Australia

Australia To Pass Bill Providing Backdoors Into Encrypted Devices, Communications (theregister.co.uk) 168

An anonymous reader quotes a report from The Register: The Australian government has scheduled its "not-a-backdoor" crypto-busting bill to land in parliament in the spring session, and we still don't know what will be in it. The legislation is included in the Department of Prime Minister and Cabinet's schedule of proposed laws to be debated from today (13 August) all the way into December. All we know, however, is what's already on the public record: a speech by Minister for Law Enforcement and Cybersecurity Angus Taylor in June, and the following from the digest of bills for the spring session: "Implement measures to address the impact of encrypted communications and devices on national security and law enforcement investigations. The bill provides a framework for agencies to work with the private sector so that law enforcement can adapt to the increasingly complex online environment. The bill requires both domestic and foreign companies supplying services to Australia to provide greater assistance to agencies."

Apart from the dodgy technological sophistry involved, this belief somewhat contradicts what Angus Taylor said in June (our only contemporary reference to what the government has in mind). "We need access to digital networks and devices, and to the data on them, when there are reasonable grounds to do so," he said (emphasis added). If this accurately reflects the purpose of the legislation, then the Australian government wants access to the networks, not just the devices. It wants a break-in that will work on networks, if law enforcement demands it, and that takes us back to the "government wants a backdoor" problem. And it remains clear that the government's magical thinking remains in place: having no idea how to achieve the impossible, it wants the industry to cover for it under the guise of "greater assistance to agencies."

Operating Systems

Linux 4.18 Releases With Steam Controller Kernel Driver, Spectre Updates (phoronix.com) 47

fstack writes: Linus Torvalds has released Linux 4.18 as the newest kernel bringing a Steam Controller kernel driver, Spectre updates for ARM64, power management updates, a "Restartable Services" system call, AMD Radeon graphics driver improvements, V3D DRM as Broadcom's new graphics driver, DM writecache support, USB 3.2 support, and many other updates. Linus Torvalds wrote of the 4.18 final release: "It was a very calm week, and arguably I could just have released on schedule last week, but we did have some minor updates. Mostly networking, but some vfs race fixes (mentioned in the rc8 announcement as 'pending') and a couple of driver fixes (scsi, networking, i2c). Some other minor random things (arm crypto fix, parisc memory ordering fix)." In a separate article, Phoronix details all the changes and new features available in this release.
IOS

Apple Delays 32-Person Group FaceTime From iOS 12 Launch (theverge.com) 18

Developer Guilherme Rambo has revealed that the 32-person FaceTime group chat feature "has been removed from the initial release of iOS 12." Apple says the feature "will ship in a future software update later this fall." The Verge: Group FaceTime chats will allow 32 participants in a video call, with tiles of people's faces where you can manually select people to highlight them in the main interface. Apple's delay to group FaceTime chats comes after the company delayed its AirPlay 2 introduction in iOS.
Facebook

Facebook Bans the Sale of All Kodi Boxes (torrentfreak.com) 121

An anonymous reader quotes a report from TorrentFreak: Facebook previously banned the sale of fully-loaded pirate streaming devices, as did Amazon and eBay, but the social network appears to have expanded this to all Kodi-powered hardware now. This is made clear in the prohibited content section of the company's commerce policies, as shown below. Facebook states that users are no longer allowed to promote "the sale or use of streaming devices with KODI installed." In addition, jailbroken or loaded devices are also banned from the platform. The issue was first noticed by CordCuttersNews which notes that sellers who violate the policy may have their Facebook accounts banned. Interestingly, Facebook will still permit the sale of "add-on equipment for KODI devices," including keyboards and remotes. However, selling any devices with the software itself is no longer allowed.
Firefox

Internet Engineering Task Force Releases the Final Version of TLS 1.3; Newest Chrome and Firefox Versions Already Support a Draft Version of It (cnet.com) 28

The encryption that protects your browser's connection to websites is getting a notch faster and a notch safer to use. From a report: That's because the Internet Engineering Task Force (IETF) on Friday finished a years-long process of modernizing the technology used to secure website communications. You may never have heard of Transport Layer Security -- TLS for short -- but version 1.3 is now complete and headed to websites, browsers and other parts of the internet that rely on its security. "Publishing TLS 1.3 is a huge accomplishment. It is one the best recent examples of how it is possible to take 20 years of deployed legacy code and change it on the fly, resulting in a better internet for everyone," said Nick Sullivan, head of cryptography for Cloudflare, which helps customers distribute their websites and other content around the world, in a blog post.

TLS 1.3 brings some significant improvements over TLS 1.2, which was finished 10 years ago. Perhaps first on the list is that it'll mean websites load faster. Setting up an encrypted connection on the web historically has caused delays since your browser and the website server must send information back and forth in a process called a handshake. The slower your broadband or the more congested your mobile network is, the more you'll notice these delays.
Firefox and Chrome already support a draft version of TLS 1.3.
Businesses

Apple Asked Developers To Adopt Subscriptions and Hike App Prices, Report Says (venturebeat.com) 276

Apple invited a group of app developers to a secret April 2017 meeting in New York's Tribeca district, asking them to move from selling apps at low prices to renting app access through subscriptions, Business Insider reports. From a story: This change is intended to keep users paying for apps "on a regular basis, putting money into developer coffers on a regular schedule," the report claims.
IBM

IBM Promised Its AI Platform Watson Would Be a Big Step Forward in Treating Cancer. But After Pouring Billions Into the Project, the Diagnosis is Gloomy. (wsj.com) 90

Can Watson cure cancer? That's what IBM asked soon after its AI system beat humans at the quiz show "Jeopardy!" in 2011. Watson could read documents quickly and find patterns in data. Could it match patient information with the latest in medical studies to deliver personalized treatment recommendations? "Watson represents a technology breakthrough that can help physicians improve patient outcomes," said Herbert Chase, a professor of biomedical informatics at Columbia University, in a 2012 IBM press release. Six years and billions of dollars later, the diagnosis for Watson is gloomy [Editor's note: the link may be paywalled; alternative source]. WSJ: More than a dozen IBM partners and clients have halted or shrunk Watson's oncology-related projects. Watson cancer applications have had limited impact on patients, according to dozens of interviews with medical centers, companies and doctors who have used it, as well as documents reviewed by The Wall Street Journal. In many cases, the tools didn't add much value. In some cases, Watson wasn't accurate. Watson can be tripped up by a lack of data in rare or recurring cancers, and treatments are evolving faster than Watson's human trainers can update the system. Dr. Chase of Columbia said he withdrew as an adviser after he grew disappointed in IBM's direction for marketing the technology. No published research shows Watson improving patient outcomes. IBM said Watson has important cancer-care benefits, like helping doctors keep up with medical knowledge.
Security

Hacked Water Heaters Could Trigger Mass Blackouts Someday (wired.com) 175

At the Usenix Security conference this week, a group of Princeton University security researchers will present a study that considers a little-examined question in power grid cybersecurity: What if hackers attacked not the supply side of the power grid, but the demand side? From a report: In a series of simulations, the researchers imagined what might happen if hackers controlled a botnet composed of thousands of silently hacked consumer internet of things devices, particularly power-hungry ones like air conditioners, water heaters, and space heaters. Then they ran a series of software simulations to see how many of those devices an attacker would need to simultaneously hijack to disrupt the stability of the power grid. Their answers point to a disturbing, if not quite yet practical scenario: In a power network large enough to serve an area of 38 million people -- a population roughly equal to Canada or California -- the researchers estimate that just a one percent bump in demand might be enough to take down the majority of the grid. That demand increase could be created by a botnet as small as a few tens of thousands of hacked electric water heaters or a couple hundred thousand air conditioners. "Power grids are stable as long as supply is equal to demand," says Saleh Soltan, a researcher in Princeton's Department of Electrical Engineering, who led the study. "If you have a very large botnet of IoT devices, you can really manipulate the demand, changing it abruptly, any time you want."
United States

US House Candidates Vulnerable To Hacks, Researchers Say (reuters.com) 35

About 30 percent of House candidates running for office this year have significant cybersecurity issues with their campaign websites, according to a new study. Reuters: The research was unveiled on Sunday at the annual Def Con security conference in Las Vegas, where some attendees have spent three days hacking into voting machines to highlight vulnerabilities in technology running polling operations. A team of four independent researchers led by former National Institutes for Standards and Technology security expert Joshua Franklin concluded that the websites of nearly one-third of U.S. House candidates, Democrats and Republicans alike, are vulnerable to attacks. NIST is a U.S. Commerce Department laboratory that provides advice on technical issues, including cyber security. Using automated scans and test programs, the team identified multiple vulnerabilities, including problems with digital certificates used to verify secure connections with users, Franklin told Reuters ahead of the presentation. The warnings about the midterm elections, which are less than three months away, come after Democrats have spent more than a year working to bolster cyber defenses of the party's national, state and campaign operations.
Australia

The Mining Town Where People Live Under the Earth (cnet.com) 105

Claire Reilly, writing for CNET: After spending a night in an underground rock cave in the middle of the Australian desert, I learned three things: The silence is deafening. Your eyes never adjust to the darkness. And if nobody brushes the ceiling before you arrive, that clump of dirt is going to scare the living hell out of you when it drops on your face at 2 a.m. I've flown 1,200 miles for the privilege of sleeping in a hole in Coober Pedy. There's no Wi-Fi down here. The glare of my MacBook feels obnoxious in the subterranean stillness. The TV plays ads for a "local" cleaning service from the next town over, but that just happens to be 400 miles away. Australia is a country defined by "the tyranny of distance," but traveling to the underground opal mining town of Coober Pedy feels like taking a holiday on Mars.

In the middle of the South Australian desert and an eight hour drive in either direction from the nearest capital city (Adelaide to the south or Alice Springs to the north), Coober Pedy is off the grid and mostly hidden underground. More than half the residents live buried in the bedrock in cavelike homes called "dugouts" in order to escape freezing winters, scorching summers and the occasional cyclone. Often, the only sign you're walking on someone's roof is the air vent that's sprouted up next to your boots. While first nation peoples have lived in the central Australian desert for thousands of years, the Coober Pedy we know today wouldn't exist without opals. Miners rushed here in the 1920s, enduring extreme conditions to hunt for the multicolored gems, digging, bulldozing and eventually blasting out earth in a bid to find the elusive seam that would make them rich. Living in Coober Pedy is not just about surviving. It's about carving out a way of life in one of the harshest environments on the planet.

[...] "It's not like we're living thousands of kilometers under the ground," he tells me. "It's pretty similar to living in a normal house." Sam's family, who live in a dugout close to Crocodile Harry's, have solar panels for power -- but those generate only enough electricity for a few hours a day. Diesel handles the rest, he says. "We have to rely on tourists to pay for our fuel," he says. "Gasoline is valuable out here. Fuel is really expensive." That means no fridge running all day and night -- they keep nonperishable food and get the rest from town every day. Otherwise, life is pretty similar to what other 18-year-olds in the city experience. Sam says he can still charge his phone and use the TV "for a bit." "We have internet when the generator's on. Dad's got an Xbox but we don't even try to use the solar for that."

Security

Malicious Faxes Leave Firms 'Open' To Cyber-Attack (bbc.com) 77

Booby-trapped image data sent by fax can let malicious hackers sneak into corporate networks, security researchers have found. From a report: Since many companies use fax machines that are also printers and photocopiers, they often have a connection to the internal network. The malicious images exploit protocols established in the 1980s that define the format of fax messages. The research was presented at the Def Con hacker conference in Las Vegas. The two researchers said millions of companies could be at risk because they currently did little to secure fax lines. "Fax has no security measures built in -- absolutely nothing," security researcher Yaniv Balmas, from Check Point software, told the BBC. Mr Balmas uncovered the security holes in the fax protocols with the help of colleague Eyal Itkin and said they were "surprised" by the extent to which fax was still used.
Youtube

The Flourishing Business of Fake YouTube Views (nytimes.com) 137

An anonymous reader shares a report: Martin Vassilev makes a good living selling fake views on YouTube videos. Working from home in Ottawa, he has sold about 15 million views so far this year, putting him on track to bring in more than $200,000, records show. Mr. Vassilev, 32, does not provide the views himself. His website, 500Views.com, connects customers with services that offer views, likes and dislikes generated by computers, not humans. When a supplier cannot fulfill an order, Mr. Vassilev -- like a modern switchboard operator -- quickly connects with another. "I can deliver an unlimited amount of views to a video," Mr. Vassilev said in an interview. "They've tried to stop it for so many years, but they can't stop it. There's always a way around."

[...] Just as other social media companies have been plagued by impostor accounts and artificial influence campaigns, YouTube has struggled with fake views for years. The fake-view ecosystem of which Mr. Vassilev is a part can undermine YouTube's credibility by manipulating the digital currency that signals value to users. While YouTube says fake views represent just a tiny fraction of the total, they still have a significant effect by misleading consumers and advertisers.

AI

Google DeepMind's AI Beats Doctors at Spotting Eye Disease in Scan (cnet.com) 40

DeepMind, Google's artificial intelligence business, is planning clinical trials of technology that can help diagnose eye disease by analyzing medical images after early tests showed its results were more accurate than human doctors. From a report: Published in the scientific journal Nature, the study claims that DeepMind, in partnership with Moorfields Eye Hospital in London, has trained its algorithms to detect over 50 sight-threatening conditions to the same accuracy as expert clinicians. It is also capable of correctly recommending the most appropriate course of action for patients and prioritise those in most urgent need of care. In a project that began two years ago, DeepMind trained its machine learning algorithms using thousands of historic and fully anonymized eye scans to identify diseases that could lead to sight loss. According to the study, they can now do so with 94 percent accuracy, and the hope is that they could eventually be used to transform how eye exams are conducted around the world. You might be wondering why we need AI to do this job that has up until now been carried out by medical staff. But diagnosing eye diseases from ocular scans is incredibly time-consuming for doctors due to their complexity. Due to the aging global population, eye disease is also becoming more prevalent not less, increasing the burden on healthcare systems.
Security

Hackers Who Attended Black Hat and DefCon Conferences Say Hotel Security Personnel Demanded Access To Their Rooms (the-parallax.com) 441

More than two dozen hackers and security experts who attended security events last week say security personnel at the Mandalay Bay, Luxor, Caesars Palace, Flamingo, Aria, Cromwell, Tuscany, Linq, or Mirage hotels had entered their rooms. Security news site The Parallax reports: Except for Tuscany, which is independent, all of these hotels are owned by either Caesars Entertainment or MGM Resorts International. And of the three hotel companies, only Caesars returned a request for comment. Richard Broome, executive vice president of communications and government relations for Caesars Entertainment, whose Caesars Palace is co-hosting DefCon this year with the Flamingo, said that following the deadliest mass shooting in U.S. history last year, "periodic" hotel room checks are now standard operating procedure in Las Vegas. On October 1, 2017, from his room at the Mandalay Bay, Stephen Paddock used semiautomatic weapons he'd outfitted with bump stocks to kill 58 people and wound at least 527 others attending a gated country music concert on the Strip below. [...] Two apparent Caesars security officers wearing hotel name tags displaying only the first names "Cynthia" and "Keith," respectively, as well as sheriff's style badges that looked like they came out of a Halloween costume kit, visited my room while I was writing this story. Cynthia told me that they are instructed to refer to the front desk guests who decline to allow their room to be searched.

After Cynthia and Keith declined to disclose their last names to me, I asked what they intended to do in the room. They told me that they would enter it, type a code into the room's phone line to signal that it's been checked, and then do a visual spot check. When I asked what they would be looking for, Cynthia replied, "WMDs -- that sort of thing." Other conference attendees reported similar but less pleasant interactions. Katie Moussouris, CEO of Luta Security, wrote on Twitter that two hotel security personnel were "banging" on her room door and "shouted" at her. She also said the hotel's security team supervisor "dismissed" her concerns over how the hotel was treating single, female travelers. Google security engineer Maddie Stone tweeted that a man wearing a light-blue shirt and a walkie-talkie entered her Caesars Palace room with a key, but without knocking, while she was getting dressed. "He left when I started screaming," she wrote, adding that a hotel manager, upon her request, said Caesars would look into whether the man was actually an employee. Stone tweeted that she left DefCon early because of the incident.

Google

Many Google Services on Android Devices and iPhones Store Location Data, Even if Location Sharing is Disabled From Privacy Settings: AP (apnews.com) 122

Google wants to know where you go so badly that it records your movements even when you explicitly tell it not to. An Associated Press investigation found that many Google services on Android devices and iPhones store your location data even if you've used privacy settings that say they will prevent it from doing so. The Associated Press reports that it has confirmed its findings with computer science researchers at Princeton. From the report: For the most part, Google is upfront about asking permission to use your location information. An app like Google Maps will remind you to allow access to location if you use it for navigating. If you agree to let it record your location over time, Google Maps will display that history for you in a "timeline" that maps out your daily movements. Storing your minute-by-minute travels carries privacy risks and has been used by police to determine the location of suspects -- such as a warrant that police in Raleigh, North Carolina, served on Google last year to find devices near a murder scene. So the company will let you "pause" a setting called Location History. Google says that will prevent the company from remembering where you've been. Google's support page on the subject states: "You can turn off Location History at any time. With Location History off, the places you go are no longer stored." That isn't true. Even with Location History paused, some Google apps automatically store time-stamped location data without asking.

For example, Google stores a snapshot of where you are when you merely open its Maps app. Automatic daily weather updates on Android phones pinpoint roughly where you are. And some searches that have nothing to do with location, like "chocolate chip cookies," or "kids science kits," pinpoint your precise latitude and longitude -- accurate to the square foot -- and save it to your Google account. The privacy issue affects some two billion users of devices that run Google's Android operating software and hundreds of millions of worldwide iPhone users who rely on Google for maps or search. Storing location data in violation of a user's preferences is wrong, said Jonathan Mayer, a Princeton computer scientist and former chief technologist for the Federal Communications Commission's enforcement bureau.

Slashdot Top Deals