Software

WikiLeaks Dump Reveals CIA Malware That Can Sabotage User Software (bleepingcomputer.com) 116

An anonymous reader writes: "While the world was busy dealing with the WannaCry ransomware outbreak, last Friday, about the time when we were first seeing a surge in WannaCry attacks, WikiLeaks dumped new files part of the Vault 7 series," reports BleepingComputer. This time, the organization dumped user manuals for two hacking tools named AfterMidnight and Assassin. Both are malware frameworks, but of the two, the most interesting is AfterMidnight -- a backdoor trojan for stealing data from infected PCs. According to its leaked manual, AfterMidnight contains a module to "subvert" user software by killing processes and delaying the execution of user software. Examples in this manual show CIA operatives how to kill browsers every 30 seconds to keep targets focused on their work, how to delay the execution of PowerPoint software with 30 seconds just to mess with their targets, or how to lock up 50% of PC resources whenever the user starts certain software. Basically, the CIA created nagware.
Security

Access Codes For United Cockpit Doors Accidentally Posted Online (techcrunch.com) 109

According to the Wall Street Journal, the access codes to United's cockpit doors were accidentally posted on a public website by a flight attendant. "[United Continental Holdings], which owns United Airlines and United Express, asked pilots to follow security procedures already in use, including visually confirming someone's identity before they are allowed onto the flight deck even if they enter the correct security code into the cockpit door's keypad," reports TechCrunch. From the report: The Air Line Pilots Association, a union that represents 55,000 pilots in the U.S. and Canada, told the WSJ on Sunday that the problem had been fixed. The notable thing about this security breach is that it was caused by human error, not a hack, and illustrates how vulnerable cockpits are to intruders despite existing safety procedures. The Air Line Pilots Association has advocated for secondary barriers made from mesh or steel cables to be installed on cockpits doors to make it harder to break into, but airlines have said that they aren't necessary.
Earth

SpaceX Launches Super-Heavy Satellite Atop Falcon 9 Rocket (usatoday.com) 85

SpaceX has successfully launched a heavy commercial communications satellite atop one of its Falcon 9 rockets today. "Weighing in at nearly 13,500 pounds atop the rocket, the fourth Inmarsat-5 satellite was the heaviest load lofted by a Falcon 9 yet," reports USA Today. From the report: The 230-foot rocket delivered the spacecraft larger than a double-decker bus to an orbit more than 22,000 miles over the equator. As a result, SpaceX did not attempt to land the rocket's first stage either at Cape Canaveral or at sea, and the Falcon 9 booster was not equipped with landing legs. The Inmarsat-5 Flight 4 satellite, built by Boeing, completes Inmarsat's four-satellite Global Xpress constellation focused on delivering high-speed broadband data to mobile customers, including commercial aircraft and ships and the U.S. military.
Medicine

38,000 People a Year Die Early Because of Diesel Emissions Testing Failures (theverge.com) 194

An anonymous reader quotes a report from The Verge: Diesel cars, trucks, and other vehicles in more than 10 countries around the world produce 50 percent more nitrogen oxide emissions than lab tests show, according to a new study. The extra pollution is thought to have contributed to about 38,000 premature deaths in 2015 globally. In the study, published today in Nature, researchers compared emissions from diesel tailpipes on the road with the results of lab tests for nitrogen oxides (NOx). The countries where diesel vehicles were tested are Australia, Brazil, Canada, China, the European Union, India, Japan, Mexico, Russia, South Korea, and the U.S., where more than 80 percent of new diesel vehicle sales occurred in 2015. The researchers found that 5 million more tons of NOx were emitted than the lab-based 9.4 million tons, according to the Associated Press. Nitrogen oxides are released into the air from motor vehicle exhaust or the burning of coal and fossil fuels, producing tiny soot particles and smog. Breathing in all this is linked to heart and lung diseases, including lung cancer, according to the International Council on Clean Transportation, which took part in the research. Governments routinely test new diesel vehicles to check whether they meet pollution limits. The problem is that these tests fail to mimic real-life driving situations, and so they underestimate actual pollution levels. The researchers estimate that the extra pollution is linked to about 38,000 premature deaths worldwide in 2015 -- mostly in the European Union, China, and India. (The U.S. saw an estimated 1,100 deaths from excess NOx.)
Facebook

ZeniMax Is Suing Samsung After Winning Its Case Against Oculus (cnn.com) 78

Games company ZeniMax successfully sued Facebook-owned Oculus for $500 million earlier this year, and now it has a new target in sight: Samsung. The company has filed a new lawsuit over Samsung's Gear VR headset, claiming that "Samsung knowingly profited from Oculus technology that was first developed at ZeniMax, then misappropriated by Oculus executive John Carmack," reports The Verge. From the report: Carmack, whose company id Software was acquired by ZeniMax in 2009, was one of the driving forces behind the Gear VR. While the headset was released by Samsung, it's described as "powered by Oculus," with heavy software optimizations developed by Carmack. But the lawsuit alleges that Carmack owed much of his success at Oculus to software he developed as part of a team at ZeniMax. Among other things, the Texas court filing claims that Carmack secretly brought Oculus (and former ZeniMax) employee Matt Hooper into id Software's offices to develop an "attack plan" for mobile VR, which Oculus would later take to Samsung. The Samsung Gear VR was also built on some of the same code as the Oculus Rift, which was the subject of ZeniMax's earlier lawsuit. ZeniMax's basic argument is that Samsung would have been aware of the lawsuit against Oculus, which was filed during the initial development of the Gear VR. But "Samsung continued to develop the Gear VR with full knowledge of ZeniMax's allegations and without obtaining any right or permission from ZeniMax to use any of its copyrights or other confidential information." The new lawsuit officially accuses Samsung of copyright infringement for using ZeniMax VR code in the Gear VR, as well as trade secret misappropriation, unfair competition, and unjust enrichment.
Security

WannaCry Ransomware Shares Code With North Korean Malware, Says Researchers (cyberscoop.com) 106

New submitter unarmed8 quotes a report from CyberScoop: The ransomware known as WannaCry that spread rapidly to 300,000 machines in 150 countries over the past few days shares code with malware written by a group of North Korean hackers known as the Lazarus Group. While the shared code is important, experts warned that it's far from proof about who created and launched the ransomware attacks. Neel Mehta, a security researcher at Google, first pointed out the shared code on Monday on Twitter. The link was quickly echoed by numerous other experts. "From a technical point of view those two functions and their references are identical," said Matt Suiche, founder of United Arab Emirates-based cybersecurity firm Comaeio. "From an attribution point of view a ransomware would subscribe to the narrative of Lazarus Group, which is stealing money like we saw with multiple financial institutions with fraudulent SWIFT transactions -- having a nation-state powered ransomware leveraging crypto currency would be a first."
Movies

Disney Chief Bob Iger Says Hackers Claim To Have Stolen Upcoming Movie (hollywoodreporter.com) 121

An anonymous reader quotes a report from Hollywood Reporter: Walt Disney CEO Bob Iger revealed Monday that hackers claiming to have access to a Disney movie threatened to release it unless the studio paid a ransom. Iger didn't disclose the name of the film, but said Disney is refusing to pay. The studio is working with federal investigators. Iger's comments came during a town hall meeting with ABC employees in New York City, according to multiple sources. The Disney chief said the hackers demanded that a huge sum be paid in Bitcoin. They said they would release five minutes of the film at first, and then in 20-minute chunks until their financial demands are met. While movie piracy has long been a scourge, ransoms appear to be a new twist. UPDATE: According to Deadline, the movie in question appears to be the upcoming film Pirates of the Caribbean: Dead Men Tell No Tales. Disney appears to be working with the FBI and will not pay the ransom.
Microsoft

Microsoft Job Posting Hints At VR MMO (roadtovr.com) 18

sqorbit writes: Microsoft has posted a job opening for a Senior Design Manager for a mixed-reality team. The posting states they are "looking to build a massively social gaming and entertainment experience for both the PC and the console." It looks like they are targeting both PC and Xbox Platforms for a VR socially geared development project. The requirements: "The Xbox Mixed Reality team is looking for an experienced senior design manager with deep expertise and passion around crafting immersive social systems and experiences. [...] Here is an opportunity to join a fun and collaborative team that experiments with the latest toys, works with state of the art tech, and crafts the future of entertainment." Road to VR notes that the company says they're looking for someone who has "Shipped at least 3 AAA consumer entertainment products" and has 7+ years using design tools; bonus points if they've got experience in "NUI, VR, AR, game design, art direction, and video storytelling."
Chrome

Should You Leave Google Chrome For the Opera Browser? (vice.com) 303

mspohr shares a report written by Jason Koebler via Motherboard who makes the case for why you should break up with Chrome and switch to the Opera browser: Over the last few years, I have grown endlessly frustrated with Chrome's resource management, especially on MacOS. Admittedly, I open too many tabs, but I'd wager that a lot of you do, too. With Chrome, my computer crawls to complete unusability multiple times a day. After one too many times of having to go into Activity Monitor to find that one single Chrome tab is using several gigs of RAM, I decided enough was enough. I switched to Opera, a browser I had previously thought was only for contrarians. This, after previous dalliances with Safari and Firefox left me frustrated. Because Opera is also based on Blink, I almost never run into a website, plugin, script, or video that doesn't work flawlessly on it. In fact, Opera works almost exactly like Chrome, except without the resource hogging that makes me want to throw my computer against a brick wall. This is exactly the point, according to Opera spokesperson Jan Standal: "What we're doing is an optimized version of Chrome," he said. "Web developers optimize most for the browser with the biggest market share, which happens to be Chrome. We benefit from the work of that optimization."

Slashdot reader mspohr adds: "I should note that this has also been my experience. I have a 2010 MacBook, which I was ready to trash since it had become essentially useless, coming to a grinding halt daily. I tried Opera and it's like I have a new computer. I never get the spinning wheel of death. (Also, the built-in ad blocker and VPN are nice.)" What has been your experience with Google Chrome and/or Opera? Do you prefer one over the other?

Robotics

A Lowe's Hardware Store Is Trialling Exoskeletons To Give Workers a Helping Hand (theverge.com) 48

slew writes: Okay, this isn't Aliens 2, but hardware chain Lowe's is "outfitting employees with a simple exoskeleton to help them on the job," reports The Verge. "The company has partnered with Virginia Tech to develop the technology, which makes lifting and moving heavy objects easier. The non-motorized exoskeletons are worn like a harness, with carbon fiber rods acting as artificial tendons -- bending when the wearer squats, and springing back when they stand up. Lowe's has issued four of the custom-built suits to employees at a store in Christiansburg, Virginia. The equipment has been in use for over a month and the company says early feedback is extremely positive. '[Employees] wear it all day, it's very comfortable, and it makes their job easier,' says Kyle Nel, the director of Lowe's Innovation Labs, adding that Lowe's is working with scientists from Virginia Tech to conduct a proper survey of the technology's usefulness. 'It's early days, but we're doing some major studies,' he says."
Desktops (Apple)

Apple Releases macOS 10.12.5, iOS 10.3.2, watchOS 3.2.2, tvOS 10.2.1 (macworld.com) 45

On Monday, Apple released point updates to all its operating systems. Starting with the desktop, the macOS 10.12.5 update for Sierra is the fifth major update since the operating system was released in September of 2016. The iPhone-maker also released the iOS 10.3.2 for iPhones, iPads and iPods to the public. The update for Macs offers a range of bug fixes, improvements to Night Shift, and a long list of security patches. The iOS 10.3.2 update offers "bug fixes and improves the security." More details -- including what's new in tvOS, and watchOS -- here.
The Courts

Judge's Order Bars Uber Engineer From LiDAR Work, Demands Returns of Stolen Files (arstechnica.com) 43

An anonymous reader quotes a report from Ars Technica: A U.S. federal judge has ordered Uber to bar its top self-driving car engineer from any work on LiDAR, and return stolen files to Google's self-driving car unit Waymo. Today's order by U.S. District Judge William Alsup demands Uber do "whatever it can to ensure that its employees return 14,000-plus pilfered files to their rightful owner." The files must be returned by May 31. The order was granted last week, but just made public in an unsealed document this morning. U.S. District Judge William Alsup found that Uber "likely knew or at least should have known" that the man it hired as its top self-driving car engineer, Anthony Levandowski, took and kept more than 14,000 Waymo files. Those files "likely contain at least some trade secrets," making some "provisional relief" for Waymo appropriate. Levandowski has previously asserted his Fifth Amendment rights with respect to his possession of the files. "If Uber were to threaten Levandowski with termination for noncompliance, that threat would be backed up by only Uber's power as a private employer, and Levandowski would remain free to forfeit his private employment to preserve his Fifth Amendment privilege," Alsup wrote. Several factors limit the amount of relief Waymo might receive. First of all, in the judge's view, not all of the 121 elements that Waymo defines as "trade secrets" are really trade secrets. Additionally, the judge has slapped aside Waymo's patent infringement accusations as "meritless."
Security

UK Tabloids Doxxed the 'Hero' Hacker Who Stopped a Global Cyberattack (theoutline.com) 164

The UK-based security researcher, who "accidentally" halted the spread of the ransomware Wanna Decryptor over the weekend, has been doxxed by UK tabloids. From a report: [...] Journalists have published his name against his will, bringing him unwanted attention and sending a signal to privacy-sensitive researchers that no good deed goes unpunished. The researcher, writing under the username MalwareTechBlog, published a blog post on his personal site with findings about the virus, explaining how it was stopped and what would have to be done to prevent it from coming back. News outlets, including the Daily Mail, The Guardian, and CNN called the anonymous researcher a hero. The researcher was initially responsive to press inquiries. He told reporters that he was 22, lived in the south of England with his parents, and worked for an L.A. security firm. However, he told The Guardian that he wanted to remain anonymous "because it just doesn't make sense to give out my personal information, obviously we're working against bad guys and they're not going to be happy about this." It took about a day for UK papers, including The Mail, The Sun, The Telegraph, and The Mirror, to suss out the researcher's name and publish photos of him, show up at his house, and track down his friends and associates for interviews. "It's caused a fair bit of stress," he told Forbes. "I don't want fame."
United States

The Reign of the $100 Graphing Calculator Required By Every US Math Class Is Finally Ending (engadget.com) 281

If you took a math class at some point in the US, there is likely a bulky $100 calculator gathering dust somewhere in your closet. Fast forward to today, and the Texas Instruments 84 -- or the TI 84-Plus, or the TI-89 or any of the other even more expensive hardware variants -- is quickly losing relevance. Engadget adds: Thanks to a new deal, they'll soon get a free option. Starting this spring, pupils in 14 US states will be able to use the TI-like Desmos online calculator during standardized testing run by the Smarter Balanced consortium. "We think students shouldn't have to buy this old, underpowered device anymore," Desmos CEO Eli Luberoff said. The Desmos calculator will be embedded directly into the assessments, meaning students will have access during tests with no need for an external device. It'll also be available to students in grades 6 through 8 and high school throughout the year. The calculator is free to use, and the company makes money by charging organizations to use it, according to Bloomberg.
Education

'U Can't Talk to Ur Professor Like This' (nytimes.com) 486

Millennial college students have become far too casual when they talk with their professors, reads an opinion piece on The New York Times. Addressing professors by their first names and sending misspelled, informal emails with text abbreviations have become common practices (Editor's note: the link could be paywalled; here's a syndicated source) among many students than educators would like, Molly Worthen, an assistant professor of history at the University of North Carolina, Chapel Hill adds. From the article: Over the past decade or two, college students have become far more casual in their interactions with faculty members. My colleagues around the country grumble about students' sloppy emails and blithe informality. "When students started calling me by my first name, I felt that was too far, and I've got to say something," Mark Tomforde, a math professor at the University of Houston said. Sociologists who surveyed undergraduate syllabuses from 2004 and 2010 found that in 2004, 14 percent addressed issues related to classroom etiquette; six years later, that number had more than doubled, to 33 percent. This phenomenon crosses socio-economic lines. My colleagues at Stanford gripe as much as the ones who teach at state schools, and students from more privileged backgrounds are often the worst offenders. [...] Insisting on traditional etiquette is also simply good pedagogy. It's a teacher's job to correct sloppy prose, whether in an essay or an email. And I suspect that most of the time, students who call faculty members by their first names and send slangy messages are not seeking a more casual rapport. They just don't know they should do otherwise -- no one has bothered to explain it to them. Explaining the rules of professional interaction is not an act of condescension; it's the first step in treating students like adults.

Slashdot Top Deals