push notifications to ping installed apps at regular intervals without alerting the user -- to refresh an inbox or social media feed while the app is running in the background, for example. But if the app doesn't ping the developer back, the app is logged as uninstalled, and the uninstall tracking tools add those changes to the file associated with the given mobile device's unique advertising ID, details that make it easy to identify just who's holding the phone and advertise the app to them wherever they go.

Bug

Microsoft's Problem Isn't How Often it Updates Windows -- It's How It Develops It (arstechnica.com) 227

Ever since Microsoft settled on a cadence of two feature updates a year -- one in April, one in October -- the quality of its operating system (taking into consideration the volume of bugs that emerge every few days) has deteriorated, writes Peter Bright of ArsTechnica. From the story: The problem with Windows as a Service is quality. Previous issues with the feature and security updates have already shaken confidence in Microsoft's updating policy for Windows 10. While data is notably lacking, there is at the very least a popular perception that the quality of the monthly security updates has taken a dive with Windows 10 and that installation of the twice-annual feature updates as soon as they're available is madness. These complaints are long-standing, too. The unreliable updates have been a cause for concern since shortly after Windows 10's release.

The latest problem has brought this to a head, with commentators saying that two feature updates a year is too many and Redmond should cut back to one, and that Microsoft needs to stop developing new features and just fix bugs. Some worry that the company is dangerously close to a serious loss of trust over updates, and for some Windows users, that trust may already have been broken. These are not the first calls for Microsoft to slow down with its feature updates -- there have been concerns that there's too much churn for both IT and consumer audiences alike to handle -- but with the obvious problems of the latest update, the calls take on a new urgency.

Slashdot Top Deals