City-run ISP makes 10Gbps available to all residents and businesses

A municipal Internet service provider in Salisbury, North Carolina, announced today that it is making 10Gbps service available throughout the city, to both businesses and residents. The city-run  Fibrant was created five years ago after city officials were unable to persuade private ISPs to upgrade their infrastructure and built fiber throughout the city. Gigabit download and upload speeds have been available to residents since last year for $105 a month , while customers can pay as little as $45 a month for 50Mbps symmetrical service. TV and phone service is available, too. Fibrant officials don’t actually expect much, if any demand from residents for the 10Gbps download and upload service. The big speed upgrade is mainly targeted at businesses, but the announcement said 10Gbps service is now “available to every premises in the city,” including all homes. Read 14 remaining paragraphs | Comments

Continued here:
City-run ISP makes 10Gbps available to all residents and businesses

Sneaky adware caught accessing users’ Mac Keychain without permission

Last month, Ars chronicled a Mac app that brazenly exploited a then unpatched OS X vulnerability so the app could install itself without requiring people to enter system passwords. Now, researchers have found the same highly questionable installer is accessing people’s Mac keychain without permission. The adware taking these liberties is distributed by Israel-based Genieo Innovation, a company that’s long been known to push adware and other unwanted apps . According to researchers at Malwarebytes, the Genieo installer automatically accesses a list of Safari extensions  that, for reasons that aren’t entirely clear, is stashed inside the Mac Keychain  alongside passwords for iCloud, Gmail, and other important accounts. Genieo acquires this access by very briefly displaying a message asking for permission to open the Safari extensions and then automatically clicking the accompanying OK button before a user has time to respond or possibly even notice what’s taking place. With that, Genieo installs an extension known as Leperdvil. The following three-second video captures the entire thing: Read 5 remaining paragraphs | Comments

Continue Reading:
Sneaky adware caught accessing users’ Mac Keychain without permission

Wikipedia blocks hundreds of linked accounts for suspect editing

The Wikimedia Foundation, the host of the online encyclopedia Wikipedia, said late Monday that it has suspended 381 accounts or “socks” that it claims accepted or charged money “to promote external interests on Wikipedia without revealing their affiliation.” The foundation said that it believed that activity from so-called “sockpuppet” accounts “were perpetrated by one coordinated group.” The foundation said that volunteer editors spent weeks investigating what it said was a violation of its terms of use . “The editors issued these blocks as part of their commitment to ensuring Wikipedia is an accurate, reliable, and neutral knowledge resource for everyone,” Wikimedia said in a statement. Read 6 remaining paragraphs | Comments

Originally posted here:
Wikipedia blocks hundreds of linked accounts for suspect editing

Microsoft, Google, Amazon, others, aim for royalty-free video codecs

Microsoft, Google, Mozilla, Cisco, Intel, Netflix, and Amazon today launched a new consortium, the Alliance for Open Media. The group plans to develop next-generation media formats—including audio and still images, but with video as the top priority—and deliver them as royalty-free open source, suitable for both commercial and noncommercial content. The issue of patent licenses and royalties continues to plague the video industry. While H.264/AVC video had relatively cheap licensing, it looks as if its successor, H.265/HEVC, is going to be considerably more expensive . Organizations that derive significant income from patent royalties and IP licensing weren’t happy with the low-cost model used for H.264, and so are pushing back. This is a great threat to open source and non-commercial streaming, which has no obvious way to pay the royalties. The HEVC royalty structure would even threaten the viability of commercial streamers such as Netflix. The Alliance for Open Media would put an end to this problem. The group’s first aim is to produce a video codec that’s a meaningful improvement on HEVC. Many of the members already have their own work on next-generation codecs; Cisco has Thor , Mozilla has been working on Daala , and Google on VP9 and VP10. Daala and Thor are both also under consideration by the IETF’s netvc working group, which is similarly trying to assemble a royalty-free video codec. Read 4 remaining paragraphs | Comments

Visit link:
Microsoft, Google, Amazon, others, aim for royalty-free video codecs

Tesla strikes deal to buy lithium hydroxide mined in northern Mexico

On Friday, Tesla struck a deal with mining companies Bacanora Minerals Ltd and Rare Earth Minerals Plc. to purchase lithium compounds from a proposed mining site in northern Mexico. The mine is not functional yet—the deal requires the mining companies to raise funding to construct a mine as well as processing facilities over the next two years. But as the supply contract published by Bacanora  (PDF) states, the companies project that once the mine is up and running, it will be able to supply 35,000 tons of lithium compounds (namely, lithium hydroxide and lithium carbonate) per year at first, eventually expanding to 50,000 tons per year. Tesla has agreed to purchase a minimum amount of lithium hydroxide from Bacanora Minerals and Rare Earth Minerals for five years after the mine becomes operational, with the potential to extend the agreement. In exchange, the mining companies will sell their mined materials to Tesla at below market rate, the Wall Street Journal reports . Read 2 remaining paragraphs | Comments

Visit link:
Tesla strikes deal to buy lithium hydroxide mined in northern Mexico

City of Chicago sues red light camera maker Redflex for more than $300 million

Red light cameras in Arizona. Robert Couse-Baker The city of Chicago has joined a lawsuit against Redflex, an Australian company that sold the city red light cameras starting in 2003. Redflex announced the legal action in a statement to stockholders  (PDF) today, sending the company’s already-suffering stock down to $0.17 per share. The suit alleges  (PDF) that Redflex bribed a former Department of Transportation manager, John Bills, with $2 million in kickbacks to secure contracts with the city. The debacle has already resulted in corruption convictions, and the company’s CEO, Karen Finley, pleaded guilty to bribery earlier this year. Beyond these issues, Redflex cameras have been implicated in faulty ticketing accusations , with the company’s cameras allegedly issuing some 13,000 undeserved tickets to motorists in 2014. Redflex cameras have reportedly raised more than $500 million in traffic fines since 2003, according to the Chicago Tribune . Read 2 remaining paragraphs | Comments

Original post:
City of Chicago sues red light camera maker Redflex for more than $300 million

Six UK teens arrested for being “customers” of Lizard Squad’s DDoS service

On August 28, the United Kingdom’s National Crime Agency announced the arrest of six teenagers, ranging in age from 15 to 18, for launching distributed denial of service attacks against multiple websites. The attacks were carried out using an attack tool created by Lizard Squad , the group behind denial of service attacks on gaming networks and the 8Chan imageboard site last winter. Called Lizard Stresser, the tool exploited compromised home routers, using them as a robot army against targeted sites and services. The six arrested “are suspected of maliciously deploying Lizard Stresser, having bought the tool using alternative payment services such as Bitcoin in a bid to remain anonymous,” an NCA spokesperson wrote in an official statement on the case. “Organizations believed to have been targeted by the suspects include a leading national newspaper, a school, gaming companies, and a number of online retailers.” Those sites, according to a source that spoke with Bloomberg Business , included Microsoft’s Xbox Live, Sony’s Playstation network, and Amazon.com. The timing of the attacks wasn’t mentioned by NCA. However, the user database of Lizard Stresser was leaked in January of this year. The NCA has been investigating individuals listed in the database and has identified a substantial number of them living in the UK. “Officers are also visiting approximately 50 addresses linked to individuals registered on the Lizard Stresser website, but who are not currently believed to have carried out attacks,” the NCA spokesperson noted. “A third of the individuals identified are under the age of 20, and the activity forms part of the NCA’s wider work to address younger people at risk of entering into serious forms of cyber crime.” Read 3 remaining paragraphs | Comments

Continued here:
Six UK teens arrested for being “customers” of Lizard Squad’s DDoS service

Uber hires researchers who hacked Chrysler Uconnect

Less than a month after their command performances at the Black Hat and Def Con security conferences in Las Vegas, security researchers Charlie Miller (late of Twitter) and Chris Valasek (formerly of the security firm IOActive) have been poached by Uber—which ironically had security flaws in its own in-car technology exposed by University of California-San Diego researchers this month as well. According to a report from Reuters , Uber will announce the hiring of Miller and Valasek on Monday. Miller and Valasek’s research on Fiat Chrysler’s Uconnect system  exposed vulnerabilities in the design of the system that allowed them to take remote control of many of the systems of a targeted vehicle—as they demonstrated by shutting down the throttle of a 2014 Jeep Cherokee while it was being driven on an interstate by Wired reporter Andy Greenberg . The research, coordinated with Fiat Chrysler, led to the distribution of a fix by Chrysler and blocking of vulnerable ports by Sprint, the mobile carrier providing the network for Uconnect. But the attention garnered by the video led to Chrysler announcing a recall of 1.4 million vehicles to accelerate the installation of the software patches. Uber announced grants to the University of Arizona to fund autonomous vehicle technology earlier this week. The hiring of Miller and Valasek is likely part of an effort to ensure that Uber’s autonomous vehicle development work remains secure and may be partially prompted by the findings of the UCSD researchers Ian Foster, Andrew Prudhomme, Karl Koscher, and Stefan Savage. The group presented research at the Usenix Security conference two weeks ago that showed a telematics device used by Uber and some auto insurers could be compromised to take remote control of systems in a similar fashion to Miller and Valasek’s hack of the Jeep. Read 1 remaining paragraphs | Comments

More:
Uber hires researchers who hacked Chrysler Uconnect

AT&T grudgingly accepts $428 million in annual government funding

AT&T has struck a deal with the US government to get nearly $428 million per year to bring 10Mbps Internet service to parts of rural America after protesting that it shouldn’t have to provide speeds that fast. The money comes from the Connect America Fund, which draws from surcharges on Americans’ phone bills to pay for rural Internet service. AT&T accepted the money even though it  argued last year that rural customers don’t need Internet service better than the old standard of 4Mbps downstream and 1Mbps upstream. The FCC ignored AT&T’s protests  in December, raising the Connect America Fund download standard to 10Mbps while leaving the 1Mbps requirement unchanged. Eight months later, AT&T is now willing to provide at least 10Mbps/1Mbps service to 1.1 million rural homes and businesses in 18 states in exchange for “$427,706,650 in annual, ongoing support from the Connect America Fund,” yesterday’s FCC announcement said . The FCC said this will bring broadband to 2.2 million customers, apparently assuming an average of two people for each home and business. AT&T will get the money over six years with an option for a seventh, potentially bringing the total to about $3 billion, according to Multichannel News . AT&T and other carriers getting Connect America funding have to deploy Internet service to 40 percent of funded locations by the end of 2017, 60 percent by the end of 2018, 80 percent by the end of 2019, and to 100 percent of locations by the end of 2020, the article said. “This is one of the largest amounts accepted by any company,” FCC Chairman Tom Wheeler said. “The financial support provided by American ratepayers will bring significant benefits to AT&T’s rural communities, and we urge state and local leaders to help communities realize these benefits by facilitating the broadband buildout.” 10Mbps/1Mbps is still lower than the definition of broadband, which the FCC raised to 25Mbps down and 3Mbps up. The 18 states where AT&T will use the money are Alabama, Arkansas, California, Florida, Georgia, Illinois, Indiana, Kansas, Kentucky, Louisiana, Michigan, Mississippi, North Carolina, Ohio, South Carolina, Tennessee, Texas, and Wisconsin. AT&T has had wireline operations in 22 states since it bought BellSouth in 2006. In exchange for getting that merger approved, AT&T promised home Internet service of at least 200kbps (meeting the definition of broadband at the time) to 100 percent of residences by the end of 2007. AT&T claimed it met the requirement but has let its network fall into disrepair in the years since, leaving millions with slow Internet service or none at all. AT&T promised to expand broadband deployment in exchange for the FCC’s recent approval of its purchase of DirecTV, but not in the areas where it will use Connect America funding. The Connect America funding is for “rural service areas where the cost of broadband deployment might otherwise be prohibitive,” the FCC said. AT&T wasn’t the only company to get Connect America Fund money yesterday. CenturyLink accepted $506 million  annually to get 10Mbps Internet to nearly 1.2 million rural homes and businesses in 33 states. Overall, ten carriers accepted $1.5 billion in annual support to serve 3.6 million homes and businesses under the latest Connect America Fund awards, another FCC announcement said . The others include Cincinnati Bell, Consolidated Telecom, Fairpoint, Frontier, Hawaiian Telcom, Micronesian Telecom, and Windstream. The tenth carrier is Verizon, though that case is a bit complicated. Verizon conditionally accepted $48.6 million a year to serve rural areas in Texas and California, subject to regulatory approval of a sale that will transfer Verizon’s systems in those states to Frontier. Verizon, which also objected to the new 10Mbps requirement, did not accept any funding in states where it’s keeping its wireline facilities. There’s still $175 million left to be doled out, due to carriers not accepting the entire amount. “In states where carriers have declined support, the subsidies will be awarded by a competitive bidding process,” the FCC said.

View the original here:
AT&T grudgingly accepts $428 million in annual government funding

BitTorrent patched against flaw that allowed crippling DoS attacks

The maintainers of the open BitTorrent protocol for file sharing have fixed a vulnerability that allowed lone attackers with only modest resources to take down large sites using a new form of denial-of-service attack. The technique was disclosed two weeks ago in a research paper submitted to the 9th Usenix Workshop on Offensive Technologies. By sending vulnerable BitTorrent applications maliciously modified data, attackers could force them to flood a third-party target with data that was 50 to 120 times bigger than the original request. By replacing the attacker’s IP address in the malicious user datagram protocol request with the spoofed address of the target, the attacker could cause the data flood to hit the victim’s computer. In a blog post published Thursday , BitTorrent engineers said the vulnerability was the result of a flaw in a  reference implementation called libuTP . To fix the weakness, the uTorrent, BitTorrent, and BitTorrent Sync apps will require acknowledgments from connection initiators before providing long responses. Read 3 remaining paragraphs | Comments

Continued here:
BitTorrent patched against flaw that allowed crippling DoS attacks