NIST’s Draft To Remove Periodic Password Change Requirements Gets Vendors’ Approval

An anonymous reader writes: A recently released draft of the National Institute of Standards and Technology’s digital identity guidelines has met with approval by vendors. The draft guidelines revise password security recommendations and altering many of the standards and best practices security professionals use when forming policies for their companies. The new framework recommends, among other things: “Remove periodic password change requirements.” There have been multiple studies that have shown requiring frequent password changes to actually be counterproductive to good password security, said Mike Wilson, founder of PasswordPing. NIST said this guideline was suggested because passwords should be changed when a user wants to change it or if there is indication of breach. Read more of this story at Slashdot.

Excerpt from:
NIST’s Draft To Remove Periodic Password Change Requirements Gets Vendors’ Approval

NIST’s Draft To Remove Periodic Password Change Requirements Gets Vendors’ Approval

An anonymous reader writes: A recently released draft of the National Institute of Standards and Technology’s digital identity guidelines has met with approval by vendors. The draft guidelines revise password security recommendations and altering many of the standards and best practices security professionals use when forming policies for their companies. The new framework recommends, among other things: “Remove periodic password change requirements.” There have been multiple studies that have shown requiring frequent password changes to actually be counterproductive to good password security, said Mike Wilson, founder of PasswordPing. NIST said this guideline was suggested because passwords should be changed when a user wants to change it or if there is indication of breach. Read more of this story at Slashdot.

Original post:
NIST’s Draft To Remove Periodic Password Change Requirements Gets Vendors’ Approval

NIST’s Draft To Remove Periodic Password Change Requirements Gets Vendors’ Approval

An anonymous reader writes: A recently released draft of the National Institute of Standards and Technology’s digital identity guidelines has met with approval by vendors. The draft guidelines revise password security recommendations and altering many of the standards and best practices security professionals use when forming policies for their companies. The new framework recommends, among other things: “Remove periodic password change requirements.” There have been multiple studies that have shown requiring frequent password changes to actually be counterproductive to good password security, said Mike Wilson, founder of PasswordPing. NIST said this guideline was suggested because passwords should be changed when a user wants to change it or if there is indication of breach. Read more of this story at Slashdot.

View article:
NIST’s Draft To Remove Periodic Password Change Requirements Gets Vendors’ Approval

NIST’s Draft To Remove Periodic Password Change Requirements Gets Vendors’ Approval

An anonymous reader writes: A recently released draft of the National Institute of Standards and Technology’s digital identity guidelines has met with approval by vendors. The draft guidelines revise password security recommendations and altering many of the standards and best practices security professionals use when forming policies for their companies. The new framework recommends, among other things: “Remove periodic password change requirements.” There have been multiple studies that have shown requiring frequent password changes to actually be counterproductive to good password security, said Mike Wilson, founder of PasswordPing. NIST said this guideline was suggested because passwords should be changed when a user wants to change it or if there is indication of breach. Read more of this story at Slashdot.

Visit link:
NIST’s Draft To Remove Periodic Password Change Requirements Gets Vendors’ Approval

Microsoft Will Support Python In SQL Server 2017

There was a surprise in the latest Community Technology Preview release of SQL Server 2017. An anonymous reader quotes InfoWorld: Python can now be used within SQL Server to perform analytics, run machine learning models, or handle most any kind of data-powered work. This integration isn’t limited to enterprise editions of SQL Server 2017, either — it’ll also be available in the free-to-use Express edition… Microsoft has also made it possible to embed Python code directly in SQL Server databases by including the code as a T-SQL stored procedure. This allows Python code to be deployed in production along with the data it’ll be processing. These behaviors, and the RevoScalePy package, are essentially Python versions of features Microsoft built for SQL Server back when it integrated the R language into the database… An existing Python installation isn’t required. During the setup process, SQL Server 2017 can pull down and install its own edition of CPython 3.5, the stock Python interpreter available from the Python.org website. Users can install their own Python packages as well or use Cython to generate C code from Python modules for additional speed. Except it’s not yet available for Linux users, according to the article. “Microsoft has previously announced SQL Server would be available for Linux, but right now, only the Windows version of SQL Server 2017 supports Python.” Read more of this story at Slashdot.

See more here:
Microsoft Will Support Python In SQL Server 2017

CBS adds movies to its All Access streaming library

While we patiently wait for the network to finally deliver Star Trek: Discovery , CBS has been slowly growing its in-house All Access streaming service. In the past few months, CBS has added live TV , NFL games and the Grammies to its event lineup, but now its on-demand selection is getting its own upgrade with the addition of full-length movies. As TechCrunch notes , CBS quietly rolled out the new section last week and only offers a small selection of 18 films licensed from Paramount Studios at the moment. Although the company plans to grow the lineup in the near future, current choices include Election , Rosemary’s Baby and Up in the Air . Anyone who needs a classic Star Trek fix will probably be delighted to learn a number of those films are included, even as they’ve suddenly disappeared from Netflix in the US. For now, CBS is hoping the latest entry to the Star Trek franchise, as well as its Good Wife spinoff The Good Fight , will be enough to start luring more users to the service. The president of CBS Interactive Marc DeBevoise recently told New York Magazine that the company plans to branch out into even more original content this year, but they’re still trying to find the sweet spot that will drive users to pay for “a premium version of CBS.” As for the release date for Discovery , DeBevoise says production is “going great, ” but wouldn’t commit to a fall premiere. Via: TechCrunch Source: Cord Cutters News

More here:
CBS adds movies to its All Access streaming library

New Destructive Malware Intentionally Bricks IoT Devices

An anonymous reader writes: “A new malware strain called BrickerBot is intentionally bricking Internet of Things (IoT) devices around the world by corrupting their flash storage capability and reconfiguring kernel parameters. The malware spreads by launching brute-force attacks on IoT (BusyBox-based) devices with open Telnet ports. After BrickerBot attacks, device owners often have to reinstall the device’s firmware, or in some cases, replace the device entirely. Attacks started on March 20, and two versions have been seen. One malware strain launches attacks from hijacked Ubiquiti devices, while the second, more advanced, is hidden behind Tor exit nodes. Several security researchers believe this is the work of an internet vigilante fed up with the amount of insecure IoT devices connected to the internet and used for DDoS attacks. “Wow. That’s pretty nasty, ” said Cybereason security researcher Amit Serper after Bleeping Computer showed him Radware’s security alert. “They’re just bricking it for the sake of bricking it. [They’re] deliberately destroying the device.” Read more of this story at Slashdot.

Taken from:
New Destructive Malware Intentionally Bricks IoT Devices

YouTube Launches ‘YouTube TV’ In Select Markets

In late February, YouTube unveiled its live TV service called YouTube TV, which offers live TV streaming over the internet for $35 per month with no long-term contract required. The company has officially launched the service today in five select markets: New York, Los Angeles, San Francisco Bay Area, Chicago, and Philadelphia. YouTube says that more markets are coming soon, however, details on when/where are scarce. PhoneDog reports: A membership to YouTube TV costs $35 per month and includes live streaming of channels like ABC, CBS, Fox, NBC, ESPN, and others. Subscribers also get an unlimited cloud DVR for recording shows that’ll last up to nine months, and six accounts that each get their own recommendations and cloud DVRs. YouTube is offering a free one-month trial of YouTube TV so that everyone can give it a try. After your first paid month, YouTube will give you a Google Chromecast to thank you for sticking with the service. Source: YouTube Official Blog Read more of this story at Slashdot.

Read More:
YouTube Launches ‘YouTube TV’ In Select Markets

Gigabyte Firmware Bugs Allow the Installation of BIOS/UEFI Ransomware

An anonymous reader writes from a report via BleepingComputer: Last week, at the BlackHat Asia 2017 security conference, researchers from cyber-security firm Cylance disclosed two vulnerabilities in the firmware of Gigabyte BRIX small computing devices, which allow an attacker to write malicious content to the UEFI firmware. During their presentation, researchers installed a proof-of-concept UEFI ransomware, preventing the BRIX devices from booting, but researchers say the same flaws can be used to plant rootkits that allow attackers to persist malware for years. The two vulnerabilities discovered are CVE-2017-3197 and CVE-2017-3198. The first is a failure on Gigabyte’s part to implement write protection for its UEFI firmware. The second vulnerability is another lapse on Gigabyte’s side, who forgot to implement a system that cryptographically signs UEFI firmware files. Add to this the fact that Gigabyte uses an insecure firmware update process, which doesn’t check the validity of downloaded files using a checksum and uses HTTP instead of HTTPS. A CERT vulnerability note was published to warn users of the impending danger and the bugs’ ease of exploitation. Read more of this story at Slashdot.

Read the original post:
Gigabyte Firmware Bugs Allow the Installation of BIOS/UEFI Ransomware

IoT Garage Door Opener Maker Bricks Customer’s Product After Bad Review

An anonymous reader quotes a report from Ars Technica: Denis Grisak, the man behind the Internet-connected garage opener Garadget, is having a very bad week. Grisak and his Colorado-based company SoftComplex launched Garadget, a device built using Wi-Fi-based cloud connectivity from Particle, on Indiegogo earlier this year, hitting 209 percent of his launch goal in February. But this week, his response to an unhappy customer has gotten Garadget a totally different sort of attention. On April 1, a customer who purchased Garadget on Amazon using the name R. Martin reported problems with the iPhone application that controls Garadget. He left an angry comment on the Garadget community board: “Just installed and attempting to register a door when the app started doing this. Have uninstalled and reinstalled iPhone app, powered phone off/on – wondering what kind of piece of shit I just purchased here…” Shortly afterward, not having gotten a response, Martin left a 1-star review of Garadget on Amazon: “Junk – DO NOT WASTE YOUR MONEY – iPhone app is a piece of junk, crashes constantly, start-up company that obviously has not performed proper quality assurance tests on their products.” Grisak then responded by bricking Martin’s product remotely, posting on the support forum: “Martin, The abusive language here and in your negative Amazon review, submitted minutes after experiencing a technical difficulty, only demonstrates your poor impulse control. I’m happy to provide the technical support to the customers on my Saturday night but I’m not going to tolerate any tantrums. At this time your only option is return Garadget to Amazon for refund. Your unit ID 2f0036… will be denied server connection.” Read more of this story at Slashdot.

Read More:
IoT Garage Door Opener Maker Bricks Customer’s Product After Bad Review