New Lenovo PCs shipped with factory-installed adware

Buy a new Lenovo computer recently? Well, it looks like it could be infected with some factory-installed adware. Users on the official Lenovo forums started noticing that search results were being injected with sponsored links (like what happens when a machine is infected with typical adware or spyware) as far back as last September, and some even report that sites including Kelley Blue Book and JetBlue wouldn’t render properly at all. This apparently isn’t the only problem, however. As Facebook engineer Mike Shaver recently discovered , the program at fault, Superfish, appears to install a man-in-the-middle certificate that allows outside parties to take a peek at secure websites you might be visiting, too. Like your bank’s , for example. This is a problem. #superfish pic.twitter.com/jKDfSo99ZR – Kenn White (@kennwhite) February 19, 2015 For its part, Lenovo admitted that it was installing Superfish on its machines (users report finding it on the G40 and the pictured-above Y40 and Z50 ) late last month and said that it’d “temporarily removed” it from new consumer products until Superfish’s developer could release an update that’d address the problems users were encountering. Lenovo’s forum post reads as such: “All, As an update on this… Due to some issues (browser pop up behavior for example), with the Superfish Visual Discovery browser add-on, we have temporarily removed Superfish from our consumer systems until such time as Superfish is able to provide a software build that addresses these issues. As for units already in market, we have requested that Superfish auto-update a fix that addresses these issues. To be clear, Superfish comes with Lenovo consumer products only and is a technology that helps users find and discover products visually. The technology instantly analyzes images on the web and presents identical and similar product offers that may have lower prices, helping users search for images without knowing exactly what an item is called or how to describe it in a typical text-based search engine. The Superfish Visual Discovery engine analyzes an image 100% algorithmically, providing similar and near identical images in real time without the need for text tags or human intervention. When a user is interested in a product, Superfish will search instantly among more than 70, 000 stores to find similar items and compare prices so the user can make the best decision on product and price. Superfish technology is purely based on contextual/image and not behavioral. It does not profile nor monitor user behavior. It does not record user information. It does not know who the user is. Users are not tracked nor re-targeted. Every session is independent. When using Superfish for the first time, the user is presented the Terms of User and Privacy Policy, and has option not to accept these terms, i.e., Superfish is then disabled.” Lenovo is far from the only OEM that pre-installs software on its computers (Dell and WildTangent games say “hi”), but putting what very much looks to be malware on machines is pretty brazen. What’s more, The Next Web even reports that antivirus software denotes Superfish as a virus and suggests removal. An enterprising YouTube user has even posted a tutorial video for doing just that, too. We’ve reached out to the company for more detail and will update this post should we hear back. Lenovo confirms they ship preinstalled software that injects ads into sites including google https://t.co/DIDMrgw62z via @shaver – Adrienne Porter Felt (@__apf__) February 19, 2015 Filed under: Laptops , Internet , Lenovo Comments Via: Adrienne Porter Felt (Twitter) Source: Lenovo forums

Read More:
New Lenovo PCs shipped with factory-installed adware

Leader of webcam spying ring ‘Blackshades’ pleads guilty

The Blackshades spying hack group may have come crashing down with a bang last year, but its alleged leader is going considerably more quietly. Alex Yucel has pleaded guilty to charges that he distributed Blackshades’ remote control tool, which let creeps eavesdrop on webcams, track keyboard strokes and hold computers for ransom. Whether or not he faces a stiff penalty is still up in the air, however. Sentencing isn’t until May 22nd, but Yucel has already said he won’t appeal if he gets less than 7.25 years in prison. The court could easily throw the book at Yucel given that Blackshades violated the privacy of half a million people, but it may not be eager to spark a prolonged fight. [Image credit: Andrew Burton/Getty Images] Filed under: Internet Comments Source: Reuters

Continue Reading:
Leader of webcam spying ring ‘Blackshades’ pleads guilty

Linux has 2,000 new developers and gets 10,000 patches for each version

Nearly 2,000 developers started contributing to Linux in the past 15 months, making up nearly half of all developers writing code for the open source operating system kernel. The new developers are helping fuel an ever-bigger Linux community, according to the latest Linux Kernel Development report, which will be released today by the Linux Foundation. The report is expected to be available at this link . “The rate of Linux development is unmatched,” the foundation said in an announcement accompanying the report. “In fact, Linux kernel 3.15 was the busiest development cycle in the kernel’s history. This rate of change continues to increase, as does the number of developers and companies involved in the process. The average number of changes accepted into the kernel per hour is 7.71, which translates to 185 changes every day and nearly 1,300 per week. The average days of development per release decreased from 70 days to 66 days.” Read 16 remaining paragraphs | Comments

View article:
Linux has 2,000 new developers and gets 10,000 patches for each version

FreeBSD-Current Random Number Generator Broken

First time accepted submitter bobo the hobo writesThe FreeBSD random number has been discovered to be generating possibly predictable SSH keys and SSL certificates for months. Time to regenerate your keys and certs if using FreeBSD-Current. A message to the freebsd-current mailing list reads in part: “If you are running a current kernel r273872 or later, please upgrade your kernel to r278907 or later immediately and regenerate keys. I discovered an issue where the new framework code was not calling randomdev_init_reader, which means that read_random(9) was not returning good random data. read_random(9) is used by arc4random(9) which is the primary method that arc4random(3) is seeded from.” Read more of this story at Slashdot.

View the original here:
FreeBSD-Current Random Number Generator Broken

Snow-Melting, No-Shovel Sidewalks and Driveways Sound Amazing

Yesterday in snowy Manhattan I fell on the sidewalk, like some kind of freaking invalid. Half of the sidewalk was covered in that blue-colored chemical salt. Since that burns my dogs’ paws, I was walking with them on the snow-covered half of the sidewalk—unaware that there was a layer of slippery ice underneath the powder. I went down like a soccer player trying to get a flag thrown. As my dogs stared at me with big eyes, I sat there in the snow, infomercial-style, thinking There’s got to be a better way! When it snows on my block, it’s up to whichever store owners are afraid of getting sued to shovel off the sidewalk in front of their businesses. Most do a feeble job and instead prefer to throw chemical salt. We residents then track this stuff inside our buildings, creating a disgusting slurry on our lobby floors. But there is a better way. Heated sidewalks! They have them in places like Iceland , Chicago , Utah , and in New York some businesses and luxury buildings pay top dollar to have them installed around their buildings. Couple years ago we even caught wind of a snow-melting footbridge in Sweden , and Holland has considered installing geothermal-powered snow-melting bike lanes. Geothermal power is probably what Iceland is using as well. But according to the links above, the heated sidewalks in use in Chicago and New York are fiendishly expensive to install and expensive to run, and probably not eco-friendly; some work by heating electrical wires beneath the sidewalks, others by running hot water through embedded pipes, like outdoor radiant-floor heating. Even more mind-blowing is that out in the suburbs, there are folks with heated driveways . Can you imagine? It snows, they flip a switch, and the driveway melts its own snow while the owner’s snowshovel sits untouched in a closet. Still, I know my building and my block will never get this technology. And as I wrote in the original post on the Swedish bridge, heated sidewalks would be impractical in New York, even aside from the cost. Because they’d be covered in sleeping homeless people. So for now, here’s my $17.29 solution:

See more here:
Snow-Melting, No-Shovel Sidewalks and Driveways Sound Amazing

Storing Data In Synthetic Fossils

Bismillah tips news of research from ETH Zurich which brings the possibility of extremely long-term data storage. The scientists encoded data in DNA, a young but established technique that has a major problem: accuracy. “[E]ven a short period of time presents a problem in terms of the margin of error, as mistakes occur in the writing and reading of the DNA. Over the longer term, DNA can change significantly as it reacts chemically with the environment, thus presenting an obstacle to long-term storage.” To get around this issue, they encapsulated the DNA within tiny silica spheres, a process roughly comparable to the fossilization of bones (abstract). The researchers say data can be preserved this way for over a million years. Read more of this story at Slashdot.

Read More:
Storing Data In Synthetic Fossils

HTTP/2 Finalized

An anonymous reader writes: Mark Nottingham, chair of the IETF HTTP working group, has announced that the HTTP/2 specification is done. It’s on its way to the RFC Editor, along with the HPACK specification, where it’ll be cleaned up and published. “The new standard brings a number of benefits to one of the Web’s core technologies, such as faster page loads, longer-lived connections, more items arriving sooner and server push. HTTP/2 uses the same HTTP APIs that developers are familiar with, but offers a number of new features they can adopt. One notable change is that HTTP requests will be ‘cheaper’ to make. … With HTTP/2, a new multiplexing feature allows lots of requests to be delivered at the same time, so the page load isn’t blocked.” Here’s the HTTP/2 FAQ, and we recently talked about some common criticisms of the spec. Read more of this story at Slashdot.

Continue reading here:
HTTP/2 Finalized

Breakthrough In Face Recognition Software

An anonymous reader writes: Face recognition software underwent a revolution in 2001 with the creation of the Viola-Jones algorithm. Now, the field looks set to dramatically improve once again: computer scientists from Stanford and Yahoo Labs have published a new, simple approach that can find faces turned at an angle and those that are partially blocked by something else. The researchers “capitalize on the advances made in recent years on a type of machine learning known as a deep convolutional neural network. The idea is to train a many-layered neural network using a vast database of annotated examples, in this case pictures of faces from many angles. To that end, Farfade and co created a database of 200, 000 images that included faces at various angles and orientations and a further 20 million images without faces. They then trained their neural net in batches of 128 images over 50, 000 iterations. … What’s more, their algorithm is significantly better at spotting faces when upside down, something other approaches haven’t perfected.” Read more of this story at Slashdot.

Read the original post:
Breakthrough In Face Recognition Software

Patent Troll Wins $15.7M From Samsung By Claiming To Own Bluetooth

An anonymous reader writes: A jury has upheld patent claims against Samsung and awarded the patent-holder $15.7 million. “The patents relate to compatibility between different types of modems, and connect to a string of applications going back to 1997. The first version of Bluetooth was invented by Swedish cell phone company Ericsson in 1994.” Lawyers for the plaintiff argue that the patents cover all devices that use Bluetooth 2.0 or later, so further cases could extend far beyond Samsung. Of course, the company that won the lawsuit wasn’t the one who made the invention, or the one who patented it. The company is Rembrandt IP, “one of the oldest and most successful” patent trolls. Read more of this story at Slashdot.

View post:
Patent Troll Wins $15.7M From Samsung By Claiming To Own Bluetooth