Security

Hackers Break Into Voting Machines Within 2 Hours at Defcon (cbsnews.com) 37

Hackers from around the world had the rare opportunity to crack election-style voting machines this weekend in Las Vegas -- and they didn't disappoint. From a report: After nearly an hour and a half, Carsten Schurmann, an associate professor with IT-University of Copenhagen, successfully cracked into a voting machine at Las Vegas' Defcon convention on Friday night, CNET reports. Schurmann penetrated Advanced Voting Solutions' 2000 WinVote machine through its Wi-Fi system. Using a Windows XP exploit from 2003, he was able to remotely access the machine, CNET reports. Voting technology was thrust into the political spotlight when election systems in several states were targeted by Russian cyber attacks. The convention purchased more than 30 voting machines for the event, although, organizers didn't specify how many models those units represented.
Cellphones

Honolulu Targets 'Smartphone Zombies' With Crosswalk Ban (reuters.com) 170

Templer421 shares news from Reuters: A ban on pedestrians looking at mobile phones or texting while crossing the street will take effect in Hawaii's largest city in late October, as Honolulu becomes the first major U.S. city to pass legislation aimed at reducing injuries and deaths from "distracted walking." The ban comes as cities around the world grapple with how to protect phone-obsessed "smartphone zombies" from injuring themselves by stepping into traffic or running into stationary objects. Starting Oct. 25, Honolulu pedestrians can be fined between $15 and $99, depending on the number of times police catch them looking at a phone or tablet device as they cross the street, Mayor Kirk Caldwell told reporters gathered near one of the city's busiest downtown intersections on Thursday... People making calls for emergency services are exempt from the ban... Opponents of the Honolulu law argued it infringes on personal freedom and amounts to government overreach.
Meanwhile, the city of London has tried putting pads on their lamp posts "to soften the blow for distracted walkers."
Cloud

Microsoft Further Pledges Linux Loyalty, Joins Cloud Native Computing Foundation (betanews.com) 109

BrianFagioli quotes BetaNews: Today, Microsoft further pledges its loyalty to Linux and open source by becoming a platinum member of the Cloud Native Computing Foundation. If you aren't familiar, the CNCF is a part of the well-respected Linux Foundation (of which Microsoft is also a member). With the Windows-maker increasingly focusing its efforts on the cloud -- and profiting from it -- this seems like a match made in heaven. In fact, Dan Kohn, Executive Director of the foundation says, "We are honored to have Microsoft, widely recognized as one of the most important enterprise technology and cloud providers in the world, join CNCF as a platinum member."

"CNCF is a part of the Linux Foundation, which helps govern for a wide range of cloud-oriented open source projects, such as Kubernetes, Prometheus, OpenTracing, Fluentd, Linkerd, containerd, Helm, gRPC, and many others," says John Gossman Azure Architect, Microsoft. "Since we joined the Linux Foundation last year, and now have decided to expand that relationship to CNCF membership as a natural next step to invest in open source communities and code at multiple levels, especially in the area of containers."

The announcement notes that Microsoft has already been contributing code to the Kubernetes project, "as well as running Kubernetes as part of the Azure Container Service."
Communications

Ask Slashdot: What Can You Do With Old Coaxial Cable? 384

Long-time Slashdot reader Theaetetus writes: I recently bought a house and the previous owner left some coax (mostly RG59) running between rooms for cable distribution. I'm a cord cutter and don't need cable, and I've already run CAT6e everywhere. But before I pull the RG59 out and try to seal the various holes he left, I figured I'd pick Slashdot's brain: can anyone think of a good non-cable use for spare coax lines?
Leave your best answers in the comments. What can you do with old coaxial cable?
United States

After Emissions Scandal, Volkswagen Pledges Charging Stations Across The US (siliconvalley.com) 142

Here's how the Volkswagen emissions scandal ends in California -- and the rest of America. An anonymous reader quotes the Bay Area News Group: In a decision with lasting implications for the growth of electric vehicles, state regulators on Thursday approved Volkswagen's plan to invest nearly $1 billion in California's EV network as penalty for its diesel-emission cheating scandal... San Jose and San Francisco are two of six cities slated for expanded community charging stations. A Volkswagen subsidiary, Electrify America, also will target low-income communities for at least 35 percent of the projects... The first phase calls for $120 million to build 400 charging stations with between 2,000 and 3,000 chargers. About $75 million will be used to develop a high-speed, highway charging network, mostly consisting of 150 kilowatt fast-chargers. The other $45 million will build community charging stations in six metro areas: San Jose, San Francisco, Sacramento, Fresno, Los Angeles and San Diego. Another $44 million will build a "Green City" in Sacramento. It will provide access to zero-emission vehicles to low-income residents, through ride-sharing and other programs. As part of the 10-year comprehensive plan, Electrify America will build a nationwide network of fast-charging stations with universal technology.
That nationwide network is expected to cost another $2 billion.
Google

Will 'Smart Cities' Violate Our Privacy? (computerworld.com) 108

An anonymous reader quotes Computerworld's article on the implications of New York City's plan to blanket the city with "smart" kiosks offering ultrafast Wi-Fi. The existence of smart-city implementations like Intersection's LinkNYC means that New Yorkers won't actually need mobile contracts anymore. Most who would otherwise pay for them will no doubt continue to do so for the convenience. But those who could not afford a phone contract in the past will have ubiquitous fast connectivity in the future. This strongly erodes the digital divide within smart cities. A 2015 study conducted by New York City found that more than a quarter of city households had no internet connectivity at home, and more than half a million people didn't own their own computer...

Over the next 15 years, the city will go through the other two phases, where sensor data will be processed by artificial intelligence to gain unprecedented insights about traffic, environment and human behavior and eventually use it to intelligently re-direct traffic and shape other city functions... And as autonomous cars gradually roll out, New York will be well positioned to be one of the first cities to legalize them, because they'll be safer thanks to 5G, sensors and data from all those kiosks.

Intersection, a Google-backed startup, has already installed 1,000 of the kiosks in New York, and is planning to install 7,000 more. The sides of the kiosk have screens which show alerts and other public information -- as well as advertisements, which cover all the costs of the installations and even bring extra money into the city coffers.

New York's move "puts pressure on other U.S. cities to follow suit," the article also points out, adding that privacy policies "are negotiated agreements between the company and the city. So if a city wants to use those cameras and sensors for surveillance, it can."
Security

US Voting Machines Cracked In 90 Minutes At DEFCON (thehill.com) 171

An anonymous reader quotes The Hill: Hackers at at a competition in Las Vegas were able to successfully breach the software of U.S. voting machines in just 90 minutes on Friday, illuminating glaring security deficiencies in America's election infrastructure. Tech minds at the annual "DEF CON" in Las Vegas were given physical voting machines and remote access, with the instructions of gaining access to the software. According to a Register report, within minutes, hackers exposed glaring physical and software vulnerabilities across multiple U.S. voting machine companies' products. Some devices were found to have physical ports that could be used to attach devices containing malicious software. Others had insecure Wi-Fi connections, or were running outdated software with security vulnerabilities like Windows XP.
Though some of the machines were out of date, they were all from "major U.S. voting machine companies" like Diebold Nixorf, Sequoia Voting Systems, and WinVote -- and were purchased on eBay or at government auctions. One of the machines apparently still had voter registration data stored in plain text in an SQLite database from a 2008 election, according to event's official Twitter feed.

By Saturday night they were tweeting video of a WinVote machine playing Rick Astley's "Never Gonna Give You Up."
China

Apple Pulls Anti-Censorship Apps from China's App Store (fortune.com) 108

An anonymous reader quotes Fortune:Services helping Chinese users circumvent the "Great Firewall of China" have been pulled from Apple's Chinese App Store en masse. On Saturday morning, at least some software makers affected by the sweep received notification from Apple that their tools were removed for violating Chinese law. Internet censorship in China restricts communications about topics including democracy, Tibetan freedom, and the 1989 Tienanmen Square protests. The culling primarily seems to have affected virtual private networks, or VPNs, which mask users' Internet activity and data from outside monitoring. According to a report by the New York Times, many of the most popular such apps are now missing from the Chinese App Store.
Businesses

P&G Cuts More Than $100 Million In 'Largely Ineffective' Digital Ads (wsj.com) 204

schwit1 quotes the Wall Street Journal: Procter & Gamble said that its move to cut more than $100 million in digital marketing spend in the June quarter had little impact on its business, proving that those digital ads were largely ineffective. Almost all of the consumer product giant's advertising cuts in the period came from digital, finance chief Jon Moeller said on its earnings call Thursday. The company targeted ads that could wind up on sites with fake traffic from software known as "bots," or those with objectionable content. "What it reflected was a choice to cut spending from a digital standpoint where it was ineffective, where either we were serving bots as opposed to human beings or where the placement of ads was not facilitating the equity of our brands," he said... The cuts echo marketing executives' mounting concerns around the efficacy of digital advertising and the growing perception that they are wasting money on digital ads that never reach their intended audience.
Cellphones

Do Kill Switches Deter Cellphone Theft? (arstechnica.com) 97

evolutionary shares an article from Ars Technica: San Francisco's district attorney says that a California state law mandating "theft-deterring technological solutions" for smartphones has resulted in a precipitous drop in such robberies. Those measures primarily include a remote kill switch after a phone has been stolen that would allow a phone to be disabled, withstanding even a hard reset. Such a kill switch has become standard in all iPhones ("Activation Lock") and Android phones ("Device Protection") since 2015... When measured from the peak in 2013, "overall robberies involving smartphones have declined an astonishing 50 percent... Because of this hard-fought legislation, stealing a smartphone is no longer worth the trouble, and that means the devices we use every day no longer make us targets for violent crime."
Printer

100x Faster, 10x Cheaper: 3D Metal Printing Is About To Go Mainstream (newatlas.com) 119

Big Hairy Ian shares an article from New Atlas: Desktop Metal -- remember the name. This Massachussetts company is preparing to turn manufacturing on its head, with a 3D metal printing system that's so much faster, safer and cheaper than existing systems that it's going to compete with traditional mass manufacturing processes... Plenty of design studios and even home users run desktop printers, but the only affordable printing materials are cheap ABS plastics. And at the other end of the market, while organizations like NASA and Boeing are getting valuable use out of laser-melted metal printing, it's a very slow and expensive process that doesn't seem to scale well.

But a very exciting company out of Massachusetts, headed by some of the guys who came up with the idea of additive manufacture in the first place, believes it's got the technology and the machinery to boost 3D printing into the big time, for real. Desktop Metal is an engineering-driven startup whose founders include several MIT professors, and Emanuel Sachs, who has patents in 3D printing dating back to the dawn of the field in 1989. The company has raised a ton of money in the last few months, including some US$115 million in a recent Series D round that brings total equity investments up over US$210 million. That money has come from big players, too, including Google Ventures... And if Desktop Metal delivers on its promises -- that it can make reliable metal printing up to 100 times faster, with 10 times cheaper initial costs and 20 times cheaper materials costs than existing laser technologies, using a much wider range of alloys -- these machines might be the tipping point for large scale 3D manufacturing.

Android

Stealthy Google Play Apps Recorded Calls and Stole Emails (arstechnica.com) 55

An anonymous reader quotes Ars Technica: Google has expelled 20 Android apps from its Play marketplace after finding they contained code for monitoring and extracting users' e-mail, text messages, locations, voice calls, and other sensitive data. The apps, which made their way onto about 100 phones, exploited known vulnerabilities to root devices running older versions of Android.... As a result, the apps were capable of surreptitiously accessing sensitive data stored, sent, or received by at least a dozen other apps, including Gmail, Hangouts, LinkedIn, and Messenger. The now-ejected apps also collected messages sent and received by Whatsapp, Telegram, and Viber, which all encrypt data in an attempt to make it harder for attackers to intercept messages while in transit... To conceal their surveillance capabilities, the apps posed as utilities for cleaning unwanted files or backing up data.
Google reports that the malicious apps also had these functions:
  • Call recording
  • VOIP recording
  • Recording from the device microphone
  • Location monitoring
  • Taking screenshots
  • Taking photos with the device camera(s)
  • Fetching device information and files
  • Fetching user information (contacts, call logs, SMS, application-specific data)

12 hours later an antivirus provider reported two more Google Play apps could surreptitiously steal text messages by downloading a malicious plugin -- and that the apps had already been downloaded at least 100,000 times.


Government

The US Congress Is Investigating Government Use Of Kaspersky Software (reuters.com) 47

An anonymous reader quotes Reuters: A U.S. congressional panel this week asked 22 government agencies to share documents on Moscow-based cyber firm Kaspersky Lab, saying its products could be used to carry out "nefarious activities against the United States," according to letters seen by Reuters. The requests made on Thursday by the U.S. House of Representatives Committee on Science, Space and Technology are the latest blow to the antivirus company, which has been countering accusations by U.S. officials that it may be vulnerable to Russian government influence... The committee "is concerned that Kaspersky Lab is susceptible to manipulation by the Russian government, and that its products could be used as a tool for espionage, sabotage, or other nefarious activities against the United States," wrote the panel's Republican chairman, Lamar Smith, in the letters... A committee aide told Reuters the survey was a "first step" designed to canvas the U.S. government and that more action may follow depending on the results.
Agencies contacted include both the Deparatment of Homeland Security and NASA. The committee wants to see internal risk assessments, plus a list of all systems using Kaspersky products and the names of government contractors using the software.
Debian

Systemd Named 'Lamest Vendor' At Pwnie Security Awards (theregister.co.uk) 436

Long-time Slashdot reader darkpixel2k shares a highlight from the Black Hat USA security conference. The Register reports: The annual Pwnie Awards for serious security screw-ups saw hardly anyone collecting their prize at this year's ceremony in Las Vegas... The gongs are divided into categories, and nominations in each section are voted on by the hacker community... The award for best server-side bug went to the NSA's Equation Group, whose Windows SMB exploits were stolen and leaked online this year by the Shadow Brokers...

And finally, the lamest vendor response award went to Systemd supremo Lennart Poettering for his controversial, and perhaps questionable, handling of the following bugs in everyone's favorite init replacement: 5998, 6225, 6214, 5144, and 6237... "Where you are dereferencing null pointers, or writing out of bounds, or not supporting fully qualified domain names, or giving root privileges to any user whose name begins with a number, there's no chance that the CVE number will referenced in either the change log or the commit message," reads the Pwnie nomination for Systemd, referring to the open-source project's allergy to assigning CVE numbers. "But CVEs aren't really our currency any more, and only the lamest of vendors gets a Pwnie!"

CSO has more coverage -- and presumably there will eventually be an official announcement up at Pwnies.com.
Programming

How Rust Can Replace C In Python Libraries (infoworld.com) 304

An anonymous reader quotes InfoWorld: Proponents of Rust, the language engineered by Mozilla to give developers both speed and memory safety, are stumping for the language as a long-term replacement for C and C++. But replacing software written in these languages can be a difficult, long-term project. One place where Rust could supplant C in the short term is in the traditionally C libraries used in other languages... [A] new spate of projects are making it easier to develop Rust libraries with convenient bindings to Python -- and to deploy Python packages that have Rust binaries.
The article specifically highlights these four new projects:
  • Rust-CPython - a set of bindings in Rust for the CPython runtime
  • PyO3 - a basic way to write Rust software with bindings to Python in both directions.
  • Snaek - lets developers create Rust libraries that are loaded dynamically into Python as needed, but don't rely on being linked statically against Python's runtime.
  • Cookiecutter PyPackage Rust Cross-Platform Publish - simplifies the process of bundling Rust binaries with a Python library.

Slashdot Top Deals