Former Microsoft employee gets 3 months in jail for leaking Windows 8 secrets

Earlier this week, a man accused of stealing trade secrets from Microsoft and handing them to a French blogger was sentenced to three months in jail and a $100 fine in the Western District of Washington. Alex Kibkalo worked for Microsoft in the company’s Russia and Lebanon offices. According to an FBI complaint filed earlier this year, Kibkalo leaked pre-release updates for Windows RT and a Microsoft-internal Activation Server SDK to a French blogger in retaliation for a poor performance review. The blogger allegedly asked a third party to verify the stolen SDK, but that third party, who connected with the blogger via Hotmail, alerted Microsoft of the theft instead. At that point, Microsoft launched its own internal investigation and searched the Hotmail account to find the blogger and his source. The company’s investigation team was soon able to trace back to Kibkalo and then discovered that he had created a virtual machine on Microsoft’s corporate network from which he uploaded the stolen goods to SkyDrive. When confronted, Kibkalo admitted to handing over software, company memos, and other documents. He was fired and later arrested. Read 3 remaining paragraphs | Comments

Original post:
Former Microsoft employee gets 3 months in jail for leaking Windows 8 secrets

Local cops in 15 US states confirmed to use cell tracking devices

ACLU A new map released  Thursday by the American Civil Liberties Union shows that fake cell towers, also known as stingrays, are used by state and local law enforcement in 15 states. Police departments in Baltimore, Chicago, Houston, Tucson, Los Angeles, and even Anchorage, among others, have been confirmed to use the devices. Beyond those states, 12 federal law enforcement agencies, ranging from the FBI to the National Security Agency, also employ them. Relatively little is known about precisely how police decide when and where to deploy them, but stingrays are used to track targeted phones and can also be used to intercept calls and text messages. However, privacy advocates worry that while the devices go after specific targets, they also often capture data of nearby unrelated people. Read 4 remaining paragraphs | Comments

Read More:
Local cops in 15 US states confirmed to use cell tracking devices

Google’s university book scanning can move ahead without authors’ OK

random letters/Flickr A federal appeals court on Tuesday upheld the right of universities, in conjunction with Google, to scan millions of library books without the authors’ permission. The 2nd US Circuit Court of Appeals, ruling in a case brought by the Authors Guild and other writers’ groups, argued that the universities were not breaching federal copyright law, because the institutions were protected by the so-called “fair use” doctrine. More than 73 percent of the volumes were copyrighted. The guild accused 13 universities in all of copyright infringement for reproducing more than 10 million works without permission and including them in what is called the HathiTrust Digital Library  (HDL) available at 80 universities. The institutions named in the case include the University of California, Cornell University, Indiana University, and the University of Michigan. Read 7 remaining paragraphs | Comments

Read the original:
Google’s university book scanning can move ahead without authors’ OK

Is Chicago using cell tracking devices? One man tries to find out

David D’Agostino A local activist has filed a new lawsuit against the Chicago Police Department in an attempt to learn how the city uses fake cell tower devices, also known as stingrays. Relatively little is known about the devices, which are used to track targeted phones and can also be used to intercept calls and text messages. The American Civil Liberties Union recently began a campaign to learn more about how stingrays are used by filing public records requests in Florida, the home state of the Stingray’s manufacturer, Harris Corporation. (While “Stringray” is a trademarked name and particular product, it has entered the technical lexicon as a generic term, like Kleenex or Xerox.) In nearly every sales agreement , that firm has required law enforcement agencies to sign nondisclosure agreements forbidding them from discussing whether or not an agency even possesses such a device, much less describing its capabilities. Read 8 remaining paragraphs | Comments

More:
Is Chicago using cell tracking devices? One man tries to find out

We “will be paying no ransom,” vows town hit by Cryptowall ransom malware

Cisco Systems The town manager of a hamlet in south eastern New Hampshire has defied demands that he pay a ransom to recover police department computer files taken hostage by Cryptowall, a newer piece of malware that encrypts hard drive contents of infected machines until victims pay for them to be decrypted. “Make no mistake, the Town of Durham will be paying no ransom,” Town Manager Todd Selig was quoted as saying by CBS Boston news. Police department computers for the town of almost 15,000 residents were reportedly infected Thursday after an officer opened what appeared to be a legitimate file attachment to an e-mail. By Friday morning, widespread “issues” were hitting the department computer network . It was shut down by noon that day to prevent the infection from spreading to other systems. The game may be RIGged The department was reportedly hit by Cryptowall, a newer form of crypto malware that rivals the better known CryptoLocker . According to a blog post published Thursday by researchers from Cisco Systems, Cryptowall has been gaining ground since April, when it was folded into the RIG exploit kit, which is software sold in underground forums that automates computer scams and malware attacks for less technically knowledgeable criminals. Cisco’s Cloud Web Security service has been blocking requests tied to more than 90 infected Internet domains pushing Cryptowall scams to more than 17 percent of service customers. Read 6 remaining paragraphs | Comments

Excerpt from:
We “will be paying no ransom,” vows town hit by Cryptowall ransom malware

“WARNING Your phone is locked!” Crypto ransomware makes its debut on Android

Eset Security researchers have documented another first in the annals of Android malware: a trojan that encrypts photos, videos, and documents stored on a device and demands a ransom for them to be restored. The crudeness of Android/Simplocker, as the malicious app has been dubbed, suggests it’s still in the proof-of-concept phase, Robert Lipovsky, a malware researcher for antivirus provider Eset, said in a recent blog post . The malware also addresses users in Russian and demands that payments be made in Ukrainian hryvnias, an indication that it targets only people in Eastern Europe. Still, the trojan—with its combination of social engineering, strong encryption, and robust Internet architecture—could be a harbinger of more serious and widespread threats to come. After all, the first Android trojans to make hefty SMS charges also debuted in the same region. Once installed on a device, the app delivers the following message: Read 3 remaining paragraphs | Comments

More:
“WARNING Your phone is locked!” Crypto ransomware makes its debut on Android

California top court says red light camera photos are evidence

A red light camera at the intersection of Sylvan and Coffee in Modesto, California. Cyrus Farivar On Thursday, the California Supreme Court upheld the admissibility of images taken from red light cameras as evidence of traffic violations in the Golden State. The unanimous decision in the case, known as The People of California v. Goldsmith , marks the end of a five-year-old legal odyssey. Fines issued as the result of a red light camera in California are by far the highest nationwide ($436 in this case)—typically they’re in the $100 range in the rest of the country. The decision  (PDF) comes amid a flurry of challenges to the red light cameras before other state high courts: the Louisiana Supreme Court recently declined to hear such a case, letting stand a lower court ruling that challenged cameras in New Orleans. The Illinois Supreme Court heard oral arguments against  such cameras in Chicago in May 2014. A decision in a similar case currently before the Ohio Supreme Court is expected before the end of the year. Read 11 remaining paragraphs | Comments

See more here:
California top court says red light camera photos are evidence

Comcast charged $2,000 for alarm system that didn’t work—for 7 years

Houston resident Lisa Leeson says she paid Comcast nearly $2,000 over seven years for an alarm system, only to find out that it never worked. Comcast, it turns out, installed the alarm system improperly. Even though the alarm made a sound indicating that it was active when Leeson and her family set it each day, “It was unable… to actually call the police and/or Comcast once it was activated,” Leeson told KPRC Local 2 Houston . What did Comcast do after the problem was finally discovered? At first, the company offered only a $20 credit, before eventually agreeing to refund all of the money. “When Davis called Comcast’s corporate office, a spokesman apologized, but not before he pointed to a line in Leeson’s alarm agreement where she agreed to ‘test her system’ on ‘a regular basis,'” the news station reported. “Chances are your alarm company requires the same, putting the onus back on you to make sure your system is functioning properly.” Read 5 remaining paragraphs | Comments

Continue Reading:
Comcast charged $2,000 for alarm system that didn’t work—for 7 years

Meet “Cupid,” the Heartbleed attack that spawns “evil” Wi-Fi networks

A packet capture showing Cupid attacking a wireless network. SysValue It just got easier to exploit the catastrophic Heartbleed vulnerability against wireless networks and the devices that connect to them thanks to the release last week of open source code that streamlines the process of plucking passwords, e-mail addresses, and other sensitive information from vulnerable routers and connected clients. Dubbed Cupid, the code comes in the form of two software extensions. The first gives wireless networks the ability to deploy “evil networks” that surreptitiously send malicious packets to connected devices. Client devices relying on vulnerable versions of the OpenSSL cryptography library can then be forced to transmit contents stored in memory. The second extension runs on client devices. When connecting to certain types of wireless networks popular in corporations and other large organizations, the devices send attack packets that similarly pilfer data from vulnerable routers. The release of Cupid comes eight weeks after the disclosure of Heartbleed , one of the most serious vulnerabilities to ever hit the Internet. The flaw, which existed for more than two years in OpenSSL, resides in “heartbeat” functions designed to keep a transport layer security (TLS) connection alive over an extended period of time. Read 5 remaining paragraphs | Comments

See more here:
Meet “Cupid,” the Heartbleed attack that spawns “evil” Wi-Fi networks

OS X Yosemite unveiled at WWDC, features big UI overhaul

Photo by DAVID ILIFF. License: CC-BY-SA 3.0 This morning at Apple’s 2014 Worldwide Developer’s Conference, Apple SVP Craig Federighi gave us our first official look at the upcoming version of the Macintosh desktop operating system. This is the tenth formal release of OS X (which is pronounced “oh ess ten,” never “oh ess ecks”); Apple’s naming convention uses “OS X” as the brand, separate from the version, and so the brand and version of this release is indeed “OS X 10.10″—”oh ess ten ten dot ten” (or “ten point ten,” if you insist). Starting with OS X 10.9, though, Apple has given the OS California-themed names—10.9 was “OS X Mavericks,” after a famous surfing location, and this new version is “OS X Yosemite,” named after California’s Yosemite National Park. Mavericks’ branding and banners were all wave-related, after the surf theme; Yosemite’s desktop features the famous slab-sided southwest face of Half Dome , one of the park’s most recognizable rock formations. (PC gamers who cut their teeth in the late 80s and 90s will also recognize Half Dome from its role as the logo of the legendary adventure gaming company Sierra On-Line .) Translucency and new Dock icons. “Translucency” is the name of the day, with trandlucent panels and sidebars popping up all in all windows. The icons in the Dock have also gotten a big overhaul, gaining a very iOS-like appearance across the board. “You wouldn’t believe how much time we spent crafting that trash can,” joked Federighi. The revised interface can also be shifted to a “dark” mode, where windows and menus shift to light text on a smoky background instead of the Mac’s more typical black-on-white. Read 6 remaining paragraphs | Comments

Read the original:
OS X Yosemite unveiled at WWDC, features big UI overhaul