Forgot your password?
typodupeerror

Slashdot is powered by your submissions, so send in your scoop

Businesses

Cable Companies: We're Afraid Netflix Will Demand Payment From ISPs 122

Posted by timothy
from the who-pays-whom-for-what dept.
Dega704 (1454673) writes While the network neutrality debate has focused primarily on whether ISPs should be able to charge companies like Netflix for faster access to consumers, cable companies are now arguing that it's really Netflix who holds the market power to charge them. This argument popped up in comments submitted to the FCC by Time Warner Cable and industry groups that represent cable companies. (National Journal writer Brendan Sasso pointed this out.) The National Cable & Telecommunications Association (NCTA), which represents many companies including Comcast, Time Warner Cable, Cablevision, Cox, and Charter wrote to the FCC:

"Even if broadband providers had an incentive to degrade their customers' online experience in some circumstances, they have no practical ability to act on such an incentive. Today's Internet ecosystem is dominated by a number of "hyper-giants" with growing power over key aspects of the Internet experience—including Google in search, Netflix and Google (YouTube) in online video, Amazon and eBay in e-commerce, and Facebook in social media. If a broadband provider were to approach one of these hyper-giants and threaten to block or degrade access to its site if it refused to pay a significant fee, such a strategy almost certainly would be self-defeating, in light of the immediately hostile reaction of consumers to such conduct. Indeed, it is more likely that these large edge providers would seek to extract payment from ISPs for delivery of video over last-mile networks."
Related: an article at Gizmodo explains that it takes surprisingly little hardware to replicate (at least most of) Netflix's current online catalog in a local data center.
Cellphones

Compromise Struck On Cellphone Unlocking Bill 69

Posted by timothy
from the pit-carrier-against-carrier dept.
NotSanguine (1917456) writes The U.S. Senate has passed a bill (S.517) today, allowing users to unlock their phones when moving to another provider. From a recent article at thehill.com: "Consumers should be able to use their existing cell phones when they move their service to a new wireless provider," [Sen. Patrick] Leahy said in a statement. "Our laws should not prohibit consumers from carrying their cell phones to a new network, and we should promote and protect competition in the wireless marketplace," he said. [Sen. Chuck] Grassley called the bipartisan compromise "an important step forward in ensuring that there is competition in the industry and in safeguarding options for consumers as they look at new cell phone contracts." "Empowering people with the freedom to use the carrier of their choice after complying with their original terms of service is the right thing to do," he said. The House in February passed a companion bill sponsored on cellphone unlocking from House Judiciary Committee Chairman Bob Goodlatte (R-Va.)." Also at Ars Technica, as pointed out by reader jessepdx.
Encryption

Russia Posts $110,000 Bounty For Cracking Tor's Privacy 84

Posted by Soulskill
from the what-happens-in-siberia-stays-in-siberia dept.
hypnosec writes: The government of Russia has announced a ~$110,000 bounty to anyone who develops technology to identify users of Tor, an anonymising network capable of encrypting user data and hiding the identity of its users. The public description (in Russian) of the project has been removed now and it only reads "cipher 'TOR' (Navy)." The ministry said it is looking for experts and researchers to "study the possibility of obtaining technical information about users and users' equipment on the Tor anonymous network."
Encryption

New SSL Server Rules Go Into Effect Nov. 1 79

Posted by Soulskill
from the encrypt-your-calendars dept.
alphadogg writes: Public certificate authorities (CAs) are warning that as of Nov. 1 they will reject requests for internal SSL server certificates that don't conform to new internal domain naming and IP address conventions designed to safeguard networks. The concern is that SSL server digital certificates issued by CAs at present for internal corporate e-mail servers, Web servers and databases are not unique and can potentially be used in man-in-the-middle attacks involving the setup of rogue servers inside the targeted network, say representatives for the Certification Authority/Browser Forum (CA/B Forum), the industry group that sets security and operational guidelines for digital certificates. Members include the overwhelming bulk of public CAs around the globe, plus browser makers such as Microsoft and Apple. The problem today is that network managers often give their servers names like 'Server1' and allocate internal IP addresses so that SSL certificates issued for them through the public CAs are not necessarily globally unique, notes Trend Micro's Chris Bailey.
Networking

Comcast Carrying 1Tbit/s of IPv6 Internet Traffic 134

Posted by Unknown Lamer
from the hurd-1.0-released dept.
New submitter Tim the Gecko (745081) writes Comcast has announced 1Tb/s of Internet facing, native IPv6 traffic, with more than 30% deployment to customers. With Facebook, Google/YouTube, and Wikipedia up to speed, it looks we are past the "chicken and egg" stage. IPv6 adoption by other carriers is looking better too with AT&T at 20% of their network IPv6 enabled, Time Warner at 10%, and Verizon Wireless at 50%. The World IPv6 Launch site has measurements of global IPv6 adoption.
Sony

Sony Agrees To $17.75m Settlement For 2011 PSN Attack 66

Posted by Unknown Lamer
from the claim-your-prize-now dept.
mrspoonsi (2955715) writes with word that Sony has agreed to settle a class action lawsuit brought by PSN users affected by the 2011 breach. From the article: Sony has finally agreed to a preliminary settlement of $15m, which may be able to appease most of the customers that suffered from this attack. The PlayStation Network users that did not partake in the "Welcome Back" program that Sony unveiled shortly after their online services were brought back will be able to choose from two of several options for compensation: One PlayStation 3 or PlayStation Portable game selected from a list of 14 games; three PlayStation 3 themes selected from a list of six themes; or a three-month subscription to PlayStation Plus free of charge. Claiming these benefits will be done on a first come, first serve basis ...The settlement isn't just about free games or services. Customers with documented identity theft charges are eligible for up to $2,500 per claim.
Science

Empathy For Virtual Characters Studied With FMRI Brain Imaging 50

Posted by Unknown Lamer
from the little-billy-loved-hearing-virtual-screams dept.
vrml (3027321) writes "A novel brain imaging study published by the prestigious Neuroimage journal sheds light on different reactions that players' brains display when they meet a virtual character in a game world. While their head was inside a fMRI machine, participants played an interactive virtual experience in which they had to survive a serious fire emergency in a building by reaching an exit as soon as possible. However, when they finally arrived at the exit, they also found a virtual character trapped under an heavy cabinet, begging them for help. Some participants chose not to help the character and took the exit, while others stopped to help although the fire became more and more serious and moving away the cabinet required considerable time. Functional brain imaging showed activation of very different brain areas in players when they met the character. When there was an increased functional connectivity of the brain salience network, which suggests an enhanced sensitivity to the threatening situation and potential danger, players ignored the character screams and went for the exit. In those players who helped the character, there was an engagement of the medial prefrontal and temporo-parietal cortices, which in the neuroscience literature are associated with the human ability of taking the perspective of other individuals and making altruistic choices. The paper concludes by emphasizing how virtual worlds can be a salient and ecologically valid stimulus for modern social neuroscience."
Encryption

CNN iPhone App Sends iReporters' Passwords In the Clear 40

Posted by Unknown Lamer
from the safe-reporting dept.
chicksdaddy (814965) writes The Security Ledger reports on newly published research from the firm zScaler that reveals CNN's iPhone application transmits user login session information in clear text. The security flaw could leave users of the application vulnerable to having their login credential snooped by malicious actors on the same network or connected to the same insecure wifi hotspot. That's particularly bad news if you're one of CNN's iReporters — citizen journalists — who use the app to upload photos, video and other text as they report on breaking news events. According to a zScaler analysis, CNN's app for iPhone exposes user credentials in the clear both during initial setup of the account and in subsequent mobile sessions. The iPad version of the CNN app is not affected, nor is the CNN mobile application for Android. A spokesman for CNN said the company had a fix ready and was working with Apple to have it approved and released to the iTunes AppStore.
Verizon

Deaf Advocacy Groups To Verizon: Don't Kill Net Neutrality On Our Behalf 76

Posted by Soulskill
from the or-on-your-behalf dept.
Dega704 sends this quote from Ars: No company has lobbied more fiercely against network neutrality than Verizon, which filed the lawsuit that overturned the FCC's rules prohibiting ISPs from blocking and discriminating against Web content. But the absence of net neutrality rules isn't just good for Verizon—it's also good for the blind, deaf, and disabled, Verizon claims. That's what Verizon lobbyists said in talks with congressional staffers, according to a Mother Jones report last month. "Three Hill sources tell Mother Jones that Verizon lobbyists have cited the needs of blind, deaf, and disabled people to try to convince congressional staffers and their bosses to get on board with the fast lane idea," the report said. With "fast lanes," Web services—including those designed for the blind, deaf, and disabled—could be prioritized in exchange for payment. Now, advocacy groups for deaf people have filed comments with the FCC saying they don't agree with Verizon's position."
Electronic Frontier Foundation

EFF Releases Wireless Router Firmware For Open Access Points 56

Posted by Soulskill
from the secure-is-as-secure-does dept.
klapaucjusz writes: The EFF has released an experimental router firmware designed make it easy to deploy open (password-less) access points in a secure manner. The EFF's firmware is based on the CeroWRT fork of OpenWRT, but appears to remove some of its more advanced routing features. The EFF is asking for help to further develop the firmware. They want the open access point to co-exist on the same router as your typical private and secured access point. They want the owner to be able to share bandwidth, but with a cap, so guests don't degrade service for the owner. They're also looking to develop a network queueing, a minimalist web UI, and an auto-update mechanism. The EFF has also released the beta version of a plug-in called Privacy Badger for Firefox and Chrome that will prevent online advertisers from tracking you.
United Kingdom

UK Users Overwhelmingly Spurn Broadband Filters 115

Posted by timothy
from the but-it's-a-free-service dept.
nk497 (1345219) writes "Broadband customers are overwhelmingly choosing not to use parental-control systems foisted on ISPs by the government — with takeup in the single-digits for three of the four major broadband providers. Last year, the government pushed ISPs to roll out network-level filters, forcing new customers to make an "active" decision about whether they want to use them or not. Only 5% of new BT customers signed up, 8% opted in for Sky and 4% for Virgin Media. TalkTalk rolled out a parental-control system two years before the government required it and has a much better takeup, with 36% of customers signing up for it. The report, from regulator Ofcom, didn't bother to judge if the filters actually work, however."
Operating Systems

Exodus Intelligence Details Zero-Day Vulnerabilities In Tails OS 132

Posted by timothy
from the compared-to-what? dept.
New submitter I Ate A Candle (3762149) writes Tails OS, the Tor-reliant privacy-focused operating system made famous by Edward Snowden, contains a number of zero-day vulnerabilities that could be used to take control of the OS and execute code remotely. At least that's according to zero-day exploit seller Exodus Intelligence, which counts DARPA amongst its customer base. The company plans to tell the Tails team about the issues "in due time", said Aaron Portnoy, co-founder and vice president of Exodus, but it isn't giving any information on a disclosure timeline. This means users of Tails are in danger of being de-anonymised. Even version 1.1, which hit public release today (22 July 2014), is affected. Snowden famously used Tails to manage the NSA files. The OS can be held on a USB stick and leaves no trace once removed from the drive. It uses the Tor network to avoid identification of the user, but such protections may be undone by the zero-day exploits Exodus holds.
Security

AirMagnet Wi-Fi Security Tool Takes Aim At Drones 52

Posted by timothy
from the command-and-control-is-next dept.
alphadogg (971356) writes "In its quest to help enterprises seek out and neutralize all threats to their Wi-Fi networks, AirMagnet is now looking to the skies. In a free software update to its AirMagnet Enterprise product last week, the Wi-Fi security division of Fluke Networks added code specifically crafted to detect the Parrot AR Drone, a popular unmanned aerial vehicle that costs a few hundred dollars and can be controlled using a smartphone or tablet. Drones themselves don't pose any special threat to Wi-Fi networks, and AirMagnet isn't issuing air pistols to its customers to shoot them down. The reason the craft are dangerous is that they can be modified to act as rogue access points and sent into range of a victim's wireless network, potentially breaking into a network to steal data."
Microsoft

No RIF'd Employees Need Apply For Microsoft External Staff Jobs For 6 Months 275

Posted by Unknown Lamer
from the no-workers-rights-for-you dept.
theodp (442580) writes So, what does Microsoft do for an encore after laying off 18,000 employees with a hilariously bad memo? Issue another bad memo — Changes to Microsoft Network and Building Access for External Staff — "to introduce a new policy [retroactive to July 1] that will better protect our Microsoft IP and confidential information." How so? "The policy change affects [only] US-based external staff (including Agency Temporaries, Vendors and Business Guests)," Microsoft adds, "and limits their access to Microsoft buildings and the Microsoft corporate network to a period of 18 months, with a required six-month break before access may be granted again." Suppose Microsoft feels that's where the NSA went wrong with Edward Snowden? And if any soon-to-be-terminated Microsoft employees hope to latch on to a job with a Microsoft external vendor to keep their income flowing, they best think again. "Any Microsoft employee who separated from Microsoft on or after July 1, 2014," the kick-em-while-they're-down memo explains, "will be required to take a minimum 6-month break from access between the day the employee separates from Microsoft and the date when the former employee may begin an assignment as an External Staff performing services for Microsoft." Likely not just to prevent leaks, but also to prevent any contractors from being reclassified as employees.
Facebook

The Loophole Obscuring Facebook and Google's Transparency Reports 18

Posted by samzenpus
from the fuzzy-math dept.
Jason Koebler writes The number of law enforcement requests coming from Canada for information from companies like Facebook and Google are often inaccurate thanks to a little-known loophole that lumps them in with U.S. numbers. For example, law enforcement and government agencies in Canada made 366 requests for Facebook user data in 2013, according to the social network's transparency reports. But that's not the total number. An additional 16 requests are missing, counted instead with U.S. requests thanks to a law that lets Canadian agencies make requests with the U.S. Department of Justice.
Google

The "Rickmote Controller" Can Hijack Any Google Chromecast 131

Posted by samzenpus
from the never-going-to-give-you-up dept.
redletterdave writes Dan Petro, a security analyst for the Bishop Fox IT consulting firm, built a proof of concept device that's able to hack into any Google Chromecasts nearby to project Rick Astley's "Never Gonna Give You Up," or any other video a prankster might choose. The "Rickmote," which is built on top of the $35 Raspberry Pi single board computer, finds a local Chromecast device, boots it off the network, and then takes over the screen with multimedia of one's choosing. But it gets worse for the victims: If the hacker leaves the range of the device, there's no way to regain control of the Chromecast. Unfortunately for Google, this is a rather serious issue with the Chromecast device that's not too easy to fix, as the configuration process is an essential part of the Chromecast experience.
Cellphones

Why My LG Optimus Cellphone Is Worse Than It's Supposed To Be 289

Posted by samzenpus
from the no-sir-I-don't-like-it dept.
Bennett Haselton writes My LG Optimus F3Q was the lowest-end phone in the T-Mobile store, but a cheap phone is supposed to suck in specific ways that make you want to upgrade to a better model. This one is plagued with software bugs that have nothing to do with the cheap hardware, and thus lower one's confidence in the whole product line. Similar to the suckiness of the Stratosphere and Stratosphere 2 that I was subjected to before this one, the phone's shortcomings actually raise more interesting questions — about why the free-market system rewards companies for pulling off miracles at the hardware level, but not for fixing software bugs that should be easy to catch. Read below to see what Bennett has to say.
China

China Has More People Going Online With a Mobile Device Than a PC 58

Posted by samzenpus
from the surfing-on-the-go dept.
An anonymous reader points out that even though China's internet adoption rate is the lowest it's been in 8 years, the number of people surfing the net from a mobile device has never been higher. "The number of China's internet users going online with a mobile device — such as a smartphone or tablet — has overtaken those doing so with a personal computer (PC) for the first time, said the official China Internet Network Information Center (CNNIC) on Monday. China's total number of internet users crept up 2.3 percent to 632 million by the end of June, from 618 million at the end of 2013, said CNNIC's internet development statistics report. Of those, 527 million — or 83 percent — went online via mobile. Those doing so with a PC made up 81 percent the total. China is the largest smartphone market in the world, and by 2018 is likely to account for nearly one-third of the expected 1.8 billion smartphones shipped that year, according to data firm IDC.
Security

Critroni Crypto Ransomware Seen Using Tor for Command and Control 122

Posted by samzenpus
from the protect-ya-neck dept.
Trailrunner7 writes There's a new kid on the crypto ransomware block, known as Critroni, that's been sold in underground forums for the last month or so and is now being dropped by the Angler exploit kit. The ransomware includes a number of unusual features and researchers say it's the first crypto ransomware seen using the Tor network for command and control.

The Critroni ransomware is selling for around $3,000 and researchers say it is now being used by a range of attackers, some of whom are using the Angler exploit kit to drop a spambot on victims' machines. The spambot then downloads a couple of other payloads, including Critroni. Once on a victim's PC, Critroni encrypts a variety of files, including photos and documents, and then displays a dialogue box that informs the user of the infection and demands a payment in Bitcoins in order to decrypt the files.

"It uses C2 hidden in the Tor network. Previously we haven't seen cryptomalware having C2 in Tor. Only banking trojans," said Fedor Sinitsyn, senior malware analyst at Kaspersky Lab, who has been researching this threat. "Executable code for establishing Tor connection is embedded in the malware's body. Previously the malware of this type, this was usually accomplished with a Tor.exe file. Embedding Tor functions in the malware's body is a more difficult task from the programming point of view, but it has some profits, because it helps to avoid detection, and it is more efficient in general."
The Almighty Buck

New Digital Currency Bases Value On Reputation 100

Posted by Soulskill
from the for-everyone-who-wanted-to-rep-grind-in-real-life dept.
An anonymous reader writes: If digital currencies are fundamentally different than physical ones, why do they work in the same way? That's a question being asked by Couchbase co-founder J. Chris Anderson, who's building a currency and transaction system where reputation is the fundamental unit of value. "Unlike with bitcoin—which keeps its currency scarce by rewarding it only to those who participate in what amounts to a race to solve complex cryptographic puzzles—anyone will be able to create a new Document Coin anytime they want. The value of each coin will be completely subjective, depending on who creates the coin and why. 'For example, the coin my disco singer friend created and gave me at my barbeque might be what gets me past the rope at the club,' Anderson says. A coin minted by tech pundit Tim O'Reilly might be highly prized in Silicon Valley circles, but of little interest to musicians. 'It's a bit like a combination of a social network with baseball trading.'" Anderson isn't aiming to supplant Bitcoin, or even challenge the money-exchange model that drives society. But he's hoping it will change the way people think about currency, and open up new possibilities for how we interact with each other.

The most delightful day after the one on which you buy a cottage in the country is the one on which you resell it. -- J. Brecheux

Working...