There’s no pumpkin in “100% canned pumpkin”

Pumpkin is too watery and stringy to can, and the USDA has an exceptionally loosey-goosey definition of “pumpkin,” which allows manufacturers to can various winter squash varieties (including one that Libby’s specially bred to substitute for pumpkin) and call it “100% pumpkin.” (more…)

View original post here:
There’s no pumpkin in “100% canned pumpkin”

Student Suspended for Posting Photo of Nasty School Water Online

When teens get in trouble for posting things online, there’s often something nefarious afoot, like drunken antics, offensive behavior, or criminal activity. But for one high school student, publicly calling out her school’s nasty water situation was apparently enough to do the trick. Read more…

Continued here:
Student Suspended for Posting Photo of Nasty School Water Online

California Launches Mandatory Data Collection For Police Use-of-Force

An anonymous Slashdot reader quotes the AP: All 800 police departments in California must begin using a new online tool launched Thursday to report and help track every time officers use force that causes serious injuries… The tool, named URSUS for the bear on California’s flag, includes fields for the race of those injured and the officers involved, how their interaction began and why force was deemed necessary. “It’s sort of like TurboTax for use-of-force incidents, ” said Justin Erlich, a special assistant attorney general overseeing the data collection and analysis. Departments must report the data under a new state law passed last November. Though some departments already tracked such data on their own, many did not… “As a country, we must engage in an honest, transparent, and data-driven conversation about police use of force, ” California Attorney General Kamala Harris said in a news release. It’s an open source tool developed by Bayes Impact, and California plans to share the code with other interested law enforcement agencies across the country. Only three other states currently require their police departments to track data about use-of-force incidents, “but their systems aren’t digital, and in Colorado’s case, only capture shootings.” Read more of this story at Slashdot.

More here:
California Launches Mandatory Data Collection For Police Use-of-Force

Security writer recovers from massive revenge cyberattack

Journalists are no stranger to making enemies bent on retaliation. However, it’s becoming increasingly difficult to survive that retaliation in internet era… just ask security writer Brian Krebs. An unknown party knocked his website offline last week with a massive distributed denial of service attack (620Gbps of non-stop data) as revenge for exposing two major cyberattack sellers who’ve since been arrested. He’s only back online after taking advantage of Google’s Project Shield , which protects journalists against censorship-oriented denial of service campaigns. His previous anti-DDoS provider, Akamai, had little choice but to drop him — the company tells the Boston Globe that a sustained attack on that level would have cost the company “millions.” The campaign might not have required an elaborate effort, either. Krebs believes that the attackers took advantage of a botnet made up of hacked Internet of Things devices like DVRs, home internet routers and security cameras , many of which have poor or even unchangeable passwords. A larger attack recently played havoc with a French web host using similar tactics. There’s also the chance that the culprits used spoofing, which magnifies attacks by tricking machines into sending reply messages to the victim. To Krebs, the incident highlights the dangers to free speech in the modern era. It’s not just that it’s relatively trivial to mount a censorship campaign, it’s that the cost of defending yourself against that campaign can be prohibitive. One anti-DDoS service estimated that an Akamai-level defense would cost Krebs over $150, 000 per year. How could any small-scale news outfit afford that kind of protection? A concerted effort to clamp down on device exploits and block spoofed traffic could be vital not just to improving basic internet security, but protecting freedom of expression. Countries with a penchant for censorship can easily use these data floods to silence critics, and they might just try so long as it’s easy. Source: Krebs on Security , Boston Globe

Read More:
Security writer recovers from massive revenge cyberattack

Spam Hits Its Highest Level Since 2010

Long-time Slashdot reader coondoggie quotes Network World: Spam is back in a big way — levels that have not been seen since 2010 in fact. That’s according to a blog post from Cisco Talos that stated the main culprit of the increase is largely the handiwork of the Necurs botnet… “Many of the host IPs sending Necurs’ spam have been infected for more than two years. “To help keep the full scope of the botnet hidden, Necurs will only send spam from a subset of its minions… This greatly complicates the job of security personnel who respond to spam attacks, because while they may believe the offending host was subsequently found and cleaned up, the reality is that the miscreants behind Necurs are just biding their time, and suddenly the spam starts all over again.” Before this year, the SpamCop Block List was under 200, 000 IP addresses, but surged to over 450, 000 addresses by the end of August. Interestingly, Proofpoint reported that between June and July, Donald Trump’s name appeared in 169 times more spam emails than Hillary Clinton’s. Read more of this story at Slashdot.

Read more here:
Spam Hits Its Highest Level Since 2010

iOS 10.0.2 update fixes bugs in headphones, Photos

Even if you’ve already updated to iOS 10 , Apple has released its first official update for its mobile/TV operating system. Bugs that could shut down the Photos app when turning on iCloud Photo Library and disable app extensions have ben smushed, but folks with the iPhone 7 or iPhone 7 Plus may want it for another reason. Some users complained about the new Lightning-connected EarPods timing out, which would stop their in-line playback controls from working to adjust the volume, answer calls or use Siri. This update fixes the problem, making things just like they were when your phone had a headphone jack . Of course, you’re probably beta testing iOS 10.1 already , looking forward to new features instead of stable builds with bugfixes . Either way, the current update should be accessible via your Settings menu now. Via: 9to5Mac , MacRumors Source: Apple

Taken from:
iOS 10.0.2 update fixes bugs in headphones, Photos

Why the Silencing of KrebsOnSecurity Opens a Troubling Chapter For the Internet

An anonymous reader quotes a report from Ars Technica: For the better part of a day, KrebsOnSecurity, arguably the world’s most intrepid source of security news, has been silenced, presumably by a handful of individuals who didn’t like a recent series of exposes reporter Brian Krebs wrote. The incident, and the record-breaking data assault that brought it on, open a troubling new chapter in the short history of the Internet. The crippling distributed denial-of-service attacks started shortly after Krebs published stories stemming from the hack of a DDoS-for-hire service known as vDOS. The first article analyzed leaked data that identified some of the previously anonymous people closely tied to vDOS. It documented how they took in more than $600, 000 in two years by knocking other sites offline. A few days later, Krebs ran a follow-up piece detailing the arrests of two men who allegedly ran the service. A third post in the series is here. On Thursday morning, exactly two weeks after Krebs published his first post, he reported that a sustained attack was bombarding his site with as much as 620 gigabits per second of junk data. That staggering amount of data is among the biggest ever recorded. Krebs was able to stay online thanks to the generosity of Akamai, a network provider that supplied DDoS mitigation services to him for free. The attack showed no signs of waning as the day wore on. Some indications suggest it may have grown stronger. At 4 pm, Akamai gave Krebs two hours’ notice that it would no longer assume the considerable cost of defending KrebsOnSecurity. Krebs opted to shut down the site to prevent collateral damage hitting his service provider and its customers. The assault against KrebsOnSecurity represents a much greater threat for at least two reasons. First, it’s twice the size. Second and more significant, unlike the Spamhaus attacks, the staggering volume of bandwidth doesn’t rely on misconfigured domain name system servers which, in the big picture, can be remedied with relative ease. The attackers used Internet-of-things devices since they’re always-connected and easy to “remotely commandeer by people who turn them into digital cannons that spray the internet with shrapnel.” “The biggest threats as far as I’m concerned in terms of censorship come from these ginormous weapons these guys are building, ” Krebs said. “The idea that tools that used to be exclusively in the hands of nation states are now in the hands of individual actors, it’s kind of like the specter of a James Bond movie.” While Krebs could retain a DDoS mitigation service, it would cost him between $100, 000 and $200, 000 per year for the type of protection he needs, which is more than he can afford. What’s especially troubling is that this attack can happen to many other websites, not just KrebsOnSecurity. Read more of this story at Slashdot.

Visit link:
Why the Silencing of KrebsOnSecurity Opens a Troubling Chapter For the Internet

Street Fighter V will roll back request for kernel access on Windows [Updated]

Enlarge / No, not really, Capcom. (credit: Aurich Lawson) On Thursday, Street Fighter V ‘s first “season” concluded with a downloadable update that included the game’s 22nd fighting character. (If you’re curious: the new guy is Urien, a tall fellow who first appeared in Street Fighter III wearing only a thong.) But the download updated more than just the game’s roster. It also brought apparent sweeping changes to the PC version—which now demands kernel access from players before every single boot of the game. Windows’ User Account Control (UAC) system warns computer users when an application wants to write or delete sensitive files, and, in the case of PC games, you typically only see these warnings during installations. SFV’s Thursday patch, however, apparently includes “an updated anti-crack solution” that Capcom insists is “not DRM” but rather an anti-cheating protocol. The anti-crack solution is causing a UAC prompt to pop up for the PC version’s users. (Our own Aurich Lawson confirmed the news by booting the latest patched version; his Windows prompt appears above.) Unfortunately, Capcom’s public-facing messages about PC version “hacks” have not been about cheats but about players finding workarounds to unlocking in-game content. In July, Capcom issued a stern warning to any PC player who found alternate ways to unlock  Street Fighter ‘s alternate costumes, which normally require grinding through the game’s lengthy “survival” modes. Capcom producers also condemned PC players who used characters hidden in that game’s version before they were officially released. Thursday’s patch notes mentioned that the new anti-crack solution is particularly targeted at “illicitly obtaining in-game currency and other entitlements” (so it’s, you know, DRM). Read 3 remaining paragraphs | Comments

Taken from:
Street Fighter V will roll back request for kernel access on Windows [Updated]

People Are Drilling Holes Into Their iPhone 7 To ‘Make a Headphone Jack’

TechRax — a popular YouTuber who destroys technology for fame and riches — has uploaded a video where he drills a hole into an iPhone 7, claiming it to be a “secret hack” to reinstall a headphone jack in the device. The only problem is that he didn’t tell people it was a joke, and of course, some people fell for it. Crave Online reports: The YouTube video has amassed over 7.5 million views since being posted online last week, with it attracting 81, 000 dislikes in the process. The comments section is currently torn between people who are in on the joke, people who criticize TechRax for damaging his iPhone 7, and most unfortunately, people who have tried the “hack” out for themselves. Although this is YouTube so you can never be quite sure of whether or not these folks are trolling, parsing the comments section reveals some pretty convincing complaints lobbed in TechRax’s direction. It’s also firmly believable that there are people dumb enough to attempt drilling a hole into their iPhone 7, which is unfortunate but that’s the way the world is in 2016. You can read the comments under the YouTube video for more “convincing complaints.” But as if the report didn’t make it clear enough already, the video is a joke. Apple removed the headphone jack and there’s no way to get it back, unless you use an adapter. Read more of this story at Slashdot.

More:
People Are Drilling Holes Into Their iPhone 7 To ‘Make a Headphone Jack’

Probe Of Leaked US NSA Hacking Tools Examines Operative’s Mistake

Joseph Menn and John Walcott, reporting for Reuters: A U.S. investigation into a leak of hacking tools used by the National Security Agency is focusing on a theory that one of its operatives carelessly left them available on a remote computer and Russian hackers found them, four people with direct knowledge of the probe told Reuters. The tools, which enable hackers to exploit software flaws in computer and communications systems from vendors such as Cisco Systems and Fortinet Inc, were dumped onto public websites last month by a group calling itself Shadow Brokers. The public release of the tools coincided with U.S. officials saying they had concluded that Russia or its proxies were responsible for hacking political party organizations in the run-up to the Nov. 8 presidential election. On Thursday, lawmakers accused Russia of being responsible. Various explanations have been floated by officials in Washington as to how the tools were stolen. Some feared it was the work of a leaker similar to former agency contractor Edward Snowden, while others suspected the Russians might have hacked into NSA headquarters in Fort Meade, Maryland. Read more of this story at Slashdot.

Continued here:
Probe Of Leaked US NSA Hacking Tools Examines Operative’s Mistake