Operating Systems

ReactOS 0.4.6 Released (osnews.com) 97

OS News reports that the latest version of ReactOS has been released: 0.4.6 is a major step towards real hardware support. Several dual boot issues have been fixed and now partitions are managed in a safer way avoiding corruption of the partition list structures. ReactOS Loader can now load custom kernels and HALs. Printing Subsystem is still greenish in 0.4.6, however Colin Finck has implemented a huge number of new APIs and fixed some of the bugs reported and detected by the ReactOS automated tests. Regarding drivers, Pierre Schweitzer has added an NFS driver and started implementing RDBSS and RXCE, needed to enable SMB support in the future, Sylvain Petreolle has imported a Digital TV tuning device driver and the UDFS driver has been re-enabled in 0.4.6 after fixing several deadlocks and issues which was making it previously unusable. Critical bugs and leakages in CDFS, SCSI and HDAUDBUS have been also fixed. General notes, tests, and changelog for the release can be found at their respective links. A less technical community changelog for ReactOS 0.4.6 is also available. ISO images are ready at the ReactOS Download page.
AI

Huawei Unveils AI Mobile Chipset Said To Rival A11 Processor In Upcoming iPhones (macrumors.com) 77

On Saturday, Chinese mobile maker Huawei unveiled its first artificial intelligence smartphone chipset, which it hopes will lure customers away from Apple's upcoming range of new iPhones and towards the Asian company's "most powerful handset yet," the Mate 10, which is set to debut next month. Mac Rumors reports: Huawei touted the Kirin 970 AI mobile chipset's built-in "neural processing unit" at the IFA consumer electronics trade show in Berlin, claiming that the technology is "20 times faster" than a traditional processor. The world's third largest smartphone maker claimed that mobile devices powered by the Kirin 970 will be able to "truly know and understand their users," by supporting real-time image recognition, voice interaction, and intelligent photography with ease. According to Nikkei, the Kirin 970 integrates 5.5 billion transistors in a single square centimeter about the size of a thumbnail, which includes an octa-core central processing unit, a 12-core graphics processing unit, a dual-image signal processor, a high-speed 1.2Gbps Cat.18 modem, and AI mobile computing architecture. The Kirin 970 is said to be based on the same 10-nanometer technology as Apple's existing A10X Fusion processor and the A11 processor that will power its new iPhone range, set to debut this month. The Mate 10 is said to be a bezel-less all-screen handset with a 6-inch, 2:1 display and a 2,160 x 1,080 resolution. Like Apple's so-called "iPhone 8," the Mate 10 is also expected to feature some form of facial recognition and improved cameras.
Social Networks

Some Instagram Employees Sell Verification For Thousands of Dollars (mashable.com) 56

An anonymous reader shares a report from Mashable, written by Kerry Flynn: "I mean if Mashable wants to pay for it, I can get you a blue check over night," reads a recent Twitter direct message. This is a guy who knows a guy, a middleman in the black market for Instagram verification, where anyone from a seasoned publicist to a 22-year-old digital marketer will offer to verify an account -- for a price. The fee is anywhere from a bottle of wine to $15,000, according to a dozen sources who have sold verification, bought verification for someone else, or directly know someone who has done one or the other. "These guys pay all their bills from one to two blue checks a month," another message from the middleman added later. The product for sale isn't a good or a service. It's a little blue check designated for public figures, celebrities, and brands on Instagram. It grants users a prime spot in search as well as access to special features. More importantly, it's a status symbol. But it's clear from people who spoke on the condition of anonymity, many of whom have their own blue checkmarks, that a black market for Instagram verification is alive and well. "Instagram has helped create this underground market," the report adds. "While anyone can apply for verification on Facebook and on Twitter, Instagram has made itself exclusive and therefore rather elitist. Influencers who have press clippings and work with big brands on sponsorship deals often can't manage to get that elusive blue checkmark, according to several verified and unverified influencers and people who have sold verification."
Government

Thousands of Job Applicants Citing Top Secret US Government Work Exposed In Amazon Server Data Breach (gizmodo.com) 115

According to Gizmodo, "Thousands of files containing the personal information and expertise of Americans with classified and up to Top Secret security clearances have been exposed by an unsecured Amazon server, potentially for most of the year." From the report: The files have been traced back to TigerSwan, a North Carolina-based private security firm. But in a statement on Saturday, TigerSwan implicated TalentPen, a third-party vendor apparently used by the firm to process new job applicants. "At no time was there ever a data breach of any TigerSwan server," the firm said. "All resume files in TigerSwan's possession are secure. We take seriously the failure of TalentPen to ensure the security of this information and regret any inconvenience or exposure our former recruiting vendor may have caused these applicants. TigerSwan is currently exploring all recourse and options available to us and those who submitted a resume."

Found on an insecure Amazon S3 bucket without the protection of a password, the cache of roughly 9,400 documents reveal extraordinary details about thousands of individuals who were formerly and may be currently employed by the U.S. Department of Defense and within the U.S. intelligence community. The files, unearthed this summer by a security analyst at the California-based cybersecurity firm UpGuard, were discovered in a folder labeled "resumes" containing the curriculum vitae of thousands of U.S. citizens holding Top Secret security clearances -- a prerequisite for their jobs at the Central Intelligence Agency, the National Security Agency, and the U.S. Secret Service, among other government agencies.

Earth

The Solar Eclipse of 2017 Destroyed Lots of Rental Camera Gear (petapixel.com) 140

Despite numerous warnings sent out to renters, a number of LensRental's camera equipment came back damaged and destroyed from the solar eclipse of 2017. PetaPixel provides pictures in a report that shows some of the damage. One photo, for example, "shows a Panasonic 20mm f/1.7 lens that had its aperture blades partially melted by the sun during the eclipse," while another shows a Canon 7D Mark II shutter being burned so bad that "the heat went past it and damaged the sensor behind it as well." LensRentals, one of the leading camera rental companies, writes about the destruction in a blog post on their website: The most common problem we've encountered with damage done by the eclipse was sensors being destroyed by the heat. We warned everyone in a blog post to buy a solar filter for your lens, and also sent out mass emails and fliers explaining what you need to adequately protect the equipment. But not everyone follows the rules, and as a result, we have quite a few destroyed sensors. To my personal surprise, this damage was far more visually apparent than I even expected, and the photos below really make it visible.

The images above are likely created because people were shooting in Live View mode, allowing them to compose the image using the back of their screen, instead of risking damage to their eyes by looking through the viewfinder. However, those who didn't use live view (and hopefully guess and checked instead of staring through the viewfinder), were more likely to face damage to their camera's mirror. While this damage was far rarer, we did get one particular camera with a damaged mirror box caused by the sun.

Earth

Finland To Introduce Law Next Year Phasing Out Coal (reuters.com) 176

An anonymous reader quotes a report from Reuters: Finland will introduce legislation next year to phase out coal and increase carbon taxes, a top government official told Reuters, which would require the country to find alternative energy sources to keep its power system stable. Coal produces roughly 10 percent of the energy consumed by Finland, which is the Nordics' heaviest coal consumer and burned about 4.1 million tons of oil equivalent in 2016. "This strategy has a goal of getting rid of coal as an energy source by 2030 [...] We have to write a law [...] and that will be next year," Riku Huttunen, director general in Finland's energy department, said. The law will, however, leave "room for manoeuvre" to ensure security of supply, he said, meaning coal-fired power plants could still be available to avoid the risk of blackouts. Finland is increasing its nuclear capacity, which could replace coal. But that may not be sufficient, a Nordic power trader said, as Finland will receive less nuclear power from neighboring Sweden, which is phasing out two reactors. Helsinki is raising its nuclear power capacity to reduce dependency on Russian energy imports. Two new reactors, Olkiluoto 3 and Hanhikivi 1, are due to go online in 2018 and 2024, respectively.
AT&T

AT&T Uverse Modems Found To Have Several Serious Security Vulnerabilities (threatpost.com) 75

dustman81 writes: AT&T Uverse modems were found to have several serious vulnerabilities, including a superuser account with hardcoded username/password exposed to the internet via SSH, a HTTP server with little authentication which allows command injection, and an internet exposed service which exposes internal clients to external attacks. Information security consulting and software development firm Nomotion reports the findings in their blog: "It was found that the latest firmware update (9.2.2h0d83) for the NVG589 and NVG599 modems enabled SSH and contained hardcoded credentials which can be used to gain access to the modem's 'cshell' client over SSH. The cshell is a limited menu driven shell which is capable of viewing/changing the WiFi SSID/password, modifying the network setup, re-flashing the firmware from a file served by any tftp server on the internet, and even controlling what appears to be a kernel module whose sole purpose seems to be to inject advertisements into the user's unencrypted web traffic. Although no clear evidence was found suggesting that this module is actually being used currently, it is present, and vulnerable. Aside from the most dangerous items listed above, the cshell application is also capable of many other privileged actions. The username for this access is remotessh and the password is 5SaP9I26." The report continues to detail the other vulnerabilities: Default credentials 'caserver' https server NVG599; Command injection 'caserver' https server NVG599; Information disclosure/hardcoded credentials; and Firewall bypass no authentication.

Further reading: FierceTelecom; The Register

Google

Google Conducted Hollywood 'Interventions' To Change Look of Computer Scientists (usatoday.com) 644

theodp writes: Most TV computer scientists are still white men," USA Today reports. "Google wants to change that. Google is calling on Hollywood to give equal screen time to women and minorities after a new study the internet giant funded found that most computer scientists on television shows and in the movies are played by white men. The problem with the hackneyed stereotype of the socially inept, hoodie-clad white male coder? It does not inspire underrepresented groups to pursue careers in computer science, says Daraiha Greene, Google CS in Media program manager, multicultural strategy." According to a Google-funded study conducted by Prof. Stacy L. Smith and the Media, Diversity, & Social Change Initiative at the USC Annenberg School for Communication and Journalism, Google's Computer Science in Media team conducted "CS interventions" with "like-minded people" to create "Google influenced storytelling." The executive summary for a USC study entitled Cracking the Code: The Prevalence and Nature of Computer Science Depictions in Media notes that "Google influenced" TV programs include HBO's Silicon Valley and AMC's Halt and Catch Fire. The USC researchers also note that "non-tech focused programs may offer prime opportunities to showcase CS in unique and counter-stereotypical ways. As the Google Team moves forward in its work with series such as Empire, Girl Meets World, Gortimer Gibbons Life on Normal Street, or The Amazing Adventures of Gumball, it appears the Team is seizing these opportunities to integrate CS into storytelling without a primary tech focus." The study adds, "In the case of certain series, we provided on-going advisement. The Fosters, Miles from Tomorrowland, Halt and Catch Fire, Ready, Jet, Go, The Powerpuff Girls and Odd Squad are examples of this. In addition to our continuing interactions, we engaged in extensive PR and marketing support including social media outreach, events and press."

Google's TV interventions have even spilled over into public education -- one of Google-sponsored Code.org's signature Hour of Code tutorials last December was Gumball's Coding Adventure, inspired by the Google-advised Cartoon Network series, The Amazing Adventures of Gumball. "We need more students around the world pursuing an education in CS, particularly girls and minorities, who have historically been underrepresented in the field," explains a Google CS First presentation for educators on the search giant's Hour of Code partnership with Cartoon Network. "Based on our research, one of the reasons girls and underrepresented minorities are not pursuing computer science is because of the negative perception of computer scientists and the relevance of the field beyond coding." According to a 2015 USC report, President Obama was kept abreast of efforts to challenge media's stereotypical portrayals of women; White House Visitor Records show that USC's Smith, the Google-funded study's lead author, and Google CS Education in Media Program Manager Julie Ann Crommett (now at Disney) were among those present when the White House Council on Women and Girls met earlier that year with representatives of the nation's leading toy makers, media giants, retailers, educators, scientists, the U.S. Dept. of Education, and philanthropists.

Businesses

Will Millennials Be Forced Out of Tech Jobs When They Turn 40? (ieeeusa.org) 247

dcblogs shared an interesting article from IEEE-USA's "Insight" newsletter: Millennials, which date from the 1980s to mid-2000s, are the largest generation. But what will happen to this generation's tech workers as they settle into middle age? Will the median age of tech firms rise as the Millennial generation grows older...? The median age range at Google, Facebook, SpaceX, LinkedIn, Amazon, Salesforce, Apple and Adobe, is 29 to 31, according to a study last year by PayScale, which analyzes self-reported data... Karen Panetta, the dean of graduate engineering education at Tufts University and the vice president of communications and public relations at the IEEE-USA, believes the outcome for tech will be Logan's Run-like, where age sets a career limit... Tech firms want people with the current skills sets and those "without those skills will be pressured to leave or see minimal career progression," said Panetta...

The idea that the tech industry may have an age bias is not scaring the new college grads away. "They see retirement so far off, so they are more interested in how to move up or onto new startup ventures or even business school," said Panetta. "The reality sets in when they have families and companies downsize and it's not so easy to just pick up and go on to another company," she said. None of this may be a foregone conclusion. Millennials may see the experience of today's older workers as a cautionary tale, and usher in cultural changes...

David Kurtz, a labor relations partner at Constangy, Brooks, Smith & Prophete, suggests tech firms should be sharing age-related date about their workforce, adding "The more of a focus you place on an issue the more attention it gets and the more likely that change can happen. It's great to get the new hot shot who just graduated from college, but it's also important to have somebody with 40 years of experience who has seen all of the changes in the industry and can offer a different perspective."
Firefox

TechRepublic: Mozilla 'Is Desperately Needed to Save the Web' (techrepublic.com) 317

"I can't remember the last time I cared about Mozilla," writes Matt Asay at TechRepublic. "I also can't remember a time when we needed it more." An anonymous reader quotes TechRepublic: Mozilla's Firefox is almost a rounding error in desktop market share, and nonexistent in mobile browser market share. It offers a few other services, like Pocket, but largely gets ignored... This is a mistake. Our world is increasingly mediated by the internet, and that internet has just a few gatekeepers, collecting tolls as we browse. As Python guru Matt Harrison put it, "Vendors control the default browser which 99.9% of people use." Those vendors are happy to sell us access to information. Nothing about it is free. You are most definitely the product.

On mobile, where the majority of the world's content is now consumed, Google and Facebook own eight of the top 10 apps, with apps devouring 87% of our time spent on smartphones and tablets, according to new comScore data. For that remaining 13% of time spent on the mobile web, Google and Apple offer the two dominant browsers... the majority of our time online is now mediated by just a few megacorporations, and for the most part their top incentive is to borrow our privacy just long enough to target an ad at us. Then there's Mozilla, an organization whose mantra is "Internet for people, not profit." That feels like a necessary voice to add to today's internet oligopoly, but it's not one we're hearing... We clearly need an organization standing up for web freedom, as expecting Google to do that is like asking the fox to guard the henhouse. Google does many great things, but its clear incentive is to sell ads. We are Google's product, as the saying goes.

The article applauds the Mozilla-sponsored Rust programming language as promising, "but not to save the web from the all-consuming embrace of Facebook and Google, especially as they wall off the experience in apps... "If I sound like I don't know what to propose Mozilla should do, it's because I don't. I simply feel strongly that the role Mozilla played in the early browser wars needs to be resurrected to save the web today."
Open Source

Reddit's Main Code Is No Longer Open Source (reddit.com) 162

An anonymous reader quotes an announcement from Reddit's founding engineer: When we open sourced Reddit back in 2008, Reddit Inc was a ragtag organization and the future of the company was very uncertain. We wanted to make sure the community could keep the site alive should the company go under and making the code available was the logical thing to do. Nine years later and Reddit is a very different company and as anyone who has been paying attention will have noticed, we've been doing a bad job of keeping our open-source product repos up to date. This is for a variety of reasons, some intentional and some not so much:

Open-source makes it hard for us to develop some features "in the clear" (like our recent video launch) without leaking our plans too far in advance. As Reddit is now a larger player on the web, it is hard for us to be strategic in our planning when everyone can see what code we are committing. Because of the above, our internal development, production and "feature" branches have been moving further and further from the "canonical" state of the open source repository... We are actively moving away from the "monolithic" version of reddit that works using only the original repository... Because of these reasons, we are making the following changes to our open-source practice. We're going to archive reddit/reddit and reddit/reddit-mobile. These will still be accessible in their current state, but will no longer receive updates.

The announcement has been condensed slightly, but Reddit's founding engineer insists that "We believe in open source, and want to make sure that our contributions are both useful and meaningful. We will continue to open source tools that are of use to engineers everywhere." In addition, "Much of the core of Reddit is based on open source technologies (Postgres, python, memcached, Cassanda to name a few!) and we will continue to contribute to projects we use and modify..."

"Those who have been paying attention will realize that this isn't really a change to how we're doing anything but rather making explicit what's already been going on."
Java

Why Oracle Should Cede Control of Java SE (infoworld.com) 110

An anonymous reader quotes InfoWorld: Now that Oracle wants to turn over leadership of enterprise Java's (Java EE's) development to a still-unnamed open source foundation, might the same thing happen with the standard edition of Java (Java SE) that Oracle also controls? Such a move could produce substantial benefits... Oracle said it has no plans to make such a move. But the potential fruits of a such a move are undeniable.

For one, a loosening of Oracle's control could entice other contributors to Java to participate more... [W]ith the current Oracle-dominated setup, other companies and individuals could be reluctant to contribute a lot if they see it as benefiting a major software industry provider -- and possible rival -- like Oracle... Indeed, the 22-year-old language and platform could be given a whole new lease on life, if the open source community rises to the occasion and boosts participation...

Despite the potential to grow Java SE by ceding control, Oracle seems content to hold on to its place as the steward of JDK development. But that could change given the tempestuous relationship Oracle has with parts of the Java community. Oracle has been at loggerheads with the community over both Java SE and Java EE... Oracle may at some point decide it is easier to just cede control rather than having to keep soothing the ruffled feathers that keep occurring among its Java partners.

United States

Dozens Of Drones Surveil Houston For Damage After Hurricane Harvey (usatoday.com) 34

An anonymous reader quotes MIT Technology Review: AT&T is using drones to inspect its cellular towers for damage, while insurance companies like Allstate and Farmers are rolling out their own fleets to follow up on claims... Rescue operations are benefitting, too. According to Axios, the company DroneDeploy is sending out vehicles to produce detailed 3-D maps that can help navigate the watery chaos. The company claims it can speed up rescue operations by providing imagery that allows rescuers to see around buildings and beneath tree cover.
The drones can fly high-definition cameras, and there's now dozens of them flying over Houston, reports USA Today: By Thursday, the Federal Aviation Administration has authorized 43 drone operators in Harvey's wake, for recovery efforts and for news organizations covering it... Eight approvals went to a railroad company to survey damage along tracks running through Houston. Five went to oil or energy companies to look for damage to fuel tanks, power lines and other facilities. Emergency-management officials are checking damage to roads, bridges and water-treatment plants... The FAA has also prohibited private drone pilots from flying in a broad area around Houston to avoid areas where emergency aircraft such as rescue helicopters are plucking people from rooftops or searching for survivors.
Security

Hacking Group 'OurMine' Temporarily Redirected WikiLeaks DNS Service (theguardian.com) 83

An anonymous reader quotes the Guardian: WikiLeaks suffered an embarrassing cyber-attack when Saudi Arabian-based hacking group OurMine took over its web address. The attack saw visitors to WikiLeaks.org redirected to a page created by OurMine which claimed that the attack was a response to a challenge from the organisation to hack them.

But while it may have been humiliating for WikiLeaks, which prides itself on technical competency, the actual âoehackâ appears to have been a low-tech affair: the digital equivalent of spray-painting graffiti on the front of a bank then claiming to have breached its security. The group appears to have carried out an attack known as "DNS poisoning" for a short while on Thursday morning. Rather than attacking WikiLeaks' servers directly, they have convinced one or more DNS servers...to alter their records. For a brief period, those DNS servers told browsers that wikileaks.org was actually located on a server controlled by OurMine.

Books

Terry Pratchett's Hard Drive Destroyed By Steamroller (nytimes.com) 161

WheezyJoe writes: In accordance with his wishes, a hard drive formerly belonging to author Terry Pratchett has been crushed by steamroller. According to friend and fellow author Neil Gaiman, Pratchett (who died at 66 in 2015) wanted "whatever he was working on at the time of his death to be taken out along with his computers, to be put in the middle of a road and for a steamroller to steamroll over them all."

According to the article, on August 25, two years after the author's passing, Mr. Pratchett's estate manager and close friend, Rob Wilkins, posted a picture of a hard drive and a steamroller on an official Twitter account they shared. The pictures posted suggest the steamroller was one powered by actual steam.

Minutes later they tweeted a photo of the crushed hard drive -- which will soon be displayed at the Salisbury Museum in England as part of their new exhibit on the life and work of Terry Pratchett.

Slashdot Top Deals