Google

'Do Not Buy a Smartwatch Right Now' (droid-life.com) 113

Since Qualcomm is set to launch a new wearable chipset on September 10, Kellen from DoidLife argues against buying a new Google Wear OS-powered smartwatch in the meantime. The new chipset will be able to execute commands quicker, and provide for substantially longer battery life. From the report: This new chipset is said to be built from the ground up, will allow watches to look pretty when you aren't using them (like a normal watch sitting idly by your side), and extend battery life. More importantly, Qualcomm is betting that this Snapdragon Wear chip will "significantly change the Wear OS ecosystem, what you expect from a smartwatch." If you buy a smartwatch today, before Qualcomm announces this chip, you will be stuck with a 2+ year old Snapdragon Wear 2100 chip. All of the new Wear OS watches that have been announced recently, use that chip. It's old. It's never been great. And it's about to be replaced by something potentially game-changing for smartwatches. A report from WinFuture says that this new Snapdragon chip will be called the Wear 3100 and will allow for "Ok Google" detection even when the display is off. It is rumored to come with Google's Pixel-branded smartwatch, although DroidLife thinks that LG will be one of the first to launch a watch with this new processor. "This LG watch is said to have physical watch hands, as well as the smarts of Wear OS and a touch display," reports DroidLife. It is expected to make its debut on September 10.
Security

Malicious Faxes Leave Firms 'Open' To Cyber-Attack (bbc.com) 77

Booby-trapped image data sent by fax can let malicious hackers sneak into corporate networks, security researchers have found. From a report: Since many companies use fax machines that are also printers and photocopiers, they often have a connection to the internal network. The malicious images exploit protocols established in the 1980s that define the format of fax messages. The research was presented at the Def Con hacker conference in Las Vegas. The two researchers said millions of companies could be at risk because they currently did little to secure fax lines. "Fax has no security measures built in -- absolutely nothing," security researcher Yaniv Balmas, from Check Point software, told the BBC. Mr Balmas uncovered the security holes in the fax protocols with the help of colleague Eyal Itkin and said they were "surprised" by the extent to which fax was still used.
Intel

Intel's 9th Gen Processors Rumored To Launch In October With 8 Cores (theverge.com) 233

According to a new report from Wccftech, Intel will introduce new Core i9, i7, and i5 chips on October 1st that will be branded as 9th generation processors. The Verge reports: The mainstream flagship processor, Intel's Core i9-9900K, is expected to ship with 8 cores and 16 threads. Leaked documents show that this will be the first mainstream Core i9 desktop processor, and will include 16 MB of L3 cache and Intel's UHD 620 graphics chip. Even Intel's 9th gen Core i7 processor is expected to ship with 8 cores and 8 threads (up from the current 6 cores), with the Core i5 shipping with 6 cores and 6 threads. Intel is reportedly launching its unlocked overclockable processors first, followed by more 9th generation processors early next year.
Data Storage

Watch Fish Swim By Petabytes of Data At Microsoft's Underwater Data Center (vice.com) 97

An anonymous reader quotes a report fro Motherboard: In June, Microsoft announced that it had placed a self-sufficient, waterproof data center off the coast of the Orkney Islands in Scotland. The data center, loaded with 864 servers capable of handling 27.6 petabytes of data, represented the culmination of nearly four years of research and development on the project, codenamed Natick. The underwater data center is the first of its kind. It's a proof of concept that aims to cut down on one of the biggest costs of running a data center on land -- cooling -- and can be rapidly deployed anywhere in the world. Due to the experimental nature of the project, however, Microsoft needed to keep a close eye on its pilot project. In order to monitor the environmental conditions around the tank, it placed two cameras nearby that livestream from the bottom of the ocean 24/7.
Businesses

PC Case Maker CaseLabs Closes Permanently (pcgamer.com) 401

U.S.-based PC case manufacturer, CaseLabs, announced on social media that it is "closing permanently" and will not be able to fill all current orders. "We have been forced into bankruptcy and liquidation," CaseLabs said in a statement. "The tariffs have played a major role raising prices by almost 80 percent (partly due to associated shortages), which cut deeply into our margins. The default of a large account added greatly to the problem... We reached out for a possible deal that would allow us to continue on and persevere through these difficult times, but in the end, it didn't happen." PC Gamer reports: CaseLabs is likely referring to the growing number of tariffs being enforced on Chinese imports by the United States government. China and the US are currently engaged in a trade war, causing many U.S. companies to lose money, lay off employees, or close entirely. CaseLabs went on to say that it won't be able to fill the backlog of case orders, but other parts will most likely ship to customers. "We are so incredibly sorry this is happening. Our user community has been very devoted to us and it's awful to think that we have let any of you down."
Security

World's Largest Chip Maker Will Lose $250M For Not Patching Windows 7 Computers (networkworld.com) 108

A major virus infection forced the closure of Taiwan Semiconductor Manufacturing Company (TSMC) factories last weekend..." writes Slashdot reader Mark Wilson, noting that it's the largest semiconductor manufacturer in the world, selling chips to Apple, Nvidia, AMD, Qualcomm, and Broadcom, and "responsible for producing iPhone processors."

Now Network World reports: The infection struck on Friday, August 3, and affected a number of unpatched Windows 7 computer systems and fab tools over two days. TSMC said it was all back to normal by Monday, August 6. TSMC did not say it was WannaCry, aka WannaCrypt, in its updates, but reportedly blamed WannaCry in follow-up conference calls with the press.... The company said this incident would cause shipment delays and additional costs estimated at 3 percent of third quarter revenue. The company had previously forecast revenues of $8.45 billion to $8.55 billion for its September quarter. A 3 percent loss would mean $250 million, though actual losses may come out lower than that. Still, that's a painful hit. TSMC also said no customer data was compromised....

TSMC isn't directly to blame here; someone [an infected production tool provided by an unidentified vendor] brought WannaCry into their offices and behind their firewall, but TSMC is still culpable because it left systems unpatched more than a year after WannaCry hit.

The Military

It'll Cost $1 Billion To Dismantle America's Nuclear-Powered Aircraft Carrier (popularmechanics.com) 209

"Six years after decommissioning USS Enterprise, the world's first nuclear-powered aircraft carrier, the U.S. Navy is still figuring out how to safely dismantle the ship," reports Popular Mechanics. schwit1 tipped us off to their report: The General Accounting Office estimates the cost of taking apart the vessel and sending the reactors to a nuclear waste storage facility at up to $1.5 billion, or about one-eighth the cost of a brand-new aircraft carrier.

The USS Enterprise was commissioned in 1961 to be the centerpiece of a nuclear-powered carrier task force, Task Force One, that could sail around the world without refueling.... The Navy decommissioned Enterprise in 2012 and removed the fuel from the eight Westinghouse A2W nuclear reactors in 2013. The plan was to scrap the ship and remove the reactors, transporting them by barge from Puget Sound Naval Base down the Washington Coast and up the Columbia River, then trucking them to the Department of Energy's Hanford Site for permanent storage. However, after decommissioning the cost of disposing of the 93,000-ton ship soared from an estimated $500-$750 million to more than a billion dollars. This caused the Navy to put a pause on disposal while it sought out cheaper options. Today the stripped-down hull of the Enterprise sits in Newport News, Virginia awaiting its fate.

"Although the Navy believes disposing of the reactors will be fairly straightforward, no one has dismantled a nuclear-powered carrier before...

"Whatever the Navy ends up doing, this will only be the first of many nuclear-powered carrier disposals."
Security

Researcher Finds A Hidden 'God Mode' on Some Old x86 CPUs (tomshardware.com) 114

"Some x86 CPUs have hidden backdoors that let you seize root by sending a command to an undocumented RISC core that manages the main CPU," Tom's Hardware reports, citing a presentation by security researcher Christopher Domas at the Black Hat Briefings conference in Las Vegas. The command -- ".byte 0x0f, 0x3f" in Linux -- "isn't supposed to exist, doesn't have a name, and gives you root right away," Domas said, adding that he calls it "God Mode." The backdoor completely breaks the protection-ring model of operating-system security, in which the OS kernel runs in ring 0, device drivers run in rings 1 and 2, and user applications and interfaces ("userland") run in ring 3, furthest from the kernel and with the least privileges. To put it simply, Domas' God Mode takes you from the outermost to the innermost ring in four bytes. "We have direct ring 3 to ring 0 hardware privilege escalation," Domas said. "This has never been done.... It's a secret, co-located core buried alongside the x86 chip. It has unrestricted access to the x86."

The good news is that, as far as Domas knows, this backdoor exists only on VIA C3 Nehemiah chips made in 2003 and used in embedded systems and thin clients. The bad news is that it's entirely possible that such hidden backdoors exist on many other chipsets. "These black boxes that we're trusting are things that we have no way to look into," he said. "These backdoors probably exist elsewhere." Domas discovered the backdoor, which exists on VIA C3 Nehemiah chips made in 2003, by combing through filed patents.

"Some of the VIA C3 x86 processors have God Mode enabled by default," Domas adds. "You can reach it from userland. Antivirus software, ASLR and all the other security mitigations are useless."
Facebook

Facebook Bans Sites That Host Blueprints of 3D-Printed Guns (cbsnews.com) 214

Yesterday, Facebook said it's banning websites that host and share blueprints of 3D-printed guns. "Sharing instructions on how to print firearms using 3D printers is not allowed under our Community Standards," said a spokesperson in an email statement. "In line with our policies, we are removing this content from Facebook." BuzzFeed was first to report the news: The move comes amid a rush by states to block these instructions from being posted. A July settlement between the State Department and Defense Distributed, an open-source organization that created the first completely 3D-printed gun, cleared the way for the group to publish the gun code. However, that was stalled when a federal judge on July 31 granted a temporary nationwide injunction that prevented Defense Distributed from uploading the plans. The injunction prevents Defense Distributed from publishing the plans. But the instructions are widely available online, on sites such as CodeIsFreeSpeech.com -- which hosts plans for parts of an AR-15, a Beretta, and Defense Distributed's Liberator. Attempts to post the site on a user's News Feed, through Facebook's Messenger app, or on Instagram (which Facebook owns) produce a variety of error messages. Other sites that host the files can still be posted through Facebook. Specifically, Facebook says that 3D-printed guns violate the regulated goods section of the social giant's community standards, which limits gun sales and exchanges to licensed dealers.
Software

Tesla's Chief Vehicle Engineer Returns To Apple (theverge.com) 130

Doug Field, the former VP of Mac hardware who left Apple to become Tesla's chief vehicle engineer, has returned to Cupertino. Field is reportedly working on the company's secretive "Project Titan" self-driving car program. The Verge reports: Field ran Tesla's vehicle production and engineering, but CEO Elon Musk took over responsibility for production this year after the company failed to meet its initial first-quarter goal for the Model 3. Field then took a leave of absence in May, and subsequently left the company altogether in June. Project Titan has reportedly been scaled back considerably from its initial scope, with hundreds of people leaving the division as Apple is said to focus on seeking carmaker partners for its self-driving software. [Daring Fireball's John Gruber] speculates that Field's return to Titan suggests Apple could still have an interest in producing vehicles itself, while cautioning that employees do move between the two companies regularly.
Privacy

Crestron Touchscreens Could Spy On Hotel Rooms, Meetings (wired.com) 21

An anonymous reader quotes a report from Wired: The connected devices you think about the least are sometimes the most insecure. That's the takeaway from new research to be presented at the DefCon hacking conference Friday by Ricky Lawshae, an offensive security researcher at Trend Micro. Lawshae discovered over two dozen vulnerabilities in Crestron devices used by corporations, airports, sports stadiums, and local governments across the country. While Crestron has released a patch to fix the issues, some of the weaknesses allowed for hackers to theoretically turn the Crestron Android touch panels used in offices and hotel rooms into spy devices.

Lawshae quickly noticed that these devices have security authentication protections disabled by default. For the most part, the Crestron devices Lawshae analyzed are designed to be installed and configured by third-party technicians, meaning an IT engineer needs to voluntarily turn on security protections. The people who actually use Crestron's devices after they're installed might not even know such protections exist, let alone how crucial they are. Crestron devices do have special engineering backdoor accounts which are password-protected. But the company ships its devices with the algorithm that is used to generate the passwords in the first place. That information can be used by non-privileged users to reverse engineer the password itself, a vulnerability simultaneously identified by both Lawshae and Jackson Thuraisamy, a vulnerability researcher at Security Compass.
There were also over two dozen other vulnerabilities that could be exploited to do things like transform them into listening devices. In addition to being able to remotely record audio via the microphones to a downloadable file, Lawshae was also able to remotely stream video from the webcam and open a browser and display a webpage to an unsuspecting room full of meeting attendees. "Crestron has issued a fix for the vulnerabilities, and firmware updates are now available," reports Wired.
Data Storage

Dropbox Is Dropping Support For All Linux File Systems Except Unencrypted Ext4 (dropboxforum.com) 258

New submitter rokahasch writes: Starting today, August 10th, most users of the Dropbox desktop app on Linux have been receiving notifications that their Dropbox will stop syncing starting November. Over at the Dropbox forums, Dropbox have declared that the only Linux filesystem supported for storage of the Dropbox sync folder starting the 7th of November will be on a clean ext4 file system. This basically means Dropbox drops Linux support completely, as almost all Linux distributions have other file systems as their standard installation defaults nowadays -- not to mention encryption running on top of even an ext4 file system, which won't qualify as a clean ext4 file system for Dropbox (such as eCryptfs which is the default in, for example, Ubuntu for encrypted home folders).

The thread is trending heavily on Dropbox' forums with the forum's most views since the thread started earlier today. The cries from a large amount of Linux users have so far remained unanswered from Dropbox, with most users finding the explanation given for this change unconvincing. The explanation given so far is that Dropbox requires a file system with support for Extended attributes/Xattrs. Extended attributes however are supported by all major Linux/Posix complaint file systems. Dropbox has, up until today, supported Linux platforms since their services began back in 2007.
A number of users have taken to Twitter to protest the move. Twitter user troyvoy88 tweets: "Well, you just let the shitstorm loose @Dropbox dropping support for some linux FS like XFS and BTRFS. No way in hell im going to reformat my @fedora #development station and removing encryption no way!"

Another user by the name of daltux wrote: "It will be time to say goodbye then, @Dropbox. I won't store any personal files on an unencrypted partition."
Android

Millions of Android Devices Are Vulnerable Right Out of the Box (wired.com) 67

Security meltdowns on your smartphone are often self-inflicted: You clicked the wrong link, or installed the wrong app. But for millions of Android devices, the vulnerabilities have been baked in ahead of time, deep in the firmware, just waiting to be exploited. Who put them there? Some combination of the manufacturer that made it, and the carrier that sold it to you. From a report: That's the key finding of new analysis from mobile security firm Kryptowire, which details troubling bugs preloaded into 10 devices sold across the major US carriers. Kryptowire CEO Angelos Stavrou and director of research Ryan Johnson will present their research, funded by the Department of Homeland Security, at the Black Hat security conference Friday. The potential outcomes of the vulnerabilities range in severity, from being able to lock someone out of their device to gaining surreptitious access to its microphone and other functions. They all share one common trait, though: They didn't have to be there. [...] "The problem is not going to go away, because a lot of the people in the supply chain want to be able to add their own applications, customize, add their own code. That increases the attack surface, and increases the probability of software error," Stavrou says. "They're exposing the end user to exploits that the end user is not able to respond to." Security researchers found 38 different vulnerabilities that can allow for spying and factory resets loaded onto 25 Android phones. That includes devices from Asus, ZTE, LG and the Essential Phone, which are distributed by carriers like Verizon or AT&T.
Businesses

'It's Time to End the Yearly Smartphone Launch Event' (vice.com) 224

Owen Williams, writing for Motherboard: Thursday, at a flashy event in New York, Samsung unveiled yet another phone: the Galaxy Note 9. Like you'd expect, it's rectangular, it has a screen, and it has a few cameras. While unveiling what it hopes will be the next hit, it unknowingly confirmed something we've all been wondering: the smartphone industry is out of ideas. Phones are officially boring: the only topic that's up for debate with the Galaxy Note 9 is the lack of the iconic notch found on the iPhone X, and that it has a headphone jack. The notch has been cloned by almost every phone maker out there, and the headphone jack is a commodity that's unfortunately dying. However, the fact that we're comparing phones with or without a chunk out of the screen or a hole for your headphones demonstrates just how stuck the industry is.

It's clear that there's nothing really to see here. Yeah, the Note is a big phone, and it has a larger battery too. It's in different colors, it's faster than last year, and it has wireless charging. Everything you see here is from a laundry list of features that other smartphone manufacturers also have, and the lack of differentiation becomes clearer every year. It's the pinnacle of technology, and it's a snooze-fest. This isn't exclusively a Samsung problem: Every manufacturer from Apple to Xiaomi faces the same predicament. The iPhone's release cycle that Apple trained the world to be accustomed to, with splashy yearly releases and million-dollar keynotes, is clearly coming to an end as consumers use their existing phones for longer every year.

Operating Systems

Samsung Unveils Tizen-Powered Galaxy Watch That Lasts 'Several Days' On Single Charge (venturebeat.com) 82

Alongside the Galaxy Note 9 and Galaxy Home Speaker, Samsung took the wraps off its new Galaxy Watch wearable at its Unpacked event in New York City. VentureBeat reports: Beyond coming in rose gold, silver, and midnight black colors, it can be had in two sizes -- the prior Gear S3 size is now called "46mm" and will start at $349.99, while a smaller-sized model is called "42mm" and will start at $329.99. Both will be available starting August 24, solely in the specific size and color configurations shown below. Samsung is also using improved glass: Gear S3 watches used Corning's Gorilla Glass SR+ and were IP68 rated for 10-foot, 30-minute water and dust resistance. The Galaxy Watch upgrades to Corning Gorilla DX+ glass and promises to keep the AMOLED screen underneath fully water-safe; it's rated for 5 ATM (165-foot/50-meter) submersion with IP68 and MIL-STD-810G certifications.

A disappointment in the new model is a reduction in its payment capabilities. The Gear S3 included both NFC and swipe-style magnetic secure transaction (MST) support to enable a wide array of Samsung Pay wireless purchases, but the Galaxy Watch drops MST support and only works with NFC. Not surprisingly, however, it does support Bluetooth 4.2 and 802.11b/g/n Wi-Fi. While continuing the use of a Tizen operating system from the Gear S3, Galaxy Watch packs a more powerful dual-core Exynos 9110 processor running at 1.15GHz. As was the case with the Gear S3 Frontier, the Galaxy Watch is available in Bluetooth-only and LTE versions, now promising LTE support across over 30 carriers in more than 15 countries. On stage, Samsung promised that the Galaxy Watch can be used for "several" days between charges; a subsequent press release said that it's actually "up to 80+ hours with typical usage" on the 46mm model, which has a 472mAh battery, versus "45+ hours" from the 270mAh battery of the 42mm model. Each model promises at least twice the longevity "with low usage."

Displays

Chemists Discover How Blue Light Speeds Blindness 144

Isao writes: It (apparently) has been known that blue light damages eyes and accelerates macular degeneration. A new article on Phys.org may have identified how this happens. It seems that unlike other light colors, blue causes a necessary molecule (retinal) to permanently kill photoreceptor cells. "The researcher found that a molecule called alpha Tocopherol, a Vitamin E derivative and a natural antioxidant in the eye and body, stops the cells from dying," reports Phys.org. "However, as a person ages or the immune system is suppressed, people lose the ability to fight against the attack by retinal and blue light." The authors will continue their research and recommend filtering and blue-light reduction in the meantime. The study has been published in the journal Scientific Reports.
Music

Samsung Announces Galaxy Home Speaker With Bixby Smart Assistant 47

The smart assistant that nobody asked for will be the brains of a new speaker Samsung is launching later this year. The Galaxy Home speaker will rival Apple's HomePod, while standing apart from competitors like Amazon's Echo and Google's Home with a promise of higher-quality audio. The Verge reports: The Galaxy Home looks like a strange vase or statue that might go on a table in the corner of your home. It's wrapped in fabric and elevated by three stout metal legs. It has a flat top with control buttons on it for skipping tracks and changing the volume. The speaker is supposed to deliver surround sound-style audio using six built-in speakers and a subwoofer. It also includes eight far-field microphones for detecting voice input. You'll be able to say "Hi, Bixby" to activate Samsung's assistant and ask it to start playing music or a number of other tasks. Samsung indicated that it'd be able to do many of the same things Bixby can do on a phone. Samsung is expected to share more details about the product at a developer conference in early November.
Intel

Intel Announces the 'World's Densest' SSD (zdnet.com) 62

Intel has unveiled its new 3D NAND solid-state drive (SSD) "ruler" form factor storage for data-center servers. From a report: The chip giant first set out this form factor a year ago, based on the Enterprise & Datacenter Storage Form Factor (EDSFF) standard for server makers to cut cooling costs and offer a more efficient format than SSDs in the classic 2.5 inch size. Intel describes the new ruler-shaped Intel SSD DC P4500, which is 12 inches by 1.5 inches, and a third of an inch thick, as the world's densest SSD. Server makers can jam up to one petabyte (PB) -- or a thousand terabytes (TB) -- of data into 1U server racks by lining up 32 of these 32TB Intel rulers together. So, instead of the decades-old 2.5-inch square SSD drives inherited from and designed for disk-based storage, Intel now has long and skinny sticks, thanks to flash. The new shape allows it to optimize SSD storage density, cooling, and power for data centers.
Android

Samsung Announces $1,000 Galaxy Note 9 Smartphone With Last-Gen Android Software Out-of-the-Box (engadget.com) 197

The Galaxy Note 9 touts a slightly larger 6.4-inch end-to-end screen, a 4,000mAh battery that promises "all-day" use, and a minimum 128GB of storage -- there's also a 512GB version that, with 512GB microSD cards, can give you a full terabyte of space. It runs Android 8.1 Oreo -- not Android Pie, which Google and Essential rolled out to some of their devices earlier this month. Engadget: Samsung is also bringing over welcome improvements from the Galaxy S9 family, including stereo speakers and the variable aperture f/1.5-2.4 primary camera (there's a second camera on the back, of course). This year, though, the most conspicuous change revolves around the S Pen. This is Samsung's first S Pen to incorporate Bluetooth, and that lets you do a whole lot more than doodle on the screen. You can use it as a remote control for selfies and presentations, and Samsung is providing a toolkit to let app developers use the pen for their own purposes. And no, you don't need to load it with batteries or plug it into a charger -- it'll top up just by staying in your phone. The base model of the Note 9, featuring 128GB of storage and 6GB of RAM, is priced at $999. The other variant will set you back by $1,250. Preorders begin on August 10th, and the phone will be available on August 24th at all major carriers or direct (and unlocked) from Samsung. CNET writes about the camera sensors on the new handset: The Galaxy Note 9 keeps the same hardware setup as the Galaxy S9 Plus. That is, dual 12-megapixel cameras on the back, one of them that automatically changes aperture when it detects the need for a low-light shot. (Samsung calls this dual aperture, and it's also on both S9 phones.) There's also an 8-megapixel front-facing camera for your selfies. What's different is AI software that analyzes the scene and quickly detects if you're shooting a flower, food, a dog, a person. There are 20 options the Note 9's been trained on, including snowflakes, cityscapes, fire, you get it. Then, the camera optimizes white balance, saturation and contrast to make photos pop.
Robotics

Ankis New Robot Has Artificial Emotional Intelligence (fastcompany.com) 35

harrymcc writes: Toymaker Anki, whose Cozmo robot has been a hit, has announced its next bot: Vector. Though it looks a lot like Cozmo, it packs far more computational power -- Cozmo relied on a phone app for smarts -- and utilizes deep-learning tech in the interest of giving Vector a subtler, more engaging personality. Over at Fast Company, Sean Captain has a deep dive into the software engineering that went into the effort. Vector is being powered by a quad-core Qualcomm Snapdragon 212 chip, and has cartoon eyes displayed on a 184 x 96-pixel screen. The robot actually scans its environment via a single 720p wide-angle camera mounted below the screen. "Cozmo springs to attention when you call its name, making twittering sounds, and lifting its bulldozer-like arms up and down," writes Captain. "If you ignore Cozmo, the bot gets more in your face, or makes loud, obnoxious snoring sounds."

While Vector can connect to the internet and display weather information, set timers, and speak answers to various questions, it's the social and visual intelligence that people may fall in love with the most. Vector is able to detect people and interact with them, even when faces aren't visible. Computer vision technical director Andrew Stein and his team "trained a convolutional neural network (CNN) -- a popular deep-learning AI technology that mimics the brains visual cortex," reports Captain. "Using the often blurry and distorted footage that Vector's camera captures as he moves around, Stein has been teaching the CNN to detect people from the back or the side, for instance, up to about 10 feet away."

Slashdot Top Deals