NIST’s Draft To Remove Periodic Password Change Requirements Gets Vendors’ Approval

An anonymous reader writes: A recently released draft of the National Institute of Standards and Technology’s digital identity guidelines has met with approval by vendors. The draft guidelines revise password security recommendations and altering many of the standards and best practices security professionals use when forming policies for their companies. The new framework recommends, among other things: “Remove periodic password change requirements.” There have been multiple studies that have shown requiring frequent password changes to actually be counterproductive to good password security, said Mike Wilson, founder of PasswordPing. NIST said this guideline was suggested because passwords should be changed when a user wants to change it or if there is indication of breach. Read more of this story at Slashdot.

Read the original post:
NIST’s Draft To Remove Periodic Password Change Requirements Gets Vendors’ Approval

NIST’s Draft To Remove Periodic Password Change Requirements Gets Vendors’ Approval

An anonymous reader writes: A recently released draft of the National Institute of Standards and Technology’s digital identity guidelines has met with approval by vendors. The draft guidelines revise password security recommendations and altering many of the standards and best practices security professionals use when forming policies for their companies. The new framework recommends, among other things: “Remove periodic password change requirements.” There have been multiple studies that have shown requiring frequent password changes to actually be counterproductive to good password security, said Mike Wilson, founder of PasswordPing. NIST said this guideline was suggested because passwords should be changed when a user wants to change it or if there is indication of breach. Read more of this story at Slashdot.

See more here:
NIST’s Draft To Remove Periodic Password Change Requirements Gets Vendors’ Approval

Gigabyte Firmware Bugs Allow the Installation of BIOS/UEFI Ransomware

An anonymous reader writes from a report via BleepingComputer: Last week, at the BlackHat Asia 2017 security conference, researchers from cyber-security firm Cylance disclosed two vulnerabilities in the firmware of Gigabyte BRIX small computing devices, which allow an attacker to write malicious content to the UEFI firmware. During their presentation, researchers installed a proof-of-concept UEFI ransomware, preventing the BRIX devices from booting, but researchers say the same flaws can be used to plant rootkits that allow attackers to persist malware for years. The two vulnerabilities discovered are CVE-2017-3197 and CVE-2017-3198. The first is a failure on Gigabyte’s part to implement write protection for its UEFI firmware. The second vulnerability is another lapse on Gigabyte’s side, who forgot to implement a system that cryptographically signs UEFI firmware files. Add to this the fact that Gigabyte uses an insecure firmware update process, which doesn’t check the validity of downloaded files using a checksum and uses HTTP instead of HTTPS. A CERT vulnerability note was published to warn users of the impending danger and the bugs’ ease of exploitation. Read more of this story at Slashdot.

Read the original post:
Gigabyte Firmware Bugs Allow the Installation of BIOS/UEFI Ransomware

Hundreds of Cisco Switches Vulnerable To Flaw Found in WikiLeaks Files

Zack Whittaker, writing for ZDNet: Cisco is warning that the software used in hundreds of its products are vulnerable to a “critical”-rated security flaw, which can be easily and remotely exploited with a simple command. The vulnerability can allow an attacker to remotely gain access and take over an affected device. More than 300 switches are affected by the vulnerability, Cisco said in an advisory. According to the advisory, the bug is found in the cluster management protocol code in Cisco’s IOS and IOS XE software, which the company installs on the routers and switches it sells. An attacker can exploit the vulnerability by sending a malformed protocol-specific Telnet command while establishing a connection to the affected device, because of a flaw in how the protocol fails to properly process some commands. Cisco said that there are “no workarounds” to address the vulnerability, but it said that disabling Telnet would “eliminate” some risks. Read more of this story at Slashdot.

View original post here:
Hundreds of Cisco Switches Vulnerable To Flaw Found in WikiLeaks Files

BMW sold 100,000 EVs in 3 years, now turns attention to autonomy

EVs have come a long way in just a few years. Just look at the waves Tesla has made since introducing the Model S in 2012. Nissan just sold its 100, 000th Leaf in the US. BMW , too, would have you know that it has been pulling its weight in this grand acceleration of EVs. In fact, the German automaker has also recently hit a major milestone since it first launched battery-powered cars under its i sub-brand. BMW has announced that it has achieved 100, 000 plug-in vehicle sales worldwide . Beginning with the battery electric i3 in November of 2013, BMW went to work building upon the knowledge and experience gained from its field tests with the ActiveE . In the three years since then, BMW has sold over 60, 000 examples of the i3. The German automaker points out that those sales figures make the i3 “the most successful electric vehicle in the premium compact segment.” It’s not a very crowded segment, but BMW filled a hole and did it well, so we’ll give them that one. Say it proudly, BMW. And, impressively, the automaker reports that 80 percent of i3 buyers are new to BMW, which means first-time owners and those ever-important conquest sales. Next came the ultra-desirable i8 plug-in hybrid. The production car looked a lot like the eye-popping concept, which the public appreciated. Demand initially outstripped production , and the car will probably continue to turn heads for some time to come, particularly when the i8 Roadster allows owners to be seen more easily. BMW says it has sold some 10, 000 examples of the i8 since its launch in mid-2014. Additionally, BMW has sold about 30, 000 plug-in hybrid versions of its other core products, which now fall under the iPerformance label. Just as EV sales are expected to grow in general, we can expect to BMW’s plug-in sales to gather momentum in the coming years, especially as it increases the number of offerings. “BMW i remains our spearhead in terms of innovation and it will continue to open up groundbreaking technologies for the BMW Group, ” says BMW Chairman of the Board of Management Harald Krüger. “When it comes to electric drivetrains, we’ve already successfully managed to put this technology transfer on the road. The next technological advance we will address is automated driving, where the BMW iNEXT will set a new benchmark.” Following a Mini Countryman PHEV and the i8 Roadster in 2018, and an all-electric Mini in 2019, BMW has confirmed it will introduce the all-electric X3 in 2020, with another EV due in 2021. We can’t wait to see what’s (i)Next. Related Video: Source: BMW

Follow this link:
BMW sold 100,000 EVs in 3 years, now turns attention to autonomy

European Commission To Issue Apple An Irish Tax Bill of $1.1 Billion, Says Report

An anonymous reader quotes a report from Reuters: The European Commission will rule against Ireland’s tax dealings with Apple on Tuesday, two source familiar with the decision told Reuters, one of whom said Dublin would be told to recoup over 1 billion euros in back taxes. The European Commission accused Ireland in 2014 of dodging international tax rules by letting Apple shelter profits worth tens of billions of dollars from tax collectors in return for maintaining jobs. Apple and Ireland rejected the accusation; both have said they will appeal any adverse ruling. The source said the Commission will recommend a figure in back taxes that it expects to be collected, but it will be up to Irish authorities to calculate exactly what is owed. A bill in excess of 1 billion euros ($1.12 billion) would be far more than the 30 million euros each the European Commission previously ordered Dutch authorities to recover from U.S. coffee chain Starbucks and Luxembourg from Fiat Chrysler for their tax deals. When it opened the Apple investigation in 2014, the Commission told the Irish government that tax rulings it agreed in 1991 and 2007 with the iPhone maker amounted to state aid and might have broken EU laws. The Commission said the rulings were “reverse engineered” to ensure that Apple had a minimal Irish bill and that minutes of meetings between Apple representatives and Irish tax officials showed the company’s tax treatment had been “motivated by employment considerations.” Read more of this story at Slashdot.

View original post here:
European Commission To Issue Apple An Irish Tax Bill of $1.1 Billion, Says Report

Hackers Make the First-Ever Ransomware For Smart Thermostats

Lorenzo Franceschi-Bicchierai, writing for Motherboard: One day, your thermostat will get hacked by some cybercriminal hundreds of miles away who will lock it with malware and demand a ransom to get it back to normal, leaving you literally in the cold until you pay up a few hundred dollars. This has been a scenario that security experts have touted as one of the theoretical dangers of the rise of the Internet of Things, internet-connected devices that are often insecure. On Saturday, what sounds like a Mr. Robot plot line came one step closer to being reality, when two white hat hackers showed off the first-ever ransomware that works against a “smart” device, in this case, a thermostat. Luckily, Andrew Tierney and Ken Munro, the two security researchers who created the ransomware, actually have no ill intention. They just wanted to make a point: some Internet of Things devices fail to take simple security precautions, leaving users in danger. “We don’t have any control over our devices, and don’t really know what they’re doing and how they’re doing it, ” Tierney told Motherboard. “And if they start doing something you don’t understand, you don’t really have a way of dealing with it.” Tierney and Munro, who both work UK-based security firm Pen Test Partners, demonstrated their thermostat ransomware proof-of-concept at the hacking conference Def Con on Saturday, fulfilling the pessimistic predictions of some people in security world. Read more of this story at Slashdot.

Original post:
Hackers Make the First-Ever Ransomware For Smart Thermostats

Linux 4.6 Brings NVIDIA GTX 900 Support, OrangeFS, Better Power Management

An anonymous reader writes: The Linux 4.6-rc1 kernel has been released. New to the Linux 4.6 kernel are a significant number of new features including NVIDIA GeForce GTX 900 open-source 3D support when using the closed-source firmware files, Dell XPS 13 Skylake laptop support, a fix for laptops that were limiting their own performance due to incorrectly thinking they were overheating, AHCI runtime power management support, Intel graphics power management features enabled by default, a new file-system (OrangeFS), and a range of other improvements. Read more of this story at Slashdot.

Read More:
Linux 4.6 Brings NVIDIA GTX 900 Support, OrangeFS, Better Power Management

Slashdot and SourceForge Sold, Now Under New Management

kodiaktau writes with a link to today’s announcement that DHI Group, Inc. (which you might know better as Dice, the company that bought Slashdot and sister site SourceForge in 2012) today announced that it completed the sale of its Slashdot and SourceForge businesses (together referred to as ‘Slashdot Media’) to BIZX, LLC in a transaction that closed on January 27, 2016. Financial terms were not disclosed. DHI first announced its plan to sell Slashdot Media in July 2015 as part of its strategy to focus on its core brands, as Slashdot Media no longer fits within the Company’s core strategic initiatives. KeyBanc Capital Markets Inc. served as the Company’s exclusive financial advisor for the transaction. (FOSS Force has a short article with some more info BIZX and the sale.) Read more of this story at Slashdot.

Continue reading here:
Slashdot and SourceForge Sold, Now Under New Management

The NSA sure breaks a lot of "unbreakable" crypto. This is probably how they do it.

There have long been rumors, leaks, and statements about the NSA “breaking” crypto that is widely believed to be unbreakable, and over the years, there’s been mounting evidence that in many cases, they can do just that. Now, Alex Halderman and Nadia Heninger, along with a dozen eminent cryptographers have presented a paper at the ACM Conference on Computer and Communications Security (a paper that won the ACM’s prize for best paper at the conference) that advances a plausible theory as to what’s going on. In some ways, it’s very simple — but it’s also very, very dangerous, for all of us. (more…)

Read More:
The NSA sure breaks a lot of "unbreakable" crypto. This is probably how they do it.