Marcel Lazar, better known as Guccifer, the hacker who terrorized politicians in 2013, pled guilty to various computer crimes in May. Today, he was sentenced to 52 months in prison. Read more…
Marcel Lazar, better known as Guccifer, the hacker who terrorized politicians in 2013, pled guilty to various computer crimes in May. Today, he was sentenced to 52 months in prison. Read more…
River Tam quotes a report from CSO Australia: Enterprise access management firm OneLogin has suffered an embarrassing breach tied to a single employee’s credentials being compromised. OneLogin on Tuesday revealed the breach affected a feature called Secure Notes that allowed its users to “store information.” That feature however is pitched to users as a secure way to digitally jot down credentials for access to corporate firewalls and keys to software product licenses. The firm is concerned Secure Notes was exposed to a hacker for at least one month, though it may have been from as early as July 2 through to August 25, according to a post by the firm. Normally these notes should have been encrypted using “multiple levels of AES-256 encryption, ” it said in a blog post. Several thousand enterprise customers, including high profile tech startups, use OneLogin for single sign-on to access enterprise cloud applications. The company has championed the SAML standard for single sign-on and promises customers an easy way to enable multi-factor authentication from devices to cloud applications. But it appears the company wasn’t using multi-factor authentication for its own systems. OneLogin’s CISO Alvaro Hoyos said a bug in its software caused Secure Notes to be “visible in our logging system prior to being encrypted and stored in our database.” The firm later found out that an employees compromised credentials were used to access this logging system. The company has since fixed the bug on the same day it detected the bug. CSO adds that the firm “also implemented SAML-based authentication for its log management system and restricted access to a limited set of IP addresses.” Read more of this story at Slashdot.
Excerpt from:
Staff Breach At OneLogin Exposes Password Storage Feature
More devices are starting to ship with USB-C connectors built-in, and today groups behind HDMI and USB announced another way to take advantage of it. That method is HDMI Alt Mode, which means cable manufacturers can build a connector that plugs directly from the port on your phone, laptop or other device into the HDMI port on a TV or monitor. With this spec, there’s no additional dongle or adapter needed in the middle. It’s all pretty simple, with just a USB Type-C cable on one end, HDMI on the other, but there are a couple of drawbacks. It supports the older HDMI 1.4b spec instead of the newer HDMI 2.0b . What that means for you is that while 4K video, 3D, HDMI-CEC and Audio Return Channel are all supported , it won’t be quite enough to send the newest Ultra HD 4K video with HDR . That’s probably not an issue if you’re just trying to play a video or two from your phone, but it’s good to know.
See the original article here:
Get ready for simple USB-C to HDMI cables
Want to know why phishing continues to be one of the most common security issue? Half of the people will click on anything without thinking twice ArsTechnica reports: A study by researchers at a university in Germany found that about half of the subjects in a recent experiment clicked on links from strangers in e-mails and Facebook messages — even though most of them claimed to be aware of the risks. The researchers at the Friedrich-Alexander University (FAU) of Erlangen-Nuremberg, Germany, led by FAU Computer Science Department Chair Dr Zinaida Benenson, revealed the initial results of the study at this month’s Black Hat security conference. Simulated “spear phishing” attacks were sent to 1, 700 test subjects — university students — from fake accounts. The e-mail and Facebook accounts were set up with the ten most common names in the age group of the targets. The Facebook profiles had varying levels of publicly accessible profile and timeline data — some with public photos and profile photos, and others with minimal data. The messages claimed the links were to photos taken at a New Year’s Eve party held a week before the study. Two sets of messages were sent out: in the first, the targets were addressed by their first name; in the second, they were not addressed by name, but more general information about the event allegedly photographed was given. Links sent resolved to a webpage with the message “access denied, ” but the site logged the clicks by each student. Read more of this story at Slashdot.
More here:
Half Of People Click Anything Sent To Them
Earlier this month, Leoni AG, one of the world’s largest manufacturers of wires and electrical cables, informed investors that the German company lost almost 40 million euros (or about $44.6 million) to online scammers. Today, we finally know how: According to investigators, the thieves simply spoofed emails to look like official payment requests, a tactic known as “ CEO fraud .” Read more…
Continued here:
An Email Scam Cost One of Europe’s Biggest Companies $40 Million
Enlarge / A Redflex red light camera at the intersection of Sylvan and Coffee in Modesto, California as seen in 2013. (credit: Cyrus Farivar) A former Chicago transportation official has been sentenced to a decade in prison. He was found guilty in January on 20 counts of mail and wire fraud , bribery, extortion, and many other charges stemming from a corrupt contract involving Redflex, a major red light camera company. During the Monday hearing, US District Judge Virginia M. Kendall also ordered John Bills to pay over $2 million in restitution. According to the Chicago Tribune , “Bills’ voice broke with emotion as he acknowledged ‘ethical and moral’ mistakes, but he denied masterminding the massive bribery scheme in exchange for growing the city’s controversial network of red light cameras into the largest in the nation.” As Ars has reported previously, Bills, who was the managing deputy commissioner at the Department of Transportation, helped steer a lucrative city contract to Redflex. After Bills urged his colleagues to approve the deal, the city hired the embattled Australian firm to provide automated enforcement cameras, known formally as its Digital Automated Red Light Enforcement Program (DARLEP), from October 2003 until February 2013. Read 4 remaining paragraphs | Comments
See original article:
Chicago official gets 10 years for role in dirty red light camera deal
At IFA in Berlin Lenovo announced a nice array of refreshed laptops and tablets, updating great devices like the Lenovo Yoga 900 series (now the Lenovo 910) with 7th generation Intel processors, but one device stood out among the rest. It’s the tiniest laptop Lenovo has on display, so tiny the company is classifying it as a tablet. The Lenovo Book is just 0.38-inches thick, which makes it the thinnest laptop currently available, and makes ultra slims like the half-inch thick Samsung Notebook 9 and Apple Macbook look positively chunky. Read more…
Read More:
The Thinnest Laptop in the World Needs a Touchscreen Keyboard
Your standard inkjet printer can mostly handle paper, occasionally transparencies, and maybe even blank DVDs while they were still a thing. But Xerox just revealed a towering machine it calls the Direct to Object Inkjet Printer because that’s exactly what it does—it prints on almost any 3D object. Read more…
Since Edward Snowden stepped into the limelight from a hotel room in Hong Kong three years ago, use of the Tor anonymity network has grown massively. Journalists and activists have embraced the anonymity the network provides as a way to evade the mass surveillance under which we all now live, while citizens in countries with restrictive Internet censorship, like Turkey or Saudi Arabia, have turned to Tor in order to circumvent national firewalls. Law enforcement has been less enthusiastic, worrying that online anonymity also enables criminal activity. Tor’s growth in users has not gone unnoticed, and today the network first dubbed “The Onion Router” is under constant strain from those wishing to identify anonymous Web users. The NSA and GCHQ have been studying Tor for a decade, looking for ways to penetrate online anonymity, at least according to these Snowden docs . In 2014, the US government paid Carnegie Mellon University to run a series of poisoned Tor relays to de-anonymise Tor users. A 2015 research paper outlined an attack effective, under certain circumstances, at decloaking Tor hidden services (now rebranded as “onion services”). Most recently, 110 poisoned Tor hidden service directories were discovered probing .onion sites for vulnerabilities, most likely in an attempt to de-anonymise both the servers and their visitors. Who can forget the now-famous “Tor stinks” slide that was part of the Snowden trove of leaked docs. Cracks are beginning to show; a 2013 analysis by researchers at the US Naval Research Laboratory (NRL), who helped develop Tor in the first place, concluded that “80 percent of all types of users may be de-anonymised by a relatively moderate Tor-relay adversary within six months.” Read 62 remaining paragraphs | Comments
Read the article:
Building a new Tor that can resist next-generation state surveillance
Tile , which raised over a million dollars on Kickstarter over three years ago, is a popular Bluetooth tracker that helps you find your missing stuff. Aside from Bluetooth, it also uses a crowd-finding feature where other Tile app users can ping you the whereabouts of a Tile that’s out of Bluetooth range. There was an update last year to Tile 2.0 , which has a louder alarm plus it’ll help find your phone as well. The problem with the existing Tile, however, is that it’s a little chunky. That’s why Tile has now introduced the Tile Slim, a much thinner version of the tracker that’ll fit more comfortably in tight spots like wallets and passport holders. But that’s not all. Tile has also announced a new initiative that just might bring Tile’s location-finding smarts to anything and everything. But let’s talk about the Slim first. As the name suggests, it is a lot wider and flatter than the original Tile, measuring 54 by 54 by 2.4mm (or as Tile says, about the width of two credit cards). The design is also a touch different. There’s a center Tile logo doubling as the button while the rest of the Slim surface has a pleasant embossed pattern. The rear is all grey, with a tiny cavity where the sound can get through. Unlike the original Tile however, there’s no loop, so you can’t use it as a keychain. But that’s because the Slim wasn’t designed to replace the original Tile; it’s just another product in the Tile stable. So you can have the original Tile for your keys, say, and the Slim for your wallet. I’ve used the original Tile with my wallet for over a year now, and it’s always left a pretty sizable dent. I switched to the Slim a few days ago and now I can barely tell it’s there. If you want, you can also adhere it to your laptop, your tablet, your ID badge or any place where a slim profile is key. Another feature that sets the Slim apart is that you can select one of four different ringtones for the alert. They’re called Bionic Birdie, Classic Call, Pep in your Step and Blues for Slim. This capability is only for the Slim and is mostly just for fun, though it could prove useful if you have multiple Tile trackers and want a way to differentiate them. To coincide with the announce of the Slim is also a redesigned app. It’s mostly just a brighter reskin to match the company’s current branding, but there’s also now a slightly different flow when adding new Tiles. It’ll ask you which Tile you’re adding — the Slim or the classic — and then it’ll coach you through the rest of the activation process. Slim works a lot like the original Tile, but here’s a brief primer in case you need a reminder on how it works. Once you’ve associated and attached a Tile tracker with an object — say your keys or your wallet — you can now use the app to find it. If the item is within Bluetooth range, the app will show it with a green circle. Tap it and the tracker will emit an alarm. If it isn’t, it’ll show you the location where it was last seen, so you can retrace your steps to look for it. Either that or you can select “Notify when Found, ” where it’ll now turn to the aforementioned crowd-finding feature to help you find it. If anyone with the Tile app running goes near the object, you’ll then get a location ping. There are around 6 million Tiles on the market in over 200 countries, so chances are pretty good that this will happen. The Slim will retail for $30/£30 each, which is $5/£10 more than the original. You can also pay $100/£95 for a 4-pack. The Slim has a guaranteed battery life of a year. We should note that, just like all the other Tiles, the battery is not replaceable — if the juice is running out, the app will let you know that you should replace it. The company does offer something called a reTile discount program that’ll let you replace your existing Tile with a new one at a discounted rate. So instead of paying $30 for a new Slim, you could just pay $21 to replace the old one. But imagine if you don’t need to buy a Tile at all. Imagine if that same Tile location-tracking smarts was simply just built into whatever it is that you don’t want to lose. That is the idea behind Tile’s other big announcement today: The Tile Platform. “We want to blanket the world in smart location, ” says Mike Farley, Tile’s CEO and co-founder. “Everything that moves should have smart location built into it.” So with that concept in mind, Tile is kicking off the Platform announcement today with three partners: EcoReco, an electric scooter company; Nomad, which makes a variety of backup battery packs and power banks; and Zillion, a maker of smartphone wallets with that battery pack built right in. Starting today, all three of these companies will start offering products with the Tile Platform. That means you would be able to use the Tile app to locate, say, a missing EcoReco scooter or a Nomad battery pack. Just add them to the app like you would with a Tile tracker and you can find them in the same way. Tile has already partnered with Land Rover to build the tech into the 2017 Discovery Sport . Eventually, Farley says he wants the Tile Platform to be in even more things. “Any product that’s mobile is fair game, ” he says. “The lowest hanging fruit is if it has Bluetooth in it already.” So, a pair of Bluetooth headphones would be ideal, or a fitness tracker like a Fitbit, or maybe a smartwatch. In the future, he could even see the Tile tech integrated into everyday items like a remote control, a car’s key fob, or perhaps a regular pair of glasses. “We spend so much time every day finding misplaced stuff. That doesn’t even factor in the cost and time it takes to replace them, nor the stress and anxiety, ” says Farley. “Our vision is that the world will be a simpler and happier place when the world has smart location.”
Read the original post:
Tile’s slimmest Bluetooth tracker won’t bulk up your wallet