Businesses

'The Supremacy of Japanese Cars Has Been 40-Plus Years In the Making' (bloomberg.com) 293

American business journalist Joe Nocera writes in a Bloomberg article about "how badly things have deteriorated for the U.S. car makers," after the recent news that both General Motors and Ford will soon be exiting the sedan market in the country. Slashdot reader gollum123 shares the report: Much of the analysis about Ford and GM's exit from the sedan market stressed that sedan sales have lost ground in recent years "as consumers have gravitated toward pickup trucks and sport-utility vehicles," as the New York Times put it. If you look at the historical sales figures of the top Japanese sedans, you'll see a small decline in recent years, but nothing like the big drop-off in sales that have hammered the American companies. So in addition to the overall decline in sedan sales, there is a second, largely overlooked, dynamic taking place: Americans have only stopped buying American sedans, not Japanese sedans. The American car companies now say they are going to count on profits from trucks and SUVs while moving toward autonomous and all-electric vehicles. They had better hope that transition takes place quickly.

I couldn't help noticing that while the top three selling vehicles in the U.S. are, indeed, American-made trucks, No. 4 on the list is Nissan's top SUV, the Rogue, the sales of which have gone from 18,000 in 2007 to 403,000 last year. No. 5 is a Toyota SUV, the Rav4 (407,000 in 2017). No. 6 is the Honda CR-V (378,000). And the leading American SUV? It's the Chevy Equinox. Last year, Chevrolet sold 290,000 of them -- 100,000 fewer than the Toyota Camry.

Wireless Networking

Starbucks Says It Will Start Blocking Porn On Its Stores' Wi-Fi In 2019 (nbcnews.com) 218

Starbucks announced that it will start blocking pornography viewing on its stores' Wi-Fi starting in 2019. "A Starbucks representative told NBC News that the viewing of 'egregious content' over its stores' Wi-Fi has always violated its policy, but the company now has a way to stop it," reports NBC News. From the report: "We have identified a solution to prevent this content from being viewed within our stores and we will begin introducing it to our U.S. locations in 2019," the company representative said. The announcement was first reported by Business Insider and comes after a petition from internet-safety advocacy group Enough is Enough garnered more than 26,000 signatures. The nonprofit launched a porn-free campaign aimed at McDonald's and Starbucks in 2014, and it says that while McDonald's "responded rapidly and positively," Starbucks did not.

In a letter that [Enough is Enough CEO Donna Rice Hughes] said she received from Starbucks over the summer, the company vowed to address the issue "once we determine that our customers can access our free Wi-Fi in a way that also doesn't involuntarily block unintended content." Starbucks has not released details about how it plans to restrict the viewing of pornographic sites or illegal content over its Wi-Fi.
In response, the vice president of YouPorn responded by sending a memo to staff banning Starbucks products from company offices starting Jan. 1, 2019.
Microsoft

Microsoft Wins $480 Million Military Contract To Bring HoloLens To Battlefield (arstechnica.com) 59

An anonymous reader quotes a report from Ars Technica: Microsoft has won a $480 million contract to develop an augmented reality system for use in combat and military training for the U.S. Army. Called Integrated Visual Augmentation System (IVAS), formerly Heads Up Display (HUD) 3.0, the goal of the project is to develop a headset that gives soldiers -- both in training and in combat -- an increase in "Lethality, Mobility, and Situational Awareness." The ambitions for the project are high. Authorities want to develop a system with a goggle or visor form factor -- nothing mounted on a helmet -- with an integrated 3D display, digital cameras, ballistic laser, and hearing protection. The system should provide remote viewing of weapon sights to enable low risk, rapid target acquisition, perform automated or assisted target acquisition, integrate both thermal and night vision cameras, track soldier vitals such as heart and breathing rates, and detect concussions. Over the course of IVAS's development, the military will order an initial run of 2,550 prototypes, with follow-on production possibly in excess of 100,000 devices.
The Internet

When the Internet Archive Forgets (gizmodo.com) 71

A reminder that Internet Archive's Wayback Machine, which many people assume keeps a permanent trail and origin of web-content, has little feasible choice but to comply with DMCA takedown notices. As a result of which, a portion of the archive of things people submit to the website continues to quietly fade away. Gizmodo: Over the last few years, there has been a change in how the Wayback Machine is viewed, one inspired by the general political mood. What had long been a useful tool when you came across broken links online is now, more than ever before, seen as an arbiter of the truth and a bulwark against erasing history. That archive sites are trusted to show the digital trail and origin of content is not just a must-use tool for journalists, but effective for just about anyone trying to track down vanishing web pages. With that in mind, that the Internet Archive doesn't really fight takedown requests becomes a problem. That's not the only recourse: When a site admin elects to block the Wayback crawler using a robots.txt file, the crawling doesn't just stop. Instead, the Wayback Machine's entire history of a given site is removed from public view.

In other words, if you deal in a certain bottom-dwelling brand of controversial content and want to avoid accountability, there are at least two different, standardized ways of erasing it from the most reliable third-party web archive on the public internet. For the Internet Archive, like with quickly complying with takedown notices challenging their seemingly fair use archive copies of old websites, the robots.txt strategy, in practice, does little more than mitigating their risk while going against the spirit of the protocol. And if someone were to sue over non-compliance with a DMCA takedown request, even with a ready-made, valid defense in the Archive's pocket, copyright litigation is still incredibly expensive. It doesn't matter that the use is not really a violation by any metric. If a rightsholder makes the effort, you still have to defend the lawsuit.

IOS

US iOS Users Targeted by Massive Malvertising Campaign (zdnet.com) 61

A cyber-criminal group known as ScamClub has hijacked over 300 million browser sessions over 48 hours to redirect users to adult and gift card scams, a cyber-security firm revealed this week. From a report: The traffic hijacking has taken place via a tactic known as malvertising, which consists of placing malicious code inside online ads. In this particular case, the code used by the ScamClub group hijacked a user's browsing session from a legitimate site, where the ad was showing, and redirected victims through a long chain of temporary websites, a redirection chain that eventually ended up on a website pushing an adult-themed site or a gift card scam.

These types of malvertising campaigns have been going on for years, but this particular campaign stood out due to its massive scale, experts from cyber-security firm Confiant told ZDNet today. "On November 12 we've seen a huge spike in our telemetry," Jerome Dang, Confiant co-founder and CTO, told ZDNet in an email. Dangu says his company worked to investigate the huge malvertising spike and discovered ScamClub activity going back to August this year.

Microsoft

Microsoft's Surface Roadmap Reportedly Includes Ambient Computing and a Modular All-in-One PC (venturebeat.com) 41

Journalist Brad Sams is releasing a book chronicling the company's Surface brand: Beneath a Surface. VentureBeat writes: While you'll want to read all 26 chapters to get the juicy details, the last one includes Microsoft's hardware roadmap for 2019, and even a part of 2020 -- spanning various Surface products and even a little Xbox. Here's a quick rundown of Microsoft's current Surface lineup plans:

Spring 2019: A new type of Surface-branded ambient computing device designed to address "some of the common frustrations of using a smartphone," but that isn't itself a smartphone.
Q4 2019: Surface Pro refresh with USB-C (finally), smaller bezels, rounded corners, and new color options.
Q4 2019: AMD-based Surface Laptop -- Microsoft is exploring using the Picasso architecture.
Late 2019: Microsoft's foldable tablet Andromeda could be larger than earlier small form factor prototypes for a pocketable device with dual screens and LTE connectivity.
Q1 2020: Surface Book update that might include new hinge designs (high-end performance parts may delay availability).
2020: A Surface monitor, and the modular design debuted for Surface Hub 2 could make its way to Surface Studio. The idea is to bring simple upgrades to all-in-one PCs, rather than having to replace the whole computer.
GeekWire adds: A pair of new lower-cost devices Xbox One S devices could come next year. Sams reports that one of the models may be all digital, without a disc drive.
News

At an All-Hands Meeting, Uber CEO Said The Company Deserves Some Fault After Its Self-Driving Car Killed a Pedestrian (businessinsider.com) 122

During an all-hands meeting at Uber earlier this week, CEO Dara Khosrowshahi and the head of the self-driving car unit, Eric Meyhofer, were questioned by employees over the culture at the self-driving unit. An anonymous reader writes: They asked about allegations of infighting and dysfunction in the unit prior to a tragic accident that killed a pedestrian, based on Business Insider's newly published investigation. (The investigation found that engineers were pressured to "tune" the self-driving car for a smoother ride in preparation of a big year-end demonstration of their progress, but that meant not allowing the car to respond to everything it saw, real or not.) What followed was a strange couple of minutes in which the executives told odd stories and quoted wrong statistics leading up to Khosrowshahi admitting, several times, "we have screwed up."

[...] Khosrowshahi showed his support of his senior leader by saying some negative things about Business Insider. And then he said, "we did screw up" and that "we are radically changing how we develop, how we test, etcetera. So we've gone through changes. We have screwed up." Sources tell Business Insider that Khosrowshahi had not been paying much attention to the self-driving car unit in his first year because he was so busy fighting fires with Uber's main business, but that this is changing now. On Tuesday, Khosrowshahi indicated as much saying, "A year forward from all the controversy that we saw last year, we are better, stronger. And I think ATG is going through that same journey," he said.

Security

Mass Router Hack Exposes Millions of Devices To Potent NSA Exploit (arstechnica.com) 73

More than 45,000 Internet routers have been compromised by a newly discovered campaign that's designed to open networks to attacks by EternalBlue, the potent exploit that was developed by, and then stolen from, the National Security Agency and leaked to the Internet at large, researchers say. From a report: The new attack exploits routers with vulnerable implementations of Universal Plug and Play to force connected devices to open ports 139 and 445, content delivery network Akamai said in a blog post. As a result, almost 2 million computers, phones, and other network devices connected to the routers are reachable to the Internet on those ports. While Internet scans don't reveal precisely what happens to the connected devices once they're exposed, Akamai said the ports --which are instrumental for the spread of EternalBlue and its Linux cousin EternalRed -- provide a strong hint of the attackers' intentions.

The attacks are a new instance of a mass exploit the same researchers documented in April. They called it UPnProxy because it exploits Universal Plug and Play -- often abbreviated as UPnP -- to turn vulnerable routers into proxies that disguise the origins of spam, DDoSes, and botnets.

China

China Halts Work by Team on Gene-Edited Babies (apnews.com) 80

China's government ordered a halt Thursday to work by a medical team that claimed to have helped make the world's first gene-edited babies, as a group of leading scientists declared that it's still too soon to try to make permanent changes to DNA that can be inherited by future generations. AP reports: Chinese Vice Minister of Science and Technology Xu Nanping told state broadcaster CCTV that his ministry is strongly opposed to the efforts that reportedly produced twin girls born earlier this month. Xu called the team's actions illegal and unacceptable and said an investigation had been ordered, but made no mention of specific actions taken. Researcher He Jiankui claims to have altered the DNA of the twins to try to make them resistant to infection with the AIDS virus. Mainstream scientists have condemned the experiment, and universities and government groups are investigating. His experiment "crossed the line of morality and ethics adhered to by the academic community and was shocking and unacceptable," Xu said. A group of leading scientists gathered in Hong Kong this week for an international conference on gene editing, the ability to rewrite the code of life to try to correct or prevent diseases.
Security

I've Got a Bridge To Sell You. Why AutoCAD Malware Keeps Chugging On (arstechnica.com) 66

Criminal hackers continue to exploit a feature in Autodesk's widely used AutoCAD program in an attempt to steal valuable computer-assisted designs for bridges, factory buildings, and other projects, researchers say. From a report: The attacks arrive in spear-phishing emails and in some cases postal packages that contain design documents and plans. Included in the same directory are camouflaged files formatted in AutoLISP, an AutoCAD-specific dialect of the LISP programming language. When targets open the design document, they may inadvertently cause the AutoLISP file to be executed. While modern versions of AutoCAD by default display a warning that a potentially unsafe script will run, the warnings can be disregarded or suppressed altogether. To make the files less conspicuous, the attackers have set their properties to be hidden in Windows and their contents to be encrypted.

The attacks aren't new. Similar ones occurred as long ago as 2005, before AutoCAD provided the same set of robust defenses against targeted malware it does now. The attacks continued to go strong in 2009. A specific campaign recently spotted by security firm Forcepoint was active as recently as this year and has been active since at least 2014, an indication that malware targeting blueprints isn't going away any time soon. [...] Forcepoint said it has tracked more than 200 data sets and about 40 unique malicious modules, including one that purported to include a design for Hong Kong's Zhuhai-Macau Bridge.

China

Bloomberg is Still Reporting on Challenged Story Regarding China Hardware Hack (washingtonpost.com) 71

Erik Wemple, writing for The Washington Post: According to informed sources, Bloomberg has continued reporting the blockbuster story that it broke on Oct. 4, including a very recent round of inquiries from a Bloomberg News/Bloomberg Businessweek investigative reporter. In emails to employees at Apple, Bloomberg's Ben Elgin has requested "discreet" input on the alleged hack. "My colleagues' story from last month (Super Micro) has sparked a lot of pushback," Elgin wrote on Nov. 19 to one Apple employee. "I've been asked to join the research effort here to do more digging on this ... and I would value hearing your thoughts (whatever they may be) and guidance, as I get my bearings."

One person who spoke with Elgin told the Erik Wemple Blog that the Bloomberg reporter made clear that he wasn't part of the reporting team that produced "The Big Hack." The goal of this effort, Elgin told the potential source, was to get to "ground truth"; if Elgin heard from 10 or so sources that "The Big Hack" was itself a piece of hackery, he would send that message up his chain of command. The potential source told Elgin that the denials of "The Big Hack" were "100 percent right."

According to the potential source, Elgin also asked about the possibility that Peter Ziatek, senior director of information security at Apple, had written a report regarding a hardware hack affecting Apple. In an interview with the Erik Wemple Blog, Ziatek says that he'd never written that report, nor is he aware of such a document. Following the publication of Bloomberg's story, Apple conducted what it calls a "secondary" investigation surrounding its awareness of events along the lines of what was alleged in "The Big Hack." That investigation included a full pat-down of Ziatek's own electronic communications. It found nothing to corroborate the claims in the Bloomberg story, according to Ziatek.

The Almighty Buck

Fed Says Millennials Are Just Like Their Parents. Only Poorer (bloomberg.com) 344

Millennials, long presumed to have less interest in the nonstop consumption of goods that underpins the American economy, might not be that different after all, a new study from the Federal Reserve says. From a report: Their spending habits are a lot like the generations that came before them, they just have less money at this point in their lives, the Fed study found. The group born between 1981 and 1997 has fallen behind because many of them came of age during the financial crisis. "We find little evidence that millennial households have tastes and preference for consumption that are lower than those of earlier generations, once the effects of age, income, and a wide range of demographic characteristics are taken into account," wrote authors Christopher Kurz, Geng Li and Daniel J. Vine.

Their findings [PDF] are grounded in an analysis of spending, income, debt, net worth, and demographic factors among different generations. The conclusion that millennials aren't all that different also holds for the researchers' more granular examination of expenditures on cars, food, and housing. "It primarily is the differences in average age and then differences in average income that explain a large and important portion of the consumption wedge between millennials and other cohorts," they conclude. So much for the young folks favoring "experiences" over tangible goods.

Microsoft

That Virus Alert on Your Computer? Scammers in India May Be Behind It (nytimes.com) 98

In India, a hub for tech support centers, a rise in scams forced Microsoft and the police to take action. From a report: You know the messages. They pop up on your computer screen with ominous warnings like, "Your computer has been infected with a virus. Call our toll-free number immediately for help." Often they look like alerts from Microsoft, Apple or Symantec. Sometimes the warning comes in a phone call. Most people ignore these entreaties, which are invariably scams. But one in five recipients actually talks to the fake tech-support centers, and 6 percent ultimately pay the operators to "fix" the nonexistent problem, according to recent consumer surveys by Microsoft.

Law enforcement authorities, working with Microsoft, have now traced many of these boiler rooms to New Delhi, India's capital and a hub of the global call-center industry. On Tuesday and Wednesday, police from two Delhi suburbs raided 16 fake tech-support centers and arrested about three dozen people. Last month, the Delhi authorities arrested 24 people in similar raids on 10 call centers. In Gautam Budh Nagar, one of the suburbs, 50 police officers swept into eight centers on Tuesday night. Ajay Pal Sharma, the senior superintendent of police there, said the scammers had extracted money from thousands of victims, most of whom were American or Canadian.

Businesses

New Parents Complain Amazon Baby-Registry Ads Are Deceptive (wsj.com) 58

Unwanted gifts arrive after friends click on promotions tucked into wish lists. From a report: Kima Nieves recently received two Aveeno bath-time sets and a box of Huggies diapers through her baby registry on Amazon. The only problem? The new mother didn't ask for the products, or even want them. Instead, Johnson & Johnson and Kimberly-Clark each paid Amazon.com hefty sums to place those sponsored products onto Ms. Nieves's and other consumers' baby registries. The ads look identical to the rest of the listed products in the registry, except for a small gray "Sponsored" tag. Unsuspecting friends and family clicked on the ads and purchased the items, assuming Ms. Nieves had chosen them. "Very sneaky," said the 28-year-old health-care analyst from Fredericksburg, Va. "That's friends' and family's money going somewhere we didn't approve of."

Amazon in recent years has charged into advertising, building the third-largest digital ad business in the U.S. after Alphabet's Google and Facebook, according to eMarketer. Its ad revenue is on pace to double this year, to $5.8 billion, eMarketer estimates. As Amazon has monetized more space on its website, shoppers are increasingly encountering sponsored ads. Amazon is "starting to see how far they can push things," said Harry Brignull, a U.K.-based consultant who specializes in spotting web-design tactics that get people to click on something. Amazon's sponsored ads have appeared in its baby registries for more than a year. Responding to a Wall Street Journal inquiry about the ads, an Amazon spokeswoman declined to comment on criticism that the ads are deceptive, but said the retailer is now phasing out the sponsored listings. "We're constantly experimenting with new ways to improve the shopping experiences for customers," she said.

News

How Restaurants Got So Loud (theatlantic.com) 233

An anonymous reader shares a report: Other sounds that reach 70 decibels include freeway noise, an alarm clock, and a sewing machine. But it's still quiet for a restaurant. Others I visited in Baltimore and New York City while researching this story were even louder: 80 decibels in a dimly lit wine bar at dinnertime; 86 decibels at a high-end food court during brunch; 90 decibels at a brewpub in a rehabbed fire station during Friday happy hour. Restaurants are so loud because architects don't design them to be quiet. Much of this shift in design boils down to changing conceptions of what makes a space seem upscale or luxurious, as well as evolving trends in food service. Right now, high-end surfaces connote luxury, such as the slate and wood of restaurants including The Osprey in Brooklyn or Atomix in Manhattan.

This trend is not limited to New York. According to Architectural Digest, mid-century modern and minimalism are both here to stay. That means sparse, modern decor; high, exposed ceilings; and almost no soft goods, such as curtains, upholstery, or carpets. These design features are a feast for the eyes, but a nightmare for the ears. No soft goods and tall ceilings mean nothing is absorbing sound energy, and a room full of hard surfaces serves as a big sonic mirror, reflecting sound around the room. The result is a loud space that renders speech unintelligible. Now that it's so commonplace, the din of a loud restaurant is unavoidable. That's bad for your health -- and worse for the staff who works there. But it also degrades the thing that eating out is meant to culture: a shared social experience that rejuvenates, rather than harms, its participants.

Slashdot Top Deals