×
Security

Researchers Discover SplitSpectre, a New Spectre-like CPU Attack (zdnet.com) 48

An anonymous reader writes from a report via ZDNet: Three academics from Northeastern University and three researchers from IBM Research have discovered a new variation of the Spectre CPU vulnerability that can be exploited via browser-based code. The vulnerability, which researchers codenamed SplitSpectre, is a variation of the original Spectre v1 vulnerability discovered last year and which became public in January 2018. The difference in SplitSpectre is not in what parts of a CPU's microarchitecture the flaw targets, but how the attack is carried out. Researchers say a SplitSpectre attack is both faster and easier to execute, improving an attacker's ability to recover code from targeted CPUs. The research team says they were successfully able to carry out a SplitSpectre attack against Intel Haswell and Skylake CPUs, and AMD Ryzen processors, via SpiderMonkey 52.7.4, Firefox's JavaScript engine. The good news is that existing Spectre mitigations would thwart the SplitSpectre attacks.
Japan

Japan's Final Pager Provider To End Its Service In 2019 (bbc.com) 45

Tokyo Telemessage, Japan's last pager provider, has announced that it will end service to its 1,500 remaining users in September 2019. It will bring a national end to telecommunication beepers, 50 years after their introduction. The BBC reports: The once-popular devices are able to receive and show wireless messages. Users would then find a phone to call the sender back. Developed in the 1950s and 1960s, they grew in popularity in the 1980s. By 1996, Tokyo Telemessage had 1.2 million subscribers. However, the rise of mobile phones rendered the pager obsolete, and few remain worldwide. Emergency services, however, continue to use the reliable technology -- including in the UK.
Intel

Intel Sues Ex-Engineer For Trying To Steal 3D XPoint Technology On His Way To Micron (theregister.co.uk) 33

Intel has filed a lawsuit last week against one of their former hardware engineers, alleging they tried to steal confidential chip blueprints to potentially pass on to Micron. "The lawsuit [...] is the latest twist in the tale of Intel and Micron's difficult partnership over 3D XPoint memory," reports The Register. From the report: The legal complaint, aimed at former employee Doyle Rivers, alleges that having "secretly" accepted a position at Chipzilla's former bedfellow, Micron, Rivers had a go at taking confidential trade and personnel data with him as he left. Intel alleged that a few days before leaving, "Rivers tried to access and copy a 'top secret' designated Intel file that Intel's electronic security system blocked from being copied."

Chipzilla said the document was related to what it was at pains to say is its "independent" work to productize the 3D XPoint tech into its Optane product line. In other words, blueprints secret to Intel. No one outside Intel, "including Micron" had been privy to such data, the complaint alleged. Intel's security system stopped the file from escaping, but according to the complaint, that did not stop Rivers from allegedly hoovering up a selection of personnel files into a USB device plugged into his computer. The chipmaker also claimed that Rivers "aggressively" recruited his former colleagues to join him on his grand adventure to pastures new.
Intel demanded that Rivers return the USB drive, but he apparently "never responded" to them. Instead, "he handed the USB device over to his new employer." It was later discovered by a forensic investigator that it had been wiped. Intel is now demanding "a neutral forensic investigator" be allowed to take a look at Rivers' PC to see what was on there, and when exactly the USB stick was erased. There's a deadline of November 16 for Rivers to agree to this probing.
Australia

Australian Fence of Sound Halves Roadkill On One Deadly Stretch of Road (digitaltrends.com) 47

Researchers in the Australian state of Tasmania are using a "virtual fence" system, consisting of alarm units mounted on posts along the side of a three-mile stretch of road, to reduce the number animals that get struck and killed by cars on a particularly deadly stretch of road. "These alarm units, around 80 feet apart, emit sounds and flashing lights to warn animals when a car is approaching," reports Digital Trends. "These do not distract drivers because the sound and light are directed to the edge of the road. They are also only loud and bright enough to be noticeable to wildlife in the immediate vicinity." From the report: "The virtual fence technology involves small devices, approximately the size of a mobile phone, mounted on a pole on the side of the road which are triggered by car headlights when they hit a sensor in the device," Samantha Fox, the researcher who led the project, told Digital Trends. "This sets off blue and yellow flashing lights and a high pitched siren. These together warn local wildlife that a car is coming, and give the animal time to move away from the road." Over the course of a three-year trial, the technology has reduced roadkill on one particular road by a massive 50 percent. On this stretch of road alone, this has meant saving the lives of around 200 animals, ranging from wombats to possums.
Medicine

Researchers Develop Hydrogel-Based Electrodes For Brain Implants (phys.org) 32

An anonymous reader quotes a report from Phys.Org: Hydrogels are physical and chemical polymer networks capable of retaining large quantities of liquid in aqueous conditions without losing their dimensional stability. They are used in a whole host of applications, and in combination with other components and they acquire specific properties such as electrical conductivity. The Materials + Technology research group in the Department of Chemical Engineering and Environment of the UPV/EHU's Faculty of Engineering selected a biopolymer that had not previously been used for applications of this type: starch. They created the hydrogel for use in neural interfaces. "Due to the fact that electrodes of neural interfaces made of platinum or gold are rigid, they require conductive polymer coatings to bring their flexibility closer to that of neural tissue. Right now, however, smaller devices are required that offer better mechanical, electrical and biological properties," explained the researcher.

The hydrogels "address these demands very well." To provide the hydrogel with electrical conductivity, they used graphene. "It provides electrical properties that are highly suited to the hydrogel, but this also has a drawback: It is not easily stabilized in water. We used extracts of salvia to overcome this obstacle and to render the graphene stable in an aqueous medium. These extracts also make the hydrogel even more suitable, if that is possible, for use in medicine as it also has antimicrobial and anti-inflammatory properties." The researchers used "click chemistry" to produce the hydrogel. "Unlike other means of synthesis, click chemistry does not tend to use catalysts in the reactions; in addition, no by-products are generated and they are high-performance reactions."

Businesses

Lowe's To Sell Off Its 'Under-Performing' Iris Smart Home Automation Business (cepro.com) 119

CIStud shares a report from CE Pro: Giant home improvement retailer Lowe's is giving up on the smart home market. The company announced its "difficult decision" to exit the home automation market and is seeking a buyer for its Iris Smart Home business as part of a "strategic reassessment." The announcement is part of multiple other maneuvers by Lowe's that include closing its Orchard Supply Hardware business, dumping its Alacrity Renovation Service, shutting down all its locations in Mexico, and shutting more than 50 locations in the U.S. and Canada. Lowe's Iris was hailed as the only entry-level home automation system that handled ZigBee, Z-Wave and Wi-Fi when it came out in 2012. Speaking to investors, president and CEO Marvin Ellison [lumped Lowe's Iris in with other initiatives as an] "underperforming... non-core business."
Iphone

Trump Suggests US Could Slap 10 Percent Tax On iPhones, Laptops From China (cnbc.com) 387

An anonymous reader quotes a report from CNBC: President Donald Trump suggested he could place a 10 percent tariff on iPhones and laptops imported from China, in an interview with the Wall Street Journal published Monday. He also said it's "highly unlikely" that he would delay an increase in tariffs from 10 percent to 25 percent on Jan. 1, just four days before a summit with Chinese President Xi Jinping. "Maybe. Maybe. Depends on what the rate is," the president said to The Wall Street Journal about the possible iPhone and laptop tariffs. "I mean, I can make it 10 percent, and people could stand that very easily."
Software

Paralyzed Individuals Operate Tablet With Brain Implant (ieee.org) 61

Last year, a study from the BrainGate consortium reported that a brain-computer interface (BCI) enabled a paralyzed man to type up to eight words per minute via thoughts alone. Now, according to new results from a BrainGate2 clinical trial, the same BCI was used to help three participants operate an off-the-shelf tablet. IEEE Spectrum reports: All three participants suffer from weakness or loss of movement in their arms due to amyotrophic lateral sclerosis (ALS, also called Lou Gehrig's disease) or spinal cord injury. Each received the brain implant, an array of microelectrodes, as part of the BrainGate2 clinical trial. For this particular study, decoded neural signals from the implant were routed through an industry-standard Human Interface Device protocol, providing a virtual mouse. That "mouse" was paired to a Google Nexus 9 tablet via Bluetooth.

Each participant was asked to try out seven common apps on the tablet: email, chat, web browser, video sharing, music streaming, a weather program and a news aggregator. The researchers also asked the users if they wanted any additional apps, and subsequently added the keyboard app, grocery shopping on Amazon, and a calculator. The participants made up to 22 point-and-click selections per minute and typed up to 30 characters per minute in email and text programs. What's more, all three participants really enjoyed using the tablet.

Medicine

Human Images From World's First Total-Body Scanner Unveiled (medicalxpress.com) 54

An anonymous reader quotes a report from Medical Xpress: EXPLORER, the world's first medical imaging scanner that can capture a 3-D picture of the whole human body at once, has produced its first scans. The brainchild of UC Davis scientists Simon Cherry and Ramsey Badawi, EXPLORER is a combined positron emission tomography (PET) and X-ray computed tomography (CT) scanner that can image the entire body at the same time. Because the machine captures radiation far more efficiently than other scanners, EXPLORER can produce an image in as little as one second and, over time, produce movies that can track specially tagged drugs as they move around the entire body.

EXPLORER will have a profound impact on clinical research and patient care because it produces higher-quality diagnostic PET scans than have ever been possible. EXPLORER also scans up to 40 times faster than current PET scans and can produce a diagnostic scan of the whole body in as little as 20-30 seconds. Alternatively, EXPLORER can scan with a radiation dose up to 40 times less than a current PET scan, opening new avenues of research and making it feasible to conduct many repeated studies in an individual, or dramatically reduce the dose in pediatric studies, where controlling cumulative radiation dose is particularly important.

Iphone

Apple's Siri May Soon Process Voice Locally On a Device, No Cloud Required (appleinsider.com) 83

Proudrooster writes: "Apple wants Siri to become more useful to users when not connected to the internet, including the possibility of an offline mode that does not rely on a backend server to assist with voice recognition or performing the required task, one that would be entirely performed on the user's device," reports Apple Insider. Just give it 10 years and everything old is new again. Siri will join the ranks of Ford/Microsoft Sync and Intel Edison. Do any other phones/cars/speakers have this option right now? The new capabilities are outlined in a recently-published patent application that describes an "Offline personal assistant."

"Rather than connected to Apple's servers, the filing suggests the speech-to-text processing and validation could happen on the device itself," reports Apple Insider. "On hearing the user make a request, the device in question will be capable of determining the task via onboard natural language processing, working out if the requested task as it hears it is useful, then performing it. "
Android

Mid-Range Google 'Pixel 3 Lite' Leaks With Snapdragon 670, Headphone Jack (9to5google.com) 94

The first alleged images of the rumored "budget" Pixel 3 have been leaked. The Pixel 3 Lite, as it is being called, looks very similar to the Pixel 3, although it features a plastic build construction, slower processor, and a headphone jack. 9to5Google reports: Just like the standard Pixel 3, there's a display that's roughly 5.56-inches in size, but this time it's an IPS LCD panel at 2220x1080 rather than an OLED panel. Obviously, there's also no notch to be seen on this alleged Pixel 3 Lite. There's a single front-facing camera as well as one speaker above that display, relatively thick bezels on the top and bottom, and a speaker along the bottom of the device as well.

Perhaps most interesting when it comes to the hardware, though, is that there's a headphone jack on the top of the phone. That's certainly unexpected since the Pixel 2 dropped the jack and Google hasn't looked back since. Tests from Rozetked reveal some of the specifications running this device as well. That includes a Snapdragon 670 chipset, 4GB of RAM, and 32GB of storage. Previous reports have pointed to a Snapdragon 710. Battery capacity on this device is also reported at 2915 mAh and there's a USB-C port along the bottom.
It is rumored to include the same 12MP and 8MP cameras found in the standard Pixel 3 and Pixel 3 XL, which will be a huge selling point for the affordable phone market. The price is expected to be around $400-500.
Security

MiSafes' Child-Tracking Smartwatches Are 'Easy To Hack' (bbc.com) 29

The location-tracking "MiSafe" smartwatch may not be as safe as the name proclaims. According to security researchers from Pen Test Partners, the watches are easy to hack as they do not encrypt the data they use or secure each child's account. The researchers found that they could track children's movements, surreptitiously listen in to their activities and make spoof calls to the watches that appeared to be from parents. The BBC reports: The MiSafes watch was first released in 2015. It uses a global positioning system (GPS) sensor and a 2G mobile data connection to let parents see where their child is, via a smartphone app. In addition, parents can create a "safe zone" and receive an alert if the child leaves the area. The adult can also listen in to what their offspring is doing at any time and trigger two-way calls.

Pen Test Partner's Ken Munro and Alan Monie learned of the product's existence when a friend bought one for his son earlier this year. Out of curiosity, they probed its security measures and found that easy-to-find PC software could be used to mimic the app's communications. This software could be used to change the assigned ID number, which was all it took to get access to others' accounts. This made it possible to see personal information used to register the product, including: a photo of the child; their name, gender and date of birth; their height and weight; the parents' phone numbers; and the phone number assigned to the watch's Sim card.

Encryption

Safari Tests 'Not Secure' Warning For Unencrypted Websites (cnet.com) 66

Similar to Chrome, Apple's Safari browser is testing a warning system for when users visit websites that aren't protected by HTTPS encryption. "The feature for now is only in Safari Technology Preview 70, a version of the web browser Apple uses to test technology it typically brings to the ordinary version of Safari," reports CNET. From the report: Apple didn't immediately respond to a request for comment on its plans for bringing the warning to mainstream Safari. Apple's browser does warn you already if you have an insecure connection to a very sensitive website for typing in passwords or credit card numbers.
Desktops (Apple)

Apple Confirms Its T2 Security Chip Blocks Some Third-Party Repairs of New Macs (theverge.com) 179

An anonymous reader shares a report from The Verge about Apple's new security-focused T2 chip found in the newest Mac computers. The introduction of the chip "has renewed concerns that Apple is trying to further lock down its devices from third-party repair services," The Verge reports. From the report: The T2 is "a guillotine that [Apple is] holding over" product owners, iFixit CEO Kyle Wiens told The Verge over email. That's because it's the key to locking down Mac products by only allowing select replacement parts into the machine when they've come from an authorized source -- a process that the T2 chip now checks for during post-repair reboot. "It's very possible the goal is to exert more control over who can perform repairs by limiting access to parts," Wiens said. "This could be an attempt to grab more market share from the independent repair providers. Or it could be a threat to keep their authorized network in line. We just don't know." Apple confirmed to The Verge that this is the case for repairs involving certain components on newer Macs, like the logic board and Touch ID sensor, which is the first time the company has publicly acknowledged the tool's use. But Apple could not provide a list of repairs that required this or what devices were affected. It also couldn't say whether it began this protocol with the iMac Pro's introduction last year or if it's a new policy instituted recently.

First revealed last month by MacRumors and Motherboard, both of which got their hands on an internal Apple document, the T2 chip could render a computer inoperable if, say, the logic board is replaced, unless the chip recognizes a special piece of diagnostic software has been run. That means if you wanted to repair certain key parts of your MacBook, iMac, or Mac mini, you would need to go to an official Apple Store or a repair shop that's part of the company's Authorized Service Provider (ASP) network. If you want to repair or rebuild portions of those devices on your own, you simply can't -- at least, according to this document. The parts affected, according to the document, are the display assembly, logic board, top case, and Touch ID board for the MacBook Pro, and the logic board and flash storage on the iMac Pro. It is also likely that logic board repairs on the new MacBook Air and Mac mini are affected, as well as the Mac mini's flash storage. Yet, the document, which is believed to have been distributed earlier this year, does not mention those products because they were unannounced at the time. Regardless, to replace those parts, a technician would need to run what's known as the AST 2 System Configuration suite, which Apple only distributes to Apple Stores and certified ASPs. So DIY shops and those out of the Apple network would be out of luck.

Data Storage

Mac Mini Teardown Reveals User-Upgradable RAM, But Soldered Down CPU and Storage (macrumors.com) 242

iFixit has released their teardown of the new Mac mini, providing a look inside the portable desktop computer. Some of the notable findings include user-upgradable RAM and soldered CPU and SSD. Mac Rumors reports: While the RAM in the previous-gen Mac mini from 2014 was soldered to the logic board, the new Mac mini has user-upgradeable RAM, as discovered earlier this week. As seen in older iMacs, the RAM is protected by a perforated shield that allows the memory modules to operate at a high frequency of 2666 MHz without interfering with other device functions, according to iFixit. To upgrade the RAM, the shield can be removed by unfastening four Torx screws.

Other silicon on the logic board of this particular Mac mini includes the Apple T2 security chip, a 3.6GHz quad-core Intel Core i3 processor, Intel UHD Graphics 630, 128GB of flash storage from Toshiba, an Intel JHL7540 Thunderbolt 3 controller, and a Gigabit Ethernet controller from Broadcom. Despite the good news about the RAM, the CPU and SSD are soldered to the logic board, as are many ports, so this isn't a truly modular Mac mini. iFixit awarded the new Mac mini a repairability score of 6/10, with 10 being the easiest to repair, topping the latest MacBook Air, MacBook, MacBook Pro, iMac, and iMac Pro, and trailing only the 2013 Mac Pro.

Data Storage

Micron Kicks Off Mass Production of 12Gb DRAM Chips (anandtech.com) 52

Micron is now producing its first LPDDR4X memory devices using its second-generation 10nm-class process technology. "The new memory devices offer standard LPDDR4X data transfer rates of up to 4.266 Gbps per pin and consumes less power than earlier LPDDR4 chips," reports AnandTech. From the report: Micron's LPDDR4X devices are made using the company's 1Y-nm fabrication tech and feature a 12 Gb capacity. The manufacturer says that its LPDDR4X memory chips consume 10% less power when compared to its LPDDR4-4266 products; this is because they feature a lower output driver voltage (I/O VDDQ), which the LPDDR4X standard reduces by 45%, from 1.1 V to 0.6 V. Micron's 12 Gb (1.5 GB) LPDDR4X devices feature a slightly lower capacity than competing 16 Gb (2 GB) LPDDR4X offerings, but they are also cheaper to manufacture. As a result, Micron can offer lower-cost quad-die 64-bit LPDDR4X-4266 packages with a 48 Gb (6 GB) capacity and a 34.1 GB/s bandwidth than some of its competitors.
Android

Samsung Will Put Notches On Its Future Phones (theverge.com) 125

Samsung is one of the biggest smartphone makers to hold off on releasing smartphones with display notches. But at the company's developer conference today, Samsung confirmed that it's soon going to join in on the trend. "A slide during the keynote showed several notch designs that are almost certainly coming to Samsung-branded devices in 2019 and beyond," reports The Verge. From the report: Hassan Anjum, a director of product marketing at Samsung, took the stage to highlight Samsung's previous breakthroughs in reducing bezels and maximizing display size year after year. "We're going to keep going. The bezels are going to shrink even further," Anjum said. "We're going to push the limits with our new lineup: the Infinity U, V, and O displays. These are new concepts that are just around the corner, and I can't wait to tell you more about them."

Infinity U: This basically looks identical to the Essential Phone's notch design. It's a small half oval that cuts down into the top middle of the display.
Infinity V: Similar to Infinity U, but with four edges instead of a curved half-oval.
Infinity O: This is a full circular cutout of the display and not so much a "notch" the top edge of the screen. Still, it seems like an eyesore and it's hard to imagine reaction to this being very positive. What's gained by that little area of display above it? Asus seems to be exploring a similar idea for its ZenFone 6, and feedback has been overwhelmingly bad.
New Infinity: This looks to be a completely notchless display. Anjum didn't discuss this one onstage, and the technology isn't quite there to allow for this design just yet. That said, Samsung could be exploring the idea of a slider phone that would house the selfie camera and other components somewhere outside their usual location.

Microsoft

Microsoft's Cortana Boss Javier Soltero Is Leaving the Company 31

Corporate Vice President of Cortana Javier Soltero is leaving the company after being in charge of Cortana for less than a year. "Soltero joined Microsoft when it bought at the end of 2014 Acompli, a mobile mail startup in San Francisco which he co-founded and led," reports ZDNet. "After joining Microsoft four years ago, Soltero spearheaded Outlook Mobile, then all of Outlook." Before being appointed to run Cortana in March of this year, he was the head of strategy for Office. From the report: Last month, Microsoft officials confirmed that Cortana was one of the technologies that management was moving from AI + Research to the Experiences & Devices team, which is under Executive Vice President Rajesh Jha. Microsoft is in the midst of trying to reposition Cortana from a standalone digital assistant to more of an assistance aide. Given the strong focus on home and work productivity by the Microsoft 365 and Office teams, officials seemingly decided it made sense for Cortana to be situated in that group.

I've heard Soltero is going to go back to doing entrepreneurial activities once he leaves by year-end. Perry Clarke is going to be working with Soltero on transition plans in the next couple of months, sources are telling me. Clarke has been with Microsoft engineering since 1996, when he led Exchange. He also has been a Microsoft Distinguished Engineer for the past several years. I've heard talk that Microsoft ultimately is looking to bring Cortana and Search together into a single engineering team.
Electronic Frontier Foundation

EFF Unveils VR Tool To Help People Spot Surveillance Devices In Their Communities (eff.org) 24

An anonymous reader quotes a report from the Electronic Frontier Foundation: The Electronic Frontier Foundation (EFF) launched a virtual reality (VR) experience on its website today that teaches people how to spot and understand the surveillance technologies police are increasingly using to spy on communities. Spot the Surveillance, which works best with a VR headset but will also work on standard browsers, places users in a 360-degree street scene in San Francisco. In the scene, a young resident is in an encounter with police. Users are challenged to identify surveillance tools by looking around the scene. The experience takes approximately 10 minutes to complete. The surveillance technologies featured in the scene include a body-worn camera, automated license plate readers, a drone, a mobile biometric device, and pan-tilt-zoom cameras. The project draws from years of research gathered by EFF in its Street-Level Surveillance project, which shines a light on how police use, and abuse, technology to spy on communities.
Hardware

SpiNNaker Powers Up World's Largest Supercomputer That Emulates a Human Brain 164

The world's largest neuromorphic supercomputer, the Spiking Neural Network Architecture (SpiNNaker), was just switched on for the first time yesterday, boasting one million processor cores and the ability to perform 200 trillion actions per second. HotHardware reports: SpiNNaker has been twenty years and nearly $19.5 million in the making. The project was originally supported by the Engineering and Physical Sciences Research Council (EPSRC), but has been most recently funded by the European Human Brain Project. The supercomputer was designed and built by the University of Manchester's School of Computer Science. Construction began in 2006 and the supercomputer was finally turned on yesterday.

SpiNNaker is not the first supercomputer to incorporate one million processor cores, but it is still incredibly unique since it is designed to mimic the human brain. Most computers send information from one point to another through a standard network. SpiNNaker sends small bits of information to thousands of points, similar to how the neurons pass chemicals and electrical signals through the brain. SpiNNaker uses electronic circuits to imitate neurons. SpiNNaker has so far been used to mimic the processing of more isolated brain networks like the cortex. It has also been used to control SpOmnibot, a robot that processes visual information and navigates towards its targets.

Slashdot Top Deals