HipChat resets all passwords after hackers break in

Today, Hipchat alerted its users that someone broke into one of its servers through a vulnerability in a third-party library. The chat service saw no evidence that other Atlassian systems or products like Jira or Trello were affected, but they’re forcing every user to reset their HipChat-connected account password as a precaution. According to the service’s blog post , the attacker might have gotten access to user information (including name, email and hashed password) of anyone using HipChat.com. There’s been no sign that over 99 percent of users’ messages or room content was compromised, though the attacker could have accessed that portion’s metadata. A small fraction (.05 percent) of instances might have been wide open to the hacker, who would have been able to see correspondence and content. Fortunately, no evidence has suggested that the attacker has accessed anyone’s financial or credit card information. “While HipChat Server uses the same third-party library, it is typically deployed in a way that minimizes the risk of this type of attack, ” the blog post said, but the service will roll a security update out for Hipchat Server just to be sure. Source: HipChat

View article:
HipChat resets all passwords after hackers break in

BrickerBot, the permanent denial-of-service botnet, is back with a vengeance

Enlarge (credit: BoatingWithTR.com ) BrickerBot, the botnet that permanently incapacitates poorly secured Internet of Things devices before they can be conscripted into Internet-crippling denial-of-service armies, is back with a new squadron of foot soldiers armed with a meaner arsenal of weapons. Pascal Geenens, the researcher who first documented what he calls the permanent denial-of-service botnet, has dubbed the fiercest new instance BrickerBot.3. It appeared out of nowhere on April 20, exactly one month after BrickerBot.1 first surfaced. Not only did BrickerBot.3 mount a much quicker number of attacks—with 1,295 attacks coming in just 15 hours—it used a modified attack script that added several “fork bomb” commands designed to more completely shock and awe its targets. BrickerBot.1, by comparison, fired 1,895 volleys during the four days it was active, and the still-active BrickerBot.2 has spit out close to 12 attacks per day. “Just like BrickerBot.1, this attack was a short but intense burst,” Geenens told Ars. “Shorter than the four days BrickerBot.1 lasted, but even more intense. The attacks from BrickerBot.3 came in on a different honeypot than the one that recorded BrickerBot.1. There is, however, no correlation between the devices used in the previous attack versus the ones in this attack.” Read 5 remaining paragraphs | Comments

Read the original:
BrickerBot, the permanent denial-of-service botnet, is back with a vengeance

Disney’s projection tech turns actors’ faces into nightmare fuel

Disney is taking scary clown makeup to the next level. It’s using a new projection system to transform the appearance of actors during live performances, tracking facial expressions and “painting” them with light, rather than physical makeup. Called Makeup Lamps, the system was developed by a team at Disney Research, and it could potentially change the way stage makeup is used in future theater productions. Makeup Lamps tracks an actor’s movements without using the facial markers common in motion capture, then it displays any color or texture the actor wants by adjusting the lighting. It can make someone appear older by creating “wrinkles” on their face, for example, or it can paint their face in creepy clown makeup, à la Heath Ledger in The Dark Knight . And all of it is done in real-time. A similar technology was used earlier this year during Lady Gaga’s performance at the Superbowl. Nobumichi Asai, creative director of Japanese visual studio WOW, was brought in to create a red lightning bolt on Gaga’s face during her David Bowie tribute. The attention that performance received has helped the technology become more mainstream. Latency — the time between generating an image that matches the actor’s pose and when the image is displayed — is a big challenge to live augmentation, of course. Large amounts of it will cause the projection and the actor’s face to appear out of sync. Disney’s research team combated this problem by limiting the complexity of its algorithms and employing a method called Kalman filtering, which uses measurements over time to make predictions and minor adjustments. “We’ve seen astounding advances in recent years in capturing facial performances of actors and transferring those expressions to virtual characters, ” said Markus Gross, vice president at Disney Research. “Leveraging these technologies to augment the appearance of live actors is the next step and could result in amazing transformations before our eyes of stage actors in theaters or other venues.” Source: EurekAlert

See the original article here:
Disney’s projection tech turns actors’ faces into nightmare fuel

Second Handwritten Copy of the Declaration of Independence Discovered in England

Harvard researchers have discovered a parchment manuscript of the Declaration of Independence at a small archive office in the United Kingdom. Only the second parchment copy known to exist, it contains several features that mark it as distinct from the original. Read more…

View article:
Second Handwritten Copy of the Declaration of Independence Discovered in England

Intel’s Optane Memory Makes Cheap Hard Drives as Fast as Expensive SSDs

It isn’t only the junk processor that makes a really cheap computer slow. Or the memory or the video card (or lack of video card). The primary reason your cheap laptop loudly chugs along at glacial speeds is because of the hard drive. Cheap laptops use cheap hard disk drives, which are much slower than the solid state… Read more…

More:
Intel’s Optane Memory Makes Cheap Hard Drives as Fast as Expensive SSDs

WikiLeaks Releases New CIA Secret: Tapping Microphones On Some Samsung TVs

FossBytes reports: The whistleblower website Wikileaks has published another set of hacking tools belonging to the American intelligence agency CIA. The latest revelation includes a user guide for CIA’s “Weeping Angel” tool… derived from another tool called “Extending” which belongs to UK’s intelligence agency MI5/BTSS, according to Wikileaks. Extending takes control of Samsung F Series Smart TV. The highly detailed user guide describes it as an implant “designed to record audio from the built-in microphone and egress or store the data.” According to the user guide, the malware can be deployed on a TV via a USB stick after configuring it on a Linux system. It is possible to transfer the recorded audio files through the USB stick or by setting up a WiFi hotspot near the TV. Also, a Live Liston Tool, running on a Windows OS, can be used to listen to audio exfiltration in real-time. Wikileaks mentioned that the two agencies, CIA and MI5/BTSS made collaborative efforts to create Weeping Angel during their Joint Development Workshops. Read more of this story at Slashdot.

Read the original post:
WikiLeaks Releases New CIA Secret: Tapping Microphones On Some Samsung TVs

Microsoft Will Support Python In SQL Server 2017

There was a surprise in the latest Community Technology Preview release of SQL Server 2017. An anonymous reader quotes InfoWorld: Python can now be used within SQL Server to perform analytics, run machine learning models, or handle most any kind of data-powered work. This integration isn’t limited to enterprise editions of SQL Server 2017, either — it’ll also be available in the free-to-use Express edition… Microsoft has also made it possible to embed Python code directly in SQL Server databases by including the code as a T-SQL stored procedure. This allows Python code to be deployed in production along with the data it’ll be processing. These behaviors, and the RevoScalePy package, are essentially Python versions of features Microsoft built for SQL Server back when it integrated the R language into the database… An existing Python installation isn’t required. During the setup process, SQL Server 2017 can pull down and install its own edition of CPython 3.5, the stock Python interpreter available from the Python.org website. Users can install their own Python packages as well or use Cython to generate C code from Python modules for additional speed. Except it’s not yet available for Linux users, according to the article. “Microsoft has previously announced SQL Server would be available for Linux, but right now, only the Windows version of SQL Server 2017 supports Python.” Read more of this story at Slashdot.

See more here:
Microsoft Will Support Python In SQL Server 2017

‘Avatar’ sequels start arriving on December 18th, 2020

James Cameron has spent years drumming up hype for his Avatar sequels with little to show for it (the first sequel was originally due this December). However, his team is finally ready to commit to specific release dates — for all the new movies. The production team has revealed that Avatar 2 should arrive on December 18th, 2020, with the rest staggered throughout the next few years. The third movie is slated for December 17th, 2021. There will be a 3-year gap between that and the fourth movie, which debuts on December 20th, 2024. The fifth and final (?) title will appear on December 19th, 2025, 16 years after the first. Cameron and crew have started “concurrent” production of the sequels, which are poised to make cases for both high frame rate video as well as Avatar ‘s signature blend of CG with real-world acting. In theory, this gives the team a better sense of the timing than it might have if it was taking a serial approach. With that said, you may still want to take these dates with a grain of salt. It’s not just that the releases have been pushed back in the past, it’s that the scope has changed over time. Cameron added a fourth sequel to the mix just in 2016, so it won’t be surprising if the schedule shifts due to further creative changes or unforeseen challenges. Really, the big news is simply that the director is getting the ball rolling after years of prep — the dates just give you a rough idea of what to expect. Via: Variety Source: Avatar (Facebook)

See the article here:
‘Avatar’ sequels start arriving on December 18th, 2020

Anbox Can Run Android Apps Natively On Linux (In A Container)

Slashdot user #1083, downwa, writes: Canonical engineer Simon Fels has publicly released an Alpha version of Anbox. Similar to the method employed for Android apps on ChromeOS, Anbox runs an entire Android system (7.1.1 at present) in an LXC container. Developed over the last year and a half, the software promises to seamlessly bring performant Android apps to the Linux desktop. After installing Anbox (based on Android 7.1.1) and starting Anbox Application Manager, ten apps are available: Calculator, Calendar, Clock, Contacts, Email, Files, Gallery, Music, Settings, and WebView. Apps run in separate resizeable windows. Additional apps (ARM-native binaries are excluded) can be installed via adb. Installation currently is only supported on a few Linux distributions able to install snaps. Contributions are welcome on Github. In a blog post Simon describes it as “a side project” that he’s worked on for over a year and a half. “There were quite a few problems to solve on the way to a really working implementation but it is now in a state that it makes sense to share it with a wider audience.” Read more of this story at Slashdot.

Read the original post:
Anbox Can Run Android Apps Natively On Linux (In A Container)

Internet Archive to ignore robots.txt directives

Robots (or spiders, or crawlers) are little computer programs that search engines use to scan and index websites. Robots.txt is a little file placed on webservers to tell search engines what they should and shouldn’t index. The Internet Archive isn’t a search engine, but has historically obeyed exclusion requests from robots.txt files. But it’s changing its mind, because robots.txt is almost always crafted with search engines in mind and rarely reflects the intentions of domain owners when it comes to archiving. Over time we have observed that the robots.txt files that are geared toward search engine crawlers do not necessarily serve our archival purposes. Internet Archive’s goal is to create complete “snapshots” of web pages, including the duplicate content and the large versions of files. We have also seen an upsurge of the use of robots.txt files to remove entire domains from search engines when they transition from a live web site into a parked domain, which has historically also removed the entire domain from view in the Wayback Machine. In other words, a site goes out of business and then the parked domain is “blocked” from search engines and no one can look at the history of that site in the Wayback Machine anymore. We receive inquiries and complaints on these “disappeared” sites almost daily. A few months ago we stopped referring to robots.txt files on U.S. government and military web sites for both crawling and displaying web pages (though we respond to removal requests sent to info@archive.org). As we have moved towards broader access it has not caused problems, which we take as a good sign. We are now looking to do this more broadly. An excellent decision. To be clear, they’re ignoring robots.txt even if you explicitly identify and disallow the Internet Archive. It’s a splendid remember that nothing published on the web is ever meaningfully private, and will always go on your permanent record.

Read the original post:
Internet Archive to ignore robots.txt directives