Staff Breach At OneLogin Exposes Password Storage Feature

River Tam quotes a report from CSO Australia: Enterprise access management firm OneLogin has suffered an embarrassing breach tied to a single employee’s credentials being compromised. OneLogin on Tuesday revealed the breach affected a feature called Secure Notes that allowed its users to “store information.” That feature however is pitched to users as a secure way to digitally jot down credentials for access to corporate firewalls and keys to software product licenses. The firm is concerned Secure Notes was exposed to a hacker for at least one month, though it may have been from as early as July 2 through to August 25, according to a post by the firm. Normally these notes should have been encrypted using “multiple levels of AES-256 encryption, ” it said in a blog post. Several thousand enterprise customers, including high profile tech startups, use OneLogin for single sign-on to access enterprise cloud applications. The company has championed the SAML standard for single sign-on and promises customers an easy way to enable multi-factor authentication from devices to cloud applications. But it appears the company wasn’t using multi-factor authentication for its own systems. OneLogin’s CISO Alvaro Hoyos said a bug in its software caused Secure Notes to be “visible in our logging system prior to being encrypted and stored in our database.” The firm later found out that an employees compromised credentials were used to access this logging system. The company has since fixed the bug on the same day it detected the bug. CSO adds that the firm “also implemented SAML-based authentication for its log management system and restricted access to a limited set of IP addresses.” Read more of this story at Slashdot.

Excerpt from:
Staff Breach At OneLogin Exposes Password Storage Feature

Half Of People Click Anything Sent To Them

Want to know why phishing continues to be one of the most common security issue? Half of the people will click on anything without thinking twice ArsTechnica reports: A study by researchers at a university in Germany found that about half of the subjects in a recent experiment clicked on links from strangers in e-mails and Facebook messages — even though most of them claimed to be aware of the risks. The researchers at the Friedrich-Alexander University (FAU) of Erlangen-Nuremberg, Germany, led by FAU Computer Science Department Chair Dr Zinaida Benenson, revealed the initial results of the study at this month’s Black Hat security conference. Simulated “spear phishing” attacks were sent to 1, 700 test subjects — university students — from fake accounts. The e-mail and Facebook accounts were set up with the ten most common names in the age group of the targets. The Facebook profiles had varying levels of publicly accessible profile and timeline data — some with public photos and profile photos, and others with minimal data. The messages claimed the links were to photos taken at a New Year’s Eve party held a week before the study. Two sets of messages were sent out: in the first, the targets were addressed by their first name; in the second, they were not addressed by name, but more general information about the event allegedly photographed was given. Links sent resolved to a webpage with the message “access denied, ” but the site logged the clicks by each student. Read more of this story at Slashdot.

More here:
Half Of People Click Anything Sent To Them

US Appeals Court Dismisses AT&T Data Throttling Lawsuit

An anonymous reader quotes a report from Reuters: A federal appeals court in California on Monday dismissed a U.S. government lawsuit that accused ATT Inc of deception for reducing internet speeds for customers with unlimited mobile data plans once their use exceeded certain levels. The company, however, could still face a fine from the Federal Communications Commission regarding the slowdowns, also called “data throttling.” The U.S. Court of Appeals for the Ninth Circuit said it ordered a lower court to dismiss the data-throttling lawsuit, which was filed in 2014 by the Federal Trade Commission. The FTC sued ATT on the grounds that the No. 2 U.S. wireless carrier failed to inform consumers it would slow the speeds of heavy data users on unlimited plans. In some cases, data speeds were slowed by nearly 90 percent, the lawsuit said. The FTC said the practice was deceptive and, as a result, barred under the Federal Trade Commission Act. ATT argued that there was an exception for common carriers, and the appeals court agreed. Read more of this story at Slashdot.

See more here:
US Appeals Court Dismisses AT&T Data Throttling Lawsuit

Microsoft Lost a City Because They Used Wikipedia Data

“Microsoft can’t tell North from South on Bing Maps, ” joked The Register, reporting that Microsoft’s site had “misplaced Melbourne, the four-million-inhabitant capital of the Australian State of Victoria.” Long-time Slashdot reader RockDoctor writes: Though they’re trying to minimise it, the recent relocation of Melbourne Australia to the ocean east of Japan in Microsoft’s flagship mapping application is blamed on someone having flipped a sign in the latitude given for the city’s Wikipedia page. Which may or may not be true. But the simple stupidity of using a globally-editable data source for feeding a mapping and navigation system is … “awesome” is (for once) an appropriate word. Well, it’s Bing, so at least no-one was actually using it. “Bing’s not alone in finding Australia hard to navigate, ” reports The Register. “In 2012 police warned not to use Apple Maps as it directed those seeking the rural Victorian town of Mildura into the middle of a desert.” Read more of this story at Slashdot.

See the original post:
Microsoft Lost a City Because They Used Wikipedia Data

Dyson Will Spend $1.4 Billion, Enlist 3,000 Engineers To Build a Better Battery

An anonymous reader quotes a report from Digital Trends: Among the 100 new products the company founder James Dyson wants to invent by 2020, the greatest investment in people and money is to improve rechargeable lithium-ion batteries, as reported by Forbes (Warning: paywalled). And Dyson is not planning incremental improvements. His opinion is that current Li-ion batteries don’t last long enough and aren’t safe enough — the latter as evidenced by their propensity to spontaneously catch on fire, which is rare but does happen. Dyson believes the answer lies in using ceramics to create solid-state lithium-ion batteries. Dyson says he intended to spend $1.4 billion in research and development and in building a battery factory over the next five years. Last year Dyson bought Ann Arbor, Michigan-based Sakti3, which focuses on creating advanced solid-state batteries, for $90 million. The global lithium-ion battery market accounts for $40 billion in annual sales, according to research firm Lux as cited by Forbes. Dyson’s company (which is an accurate description since he has 100-percent ownership) currently employs 3, 000 engineers worldwide. He intends to hire another 3, 000 by 2020. Their average age is 26. Dyson values young engineers, saying, “The enthusiasm and lack of fear is important. Not taking notice of experts and plowing on because you believe in something is important. It’s much easier to do when you’re young.” Read more of this story at Slashdot.

View article:
Dyson Will Spend $1.4 Billion, Enlist 3,000 Engineers To Build a Better Battery

Ubuntu Linux 16.10 ‘Yakkety Yak’ Beta 1 Now Available For Download

An anonymous reader quotes a report from BetaNews: Today, the first beta of Ubuntu Linux 16.10 sees release. Once again, a silly animal name is assigned, this time being the letter “Y” for the horned mammal, “Yakkety Yak.” This is also a play on the classic song “Yakety Yak” by The Coasters. Please be sure not to “talk back” while testing this beta operating system! “Pre-releases of the Yakkety Yak are not encouraged for anyone needing a stable system or anyone who is not comfortable running into occasional, even frequent breakage. They are, however, recommended for Ubuntu flavor developers and those who want to help in testing, reporting and fixing bugs as we work towards getting this bos grunniens ready. Beta 1 includes a number of software updates that are ready for wider testing. These images are still under development, so you should expect some bugs, ” says Set Hallstrom, Ubuntu Studio project lead. He adds: “While these Beta 1 images have been tested and work, except as noted in the release notes, Ubuntu developers are continuing to improve the Yakkety Yak. In particular, once newer daily images are available, system installation bugs identified in the Beta 1 installer should be verified against the current daily image before being reported in Launchpad. Using an obsolete image to re-report bugs that have already been fixed wastes your time and the time of developers who are busy trying to make 16.10 the best Ubuntu release yet. Always ensure your system is up to date before reporting bugs.” Here are the following download links: Lubuntu, Ubuntu GNOME, Ubuntu Kylin, Ubuntu MATE, Ubuntu Studio. Read more of this story at Slashdot.

Continue reading here:
Ubuntu Linux 16.10 ‘Yakkety Yak’ Beta 1 Now Available For Download

Intel Launches Flurry of 3D NAND-Based SSDs For Consumer and Enterprise Markets

MojoKid writes: Intel launched a handful of new SSD products today that cover a broad spectrum of applications and employ 3D NAND technology. The SSD 600p Series is offered in four capacities ranging from 128GB, to 256GB, 512GB and 1TB. The drivers are targeted at consumer desktops and notebooks and are available in the M.2 form-factor. The entry-level 128GB model offers sequential reads and writes of up to 770 MB/sec and 450 MB/sec respectively. At higher densities, the multi-channel 1TB model offers sequential reads and writes that jump to 1, 800 MB/sec and 560 MB/sec respectively. The 128GB SSD 600p weighs in at $69, while the 1TB model is priced at $359, or about .36 cents per GiB. For the data center, Intel has also introduced the DC P3520 and DC S3520 Series SSDs in 2.5-inch and PCIe half-height card form-factors. Available in 450GB to 2TB capacities, the range-topping 2TB model offers random reads/writes of 1, 700 MB/sec and 1, 350 MB/sec respectively. Finally, Intel launched the SSD E 6000p (PCIe M.2) and SSD E 5420s Series (SATA). The former supports Core vPro processors and is targeted at point-of-sale systems and digital signage. The latter is aimed at helping customers ease the transition from HDDs to SSDs in IoT applications. Read more of this story at Slashdot.

Read the article:
Intel Launches Flurry of 3D NAND-Based SSDs For Consumer and Enterprise Markets

US Unveils Charges Against KickassTorrents, Names Two More Defendants

A total of three men are said to be operators of file-sharing site KickassTorrents (KAT), according to U.S. prosecutors. Last month, federal authorities arrested the 30-year-old Ukrainian mastermind of KAT, Artem Vaulin, and formally charged him with one count of conspiracy to commit criminal copyright infringement, one count of conspiracy to commit money laundering, and two counts of criminal copyright infringement. Two other Ukrainians were named in the new indictment (PDF): Levgen (Eugene) Kutsenko and Oleksander (Alex) Radostin. While only Vaulin has been arrested, bench warrants have been issue for the arrest of all three men. Ars Technica reports: “Prosecutors say the three men developed and maintained the site together and used it to ‘generate millions of dollars from the unlawful distribution of copyright-protected media, including movies, television shows, music, video games, computer software, and electronic books.’ They gave out ‘Reputation’ and ‘User Achievement’ awards to users who uploaded the most popular files, including a special award for users who had uploaded more than 1, 000 torrents. The indictment presents a selection of the evidence that the government intends to use to convict the men, and it isn’t just simple downloads of the copyrighted movies. The government combed through Vaulin’s e-mails and traced the bitcoins that were given to him via a ‘donation’ button.” Read more of this story at Slashdot.

Read More:
US Unveils Charges Against KickassTorrents, Names Two More Defendants

20% of Scientific Papers On Genes Contain Conversion Errors Caused By Excel, Says Report

An anonymous reader writes from a report via WinBeta: A new report from scientists Mark Ziemann, Yotam Eren, and Assam El-Osta says that 20% of scientific papers on genes contain gene name conversion errors caused by Excel. In the scientific article, titled “Gene name errors are widespread in the scientific literature, ” article’s abstract section, the scientists explain: “The spreadsheet software Microsoft Excel, when used with default settings, is known to convert gene names to dates and floating-point numbers. A programmatic scan of leading genomics journals reveals that approximately one-fifth of papers with supplementary Excel gene lists contain erroneous gene name conversions.” It’s easy to see why Excel might have problems with certain gene names when you see the “gene symbols” that the scientists use as examples: “For example, gene symbols such as SEPT2 (Septin 2) and MARCH1 [Membrane-Associated Ring Finger (C3HC4) 1, E3 Ubiquitin Protein Ligase] are converted by default to ‘2-Sep’ and ‘1-Mar’, respectively. Furthermore, RIKEN identifiers were described to be automatically converted to floating point numbers (i.e. from accession ‘2310009E13’ to ‘2.31E+13’). Since that report, we have uncovered further instances where gene symbols were converted to dates in supplementary data of recently published papers (e.g. ‘SEPT2’ converted to ‘2006/09/02’). This suggests that gene name errors continue to be a problem in supplementary files accompanying articles. Inadvertent gene symbol conversion is problematic because these supplementary files are an important resource in the genomics community that are frequently reused. Our aim here is to raise awareness of the problem.” You can view the scientific paper in its entirety here. Read more of this story at Slashdot.

Read More:
20% of Scientific Papers On Genes Contain Conversion Errors Caused By Excel, Says Report

iOS and Android Combined For Record 99% of Smartphone Sales Last Quarter

An anonymous reader writes: The research firm Gartner has crunched some numbers and found that Android and iOS accounted for a record 99.1% worldwide market share in the second calendar quarter of 2016, which is compared to 96.8% in the year-ago period. What some may view as even more shocking is that Android accounted for 86.2% of the market share in the second quarter, up from 82.2% a year ago. Meanwhile, iOS lost some ground as it dropped to 12.9% market share from 14.6% in the year-ago period. It’s no surprise that Windows and BlackBerry have been losing market share. They dropped to 0.6% and 0.1% market share worldwide respectively. Just six years ago, BlackBerry and Symbian operating systems were industry leaders. Now, they’re industry losers. Which third-party operating system has what it takes to take on the establishment? Read more of this story at Slashdot.

See more here:
iOS and Android Combined For Record 99% of Smartphone Sales Last Quarter