Microsoft wants you to trade in your MacBook Air for a Surface Pro 3

Ready to kick your MacBook Air to the curb (and wonder how much exactly in in-store credit it’s worth)? Your friendly neighborhood Microsoft Store is ready to help. Peter Bright This weekend, Microsoft Stores launched a trade-in program to encourage sales of the new Surface Pro 3 , but the trade-in promotion named only a single device : the MacBook Air, at a value of “up to $650” toward any Surface Pro 3 purchase. At the lowest specification, that trade-in amount would let buyers walk out of a Microsoft Store with an Intel i3 Surface Pro 3 for as little as $150. Though Microsoft Stores maintain a trade-in program that accepts video games, consoles, Apple iDevices, and PC laptops, this is the first promotion from Microsoft Stores that has actively sought Apple laptops—or, in this case, laptop singular. Seeing as how Microsoft has attempted to position the Surface Pro 3 as the best of both tablet and laptop worlds, the capable, paper-thin MacBook Air is the obvious recipient of Microsoft’s promotional crosshairs. We called the flagship Microsoft Store in Seattle with trade-in value questions, and while the representative said that any Macbook Air could be traded in at stores in the United States and Canada, he insisted that Microsoft won’t break down the exact trade-in value of a given Macbook Air or any other Apple hardware (iPhones, iPads, etc.) without seeing the product in person. The response came even after we tried listing off our MacBook Air’s processor, hard drive, and other specs. This stays in line with Microsoft Store policy through their own website to not disclose trade-in values. Read on Ars Technica | Comments

Read more here:
Microsoft wants you to trade in your MacBook Air for a Surface Pro 3

IE users get new protection against potent form of malware attack

a_codepoet Microsoft developers have fortified Internet Explorer with new protections designed to prevent a type of attack commonly used to surreptitiously install malware on end-user computers. The “isolated heap for DOM objects” made its debut with last week’s Patch Tuesday . Just as airbags lower the chance of critical injuries in automobile accidents, the new IE protection is designed to significantly lessen the damage attackers can do when exploiting so-called use-after-free flaws in the browser code. As the name suggests, use-after-free bugs are the result of code errors that reference computer memory objects after they have already been purged, or freed, from the operating system heap. Attackers can exploit them by refilling the improperly freed space with malicious code that logs passwords, makes computers part of a botnet, or carries out other nefarious behavior. Use-after-free flaws are among the most commonly exploited, often at great expense to end users. Recent in-the-wild attacks that targeted IE versions 9, 10, and 11 capitalized on a use-after-free bug. The bug class has been at the heart of many other real-world attacks on IE that are too numerous to count . (They have also been known to bring down Google Chrome and Mozilla Firefox.) Wei Chen, an exploit developer with Rapid 7’s Metasploit vulnerability framework, likens use-after-free exploits to sneaking tainted cookies into an already-opened bag of Oreos. Read 5 remaining paragraphs | Comments

View article:
IE users get new protection against potent form of malware attack

At least 32,000 servers broadcast admin passwords in the clear, advisory warns

An alarming number of servers containing motherboards manufactured by Supermicro continue to expose administrator passwords despite the release of an update that patches the critical vulnerability, an advisory published Thursday warned. The threat resides in the baseboard management controller (BMC), a motherboard component that allows administrators to monitor the physical status of large fleets of servers, including their temperatures, disk and memory performance, and fan speeds. Unpatched BMCs in Supermicro motherboards contain a binary file that stores remote login passwords in clear text. Vulnerable systems can be detected by performing an Internet scan on port 49152. A recent query on the Shodan search engine indicated there are 31,964 machines still vulnerable, a number that may not include many virtual machines used in shared hosting environments. “This means at the point of this writing, there are 31,964 systems that have their passwords available on the open market,” wrote Zachary Wikholm, a senior security engineer with the Carinet Security Incident Response Team. “It gets a bit scarier when you review some of the password statistics. Out of those passwords, 3,296 are the default combination. Since I’m not comfortable providing too much password information, I will just say that there exists a subset of this data that either contains or just was ‘password.'” Read 5 remaining paragraphs | Comments

Visit site:
At least 32,000 servers broadcast admin passwords in the clear, advisory warns

Tell a lie, remove the gear: How the NSA covers up when cable taps are found

Der Spiegel via Edward Snowden via NSA Sometimes, the spooks do get caught. German magazine Der Spiegel yesterday revealed a new slide  (PDF) from the Edward Snowden document cache that offers a tantalizing glimpse of what it looks like when someone stumbles on an intelligence agency cable tap. The NSA’s Special Source Operations (SSO) branch isn’t in the business of computer hacking but of cable tapping; its logo shows an eagle flying above the globe and clutching a string of wires in its talons. These taps, each obscured with a codename, are often made deep within the network of telecom providers and often with the cooperation of key executives. But sometimes non-cleared people start raising questions about just what might be going on, as was the case with AT&T whistleblower Mark Klein, who revealed an NSA “secret room” in San Francisco . On March 14, 2013, an SSO weekly briefing included a note regarding such a discovery. The unit had been informed two days earlier that “the access point for WHARPDRIVE was discovered by commercial consortium personnel. Witting partner personnel have removed the evidence and a plausible cover story was provided. All collection has ceased.” Read 2 remaining paragraphs | Comments

See the original post:
Tell a lie, remove the gear: How the NSA covers up when cable taps are found

Hacker infects Synology storage devices, makes off with $620,000 in Dogecoin

One of the affected Synology devices. Synology A hacker generated digital coins worth more than $620,000 by hijacking a popular type of Internet-connected storage device from Synology, security researchers said. The incident, which was documented in a research report published Tuesday by Dell SecureWorks, is only the latest hack to steal other people’s computing resources to perform the computationally intense process of digital currency mining. The cryptographic operations behind the process often draw large amounts of power and produce lots of heat. People looking to acquire a large war chest of digital coins typically must pour large amounts of money and effort into the endeavor. One way malicious actors get by this requirement is by compromising large numbers of devices operated by other people. The devices then perform the work at the expense of the unsuspecting end users and pass on the proceeds to the attacker. According to researchers from SecureWorks Counter Threat Unit, the attackers exploited four separate vulnerabilities contained in the software of Synology network-attached storage boxes. The vulnerabilities were documented in September and fixed in February by Synology . By then, large numbers of people began complaining their Synology devices were running sluggishly and extremely hot . It turns out that at least some of them were running software that mined large sums of the Dogecoin cryptocurrency. Read 4 remaining paragraphs | Comments

See more here:
Hacker infects Synology storage devices, makes off with $620,000 in Dogecoin

Undergrad breaks Android crypto ransomware

Early in June, Ars reported the discovery of Android/Simplocker , which appeared to be the first cryptographic ransomware Trojan targeted at Android devices. Simplocker encrypts photos, documents, and videos in devices’ local storage and then instructs the device owner to send money if they ever want to see that content again. One researcher—Simon Bell, an undergraduate student at the University of Sussex—managed to dissect the code for Simplocker. He found that while the code actually called back to a command and control server over the Tor anonymizing network to pass information about the infected device, all of the encryption work was done by the malware itself. Today, Bell released an antidote to Simplocker —a Java program that can decrypt the files attacked by the malware. “The antidote was incredibly easy to create because the ransomware came with both the decryption method and the decryption password,” Bell wrote. “Therefore producing an antidote was more of a copy-and-paste job than anything.” Read 3 remaining paragraphs | Comments

Original post:
Undergrad breaks Android crypto ransomware

Report: Seattle paid $17,500 to boost online reputation of city official

tdlucas5000 A newly-published document shows that Seattle’s publicly-owned electrical utility paid thousands of dollars to Brand.com to manage the online reputation of CEO Jorge Carrasco. The document , which was received and published Saturday by the Seattle Times after a public records request, shows that Brand.com charged City Light $5,000 in December 2013. As the contract states: Read 6 remaining paragraphs | Comments

Excerpt from:
Report: Seattle paid $17,500 to boost online reputation of city official

Unicode 7.0 introduces 2,834 new characters, including 250 emoji

We can leave dumb old “words” behind as soon as emoji evolve to express all forms of human feeling and emotion. Andrew Cunningham The Unicode Consortium has just announced the release of version 7.0 of the Unicode Standard , the list of characters ” which specifies the representation of text in all modern software products and standards .” Unicode 7.0 adds 2,834 new characters to the existing list of 110,187 characters defined by Unicode 6.3, including new symbols for currency, new “lesser-used and historic scripts,” and extended support “for written languages of North America, China, India, other Asian countries, and Africa.” Of course, the Internet being what it is, what people seem the most excited about are the 250 new emoji characters, listed here by Emojipedia . Notable additions include “hot pepper,” “sleuth or spy,” “man in business suit levitating,” “reversed hand with middle finger extended,” and “raised hand with part between middle and ring fingers” (aka the ” live long and prosper ” thing). The list of emoji also extends the character set’s adorable fascination with outmoded technology thanks to icons like “soft shell floppy disk,” “fax icon,” and “old personal computer.” Mostly absent from that list of new emoji are the more racially diverse characters Apple said it was trying to introduce back in March . There are a few characters that suggest progress on that front (“sideways black left pointing index,” “black up pointing backhand index,” and so on, assuming that “index” is a reference to index fingers), but those additions don’t introduce parity between black- and white-skinned icons, nor do they account for other skin tones. That’s not necessarily surprising, since these standards take a long time to change—hopefully more characters are introduced in a future Unicode release. Read 1 remaining paragraphs | Comments

View article:
Unicode 7.0 introduces 2,834 new characters, including 250 emoji

Is Chicago using cell tracking devices? One man tries to find out

David D’Agostino A local activist has filed a new lawsuit against the Chicago Police Department in an attempt to learn how the city uses fake cell tower devices, also known as stingrays. Relatively little is known about the devices, which are used to track targeted phones and can also be used to intercept calls and text messages. The American Civil Liberties Union recently began a campaign to learn more about how stingrays are used by filing public records requests in Florida, the home state of the Stingray’s manufacturer, Harris Corporation. (While “Stringray” is a trademarked name and particular product, it has entered the technical lexicon as a generic term, like Kleenex or Xerox.) In nearly every sales agreement , that firm has required law enforcement agencies to sign nondisclosure agreements forbidding them from discussing whether or not an agency even possesses such a device, much less describing its capabilities. Read 8 remaining paragraphs | Comments

More:
Is Chicago using cell tracking devices? One man tries to find out

RadioShack continues death march, loses $98.3 million in a quarter

On Tuesday, electronics retailer RadioShack reported its quarterly earnings , and the results were not good. The company lost $98.3 million in its first fiscal quarter of 2014, a figure that’s more than triple the loss it sustained in the same quarter last year. Ars put RadioShack on our 2014 “Deathwatch” earlier in January, and not without reason. The retailer has relied on mobile phone sales to buoy it through the hard times and has tried to rebrand itself as the place to shop for Do-It-Yourselfers, stocking its shelves with various Arduino projects. But customers can find the handsets they need in carriers’ shops, and they often choose to buy DIY electronics goods online or in hardware stores. In a press release , the company attributed the quarter results to ” an industry-wide decline in consumer electronics and a soft mobility market which impacted traffic trends throughout the quarter.” Read 3 remaining paragraphs | Comments

Originally posted here:
RadioShack continues death march, loses $98.3 million in a quarter