Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror
×
Security

Anthem Blocking Federal Auditor From Doing Vulnerability Scans 116

chicksdaddy writes Anthem Inc., the Indiana-based health insurer, has informed a federal auditor, the Office of Personnel Management, that it will not permit vulnerability scans of its network — even after acknowledging that it was the victim of a massive breach that leaked data on tens of millions of patients. According to this article, Anthem is citing "company policy" that prohibits third party access to its network in declining to let auditors from OPM's Office of the Inspector General (OIG) conduct scans for vulnerable systems. OPM's OIG performs a variety of audits on health insurers that provide health plans to federal employees under the Federal Employee Health Benefits Program, or FEHBP. Insurers aren't mandated to comply — though most do. This isn't Anthem's first time saying "no thanks" to the offer of a network vulnerability scan. The company also declined to let OIG scan its network in 2013. A partial audit report issued at the time warned that the company, then known as WellPoint, "provided us with conflicting statements" on issues related to information security, including Wellpoint's practices regarding regular configuration audits and its plans to shift to IBM's Tivoli Endpoint Manager (TEM) platform.
United States

US Marshals Service Refuses To Release Already-Published Stingray Info 90

v3rgEz (125380) writes The U.S. Marshals Service is known to be one of the most avid users of StingRays, and documents confirm that the agency has spent more than $9 million on equipment and training since 2009. But while it appears the USMS is not under any nondisclosure agreement with the device manufacturer, the agency has withheld a wide range of basic information under an exemption meant to protect law enforcement techniques — despite the fact that that same information is available via a federal accounting website.
The Courts

Software Freedom Conservancy Funds GPL Suit Against VMWare 188

Jeremy Allison - Sam writes with this excerpt from a news release from the Software Freedom Conservancy: Software Freedom Conservancy announces today Christoph Hellwig's lawsuit against VMware in the district court of Hamburg in Hamburg, Germany. This is the regretful but necessary next step in both Hellwig and Conservancy's ongoing effort to convince VMware to comply properly with the terms of the GPLv2, the license of Linux and many other Open Source and Free Software included in VMware's ESXi products. Serge Wroclawski points out the SFC's technical FAQ about the suit. One nugget: This case is specifically regarding a combined work that VMware allegedly created by combining their own code (“vmkernel”) with portions of Linux's code, which was licensed only under GPLv2. As such, this, to our knowledge, marks the first time an enforcement case is exclusively focused on this type of legal question relating to GPL
Canada

Quebecker Faces Jail For Not Giving Up Phone Password To Canadian Officials 340

wired_parrot writes Canadian customs officials have charged a 38-year old man with obstruction of justice after he refused to give up his Blackberry phone password [on arrival in Canada by plane from the Dominican Republic]. As this is a question that has not yet been litigated in Canadian courts, it may establish a legal precedent for future cases. From the article: [Law professor Rob] Currie says the issue of whether a traveller must reveal a password to an electronic device at the border hasn't been tested by a court. "This is a question that has not been litigated in Canada, whether they can actually demand you to hand over your password to allow them to unlock the device," he said. "One thing for them to inspect it, another thing for them to compel you to help them."
Government

New Zealand Spied On Nearly Two Dozen Pacific Countries 129

An anonymous reader writes New documents from Edward Snowden indicate New Zealand undertook "full take" interception of communications from Pacific nations and forwarded the data to the NSA. The data, collected by New Zealand's Government Communications Security Bureau, was then fed into the NSA's XKeyscore search engine to allow analysts to trawl for intelligence. The New Zealand link helped flesh out the NSA's ambitions to intercept communications globally.
Cellphones

Microsoft Convinced That Windows 10 Will Be Its Smartphone Breakthrough 445

jfruh (300774) writes At the Mobile World Congress in Barcelona, handset manufacturers are making all the right noises about support for Windows 10, which will run on both ARM- and Intel-based phones and provide an experience very much like the desktop. But much of the same buzz surrounded Windows 8 and Windows 7 Phone. In fact, Microsoft has tried and repeatedly failed to take the mobile space by storm.
Businesses

Demand For Linux Skills Rising This Year 94

Nerval's Lobster writes This year is shaping up as a really good one for Linux, at least on the jobs front. According to a new report (PDF) from The Linux Foundation and Dice, nearly all surveyed hiring managers want to recruit Linux professionals within the next six months, with 44 percent of them indicating they're more likely to hire a candidate with Linux certification over one who does not. Forty-two percent of hiring managers say that experience in OpenStack and CloudStack will have a major impact on their hiring decisions, while 23 percent report security is a sought-after area of expertise and 19 percent are looking for Linux-skilled people with Software-Defined Networking skills. Ninety-seven percent of hiring managers report they will bring on Linux talent relative to other skills areas in the next six months.

Submission + - Microsoft Convinced That Windows 10 Will Be Its Smartphone Breakthrough (itworld.com) 1

jfruh writes: At the Mobile World Congress in Barcelona, handset manufacturers are making all the right noises about support for Windows 10, which will run on both ARM- and Intel-based phones and provide an experience very much like the desktop. But much of the same buzz surrounded Windows 8 and Windows 7 Phone. In fact, Microsoft has tried and repeatedly failed to take the mobile space by storm.

Submission + - New Zealand spied on nearly two dozen Pacific countries (zdnet.com)

An anonymous reader writes: New documents from Edward Snowden indicate New Zealand undertook "full take" interception of communications from Pacific nations and forwarded the data to the NSA.

The data, collected by New Zealand's Government Communications Security Bureau, was then fed into the NSA's XKeyscore search engine to allow analysts to trawl for intelligence.

The New Zealand link helped flesh out the NSA's ambitions to intercept communications globally.

Submission + - 'The Moon Is a Harsh Mistress' Coming to the Big Screen 2

HughPickens.com writes: Hollywood Reporter reports that Twentieth Century Fox recently picked up the movie rights to "The Moon is a Harsh Mistress," based on the classic sci-fi book by Robert A. Heinlein and will retitled the movie as 'Uprising'. Heinlein's 1966 sci-fi novel centers on a lunar colony's revolt against rule from Earth and the book popularized the acronym TANSTAAFL (There ain't no such thing as a free lunch), a central, libertarian theme. The novel was nominated for the 1966 Nebula award (honoring the best sci-fi and fantasy work in the U.S.) and won the Hugo Award for best science fiction novel in 1967. An adaptation has been attempted twice before — by DreamWorks, which had a script by Ted Elliott and Terry Rossio, and by Phoenix Pictures, with Harry Potter producer David Heyman attached — but both languished and the rights reverted to Heinlein's estate. Brian Singer, who previously directed X-Men: Days of Future Past, will adopt the screenplay and reportedly direct. Several of Heinlein's novels have been adapted for the big and small screen, including the 1953 film Project Moonbase, the 1994 TV miniseries Red Planet, the 1994 film The Puppet Masters, and — very loosely — the 1997 film Starship Troopers.

Submission + - Racial Discrimination Affects Virtual Reality Characters too (elsevier.com)

vrml writes: You are looking for the exit of a building in a virtual reality experience when a virtual character gets stuck in a room and cries for your help. Could the color of the skin (black or white) of the virtual human influence your decision to provide or refuse help? That's what comes out from a new study published by the Computers in Human Behavior journal. White users were told that they had to reach the exit of the virtual building as soon as possible. The number of users who decided to help tripled when the virtual victim was white rather than black. Researchers tried also other conditions in which they did not put users under time pressure: this reduced the discrimination, although the number of users who helped remained more favorable for the white rather than the black virtual human. The paper explains these results in terms of the automatic categorization processes that originate from unwanted, unconscious social and cultural biases: putting people under pressure increases automatic responses, leading to more discrimination towards the black character.
Mars

Mars Curiosity Rover Experiences Short Circuit, Will Be Stationary For Days 33

hypnosec writes: NASA says its Mars Curiosity rover has experienced a transient short circuit. The team has halted all work from the rover temporarily while engineers analyze the situation. Telemetry data received from Curiosity indicated the short circuit, after which the vehicle followed its programmed response, stopping the arm activity underway whenthe irregularity in the electric current happened. Curiosity will stay parked as its engineers analyze the situation and figure out if any damage has been done. NASA says a transient short circuit would have little effect on the rover's operations in some systems, but it could force the team to restrict use of whatever mechanism caused the problem.
Music

Video A Versatile and Rugged MIDI Mini-Keyboard (Video) 56

The K-Board won a "Best in Show" award at CES 2015. Plus, as Timothy said, "I always like pour and stomp demos." And it's totally cross-platform. If your computer, tablet or smartphone has a USB port and (almost) any kind of music software, it works. In theory, you could hook a K-Board to your Android or iOS device and use it to accompany yourself while you sing for spare change on a downtown corner. Or noodle around to get a handle on a theme you'll use in your next major symphony. Or...?

Submission + - FREAK Attack Threatens SSL Clients (threatpost.com)

msm1267 writes: For the nth time in the last couple of years, security experts are warning about a new Internet-scale vulnerability, this time in some popular SSL clients. The flaw allows an attacker to force clients to downgrade to weakened ciphers and break their supposedly encrypted communications through a man-in-the-middle attack.

Researchers recently discovered that some SSL clients, including OpenSSL, will accept weak RSA keys–known as export-grade keys–without asking for those keys. Export-grade refers to 512-bit RSA keys, the key strength that was approved by the United States government for export overseas. This was an artifact from decades ago and it was thought that most servers and clients had long ago abandoned such weak ciphers.

The vulnerability affects a variety of clients, most notably Apple’s Safari browser. The bug was discovered by a large group of researchers from Microsoft Research and the French National Institute for Research in Computer Science and Control, and they found that given a server that supports export-grade ciphers and a client that accepts those weak keys, an attacker with a man-in-the-middle position could force a client to downgrade to the weak keys. He could then take the key and factor it, which researchers were able to do in about seven and a half hours, using Amazon EC2. And because it’s resource-intensive to generate RSA keys, servers will generate one and re-use it indefinitely.

Slashdot Top Deals

If you want to put yourself on the map, publish your own map.

Working...