NIST’s Draft To Remove Periodic Password Change Requirements Gets Vendors’ Approval

An anonymous reader writes: A recently released draft of the National Institute of Standards and Technology’s digital identity guidelines has met with approval by vendors. The draft guidelines revise password security recommendations and altering many of the standards and best practices security professionals use when forming policies for their companies. The new framework recommends, among other things: “Remove periodic password change requirements.” There have been multiple studies that have shown requiring frequent password changes to actually be counterproductive to good password security, said Mike Wilson, founder of PasswordPing. NIST said this guideline was suggested because passwords should be changed when a user wants to change it or if there is indication of breach. Read more of this story at Slashdot.

Read the original:
NIST’s Draft To Remove Periodic Password Change Requirements Gets Vendors’ Approval

NIST’s Draft To Remove Periodic Password Change Requirements Gets Vendors’ Approval

An anonymous reader writes: A recently released draft of the National Institute of Standards and Technology’s digital identity guidelines has met with approval by vendors. The draft guidelines revise password security recommendations and altering many of the standards and best practices security professionals use when forming policies for their companies. The new framework recommends, among other things: “Remove periodic password change requirements.” There have been multiple studies that have shown requiring frequent password changes to actually be counterproductive to good password security, said Mike Wilson, founder of PasswordPing. NIST said this guideline was suggested because passwords should be changed when a user wants to change it or if there is indication of breach. Read more of this story at Slashdot.

Read more here:
NIST’s Draft To Remove Periodic Password Change Requirements Gets Vendors’ Approval

NIST’s Draft To Remove Periodic Password Change Requirements Gets Vendors’ Approval

An anonymous reader writes: A recently released draft of the National Institute of Standards and Technology’s digital identity guidelines has met with approval by vendors. The draft guidelines revise password security recommendations and altering many of the standards and best practices security professionals use when forming policies for their companies. The new framework recommends, among other things: “Remove periodic password change requirements.” There have been multiple studies that have shown requiring frequent password changes to actually be counterproductive to good password security, said Mike Wilson, founder of PasswordPing. NIST said this guideline was suggested because passwords should be changed when a user wants to change it or if there is indication of breach. Read more of this story at Slashdot.

Original post:
NIST’s Draft To Remove Periodic Password Change Requirements Gets Vendors’ Approval

NIST’s Draft To Remove Periodic Password Change Requirements Gets Vendors’ Approval

An anonymous reader writes: A recently released draft of the National Institute of Standards and Technology’s digital identity guidelines has met with approval by vendors. The draft guidelines revise password security recommendations and altering many of the standards and best practices security professionals use when forming policies for their companies. The new framework recommends, among other things: “Remove periodic password change requirements.” There have been multiple studies that have shown requiring frequent password changes to actually be counterproductive to good password security, said Mike Wilson, founder of PasswordPing. NIST said this guideline was suggested because passwords should be changed when a user wants to change it or if there is indication of breach. Read more of this story at Slashdot.

Taken from:
NIST’s Draft To Remove Periodic Password Change Requirements Gets Vendors’ Approval

The New Mystery Science Theater 3000 Is the Perfect Pop Culture Revival

Fans don’t like to let their favorites go, but now they don’t have to. We live in a world desperate to remake, reboot, and flat-out return to beloved franchises, hunting the closest thing to a sure audience there is. But the more beloved these continuations are, they harder they are to get right. Fans want them to… Read more…

More:
The New Mystery Science Theater 3000 Is the Perfect Pop Culture Revival

Ubuntu 17.04 ‘Zesty Zapus’, Featuring Unity, Now Available To Download

Brian Fagioli, writing for BetaNews: Ubuntu 17.04 “Zesty Zapus” is available for download. No, this is not an Alpha or Beta, but an official stable version of the Linux-based operating system. Unfortunately, the release is a bit tainted — it uses Unity as the official desktop environment, which Canonical has announced will be killed. Not to mention, there has been some controversy regarding some comments by Ubuntu founder Mark Shuttleworth. Just yesterday, the CEO of Canonical announced she is leaving the position. With all of the aforementioned controversy and chaos, it is understandably hard to get too excited for “Zesty Zapus, ” especially as this is not a long term support version. With that said, if you are an existing Ubuntu user that likes Unity, this is certainly a worthwhile upgrade if you are OK with the shorter support. Unity may no longer have a future, but version 7 will continue to be supported — for a while, at least. Read more of this story at Slashdot.

Excerpt from:
Ubuntu 17.04 ‘Zesty Zapus’, Featuring Unity, Now Available To Download

Scientists Sent a Rocket To Mars For Less Than It Cost To Make ‘The Martian’

Ipsita Agarwal via Backchannel retells the story of how India’s underfunded space organization, ISRO, managed to send a rocket to Mars for less than it cost to make the movie “The Martian, ” starring Matt Damon as Mark Watney. “While NASA’s Mars probe, Maven, cost $651 million, the budget for this mission was $74 million, ” Agarwal writes. In what appears to be India’s version of “Hidden Figures” (a movie that also cost more to make than ISRO’s budget for the Mars rocket), the team of scientists behind the rocket launch consisted of Indian women, who not only managed to pull off the mission successfully but did so in only 18 months. Backchannel reports: A few months and several million kilometers later, the orbiter prepared to enter Mars’ gravity. This was a critical moment. If the orbiter entered Mars’ gravity at the wrong angle, off by so much as one degree, it would either crash onto the surface of Mars or fly right past it, lost in the emptiness of space. Back on Earth, its team of scientists and engineers waited for a signal from the orbiter. Mission designer Ritu Karidhal had worked 48 hours straight, fueled by anticipation. As a child, Minal Rohit had watched space missions on TV. Now, Minal waited for news on the orbiter she and her colleague, Moumita Dutta, had helped engineer. When the signal finally arrived, the mission control room broke into cheers. If you work in such a room, deputy operations director, Nandini Harinath, says, “you no longer need to watch a thriller movie to feel the thrill in life. You feel it in your day-to-day work.” This was not the only success of the mission. An image of the scientists celebrating in the mission control room went viral. Girls in India and beyond gained new heroes: the kind that wear sarees and tie flowers in their hair, and send rockets into space. User shas3 notes in a comment on Hacker News’ post: “If you are interested in Indian women scientists and engineers, there is a nice compilation (a bit tiresome to read, but worth it, IMO) of biographical essays called ‘Lilvati’s Daughters.'” Read more of this story at Slashdot.

More here:
Scientists Sent a Rocket To Mars For Less Than It Cost To Make ‘The Martian’

APFS is coming soon: iOS 10.3 will automatically upgrade your filesystem

After many years and at least one false start , Apple announced at WWDC last year that it would begin shipping a new, modern file system in 2017. Dubbed APFS (for Apple File System), it is designed to improve support for solid-state storage and encryption and to safeguard data integrity. When released, it will finally replace the nearly two-decade-old HFS+ filesystem that Apple has been tacking new features onto since 1998. An early version of APFS was included in macOS Sierra as a beta for developers to experiment with, but it was intentionally limited in some important ways; it couldn’t be used as a boot drive, it didn’t support Fusion Drives, and you can’t back up APFS volumes with Time Machine. We weren’t expecting to hear more about a final APFS rollout until this year’s WWDC, but it looks like Apple is getting ready to start the party already: according to the beta release notes for iOS 10.3 , devices that are upgraded will automatically have their HFS+ file systems converted to APFS. From the release notes: When you update to iOS 10.3, your iOS device will update its file system to Apple File System (APFS). This conversion preserves existing data on your device. However, as with any software update, it is recommended that you create a backup of your device before updating. Apple’s stated end goal is to perform an in-place file system conversion for all its currently supported devices, including all Macs, iPhones, iPads, iPods, Apple TVs, and Apple Watches. iOS 10.3 will provide some early information on how reliable that conversion will be. Read 2 remaining paragraphs | Comments

Read More:
APFS is coming soon: iOS 10.3 will automatically upgrade your filesystem

All the major new additions in the iOS 10.3 and macOS 10.12.4 betas

Enlarge / Devices running iOS 10. (credit: Andrew Cunningham) As predicted yesterday, now that Apple has the iOS 10.2.1  and macOS 10.12.3 releases out the door, it’s turning its attention to larger updates. Apple is releasing the first betas of iOS 10.3 and macOS 10.12.4 to the public today and has given us a broad overview of the biggest changes that people will see when these are released to the public in a couple of months. The iOS 10.3 update is the more significant of the two. For starters, it adds AirPods  to Find My iPhone to make them easier to find if you lose them, which, given how small they are, is bound to happen to AirPod owners eventually. Most of the other changes come in the form of small additions to existing features. SiriKit , which can already hook into compatible payment and ride-sharing apps, can now be used to pay bills and check on the status of payments. You’ll also be able to schedule a ride with Siri—calling an Uber to come at 2pm rather than “right now,” for instance. The weather icon in Maps can be 3D Touched on compatible devices (the iPhone 6S and 7 series, as of this writing) to show hourly forecasts and other information. The CarPlay UI picks up shortcuts for launching the two most recently used apps and can display EV charging stations in Maps. HomeKit now supports programmable light switches. Facemarks on the Chinese and Japanese keyboards have been shuffled around to make it easier to type, and the Conversation View that Mail picked up in iOS 10 has gotten some “navigation improvements.” Read 5 remaining paragraphs | Comments

Read the original post:
All the major new additions in the iOS 10.3 and macOS 10.12.4 betas

Virulent Android malware returns, gets >2 million downloads on Google Play

Enlarge (credit: portal gda ) A virulent family of malware that infected more than 10 million Android devices last year has made a comeback, this time hiding inside Google Play apps that have been downloaded by as many as 12 million unsuspecting users. HummingWhale, as the professionally developed malware has been dubbed, is a variant of HummingBad, the name given to a family of malicious apps researchers documented in July invading non-Google app markets . HummingBad attempted to override security protections by exploiting unpatched vulnerabilities that gave the malware root privileges in older versions of Android. Before Google shut it down, it installed more than 50,000 fraudulent apps each day, displayed 20 million malicious advertisements, and generated more than $300,000 per month in revenue. Of the 10 million people who downloaded HummingBad-contaminated apps, an estimated 286,000 of them were located in the US. HummingWhale, by contrast, managed to sneak its way into about 20 Google Play apps that were downloaded from 2 million to 12 million times, according to researchers from Check Point, the security company that has been closely following the malware family for almost a year. Rather than rooting devices, the latest variant includes new virtual machine techniques that allow the malware to perform ad fraud better than ever, company researchers said in a blog post published Monday . Read 6 remaining paragraphs | Comments

Visit link:
Virulent Android malware returns, gets >2 million downloads on Google Play