Facebook

Despite EU Court Rulings, Facebook Says US Is Safe To Receive Europeans' Data (politico.eu) 32

Despite the European Union's highest court twice declaring that the United States does not offer sufficient protection for Europeans' data from American national security agencies, the social media giant's lawyers continue to disagree, according to internal documents seen by POLITICO. Their conclusion that the U.S. is safe for EU data is part of Facebook's legal argument for it to be able to continue shipping data across the Atlantic. From the report: In July 2020, the Court of Justice of the European Union (CJEU) struck down a U.S.-EU data transfer instrument called Privacy Shield. The court concluded Washington did not offer adequate protection for EU data shipped overseas because U.S. surveillance law was too intrusive for European standards. In the same landmark ruling, the Luxembourg-based court upheld the legality of another instrument used to export data out of Europe called Standard Contractual Clauses (SCCs). But it cast doubt on whether these complex legal instruments could be used to shuttle data to countries where EU standards cannot be met, including the U.S. The CJEU reached a similar conclusion in 2015, striking down the predecessor agreement to Privacy Shield because of U.S. surveillance law and practices. In both rulings, Europe's top judges categorically stated Washington did not have sufficiently high privacy standards. Still, Facebook -- the company at the heart of both cases -- thinks it shouldn't follow the court's reasoning.

The company's lawyers argue in the documents that the EU court ruling "should not be relied on" for the social media company's own assessment of data transfers to the U.S., because the judges' findings relate to Privacy Shield data pact, and not the Standard Contractual Clauses which Facebook uses to transfer data to the U.S. "The assessment of U.S. law (and practice) under Article 45 GDPR is materially different to the assessment of law and practice required under Article 46 GDPR," the document reads. That refers to the two different types of legal data transfer instruments under the EU's General Data Protection Regulation and indicates that assessment under SCCs is different to assessment under Privacy Shield. The company also says that changes to U.S. law and practices since the July 2020 ruling should be taken into account. As an example, it cites the U.S. Federal Trade Commission, a watchdog, "carrying out its role as a data protection agency with unprecedented force and vigour." Those arguments have been central to Washington's pitch during ongoing transatlantic negotiations over a new EU-U.S. data agreement.
"Though companies have to take the EU court ruling into account when making their own assessments of third party country regimes, they can, in theory, diverge from the court's findings if they believe it is justified in a particular situation," notes Politico. "This means that companies like Facebook can, in theory, continue to ship data out of Europe if they can prove its sufficiently protected."
Google

More Than 35,000 Java Packages Impacted by Log4j Vulnerabilities, Google Says (therecord.media) 39

Google's open-source team said they scanned Maven Central, today's largest Java package repository, and found that 35,863 Java packages use vulnerable versions of the Apache Log4j library. From a report: This includes Java packages that use Log4j versions vulnerable to the original Log4Shell exploit (CVE-2021-44228) and a second remote code execution bug discovered in the Log4Shell patch (CVE-2021-45046). James Wetter and Nicky Ringland, members of the Google Open Source Insights Team, said in a report today that typically when a major Java security flaw is found, it typically tends to affect only 2% of the Maven Central index. However, the 35,000 Java packages vulnerable to Log4Shell account to roughly 8% of the Maven Central total of ~440,000, a percentage the two described using just one word -- "enormous." But since the vulnerability was disclosed last week, Wetter and Ringland said the community has responded positively and has already fixed 4,620 of the 35,863 packages they initially found vulnerable. This number accounts to 13% of all the vulnerable packages.
Facebook

Meta Shareholders Call for Oversight Audit (axios.com) 16

A group of Meta shareholders, along with the Campaign for Accountability, has submitted a resolution calling for an independent evaluation of the board's ability to oversee public safety on Facebook's platforms, Axios has learned. From the report: Facebook's parent company is facing pressure on multiple fronts from regulators, legislators and former employees -- and now investors. A letter sent earlier this month to Meta's corporate secretary, a copy of which was seen by Axios, says that, "Shareholders request the board commission an independent assessment of the Audit and Risk Oversight Committee's capacities and performance in overseeing company risks to public safety and the public interest and in supporting strategic risk oversight on these issues by the full board."

The letter is being submitted by the Harrington Associates and Park Foundation, both Facebook shareholders, in conjunction with the Campaign for Accountability. It aims to be included in Meta's annual proxy and submitted to a vote of shareholders. Other shareholders are also pushing similar resolutions this year, including an effort led by state investment officials in New York and Illinois. Facebook maintains it takes its responsibilities seriously, and told the Wall Street Journal that it has spent more than $5 billion this year on safety and security.

Earth

Himalayan Glaciers Are Melting at Furious Rate, New Study Shows (wsj.com) 129

Glaciers across the Himalayas are melting at an extraordinary rate, with new research showing that the vast ice sheets there shrank 10 times faster in the past 40 years than during the previous seven centuries. From a report: Avalanches, flooding and other effects of the accelerating loss of ice imperil residents in India, Nepal and Bhutan and threaten to disrupt agriculture for hundreds of millions of people across South Asia, according to the researchers. And since water from melting glaciers contributes to sea-level rise, glacial ice loss in the Himalayas also adds to the threat of inundation and related problems faced by coastal communities around the world. "This part of the world is changing faster than perhaps anybody realized," said Jonathan Carrivick, a University of Leeds glaciologist and the co-author of a paper detailing the research published Monday in the journal Scientific Reports. "It's not just that the Himalayas are changing really fast, it's that they're changing ever faster."

Scientists have long observed ice loss from large glaciers in New Zealand, Greenland, Patagonia and other parts of the world. But ice loss in the Himalayas is especially rapid, the new study found. The researchers didn't pinpoint a reason but noted that regional climate factors, such as shifts in the South Asian monsoon, may play a role. The new finding comes as there is scientific consensus that ice loss from glaciers and polar ice sheets results from rising global temperatures caused by greenhouse-gas emissions from the burning of fossil fuels. Many peer-reviewed scientific studies have identified human activity as a cause of rising global temperatures. So did a report issued in August by the United Nations Intergovernmental Panel on Climate Change, which said "human influence is very likely the main driver of the global retreat of glaciers since the 1990s." For the new study, Dr. Carrivick and his colleagues scanned satellite photos of almost 15,000 glaciers in the region for signs of the large ridges of rock and debris that glaciers leave behind as they slowly grind their way through the valleys. Using the locations of these ancient glacial tracks, the scientists estimated the span of ice sheet coverage in previous centuries.

Cloud

Is the Cloud Making Internet Services More Fragile? (nbcnews.com) 119

In the past three weeks, two major outages at Amazon's cloud computing service "led to widespread disruptions at other online services," reports NBC News. And they also cite June's "service configuration" issue at cloud CDN Fastly, which took countless sites offline including PayPal, Reddit and GitHub, and an AWS outage in November of 2020 which affected clients like Apple.

"The drumbeat of issues underscores that the internet, despite all it's capable of, is sometimes fragile...." The latest disruption occurred Wednesday, when customers of DoorDash, Hulu and other websites complained that they couldn't connect. The problems were traced to Amazon Web Services, or AWS, the most widely used cloud services company, which reported that outages in two of its 26 geographic regions were affecting services nationwide. A similar disruption took place Dec. 7, crippling video streams, halting internet-connected robot vacuum cleaners and even shutting down pet food dispensers in a series of reminders of how much life has moved online, especially during the coronavirus pandemic. AWS published an unusually detailed description of what went wrong, along with an apology.

The incidents helped to explode the illusion, reinforced by decades of steadily improving internet speed and reliability, that everyday consumers can rely on online services to be available without fail.... Experts in computer science and security said the interruptions don't really call into question the fundamental design of the internet, one of the founding ideas of which was that a distributed system can mostly continue functioning even if one piece goes down. But they said the problems are rooted in the uneven development of the internet, because certain data centers are more important than others; cloud businesses run by Amazon, Google and Microsoft concentrate more power; and corporate customers of cloud services don't always want to pay extra for backup systems and staff members.

Sean O'Brien, a lecturer in cybersecurity at Yale Law School, said the outages call into question the wisdom of relying so much on big data centers. " 'The cloud' has never been sustainable and is merely a euphemism for concentrated network resources controlled by a centralized entity," he said, adding that alternatives like peer-to-peer technology and edge computing may gain favor. He wrote after last week's outage that the big cloud providers amounted to a "feudal" system.

"There are many points of failure whose unavailability or suboptimal operation would affect the entire global experience of the internet," said Vahid Behzadan, an assistant professor of computer science at the University of New Haven... "The fact that we've had repeated outages in a short period of time is a cause for alarm," Behzadan said, noting that U.S. businesses have staked a lot on the assumption that cloud services are resilient.

NBC cites reports that some companies are now taking a look at using multicloud solutions. And these outages may encourage businesses to finally take the plunge, adds the CS professor from New Haven.

"The internet will not die any time soon. But whatever won't kill the internet makes it stronger."
Transportation

Amazon Driver Was Warned She'd Be Fired For Returning With Packages During a Tornado (theverge.com) 179

Joe_Dragon shares a report from The Verge: An Amazon delivery driver in Illinois was told to keep delivering packages after she reported hearing tornado sirens, with the dispatcher saying that the sirens were "just a warning." According to a report by Bloomberg, which includes screenshots of the conversation, the driver was told that returning to the warehouse would be viewed as a route refusal, "which [would] ultimately end with you not having a job come tomorrow morning."

The conversation reportedly happened on Friday evening, around an hour and a half before a tornado hit an Amazon facility around 30 miles away from the driver. After being told twice to "just keep delivering," the driver was eventually instructed to shelter in place "for 15-20 minutes, then continue as normal." (The instructions to shelter in place were repeated several more times after.) The driver, expressing that a delivery van wouldn't provide much safety, said she wanted to return to base. ""If you decide to come back, that choice is yours.""

The dispatcher's response is harrowing: "If you decide to come back, that choice is yours. But I can tell you it won't be viewed as for your own safety. The safest practice is to stay exactly where you are." The dispatcher said drivers couldn't be recalled unless Amazon directed it and that she would lose her job if she returned. The tornado ended up touching down near a highway, throwing cars in the air, according to Bloomberg, though the driver involved in the text exchange is reported to be safe. Amazon told Bloomberg that the dispatcher "should have immediately directed the driver to seek shelter" when they reported hearing the sirens and said that "under no circumstance should the dispatcher have threatened the driver's employment." The company says it's investigating the incident.

Wireless Networking

Anti-5G Necklaces Found To Be Radioactive (bbc.com) 80

Necklaces and accessories claiming to "protect" people from 5G mobile networks have been found to be radioactive. The BBC reports: The Dutch authority for nuclear safety and radiation protection (ANVS) issued a warning about ten products it found gave off harmful ionizing radiation. It urged people not to use the products, which could cause harm with long-term wear. [...] The products identified included an "Energy Armor" sleeping mask, bracelet and necklace. A bracelet for children, branded Magnetix Wellness, was also found to be emitting radiation.

"Don't wear it any more, put it away safely and wait for the return instructions," the ANVS said in a statement. "The sellers in the Netherlands known to the ANVS have been told that the sale is prohibited and must be stopped immediately, and that they must inform their customers about this." The ANVS has published a full list of the products it identified as radioactive on its website.
Further reading: Worried About 5G's Health Effects? Don't Be
Facebook

Facebook Bans 7 'Surveillance-For-Hire' Companies That Spied On 50,000 Users (npr.org) 9

An anonymous reader quotes a report from NPR: The parent company of Facebook and Instagram has banned seven firms it says used its platforms to spy on some 50,000 unsuspecting targets, including human rights activists, government critics, celebrities, journalists and ordinary people in more than 100 countries. These "surveillance-for-hire" companies were linked to around 1,500 accounts on Facebook and Instagram that were used to collect information on people and try to trick them into handing over sensitive personal information so that the firms could install spyware on their devices, according to a report released on Thursday by Meta, formerly known as Facebook.

"Each of these actors rely on networks of fake accounts on our platforms that are used to deceive users and mislead them," Nathaniel Gleicher, Meta's head of security policy, told NPR. Some firms also used Meta's WhatsApp to infect targets' phones with malware. The surveillance was also carried out over other internet services, from email and text messages to Twitter and YouTube. The goal, Gleicher said, is to "spy on people or snoop on them without them knowing about it." Gleicher's team spent months investigating surveillance activity before taking action against the seven companies for violating Meta's community standards and terms of service. Four of the firms are based in Israel, and the other three in China, India, and North Macedonia.

They include Black Cube, an Israel-based intelligence group reportedly used by Harvey Weinstein to dig up dirt on his accusers and journalists. Meta said Black Cube created fake accounts posing as graduate students, human rights workers and film and TV producers and tried to set up phone calls and get email addresses for a wide range of targets, from Palestinian activists to people working in medicine, mining and nonprofit organizations to figures involved in Russia's tech, finance, real estate and media sectors. [...] Another Israeli firm called Bluehawk CI tried to trick government opponents in the United Arab Emirates by pretending to be reporters for Fox News and Italy's La Stampa, Meta said. Meta also took down accounts connected to "an unidentified entity in China" that, Meta says, made tools used by Chinese law enforcement to spy on minority groups in Xinjiang, Myanmar and Hong Kong.
"Meta has banned the companies from its platforms, removed the accounts it linked to them, and sent them cease-and-desist warnings," adds NPR. "It is notifying around 50,000 people whom it believes were targeted, and shared its findings with security researchers, other tech companies and policymakers."
Google

Google Drive Could Soon Start Locking Your Files (techradar.com) 76

Google has announced a new policy for cloud storage service Drive, which will soon begin to restrict access to files deemed to be in violation of the company's policies. TechRadar reports: As explained in a new blog post, Google will take active steps to identify files hosted on its platform that are in breach of either its Terms of Service or abuse program policies. These files will be flagged to their owner and restricted automatically, which means they can no longer be shared with other people, and access will be withdrawn from everyone but the owner. "This will help ensure owners of Google Drive items are fully informed about the status of their content, while also helping to ensure users are protected from abusive content," the company explained.

According to Google, the motive behind the policy change is to shield against the abuse of its services. This broad catchall encompasses cybercriminal activity (like malware hosting, phishing etc.), hate speech, and content that might endanger children, but also sexually explicit material. "We need to curb abuses that threaten our ability to provide these services, and we ask that everyone abide by [our policies] to help us achieve this goal," states Google in its policy document. "After we are notified of a potential policy violation, we may review the content and take action, including restricting access to the content, removing the content, and limiting or terminating a user's access to Google products."
Google goes on to say that it may make "exceptions based on artistic, educational, documentary or scientific considerations." As noted by TechRadar, "there is a system to request a review of a decision if someone feels a file has been restricted unfairly, but it's unclear how the process will be handled on Google's end and how long it might take."
Businesses

Adobe Stock Plummets 10%, Its Second-Worst Day In Past Decade (cnbc.com) 32

Adobe shares plummeted 10% on Thursday after the software maker issued a revenue forecast for the fiscal first quarter that fell well shy of analysts' estimates. CNBC reports: The stock suffered its second-worst drop in the past decade, surpassed only by a 15% slide in mid-March of last year, when coronavirus panic rattled the markets. Adobe's three worst days of the year have come in December, pushing the stock down 16% for the month and putting it on pace for its steepest monthly decline since June 2010. Adobe said revenue in its fiscal first quarter, which goes through Feb. 2022, will be $4.23 billion, trailing analysts' predictions for revenue of $4.34 billion, according to Refinitiv. For the full year, Adobe expects sales of $17.9 billion, which is below analysts' average estimate for revenue of $18.16 billion.

In the fourth quarter, Adobe said revenue climbed 20% to $4.11 billion, which beat estimates, led by 21% growth in the company's digital media segment. However, inflation and concerns about interest rates have led investors to put 2021 behind them and focus more on the coming year. That's drawn them out of high-growth, high-multiple stocks and into sectors that are generally viewed as more resistant to inflationary pressures and rate hikes. [...] Adobe fell $64.24 to $566.09 at the close. The stock is down 19% from its 52-week high last month.

Social Networks

Schools Across US Cancel Classes Over Unconfirmed TikTok Threats (theverge.com) 44

An anonymous reader quotes a report from The Verge: School districts across the United States are cancelling classes on Friday, December 17th due to reports of threats that are supposedly being made on TikTok. Districts in California, Texas, Minnesota, and Missouri have said they plan to close down Friday in response, according to the districts and local media reports. Elsewhere, districts have said they plan to have heightened police presence or have emailed parents to say they've been investigating the allegations. But so far, there's little evidence that the threats are credible -- or even exist. The districts and local police departments largely say they've heard about a trend referencing the possibility of shootings or bombings on December 17th, but it's not clear how many have seen a specific threat or a threat against their schools in particular.

A number of districts and law enforcement divisions say they've looked into it and don't view the threats as credible or even real. "Law enforcement agencies have investigated this threat and determined that it originated in Arizona and is not credible," Baltimore County Public Schools wrote on Twitter. "Currently, there have been no threats to any of the schools in Mexico, [Missouri]," wrote a Missouri school district. "There have been no local, credible threats," Ohio's Milford Exempted Village School District wrote to parents. In New Jersey, Governor Phil Murphy tweeted, "there are no known specific threats against New Jersey schools."

The reports of threats on TikTok may be self-perpetuating. Videos being posted to TikTok warn others that they should skip school on December 17th due to supposed threats of shootings or bombings, which seem to have prompted others to create similar videos. And now that schools are canceling classes in response to those supposed threats, a new wave of videos have popped up with additional warnings based on both the supposed claims and the actual, factual cancellations of some school classes. TikTok says it has not identified any videos making specific threats. "We have not found evidence of such threats originating or spreading via TikTok," the company wrote in a tweet Thursday afternoon. TikTok said it is working with law enforcement to look into the warnings with "utmost seriousness," nonetheless.

IT

This USB 'Kill Cord' Can Instantly Wipe Your Laptop if Snatched or Stolen (techcrunch.com) 67

An anonymous reader shares a report: Journalists, activists, and human rights defenders face a constant battle to keep files safe from a growing set of digital threats and surveillance. But physical attacks can be challenging to defend against, whether an opportunist snatch-and-grab thief or an oppressive government kicking down someone's door. This week, a project called BusKill launched a custom USB magnetic breakaway cable that acts as a "dead man's switch," locking a computer if someone physically snatches it and severs the magnetic connectors. BusKill has been in the works for more than two years as a do-it-yourself project. Anyone with the hardware could compile the source code, but it only worked on Linux and components quickly sold out. After a crowdsourcing effort, the cable is now available to buy starting at $59 and has an accompanying app that works on macOS, Windows, and Linux, allowing the person using the cable to easily arm and disarm the cable with a touch of a button.
Transportation

Boeing Wants To Build Its Next Airplane in the 'Metaverse' (reuters.com) 81

In Boeing's factory of the future, immersive 3-D engineering designs will be twinned with robots that speak to each other, while mechanics around the world will be linked by $3,500 HoloLens headsets made by Microsoft. From a report: It is a snapshot of an ambitious new Boeing strategy to unify sprawling design, production and airline services operations under a single digital ecosystem -- in as little as two years. Critics say Boeing has repeatedly made similar bold pledges on a digital revolution, with mixed results. But insiders say the overarching goals of improving quality and safety have taken on greater urgency and significance as the company tackles multiple threats.

The planemaker is entering 2022 fighting to reassert its engineering dominance after the 737 MAX crisis, while laying the foundation for a future aircraft program over the next decade -- a $15 billion gamble. It also aims to prevent future manufacturing problems like the structural flaws that have waylaid its 787 Dreamliner over the past year. "It's about strengthening engineering," Boeing's chief engineer, Greg Hyslop, told Reuters in his first interview in nearly two years. "We are talking about changing the way we work across the entire company." After years of wild market competition, the need to deliver on bulging order books has opened up a new front in Boeing's war with Europe's Airbus, this time on the factory floor.

Microsoft

Microsoft Moves More Settings Away from the Control Panel on Windows 11 (windowscentral.com) 115

An anonymous reader shares a report: Microsoft started shifting options from the Control Panel to the Settings app in Windows 8. The company has gradually moved settings away from the Control Panel since then. Quite a few options migrated over with the rollout of Windows 11, but a recent Insider build of Windows 11 moved a small handful of settings to the Settings app. Microsoft outlined the changes in the release notes of Windows 11 build 22509, which came out on December 1, 2021. The moves garnered attention from several outlets over the last week:

1. We have moved the advanced sharing settings (such as Network discovery, File and printer sharing, and public folder sharing) to a new page in Settings app under Advanced Network Settings.
2. We've made some updates to the device specific pages under Printers & Scanners in Settings to show more information about your printer or scanner directly in Settings when available.
3. Some of the entry points for network and devices settings in Control Panel will now redirect to the corresponding pages in Settings.

Music

Apple Is Rebuilding Apple Music As a Full Native App (9to5mac.com) 38

Apple is rebuilding Apple Music as a full native app with the first beta of macOS Monterey 12.2. 9to5Mac reports: Back in 2019, when Apple introduced macOS Catalina, the well-known iTunes was replaced by the Music app to better reflect the company's strategy on iOS and tvOS. However, although under a new name, the Music app on macOS retained the iTunes backend, which was basically a bunch of web content loaded into an app. While this works for most users, having web content within apps makes the experience less fluid. Luckily Apple is finally changing this with macOS Monterey 12.2 beta, which includes some big changes to the Music app backend.

As first noted by Luming Yin on Twitter, Apple Music in macOS 12.2 beta now uses AppKit -- which is macOS' native interface framework. 9to5Mac was able to confirm based on macOS code that the Music app is now using JET, which is a technology created by Apple to turn web content into native apps. Some parts of the Music app were already native, such as the music library. But now Mac users will notice that searching for new songs in Apple Music is much faster as the results pages are displayed with a native interface instead of as a webpage. Scrolling between elements has also become smoother with the beta app, and trackpad gestures are now more responsive.

Medicine

Fossil Fuel Combustion Kills More Than 1 Million People Every Year, Study Says (arstechnica.com) 151

An anonymous reader writes: Burning fossil fuels kills more than 1 million people ever year, according to a new study that examined the worldwide health effects of fine particulate pollution, also known as PM2.5. Coal, which produces sooty, particulate-laden pollution, is responsible for half of those deaths, while natural gas and oil are responsible for the other half. Some 80 percent of premature deaths due to fossil fuel combustion takes place in South Asia or East Asia, the report said. Because fine particulate pollution can be so easily inhaled and swept into the bloodstream, it is responsible for a range of diseases, including heart disease, diabetes, COPD, lung cancer, and stroke. More recently, researchers have found links between PM2.5 and other, less obvious diseases like kidney failure and Parkinson's. People who have experienced long-term exposure to PM2.5 are also at greater risk of hospitalization if they fall ill with COVID.

The researchers gathered monthly pollution and source data from 1970 to 2017 and ran it through a global air-quality model in conjunction with satellite data. The result was a global map of outdoor PM2.5 with a resolution of about 1 km^2. From there, they estimated the average outdoor exposure for people living in various parts of the world. The study was coordinated by the nonprofit Health Effects Institute, and its coauthors were Randall Martin, a professor of energy, environmental and chemical engineering at Washington University, and Michael Brauer, a professor of population and public health at the University of British Columbia. In regions like South Asia and East Asia and some Eastern and Central European countries, coal causes a majority of the premature deaths that result from fossil fuel combustion. That's due in part to those regions' reliance on coal and because their regulations are typically not as stringent as elsewhere. In regions like North America and Western Europe, which are less reliant on coal, oil and natural gas cause the majority of deaths from fossil fuel-related particulate pollution. Even in the US, a country with relatively stringent clean air laws, fine particulate pollution from fossil fuels is responsible for about 20,000 deaths annually, according to the study.

Social Networks

TikTok Is Testing a Desktop Streaming Software Called TikTok Live Studio (techcrunch.com) 13

TikTok is testing a Windows program called TikTok Live Studio that will let users watch them play video games live on TikTok. TechCrunch reports: Once downloaded to your desktop, the program allows users to log in with their TikTok account and stream directly to TikTok Live. Within the program, you can communicate with viewers through the chat feature, and you can stream content from your computer, your phone or a gaming console. TikTok told TechCrunch that this program is currently available only in a handful of Western markets for a few thousand users. [...] Live Studio isn't guaranteed to roll out, the company told TechCrunch -- whenever TikTok tests a feature, that doesn't mean it's here to stay forever. But if we do see a true launch of TikTok Live Studio, the platform will study what creators are using the software for, then tailor it to better suit those use cases. [...] This streaming software could also mark an opportunity for TikTok to reach more desktop users.
Security

Google Says NSO Pegasus Zero-Click 'Most Technically Sophisticated Exploit Ever Seen' (securityweek.com) 106

wiredmikey shares a report from SecurityWeek: Security researchers at Google's Project Zero have picked apart one of the most notorious in-the-wild iPhone exploits and found a never-before-seen hacking roadmap that included a PDF file pretending to be a GIF image with a custom-coded virtual CPU built out of boolean pixel operations. If that makes you scratch your head, that was exactly the reaction from Google's premier security research team after disassembling the so-called FORCEDENTRY iMessage zero-click exploit used to plant NSO Group's Pegasus surveillance tool on iPhones.

"We assess this to be one of the most technically sophisticated exploits we've ever seen," Google's Ian Beer and Samuel Grob wrote in a technical deep-dive into the remote code execution exploit that was captured during an in-the-wild attack on an activist in Saudi Arabia. In its breakdown, Project Zero said the exploit effectively created "a weapon against which there is no defense," noting that zero-click exploits work silently in the background and does not even require the target to click on a link or surf to a malicious website. "Short of not using a device, there is no way to prevent exploitation by a zero-click exploit," the research team said.

The researchers confirmed the initial entry point for Pegasus was Apple's proprietary iMessage that ships by default on iPhones, iPads and macOS devices. By targeting iMessage, the NSO Group hackers needed only a phone number of an AppleID username to take aim and fire eavesdropping implants. Because iMessage has native support for GIF images (especially those that loop endlessly), Project Zero's researchers found that this expanded the attack surface and ended up being abused in an exploit cocktail that targeted a security defect in Apple's CoreGraphics PDF parser. Within Apple's CoreGraphics PDF parser, the NSO exploit writers abused Apple's implementation of the open-source JBIG2, a domain specific image codec designed to compress images where pixels can only be black or white. Describing the exploit as "pretty terrifying," Google said the NSO Group hackers effectively booby-trapped a PDF file, masquerading as a GIF image, with an encoded virtual CPU to start and run the exploit.
Apple patched the exploit in September and filed a lawsuit seeking to hold NSO Group accountable.
Businesses

Reddit Files To Go Public (cnbc.com) 33

Reddit on Wednesday announced that it has confidentially submitted a draft registration statement with the Securities and Exchange Commission to go public. CNBC reports: The social media company did not make the filing publicly available. The company also did not say how many shares would be offered nor the price range for the proposed offering. Although Reddit was created in 2005, it has taken a unique road toward going public.

Conde Nast Publications acquired Reddit in 2006. The social media services remained a part of the publication company until it was made an independent subsidiary in 2011. Since then, it raised a series of funding rounds from venture capital firms. Most recently, the company announced that it had raised a $700 million round in August 2021 at a valuation of more than $10 billion.

The Internet

Comcast Will Keep Data Caps Out of the Northeast In 2022 (lightreading.com) 26

An anonymous reader quotes a report from Light Reading: Comcast confirmed that it won't activate data caps and usage-based broadband policies in its Northeast division in 2022, effectively extending an earlier delay to keep the policy out of the region through the end of 2021. There's still no telling whether Comcast will revisit the plan for 2023 and beyond. "We don't have plans to implement our data usage plan in our Northeast markets in 2022 at this time," a Comcast official told Light Reading. Word of Comcast's latest decision follows one made in February 2021 to delay the implementation of data usage and capping policies in its Northeast division until 2022.

Comcast had activated usage-based policies in its Northeast division (which includes parts of 13 states and Washington, D.C., and areas where the cable op competes with the cap-free Verizon Fios service) in early 2021. But Comcast put the policy back on ice there after catching heat from lawmakers about introducing the policy during a pandemic that had forced people to work and school from home and vastly increase their broadband data consumption. Comcast's data usage policies are still active in its Central and West divisions. Comcast restored and updated its data usage policies in July 2020, raising the monthly limit to 1.2 terabytes -- 200 gigabytes more than the 1TB limit that was in place prior to the original COVID-19 outbreak.
"Under the current plan, residential broadband customers who exceed 1.2TB of data per month are charged $10 for each additional bucket of 50GB, up to a maximum of $100 per month (Comcast's maximum data overage charge prior to the pandemic was $200)," the report notes. "Comcast also sells a standalone unlimited data option that costs an additional $30 per month."

Slashdot Top Deals