The Internet

The 'Scunthorpe Problem' Has Never Really Been Solved (vice.com) 382

dmoberhaus writes: Yesterday, a writer for SB Nation named Natalie Weiner posted a screenshot of a rejection form she received when she tried to sign up for a website. Her submission was rejected because a spam algorithm considered her last name "offensive." After she posted about this, hundreds of other people with similarly "offensive" last names sounded off about how they had experienced similar issues. As it turns out, this phenomenon is so widespread that it has a name among computer scientists. It's called the Scunthorpe problem and it's been a scourge of the internet since the beginning. Motherboard spoke to content moderation experts about its origins and why it's such a hard problem to solve 20 years later. A big reason why the problem has yet to be solved is "because creating effective obscenity filters depends on the filter's ability to understand a word in context," reports Motherboard. "Despite advances in [AI], this is something that even the most advanced machine-learning algorithms still struggle with today."

"This works both ways around," Michael Veale, a researcher studying responsible machine learning at University College London, told Motherboard. "Cock (a bird) and Dick (the given name) are both harmless in certain contexts, even in children's settings online, but in other cases parents might not want them used. Equally, those wanting to abuse a system can find ways around it."
Encryption

Vint Cerf on Differential Traceability on the Internet (acm.org) 105

Addressing the bad behaviors on the Internet, that range from social network bullying and misinformation to email spam, distributed denial of service attacks, direct cyberattacks against infrastructure, malware propagation, identity theft, and a host of other ills require a wide range of technical and legal considerations, says Vint Cerf, even as he steers clear that he supports encryption. But is there a way to bring more accountability and traceability on our actions on the internet without compromising our privacy? He has a proposition: What is of interest to me is a concept to which I was introduced at the Ditchley workshop, specifically, differential traceability. The ability to trace bad actors to bring them to justice seems to me an important goal in a civilized society. The tension with privacy protection leads to the idea that only under appropriate conditions can privacy be violated. By way of example, consider license plates on cars. They are usually arbitrary identifiers and special authority is needed to match them with the car owners (unless, of course, they are vanity plates like mine: "Cerfsup"). This is an example of differential traceability; the police department has the authority to demand ownership information from the Department of Motor Vehicles that issues the license plates. Ordinary citizens do not have this authority.

In the Internet environment there are a variety of identifiers associated with users (including corporate users). Domain names, IP addresses, email addresses, and public cryptography keys are examples among many others. Some of these identifiers are dynamic and thus ambiguous. For example, IP addresses are not always permanent and may change (for example, temporary IP addresses assigned at Wi-Fi hotspots) or may be ambiguous in the case of Network Address Translation. Information about the time of assignment and the party to whom an IP address was assigned may be needed to identify an individual user. There has been considerable debate and even a recent court case regarding requirements to register users in domain name WHOIS databases in the context of the adoption of GDPR. If we are to accomplish the simultaneous objectives of protecting privacy while apprehending those engaged in harmful or criminal behavior on the Internet, we must find some balance between conflicting but desirable outcomes.

Google

Google To Stop Supporting Public URL Submissions To Its Search Index (searchengineland.com) 32

Google announced this week that it is discontinuing the public method of submitting URLs to its search index. The "addurl" page, which is still listed in this help document, now redirects to the Google Search Console login page. From a report: Google Webmasters said, "We've had to drop the public submission feature." The company did not say why it was necessary to drop it. Maybe it has to do with spam issues or abuse. Google added, "... but we continue to welcome your submissions using the usual tool in Search Console and through sitemaps directly." The last time Google updated the submit content tool was back in 2012, when it moved it to the classic Google Webmaster Tools URL. Google says webmasters should submit content only through Search Console's Fetch as Google tool or via sitemaps.
Facebook

Facebook Notification Spam Has Crossed the Line (wired.com) 98

Facebook has always nudged truant users back to its platform though emails and notifications. But recently, those prods have evolved beyond comments related to activity on your own profile. From a report: Now Facebook will nag you when an acquaintance comments on someone else's photo, or when a distant family member updates their status. The spamming has even extended to those who sign up for two-factor authentication -- which is a great way to turn people off to that extra layer of security. "The part of it that bugs me is that two-factor authentication is something [Facebook] should be encouraging people to use, but instead the way this is working here is that they're driving people away from two-factor and making people less secure," says Matt Green, a professor at the Johns Hopkins University Information Security Institute, who has done contracted security work for Facebook in the past.

"It's abusive, people's attention is deliberately tweaked by what looks like a two-factor authentication message." Green says he's received near-daily SMS messages from Facebook since January alerting him that one of his friends performed some action on the platform. Before he started receiving the messages, Green says he hadn't logged into Facebook for a long time and had actually forgotten his password. The weirdest part about the SMS notifications is what happens if you reply to them. If you respond, your message is posted to your own profile.
Further reading: Facebook Really Wants You To Come Back, Facebook Is Spamming Users Via Their 2FA Phone Numbers, and Facebook Makes Moves On Instagram's Users.
Facebook

In a Bid To Curtail Spread of Misinformation, Facebook's WhatsApp Now Tells Users When a Message Has Been Forwarded (hindustantimes.com) 65

In a bid to fight spread of misinformation on its platform, Facebook-owned WhatsApp announced on Tuesday that it is launching a new feature globally that will highlight when a message has been forwarded versus composed by the sender. At the centre of the issue is high-volume sharing of misleading and false information, often arching political and religious sentiments, that is tricking a significant number of WhatsApp users. (WhatsApp is used by more than a billion users worldwide.) From a report: From now on, WhatsApp will put a "forwarded" label on these messages. "This extra context will help make one-on-one and group chats easier to follow. It will also help you determine if your friend or relative wrote the message they sent or if it came from someone else," the company said in a note. "WhatsApp cares deeply about your safety. We encourage you to think before sharing forwarded messages. As a reminder, you can report spam or block a contact in one tap and always reach out to WhatsApp directly for help," it added. To see this new forwarded label, users are required to have the newest supported version of WhatsApp on their phones. Additionally, this week the company relaunched a campaign in India as part of which it is running full-page ads on several newspapers in the country to create awareness about the issue.
Twitter

Twitter Suspended 70 Million Accounts In Past Two Months, Says Report (theverge.com) 79

According to The Washington Post, Twitter has suspended 70 million accounts in the past two months as part of a crackdown on malicious activity on its platform. "The rate of suspensions for May and June is reportedly twice the company's October 2017 suspension rate," reports The Verge. From the report: In a blog post last month, Twitter said it had been working to improve its safety policies, and that its "systems identified and challenged more than 9.9 million potentially spammy or automated accounts per week."

The Post reports that the change in enforcement could cause a decline in users for the company's second quarter, although a Twitter executive told the publication that many of the accounts rarely tweeted, and would therefore not dramatically impact the company's active user count. A Twitter spokesperson said in a statement to The Verge that the company noted in its first-quarter shareholder letter this year that âoeongoing information quality effortsâ had negatively impacted monthly users, and that the efforts could continue to impact user numbers in the future.

Operating Systems

All-Radio 4.27 Portable Can't Be Removed? Then Your PC Is Severely Infected (bleepingcomputer.com) 247

CaptainDork shares a report from Bleeping Computer: Starting yesterday, there have been numerous reports of people's Windows computers being infected with something called "All-Radio 4.27 Portable." After researching this heavily today, it has been determined that seeing this program is a symptom of a much bigger problem on your computer. If your computer is suddenly displaying the above program, then your computer is infected with malware that installs rootkits, miners, information-stealing Trojans, and a program that is using your computer to send send out spam.

Unfortunately, while some security programs are able to remove parts of the infection, the rootkit component needs manual removal help. Due to this, if you are infected with this malware, I strongly suggest that you create a malware removal help topic in our Virus Removal forum in order to receive one-on-one help in cleaning your computer. Some of the VirusTotal scans associated with this infection have also indicated that an information stealing Trojan could have been installed by this malware bundle as well. Therefore, it is strongly suggested that you change your passwords using a clean machine if you had logged into any accounts while infected.
6/29/18: The story has been updated to specify that this malware campaign is targeting Windows computers.
The Internet

Gmail Proves That Some People Hate Smart Suggestions (techcrunch.com) 181

Citing a number of complaints following Google's Gmail makeover, TechCrunch's Romain Dillet makes the case for why some users don't want smart suggestions in the email service: There's a reason why Gmail lets you disable all the smart features. Some users don't want smart categories, important emails first and smart reply suggestions. Arguably, the only smart feature everyone needs is the spam filter. A pure chronological feed of your email messages is incredibly valuable as well. That's why many Instagram users are still asking for a chronological feed. Sure, algorithmic feeds can lead to more engagement and improved productivity. Maybe Google conducted some tests and concluded that you end up answering more emails if you let Gmail do its thing. But you may want to judge the value of each email without an algorithmic ranking.

VCs could spot the next big thing without any bias. Journalists could pay attention to young and scrappy startups as much as the new electric scooter startup in San Francisco. Universities could give a grant to students with unconventional applications. The HR department of your company could look at all applications without following Google's order.

Cellphones

Why No One Answers Their Phone Anymore (theatlantic.com) 429

An anonymous reader shares an excerpt from a report via The Atlantic, written by Alexis C. Madrigal: No one picks up the phone anymore. Even many businesses do everything they can to avoid picking up the phone. Of the 50 or so calls I received in the last month, I might have picked up four or five times. The reflex of answering -- built so deeply into people who grew up in 20th-century telephonic culture -- is gone. There are many reasons for the slow erosion of this commons. The most important aspect is structural: There are simply more communication options. Text messaging and its associated multimedia variations are rich and wonderful: words mixed with emoji, Bitmoji, reaction gifs, regular old photos, video, links. Texting is fun, lightly asynchronous, and possible to do with many people simultaneously. It's almost as immediate as a phone call, but not quite. You've got your Twitter, your Facebook, your work Slack, your email, FaceTimes incoming from family members. So many little dings have begun to make the rings obsolete.

But in the last couple years, there is a more specific reason for eyeing my phone's ring warily. Perhaps 80 or even 90 percent of the calls coming into my phone are spam of one kind or another. [...] There are unsolicited telemarketing calls. There are straight-up robocalls that merely deliver recorded messages. There are the cyborg telemarketers, who sit in call centers playing prerecorded bits of audio to simulate a conversation. There are the spam phone calls, whose sole purpose seems to be verifying that your phone number is real and working.

Advertising

Ads Are Coming To Facebook Stories (techcrunch.com) 31

Facebook Stories has reached 150 million daily active users after launching nearly 14 months ago. So what's the next logical step after reaching such a milestone? Advertisements. According to TechCrunch, Facebook Stories will start testing its first ads today in the U.S., Mexico and Brazil. From the report: They're 5- to 15-second video ads users can skip, and while there's no click-through or call to action now, Facebook plans to add that in the coming months. Advertisers can easily extend their Instagram Stories ads to this new surface, or have Facebook automatically reformat their News Feed ads with color-matched borders and text at the bottom. Facebook also plans to give businesses more metrics on their Stories performance to convince them the feature is worth their ad dollars.
Twitter

Twitter Will Start Hiding Tweets That 'Detract From the Conversation' (slate.com) 186

Yesterday, Twitter announced several new changes to quiet trolls and remove spam. According to Slate, the company "will begin hiding tweets from certain accounts in conversations and search results." In order to see them, you'll now have to scroll to the bottom of the conversation and click "Show more replies," or go into your search settings and choose "See everything." From the report: When Twitter's software decides that a certain user is "detract[ing] from the conversation," all of that user's tweets will be hidden from search results and public conversations until their reputation improves. And they won't know that they're being muted in this way; Twitter says it's still working on ways to notify people and help them get back into its good graces. In the meantime, their tweets will still be visible to their followers as usual and will still be able to be retweeted by others. They just won't show up in conversational threads or search results by default. The change will affect a very small fraction of users, explained Twitter's vice president of trust and safety, Del Harvey -- much less than 1 percent. Still, the company believes it could make a significant difference in the average user's experience. In early testing of the new feature, Twitter said it has seen a 4 percent drop in abuse reports in its search tool and an 8 percent drop in abuse reports in conversation threads.
Google

Google Hasn't Stopped Reading Your Emails (theoutline.com) 186

An anonymous reader shares a report: If you're a Gmail user, your messages and emails likely aren't as private as you'd think. Google reads each and every one, scanning your painfully long email chains and vacation responders in order to collect more data on you. Google uses the data gleaned from your messages in order to inform a whole host of other products and services, NBC News reported Thursday.

Though Google announced that it would stop using consumer Gmail content for ad personalization last July, the language permitting it to do so is still included in its current privacy policy, and it without a doubt still scans users emails for other purposes. Aaron Stein, a Google spokesperson, told NBC that Google also automatically extracts keyword data from users' Gmail accounts, which is then fed into machine learning programs and other products within the Google family. Stein told NBC that Google also "may analyze [email] content to customize search results, better detect spam and malware," a practice the company first announced back in 2012.

IT

Nigerian Email Scammers Are More Effective Than Ever (wired.com) 129

You would think that after decades of analyzing and fighting email spam, there'd be a fix by now for the internet's oldest hustle -- the Nigerian Prince scam. But the problem, a new report suggests, has only grown to become more widespread and sophisticated. From the report: There's generally more awareness that a West African noble demanding $1,000 in order to send you millions is a scam, but the underlying logic of these "pay a little, get a lot" schemes, also known as 419 fraud, still ensnares a ton of people. In fact, groups of fraudsters in Nigeria continue to make millions off of these classic cons. And they haven't just refined the techniques and expanded their targets -- they've gained minor celebrity status for doing it.

On Thursday, the security firm Crowdstrike published detailed findings on Nigerian confraternities, cultish gangs that engage in various criminal activities and have steadily evolved email fraud into a reliable cash cow. The groups, like the notorious Black Axe syndicate, have mastered the creation of compelling and credible-looking fraud emails. Crowdstrike notes that the groups aren't very regimented or technically sophisticated, but flexibility and camaraderie still allow them to develop powerful scams.

Communications

Forty Years of Spam Email (bbc.com) 95

An anonymous reader writes: The BBC has a video celebrating the 40th birthday of spam email. Here's a transcript of the video: "It is 40 years since the first spam email was sent. Marketer Gary Thuerk composed an email selling his company's newest computers and sent it to 400 users on ARPANET, which was the network that become the basis for the internet. Why is it called spam? It has been suggested that it was called spam after a song in a Monty Python sketch. Where patrons of a cafe were repeatedly offered something they didn't want. The concept of spam is nothing new. Unsolicited telegrams were sent over 100 years ago and we've come to accept junk mail as part of everyday life. Now [nearly 60%] of all email is spam. Like most rubbish, it can be found everywhere on earth."
Facebook

Facebook Brags That Messenger Has 300,000 Business Bots (mashable.com) 92

An anonymous reader quotes a report from Mashable: At F8, Facebook's Vice President of Messaging Products, David Marcus, jovially reported that Messenger's integration with business is going swimmingly. According to Marcus, over 8 billion messages have been sent between people and businesses. And there are 300,000 monthly active bots engaging with customers on messenger. Facebook introduced messenger bots for businesses at F8 in 2016. The idea is that bots allow for automated communication between businesses and customers, helping with issues like product recommendations and customer service. According to Marcus, that 300,000 number grew from just 100,000 monthly active bots in its first year.
Google

Gmail's Big Upgrade Featuring New Web App, Confidential Mode, Nudges, and Snooze Goes Live (venturebeat.com) 78

Google on Wednesday pushed out the biggest revamp of Gmail in years. The company is bringing to the flagship Gmail service many (but not all) of the features it trialed in Inbox for Gmail, and adding a few new ones, too. From a report: While the overhaul does usher in a new look to the Gmail web app, bringing it into the material design fold, this update is more about throwing new features into the mix than moving things around and causing confusion. G Suite -- Google's paid productivity service for businesses, which also includes Gmail -- appears to be the core focus of this update, however these features will also be made available to standard Gmail users. [...] Google is adamant that no person within the company will ever read your emails, but that doesn't mean your email content is protected from third-party infiltration. To address this, Gmail will soon offer users a dedicated "confidential mode" -- on the web and in its mobile apps -- that is designed to protect against two kinds of attacks. [...] In addition to privacy and security updates, Gmail on mobile and the web is getting a bunch of new features to help solve the perennial problem of email overload. One of those tools is "nudging," which leans on Google's AI smarts and automated processing, similar to how its spam filter works, to remind users to follow up on a message they've received.
Google

Google's Phone App Is Getting the Power To Send Spam Calls Straight To Voicemail (9to5google.com) 85

According to 9to5Google, Google's dialer app for Pixel, Nexus, and Android One devices is being upgraded with the ability to send spam calls straight to voicemail. "In 2016, the app began alerting users to potential spam callers by flashing the incoming call screen bright red, with another 'Suspected spam caller' alert just underneath the phone number," reports 9to5Google. The new spam filtering feature goes a step further. From the report: [U]sers will not receive a missed call or voicemail notification, though filtered calls will appear in call history and any voicemails left will still show up in that respective tab. This feature is rolling out worldwide over the next few weeks, but those who join the new beta will have initial access to it. Like its other programs, Google notes that the test allows you to use experimental features before they're released. Google warns that features will still be in-development, might be unstable, and have "a few problems." Meanwhile, users will have the ability to submit in-app feedback throughout the process. Head to the Google Play listing for the Phone app and scroll down to "Become a tester" in order to join.
Businesses

How Much VR User Data Is Oculus Giving To Facebook? (theverge.com) 60

Facebook owns many other apps and services, including the Oculus virtual-reality platform, which collects incredibly detailed information about where users are looking and how they're moving. Since most of the discussion about how Facebook handles user information is focused on the social network itself, The Verge's Adi Robertson looks into the link between Facebook and Oculus: A VR platform like Oculus offers lots of data points that could be turned into a detailed user profile. Facebook already records a "heatmap" of viewer data for 360-degree videos, for instance, flagging which parts of a video people find most interesting. If it decided to track VR users at a more detailed level, it could do something like track overall movement patterns with hand controllers, then guess whether someone is sick or tired on a particular day. Oculus imagines people using its headsets the way they use phones and computers today, which would let it track all kinds of private communications. The Oculus privacy policy has a blanket clause that lets it share and receive information from Facebook and Facebook-owned services. So far, the company claims that it exercises this option in very limited ways, and none of them involve giving data to Facebook advertisers. "Oculus does not share people's data with Facebook for third-party advertising," a spokesperson tells The Verge.

Oculus says there are some types of data it either doesn't share or doesn't retain at all. The platform collects physical information like height to calibrate VR experiences, but apparently, it doesn't share any of it with Facebook. It stores posts that are made on the Oculus forums, but not voice communications between users in VR, although it may retain records of connections between them. The company also offers a few examples of when it would share data with Facebook or vice versa. Most obviously, if you're using a Facebook-created VR app like Spaces, Facebook gets information about what you're doing there, much in the same way that any third-party app developer would. You can optionally link your Facebook account to your Oculus ID, in which case, Oculus will use your Facebook interests to suggest specific apps or games. If you've linked the accounts, any friend you add on Facebook will also become your friend on Oculus, if they're on the platform.
Oculus does, however, share data between the two services to fight certain kinds of banned activity. "If we find someone using their account to send spam on one service, we can disable all of their accounts," an Oculus spokesperson says. "Similarly, if there's 'strange activity' on a specific Oculus account, they can share the IP address it's coming from with Facebook," writes Robertson. "The biggest problem is that there's nothing stopping Facebook and Oculus from choosing to share more data in the future."
Facebook

Steve Wozniak Drops Facebook: 'The Profits Are All Based On the User's Info' (arstechnica.com) 246

Apple cofounder Steve Wozniak has formally deactivated his Facebook account. In an email interview with USA Today, Wozniak wrote that he was no longer satisfied with Facebook, knowing that it makes money off of user data. "The profits are all based on the user's info, but the users get none of the profits back," he wrote. "Apple makes its money off of good products, not off of you. As they say, with Facebook, you are the product." Ars Technica reports: His Sunday announcement to his Facebook followers came just ahead of Facebook CEO Mark Zuckerberg's scheduled testimony before Congress on Tuesday. The CEO is also reportedly set to meet with members of Congress privately on Monday. Wozniak wrote that Facebook had "brought me more negatives than positives." Still, when Wozniak tried to change some of his privacy settings in the aftermath of Cambridge Analytica, he said he was "surprised" to find out how many categories for ads he had to remove. "I did not feel that this is what people want done to them," added Wozniak. "Ads and spam are bad things these days and there are no controls over them. Or transparency."
Youtube

YouTube Shooter 'Nasim Aghdam' Reportedly Had Website With Manifesto That Targeted YouTube For Censorship, Demonetization (abc7news.com) 722

The woman who entered the YouTube headquarters in San Bruno, California, this morning and started shooting has been identified as Nasim Aghdam. According to ABC7 News, "the YouTube shooter was a user of the platform" and had "a website with an alleged manifesto that targeted YouTube for censorship and demonetization of her video content. According to her website, a possible motivation for the shooting could have been tied to her many YouTube accounts, which she says have seen a decline in viewership over the past few months."

Slashdot Top Deals