Open Source

New SystemD Vulnerability Discovered (theregister.co.uk) 204

The Register reports that a new security bug in systemd "can be exploited over the network to, at best, potentially crash a vulnerable Linux machine, or, at worst, execute malicious code on the box" by a malicious host on the same network segment as the victim. According to one Red Hat security engineer, "An attacker could exploit this via malicious DHCP server to corrupt heap memory on client machines, resulting in a denial of service or potential code execution." According to the bug description, systemd-networkd "contains a DHCPv6 client which is written from scratch and can be spawned automatically on managed interfaces when IPv6 router advertisements are received."

OneHundredAndTen shared this article from the Register: In addition to Ubuntu and Red Hat Enterprise Linux, systemd has been adopted as a service manager for Debian, Fedora, CoreOS, Mint, and SUSE Linux Enterprise Server. We're told RHEL 7, at least, does not use the vulnerable component by default.

Systemd creator Leonard Poettering has already published a security fix for the vulnerable component -- this should be weaving its way into distros as we type. If you run a systemd-based Linux system, and rely on systemd-networkd, update your operating system as soon as you can to pick up the fix when available and as necessary.

Python

Twelve Malicious Python Libraries Found and Removed From PyPI (zdnet.com) 36

An anonymous reader writes: A software security engineer has identified 12 Python libraries uploaded on the official Python Package Index (PyPI) that contained malicious code. The 12 packages used typo-squatting in the hopes a user would install them by accident or carelessness when doing a "pip install" operation for a mistyped more popular package, like Django (ex: diango).

Eleven libraries would attempt to either collect data about each infected environment, obtain boot persistence, or even open a reverse shell on remote workstations. A twelfth package, named "colourama," was financially-motivated and hijacked an infected users' operating system clipboard, where it would scan every 500ms for a Bitcoin address-like string, which it would replace with the attacker's own Bitcoin address in an attempt to hijack Bitcoin payments/transfers made by an infected user.

54 users downloaded that package -- although all 12 malicious packages have since been taken down.

Four of the packages were misspellings of django -- diango, djago, dajngo, and djanga.
Space

NASA Revives Hubble Space Telescope After Three-Week Mechanical Failure (nasa.gov) 25

"NASA's Hubble Space Telescope returned to normal operations late Friday, Oct. 26, and completed its first science observations on Saturday, Oct. 27 at 2:10 AM EDT," NASA reports. The observations were of the distant, star-forming galaxy DSF2237B-1-IR and were taken in infrared wavelengths with the Wide Field Camera 3 instrument. The return to conducting science comes after successfully recovering a backup gyroscope, or gyro, that had replaced a failed gyro three weeks earlier. A gyro is a device that measures the speed at which the spacecraft is turning, which is necessary to help Hubble turn and lock on to new targets. One of Hubble's gyros failed on Oct. 5, and the spacecraft's operations team activated a backup gyro the next day. However, the backup incorrectly returned rotation rates that were far in excess of the actual rates.

Last week the operations team commanded Hubble to perform numerous maneuvers, or turns, and switched the gyro between different operational modes, which successfully cleared what was believed to be blockage between components inside the gyro that produced the excessively high rate values. Next, the team monitored and tested the gyro with additional maneuvers to make sure that the gyro was stable. The team then installed additional safeguards on the spacecraft in case the excessive rate values return, although this is not anticipated...

Hubble is now back in its normal science operations mode with three fully functional gyros. Originally required to last 15 years, Hubble has now been at the forefront of scientific discovery for more than 28 years. The team expects the telescope will continue to yield amazing discoveries well into the next decade, enabling it to work alongside the James Webb Space Telescope.

Crime

Kansas 'Swat' Perpetrator Will Now Plead Guilty To Dozens More Swat Incidents (nbcnews.com) 196

An anonymous reader quotes NBC News: The California man behind a years-long string of hoax 911 calls -- including one that ended in a Kansas man's death -- wants to plead guilty to all charges, court documents revealed. Tyler Rai Barriss, 25, intends to waive his right to trial and admit guilt to a 46-count federal indictment, according to a document he signed on Oct. 18 and was filed in U.S. District Court on Wednesday. Barriss faces up to life behind bars for his dozens of acts of "swatting" -- calling police to falsely report a serious crime, in hopes of drawing a massive response to the home of an unsuspecting target.... According to the court records, Barriss will admit to dozens of "swatting" incidents all over America between 2015 and the end of 2017, The false alarms connected to Barriss happened in Ohio, Nevada, Illinois, Indiana, Virginia, Texas, Arizona, Massachusetts, MIssouri, Maine, Pennsylvania, New Mexico, Indiana, Michigan, Florida, Connecticut and New York.
Barriss performed SWATs if clients sent him $10 over PayPal -- occasionally demanding "upwards of $50," according to a new (possibly pay-walled) article on Wired. A Call of Duty player hired Barriss to SWAT a teammate who'd caused them to lose a $1.50 wager, but his intended target supplied a false address across town which resulted in the fatal police shooting.

Both gamers are now "awaiting trial on lesser charges," reports NBC.
Businesses

Authors of Controversial 'Seattle Minimum Wage' Study Revise Their Conclusions (bloombergquint.com) 290

Seattle's increase in the minimum wage "brought benefits to many workers employed at the time, while leaving few employed workers worse off," reports the New York Times -- citing a new study by the same researchers who'd claimed last year that workers were hurt by the wage increase.

"The dire warnings about minimum-wage increases keep proving to be wrong," argues a Bloomberg columnist, in an article shared by gollum123: The authors behind an earlier study predicting a negative impact have all-but recanted their initial conclusions. However, the authors still seem perplexed about why they went awry in the first place.... The increase was an "economic death wish" that was going to tank the expansion and kill jobs, according to the sages at conservative think tanks... Despite their dire forecasts, not only were new restaurants not closing, they were in fact opening; employment in food services and drinking establishments has soared...

As we noted in 2017, the study's fatal flaw was that its analysis excluded large multistate businesses with more than one location. When thinking about the impact of raising minimum wages, one can't simply omit most of the biggest minimum-wage employers in the region, such as McDonald's and other fast-food chains, or Wal-Mart and other major retailers... There were two other glaring defects in the first study that are worth mentioning. The first is that its findings contradicted the vast majority research on minimum wages. As was demonstrated back in 1994 by economists Alan Krueger and David Card, modest, gradual wage increases have not been shown to reduce employment or hours worked in any significant way. Ignoring that body of research without a very good reason made the initial University of Washington study questionable at best. Second, there potentially is a problem with having a lead researcher -- economist Jacob Vigdor, whose affiliations among others include the right-leaning Manhattan Institute -- whose impartiality is open to question.
Long-time Slashdot reader Martin S. writes that "When the UK introduced the minimum wage we had the same doom and gloom scenarios," adding that "the reality was very different." He argues that increasing the minimum wage "increased productivity so business did not suffer, reduced government spending on benefits, and increased the the velocity of money improving the overall economy.

"It had no measurable effect on unemployment."
Ubuntu

Canonical Releases Statistics Showing Adoption of Snap Packages (neowin.net) 62

Canonical is applauding what it calls "exceptional adoption" of snaps -- and has shared some new statistics about its whole "Snappy" software deployment and package management system. Long-time Slashdot reader AmiMoJo shared this article from Neowin: snaps are seeing 100,000 installs every day on cloud, server, container, desktop and on IoT devices, which works out to around three million installs each month. Of course, these statistics don't only take into account snap installs on Ubuntu, but other distributions too. Canonical said that snaps are supported on 41 Linux distributions including Ubuntu, Debian, Linux Mint, Arch Linux, Fedora, and many more...

Snap packages first launched alongside Ubuntu 16.04 which was released in 2016. They have several benefits over typical Linux packages, for example, their dependencies are bundled into the package making them easy to install, they get automatic updates and can be rolled back by the maintainer if issues arise, and they're sandboxed, giving the user more security.

Education

With Few US Students Taking CS Classes, Code.org 'Scales Back' Funding For CS Education (acm.org) 162

"In 2012, most CS teacher professional development was paid for by the National Science Foundation or Google." And in the years that followed, 80,000 primary and secondary school teachers received opportunities to learn how to teach computer science without paying any fees -- thanks to tech-bankrolled Code.org.

But is anyone taking the classes? Slashdot reader theodp quotes a Communications of the ACM post by University of Michigan professor Mark Guzdial: In 2013, Code.org began, and they changed the face of CS education in the United States . It started out as just a video (linked here, seen over 14 million times), and grew into an organization that created and provided curriculum, offered teacher professional development, and worked with states and districts around public policy initiatives. A recent report from Code.org showed that 44 states have enacted public policies to promote computing education in the five years from 2013 to 2018, and much of that happened through Code.org's influence....

Now, Code.org has announced that they are starting to scale back their funding, which begins a multi-year transition to shift the burden of paying for teacher professional development to the local regions.... The only question is whether it's too soon. Will local regions step up and demonstrate that they value computer science by paying for it...? I'd guess that many states have between 40% and 70% of their high schools now offering computer science. However, even though many schools offer computer science, there are still few students taking computer science.

Indiana reported that only 0.4% of Indiana high school students had enrolled in their most popular course. Meanwhile in one region in Texas, 54 of 159 high schools offer computer science, yet only 2.3% of their students have ever taken a computer science class. But of course, there's another issue.

"If Code.org (or NSF or Google) are paying for all the development of CS teachers, then the districts don't get to say, 'In our community we care about this and we care less about that.' The U.S. education system is organized around the local regions calling the shots, setting the priorities, and deciding what they want teachers to teach."
Government

Morocco Decides To Scrap Seasonal Time Changes (bbc.com) 95

An anonymous reader quotes a report from the BBC: Morocco has decided to scrap winter time and will instead keep its clocks at summer time, GMT+1, all year around. Greenwich Mean Time (GMT) is the time measured on the Earth's zero degree line of longitude, or meridian. The announcement comes less than two days before the clocks would have gone back by one hour on Sunday. Avoiding the switch would save "an hour of natural light", Administrative Reform Minister Mohammed Ben Abdelkader told Maghreb Arabe Press. The north African nation joins a number of others, mainly in Africa and Asia, which do not use daylight saving.
Mars

Mysterious White Cloud Hangs Over Martian Volcano (vice.com) 59

Last month, the European Space Agency's Mars Express orbiter spotted a white cloud suspended over the western slope of Arsia Mons, an enormous volcano near the red planet's equator. The 930-mile-long cloud looks like the kind of volcanic plumes huffed out by Earth's active volcanoes -- but it's not; "Arsia Mons is long extinct -- its last eruption is estimated to have occurred around 50 million years ago," reports Motherboard. From the report: The volcano still plays a role in shaping the water-ice cloud, though, along with atmospheric dust levels and the Martian seasons. With its 12-mile-high peak and diameter of nearly 400 miles, Arsia Mons is 30 times more voluminous than the largest volcanoes on Earth. Its humongous bulk condenses and cools air currents as they pass over the summit, creating this âoeorographic cloudâ -- a nephologic formation that tend to form over leeward (downwind) slopes -- on the western flank of the volcano.
Desktops (Apple)

Apple Expected To Announce iPad Pro With USB-C Next Week (bloomberg.com) 130

Bloomberg highlights all the big announcements expected to be made next week at Apple's October hardware event, such as an iPad Pro with a USB-C port instead of a Lightning port, a MacBook Air successor, and a new Mac Mini. From the report: The update to the iPad Pro will be the most significant in the product's history. The device was originally launched in 2015 in part as a counter-measure to Microsoft's Surface Pro, which gained a following with business users seeking large tablets with support for attachable keyboards and styluses. The iPad Pro models, which have larger screens, better cameras, and faster processors, are more expensive, which has sustained revenue growth. [Some of the new features, according to people familiar with the plans, include a nearly edge-to-edge display with slimmer bezels, a USB-C connector, Face ID, Animojis, a faster processor (variant of the A12 Bionic chip), a custom Apple graphics chip, and an updated Apple Pencil.]

For the Mac, Apple is planning its first wide-ranging upgrades since June 2017. The MacBook Air and Mac mini, a small desktop machine without a screen, have gone several years without notable changes. This, combined with interest in larger smartphones and competing PCs, led Apple to report the fewest Mac sales since 2010 in its fiscal third quarter. [Apple is reportedly planning a new entry-level laptop to replace the aging MacBook Air. It's expected to have a higher-resolution 13-inch screen, as well as slimmer bezels around the display. The Mac mini will have new processors and features for professional users. Apple's also working on refreshed iMacs, iMac Pros, and 12-inch MacBooks with faster processors, and at least some of these updates could be ready for the October launch.]
The event's theme is "making," and it will take place in New York City on Tuesday at 10:00am EST.
Medicine

FDA Approves First New Flu Drug In 20 Years (popsci.com) 39

An anonymous reader quotes a report from Popular Science: The Food & Drug Administration just announced that they had approved the aptly-named Xofluza, the first new antiviral drug in two decades, to help alleviate the symptoms of a flu infection. The reason Xofluza got a priority review from the FDA is that it works through a different mechanism than Tamiflu. Both are antivirals, meaning they prevent the replication of the virus, but they work at different stages in that process. First, a quick primer on how viruses infect you: a virus is basically a packet of genetic material that injects itself into a cell and hijacks the cell's normal replication machinery, forcing it to produce millions of copies of the virus. A protein called viral neuraminidase allows those copies to exit the cell and go infect new parts of your body. Most of our effective antivirals are neuraminidase inhibitors -- the virus can still replicate, but it's prevented from escaping.

Xofluza works by preventing the viral replication in the first place. It blocks viral polymerase, an enzyme that helps make copies of the invading genetic material. This doesn't necessarily make it better or more effective -- the FDA notes that early trials suggest it's about as effective as Tamiflu -- but as the FDA Commissioner Scott Gottlieb pointed out in a press release, "Having more treatment options that work in different ways to attack the virus is important because flu viruses can become resistant to antiviral drugs."

Bitcoin

Chinese Court Rules Bitcoin Should Be Protected As Property (coindesk.com) 51

A Chinese court has ruled that despite the country's central bank's ban on cryptocurrency trading, bitcoin should be legally protected as a property with economic values. CoinDesk reports: The Shenzhen Court of International Arbitration published a case analysis on Thursday via WeChat, detailing its ruling on a recent economic dispute that involved a business contract relating to possession and transfer of crypto assets. According to the case analysis, the unnamed plaintiff signed a contract agreement with the defendant, which allowed the latter to trade and manage a pool of cryptocurrencies on the plaintiff's behalf. However, the plaintiff said the defendant failed and refused to return the cryptocurrencies after an agreed deadline. As a result, they brought the case to the arbitrator, seeking the return of the assets with interest. The court concluded that, whether bitcoin is a legal tender or not, does not have an impact on the fact that bitcoin ownership should be protected legally based on China's contract law, adding: "Bitcoin has the nature of a property, which can be owned and controlled by parties, and is able to provide economic values and benefits."
Google

Google's Smart City Dream Is Turning Into a Privacy Nightmare (engadget.com) 61

schwit1 shares a report from Engadget: Sidewalk Labs, an Alphabet division focused on smart cities, is caught in a battle over information privacy. The team has lost its lead expert and consultant, Ann Cavoukian, over a proposed data trust that would approve and manage the collection of information inside Quayside, a conceptual smart neighborhood in Toronto. Cavoukian, the former information and privacy commissioner for Ontario, disagrees with the current plan because it would give the trust power to approve data collection that isn't anonymized or "de-identified" at the source. "I had a really hard time with that," she told Engadget. "I just couldn't... I couldn't live with that."

Cavoukian isn't the first privacy expert to abandon the Quayside project. Saadia Muzaffar, founder of TechGirls Canada, left the Digital Strategy Advisory Panel earlier this month. In a resignation letter, she said Waterfront Toronto had shown "apathy and [an] utter lack of leadership regarding shaky public trust and social license." The advisory panel was attended "in good faith," she said, but showed "a blatant disregard for resident concerns about data." These disagreements will add to the concerns of Torontonians. Sidewalk Labs still has time to address these issues and create a master plan that will be accepted by everyone. If the company continues to lose public trust, though, there's a good chance residents and government officials will make up their minds and reject the plan before reading the first page.

Microsoft

Microsoft Closes Its $7.5 Billion Purchase of GitHub (techcrunch.com) 87

Microsoft has official closed its acquisition of GitHub, the Git-based code sharing and collaboration service with 31 million developers. "The Redmond, WA-based software behemoth first said it would acquire GitHub for $7.5 billion in stock in June of this year, and after the acquisition closed it would continue to run it as an independent platform and business," reports TechCrunch. From the report: The acquisition is yet another sign of how Microsoft has been doubling down on courting developers and presenting itself as a neutral partner to help them with their projects. That is because, despite its own very profitable proprietary software business, Microsoft also has a number of other businesses -- for example, Azure, which competes with AWS and Google Cloud -- that rely heavily on it being unbiased towards one platform or another. And GitHub, Microsoft hopes, will be another signal to the community of that position. In that regard, it will be an interesting credibility test for the companies. Nat Friedman, previously the CEO of Xamarin, will be the CEO of GitHub on Monday. He says the site will be run as an independent platform and business.

"We will always support developers in their choice of any language, license, tool, platform, or cloud," he writes, noting that there will be more tools to come. "We will continue to build tasteful, snappy, polished tools that developers love," he added.
Security

Trivial Bug In X.Org Server Gives Root Permissions On Linux, BSD Systems (bleepingcomputer.com) 114

An anonymous reader quotes a report from Bleeping Computer: A vulnerability that is trivial to exploit allows privilege escalation to root level on Linux and BSD distributions using X.Org server, the open source implementation of the X Window System that offers the graphical environment. The flaw is now identified as CVE-2018-14665 (credited to security researcher Narendra Shinde). It has been present in xorg-server for two years, since version 1.19.0 and is exploitable by a limited user as long as the X server runs with elevated permissions.

An advisory on Thursday describes the problem as an "incorrect command-line parameter validation" that also allows an attacker to overwrite arbitrary files. Privilege escalation can be accomplished via the -modulepath argument by setting an insecure path to modules loaded by the X.org server. Arbitrary file overwrite is possible through the -logfile argument, because of improper verification when parsing the option. Apart from OpenBSD, other operating systems affected by the bug include Debian and Ubuntu, Fedora and its downstream distro Red Hat Enterprise Linux along with its community-supported counterpart CentOS.

Slashdot Top Deals