Advertising

A Huge Trove of Patient Data Leaks, Thanks To Telemarketers' Bad Security (zdnet.com) 44

"A trove of records containing personal and health information on close to a million people was exposed after a former developer working at a telemarketing company uploaded a backup of its database to the internet," writes ZDNet. An anonymous reader quotes their report: The data contained personal and health-related information, such as names, addresses, dates of birth, phone numbers, email addresses, Social Security numbers, health insurance information, and other data relating to the types of health problems the individuals have regarding the products they need, though many of the records were truncated or incomplete. An examination showed that the database was used to market products to thousands of customers by telemarketers at HealthNow -- no longer a registered business as of 2015. Several records we've seen included customized notes written by staff who were tasked with calling customers, such as when they are home and any other relevant information on the subject.
The database apparently lingered online for years in an AWS instance until it was discovered two weeks ago in search results from Shodan by a Twitter user calling himself Flash Gordon. Databreaches.net, which investigated the breach with ZDNet, believes this as a teachable moment. "Before you give your personal or health insurance information to telemarketers or firms that call to offer you supplies for diabetes or back pain or other conditions, think twice."
Security

McAfee: Big Spike In Mac OS Malware In 2016, Mostly From Adware Bundling (fortune.com) 64

An anonymous reader quotes Fortune: Security firm McAfee released a report this week that showed a big jump in 2016 regarding malware hitting the Mac operating system. The McAfee report said there were 460,000 malware instances affecting the Mac OS in the fourth quarter of 2016, an over 700% jump from the previous year during the same quarter.

McAfee's new report confirms similar research by other cybersecurity firms in recent years that show an increased prevalence of malware affecting Apple computers. Essentially, as more people buy Apple computers, there are more possibilities for malware to infect the machines. But while an over 700% surge in malware may sound frightening, it should be noted that "the big increase in Mac OS malware was due to adware bundling," the report's authors wrote.

Transportation

Electric Vertical Take-Off Aircraft Successfully Tested By DARPA (newatlas.com) 86

Slashdot reader drunkdrone tipped us off to some big aviation news: After several years of development DARPA has successfully completed flight-testing of one of the most novel, and odd-looking, aircraft designs we've seen in some time -- the sub-scale electric X-Plane. After calling for an innovative new approach to an aircraft with vertical takeoff and landing capabilities, DARPA awarded its Phase 2 contract to Aurora Flight Sciences in early 2016. Aurora's design includes 24 electric ducted fans, 18 on the main wings and six on the smaller front canards. Both the main wings and the canards are designed to tilt upwards for vertical takeoff before rotating to the horizontal for regular flight... The prototype was also used to trial a number of other technologies DARPA has been developing, such as 3D-printed plastics for flight structures and aerodynamic surfaces.
The article includes video of the test flight, and reportedly the aircraft also successfully tested "sustained hovering." DARPA will now begin officially developing a full-scale aircraft, which has been designated "the XV-24A."
Networking

Tunnelled IPv6 Attacks Bypass Network Intrusion Detection Systems (itnews.com.au) 113

"The transition to internet protocol version 6 has opened up a whole new range of threat vectors that allow attackers to set up undetectable communications channels across networks, researchers have found." Slashdot reader Bismillah summarizes a report from IT News. Researchers at NATO's Cooperative Cyber Defence Centre of Excellence and Estonia's University of Tallinn have worked out how to set up communications channels using IPv6 transition mechanisms, to exfiltrate data and for systems control over IPv4-only and dual-stack networks -- without being spotted by network intrusion detection systems.
The article argues that "Since IPv6 implementations and security solutions are relatively new and untested, and systems engineers aren't fully aware of them, the new protocol can become a network backdoor attackers can exploit undetected." The researchers' paper is titled "Hedgehog In The Fog."
Programming

Eric S. Raymond Unveils New List Of 'Hacker Archetypes' (ibiblio.org) 116

An anonymous reader writes: Open source guru Eric S. Raymond has announced public brainstorming on a "gallery of hacker archetypes to help motivate newbies" by defining several different psychologies commonly found among programmers. He's unveiled an initial list developed with a friend, along with some interesting commentary. (Algorithmicists often have poor social skills and "a tendency to fail by excessive cleverness. Never let them manage anyone!")

Raymond cautions that "No hacker is only one of these" -- though apparently most of the hackers he knows appear to be two of them, "an indication that we are, even if imperfectly, zeroing in on real traits." But the blog post ends by asking "What archetypes, if any, are we missing?"

It'll be interesting to see if Slashdot readers if they recognize themselves in any of the archetypes. But the blog post also answers the inevitable question. What archetype is Eric S. Raymond?

"Mostly Architect with a side of Algorithmicist and a touch of Jack-of-All-Trades."
The Internet

Server Snafu Exposes Ask.com User Search Queries Via Internal Status Page (bleepingcomputer.com) 10

"The Ask.com search engine went through some sort of technical issue late Friday night, as its servers were exposing the internal Apache server status page, revealing recently processed search queries," reports BleepingComputer. An anonymous reader writes: The issue is now fixed, but a copy of the server status page with some search queries can still be viewed in Google's search engine cache. "Some of the weirdest search queries were collected by users in a Hacker News thread," reports BleepingComputer, adding "As you'd expect, the server page included plenty of searches for porn."

The issue also affected localized Ask.com servers, such as uk.ask.com/server-status, us.ask.com/server-status, and de.ask.com/server-status, but no user data was exposed, as the search queries passed through load balancers and already hid user IPs.

United States

US Hacker Sets Off 156 Sirens At Midnight (dallasnews.com) 230

"I had the displeasure of being awoken at midnight to the sounds of civil-defense/air-raid sirens," writes very-long-time Slashdot reader SigIO, blaming "some schmuck with a twisted sense of humor." The Dallas News reports: Rocky Vaz, director of Dallas' Office of Emergency Management, said that all 156 of the city's sirens were activated more than a dozen times... Dallas officials blame computer hacking for setting off emergency sirens throughout the city early Saturday... It took until about 1:20 a.m. to silence them for good because the emergency system had to be deactivated. The system remained shut down Saturday while crews safeguarded it from another hack.

The city has figured out how the emergency system was compromised and is working to prevent it from happening again, he said... The city said the system should be restored Sunday or Monday.

City officials reported 4,400 calls to their 9-1-1 emergency phone number in the first four hours of Saturday morning, with over 800 occurring in that first 15 minutes when all 156 sirens started going off simultaneously.
The Internet

Die-Hard Sysops Are Resurrecting BBS's From The 1980s (arstechnica.com) 245

Ars Technica reports on vintage computing hobbyists "resurrecting digital communities that were once thought lost to time...some still running on original 8-bit hardware." Sometimes using modern technology like Raspberry Pi and TCPser (which emulates a Hayes modem for Telnet connections), they're reviving decades-old dial-up bulletin board systems (or BBSes) as portals "to places that have been long forgotten." An anonymous reader writes: One runs the original software on a decades-old Commodore 128DCR. Another routes telnet connections across a real telephone circuit that connects to a Hayes modem. And after 23 years, the Dura-Europos BBS is back in business, using an Apple IIe running its original GBBS Pro software -- augmented with a modern CFFA3000 compact flash drive, and a Raspberry Pi running TCPser. [It's at dura-bbs.net, using port 6359.] Ars Technica blames "the meteoric rise of the World Wide Web and the demise of protocols that came before it" for the death of BBSes. "Owners of older 8-bit machines had little reason to maintain their hardware as their userbase migrated to the open pastures of the Web, and the number of bulletin board systems plummeted accordingly...

"Despite the threat of extinction, however, it turns out that some sysops never quite gave up on the BBS," and for many modern-day users, "it's simply a matter of 'dialing' the BBS using a domain name and port number instead of a phone number in their preferred terminal software." There they'll find primitive BBS games like STARTREK, Chess, and Blackjack, but also "old conversation threads dating back decades were available verbatim... It's like a buried digital time capsule."

One user says visiting a web site today "has a very public feel to it, whereas a BBS feels very much like being invited into someone's living room." The article also remembers "the dulcet tones of a 1200 baud connection (or 2400, if you were very lucky)," adding that "to see what was accomplished with so little was simply humbling."
Businesses

Staples Tries Co-Working Spaces To Court Millennials And Entrepreneurs (pilotonline.com) 177

Are there any Slashdot readers who are doing their work in co-working spaces? An anonymous reader writes: Staples office-supply stores is aggressively repositioning its brand to entice new customers like tech entrepreneurs and small businesses, reports The New York Times. "A case in point: Staples' partnership with Workbar, a Boston-based co-working company founded in 2009... Workbar attracts the coveted millennial generation, as well as entrepreneurs, a potential pipeline for new small business customers." Three co-working spaces have now been added to Staples stores, including their original flagship store in Boston, and the Times spotted funky art, skylights, an artificial putting green, as well as gourmet coffee "and -- on some nights -- happy hours with beer and wine."

"This blend of old and new shows how Staples Inc. is digging up its roots as one of the first, and most successful, big-box retailers. Under Shira Goodman, the company's new chief executive officer, Staples hopes it can reverse its years of declining sales, unlike so many other retailers left for dead in the internet age."

The company also reports online orders already make up 60% of their sales, which they hope to push to 80% by 2020, according to the Motley Fool. "Selling products, 50% of which are outside of traditional office supply categories, to businesses large and small has proven to be a resilient business for Staples."
Transportation

Hyperloop One Announces 11 Possible US Routes, Completes Vegas Test Track (theverge.com) 270

An anonymous reader writes: Thursday Hyperloop One executives announced that they've finished constructing their 1,640-foot-long "DevLoop" test track in the desert outside Las Vegas. But they also revealed possible U.S. routes for their high-speed transportation solution "to initiate a nationwide conversation about the future of American transportation" -- five of them suggested by state transportation department officials from Texas, Florida, Colorado, Nevada and Missouri.

Last May the company invited pitches for routes to various cities, and Thursday's 11 pitches were chosen from 2,600 participants. These 11 pitches will compete with 24 other pitches from around the globe to be one of the three chosen to "work closely with Hyperloop One engineering and business development teams to explore project development and financing." And Thursday they also announced that "by year's end the company will have a team of 500 engineers, fabricators, scientists and other employees dedicated to bringing the technology to life."

Click through for more information, and the list of the 11 U.S. cities being suggested for hyperloop destinations.
Java

Ask Slashdot: Should I Move From Java To Scala? 245

"Scala is one of the JVM languages that manages to maintain a hip and professional vibe at the same time," writes long-time Slashdot reader Qbertino -- building up to a big question: One reason for this probably being that Scala was built by people who knew what they were doing. It has been around for a few years now in a mature form and I got curious about it a few years back. My question to the Slashdot community: Is getting into Scala worthwhile from a practical/industry standpoint or is it better to just stick with Java? Have you done larger, continuous multi-year, multi-man and mission-critical applications in Scala and what are your experiences?
The original submission asks two related questions. First, "Do you have to be a CS/math genius to make sense of Scala and use it correctly?" But more importantly, "Is Scala there to stay wherever it is deployed and used in real-world scenarios, or are there pitfalls and cracks showing up that would deter you from using Scala once again?" So share your experiences and answers in the comments. Would you recommend moving from Java to Scala?
Privacy

Hacker Group Leaks 'NSA's Top Secret Arsenal of Digital Weapons' (vice.com) 69

Hacker group 'The Shadow Brokers', which last year allegedly released top-secret tools that the National Security Agency had used to break into the networks of foreign governments and other espionage targets, today said it is disappointed with President Donald Trump, and released more such alleged tools. From a report on Motherboard: On Saturday, The Shadow Brokers, a hacker or group of hackers that has previously dumped NSA hacking tools, released more alleged exploits. The group published a password for an encrypted cache of files they distributed last year. "Be considering this our form of protest," the group wrote in a rambling, politically loaded rant published on Medium. Back in August, The Shadow Brokers released a number of exploits stolen from the NSA. Many of these affected hardware firewalls, from companies such as Cisco and Juniper. At the time, the group also dumped another cache allegedly containing more hacking tools, and said they would release the corresponding password to the winner of a bitcoin auction. That fund-raising effort was ultimately unsuccessful, and The Shadow Brokers claimed they were calling the whole thing off in January. But now, anyone can unlock the auction data dump. (Motherboard confirmed that the password did indeed decrypt the original auction file). In a series of tweets, Edward Snowden said, "NSA just lost control of its Top Secret arsenal of digital weapons; hackers leaked it. 1) https://github.com/x0rz/EQGRP 2) For those who have never heard of the hacker group behind today's leak of NSA's cyberweapons, last year's story."

He adds, "quick review of the ShadowBrokers leak of Top Secret NSA tools reveals it's nowhere near the full library, but there's still so much here that NSA should be able to instantly identify where this set came from and how they lost it. If they can't, it's a scandal."
Bug

IRS Warns Tax Info Leaked By US Financial Aid Site (cnn.com) 21

"Hackers accessed the data of up to 100,000 people through a tool that helps students get financial aid," writes CNN. An anonymous reader quotes their report: IRS Commissioner John Koskinen testified before the Senate Finance Committee Thursday that a breach had been discovered in the fall. In September, he said, his agency discovered that fraudsters could use someone's personal data to fill out a financial aid application, and the "Data Retrieval Tool" would populate the application with tax information. That information could be used to file false tax returns. The commissioner said fewer than 8,000 of these returns were processed, and refunds were issued totaling $30 million...

In October, the IRS told the Department of Education that the system could be abused by criminals, but because up to 15 million people use the system for convenience, they kept it available. However, in February, the agency witnessed a pattern of fraudulent activity, and it shut down the automated tool in March.

Now financial aid seekers will have to manually enter their parents' reported income from previous tax years -- at least until a new version of the tool comes online next October. In the meantime, the IRS is alerting 100,000 users who started an application but didn't finish it, warning them that their tax information may have been compromised.
Google

Google Announces Android Cross-Licensing Program 'PAX' -- But Why? (consortiuminfo.org) 33

"Linux and open-source software have had to contend with intellectual property legal challenges for years," writes ZDNet. "Now, Google has started a new effort to bring peace to potential Android IP sore points: PAX... a royalty-free, community-patent cross-license." PAX is starting with nine members: Google, Samsung Electronics, LG Electronics, HTC, Foxconn Technology Group, Coolpad, BQ, HMD Global, and Allview. These companies own more than 230,000 global patents. PAX's purpose is to create a "community-driven [patent] clearinghouse, developed together with our Android partners, [that] ensures that innovation and consumer choice -- not patent threats -- will continue to be key drivers of our Android ecosystem. PAX is free to join and open to anyone."
Slashdot reader Andy Updegroved writes: The question is why? The announcement and the related website are extremely brief, and although everyone is invited to get a copy of the cross license, Google reserves the right to decide first whether your motives are pure and you can keep a secret. And so far, the only members of the "PAX Community" listed are existing Google business partners. Is Google aware of some new patent tempest brewing just over the horizon, about to burst into public view? And will any other company names and logos be added to the PAX Community Web page? We'll just have to stay tuned to find out.
Andy Updegrove tells ZDNet it does involve "formal cross-licenses between participants, and therefore enforceable rights, but not an infrastructure to do more (at least insofar as one can tell from the initial announcement)."
IBM

After 25 Years, 'Lost' OS/2 2.0 Build 6.605 Finally Re-Discovered (os2museum.com) 93

"In a fascinating example of poor timing, disk images of OS/2 2.0 pre-release level 6.605 from July/September 1991 were missing for over 25 years, only to show up literally one day after after the 25th anniversary of the OS/2 2.0 release," writes the site OS/2 Museum. An anonymous reader writes: It's the last OS/2 2.0 pre-release which didn't use the Workplace Shell (WPS), but "instead utilized the same old Desktop Manager as OS/2 1.2/1.3, which makes it the closest surviving relative of the Microsoft OS/2 2.0 SDK." Featuring a 16-bit/32-bit hybrid kernel and a "DOS Window" icon (as well as a few games like Reversi and Klondike Solitaire), "the look and feel was not quite the same as OS/2 1.3 and in fact was a cross between OS/2 1.3 and Windows 3.1."
The elusive 6.605 pre-release fell between 6.149 and 6.167 -- and "It is not known what possessed IBM to assign it a completely out-of-sequence number."

Slashdot Top Deals