Intel Security Releases Detection Tool For EFI Rootkits After CIA Leak

After WikiLeaks revealed data exposing information about the CIA’s arsenal of hacking tools, Intel Security has released a tool that allows users to check if their computer’s low-level system firmware has been modified and contains unauthorized code. PCWorld reports: The release comes after CIA documents leaked Tuesday revealed that the agency has developed EFI (Extensible Firmware Interface) rootkits for Apple’s Macbooks. The documents from CIA’s Embedded Development Branch (EDB) mention an OS X “implant” called DerStarke that includes a kernel code injection module dubbed Bokor and an EFI persistence module called DarkMatter. In addition to DarkMatter, there is a second project in the CIA EDB documents called QuarkMatter that is also described as a “Mac OS X EFI implant which uses an EFI driver stored on the EFI system partition to provide persistence to an arbitrary kernel implant.” The Advanced Threat Research team at Intel Security has created a new module for its existing CHIPSEC open-source framework to detect rogue EFI binaries. CHIPSEC consists of a set of command-line tools that use low-level interfaces to analyze a system’s hardware, firmware, and platform components. It can be run from Windows, Linux, macOS, and even from an EFI shell. The new CHIPSEC module allows the user to take a clean EFI image from the computer manufacturer, extract its contents and build a whitelist of the binary files inside. It can then compare that list against the system’s current EFI or against an EFI image previously extracted from a system. Read more of this story at Slashdot.

Read More:
Intel Security Releases Detection Tool For EFI Rootkits After CIA Leak

Mozilla Firefox 52 Released As ESR Branch, Will Receive Security Updates Until 2018

prisoninmate quotes a report from Softpedia: Back in January, we told you that the development of the Mozilla Firefox 52.0 kicked off with the first Beta release and promised to let users send and open tabs from one device to another, among numerous other improvements and new features. Nine beta builds later, Mozilla has pushed today, March 7, the final binary and source packages of the Mozilla Firefox 52.0 web browser for all supported platforms, including GNU/Linux, macOS, and Windows. The good news is that Firefox 52.0 is an ESR (Extended Support Release) branch that will be supported until March-April 2018. Prominent features of the Mozilla Firefox 52.0 ESR release include support for the emerging WebAssembly standard to boost the performance of Web-based games and apps without relying on plugins, the ability to send and open tabs from one device to another, as well as multi-process for Windows users with touchscreens. With each new Firefox release, Mozilla’s developers attempt to offer new ways to improve the security of the widely-used web browser across all supported platforms. Firefox 52.0 ESR implements a “This connection is not secure” warning for non-secure pages that require user logins, along with a new Strict Secure Cookies specification. Read more of this story at Slashdot.

Read the article:
Mozilla Firefox 52 Released As ESR Branch, Will Receive Security Updates Until 2018

Windows 10 Build 15048 Has a Windows Mixed Reality Demo You Can Try

Microsoft’s big push into mixed reality involves headsets from multiple manufacturers (including ASUS, Dell, HP, Lenovo), and developer kits with Acer’s headset will begin a phased rollout this month. But Windows 10’s latest “Insider Preview” build already includes a mixed reality simulator with a first-person 3D environment that can be navigated with the W, A, S and D keys. Slashdot reader Mark Wilson writes: From the look of the changelog for Windows 10 build 15048 that was released a few days ago to Insiders, it looked to be little more than a bug fixing release. But in fact Microsoft has already started to include references to — and even a portal for — Windows Mixed Reality. We have seen reference to Windows Holographic in Windows 10 before, but this is the first time there has been anything to play with. It coincides nicely with Microsoft revealing that Windows Mixed Reality is the new name for Windows Holographic, and it gives Insiders the chance to not only see if their computer meets the recommended specs, but also to try out a Windows Mixed reality simulation. Read more of this story at Slashdot.

Originally posted here:
Windows 10 Build 15048 Has a Windows Mixed Reality Demo You Can Try

More Fast Food Restaurants Are Now Automating

An anonymous reader writes: Wendy’s is adding self-service ordering kiosks “to at least 1, 000 restaurants, or about 15% of its stores, ” reports the Los Angeles Times, while McDonald’s and Panera Bread are now planning to add kiosks to every restaurant. “Lots of restaurants, not just fast-food chains, are really trying to mitigate the costs of higher wages, ” says one market research firm, while also citing a survey which found 40% of millennials willing to use kiosks (compared to 30% of restaurant-goers overall). But in some cases this means more work for human employees. Quartz points out that McDonalds doesn’t plan to reduce its workforce after installing kiosks, and Panera Bread “has said that at some locations where it has ordering kiosks, it has actually increased human hours to help the kitchen keep up with the higher number of orders that come in through the more efficient ordering system.” Read more of this story at Slashdot.

See more here:
More Fast Food Restaurants Are Now Automating

Researchers Store Computer OS, Short Movie On DNA

An anonymous reader quotes a report from Phys.Org: In a new study published in the journal Science, a pair of researchers at Columbia University and the New York Genome Center (NYGC) show that an algorithm designed for streaming video on a cellphone can unlock DNA’s nearly full storage potential by squeezing more information into its four base nucleotides. They demonstrate that this technology is also extremely reliable. Erlich and his colleague Dina Zielinski, an associate scientist at NYGC, chose six files to encode, or write, into DNA: a full computer operating system, an 1895 French film, “Arrival of a train at La Ciotat, ” a $50 Amazon gift card, a computer virus, a Pioneer plaque and a 1948 study by information theorist Claude Shannon. They compressed the files into a master file, and then split the data into short strings of binary code made up of ones and zeros. Using an erasure-correcting algorithm called fountain codes, they randomly packaged the strings into so-called droplets, and mapped the ones and zeros in each droplet to the four nucleotide bases in DNA: A, G, C and T. The algorithm deleted letter combinations known to create errors, and added a barcode to each droplet to help reassemble the files later. In all, they generated a digital list of 72, 000 DNA strands, each 200 bases long, and sent it in a text file to a San Francisco DNA-synthesis startup, Twist Bioscience, that specializes in turning digital data into biological data. Two weeks later, they received a vial holding a speck of DNA molecules. To retrieve their files, they used modern sequencing technology to read the DNA strands, followed by software to translate the genetic code back into binary. They recovered their files with zero errors, the study reports. The study also notes that “a virtually unlimited number of copies of the files could be created with their coding technique by multiplying their DNA sample through polymerase chain reaction (PCR).” The researchers also “show that their coding strategy packs 215 petabytes of data on a single gram of DNA.” Read more of this story at Slashdot.

Taken from:
Researchers Store Computer OS, Short Movie On DNA

An Incorrect Command Entered By Employee Triggered Disruptions To S3 Storage Service, Knocking Down Dozens of Websites, Amazon Says

Amazon is apologizing for the disruptions to its S3 storage service that knocked down and — in some cases affected — dozens of websites earlier this week. The company also outlined what caused the issue — the event was triggered by human error. The company said an authorized S3 team member using an established playbook executed a command which was intended to remove a small number of servers for one of the S3 subsystems that is used by the S3 billing process. “Unfortunately, one of the inputs to the command was entered incorrectly and a larger set of servers was removed than intended, ” the company said in a press statement Thursday. It adds: The servers that were inadvertently removed supported two other S3 subsystems. One of these subsystems, the index subsystem, manages the metadata and location information of all S3 objects in the region. This subsystem is necessary to serve all GET, LIST, PUT, and DELETE requests. The second subsystem, the placement subsystem, manages allocation of new storage and requires the index subsystem to be functioning properly to correctly operate. The placement subsystem is used during PUT requests to allocate storage for new objects. Removing a significant portion of the capacity caused each of these systems to require a full restart. While these subsystems were being restarted, S3 was unable to service requests. Other AWS services in the US-EAST-1 Region that rely on S3 for storage, including the S3 console, Amazon Elastic Compute Cloud (EC2) new instance launches, Amazon Elastic Block Store (EBS) volumes (when data was needed from a S3 snapshot), and AWS Lambda were also impacted while the S3 APIs were unavailable. Read more of this story at Slashdot.

Continue reading here:
An Incorrect Command Entered By Employee Triggered Disruptions To S3 Storage Service, Knocking Down Dozens of Websites, Amazon Says

For This Year’s iPhone, Apple Is Ditching Lightning Connector and Home Button, But Embracing USB Type-C and Curved Display

Apple has decided to adopt a flexible display for at least one model of the new iPhone, reports WSJ. From the report: People with direct knowledge of Apple’s production plans said the Cupertino, Calif., company has decided to go ahead with the technology, and it will release a phone model using the OLED screens this year (Editor’s note: the link could be paywalled; alternate source). The technology allows manufacturers to bend screens in ways they couldn’t previously — such as by introducing a curve at the edge of the phone as in some Samsung models. However, once the phone is manufactured, the OLED screen can’t be bent or folded by the user, at least with current technology. Using OLED displays would allow Apple to introduce a phone with a new look to fuel sales. They said Apple would introduce other updates including a USB-C port for the power cord and other peripheral devices instead of the company’s original Lightning connector. The models would also do away with a physical home button, they said. Those updates would give the iPhone features already available on other smartphones. Read more of this story at Slashdot.

Read More:
For This Year’s iPhone, Apple Is Ditching Lightning Connector and Home Button, But Embracing USB Type-C and Curved Display

Raspberry Pi Zero W is a $10 Computer With Wi-Fi and Bluetooth

On the fifth birthday of the original Raspberry Pi, the foundation has announced the Raspberry Pi Zero W, a slightly more capable variant of the miniature computer. From a report on BetaNews: It’s essentially a Pi Zero with the addition of the two features many people have been requesting — wireless LAN and Bluetooth. Priced at $10, the Pi Zero W uses the same Cypress CYW43438 wireless chip as Raspberry Pi 3 Model B to deliver 802.11n wireless LAN and Bluetooth 4.0 connectivity. The full list of features is as follows: 1GHz, single-core CPU, 512MB RAM, mini-HDMI port, micro-USB On-The-Go port, micro-USB power, HAT-compatible 40-pin header, composite video and reset headers, CSI camera connector, 11n wireless LAN, and Bluetooth 4.0. Read more of this story at Slashdot.

See the original post:
Raspberry Pi Zero W is a $10 Computer With Wi-Fi and Bluetooth

Fasting Diet ‘Regenerates Diabetic Pancreas’

According to a new study published in the journal Cell, a certain type of fasting diet can trigger the pancreas to regenerate itself. Of course, the researchers advise people not to try this without medical advice. BBC reports: In the experiments, mice were put on a modified form of the “fasting-mimicking diet.” It is like the human form of the diet when people spend five days on a low calorie, low protein, low carbohydrate but high unsaturated-fat diet. It resembles a vegan diet with nuts and soups, but with around 800 to 1, 100 calories a day. Then they have 25 days eating what they want — so overall it mimics periods of feast and famine. Previous research has suggested it can slow the pace of aging. But animal experiments showed the diet regenerated a special type of cell in the pancreas called a beta cell. These are the cells that detect sugar in the blood and release the hormone insulin if it gets too high. There were benefits in both type 1 and type 2 diabetes in the mouse experiments. Type 1 is caused by the immune system destroying beta cells and type 2 is largely caused by lifestyle and the body no longer responding to insulin. Further tests on tissue samples from people with type 1 diabetes produced similar effects. Read more of this story at Slashdot.

Read the original post:
Fasting Diet ‘Regenerates Diabetic Pancreas’

World’s Largest Spam Botnet Adds DDoS Feature

An anonymous reader writes from a report via BleepingComputer: Necurs, the world’s largest spam botnet with nearly five million infected bots, of which one million are active each day, has added a new module that can be used for launching DDoS attacks. The sheer size of the Necurs botnet, even in its worst days, dwarfs all of today’s IoT botnets. The largest IoT botnet ever observed was Mirai Botnet #14 that managed to rack up around 400, 000 bots towards the end of 2016 (albeit the owner of that botnet has now been arrested). If this new feature were to ever be used, a Necurs DDoS attack would easily break every DDoS record there is. Fortunately, no such attack has been seen until now. Until now, the Necurs botnet has been seen spreading the Dridex banking trojan and the Locky ransomware. According to industry experts, there’s a low chance we’d see the Necurs botnet engage in DDoS attacks because the criminal group behind the botnet is already making too much money to risk exposing their full infrastructure in DDoS attacks. Read more of this story at Slashdot.

See the original post:
World’s Largest Spam Botnet Adds DDoS Feature