United States

House Panel To Hold Public Hearing on Unexplained Aerial Sightings (nytimes.com) 65

A House subcommittee is scheduled to hold next week the first open congressional hearing on unidentified aerial vehicles in more than half a century, with testimony from two top defense intelligence officials. From a report: The hearing comes after the release last June of a report requested by Congress on "unidentified aerial phenomena." The nine-page "Preliminary Assessment" from the Office of the Director of National Intelligence focused on 144 incidents dating back to 2004 and was able to explain only one. The report declined to draw inferences, saying that the available reporting was "largely inconclusive" and noting that limited and inconsistent data created a challenge in evaluating the phenomena. But it said most of the phenomena reported "do represent physical objects." The assessment concluded that the objects were not secret U.S. technology and that "we currently lack data to indicate any UAP are part of a foreign collection program or indicative of a major technological advancement by a potential adversary."
Piracy

US Copyright Office Seeks Input On Mandatory DMCA 'Upload Filters' (torrentfreak.com) 83

An anonymous reader quotes a report from TorrentFreak: The U.S. Copyright Office has launched a public consultation to evaluate whether it's wise to make certain technical protection measures mandatory under the DMCA. The Office hopes to hear all relevant stakeholders and the public at large in what may become a de facto review of the recently introduced SMART Copyright Act. [...] Following repeated nudges from Senators Thom Tillis and Patrick Leahy, the Copyright Office started looking into automated tools that online services can use to ensure that pirated content can't be easily reuploaded. This "takedown and staydown' approach relies on technical protection tools, which include upload filters. This is a sensitive subject that previously generated quite a bit of pushback when the EU drafted its Copyright Directive. To gauge the various options and viewpoints, the Copyright Office launched a consultation last year, which triggered a wave of objections and opposition.

Last week, the Office followed up with yet another consultation, asking for input on shortcomings in the current DMCA legislation and what alternatives could help to improve things. As things stand, online services are allowed to implement their own upload filters, which many do. Scanning uploads for potentially copyright-infringing content isn't mandatory but that could change in the future. The consultation outline mentions several potential changes to the DMCA's Section 512, such as online services losing their safe harbor protection if they fail to implement specific "standard technical measures" (STMs). "Is the loss of the section 512 safe harbors an appropriate remedy for interfering with or failing to accommodate STMs?" the Copyright Office asks. "Are there other obligations concerning STMs that ought to be required of internet service providers?" the list of questions continues.

Stakeholders are asked to share their views on these matters. While it is uncertain whether any measures will be made mandatory, the Copyright Office is already looking ahead. For example, who gets to decide what STMs will be mandatory, and how would the rulemaking process work? "What entity or entities would be best positioned to administer such a rulemaking? What should be the frequency of such a rulemaking? What would be the benefits of such a rulemaking? What would be the drawbacks of such a rulemaking?"

Google

Google Play Users In Russia Can No Longer Update Or Download Paid Apps (9to5google.com) 74

Back in March, Google halted Android app and subscription purchases in Russia due to sanctions. Google Play is now "blocking the downloading of paid apps and updates to paid apps in Russia starting May 5, 2022.â 9to5Google reports: The company cites "compliance efforts" as being responsible for this latest policy. There are no changes to free applications as Google says in the Q&A of its support article on the matter: "Can I publish new apps or update existing apps during this pause? You can still publish new free apps, and update existing free apps. Updates to paid apps are blocked for compliance reasons."

Google has recommended developers defer payment renewals (which is possible for up to one year). Another given possibility for developers was making apps free or removing the paid subscription "during this pause." That was advised for applications that provide a "critical service to users that keeps them safe and provides access to information."

Microsoft

Microsoft Recommends People Uninstall Optional Windows 11 Update KB5012643 (extremetech.com) 75

DrunkenTerror shares a report from ExtremeTech: Microsoft is advising Windows 11 users to uninstall a recent update. Reports indicated the optional update KB5012643 is causing various apps to crash. The problem involves an interaction between the update and the .Net Framework that's part of Windows. At this time it's unclear which apps are affected by the issue, leaving uninstallation as the "only" viable solution.

"Affected apps are using certain optional components in .NET Framework 3.5, such as Windows Communication Foundation (WCF) and Windows Workflow (WWF) components." This update also broke Safe Mode. Microsoft says when users booted into 'Safe Mode without networking' users might see the screen flicker. Per MS, "Components that rely on explorer.exe, such as File Explorer, the Start menu, and the taskbar, can be affected and appear unstable." Microsoft issued a Known Issue Rollback (KiR) for this already so it should be fixed. If you encounter it, you should be able to resolve it by enabling network support in Safe Mode.

Piracy

Pirate Site Blocking Is Making Its Way Into Free Trade Agreements (torrentfreak.com) 39

The new free trade agreement between Australia and the UK includes a site blocking paragraph. The text requires the countries to provide injunctive relief to require ISPs to prevent subscribers from accessing pirate sites. While this doesn't change much for the two countries, rightsholders are already eying similar requirements for trade deals with other nations. TorrentFreak reports: The inclusion of a blocking paragraph in the copyright chapter of the trade deal was high on the agenda of various copyright holder groups. Following a series of hearings and consultations, both countries settled on the following text:

1. Each Party shall provide that its civil judicial authorities have the authority to grant an injunction against an ISP within its territory, ordering the ISP to take action to block access to a specific online location, in cases where:
(a) that online location is located outside the territory of that Party; and
(b) the services of the ISP are used by a third party to infringe copyright or related rights in the territory of that Party.

2. For greater certainty, nothing in this Article precludes a Party from providing that its judicial authorities may grant an injunction to take action to block access to online locations used to infringe intellectual property rights in circumstances other than those specified in paragraph 1.


This hasn't gone unnoticed by the Alliance for Intellectual Property, which represents rightsholder organizations such as the MPA, BPI, and the Premier League. The group repeatedly urged the UK Government to include site-blocking powers in the agreement. In a recent submission to the UK Government, the Alliance once again stresses the importance of site blocking, while also hinting at broadening the current anti-piracy toolbox. "It has become a hugely valuable tool in the armory of rights holders looking to protect their IP. It is vital that the UK Government ensures the preservation of the no-fault injunctive relief regime," the Alliance writes. "We would also encourage the opening of dialogue, wherever possible, to share experience around UK practices and to encourage faster, more efficient website blocking procedures, whether through civil, criminal, administrative or voluntary means."

The site-blocking language is already included in the latest trade deal draft but the Alliance is also looking ahead at future agreements with other countries. In this context, the blocking paragraph will send a clear message. "We would therefore urge the UK Government to include reference to the site blocking legislation in the FTA with Australia as it will send an important message to future countries that we might chose [sic] to negotiate trade agreements with." The Alliance for Intellectual Property doesn't mention any other countries by name. However, it specifically references a report from the U.S. Copyright Office where site blocking was mentioned as a potential future anti-piracy option. In the same report, the Copyright Office also stressed that further research would be required on the effect and impact of a U.S. site-blocking scheme, but the idea wasn't dismissed outright.

Facebook

Facebook To Discontinue 'Nearby Friends' and Other Location-Based Features (9to5mac.com) 11

Facebook on Thursday began informing users that Nearby Friends and other location-based features will soon be discontinued at the end of the month. While the reasons are currently unclear, the company claims that all information related to these features will be deleted from Facebook's servers. 9to5Mac reports: Users have been getting a notification in the Facebook app for iOS and Android about the end of Nearby Friends, a feature that lets people share their current location with other Facebook friends. At the same time, Facebook also says that Time Alerts, Location History, and Background Location are also "going away soon." According to the company, Nearby Friends and other location-based features will no longer be available to users after May 31, 2022.

Some of the data, such as the user's location history (which automatically uses your location to create a map of places you have visited, will be available for download by August 1, 2022. After that, Facebook says that this data will be deleted. Unfortunately, this doesn't mean that Facebook's app will stop collecting users' location. The company states that location data will still be collected "for other experiences." Of course, you can always disable the Facebook app's access to your location by going into the iOS Privacy settings.

Security

Hackers Are Now Hiding Malware In Windows Event Logs (bleepingcomputer.com) 49

Security researchers have noticed a malicious campaign that used Windows event logs to store malware, a technique that has not been previously documented publicly for attacks in the wild. BleepingComputer reports: The method enabled the threat actor behind the attack to plant fileless malware in the file system in an attack filled with techniques and modules designed to keep the activity as stealthy as possible. [...] The dropper copies the legitimate OS error handling file [...] and then drops an encrypted binary resource to the 'wer.dll' (Windows Error Reporting) in the same location, for DLL search order hijacking to load malicious code. DLL hijacking is a hacking technique that exploits legitimate programs with insufficient checks to load into memory a malicious Dynamic Link Library (DLL) from an arbitrary path.

[Denis Legezo, lead security researcher at Kaspersky] says that the dropper's purpose is to loader on the disk for the side-loading process and to look for particular records in the event logs (category 0x4142 - 'AB' in ASCII. If no such record is found, it writes 8KB chunks of encrypted shellcode, which are later combined to form the code for the next stager. "The dropped wer.dll is a loader and wouldn't do any harm without the shellcode hidden in Windows event logs," says Legezo. The new technique analyzed by Kaspersky is likely on its way to becoming more popular as Soumyadeep Basu, currently an intern for Mandiant's red team, has created and published on GitHub source code for injecting payloads into Windows event logs.

The Courts

Match Sues Google Over App Store Billing Rules (bloomberg.com) 31

Match Group accused Alphabet's Google in a lawsuit of acting as a monopolist with its app store billing rules, the latest escalation in a brawl over the mobile-app industry. From a report: Match Group, which operates dating apps such as Tinder and OkCupid, alleged that Google breaks federal and state laws and abuses its power with a requirement that app developers use its billing system on Android devices. "Ten years ago, Match Group was Google's partner. We are now its hostage," Match Group said in a complaint filed Monday in northern California federal court.

"Blinded by the possibility of getting an ever-greater cut of the billions of dollars users spend each year on Android apps, Google set out to monopolize the market for how users pay for their Android apps." Google, like Apple, has faced enormous recent legal and political scrutiny over the commission fees and billing restrictions both companies apply to paid services in their app stores. Congress is currently weighing a bill to force Google and Apple to change their business models.

The Internet

Low-Wage Earners To Get High-Speed Internet For $30 in Biden Program (washingtonpost.com) 226

echo123 writes: Twenty Internet providers, including AT&T, Comcast and Verizon, have agreed to provide high-speed service at a steep discount to low-income consumers, the White House announced Monday, significantly expanding broadband access for millions of Americans. The plan, a feature of the $1 trillion infrastructure package passed by Congress last year, would cost qualifying households no more than $30 per month. The discounts plus existing federal Internet subsidies mean the government will cover the full cost of connectivity if consumers sign on with one of the 20 participating companies. The White House estimates the program will cover 48 million households, or 40 percent of the country.

The 100-megabit-per-second service is fast enough for a family to work from home, complete schoolwork, browse the Internet and stream high-definition movies and TV shows, the White House said. Households can qualify for the subsidies, called the Affordable Connectivity Program, if their income is at or below 200 percent of federal poverty guidelines, a member of the household participates in certain federal anti-poverty initiatives -- including Medicaid, Supplemental Nutrition Assistance Program, federal housing assistance, Pell Grant tuition assistance, or free or reduced-price school meals -- or if the household already qualifies for an Internet provider's low-income service program. Consumers can check whether they qualify for discounted service at getinternet.gov.

Education

Illinois College, Hit By Ransomware Attack, To Shut Down (nbcnews.com) 58

Lincoln College is scheduled to close its doors Friday, becoming the first U.S. institution of higher learning to shut down in part due to a ransomware attack. From a report: A goodbye note posted to the school's website said that it survived both World Wars, the Spanish flu and the Great Depression, but was unable to handle the combination of the Covid pandemic and a severe ransomware attack in December that took months to remedy. "Lincoln College was a victim of a cyberattack in December 2021 that thwarted admissions activities and hindered access to all institutional data, creating an unclear picture of Fall 2022 enrollment projections," the school wrote in its announcement. "All systems required for recruitment, retention, and fundraising efforts were inoperable. Fortunately, no personal identifying information was exposed. Once fully restored in March 2022, the projections displayed significant enrollment shortfalls, requiring a transformational donation or partnership to sustain Lincoln College beyond the current semester." The Illinois school, which is named after President Abraham Lincoln and broke ground on his birthday in 1865, is one of only a handful of rural American colleges that qualify as predominantly Black institutions by the Department of Education.
Businesses

Uber CEO Tells Staff Company Will Cut Down on Costs, Treat Hiring as a 'Privilege' (cnbc.com) 64

Uber will cut back on spending and focus on becoming a leaner business to address a "seismic shift" in investor sentiment, CEO Dara Khosrowshahi told employees in an email obtained by CNBC. From the report: "After earnings, I spent several days meeting investors in New York and Boston," Khosrowshahi said in the email, which was sent out late Sunday. "It's clear that the market is experiencing a seismic shift and we need to react accordingly." [...] To address the shift in economic sentiment, the ride-hailing firm will slash spending on marketing and incentives and treat hiring as a "privilege," Khosrowshahi said. "We have to make sure our unit economics work before we go big," the Uber boss wrote. "The least efficient marketing and incentive spend will be pulled back... We will treat hiring as a privilege and be deliberate about when and where we add headcount," he added. "We will be even more hardcore about costs across the board."
Businesses

The Tech Industry's Epic Two-Year Run Sputters (wsj.com) 24

Investors are divided about whether technology companies are set for a deep retrenchment or if growth is simply slowing from pandemic highs. From a report: The technology industry, which powered the U.S. economy during the pandemic and grew at tremendous scale during a decade of ultralow interest rates, is confronting one of the most punishing stretches in years. Global powerhouses and fledgling startups are feeling pain from a variety of economic, industry and market factors, spawning postpandemic turbulence in e-commerce, digital advertising, electric vehicles, ride-hailing and other segments. Companies that emerged as job-creating juggernauts in the past two years -- collectively adding hundreds of thousands of workers to their payrolls in engineering, warehouse and delivery jobs -- have begun to freeze hiring or even lay off employees.

Concerned that some of the forces that have propelled tech ever upward have begun to fade, investors have sent share prices for a number of companies, including Lyft and Peloton plunging on disappointing financial results or other news. The stocks of Netflix, Facebook parent Meta Platforms and Amazon.com all are down more than 30% this year, exceeding the more-than-13% drop in the S&P 500. Investors are divided on the question of whether the slowdown is temporary -- as well-positioned companies work through a period of stagnation after expanding ultrafast in recent years -- or if these are the early signs of a deeper retrenchment for the industry and its investors.

Social Networks

Instagram To Start Testing NFTs With Select Creators this Week (techcrunch.com) 12

Instagram head Adam Mosseri announced today that the platform is going to start testing NFTs with select creators in the United States this week. From a report: Mosseri noted that there will be no fees associated with posting or sharing a digital collectible on Instagram. At launch, the supported blockchains for showcasing NFTs on Instagram are Ethereum and Polygon, with support for Flow and Solana coming soon. The third-party wallets compatible for use will include Rainbow, Trust Wallet and MetaMask. Creators and people who are part of the test can now share NFTs that they've made or that they've bought. You can share these NFTs in your main Feed, Stories, or in messages. Mosseri outlined that only a limited number of people have access to the test, but the company plans to roll out more functionality related to NFTs in the future once it gets feedback from its initial testing.
China

Pentagon's China Warning Prompts Calls To Vet US Funding of Startups (wsj.com) 20

Congress may soon require government agencies to vet tech startups seeking federal funding, after a Defense Department study found China is exploiting a popular program that funds innovation among small American companies. From a report: The study, which was viewed by The Wall Street Journal, found China is using state-sponsored methods to target companies that have received Pentagon funding from the Small Business Innovation Research program. The SBIR program for decades has sought to promote innovation through a competitive U.S. government award process.

The April 2021 report, which has been circulating among lawmakers on Capitol Hill, details eight case studies it says have "national and economic security implications." The studies include examples of program participants who dissolve their American companies, join Chinese government talent programs and continue their work at institutions that support the People's Liberation Army, the armed wing of the Communist Party. The report also documents instances of SBIR recipients taking venture-capital money from Chinese state-owned firms and of working with Chinese entities that support the country's defense industry. The report concludes that the SBIR program needs a due-diligence process to identify entities of potential concern that would then receive a more detailed review.

Businesses

NSO Group Keeping Owners 'in the Dark', Manager Says (ft.com) 24

Israeli spyware company NSO Group has stonewalled questions over whether it is operating legally, according to consultants acting on behalf of the controversial company's owners. From a report: Berkeley Research Group, the US consultancy that was last year put in charge of the private equity fund that owns 70 per cent of NSO, has told EU lawmakers that its inquiries about NSO's "lawfulness" have been "ignored and/or frustrated by NSO Group's management team." Concerns remain about âoethe historical management of the NSO Group" and "possible ongoing activities in relation to which [BRG is] being kept in the dark," BRG's lawyers wrote in a letter to MEPs. BRG's complaint is a further escalation of the controversy surrounding NSO, which was once a highly prized asset that Israel used as a diplomatic calling card, but is now facing lawsuits from Meta and Apple and has been blacklisted by the US. NSO's Pegasus software can infiltrate a smartphone and mirror its encrypted contents. It was last year found to have been used to target smartphones belonging to 37 journalists, human rights activists and other prominent figures.
GNOME

GNOME Patent Troll Gets Stripped of Patent Rights (opensource.org) 40

An anonymous Slashdot reader writes: Remember that patent lawsuit filed against GNOME's Shotwell in 2019? An enterprising open source lawyer has challenged it within the patent office and gotten the whole thing canceled!
OpenSource.org argues that decision by the U.S. patent office "may well give patent trolls cause to steer clear of open source projects — even more than the fierce resistance the community impressively funded and mounted in the GNOME case." Of the many methods developed over the past 20 years to eliminate patent threats against FOSS, none is as powerful as challenging the nefarious patents directly. That's what McCoy Smith, founder of OSI sponsor LexPan Law, did.... Smith pointed out in a re-examination request to the U.S. Patent & Trademark Office that the patent was not for any new invention.

They agreed. As a result, all of these "claims" in the Rothschild '086 Patent — the part of a patent describing what the patent rights cover — have consequently been canceled. The Rothschild '086 patent can no longer be used against any victim, including open source projects.

Of course, that's little comfort to the 20+ victims attacked after GNOME with the now-proven-worthless Rothschild '086 patent, or the 50+ companies targeted with related patents that haven't yet been re-examined.... Still, it's good to know there are open source champions of all sizes defending the development of open software.

Censorship

Millions of Russians are 'Tearing Holes in the Digital Iron Curtain' Using VPNs (msn.com) 96

After Russia invaded Ukraine in late February, "VPNs have been downloaded in Russia by the hundreds of thousands a day," reports the Washington Post, "a massive surge in demand that represents a direct challenge to President Vladimir Putin and his attempt to seal Russians off from the wider world.

"By protecting the locations and identities of users, VPNs are now granting millions of Russians access to blocked material...." Daily downloads in Russia of the 10 most popular VPNs jumped from below 15,000 just before the war to as many as 475,000 in March. As of this week, downloads were continuing at a rate of nearly 300,000 a day, according to data compiled for The Washington Post by the analytics firm Apptopia, which relies on information from apps, public data and an algorithm to come up with estimates. Russian clients typically download multiple VPNs, but the data suggests millions of new users per month. In early April, Russian telecom operator Yota reported that the number of VPN users was over 50 times as high as in January, according to the Tass state news service.

The Internet Protection Society, a digital rights group associated with jailed Russian opposition leader Alexei Navalny, launched its own VPN service last month and reached its limit of 300,000 users within 10 days, according to executive director Mikhail Klimarev. Based on internal surveys, he estimates that the number of VPN users in Russia has risen to roughly 30 percent of the 100 million Internet users in Russia. To combat Putin, "Ukraine needs Javelin and Russians need Internet," Klimarev said....

In the days before the war, and in the weeks since then, Russian authorities have also ratcheted up pressure on Google, asking the search engine to remove thousands of Internet sites associated with VPNs, according to the Lumen database, an archive of legal complaints related to Internet content. Google, which did not respond to a request for comment, still includes banned sites in search results.... Although downloading a VPN is technically easy, usually requiring only a few clicks, purchasing a paid VPN has become complicated in Russia, as Western sanctions have rendered Russian credit and debit cards nearly useless outside the country. That has forced many to resort to free VPNs, which can have spotty service and can sell information about users.

Vytautas Kaziukonis, chief executive of Surfshark — a Lithuania-based VPN that saw a 20-fold increase in Russian users in March — said some of those customers are now paying in cryptocurrencies or through people they know in third countries.

One 52-year-old told the Post that downloading a VPN "brought back memories of the 1980s in the Soviet Union, when he used a shortwave radio to hear forbidden news of dissident arrests on Radio Liberty, which is funded by the United States."

"We didn't know what was going on around us. That's true again now."
Google

The UK Government's Plan to Rein in Big Tech (bbc.com) 24

The BBC reports: Large tech companies such as Google and Facebook will have to abide by new competition rules in the UK or risk facing huge fines, the government said. The new Digital Markets Unit (DMU) will be given powers to clamp down on "predatory practices" of some firms.

The regulator will also have the power to fine companies up to 10% of their global turnover if they fail to comply.... The Department for Digital, Culture, Media and Sport (DCMS) said as well as large fines, tech firms could be handed additional penalties of 5% of daily global turnover for each day an offence continues. For companies like Apple that could be tens of billions of US dollars. "Senior managers will face civil penalties if their firms fail to engage properly with requests for information," the government said. However, it is unclear when exactly the changes will come into force, as the government has said the necessary legislation will be introduced "in due course...."

Google's search engine, which is currently the default search engine on Apple products, will also be looked at by the regulator, the government said.

It added it wants news publishers to be paid fairly for their content — and will give the regulator power to resolve conflicts.

The BBC reports the new rules also "aim to give users more control over their data," and that the new regulator "will also make it easier for people to switch between phone operating systems such as Apple iOS or Android and social media accounts, without losing data and messages."
Transportation

Mercedes-Benz Opens Sales of Level 3 Self-Driving System In Germany (motor1.com) 71

An anonymous reader quotes a report from Motor1: The two flagship models from Mercedes-Benz, the S-Class and the all-electric EQS, will soon be able to be ordered with conditional self-driving tech in Germany. Starting from May 17, the so-called Drive Pilot system will be offered as an extra-cost option for the two sedans, allowing the driver to hand the entire control of the machine over to the system under certain conditions. The Stuttgart-based automaker became the first in the industry to receive international approval for Level 3 autonomous tech in December last year. Releasing the system on the market now becomes the next logical step and Mercedes will ask 5,000 euros for Drive Pilot on the S-Class and 7,430 euros on the EQS, respectively around $5,260 and $7,813 at the current exchange rates. These figures include both the required hardware and software and for now, no further subscriptions are needed.

It's important to note that Level 3 doesn't mean a fully autonomous vehicle. The system used by Mercedes allows the driver to hand all driving tasks to the tech in heavy traffic or on suitable motorways in Germany with speeds of up to 60 kilometers per hour. Under these conditions, the driver can fully disengage from driving with the system controlling the speed and distance, as well as guiding the vehicle within its lane. More importantly, the system also reacts to unexpected traffic situations and avoids dangerous maneuvers.
Mercedes is currently working on receiving certification in the United States, notes Motor1.
Bug

Google Docs Crashes On Seeing 'And. And. And. And. And.' (bleepingcomputer.com) 63

A bug in Google Docs is causing it to crash when a series of words are typed into a document opened with the online word processor. BleepingComputer reports: It's official -- Google Docs crashes at the sight of "And. And. And. And. And." when the "Show grammar suggestion" is turned on. A Google Docs user, Pat Needham brought up the issue on Google Docs Editors Help forum. [...] Another user, Sergii Dymchenko, said strings like "But. But. But. But. But." triggered the same response. Some also noticed putting any of the terms like "Also, Therefore, And, Anyway, But, Who, Why, Besides, However," in the same format achieved the outcome.

Once crashed, you may not be able to easily re-access the document as doing so would trigger the crash again. BleepingComputer was able to reproduce the issue last night and reached out to Google. Google told us it is aware of the bug and working on a fix. [...] Until Google has an answer as to what causes this problem, it might be wise to turn off grammar suggestions by navigating to Tools, Spelling and grammar and unticking 'Show grammar suggestions.' If the bug has already been triggered and you're locked out of the Google Doc in question, there might be a workaround. Use the Google Docs mobile app to access the document, remove the offending words and the file should now open up gracefully on your Google Docs web version too.

Slashdot Top Deals