Security

Intel's Reworked Microcode Security Fix License No Longer Prohibits Benchmarking (theregister.co.uk) 76

An anonymous reader quotes a report from The Register: Intel has backtracked on the license for its latest microcode update that mitigates security vulnerabilities in its processors -- after the previous wording outlawed public benchmarking of the chips. The reason for Intel's insistence on a vow of silence is that -- even with the new microcode in place -- turning off hyper-threading is necessary to protect virtual machines from attack via Foreshadow -- and that move comes with a potential performance hit. Predictably, Intel's contractual omerta had the opposite effect and drew attention to the problem. "Performance is so bad on the latest Spectre patch that Intel had to prohibit publishing benchmarks," said Lucas Holt, MidnightBSD project lead, via Twitter.

In response to the outcry, Intel subsequently said it would rewrite the licensing terms. And now the fix is in. Via Twitter, Imad Sousou, corporate VP and general manager of Intel Open Source Technology Center, on Thursday said: "We have simplified the Intel license to make it easier to distribute CPU microcode updates and posted the new version here. As an active member of the open source community, we continue to welcome all feedback and thank the community." The reworked license no longer prohibits benchmarking.
Long-time Slashdot reader and open-source pioneer, Bruce Perens, first brought Intel's microcode update to our attention. In a phone interview with The Register, Perens said he approved of the change. "This is a relatively innocuous license for proprietary software and it can be distributed in the non-free section of Debian, which is where is used to be, and it should be distributable by other Linux distributions," he said. "You can't expect every lawyer to understand CPUs. Sometimes they have to have a deep conversation with their technical people."
Security

Crowdsourcing the Hunt For Software Bugs is a Booming Business -- and a Risky One (technologyreview.com) 12

The cybersecurity gig economy has expanded to hundreds of thousands of hackers, many of whom have had some experience in the IT security industry. Some still have jobs and hunt bugs in their spare time, while others make a living from freelancing. They are playing an essential role in helping to make code more secure at a time when attacks are rapidly increasing and the cost of maintaining dedicated internal security teams is skyrocketing. From a report: The best freelance bug spotters can make significant sums of money. HackerOne, which has over 200,000 registered users, says about 12 percent of the people using its service pocket $20,000 or more a year, and around 3 percent make over $100,000. The hackers using these platforms hail mostly from the US and Europe, but also from poorer countries where the money they can earn leads some to work full time on bug hunting.
Privacy

Venmo Considers Making it Harder to See What Other People Are Buying, Report Says (bloomberg.com) 32

Tap on the Venmo app on your phone, and chances are you'll greeted with a running list of payments made from one person to another for anything from brunch bills to rent payments. But the real-time ticker of strangers' spending habits could soon go away. From a report: In recent weeks, executives at PayPal, the parent company of Venmo, were weighing whether to remove the option to post and view public transactions, said a person familiar with the deliberations. It's unclear if those discussions are still ongoing, and regardless of the outcome, payments between friends would still be visible on the home feed, said the person, who asked not to be identified because the discussions are private. "Venmo is always evaluating what's best for our customers," a PayPal spokesman wrote in an emailed statement. "The safety and privacy of Venmo users and their information is always a top priority, and we do a number of things to keep our users informed and help them protect and control their privacy."
Security

How an International Hacker Network Turned Stolen Press Releases Into $100 million (theverge.com) 34

Isobel Koshiw, reporting for The Verge: At a Kiev nightclub in the spring of 2012, 24-year-old Ivan Turchynov made a fateful drunken boast to some fellow hackers. For years, Turchynov said, he'd been hacking unpublished press releases from business newswires and selling them, via Moscow-based middlemen, to stock traders for a cut of the sizable profits. Oleksandr Ieremenko, one of the hackers at the club that night, had worked with Turchynov before and decided he wanted in on the scam. With his friend Vadym Iermolovych, he hacked Business Wire, stole Turchynov's inside access to the site, and pushed the main Moscovite ringleader, known by the screen name eggPLC, to bring them in on the scheme. The hostile takeover meant Turchynov was forced to split his business. Now, there were three hackers in on the game.

Newswires like Business Wire are clearinghouses for corporate information, holding press releases, regulatory announcements, and other market-moving information under strict embargo before sending it out to the world. Over a period of at least five years, three US newswires were hacked using a variety of methods from SQL injections and phishing emails to data-stealing malware and illicitly acquired login credentials. Traders who were active on US stock exchanges drew up shopping lists of company press releases and told the hackers when to expect them to hit the newswires. The hackers would then upload the stolen press releases to foreign servers for the traders to access in exchange for 40 percent of their profits, paid to various offshore bank accounts. Through interviews with sources involved with both the scheme and the investigation, chat logs, and court documents, The Verge has traced the evolution of what law enforcement would later call one of the largest securities fraud cases in US history.

NASA

VP Pence Talks Moon Return and Mars Mission at NASA 146

Vice President Mike Pence spoke at NASA's Johnson Space Center on Thursday about the agency's plans to send humans back to the moon for the first time in almost half a century and eventually on to Mars. He said: The next Americans who set foot on the Moon will start their journey by stepping through the NASA's Orion hatch. And this extraordinary spacecraft will one day bridge the gap between our planet and the next.

The International Space Station has been an unqualified success. Soon and very soon American astronauts will return to space on American rockets launched from American soil. America will not ever abandon the critical domain of space, we will open the way for innovators and development and we will lead once again in human exploration. Our administration is working tirelessly to put an American crew aboard the lunar orbital platform before the end of 2024.
In a prepared statement, Pence added, "We're renewing our national commitment to discovery and exploration and write the next great chapter of our nation's journey into space. It's now the official policy of the US that we'll return to the Moon, put Americans on Mars and once again explore the farthest depths of outer space."
Privacy

China Sees Surge in Personal Information Up For Sale (reuters.com) 19

Personal data has become widely available in China and can be scooped up for pennies by insurance companies, banks, loan sharks, and scammers alike, according to sellers and financiers interviewed by Reuters. From a report: In May, China introduced its most comprehensive data protection laws to date, tightening restrictions on the sharing of private data held by financial institutions and other firms. "Personal information leaks are risky," said Susan Ning, a partner at the law firm King & Wood Mallesons in Beijing. "Such information can facilitate other crimes," she added. Insurers often buy numbers from shadowy online data sellers, who themselves have acquired the information illegally, according to people in the industry. Some companies illegally buy information from the department of motor vehicles, car licensing authorities, car sellers, or from police stations, said Michelle Hu, a partner at Boston Consulting Group who has been a consultant on insurance deals. By entering keywords like "personal data" or "cellphone data", in Chinese, Reuters found more than 30 groups created for the purpose of selling and buying personal information on Tencent's instant messaging service QQ and Baidu forum site Tieba.
Communications

Encrypted Communications Apps Failed To Protect Michael Cohen (fastcompany.com) 475

An anonymous reader shares a report: Within the detailed federal allegations against former Trump lawyer Michael Cohen, who pleaded guilty earlier this week to eight charges including campaign finance violations, are multiple references to texts sent by Cohen and even a call made "through an encrypted telephone application." Cohen was apparently a fan of encrypted communications apps like WhatsApp and Signal, but those tools failed to keep his messages and calls out of sight from investigators. In June, prosecutors said in a court filing the FBI had obtained 731 pages of messages and call logs from those apps from Cohen's phones. Investigators also managed to reconstruct at least 16 pages of physically shredded documents. Those logs, judging by the charging document, appear to have helped document at least Cohen's communications with officials at the National Enquirer about allegations from porn actress Stormy Daniels -- whom Cohen allegedly paid on behalf of Trump, violating campaign finance law. It's unclear if the FBI actually broke through any layers of encryption to get the data. It's possible that Cohen, who apparently at times taped conversations, stored the conversation logs in a less-than-secure way.
Media

Reality Winner Sentenced To More Than 5 Years For Leaking Info About Russia Hacking Attempts (nbcnews.com) 261

A former government contractor who pleaded guilty to leaking U.S. secrets about Russia's attempts to hack the 2016 presidential election was sentenced Thursday to five years and three months in prison. From a report: It was the sentence that prosecutors had recommended in the plea deal -- the longest sentence ever given for a federal crime involving leaks to the news media -- for Reality Winner, the Georgia woman at the center of the case. Winner was also sentenced to three years of supervised release and no fine, except for a $100 special assessment fee. The crime carried a maximum penalty of 10 years. U.S. District Court Judge J. Randal Hall in Augusta, Georgia, was not bound to follow the plea deal, but elected to give Winner the amount of time prosecutors requested. Winner, 26, who contracted for the National Security Agency, pleaded guilty in June to copying a classified report that detailed the Russian government's efforts to penetrate a Florida-based voting software supplier. Further reading: How a Few Yellow Dots Burned the Intercept's NSA Leaker.
PHP

As PHP 5.6, Still Used By a Large Number of Websites, Approaches Its End of Life Deadline, Some Worry About the Consequences (linkedin.com) 151

An anonymous reader writes: I know PHP isn't to some devs liking, but chances are you know people who work with PHP or have sites that are built with it. PHP 5.6 and 7.0 are shortly coming to the end of the support period for security patches, so what plans have you made to migrate code and sites to newer platforms? With apparently huge numbers (80%) of sites still running PHP 5.6, there appears to be little industry acknowledgement of the issue. Is there a ticking PHP Time Bomb waiting to go off?
Privacy

Spyware Company Leaves 'Terabytes' of Selfies, Text Messages, and Location Data (vice.com) 58

An anonymous reader writes: Spyfone, a company that sells surveillance software to parents and employers left 'terabytes of data' including photos, audio recordings, text messages and web history, exposed in a poorly-protected Amazon S3 bucket. News outlet Motherboard verified that the researcher could access anyone's data by creating a free account and installing the spyware on a test device. After a few hours, the researcher sent me back a picture I took.
United States

DNC Says Reported Hack Attempt Was a False Alarm (wsj.com) 115

furry_wookie writes: A suspected attempt to hack into the Democratic National Committee's voter database was actually a cybersecurity test [Editor's note: the originally submitted article might be paywalled; an alternative source], the organization said. The DNC, which was [allegedly] hacked by Russian intelligence officers during the 2016 presidential campaign, said Tuesday it had contacted the Federal Bureau of Investigation after being alerted to an apparent phishing scheme by the computer security firm Lookout Inc., which uncovered a replica of the login page to the DNC's Votebuilder database during an online scan. In a statement early Wednesday, Bob Lord, the DNC's chief information security officer, said the DNC and its partners who reported the site 'now believe it was built by a third party as part of a simulated phishing test.'
Australia

Australia Bans Huawei, ZTE From Supplying Technology For Its 5G Network (techcrunch.com) 77

An anonymous reader quotes a report from TechCrunch: Australia has blocked Huawei and ZTE from providing equipment for its 5G network, which is set to launch commercially next year. In a tweet, Huawei stated that the Australian government told the company that both it and ZTE are banned from supplying 5G technology to the country, despite Huawei's assurances that it does not pose a threat to national security. Earlier today, the Australian government issued new security guidelines for 5G carriers. Although it did not mention Huawei, ZTE or China specifically, it did strongly hint at them by stating "the Government considers that the involvement of vendors who are likely to be subject to extrajudicial directions from foreign government that conflict with Australian law, may risk failure by the carrier to adequately protect a 5G network from unauthorized access or interference." In its new security guidelines, the Australian government stated that differences in the way 5G operates compared to previous network generations introduces new risks to national security. In particular, it noted the diminishing distinctions between the core network, where more sensitive functions like access control and data routing occur, and the edge, or radios that connect customer equipment, like laptops and mobile phones, to the core. Huawei Australia said in a statement: "We have been informed by the Govt that Huawei & ZTE have been banned from providing 5G technology to Australia. This is a extremely disappointing result for consumers. Huawei is a world leader in 5G. Has safely & securely delivered wireless technology in Aust for close to 15 yrs."
Transportation

Driverless Startup Zoox Suddenly Removes CEO 58

Last month, Bloomberg shed some light on a secretive Australian startup called Zoox that is working on an autonomous vehicle unlike any other. It can reportedly make noises to communicate with pedestrians and drive bidirectionally, meaning it can cruise into a parking spot one way and cruise out the other. Today, it is being reported that their CEO Tim Kentley-Klay is being dismissed from the company after closing a massive financing round in July to the tune of $500 million. From the report: Kentley-Klay tweeted on Wednesday that the firing came "without a warning, cause or right of reply." "Today was Silicon Valley up to its worst tricks," he wrote. Jesse Levinson, the company's other co-founder and current chief technology officer, will be promoted to president, said a person familiar with the decision who asked not to be identified because the discussions are private. The person declined to offer an explanation for the move. Carl Bass, the former CEO of Autodesk and a Zoox board member, was named executive chairman for the company.

In an emotional missive on Twitter, Kentley-Klay criticized the board for their decision. "Rather than working through the issues in an epic startup for the win, the board chose the path of fear," he wrote, charging that the directors were "optimizing for a little money in hand at the expense of profound progress." Before starting Zoox, Kentley-Klay was offered a job with Google's self-driving project, now called Waymo. He turned it down, and has touted Zoox's strategy of building its own vehicles for full autonomy as wiser than the standard approach of retrofitting existing cars that Alphabet Inc.'s Waymo and others are taking. The Zoox board, which includes Levinson, voted to oust Kentley-Klay, said the person familiar with the situation.
Earth

New Research Suggests Evolution Might Favor 'Survival of the Laziest' (phys.org) 153

Zorro shares a report from Phys.org: If you've got an unemployed, 30-year-old adult child still living in the basement, fear not. A new large-data study of fossil and extant bivalves and gastropods in the Atlantic Ocean suggests laziness might be a fruitful strategy for survival of individuals, species and even communities of species. The results have just been published in the Proceedings of the Royal Society B by a research team based at the University of Kansas. Looking at a period of roughly 5 million years from the mid-Pliocene to the present, the researchers analyzed 299 species' metabolic rates -- or, the amount of energy the organisms need to live their daily lives -- and found higher metabolic rates were a reliable predictor of extinction likelihood. "We wondered, 'Could you look at the probability of extinction of a species based on energy uptake by an organism?'" said Luke Strotz, postdoctoral researcher at KU's Biodiversity Institute and Natural History Museum and lead author of the paper. "We found a difference for mollusk species that have gone extinct over the past 5 million years and ones that are still around today. Those that have gone extinct tend to have higher metabolic rates than those that are still living. Those that have lower energy maintenance requirements seem more likely to survive than those organisms with higher metabolic rates."

Strotz' co-author Bruce Lieberman added: "Maybe in the long term the best evolutionary strategy for animals is to be lassitudinous and sluggish -- the lower the metabolic rate, the more likely the species you belong to will survive. Instead of 'survival of the fittest,' maybe a better metaphor for the history of life is 'survival of the laziest' or at least 'survival of the sluggish.'"
Medicine

Poor Sleep Alters Metabolism and Boosts Body's Ability To Store Fat, Study Finds (theguardian.com) 233

An anonymous reader quotes a report from The Guardian: The latest study provides new evidence that sleep deprivation has a direct influence on basic metabolism and the body's balance between fat and muscle mass. In the study, published in the journal Science Advances, 15 healthy volunteers each attended a testing session on two occasions, once after a normal night's sleep and once after staying up all night. During the visit, they gave samples of fat and muscle tissue and blood. After sleep deprivation, people's fat tissue showed changes in gene activity that are linked to cells increasing their tendency to absorb lipids and also to proliferate.

By contrast, in muscle the scientists saw reduced levels of structural proteins, which are the building blocks the body requires to maintain and build muscle mass. Previous epidemiological studies have also found shift workers and those who sleep less have lower muscle mass. This may be in part down to lifestyle factors, but the latest work shows that there are also fundamental biological mechanisms at play. The study also found an increase in inflammation in the body after sleep deprivation, which is a known risk factor for type 2 diabetes.

Slashdot Top Deals