Google

Bitdefender Disables Anti-Exploit Monitoring in Chrome After Google Policy Change (bleepingcomputer.com) 69

secwatcher shares a report: Last week we reported that Chrome has started displaying alerts more often that suggest users remove programs that are considered incompatible applications with Chrome because they inject code into the browser's processes. These alerts are displayed by Chrome after the browser crashes and suggest the user remove the listed programs because "this application could prevent Chrome from working properly." One of the programs that a lot of users have seen listed in these alerts and is suggested to be removed is the Bitdefender antivirus program as shown above. Having a well known company like Google telling users to remove a security solution is a problem as these programs are important for many users to have installed on their computers in order to protect them from malware, unwanted programs, and malicious websites. Due to these alerts and their suggestion to remove the antivirus software, Bogdan Botezatu, a senior e-threat analyst for Bitdefender, has told Bleeping Computer that as of August 20th, Bitdefender is no longer monitoring Chrome 66 and later with their anti-exploit technology.
Communications

IRC Turns 30 (www.oulu.fi) 157

IRC (Internet Relay Chat) was born at the Department of Information Processing Science of the University of Oulu 30 years ago. Taking some time out of his summer job, Jarkko Oikarinen developed the internet chat system. For the last several years, Oikarinen has been working at Google, overseeing the development of several communication services. Though several mainstream services have ended support for IRC over the years, the system is still in existence and used by many.
Communications

Hackers Stole Personal Data of 2 Million T-Mobile Customers (vice.com) 56

On late Thursday, T-Mobile revealed that hackers stole some of the personal data of 2 million people in a new data breach. From a report: In a brief intrusion, hackers stole "some" customer data including names, email addresses, account numbers, and other billing information. The good news is that they did not get credit card numbers, social security numbers, or passwords, according to the company. In its announcement, T-Mobile said that its cybersecurity team detected an "unauthorized capture of some information" on Monday, Aug. 20. A company spokesperson told me that the breach affected "about" or "slightly less than" 3% of its 77 million customers.
Software

Linux Apps Are Not Coming To Many Still-Supported Chromebooks (betanews.com) 61

While we know that Linux app support is coming to a range of Chromebooks from Lenovo, Acer, Dell and others, a post on the Chromium Gerrit reveals that devices running Linux 3.14 or older will miss out. BetaNews: Chrome OS is able to run Linux apps through the use of containers which help to keep the rest of the operating system safe from harm. As container support requires features that are only found in more recent versions of the Linux kernel, it means that many Chromebooks -- whose kernels are usually not updated -- will not be able to run Linux apps.

Here's the full list of Chromebooks that won't be getting the Linux love: AOpen Chromebase Mini (Feb 2017; tiger, veyron_pinky), AOpen Chromebox Mini (Feb 2017; fievel, veyron_pinky), ASUS Chromebook C201 (May 2015; speedy, veyron_pinky), Acer C670 Chromebook 11 (Feb 2015; paine, auron), Acer Chromebase 24 (Apr 2016; buddy, auron), Acer Chromebook 15 (Apr 2015; yuna, auron), Acer Chromebox CXI2 (May 2015; rikku, jecht), Asus Chromebit CS10 (Nov 2015; mickey, veyron_pinky), Asus Chromebook Flip C100PA (Jul 2015; minnie, veyron_pinky), Asus Chromebox CN62 (Aug 2015; guado, jecht), Dell Chromebook 13 7310 (Aug 2015; lulu, auron), Google Chromebook Pixel (Mar 2015; samus), Lenovo ThinkCentre Chromebook (May 2015; tidus, jecht), Toshiba Chromebookk 2 (Sep 2015; gandof, auron).

Security

North Korean Hackers Hit Cryptocurrency Exchange With macOS Malware (securityweek.com) 100

A North Korea-linked hacking group, dubbed Lazarus, deployed malware for macOS in an effort to infiltrate cryptocurrency exchanges. "In one of the attacks, which Kaspersky refers to as Operation AppleJeus, the group tricked an unsuspecting employee to download a trojanized cryptocurrency trading application that covertly downloaded and installed the Fallchill malware," reports SecurityWeek. Their malware was designed to target macOS in addition to Windows, marking the first time Lazarus has been observed using malware for Apple's OS, according to Kaspersky. The malware was reportedly pushed via an update. Slashdot reader asjk writes: The legitimate-looking application is called Celas Trade Pro and comes from Celas Limited. It's an all-in-one style cryptocurrency trading program which installs malicious code via an update. "... [the program] was seen running the Updater.exe module, which would collect system information and send it back to the server in the form of a GIF image," reports SecurityWeek. "Based on the server's response, the updater either keeps quiet or extracts a payload with base64 and decrypts it using RC4 with another hardcoded key to retrieve an executable file."
Operating Systems

Windows 95 Is Now An App You Can Download and Install On macOS, Windows, and Linux (theverge.com) 183

Slack developer Felix Rieseberg has made Windows 95 into an electron app that you can run on macOS, Windows, and Linux. The source code and app installers are available on GitHub. According to The Verge, "apps like Wordpad, phone dialer, MS Paint, and Minesweeper all run like you'd expect," but "Internet Explorer isn't fully functional as it simply refused to load pages." From the report: The app is only 129MB in size and you can download it over at Github for both macOS and Windows. Once it's running it surprisingly only takes up around 200MB of RAM, even when running all of the old Windows 95 system utilities, apps, and games. If you run into any issues with the app you can always reset the Windows 95 instance inside the app and start over again. Enjoy this quirky trip down memory lane.
Businesses

Apple Hired Scores of Ex-Tesla Employees This Year (cnbc.com) 108

According to CNBC, citing current and former Tesla employees and LinkedIn, Apple has hired scores of employees from Tesla since late 2017, including manufacturing, security and software engineers, as well as supply chain experts. The report mentions that they're hiring Tesla employees not just for the company's Project Titan self-driving car project, but for its other products too. From the report: In 2018 so far, LinkedIn data shows Apple has hired at least 46 people who worked at Tesla directly before joining the consumer electronics juggernaut. Eight of these were engineering interns. This year Apple has also hired former Tesla Autopilot, QA, Powertrain, mechanical design and firmware engineers, and several global supply chain managers. Some employees joined directly from Tesla, while others had been dismissed or laid off before joining Apple. Some ex-Tesla employees who joined Apple this year have not yet updated their public social media profiles with their new career info. That includes Apple's most noteworthy hire, Doug Field, Tesla's former Senior Vice President of Engineering. Tesla disputes CNBC's report, saying that voluntary attrition has decreased by one-third over the last twelve months, and that it has recently added talent from Apple and other companies. Regarding competition with Apple for talent, a Tesla spokesperson said, "We wish them well. Tesla is the hard path. We have 100 times less money than Apple, so of course they can afford to pay more. We are in extremely difficult battles against entrenched auto companies that make 100 times more cars than we did last year, so of course this is very hard work."
Beer

No Healthy Level of Alcohol Consumption, Says Major Study (theguardian.com) 590

An anonymous reader quotes a report from The Guardian: Even the occasional drink is harmful to health, according to the largest and most detailed research carried out on the effects of alcohol, which suggests governments should think of advising people to abstain completely. The uncompromising message comes from the authors of the Global Burden of Diseases study, a rolling project based at the University of Washington, in Seattle, which produces the most comprehensive data on the causes of illness and death in the world. Alcohol, says their report published in the Lancet medical journal, led to 2.8 million deaths in 2016. It was the leading risk factor for premature mortality and disability in the 15 to 49 age group, accounting for 20% of deaths. The study was carried out by researchers at the Institute of Health Metrics and Evaluation (IHME), who investigated levels of alcohol consumption and health effects in 195 countries between 1990 to 2016. They used data from 694 studies to work out how common drinking was and from 592 studies including 28 million people worldwide to work out the health risks. According to the report, "27.1% of cancer deaths in women and 18.9% in men over 50 were linked to their drinking habits." The biggest causes of death linked to alcohol in younger people were tuberculosis (1.4% of deaths), road injuries (1.2%), and self-harm (1.1%).

"Worldwide we need to revisit alcohol control policies and health programs, and to consider recommendations for abstaining from alcohol," said the report's senior author, Professor Emmanuela Gakidou. "These include excise taxes on alcohol, controlling the physical availability of alcohol and the hours of sale, and controlling alcohol advertising. Any of these policy actions would contribute to reductions in population-level consumption, a vital step toward decreasing the health loss associated with alcohol use."
Businesses

Comcast/Charter Lobby Asks FTC To Preempt State Broadband Regulations (arstechnica.com) 80

Lobby groups on behalf of Comcast and Charter are asking the FTC to preempt state and local broadband regulations. "In comments filed this week, cable industry lobby group NCTA told the FTC that 'there is plainly no reasonable basis in today's marketplace for singling out ISPs for unique regulatory burdens,'" reports Ars Technica. "The FTC should let 'market forces' prevent bad behavior and avoid specific net neutrality or privacy regulation for the broadband industry, the lobby group said." From the report: The comments were filed in an FTC proceeding titled "Competition and Consumer Protection in the 21st Century." The FTC is planning to hold hearings on the communications industry, the FTC's enforcement processes, and other competition and consumer protection topics. "The FTC should ensure that the Internet is subject to uniform, consistent federal regulations, including by issuing guidance explicitly setting forth that inconsistent state and local requirements are preempted," the NCTA wrote.

The FTC should endorse and reinforce the FCC's ruling by issuing guidance to state attorneys general and consumer protection authorities reaffirming that they are bound by FCC and FTC precedent in this arena," NCTA argued. NCTA's filing focused mostly on potential privacy regulation, saying that the FCC should continue its "technology-neutral approach to privacy and data security." Net neutrality concerns are best addressed by existing antitrust laws, the filing said.

Google

Google Removes Accounts Tied To Iran-Led Misinformation Campaign (engadget.com) 87

In a blog post, Google shared an update regarding its efforts to combat state-sponsored phishing attacks and to remove accounts associated with an influence operation linked to Iran. Engadget reports: The company said that in recent months, it has detected and blocked state-sponsored groups from targeting political campaigns, journalists, activists and academics with phishing attempts. Google has also been working with the cybersecurity group FireEye, which has been providing Google with information on an Iran-based misinformation operation. FireEye identified three email accounts, three YouTube channels and three Google+ accounts linked to that operation, which Google subsequently took down.

In conjunction to the intelligence provided by FireEye, Google also investigated other suspicious groups linked to Iran. The company identified and removed 39 YouTube channels, six Blogger blogs and 13 Google+ accounts it believed to be connected to the Islamic Republic of Iran Broadcasting. Relevant videos on the now-terminated YouTube channels had garnered 13,466 views in the U.S.
Facebook and Twitter were also made aware of the Iranian operation. Twitter announced that it suspended 284 accounts believed to have originated from Iran for "engaging in coordinated manipulation." Meanwhile, Facebook said it removed "652 pages that it says were linked to a campaign originating in Iran, as well as an unspecified number of accounts liked to Russian military intelligence services," reports Engadget.
Businesses

Netflix Is the Latest Company To Try Bypassing Apple's App Store (marketwatch.com) 71

Netflix is testing a way for users to register and pay for the streaming service while bypassing Apple's app store and hefty commission fees. MarketWatch reports: Netflix is looking into a new sign-up approach where users in some countries are no longer able to register for streaming service. They are being redirected to the mobile web version of the app and asked to enter payment details with Netflix directly. The test is running in 33 countries, not including the U.S., through the month of September, according to TechCrunch. This comes just months after Netflix in May made billing through Google Pay unavailable to new customers, though current subscribers that pay via Google Play can continue to do so until they cancel their accounts.
Communications

The Consequences of Indecency (techcrunch.com) 502

Ron Wyden, a senior U.S. Senator from Oregon, argues there should be consequences for internet companies that refuse to remove hate speech from their platforms. An anonymous reader shares an excerpt from a report Wyden wrote via TechCrunch: I wrote the law that allows sites to be unfettered free speech marketplaces. I wrote that same law, Section 230 of the Communications Decency Act, to provide vital protections to sites that didn't want to host the most unsavory forms of expression. The goal was to protect the unique ability of the internet to be the proverbial marketplace of ideas while ensuring that mainstream sites could reflect the ethics of society as a whole. In general, this has been a success -- with one glaring exception. I never expected that internet CEOs would fail to understand one simple principle: that an individual endorsing (or denying) the extermination of millions of people, or attacking the victims of horrific crimes or the parents of murdered children, is far more indecent than an individual posting pornography.

Social media cannot exist without the legal protections of Section 230. That protection is not constitutional, it's statutory. Failure by the companies to properly understand the premise of the law is the beginning of the end of the protections it provides. I say this because their failures are making it increasingly difficult for me to protect Section 230 in Congress. Members across the spectrum, including far-right House and Senate leaders, are agitating for government regulation of internet platforms. Even if government doesn't take the dangerous step of regulating speech, just eliminating the 230 protections is enough to have a dramatic, chilling effect on expression across the internet. Were Twitter to lose the protections I wrote into law, within 24 hours its potential liabilities would be many multiples of its assets and its stock would be worthless. The same for Facebook and any other social media site. Boards of directors should have taken action long before now against CEOs who refuse to recognize this threat to their business.
In an interview with Recode, Wyden said that platforms should be punished for hosting content that goes against "common decency." "I think what the Alex Jones case shows, we're gonna really be looking at what the consequences are for just leaving common decency in the dust," Wyden told Recode's Kara Swisher. "...What I'm gonna be trying to do in my legislation is to really lay out what the consequences are when somebody who is a bad actor, somebody who really doesn't meet the decency principles that reflect our values, if that bad actor blows by the bounds of common decency, I think you gotta have a way to make sure that stuff is taken down."
Sony

Nikon Strikes Back At Sony With First Full-Frame Mirrorless Cameras (theverge.com) 90

After weeks of teases, Nikon has unveiled its first brand new full-frame mirrorless cameras to challenge Sony in the mirrorless market. As The Verge notes, the Z7 and Z6 are "basically a tit-for-tat response to Sony's A7III and A7RIII, and Nikon is aggressively going several steps beyond what Canon has attempted with mirrorless cameras." From the report: The Z7, coming on September 27th, has a 45.7-megapixel sensor, 493 focus points, and 64-25600 ISO. The Z6 will follow in "late November" with a 24.5-megapixel sensor, 273 focus points, and 100-51200 ISO. The cameras bring with them an all-new Z mount system that will debut with a 24-70mm f/4 "kit" lens. With the lens bundled, the Z7 will run $3,999.95, with the Z6 at $2,599.95. The lens runs $999.95 on its own and has a minimum focus distance of under 12 inches across its zoom range. A 35mm f/1.8 prime ($845.95) will be available at launch as well. There's also a 50mm f/1.8 prime ($599.95) coming in October that Nikon tells me has astounded some of its engineers with sharpness and edge-to-edge clarity. The company is releasing a $250 FTZ adapter that will allow these cameras to support Nikon's F-mount lenses. The adapter offers "full compatibility" (support for autofocus and auto exposure) with over 90 lenses. "Nikon is promising basic compatibility with approximately 360 existing F lenses for those that don't mind handling focus and exposure," reports The Verge.
Privacy

Millions of Texas Voter Records Exposed Online (techcrunch.com) 79

A folder containing an estimated 14.8 million Texas voter records was left on an unsecured server without a password. Considering Texas has 19.3 million registered voters, this leak is very substantial. The file was discovered by a New Zealand-based data breach hunter who goes by the pseudonym Flash Gordon. TechCrunch reports: It's not clear who owned the server where the exposed file was found, but an analysis of the data reveals that it was likely originally compiled by Data Trust, a Republican-focused data analytics firm created by the GOP to provide campaigns with voter data. The file -- close to 16 gigabytes in size -- contained dozens of fields, including personal information like a voter's name, address, gender and several years' worth of voting history, including primaries and presidential elections. It's not known exactly when the data was compiled, but an analysis of the data suggests it was prepared in time for the 2016 presidential election. It's also not known if the file is a subset of the 198 million records leak last year -- or if it's a standalone data set.
Microsoft

Microsoft Hit With US Bribery Probe Over Deals in Hungary (wsj.com) 52

Microsoft is being investigated by U.S. authorities over potential bribery and corruption related to software sales in Hungary, WSJ reported Thursday. From a report: The investigation follows a series of similar probes into Microsoft business partners that surfaced in 2013 in five other countries. Microsoft made a push earlier this decade to expand in emerging markets, as well as smaller, middle-income countries like Hungary. In some cases, those bets have turned into legal and reputational challenges. The U.S. Justice Department and the Securities and Exchange Commission are probing how Microsoft sold software such as Word and Excel to middleman firms in Hungary that then sold those products to government agencies there in 2013 and 2014, according to these people. Microsoft sold some of its products to these intermediaries at steep discounts, and then these firms sold the products to the Hungarian government at closer to full price, these people said.

Slashdot Top Deals