Government

Russian Cyber Hacks On US Electoral System Far Wider Than Previously Known (bloomberg.com) 520

An anonymous reader shares a Bloomberg article: Russia's cyberattack on the U.S. electoral system before Donald Trump's election was far more widespread than has been publicly revealed, including incursions into voter databases and software systems in almost twice as many states as previously reported. In Illinois, investigators found evidence that cyber intruders tried to delete or alter voter data. The hackers accessed software designed to be used by poll workers on Election Day, and in at least one state accessed a campaign finance database. Details of the wave of attacks, in the summer and fall of 2016, were provided by three people with direct knowledge of the U.S. investigation into the matter. In all, the Russian hackers hit systems in a total of 39 states, one of them said. The scope and sophistication so concerned Obama administration officials that they took an unprecedented step -- complaining directly to Moscow over a modern-day "red phone." In October, two of the people said, the White House contacted the Kremlin on the back channel to offer detailed documents of what it said was Russia's role in election meddling and to warn that the attacks risked setting off a broader conflict.
Communications

Someone Built a Tool To Get Congress' Browser History (vice.com) 68

A software engineer in North Carolina has created a new plugin that lets website administrators monitor when someone accesses their site from an IP address associated with the federal government. It was created in part to protest a measure signed by President Trump in April that allows internet service providers to sell sensitive information about your online habits without needing your consent. Motherboard reports: A new tool created by Matt Feld, the founder of several nonprofits including Speak Together, could help the public get a sense of what elected officials are up to online. Feld, a software engineer working in North Carolina, created Speak Together to share "technical projects that could be used to reduce the opaqueness between government and people," he told Motherboard over the phone. "It was born out of just me trying to get involved and finding the process to be confusing." The tool lets website administrators track whether members of Congress, the Senate, White House staff, or Federal Communications Commission (FCC) staff are looking at their site. If you use Feld's plug-in, you'll be able to see whether someone inside government is reading your blog. You won't be able to tell if President Trump viewed a web page, but you will be able to see that it was someone using an IP address associated with the White House. The tool works similarly to existing projects like CongressEdits, an automated Twitter account that tweets whenever a Wikipedia page is edited from IP addresses associated with Congress.
Network

Hackers Can Spoof Phone Numbers, Track Users Via 4G VoLTE Mobile Technology (bleepingcomputer.com) 38

An anonymous reader writes: "A team of researchers from French company P1 Security has detailed a long list of issues with the 4G VoLTE telephony, a protocol that has become quite popular all over the world in recent years and is currently in use in the US, Asia, and most European countries," reports Bleeping Computer. Researchers say they identified several flaws in the VoLTE protocol (a mixture of LTE and VoIP) that allow an attacker to spoof anyone's phone number and place phone calls under new identities, and extract IMSI and geo-location data from pre-call message exchanges. These issues can be exploited by both altering some VoLTE packets and actively interacting with targets, but also by passively listening to VoLTE traffic on an Android device. Some of these flaws don't even need a full call/connection to be established between the victim and the target for the data harvesting operation to take place. Additionally, another flaw allows users to make calls and use mobile data without being billed. The team's research paper, entitled "Subscribers remote geolocation and tracking using 4G VoLTE enabled Android phone" was presented last week at SSTIC (Symposium sur la Securite des Technologies de l'Information et des Communications), a security conference held each year in Rennes, France.
Facebook

Man Sentenced to Death For Blasphemous Facebook Comments In Pakistan (gizmodo.com) 469

In what is believed to be "the first time the death penalty had been awarded in a case related to social media," a 30-year-old man in Pakistan has been sentenced to death for blasphemy in comments made on Facebook. Gizmodo reports: The prosecutor told The Times of India that Taimoor Raza was arrested "after playing blasphemous and hate speech material on his phone on a bus stop in Bahawalpur, where a counter-terrorism officer arrested him and confiscated his phone." It was the material on Raza's phone that led to his arrest. The Guardian reports that the accused's brother said Raza "indulged in a sectarian debate on Facebook with a person, who we later come to know, was a [counter-terrorism department] official with the name of Muhammad Usman." Raza's defense attorney told The Guardian the initial charges were limited to "insulting remarks on sectarian grounds," which carries a maximum two-year jail sentence, but that "derogatory acts against prophet Muhammad," which carry a death sentence, were added later. According to The Times of India, Raza will be able to appeal the ruling to the Pakistani High Court and the Supreme Court. Facebook said in a statement: "We are deeply saddened and concerned by the death sentence served in Pakistan for a Facebook post. Facebook uses powerful systems to keep people's information secure and tools to keep their accounts safe, and we do not provide any government with direct access to people's data. We will continue to protect our community from unnecessary or overreaching government intervention."
Education

Wisconsin Speech Bill Might Allow Students To Challenge Science Professors (arstechnica.com) 438

An anonymous reader quotes a report from Ars Technica: There have been some well-publicized incidents in which student groups or other protesters have interfered with scheduled appearances by right-wing speakers at U.S. universities. In response, a number of states have considered "campus free speech" bills based on model legislation produced by the Goldwater Institute, a conservative think tank. Different bills introduce specific penalties for students who shout down the speech of others and prevent college administrators from disinviting speakers, to give two examples. One such bill is being debated in Wisconsin. Faculty and university officials in the state are concerned about what else might be prevented by the bill's overly vague language, according to the local Cap Times. As often happens with bills relevant to science education, the debate has also elicited some rather bizarre comments from the bill's sponsors. The trouble comes from this section of the bill: "That each institution shall strive to remain neutral, as an institution, on the public policy controversies of the day, and may not take action, as an institution, on the public policy controversies of the day in such a way as to require students or faculty to publicly express a given view of social policy." While the bills' scope is focused on public events involving invited speakers, there are a couple key questions here. University officials want to know how far this requirement "to remain neutral" extends. For example, the University of Wisconsin-Madison has spoken out against proposed bans on stem cell research on campus. Would the university run afoul of this law if it did so again?
Bitcoin

Why Ethereum Is Outpacing Bitcoin (venturebeat.com) 150

Even as Bitcoin hits its all-time high, people's interest in other cryptocurrencies hasn't waned, especially Ethereum. But what makes Ethereum popular among some? From an article on VentureBeat: Despite its recent appreciation in value, as a technology, Bitcoin has stagnated over the last three years. Two rival factions have emerged with violently opposing views on what should be done to allow the Bitcoin network to handle more transactions than it can right now. While Bitcoin has been paralysed by indecision, Ethereum has raced ahead with technology that not only does everything Bitcoin can do faster, in higher volume, and at lower cost -- it does a lot more besides. [...] Bitcoin is really only useful as a store of value. Even then, its usefulness for actually transacting value is limited. In a world where people are used to online payments being confirmed instantly, Bitcoin transactions can take anywhere from tens of minutes to several hours, depending on how busy the network is. It's also expensive -- especially if you're only sending small amounts. The average transaction currently costs about $1.50. Ethereum, on the other hand, was never intended as a Bitcoin competitor. Ethereum is actually a platform for new kinds of decentralized (often financial) applications (dApps) that run on a peer-to-peer network of computers. These dApps are designed to disintermediate the kinds of relationships and transactions for which we have traditionally required things like banks, public registries, and the legal system. For technologists, this is exciting stuff, and a vibrant community of software developers has enthusiastically embraced it. Hundreds of projects, startups, and companies at every scale -- including the likes of Intel, Microsoft, and Samsung -- are building software using Ethereum.
The Almighty Buck

Report Reveals In-App Purchase Scams In the App Store (macrumors.com) 48

In a Medium article titled How to Make $80,000 Per Month On the Apple App Store, Johnny Lin uncovers a scamming trend in which apps advertising fake services are making thousands of dollars a month from in-app purchases. The practice works by manipulating search ads to promote dubious apps in the App Store and then preys on unsuspecting users via the in-app purchase mechanism. MacRumors reports: "I scrolled down the list in the Productivity category and saw apps from well-known companies like Dropbox, Evernote, and Microsoft," said Lin. "That was to be expected. But what's this? The #10 Top Grossing Productivity app (as of June 7th, 2017) was an app called 'Mobile protection :Clean & Security VPN.' Given the terrible title of this app (inconsistent capitalization, misplaced colon, and grammatically nonsensical 'Clean & Security VPN?'), I was sure this was a bug in the rankings algorithm. So I check Sensor Tower for an estimate of the app's revenue, which showed ... $80,000 per month?? That couldn't possibly be right. Now I was really curious." To learn how this could be, Lin installed and ran the app, and was soon prompted to start a "free trial" for an "anti-virus scanner" (iOS does not need anti-virus software thanks to Apple's sandboxing rules for individual apps). Tapping on the trial offer then threw up a Touch ID authentication prompt containing the text "You will pay $99.99 for a 7-day subscription starting Jun 9, 2017." Lin was one touch away from paying $400 a month for a non-existent service offered by a scammer. Lin dug deeper and found several other similar apps making money off the same scam, suggesting a wider disturbing trend, with scam apps regularly showing up in the App Store's top grossing lists.
Hardware

Ask Slashdot: What Would Happen If You Were To Put a Computer Inside a Fridge? 181

dryriver writes: This is not asking what would happen if you were to place your iMac inside your kitchen fridge. Rather, what if a computer casing for a high-powered graphics workstation with multiple CPUs and GPUs, lets say, worked just like a small fridge or freezer, cooling your hardware down without using any CPU fans or liquid cooling and similar. How much would such a fridge-casing cost to make and buy, how much electricity would it consume, how much bigger would it be than a normal PC casing, and would it be a practical solution to the problem of keeping high-powered computer hardware cool for extended periods of time? Bonus question: Is such a thing as a fridge-casing or "Fridgeputer" sold anywhere on the world market right now? Linus Tech Tips tackled this question in a video a couple of years ago, titled "PC Build in a Fridge - Does it Work?"
The Almighty Buck

US Banks Launching Answer To Peer-To-Peer Payment App Venmo (reuters.com) 43

The U.S. banking industry is about to launch its answer to the popular mobile payments app Venmo. "Over the next week, five of the largest U.S. banks will light up their segments of a new payments network called Zelle, executives said in interviews," reports Reuters. "They plan to announce details of the launch on Monday, and expect another two dozen banks and credit unions to join over the next year." From the report: The long-awaited network will allow tens of millions of bank customers to send money to each other instantly - known as person-to-person payments - with a few taps on their smartphones. That is an improvement over Venmo, which immediately alerts users that a money transfer is in progress, but takes time to shift funds between bank accounts. Customers who use existing bank payment apps may not notice much of a change beyond marketing. Transfers will simply happen faster because the banks are finally linking to each other, executives said. JPMorgan, Bank of America Corp, Wells Fargo & Co, U.S. Bancorp and Capital One Financial Corp will be the first to plug into Zelle.
Businesses

Wordpress Parent Automattic Is Closing Its San Francisco Office Because Its Employees Never Show Up (qz.com) 92

An anonymous reader quotes a report from Quartz: Automattic, the technology company that owns WordPress.com, has a beautiful office in a converted San Francisco warehouse, with soaring ceilings, a library, and a custom-made barn door. If you like the space, you're free to move in. The office at 140 Hawthorne went on the market after CEO Matt Mullenweg came to the realization not enough employees used it. As he explained on the Stack Overflow podcast earlier this year: "We got an office there about six or seven years ago, pretty good lease, but nobody goes in it. Five people go in it and it's 15,000 square feet. They get like 3,000 square feet each. There are as many gaming tables as there are people." Automattic has always given its 550 employees the choice of working remotely; the San Francisco space was an optional co-working space, spokesman Mark Armstrong said. The company maintains similar offices in Cape Town, South Africa, and outside Portland, Maine, and gives employees a $250-a-month stipend if they want to use commercial co-working offices elsewhere. And if they'd rather work at Starbucks, Automattic will pay for their coffee.
Power

Researchers Reveal Malware Designed To 'Power Down' Electric Grid (securityledger.com) 42

chicksdaddy writes: A sample of malicious software discovered at the site of a December, 2016 cyber attack on Ukraine's electrical grid is a previously unknown program that could be capable of causing physical damage to the electrical grid, according to reports by two security firms. The Security Ledger reports: "Experts at the firm ESET and Dragos Security said on Monday that the malicious software, dubbed CrashOverride (Dragos) or Industroyer (ESET) affected a 'single transmission level substation' in the Ukraine attack on December 17th, 2016 in what appears to have been a test run. Still, experts said that features in the malware show that adversaries are automating and standardizing what were previously manual attacks against critical infrastructure, while also adding features that could be used to physically disable or damage critical systems -- the first evidence of such activity since the identification of the Stuxnet malware in 2010. The Crash Override malware 'took an approach to understand and codify the knowledge of the industrial process to disrupt operations as STUXNET (sp) did,' wrote Dragos Security in a report. The malware improves on features seen in other malicious software that it knows to target industrial control systems. Specifically, the malware makes use of and manipulates industrial control system-specific communications protocols. That's similar to features in ICS malware known as Havex that targeted grid operators in Europe and the United States in 2014. The Crash Override malware also targeted the libraries and configuration files of so-called 'Human Machine Interfaces' (or HMIs) to understand the environment they have infected. It can use HMIs, which provide a graphical interface for managing industrial control system equipment, to connect spread to other Internet connected equipment and systems, Dragos said."
Wireless Networking

Logitech Reveals Mouse Mat That Is a Giant Wireless Charging Pad (theverge.com) 62

Logitech has just revealed a new Powerplay technology that builds wireless charging directly into its mouse pad, allowing compatible wireless mice to charge constantly while on the pad. The Verge reports: The wireless charging tech built inside the Powerplay mouse mat is proprietary to Logitech, and the company claims it took more than four years of research and development to make it a reality. I asked Logitech why it didn't go with something more ubiquitous like the Qi standard, and the answer I received was that it wouldn't have been possible to cover the whole surface (275mm x 320mm) of the pad with Qi. Alongside the Logitech G Powerplay, which is to be priced at $99.99 and released in August, Logitech has also announced the first two mice officially compatible with it: the G903 and G703. The G903 is a very modest upgrade from the G900 while the G703 is practically identical to the well liked G403; both of the two new models use the PMW3366 optical sensor and just add improved switches rated to last longer. The G903 will cost $149.99 and the G703 will be $99.99 when they go on sale later this month.
Government

'COVFEFE Act' Would Make Social Media a Presidential Record (thehill.com) 322

An anonymous reader quotes a report from The Hill: Rep. Mike Quigley (D-Ill.) introduced legislation Monday to classify presidential social media posts -- including President Trump's much-discussed tweets -- as presidential records. The Communications Over Various Feeds Electronically for Engagement (COVFEFE) Act, which has the same acronym as an infamous Trump Twitter typo last month, would amend the Presidential Records Act to include "social media." Presidential records must be preserved, according to the Presidential Records Act, which would make it potentially illegal for the president to delete tweets. "President Trump's frequent, unfiltered use of his personal Twitter account as a means of official communication is unprecedented. If the President is going to take to social media to make sudden public policy proclamations, we must ensure that these statements are documented and preserved for future reference. Tweets are powerful, and the President must be held accountable for every post," said Quigley in a statement. Most people took the "covfefe" tweet to be a typo, although press secretary Sean Spicer told the media that the term was used intentionally. "The president and a small group of people know exactly what he meant," he said.
The Courts

Microsoft Wins Xbox Class-Action Fight at US Supreme Court (reuters.com) 26

The U.S. Supreme Court on Monday ruled in favor of Microsoft in its bid to fend off class action claims by Xbox 360 owners who said the popular videogame console gouges discs because of a design defect. From a report: The court, in a 8-0 ruling, overturned a 2015 decision by the San Francisco-based 9th U.S. Circuit Court of Appeals that allowed console owners to appeal the dismissal of their class action lawsuit by a federal judge in Seattle in 2012. Typically parties cannot appeal a class certification ruling until the entire case has reached a conclusion. But the 9th Circuit allowed the console owners to voluntarily dismiss their lawsuit so they could immediately appeal the denial of a class certification. Justice Ruth Bader Ginsburg, writing on behalf of the court, said such a move was not permitted because a voluntary dismissal of a lawsuit is not a final decision and thus cannot be appealed. The approach sought by the plaintiffs would undermine litigation rules "designed to guard against piecemeal appeals," Ginsburg wrote.
Security

Researchers Have Found a Way To Root Out Identity Thieves By Analyzing Their Mouse Movements With AI (qz.com) 62

An anonymous reader shares an article: In the study, published recently in PLoS One, the researchers quizzed 40 respondents about their personal details. Half of the respondents were asked to answer the questions truthfully, but the other half were given details about fake identities they had to memorize and use in the quiz. The computer quiz kept track of the movement of each respondent's mouse as they answered the questions, and noted how the fakes differed from the truth-tellers when they moved the cursor from the bottom of the screen to the answers at the top. The quiz consisted of 12 questions like, "Do you live in Padua?" and "Are you Italian?" That covered details an identity thief could easily remember and answer, but then the quiz threw them a curve ball. "What is your zodiac sign," it asked in the second series of 12 questions, which were designed to be easy for the genuine respondents, but more difficult for the fakers to work out. After the researchers took the mouse-movement data collected from the quizzes and trained a machine-learning algorithm to analyze it, they found that was indeed the case. It was able to discern the fake responses from the real ones 95% of the time.

Slashdot Top Deals