Ubuntu Linux Forums Hacked — IP Address, Username, Email of 2M Accounts Compromised

Canonical announced on Friday that Ubuntu forums have been hacked. The company adds that data such as IP address, username, and email address of over two million users have been compromised. BetaNews reports: Keep in mind, this does not mean that the operating system has experienced a vulnerability or weakness. The only thing affected are the online forums that people use to discuss the OS. Still, such a hack is embarrassing as it happened due to Canonical’s failure to install a patch.In a blog post, Jane Silber, Chief Executive Officer, Canonical said, “after some initial investigation, we were able to confirm there had been an exposure of data and shut down the Forums as a precautionary measure. Deeper investigation revealed that there was a known SQL injection vulnerability in the Forumrunner add-on in the Forums which had not yet been patched.” Read more of this story at Slashdot.

See the original post:
Ubuntu Linux Forums Hacked — IP Address, Username, Email of 2M Accounts Compromised

Programming Bug Costs Citigroup $7M After Legit Transactions Mistaken For Test Data For 15 Years

An anonymous reader shares a report on The Register:A programming blunder in its reporting software has led to Citigroup being fined $7m. According to the US Securities and Exchange Commission (SEC), that error [PDF] resulted in the financial regulator being sent incomplete “blue sheet” information for a remarkable 15 years — from May 1999 to April 2014. The mistake was discovered by Citigroup itself when it was asked to send a large but precise chunk of trading data to the SEC in April 2014 and asked its technical support team to help identify which internal ID numbers they should run a request on. That team quickly noticed that some branches’ trades were not being included in the automated system and alerted those above them. Four days later a patch was in place, but it wasn’t until eight months later that the company received a formal report noting that the error had affected SEC reports going back more than a decade. The next month, January 2015, Citigroup fessed up to the SEC.The glitch resided in new alphanumeric branch codes that the bank had introduced in the mid-1990s. The program code filtered out any transactions that were given three-digit branch codes from 089 to 100 and used those prefixes for testing purposes. The report adds, “But in 1998, the company started using alphanumeric branch codes as it expanded its business. Among them were the codes 10B, 10C and so on, which the system treated as being within the excluded range, and so their transactions were removed from any reports sent to the SEC.” Read more of this story at Slashdot.

View article:
Programming Bug Costs Citigroup $7M After Legit Transactions Mistaken For Test Data For 15 Years

Russian Hackers Reportedly Stole Donald Trump Opposition Research From The DNC

Russian hackers were able to snatch all of the Democratic National Committee’s opposition research on Donald Trump, according to US officials who spoke to the Washington Post . The hackers were able to read emails and instant messages as a result of the breach. Read more…

Continue Reading:
Russian Hackers Reportedly Stole Donald Trump Opposition Research From The DNC

Fitness App Runkeeper Secretly Tracks Users At All Times, Sends Data to Advertisers

An anonymous reader writes: FitnessKeeper, the company behind running app Runkeeper, is in hot water in Europe. The company has received a formal complaint from the Norwegian Consumer Council for breaching European data protection laws. But why? Runkeeper tracks its users’ location at all times — not just when the app is active — and sends that data to advertisers. The NCC, a consumer rights watchdog, is conducting an investigation into 20 apps’ terms and conditions to see if the apps do what their permissions say they do and to monitor data flows. Tinder has already been reported to the Norwegian data protection authority for similar breaches of privacy laws. The NCC’s investigation into Runkeeper discovered that user location data is tracked around the clock and gets transmitted to a third party advertiser in the U.S. called Kiip.me.Finn Myrstad, the council’s digital policy director, said: We checked the apps technically, to see the data flows and to see if the apps actually do what they say they do. Everyone understands that Runkeeper tracks users while they exercise, but to continue after the training has ended is not okay. Not only is it a breach of privacy laws, we are also convinced that users do not want to be tracked in this way, or for information to be shared with third party advertisers. Read more of this story at Slashdot.

Read More:
Fitness App Runkeeper Secretly Tracks Users At All Times, Sends Data to Advertisers

Samsung Smart Home Flaws Let Hackers Pick Connected Doors From Anywhere In the World

Researchers have discovered flaws in Samsung’s Smart Home automation system, which if exploited, allows them to carry a range of remote attacks. These attacks include digitally picking connected door locks from anywhere in the world. The flaws have been documented by researchers from the University of Michigan ahead of the 2016 IEEE Symposium on Security and Privacy. “All of the above attacks expose a household to significant harm — break-ins, theft, misinformation, and vandalism, ” the researchers wrote in a paper. “The attack vectors are not specific to a particular device and are broadly applicable.” Dan Goodin, reports for Ars Technica: Other attacks included a malicious app that was able to obtain the PIN code to a smart lock and send it in a text message to attackers, disable a preprogrammed vacation mode setting, and issue a fake fire alarm. The one posing the biggest threat was the remote lock-picking attack, which the researchers referred to as a “backdoor pin code injection attack.” It exploited vulnerabilities in an existing app in the SmartThings app store that gives an attacker sustained and largely surreptitious access to users’ homes. The attack worked by obtaining the OAuth token that the app and SmartThings platform relied on to authenticate legitimate users. The only interaction it required was for targeted users to click on an attacker-supplied HTTPS link that looked much like this one that led to the authentic SmartThings login page. The user would then enter the username and password. A flaw in the app allowed the link to redirect the credentials away from the SmartThings page to an attacker-controlled address. From then on, the attackers had the same remote access over the lock that users had. Read more of this story at Slashdot.

Visit link:
Samsung Smart Home Flaws Let Hackers Pick Connected Doors From Anywhere In the World

WordPress.com Enables HTTPS Encryption For All Websites

On Friday, WordPress announced that it is bringing free HTTPS to all — “million-plus” — custom domains, essentially ramping up security on every blog and website. The publishing platform says it partnered with Let’s Encrypt project to implement HTTPS across such a voluminous number of sites. From the blog: For you, the users, that means you’ll see secure encryption automatically deployed on every new site within minutes. We are closing the door to un-encrypted web traffic (HTTP) at every opportunity. Read more of this story at Slashdot.

Continue reading here:
WordPress.com Enables HTTPS Encryption For All Websites

Wikipedia fund gives the site a long-term future

Wikipedia just turned 15 years old, but you wouldn’t know it from the nigh-on inescapable donation drives — the crowdsourced encyclopedia often seems as if it’s months away from extinction. The Wikimedia Foundation (its parent organization) may have a way to keep the site around for the long haul, however. It’s launching the Wikimedia Endowment , a “perpetual” support fund for Wikipedia and other Foundation efforts. The goal is to raise $100 million over the next 10 years, or enough to both improve its independence and give it room to grow. The Endowment may well be necessary. Wikipedia revolves around its free, no-ads approach to information, and there’s no guarantee that it’ll find enough people to chip in. This prevents it from having to turn to ads and otherwise compromise its relatively impartial stance. Moreover, the team is eager to add more videos and continue adapting to the mobile world — those expansions will cost money. The organization still has to be frugal (it’s not about to beat YouTube), but it shouldn’t be at risk of falling behind. [Image credit: Lionel Bonaventure/AFP/Getty Images] Via: The Guardian Source: Wikimedia Endowment

More here:
Wikipedia fund gives the site a long-term future

Next Month You Can Use Windows 7, 8 Product Keys to Activate Windows 10

Upgrading to Windows 10 is easy if you’re already on Windows 7 or 8 . However, if you want a clean install , you have to install an older version first. Next month, the first big update to Windows 10 will fix this. Read more…

Follow this link:
Next Month You Can Use Windows 7, 8 Product Keys to Activate Windows 10

Americans Rejoice At Lower Gas Prices

HughPickens.com writes Drivers across America are rejoicing at falling gasoline prices as pumps across the country dip below $3 a gallon. According to Sharon E. Burke while it’s nice to get the break at the gas pump and the economic benefits of an energy boom at home, the national security price of oil remains high and the United States should be doing everything it can to diversify global energy suppliers. Ultimately, the only way to solve our long term energy problem is to make a sustained, long-term investment in the alternatives to petroleum. But October saw a 52 percent jump in Jeep SUV sales and a 36 percent rise in Ram trucks while some hybrid and electric vehicle sales fell at the same time. “This is like putting a Big Mac in front of people who need to diet or watch their cholesterol, ” says Anthony Perl. “Some people might have the willpower to stick with their program, and some people will wait until their first heart attack before committing to a diet—but if we do that at a planetary scale it will be pretty traumatic.” Nicholas St. Fleur writes at The Atlantic that low oil prices may also undermine the message from the UN’s climate panel. The price drop comes after the UN declared earlier this week that fossil fuel emissions must drop to zero by the end of the century in order to keep global temperatures in check. “I don’t think people will see the urgency of dealing with fossil fuels today, ” says Perl. Falling oil prices may also deter businesses from switching to energy-saving technology, as a 2006 study in the Energy Journal suggested. Saving several pennies at the pump, Perl says, may tempt Americans away from actions that can lead to a sustainable, post-carbon future. Read more of this story at Slashdot.

Read More:
Americans Rejoice At Lower Gas Prices

Minnesota Teen Wins Settlement After School Takes Facebook Password

schwit1 (797399) writes “A Minnesota school district has agreed to pay $70, 000 to settle a lawsuit that claimed school officials violated a student’s constitutional rights by viewing her Facebook and email accounts without permission. The lawsuit, filed in 2012 by the American Civil Liberties Union of Minnesota, alleged that Riley Stratton, now 15, was given detention after posting disparaging comments about a teacher’s aide on her Facebook page, even though she was at home and not using school computers. After a parent complained about the Facebook chat, the school called her in and demanded her password. With a sheriff deputy looking on, she complied, and they browsed her Facebook page in front of her, according to the report. ‘It was believed the parent had given permission to look at her cellphone, ‘ Minnewaska Superintendent Greg Schmidt said Tuesday. But Schmidt said the district did not have a signed consent from the parent. That is now a policy requirement, he said.'” Asks schwit1, “How is this not a violation of the CFAA?” It sounds like the school was violating Facebook’s Terms of Service, too. Read more of this story at Slashdot.

View the original here:
Minnesota Teen Wins Settlement After School Takes Facebook Password