Shared posts

08 Nov 16:07

No Implants Needed For Precise Control Deep Into the Brain

by BeauHD
An anonymous reader quotes a report from IEEE Spectrum: In April, Guoping Feng and colleagues at MIT, along with [Karl Deisseroth, a neuroscientist and bioengineer at Stanford University] demonstrated a minimally invasive optogenetic system that required drilling a small hole in the skull, then being able to control opsin-expressing neurons six millimeters deep into the brain using blue light. This approach used of a type of opsin that slowly activates neurons in a step-wise manner. In the most recent study [published in the journal Nature Biotechnology], Deisseroth and colleagues sought to instead enable both deep and fast optogenetics without surgery. The Stanford team expressed in the brain cells of mice a powerful new opsin called ChRmine (pronounced like the deep-red color "carmine"), discovered by Deisseroth's group last year in a marine organism. Then, they shined a red light outside the skull and were able to activate neural circuits in the midbrain and brainstem at depths of up to 7 millimeters. With the technique, the scientists turned on and off brain circuits with millisecond precision. "It really worked well, far better than we even expected might be possible," says Deisseroth. The team then tested the effectiveness of the system. In one instance, they used light to quickly and precisely stop seizures in epileptic mice, and in another to turn on serotonin-producing neurons to promote social behavior in mice. Most optogenetic techniques involve injecting viruses with an opsin gene of choice directly into the brain with a needle. To avoid this, the Stanford team used a type of PHP virus developed at CalTech that can be injected in the blood. The virus then crosses the blood-brain barrier to deliver its payload, an opsin gene, to brain cells. In this case, even the delivery of the gene is noninvasive -- no needle penetrates the brain. Deisseroth's team is now testing the non-invasive technique in fish and collaborating with others to apply it to non-human primates. They're also working with the Seattle-based Allen Institute to develop mouse lines bred with ChRmine in their cells.

Read more of this story at Slashdot.

03 Nov 09:08

Hangover alpha 2 lets Windows x86/x64 programs run on ARM64, POWER 64-bit

by Thom Holwerda

The Wine program for running Windows games/applications on Linux and other platforms can run on a number of different architectures, but Wine doesn’t handle the emulation of running Windows x86/x64 binaries on other architectures like 64-bit ARM or PowerPC. But that’s what the Wine-based Hangover is about with currently allowing those conventional Windows binaries to run on AArch64 (ARM64) and 64-bit POWER too.

Hangover started out with a focus on Windows x64 binaries on ARM64 in looking at the possible use-case of running Windows software on ARM mobile devices and more. This year with the help of Raptor Computing Systems there has been Hangover support added for IBM POWER 64-bit.

It would be really amazing if Linux on POWER could make use of WINE like regular x86 Linux users can. It’s a long way off, still, but progress is being made.

04 Oct 09:03

Cloudflare's Privacy Crusade Continues With a Challenge To Google Analytics

by BeauHD
An anonymous reader quotes a report from Fortune: Cloudflare is launching a privacy-friendly rival to Google Analytics. Google Analytics is a free toolkit that's used by website administrators across the globe to help them track the behavior of the people visiting those sites -- how they find them, what they do there, the devices they're using, and so on. However, the service -- the most popular of its kind -- also helps Google track websites' visitors, so it can better profile them for advertising purposes. This privacy-invasive aspect makes many people squeamish. And that's where Cloudflare would now like to step in. Around its birthday every year, the decade-old company -- which went public last year -- announces a move intended to "give back" to the wider Internet community. These moves are often related to privacy. On Tuesday, it unveiled Cloudflare Web Analytics, a free-to-use toolkit that largely replicates what Google Analytics offers -- minus the invasive tracking, and thus the ability to assess the performance of targeted ads carried on websites. Cloudflare Web Analytics is immediately available to the company's paid customers, but any website owner will be able to use it from some point in the coming months. Cloudflare's scale is crucial here [...] because it takes substantial resources to run a free analytics platform, and Cloudflare already has a giant network that can support the load. Cloudflare Web Analytics isn't the company's only big announcement this week. "On Monday, Cloudflare launched a beta testing program for a cloud technology called Durable Objects," the report adds. "You can read the technical explanation here, but in essence this is a tool that allows developers of online services to make those services comply with the increasing number of data-localization and data-protection laws that limit where users' data is supposed to go." "With Durable Objects, Cloudflare says, it is possible to specify where particular data will reside on Cloudflare's network, so -- for example -- a German user's data does not have to leave Germany. Or, with an eye to other current news, a service such as TikTok could ensure that U.S. users' data never leaves the U.S., without having to create a separate version of its service for that country."

Read more of this story at Slashdot.

26 Sep 14:46

The Best Chrome Extensions To Prevent Creepy Web Tracking

by BeauHD
Wired has highlighted several browser extensions that "are a simple first step in improving your online privacy." Other steps to take include adding a privacy-first browser and VPN to further mask your web activity. An anonymous reader shares the report: Privacy Badger is one of the best options for blocking online tracking in your current browser. For a start, it's created by the Electronic Frontier Foundation, a US-based non-profit digital rights group that's been fighting online privacy battles since 1990. It's also free. Privacy Badger tracks all the elements of web pages you visit -- including plugins and ads placed by external companies. If it sees these appearing across multiple sites you visit then the extension tells your browser not to load any more of that content. DuckDuckGo is best-known for its anonymous search engine that doesn't collect people's data. DuckDuckGo also makes an extension for Chrome. The Privacy Essentials extension blocks hidden third-party trackers, showing you which advertising networks are following you around the web over time. The tool also highlights how websites collect data through a partnership with Terms of Service Didn't Read and includes scores for sites' privacy policies. It also adds its non-tracking search to Chrome. The Ghostery browser extension blocks trackers and shows lists of which ones are blocked for each site (including those that are slow to load), allows trusted and restricted sites to be set up and also lets people you block ads. The main Ghostery extension is free but there's also a paid for $49 per month subscription that provides detailed breakdowns of all trackers and can be used for analysis or research. There are Ghostery extensions for Chrome, Firefox, Microsoft Edge and Opera. Unlike other tools here, Adblock Plus is primarily marketed as an ad blocking tool -- the others don't necessarily block ads by default but aim to be privacy tools that may limit the most intrusive types of ads. Using an ad blocker comes with a different set of ethical considerations to tools that are designed to stop overly intrusive web tracking; ad blockers will block a much wider set of items on a webpage and this can include ads that don't follow people around the web. Adblock Plus is signed up to the Acceptable Ads project that shows non-intrusive ads by default (although this can be turned off). On a privacy front Adblock Plus's free extensions block third party trackers and allow for social media sharing buttons that send information back to their owners to be disabled.

Read more of this story at Slashdot.

24 Sep 17:22

What No Man Has Seen Before: Remastering Deep Space Nine To Maximum Quality

by BeauHD
Dputiger writes: After nine months of work, I've published workflows, example videos, and screenshots showing how to restore Star Trek: Deep Space Nine from the rather potato quality of its DVDs to something you could plausibly call HD equivalent. These are the results. "With careful processing and good upscaling, it's possible to give Deep Space Nine a clarity that I think approaches that of what's typically referred to as 'HD' content, though it's still limited to the NTSC color gamut as opposed to later standards like Rec. 709," writes Joel Hruska via ExtremeTech. "At its worst -- allowing for some deviations from perfection -- it'll still look like the best damn DVD you've ever seen. At its best -- and I consider the shot of Sisko up there to be one of the best -- I'd argue that he, at least, comes across in HD levels of detail." The article "is not a step-by-step tutorial on how to perform this process," Hruska writes, adding, "that will be its own project." There will, however, be enough information that anyone with a passing knowledge of AviSynth "should be able to recreate both approaches."

Read more of this story at Slashdot.

23 Sep 17:24

The Fairphone 3+ Is a Repairable Dream That Takes Beautiful Photos

by BeauHD
The Fairphone 3+ is a $550 phone with modular parts that can easily be swapped out by users themselves. "In many ways, a Fairphone is the antithesis of the iPhone," writes Catie Keck via Gizmodo. "It doesn't benefit most retailers to allow you to easily repair your own stuff, meaning that a lot of gizmos these days -- particularly higher-end electronics -- are packed with proprietary parts and sometimes even software locks to dissuade consumers from attempting to perform repairs themselves." While it is a "repairable dream" and features two big camera upgrades over the Fairphone 3 (which does support the new upgraded camera modules), it's, sadly, only available overseas. Keck writes: Fairphone 3+ has 64GB of memory but can be upgraded to 400GB with a MicroSD card. It has a Qualcomm 632 processor, a 5.65-inch display, Bluetooth 5, a 3000mAh battery that supports Qualcomm QuickCharge, and six total modules to swap out for easy repair. A thing I didn't expect to love as much as I did was fingerprint ID on the backside of the phone -- particularly as Face ID on my iPhone 11 has become a massive pain in the butt in these mask-on times. At present, Fairphone doesn't support 4G connectivity in the U.S., my biggest gripe with the phone second only to the fact that the phones only ship within Europe. [...] Fairphone runs on Android -- the Fairphone 3+ comes with Android 10 pre-installed and ready to go. As for its camera, I was happy enough with the photograph with the newer lens. Photo nerds may be more sensitive to the trade-offs when compared with, say, the iPhone 11 Pro, but for the average person, I think Fairphone's cameras would work beautifully. I especially loved the portrait mode on the front camera, which worked in even exceptionally low-light environments for me. Software likely isn't the primary reason that anyone is looking at getting a Fairphone device, but shipping pre-installed with a lot of familiar apps means making the switch will likely be relatively painless, though so far my iPhone is a bit snappier overall in terms of performance. Again, the tradeoff is a commitment to repairability that you simply won't get with an Apple device unless the company radically overhauls its entire business model or unless it's forced, neither of which seems remotely likely for the foreseeable future.

Read more of this story at Slashdot.

20 Sep 15:46

How to Play Chrome's Hidden 'Dinosaur Game' and Firefox's 'Unicorn Pong'

by EditorDavid
How-To Geek has discovered three of the world's most popular web browsers contain Easter Eggs: It seems like every browser has a hidden game these days. Chrome has a dinosaur game, Edge has surfing, and Firefox has . . . unicorn pong? Yep, you read that right — here's how to play it. First, open Firefox. Click the hamburger menu (the three horizontal lines) at the upper right, and then click "Customize." On the "Customize Firefox" tab, you'll see a list of interface elements to configure the toolbar. Click and drag all the toolbar items except "Flexible Space" into the "Overflow Menu" on the right. Click the Unicorn button that appears at the bottom of the window.... There's screenshots in the article illustrating all of the steps — and the result.

Read more of this story at Slashdot.

20 Sep 11:34

Microsoft Warns Workaround Preventing Lenovo ThinkPad BSOD Increases Risk

by EditorDavid
An anonymous reader quotes ZDNet: Microsoft has finally published a support document detailing its workaround for the August 2020 Patch Tuesday update for Windows 10 version 2004 that caused blue screens of deaths (BSODs) on newer Lenovo ThinkPads and broke Windows Hello biometric login... It's the same as Lenovo's earlier workaround but comes with a stern security warning from Microsoft. Microsoft also explains how Lenovo Vantage violates Microsoft's security controls in Windows. Users might bypass the BSOD screen, but they are endangering their computers by implementing the workaround, according to Microsoft. The workaround also affects some of Microsoft's latest security features for Windows 10, such as Hypervisor Code Integrity for shielding the OS from malicious drivers, as well as Windows Defender Credential Guard. "This workaround may make a computer or a network more vulnerable to attack by malicious users or by malicious software such as viruses. We do not recommend this workaround but are providing this information so that you can implement this workaround at your own discretion. Use this workaround at your own risk," Microsoft states.... The good news for affected ThinkPad users is that Microsoft and Lenovo are working together on a fix. However, Microsoft hasn't said when that will be available.

Read more of this story at Slashdot.

18 Sep 07:50

Security Researchers Detail New 'BlindSide' Speculative Execution Attack

by EditorDavid
"Security researchers from Amsterdam have publicly detailed 'BlindSide' as a new speculative execution attack vector for both Intel and AMD processors," reports Phoronix: BlindSide is self-described as being able to "mount BROP-style attacks in the speculative execution domain to repeatedly probe and derandomize the kernel address space, craft arbitrary memory read gadgets, and enable reliable exploitation. This works even in face of strong randomization schemes, e.g., the recent FGKASLR or fine-grained schemes based on execute-only memory, and state-of-the-art mitigations against Spectre and other transient execution attacks." From a single buffer overflow in the kernel, researchers claim three BlindSide exploits in being able to break KASLR (Kernel Address Space Layout Randomization), break arbitrary randomization schemes, and even break fine-grained randomization. There's more information on the researcher's web site, and they've also created an informational video. And here's a crucial excerpt from their paper shared by Slashdot reader Hmmmmmm: In addition to the Intel Whiskey Lake CPU in our evaluation, we confirmed similar results on Intel Xeon E3-1505M v5, XeonE3-1270 v6 and Core i9-9900K CPUs, based on the Skylake, KabyLake and Coffee Lake microarchitectures, respectively, as well as on AMD Ryzen 7 2700X and Ryzen 7 3700X CPUs, which are based on the Zen+ and Zen2 microarchitectures. Overall, our results confirm speculative probing is effective on a modern Linux system on different microarchitectures, hardened with the latest mitigations.

Read more of this story at Slashdot.

18 Sep 07:28

CISA: Chinese State Hackers Are Exploiting F5, Citrix, Pulse Secure, and Exchange Bugs

by msmash
The Cybersecurity and Infrastructure Security Agency (CISA) has published a security advisory today warning of a wave of attacks carried out by hacking groups affiliated with China's Ministry of State Security (MSS). From a report: CISA says that over the past year, Chinese hackers have scanned US government networks for the presence of popular networking devices and then used exploits for recently disclosed vulnerabilities to gain a foothold on sensitive networks. The list of targeted devices includes F5 Big-IP load balancers, Citrix and Pulse Secure VPN appliances, and Microsoft Exchange email servers. For each of these devices, major vulnerabilities have been publicly disclosed over the past 12 months, such as CVE-2020-5902, CVE-2019-19781, CVE-2019-11510, and CVE-2020-0688, respectively. According to a table summarizing Chinese activity targeting these devices published by CISA today, some attacks have been successful and enabled Chinese hackers to gain a foothold on federal networks.

Read more of this story at Slashdot.

18 Sep 06:33

FBI Says Credential Stuffing Attacks Are Behind Some Recent Bank Hacks

by msmash
The FBI has sent a private security alert to the US financial sector last week warning organizations about the increasing number of credential stuffing attacks that have targeted their networks and have led to breaches and considerable financial losses. From a report: Credential stuffing is a relatively new term in the cyber-security industry. [...] According to an FBI security advisory obtained by ZDNet today, credential stuffing attacks have increased in recent years and have now become a major problem for financial organizations. "Since 2017, the FBI has received numerous reports on credential stuffing attacks against US financial institutions, collectively detailing nearly 50,000 account compromises," the FBI said. "The victims included banks, financial services providers, insurance companies, and investment firms."

Read more of this story at Slashdot.

02 Sep 18:29

A Closer Look At Elon Musk's Neuralink Surgical Robot

by BeauHD
Earlier today, Elon Musk demonstrated his startup Neuralink's brain link device working in a pig named Gertrude. While the science and the device itself were front-and-center at the presentation, the surgical robot the company debuted is equally as important because it's designed to handle the full surgical installation process. "That includes opening up the scalp, removing a portion of the skull, inserting the hundreds of 'thread' electrodes 6mm deep along with the accompanying chip, then closing the incision," reports CNET. TechCrunch takes a closer look at the robot: The rounded polycarbonate sci-fi design of the brain surgeon bot looks like something out of the Portal franchise, but it's actually the creation of Vancouver-based industrial design firm Woke Studio. To be clear, Musk's engineers and scientists have created the underlying technology, but Woke built the robot's look and user experience, as well as the behind-the-ear communication end piece that Neuralink has shown in prior presentations. Neuralink's bot features clean white (required for ensuring sterility, per Woke), arcing lines and smooth surfaces for a look that at once flags its advanced technical capabilities, but also contains some soothing and more approachable elements, which is wise considering what the machine is intended to do. Woke says the Neuralink surgical robot can be separated into three main parts: The head, the body and base. The head of the robot is that helmet-like piece, which actually holds the head of the patient. It also includes a guide for the surgical needle, as well as embedded cameras and sensors to map the patent's brain. The intent of the design of this piece, which includes a mint-colored interior, is to give the robot "an anthroprmorphic characteristic" that helps distract from the invasive nature of the procedure. There are also single-use disposable bags that line the interior of the helmet for sterile operation. The Neuralink robot also has a "body," that humped rear assembly, which includes all the parts responsible for the motion of the robot as it sets up from the procedure. The third element is the base, which basically keeps the whole thing from tipping over, and apparently also contains the computing brains of the brain-bot itself.

Read more of this story at Slashdot.

23 Aug 09:47

Solar Panels Are Starting to Die, Leaving Behind Toxic Trash

by EditorDavid
"Solar panels are an increasingly important source of renewable power that will play an essential role in fighting climate change. They are also complex pieces of technology that become big, bulky sheets of electronic waste at the end of their lives — and right now, most of the world doesn't have a plan for dealing with that," reports Wired. (Alternate URL here.) But we'll need to develop one soon, because the solar e-waste glut is coming. By 2050, the International Renewable Energy Agency projects that up to 78 million metric tons of solar panels will have reached the end of their life, and that the world will be generating about 6 million metric tons of new solar e-waste annually. While the latter number is a small fraction of the total e-waste humanity produces each year, standard electronics recycling methods don't cut it for solar panels. Recovering the most valuable materials from one, including silver and silicon, requires bespoke recycling solutions. And if we fail to develop those solutions along with policies that support their widespread adoption, we already know what will happen. "If we don't mandate recycling, many of the modules will go to landfill," said Arizona State University solar researcher Meng Tao, who recently authored a review paper on recycling silicon solar panels, which comprise 95 percent of the solar market... And because solar panels contain toxic materials like lead that can leach out as they break down, landfilling also creates new environmental hazards.

Read more of this story at Slashdot.

27 Jul 08:55

Apple Being Sued For Refusing To Help iTunes Gift Card Scam Victims

by EditorDavid
"Apple is being sued for allegedly refusing to help those who have fallen victim to a iTunes gift card scam," reports 9to5Mac, in an article shared by Slashdot reader AmiMoJo: An 11-count class action lawsuit has been filed against the company. Apple is accused of lying when it says that there is no way to trace or refund the value of the cards... iTunes gift card scams usually work in a slightly different way, typically being used to buy paid apps owned by the scammers, so they receive 70% of the money when paid by Apple. The lawsuit says that Apple tells scam victims there is nothing that can be done once the money has been spent, but argues that this isn't true. In fact, Apple holds 100% of the funds for a period of 4-6 weeks, between the apps being purchased and Apple paying the developer. During this time, the company is in a position to refund 100% of the card value. Additionally, Apple takes a 30% commission, so would always be in a position to refund this much, even after the scammer has been paid. ZDNet quotes the court documents as arguing that Apple "is incentivized to allow the scam to continue because it reaps a 30% commission on all scammed proceeds... knowingly or recklessly, Apple plays a vital role in the scheme by failing to prevent payouts to the scammers."

Read more of this story at Slashdot.

14 Jul 18:20

Johnnie Walker Maker Creates Plastic-Free Paper-Based Spirits Bottle

by BeauHD
An anonymous reader quotes a report from The Guardian: The multinational drinks company Diageo says it has created the world's first paper-based spirits bottle that is 100% plastic-free. The company said it was aiming to launch the bottle early next year with its Johnnie Walker whisky brand in one market before rolling it out worldwide. The bottle is made from sustainably sourced pulp, complies with international food and drink safety standards and is fully recyclable. The contents are protected by a liner, made of resin rather than plastic, which holds the liquid but disintegrates when finished. The cap will be made of aluminum. The report notes that a paper beer bottle was unveiled last year by Danish brewer Carlsberg.

Read more of this story at Slashdot.

09 Jul 18:03

IBM's New Differential Privacy Library Works With Just a Single Line of Code

by EditorDavid
Friday IBM Research updated their open source "IBM Differential Privacy Library," a suite of new lightweight tools offering "an array of functionality to extract insight and knowledge from data with robust privacy guarantees." "Most tasks can be run with only a single line of code," brags a new blog post (shared by Slashdot reader IBMResearch), explaining how it works: This year for the first time in its 230-year history the U.S. Census will use differential privacy to keep the responses of its citizens confidential when the data is made available. But how does it work? Differential privacy uses mathematical noise to preserve individuals' privacy and confidentiality while allowing population statistics to be observed. This concept has a natural extension to machine learning, where we can protect models against privacy attacks, while maintaining overall accuracy. For example, if you want to know my age (32) I can pick a random number out of a hat, say ±7 — you will only learn that I could be between 25 and 39. I've added a little bit of noise to the data to protect my age and the US Census will do something similar. While the US government built its own differential privacy tool, IBM has been working on its own open source version and today we are publishing our latest release v0.3. The IBM Differential Privacy Library boasts a suite of tools for machine learning and data analytics tasks, all with built-in privacy guarantees. Our library is unique to others in giving scientists and developers access to lightweight, user-friendly tools for data analytics and machine learning in a familiar environment... What also sets our library apart is our machine learning functionality enables organisations to publish and share their data with rigorous guarantees on user privacy like never before... Also included is a collection of fundamental tools for data exploration and analytics. All the details for getting started with the library can be found at IBM's Github repository.

Read more of this story at Slashdot.

09 Jul 17:26

The Far Side Returns After 25 Years, and It's All Digital

by BeauHD
Gary Larson has released new comics for the The Far Side, the first strips since January 1995. Larson does however caution that this is "not a resurrection of The Far Side daily cartoons." He adds: "I'm just exploring, experimenting, and trying stuff." The Verge reports: The first of the new comics features bears, aliens, and taxidermy (all staples of The Far Side). The style is comfortably familiar, with two large exceptions: instead of watercolor, the new comics are done in digital brushstrokes that make the images feel more volumetric and vibrant than the original full-color cartoons. Also, the penned outlines, which exist in both the watercolor and black-and-white original comics, are almost entirely gone. The end result is images that evoke the feel of the old comics but are somehow a little less cartoony. The characters and elements all feel unified in the scene together. Both the style changes and the comic's return are due to the fact that Larson is now using a digital tablet. After years of frustration dealing with clogged pens and dried-up markers, Larson decided to give going digital a chance. "I was stunned at all the tools the thing offered, all the creative potential it contained. I simply had no idea how far these things had evolved," Larson writes in an opening letter for New Stuff, the title for his new works. "Perhaps fittingly, the first thing I drew was a caveman."

Read more of this story at Slashdot.

05 Jul 11:07

Oracle Celebrates 'The 25 Greatest Java Apps Ever Written'

by EditorDavid
Oracle's Java magazine is celebrating the 25th anniversary of the programming language with a list of the 25 greatest Java apps ever written: From space exploration to genomics, from reverse compilers to robotic controllers, Java is at the heart of today's world. Here are a few of the countless Java apps that stand out from the crowd. The story of Java began in 1991, at a time when Sun Microsystems sought to extend their lead in the computer workstation market into the burgeoning personal electronics market. Little did anyone know that the programming language Sun was about to create would democratize computing, inspire a worldwide community, and become the platform for an enduring software development ecosystem of languages, runtime platforms, SDKs, open source projects, and lots and lots of tools. After a few years of secret development led by James Gosling, Sun released the landmark "write once, run anywhere" Java platform in 1995, refocusing it beyond its original design for interactive television to applications for the burgeoning World Wide Web. By the turn of the century, Java was animating everything from smartcards to space vehicles. Today, millions of developers program in Java. Although Java continues to evolve at an ever-faster pace, on the occasion of the platform's 25th anniversary, Java Magazine decided to take a look back at how Java molded our planet. What follows is a list of the 25 most ingenious and influential Java apps ever written, from Wikipedia Search to the US National Security Agency's Ghidra. The scope of these applications runs the gamut: space exploration, video games, machine learning, genomics, automotive, cybersecurity, and more. The list includes Eclipse, Minecraft, the Maestro Mars Rover controller, and "VisibleTesla," the open source app created by an automobile enthusiast to monitor and control his Tesla Model S.

Read more of this story at Slashdot.

22 Apr 16:04

Researchers Say They Caught an iPhone Zero-Day Hack in the Wild

by msmash
In the summer of 2016, researchers at a digital rights organization and a cybersecurity firm announced they had caught one of the rarest fish in the cybersecurity ocean -- an in the wild attack against an iPhone, using unknown vulnerabilities inside Apple's vaunted operating system. Since then, only a handful of similar attacks have been caught and publicly disclosed. Now, a small startup said it has caught another one. From a report: ZecOps, a company based in San Francisco, announced on Wednesday that a few of its customers were targeted with two zero-day exploits for iOS last year. Apple will patch the vulnerability underlying these attacks on an upcoming release of iOS 13. "We concluded with high confidence that it was exploited in the wild," Zuk Avraham, the founder of ZecOps, told Motherboard. "One of [the vulnerabilities] we clearly showed that it can be triggered remotely, the other one requires an additional vulnerability to trigger it remotely." "These vulnerabilities," ZecOps researchers wrote in a report they published Wednesday, "are widely exploited in the wild in targeted attacks by an advanced threat operator(s) to target VIPs, executive management across multiple industries, individuals from Fortune 2000 companies, as well as smaller organizations such as MSSPs." One of the two vulnerabilities, according to Avraham, is what's known as a remote zero-click. This kind of attack is dangerous because it can be used by an attacker against anyone on the internet, and the target gets infected without any interaction -- hence the zero-click definition. Vulnerabilities or exploits called zero-days are bugs in software or hardware that are unknown to their manufacturers and can be used to hack targets. They can be particularly effective attacks because they use flaws that are not patched yet, meaning there's no code deployed to specifically defend against them.

Read more of this story at Slashdot.

07 Dec 15:45

Recordings Reveal That Plants Make Ultrasonic Squeals When Stressed

by BeauHD
Researchers have discovered that plants make airborne sounds when stressed, which they say "could open up a new field of precision agriculture where farmers listen for water-starved crops," reports New Scientist. From the report: Itzhak Khait and his colleagues at Tel Aviv University in Israel found that tomato and tobacco plants made sounds at frequencies humans cannot hear when stressed by a lack of water or when their stem is cut. Microphones placed 10 centimeters from the plants picked up sounds in the ultrasonic range of 20 to 100 kilohertz, which the team says insects and some mammals would be capable of hearing and responding to from as far as 5 meters away. A moth may decide against laying eggs on a plant that sounds water-stressed, the researchers suggest. Plants could even hear that other plants are short of water and react accordingly, they speculate. On average, drought-stressed tomato plants made 35 sounds an hour, while tobacco plants made 11. When plant stems were cut, tomato plants made an average of 25 sounds in the following hour, and tobacco plants 15. Unstressed plants produced fewer than one sound per hour, on average. It is even possible to distinguish between the sounds to know what the stress is. The researchers trained a machine-learning model to discriminate between the plants' sounds and the wind, rain and other noises of the greenhouse, correctly identifying in most cases whether the stress was caused by dryness or a cut, based on the sound's intensity and frequency. Water-hungry tobacco appears to make louder sounds than cut tobacco, for example. The study, which has not yet been published in a journal, can be found here.

Share on Google+

Read more of this story at Slashdot.

26 Oct 07:07

Man Kept Getting Drunk Without Drinking. Docs Found Brewer's Yeast In His Guts

by BeauHD
An anonymous reader quotes a report from Ars Technica: After years of inexplicably getting drunk without drinking alcohol, having mood swings and bouts of aggression, landing a DWI charge on the way to work one morning, and suffering a head injury in a drunken fall, an otherwise healthy 46-year-old North Carolina man finally got confirmation of having alcohol-fermenting yeasts overrunning his innards, getting him sloshed any time he ate carbohydrate-laden meals. Through the years, medical professionals and police officers refused to believe he hadn't been drinking. They assumed the man was lying to hide an alcohol problem. Meanwhile, he went to an untold number of psychiatrists, internists, neurologists, and gastroenterologists searching for answers. Those answers only came after he sought help from a support group online and then contacted a group of researchers at Richmond University Medical Center in Staten Island, New York. By then, it was September of 2017 -- more than seven years after his saga began. The New York researchers finally confirmed that he had a rarely diagnosed condition called "auto-brewery syndrome." From there, the researchers started him on powerful anti-fungal medications to try to clear the boozy germs from his system. But he relapsed just weeks later after sneaking some forbidden pizza and soda. The researchers tried again, giving him an even stronger round of anti-fungal drugs, this time through a tube directly into his veins (central catheter). By February of 2018, tests indicated he was free of the fermenting fungi. He went back to eating his normal diet and passed his daily breathalyzer tests. He has stayed that way since, the researchers report.

Share on Google+

Read more of this story at Slashdot.

23 Jun 10:43

Replacing JavaScript: How eBay Made a Web App 50x Faster With WebAssembly

by EditorDavid
"Online marketplace eBay has revealed how it boosted performance of a demanding web app by 50x using WebAssembly," reports TechRepublic: The "astonishing" speed-up after switching from a JavaScript-based to a largely WebAssembly-based web app was detailed by the eBay engineering team, who say the performance boost helped make it possible to build a highly-accurate barcode scanner as a web app... a feature it offers in its Android and iOS apps to allow sellers to scan items they are auctioning. "WebAssembly was different. It has tremendous potential, we just did not have the right use case. Well, that changed recently," write the eBay software engineering team. One of the advantages of WebAssembly (Wasm) is that it offers code portability for a variety of languages, allowing developers to take code they've written for other platforms and compile to WebAssembly so it can run in major web browsers. Consequently eBay was able to take the existing version of its barcode scanner written in C++ and compile that to Wasm using Emscripten, adopting the Docker and Node.js-based approach outlined here. After a few minor teething problems, the eBay team were able to run the barcode scanner in the browser, using a Worker thread and JavaScript glue code. The Wasm-based scanner was able to process images of the barcode at 50 Frames per Second (FPS), compared to about 1FPS in an earlier JavaScript-based scanner eBay had tested, a speed-up the team described as "astonishing". Unfortunately, the Wasm code only successfully completed scans 60% of the time, because it wasn't using the inbuilt APIs available for the C++ code to either autofocus or provide user tap focus for the center of the scanned object. eBay's team ultimately ended up implementing three separate worker threads running the Wasm code, the open-source barcode reader ZBar, and their original JavaScript-based scanner code. "The winning response (i.e. the first one to send a valid barcode) is sent to the main thread, and all workers are terminated... With three threads racing against each other, the success rate was indeed close to 100%."

Share on Google+

Read more of this story at Slashdot.

16 Jun 18:23

Hackers Breached 3 US Antivirus Companies, Researchers Reveal

by msmash
In a report published Thursday, researchers at the threat-research company Advanced Intelligence (AdvIntel) revealed that a collective of Russian and English-speaking hackers are actively marketing the spoils of data breaches at three US-based antivirus software vendors. From a report: The collective, calling itself "Fxmsp," is selling both source code and network access to the companies for $300,000 and is providing samples that show strong evidence of the validity of its claims. Yelisey Boguslavskiy, director of research at AdvIntel, told Ars that his company notified "the potential victim entities" of the breach through partner organizations; it also provided the details to US law enforcement. In March, Fxmsp offered the data "through a private conversation," Boguslavskiy said. "However, they claimed that their proxy sellers will announce the sale on forums."

Share on Google+

Read more of this story at Slashdot.

06 Apr 09:06

Huawei Laptop 'Backdoor' Flaw Raises Concerns

by msmash
A flaw in Huawei Matebook laptops, found by Microsoft researchers, could have been used to take control of machines. From a report: The "sophisticated flaw" had probably been introduced at the manufacturing stage, one expert told BBC News. Huawei is under increasing scrutiny around the world over how closely it is tied to the Chinese government. The company, which denies any collusion with Beijing, corrected the flaw after it was notified about it in January. Prof Alan Woodward, a computer security expert based at Surrey University, told BBC News the flaw had the hallmarks of a "backdoor" created by the US's National Security Agency to spy on the computers of targets. That tool was leaked online and has been used by a wide variety of hackers, including those who are state-sponsored and criminal gangs. "It was introduced at the manufacture stage but the path by which it came to be there is unknown and the fact that it looks like an exploit that is linked to the NSA doesn't mean anything," Prof Woodward said.

Share on Google+

Read more of this story at Slashdot.

12 Feb 18:29

Encryption for everyone: how Adiantum will keep more Android devices secure

by Thom Holwerda
Adiantum is a new form of encryption that we built specifically to run on phones and smart devices that don’t have the specialized hardware to use current methods to encrypt locally stored data efficiently. Adiantum is designed to run efficiently without that specialized hardware. This will make the next generation of devices more secure than their predecessors, and allow the next billion people coming online for the first time to do so safely. Adiantum will help secure our connected world by allowing everything from smart watches to internet-connected medical devices to encrypt sensitive data. (For more details about the ins and outs of Adiantum, check out the security blog.) Encryption should be available on every single Android phone, not just the high-end, expensive models only the lucky few in the world can afford. Good move.
11 Feb 22:13

Researcher Reveals a Severe, Unpatched Mac Password Flaw To Protest Apple Bug Bounty

by msmash
Linuz Henze, a credible researcher, has revealed an exploit that in a single button press can reveal the passwords in a Mac's keychain. From a report: Keychain is where macOS stores most of the passwords used on the machine, ranging from iMessage private encryption keys to certificates, secured notes, Wi-Fi, and other Apple hardware passwords, app passwords, and web passwords. A pre-installed app called Keychain Access enables users to view the entire list of stored items, unlocking each one individually by repeatedly entering the system password, but Henze's KeySteal exploit grabs everything with a single press of a "Show me your secrets" button. While the demo is run on a 2014 MacBook Pro without Apple's latest security chips, Henze says that it works "without root or administrator privileges and without password prompts, of course." It appears to work on the Mac's login and system keychains, but not iCloud's keychain. Generally, white hat security researchers publicly reveal flaws like this only after informing the company and giving it ample time to fix the issues. But Henze is refusing to assist Apple because it doesn't offer paid bug bounties for macOS.

Share on Google+

Read more of this story at Slashdot.

11 Feb 22:06

Microsoft: 70 Percent of All Security Bugs Are Memory Safety Issues

by msmash
Around 70 percent of all the vulnerabilities in Microsoft products addressed through a security update each year are memory safety issues; a Microsoft engineer revealed last week at a security conference. From a report: Memory safety is a term used by software and security engineers to describe applications that access the operating system's memory in a way that doesn't cause errors. Memory safety bugs happen when software, accidentally or intentionally, accesses system memory in a way that exceeds its allocated size and memory addresses. Users who often read vulnerability reports come across terms over and over again. Terms like buffer overflow, race condition, page fault, null pointer, stack exhaustion, heap exhaustion/corruption, use after free, or double free -- all describe memory safety vulnerabilities. Speaking at the BlueHat security conference in Israel last week, Microsoft security engineer Matt Miller said that over the last 12 years, around 70 percent of all Microsoft patches were fixes for memory safety bugs.

Share on Google+

Read more of this story at Slashdot.

09 Dec 14:10

Cyber-Espionage Group Uses Chrome Extension To Infect Victims

by msmash
In what appears to be a first on the cyber-espionage scene, a nation-state-backed hacking group has used a Google Chrome extension to infect victims and steal passwords and cookies from their browsers. From a report: This is the first time an APT (Advanced Persistent Threat -- an industry term for nation-state hacking groups) has been seen (ab)using a Chrome extension, albeit it's not the first time one has used a browser extension, as the Russian-linked Turla APT previously used a Firefox add-on in 2015. According to a report that's going to be published later today by the ASERT team at Netscout reveals the details of a spear-phishing campaign that's been pushing a malicious Chrome extension since at least May 2018. Hackers used spear-phishing emails to lure victims on websites copied from legitimate academic organizations. These phishing sites, now down, showed a benign PDF document but prevented users from viewing it, redirecting victims to the official Chrome Web Store page to install a (now removed) Chrome extension named Auto Font Manager.

Share on Google+

Read more of this story at Slashdot.

27 Aug 14:26

Intel Discloses Three More Chip Flaws

by msmash
Intel on Tuesday disclosed three more possible flaws in some of its microprocessors that can be exploited to gain access to certain data from computer memory. From a report: Its commonly used Core and Xeon processors were among the products that were affected, the company said. "We are not aware of reports that any of these methods have been used in real-world exploits, but this further underscores the need for everyone to adhere to security best practices," the company said in a blog post. Intel also released updates to address the issue and said new updates coupled those released earlier in the year will reduce the risk for users, including personal computer clients and data centres. In January, the company came under scrutiny after security researchers disclosed flaws that they said could let hackers steal sensitive information from nearly every modern computing device containing chips from Intel, Advanced Micro Devices and ARM.

Share on Google+

Read more of this story at Slashdot.

23 Aug 17:35

Despite being shunned in the US, Huawei flourishes in Europe

by donotreply@osnews.com (Thom Holwerda)
When major smartphone manufacturers talk about growth, they generally target three different markets: China, which is the biggest; the United States, which is highly influential and profitable; and the rest. India will soon rise from the latter pile, but until it does, Europe might be the most interesting battleground for the respective companies dominating the US and Chinese spheres. Until very recently, Western Europe looked a lot like the United States, with Samsung commanding more than a third of the market, Apple in a close second spot, and minnows picking up the scraps. But IDC's latest data, as provided to The Verge, shows China's Huawei enjoying a meteoric rise since the start of 2017. Yes, the same Huawei that the US government advises its citizens to avoid.

Huawei is marketing quite aggressively over here, but I still haven't seen any of their phones in the wild. It's exclusively Samsung and Apple, so far.