Mozilla Will Fund Code Audits For Open Source Software

Reader Orome1 writes: The Mozilla Foundation has set up the Secure Open Source (SOS) Fund, whose aim is to help open source software projects get rid their code of vulnerabilities. Projects that want Mozilla’s help must be open source/free software and must be actively maintained, but they have a much better probability to being chosen if their software is commonly used and is vital to the continued functioning of the Internet or the Web. Three open source projects — PCRE, libjpeg-turbo, and phpMyAdmin — have already gone through the process, and the result was removal of 43 vulnerabilities (including one critical). Read more of this story at Slashdot.

See more here:
Mozilla Will Fund Code Audits For Open Source Software

Yahoo Preps Auction For 3,000 Patents Worth $1 Billion

An anonymous reader quotes a report from Ars Technica: The Wall Street Journal reports that bids are being accepted for nearly 3, 000 Yahoo patents and pending applications. In April, Yahoo moved 2, 659 patents into a patent-holding company called Excalibur IP LLC, which was seen as a first step toward a patent sale. “This represents a unique opportunity for companies operating in the Internet industry to acquire some of the most pioneering and foundational patents related to Web search and advertising, ” Yahoo said in a statement. Those invited to join the auction include “strategic buyers, private-equity firms, and investment firms focused on intellectual property, ” according to the Journal. Preliminary bids are due by the middle of this month, and the patents are expected to fetch more than $1 billion, according to “people familiar with the matter” who spoke to the Journal. Bloomberg, which also reported on the patent sale, said there was no official reserve price or bidding guidelines. Yesterday, Verizon submitted a $3 billion bid for Yahoo’s core internet business. The sale will include 500 U.S. patents and more than 600 pending applications, but will not include the larger collection of patents going in the patent sale. Read more of this story at Slashdot.

See the article here:
Yahoo Preps Auction For 3,000 Patents Worth $1 Billion

Google To Deprecate SSLv3, RC4 in Gmail IMAP/POP Clients

Michael Mimoso, reporting for Threatpost: Google said that it will initiate on June 16 a gradual deprecation of SSLv3 and RC4 for Gmail IMAP/POP mail clients. Both the crypto protocols cipher are notoriously unsafe and are being phased out in big chunks of the Internet. Google, for its part, had already announced in May that it would no longer support SSLv3 and RC4 connections for Gmail SMTP. Google does note that most mail clients already default to safer TLS connections, and most will not be affected by the impending changes.”Unlike Gmail SMTP, this change will be rolled out as a gradual change, where it may take longer than 30 days for users to be fully restricted from connecting to Gmail from SSLv3 or RC4 connections; however, we recommend updating your clients soon in order to avoid any potential disruption, ” Google said in an announcement. Read more of this story at Slashdot.

Read More:
Google To Deprecate SSLv3, RC4 in Gmail IMAP/POP Clients

Many Lexus Navigation Systems Bricked By Over-The-Air Software Update

An anonymous reader quotes a report from The Verge: An unknown number of Lexus automobiles have seen their infotainment and navigation head units broken by a bug in an over-the-air software update from Lexus. The glitch, which was confirmed by a Lexus spokesperson, was delivered in a routine software update. In affected cars, it can cause the dashboard screen to spontaneously reset itself and, as a result, both the radio and navigation system can be unusable. It affects cars equipped with Lexus’ Enform system with navigation. Lexus social media channels have been flooded by frustrated owners, but the company has been unable to give any estimates for when the problem will be resolved. The company also couldn’t say whether customers will see the problem fix itself with another software update or if they will need to head into dealers to get it fixed. Some users on Twitter have reported success with disconnecting their battery for a few moments to force a reset of the system. Read more of this story at Slashdot.

View post:
Many Lexus Navigation Systems Bricked By Over-The-Air Software Update

Firefox 47 Arrives With Synced Tabs Sidebar, Better YouTube Playback

An anonymous reader quotes a report from VentureBeat: Mozilla today launched Firefox 47 for Windows, Mac, Linux, and Android. The browser has gained a sidebar for synced tabs from other devices, improvements to YouTube playback and HTML5 support, and is seeing the end of support for Android Gingerbread. [If you’re logged in with your Firefox Account, the sidebar will show all your open tabs from your smartphone and other computers. The sidebar even lets you search for specific tabs. Next, Firefox 47 supports the open source VP9 video codec on machines with powerful multiprocessors. VP9 is the successor to VP8, both of which fall under Google’s WebM project of freeing web codecs from royalty constraints.] Firefox 47 is available for download on Firefox.com, and will be slowly released on Google Play. You can view the full Firefox 47 changelog here. If you’re a developer, Firefox 47 for developers offers more details for you. Read more of this story at Slashdot.

Read the original:
Firefox 47 Arrives With Synced Tabs Sidebar, Better YouTube Playback

Finnish Mail System Abandons Tuesday Delivery

Reader jones_supa writes: In a world moving to electronic communications, the snail mail traffic has seen a huge drop. Because of this, Posti, the mail delivery organization of Finland will not be delivering letters and magazines on Tuesdays anymore. Tuesday was selected because it generally has the lowest volume of mail. For example, magazines and advertisements are targeted to the end of the week, so that people have more time for shopping dreams in the weekend. Another reason is that Posti recently launched a lawn mowing service which operates on Tuesdays. Read more of this story at Slashdot.

View the original here:
Finnish Mail System Abandons Tuesday Delivery

‘Alarming’ Rise In Ransomware Tracked

An anonymous reader quotes a report from BBC: Cyber-thieves are adopting ransomware in “alarming” numbers, say security researchers. There are now more than 120 separate families of ransomware, said experts studying the malicious software. Other researchers have seen a 3, 500% increase in the criminal use of net infrastructure that helps run ransomware campaigns. The rise is driven by the money thieves make with ransomware and the increase in kits that help them snare victims. Ransomware was easy to use, low risk and offered a high reward, said Bart Parys, a security researcher who helps to maintain a list of the growing numbers of types of this kind of malware. Mr Parys and his colleagues have now logged 124 separate variants of ransomware. Some virulent strains, such as Locky and Cryptolocker, were controlled by individual gangs, he said, but others were being used by people buying the service from an underground market. A separate indicator of the growth of ransomware came from the amount of net infrastructure that gangs behind the malware had been seen using. The numbers of web domains used to host the information and payment systems had grown 35-fold, said Infoblox in its annual report which monitors these chunks of the net’s infrastructure. A lot of ransomware reached victims via spear-phishing campaigns or booby-trapped adverts, he said, but other gangs used specialized “crypters” and “packers” that made files look benign. Others relied on inserting malware into working memory so it never reached the parts of a computer on which most security software keeps an eye. Ars Technica reports that drive-by attacks that install the TeslaCrypt crypto ransomware are now able to bypass Microsoft’s EMET. Read more of this story at Slashdot.

Read More:
‘Alarming’ Rise In Ransomware Tracked

Apple Offers No Explanation for 7-Hour Outage

Apple services went offline for up to 7 hours Thursday — and the company has yet to offer an explanation. An anonymous reader writes: The outage affected the App Store, iTunes in the Cloud, Apple TV, Mail Drop, Find my iPhone, and Photos. During the outage, Apple responded to complaints on Twitter, “Thank you for the information. We’re aware of this issue and are investigating, ” Tech Times reports that the iCloud Music Library had also experienced an outage on Wednesday, and that just weeks ago Apple released an operating system update which bricked several iPad Pros. And yesterday Amazon also experienced a service outage. Read more of this story at Slashdot.

Read the original post:
Apple Offers No Explanation for 7-Hour Outage

Facebook Nixes Access To Chats Outside Of Messenger Walled Garden

Tom Mendelsohn, reporting for Ars Technica: Some smartphone users of Facebook are reporting that they’re no longer able to access their messages from the mobile site, and that they’re being directed towards the free content ad network’s dedicated Messenger app. Users of the regular Facebook mobile app were shunted over to Facebook Messenger to access their chats a while ago. Now, folk who access the service on their phone’s Web browsers, or via third-party apps such as Tinfoil or Metal, are beginning to find that they can no longer view their messages. Complaints are popping up from users who are being told by Facebook that “your conversations are moving to Messenger.” Some Android users are even finding themselves automatically redirected to the download link on the Google Play store when they try and view their messages on the mobile site. Read more of this story at Slashdot.

Read the article:
Facebook Nixes Access To Chats Outside Of Messenger Walled Garden

Wal-Mart Says It Is 6-9 Months From Using Drones To Check Warehouse Inventory

Multinational retail corporation Wal-mart announced on Thursday that it is six to nine months from starting to use drones to check warehouse inventories in the United States. The drones, which are capable of operating on autopilot, fly through the aisles snapping 30 images a second, and deliver real-time data to employees about whether the correct product is shelved in the proper place. From a Reuters report: Finding ways to more efficiently warehouse, transport and deliver goods to customers has taken on new importance for Wal-Mart as it deals with wages costs while seeking to beat back price competition and boost online sales. Wal-Mart said the camera and technology on top of the drones have been custom-built for the retailer. Read more of this story at Slashdot.

View the original here:
Wal-Mart Says It Is 6-9 Months From Using Drones To Check Warehouse Inventory