Apple releases OS X 10.9.5 with fixes, new code signing requirements [updated]

Yesterday evening Apple released OS X 10.9.5 to the general public, the fifth major update for OS X Mavericks. As usual, the update comes with a handful of fixes for user-facing features as well as a small pile of security updates . Many of these security patches are also available for OS X 10.7.5 and 10.8.5 in separate updates. Like OS X 10.9.4 , the update focuses on smaller problems that affect a subset of Macs. The new features include Safari 7.0.6, improved “reliability for VPN connections that use USB smart cards for authentication,” and better reliability for connecting to file servers that use the SMB protocol. For businesses using OS X, the update fixes a problem that could keep system admins from “performing some administrative tasks successfully” on larger groups of Macs, and it also speeds up authentication “when roaming on 802.1x networks which use EAP-TLS.” Among the security updates are fixes for Bluetooth, CoreGraphics generally and the Intel graphics driver specifically, and OS X’s version of OpenSSL among many others. The latter problems were fixed by updating from OpenSSL version 0.9.8y to 0.9.8za. Read 6 remaining paragraphs | Comments

See original article:
Apple releases OS X 10.9.5 with fixes, new code signing requirements [updated]

Artificial sweeteners may leave their users glucose intolerant

Flickr user Bukowsky18 People who are watching their weight will often opt for a diet soda, reasoning that the fewer calories, the better. But the availability of drinks and foods made with artificial sweeteners like saccharin, sucralose, and aspartame hasn’t seemed to help much with our booming obesity levels. Now, some researchers might have identified a reason for this: the sweeteners leave their users with elevated blood glucose levels. But they don’t seem to act directly on human metabolism. Instead, the effects come through alterations in the bacterial populations that live inside us. The paper that describes this work, which was performed by a large collaboration of researchers from Israel, is being released by Nature today. The researchers note that epidemiological studies about the effects of artificial sweeteners have produced mixed results; some show a benefit, while others indicate that they’re associated with weight gain and diabetes risk. Given that human populations haven’t given us a clear answer, the researchers turned to mice, where they could do a carefully controlled study. They started taking a group of genetically matched mice and spiking their drinking water with either sucrose or a commercial prep of an artificial sweetener (either saccharin, sucralose, or aspartame). After five weeks, they checked the blood glucose levels of these animals. Eleven weeks later, the groups that were given the artificial sweeteners all had elevated blood glucose levels compared to those that received sucrose. This is typically a sign of metabolic problems, most often caused by insulin losing its effectiveness. It can be a precursor to type 2 diabetes. Read 10 remaining paragraphs | Comments

Read More:
Artificial sweeteners may leave their users glucose intolerant

iPhone 6 and 6 Plus pre-orders break record, top 4 million in one day

The iPhone 5S (left) next to the iPhone 6 and the iPhone 6 Plus. Which size is the one for you? Megan Geuss On Monday, Apple confirmed that its iPhone 6 and iPhone 6 Plus pre-order numbers broke records for the smartphone line, as they combined to rack up over four million purchases in the first 24 hours  they were on sale. As we reported —and Apple’s announcement confirmed—many of those pre-orders won’t ship to customers until October. The pre-orders, which started  early Friday morning in nine nations , handily surpassed the first-day numbers of the iPhone 5; that model received over two million pre-orders in 2012 , though its actual first-weekend sales upon retail launch reached five million . That doesn’t mean Apple’s first-week in-store supply will be able to feed the sort of demand that the iPhone 6 is generating. Anybody curled up in a sleeping bag in front of an Apple Store right now, however, can take comfort in the fact that Apple will make “additional supply” of both models available to purchase at 8am local time this coming Friday. All four major American carriers’ stores will also have phones available on Friday, as well as “additional carriers and select Apple Authorized Resellers.” Read 1 remaining paragraphs | Comments

See the original post:
iPhone 6 and 6 Plus pre-orders break record, top 4 million in one day

Hacker exploits printer Web interface to install, run Doom

Doom on a printer’s menu screen! Personally, we can’t wait until someone makes Descent playable on a toaster. Context Internet Security On Friday, a hacker presenting at the 44CON Information Security Conference in London picked at the vulnerability of Web-accessible devices and demonstrated how to run unsigned code on a Canon printer via its default Web interface. After describing the device’s encryption as “doomed,” Context Information Security consultant Michael Jordon made his point by installing and running the first-person shooting classic  Doom on a stock Canon Pixma MG6450. Sure enough, the printer’s tiny menu screen can render  a choppy and discolored but playable version of id Software’s 1993 hit, the result of Jordon discovering that Pixma printers’ Web interfaces didn’t require any authentication to access. “You could print out hundreds of test pages and use up all the ink and paper, so what?” Jordon wrote at Context’s blog report about the discovery , but after a little more sniffing, he found that the devices could also easily be redirected to accept any code as legitimate firmware. A vulnerable Pixma printer’s Web interface allows users to change the Web proxy settings and the DNS server. From there, an enterprising hacker can crack the device’s encryption in eight steps, the final of which includes unsigned, plain-text firmware files. The hacking possibilities go far beyond enabling choppy, early ’90s gaming: “We can therefore create our own custom firmware and update anyone’s printer with a Trojan image which spies on the documents being printed or is used as a gateway into their network,” Jordon wrote. Read 4 remaining paragraphs | Comments

Read More:
Hacker exploits printer Web interface to install, run Doom

OneDrive finally gets file sharing as easy as Dropbox

We reported last week that Microsoft’s OneDrive cloud service was finally syncing files larger than 2GB. The company today confirmed the change, and disclosed what the new size limit is: 10GB. Not quite enough for a Blu-Ray, but it should solve the file size problem for most users. That’s not the only improvement that Microsoft has made. The desktop client will, at long last, make it easy to share files in OneDrive with other people; right clicking the file in Explorer will have a straightforward “Share a OneDrive link” menu item to create a link that can be e-mailed, tweeted, or otherwise passed around. The lack of such a feature has long made using OneDrive much more annoying than using the competing Dropbox service. The new menu item is rolling out to OneDrive users on Windows 7 and Windows 8 over the next few weeks. The client for Windows 8.1 and OS X will be updated at some time after that. Read 1 remaining paragraphs | Comments

More:
OneDrive finally gets file sharing as easy as Dropbox

Intel demos next-next-gen “Skylake” processors, coming in late 2015

A Core M CPU package based on the Broadwell architecture. Intel Intel’s Broadwell CPU architecture has only just started rolling out , and most of the processors that use it aren’t even supposed to launch until early next year. The new 14nm manufacturing process is causing the delay , but yesterday at the Intel Developer Forum the company tried to demonstrate that Broadwell’s lateness wouldn’t affect the rest of its roadmap. To that end, Intel highlighted a couple of working developer systems based on the new “Skylake” architecture, as summarized here by Anandtech . The company didn’t go into specific performance or power consumption numbers (both because it’s early and because Intel probably doesn’t want to take the wind out of Broadwell’s sails), but it showed working silicon rendering 3D games and playing back 4K video to prove that the chips are working. The first Skylake processors are reportedly due out late in 2015 following the beginning of volume production in the second half of the year. Here are the basic facts we already know about Skylake: it’s a “tock” on Intel’s roadmap, meaning it introduces a new architecture on a manufacturing process that’s already up and running. In this case, that’s Intel’s 14nm process, which Intel  insists has recovered from its early problems . Some of the CPUs in Intel’s lineup—specifically  mid-to-low-end socketed desktop CPUs —will get their next refresh using Skylake instead of Broadwell. Whether this is because Intel wants to reserve 14nm manufacturing capacity for lower-power, higher-margin chips or because it just doesn’t think the power-consumption-obsessed Broadwell is a good fit for regular desktops is anyone’s guess. Read 1 remaining paragraphs | Comments

See more here:
Intel demos next-next-gen “Skylake” processors, coming in late 2015

[Update] iFixit cracks open the Moto 360, finds smaller battery than advertised

Hey that’s not 320 mAh. iFixit/Ron Amadeo iFixit  has gotten ahold of the Moto 360 and applied the usual spudgers and heat packs to rip open the little round smartwatch. There weren’t too many surprises (everything is round!) except for the battery: it’s smaller than advertised. In iFixit’s pictures, the 360’s battery is only labeled as 300 mAh, 20 mAh less than advertised . The 300 mAh battery has only 75 percent of the capacity of the 400 mAh battery found in the LG G Watch, and together with the OMAP 3 processor, it’s not a great combination for all-day battery life. We’ve asked Motorola for a comment about the smaller battery in iFixit’s 360, but the company hasn’t gotten back to us yet. We’ll update this post if we hear anything. The company’s response is below. As for the rest of the device, the round LCD looks pretty much the same as it does on the outside, and even the main PCB is round. iFixit managed to nail the processor down to an  OMAP3630 , which as we suspected is built on a 45nm process. Read 2 remaining paragraphs | Comments

More:
[Update] iFixit cracks open the Moto 360, finds smaller battery than advertised

Meet the tech company performing ad injections for Big Cable

Front Porch ad. A Northern California company that bills itself as the “worldwide leader in Wi-Fi monetization” is the vendor behind Comcast’s and other US cable companies’ promotional advertising campaign performed through JavaScript injection, Comcast said Monday. Comcast spokesman Charlie Douglas confirmed the vendor’s name, Front Porch of Sonora, hours after Ars reported that Comcast recently started serving Comcast ads to devices connected to one of its 3.5 million publicly accessible Wi-Fi hotspots across the US. We wrote that Comcast’s decision to inject data into the net raises security concerns and cuts to the heart of the ongoing net neutrality debate . As it turns out, Front Porch also does business with Cox, Time Warner, Bright House, and Cablevision in the US, Front Porch CTO Carlos Vazquez said in a telephone interview. Read 8 remaining paragraphs | Comments

Read the original:
Meet the tech company performing ad injections for Big Cable

Cable companies want to unbundle broadcast TV, and broadcasters are angry

Iain Watson A Congressional proposal to let cable and satellite customers choose which broadcast TV channels they pay for has led to a battle between small cable companies and broadcasters. While cable companies usually are opponents of mandates to sell channels individually instead of in bundles , in this case they are fighting for à la carte and against the broadcasters. The “Local Choice” proposal by US Sen. Jay Rockefeller (D-WV) and Sen. John Thune (R-SD) affects local broadcast stations such as affiliates of NBC, CBS, ABC, and Fox. A group called TVfreedom.org that represents local broadcasters and other organizations today criticized the American Cable Association (ACA) for supporting Local Choice. “We believe ‘Local Choice’ represents a frontal assault on free and local TV broadcasting,” TVfreedom Public Affairs Director Robert Kenny wrote . “It would tilt television’s balance of power in favor of pay-TV providers at the expense of broadcasters invested in localism. It would cost consumers more on their monthly bills, and do nothing to address shoddy pay-TV service or the deceptive billing practices of cable and satellite TV providers.” TVfreedom is composed of “local broadcasters, community advocates, network television affiliate associations, multicast networks, manufacturers and other independent broadcaster-related organizations” and says its mission is to make sure “cable and satellite TV providers [are] held accountable for stifling innovation and repeatedly using their own customers as bargaining chips while increasing their record profits.” The group chided the ACA for supporting à la carte pricing this year despite arguing in a previous case that “Current technology costs make à la carte a financial impossibility for ACA member systems, the business model is entirely unproven, and no lawful basis exists for imposing regulated a la carte.” Read 10 remaining paragraphs | Comments

Read More:
Cable companies want to unbundle broadcast TV, and broadcasters are angry

Oculus targets $200 to $400 range for consumer version of VR headset

Kyle Orland When Oculus eventually releases a consumer version (CV1) of its Rift virtual reality headset, the company wants to “stay in that $200-$400 price range,” founder Palmer Luckey told Eurogamer in a recent interview. That lines up roughly with the $350 currently being charged for the second Development Kit (DK2) version of the Rift, which began shipping to developers recently. Luckey warned Eurogamer, though, that the consumer version price range “could slide in either direction depending on scale, pre-orders, the components we end up using, business negotiations…” One thing that won’t be sliding around anymore is the technical specs for the CV1. “We know what we’re making and now it’s a matter of making it.” Luckey wouldn’t be pinned down on the specifics of those consumer specs, but he said to expect a jump in resolution above the DK2, similar to the 720p to 1080p jump we saw between the first development kits (DK1) and DK2. Luckey also teased improvements to 90Hz “or higher” refresh rate (up from 75Hz in DK2) and lowered weight and size for the consumer headset. Read 2 remaining paragraphs | Comments

View post:
Oculus targets $200 to $400 range for consumer version of VR headset