Security

Hacker Adrian Lamo Dies At 37 (zdnet.com) 137

Adrian Lamo, a well-known hacker known for his involvement in passing information on whistleblower Chelsea Manning and hacking into systems at The New York Times, Microsoft, and Yahoo in the early-2000s, has died at 37. ZDNet reports: His father, Mario, posted a brief tribute to his son in a Facebook group on Friday. "With great sadness and a broken heart I have to let know all of Adrian's friends and acquittances that he is dead. A bright mind and compassionate soul is gone, he was my beloved son," he wrote. The coroner for Sedgwick County, where Lamo lived, confirmed his death, but provided no further details. Circumstances surrounding Lamo's death are not immediately known. A neighbor who found his body said he had been dead for some time.
Facebook

Facebook Says It is Sorry For Suggesting Child Sex Videos in Search (cnet.com) 48

Facebook issued an apology on Friday after offensive terms appeared in the social network's search predictions late Thursday. From a report: When users typed "videos of" into the search bar, Facebook prompted them to search phrases including "videos of sexuals," "videos of girl sucking dick under water" and, perhaps most disturbingly, "video of little girl giving oral." Shocked users reported the problem on Twitter, posting screenshots of the search terms, which also included multiple suggestions relating to the school shooting in Florida last month. The social network appeared to have fixed the problem by Friday morning.
Businesses

'They'll Squash You Like a Bug': How Silicon Valley Keeps a Lid on Leakers (theguardian.com) 99

The public image of Silicon Valley's tech giants is all colourful bicycles, ping-pong tables, beanbags and free food, but behind the cartoonish facade is a ruthless code of secrecy. From a report: They rely on a combination of Kool-Aid, digital and physical surveillance, legal threats and restricted stock units to prevent and detect intellectual property theft and other criminal activity. However, those same tools are also used to catch employees and contractors who talk publicly, even if it's about their working conditions, misconduct or cultural challenges within the company. While Apple's culture of secrecy, which includes making employees sign project-specific NDAs and covering unlaunched products with black cloths, has been widely reported, companies such as Google and Facebook have long put the emphasis on internal transparency.

Zuckerberg hosts weekly meetings where he shares details of unreleased new products and strategies in front of thousands of employees. Even junior staff members and contractors can see what other teams are working on by looking at one of many of the groups on the company's internal version of Facebook. "When you first get to Facebook you are shocked at the level of transparency. You are trusted with a lot of stuff you don't need access to," said Evans, adding that during his induction he was warned not to look at ex-partners' Facebook accounts.

China

China To Bar People With Bad 'Social Credit' From Planes, Trains (reuters.com) 170

China says it will begin applying its so-called social credit system to flights and trains and stop people who have committed misdeeds from taking such transport for up to a year. From a report: People who would be put on the restricted lists included those found to have committed acts like spreading false information about terrorism and causing trouble on flights, as well as those who used expired tickets or smoked on trains, according to two statements issued on the National Development and Reform Commission's website on Friday. Those found to have committed financial wrongdoings, such as employers who failed to pay social insurance or people who have failed to pay fines, would also face these restrictions, said the statements which were dated March 2. It added that the rules would come into effect on May 1.
Bitcoin

For the First Time, a US City Has Banned Cryptocurrency Mining (businessinsider.com) 198

CaptainDork writes: The city of Plattsburgh, New York is imposing an 18-month moratorium on commercial cryptocurrency mining. The official reasoning for the moratorium is to "protect and enhance the City's natural, historic, cultural and electrical resources." Plattsburgh residents have seen skyrocketing electrical bills -- as much as $100 to $200 increases -- as a result of commercial cryptomining operations that mine for cryptocurrencies like bitcoin, according to Plattsburgh Mayor Colin Read, who spoke with Motherboard. The city is taking action to protect its citizens from those rising electrical bills that the city of Plattsburgh says is caused by cryptomining operations.

It turns out that commercial cryptocurrency mining operations used up so much electricity that the city of Plattsburgh exceeded its allotted monthly budget of electricity. One single cryptocurrency mining operation called Coinmint used up around 10% of the city's allotted power supply alone in January and February, according to Motherboard. When its electrical budget was exceeded in January, the city had to buy electricity from the open market at a higher cost, which was distributed among its residents.

The Internet

Tumblr Has a Massive Creepshots Problem (vice.com) 122

After Reddit famously banned the creepshots sub-reddit, which shared non-consensual, revealing photos of women, Tumblr now has a slew of users pushing out similar photos across at least dozens of dedicated blogs, a Motherboard investigation has found. From the report: Simply typing 'creepshot' or related terms into Tumblr's built-in search function returns a steady stream of tagged posts, and Google queries easily reveal links to relevant Tumblr blogs. Motherboard found just under 70 Tumblr blogs focused on sharing creepshots, most with a bevy of content. In some cases, the Tumblrs also host 'upskirt' photos or videos, where a camera is deliberately, and stealthily, positioned to look up an unsuspecting person's skirt. Some of the subjects of these images, as well as many of the clothed creepshots, appear to be young, possibly teenagers.

"This is only the tip of the iceberg, there are probably hundreds of these accounts filming in high schools, college campuses, in malls, and on the streets. And Tumblr seems to not care at all about the problem," an anonymous tipster, who first alerted Motherboard to the issue, wrote in an email. One of the most popular creepshot Tumblrs has some 11,000 followers, and one of its posts has over 53,000 interactions linked to it, including reblogs, where the video or picture then appears on the user's own Tumblr, spreading the content further.

Google

Yet Again, Google Tricked Into Serving Scam Amazon Ads (zdnet.com) 49

Zack Whittaker, reporting for ZDNet: For hours on Thursday, the top Google search result for "Amazon" was pointed to a scam site. The bad ad appeared at the very top of the search result for anyone searching for the internet retail giant -- even above the legitimate search result for Amazon.com. Anyone who clicked on the ad was sent to a page that tried to trick the user into calling a number for fear that their computer was infected with malware -- and not sent to Amazon.com as they would have hoped.

The page presents itself as an official Apple or Windows support page, depending on the type of computer you're visiting the page from. An analysis of the webpage's code showed that anyone trying to dismiss the popup box on the page would likely trigger the browser expanding to full-screen, giving the appearance of ransomware. A one-off event would be forgivable. But this isn't the first time this has happened. It's at least the second time in two years that Google has served up a malicious ad under Amazon's name.

Android

Android Is Now as Safe as the Competition, Google Says (cnet.com) 116

In an interview with CNET, David Kleidermacher, Google's head of security for Android, Google Play and Chrome OS, said Android is now as safe as the competition. From the interview: That's a big claim, considering that Android's main competitor is Apple's iPhone. This bold idea permeates the annual Android Security Report that Google released Thursday. "Android security made a significant leap forward in 2017 and many of our protections now lead the industry," the report says on page one. Echoing the report, Kleidermacher told CNET that Android flaws have become harder for researchers to find and that the software now protects users from malicious software so well the problems that used to leave users exposed to bad actors aren't such a big problem anymore.
Wireless Networking

Ask Slashdot: Are There Any USB-C Wireless Video Solutions? 127

jez9999 writes: Sometimes it feels like we're on the cusp of a technology but not quite there yet, and that's the way it feels for me after searching around for USB-C wireless video solutions. There are several wireless video solutions that use HDMI on the receiver end, of course, but these aren't ideal because HDMI can't provide power. This means you need a separate receiver box and power cable going into the box, but cables are what you're trying to get away from with wireless video!

So the answer to this would seem to be USB-C. It supports HDMI video as well as power, so in theory you could create a receiver dongle that just plugged into a TV (or monitor with speakers) and required no external power cable. Unfortunately, I haven't been able to find anything like this on the market.

There is Airtame, but that doesn't work with a 'dumb' TV -- it needs to plug in to a computer that you can install software on to stream the video. What I'd like is to be able to wall-mount a new TV and just plug in a wireless dongle to stream the video with no extra setup required on the receiver end.

Does anyone know of a solution like this that exists right now, or one that's being developed?
United States

Chinese Hackers Hit US Firms Linked To South China Sea Dispute (bloomberg.com) 52

Chinese hackers have launched a wave of attacks on mainly U.S. engineering and defense companies linked to the disputed South China Sea, the cybersecurity firm FireEye Inc. said. From a report: The suspected Chinese cyber-espionage group dubbed TEMP.Periscope appeared to be seeking information that would benefit the Chinese government, said FireEye, a U.S.-based provider network protection systems. The hackers have focused on U.S. maritime entities that were either linked to -- or have clients operating in -- the South China Sea, said Fred Plan, senior analyst at FireEye in Los Angeles.

"They are going after data that can be used strategically, so it is line with state espionage," said Plan, whose firm has tracked the group since 2013. "A private entity probably wouldn't benefit from the sort of data that is being stolen." The TEMP.Periscope hackers were seeking information in areas like radar range or how precisely a system in development could detect activity at sea, Plan said. The surge in attacks picked up pace last month and was ongoing.

Businesses

US Utilities Have Finally Realized Electric Cars May Save Them (qz.com) 297

Pity the utility company. For decades, electricity demand just went up and up, as surely as the sun rose in the east. Power companies could plan ahead with confidence. No longer. From a report: This year, the Tennessee Valley Authority scrapped its 20-year projections through 2035, since it was clear they had drastically underestimated the extent to which renewable energy would depress demand for electricity from the grid. But there is a bright spot for utilities: electric vehicles (EV), which make up 1% of the US car market.

For years, that market barely registered on utilities' radar. As EVs find growing success, utilities are building charging infrastructure and arranging generous rebates. Pacific Gas and Electric, Southern California Edison, San Diego Gas & Electric, and New Jersey's PSE&G have partnered with carmakers to offer thousands of dollars in rebates for BMW, Nissan, and other brands. Now utilities are asking Congress for help as they attempt to keep tapping into EV demand. A collection of 36 of the nation's largest utilities wrote a letter (PDF) to congressional leadership on March 13, asking for a lift on the cap on EV tax credits. The signatories' include California's Pacific Gas & Electric, New York's Consolidated Edison, the southeast's Duke Energy Company, and others covering almost every state. At the moment, Americans who buy electric vehicles receive a $7,500 federal tax credit (along with some state incentives) for each vehicle.

Earth

Microplastics Found In 93 Percent of Bottled Water Tested In Global Study (www.cbc.ca) 177

An anonymous reader quotes a report from CBC.ca: The bottled water industry is estimated to be worth nearly $200 billion a year, surpassing sugary sodas as the most popular beverage in many countries. But its perceived image of cleanliness and purity is being challenged by a global investigation that found the water tested is often contaminated with tiny particles of plastic. The research was conducted on behalf of Orb Media, a U.S-based non-profit journalism organization with which CBC News has partnered. Professor Sherri Mason, a microplastics researcher who carried out the laboratory work at the State University of New York, and his team tested 259 bottles of water purchased in nine countries (none were bought in Canada). Though many brands are sold internationally, the water source, manufacturing and bottling process for the same brand can differ by country. The 11 brands tested include the world's dominant players -- Nestle Pure Life, Aquafina, Dasani, Evian, San Pellegrino and Gerolsteiner -- as well as major national brands across Asia, Africa, Europe and the Americas. Researchers found 93 per cent of all bottles tested contained some sort of microplastic, including polypropylene, polystyrene, nylon and polyethylene terephthalate (PET).

Orb found on average there were 10.4 particles of plastic per liter that were 100 microns (0.10 mm) or bigger. This is double the level of microplastics in the tap water tested from more than a dozen countries across five continents, examined in a 2017 study by Orb that looked at similar-sized plastics. Other, smaller particles were also discovered -- 314 of them per liter, on average -- which some of the experts consulted about the Orb study believe are plastics but cannot definitively identify. The amount of particles varied from bottle to bottle: while some contained one, others contained thousands.

Security

Microsoft Launches Bounty Program For Speculative Execution Side Channel Vulnerabilities (betanews.com) 21

An anonymous reader shares a report: Microsoft has launched a bug bounty program that will reward anyone who finds the next Meltdown or Spectre vulnerability. Known as speculative execution side channel vulnerabilities, Microsoft is willing to reward anyone who reports bugs that could cause problems like earlier in the year. The rewards on offer range from $5,000 up to $250,000 depending on the severity of the vulnerability, and the bounty program runs until the end of 2018. Microsoft says that it will operate under the principles of coordinated vulnerability disclosure.
NASA

No, Space Did Not Permanently Alter 7 Percent of Scott Kelly's DNA (theverge.com) 51

Several stories this week have proclaimed that the DNA of former NASA astronaut Scott Kelly changed during his year living on the International Space Station. The stories say that 7 percent of his genes did not return back to normal when he came back to Earth. It makes it seem as if the space environment permanently altered his genetic code. The problem? That's not true. From a report: The mistake stems from an inaccurate interpretation of NASA's ongoing Twins Study. When Scott went to space in 2015, his identical twin Mark -- also a former NASA astronaut -- stayed on the ground. The idea was that Mark would serve as a control subject -- a nearly identical genetic copy that NASA could use to figure out how the space environment changed Scott's body. Some fascinating results have come out of the experiment. For one thing, Scott's gut bacteria changed significantly while he was in space. And yes, he did experience genetic changes. The protective caps on the ends of his DNA strands -- known as telomeres -- increased while in space. But space didn't permenantly alter 7 percent of his DNA. [...] NASA also confirmed this in a statement to The Verge: "Scott's DNA did not fundamentally change," a NASA spokesperson said. "What researchers did observe are changes in gene expression, which is how your body reacts to your environment. This likely is within the range for humans under stress, such as mountain climbing or SCUBA diving."
Privacy

The 600+ Companies PayPal Shares Your Data With (schneier.com) 48

AmiMoJo shares a report from Schneier on Security: One of the effects of GDPR -- the new EU General Data Protection Regulation -- is that we're all going to be learning a lot more about who collects our data and what they do with it. Consider PayPal, that just released a list of over 600 companies they share customer data with. Here's a good visualization of that data. Is 600 companies unusual? Is it more than average? Less? We'll soon know.

Slashdot Top Deals