New submitter mikehusky quotes a report from The Register: Washington D.C. think tank the Institute for Critical Infrastructure Technology is calling for regulation on "negligence" in the design of internet-of-things (IoT) devices. If the world wants a bonk-detecting Wi-Fi mattress, it must be a malware-free bonk-detecting Wi-Fi mattress. The report adds: "Researchers James Scott and Drew Spaniel point out in their report Rise of the Machines: The Dyn Attack Was Just a Practice Run [PDF] that IoT represents a threat that is only beginning to be understood. The pair say the risk that regulation could stifle market-making IoT innovation (like the Wi-Fi cheater-detection mattress) is outweighed by the need to stop feeding Shodan. 'Regulation on IoT devices by the United States will influence global trends and economies in the IoT space, because every stakeholder operates in the United States, works directly with United States manufacturers, or relies on the United States economy. Nonetheless, IoT regulation will have a limited impact on reducing IoT DDoS attacks as the United States government only has limited direct influence on IoT manufacturers and because the United States is not even in the top 10 countries from which malicious IoT traffic originates.' State level regulation would be 'disastrous' to markets and consumers alike. The pair offer their report in the wake of the massive Dyn and Mirai distributed denial of service attacks in which internet of poorly-designed devices were enslaved into botnets to hammer critical internet infrastructure, telcos including TalkTalk, routers and other targets."
Check out the new SourceForge HTML5 internet speed test! No Flash necessary and runs on all devices. ×
Tekla Perry writes: An autonomous shuttle from Auro Robotics is picking up and dropping off students, faculty, and visitors at the Santa Clara University Campus seven days a week. It doesn't go fast, but it has to watch out for pedestrians, skateboarders, bicyclists, and bold squirrels (engineers added a special squirrel lidar on the bumper). An Auro engineer rides along at this point to keep the university happy, but soon will be replaced by a big red emergency stop button (think Staples Easy button). If you want a test drive, just look for a "shuttle stop" sign (there's one in front of the parking garage) and climb on, it doesn't ask for university ID.
An anonymous reader quotes a report from Space.com: For several decades now, scientists from around the world have been pursuing a ridiculously ambitious goal: They hope to develop a nuclear fusion reactor that would generate energy in the same manner as the sun and other stars, but down here on Earth. Incorporated into terrestrial power plants, this "star in a jar" technology would essentially provide Earth with limitless clean energy, forever. And according to new reports out of Europe this week, we just took another big step toward making it happen. In a study published in the latest edition of the journal Nature Communications, researchers confirmed that Germany's Wendelstein 7-X (W7-X) fusion energy device is on track and working as planned. The space-age system, known as a stellerator, generated its first batch of hydrogen plasma when it was first fired up earlier this year. The new tests basically give scientists the green light to proceed to the next stage of the process. It works like this: Unlike a traditional fission reactor, which splits atoms of heavy elements to generate energy, a fusion reactor works by fusing the nuclei of lighter atoms into heavier atoms. The process releases massive amounts of energy and produces no radioactive waste. The "fuel" used in a fusion reactor is simple hydrogen, which can be extracted from water. The W7-X device confines the plasma within magnetic fields generated by superconducting coils cooled down to near absolute zero. The plasma -- at temperatures upwards of 80 million degrees Celsius -- never comes into contact with the walls of the containment chamber. Neat trick, that. David Gates, principal research physicist for the advanced projects division of PPPL, leads the agency's collaborative efforts in regard to the W7-X project. In an email exchange from his offices at Princeton, Gates said the latest tests verify that the W7-X magnetic "cage" is working as planned. "This lays the groundwork for the exciting high-performance plasma operations expected in the near future," Gates said.
An anonymous reader quotes a report from New York Post: Radiation from Japan's 2011 Fukushima nuclear disaster has apparently traveled across the Pacific. Researchers reported that radioactive matter -- in the form of an isotope known as cesium-134 -- was collected in seawater samples from Tillamook Bay and Gold Beach in Oregon. The levels were extremely low, however, and don't pose a threat to humans or the environment. In 2011, a 9.0-magnitude earthquake triggered a wave of tsunamis that caused colossal damage to Japan's Fukushima Daiichi nuclear power plant. The disaster released several radioactive isotopes -- including the dangerous fission products of cesium-137 and iodine-131 -- that contaminated the air and water. The ocean was later contaminated by the radiation. But cesium-134 is the fingerprint of Fukushima due to its short half-life of two years, meaning the level is cut in half every two years. Cesium-137 has a 30-year half-life. Particles from Chernobyl, nuclear weapons tests, and discharge from other nuclear power plants are still detectable -- in small, harmless amounts. While this is the first time cesium-134 has been detected on US shores, Higley said "really tiny quantities" have previously been found in albacore tuna. The Oregon samples were collected by the Woods Hole Oceanographic Institution in January and February. Each sample measured 0.3 becquerels, a unit of radioactivity, per cubic meter of cesium-134 -- significantly lower than the 50 million becquerels per cubic meter measured in Japan after the disaster.
Uber treats its drivers as Victorian-style "sweated labor", with some taking home less than the minimum wage, according to a report into its working conditions based on the testimony of dozens of drivers. From a report on The Guardian: Drivers at the taxi-hailing app company reported feeling forced to work extremely long hours, sometimes more than 70 a week, just to make a basic living, said Frank Field, the Labor MP and chair of the work and pensions committee. Field received testimony from 83 drivers who said they often took home significantly less than the "national living wage" after paying their running costs. The report says they described conditions that matched the Victorian definition of sweated labor: "when earnings were barely sufficient to sustain existence, hours of labor were such as to make lives of workers periods of ceaseless toil; and conditions were injurious to the health of workers and dangerous to the public."
An anonymous reader quotes a report from CyberScoop: Georgia's secretary of state has claimed the Department of Homeland Security tried to breach his office's firewall and has issued a letter to Homeland Security Secretary Jeh Johnson asking for an explanation. Brian Kemp issued a letter to Johnson on Thursday after the state's third-party cybersecurity provider detected an IP address from the agency's Southwest D.C. office trying to penetrate the state's firewall. According to the letter, the attempt was unsuccessful. The attempt took place on Nov. 15, a few days after the presidential election. The office of the Georgia Secretary of State is responsible for overseeing the state's elections. "At no time has my office agreed to or permitted DHS to conduct penetration testing or security scans of our network," Kemp wrote in the letter, which was also sent to the state's federal representatives and senators. "Moreover, your department has not contacted my office since this unsuccessful incident to alert us of any security event that would require testing or scanning of our network. This is especially odd and concerning since I serve on the Election Cyber Security Working Group that your office created." "The Department of Homeland Security has received Secretary Kemp's letter," a DHS spokesperson told CyberScoop. "We are looking into the matter. DHS takes the trust of our public and private sector partners seriously, and we will respond to Secretary Kemp directly." Georgia was one of two states that refused cyber-hygiene support and penetration testing from DHS in the leadup to the presidential election. The department had made a significant push for it after hackers spent months exposing the Democratic National Committee's internal communications and data.
Digital currency bitcoin hit its highest levels in almost three years on Friday, extending gains since India sparked a cash shortage by removing high-denomination bank notes from circulation a month ago. From a report on Reuters: Bitcoin was trading as high as $774 on the New York-based itBit exchange, up almost 1 percent on the day and the highest since February 2014, having climbed almost 9 percent in the past month. It has climbed around 80 percent so far this year, far exceeding its 35 percent rise in 2015.
Samsung confirmed on Friday that it will indeed release an update to Galaxy Note7 smartphones in the United States to "prevent US Galaxy Note7 devices from charging and will eliminate their ability to work as mobile devices." In a new wrinkle to this whole situation, Verizon said today it will not be releasing Samsung's software update to Galaxy Note7 users on Verizon network. In a blog post, Verizon said: "Verizon will not be taking part in this update because of the added risk this could pose to Galaxy Note 7 users that do not have another device to switch to. We will not push a software upgrade that will eliminate the ability for the Note 7 to work as a mobile device in the heart of the holiday travel season. We do not want to make it impossible to contact family, first responders or medical professionals in an emergency situation." To recall, the Galaxy Note7 remains banned on airlines by the FAA and has also been prohibited from being used on many other public transit services in the United States. Elsewhere in the world, similar bans have been imposed on the phone.
President Barack Obama has ordered a full review of hacking activities aimed at disrupting last month's presidential election, media outlets reported Friday citing a top White House official. The results are to be delivered to Obama before he leaves the office. From a report on Reuters: "The president has directed the intelligence community to conduct a full review of what happened during the 2016 election process ... and to capture lessons learned from that and to report to a range of stakeholders, to include the Congress," homeland security adviser Lisa Monaco said during an event hosted by the Christian Science Monitor.
Mars One says its project to start a human colony on the Red Planet will be delayed by five years. The Dutch company says it will send its first crews to Mars in 2031 instead of its previous target date of 2026. From a report on Time: The venture is delaying its missions so it can raise more money, according to CEO Bas Lansdorp. "Of course the whole Mars One team would have preferred to be able to stick to the original schedule, but this new timeline significantly improves our odds of successfully achieving this mission roadmap," he said in a statement. This is far from the first time Mars One has delayed its project. Despite Lansdorp's confidence, other scientists have expressed significant doubts about the mission's feasibility.
The White House said on Thursday that it raised concerns about China's new cyber security law during a meeting with a Chinese official after the latest round of talks between the two countries on cyber crime. From a report on Reuters: U.S. National Security Adviser Susan Rice met with Chinese State Councilor Guo Shengkun to discuss the importance "of fully adhering" to an anti-hacking accord signed last year between the China and the United States, National Security Council spokesman Ned Price said. The deal, brokered during Chinese President Xi Jinping's state visit to Washington in 2015, included a pledge that neither country would knowingly carry out hacking for commercial advantages. Rice told Guo that the United States was concerned "about the potential impacts" of a law that China adopted in November aimed at combating hacking and terrorism.
Those who are still clinging on to their Galaxy Note 7, even after Samsung recalled the devices due to faulty batteries in mid-September, may want to seriously reconsider returning them to the Korean company. The Verge has obtained an image of an alert that went out to at least one Note 7 owner on U.S. Cellular today stating that, "As of December 15th, Samsung will modify the software to prevent the Galaxy Note 7 from charging. The phone will no longer work." The Verge reports: It's not clear whether Note 7s will be disabled across the major U.S. carriers as well, but it seems likely that'll be the case. In the past, updates disabling Note 7 features have rolled out across Verizon, ATT, and other carriers within a matter of days. That's probably what'll happen here, as well. By preventing the phone from charging, Samsung takes the final step to making the phone entirely unusable. It's still offering Note 7 owners the ability to fully return the phone or exchange it for another Samsung device. As of November 4th, when Samsung last provided an update, 85 percent of Note 7s sold in the U.S. had been recovered. That still left around 285,000 phones unaccounted for. Completely disabling the phone seems to be Samsung's last-ditch effort to either recover the remaining devices or remove what risk they still pose to consumers.
Trailrunner7 quotes a report from On the Wire: Malware gangs, like sad wedding bands bands, love to play the hits. And one of the hits they keep running back over and over is the Zeus banking Trojan, which has been in use for many years in a number of different forms. Researchers have unearthed a new piece of malware called Floki Bot that is based on the venerable Zeus source code and is being used to infect point-of-sale systems, among other targets. Flashpoint conducted the analysis of Floki Bot with Cisco's Talos research team, and the two organizations said that the author behind the bot maintains a presence on a number of different underground forums, some of which are in Russian or other non-native languages for him. Kremez said that attackers sometimes will participate in foreign language forums as a way to expand their knowledge. Along with its PoS infection capability, Floki Bot also has a feature that allows it to use the Tor network to communicate. "During our analysis of Floki Bot, Talos identified modifications that had been made to the dropper mechanism present in the leaked Zeus source code in an attempt to make Floki Bot more difficult to detect. Talos also observed the introduction of new code that allows Floki Bot to make use of the Tor network. However, this functionality does not appear to be active for the time being," Cisco's Talos team said in its analysis.
Google today announced it will open up Home to third-party developers, allowing all developers to start bringing their applications and services to the Google Assistant. Developers can start building "conversation actions" for the Google Assistant, which "allows developers to create back-and-forth conversations with users through the Assistant," writes Frederic Lardinois via TechCrunch. "Users can simply start these conversations by using a phrase like 'OK Google, talk to Eliza.'" TechCrunch reports: While the Assistant also runs on the Pixel phones and inside the Allo chat app, Google says it plans to bring actions to these other "Assistant surfaces" in the future, but it's unclear when exactly this will happen. To help developers who want to build these new Conversation Actions get started, Google has teamed up with a number of partners, including API.AI, GupShup, DashBot and VoiceLabs, Assist, Notify.IO, Witlingo and Spoken Layer. Google has also allowed a small number of partners to enable their apps on Google Home already. These integrations will roll out as early as next week. Given that users will be able to invoke these new actions with a simple command (and without having to first enable a skill, like on Alexa), Google's platform looks to be a rather accessible and low-friction way for developers to get their voice-enabled services to users. Google will have the final say over which actions will be enabled on Google Home.
An anonymous reader quotes a report from Washington Post: For the first time in more than two decades, life expectancy for Americans declined last year (Warning: may be paywalled; alternate source) -- a troubling development linked to a panoply of worsening health problems in the United States. Rising fatalities from heart disease and stroke, diabetes, drug overdoses, accidents and other conditions caused the lower life expectancy revealed in a report released Thursday by the National Center for Health Statistics. In all, death rates rose for eight of the top 10 leading causes of death. The new report raises the possibility that major illnesses may be eroding prospects for an even wider group of Americans. Its findings show increases in "virtually every cause of death. It's all ages," said David Weir, director of the health and retirement study at the Institute for Social Research at the University of Michigan. Over the past five years, he noted, improvements in death rates were among the smallest of the past four decades. "There's this just across-the-board [phenomenon] of not doing very well in the United States." Overall, life expectancy fell by one-tenth of a year, from 78.9 in 2014 to 78.8 in 2015, according to the latest data. The last time U.S. life expectancy at birth declined was in 1993, when it dropped from 75.6 to 75.4, according to World Bank data. The overall death rate rose 1.2 percent in 2015, its first uptick since 1999. More than 2.7 million people died, about 45 percent of them from heart disease or cancer.
What may come as no surprise to Facebook users, the social media company announced in a blog post that the U.S. presidential election was the most "talked about" topic on Facebook in 2016. Phys.Org highlights the other most-discussed topics in its report: The bitterly contested election in which Donald Trump defeated Hillary Clinton was ranked as the leading issue, followed by Brazil's political developments which included the impeachment of president Dilma Rousseff, Facebook said in a blog post. On the lighter side at number three was the runaway success of Pokemon Go, the location-based augmented reality game for smartphone users. Other subject matters shared among Facebook's 1.79 billion users were more sober, with the fourth leading topic the "Black Lives Matter" movement, followed by the election in the Philippines of Rodrigo Duterte. Number six on the list was the Olympic games, followed by Brexit, the Super Bowl and the deaths of rock star David Bowie and boxing icon Muhammad Ali. Facebook said it measured leading topics by how frequently an issue was mentioned in posts made between January 1 and November 27.
An anonymous reader quotes a report from The Verge: Yik Yak has laid off 60 percent of employees amid a downturn in the app's growth prospects, The Verge has learned. The three-year-old anonymous social network has raised $73.5 million from top-tier investors on the promise that its young, college-age network of users could one day build a company to rival Facebook. But the challenge of growing its community while moving gradually away from anonymity has so far proven to be more than the company could muster. Employees who were affected were informed of the layoffs Thursday morning, sources told The Verge. Yik Yak employed about 50 people, and now only about 20 remain, the company said. The community, marketing, design, and product teams were all deeply affected, one source said. Atlanta-based Yik Yak was founded in 2014 by Furman University students Tyler Droll and Brooks Buffington. The app updated the concept of dorm newsletters for the mobile era, letting anyone post comments about school, their campus, or life in general. The fact that comments were anonymous initially helped the app grow, as it encouraged more candid forms of sharing than students might otherwise post on Facebook or Instagram.
An anonymous reader quotes a report from Network World: Some 2.7 million ATT customers will share $88 million in compensation for having had unauthorized third-party charges added to their mobile bills, the Federal Trade Commission announced this morning. The latest shot in the federal government's years-long battle against such abuses, these refunds will represent the most money ever recouped by victims of what is known as "mobile cramming," according to the FTC. From an FTC press release: "Through the FTC's refund program, nearly 2.5 million current ATT customers will receive a credit on their bill within the next 75 days, and more than 300,000 former customers will receive a check. The average refund amount is $31. [...] According to the FTC's complaint, ATT placed unauthorized third-party charges on its customers' phone bills, usually in amounts of $9.99 per month, for ringtones and text message subscriptions containing love tips, horoscopes, and 'fun facts.' The FTC alleged that ATT kept at least 35 percent of the charges it imposed on its customers." The matter with ATT was originally made public in 2014 and also involved two companies that actually applied the unauthorized charges, Tatto and Acquinity.
Congress passed a bill yesterday that will make it illegal for people to use software bots to buy concert tickets. Ars Technica reports: The Better Online Ticket Sales (BOTS) Act makes it illegal to bypass any computer security system designed to limit ticket sales to concerts, Broadway musicals, and other public events with a capacity of more than 200 persons. Violations will be treated as "unfair or deceptive acts" and can be prosecuted by the Federal Trade Commission or the states. The bill passed the Senate by unanimous consent last week, and the House of Representatives voted yesterday to pass it as well. It now proceeds to President Barack Obama for his signature. Computer programs that automatically buy tickets have been a frustration for the concert industry and fans for a few years now. The issue had wide exposure after a 2013 New York Times story on the issue. Earlier this year, the office of New York Attorney General Eric Schneiderman completed an investigation into bots. The New York AG's ticket sales report (PDF) found that the tens of thousands of tickets snatched up by bots were marked up by an average of 49 percent.
BenBoy writes: John Herschel Glenn Jr. (July 18, 1921 -- December 8, 2016) was an American aviator, engineer, astronaut, and United States Senator from Ohio. He was one of the "Mercury Seven" group of military test pilots selected in 1959 by NASA to become America's first astronauts and fly the Project Mercury spacecraft. He passed away today at age 95.