Ubuntu Linux 17.04 ‘Zesty Zapus’ Final Beta Now Available For Download

BrianFagioli writes: The final beta of Ubuntu 17.04 ‘Zesty Zapus’ became available for download Thursday. While it is never a good idea to run pre-release software on production machines, Canonical is claiming that it should be largely bug free at this point. In other words, if you understand the risks, it should be a fairly safe. Home users aside, this is a good opportunity for administrators to conduct testing prior to the official release next month. “The Ubuntu team is pleased to announce the final beta release of the Ubuntu 17.04 Desktop, Server, and Cloud products. Codenamed ‘Zesty Zapus’, 17.04 continues Ubuntu’s proud tradition of integrating the latest and greatest open source technologies into a high-quality, easy-to-use Linux distribution, ” says Adam Conrad, Canonical. “The team has been hard at work through this cycle, introducing new features and fixing bugs.” Read more of this story at Slashdot.

Read more here:
Ubuntu Linux 17.04 ‘Zesty Zapus’ Final Beta Now Available For Download

How to Get Windows and macOS Apps on Your Chromebook

As capable as Chromebooks have become , there are times when you might need to load up Photoshop, iTunes or something else that relies on Windows or macOS. Not only can Chrome OS do this, it’s not that difficult to set up…if you know the right plug-ins to use. Here’s how to get started. Read more…

More here:
How to Get Windows and macOS Apps on Your Chromebook

The best password managers

By Joe Kissell This post was done in partnership with The Wirecutter , a buyer’s guide to the best technology. When readers choose to buy The Wirecutter’s independently chosen editorial picks, it may earn affiliate commissions that support its work. Read the full article here . If you’re not using a password manager, start now. As we wrote in Password Managers Are for Everyone—Including You , a password manager makes you less vulnerable online by generating strong random passwords, syncing them securely across your browsers and devices so they’re easily accessible everywhere, and filling them in automatically when needed. After 15 hours of research and testing, we believe that LastPass is the best password manager for most people. It has all the essential features plus some handy extras, it works with virtually any browser on any device, and most of its features are free. Who should get this Everyone should use a password manager . The things that make strong passwords strong—length, uniqueness, variety of characters—make them difficult to remember, so most people reuse a few easy-to-remember passwords everywhere they go online. But reusing passwords is dangerous: If just one site suffers a security breach, an attacker could access your entire digital life: email, cloud storage, bank accounts, social media, dating sites, and more. And if your reused password is weak, the problem is that much worse, because someone could guess your password even if there isn’t a security breach. If you have more than a handful of online accounts—and almost everyone does—you need a good password manager. It enables you to easily ensure that each password is both unique and strong, and it saves you the bother of looking up, remembering, typing, or even copying and pasting your passwords when you need them. If you don’t already use a password manager, you should get one, and LastPass is a fabulous overall choice for most users. How we picked and tested Although I’d already spent countless hours testing password managers in the course of writing my book Take Control of Your Passwords , for this article I redid most of the research and testing from scratch, because apps in this category change constantly—and often dramatically. I looked for tools that do their job as efficiently as possible without being intrusive or annoying. A password manager should disappear until you need it, do its thing quickly and with minimum interaction, and require as little thought as possible (even when switching browsers or platforms). And the barrier to entry should be low enough—in terms of both cost and simplicity—for nearly anyone to get up to speed quickly. I began by ruling out the password autofill features built into browsers like Chrome and Firefox—although they’re better than nothing, they tend to be less secure than stand-alone apps, and they provide no way to use your stored passwords with other browsers. Next I looked for apps that support all the major platforms and browsers. If you use only one or two platforms or browsers, support for the others may be irrelevant to you, but broad compatibility is still a good sign. This means, ideally, support for the four biggest platforms—Windows, macOS, iOS, and Android—as well as desktop browser integration with at least Chrome and Firefox, plus Safari on macOS. I excluded apps that force you to copy and paste passwords into your browser rather than offering a browser extension that lets you click a button or use a keystroke to fill in your credentials. And, because most of us use more than one computing device, the capability to sync passwords securely across those devices is essential. After narrowing down the options, I tested eight finalists: 1Password, Dashlane, Enpass, Keeper, LastPass, LogmeOnce, RoboForm, and Sticky Password. I tested for usability by doing a number of spot checks to verify that the features described in the apps’ marketing materials matched what I saw in real life. I set up a simple set of test forms on my own server that enabled me to evaluate how each app performed basic tasks such as capturing manually entered usernames and passwords, filling in those credentials on demand, and dealing with contact and credit card data. If my initial experiences with an app were good, I also tried that app with as many additional platforms and browsers as I could in order to form a more complete picture of its capabilities. I did portions of my testing on macOS 10.12, Windows 10, Chromium OS (as a stand-in for Chrome OS), iOS 10, Apple Watch, and Android. Our pick You can access LastPass in a browser extension, on the Web, or in a stand-alone app. Before I get to what’s great about LastPass, a word of context: LastPass , Dashlane , and 1Password are significantly better than the rest of the field. I suspect most people would be equally happy with any of them. What tipped the scales in favor of LastPass was the company’s announcement on November 2, 2016, that it was making cross-device syncing (formerly a paid feature) available for free. Although there’s still a Premium subscription that adds important features (more on that in our full guide ), this change makes LastPass a no-brainer for anyone who hasn’t yet started using a password manager. Even its $12/year premium tier is much cheaper than 1Password or Dashlane’s paid options. LastPass has the broadest platform support of any password manager I saw. Its autofill feature is flexible and nicely designed. You can securely share selected passwords with other people; there’s also an Emergency Access feature that lets you give a loved one or other trusted person access to your data. An Automatic Password Change feature works on many sites to let you change many passwords with one click, and a Security Challenge alerts you to passwords that are weak, old, or duplicates, or that go with sites that have suffered data breaches. LastPass works on macOS, Windows, iOS, Android, Chrome OS, Linux, Firefox OS, Firefox Mobile, Windows RT, Windows Phone—even Apple Watch and Android Wear smartwatches. (Sorry, no BlackBerry, Palm, or Symbian support.) It’s available as a browser extension for Chrome, Firefox, Safari, Internet Explorer, and Microsoft Edge, and it has desktop and mobile apps for various platforms. Upgrade pick for Apple users 1Password offers Mac and iOS users features not found in LastPass, plus a more-polished interface. If you’re a Mac, iPhone, and/or iPad user with a few extra bucks, and you’d like even more bells and whistles in your password manager, 1Password is well worth a look. 1Password has a more polished and convenient user interface than either LastPass or Dashlane. It’s also a little faster at most tasks; it has a local storage option if you don’t trust your passwords to the cloud; it gives you more options than LastPass for working with attached files; and it can auto-generate one-time tokens for many sites that use two-step verification—LastPass requires a separate app for this. 1Password is, however, more expensive than LastPass and doesn’t work on as many platforms: Windows and Chromebook users, especially, are better off with LastPass. This guide may have been updated by The Wirecutter . To see the current recommendation, please go here . Note from The Wirecutter: When readers choose to buy our independently chosen editorial picks, we may earn affiliate commissions that support our work.

Excerpt from:
The best password managers

Virally growing attacks on unpatched WordPress sites affects ~2m pages

Enlarge (credit: Wordfence ) Attacks on websites running an outdated version of WordPress are increasing at a viral rate. Almost 2 million pages have been defaced since a serious vulnerability in the content management system came to light nine days ago. The figure represents a 26 percent spike in the past 24 hours. A rogues’ gallery of sites have been hit by the defacements. They include conservative commentator Glenn Beck’s glennbeck.com, Linux distributor Suse’s news.opensuse.org, the US Department of Energy-supported jcesr.org, the Utah Office of Tourism’s travel.utah.gov, and many more. At least 19 separate campaigns are participating and, in many cases, competing against each other in the defacements. Virtually all of the vandalism is being carried out by exploiting a severe vulnerability WordPress fixed in WordPress version 4.7.2, which was released on January 26. In an attempt to curb attacks before automatic updates installed the patch, the severity of the bug—which resides in a programming interface known as REST—wasn’t disclosed until February 1. Read 4 remaining paragraphs | Comments

Continue reading here:
Virally growing attacks on unpatched WordPress sites affects ~2m pages

The City Of Munich Now Wants To Abandon Linux And Switch Back to Windows

“The prestigious FOSS project replacing the entire city’s administration IT with FOSS based systems, is about to be cancelled and decommissioned, ” writes long-time Slashdot reader Qbertino. TechRepublic reports: Politicians at open-source champion Munich will next week vote on whether to abandon Linux and return to Windows by 2021. The city authority, which made headlines for ditching Windows, will discuss proposals to replace the Linux-based OS used across the council with a Windows 10-based client. If the city leaders back the proposition it would be a notable U-turn by the council, which spent years migrating about 15, 000 staff from Windows to LiMux, a custom version of the Ubuntu desktop OS, and only completed the move in 2013… The use of the open-source Thunderbird email client and LibreOffice suite across the council would also be phased out, in favor of using “market standard products” that offer the “highest possible compatibility” with external and internal software… The full council will vote on whether to back the plan next Wednesday. If all SPD and CSU councillors back the proposal put forward by their party officials, then this new proposal will pass, because the two parties hold the majority. The leader of the Munich Green Party says the city will lose “many millions of euros” if the change is implemented. The article also reports that Microsoft moved its German headquarters to Munich last year. Read more of this story at Slashdot.

Link:
The City Of Munich Now Wants To Abandon Linux And Switch Back to Windows

Microsoft Teases Windows 10’s Upcoming ‘Project Neon’ Design Language

An anonymous reader quotes a report from Windows Central: Microsoft just gave developers a sneak peek at Project Neon, Microsoft’s upcoming design language for Windows 10 that aims to add fluidity, animation and blur to apps and the operating system. We exclusively revealed that this was in the works in late 2016, and today Microsoft has given us a first peak at what Project Neon will look like. During the Windows Developer Day livestream, an image of Project Neon was seen the background of one of the PowerPoint slides being shown off on stage. Although not much, it’s further confirmation that this is the end goal for Windows 10’s UI, and Project Neon will be bringing a fresh coat of paint to apps. Project Neon should benefit all types of Windows 10 devices, including Windows 10 Mobile, HoloLens and even Xbox. We’re still several months away from Project Neon being everywhere in Windows 10, and we’re expecting to see more at BUILD this coming May. In fact, a lot of the Project Neon APIs are available in the latest Insider Preview builds of Windows 10, meaning developers can already begin taking advantage of these new user interfaces and design language! Animations and transitions are a big deal with Project Neon, with the goal of making the operating system and apps feel like they work together. Peter Bright does a good job summarizing the looks of the screenshot via Ars Technica: “The picture shows a refreshed version of the Groove music app on a Windows desktop. The fundamentals of the app and its layout aren’t changed, underscoring that Neon is very much an iteration of the current Metro/Microsoft Design Language (MDL). The window has shed its discrete title bar and one pixel border, with the application content now extending to the very edge of the window. The search text field no longer has a box around it, and the left hand pane has a hint of translucency to it.” You can view the screenshot here and judge it for yourself. Read more of this story at Slashdot.

More here:
Microsoft Teases Windows 10’s Upcoming ‘Project Neon’ Design Language

Privacy-Centric Linux Distro Tails 3.0 Will Drop 32-Bit Processor Support

All of its outgoing connections are routed through Tor, and it even blocks non-anonymous connections. You can carry it around on a USB stick, and Edward Snowden uses it. But a big change is coming with Tails 3.0. BrianFagioli quotes BetaNews: Unfortunately for some users, Tails will soon not work on their computers. The upcoming version 3.0 of the operating system is dropping 32-bit processor support. While a decline in compatibility is normally a bad thing, in this case, it is good. You see, because there are so few 32-bit Tails users, the team was wasting resources by supporting them. Not to mention, 64-bit processors are more secure too… “In the beginning of 2016, only 4% of Tails users were still using a 32-bit computer. Of course, some of these computers will keep working for a while. But once the number had fallen this low, the benefits of switching Tails to 64-bit outweighed the reasons we had to keep supporting 32-bit computers, ” says the Tails team… “In the last few years, the developers who maintain Tails have spent lots of time addressing such issues. We would rather see them spend their time in ways that benefit our users on the long term, and not on problems that will vanish when Tails switches to 64-bit eventually.” Read more of this story at Slashdot.

Continue Reading:
Privacy-Centric Linux Distro Tails 3.0 Will Drop 32-Bit Processor Support

GitLab.com Melts Down After Wrong Directory Deleted, Backups Fail

An anonymous reader quotes a report from The Register: Source-code hub Gitlab.com is in meltdown after experiencing data loss as a result of what it has suddenly discovered are ineffectual backups. On Tuesday evening, Pacific Time, the startup issued the sobering series of tweets, starting with “We are performing emergency database maintenance, GitLab.com will be taken offline” and ending with “We accidentally deleted production data and might have to restore from backup. Google Doc with live notes [link].” Behind the scenes, a tired sysadmin, working late at night in the Netherlands, had accidentally deleted a directory on the wrong server during a frustrating database replication process: he wiped a folder containing 300GB of live production data that was due to be replicated. Just 4.5GB remained by the time he canceled the rm -rf command. The last potentially viable backup was taken six hours beforehand. That Google Doc mentioned in the last tweet notes: “This incident affected the database (including issues and merge requests) but not the git repos (repositories and wikis).” So some solace there for users because not all is lost. But the document concludes with the following: “So in other words, out of 5 backup/replication techniques deployed none are working reliably or set up in the first place.” At the time of writing, GitLab says it has no estimated restore time but is working to restore from a staging server that may be “without webhooks” but is “the only available snapshot.” That source is six hours old, so there will be some data loss. Read more of this story at Slashdot.

See original article:
GitLab.com Melts Down After Wrong Directory Deleted, Backups Fail

Firefox 51 Arrives With HTTP Warning, WebGL 2 and FLAC Support

Reader Krystalo writes: Mozilla today launched Firefox 51 for Windows, Mac, Linux, and Android. The new version includes a new warning for websites which collect passwords but don’t use HTTPS, WebGL 2 support for better 3D graphics, and FLAC (Free Lossless Audio Codec) playback. Mozilla doesn’t break out the exact numbers for Firefox, though the company does say “half a billion people around the world” use the browser. In other words, it’s a major platform that web developers target — even in a world increasingly dominated by mobile apps. Read more of this story at Slashdot.

See original article:
Firefox 51 Arrives With HTTP Warning, WebGL 2 and FLAC Support

Malwarebytes Discovers ‘First Mac Malware of 2017’

wiredmikey writes: Security researchers have a uncovered a Mac OS based espionage malware they have named “Quimitchin.” The malware is what they consider to be “the first Mac malware of 2017, ” which appears to be a classic espionage tool. While it has some old code and appears to have existed undetected for some time, it works. It was discovered when an IT admin noticed unusual traffic coming from a particular Mac, and has been seen infecting Macs at biomedical facilities. From SecurityWeek.com: “Quimitchin comprises just two files: a .plist file that simply keeps the .client running at all times, and the .client file containing the payload. The latter is a ‘minified and obfuscated’ perl script that is more novel in design. It combines three components, Thomas Reed, director of Mac offerings at Malwarebytes and author of the blog post told SecurityWeek: ‘a Mac binary, another perl script and a Java class tacked on at the end in the __DATA__ section of the main perl script. The script extracts these, writes them to /tmp/ and executes them.’ Its primary purpose seems to be screen captures and webcam access, making it a classic espionage tool. Somewhat surprisingly the code uses antique system calls. ‘These are some truly ancient functions, as far as the tech world is concerned, dating back to pre-OS X days, ‘ he wrote in the blog post. ‘In addition, the binary also includes the open source libjpeg code, which was last updated in 1998.’ The script also contains Linux shell commands. Running the malware on a Linux machine, Malwarebytes ‘found that — with the exception of the Mach-O binary — everything ran just fine.’ It is possible that there is a specific Linux variant of the malware in existence — but the researchers have not been able to find one. It did find two Windows executable files, courtesy of VirusTotal, that communicated with the same CC server. One of them even used the same libjpeg library, which hasn’t been updated since 1998, as that used by Quimitchin.” Read more of this story at Slashdot.

Original post:
Malwarebytes Discovers ‘First Mac Malware of 2017’