Apps come bundled with secret Bitcoin mining programs, paper over the practice with EULAs

Researchers at Malwarebytes have discovered that some programs covertly install Bitcoin-mining software on users’ computers , papering over the practice by including sneaky language in their license agreements allowing for “computer calculations, security.” The malicious programs include YourFreeProxy from Mutual Public, AKA We Build Toolbars, LLC, AKA WBT. YourFreeProxy comes with a program called Monitor.exe, which repeatedly phones home to WBT, eventually silently downloading and installing a Bitcoin mining program called “jhProtominer.” So now that we have proof that a PUP is installing miners on users systems, do they do it without ever letting the user know? Well not exactly, their EULA specifically covers a section on Computer Calculations: COMPUTER CALCULATIONS, SECURITY: as part of downloading a Mutual Public, your computer may do mathematical calculations for our affiliated networks to confirm transactions and increase security. Any rewards or fees collected by WBT or our affiliates are the sole property of WBT and our affiliates. Their explanation is basically the purpose of Bitcoin Miners and that they will install this software on the system, run it, use up your system resources and finally keep all rewards from the effort YOUR system puts in. Talk about sneaky. In my opinion, PUPs have gone to a new low with the inclusion of this type of scheme, they already collected information on your browsing and purchasing habits with search toolbars and redirectors. They assault users with pop-up ads and unnecessary software to make a buck from their affiliates. Now they are just putting the nails in the coffin by stealing resources and driving user systems to the grave. Potentially Unwanted Miners – Toolbar Peddlers Use Your System To Make BTC [Adam Kujawa/Malwarebytes] ( via /. )        

Originally posted here:
Apps come bundled with secret Bitcoin mining programs, paper over the practice with EULAs

New CC licenses: tighter, shorter, more readable, more global

Creative Commons has released version 4.0 of its sharing-friendly, easy-to-use copyright licenses . The new licenses represent a significant improvement over earlier versions. They work in over 60 jurisdictions out of the box, without having to choose different versions depending on which country you’re in; they’re more clearly worded; they eliminate confusion over jurisdiction-specific rights like the European database right and moral rights. They clarify how license users are meant to attribute the works they use; provide for anonymity in license use; and give license users a 30 day window to correct violations, making enforcement simpler. Amazingly, they’re also shorter than the previous licenses, and easier to read, to boot. 30-day window to correct license violations All CC licenses terminate when a licensee breaks their terms, but under 4.0, a licensee’s rights are reinstated automatically if she corrects a breach within 30 days of discovering it. The cure period in version 4.0 resembles similar provisions in a some other public licenses and better reflects how licensors and licensees resolve compliance issues in practice. It also assures users that provided they act promptly, they can continue using the CC-licensed work without worry that they may have lost their rights permanently. Increased readability The 4.0 license suite is decidedly easier to read and understand than prior versions, not to mention much shorter and better organized. The simplified license structure and use of plain language whenever possible increases the likelihood that licensors and reusers will understand their rights and obligations. This improves enforceability of the licenses and reduces confusion and disagreement about how the licenses operate. Clarity about adaptations The BY and BY-NC 4.0 licenses are clearer about how adaptations are to be licensed, a source of confusion for some under the earlier versions of those licenses. These licenses now clarify that you can apply any license to your contributions you want so long as your license doesn’t prevent users of the remix from complying with the original license. While this is how 3.0 and earlier versions are understood, the 4.0 licenses make it abundantly clear and will help remixers in understanding their licensing obligations. What’s New in 4.0        

More:
New CC licenses: tighter, shorter, more readable, more global

Google admits that Youtube/Google Plus integration increased ASCII porn, spam and trolling – UPDATED

Earlier this month, mathematics vlogger Vi Hart posted a ringing denunciation of the new integration of Youtube comments with Google Plus, arguing that the ham-fisted change had brought Youtube comments to an even lower low. Hart said that the new system gave precedence to people who were able to provoke lots of replies with trollish and insulting behavior, crowding out good commenters. Now, Youtube has officially recognized that the new system has led to an increase in spam, flaming, and the posting of ASCII art pornography . It’s part of a wider program through which Google is attempting to drive all its users into Google Plus (largely because advertisers are willing to pay higher rates for “social” ads, this being the latest industry mania). Googlers’ annual bonuses are being paid out based on Google Plus’s success, meaning that across the business, Google Plus is being crammed into every possible corner . The latest Android system, KitKat, tries to force users into Google Plus accounts for sending and receiving SMSes, and makes you opt out of Google Plus about six times during setup. When Google Plus came in, its company proponents insisted that forcing people to use their real names would improve civility. As is often the case when doctrine fails to line up with reality, they have now doubled down on their folly. If Google Plus hasn’t made the Internet “civil,” the problem can’t be that Real Names don’t work — the problem must be that Google Plus hasn’t been wedged into enough corners of the Internet. It’s hard to believe that Google managed to make Youtube comments worse, but there you have it. It turns out that if you provide Google engineers and product designers with sufficient motivation, there’s no limit to how bad things can get. Update : Thanks to David Otaguro for clarifying that the Google bonuses for Google Plus success was a one-year only affair to coincide with the service’s launch, and that the bonus was only partially based on Google Plus’s success. The Google+ integration has also proven unpopular in a broader sense for a couple of reasons. The change constitutes a) meddling with a well-understood, if broken, system in the interest of creating engagement and more data affiliated with real people, thus creating more business for Google, and b) doing so using Google’s social network, which sits somewhere on a spectrum between reviled and ignored. Google seems to be counting on the outcry against Google+ itself to eventually settle down. The company’s response to the newly bad YouTube comments has been to finally introduce better content moderation at a high level. The update to the system will have “better recognition of bad links,” according to the YouTube blog post, as well as “improved ASCII art detection” and altering the display of long comments. The next step will be to add bulk comment moderation, a long-requested feature that YouTube has avoided until now. The post also mentions briefly that the team is “working on improving comment ranking.” However, no details are provided on how the system will overcome YouTube’s ability to co-opt the definition of “engaged” and turn it into, specifically, “controversial.” The Google+ integration, though, appears to be here to stay. That’s despite the fact that the strongest user-based case for its use—that accountability will prevent trolls from trolling—has been killed, drowned in a sea of ASCII penises. YouTube hilariously impotent against ASCII comment pornographers [Casey Johnston/Ars Technica]        

See original article:
Google admits that Youtube/Google Plus integration increased ASCII porn, spam and trolling – UPDATED

LED stickers: turn your notebook into a lightshow

Noah Swartz writes, “Jie Qi from the MIT Media Lab and Bunnie Huang of Hacking the Xbox fame have teamed up to make LED stickers! Using adhesive copper tape you can turn any notebook into a fantastical light up circuit sketchbook. I got to play with them myself at FOO Camp and they’re as easy to use as the look, and in the time since Ji and Bunnie have gone back to the lab and made a number of sensor and controller stickerss that give you loads of options of what to make. They’re running a fundraiser to do a big production run of these over at Crowdsupply, and while they have funding I’m sure lots of people will be kicking themselves if they don’t manage to grab some of these while they can.” Circuit Stickers ( Thanks, Noah! )        

View original post here:
LED stickers: turn your notebook into a lightshow

GCHQ used fake Slashdot, LinkedIn to target employees at Internet exchanges

A new Snowden leak, reported by Laura Poitras in Der Spiegel , shows that the UK spy agency GCHQ used fake versions of Slashdot and LinkedIn to attack tech staff at Global Roaming Exchanges — interchange points where large networks meet up. It’s speculated that the attacks were used to compromise Belgacom International Carrier Services (BICS) . GRX is roughly analogous to an IX (Internet Exchange), and it acts as a major exchange for mobile Internet traffic while users roam around the globe. There are only around two dozen such GRX providers globally. This new attack specifically targeted administrators and engineers of Comfone and Mach (which was acquired over the summer by Syniverse), two GRX providers. Der Spiegel suggests that the Government Communications Headquarters (GCHQ), the British sister agency to the NSA, used spoofed versions of LinkedIn and Slashdot pages to serve malware to targets. This type of attack was also used to target “nine salaried employees” of the Organization of Petroleum Exporting Countries (OPEC), the global oil cartel. This new revelation may be related to an attack earlier this year against Belgacom International Carrier Services (BICS), a subsidiary of the Belgian telecom giant Belgacom. BICS is another one of the few GRX providers worldwide. UK spies continue “quantum insert” attack via LinkedIn, Slashdot pages [Cyrus Farivar/Ars Technica] ( via TechDirt )        

Follow this link:
GCHQ used fake Slashdot, LinkedIn to target employees at Internet exchanges

Glowing 3D printed squid filled with bioluminescent soup

Rebecca Klee and Siouxsie Wiles’s “Living Light” is a 3D printed hollow squid filled with bioluminescent bacteria. They’ve thoroughly documented their build-process, and the project is really shaping up to be gorgeous. From the lab to the park ( via O’Reilly Radar )        

Continue reading here:
Glowing 3D printed squid filled with bioluminescent soup

Fiber Fix: repair tape with embedded super-strong, fast-curing resin

Fiber Fix is a repair-tape impregnated with fast-curing, moisture-activated resin; the manufacturer claims it hardens to a strength 100 times that of duct-tape, comparable to steel. Baseline room-humidity is generally enough to activate it once it’s removed from its airtight pouch, but you can also soak it before applying. It cures to usability in 10 minutes, and fully sets in 24 hours. It’s $20 for three rolls in varying widths — though be careful, as it’s reportedly a real pain to get off your hands. Fiber Fix [Amazon] Fiberfix.com ( via Oh Gizmo )        

See original article:
Fiber Fix: repair tape with embedded super-strong, fast-curing resin

Promising work on diabetes vaccine

Researchers at Finland’s Tampere University have identified a set of viruses they believe to be responsible for Type 1 diabetes , and they have formulated a vaccine for it that has had promising results in mice. The enterovirus in question attacks the pancreas, and is similar to the virus that causes polio. They’re forming a research syndicate to raise the €700m needed for human trials. Researchers have looked at more than a hundred different strains of the virus and pinpointed five that could cause diabetes. They believe they could produce a vaccine against those strains. ”We have identified one virus type that carries the biggest risk,” said professor Heikki Hyöty. ”A vaccine could also protect against its close relatives, to give the best possible effect.” Finnish team makes diabetes vaccine breakthrough ( via /. )        

See the original article here:
Promising work on diabetes vaccine

Researchers get slo-mo footage of the collapse of a quantum waveform

Research from UC Berkeley’s Kater Murch and team has allowed fine observation of a quantum waveform collapse. Observing single quantum trajectories of a superconducting quantum bit , published in Nature , describes the experiment, which used indirect observations of microwaves that had passed through a box containing a circuit where a particle was in a state of superposition, allowing the researchers to view the collapse in slow-motion.        

Read More:
Researchers get slo-mo footage of the collapse of a quantum waveform