Security

Even the Dumbest Ransomware Is Almost Unremovable On Smart TVs (symantec.com) 151

An anonymous reader writes: Apparently even the easiest-to-remove ransomware is painfully hard to uninstall from smart TVs, if they're running on the Android TV platform, and many are. This didn't happen in a real-world scenario (yet), and was only a PoC test by Symantec. The researcher managed to remove the ransomware only because he enabled the Android ADB tool beforehand, knowing he would infect the TV with the ransomware. "Without this option enabled, and if I was less experienced user, I'd probably still be locked out of my smart TV, making it a large and expensive paper weight," said the researcher.
Privacy

Green Light Or No, Nest Cam Never Stops Watching (securityledger.com) 199

chicksdaddy writes: How do you know when the Nest Cam monitoring your house is "on" or "off"? It's simple: just look at the little power indicator light on the front of the device — and totally disregard what it is telling you. The truth is: the Nest Cam is never "off" despite an effort by Nest and its parent Google to make it appear otherwise. That, according to an analysis of the Nest Cam by the firm ABI Research, which found that turning the Nest Cam "off" using the associated mobile application only turns off the LED power indicator light on the front of the device. Under the hood, the camera continues to operate and, according to ABI researcher Jim Mielke, to monitor its surroundings: noting movement, sound and other activity when users are led to believe it has powered down.

Mielke reached that conclusion after analyzing Nest Cam's power consumption. Typically a shutdown or standby mode would reduce current by as much as 10 to 100 times, Mielke said. But the Google Nest Cam's power consumption was almost identical in "shutdown" mode and when fully operational, dropping from 370 milliamps (mA) to around 340mA. The slight reduction in power consumption for the Nest Cam when it was turned "off" correlates with the disabling of the LED power light, given that LEDs typically draw 10-20mA.

In a statement to The Security Ledger, Nest Labs spokesperson Zoz Cuccias acknowledged that the Nest Cam does not fully power down when the camera is turned off from the user interface (UI). "When Nest Cam is turned off from the user interface (UI), it does not fully power down, as we expect the camera to be turned on again at any point in time," Cuccias wrote in an e-mail. "With that said, when Nest Cam is turned off, it completely stops transmitting video to the cloud, meaning it no longer observes its surroundings." The privacy and security implications are serious. "This means that even when a consumer thinks that he or she is successfully turning off this camera, the device is still running, which could potentially unleash a tidal wave of privacy concerns," Mielke wrote.

Handhelds

Ask Slashdot: What Single Change Would You Make To a Tech Product? 508

An anonymous reader writes: We live in an age of sorcery. The supercomputers in our pockets are capable of doing things it took armies of humans to accomplish even a hundred years ago. But let's face it: we're also complainers at heart. For every incredible, revolutionary device we use, we can find something that's obviously wrong with it. Something we'd instantly fix if we were suddenly put in charge of design. So, what's at the top of your list? Hardware, software, or service — don't hold back.

Here's an example: over the past several years, e-readers have standardized on 6-inch screens. For all the variety that exists in smartphone and tablet sizing, the e-reader market has decided it must copy the Kindle form factor or die trying. Having used an e-reader before all this happened, I found a 7-8" e-ink screen to be an amazingly better reading experience. Oh well, I'm out of luck. It's not the worst thing in the world, but I'd fix it immediately if I could.
Security

Ransomware Expected To Hit 'Lifesaving' Medical Devices In 2016 (forrester.com) 108

An anonymous reader writes: A surge in ransomware campaigns is expected to hit the medical sector in 2016, according to a recent report published by forecasters at Forrester Research. The paper 'Predictions 2016: Cybersecuirty Swings To Prevention' suggests that the primary hacking trend of the coming year will be "ransomware for a medical device or wearable," arguing that cybercriminals would only have to make mall modifications to current malware to create a feasible attack. Pacemakers and other vital health devices would become prime targets, with attackers toying with their stability and potentially threatening the victim with their own life should the ransom demands not be met.
Hardware Hacking

Hands-On With the Voltera V-One PCB Printer (hackaday.com) 37

szczys writes: Eric Evenchick was one of the first backers of the Voltera V-One PCB Printer and just received the 6th device shipped so far. He ran it through its paces and published a review that gives it a positive rating. The hardware uses conductive ink to print traces on FR4 substrate. The board is then flipped upside down and the traces baked on the machine to make them robust. Next the printer dispenses solder paste and the same heating method is used to reflow after components are placed by hand.
Security

It's Way Too Easy To Hack the Hospital (bloomberg.com) 116

schwit1 sends along a lengthy piece from Bloomberg about the chaos currently surrounding medical device security: The Mayo Clinic had assembled an all-star team of about a dozen computer jocks, investigators from some of the biggest cybersecurity firms in the country, as well as the kind of hackers who draw crowds at conferences such as Black Hat and Def Con. The researchers split into teams, and hospital officials presented them with about 40 different medical devices. Do your worst, the researchers were instructed. Hack whatever you can.

Like the printers, copiers, and office telephones used across all industries, many medical devices today are networked, running standard operating systems and living on the Internet just as laptops and smartphones do. Like the rest of the Internet of Things—devices that range from cars to garden sprinklers—they communicate with servers, and many can be controlled remotely. As quickly became apparent to Rios and the others, hospital administrators have a lot of reasons to fear hackers. For a full week, the group spent their days looking for backdoors into magnetic resonance imaging scanners, ultrasound equipment, ventilators, electroconvulsive therapy machines, and dozens of other contraptions. The teams gathered each evening inside the hospital to trade casualty reports.

"Every day, it was like every device on the menu got crushed," Rios says. "It was all bad. Really, really bad." The teams didn't have time to dive deeply into the vulnerabilities they found, partly because they found so many—defenseless operating systems, generic passwords that couldn't be changed, and so on.

Sooner or later, hospitals would be hacked, and patients would be hurt. He'd gotten privileged glimpses into all sorts of sensitive industries, but hospitals seemed at least a decade behind the standard security curve. "Someone is going to take it to the next level. They always do," says Rios. "The second someone tries to do this, they'll be able to do it. The only barrier is the goodwill of a stranger."

Communications

Bluetooth 2016 Roadmap Brings Fourfold Range Increase and Mesh Networking (thestack.com) 29

An anonymous reader writes: The Bluetooth Special Interest Group (SIG) has announced its roadmap for Bluetooth Smart in 2016, promising a fourfold range increase in the low-energy, IoT-oriented version of the protocol, along with dedicated mesh networking, a 100% increase in speed and no extra consumption of energy. The last set of upgrades to the protocol offered direct access to the internet and security enhancements. Since Bluetooth must currently contend with attacks on everything from cars to toilets, the increased range means that developers may not be able to rely on 'fleeting contact' as a security feature quite as much.
Cellphones

Qualcomm Unveils Snapdragon 820 With Adreno 530 Graphics For Mobile Devices (hothardware.com) 34

MojoKid writes: Qualcomm held an event in New York City today to demonstrate for the first time its highly anticipated Snapdragon 820 System-on-Chip (SoC). More than just a speed bump and refresh of the Snapdragon 810, Qualcomm says it designed the Snapdragon 820 "from the ground up to be unlike anything else." Behind that marketing spin is indeed an SoC with a custom 64-bit quad-core Kyro processor clocked at up to 2.2GHz. Qualcomm says it delivers up to twice the performance and twice the power efficiency of its predecessor, which is in fact an 8-core chip. Qualcomm officials have quoted 2x the performance of their previous gen Snapdragon 810 in single threaded throughput alone, which is a sizable gain. Efficiency is also being touted here, and according to Qualcomm, the improvements it made to the underlying architecture translate into nearly a third (30 percent) less power consumption. That should help the Snapdragon 820 steer clear of overheating concerns, which is something the 810 wasn't able to do.
The Almighty Buck

Another $1 Million Crowdfunded Gadget Company Collapses (techcrunch.com) 109

An anonymous reader writes: In 2012, a company raised over a million dollars on Indiegogo to build a robotic dragonfly. It was originally supposed to be delivered in 2013. Unfortunately for backers, the company seems to be struggling to complete the project. They haven't been able to resolve issues with the drone falling apart after just a few seconds of flight. Unless they locate investors soon, they're going to run out of funds to continue work at full force. They're in the process of uploading all design work and their knowledge base, in case they have to officially cancel the project. They say some part-time work will continue as long as funds allow. The TechCrunch article warns, "This is just the latest example of how consumers need to be more careful with crowdfunding. There are no guarantees with crowdfunding and there is more risk involved than what's advertised."
Technology

Ask Slashdot: Smart Electronics For a Marathoner? 169

New submitter IMightB writes: My question is basically what is the best smart watch style device for runners. Must have features GPS, bluetooth and music storage for roughly 5 hours of use during a marathon. Pretty much everything else is a nice to have. My wife has recently decided to enter her first marathon and unfortunately, the other day during a training run her 7gen iPod Mini gave up the ghost due to moisture accumulating in the armband and her Garmin Forerunner 15 only lasts about 3 hours with GPS on (despite Manufacturer claims to the contrary). She would like to consolidate devices down to something with a watch style format and start using a bluetooth headset. I currently use, and really like, a pair of aging Jaybird JF3's for a bluetooth headset and will probably recommend to her whatever Jaybirds current equivalent is in their lineup. But the watch portion is eluding me still. Based on my current research, the Sony SmartWatch 3 may be the only one that fits my wife's 'Must have Requirements' Are there other options available? Can anyone with marathon or distance running experience share their thoughts on this subject? Thanks in Advance.
Security

How DMCA Rulemaking Has a Chilling Effect On Security Research (vice.com) 31

citadrianne writes: Jay Radcliffe is a security researcher with diabetes. In 2011, he gave a talk at Black Hat, showing how his personal insulin pump could be hacked—with potentially deadly consequences. As a result of his 2011 presentation, he worked with the Department of Homeland Security and the Food and Drug Administration to address security vulnerabilities in insulin pumps. "The specific technical details of that research have never been published in order to protect patients using those devices," he wrote in his testimony to the Librarian of Congress and the U.S. Copyright Office. Every three years, the Librarian of Congress puts a whole bunch of people through a twisted bureaucratic process called DMCA (Digital Millennium Copyright Act) rulemaking. Technically speaking, DMCA rulemaking doesn't make things illegal or legal per se, but many people—like Jay Radcliffe—look to the rulemaking for a green light to do their work.
Businesses

How GoDaddy's Quest For Respect Led To an Improbable Partnership With MIT (fastcompany.com) 38

harrymcc writes: GoDaddy, the world's biggest domain registrar, remains most famous for its tacky Super Bowl ads and controversial founder, Bob Parsons. But in recent years, the company was sold, hired a CEO from Microsoft and Yahoo, and has made a major effort to reinvent itself as a serious, uncontroversial, technologically-savvy outfit. And now it's partnered with MIT's Media Lab in an ambitious experiment--which I wrote about over at Fast Company--involving placing sensors around downtown Boston to collect big data that could help the small businesses which line the city's streets.
Emulation (Games)

Hacking Jules Coaxes Android Wear To Run Nintendo 64 and PSP Emulators (androidpolice.com) 37

Espectr0 writes: YouTube user Hacking Jules would like you to see his collection of game emulators running on Android Wear. He manages to play classic 3D Mario and Zelda games running in a Nintendo 64 emulator on the original LG G-Watch, while also running Monster Hunter on the PPSSPP emulator.As the linked article admits, this is a work of passion rather than practicality -- if you actually want to play those games enjoyably, don't trade your console or conventional emulator for a smart watch.
Google

Google Wants To Monitor Your Mental Health (telegraph.co.uk) 105

New submitter Alypius writes: Dr Tom Insel, the head of the NIH, will be joining Google Life Sciences to research how wearable technology, already used for monitoring physical activity and sleep, can be expanded to cover mental health issues such as depression. Dr. Insel will also be researching how to integrate tech to monitor other aspects of day-to-day living such as calorie and alcohol consumption.
DRM

DRM Circumvention Now Lawful For More Devices 106

BUL2294 writes: The U.S. Library of Congress' Copyright Office has published their newest rules regarding DRM circumvention. Much to the chagrin of car makers and agricultural vehicle manufacturers, DRM circumvention, with the exception of telmatics ("black box") and entertainment systems, and anything that would run afoul of DOT or EPA regulations, is now allowed for "diagnosis, repair or lawful modification of a vehicle function." In addition, jailbreaking is now extended to tablets, wearables, and smart TVs, but not to single-purpose devices like e-readers. An exemption has been carved out for security researchers to hack cars, voting machines, and medical devices — as long as that device is not being used for its purpose and is in an isolated environment. Finally, owners of abandoned video games that require server authentication (where such authentication is no longer available) may also circumvent DRM. DRM circumvention is NOT allowed for jailbreaking gaming systems and e-readers, and does not allow for "format-shifting" (e.g. moving e-books from one platform to another).

The full text of the new rules is available online (PDF), and will be published in the Federal Register on October 28, 2015.
Education

Official, Customized Raspberry Pi Versions Coming Soon (linuxgizmos.com) 93

DeviceGuru writes: The immensely popular Raspberry Pi will soon be offered in customized versions, through an exclusive arrangement between Raspberry Pi Trading and Element14. According to the companies' announcement, Element14 will provide design and manufacturing services to OEM customers to create 'bespoke designs' based upon the Raspberry Pi technology platform. That's weird U.K. English for saying that contracts for creating customized Raspberry Pi SBCs will entail substantial NRE fees and 3,000 to 5,000 unit orders, depending on the nature of the customization. The tweaked Pi's are likely to have revised board layouts, additional or alternative functions, interfaces, connectors, and memory configurations, and more. A handful of unsanctioned Raspberry Pi knock-offs have already appeared over the past couple of years, including various Orange Pi and Banana Pi flavors, which certainly didn't involve any 'bespeaking.' More info is at Element14's CustomPi page.
Security

Why IoT Security Is So Critical (techcrunch.com) 148

An anonymous reader writes: Software engineer Ben Dickson starts off an opinion piece about Internet of Things security with this amusing comment: "Twenty years ago, if you told me my phone could be used to steal the password to my email account or to take a copy of my fingerprint data, I would've laughed at you and said you watch too much James Bond. But today, if you tell me that hackers with malicious intents can use my toaster to break into my Facebook account, I will panic and quickly pull the plug from the evil appliance." Dickson then lays out many of the issues with securing internet-connected devices, and explains the work being done to make them more secure. He highlights areas that manufacturers must focus on: "In contrast to human-controlled devices, they go through a one-time authentication process, which can make them perfect sources of infiltration into company networks. Therefore, more security needs to be implemented on these gateways to improve the overall security of the system. ... There also must be a sound plan for installing security updates on IoT devices. Each consumer will likely soon own scores — if not hundreds — of connected devices. The idea of manually installing updates on so many devices is definitely out of the question, but having them automatically pushed by manufacturers also can be a risky business."
Cellphones

Hands-On With the Fairphone 2 Modular Android Smartphone (arstechnica.com) 107

An anonymous reader writes: In just a couple of months, the world's first consumer-ready modular smartphone will start shipping. It's called the Fairphone 2, and it will run Android 5.1. Ars Technica got hands-on time with the device, and they say it works surprisingly well. It's a bit thicker than most modern phones, but that's the trade-off for being able to swap out components. "The smartphone consists of seven major building blocks: the back cover, removable battery, display assembly, main chassis, receiver module, rear camera module, and speaker module. Positioned this way, the components that break most often, like the screen, are isolated for better repairability. In addition to swappable blocks, you can even change things inside the modules: for example, a mic or a speaker. They are press-fit, not glued, and can be extracted with simple tools."

Assembly and disassembly is pretty straightforward, as well: "The modules are held together by Phillips screws marked with blue circles. All screws are the same, so you won't have to remember which one goes where. It's quite hard to make a mistake in the assembling process, however Fairphone promises to release additional manuals and video instructions in collaboration with iFixit." The company also thinks it's important to get the phone's materials and components from ethical sources.

Handhelds

Is Amazon Harming the E-reader Category? (teleread.com) 200

An anonymous reader sends a story from TeleRead which argues that Amazon doing harm to the e-reader category of devices it helped create. The company has been aggressively pushing adoption of its Kindle Fire brand of tablets, dropping the price for the cheapest model down to $50. Compare that to the basic version of the e-ink Kindle: $80 if you don't want it cluttered with "special offers." If you care enough about an e-ink screen, you might still buy it, but most of those people probably already have e-readers. The general populace, when looking at the tablet's color screen, app ecosystem, and access to forms of entertainment beyond books, will probably consider the tablet a no-brainer.

This is in Amazon's best interest; if you buy an e-reader, you're only going to be buying books for it. If you buy a tablet, they can sell you videos and software, too. Amazon has succeeded in pushing several competing e-readers out of the market. They also refuse to experiment or innovate on the design; there have been no significant changes since the Paperwhite's backlighting technology in 2012. Given that ebook sales are no longer growing explosively, this could be a sign that the e-reader category of devices is stagnating.
Networking

Jamming Wi-Fi With a $15 Dongle 136

An anonymous reader writes with this report about just how easy it is to disrupt if not entirely kill modern consumer-grade networks -- not just Wi-Fi, but Bluetooth and Zigbee networks, too. Crucial to determining the likelihood of any given kind of attack, though, is how much it would cost the attacker to attempt. The bad news for network owners and users is that it doesn't cost much at all: "According to Mathy Vanhoef, a PhD student at KU Leuven (Belgium), it can easily be done by using a Wi-Fi $15 dongle bought off Amazon, a Raspberry Pi board, and an amplifier that will broaden the range of the attack to some 120 meters."

Slashdot Top Deals