NextCry Ransomware Targets NextCloud Linux Servers and Remains Undetected Features

The ransom note that NextCry victims receive reads ““READ_FOR_DECRYPT”, and demands 0.025 BTC for a victim’s files to be unlocked.

One NextCloud user, xact64, shared his experience with the malware on a Bleeping Computer forum in an effort to find a way to decrypt personal files which had been instantaneously locked in a NextCry attack: “I realized immediately that my server got hacked and those files got encrypted. “The first thing I did was pull the server to limit the damage that was being done (only 50% of my files got encrypted).” He added, “I have my own Linux server (an old thin client I gave a second life) with NGINX reverse-proxy”.

This statement provides insight into how hackers may have been able to access his system. On October 24, NextCloud disclosed a remote code execution vulnerability (CVE-2019-11043) which has been exploited to compromise servers with the default Nextcloud NGINX configuration.

NextCloud recommends that administrators upgrade their PHP packages and NGINX configuration file to the latest version to protect against NextCry attacks.

Source: NextCry Ransomware Targets NextCloud Linux Servers and Remains Undetected Features

Bad news: ‘Unblockable’ web trackers emerge. Good news: Firefox with uBlock Origin can stop it. Chrome, not so much

Developers working on open-source ad-blocker uBlock Origin have uncovered a mechanism for tracking web browsers around the internet that defies today’s blocking techniques.

A method to block this so-called unblockable tracker has been developed by the team, though it only works in Firefox, leaving Chrome and possibly other browsers susceptible. This fix is now available to uBlock Origin users.

The tracker relies on DNS queries to get past browser defenses, so some form of domain-name look-up filtering could thwart this snooping. As far as netizens armed with just their browser and a regular old content-blocker plugin are concerned, this tracker can sneak by unnoticed. It can be potentially used by advertising and analytics networks to fingerprint netizens as they browse through the web, and silently build up profiles of their interests and keep count of pages they visit.

And, interestingly enough, it’s seemingly a result of an arms race between browser makers and ad-tech outfits as they battle over first and third-party cookies.

[…]

Many marketers, keen on maintaining their tracking and data collection capabilities, have turned to a technique called DNS delegation or DNS aliasing. It involves having a website publisher delegate a subdomain that the third-party analytics provider can use and aliasing it to an external server using a CNAME DNS record. The website and its external trackers thus seem to the browser to be coming from the same domain and are allowed to operate.

As Eulerian explains on its website, “The collection taking place under the name of the advertiser, and not under a third party, neither the ad blockers nor the browsers, interrupt the calls of tags.”

But wait, there’s more

Another marketing analytics biz, Wizaly, also advocates this technique to bypass Apple’s ITP 2.2 privacy protections.

As does Adobe, which explains on its website that one of the advantages of CNAME records for data collection is they “[allow] you to track visitors between a main landing domain and other domains in browsers that do not accept third-party cookies.”

In a conversation with The Register, Aeris said Criteo, an ad retargeting biz, appears to have deployed the technique to their customers recently, which suggests it will become more pervasive. Aeris added that DNS delegation clearly violates Europe’s GDPR, which “clearly states that ‘user-centric tracking’ requires consent, especially in the case of a third-party service usage.”

A recent statement from the Hamburg Commissioner for Data Protection and Freedom of Information in Germany notes that Google Analytics and similar services can only be used with consent.

“This exploit has been around for a long time, but is particularly useful now because if you can pretend to be a first-party cookie, then you avoid getting blocked by ad blockers, and the major browsers – Chrome, Safari, and Firefox,” said Augustine Fou, a cybersecurity and ad fraud researcher who advises companies about online marketing, in an email to The Register.

“This is an exploit, not an ‘oopsies,’ because it is a hidden and deliberate action to make a third-party cookie appear to be first-party to skirt privacy regulations and consumer choice. This is yet another example of the ‘badtech industrial complex’ protecting its river of gold.”

[…]

Two days ago, uBlock Origin developer Raymond Hill deployed a fix for Firefox users in uBlock Origin v1.24.1b0. Firefox supports an API to resolve the hostname of a DNS record, which can unmask CNAME shenanigans, thereby allowing developers to craft blocking behavior accordingly.

“uBO is now equipped to deal with third-party disguised as first-party as far as Firefox’s browser.dns allows it,” Hill wrote, adding that he assumes this can’t be fixed in Chrome at the moment because Chrome doesn’t have an equivalent DNS resolution API.

Aeris said, “For Chrome, there is no DNS API available, and so no easy way to detect this,” adding that Chrome under Manifest v3, a pending revision of Google’s extension platform, will break uBO. Hill, uBO’s creator, recently confirmed to The Register that’s still the case.

Even if Chrome were to implement a DNS resolution API, Google has made it clear it wants to maintain the ability to track people on the web and place cookies, for the sake of its ad business.

Apple’s answer to marketer angst over being denied analytic data by Safari has been to propose a privacy-preserving ad click attribution scheme that allows 64 different ad campaign identifiers – so marketers can see which worked.

Google’s alternative proposal, part of its “Privacy Sandbox” initiative, calls for an identifier field capable of storing 64 bits of data – considerably more than the integer 64.

As the Electronic Frontier Foundation has pointed out, this enables a range of numbers up to 18 quintillion, allowing advertisers to create unique IDs for every ad impression they serve, information that could then be associated with individual users.

Source: Bad news: ‘Unblockable’ web trackers emerge. Good news: Firefox with uBlock Origin can stop it. Chrome, not so much • The Register

Extraterrestrial ribose and other sugars found in primitive meteorites

Ribose is an essential sugar for present life as a building block of RNA, which could have both stored information and catalyzed reactions in primitive life on Earth. Meteorites contain a number of organic compounds including components of proteins and nucleic acids. Among the constituent molecular classes of proteins and nucleic acids (i.e., amino acids, nucleobases, phosphate, and ribose/deoxyribose), the presence of ribose and deoxyribose in space remains unclear. Here we provide evidence of extraterrestrial ribose and other bioessential sugars in primitive meteorites. Meteorites were carriers of prebiotic organic molecules to the early Earth; thus, the detection of extraterrestrial sugars in meteorites implies the possibility that extraterrestrial sugars may have contributed to forming functional biopolymers like RNA.

Source: Extraterrestrial ribose and other sugars in primitive meteorites | PNAS

1.2 Billion Records Found Exposed Online in a Single Server, contain social media profiles

In October, dark web researcher Vinny Troia found one such trove sitting exposed and easily accessible on an unsecured server, comprising 4 terabytes of personal information—about 1.2 billion records in all.

While the collection is impressive for its sheer volume, the data doesn’t include sensitive information like passwords, credit card numbers, or Social Security numbers. It does, though, contain profiles of hundreds of millions of people that include home and cell phone numbers, associated social media profiles like Facebook, Twitter, LinkedIn, and Github, work histories seemingly scraped from LinkedIn, almost 50 million unique phone numbers, and 622 million unique email addresses.

“It’s bad that someone had this whole thing wide open,” Troia says. “This is the first time I’ve seen all these social media profiles collected and merged with user profile information into a single database on this scale. From the perspective of an attacker, if the goal is to impersonate people or hijack their accounts, you have names, phone numbers, and associated account URLs. That’s a lot of information in one place to get you started.”

Source: 1.2 Billion Records Found Exposed Online in a Single Server  | WIRED

Sacha Baron Cohen gave the greatest speech on why social networks need to be kept in check, biggest propaganda machines in history

Cohen gave the speech yesterday, at an awards gala for the Anti-Defamation League (ADL), where he was the recipient of ADL’s International Leadership Award.

While accepting his award, Cohen touched on the role companies like Facebook, Google, and Twitter have played in spreading lies and hate speech online, calling the sites “the greatest propaganda machine in history.”

Cohen’s speech, in video format is embedded above. Below is a short summary of his main talking points. A full transcript, courtesy of the ADL, is embedded below the summary:

  • Cohen called Facebook, YouTube and Google, Twitter and others — the biggest propaganda machine in history.
  • He coined the term “Silicon Six” to describe the six US billionaires that control this machine — naming Zuckerberg at Facebook, Sundar Pichai at Google, Larry Page and Sergey Brin at Alphabet, Susan Wojcicki at YouTube, and Jack Dorsey at Twitter.
  • The actor ripped Zuckerberg for defending holocaust deniers.
  • He ripped Zuckerberg for his platform facilitating Russia’s interference in US elections.
  • He ripped Zuckerberg for facilitating the Myanmar genocide.
  • Said if another genocide takes place, Zuckerberg needs to go to jail.
  • Cohen ripped Facebook for allowing political ads. Said if Facebook existed in the 1930s they would have allowed Hitler to post “post 30-second ads on his ‘solution’ to the ‘Jewish problem’.”
  • Cohen likened the Christchurch massacre video to “a snuff film broadcast by social media.”
  • He said social media sites are today’s largest publishers, and should have to abide to the same standards that newspapers, radio, and TV stations abide.
  • He agreed that social media should function based on government-mandated rules, and not by internal policies set by billionaires more focused on protecting share prices than human life. He called “for regulation and legislation to curb the greed of these high-tech robber barons.”

Source: Sacha Baron Cohen gave the greatest speech on why social networks need to be kept in check | ZDNet

Monero Wallet downloads compromised for 35 minutes

Security Warning: CLI binaries available on getmonero.org may have been compromised at some point during the last 24h.
byu/binaryFate inMonero

Some users noticed the hash of the binaries they downloaded did not match the expected one: https://github.com/monero-project/monero/issues/6151
It appears the box has been indeed compromised and different CLI binaries served for 35 minutes. Downloads are now served from a safe fallback source.

Always check the integrity of the binaries you download!

If you downloaded binaries in the last 24h, and did not check the integrity of the files, do it immediately. If the hashes do not match, do NOT run what you downloaded. If you have already run them, transfer the funds out of all wallets that you opened with the (probably malicious) executables immediately, using a safe version of the Monero wallet (the one online as we speak is safe — but check the hashes).

More information will be posted as several people are currently investigating to get to the bottom of this.

Correct hashes are available here (check the signature): https://web.getmonero.org/downloads/hashes.txt

Police can keep Amazon Ring camera video forever, and share with whomever they’d like, company tells senator

More than 600 police forces across the country have entered into partnerships with the camera giant allowing them to quickly request and download video captured by Ring’s motion-detecting, internet-connected cameras inside and around Americans’ homes.

The company says the videos can be a critical tool in helping law enforcement investigate crimes such as trespassing, burglary and package theft. But some lawmakers and privacy advocates say the systems could also empower more widespread police surveillance, fuel racial profiling and spark new neighborhood fears.

In September, following a report about Ring’s police partnerships in The Washington Post, Sen. Edward Markey, D-Mass., wrote to Amazon asking for details about how it protected the privacy and civil liberties of people caught on camera. Since that report, the number of law enforcement agencies working with Ring has increased nearly 50%.

In two responses from Amazon’s vice president of public policy, Brian Huseman, the company said it placed few restrictions on how police used or shared the videos offered up by homeowners. (Amazon CEO Jeff Bezos also owns The Washington Post.)

Police in those communities can use Ring software to request up to 12 hours of video from anyone within half a square mile of a suspected crime scene, covering a 45-day time span, Huseman said. Police are required to include a case number for the crime they are investigating, but not any other details or evidence related to the crime or their request.

Markey said in a statement that Ring’s policies showed the company had failed to enact basic safeguards to protect Americans’ privacy.

“Connected doorbells are well on their way to becoming a mainstay of American households, and the lack of privacy and civil rights protections for innocent residents is nothing short of chilling,” he said.

“If you’re an adult walking your dog or a child playing on the sidewalk, you shouldn’t have to worry that Ring’s products are amassing footage of you and that law enforcement may hold that footage indefinitely or share that footage with any third parties.”

Ring, which Amazon bought last year for more than $800 million, did not immediately respond to requests for comment.

Source: Police can keep Ring camera video forever, and share with whomever they’d like, company tells senator – Stripes

Why tech companies need to hire philosophers

I have spent the better half of the last two years trying to convince companies like Google, Facebook, Microsoft, DeepMind, and OpenAI that they need to hire philosophers.

My colleagues and I—a small collective of academics that make up a program called Transformations of the Human at the Los Angeles-based think tank called the Berggruen Institute—think that the research carried out by these companies has been disrupting the very concept of the human that we—in the West particularly—have taken for granted for almost half a millennium.

It’s not only that, though. These companies have helped create realities that we can no longer navigate with the old understanding of what it means to be human.

We need new ones—for ourselves, so that we are able to navigate and regulate the new worlds we live in, but also for the engineers who create tech products, tools, and platforms, so that they can live up to the philosophical stakes of their work.

To make that possible, we need philosophers and artists working alongside computer and software engineers.

[…]

I realized that fields like AI and microbiome research or synthetic biology not only undermine the historic way we think of the human—they also allow for new possibilities for understanding the world.

It suddenly dawned on me that I could look at each one of these fields, not just AI and the microbiome, but also synthetic biology, biogeochemistry, and others, as if they were a kind of philosophical laboratory for re-articulating our reality.

[…]

We are living in an era of a major, most far-reaching philosophical event: A radical re-articulation of what it is to be human and of the relation between humans, nature, and technology.

Yet at present, no one really formally talks about this philosophical quality of tech. Hence, no one attends to it, with the inevitable consequence that the sweeping re-articulation of the human unfolds around us in a haphazard, entirely unconscientious way.

Shouldn’t we try to change this?

When I shared my enthusiasm with my colleagues in academia, I found that what was exciting to me was an unbearable provocation for many others.

My suggestion that the question concerning the human has migrated into the fields of the natural sciences and engineering—that is, into fields not concerned with the traditional study of the human and humanity at all—were received as threat to academics in the arts. If humans are no longer more than nature or machines, then what are the arts even good for?

[…]

Today, we have philosophy and art teams at Element AI, Facebook, and Google, and also at AI labs at MIT, Berkeley, and Stanford. Our researchers are in regular conversation with DeepMind, OpenAI, and Microsoft.

[…]

What we need now is a completely new model for an educational institution, one that can produce a new kind of practitioner.

We need a workforce that thinks differently, and that can understand engineering, from AI to microbiome research to synthetic biology to geoengineering and many other fields—as philosophical and artistic practices that ceaselessly re-invent the human.

Almost every month, you’ll likely read about another billion-dollar endowment for a new tech school. On the one hand, there’s nothing wrong with this—I agree we always need better, smarter, tech.

On the other hand, these tech schools tend to reproduce the old division of labor between the faculty of arts and the faculties of science and engineering. That is, they tend to understand tech as just tech and not as the philosophical and artistic field that it is.

What we need are not so much tech schools, as institutions that combine philosophy, art, and technology into one integrated curriculum.

Source: Why tech companies need to hire philosophers — Quartz

I completely agree with Mr Tobias Rees

This article is absolutely worth reading in full.