Programming Bug Costs Citigroup $7M After Legit Transactions Mistaken For Test Data For 15 Years

An anonymous reader shares a report on The Register:A programming blunder in its reporting software has led to Citigroup being fined $7m. According to the US Securities and Exchange Commission (SEC), that error [PDF] resulted in the financial regulator being sent incomplete “blue sheet” information for a remarkable 15 years — from May 1999 to April 2014. The mistake was discovered by Citigroup itself when it was asked to send a large but precise chunk of trading data to the SEC in April 2014 and asked its technical support team to help identify which internal ID numbers they should run a request on. That team quickly noticed that some branches’ trades were not being included in the automated system and alerted those above them. Four days later a patch was in place, but it wasn’t until eight months later that the company received a formal report noting that the error had affected SEC reports going back more than a decade. The next month, January 2015, Citigroup fessed up to the SEC.The glitch resided in new alphanumeric branch codes that the bank had introduced in the mid-1990s. The program code filtered out any transactions that were given three-digit branch codes from 089 to 100 and used those prefixes for testing purposes. The report adds, “But in 1998, the company started using alphanumeric branch codes as it expanded its business. Among them were the codes 10B, 10C and so on, which the system treated as being within the excluded range, and so their transactions were removed from any reports sent to the SEC.” Read more of this story at Slashdot.

View article:
Programming Bug Costs Citigroup $7M After Legit Transactions Mistaken For Test Data For 15 Years

Pokemon Go Becomes Biggest Mobile Game In US History

An anonymous reader writes: Pokemon Go is now the biggest mobile game of all time in the U.S. Not only has it surpassed Twitter’s daily users, but it is seeing people spend more time in its app than in Facebook. An earlier report from SimilarWeb says Pokemon Go has surpassed Tinder in terms of installations — the app surpassed Tinder on July 7th. Today, the tracking firm says Pokemon Go has managed to surpass Twitter in terms of daily active users on Monday. It says almost 6% of the entire U.S. Android population is engaging with the app on a daily basis. A new report from SurveyMonkey intelligence indicated that Pokemon Go has claimed the title “biggest mobile game in U.S. history.” The game saw just under 21 million daily active users in the U.S. on Monday. It’s reportedly closing in on Snapchat on Android, and could surpass Google Maps on Android as well. According to app store intelligence firm SensorTower, the average iPhone user on iOS spent 33 minutes catching Pokemon, which is more than any other apps it analyzed, including Facebook, Snapchat, Twitter, Instagram, and Slither.io. The app with the second-most average usage at 22 minutes, 8 seconds, was Facebook. SurveyMonkey did note that Pokemon Go still falls short of other games when it comes to time spent in games. Game of War sees nearly 2 hours of total daily usage for the average user, while Candy Crush Saga sees daily usage of about 43 minutes. In just two days, Pokemon Go brought Nintendo’s market value to $7.5 billion. It’s worth noting that it remains to be seen whether or not the game will continue to break records or turn into a ghost town like Nintendo’s first mobile game, Miitomo. Read more of this story at Slashdot.

View article:
Pokemon Go Becomes Biggest Mobile Game In US History

Porsche screws up

Legendary automaker Porsche may have mistakenly swapped two screws in its 918 Spyder hybrid-hypercar’s seat belt system. Thinking of the customer, Porsche has voluntarily recalled their $850k practical, about town race car. Via Autoevolution : A mistake in the original parts catalog for the Porsche 918 Spyder has led to a recall of the hybrid hypercard. Porsche 918 SpyderAccording to Porsche, the printed document unwittingly transposed the locations for the screws which tighten the seat belt mount and the belt reel mount. Since those screws are one-time-use only, and are also not the same, technicians who had to work on them might have unintentionally installed the wrong screw in the wrong position. Because of this mishap in the original parts catalog, which has since been corrected, there is a risk of some Porsche 918 Spyder models having wrong screws fitted to their seatbelt mounts and seat belt reel mounts.

Visit link:
Porsche screws up

20-year-old Windows bug lets printers install malware—patch now

Enlarge (credit: Vectra Networks) For more than two decades, Microsoft Windows has provided the means for clever attackers to surreptitiously install malware of their choice on computers that connect to booby-trapped printers, or other devices masquerading as printers, on a local area network. Microsoft finally addressed the bug on Tuesday during its monthly patch cycle. The vulnerability resides in the Windows Print Spooler, which manages the process of connecting to available printers and printing documents. A protocol known as Point-and-Print allows people who are connecting to a network-hosted printer for the first time to automatically download the necessary driver immediately before using it. It works by storing a shared driver on the printer or print server and eliminates the hassle of the user having to manually download and install it. Researchers with security firm Vectra Networks discovered that the Windows Print Spooler doesn’t properly authenticate print drivers when installing them from remote locations. The failure makes it possible for attackers to use several different techniques that deliver maliciously modified drivers instead of the legitimate one provided by the printer maker. The exploit effectively turns printers, printer servers, or potentially any network-connected device masquerading as a printer into an internal drive-by exploit kit that infects machines whenever they connect. Read 9 remaining paragraphs | Comments

Continue reading here:
20-year-old Windows bug lets printers install malware—patch now

Someone Bought Einstein’s Smelly Leather Jacket for Nearly $150,000

Today, Christie’s auctioned off the well-worn leather jacket of Albert Einstein . You may know him as the Nobel Prize-winning mathematician who figured out the essence of the universe almost a full century before science could prove him right . But he also had great fashion sense. Read more…

Continued here:
Someone Bought Einstein’s Smelly Leather Jacket for Nearly $150,000

Tor Project Completely Replaces Board After Sexual Assault Scandal

A little more than one month after the Tor Project’s public face Jacob Applebaum stepped down following accusations from multiple women that he sexually assaulted them, the nonprofit has completely replaced its board. Read more…

Excerpt from:
Tor Project Completely Replaces Board After Sexual Assault Scandal

Rare US version of the N64’s disc-drive add-on unearthed near Seattle

Jason Lindsey That’s quite the find! 6 more images in gallery Nintendo has launched a few pieces of hardware in Japan that never made their way to the West, including the backlit Game Boy Light and the Satellaview online attachment for the Super Famicom. But the best-known of Nintendo’s Japan-only hardware has to be the 64DD—as in, the disk-drive attachment for the Nintendo 64 that landed with a whopping thud in Japan in 1999. Though Nintendo of America had originally hinted at the add-on launching in the United States, that never happened, even though the company had once reached out to Western developers about making software for the system—and taking advantage of its disks’ maximum 38MB of rewritable memory (which was huge compared to the N64’s 32KB memory cards). But that doesn’t mean an American 64DD  never existed. A game-console collector announced on Tuesday that he had discovered an English-language version of the 64DD hardware—and based on insider Nintendo knowledge, this is almost certainly a retail prototype, as opposed to a dev kit. Former Sierra game developer Jason Lindsey took to the Assembler Games forums this week—where you’ll find no shortage of classic and rare gaming topics —to show off his latest acquisition. Lindsey told the forum that he had purchased a “prototype for the US version of the 64DD.” His attached photos include two screens of the 64DD’s boot-up sequence, which normally contains kanji characters asking players to insert a disk; his unit, however, offers those instructions in English. Read 5 remaining paragraphs | Comments

Read this article:
Rare US version of the N64’s disc-drive add-on unearthed near Seattle

FDIC was hacked by China, and CIO covered it up

Insuring deposits, but not your identity. Thanks, FDIC. (credit: Matthew G. Bisanz ) A report published by the House Committee on Science, Space and Technology today found that hackers purported to be from China had compromised computers at the Federal Deposit Insurance Corporation repeatedly between 2010 and 2013. Backdoor malware was installed on 12 workstations and 10 servers by attackers—including the workstations of the chairman, chief of staff, and general counsel of FDIC. But the incidents were never reported to the US Computer Emergency Response Team (US-CERT) or other authorities, and were only brought to light after an Inspector General investigation into another serious data breach at FDIC in October of 2015. The FDIC failed at the time of the “advanced persistent threat” attacks to report the incidents. Then-Inspector General at FDIC, Jon Rymer, lambasted FDIC officials for failing to follow their own policies on breach reporting. Further investigation into those breaches led the committee to conclude that former FDIC CIO Russ Pittman misled auditors about the extent of those breaches, and told employees not to talk about the breaches by a foreign government so as not to ruin FDIC Chairman Martin Gruenberg’s chances of confirmation. The cascade of bad news began with an FDIC Office of the Inspector General (OIG) investigation into the October “Florida incident.” On October 23, 2015, a member of the Federal Deposit Insurance Corporation’s Information Security and Privacy Staff (ISPS) discovered evidence in the FDIC’s data loss prevention system of a significant breach of sensitive data—over 1,200 documents, including Social Security numbers from bank data for over 44,000 individuals and 30,715 banks, were copied to a USB drive by a former employee of FDIC’s Risk Management Supervision field office in Gainesville, Florida. The employee had copied the files prior to leaving his position at FDIC. Despite intercepting the employee, the actual data was not recovered from him until March 25, 2016. The former employee provided a sworn statement that he had not disseminated the information, and the matter was dropped. Read 3 remaining paragraphs | Comments

Read More:
FDIC was hacked by China, and CIO covered it up

Windows Server 2016 coming in September, with new servicing for Nano Server

It’s not quite an exact launch date, but Microsoft has announced that both Windows Server 2016 and System Center 2016 will launch at its Ignite conference (the successor to TechEd) this fall. Ignite runs from September 26-30 and is being held in Atlanta, Georgia. Microsoft has also described how Windows Server 2016 will be serviced going forward. Full installations of the operating system—including the GUI and shell—will continue to be serviced on the “5+5” model that Microsoft has used for previous operating systems. That’s five years of mainstream support, during which both bug fixes and feature improvements are made, and then five years of extended support, during which only security bugs will be fixed. The slimmed down Server Core installation will also be given this 5+5 servicing. The new Nano Server option, however, will be handled in a different way. Nano Server installations will be updated more or less in tandem with the Windows 10 Current Branch for Business (CBB) release. CBB trails the main consumer branch by about six months, giving new features a bit of time to receive some real-world testing before being distributed to more conservative organizations. CBB is expected to be updated two to three times a year, and this will apply to Nano Server deployments of Windows Server 2016 just as it does to CBB deployments of Windows 10. Read 3 remaining paragraphs | Comments

View article:
Windows Server 2016 coming in September, with new servicing for Nano Server