Security

Director of National Intelligence Warns of IoT Security Threats (engadget.com) 36

According to Director of National Intelligence Daniel Coats, IoT devices may be used to shut down US intelligence operations in the future. From a report: At an open hearing today, the Senate Select Committee on Intelligence (SSCI) heard testimony on the worldwide threat assessment of the US intelligence community. Coats' opening statements included a warning of the dangers of poor smart device security as well as the continued inevitability of Russian cyber threats. Coat's testimony lists these concerns first, with Russia topping the list of enemy actors. Coats says that the Kremlin has taken a much more aggressive "cyber posture," which "was evident in Russia's efforts to influence the 2016 US election." Coats' report (PDF) also says that Russian actors have conducted attacks on critical infrastructure networks, even going so far as to pretend to be third parties hiding behind false online personas. "Russia is a full-scope cyber actor that will remain a major threat to US Government, military, diplomatic, commercial, and critical infrastructure," says Coats in the written version of his statement. The document notes that China, Iran and North Korea, as well as terrorists and criminals, are also threats. Coats also spoke at length about "smart" devices, which have increased the number of vectors that hostile actors can attack. The denial-of-service (DDoS) attacks that we already see will only become more prevalent. These botnets use weakly-protected IoT devices to overwhelm websites and other networks. "In the future," Coats says in his report, "state and non-state actors will likely use IoT devices to support intelligence operations or domestic security or to access or attack targeted computer networks."
Education

'The Traditional Lecture Is Dead' (wired.com) 233

Rhett Allain, an Associate Professor of Physics at Southeastern Louisiana University, writing for Wired: What is the traditional lecture? It is a model of learning in which a teacher possesses the knowledge on a given topic and disseminates it to students. This model dates to the beginning of education, when it was the only way of sharing information. In fact, you occasionally still see the person presenting the lecture called a reader, because way back before the internet and even the printing press, a teacher would literally read from a book so students could copy it all down. Now, don't get me wrong. The traditional lecture model worked wonderfully for eons. But it is an outdated idea (free pass for adblockers). Close your eyes and imagine yourself in a college physics course with a professor giving a traditional lecture. Now open your eyes. Did you envision The Best Physics Lecture EVAR? I doubt it. You probably pictured someone droning on and on in front of a chalkboard or PowerPoint presentation. No way that is more engaging or interesting than an episode of The Mechanical Universe , and if you're a teacher who uses traditional lectures, just stop and play the show instead. Everyone will be better off. You may think by now that I think most physics professors are dolts. I promise that's not the case. But traditional lectures simply aren't effective. Research shows students don't learn by hearing or seeing, they learn by doing, a model often called active learning. Physics faculty should start thinking about how they can go beyond just a traditional lecture. There are some easy things they can do (or students can ask them to do) to make learning more engaging. First, make students read the book outside of class, rather than in class. If your lecture merely covers the material in the textbook, why make students buy the textbook? Now, you may put a different spin on the material, but still. You're merely repeating what students can read on their own. Let them do that on their own time, and use the classroom for experiments and demonstrations and so forth.
Businesses

Amazon Is the 2nd Most Popular App Among Teens, Says Study (cnbc.com) 56

An anonymous reader writes: When it comes to apps they're using these days, teens and millennials say Snapchat is king -- no surprise there. But second place? It's not Instagram: It's Amazon. This is according to a survey -- The 2017 Love List Brand Affinity Index, run by Conde Nast and Goldman Sachs -- that asked 2,345 U.S. millennial and Gen Z shoppers about their fashion, retail and consumer preferences. The survey skewed towards younger consumers. One question asked which apps they were using currently that they weren't using a few months ago: Snapchat and Amazon came in first and second. (Other popular apps -- Instagram, Twitter and Pinterest -- came in third, fourth and fifth respectively.) "Users are looking for efficiency, speed and convenience, and Amazon hits all those buckets," said Conde Nast chief marketing officer Pam Drucker Mann told CNBC. On a side note, it appears people generally don't have many gripes with Amazon. Early results of our poll from Wednesday suggests Amazon is the last company (of the five tech giants) whose services people are keen on ditching. Also, regardless of how some of us feel about Snapchat, the company seems to be a hit among teenagers.
The Courts

Man To Pay $300,000 In Damages For Hacking Employer (bbc.com) 69

An anonymous reader writes: A former private security officer in California must pay nearly $319,000 in damages for attacking his employer's computer systems. Yovan Garcia accessed payroll records at Security Specialists, which provides private security patrols, to inflate the number of hours he had worked. He later hacked the firm's servers to steal data and defaced its website. District Judge Michael Fitzgerald said Garcia had used the stolen data to help set up a rival business. Security Specialists first noticed issues with Mr Garcia's pay records in July 2014, about two years after he joined. In one example, they showed he had worked 12 hours per day over a two-week period and was owed 40 hours of overtime pay, when in fact he only worked eight hours per day.
The Internet

NYU Accidentally Exposed Military Code-breaking Computer Project To Entire Internet (theintercept.com) 75

An anonymous reader writes: A confidential computer project designed to break military codes was accidentally made public by New York University engineers. An anonymous digital security researcher identified files related to the project while hunting for things on the internet that shouldn't be, The Intercept reported. He used a program called Shodan, a search engine for internet-connected devices, to locate the project. It is the product of a joint initiative by NYU's Institute for Mathematics and Advanced Supercomputing, headed by the world-renowned Chudnovsky brothers, David and Gregory, the Department of Defense, and IBM. Information on an exposed backup drive described the supercomputer, called -- WindsorGreen -- as a system capable of cracking passwords.
Windows

Apple is Bringing iTunes To the Windows Store (theverge.com) 87

Tom Warren, writing for The Verge: Apple is planning to bring its iTunes desktop app to the Windows Store. In a surprise announcement at the Build developer event today, Microsoft revealed it has been working with Apple to get iTunes listed in the Windows Store. It might not sound like an important addition, but iTunes is one of the most searched for apps that's currently missing in the Windows Store. USA Today veteran columnist, summing up the announcement, "Microsoft announces that iTunes (incl Apple Music and full support for iPhone) is coming to the Windows Store. Big get for Microsoft." Microsoft's communication head, summing up the situation, "Didn't see that one coming, did you!"
Facebook

Snap CEO Evan Spiegel Is Not Afraid of Facebook (recode.net) 42

An anonymous reader writes: Snap CEO Evan Spiegel addressed on Wednesday what many have been hoping he would address for months: What he thinks about Facebook and the fact the social giant is copying all of Snapchat's best features. On Snap's Q1 earnings call Wednesday, Spiegel was asked bluntly: "Does Facebook scare you? Why or why not?" Spiegel laughed. Then talked about how important it is to be creative. Then said this: "At the end of the day, just because Yahoo, for example, has a search box, it doesn't mean they're Google." Fun fact: Yahoo is an investor in Snap.
Microsoft

Microsoft Announces Windows 10 Fall Creators Update, the Next Major Update To Desktop OS (betanews.com) 121

At its developer conference on Thursday, Microsoft announced that the next major update to its desktop operating system will be called Windows 10 Fall Creators Update. It will be made available in September later this year. The update will come with several new features: Timeline, Pick Up Where You Left Off, Clipboard, OneDrive Files On-Demand, and Story Remix app among others. Timeline is a new feature that improves the Task View area to provide a list of apps and workspaces that you were using previously or on other devices. Think of it like a time machine for resuming old sessions. Timeline also combines with a new Pick Up Where You Left Off feature to let you resume sessions and apps on multiple devices. A report adds: "With Files On-Demand, you can access all your files in the cloud without having to download them and use storage space on your device. You don't have to change the way you work, because all your files -- even online files -- can be seen in File Explorer and work just like every other file on your device," says Jeff Teper, corporate vice president, Office, OneDrive and SharePoint teams. [...] Windows 10 Fall Creators Update will continue the use of Project Neon, which now has an official name of "Microsoft Fluent Design System." It is important to note that this design focus is not a Windows 10 FCU feature, but something Microsoft intends to implement in apps across platforms and device types. End users should start to experience it more with FCU, however. [...] Windows 10 Fall Creators Update will come with a new app called "Windows Story Remix." This app is designed to help users transform their existing photos and videos. This tool can be used to create stories from content in a fun way.
Ubuntu

Ubuntu Arrives in the Windows Store, Suse and Fedora Are Coming To the Windows Subsystem For Linux (venturebeat.com) 212

At its Build developer conference today, Microsoft announced that Ubuntu has arrived in the Windows Store. From a report: The company also revealed that it is working with Fedora and Suse to bring their distributions to the Windows Subsystem for Linux (WSL) in Windows 10. At the conference last year, Microsoft announced plans to bring the Bash shell to Windows. The fruits of that labor was WSL, a compatibility layer for running Linux binary executables (in ELF format) natively on Windows, which arrived with the Windows 10 Anniversary Update released in August 2016. Microsoft also partnered with Canonical to allow Ubuntu tools and utilities to run natively on top of the WSL. By bringing Ubuntu to the Windows Store, the company is now making it even easier for developers to install the tools and run Windows and Linux apps side by side. Working with other Linux firms shows that Microsoft's deal with Canonical was not a one-time affair, but rather part of a long-term investment in the Linux world.
Security

Keylogger Found in Audio Driver of HP Laptops, Says Report (bleepingcomputer.com) 116

An anonymous reader writes: The audio driver installed on some HP laptops includes a feature that could best be described as a keylogger, which records all the user's keystrokes and saves the information to a local file, accessible to anyone or any third-party software or malware that knows where to look. Swiss cyber-security firm modzero discovered the keylogger on April 28 and made its findings public today. According to researchers, the keylogger feature was discovered in the Conexant HD Audio Driver Package version 1.0.0.46 and earlier. This is an audio driver that is preinstalled on HP laptops. One of the files of this audio driver is MicTray64.exe (C:\windows\system32\mictray64.exe). This file is registered to start via a Scheduled Task every time the user logs into his computer. According to modzero researchers, the file "monitors all keystrokes made by the user to capture and react to functions such as microphone mute/unmute keys/hotkeys."
Businesses

Amazon To Build Homeless Shelter In Its New Seattle Headquarters (cnn.com) 238

Amazon is trying to do its part to help the homelessness problem in its hometown of Seattle. The company announced on Wednesday that it would donate more than 47,000 square feet of space within its newest Seattle headquarters building as a permanent location to house homeless people. CNNMoney reports: "Mary's Place does incredible, life-saving work every day for women, children, and families experiencing homelessness in the Seattle community," Amazon CEO Jeff Bezos said in a statement. "We are lucky to count them as neighbors and thrilled to offer them a permanent home within our downtown Seattle headquarters." Amazon is partnering with local nonprofit Mary's Place to create 65 rooms, which will house more than 200 homeless people every night. The new Mary's Place shelter will open in early 2020. It will also have a resource center like those the nonprofit offers in North Seattle and White Center, where 40-plus local nonprofits and volunteers work with staff to help families obtain employment and permanent housing.
Botnet

New IoT Malware Targets 100,000 IP Cameras Via Known Flaw (csoonline.com) 60

Researcher Pierre Kim has found a new malware, called Persirai, that has been infecting over 100,000 Chinese-made, internet-connected cameras. According to Trend Micro, the malware has been active since last month and works by exploiting flaws in the cameras that Kim reported back in March. CSO Online reports: At least 1,250 camera models produced by a Chinese manufacturer possess the bugs, the researcher went on to claim. Over a month later in April, Trend Micro noticed a new malware that spreads by exploiting the same products via the recently disclosed flaws. The security firm estimates that about 120,000 cameras are vulnerable to the malware, based on Shodan, a search engine for internet-connected hardware. The Persirai malware is infecting the cameras to form a botnet, or an army of enslaved computers. These botnets can launch DDoS attacks, which can overwhelm websites with internet traffic, forcing them offline. Once Persirai infects, it'll also block anyone else from exploiting the same vulnerabilities on the device. Security firm Qihoo 360 has also noticed the malware and estimated finding 43,621 devices in China infected with it. Interestingly, Persirai borrows some computer code from a notorious malware known as Mirai, which has also been infecting IoT devices, such as DVRs, internet routers, and CCTV cameras, but by guessing the passwords protecting them.
ISS

Buzz Aldrin To NASA: Retire the International Space Station ASAP To Reach Mars (space.com) 349

An anonymous reader quotes a report from Space.com: If NASA and its partner agencies are serious about putting boots on Mars in the near future, they should pull the plug on the International Space Station (ISS) at the earliest opportunity, Buzz Aldrin said. "We must retire the ISS as soon as possible," the former Apollo 11 moonwalker said Tuesday (May 9) during a presentation at the 2017 Humans to Mars conference in Washington, D.C. "We simply cannot afford $3.5 billion a year of that cost." Instead, Aldrin said, NASA should continue to hand over activities in low Earth orbit (LEO) to private industry partners. Indeed, the space agency has been encouraging that move by awarding contracts to companies such as SpaceX, Orbital ATK and Boeing to ferry cargo and crew to and from the ISS. Bigelow Aerospace, Axiom Space or other companies should build and operate LEO space stations that are independent of the ISS, he added. Ideally, the first of these commercial outposts would share key orbital parameters with the station that China plans to have up and running by the early 2020s, to encourage cooperation with the Chinese, Aldrin said. Establishing private outposts in LEO is just the first step in Aldrin's plan for Mars colonization, which depends heavily on "cyclers" -- spacecraft that move continuously between two cosmic destinations, efficiently delivering people and cargo back and forth.
Medicine

A Baffling Brain Defect Is Linked to Gut Bacteria, Scientists Say (sciencealert.com) 55

Gina Kolata from The New York Times writes about a baffling brain disorder that is linked to a particular type of bacteria living in the gut (Warning: source may be paywalled; alternate source) The new study, published on Wednesday in Nature, is among the first to suggest convincingly that these bacteria may initiate disease in seemingly unrelated organs, and in completely unexpected ways. The researchers studied hereditary cerebral cavernous malformations -- blood-filled bubbles that protrude from veins in the brain and can leak blood or burst at any time. When Dr. Mark Kahn, professor of cardiovascular medicine at the University of Pennsylvania's Perelman School of Medicine, began this work, the microbiome was the last thing on his mind. Dr. Kahn and his colleagues studied cerebral cavernous malformations as part of a larger effort to understand the development and function of blood vessels. Three genes have been linked to the disorder, and Dr. Kahn and his colleagues tried to figure out what these mutations really do. The scientists were able to mimic the condition in mice by deleting a gene that is mutated in many patients. A year ago, the scientists moved to a new building, and something unexpected happened. The experimental mice stopped developing the brain malformations. Dr. Kahn's student, Alan T. Tang, had been deleting the gene by injecting a drug into the abdomens of the mice. Sometimes a mouse would get an infection that would lead to an abscess, and bacteria leaked from the gut into the blood. In the new building, only those mice still developed the brain defect. The other gene-deleted mice did not. He and his colleagues finally identified the culprit: Gram-negative bacteria, named for the way they stain, that carry a molecule in their cell walls, a lipopolysaccharide. Without a functioning gene, the lipopolysaccharide can signal veins in the brain to form blood bubbles.
United Kingdom

Call Center Operator and His Cousin Steal $645,000 From UK Water Supplier (bleepingcomputer.com) 97

An anonymous reader writes: "An unnamed UK-based regional water supply company lost over $645,000 in a sophisticated scam that involved social engineering, an inside man, and international bank transfers," reports BleepingComputer. According to a recently disclosed report, one of the water supplier's call center operators was taking screenshots of customer details and sending this data to his cousin in the UK. This person would trick other call center operators to reset the passwords for those accounts, add his bank account info to the account, and request a refund for previous transactions. Their operation was discovered after customers, usually small-to-medium businesses, discovered they couldn't access their accounts anymore, and also reported new bank account details. A search of the CRM logs revealed that only one call center operator had accessed those profiles, albeit he never initiated or approved refunds. When questioned, the arrogant employee signed an affidavit allowing investigators to search his home PC, thinking they would never discover anything, since he already wiped his hard drive. They did because he forgot to delete his shadow volume copies, where investigators discovered copies of emails sent to his cousin in the UK. These emails contained the screenshots of his work PC with SMB client data. In the end, the call center employee ended up helping authorities secure a conviction for his cousin.

Slashdot Top Deals