Windows

Microsoft Releases New Tool To Get More Distros on Windows (zdnet.com) 216

Microsoft has released a tool to help Linux distribution maintainers bring their distros to the Windows Store to run on Windows 10's Windows Subsystem for Linux. From a report: Microsoft describes the tool as a "reference implementation for a Windows Subsystem for Linux (WSL) distribution installer application," which is aimed at both distribution maintainers and developers who want to create custom Linux distributions for running on WSL. "We know that many Linux distros rely entirely on open-source software, so we would like to bring WSL closer to the OSS community," said Tara Raj of Microsoft's WSL team. "We hope open-sourcing this project will help increase community engagement and bring more of your favorite distros to the Microsoft Store." WSL helps programmers build a full Linux development environment for testing production code on a Windows machine.
Security

Atlanta, Hit by Ransomware Attack, Also Fell Victim To Leaked NSA Exploits (zdnet.com) 75

Zack Whittaker, reporting for ZDNet: It's been almost a week since the City of Atlanta was hit by a ransomware attack, which encrypted city data and led to the shutdown of some services. Mayor Keisha Lance Bottoms said in a press conference Monday that the city's government is working on recovering the network after ransom notes appeared on computer displays on Thursday afternoon. The city has hired local cybersecurity firm SecureWorks to assess the situation. Reports say the notorious SamSam ransomware was used in the Atlanta attack, which exploits a deserialization vulnerability in Java-based servers.

[...] But according to one security firm, last week's cyberattack was not a surprise because the city had fallen victim to leaked government exploits used in the WannaCry outbreak. New data provided by Augusta, Ga.-based cybersecurity firm Rendition Infosec, seen by ZDNet, shows that the city's network was silently infected last year with leaked exploits developed by the National Security Agency. The cybersecurity firm's founder Jake Williams said at least five internet-facing city servers were infected with the NSA-developed DoublePulsar backdoor in late April to early May 2017. That was more than a month after Microsoft released critical patches for the exploits and urged users to install.

Facebook

It's Possible that the Facebook App is Listening To You, Cambridge Analytica Whistleblower Says (theoutline.com) 204

Jon Christian, writing for The Outline: During an appearance before a committee of U.K. lawmakers today, Cambridge Analytica whistleblower Christopher Wylie breathed new life into longstanding rumors that the Facebook app listens to its users in order to target advertisements. Damian Collins, a member of parliament who chaired the committee, asked whether the Facebook app might listen to what users are discussing and use it to prioritize certain ads.

"That's probably a question for Facebook," Wylie said. But, Wylie said in a meandering reply, it's possible that Facebook and other smartphone apps are listening in for reasons other than speech recognition. Specifically, he said, they might be trying to ascertain what type of environment a user is in in order to "improve the contextual value of the advertising itself. There's audio that could be useful just in terms of, are you in an office environment, are you outside, are you watching TV, what are you doing right now?" Wylie said, without elaborating on how that information could help target ads.

AI

Baidu Shows Off Its Instant Pocket Translator (technologyreview.com) 43

MIT Technology Review: Baidu showed off the speed of its pocket translator for the first time in the United States during an afternoon presentation at MIT Technology Review's EmTech Digital conference in San Francisco. The Chinese Internet giant has made significant strides improving machine language translation since 2015, using an advanced form of artificial intelligence known as deep learning, said Hua Wu, the company's chief scientist focused on natural-language processing. On stage, the Internet-connected device was able to almost instantly translate a short conversation between Wu and senior editor Will Knight. It easily rendered Knight's questions -- including "Where can I buy this device?" and "When will machines replace humans?" -- into Mandarin, and relayed Wu's responses in clear, if machine-inflected, English.
Medicine

Meet the Interstitium, the Largest Organ We Never Knew We Had (thedailybeast.com) 208

An anonymous reader quotes a report from The Daily Beast: A study published in Scientific Reports on Tuesday suggests that a previously unknown organ has been found in the human body. More astonishingly, the paper puts forth the idea that this new organ is the largest by volume among all 80 organs -- if what the researchers found is, in fact, an organ. The new organ, [pathologist Neil Theise] explained, was a thin layer of dense connective tissue throughout the body, sandwiched just under our skin and within the middle layer of every visceral organ. The organ also made up all the fascia, or the thin mesh of tissue separating every muscle and all the tissue around every vein and artery, from largest to smallest. What initially seemed to be a solid, dense, connective tissue layer was actually a complex network of fluid-filled cavities that are strong and flexible, yet so tiny and undiscerning that they escaped the attention of the brightest scientific minds for generations. In fact, Theise expanded, this "interstitium" could explain many of modern medicine's mysteries, often dismissed by the establishment as either silly or explainable by other phenomena. Take acupuncture, Theise said -- that energetic healing jolt may be traced to the interstitium. Or perhaps the interstitium acted as a "shock absorber," something that protected other organs and muscles in daily function. Also, the space is in direct communication with the lymphatic system as the origin of lymph fluid -- which means the interstitium's system of fluid-filled backroads could explain the metastasis of cancer cells and their quick spread beyond the limits of the organ in which the cancer started.
Cloud

Google Launches More Realistic Text-To-Speech Service Powered By DeepMind's AI (theverge.com) 34

Google is launching a new AI voice synthesizer, named Cloud Text-to-Speech, that will be available for any developer or business that needs voice synthesis on tap, whether that's for an app, website, or virtual assistant. The Cloud Text-to-Speech service is being powered by WaveNet, software created by Google's UK-based AI subsidiary DeepMind. The Verge explains why this is significant: First, ever since Google bought DeepMind in 2014, it's been exploring ways to turn the company's AI talent into tangible products. So far, this has meant using DeepMind's algorithms to reduce electricity costs in Google's data centers by 40 percent and DeepMind's forays into health care. But, directly integrating WaveNet into its cloud service is arguably more significant, especially as Google tries to win cloud business away from Amazon and Microsoft, presenting its AI skills as its differentiating factor. Second, DeepMind's AI voice synthesis tech is some of the most advanced and realistic in the business. Most voice synthesizers (including Apple's Siri) use what's called concatenative synthesis, in which a program stores individual syllables -- sounds such as "ba," "sht," and "oo" -- and pieces them together on the fly to form words and sentences. This method has gotten pretty good over the years, but it still sounds stilted.

WaveNet, by comparison, uses machine learning to generate audio from scratch. It actually analyzes the waveforms from a huge database of human speech and re-creates them at a rate of 24,000 samples per second. The end result includes voices with subtleties like lip smacks and accents. When Google first unveiled WaveNet in 2016, it was far too computationally intensive to work outside of research environments, but it's since been slimmed down significantly, showing a clear pipeline from research to product.
The Verge has embedded some samples in their report to see how WaveNet sounds.
Businesses

Nearly a Third of Tech Workers Are Ready To #DeleteFacebook (betanews.com) 307

An anonymous reader quotes a report from BetaNews: A survey conducted in the wake of the #DeleteFacebook campaign that followed revelations about the data breach and the logging of Android users' calls and texts, found that a surprising number of tech workers were ready to delete their Facebook accounts. 31 percent backed the #DeleteFacebook campaign, including 50 percent of Microsoft workers, and 38 percent of Google workers. The survey -- conducted using the anonymous app Blind -- found that nearly a third of those questioned were planning to delete their Facebook accounts. In all, over 2,600 people were surveyed between March 20, 2018 and March 24, 2018, so it neatly took in the peak of the controversy. Broken down by company, the numbers make for interesting reading:

-50 percent of Microsoft employees said they will delete Facebook.
-46 percent of Snapchat employees said they would delete Facebook.
-40 percent of Uber employees said they would delete Facebook.
-38 percent of Google employees said they would delete Facebook.
-34 percent of Amazon employees said they would delete Facebook.
-2 percent of Facebook employees said they would delete Facebook.

AI

NVIDIA Unveils 2 Petaflop DGX-2 AI Supercomputer With 32GB Tesla V100, NVSwitch Tech 41

bigwophh writes from a report via HotHardware: NVIDIA CEO Jensen Huang took to the stage at GTC today to unveil a number of GPU-powered innovations for machine learning, including a new AI supercomputer and an updated version of the company's powerful Tesla V100 GPU that now sports a hefty 32GB of on-board HBM2 memory. A follow-on to last year's DGX-1 AI supercomputer, the new NVIDIA DGX-2 can be equipped with double the number of Tesla V100 processing modules for double the GPU horsepower. The DGX-2 can also have four times the available memory space, thanks to the updated Tesla V100's larger 32GB of memory. NVIDIA's new NVSwitch technology is a fully crossbar GPU interconnect fabric that allows NVIDIA's platform to scale to up to 16 GPUs and utilize their memory space contiguously, where the previous DGX-1 NVIDIA platform was limited to 8 total GPU complexes and associated memory. NVIDIA claims NVSwitch is five times faster than the fastest PCI Express switch and offers an aggregate 2.4TB per second of bandwidth. A new Quadro card was also announced. Called the Quadro GV100, it too is being powered by Volta. The Quadro GV100 packs 32GB of memory and supports NVIDIA's recently announced RTX real-time ray tracing technology.
China

Forget Millennials, the Internet's Most Wanted Users Are Older -- and Poorer (wsj.com) 58

An anonymous reader writes: China's relatively young internet industry is facing a mature-market problem: User growth for popular online services such as instant messaging, search, online news and video has fallen to single digits. Online population growth has hovered around 5% to 6% annually since 2014, which is only slightly higher than in mature economies. Unlike in many developed markets, a vast number of Chinese are unconnected. As they slowly come online, they're creating a sizable market that companies can tap into -- if they can figure out how.

"The Chinese internet is experiencing the third wave of [a] demographic dividend," said Wang Hua, a partner at venture-capital firm Sinovation Ventures, at a speech in December. The first wave, he said, were early adopters, while the second was driven by young people in major cities. "About half of the Chinese population is not yet heavy internet users, and they're the third wave of the demographic dividend," he says. "And they're usually the ones that are in charge of a family's daily consumption." Only 56% of 1.4 billion Chinese -- about 772 million people -- use the internet, according to official data. The U.S. reached that level of penetration in 2002, according to the United Nations. Interest in the lower end of the internet market has been building; live-streaming services have managed to attract working-class Chinese. This time around, the spread of e-commerce and new business models are unlocking more potential.

Privacy

Researchers Discover Flaws in Digital Currency Monero That Could Reveal Identity of Users (wired.com) 35

Researchers have discovered flaws in Monero, a digital currency that boasts a high degree of anonymity, that could lead to the identification of users. From a report: Monero is designed to mix up any given Monero "coin" with other payments, so that anyone scouring Monero's blockchain can't link it to any particular identity or previous transaction from the same source. But in a recent paper, a team of researchers from a broad collection of institutions -- including Princeton, Carnegie Mellon, Boston University, MIT, and the University of Illinois at Urbana-Champaign -- point to flaws in that mixing that make it possible to nonetheless extract individual transactions.

That shouldn't just worry anyone trying to stealthily spend Monero today. It also means evidence of earlier not-quite-untraceable payments remain carved into Monero's blockchain for years to come, visible for any snoop that cares to look.

Security

Intel CPUs Vulnerable To New 'BranchScope' Attack (securityweek.com) 102

wiredmikey writes: Researchers have discovered a new side-channel attack method dubbed "BranchScope" that can be launched against devices with Intel processors. The attack has been identified and demonstrated by a team of researchers, and similar to Meltdown and Spectre, can be exploited by an attacker to obtain potentially sensitive information they normally would not be able to access directly. The attacker needs to have access to the targeted system and they must be able to execute arbitrary code.

Researchers believe the requirements for such an attack are realistic, making it a serious threat to modern computers, "on par with other side-channel attacks." The BranchScope attack has been demonstrated on devices with three types of Intel i5 and i7 CPUs based on Skylake, Haswell and Sandy Bridge microarchitectures.
Further reading: As predicted, more branch prediction processor attacks are discovered (ArsTechnica).
Microsoft

Microsoft To Ban 'Offensive Language' From Skype, Xbox, Office and Other Services (csoonline.com) 317

According to Microsoft's new Terms of Services agreement, you could get banned for "offensive language," resulting in the termination of your Gold Membership and/or any Microsoft account balances. The changes go into effect on May 1. CSO Online reports: [I]f you and a significant other are getting hot and heavy via Skype, you better watch your language and any nudity because that, too, can get you banned. The ban hammer could also fall if Cortana is listening at the wrong moment or if documents and files hosted on Microsoft services violate Microsoft's amended terms. But how would Microsoft even know if you had truly been "offensive?" Well, that part falls under Code of Conduct Enforcement, which states, "When investigating alleged violations of these Terms, Microsoft reserves the right to review Your Content in order to resolve the issue." Microsoft did add, "However, we cannot monitor the entire Services and make no attempt to do so." I'm not sure that will make you feel better, as another portion states that Microsoft "may also block delivery of a communication (like email, file sharing or instant message) to or from the Services in an effort to enforce these Terms or we may remove or refuse to publish Your Content for any reason."
Security

macOS High Sierra Logs Encryption Passwords in Plaintext for APFS External Drives (bleepingcomputer.com) 62

Catalin Cimpanu, writing for BleepingComputer: macOS High Sierra users are once again impacted by a major APFS bug after two other major vulnerabilities affected Apple's new filesystem format in the last five months. This time around, according to a report from Mac forensics expert Sarah Edwards, recent versions of macOS High Sierra are logging encryption passwords for APFS-formatted external drives in plaintext, and storing this information in non-volatile (on-disk) log files.

The issue, if exploited, could allow an attacker easy access to the encryption password of encrypted APFS external volumes, such as USB thumb drives, portable hard drives, and other external storage mediums. This bug goes against all well-established Apple development and security rules, according to which apps and utilities should use the Keychain app to store valuable information, and should definitely avoid storing passwords in cleartext.
Video 1, and 2.
Apple

An Apple Facility That Repairs iPhones in California Won't Stop Calling 9-1-1 -- and Nobody Knows How To Stop It (businessinsider.com) 190

The small city of Elk Grove, California received more than 2,000 erroneous 911 calls from Apple devices at an Apple repair facility. The months-long issue is yet to be resolved. From a report: Between October 20, 2017 and February 23, 2018, the police department in Elk Grove, California received 2,028 calls on its 911 lines originating from the Apple facility -- an average of 16 calls per day. At one point in January, the calls from the Apple factory were so frequent that they tied up every single one of Elk Grove's six 911 lines, according to public documents reviewed by Business Insider. "They lit us up like a Christmas tree," one dispatcher wrote in in an email to other dispatchers. It was obvious to Elk Grove police that the 911 calls were not real emergencies, but rather, the equivalent of accidental "butt dials," mysteriously ringing the city's hotline on an assembly-line scale.

For whatever reason, many of the iPhones being repaired at the Apple facility were going rogue and dialing 911. But for city officials trying to stop the nuisance and to ensure that a critical emergency resource was not overburdened, fixing the problem has not been easy. Despite crediting Apple for being responsive to their pleas for help, Elk Grove officials have been frustrated by the company's inability to fix the problem. At one point, officials even discussed the possibility of getting the state government involved and sending police to the factory.

AT&T

AT&T/Verizon Lobbyists To 'Aggressively' Sue States That Enact Net Neutrality (arstechnica.com) 133

An anonymous reader quotes a report from Ars Technica: A lobby group that represents AT&T, Verizon, and other telcos plans to sue states and cities that try to enforce net neutrality rules. USTelecom, the lobby group, made its intentions clear yesterday in a blog post titled, "All Americans Deserve Equal Rights Online." "Broadband providers have worked hard over the past 20 years to deploy ever more sophisticated, faster and higher-capacity networks, and uphold net neutrality protections for all," USTelecom CEO Jonathan Spalter wrote. "To continue this important work, there is no question we will aggressively challenge state or municipal attempts to fracture the federal regulatory structure that made all this progress possible." The USTelecom board of directors includes AT&T, Verizon, Frontier, CenturyLink, Windstream, and other telcos. The group's membership "ranges from the nation's largest telecom companies to small rural cooperatives."

Slashdot Top Deals