Government

Russian Hackers Reach US Utility Control Rooms, Homeland Security Officials Say (wsj.com) 371

"Russian hackers [...] broke into supposedly secure, "air-gapped" or isolated networks owned by utilities (Warning: source may be paywalled; alternative source) with relative easy by first penetrating the networks of key vendors who had trusted relationships with the power companies," reports The Wall Street Journal, citing officials at the Department of Homeland Security. "They got to the point where they could have thrown switches" and disrupted power flows, said Jonathan Homer, chief of industrial-control-system analysis for DHS. The hacking campaign started last year and likely is continuing. From the report: DHS has been warning utility executives with security clearances about the Russian group's threat to critical infrastructure since 2014. But the briefing on Monday was the first time that DHS has given out information in an unclassified setting with as much detail. It continues to withhold the names of victims but now says there were hundreds of victims, not a few dozen as had been said previously. It also said some companies still may not know they have been compromised, because the attacks used credentials of actual employees to get inside utility networks, potentially making the intrusions more difficult to detect.

The attackers began by using conventional tools -- spear-phishing emails and watering-hole attacks, which trick victims into entering their passwords on spoofed websites -- to compromise the corporate networks of suppliers, many of whom were smaller companies without big budgets for cybersecurity. Once inside the vendor networks, they pivoted to their real focus: the utilities. It was a relatively easy process, in many cases, for them to steal credentials from vendors and gain direct access to utility networks. Then they began stealing confidential information. For example, the hackers vacuumed up information showing how utility networks were configured, what equipment was in use and how it was controlled. They also familiarized themselves with how the facilities were supposed to work, because attackers "have to learn how to take the normal and make it abnormal" to cause disruptions, said Mr. Homer. Their goal, he said: to disguise themselves as "the people who touch these systems on a daily basis."

Security

Researchers Detail New CPU Side-Channel Attack Named SpectreRSB (bleepingcomputer.com) 39

An anonymous reader writes: "Scientists from the University of California, Riverside (UCR) have published details last week about a new Spectre-class attack that they call SpectreRSB," reports Bleeping Computer. "Just like all 'Spectre-class' attacks, SpectreRSB takes advantage of the process of speculative execution -- a feature found in all modern CPUs that has the role of improving performance by computing operations in advance and later discarding unneeded data. The difference from previous Spectre-like attacks is that SpectreRSB recovers data from the speculative execution process by attacking a different CPU component involved in this 'speculation' routine, namely the Return Stack Buffer (RSB)." In a research paper, academics say they've used SpectreRSB attacks to recover data belonging to other processes, and have even tricked the RSB into spilling SGX secrets. The attack works on Intel, AMD, and ARM processors, known to use RSB. The attack can also bypass all the mitigations put in place for the original Spectre/Meltdown flaws.
Transportation

Student Engineers Build Hyperloop Test Pods That Set a New Speed Record (bbc.com) 92

Engineering students from the Technical University of Munich have won a hyperloop competition that aims to refine the technologies that could underpin the super-fast transport system. According to the BBC, "The team's pod hit 457km/h (290mph) on a 1.2km (0.75 mile) test track." This marks the third win in a row for the team. From the report: In the latest round of the competition, the Munich team, WARR Hyperloop, outpaced rival capsules, which could manage speeds of only 88mph (Delft University) and 55mph (EPF Loop, from Switzerland), to beat its own record speed, 323km/h, set in the second competition, in September 2017. In a change from earlier competitions, all the pods being tested this time had to be self-propelled. Previously, the pods could rely on a SpaceX-built "pusher" vehicle that helped them travel down the test tube.
Iphone

Leaked Videos Reveal Apple's Internal iPhone Repair Procedures (vice.com) 71

An anonymous reader quotes a report from Motherboard: Someone has uploaded what appear to be 11 of Apple's internal repair videos to YouTube. Apple did not immediately respond to a request for comment, but two sources in the repair community familiar with Apple's repair policies told Motherboard these are indeed genuine Apple how-to videos. The videos themselves have an Apple copyright on them, the host references internal Apple documentation and diagnostic tests, and, most importantly, the videos use proprietary Apple disassembly and repair tools that Motherboard has previously confirmed are manufactured by and are exclusive to Apple.

The videos on how to open an iPhone X and replace its battery are particularly interesting, and show that the DIY repair community has gotten extremely good at reverse-engineering Apple's official procedures. The instructor walks the repair tech through the process of opening the case on the iPhone X in a way that closely mirrors the process that sites such as iFixit have been doing for a few years now. The video starts by instructing the tech to remove the screws near the lighting port, then inserting the iPhone X into a device that uses suction cups to pry the screen away from the body while the tech uses a small tool to cut the adhesive along the seams at the edge of the device. Apple's suction cup tool looks like a bulkier version of iFixit's iSclack tool -- a suction cup device that customers can use to disassemble and repair their own device. The video about replacing the iPhone X's battery is remarkably similar to the iFixit video of the same procedure.

Google

Google Video Shows All-White Redesigns For Gmail, Google Photos, and More (arstechnica.com) 105

An anonymous reader shares a report: This year, Google is pushing out a major revamp to its Material Design guidelines. The new design language is slowly creeping across Google's portfolio, and so far we've seen big changes for Gmail.com, early builds of Chrome, and for Android P. The Android side of things has so far only been the base operating system, but now a new Google design video has surfaced that shows off new designs for Gmail, Google Photos, Google Trips, and Google Drive.

[...] The Gmail screens strip the app of its trademark red UI elements and give us a white bottom bar and white background. The phone inbox shows attached documents and even has large thumbnails for images. The message screen appears to show attachments on a horizontal scrolling carousel, which looks a lot like the horizontally scrolling news articles in the Google Feed. This screen again places the important controls down at the bottom of the screen, where a bottom bar houses the usual "Mark as Read," "Delete," "Archive," and "Reply All" buttons. We even get to see the compose screen for a second, which shows previous replies above your compose field.

Microsoft

Microsoft Launches Open-Source Quantum Katas Project On GitHub To Teach Q# Programming (betanews.com) 37

BrianFagioli shares a report from BetaNews: Microsoft seems eager to get programmers on the quantum bandwagon, as today, it launched the open-source Quantum Katas on GitHub. What exactly is it? It is essentially a project deigned to teach Q# programming for free. "For those who want to explore quantum computing and learn the Q# programming language at their own pace, we have created the Quantum Katas -- an open-source project containing a series of programming exercises that provide immediate feedback as you progress," says The Microsoft Quantum Team. "Coding katas are great tools for learning a programming language. They rely on several simple learning principles: active learning, incremental complexity growth, and feedback."

The team further says, "The Microsoft Quantum Katas are a series of self-paced tutorials aimed at teaching elements of quantum computing and Q# programming at the same time. Each kata offers a sequence of tasks on a certain quantum computing topic, progressing from simple to challenging. Each task requires you to fill in some code; the first task might require just one line, and the last one might require a sizable fragment of code. A testing framework validates your solutions, providing real-time feedback."
You can view the project on GitHub here.
Security

American Airlines Is Using a CT Scanner To Screen Luggage At New York's JFK Airport (theverge.com) 125

According to American Airlines, the airline is working with the TSA to install a new bag-scanning machine at New York's John F. Kennedy International Airport. "The machine uses the same technology as CT scanners, providing a 3D image of bag's contents, and is expected to be operational in late July," reports The Verge. From the report: The new scanner, which will be used at the airport's Terminal 8 security checkpoint, will allow TSA to rotate a bag's image 360 degrees to show its contents. American Airlines says this should provide a more effective way for agents to inspect bags for explosives and other prohibited items. TSA administrator David Pekoske tells CBS News that the new machines could allow for liquids, gels, aerosols, and laptops to be left in bags. The TSA plans to have 15 of the new CT scanners at airports by the end of the year, and are authorized to purchase up to 240 of the machines, which cost $300,000 each, in 2019. The technology has also been tested at Phoenix Sky Harbor International Airport and in Boston.
Nintendo

Nintendo To ROM Sites: Forget Cease-and-Desist, Now We're Suing (arstechnica.com) 296

An anonymous reader quotes a report from Ars Technica: Nintendo's attitude toward ROM releases -- either original games' files or fan-made edits -- has often erred on the side of litigiousness. But in most cases, the game producer has settled on cease-and-desist orders or DMCA claims to protect its IP. This week saw the company grow bolder with its legal action, as Nintendo of America filed a lawsuit (PDF) on Thursday seeking millions in damages over classic games' files being served via websites. The Arizona suit, as reported by TorrentFreak, alleges "brazen and mass-scale infringement of Nintendo's intellectual property rights" by the sites LoveROMs and LoveRetro. These sites combine ROM downloads and in-browser emulators to deliver one-stop gaming access, and the lawsuit includes screenshots and interface explanations to demonstrate exactly how the sites' users can gain access to "thousands of [Nintendo] video games, related copyrighted works, and images." The biggest amount of money Nintendo is seeking comes from "$150,000 for the infringement of each Nintendo copyrighted work and up to $2,000,000 for the infringement of each Nintendo trademark." The company has also requested full disclosure of the operators' "receipts and disbursements, profit and loss statements, advertising revenue, donations and cryptocurrency revenue, and other financial materials."

LoveROMs has since removed all Nintendo-affiliated links, including ROMs and emulators, and the site announced on its social media channels that "all Nintendo titles have been removed from our site." Meanwhile, LoveRetro.co now redirects visitors to a page that reads: "Loveretro has effectively been shut down until further notice."
Google

None of Google's 85,000 Employees Have Been Phished in More Than a Year After Company Required Them to Use Physical Security Keys For 2FA (krebsonsecurity.com) 126

Google has not had any of its 85,000+ employees successfully phished on their work-related accounts since early 2017, when it began requiring all employees to use physical Security Keys in place of passwords and one-time codes, the company told KrebsOnSecurity. From the report: Security Keys are inexpensive USB-based devices that offer an alternative approach to two-factor authentication (2FA), which requires the user to log in to a Web site using something they know (the password) and something they have (e.g., a mobile device). A Google spokesperson said Security Keys now form the basis of all account access at Google. "We have had no reported or confirmed account takeovers since implementing security keys at Google," the spokesperson said. "Users might be asked to authenticate using their security key for many different apps/reasons. It all depends on the sensitivity of the app and the risk of the user at that point in time." The basic idea behind two-factor authentication is that even if thieves manage to phish or steal your password, they still cannot log in to your account unless they also hack or possess that second factor.
Businesses

Visualizing the Best and Worst Paid Jobs in the Tech Sector (howmuch.net) 94

An anonymous reader writes: We often associate the tech sector with high-paying jobs and cool offices, but it turns out that the grass is not always green on the other side. Using data from the Bureau of Labor Statistics, personal finance site HowMuch has created a graph that showcases the 15 best and worst paid jobs in the technology industry.
Sony

Mobile Photography Set For Major Quality Bump With Sony's 48-Megapixel Sensor (newatlas.com) 112

Smartphone camera sensors and lenses have to operate in a very tight space, but they continue to close the gap on full-size digital cameras year after year. Sony's new IMX586 sensor boasts a 48-megapixel resolution, the highest yet for a mobile sensor, and should be coming to a phone near you soon. From a report: That increased resolution shrinks the pixel size down to 0.8 microns, which would usually lead to lower sensitivity and poor light collection. However, thanks to some smart technology called a Quad Bayer array -- where neighboring pixels are intelligently combined -- Sony says the effective pixel size is 1.6 microns. The bigger the pixel size, the better the light capture and low-light performance. In comparison, the Google Pixel 2 -- one of the best photo-taking phones on the market right now -- has a camera with a 1.4-micron pixel size. On paper, that means Sony has managed to produce a sensor that combines a huge amount of detail with excellent light capture and low noise levels as well. We'll have to wait until the sensor is actually on the market to know for sure, but the signs are good.
Portables (Apple)

Apple Seemingly Unable To Recover Data From 2018 MacBook Pro With Touch Bar When Logic Board Fails (macrumors.com) 341

An anonymous reader shares a report: In 2016, when Apple introduced the first MacBook Pro with Touch Bar models, the repair experts at iFixit discovered the notebooks have non-removable SSDs, soldered to the logic board, prompting concerns that data recovery would not be possible if the logic board failed. Fortunately, that wasn't the case. Apple has a special tool for 2016 and 2017 models of the MacBook Pro with Touch Bar that allows Genius Bars and Apple Authorized Service Providers to recover user data when the logic board fails, but the SSD is still intact. [...] But, unfortunately, it appears the tool will not work with the latest models.

Last week, iFixit completed a teardown of the 2018 MacBook Pro, discovering that Apple has removed the data recovery connector from the logic board on both 13-inch and 15-inch models with the Touch Bar, suggesting that the Customer Data Migration Tool can no longer be connected. MacRumors contacted multiple reliable sources at Apple Authorized Service Providers to learn more, and based on the information we obtained, it does appear that the tool is incompatible with 2018 MacBook Pro with Touch Bar models. Multiple sources claim that data cannot be recovered if the logic board has failed on a 2018 MacBook Pro. If the notebook is still functioning, data can be transferred to another Mac by booting the system in Target Disk Mode, and using Migration Assistant, which is the standard process that relies on Thunderbolt 3 ports.

The Internet

Apple's iPhones Trail Samsung, Google Devices in Internet Speeds (bloomberg.com) 75

An anonymous reader shares a report: Apple's iPhone 8, iPhone 8 Plus and $1,000 iPhone X trail the latest smartphones from Samsung Electronics and Alphabet's Google in download speeds, according to data from Ookla, a company that provides the most popular online service for measuring the speed of an internet connection with its Speedtest app and website. Faster internet data means that users can load websites and start watching movies more quickly, make crisper video calls and get higher-quality video.

[...] Ookla's data are important because they are created by users -- not in a corporate lab -- and encompass the range of random real-world conditions that affect performance like distance from cellular towers and network congestion. Ookla said it hosts millions of tests a day and has done 20 billion in total.

[...] The speed-test data, reviewed by Bloomberg, show that Samsung's Galaxy S9 phones had an average download speed -- across carriers in the U.S. -- of 38.9 megabits per second, based on about 102,000 tests over the past three months. The larger model, the S9+, delivered speeds of 38.4 Mbps, according to a sample size of about 169,000 phone connections. The iPhone X on average downloaded data at 29.7 Mbps, based on a 603,000 tests. The iPhone 8 Plus and iPhone 8 were close behind with speeds of 29.4 Mbps and 28.6 Mbps, respectively.

Intel

Academics Publish New Software-Level Protections Against Spectre and Rowhammer Attacks (bleepingcomputer.com) 47

Catalin Cimpanu, writing for BleepingComputer: Academics from multiple universities have announced fixes for two severe security flaws known as Spectre and Rowhammer. Both these fixes are at the software level, meaning they don't require CPU or RAM vendors to alter products, and could, in theory, be applied as basic software patches.

The first of these new mitigation mechanisms was announced on Thursday, last week. A research team from Dartmouth College in New Hampshire says it created a fix for Spectre Variant 1 (CVE-2017-5753), a vulnerability discovered at the start of the year affecting modern CPUs. Their fix uses ELFbac, an in-house-developed Linux kernel patch that brings access control policies to runtime virtual memory accesses of Linux processes, at the level of ELF binary executables.

[...] The second fix for a major flaw announced last week came on Saturday from the Systems and Network Security Group at VU Amsterdam. Researchers announced a new technique called ZebRAM that they said is a comprehensive software protection against Rowhammer attacks.

Science

Scientists Take Step Toward Creating Artificial Embryos (reuters.com) 118

An international team of scientists has moved closer to creating artificial embryos after using mouse stem cells to make structures capable of taking a crucial step in the development of life. From a report: Experts said the results suggested human embryos could be created in a similar way in future -- a step that would allow scientists to use artificial embryos rather than real ones to research the very earliest stages of human development. The team, led by Magdalena Zernicka-Goetz, a professor at Britain's Cambridge University, had previously created a simpler structure resembling a mouse embryo in a lab dish. That work involved two types of stem cells and a three-dimensional scaffold on which they could grow. But in new work published on Monday in the journal Nature Cell Biology, the scientists developed the structures further -- using three types of stem cells -- enabling a process called gastrulation, an essential step in which embryonic cells begin self-organizing into a correct structure for an embryo to form.

Slashdot Top Deals