Researchers Point Out ‘Theoretical’ Security Flaws In AMD’s Upcoming Zen CPU

An anonymous reader writes from a report via BleepingComputer: The security protocol that governs how virtual machines share data on a host system powered by AMD Zen processors has been found to be insecure, at least in theory, according to two German researchers. The technology, called Secure Encrypted Virtualization (SEV), is designed to encrypt parts of the memory shared by different virtual machines on cloud servers. AMD, who plans to ship SEV with its upcoming line of Zen processors, has published the technical documentation for the SEV technology this past April. The German researchers have analyzed the design of SEV, using this public documentation, and said they managed to identify three attack channels, which work, at least in theory. [In a technical paper released over the past weekend, the researchers described their attacks:] “We show how a malicious hypervisor can force the guest to perform arbitrary read and write operations on protected memory. We describe how to completely disable any SEV memory protection configured by the tenant. We implement a replay attack that uses captured login data to gain access to the target system by solely exploiting resource management features of a hypervisor.” AMD is scheduled to ship SEV with the Zen processor line in the first quarter of 2017. Read more of this story at Slashdot.

Read More:
Researchers Point Out ‘Theoretical’ Security Flaws In AMD’s Upcoming Zen CPU

First Dinosaur Tail Found Preserved in Amber

The tail of a beautiful, feathered dinosaur has been found perfectly preserved in amber from Myanmar. It is a huge breakthrough that could help open a new window on the biology of a group that dominated Earth for more than 160 million years. From a report on the National Geographic: The semitranslucent mid-Cretaceous amber sample, roughly the size and shape of a dried apricot, captures one of the earliest moments of differentiation between the feathers of birds of flight and the feathers of dinosaurs. Inside the lump of resin is a 1.4-inch appendage covered in delicate feathers, described as chestnut brown with a pale or white underside. CT scans and microscopic analysis of the sample revealed eight vertebrae from the middle or end of a long, thin tail that may have been originally made up of more than 25 vertebrae. NPR has a story on how this amber was found. An excerpt from it reads: In 2015, Lida Xing was visiting a market in northern Myanmar when a salesman brought out a piece of amber about the size of a pink rubber eraser. Inside, he could see a couple of ancient ants and a fuzzy brown tuft that the salesman said was a plant. As soon as Xing saw it, he knew it wasn’t a plant. It was the delicate, feathered tail of a tiny dinosaur. Read more of this story at Slashdot.

Read More:
First Dinosaur Tail Found Preserved in Amber

Earth’s Day Lengthens By Two Milliseconds a Century, Astronomers Find

Researchers at Durham University and the UK’s Nautical Almanac Office compiled nearly 3, 000 years of celestial records and found that with every passing century, the day on Earth lengthens by two milliseconds as the planet’s rotation gradually winds down. The Guardian reports: The split second gained since the first world war may not seem much, but the time it takes for a sunbeam to travel 600km towards Earth can cost an Olympic gold medal, as the American Tim McKee found out when he lost to Sweden’s Gunnar Larsson in 1972. For those holding out for a whole extra hour a day, be prepared for a long wait. Barring any change in the rate of slowing down, an Earth day will not last 25 hours for about two million centuries more. Researchers at Durham University and the UK’s Nautical Almanac Office gathered historical accounts of eclipses and other celestial events from 720BC to 2015. The oldest records came from Babylonian clay tablets written in cuneiform, with more added from ancient Greek texts, such as Ptolemy’s 2nd century Almagest, and scripts from China, medieval Europe and the Arab dominions. The ancient records captured the times and places that people witnessed various stages of solar and lunar eclipses, while documents from 1600AD onwards described lunar occultations, when the moon passed in front of particular stars and blocked them from view. To find out how the Earth’s rotation has varied over the 2, 735-year-long period, the researchers compared the historical records with a computer model that calculated where and when people would have seen past events if Earth’s spin had remained constant. The astronomers found that Earth’s spin would have slowed down even more had it not been for a counteracting process. Since the end of the most recent ice age, land masses that were once buried under slabs of frozen water have been unloaded and sprung back into place. The shift caused the Earth to be less oblate — or squished — on its axis. And just as a spinning ice skater speeds up when she pulls in her arms, so the Earth spins faster when its poles are less compressed. Changes in the world’s sea levels and electromagnetic forces between Earth’s core and its rocky mantle had effects on Earth’s spin too, according to the scientists’ report in Proceedings of the Royal Society. Read more of this story at Slashdot.

Visit site:
Earth’s Day Lengthens By Two Milliseconds a Century, Astronomers Find

Cesarean Births Could Be Affecting Human Evolution, Study Says

CanadianRealist writes: Larger babies delivered by cesarean section may be affecting human evolution. Researchers estimate cases where the baby cannot fit down the birth canal have increased from 30 in 1, 000 in the 1960s to 36 in 1, 000 births today, [according to estimates from researchers at the University of Vienna in Austria.] Science Alert reports: “In the past, larger babies and mothers with narrow pelvis sizes might both have died in labour. Thanks to C-sections, that’s now a lot less likely, but it also means that those ‘at risk’ genes from mothers with narrow pelvises are being carried into future generations. More detailed studies would be required to actually confirm the link between C-sections and evolution, as all we have now is a hypothesis based on the birth data.” Agreed, more studies required part. Cesareans may simply be becoming more common with “too large” defined as cesarean seems like a better idea. It’s reasonable to pose the question based simply on an understanding of evolution. Like it’s reasonable to conjecture that length of human pregnancy is a compromise between further development in utero, and chance of mother and baby surviving the delivery. Read more of this story at Slashdot.

See the article here:
Cesarean Births Could Be Affecting Human Evolution, Study Says

Google Says It Is About To Reach 100 Percent Renewable Energy

Google said today it will power 100 percent of its sprawling data centers and offices with renewable energy starting next year. The company said today it has bought enough wind and solar power to account for all the electricity it uses globally each year. In comparison, 44 percent of Google’s power supplies came from renewables last year. From a blogpost: To reach this goal we’ll be directly buying enough wind and solar electricity annually to account for every unit of electricity our operations consume, globally. And we’re focusing on creating new energy from renewable sources, so we only buy from projects that are funded by our purchases. Over the last six years, the cost of wind and solar came down 60 percent and 80 percent, respectively, proving that renewables are increasingly becoming the lowest cost option. Electricity costs are one of the largest components of our operating expenses at our data centers, and having a long-term stable cost of renewable power provides protection against price swings in energy. Read more of this story at Slashdot.

Read this article:
Google Says It Is About To Reach 100 Percent Renewable Energy

Google Is Rolling Out Android 7.1.1

Google is rolling out Android 7.1.1 for Pixel and Nexus smartphones, including the Nexus 6, Nexus 5X, Nexus 6P, Nexus 9, Pixel, Pixel XL, Nexus Player, Pixel C and General Mobile 4G (Android One). You can download it over-the-air when it becomes available “over the next several weeks” or flash it yourself. Engadget details some of the new features found in Android 7.1.1: As for what you can find from a feature perspective, Google has added support for its “image keyboard” that lets you easily find and send pictures and GIFs without leaving your messaging app of choice. Google says it’ll work inside of Hangouts, Allo, and the default Messaging app. Ironically enough, the feature has been available in the Gboard iOS keyboard that Google launched in the spring, but it’s good to see it coming to more Android phones now. Android 7.1.1 also includes Google’s latest set of more diverse emoji, specifically focused on showing a “wider range of professions” for women. And it also contains the excellent app shortcut feature that originally launched on the Pixel — if you press and hold on an app’s icon, a sub-menu of shortcuts will show up. You’ll be able to quickly send a message to a specific contact or navigate to a saved location using these shortcuts, for example. They’re very much like the “force touch” shortcuts found on the iPhone, but that doesn’t make them any less useful. Read more of this story at Slashdot.

See original article:
Google Is Rolling Out Android 7.1.1

Dailymotion Hack Exposes Millions of Accounts

Millions of accounts associated with video sharing site Dailymotion, one of the biggest video platforms in the world, have been stolen. From a ZDNet report: A hacker extracted 85.2 million unique email addresses and usernames from the company’s systems, but about one-in-five accounts — roughly 18.3 million– had associated passwords, which were scrambled with the bcrypt hashing function, making the passwords difficult to crack. The hack is believed to have been carried out on October 20 by a hacker, whose identity isn’t known, according to LeakedSource, a breach notification service, which obtained the data. Dailymotion launched in 2005, and is currently the 113rd most visited website in the world, according to Alexa rankings. Read more of this story at Slashdot.

Read More:
Dailymotion Hack Exposes Millions of Accounts

Netflix Keeping Bandwidth Usage Low By Encoding Its Video With VP9 and H.264/AVC Codecs

Netflix announced last week that it is getting offline video downloads support. The company has since shared that it is using VP9 video compression codec to ensure that the file sizes don’t weigh a lot. An anonymous reader shares an article on Slashgear (edited): For streaming content, Netflix largely relies on H.264/AVC to reduce the bandwidth, but for downloading content, it uses VP9 encoding. VP9 can allow better quality videos for the same amount of data needed to download. The challenge is that VP9 isn’t supported by all streaming providers — it is supported on Android devices and via the Chrome browser. So to get around that lack of support on iOS, Netflix is offering downloads in H.264/AVC High whereas streams are encoded in H.264/AVC Main on such devices. Netflix chooses the optimal encoding format for each title on its service after finding, for instance, that animated films are easier to encode than live-action. Netflix says that H.264 High encoding saves 19% bandwidth compared to other encoding standards while VP9 saves 36%. Read more of this story at Slashdot.

Follow this link:
Netflix Keeping Bandwidth Usage Low By Encoding Its Video With VP9 and H.264/AVC Codecs

Canonical Sues Cloud Provider Over ‘Unofficial’ Ubuntu Images

An anonymous reader quotes OStatic’s update on Canonical’s lawsuit against a cloud provider: Canonical posted Thursday that they’ve been in a dispute with “a European cloud provider” over the use of their own homespun version of Ubuntu on their cloud servers. Their implementation disables even the most basic of security features and Canonical is worried something bad could happen and it’d reflect badly back on them… They said they’ve spent months trying to get the unnamed provider to use the standard Ubuntu as delivered to other commercial operations to no avail. Canonical feels they have no choice but to “take legal steps to remove these images.” They’re sure Red Hat and Microsoft wouldn’t be treated like this. Mark Shuttleworth, the founder of Ubuntu, wrote in his blog post that Ubuntu is “the leading cloud OS, running most workloads in public clouds today, ” whereas these homegrown images “are likely to behave unpredictably on update in weirdly creative and mysterious ways… We hear about these issues all the time, because users assume there is a problem with Ubuntu on that cloud; users expect that ‘all things that claim to be Ubuntu are genuine’, and they have a right to expect that… “To count some of the ways we have seen home-grown images create operational and security nightmares for users: clouds have baked private keys into their public images, so that any user could SSH into any machine; clouds have made changes that then blocked security updates for over a week… When things like this happen, users are left feeling let down. As the company behind Ubuntu, it falls to Canonical to take action.” Read more of this story at Slashdot.

Read More:
Canonical Sues Cloud Provider Over ‘Unofficial’ Ubuntu Images

Chrome 55 Now Blocks Flash, Uses HTML5 By Default

An anonymous reader quotes Bleeping Computer: Chrome 55, released earlier this week, now blocks all Adobe Flash content by default, according to a plan set in motion by Google engineers earlier this year… While some of the initial implementation details of the “HTML5 By Default” plan changed since then, Flash has been phased out in favor of HTML5 as the primary technology for playing multimedia content in Chrome. Google’s plan is to turn off Flash and use HTML5 for all sites. Where HTML5 isn’t supported, Chrome will prompt users and ask them if they want to run Flash to view multimedia content. The user’s option would be remembered for subsequent visits, but there’s also an option in the browser’s settings section, under Settings > Content Settings > Flash > Manage Exceptions, where users can add the websites they want to allow Flash to run by default. Exceptions will also be made automatically for your more frequently-visited sites — which, for many users, will include YouTube. And Chrome will continue to ship with Flash — as well as an option to re-enable Flash on all sites. Read more of this story at Slashdot.

Read this article:
Chrome 55 Now Blocks Flash, Uses HTML5 By Default