Security

Cryptocurrency App Mocks Competitor For Getting Hacked. Gets Hacked 4 Days Later (zdnet.com) 30

An anonymous reader writes: A hacker going online by the pseudonym of "aabbccddeefg" has exploited a vulnerability to steal over 44,400 EOS coins ($220,000) from a blockchain-based betting app. The hack targeted a blockchain app that lets users bet with EOS coins in a classic dice game.

The entire incident is quite hilarious because four days before it happened, the company behind the app was boasting on Twitter that every other dice betting game had been hacked and lost funds. "DEOS Games, a clone and competitor of our dice game, has suffered a severe hack today that drained their bankroll," the company said in a now deleted tweet. "As of now every single dice game and clone site has been hacked. We have the biggest bankroll, the best developers, and a superior UI. Play on."

While the hack is somewhat the definition of karma police, it is also quite funny because the hacker himself didn't really care about hiding his tracks or laundering the stolen funds. "So this guy hacks EOSBET and what does he do? Play space invaders. I'm not even kidding...," a user analyzing the hacker's account said.

Privacy

Do Data Breaches Affect Stock Performance in the Long Run? (zdnet.com) 32

Trailrunner7 tipped us off to this story on ZDNet: A multi-year study on the stock price evolution for breached companies reveals that data breaches have a long-term impact on a company's stock price, even if it's somewhat minimal. The study, carried out by the research team behind the CompariTech web portal, looked only at companies listed on the New York Stock Exchange that suffered and publicly disclosed breaches of one million records and over in the past three years. In total, the list included 28 companies, such as Apple, Adobe, Anthem, Community Health Systems, Dun & Bradstreet, eBay, Equifax, Experian, Global Payments, Home Depot, Health Net, Heartland Payment Systems, JP Morgan Chase, LinkedIn, Monster, T-Mobile, Sony, Staples, Target, TJ Maxx, Under Armour, Vodafone, and Yahoo. "In the long term, breached companies underperformed the market," the CompariTech team concluded in their report.

"After 1 year, Share price grew 8.53% on average, but underperformed the NASDAQ by -3.7%. After 2 years, average share price rose 17.78%, but underperformed the NASDAQ by -11.35%. And after three years, average share price is up by 28.71% but down against the NASDAQ by -15.58%." Study authors noted that the impact of data breaches likely diminished over time, but the damage was still visible in the stock's NASDAQ performance indicator even after three years, in some cases. Although other factors also weighed into how a stock performed, the fact that all of the analyzed breached companies had a poor performance cannot be ignored.

Finance and payment companies suffered the largest drops in their stock prices after a data breach -- with the drops being larger when the breached data included "highly sensitive" info like credit card and social security numbers.
Communications

Some Northern California Cities Are Blocking Deployment of 5G Towers (techcrunch.com) 187

Hkibtimes tipped us off to some interesting news from TechCrunch: The Bay Area may be the center of the global technology industry, but that hasn't stopped one wealthy enclave from protecting itself from the future. The city council of Mill Valley, a small town located just a few miles north of San Francisco, voted unanimously late last week to effectively block deployments of small-cell 5G wireless towers in the city's residential areas. Through an urgency ordinance, which allows the city council to immediately enact regulations that affect the health and safety of the community, the restrictions and prohibitions will be put into force immediately for all future applications to site 5G telecommunications equipment in the city. Applications for commercial districts are permitted under the passed ordinance....

According to the city, it received 145 pieces of correspondence from citizens voicing opposition to the technology, compared to just five letters in support of it -- a ratio of 29 to 1. While that may not sound like much, the city's population is roughly 14,000, indicating that about 1% of the population had voiced an opinion on the matter. Blocks on 5G deployments are nothing new for Marin County, where other cities including San Anselmo and Ross have passed similar ordinances designed to thwart 5G expansion efforts over health concerns... The telecom industry has long vociferously denied a link between antennas and health outcomes, although California's Department of Public Health has issued warnings about potential health effects of personal cell phone antennas. Reduced radiation emissions from 5G antennas compared to 4G antennas would presumably further reduce any health effects of this technology.

The article concludes that restrictions like Mill Valley's "will make it nearly impossible to deploy 5G in a timely manner."
Crime

Man Jailed For Hundreds of Fake TripAdvisor Reviews (tripadvisor.com) 59

An Italian man was sentenced to nine months in jail for selling fake reviews on TripAdvisor to several hundred businesses. He'll also be fined 8,000 euros (about $9,300).

TripAdvisor had threatened businesses with a red badge icon warning travelers thatreviews had been manipulated, after which "several businesses were willing to share information to support TripAdvisor's investigations." From TripAdvisor's Insights blog:
Back in 2015, our dedicated team of fraud investigators identified a new illegal business in Italy called PromoSalento that was offering to write fake reviews for hospitality businesses... PromoSalento attempted to avoid our scrutiny by regularly changing their usernames and email addresses, but our fraud detection processes use a suite of advanced technologies to evaluate hundreds of review attributes such as IP addresses, browser types and even the screen resolution of a reviewer's device. Based on that analysis, we were able to see a trail of digital and behavioral 'breadcrumbs' that led our team straight back to PromoSalento....

Writing fake reviews on TripAdvisor has always been a violation of the law in many jurisdictions, for instance falling under the EU Unfair Commercial Practices Directive, as well as national laws relating to consumer protection, fraud and false advertising. However, this is the first time we have seen the laws being enforced to the point of securing a criminal conviction.

"As many as 16 percent of online reviews are fake, according to research by the European Parliament," reports CBS News. Yet they add that when it comes to accountability and consumer safety, many Americans believe online reviews are more effective than government oversight.
Chrome

Google Temporarily Brings Back the www In Chrome URLs -- But Should They? (digitaltrends.com) 144

An anonymous reader quotes Digital Trends: With the launch of Chrome 69, Google stunned users last week with a surprising decision to no longer display the "www" and "m" part of the URL in the Chrome search bar, but user backlash forced Google to soften its stance. Google's course reversal, although welcomed by users, is only short term, and the search giant said it will change course once again with the release of the Chrome 70 browser....

Critics have argued that by not displaying the special-case subdomains, it was harder for users to identify sites as legitimate, and the move could lead to more scams on the internet. Others go as far as questioning Google's motives for not displaying the "www" and "m" portion of a web address, and these users speculated that the move may be to disguise Google's AMP -- or Accelerated Mobile Pages -- subdomain to make it indistinguishable for the actual domain....

With the launch of Chrome 70, Google plans on hiding the 'www' portion of a web address inside the search bar, but it will continue to display the 'm' subdomain. "We are not going to elide 'm' in M70 because we found large sites that have a user-controlled 'm' subdomain," Google Chromium product manager Emily Schecter said. "There is more community consensus that sites should not allow the 'www' subdomain to be user controlled."

ZDNet notes that while Chrome's billion-plus users were surprised, "Apple's Safari likewise hides the www and m but it hasn't caused as much concern, likely because of Google's outsized influence over the web and Chrome's dominance of the browser market."

TechRepublic quotes a community feedback post that had argued that "Lying about the hostname to novices and power users alike in the name of simplifying the UI seems imprudent from a security perspective."
Graphics

Nvidia Scanner Brings One-Click Overclocking To Its GeForce RTX Graphics Cards (pcworld.com) 39

Nvidia's new "Scanner" tool for the company's newest GeForce RTX 2080 graphics cards will provide one-click overclocking. PCWorld reports: Nvidia Scanner isn't actually a tool you can download. Instead, it's an API that developers can implement, similar to how current GeForce overclocking software relies on Nvidia's NVAPI. Tom Peterson, Nvidia's director of technical marketing, says all of the major overclocking programs will implement Scanner. You simply press the Test button, and the software starts walking through your graphics card's volt frequency curve, running arithmetic tests all the while. If the overclock starts pushing too far, Nvidia Scanner will discover a math error before your card crashes. When that happens, Scanner ramps up your card's voltage and starts testing again. After about 20 minutes, Scanner will have a complete understanding of your RTX card's capabilities, and automatically generate an overclocking profile built to squeeze as much performance as possible out of it without crashing. Easy-peasy. PCWorld's Brad Chacos mentions a demonstration where "Nvidia's Tom Peterson showed Nvidia Scanner pushing the GeForce RTX 2080 -- which ships with a 1,710MHz boost clock -- all the way to 2,130MHz at 1,068mV."
Moon

SpaceX Says It Signed First Private Passenger To the Moon (nbcnewyork.com) 143

SpaceX announced Thursday that it's booked the world's first private passenger to the moon. The private aerospace company said on Twitter the unnamed traveler would board its Big Falcon Rocket (BFR) to the moon, where only 24 people have ever traveled. Only 12 of those people actually walked on the moon. NBC New York reports: SpaceX didn't reveal any details about the potentially historic voyage but said it plans to reveal the traveler's identity and more on Monday, Sept. 17. The company called the plan "an important step toward enabling access for everyday people who dream of traveling to space." Musk shared the announcement on his personal page but remained tight-lipped as well. However, when asked if the passenger was him, Musk responded with an emoji of the Japanese flag.
Science

Study Suggests BPA-Free Plastics Are Just As Harmful To Health (gizmodo.com) 84

An anonymous reader quotes a report from Gizmodo: Plastic products that boast of being "BPA-free" aren't necessarily any safer for us, suggests a new mouse study published Thursday in Current Biology. The chemicals used to replace BPA in these plastics can still leak out and affect the sperm and eggs of both male and female mice, it found. And these same effects could be happening in people. Bisphenol A, or BPA, is a chemical commonly used to create polycarbonate plastics and epoxy resins. These clear white plastics are themselves used in food and drink packaging, as well as consumer products and medical devices, while resins are used to coat metal products like canned foods. When these products degrade or are otherwise damaged (from being repeatedly heated in a microwave, for example), they can leach out BPA, exposing us to it. As a result, it's estimated that 93 percent of Americans have some level of BPA in their system.

While working on another project, the authors began seeing some but not all of their control mice, both male and female, develop reproductive problems. Though the mice had kept in cages made of polysulfone, not polycarbonate, the researchers noticed a whitish residue in some of the cages, indicating they had been damaged and were leaching chemicals. When Patricia Hunt, a researcher at the Center for Reproductive Biology at Washington State University, and her team analyzed the chemical signature of the damaged cages, they found both BPA and BPS, a bisphenol that is widely replacing BPA. The cases were polysulfone plastic, which is partly made from BPA, but it's advertised to be more heat and chemical resistant than polycarbonate and thus less likely to break down. Polysulfone isn't thought to degrade into BPS, but Hunt's team found that if certain chemical bonds in the plastic were broken in the right way, BPS could form. Following in the vein of their original experiments with BPA, Hunt's team exposed more mice to low doses of BPS, and compared their reproductive health to mice exposed to BPA and mice raised in fresh new cages, presumably free of any BPA/BPS contamination. The BPS mice had more defects in their egg and sperm cells than did the control mice, but the level of damage was similar to that seen in mice they exposed to the same dose of BPA alone.
"Though manufacturers have shied away from making explicit claims about BPA replacements being safer, Hunt noted, customers have certainly assumed that they are safer," the report notes.
AI

US Lawmakers Say AI Deepfakes 'Have the Potential To Disrupt Every Facet of Our Society' (theverge.com) 198

Yesterday, several lawmakers sent a letter to the Director of National Intelligence, Dan Coats, asking him to assess the threat posed to national security by deepfakes -- a new type of AI-assisted video editing that creates realistic results with minimal effort. The Verge reports: The letter says "hyper-realistic digital forgeries" showing "convincing depictions of individuals doing or saying things they never did" could be used for blackmail and misinformation. "As deep fake technology becomes more advanced and more accessible, it could pose a threat to United States public discourse and national security," say the letter's signatories, House representatives Adam Schiff (D-CA), Stephanie Murphy (D-FL), and Carlos Curbelo (R-FL). The trio want the intelligence community to produce a report that includes descriptions of when "confirmed or suspected" deepfakes have been produced by foreign individuals (there are no current examples of this), and to suggest potential countermeasures. In a press statement, Curbelo said: "Deep fakes have the potential to disrupt every facet of our society and trigger dangerous international and domestic consequences [...] As with any threat, our Intelligence Community must be prepared to combat deep fakes, be vigilant against them, and stand ready to protect our nation and the American people."
Businesses

Drone Startup Airware Is Shutting Down After Raising $118 Million (techcrunch.com) 38

Drone operating system startup Airware, which has appeared in a number of stories over the years, announced today that it will be shutting down immediately despite having raised $118 million from investors. " The startup ran out of money after trying to manufacture its own hardware that couldn't compete with drone giants like China's DJI," reports TechCrunch. "The company at one point had as many as 140 employees, all of which are now out of a job." From the report: Founded in 2011 by Jonathan Downey, the son of two pilots, Airware first built an autopilot system for programming drones to follow certain routes to collect data. It could help businesses check rooftops for damage, see how much of a raw material was coming out of a mine, or build constantly-updated maps of construction sites. Later it tried to build its own drones before pivoting to consult clients on how to most efficiently apply unmanned aerial vehicles. While flying high, Airware launched its own Commercial Drone Fund for investing in the market in 2015, and acquired 38-person drone analytics startup Redbird in 2016. In this pre-crypto, pre-AI boom, Airware scored a ton of hype from us and others as they tried to prove drones could be more than war machines. But over time, the software that shipped with commercial drone hardware from other manufacturers was good enough to make Airware irrelevant, and a downward spiral of layoffs began over the past two years, culminating in today's shutdown. Demonstrating how sudden the shut down is, Airware opened a Tokyo headquarters alongside an investment and partnership from Mitsubishi just four days ago. As for the employees, they "will get one week's severance, COBRA insurance until November, and payouts for unused paid time off," reports TechCrunch.
Businesses

San Francisco Gets Its First Cashierless Store (cnbc.com) 94

Last Week, San Francisco got its first completely automated cashierless store, called Standard Market. The store requires users to download their app before they can enter the 1,900-square-foot building. Once they do that, they can enter the store, grab the items they need, and walk out -- all without ever interacting with a cashier. The 27 cameras positioned on the ceiling are supposedly able to identify which items shoppers walk out with. CNBC reports: The start-up behind this operation is Standard Cognition, which has raised $11.2 million in venture capital and formed partnerships with four retail chains around the world. This first market is a prototype to showcase the technology and work on the bugs. The ambitious goal is to add the tech in 100 stores a day (each day!) by 2020. Five of the seven founders came from the Securities and Exchange Commission, where they built artificial intelligence software to detect fraud and trade violations, before starting Standard Cognition in 2017. Now these fraud experts are working to discern something equally complicated: whether I am stealing a snack. The store is very similar to Amazon's cashierless Go market, but differs in that it relies exclusively on the ceiling cameras and AI software to figure out what you're buying. "The goal is to predict, and prevent, shoplifting, because unlike Amazon's Go stores, which have a subway turnstile-like gate for entry and exit, Standard Market has an open door, and the path is clear," reports CNBC. "Once the system decides it has detected potential theft behavior, a store attendant will get a text and walk over for 'a polite conversation,' Standard Cognition's co-founder and chief operating officer, Michael Suswal, said."
Medicine

What Cardiologists Think About the Apple Watch's Heart-Tracking Feature (sfgate.com) 90

An anonymous reader quotes a report from SFGate: The newest Apple Watch can now flag potential problems with your heartbeat -- a feature that's been cleared by the Food and Drug Administration and that Apple is marking as a major achievement. But some doctors said that including heart-monitoring tools in such a popular consumer product could prompt unnecessary anxiety and medical visits. Physicians say the watch could be good for patients who have irregular heart rhythms but may not realize it. Some people who have atrial fibrillation, the condition for which the watch is screening, don't always have noticeable symptoms. In an ideal situation, someone who doesn't know they have a problem could get a warning from their watch and take that data to their doctor.

But there is also concern that widespread use of electrocardiograms without an equally broad education initiative could burden an already taxed health-care system. Heart rhythms naturally vary, meaning that it's likely that Apple Watch or any heart monitor could signal a problem when there isn't one -- and send someone running to the doctor for no reason. "People are scared; their heart scares them," John Mandrola, a cardiologist at Baptist Health in Louisville, said. "That leads to more interaction with the health-care system." An extra visit to your doctor may not sound like a bad thing, but Mandrola said it would potentially lead to another round of tests or even unnecessary treatment if there are other signs that can be misinterpreted. And doctors might wind up facing a crowd of anxious Apple Watch users getting false signals -- something physicians have already had to deal with as fitness trackers that monitor heart rates have become popular.

Communications

Why Can't More Than Four People Have a Conversation at Once? (qz.com) 75

Apparently, there exists something called the 'dinner party problem' which states that it is difficult to sustain a casual conversation that includes more than four speakers. If a fifth person were to join that conversation, so goes the theory, the conversation would quickly fission into smaller groups. Somebody looked into it, of course. From a story: The question bothered Jaimie Krems, an assistant professor of psychology at Oklahoma State University. Krems had previously studied under Robin Dunbar, the Oxford University evolutionary psychologist who theorized that cohesion in any human social group falls apart once the group reaches 150 -- a figure now known as Dunbar's number. But just as the dynamics of large groups start changing around 150, something also happens to the casual conversations of small groups once they surpass four members.

Social psychologists have noted the pattern in group conversations in research stretching back decades. There's evidence that this four-person limit on conversations has been in place for about as long as humans have been having chatting with one another. Shakespeare rarely allowed more than four speaking characters in any scene; ensemble films rarely have more than four actors interacting at once. But why do we max out at four? In a forthcoming paper in the journal Evolution and Human Behavior, Krems and Jason Wilkes offer one theory rooted in evolutionary psychology. Pairs (or "dyads," in psychology research parlance) are the essential building blocks of a society. Let's imagine a conversation between four hypothetical humans: you, Chris, Pat, and Taylor. In a four-person conversation, there are six possible pairs of people who can be talking to one another at once. you and Chris, you and Pat, you and Taylor, Chris and Pat, Chris and Taylor, and Pat and Taylor. That's three pairs you're part of, and three pairs you're not. Essentially, you have a role in influencing half of the possible conversations that could be happening in that group. If there are three people in the conversation, there are three possible pairs, only one of which excludes you. If there are five people, there are 10 possible pairs, and the majority -- six -- don't include you, which makes it harder to get your point across.

Wine

Some Linux Gamers Using Wine/DXVK To Play Blizzard's Overwatch Banned (phoronix.com) 81

Longtime Slashdot reader DrYak writes: Phoronix is reporting that multiple users who all use Wine and DXVK compatibility layers have seen their Overwatch accounts banned by Blizzard. Previously, Blizzard has stated: "playing on Linux or even a Mac while on an emulated Windows environment is not bannable." But users report on Reddit getting banned simply after testing some rendering options. Tech support has answered that they are escalating the ticket and trying to take a closer look, hoping to avoid this from happening to other Linux users. According to Phoronix, the most common explanation for the bans "is a false-positive from Blizzard's anti-cheat technology having issue with DXVK."
Cellphones

Almost Half of US Cellphone Calls Will Be Scams By Next Year, Says Report (cnet.com) 278

According to a new report from First Orion, nearly half of the mobile phone calls received in the U.S. next year will be scams. "The percentage of scam calls in U.S. mobile traffic increased from 3.7 percent last year to 29.2 percent this year, and it's predicted to rise to 44.6 percent in 2019, First Orion said in a press release Wednesday," reports CNET. From the report: The most popular method scammers use to try to get people to pick up the phone is called "neighborhood spoofing," where they disguise their numbers with a local prefix so people presume the calls are safe to pick up, First Onion said. Third-party call blocking apps may help protect consumers from known scam numbers, but they can't tell if a scammer hijacks someone's number and uses it for scam calls. "Scammers relentlessly inundate mobile phones with increasingly convincing and scary calls," said Gavin Macomber, senior vice president of marketing at First Orion, in an email statement. "Solving a problem of this magnitude requires a comprehensive, in-network carrier solution that dives deeper than third-party applications ever could by detecting and eliminating unwanted and malicious calls before they reach your phone."

Slashdot Top Deals