NIST’s Draft To Remove Periodic Password Change Requirements Gets Vendors’ Approval

An anonymous reader writes: A recently released draft of the National Institute of Standards and Technology’s digital identity guidelines has met with approval by vendors. The draft guidelines revise password security recommendations and altering many of the standards and best practices security professionals use when forming policies for their companies. The new framework recommends, among other things: “Remove periodic password change requirements.” There have been multiple studies that have shown requiring frequent password changes to actually be counterproductive to good password security, said Mike Wilson, founder of PasswordPing. NIST said this guideline was suggested because passwords should be changed when a user wants to change it or if there is indication of breach. Read more of this story at Slashdot.

View post:
NIST’s Draft To Remove Periodic Password Change Requirements Gets Vendors’ Approval

IT Contractors In Australia Are Not Being Paid Due To Dispute With Payroll Service

New submitter evolutionary writes: Plutus Payroll, an Australian payroll company, is refusing to pay contractors due to a dispute with companies using their services. Around 1, 000 IT workers are unable to receive payment for services rendered. One may ask, “Where are the companies who actually hired the IT workers?” The Register reports: “This story starts with Australia’s employment laws, which see lots of contractors officially employed by recruitment companies or payroll companies. The company at which the contractor works likes this arrangement as it means they don’t have to put such people on their books. Recruitment companies and payroll companies charge for the service. Contractors generally like the convenience of having one employer even though they hop from gig to gig. The system requires fluid payments. Companies who hire contractors pay the recruiter, which either pays contractors direct or pays the payroll company contractors prefer. If the cash stops flowing, contractors get crunched. That’s what’s happened to around 1, 000 contractors who elected to use Plutus as their paymasters: the company says it is in the midst of a completely unexplained ‘dispute’ that leaves it unable to pay contractors, or receive money from recruitment companies, but is still solvent. The Register has checked with the bank that Plutus clients say sends them their money — the bank says it is aware of no dispute. One possible reason for the mess is that Plutus did not charge for its services. How it made money is therefore a mystery. Another scenario concerns the company’s recent acquisition: perhaps its new owners are being denied access to some service Plutus could access as a standalone company. Plutus is saying nothing of substance about the situation. A spokesperson tells us the company deeply regrets the situation but won’t divulge anything about the dispute and has offered no details about when contractors can expect resolution.” Read more of this story at Slashdot.

Continue reading here:
IT Contractors In Australia Are Not Being Paid Due To Dispute With Payroll Service

‘First Pirated Ultra HD Blu-Ray Disk’ Appears Online

Has AACS 2.0 encryption used to protect UHD Blu-ray discs been cracked? While the details are scarce, a cracked copy of a UHD Blu-ray disc surfaced on the HD-focused BitTorrent tracker UltraHDclub. TorrentFreak reports: The torrent in question is a copy of the Smurfs 2 film and is tagged “The Smurfs 2 (2013) 2160p UHD Blu-ray HEVC Atmos 7.1-THRONE.” This suggests that AACS 2.0 may have been “cracked” although there are no further technical details provided at this point. UltraHDclub is proud of the release, though, and boasts of having the “First Ultra HD Blu-ray Disc in the NET!” Those who want to get their hands on a copy of the file have to be patient though. Provided that they have access to the private tracker, it will take a while to download the entire 53.30 GB disk. TorrentFreak reached out to both the uploader of the torrent and an admin at the site hoping to find out more, but thus far we have yet to hear back. From the details provided, the copy appears to be the real deal although not everyone agrees. Read more of this story at Slashdot.

Read More:
‘First Pirated Ultra HD Blu-Ray Disk’ Appears Online

Linux Kernel 4.11 Officially Released

prisoninmate quotes Softpedia: Linux kernel 4.11 has been in development for the past two months, since very early March, when the first Release Candidate arrived for public testing. Eight RCs later, we’re now able to download and compile the final release of Linux 4.11 on our favorite GNU/Linux distributions and enjoy its new features. Prominent ones include scalable swapping for SSDs, a brand new perf ftrace tool, support for OPAL drives, support for the SMC-R (Shared Memory Communications-RDMA) protocol, journalling support for MD RAID5, all new statx() system call to replace stat(2), and persistent scrollback buffers for VGA consoles… The Linux 4.11 kernel also introduces initial support for Intel Gemini Lake chips, which is an Atom-based, low-cost computer processor family developed using Intel’s 14-nanometer technology, and better power management for AMD Radeon GPUs when the AMDGPU open-source graphics driver is used. Read more of this story at Slashdot.

More here:
Linux Kernel 4.11 Officially Released

A Database of Thousands of Credit Cards Was Left Exposed on the Open Internet

A US online pet store has exposed the details of more than 110, 400 credit cards used to make purchases through its website, researchers have found. From a report on ZDNet: In a stunning show of poor security, the Austin, TX-based company FuturePets.com exposed its entire customer database, including names, postal and email addresses, phone numbers, credit card information, and plain-text passwords. Several customers that we reached out to confirmed some of their information when it was provided by ZDNet, but did not want to be named. The database was exposed because of the company’s own insecure server and use of “rsync, ” a common protocol used for synchronizing copies of files between two different computers, which wasn’t protected with a username or password. Read more of this story at Slashdot.

Read the original:
A Database of Thousands of Credit Cards Was Left Exposed on the Open Internet

Facebook and Google Were Victims of $100M Payment Scam

Employees of Facebook and Google were the victims of an elaborate $100 million phishing attack, according to a new report on Fortune, which further adds that the employees were tricked into sending money to overseas bank accounts. From the report: In 2013, a 40-something Lithuanian named Evaldas Rimasauskas allegedly hatched an elaborate scheme to defraud U.S. tech companies. According to the Justice Department, he forged email addresses, invoices, and corporate stamps in order to impersonate a large Asian-based manufacturer with whom the tech firms regularly did business. The point was to trick companies into paying for computer supplies. The scheme worked. Over a two-year span, the corporate imposter convinced accounting departments at the two tech companies to make transfers worth tens of millions of dollars. By the time the firms figured out what was going on, Rimasauskas had coaxed out over $100 million in payments, which he promptly stashed in bank accounts across Eastern Europe. Fortune adds that the investigation raises questions about why the companies have so far kept silence and whether — as a former head of the Securities and Exchange Commission observes — it triggers an obligation to tell investors about what happened. Read more of this story at Slashdot.

View original post here:
Facebook and Google Were Victims of $100M Payment Scam

All-Electric ‘Flying Car’ Takes Its First Test Flight In Germany

Today, Munich-based Lilium Aviation conducted the first test flight of its all-electric, two-seater, vertical take-off and landing (VTOL) prototype. “In a video provided by the Munich-based startup, the aircraft can be seen taking off vertically like a helicopter, and then accelerating into forward flight using wing-borne lift, ” reports The Verge. From the report: The craft is powered by 36 separate jet engines mounted on its 10-meter long wings via 12 movable flaps. At take-off, the flaps are pointed downwards to provide vertical lift. And once airborne, the flaps gradually tilt into a horizontal position, providing forward thrust. During the tests, the jet was piloted remotely, but its operators say their first manned flight is close-at-hand. And Lilium claims that its electric battery “consumes around 90 percent less energy than drone-style aircraft, ” enabling the aircraft to achieve a range of 300 kilometers (183 miles) with a maximum cruising speed of 300 kph (183 mph). “It’s the same battery that you can find in any Tesla, ” Nathen told The Verge. “The concept is that we are lifting with our wings as soon as we progress into the air with velocity, which makes our airplane very efficient. Compared to other flights, we have extremely low power consumption.” The plan is to eventually build a 5-passenger version of the jet. Read more of this story at Slashdot.

Visit site:
All-Electric ‘Flying Car’ Takes Its First Test Flight In Germany

Microsoft Says It Will Release Two Feature Updates Per Year For Windows 10, Office

Microsoft is making a few changes to how it will service Windows, Office 365 ProPlus and System Center Configuration Manager. From a report: Announced today, Microsoft will be releasing two feature updates a year for Windows 10 in March in September and with each release, System Center Configuration Manager will support this new aligned update model for Office 365 ProPlus and Windows 10, making both easier to deploy and keep up to date. This is a big change for Microsoft as Windows will now be on a more predictable pattern for major updates and by aligning it with Office 365 Pro Plus, this should make these two platforms easier to service from an IT Pro perspective. The big news here is also that Microsoft is announcing when Redstone 3 is targeted for release. The company is looking at a September release window but it is worth pointing out that they traditionally release the month after the code is completed. Read more of this story at Slashdot.

Visit site:
Microsoft Says It Will Release Two Feature Updates Per Year For Windows 10, Office

Toyota Unveils Plan For Hydrogen Powered Semi Truck

New submitter omaha393 quotes a report from R&D Magazine: Toyota announced a new initiative on Wednesday aimed at advancing its work in vehicles powered by alternative energy sources. The automaker unveiled Project Portal, which is a novel hydrogen fuel cell system designed for heavy duty truck use at the Port of Los Angeles. A proof-of-concept truck powered by this fuel cell will be part of a feasibility study held at the Port this summer, with the goal of examining the potential of this technology in heavy-duty applications. The test vehicle will produce more than 670 horsepower and 1, 325 pound feet of torque from two of these novel fuel cell stacks along with a 12kWh battery. Overall, the combined weight capacity is 80, 000 pounds that will be carried over 200 miles. omaha393 adds: “While hydrogen fuel has been criticized due to high cost of production and safety concerns, recent advances in catalysis and solid storage systems have made the prospect of hydrogen fuel an attractive commercial prospect for the future.” Read more of this story at Slashdot.

View the original here:
Toyota Unveils Plan For Hydrogen Powered Semi Truck

StarCraft Is Now Free, Nearly 20 Years After Its Release

An anonymous reader quotes a report from TechCrunch: Nearly two decades after its 1998 release, StarCraft is now free. Legally! Blizzard has just released the original game — plus the Brood War expansion — for free for both PC and Mac. You can find it here. Up until a few weeks ago, getting the game with its expansion would’ve cost $10-15 bucks. The company says they’ve also used this opportunity to improve the game’s anti-cheat system, add “improved compatibility” with Windows 7, 8.1, and 10, and fix a few long lasting bugs. So why now? The company is about to release a remastered version of the game in just a few months, its graphics/audio overhauled for modern systems. Once that version hits, the original will probably look a bit ancient by comparison — so they might as well use it to win over a few new fans, right? Read more of this story at Slashdot.

More:
StarCraft Is Now Free, Nearly 20 Years After Its Release