Catch up on stories from the past week (and beyond) at the Slashdot story archive

 



Forgot your password?
typodupeerror

Submission + - Inside the Tech Support Scam Ecosystem

Trailrunner7 writes: A team of three doctoral students, looking for insights into the inner workings of tech support scams, spent eight months collecting data on and studying the tactics and infrastructure of the scammers, using a purpose-built tool. What they uncovered is a complex, technically sophisticated ecosystem supported by malvertising and victimizing people around the world.

The study is the first analysis of its kind on tech support scams, and it’s the work of three PhD candidates at Stony Brook University. The team built a custom tool called RoboVic that performed a “systematic analysis of technical support scam pages: identified their techniques, abused infrastructure, and campaigns”. The tool includes a man-in-the-middle proxy that catalogs requests and responses and also will click on pop-up ads, which are key to many tech-support scams.

In their study, the researchers found that the source for many of these scams were “malvertisements”, advertisements on legitimate websites, particularly using ad-based URL shorteners, that advertised for malicious scams. This gives the scammers an opportunity to strike on what would seem like a relatively safe page. Although victims of these scams can be anywhere, the researchers found that 85.4 percentof the IP addresses in these scams were located across different regions of India, with 9.7 percentlocated in the United States and 4.9 percent in Costa Rica. Scammers typically asked users for an average of $291, with prices ranging from $70 to $1,000.

Submission + - FDA slams St. Jude Medical for ignoring security flaws in medical devices (securityledger.com)

chicksdaddy writes: The U.S. Food and Drug Administration issued a letter of warning to medical device maker Abbott on Wednesday, slamming the company for what it said was a pattern of overlooking security and reliability problems in its implantable medical devices at its St. Jude Medical division and describing a range of the company’s devices as “adulterated,” in violation of the US Federal Food, Drug and Cosmetic Act, the Security Ledger reports. (https://securityledger.com/2017/04/fda-st-judes-knew-about-device-flaws-2-years-before-muddy-waters-report/)

In a damning warning letter (https://www.fda.gov/ICECI/EnforcementActions/WarningLetters/2017/ucm552687.htm), the FDA said that St. Jude Medical knew about serious security flaws in its implantable medical devices as early as 2014, but failed to address them with software updates or by replacing those devices. The government found that St. Jude, time and again, failed to adhere to internal security and product quality guidelines, a lapse that resulted in at least one patient death.

St. Jude Medical, which is now wholly owned by the firm Abbott, learned of serious and exploitable security holes in the company’s “high voltage and peripheral devices” in an April, 2014 “third party assessment” commissioned by the company. But St. Jude “failed to accurately incorporate the findings of that assessment” in subsequent risk assessments for the affected products, including Merlin@home, a home-based wireless transmitter that is used to provide remote care for patients with implanted cardiac devices, the FDA revealed. Among the security flaws: a “hardcoded universal unlock code” for the company’s implantable, high voltage devices.

The report casts doubt on a defamation lawsuit St. Jude filed against the firm MedSec Holdings Ltd over its August, 2016 report that warned of widespread security flaws in St. Jude products, including Merlin@home. The MedSec report on St. Judes technology was released in conjunction with a report by the investment firm Muddy Waters Research, which specializes in taking “short” positions on firms. (https://securityledger.com/2016/08/the-big-short-alleged-security-flaws-fuel-bet-against-st-jude-medical/) At the time, MedSec said that the security of the company’s medical devices and support software was “grossly inadequate compared with other leading manufacturers,” and represents “unnecessary health risks and should receive serious notice among hospitals, regulators, physicians and cardiac patients.” St. Judes has called the MedSec allegations false, but it now appears that the company had heard similar warnings raised by its own third-party security auditor more than a year prior.

Comment Would you like some toast? (Score 1) 49

"Would you like some toast? Some nice hot crisp brown buttered toast. No? How about a muffin then? Nothing? You know the last time you had toast. 18 days ago, 11.36, Tuesday 3rd, two rounds. I mean, what's the point in buying a toaster with artificial intelligence if you don't like toast. I mean, this is my job. This is cruel, just cruel." I was surprised when I heard that they pushed an advertisement out, and shocked when they tried to defend it. Now they're saying it's not an ad because they didn't get money (note the weaseling) for it? That's Don Draper-esque level hubris.

Comment Copyright terms are immoral (Score 4, Interesting) 148

I'll have some respect for copyright when the terms aren't life of the author plus 75 years. That's ridiculous. If someone makes a work today, I'll have been dead 50 odd years before it's in the public domain - assuming, a big assumption, that the shill maximalists don't get the terms extended even more towards perpetuity.

Current terms are also theft: they are the theft of things that could have been. If terms were 20 years then at that mark new works could be created by anyone who would wish and their work would then get 20 years. You want to see an explosion of culture? Look at that right there. Creative works that take ideas in ways the original author couldn't conceive of or didn't think was worth the money. 20 year term: and I will never infringe again, unjust terms bring all of copyright into contempt.

For a free (pdf download) of a book which explains the issue in detail, see: The Public Domain.

Comment 26 BILLION Dollars! (Score 1) 27

I still can't believe they spent 26 BILLION dollars on Linkedin. Like seriously, whatever they're smoking I want some too. That amount of money is so astronomical that even if they blew the budget by 10 times they could have seriously built their own Linkedin 5 times over. Whoever approved that dollar figure is fucking insane, stupid, trying to sink the company, or all of the above.

Comment Post-Scarcity Star Trek Economy (Score 5, Interesting) 260

Currency is an abstraction of labor, we use it to manage the effort put into things during trade - it's a lot more convenient than carrying around four cows and a goat. So, robots come along and take all the jobs? Well, no more scarcity of labor. And the systems of currency and capitalism we have grown so far get upended. They won't go out the window but they will see massive restructurings. If labor is not scarce, want a house? Go pick one down the street where the machines built fifty of them. Free. Because there was no scarce labor involved. Capitalism? Well, in a post scarcity economy the invisible hand that makes it go remains to be seen how that adapts. In the short term however, say ten to thirty years, a transition system where perhaps everyone gets a guaranteed minimum income until our society fully adapts to machines could help to minimize social upheaval over the machines taking all the jobs.

Comment Oracle wants us to have crappy computers. (Score 4, Interesting) 357

This is plain double-speak. If Oracle had their way they'd kill GPL software. Innovation revolves around an application programming interface. The API is the "shape" of the program. The code inside the shape is the implementation. The GPL revolves around the implementation and has nothing to say about the shape. If shapes were always copyrightable then that would absolutely kill innovation. All of a sudden if you used someone else's shape in a way they didn't like they could totally shut you down with just the threat of a lawsuit - not everyone has deep pockets to fight that. Copyrighted API's would become just another kind of currency much in the way software patents already are. If you can't beat them with money then beat them, forced licensing, with other kinds of currency. In the Oracle world we wouldn't even enjoy the powerful computers we have today. Decades ago Phoenix clean-room reverse-engineered IBM's BIOS and made the same shape with a different implementation. If that shape had never been open we would have never experienced the rapid advancement of a bazaar that component manufacturers can revolve around. We would have been stuck with IBM's will and computing would have stagnated because they would not necessarily have had an interest in advancing it as much as competition does. At the time IBM's BIOS was reverse-engineered they weren't even the best computers. There were others that were much better like the Commodore Amiga, however, when the ecosystem around an open BIOS happened then the feedback effects from that made it win. Without a doubt.

Comment Re:Stop using Java (Score 1) 243

How about Django, PHP, Ruby, Python, Wordpress, ASP, etc? Oracle has now demonstrated that Java is a toxic brand: they will try to extract money out of you by force if you use it. For existing projects you may have little choice to stick with Java for the time being. For new projects however you'd be a fool to trust the devil.

Comment Re:Stop using Java (Score 4, Insightful) 243

So, you're saying: "keep taking it up the ass because I can't imagine changing my tool chain?"

There are plenty of alternatives to Java, .Net is a valid one despite your claim, and others like Python or C/C++ are equally valid. The trick with C/C++ is to use an abstraction layer between your code and the operating system. Like GUI toolkits and such. Let the GUI toolkit implement the different back-ends, your code calls it the same on all platforms.

Comment Re:Substrate does not need to be what we're made o (Score 1) 73

Another illustration from fiction is Dragon's Egg.

Really though, what matters for "life" is that whatever the substrate is is able to store information - DNA in our case - and have an ecosystem of related ways to raise and lower energy states in appropriate materials. If both those conditions are met then the process a specific set of material changes with can be called "alive."

Slashdot Top Deals

"It's what you learn after you know it all that counts." -- John Wooden

Working...