Australia

Australia's Giant Carbon Capture Project Fails To Meet Key Targets (smh.com.au) 89

The world's largest carbon capture and storage project has failed to meet a crucial target of capturing and burying an average of 80% of the carbon dioxide produced from gas wells in Western Australia over five years. From a report: The energy giant Chevron agreed to the target with the West Australian government when developing its $54 billion Gorgon project to extract and export gas from fields off the WA coast. The five year milestone passed on Sunday. In a statement the energy giant Chevron announced that since operations began in August 2019 it had injected five million tonnes of greenhouse gases underground. According to the independent analyst Peter Milne, that leaves a shortfall of around 4.6 million tonnes, which he estimates would cost about $100 million to offset via carbon credits.

The project has national and even international significance, with the oil and gas industry and the federal government declaring the success of carbon capture and storage to be crucial in tackling climate change while making use of fossil fuels. "It is essential we position Australia to succeed by investing now in the technologies that will support our industries into the future, with lower emissions energy that can support Australian jobs," Prime Minister Scott Morrison said in April while announcing $263.7 million in funding to develop carbon capture and storage technology.

Cellphones

Right-wing Activist's $500 'Freedom Phone' Actually Cheap Rebranded Android Model Made in China (gizmodo.com) 226

"This week, a 22-year-old self-described Bitcoin millionaire introduced the Freedom Phone, a $499 device meant to be completely free from 'Big Tech's' censorship and influence," reports PC Magazine.

"But it turns out the same smartphone is actually from China, and probably just a cheap knock-off." The Freedom Phone comes from Erik Finman, who unveiled the device earlier this week. He claims the product has everything Trump supporters could dream of, including an "uncensorable" app store, preinstalled conservative-friendly apps including Parler and Rumble, and even its own anti-surveillance operating system called FreedomOS... However, The Daily Beast noticed the Freedom Phone looks strikingly similar to a budget smartphone device from a Chinese vendor called Umidigi. The device is called the Umidigi A9 pro, and you can actually buy it over on the Chinese e-commerce site AliExpress starting at $119. Finman later told The Daily Beast that the Freedom Phone was indeed sourced from Umidigi, a company that's based in Shenzhen, China...

An uncensorable app store opens the door for hackers and shady developers to circulate malware and data-collecting programs to users. We're also doubtful Freedom Phone has its own operating system if it can run apps such as Parler and Rumble, in addition to Signal, Telegram and Brave

The Daily Beast adds this anecdote: The Freedom Phone's "Freedom OS" operating system is based on Google's Android operating system, according to Finman. But during a livestream video promoting the phone, right-wing activist Anna Khait was confused by her fans' basic questions about the phone. "Is it an Android?" Khait said. "I'm not really sure. No, it's a Freedom Phone."
Gizmodo calls the phone's web site "radically vague on the details." There is no information about the phone's operating system, storage, camera, CPU, or RAM capabilities. It has a list of features, but there are no actual details about them. Instead, under each feature, there's merely a "Buy it now" button which redirects you to the site's shopping cart. The phone's hefty price, combined with the company's total lack of transparency, is ridiculous — essentially asking the buyer to cough up half a grand in exchange for, uh, something...!
But Gizmodo also shares a philosophical thought: Before we get into the specifics of why this device probably sucks, let me just say that the desire to have a phone that is dedicated to protecting your autonomy and privacy is a reasonable one — and should be encouraged. That said, I don't think the Freedom Phone provides that. Actually, aside from its overt partisan bent, it's impossible to tell what kind of device this is because Finman and his acolytes haven't provided any information about it...

The funny thing is, if Trump voters are looking for a way to get off the "Big Tech" grid, there's no need for them to buy this sketchy shit. There are actually entire subcultures within the phone industry dedicated to escaping the Android/iOS paradigm. You can wade into the de-Googled phone sector, for instance — where Android phones are sold that have ostensibly been refurbished to rid the devices of code that will "send your personal data" back to the tech giant. There's also the Linux-based Pinephone, which sells at a fraction of the Freedom Phone's cost (between $150 and $200), and is a favorite of those in the privacy community. All of these come with caveats, obviously, but the point is that there are much more transparent and affordable options than the Freedom Phone...

It'd be nice if Americans could actually come together around the issue of privacy since it's an area where — regardless of political party — we're all collectively getting screwed.

Games

Valve Launches Steam Deck, a $400 PC Gaming Portable (techcrunch.com) 110

A new challenger has emerged in the gaming hardware category. Game distribution giant Valve today announced the launch of Steam Deck, a $399 gaming portable designed to take PC games on the go. From a report: The handheld (which has echoes of several portable gaming rigs of years past) features a seven-inch screen and runs on a quad-core Zen 2 CPU, coupled with AMD RDNA 2 graphics and 16GB of RAM. Storage runs 64GB to 512GB, the latter of which bumps the price up to $649. The built-in storage can be augmented via microSD.

[...] Flanking the 1280 x 800 touchscreen are a pair of trackpads and thumb sticks. A built-in gyroscope also uses movement to control the gaming experience. There's a single USB-C port for charging, peripherals and connecting to a big screen, while a 40Wh battery promises between 7-8 hours of gameplay, by Valve's numbers.

The Almighty Buck

India Bans Mastercard From Adding New Customers (techcrunch.com) 25

Reserve Bank of India has indefinitely barred Mastercard from issuing new debit, credit or prepaid cards to customers in the South Asian market over noncompliance with local data storage rules. TechCrunch reports: The South Asian market's central bank said the new restrictions will go into effect on July 22. "Notwithstanding lapse of considerable time and adequate opportunities being given, the entity has been found to be noncompliant with the directions on Storage of Payment System Data," RBI said in a statement Wednesday. The new order won't impact existing customers of Mastercard, which is one of the top three card issuers in India, RBI said. "Mastercard shall advise all card-issuing banks and non-banks to conform to these directions," it said. This isn't the first time India's central bank has penalized a firm for noncompliance with local data-storage rules, which were unveiled in 2018 and mandated compliance within six months. The rules require payments firms to store all Indian transaction data within servers in the country. In April, RBI restricted American Express and Diners Club from adding new customers, citing violation of the same rules.
Data Storage

Backblaze Raises Subscription Pricing of Personal Backup (backblaze.com) 73

Backblaze CEO Gleb Budman, writing on the company blog: Over the last 14 years, we have worked diligently to keep our costs low and pass our savings on to customers. We've invested in deduplication, compression, and other technologies to continually optimize our storage platform and drive our costs down -- savings which we pass on to our customers in the form of storing more data for the same price.

However, the average backup size stored by Computer Backup customers has spiked 15% over just the last two years. Additionally, not only have component prices not fallen at traditional rates, but recently electronic components that we rely on to provide our services have actually increased in price.

The combination of these two trends, along with our desire to continue investing in providing a great service, is driving the need to modestly increase our prices.
The new monthly plan now costs $7, while the yearly plan will set you back by $70.
Piracy

Stream-Ripping Can Be Perfectly Legal, French Ministry of Culture Says (torrentfreak.com) 28

An anonymous reader quotes a report from TorrentFreak: Downloading music via stream-ripping tools can be perfectly legal, the French Ministry of Culture has confirmed. The resulting copies fall under the private copying exemption. However, this only applies if the stream-ripping service doesn't circumvent technical protection measures, which is a widely contested issue. [...] Copyright holders are convinced that stream-ripping sites break the law but, in most countries, legal uncertainties remain. In the US, for example, popular stream-ripper Yout.com has sued the RIAA in an effort to have its site declared legal. This case, which remains ongoing, could set an important precedent.

In France, the Ministry of Culture was recently questioned on the stream-ripping issue. Philippe Latombe, a member of the MoDem party, asked the Government whether copies downloaded through these services are considered illegal. The question was part of a broader inquiry into the private copying rules and regulations. These allow people to copy music and movies in exchange for a tax that's paid on storage media and devices including blank CDs, hard disks, and smartphones. Responding to the question, the Ministry of Culture confirmed that, under the right conditions, it's perfectly legal to use stream-ripping services to download music and other media. "[Stream-ripping] is legal and the resulting copy falls under the exception for private copying as provided by law, if several conditions are met: it must be made from a lawful source at the request of the user, without being stored by the converter, and no circumvention of technical protection measures must be carried out." If these three boxes are ticked, stream-ripping is in the same league as ripping or copying an old-fashioned CD or DVD.

The big question, however, is in what situation all these conditions would apply? With regard to YouTube ripping, the "source" could be considered legal, as artists and labels often upload the videos themselves. The second box is also ticked by many stream-rippers as they don't permanently store music. The operator of the stream-rippers FLVto and 2Conv recently said that his site doesn't even store basic logs as that would involve significant costs. This brings us to the third and final condition; whether the stream-ripper circumvents technical protection measures. This is a crucial question and the answer largely depends on who you ask.

Power

Which Energy Future: Power Lines or Rooftop Solar Panels (and Storage Batteries)? (nytimes.com) 271

The New York Times reports on "an intense policy struggle" in America's national and state governments:

-On one side, large electric utilities and President Biden want to build thousands of miles of power lines to move electricity created by distant wind turbines and solar farms to cities and suburbs.

- On the other, some environmental organizations and community groups are pushing for greater investment in rooftop solar panels, batteries and local wind turbines.


And the result "could lock in an energy system that lasts for decades." At issue is how quickly the country can move to cleaner energy and how much electricity rates will increase... The option supported by Mr. Biden and some large energy companies would replace coal and natural gas power plants with large wind and solar farms hundreds of miles from cities, requiring lots of new power lines. Such integration would strengthen the control that the utility industry and Wall Street have over the grid. "You've got to have a big national plan to make sure the power gets from where it is generated to where the need is," Energy Secretary Jennifer Granholm said in an interview.

But many of Mr. Biden's liberal allies argue that solar panels, batteries and other local energy sources should be emphasized because they would be more resilient and could be built more quickly... In all probability, there will be a mix of solutions that include more transmission lines and rooftop solar panels. What combination emerges will depend on deals made in Congress but also skirmishes playing out across the country...

As millions of California homes went dark during a heat wave last summer, help came from an unusual source: batteries installed at homes, businesses and municipal buildings. Those batteries kicked in up to 6 percent of the state grid's power supply during the crisis, helping to make up for idled natural gas and nuclear power plants. Rooftop solar panels generated an additional 4 percent of the state's electricity... California showed that homes and businesses don't have to be passive consumers. They can become mini power plants, potentially earning as much from supplying energy as they pay for electricity they draw from the grid. Home and business batteries, which can be as small as a large television and as big as a computer server room, are charged from the grid or rooftop solar panels...

Regulators generally allow utilities to charge customers the cost of investments plus a profit margin, typically about 10.5 percent, giving companies an incentive to build power plants and lines... A 2019 report by the National Renewable Energy Laboratory, a research arm of the Energy Department, found that greater use of rooftop solar can reduce the need for new transmission lines, displace expensive power plants and save the energy that is lost when electricity is moved long distances. The study also found that rooftop systems can put pressure on utilities to improve or expand neighborhood wires and equipment.

The director of a Chicago-based environmental nonprofit tells the Times that "Solar energy plus storage is as transformative to the electric sector as wireless services were to the telecommunications sector."

In a weird twist, fossil fuel companies are now joining forces with local groups (including environmental groups) to fight the construction of new power lines.
Android

Qualcomm and ASUS Made a Phone for Snapdragon Insiders (engadget.com) 16

ASUS and Qualcomm have teamed up to make a smartphone that shows off some of the latter's mobile tech. Although the phone is ostensibly for the 1.6 million members of the Snapdragon Insiders program (which is a bit like Microsoft's Windows Insider early-access scheme), it'll be more broadly available by August. From a report: The snappily named Smartphone for Snapdragon Insiders harnesses Qualcomm's Snapdragon 888 5G chipset with a 2.84 GHz octa-core processor and the Adreno 660 GPU. It has what Qualcomm describes as "the most comprehensive support for all key 5G sub-6 and mmWave bands" of any device, along with WiFi 6 and WiFi 6E support with speeds of up to 3.6 Gbps. You'll get 16GB of LPDDR5 memory and 512GB of storage. The 6.78-inch AMOLED display from Samsung has a 144 Hz refresh rate, which could help make it a solid gaming phone. The screen has up to 1,200 nits of brightness and it's HDR10 and HDR10+ certified. The phone has three rear cameras: a 64MP main lens, 12MP ultrawide camera and 8MP telephoto. The array can capture video in up to 8K. The device also has a 24MP front camera and AI auto-zoom. You'll be able to buy the $1,499 device at ASUSTeK's eShop and other retailers.
China

Prenatal Test Developed With Chinese Military Harvests Gene Data From Millions of Women (reuters.com) 122

A prenatal test taken by millions of pregnant women globally was developed by Chinese gene company BGI Group in collaboration with the Chinese military and is being used by the firm to collect genetic data, a Reuters review of publicly available documents found. From the report: The report is the first to reveal that the company collaborated with the People's Liberation Army (PLA) to develop and improve the test, taken in early pregnancy, as well as the scope of BGI's storage and analysis of the data. The United States sees BGI's efforts to collect and analyze human gene data as a national security threat. China's biggest genomics firm, BGI began marketing the test abroad in 2013. Branded NIFTY, it is among the world's top selling non-invasive prenatal tests (NIPT). These screen a sample of blood from a pregnant woman to detect abnormalities such as Down's syndrome in a developing fetus. So far more than 8 million women globally have taken BGI's prenatal tests, BGI has said. NIFTY is sold in at least 52 countries, including Britain, Europe, Canada, Australia, Thailand and India, but not the United States.

BGI uses leftover blood samples sent to its laboratory in Hong Kong and genetic data from the tests for population research, the company confirmed to Reuters. Reuters found the genetic data of over 500 women who took the test, including women in Europe and Asia, is also stored in the government-funded China National GeneBank in Shenzhen, which BGI runs. Reuters found no evidence BGI violated privacy agreements or regulations; the company said it obtains signed consent and destroys overseas samples and data after five years. "At no stage throughout the testing or research process does BGI have access to any identifiable personal data," the company said. However, the test's privacy policy says data collected can be shared when it is "directly relevant to national security or national defense security" in China. BGI said it "has never been asked to provide -- nor provided -- data from its NIFTY tests to Chinese authorities for national security or national defense purposes."
"Non-invasive prenatal testing kits marketed by Chinese biotech firms serve an important medical function, but they can also provide another mechanism for the People's Republic of China and Chinese biotech companies to collect genetic and genomic data from around the globe," the U.S. National Counterintelligence and Security Center said.

China's foreign ministry said Reuters' findings reflected "groundless accusations and smears" of U.S. agencies.
Nintendo

Nintendo Switch OLED Model Will Go on Sale October 8th for $350 (theverge.com) 28

Nintendo is announcing a new Switch model today with a larger 7-inch 720p OLED display. While rumors had suggested this new Switch would ship with a new Nvidia chip inside, it doesn't look like that's the case. From a report: Nintendo lists this Switch OLED model as only supporting 1080p via TV mode, and rumors had suggested 4K support, thanks to a rumored Nvidia chip upgrade. The Switch OLED model will go on sale for $350 starting on October 8th. Other than the new screen, this revised model includes an adjustable stand for tabletop play, 64GB of built-in storage (up from 32GB), a new dock with a wired ethernet port built in, and improved audio for handheld or tabletop play. Nintendo only mentions "up to 1080p via HDMI in TV mode" for the TV dock, so the rumored 4K mode isn't part of this OLED Switch.
Power

California Tests Off-the-Grid Solutions to Climate-Related Power Outages (apnews.com) 84

California's energy commission has funded dozens of projects "serving as test beds for policies that might lead to commercialization of microgrids," reports the Associated Press: When a wildfire tore through Briceburg nearly two years ago, the tiny community on the edge of Yosemite National Park lost the only power line connecting it to the electrical grid. Rather than rebuilding poles and wires over increasingly dry hillsides, which could raise the risk of equipment igniting catastrophic fires, the nation's largest utility decided to give Briceburg a self-reliant power system. The stand-alone grid made of solar panels, batteries and a backup generator began operating this month.

It's the first of potentially hundreds of its kind as Pacific Gas & Electric works to prevent another deadly fire like the one that forced it to file for bankruptcy in 2019.

The ramping up of this technology is among a number of strategies to improve energy resilience in California as a cycle of extreme heat, drought and wildfires hammers the U.S. West, triggering massive blackouts and threatening the power supply in the country's most populous state... "I don't think anyone in the world anticipated how quickly the changes brought on by climate change would manifest. We're all scrambling to deal with that," said Peter Lehman, the founding director of the Schatz Energy Research Center, a clean energy institute in Arcata. The response follows widespread blackouts in California in the past two years that exposed the power grid's vulnerability to weather. Fierce windstorms led utilities to deliberately shut off power to large swaths of the state to keep high-voltage transmission lines from sparking fire. Then last summer, an oppressive heat wave triggered the first rolling outages in 20 years. More than 800,000 homes and businesses lost power over two days in August.

During both crises, a Native American reservation on California's far northern coast kept the electricity flowing with the help of two microgrids that can disconnect from the larger electrical grid and switch to using solar energy generated and stored in battery banks near its hotel-casino. As most of rural Humboldt County sat in the dark during a planned shutoff in October 2019, the Blue Lake Rancheria became a lifeline for thousands of its neighbors: The gas station and convenience store provided fuel and supplies, the hotel housed patients who needed a place to plug in medical devices, the local newspaper used the conference room to put out the next day's edition, and a hatchery continued pumping water to keep its fish alive... During a few hours of rolling blackouts last August, the reservation's microgrids went into "island mode" to help ease stress on the state's maxed-out grid...

State facilities are planning to quadruple the amount of battery storage from 500 megawatts to 2,000 megawatts by this August.

But unfortunately, "There are setbacks too: An intensifying drought is weakening the state's hydroelectric facilities..."
Cloud

Apple's Spending on Google Cloud Storage On Track to Soar 50% This Year (theinformation.com) 44

Apple executives have taken swipes at Google in the past over its privacy practices. But the iPhone maker trusts Google enough so that over the past year it has dramatically increased the amount of Apple user data it stores in Google's cloud, The Information reported [Editor's note: the link may be paywalled; alternative source], citing a person with direct knowledge of the matter. From the report: The increase cements Apple's status as the largest corporate client for Google's storage service, dwarfing other high-profile Google customers such as ByteDance and Spotify. As of mid-May, Apple was on track to spend around $300 million on Google cloud storage this year, which would represent an increase of roughly 50% from all of 2020, the person said. Inside Google's cloud unit, the person said, staffers have even given Apple a code name that hints at its size: Bigfoot.
Data Storage

Another Exploit Hits WD My Book Live Owners (tomshardware.com) 50

While it will come as no comfort to those who had their Western Digital My Book Live NAS drives wiped last week, it seems they were attacked by a combination of two exploits, and possibly caught in the fallout of a rivalry between two different teams of hackers. Tom's Hardware reports: Initially, after the news broke on Friday, it was thought a known exploit from 2018 was to blame, allowing attackers to gain root access to the devices. However, it now seems that a previously unknown exploit was also triggered, allowing hackers to remotely perform a factory reset without a password and to install a malicious binary file. A statement from Western Digital, updated today, reads: "My Book Live and My Book Live Duo devices are under attack by exploitation of multiple vulnerabilities present in the device ... The My Book Live firmware is vulnerable to a remotely exploitable command injection vulnerability when the device has remote access enabled. This vulnerability may be exploited to run arbitrary commands with root privileges. Additionally, the My Book Live is vulnerable to an unauthenticated factory reset operation which allows an attacker to factory reset the device without authentication. The unauthenticated factory reset vulnerability [has] been assigned CVE-2021-35941."

Analysis of WD's firmware suggests code meant to prevent the issue had been commented out, preventing it from running, by WD itself, and an authentication type was not added to component_config.php which results in the drives not asking for authentication before performing the factory reset. The question then arises of why one hacker would use two different exploits, particularly an undocumented authentication bypass when they already had root access through the command injection vulnerability, with venerable tech site Ars Technica speculating that more than one group could be at work here, with one bunch of bad guys trying to take over, or sabotage, another's botnet.
Western Digital advises users to disconnect their device(s) from the internet. They are offering data recovery services beginning in July, and a trade-in program to switch the obsolete My Book Live drives for more modern My Cloud devices.
Data Storage

Intel's New Optane SSD P5800X Is the Fastest SSD Drive Ever Made (hothardware.com) 24

MojoKid writes: Intel recently shifted its storage strategy somewhat and is now catering its flagship Optane SSD P5800X, which was formerly targeted solely at data centers, to workstation users. The Optane SSD P5800X is based on a proprietary PCIe Gen 4x4 native controller and it features Intel's second-generation Intel Optane memory. In terms of performance, in some of the first benchmark numbers to hit the web, the drive is an absolute beast in the workloads that matter most for the vast majority of workstation users and enthusiasts. Random reads and writes are exceptionally good and access times at low queue depths are best-of-class. The Optane SSD P5800X's sequential transfers, while strong, aren't quite on the same level as some of today's fastest NAND-based PCIe 4 solid state drives, but they do exceed 7GB/s, which is still extremely fast. Overall, it's essentially the fastest SSD ever made. Endurance is off the charts too. However, all of that SSD horsepower comes at a price though, at a little over $2.50 per Gig and over $2,000 for an 800GB drive. With capacities of 400GB, 800GB and 1.6TB, the new Intel Optane SSD P5800X is shipping and available now.
OS X

Apple Makes OS X Lion and Mountain Lion Free To Download (macrumors.com) 47

Mac OS X Lion and OS X Mountain Lion can now be downloaded for free from Apple's website. "Apple has kept OS X 10.7 Lion and OS X 10.8 Mountain Lion available for customers who have machines limited to the older software, but until recently, Apple was charging $19.99 to get download codes for the updates," notes MacRumors. "The $19.99 fee dates back to when Apple used to charge for Mac updates. Apple began making Mac updates free with the launch of OS X 10.9 Mavericks, which also marked the shift from big cat names to California landmark names." From the report: Mac OS X Lion is compatible with Macs that have an Intel Core 2 Duo, Core i3, Core i5, Core i7, or Xeon processor, a minimum of 2GB RAM, and 7GB storage space. Mac OS X Mountain Lion is compatible with the following Macs: iMac (Mid 2007-2020), MacBook (Late 2008 Aluminum, or Early 2009 or newer), MacBook Pro (Mid/Late 2007 or newer), MacBook Air (Late 2008 or newer), Mac mini (Early 2009 or newer), Mac Pro (Early 2008 or newer), and Xserve (Early 2009). Macs that shipped with Mac OS X Mavericks or later are not compatible with the installer, however.
Security

Using VMs To Hide Ransomware Attacks is Becoming More Popular 41

An anonymous reader shares a report: In early 2020, security researchers were baffled to discover that a ransomware gang had come up with an innovative trick that allowed it to run its payload inside virtual machines on infected hosts as a technical solution that bypassed security software. One year later, that technique has spread among the cybercrime underground and is now used by multiple ransomware operators. Initially seen with the Ragnar Locker gang in May 2020, the technique was also adopted by a Maze ransomware subgroup later in the year and has been recently spotted in attacks where the Conti and MountLocker ransomware strains were deployed. In hindsight, it should be no surprise that this technique is becoming more popular, as it has tangible benefits for any threat actor. The general idea behind such an attack is that a ransomware gang that has a small foothold on an infected host can download and install VM software. The ransomware gang will then start a VM instance, share the host computer's storage space with the VM, and then proceed to encrypt the victim's files from within the VM, where the host's antivirus software cannot reach and detect the ransomware during execution.
Data Storage

Western Digital Blames Remotely-Installed Trojans for Wiping 'My Book' Storage Devices (westerndigital.com) 103

Some users who bought an external hard drive that's delightfully shaped like a book ended up with "terabytes' worth of data, years of memories and months of hard work vanished in an instant," reports Engadget. (Though according to a new statement from Western Digital, "Some customers have reported that data recovery tools may be able to recover data from affected devices, and we are currently investigating the effectiveness of these tools.")

But why were these deletions from "My Books" happening in the first place? A Slashdot reader shares the first clue from Engadget's report: Several owners looked into the cause of the issue and determined that their devices were wiped after receiving a remote command for a factory reset. The commands starting going out at 3PM on Wednesday and lasted throughout the night. One user posted a copy of their log showing how a script was run to shut down their storage device for a factory restore.
Friday Western Digital's statement offered much more detail: Western Digital has determined that some My Book Live and My Book Live Duo devices are being compromised through exploitation of a remote command execution vulnerability... The log files we have reviewed show that the attackers directly connected to the affected My Book Live devices from a variety of IP addresses in different countries. This indicates that the affected devices were directly accessible from the Internet, either through direct connection or through port forwarding that was enabled either manually or automatically via UPnP.

Additionally, the log files show that on some devices, the attackers installed a trojan with a file named ".nttpd,1-ppc-be-t1-z", which is a Linux ELF binary compiled for the PowerPC architecture used by the My Book Live and Live Duo. A sample of this trojan has been captured for further analysis and it has been uploaded to VirusTotal.

Our investigation of this incident has not uncovered any evidence that Western Digital cloud services, firmware update servers, or customer credentials were compromised. As the My Book Live devices can be directly exposed to the internet through port forwarding, the attackers may be able to discover vulnerable devices through port scanning...

At this time, we recommend you disconnect your My Book Live and My Book Live Duo from the Internet to protect your data on the device by following these instructions on our Knowledge Base. We have heard customer concerns that the current My Cloud OS 5 and My Cloud Home series of devices may be affected. These devices use a newer security architecture and are not affected by the vulnerabilities used in this attack. We recommend that eligible My Cloud OS 3 users upgrade to OS 5 to continue to receive security updates for your device

Data Storage

Xbox's DirectStorage API Will Speed Up Gaming PCs On Windows 11 Only (pcgamesn.com) 93

An anonymous reader quotes a report from PCGamesN: Microsoft has finally debuted Windows 11, and it's not just packing auto HDR and native Android apps. The long-teased DirectStorage API that's meant to cut down loading times on gaming PCs much in the same way the Xbox Velocity Architecture speeds things up on Microsoft's consoles is on its way, and it won't be coming to Windows 10 like we originally thought. The Windows 11 exclusive feature improves communication between your storage device and graphics card, allowing assets to load quicker without having to pass through the CPU first. Naturally, this means more time spent gaming and less time reading the same hints as you move from area to area.

It'll work best with systems that are dubbed 'DirectStorage Optimized', containing the right hardware and drivers for the job. If you're more of the DIY type that prefers to build the best gaming PC yourself, requirements demand an NVMe SSD with 1TB of storage or more. PCIe 4.0 NVMe SSDs and the latest GPUs from Nvidia and AMD will offer a better experience, but DirectStorage will still work with older standards like the third generation PCIe 3.0 -- you won't have much luck with 2.5-inch SATA drives, though. DirectStorage will only work with games built using DirectX 12, so there's no telling how many titles will support the feature when you upgrade to Windows 11 for free later this year.

Windows

Microsoft Is Changing the Windows 11 Minimum Requirements (theverge.com) 174

The specs required to run Microsoft's new Windows 11 OS are only slightly higher than Windows 10's current requirements. All you'll need is a 64-bit CPU (or SoC), 4GB of RAM, and 64GB of storage. The Verge reports: This marks the end of Windows support for older 32-bit hardware platforms, even though it will continue to run 32-bit software. The fastest way to find out if your system can handle Windows 11 is to download Microsoft's PC Health App, which will automatically tell you if your specs and settings are ready for the new OS. The system requirements listed by Microsoft are [available here].
Data Storage

WD My Book Users Wake Up To Find Their Data Deleted (arstechnica.com) 3

PuceBaboon writes: Ars Technica is reporting that some owners of Western Digital's My Book network-connected disk drives are experiencing data loss on their devices. The as yet unverified problem appears to be an externally initiated factory-reset, resulting in a loss of all existing data. At this early stage, Western Digital is warning users that they should disconnect their devices from the internet to protect their data. A thread on Western Digital's support forum alerted Ars Technica of the problem. Western Digital representatives write in an email: The incident is under active investigation from Western Digital. We do not have any indications of a breach or compromise of Western Digital cloud services or systems. We have determined that some My Book Live devices have been compromised by a threat actor. In some cases, this compromise has led to a factory reset that appears to erase all data on the device. The My Book Live device received its final firmware update in 2015. At this time, we are recommending that customers disconnect their My Book Live devices from the Internet to protect their data on the device. We have issued the following statement to our customers and will provide updates to this thread when they are available: https://community.wd.com/t/action-required-on-my-book-live-and-my-book-live-duo/268147
UPDATE (6/26): Western Digital wrote Friday that "Some customers have reported that data recovery tools may be able to recover data from affected devices, and we are currently investigating the effectiveness of these tools." After reviewing logs from their affected customers, the company now believes the affected devices were directly accessible from the Internet, allowing attackers to remotely install a malicious Trojan file.

"Our investigation of this incident has not uncovered any evidence that Western Digital cloud services, firmware update servers, or customer credentials were compromised. As the My Book Live devices can be directly exposed to the internet through port forwarding, the attackers may be able to discover vulnerable devices through port scanning."

Slashdot Top Deals