Security

Iran Allegedly Hit By Computer Virus More Violent Than Stuxnet (timesofisrael.com) 181

TTL0 shares a report from The Times of Israel: Iranian infrastructure and strategic networks have come under attack in the last few days by a computer virus similar to Stuxnet but "more violent, more advanced and more sophisticated," and Israeli officials are refusing to discuss what role, if any, they may have had in the operation, an Israeli TV report said Wednesday. "Remember Stuxnet, the virus that penetrated the computers of the Iranian nuclear industry?" the report on Israel's Hadashot news asked. Iran "has admitted in the past few days that it is again facing a similar attack, from a more violent, more advanced and more sophisticated virus than before, that has hit infrastructure and strategic networks." The Iranians, the TV report went on, are "not admitting, of course, how much damage has been caused." On Sunday, Gholamreza Jalali, the head of Iran's civil defense agency, said Tehran had neutralized a new version of Stuxnet, Reuters reported. Stuxnet penetrated Iran's nuclear program, "taking control and sabotaging parts of its enrichment processes by speeding up its centrifuges," the report notes. We'll update this story when more details become available.
Space

NASA's Dawn Spacecraft Is Dead (theverge.com) 86

NASA's Dawn spacecraft has run out of fuel, leading the agency to officially end its mission of exploring the two largest objects in the asteroid belt, Vesta and Ceres. "Today, we celebrate the end of our Dawn mission -- its incredible technical achievements, the vital science it gave us and the entire team who enabled the spacecraft to make these discoveries," Thomas Zurbuchen, associate administrator of NASA's Science Mission Directorate in Washington, D.C., said in a statement. "The astounding images and data that Dawn collected from Vesta and Ceres are critical to understanding the history and evolution of our solar system," Zurbuchen added. Space.com reports: The $467 million Dawn mission launched in September 2007 to study the protoplanet Vesta and the dwarf planet Ceres, which are about 330 miles (530 kilometers) and 590 miles (950 km) wide, respectively. Scientists regard these two bodies as leftovers from the solar system's planet-formation period, which explains the mission's name. Dawn arrived at Vesta in July 2011, then scrutinized the object from orbit for 14 months. The probe's work revealed many intriguing details about Vesta. For example, liquid water once flowed across the protoplanet's surface (likely after buried ice was melted by meteorite impacts), and Vesta sports a towering peak near its south pole that's nearly as tall as Mars' famous Olympus Mons volcano. Dawn left Vesta in September 2012.

The mission team concluded that Dawn had run out of hydrazine after the probe missed scheduled communication check-ins yesterday (Oct. 31) and today. Hydrazine is the fuel used by Dawn's pointing thrusters, so the spacecraft can no longer orient itself to study Ceres, relay data to Earth or recharge its solar panels. Dawn will remain in orbit around Ceres for at least 20 years, and probably much longer than that. Mission team members have said there's a greater than 99 percent probability that the probe won't spiral down onto Ceres' frigid, battered surface for at least five more decades.
It's been a rough week for space explorers as not only did Dawn run out of fuel, but the Kepler telescope did too and had to be retired.
Cellphones

Study of Cellphone Risks Finds 'Some Evidence' of Link To Cancer, At Least In Male Rats (nytimes.com) 153

An anonymous reader quotes a report from The New York Times: For decades, health experts have struggled to determine whether or not cellphones can cause cancer. On Thursday, a federal agency released the final results of what experts call the world's largest and most costly experiment to look into the question. The study originated in the Clinton administration, cost $30 million and involved some 3,000 rodents. The experiment, by the National Toxicology Program, found positive but relatively modest evidence that radio waves from some types of cellphones could raise the risk that male rats develop brain cancer. But he cautioned that the exposure levels and durations were far greater than what people typically encounter, and thus cannot "be compared directly to the exposure that humans experience." Moreover, the rat study examined the effects of a radio frequency associated with an early generation of cellphone technology, one that fell out of routine use years ago. Any concerns arising from the study thus would seem to apply mainly to early adopters who used those bygone devices, not to users of current models.

The lowest level of radiation in the federal study was equal to the maximum exposure that federal regulations allow for cellphone users. That level of exposure rarely occurs in typical cellphone use, the toxicology agency said. The highest level was four times higher than the permitted maximum. The rodents in the studies were exposed to radiation nine hours a day for two years -- far longer even than heavy users of cellphones. For the rats, the exposures started before birth and continued until they were about 2 years old. Some 2 to 3 percent of the male rats exposed to the radiation developed malignant gliomas, a deadly brain cancer, compared to none in a control group that received no radiation. Many epidemiologists see no overall rise in the incidence of gliomas in the human population.
"The study also found that about 5 to 7 percent of the male rats exposed to the highest level of radiation developed certain heart tumors, called schwannomas, compared to none in the control group," the NYT reports.

It's worth nothing that the rats were exposed to radiation at a frequency of 900 megahertz, the frequency used in the second generation of cellphones that prevailed in the 90s, when the study was first conceived. For comparison, fourth generation (4G) and fifth generation (5G) phones employ much higher frequencies, which are "far less successful at penetrating the bodies of humans and rats," the NYT reports.
Education

'Hologram' Lecturers To Teach Students at Imperial College London (bbc.com) 57

Imperial College London will be using holograms of lecturers to teach students from afar. "Imperial will initially limit its use to its Business School's activities but expects the technology could eventually become common," reports the BBC. From the report: Strictly speaking, the illusions are not holograms but neither are they the Pepper's Ghost effect used by politicians including French presidential candidate Jean-Luc Melenchon and India's Prime Minister Narendra Modi as well the entertainment industry. Instead, they use a technique developed by a Canadian company, Arht Media. "The problem with Pepper's Ghost is that it can be intricate to set up and can cost about $200,000 to run an event," said Dr David Lefevre, director of Imperial's Edtech Lab. "This is simpler -- you project upon a glass screen, and a backdrop behind it uses software to give it an illusion of depth. "It runs at the low thousands each time, so for the first time universities can afford it." To send their image, lecturers need to use a "capture studio," which involves filming them against a black backdrop while being lit from both sides.
Security

Bleedingbit Zero-Day Chip Flaws May Expose Majority of Enterprises To Remote Code Execution Attacks (zdnet.com) 55

Two new zero-day vulnerabilities called "Bleeding Bit" have been revealed by security firm Armis, impacting Bluetooth Low-Energy (BLE) chips used in millions of Cisco, Meraki, and Aruba wireless access points (APs). "Developed by Texas Instruments (TI), the vulnerable BLE chips are used by roughly 70 to 80 percent of business wireless access points today by way of Cisco, Meraki and Aruba products," reports ZDNet. From the report: The first vulnerability, CVE-2018-16986, impacts Cisco and Meraki APs using TI BLE chips. Attacks can remotely send multiple benign BLE broadcast messages, called "advertising packets," which are stored on the memory of the vulnerable chip. As long as a target device's BLE is turned on, these packets -- which contain hidden malicious code to be invoked later on -- can be used together with an overflow packet to trigger an overflow of critical memory. If exploited, attackers are able to trigger memory corruption in the chip's BLE stack, creating a scenario in which the threat actor is able to access an operating system and hijack devices, create a backdoor, and remotely execute malicious code.

The second vulnerability, CVE-2018-7080, is present in the over-the-air firmware download (OAD) feature of TI chips used in Aruba Wi-Fi access point Series 300 systems. The vulnerability is technically a leftover development backdoor tool. This oversight, the failure to remove such a powerful development tool, could permit attackers to compromise the system by gaining a foothold into a vulnerable access point. "It allows an attacker to access and install a completely new and different version of the firmware -- effectively rewriting the operating system of the device," the company says. "The OAD feature doesn't offer a security mechanism that differentiates a "good" or trusted firmware update from a potentially malicious update."

Patents

Patent Troll Values Its Entire Portfolio At $2, Goes Bankrupt (arstechnica.com) 117

mspohr shares a report from Ars Technica: In September 2018, Shipping & Transit LLC (formerly known as ArrivalStar) filed for Chapter 7 bankruptcy -- voluntary liquidation -- but no one seems to have noticed until the Electronic Frontier Foundation pointed it out on October 31. The company claimed that it held the patent on vehicle tracking and related alerts. But about 15 months ago, judges began to rule against Shipping & Transit for the first time. That seems to have put a damper on its entire business model.

Now, according to Shipping & Transit LLC's federal bankruptcy filings, its global patent holdings (34 in the United States and 29 elsewhere) are worth a whopping $2. Meanwhile, it owes more than $423,000 to numerous creditors, including banks, law firms, and something called the "West African Investment Trust," based in Geneva, Switzerland.

Google

Google Employees Stage Protest Over Handling of Sexual Harassment (nytimes.com) 271

An anonymous reader quotes a report from The New York Times: Employees at Google offices around the world held a wave of walkouts on Thursday to protest the company's handling of sexual harassment. The walkouts, which started in Asia and spread across continents, were planned for around 11 a.m. in their time zones. Protests were held through the day in Google offices in the United States. The backlash was prompted by an article in The New York Times last week that revealed that Google had paid millions of dollars in exit packages to male executives accused of harassment, while staying silent about the transgressions. As late morning arrived in different time zones on Thursday, Google employees walked away from their work at offices including Singapore; Hyderabad, India; Berlin; Zurich; Dublin; London; New York; and its headquarters in Mountain View, California.

Employees posted photos on social media, but it was unclear how long the protests lasted as many of those who stopped working stayed inside the buildings. The employees who organized the walkout have called on Google to end its use of private arbitration in cases of alleged sexual assault and harassment. They have also demanded the publication of a transparency report on instances of sexual harassment, further disclosures of salaries and compensation, an employee representative on the company board and a chief diversity officer who could speak directly to the board.

Iphone

Apple Launches Program To Repair Old Devices Like the iPhone 4S (9to5mac.com) 115

Apple is introducing a new "Repair Vintage Apple Products Pilot" program that will extend the period of time customers can receive repairs for older devices. "The new program at first will include the iPhone 5 and other Apple products that are about to become obsolete, and in the coming weeks will add more products to the list for devices that previously lost repair support," reports 9to5Mac. Some of the devices that will be included on the list include the iPhone 4s and MacBook Pro (15-inch, Mid 2012). From the report: Apple has long had a 5-7 year lifespan for repairing its products, meaning that owners of an iPhone, iPad or Mac can have repairs performed through Apple or an authorized service provider even when not under warranty. Usually after 5-7 years, products are then classified as "vintage" or "obsolete" (depending on the country and local laws) and Apple staff no longer offers parts or repairs. The company maintains a list of products that are classified as vintage and obsolete on its website.

For the new Pilot program, Apple will only be offering repairs for vintage devices based on part availability. Otherwise customers will be told that inventory isn't available because the product is considered vintage. So the new program doesn't guarantee you a repair, but it's a nice change from Apple's previous policy where it stopped offering repairs entirely after classifying devices as vintage.

Privacy

Senator Introduces Bill That Would Send CEOs To Jail For Violating Consumer Privacy (vice.com) 104

Oregon Senator Ron Wyden has introduced the Consumer Data Protection Act that "would dramatically beef up Federal Trade Commission authority and funding to crack down on privacy violations, let consumers opt out of having their sensitive personal data collected and sold, and impose harsh new penalties on a massive data monetization industry that has for years claims that self-regulation is all that's necessary to protect consumer privacy," reports Motherboard. From the report: Wyden's bill proposes that companies whose revenue exceeds $1 billion per year -- or warehouse data on more than 50 million consumers or consumer devices -- submit "annual data protection reports" to the government detailing all steps taken to protect the security and privacy of consumers' personal information. The proposed legislation would also levy penalties up to 20 years in prison and $5 million in fines for executives who knowingly mislead the FTC in these reports. The FTC's authority over such matters is currently limited -- one of the reasons telecom giants have been eager to move oversight of their industry from the Federal Communications Commission to the FTC. "Today's economy is a giant vacuum for your personal information -- everything you read, everywhere you go, everything you buy and everyone you talk to is sucked up in a corporation's database," Wyden said in a statement. "But individual Americans know far too little about how their data is collected, how it's used and how it's shared."

"It's time for some sunshine on this shadowy network of information sharing," Wyden said. "My bill creates radical transparency for consumers, gives them new tools to control their information and backs it up with tough rules with real teeth to punish companies that abuse Americans' most private information."
AT&T

AT&T Blacks Out HBO, Cinemax For Dish, Sling TV Users Over Carriage Dispute (telecompaper.com) 107

An anonymous reader quotes a report from Telecompaper: AT&T has blocked its HBO and Cinemax channels for Dish and Sling TV customers over a carriage dispute. This is the first channel blackout for HBO in its 40 years of operation. Pay-TV provider Dish and OTT services Sling TV said AT&T is making "untenable demands designed specifically to harm customers, particularly those in rural areas, as well as damage competing pay-TV providers" and that at the time of the merger, no guidelines were set in place to ensure AT&T "played fair" for HBO and Cinemax subscribers, regardless of their pay-TV provider.

Dish said AT&T is demanding it pay for a guaranteed number of subscribers, regardless of how many people actually want to subscribe to HBO. The company noted that during the arbitration process, AT&T will have to restore its channels to Dish customers. The company and Sling TV will credit customers on their bill for the time they do not receive either HBO or Cinemax. Dish added that it is also offering customers a free preview of HDNET Movies.
An HBO spokesperson said in a statement: "During our forty-plus years of operation, HBO has always been able to reach agreement with our valued distributors and our services have never been taken down or made unavailable to subscribers due to an inability to conclude a deal. Unfortunately, Dish is making it extremely difficult, responding to our good faith attempts with unreasonable terms. Past behavior shows that removing services from their customers is becoming all too common a negotiating tactic for them. We hope the situation with Dish changes soon but, in the meantime, our valued customers should take advantage of the other ways to access an HBO subscription so they can continue to enjoy our acclaimed programming."
Portables (Apple)

New iPad Pro Has Comparable Performance To 2018 15" MacBook Pro in Benchmarks (macrumors.com) 171

A series of benchmark results have shown up on Geekbench for the new iPad Pro, and its new eight-core A12X Bionic chip is truly a powerhouse. From a report: The new iPad Pro achieved single-core and multi-core scores of 5,025 and 18,106 respectively based on an average of two benchmark results, making it by far the fastest iPad ever and comparable even to the performance of the latest 15-inch MacBook Pro models with Intel's six-core Core i7 chips. We've put together a chart that compares Geekbench scores of the new iPad Pro and various other iPad, Mac, and iPhone models.

That the new iPad Pro rivals the performance of the latest 15-inch MacBook Pro with a 2.6GHz six-core Core i7 processor is impressive, but even more so when you consider that the tablet starts at $799. The aforementioned MacBook Pro configuration is priced at $2,799, although with 512GB of storage. Even the new 11-inch iPad Pro with 512GB of storage is only $1,149, less than half that of the Core i7-equipped MacBook Pro.

Android

Android Pie Has a Battery Life Problem (venturebeat.com) 76

Emil Protalinski, writing for VentureBeat: After upgrading to Android Pie, most users have either seen a slight improvement in battery life or reported no perceivable difference. But soon after we published our story, some users told us that they are experiencing the opposite: significantly higher battery drain after upgrading to Pie. We've been tracking this issue for the past few months, during which the Pixel 3 and Pixel 3 XL launched with Android Pie out-of-the-box and new device owners reported similar problems. Some Android Pie users simply don't expect their phones to make it through the day.

Users on Reddit, the Pixel forums, and Google's issue tracker have been discussing battery life issues on existing devices after upgrading to Android Pie, and some even on new devices (although there are naturally fewer of those cases). VentureBeat was able to independently confirm the issue on a Pixel 2 XL and a Pixel 3 -- we sent the details to Google. Given that Adaptive Battery is the main feature highlight when it comes to battery improvement in Android Pie, many suspected it could be the culprit. Users have reported, however, that turning it off didn't help the situation much, if at all. We were also able to independently verify that Adaptive Battery is not the cause. Adaptive Battery is only available in Pie, but in our tests battery life only drained faster with the feature off. We did, however, confirm that the problem is unique to Android Pie. Users have reported significant battery drain when their phones are idle, anywhere between 10 percent to 20 percent drained in an hour.

Businesses

US Accuses China, Taiwan Firms With Stealing Secrets From Chip Giant Micron (yahoo.com) 99

US Attorney General Jeff Sessions announced charges Thursday against Chinese and Taiwan companies for theft of an estimate $8.75 billion worth of trade secrets from US semiconductor giant Micron. From a report: Sessions said the case was the latest in a series that are part of a state-backed program by Beijing to steal US industrial and commercial secrets. "Taken together, these cases and many others like them paint a grim picture of a country bent on stealing its way up the ladder of economic development and doing so at American expense," Session said. "This behavior is illegal. It is wrong. It is a threat to our national security. And it must stop." The indictment released in the US district court in San Jose, California alleges that Chinese state-owned Fujian Jinhua Integrated Circuit Co. and privately owned United Microelectronics Corporation of Taiwan, along with three UMC executives, conspired to steal Micron trade secrets to help UMC and Fujian Jinhua develop DRAM chips used in many computer processors. It said the three Taiwanese men -- Stephen Chen Zhengkun, He Jianting and Kenny Wang Yungming -- all previously worked at Micron and stole its technology when they joined UMC with the express purpose of transferring it to Fujian Jinhua, a two-year-old firm. Chen was originally a top executive at Micron, then moved to lead UMC, and subsequently became president of Fujian Jinhua.
Government

US Declines in Internet Freedom Rankings (techcrunch.com) 153

If you need a safe haven on the internet, where the pipes are open and the freedoms are plentiful -- you might want to move to Estonia or Iceland. From a report: The latest "internet freedoms" rankings are out, courtesy of Freedom House's annual report into the state of internet freedoms and personal liberties, based on rankings of 65 countries that represent the vast majority of the world's internet users. Although the U.S. remains firmly in the top 10, it dropped a point on the year earlier after a recent rash of changes to internet regulation and a lack of in the realm of surveillance. Last year, the U.S. was 21 in the global internet freedom ranking -- the lower number, the better a country ranks. That was behind Estonia, Iceland, Canada, Germany and Australia. This year the U.S. is at 22 -- thanks to the repeal of net neutrality and the renewal of U.S. spy powers. The report also cited "disinformation and hyperpartisan content" -- or fake news -- as a "pressing concern."
Facebook

Apple, Amazon, Google and More Than 50 Other Companies Sign Letter Against Trump Administration's Proposed Gender Definition Changes (cnbc.com) 769

Apple, Amazon, Facebook and Google, and dozens of other tech companies have come together to condemn discrimination against transgender people in the face of actions President Donald Trump is reportedly considering to reduce their legal protections. From a report: The move is a response to an Oct. 21 New York Times report that the Trump administration is considering limiting the definition of gender to birth genitalia. "Sex means a person's status as male or female based on immutable biological traits identifiable by or before birth," the Department of Health and Human Services proposed in a memo obtained by the Times. If legislation were to move forward, it would jeopardize legal protections for an estimated 1.4 million Americans who identify as a gender other than the one they were assigned at birth, the Times said.

The statement from the companies, which have nearly 4.8 million employees, said diversity and inclusion are good for business. "Transgender people are our beloved family members and friends, and our valued team members," the statement said. "What harms transgender people harms our companies."

Slashdot Top Deals