Network

Comcast Sues Vermont To Avoid Building 550 Miles of New Cable Lines (arstechnica.com) 201

An anonymous reader quotes a report from Ars Technica: Comcast has sued the state of Vermont to try to avoid a requirement to build 550 miles of new cable lines. Comcast's lawsuit against the Vermont Public Utility Commission (VPUC) was filed Monday in U.S. District Court in Vermont and challenges several provisions in the cable company's new 11-year permit to offer services in the state. One of the conditions in the permit says that "Comcast shall construct no less than 550 miles of line extensions into un-cabled areas during the [11-year] term." Comcast would rather not do that. The company's court complaint says that Vermont is exceeding its authority under the federal Cable Act while also violating state law and Comcast's constitutional rights: "The VPUC claimed that it could impose the blanket 550-mile line extension mandate on Comcast because it is the 'largest' cable operator in Vermont and can afford it. These discriminatory conditions contravene federal and state law, amount to undue speaker-based burdens on Comcast's protected speech under the First Amendment of the United States Constitution... and deprive Comcast and its subscribers of the benefits of Vermont law enjoyed by other cable operators and their subscribers without a just and rational basis, in violation of the Common Benefits Clause of the Vermont Constitution."
Earth

The Oldest Known Human Remains In the Americas Have Been Found In a Mexican Cave (seeker.com) 138

schwit1 shares a report from Seeker: An ice-free corridor between the Americas and Asia opened up about 12,500 years ago, allowing humans to cross over the Bering land bridge to settle what is now the United States and places beyond to the south. History books have conveyed that information for years to explain how the Americas were supposedly first settled by people, such as those from the Clovis culture. At least one part of the Americas was already occupied by humans before that time, however, says new research on the skeleton of a male youth found in Chan Hol cave near Tulum, Mexico. Dubbed the Young Man of Chan Hol, the remains date to 13,000 years ago, according to a paper published in the journal PLOS ONE. How he arrived at the location remains a great mystery given the timing and the fact that Mexico is well over 4,000 miles away from the Bering land crossing. For the new study, Gonzalez, Stinnesbeck, and their colleagues dated the Young Man of Chan Hol's remains by analyzing the bones' uranium, carbon, and oxygen isotopes, which were also found in stalagmite that had grown through the pelvic bone. The scientists believe that the resulting age of 13,000 years could apply to at least two other skeletons found in caves around Tulum: a teenage female named Naia and a 25-30-year-old female named Eve of Naharon. Gonzalez said that the shape of the skulls suggests that Eve and the others "have more of an affinity with people from Southeast Asia." He and his team further speculated that the individuals could have originated in Indonesia.
Space

India's Workhorse Rocket Fails For the First Time In Decades (theverge.com) 78

India's premier rocket, known as the Polar Satellite Launch Vehicle, failed to put a navigation satellite into orbit earlier this morning, after some unknown malfunction prevented the satellite from leaving the vehicle. The Verge reports: The rocket successfully took off from the Satish Dhawan Space Centre in southeastern India at 9:30AM ET. About a little over 10 minutes into the flight, however, the rocket seemed to be in a lower altitude than it need to be. A host during the live broadcast of the launch noted that there was a "variation" in the rocket's performance. Later, an official with the Indian Space Research Organization (ISRO) confirmed that the payload fairing -- the cone-like structure that surrounds the satellite on the top of the rocket -- failed to separate and expose the satellite to space. So the satellite was effectively trapped inside the fairing and could not be deployed into orbit. It seems possible that the rocket's low trajectory had to do with the fact that the fairing didn't separate, making the vehicle heavier than it was supposed to be.

It's an unexpected failure for a fairly reliable rocket. Over the last 24 years, the PSLV has flown 41 times and has only suffered two failures in its launch history -- the most recent mishap occurring during a mission in 1997. However, that mission was not a total loss as the satellite it carried was still able to make it to orbit. This was the first total failure of the rocket to happen since the PSLV's very first failure in 1993.

United States

Stanford Study Finds New Dads In US Are Older Than Ever (mercurynews.com) 191

An anonymous reader quotes a report from The Mercury News: American fathers keep getting older, raising the prospect of increased birth defects but also greater economic and emotional security for U.S. families, according to new research from Stanford University's School of Medicine. The average age of the fathers of newborns in the United States has climbed by 3.5 years over the past four decades, growing from 27.4 years in 1972 to 30.9 years in 2015, said the study -- the nation's most detailed analysis ever of paternal age. The number of newborns whose fathers were over age 40 has more than doubled over the past four decades. Those births now make up nearly 9 percent of births in the U.S., Dr. Michael Eisenberg and Yash Khandwala reported in the journal Human Reproduction. The share of fathers who were over age 50 rose from 0.5 percent to 0.9 percent. Asian-American fathers -- men of Japanese and Vietnamese descent, in particular -- are the oldest, becoming fathers at the average age of 36 years, the study said. Black and Hispanic men are the youngest fathers -- age 30.4 and 30, respectively. White men, on average, have children at age 31. Paternal age rose with educational attainment. The typical newborn's father with a college degree is 33.3 years old -- compared with 29.8 years for high school graduates.
Security

Hacking Retail Gift Cards Remains Scarily Easy (wired.com) 108

Willium Caput, a researcher for the firm Evolve Security, examined a stack of gift cards he obtained from a major Mexican restaurant chain and noticed a pattern: aside from the final four digits of the cards that appeared to be random, the rest remained constant except one digit that appeared to increase by one with every card he examined. Andy Greenberg explains how Caput plans to defraud the system in his report via WIRED (Warning: source may be paywalled; alternative source): "You take a small sample of gift cards from restaurants, department stores, movie theaters, even airlines, look at the pattern, determine the other cards that have been sold to customers and steal the value on them," says Caput. To pull off the trick, Caput says he has to obtain at least one of the target company's gift cards. Unactivated cards often sit out for the taking at restaurants and retailers, or he can just buy one. (Not all cards change by a value of one, as that first Mexican restaurant did. But Caput says obtaining two or three cards can help to determine the patterns of those that don't.) Then he simply visits the web page that the store or restaurant uses for checking a card's value. From there, he runs the bruteforcing software Burp Intruder to cycle through all 10,000 possible values for the four random digits at the end of the card's number, a process that takes about 10 minutes. By repeating the process and incrementing the other, predictable numbers, the site will confirm exactly which cards have how much value. "If you can find just one of their gift cards or vouchers, you can bruteforce the website," he says.

Once a thief has determined those activated, value-holding card numbers, he or she can use them on the retailer's ecommerce page, or even in person; Caput's written them to a blank plastic card with a $120 magnetic-strip writing device available on Amazon, and found that most retailers accept his cards without questions. (Caput only asks the store or restaurant to check the card's balance, rather than spend any money from the cards belonging to actual victims.) "It's a pretty anonymous attack," Caput says. "I can go in, order food, and walk out. The person's card says it has $50 on it, and then it's gone."
Caput said he plans to present his findings at the Toorcon hacker conference this weekend.
Transportation

Samsung Gets Self-Driving Car Permit In California (cnet.com) 18

Samsung on Wednesday has obtained a permit from the California Department of Motor Vehicles to test autonomous cars on the streets of California. Samsung joins a group of other tech companies already on the list, including Apple, Uber, Nvidia and Alphabet's Waymo, as well as several automakers like Ford, BMW, Volkswagen and Tesla. CNET reports: Samsung confirmed the news, but said it doesn't plan to actually manufacture self-driving cars. "As a global leader in connectivity, memory, and sensor technology, Samsung Electronics looks forward to participating in California's Autonomous Vehicle Tester Program and joining in the pursuit of a smarter, safer transportation future," a Samsung spokesman said in a statement. "While we have no plans to enter the car-manufacturing business, we are excited to help develop and deliver the next generation of automotive innovation." The company received a permit from the South Korean government to test autonomous cars in that country in May. Last year, it bought a car tech company called Harman for $8 billion.
Data Storage

SanDisk Breaks Storage Record With 400GB MicroSD Card (extremetech.com) 70

SanDisk has managed to cram 400GB into a microSD card, making it the largest microSD card currently on the market. The company said the capacity breakthrough was the result of Western Digital, the company that owns SanDisk, "leveraging its proprietary memory technology and design and production processes that allow for more bits per die." The nitty-gritty details weren't revealed beyond that. ExtremeTech reports: The speed appears to come with a tradeoff. SanDisk trumpets its A1 speed rating, saying: "Rated A1, the SanDisk Ultra microSD card is optimized for apps, delivering faster app launch and performance that provides a better smartphone experience." This is a generous reading of the A1's target performance specification. Last year, the SD Association released a report discussing the App Performance Class memory card specification and why the spec was created in the first place. When Android added support for running applications from an SD card, there was a need to make certain the cards people bought would be quick enough to run apps in the first place. The A1 is rated for 1500 read and 500 write IOPS, with a sequential transfer speed of 10MB/s.

This SanDisk drive should run applications just fine. SanDisk claims it can be used for recording video, not just storing it. But it's not going to be fast enough for 4K data; Class 10 devices are limited to 10MB/s of sequential write performance. Obviously not all phones support shooting in 4K anyway, so whether this is a limitation will depend on what device you plan to plug it into. The 100MB/s speed trumpeted by Western Digital is a reference to read speeds; write speeds are lower and likely closer to the 10MB/s sequential target mentioned above. The microSD card is expected to retail for $250.

Businesses

Hollywood is Suffering Its Worst-attended Summer Movie Season in 25 years (latimes.com) 501

The number of movie tickets sold in the U.S. this summer (425 million) is likely to be the lowest level since 1992, the L.A. Times reports. "Theaters, studios hit by summer box-office blues." The reason: Too many bad movies, including sequels, reboots and aging franchises that no one wanted to see. Some point to rising ticket prices, which hit a record high in the second quarter. From the report: Then there are long-term challenges, including competition from streaming services such as Netflix and the influence of the movie review site Rotten Tomatoes. How about all of the above? What is clear: This summer was marred with multiple high-profile films that flopped stateside, including "The Mummy," "Baywatch," "The Dark Tower" and "King Arthur: Legend of the Sword." Sequels in the "Alien," "Transformers" and "Pirates of the Caribbean" franchises also disappointed. The business is also reckoning with broader, longer-term threats that have kept Americans from flocking to theaters the way they used to. People now have more entertainment options than ever, and cinemas have struggled to keep up, despite efforts to adapt with improved technology and services, industry analysts say. The problem is exacerbated by an unforgiving social media environment in which bad movies are immediately punished by online word of mouth.
The Courts

Amazon Sold Eclipse Glasses That Cause 'Permanent Blindness,' Alleges Lawsuit (arstechnica.com) 229

An anonymous reader quotes a report from Ars Technica: A South Carolina couple claims in a proposed federal class-action lawsuit (PDF) that Amazon sold defective eclipse-watching glasses that partially blinded them during the historic coast-to-coast solar eclipse on August 21. Corey Payne and fiance Kayla Harris say in their lawsuit that because of the eyewear Payne purchased from Amazon, the couple is now suffering from "blurriness, a central blind spot, increased sensitivity, changes in perception of color, and distorted vision." Amazon issued a recall of defective and perhaps counterfeit eclipse eyewear in an e-mail sent out to customers before the event. Payne said he did not receive the message. His suit seeks to represent others who were injured or may be injured from the eyewear purchased on Amazon. The alleged Tennessee-based maker of the glasses, American Paper Optics, is not named in the suit. The suit seeks funds "for medical monitoring" because "Plaintiffs and members of the proposed class have or will experience varying degrees of eye injury ranging from temporary discomfort to permanent blindness." The suit also demands unspecified monetary damages, punitive damages, and legal fees and costs.
Businesses

Postmates Lays Off All Its City Managers (techcrunch.com) 59

According to TechCrunch, Postmates has let go of all of its city managers, as it centralizes some of its operations at its headquarters in San Francisco. "The total number of people affected by the move is 15 across markets like Boston, Denver, Las Vegas, Nashville, New York, Philadelphia, St Louis, San Diego, and Washington, DC," reports TechCrunch. From the report: In a statement, Postmates said that general managers will take on city managers' responsibilities. "Postmates has grown rapidly over the last six years -- and continues to grow in more than 200 cities across the U.S. As part of that growth, we've decided to centralize some of our regional marketing efforts within our San Francisco headquarters," a spokesperson said in the emailed statement. "Centralizing these functions will enable us to execute more quickly -- and ultimately help us be more nimble and effective as we continue to aggressively scale the company. Our general managers will remain in place and continue to help lead our local efforts. We are thankful to our city managers for all their hard work, and we're confident that they will be successful in their future endeavors."

One of the tipsters, an ex-city manager, said that employees were taken by surprise: Postmates had just earlier this month organized a retreat for the city managers, which they saw as a team building exercise. The tipster also added that the murmurs were that the cost-cutting was being done "as a precursor to an acquisition," but Postmates' spokesperson denied that this is the case, and also ruled out a merger and fundraising as reasons for the cuts.

Android

LG Announces V30 Smartphone With 'FullVision' OLED Display, Dual Cameras (phonedog.com) 45

At a press conference in Berlin, LG announced their newest flagship smartphone, the LG V30. The V30 doesn't feature a removable battery or a secondary display like its predecessor, but it does feature faster performance and a significantly redesigned build construction that puts in more in line with Samsung and Apple's offerings. PhoneDog reports: A bigger device with beefier specs, the LG's V series took more design cues from the G series this year more than ever. As expected, LG got rid of the secondary display in favor of a single 6-inch LG P-OLED display (not Super AMOLED, although practically the same with rich black and vibrant colors). The V30 switches out its secondary display for slimmer bezels, which may prove to be a smart move considering how popular the concept is this year. Specs look pretty solid, although there were reports that the device would feature 6GB of RAM rather than 4GB. The bread and butter of the V30 are its sophisticated audio and its dual rear camera set-up. Speaking of the back of the device, another small advantage that LG may have over the competition is the center placement of its rear fingerprint sensor, which has been a bit of a pain point for Samsung this year with the S8 and the Note 8. The LG V30 is set to release on September 21 in South Korea, with releases in North America, Asia, Africa, and Europe following shortly after. LG also has yet to announce a price for the V30, although rumors peg it to be around 800,000 KRW in South Korea (which equates to about $699 in the U.S.). For those interested, GSMArena has a full spec sheet available for the LG V30. Some of the noteworthy specs include a 6-inch LG P-OLED display with an 18:9 aspect ratio and QHD (1440 x 2880) resolution, Snapdragon 835 processor with 4GB RAM, dual 16-megapixel/13-megapixel rear-facing camera sensors, headphone jack, 32-bit/192kHz audio, wireless charging and Android 7.1.2 Nougat.
Communications

Apple Calls For FCC To Keep 'Strong, Enforceable' Net Neutrality Protections (appleinsider.com) 50

An anonymous reader quotes a report from Apple Insider: Apple has written to the U.S. Federal Communications Commission in support for the concept of net neutrality, with its four-page commentary arguing for the government agency to "retain strong, enforceable open internet protections" instead of rolling back the rules forbidding "fast lane" internet connections. "An open internet ensures that hundreds of millions of consumers get the experience they want, over the broadband connections they choose, to use the devices they love, which have become an integral part of their lives," starts the comment signed by Cynthia Hogan, Apple's Vice President of Public Policy for the Americas. Citing a "deep respect" for its customers' privacy, security, and control over personal information, Apple believes this extends to their internet connection choices as well. "What consumers do with those tools is up to them -- not Apple, and not broadband providers," the statement claims, before urging the FCC to keep advancing the key principles of net neutrality. Based on a belief of consumer choice with regards to connectivity, Apple insists broadband providers should not "block, throttle, or otherwise discriminate against lawful websites and services," and not create "paid fast lanes on the internet." Lifting current FCC bans on these restrictions could allow broadband providers to favor one service over another's, "fundamentally altering the internet as we know it today -- to the detriment of consumers, competition, and innovation." Allowing such fast lanes could result in an internet with heavily distorted competition, caused through online providers being forced to make deals or risk losing customers from providing a hampered service. Apple suggests the practice could "create artificial barriers to entry for new online services, making it harder for tomorrow's innovations to attract investment and succeed," effectively turning broadband providers into a king-maker based on its priorities.
Canada

A Canadian University Gave $11 Million To a Scammer (vice.com) 52

A Canadian university transferred more than $11 million CAD (around $9 million USD) to a scammer that university staff believed to be a vendor in a phishing attack, a university statement published on Thursday states. From a report: Staff at MacEwan University in Edmonton, Alberta became aware of the fraud on Wednesday, August 23, the statement says. According to the university, the attacker sent a series of emails that convinced staff to change payment details for a vendor, and that these changes resulted in the transfer of $11.8 million CAD into bank accounts that the school has traced to Canada and Hong Kong. The school is working with authorities in Edmonton, Montreal, London, and Hong Kong, the statement reads. According to the university, its IT systems were not compromised and no personal or financial information was stolen. A phishing scam is not technically a "hack," it should be noted, and only requires the attacker to convince the victim to send money. The school's preliminary investigation found that "controls around the process of changing vendor banking information were inadequate, and that a number of opportunities to identify the fraud were missed."
The Internet

The FCC Website Lets You Upload Malware Using Its Own Public API Key (hackernoon.com) 41

The FCC lets you upload any file to their website and make that file publicly accessible using the FCC.gov domain. Or rather they don't, but they have somehow not realized that they are letting people do it and telling them how in their own documentation. From a report: Take a look at this document about FCC Chairman Ajit Pai which has clearly not been put there by anyone who works at the FCC, neither has this one. Those currently uploading files are able to do this using the FCC's own public API, a key that they seem to send to anyone with any email address. Obviously I am not going to tell you how, but if you have enough of the right kind of technical experience the public FCC API documentation will. People seem to be experimenting uploading different filetypes, so far they have managed pdf/gif/ELF/exe/mp4 files up to 25MB in size, which means that you could easily host malware on the FCC.gov website right now and use it in phishing campaigns that link to malware on a .gov website.
Music

Traditional Radio Faces a Grim Future, New Study Says (variety.com) 240

In a 30-page report, Larry Miller, the head of New York University's Steinhart Music Business Program, argues that traditional radio has failed to engage with Generation Z -- people born after 1995 -- and that its influence and relevance will continue to be subsumed by digital services unless it upgrades. Key points made in the study include: Generation Z, which is projected to account for 40% of all consumers in the U.S. by 2020, shows little interest in traditional media, including radio, having grown up in an on-demand digital environment. AM/FM radio is in the midst of a massive drop-off as a music-discovery tool by younger generations, with self-reported listening to AM/FM radio among teens aged 13 and up declining by almost 50 percentage points between 2005 and 2016. Music discovery as a whole is moving away from AM/FM radio and toward YouTube, Spotify and Pandora, especially among younger listeners, with 19% of a 2017 study of surveyed listeners citing it as a source for keeping up-to-date with music -- down from 28% the previous year. Among 12-24 year olds who find music discovery important, AM/FM radio (50%) becomes even less influential, trailing YouTube (80%), Spotify (59%), and Pandora (53%). By 2020, 75% of new cars are expected to be "connected" to digital services, breaking radio's monopoly on the car dashboard and relegating AM/FM to just one of a series of audio options behind the wheel. According to the U.S. Department of Transportation, the typical car in the U.S. was 11.6 years old in 2016, which explains why radio has not yet faced its disruption event. However, drivers are buying new cars at a faster rate than ever, and new vehicles come with more installed options for digital music services.

Slashdot Top Deals