California Senate Defies FCC, Approves Net Neutrality Law

The California State Senate yesterday approved a bill to impose net neutrality restrictions on Internet service providers, challenging the Federal Communications Commission attempt to preempt such rules. From a report: The FCC’s repeal of its own net neutrality rules included a provision to preempt state and municipal governments from enforcing similar rules at the local level. But the governors of Montana and New York have signed executive orders to enforce net neutrality and several states are considering net neutrality legislation. The FCC is already being sued by t21 states and the District of Columbia, which are trying to reverse the net neutrality repeal and the preemption of state laws. Attempts to enforce net neutrality rules at the state or local level could end up being challenged in separate lawsuits. Read more of this story at Slashdot.

Read this article:
California Senate Defies FCC, Approves Net Neutrality Law

The World’s First 88-inch 8K OLED Display

From a report: Come CES, LG will be letting attendees get up close with its new 88-inch 8K OLED display, which is both the largest and the highest-resolution OLED panel to date. But as far as specs go, that’s all we have for now. Previously, the largest OLED screen size was 77 inches, and it “only” came in 4K. While this combination is currently offered to consumers by the likes of LG Electronics, Sony and Panasonic, they all source their large OLED panels from LG Display. Read more of this story at Slashdot.

See the article here:
The World’s First 88-inch 8K OLED Display

How Pirates Of The Caribbean Hijacked America’s Metric System

If the United States were more like the rest of the world, a McDonald’s Quarter Pounder might be known as the McDonald’s 113-Grammer, John Henry’s 9-pound hammer would be 4.08 kilograms, and any 800-pound gorillas in the room would likely weigh 362 kilos. NPR explores: One reason this country never adopted the metric system might be pirates. Here’s what happened: In 1793, the brand new United States of America needed a standard measuring system because the states were using a hodgepodge of systems. “For example, in New York, they were using Dutch systems, and in New England, they were using English systems, ” says Keith Martin, of the research library at the National Institute of Standards and Technology. This made interstate commerce difficult. The secretary of state at the time was Thomas Jefferson. Jefferson knew about a new French system and thought it was just what America needed. He wrote to his pals in France, and the French sent a scientist named Joseph Dombey off to Jefferson carrying a small copper cylinder with a little handle on top. It was about 3 inches tall and about the same wide. This object was intended to be a standard for weighing things, part of a weights and measure system being developed in France, now known as the metric system. The object’s weight was 1 kilogram. Crossing the Atlantic, Dombey ran into a giant storm. “It blew his ship quite far south into the Caribbean Sea, ” says Martin. And you know who was lurking in Caribbean waters in the late 1700s? Pirates. Read more of this story at Slashdot.

Taken from:
How Pirates Of The Caribbean Hijacked America’s Metric System

Microsoft Disables Word DDE Feature To Prevent Further Malware Attacks

An anonymous reader writes: As part of the December 2017 Patch Tuesday, Microsoft has shipped an Office update that disables the DDE feature in Word applications, after several malware campaigns have abused this feature to install malware. DDE stands for Dynamic Data Exchange, and this is an Office feature that allows an Office application to load data from other Office applications. For example, a Word file can update a table by pulling data from an Excel file every time the Word file is opened. DDE is an old feature, which Microsoft has superseded via the newer Object Linking and Embedding (OLE) toolkit, but DDE is still supported by Office applications. The December Patch Tuesday disables DDE only in Word, but not Excel or Outlook. The reason is that several cybercrime and spam groups have jumped on this technique, which is much more effective at running malicious code when compared to macros or OLE objects, as it requires minimal interaction with a UI popup that many users do not associate with malware. For Outlook and Excel, Microsoft has published instructions on how users can disable DDE on their own, if they don’t want this feature enabled. Read more of this story at Slashdot.

Continue reading here:
Microsoft Disables Word DDE Feature To Prevent Further Malware Attacks

Another Million Subscribers Cut the Pay TV Cord Last Quarter

A report from FierceCable says that a million more U.S. pay TV subscribers cut the TV cord last quarter. “Only five of the seven biggest pay TV providers have released their third quarter subscriber data, but collectively these companies saw a net loss of 632, 000 pay TV subscribers during the period (385, 000 for AT&T and DirecTV, 125, 000 for Comcast, 104, 000 for Charter, 18.000 for Verizon FiOS TV), ” reports DSLReports. “Dish has yet to report its own cord cutting tallies, but the company is again expected to be among the hardest hit due to a high level of retransmission fee feuds and a lack of broadband bundles.” Read more of this story at Slashdot.

Read the original post:
Another Million Subscribers Cut the Pay TV Cord Last Quarter

New VibWrite System Uses Finger Vibrations To Authenticate Users

An anonymous reader quotes a report from Bleeping Computer: Rutgers engineers have created a new authentication system called VibWrite. The system relies on placing an inexpensive vibration motor and receiver on a solid surface, such as wood, metal, plastic, glass, etc.. The motor sends vibrations to the receiver. When the user touches the surface with one of his fingers, the vibration waves are modified to create a unique signature per user and per finger. Rutgers researchers say that VibWrite is more secure when users are asked to draw a pattern or enter a code on a PIN pad drawn on the solid surface. This also generates a unique fingerprint, but far more complex than just touching the surface with one finger. During two tests, VibWrite verified users with a 95% accuracy and a 3% false positive rate. The only problem researchers encountered in the live trials was that some users had to draw the pattern or enter the PIN number several times before they passed the VibWrite authentication test. Besides improvements to the accuracy with which VibWrite can detect finger vibrations, researchers also plan to look into how VibWrite will behave in outdoor environments to account for varying temperatures, humidity, winds, wetness, dust, dirt, and other conditions. This new novel user authentication system is described in full in a research paper entitled “VibWrite: Towards Finger-input Authentication on Ubiquitous Surfaces via Physical Vibration.” Read more of this story at Slashdot.

View post:
New VibWrite System Uses Finger Vibrations To Authenticate Users

Ransomware Hack Targeting 2 Million an Hour

New submitter Zorro writes: A ransomware attack sweeping the globe right now is launching about 8, 000 different versions of the virus script at Barracuda’s customers, Eugene Weiss, lead platform architect at Barracuda, told Axios, and it’s hitting at a steady rate of about 2 million attacks per hour. What to watch out for: An incoming email spoofing the destination host, with a subject about “Herbalife” or a “copier” file delivery. Two of the latest variants Barracuda has detected include a paragraph about legalese to make it seem official, or a line about how a “payment is attached, ” which tricks you to click since, as Weiss puts it, “everyone wants a payment.” Read more of this story at Slashdot.

View the original here:
Ransomware Hack Targeting 2 Million an Hour

Backdoor Found In WordPress Plugin With More Than 200,000 Installations

According to Bleeping Computer, a WordPress plug that goes by the name Display Widgets has been used to install a backdoor on WordPress sites across the internet for the past two and a half months. While the WordPress.org team removed the plugin from the official WordPress Plugins repository, the plugin managed to be installed on more than 200, 000 sites at the time of its removal. The good news is that the backdoor code was only found between Display Widgets version 2.6.1 (released June 30) and version 2.6.3 (released September 2), so it’s unlikely everyone who installed the plugin is affected. WordPress.org staff members reportedly removed the plugin three times before for similar violations. Bleeping Computer has compiled a history of events in its report, put together with data aggregated from three different investigations by David Law, White Fir Design, and Wordfence. The report adds: The original Display Widgets is a plugin that allowed WordPress site owners to control which, how, and when WordPress widgets appear on their sites. Stephanie Wells of Strategy11 developed the plugin, but after switching her focus to a premium version of the plugin, she decided to sell the open source version to a new developer who would have had the time to cater to its userbase. A month after buying the plugin in May, its new owner released a first new version — v2.6.0 — on June 21. Read more of this story at Slashdot.

See the original post:
Backdoor Found In WordPress Plugin With More Than 200,000 Installations

Leaked memo says hackers may have compromised UK power plants

State-sponsored hackers have “probably compromised” the UK’s energy industry. A leaked memo from the National Cybersecurity Centre (NCSC) identifies links “from multiple UK IP addresses to infrastructure associated with advanced state-sponsored hostile threat actors.” These threats are “known to target the energy and manufacturing sectors, ” the document says. The memo, obtained by Motherboard and verified by a number of sources, goes on to say that as a result of these connections, “a number of industrial control system engineering and services organisations are likely to have been compromised.” The NCSC has neither confirmed nor denied the authenticity of the memo. However, in a statement given to the BBC it said: “We are aware of reports of malicious cyber-activity targeting the energy sector around the globe … We are liaising with our counterparts to better understand the threat and continue to manage any risks to the UK.” The leaked memo follows claims that Russian hackers have tried to infiltrate America’s nuclear power industry via phishing emails, as well as allegations that Ireland’s Electricity Supply Board has been targeted by groups with links to the Kremlin. These reports appear to be connected, suggesting there may be a large-scale effort brewing to identify vulnerabilities in global energy industry. It appears that despite the hack no actual damage has been done, but we’ve seen the consequences of cyberattacks on critical infrastructure — this development will no doubt call into question the effectiveness of national security once again. Via: The Guardian Source: Motherboard

Taken from:
Leaked memo says hackers may have compromised UK power plants

First insider build of Windows Server arrives with new virtualization features

Enlarge / Server administrator kaiju hates user password reset requests. (credit: Bandai Namco Entertainment America (CC) ) Back in May , Microsoft announced that Windows Server would be joining the Windows Insider Program. Late last night, the first preview release of Windows Server was published. The biggest areas of improvement in the new build are around virtualization and containers. The preview allows exposing more of the underlying hardware capabilities to virtual machines, with support for virtualized non-volatile memory and virtualized power/battery status. For both containers and virtual machines, networking capabilities have been enhanced to enable a wider range of virtual network capabilities with greater performance. The focus on containerization has also seen the Nano Server deployment of Windows Server change. Presently, Nano Server is still a full operating system, but with the Redstone 3 release of Windows later this year, that’s going to change. It’s going to be a strictly container-only deployment. Upgrading and maintaining Nano Server will be done through updating the container image. This has enabled Microsoft to strip down the Nano Server installation. It no longer requires, for example, the Windows servicing stack. Because it’s upgraded simply by replacing the image, Nano Server no longer needs to use Windows Update itself. The result is a 70 percent reduction in the image’s footprint. Read 3 remaining paragraphs | Comments

View article:
First insider build of Windows Server arrives with new virtualization features