Security

Linux: Beep Command Can Be Used to Probe for the Presence of Sensitive Files (bleepingcomputer.com) 109

Catalin Cimpanu, writing for BleepingComputer: A vulnerability in the "beep" package that comes pre-installed with Debian and Ubuntu distros allows an attacker to probe for the presence of files on a computer, even those owned by root users, which are supposed to be secret and inaccessible. The vulnerability, tracked as CVE-2018-0492, has been fixed in recent versions of Debian and Ubuntu (Debian-based OS). At its core, the bug is a race condition in the beep utility that allows the OS to emit a "beep" sound whenever it is deemed necessary. Security researchers have discovered a race condition in the beep package that allows an attacker to elevate his code to root-level access.
Chrome

Biometric and App Logins Will Soon Be Pushed Across the Web (vice.com) 161

Soon, it will be much easier to log into more websites using a hardware key plugged into your laptop, a dedicated app, or even the fingerprint scanner on your phone. Motherboard: On Tuesday, a spread of organizations and businesses, including top browser vendors such as Microsoft and Google, announced a new standards milestone that will streamline the process for web developers to add extra login methods to their sites, potentially keeping consumers' accounts and data more secure. "For users, this will be a natural transition. People everywhere are already using their fingers and faces to 'unlock' their mobile phones and PCs, so this will be natural to them -- and more convenient," Brett McDowell, executive director at the FIDO Alliance, one of the organizations involved in setting up the standard, told Motherboard in an email.

"What they use today to 'unlock' will soon allow them to 'login' to all their favorite websites and a growing number of native apps that already includes Bank of America, PayPal, eBay and Aetna," he added. Passwords continue to be one of the weaker points in online security. A hacker may phish a target's password and log into their account, or take passwords from one data breach and use them to break into accounts on another site. The login standard, called Web Authentication (WebAuthn), will let potentially any website or online service use apps, security keys, or biometrics as a login method instead of a password, or use those alternative approaches as a second method of verification. The key here is making it easy and open for developers to use, and for it to work across all different brands of browsers. The functionality is already available in Mozilla's Firefox, and will be rolled out to Microsoft's Edge and Google Chrome in the new few months. Opera has committed to supporting WebAuthn as well.

Youtube

YouTube Hack: Several High-Profile Videos Mysteriously Disappear From Platform, Some Defaced 158

Several high-profile music videos on YouTube were mysteriously deleted early Tuesday, in what appears like the result of a security compromise. Some of the videos that have been pulled from Google's video platform include Luis Fonsi and Daddy Yankee's "Despacito" -- which is also the most popular video on the platform. Users reported Tuesday that the thumbnail of the video was replaced by a masked gang holding guns, who identify themselves as "Prosox and Kuroi'sh." Several songs from DJ Snake, Drake, Katy Perry, Selena Gomez, Shakira, and Taylor Swift have also been either deleted or altered with. On Twitter, a person who claims to be one of the hackers, said, "@YouTube Its just for fun i just use script "youtube-change-title-video" and i write "hacked" don t judge me i love youtube." Google has yet to acknowledge the incident. Further reading: BBC.
Communications

Oregon Becomes Second State To Pass a Net Neutrality Law (katu.com) 91

An anonymous reader quotes a report from KATU: Oregon Gov. Kate Brown signed a bill Monday withholding state business from internet providers who throttle traffic, making the state the second to finalize a proposal aimed at thwarting moves by federal regulators to relax net neutrality requirements. The bill stops short of actually putting new requirements on internet service providers in the state, but blocks the state from doing business with providers that offer preferential treatment to some internet content or apps, starting in 2019. The move follows a December vote by the Federal Communications Commission repealing Obama-era rules that prohibited such preferential treatment, referred to generally as throttling, by providers like AT&T, Comcast, and Verizon. Brown's signature makes the state the second to enact such legislation, according to the National Conference of State Legislatures. It also stakes out the state's claim to a moderate approach, compared to others: Five weeks to the day before Brown, Washington State Gov. Jay Inslee signed a bill in his state to directly regulate providers there. The prohibition, which restricts with whom the state may contract for internet services, applies to cities and counties, but exempts areas with only a single provider.
Power

Your Future Home Might Be Powered By Car Batteries (bloomberg.com) 319

Increasingly utilities and automakers are wondering if they could use the batteries inside electric cars as storage for the entire public power grid. An anonymous reader shares a report: The idea, known as "vehicle-to-grid," is to someday have millions of drivers become mini electricity traders, charging up when rates are cheap and pumping energy back into the grid during peak hours or when the sun simply isn't shining. If it works -- and it's a big if -- renewable energy could get much cheaper and more widely used. "We really, really need storage in order to make better use of wind and solar power, and electric cars could provide it," said Daniel Brenden, an analyst who studies the electricity market at BMI Research in London. "The potential is so huge." Today, fewer than one percent of the world's vehicles are electric, but by 2040 more than half of all new cars will run on the same juice as televisions, computers and hair dryers, according to estimates by Bloomberg New Energy Finance. Once cars and everything else are fed from the same source, they can share the same plumbing.
China

China Removes Four News Apps From Smartphone Stores To Tighten Control (scmp.com) 52

The mobile apps for four popular news apps in China, including the most popular aggregator, Jinri Toutiao, were removed from a number of Chinese smartphone app stores following reports of a crackdown by the country's media watchdog, local media reported on Monday. From the report: Toutiao, with about 120 million daily active users, was not available on the app stores of smartphone manufacturers Xiaomi and Meizu on Monday afternoon. The apps for Tiantian Kuaibao, Netease News and Ifeng News were also not found on Xiaomi. China's authorities have asked several of the country's smartphone app stores to remove the four apps by 3pm on Monday as part of efforts to "regulate order in the broadcasting environment," according to Chinese news portal Sohu.com. The apps will be removed for between three days to three weeks, with Toutiao being offline for the longest period, according to the Sohu report. [...] China has shut down more than 13,000 websites in the last three years as Beijing sought to tighten its grip on the internet.
Businesses

How Much VR User Data Is Oculus Giving To Facebook? (theverge.com) 60

Facebook owns many other apps and services, including the Oculus virtual-reality platform, which collects incredibly detailed information about where users are looking and how they're moving. Since most of the discussion about how Facebook handles user information is focused on the social network itself, The Verge's Adi Robertson looks into the link between Facebook and Oculus: A VR platform like Oculus offers lots of data points that could be turned into a detailed user profile. Facebook already records a "heatmap" of viewer data for 360-degree videos, for instance, flagging which parts of a video people find most interesting. If it decided to track VR users at a more detailed level, it could do something like track overall movement patterns with hand controllers, then guess whether someone is sick or tired on a particular day. Oculus imagines people using its headsets the way they use phones and computers today, which would let it track all kinds of private communications. The Oculus privacy policy has a blanket clause that lets it share and receive information from Facebook and Facebook-owned services. So far, the company claims that it exercises this option in very limited ways, and none of them involve giving data to Facebook advertisers. "Oculus does not share people's data with Facebook for third-party advertising," a spokesperson tells The Verge.

Oculus says there are some types of data it either doesn't share or doesn't retain at all. The platform collects physical information like height to calibrate VR experiences, but apparently, it doesn't share any of it with Facebook. It stores posts that are made on the Oculus forums, but not voice communications between users in VR, although it may retain records of connections between them. The company also offers a few examples of when it would share data with Facebook or vice versa. Most obviously, if you're using a Facebook-created VR app like Spaces, Facebook gets information about what you're doing there, much in the same way that any third-party app developer would. You can optionally link your Facebook account to your Oculus ID, in which case, Oculus will use your Facebook interests to suggest specific apps or games. If you've linked the accounts, any friend you add on Facebook will also become your friend on Oculus, if they're on the platform.
Oculus does, however, share data between the two services to fight certain kinds of banned activity. "If we find someone using their account to send spam on one service, we can disable all of their accounts," an Oculus spokesperson says. "Similarly, if there's 'strange activity' on a specific Oculus account, they can share the IP address it's coming from with Facebook," writes Robertson. "The biggest problem is that there's nothing stopping Facebook and Oculus from choosing to share more data in the future."
Crime

Backpage Founders Charged With Money Laundering, Aiding Prostitution (theverge.com) 256

Federal authorities have charged the two founders of classified site Backpage.com, along with five other employees, with laundering money and facilitating prostitution. According to The Washington Post, the Justice Department claims Backpage took "consistent and concerted action" to knowingly allow ads for illegal sex work. The indictment alleges that "virtually every dollar flowing into Backpage's coffers represents the proceeds of illegal activity." The Verge reports: Law enforcement agencies seized Backpage's servers last week, and co-founder Michael Lacey was charged in a sealed 93-count indictment, which has now been revealed. Lacey, as well as his co-founder James Larkin, were already charged with violating California money laundering laws, although a judge threw out state-level pimping charges. Beyond Lacey and Larkin, the Backpage indictment includes charges against the site's chief financial officer, operations manager, assistant operations manager, and marketing director. It also charges the executive vice president of one of Backpage's parent companies. Backpage CEO Carl Ferrer, who was previously charged with pimping in California, was not charged in this indictment. The Justice Department claims Backpage's owners tried to cover up the fact that most of its "adult services" ads involved prostitution, and that Backpage allowed child sex traffickers to keep ads on the site as long as they deleted age-related keywords. The indictment also claims that Backpage disguised payments for illegal services by having customers funnel money to foreign bank accounts or apparently unrelated companies, or by transferring funds into cryptocurrency. These federal chargers are reportedly unrelated to the Stop Enabling Sex Traffickers Act, a bill that would make website operators liable for illegal content posted to their sites. The bill is currently awaiting Trump's signature.
IOS

Recent iOS Update Kills Functionality On iPhone 8s Repaired With Aftermarket Screens (vice.com) 229

An anonymous reader quotes a report from Motherboard: Apple released iOS 11.3 at the end of March, and the update is killing touch functionality in iPhone 8s repaired with some aftermarket screens that worked prior to the update. That means people who broke their phone and had the audacity to get it repaired by anyone other than Apple is having a hard time using their phone. "This has caused my company over 2,000 reshipments," Aakshay Kripalani, CEO of Injured Gadgets, a Georgia-based retailer and repair shop, told me in a Facebook message. "Customers are annoyed and it seems like Apple is doing this to prevent customers from doing 3rd party repair." According to Michael Oberdick -- owner and operator of iOutlet, an Ohio-based pre-owned iPhone store and repair shop, every iPhone screen is powered by a small microchip, and that chip is what the repair community believes to be causing the issue. For the past six months, shops have been able to replace busted iPhone 8 screens with no problem, but something in the update killed touch functionality. According to several people I spoke to, third-party screen suppliers have already worked out the issue, but fixing the busted phones means re-opening up the phone and upgrading the chip. It remains to be seen whether Apple will issue a new software update that will suddenly fix these screens, but that is part of the problem: Many phones repaired by third parties are ticking timebombs; it's impossible for anyone to know if or when Apple will do something that breaks devices fixed with aftermarket parts. And every time a software update breaks repaired phones, Apple can say that third-party repair isn't safe, and the third-party repair world has to scramble for workarounds and fixes.
Space

Northrop Grumman, Not SpaceX, Reported To Be at Fault For Loss of Top-Secret Zuma Satellite (cnbc.com) 70

Northrop Grumman built and operated the components that failed during the controversial January launch of the U.S. spy satellite known as Zuma, WSJ reported over the weekend. From a report: Two independent investigations, made up of federal and industry officials, pointed to Northrop's payload adapter as the cause of the satellite's loss, the report said, citing people familiar with the probes. The payload adapter is a key part of deploying a satellite in orbit, connecting the satellite to the upper stage of a rocket. Zuma is believed to have cost around $3.5 billion to develop, according to the report. The satellite was funded through a process that received a lesser degree of oversight from Congress compared with similar national security-related satellites, industry officials said.
Transportation

Dual-Motor Tesla Model 3 Possibly Coming In July (electrek.co) 71

According to Elon Musk, the dual-motor Tesla Model 3 is expected to be released in July. "Musk linked the release of the new Model 3 powertrain with the automaker achieving a production rate of 5,000 Model 3 vehicles per week," reports Electrek. From the report: Earlier this year, we reported on Tesla registering 19 Model 3 VINs with dual motor powertrain with NHTSA in the latest batch of new VINs. It happened right after the Tesla Model 3 dual motor powertrain design leaked in the latest design studio update. Then in February, Tesla registered a new batch of Model 3 VINs, including two dozen Model 3 VINs with the dual motor powertrain. It raised Model 3 reservation holders' hope that the new configuration could soon become available, but now Musk confirmed that it is still a few months away in a series of tweets last night. The CEO also linked the timing with the release of the Model 3 white interior. Tesla currently only offers a single interior option with black upholstery. The dual motor Model 3 is expected to deliver a slightly longer range and offer a quicker acceleration than the current single motor rear-wheel-drive version.
Power

All Apple Operations Now Run Off 100 Percent Renewable Energy (9to5mac.com) 116

According to a recently-shared press release, Apple has finally hit its goal of running its own operations off 100% renewable energy. "All Apple facilities, from Apple Park to its data centers to worldwide fleet of Apple retail stores, are now solely powered by green energy," reports 9to5Mac. From the report: This figure does not include Apple's third-party suppliers or manufacturers, although the company is convincing many of those to switch to 100% renewable sources too. Apple's environment VP Lisa Jackson discussed the news in an interview with Fast Company. Jackson highlights how Apple has not only focused on reducing emissions but also contributed to the availability of green energy on the grid. Apple has gone from 16% renewable energy to 100% in eight years, with CO2 emissions falling by 58%. The company has built numerous wind and solar farms in cooperation with local institutions, as well as intense focus on environmental sustainability during development of its new buildings like Apple Park. Its data centers are flanked by fields of solar panels. Filling out the last 4% required Apple to find renewable energy sources in some of its more remote retail stores and offices. It has signed power purchase agreements in Brazil, India, Israel, Mexico and Turkey.
Security

Don't Give Away Historic Details About Yourself (krebsonsecurity.com) 158

Brian Krebs: Social media sites are littered with seemingly innocuous little quizzes, games and surveys urging people to reminisce about specific topics, such as "What was your first job," or "What was your first car?" The problem with participating in these informal surveys is that in doing so you may be inadvertently giving away the answers to "secret questions" that can be used to unlock access to a host of your online identities and accounts. I'm willing to bet that a good percentage of regular readers here would never respond -- honestly or otherwise -- to such questionnaires (except perhaps to chide others for responding). But I thought it was worth mentioning because certain social networks -- particularly Facebook -- seem positively overrun with these data-harvesting schemes. What's more, I'm constantly asking friends and family members to stop participating in these quizzes and to stop urging their contacts to do the same.

On the surface, these simple questions may be little more than an attempt at online engagement by otherwise well-meaning companies and individuals. Nevertheless, your answers to these questions may live in perpetuity online, giving identity thieves and scammers ample ammunition to start gaining backdoor access to your various online accounts.

The Internet

'Erotic Review' Blocks US Internet Users To Prepare For Government Crackdown (arstechnica.com) 154

An anonymous reader quotes a report from Ars Technica: A website that hosts customer reviews of sex workers has started blocking Internet users in the United States because of forthcoming changes in U.S. law. Congress recently passed the Stop Enabling Sex Traffickers Act bill (SESTA), and President Trump is expected to sign it into law. SESTA will make it easier to prosecute websites that host third-party content that promotes or facilitates prostitution, even in cases when the sex workers aren't victims of trafficking. After Congress approved the bill, Craigslist removed its "Personals" section and Reddit removed some sex-related subreddits. The Erotic Review (TER) has followed suit by blocking any user who appears to be visiting the website from the United States.

"As a result of this new law, TER has made the difficult decision to block access to the website from the United States until such time as the courts have enjoined enforcement of the law, the law has been repealed or amended, or TER has found a way to sufficiently address any legal concerns created by the new law," the website's home page says in a notice to anyone who accesses the site from a US location. The Erotic Review explained in an FAQ why it blocked US-based users even before SESTA takes effect. (The bill is also known as the Allow States and Victims to Fight Online Sex Trafficking Act, or FOSTA.) "TER has always operated within the law, and it takes SESTA seriously," the FAQ says. "Because we do not know when SESTA will be signed into law, TER wants to be certain that it is in compliance with the statute the moment it becomes effective."
TER can still be accessed outside the U.S., and U.S.-based users can still access the site via a VPN service. "Non-U.S. are asked to agree to a disclaimer, which requires users to agree to 'report suspected exploitation of minors and/or human trafficking' and that they 'will not access TER from a Prohibited Country,'" reports Ars.
Businesses

The Uber-For-Bikes Startup Is Now Officially Part of Uber (qz.com) 51

Uber's first acquisition under CEO Dara Khosrowshahi is of Jump Bikes, a startup that rents out shared electric dockless bikes in San Francisco and Washington DC. "The deal comes two months after Uber partnered with Jump in San Francisco to make bike rentals available through the Uber app," reports Quartz. From the report: TechCrunch reports that the deal was valued at close to $200 million. Jump, which launched in 2008 as Social Bicycles, had raised about $15 million in funding. In January the company became the first in San Francisco to receive a permit for a dockless e-bike program. Jump's team will stay "independent and focused on growth vs. integration," with CEO Ryan Rzepecki reporting directly to Khosrowshahi, Uber's CEO told his company in an email this morning (April 9). In a post on Medium, Rzepecki said Khosrowshahi's leadership made Jump feel more comfortable with the deal. "We could see the shift in the company once Dara was named CEO as he began leading with humility and in a way that we felt reflected our values," Rzepecki wrote.

Slashdot Top Deals