U.S. Indicts 7 Iranians Accused of Hacking U.S. Financial Institutions

An anonymous reader quotes a report from NPR: The U.S. Department of Justice has indicted seven Iranians with intelligence links over a series of crippling cyberattacks against 46 U.S. financial institutions between 2011 and 2013. The indictment, which was unsealed Thursday, also accuses one of the Iranians of remotely accessing the control system of a small dam in Rye, N.Y, during the same period. Attorney General Loretta Lynch said the indictment is meant to send a message: “That we will not allow any individual, group, or nation to sabotage American financial institutions or undermine the integrity of fair competition in the operation of the free market.” According to the indictment, the seven men worked for two Iran-based computer security companies that have done work for the Iranian government, including the powerful Islamic Revolutionary Guard Corps. The men allegedly carried out large-scale distributed denial of service (DDoS) attacks, which overwhelm a server with communications in order to disable it. Read more of this story at Slashdot.

More:
U.S. Indicts 7 Iranians Accused of Hacking U.S. Financial Institutions

Report: “YouTube Connect” will be a livestreaming Periscope competitor

VentureBeat  has the scoop on another YouTube service: YouTube Connect. Connect would be a livestreaming service which would take on “spur-of-the-moment” live video services like Facebook Live and Twitter’s Periscope. The report says the service would include apps on Android and iOS with “much of the same functionality” as Periscope and Facebook Live. Streaming would be immediate and paired with chat and “tagging” features. There is supposedly even a “news feed” that would list videos from friends and your YouTube subscriptions. Live broadcasts would be saved for later on-demand viewing and would show up on the content creator’s YouTube channel. The new service would be yet another expansion of the YouTube brand and app lineup. Including Connect, YouTube’s video empire would be spread across a whopping seven apps: the regular YouTube app, YouTube Gaming, YouTube Music, YouTube Kids, YouTube Creator Studio, and YouTube Capture. There is also the umbrella subscription service YouTube Red. Read 3 remaining paragraphs | Comments

Follow this link:
Report: “YouTube Connect” will be a livestreaming Periscope competitor

Rage-quit: Coder unpublished 17 lines of JavaScript and “broke the Internet”

(credit: Photo illustration by Aurich Lawson) It all started with a request from the developers of a messaging application to an open-source developer to change the name of a library. It ended with JavaScript developers around the world crying out in frustration as hundreds of projects suddenly stopped working—their code failing because of broken dependencies on modules that a developer removed from the repository over a policy dispute. At the center of it all is npm, Inc. , the Oakland startup behind the largest registry and repository of JavaScript tools and modules. Isaac Schlueter, npm’s creator, said that the way the whole thing shook out was a testament to how well open source works—the missing link was replaced by another developer quickly. But many developers are less than elated by the fact that code they’ve become dependent on can be pulled out from under them without any notice. The disruption caused by the wholesale unpublishing of code modules by their author, Azer Koçulu, was repaired in two hours, Schlueter told Ars, as other developers filled in the holes in the repository. The incident is, however, prompting Schlueter and the team at nmp Inc. to take a look at how to prevent one developer from causing so much collateral damage. Read 21 remaining paragraphs | Comments

Original post:
Rage-quit: Coder unpublished 17 lines of JavaScript and “broke the Internet”

Netflix is the one limiting its video quality on AT&T and Verizon

Last week as T-Mobile CEO John Legere announced that his company’s Binge On program would expand to cover YouTube, he mentioned a strange point: that even the “mobile optimized” 480p Netflix streams T-Mobile offers were higher-res than what you get streaming via AT&T or Verizon. Executives from those companies said they don’t reduce the resolution of videos on their networks, although tests revealed that Legere was right — Netflix does only stream at 360p on AT&T and Verizon. Now the Wall Street Journal has reported that the culprit behind this restriction was actually Netflix itself. 7/ @TMobile has been listening to customers and thanks to a little partnership, @YouTube is now a #BingeOn partner! https://t.co/VQVZoM86Jh — John Legere (@JohnLegere) March 17, 2016 In an odd wrinkle on net neutrality discussions over whether or not broadband providers might restrict video quality of streaming companies they compete with, Netflix chose to limit its own quality on those two networks. Through a blog post and statements to WSJ , Netflix explains that it set a cap at 600kbps to avoid using up too much data under the caps set by those providers for their customers. Sprint and T-Mobile were apparently exempt because of a history of “more consumer friendly policies.” It all makes sense considering how quickly users can chew through bandwidth caps with HD video on mobile, although it seems odd that it wasn’t made clear until now. According to Netflix, this hasn’t been an issue for its users, who are more concerned about saving bandwidth than quality. However, it will soon introduce a “data saver” feature on its mobile apps to let users choose what bandwidth they want to stream over cellular networks — just in case you’re willing to burn a few GB so you can actually see what’s going on in Daredevil . Source: Netflix Blog , Wall Street Journal

Read the original:
Netflix is the one limiting its video quality on AT&T and Verizon

London to NYC in just 3.4 hours? A roundtrip will set you back $5,000

An artist’s conception of the Boom aircraft at London’s Heathrow Airport. (credit: Boom) After more than a decade of dormancy commercial supersonic flight may soon return to the skies. The Soviet Tupolev supersonic aircraft flew just a few dozen flights back in 1977, and the Concorde, flown by British Airways and Air France, retired in 2003 after a fatal accident three years earlier that compounded economic problems. But now Richard Branson and his Virgin empire are ready to try it again. According to   The Guardian , Branson has signed a deal with an American firm to bring commercial supersonic travel to the airways, beginning with trans-Atlantic flights between London and New York City. The agreement brings Branson’s Virgin Galactic into a partnership with Colorado-based Boom, founded by Amazon executive Blake Scholl. Virgin Galactic, according to a company spokeswoman, will provide engineering, design, operations, and manufacturing services, along with flight tests at Virgin’s base in Mojave, Calif. It will then have an option to buy the first 10 airframes from Boom. Read 8 remaining paragraphs | Comments

View article:
London to NYC in just 3.4 hours? A roundtrip will set you back $5,000

CCTV DVR Vulnerabilities Traced To Chinese OEM Which Spurned Researchers’ Advice

An anonymous reader writes: RSA security researcher Rotem Kerner has identified a common vulnerability in the firmware of 70 different CCTV DVR vendors, which allows crooks to execute code and gain root privileges on the affected devices. The problem was actually in the firmware of just one DVR sold by Chinese firm TVT. The practice of “white-labeling” products helped propagate this issue to other “manufacturers” who did nothing more than to buy a non-branded DVR, tweaked its firmware, slapped their logo on top, and sold it a their own, vulnerability included. Read more of this story at Slashdot.

View article:
CCTV DVR Vulnerabilities Traced To Chinese OEM Which Spurned Researchers’ Advice

Anti-Vaxxers successfully bring back measles and whooping cough

Anti-Vaxxers are responsible for the rise in two infectious diseases we’d nearly eliminated from the United States. Researchers at Emory and Johns Hopkins Universities have determined, through a National Institute of Health review , that the rise in measles is directly attributable to vaccine refusal, and that it is certainly helping whooping cough out as well. From the NIH study’s abstract: Findings We identified 18 published measles studies (9 annual summaries and 9 outbreak reports), which described 1416 measles cases (individual age range, 2 weeks-84 years; 178 cases younger than 12 months) and more than half (56.8%) had no history of measles vaccination. Of the 970 measles cases with detailed vaccination data, 574 cases were unvaccinated despite being vaccine eligible and 405 (70.6%) of these had nonmedical exemptions (eg, exemptions for religious or philosophical reasons, as opposed to medical contraindications; 41.8% of total). Among 32 reports of pertussis outbreaks, which included 10 609 individuals for whom vaccination status was reported (age range, 10 days-87 years), the 5 largest statewide epidemics had substantial proportions (range, 24%-45%) of unvaccinated or undervaccinated individuals. However, several pertussis outbreaks also occurred in highly vaccinated populations, indicating waning immunity. Nine reports (describing 12 outbreaks) provided detailed vaccination data on unimmunized cases; among 8 of these outbreaks from 59% through 93% of unvaccinated individuals were intentionally unvaccinated. Conclusions and Relevance A substantial proportion of the US measles cases in the era after elimination were intentionally unvaccinated. The phenomenon of vaccine refusal was associated with an increased risk for measles among people who refuse vaccines and among fully vaccinated individuals. Although pertussis resurgence has been attributed to waning immunity and other factors, vaccine refusal was still associated with an increased risk for pertussis in some populations. We all pay for anti-vaxx ignorance.

See the article here:
Anti-Vaxxers successfully bring back measles and whooping cough

How One Dev Broke Node and Thousands of Projects In 11 Lines of JavaScript

An anonymous reader quotes an article written by Chris Williams for The Register: Programmers were left staring at broken builds and failed installations on Tuesday after someone toppled the Jenga tower of JavaScript. A couple of hours ago, Azer Koculu unpublished more than 250 of his modules from NPM, which is a popular package manager used by JavaScript projects to install dependencies. Koculu yanked his source code because, we’re told, one of the modules was called Kik and that apparently attracted the attention of lawyers representing the instant-messaging app of the same name. According to Koculu, Kik’s briefs told him to take down the module, he refused, so the lawyers went to NPM’s admins claiming brand infringement. When NPM took Kik away from the developer, he was furious and unpublished all of his NPM-managed modules. ‘This situation made me realize that NPM is someone’s private land where corporate is more powerful than the people, and I do open source because Power To The People, ‘ Koculu blogged. Unfortunately, one of those dependencies was left-pad. It pads out the lefthand-side of strings with zeroes or spaces. And thousands of projects including Node and Babel relied on it. With left-pad removed from NPM, these applications and widely used bits of open-source infrastructure were unable to obtain the dependency, and thus fell over. Read more of this story at Slashdot.

Read More:
How One Dev Broke Node and Thousands of Projects In 11 Lines of JavaScript

Angola’s Wikipedia Pirates Are Exposing Loopholes in Zero Rating

Reader Jason Koebler quotes a Motherboard article: Wikimedia and Facebook have given Angolans free access to their respective websites, but not to the rest of the internet. So, naturally, Angolans have taken to hiding pirated movies and music in Wikipedia articles and are also sharing links to these files on Facebook, creating a totally free and clandestine file sharing network in a country where mobile internet data is extremely expensive. It’s undeniably a creative use of two services that were designed to give people in the developing world some access to the internet. But now that Angolans are causing headaches for Wikipedia editors and the Wikimedia Foundation, no one is sure what to do about it. Read more of this story at Slashdot.

Read More:
Angola’s Wikipedia Pirates Are Exposing Loopholes in Zero Rating

The New Apple TV Is Jailbroken, Provided You Didn’t Just Update It

Pangu, the team behind the most recent jailbreaks on iOS , have just released a jailbreak for the Apple TV. There are a lot of caveats for using it, including the fact you’ll need to still be running tvOS 9.0/9.0.1. Read more…

More:
The New Apple TV Is Jailbroken, Provided You Didn’t Just Update It