Desktops (Apple)

Intel Memory Access Design Flaw Partially Addressed by Apple in macOS 10.13.2 [Unconfirmed] (macrumors.com) 49

An anonymous reader shares a report: A serious design flaw and security vulnerability discovered in Intel CPUs has reportedly already been partially addressed by Apple in the recent macOS 10.13.2 update, which was released to the public on December 6. According to developer Alex Ionescu, Apple introduced a fix in macOS 10.13.2, with additional tweaks set to be introduced in macOS 10.13.3, currently in beta testing. AppleInsider also says that it has heard from "multiple sources within Apple" that updates made in macOS 10.13.2 have mitigated "most" security concerns associated with the KPTI vulnerability. A Bloomberg reporter pointed out that Apple has not officially commented on the story.
Microsoft

Microsoft Issues Rare Out-of-Band Emergency Windows Update For Processor Security Bugs (theverge.com) 129

An anonymous reader shares a report: Microsoft is issuing a rare out-of-band security update to supported versions of Windows today (Wednesday). The software update is part of a number of fixes that will protect against a newly-discovered processor bug in Intel, AMD, and ARM chipsets. Sources familiar with Microsoft's plans tell The Verge that the company will issue a Windows update that will be automatically applied to Windows 10 machines at 5PM ET / 2PM PT today. The update will also be available for older and supported versions of Windows today, but systems running operating systems like Windows 7 or Windows 8 won't automatically be updated through Windows Update until next Tuesday. Windows 10 will be automatically updated today.
Intel

Intel Says CEO Dumping Tons of Stock Last Year 'Unrelated' To Big Security Exploit (gizmodo.com) 93

An anonymous reader shares a report: Late last year, the CEO of Intel sold millions of dollars in company stock, as CEOs often do. The sale appears to have occurred while developers were reportedly rushing to fix a major security flaw affecting Intel processors made in the last decade. According to a report published by the Register this week, "a fundamental design flaw in Intel's processor chips has forced a significant redesign of the Linux and Windows kernels to defang the chip-level security bug." Windows and Linux developers have reportedly been working to address the issue since November. As our friends at Gizmodo ES pointed out, Intel's CEO Brian Krzanich sold roughly $11 million in company stock at the end of November. Counting the employee stock options Krzanich exercised, the CEO unloaded 245,743 shares, leaving him with 250,000 remaining shares -- the minimum Krzanich is required to own according to the company's bylaws, the Motley Fool reported. To be clear, this isn't proof of some insider-trading conspiracy. Contacted by Gizmodo, an Intel spokesperson called the sale "unrelated," and said it "was made pursuant to a pre-arranged stock sale plan (10b5-1) with an automated sale schedule."
Google

Google Says Almost All CPUs Since 1995 Vulnerable To 'Meltdown' And 'Spectre' Flaws (bleepingcomputer.com) 269

Catalin Cimpanu, reporting for BleepingComputer: Google has just published details on two vulnerabilities named Meltdown and Spectre that in the company's assessment affect "every processor [released] since 1995." Google says the two bugs can be exploited to "to steal data which is currently processed on the computer," which includes "your passwords stored in a password manager or browser, your personal photos, emails, instant messages and even business-critical documents." Furthermore, Google says that tests on virtual machines used in cloud computing environments extracted data from other customers using the same server. The bugs were discovered by Jann Horn, a security researcher with Google Project Zero, Google's elite security team. These are the same bugs that have been reported earlier this week as affecting Intel CPUs. Google was planning to release details about Meltdown and Spectre next week but decided to publish the reports today "because of existing public reports and growing speculation in the press and security research community about the issue, which raises the risk of exploitation."
Network

Asus Is Turning Its Old Routers Into Mesh Wi-Fi Networks (theverge.com) 30

Asus' new AiMesh system lets you repurpose your existing Asus routers as part of a mesh network, potentially saving you lots of money since you won't have to replace your whole network with a bunch of new devices. The Verge reports: For now, the mesh support is coming to a few routers today in beta, including the ASUS RT-AC68U, RT-AC1900P, RT-AC86U, RT-AC5300, and the ROG Rapture GT-AC5300, with additional support planned for the RT-AC88U and RT-AC3100 later this year. The setup looks pretty simple, too. Once your main router is set up and updated to the latest firmware, just take your other routers that are going to be the mesh nodes, plug them in near the main router, and run a factory reset, after which they'll automatically pop up in the Asus Router app to add to your mesh.
AI

AI System Sorts News Articles By Whether Or Not They Contain Actual Information (vice.com) 80

In a new paper published in the Journal of Artificial Intelligence Research, computer scientists from Google and the University of Pennsylvania describe a new machine learning approach to classifying written journalism according to a formalized idea of "content density." "With an average accuracy of around 80 percent, their system was able to accurately classify news stories across a wide range of domains, spanning from international relations and business to sports and science journalism, when evaluated against a ground truth dataset of already correctly classified news articles," reports Motherboard. From the report: At a high level this works like most any other machine learning system. Start with a big batch of data -- news articles, in this case -- and then give each item an annotation saying whether or not that item falls within a particular category. In particular, the study focused on article leads, the first paragraph or two in a story traditionally intended to summarize its contents and engage the reader. Articles were drawn from an existing New York Times linguistic dataset consisting of original articles combined with metadata and short informative summaries written by researchers.
Google

Google's Project Zero Team Discovered Critical CPU Flaw Last Year (techcrunch.com) 124

An anonymous reader quotes a report from TechCrunch: In a blog post published minutes ago, Google's Security team announced what they have done to protect Google Cloud customers against the chip vulnerability announced earlier today. They also indicated their Project Zero team discovered this vulnerability last year (although they weren't specific with the timing). The company stated that it informed the chip makers of the issue, which is caused by a process known as "speculative execution." This is an advanced technique that enables the chip to essentially guess what instructions might logically be coming next to speed up execution. Unfortunately, that capability is vulnerable to malicious actors who could access critical information stored in memory, including encryption keys and passwords. According to Google, this affects all chip makers, including those from AMD, ARM and Intel (although AMD has denied they are vulnerable). In a blog post, Intel denied the vulnerability was confined to their chips, as had been reported by some outlets. The Google Security team wrote that they began taking steps to protect Google services from the flaw as soon as they learned about it.
Advertising

Yes, Your Amazon Echo Is an Ad Machine (gizmodo.com) 177

An anonymous reader quotes a report from Gizmodo: CNBC reports that Amazon is in discussions with huge companies that want to promote their goods on Echo devices. Proctor & Gamble as well as Clorox are reportedly in talks for major advertising deals that would allow Alexa to suggest products for you to buy. CNBC uses the example of asking Alexa how to remove a stain, with Alexa in turn recommending a Clorox product. So far it's unclear how Amazon would identify promoted responses from Alexa, if at all. Here's the really wacky thing: Amazon has already been doing this sort of thing to some degree. Currently, paid promotions are built into Alexa responses, but maybe you just haven't noticed it. CNBC uses this example: "There are already some sponsorships on Alexa that aren't tied to a user's history. If a shopper asks Alexa to buy toothpaste, one response is, 'Okay, I can look for a brand, like Colgate. What would you like?'" So it seems like Amazon wants to get you coming and going. Not only does the company want to let you buy stuff with your voice. Jeff Bezos and friends also want to make money by suggesting what to buy and even by pushing those products higher up in the search results so that you're more likely to do it.
The Internet

Ajit Pai Backs Out of Planned CES 2018 Appearance (techcrunch.com) 277

New submitter sdinfoserv writes: Ajit Pai, the most hated person in tech since Darl McBride, backed out of a speaking engagement at CES 2018. Apparently he lacks the spine to justify himself before the group of individuals his decisions affect most. Consumer Technology Association head Gary Shapiro announced: "Unfortunately, Federal Communications Commission Chairman Ajit Pai is unable to attend CES 2018. We look forward to our next opportunity to host a technology policy discussion with him before a public audience."
The Internet

After Beating Cable Lobby, Colorado City Moves Ahead With Muni Broadband (arstechnica.com) 198

Last night, the city council in Fort Collins, Colorado, voted to move ahead with a municipal fiber broadband network providing gigabit speeds, two months after the cable industry failed to stop the project. Ars Technica reports: Last night's city council vote came after residents of Fort Collins approved a ballot question that authorized the city to build a broadband network. The ballot question, passed in November, didn't guarantee that the network would be built because city council approval was still required, but that hurdle is now cleared. Residents approved the ballot question despite an anti-municipal broadband lobbying campaign backed by groups funded by Comcast and CenturyLink. The Fort Collins City Council voted 7-0 to approve the broadband-related measures, a city government spokesperson confirmed to Ars today.

While the Federal Communications Commission has voted to eliminate the nation's net neutrality rules, the municipal broadband network will be neutral and without data caps. "The network will deliver a 'net-neutral' competitive unfettered data offering that does not impose caps or usage limits on one use of data over another (i.e., does not limit streaming or charge rates based on type of use)," a new planning document says. "All application providers (data, voice, video, cloud services) are equally able to provide their services, and consumers' access to advanced data opens up the marketplace." The city will also be developing policies to protect consumers' privacy. The city intends to provide gigabit service for $70 a month or less and a cheaper Internet tier.

Power

Why Most Electric Cars Are Leased, Not Owned (bloomberg.com) 206

Bloomberg's research shows that drivers in the U.S. lease almost 80 percent of battery-powered vehicles and 55 percent of plug-in hybrids. "The lease rate for the country's entire fleet hovers around 30 percent," reports Bloomberg, noting that Tesla does not divulge how many of its vehicles are leased since it sells its cars directly rather than through dealerships. From the report: The lopsided consumer preference for leases is fueled by the meager demand for battery-powered vehicles on the used market. Partly this is a consequence of public policy meant to spur electric vehicle adoptions: buyers of pre-owned cars can't grab thousands of dollars in federal and state incentives. The high lease rate is also fueled by the bet [many] are making that upcoming models will far exceed today's in value and capabilities. Perhaps electric vehicles will truly arrive when they are no longer compared to smartphones, which become obsolete after three years.
Wireless Networking

Roombas Will Soon Build a Wi-Fi Coverage Map While They Clean (techcrunch.com) 58

An anonymous reader quotes a report from TechCrunch: The feature is arriving later this month on the iRobot app, making it possible for WiFi-enabled Roombas to create a map of indoor signals. The map exists alongside the existing Clean Map feature, letting users toggle between the two, like they would, say, satellite and standard imagery in Google Maps. The maps themselves won't go into too much detail -- no upload and download speeds like you see on many mobile speed test apps. Instead, the information will show up as decibel readings. Really, it's intended as a handy way of showing off where you might want to toss a range extender, to help get rid of dead spots. All of Roomba's vacuums, save for the lowest-end model, will support the feature. The beta program launches January 23rd and appears to only be available for U.S. users.
Privacy

2 Years Later, Security Holes Linger In GPS Services Used By Millions of Devices (securityledger.com) 12

chicksdaddy quotes a report from The Security Ledger: Security researchers say that serious security vulnerabilities linger in GPS software by the China-based firm ThinkRace more than two years after the hole was discovered and reported to the firm, The Security Ledger reports. Data including a GPS enabled device's location, serial number, assigned phone number and model and type of device can be accessed by any user with access to the GPS service. In some cases, other information is available including the device's location history going back 1 week. In some cases, malicious actors could also send commands to the device via SMS including those used to activate or deactivate GEO fencing alarms features, such as those used on child-tracking devices.

The vulnerabilities affect hundreds of thousands of connected devices that use the GPS services, from smart watches, to vehicle GPS trackers, fitness trackers, pet trackers and more. At issue are security holes in back-end GPS tracking services that go by names like amber360.com, kiddo-track.com, carzongps.com and tourrun.net, according to Michael Gruhn, an independent security researcher who noted the insecure behavior in a location tracker he acquired and has helped raise awareness of the widespread flaws. Working with researcher Vangelis Stykas, Gruhn discovered scores of seemingly identical GPS services, many of which have little security, allowing low-skill hackers to directly access data on GPS tracking devices.

Alas, news about the security holes is not new. In fact, the security holes in ThinkRace's GPS services are identical to those discovered by New Zealand researcher Lachlan Temple in 2015 and publicly disclosed at the time. Temple's research focused on one type of device: a portable GPS tracker that plugged into a vehicle's On Board Diagnostic (or OBD) port. However, Stykas and Gruhn say that they have discovered the same holes spread across a much wider range of APIs (application program interfaces) and services linked to ThinkRace.

Businesses

Spotify Files To Go Public (bloomberg.com) 24

According to Bloomberg, Spotify filed to go public on the New York Stock Exchange, "in the highest-profile test yet of a technique that lets companies list shares without raising money through a traditional stock offering." From the report: With steady cash from more than 60 million paying subscribers, the world's largest paid music-streaming service doesn't need more funding. Instead of an initial public offering, it's trying a direct listing, which essentially lets private stakeholders start trading their shares on a public exchange. That avoids underwriting fees and restrictions on stock sales by current owners, and doesn't dilute the holdings of executives and investors. Spotify, which has been valued at about $15 billion, would be the most prominent company by far to attempt a direct listing, a method that until now has been used by small issuers and real estate investment trusts. It would also be a first for the New York Stock Exchange, which has sought permission from the Securities & Exchange Commission to change its rules for the occasion.
Transportation

Analysts Expect Tesla To Miss Its First 2018 Model 3 Production Target (usnews.com) 120

schwit1 shares a report from U.S. News & World Report: In October, Tesla reported that it produced 220 Model 3 vehicles in the third quarter. CEO Elon Musk had previously said the company would produce more than 1,600 Model 3s by September. Loup Ventures analyst Gene Munster isn't the only analyst to doubt Tesla's fourth-quarter Model 3 production. KeyBanc analyst Brad Erickson reduced his fourth-quarter Model 3 production target by two-thirds, cutting it from 15,000 to only 5,000. According to Munster, Tesla investors may need to wait several more quarters for the Model 3 story to play out. "We predict a breakout year for the Model 3 in 2019 which means, until then, other elements like solid Model S and X production numbers, increasing energy deployments like the South Australia installation, and future vehicles (Roadster, Semi, Model Y, and pickup truck) will stoke investor optimism," he says. schwit1 adds: "Elon Musk promised Tesla would produce 500,000 Model 3 sedans in 2018 and has accepted refundable $1,000 deposits on nearly that many. At current production rates, it will be years before pre-orders are filled. The Model 3's good will and good reviews won't matter much if Tesla can't ramp up production, which even bulls like Munster believes is running at least a year late."

Slashdot Top Deals