The Linkielist

Linking ideas with the world

The Linkielist

Google side with Hedge funds, wipes Play Store reviews of RobinHood by pissed off GameStop traders

Google has removed a wave of negative reviews of popular stock-market trading apps targeted by furious investors.

Platforms such as Robinhood have been hit after preventing independent traders buying GameStop and AMC shares.

Users of a Reddit message board had managed to upset the market by buying the shares and inflating their value, hitting established hedge funds.

Many online traders, feeling betrayed by Robinhood’s restrictions, have hit back with critical reviews of the app.

Google has removed tens of thousands of one-star reviews for the widely-used trading app – which had previously had a four-star average.

It says it takes action when it sees “fake ratings”, designed to manipulate a product’s average score.

But more one-star ratings – the minimum possible – have continued to appear.

While Robinhood stopped independent users from buying some shares after the surge in investment by independent traders, they still remained available to large, professional traders elsewhere- leading to accusations that Robinhood was effectively protecting big investors and manipulating the stock market.

Robinhood said that the restrictions were put in place for “risk-management” reasons – and not because it had been told to limit activity by anyone else.

But as first reported by 9to5Google, it prompted a co-ordinated campaign to hit the app with a barrage of one-star reviews.

The site reported that more than 100,000 negative reviews had brought the average rating from four stars down to just one.

Hours later, Google intervened to delete roughly 100,000 reviews, according to the review counter, restoring the app’s high rating.

A selection of three one-star reviews pulled from the Google Play Storeimage copyrightGoogle Play

Google rules are designed to prevent so-called “review bombing” – when reviewers co-ordinate to drag down an app’s rating, usually because of some external scandal or political disagreement.

It has not yet responded to requests to comment on its Play Store decision.

‘Unacceptable’

While there had been calls on social media to review Robinhood negatively, many investors feel they have a legitimate grievance.

Some users of the Reddit WallStreetBets community, which is at the centre of the movement, believe they are taking a principled stance against hedge funds short-selling the stocks, hoping the company will fail.

The concern is also reflected by some major US politicians from both parties.

The BBC is not responsible for the content of external sites.View original tweet on Twitter

Democrat congresswoman Alexandria Ocasio-Cortez has said Congress should investigate Robinhood, calling the app’s decision to block small traders “unacceptable”.

Her long-time political enemy, Republican Ted Cruz, tweeted that he fully agreed, as did entrepreneur Elon Musk.

Within hours, Senator Sherrod Brown – who runs the Senate Banking Committee – said he planned to hold a hearing on the current state of the US stock market.

“People on Wall Street only care about the rules when they’re the ones getting hurt,” he said.

Source: Google halts Play Store ‘review bombing’ by GameStop traders – BBC News

Let’s be clear – these guys have a very legitimate grievance with RobinHood.

ProtonMail, Tutanota among authors of letter urging EU to reconsider encryption rules

Encrypted service providers are urging lawmakers to back away from a controversial plan that critics say would undercut effective data protection measures.

ProtonMail, Threema, Tresorit and Tutanota — all European companies that offer some form of encrypted services — issued a joint statement this week declaring that a resolution the European Council adopted on Dec. 14 is ill-advised. That measure calls for “security through encryption and security despite encryption,” which technologists have interpreted as a threat to end-to-end encryption. In recent months governments around the world, including the U.S., U.K., Australia, New Zealand, Canada, India and Japan, have been reigniting conversations about law enforcement officials’ interest in bypassing encryption, as they have sporadically done for years.

In a letter that will be sent to council members on Thursday, the authors write that the council’s stated goal of endorsing encryption, and the council’s argument that law enforcement authorities must rely on accessing electronic evidence “despite encryption,” contradict one another. The advancement of legislation that forces technology companies to guarantee police investigators a way to intercept user messages, for instance, repeatedly has been scrutinized by technology leaders who argue there is no way to stop such a tool from being abused.

The resolution “will threaten the basic rights of millions of Europeans and undermine a global shift towards adopting end-to-end encryption,” say the companies, which offer users either encrypted email, file-sharing or messaging.

“[E]ncryption is an absolute, data is either encrypted or it isn’t, users have privacy or they don’t,” the letter, which was shared with CyberScoop in advance, states. “The desire to give law enforcement more tools to fight crime is obviously understandable. But the proposals are the digital equivalent of giving law enforcement a key to every citizens’ home and might begin a slippery slope towards greater violations of personal privacy.”

[…]

Source: ProtonMail, Tutanota among authors of letter urging EU to reconsider encryption rules

Robinhood, TD Ameritrade restrict buying of GameStop, AMC stock – shorters continue game, killing pumpers. Reps + Dems agree market manipulation. The shorters are big customers and are reloading their short positions.

GameStop’s stock has continued to make big moves, briefly crossing $450 a share on Thursday, fueled by Reddit users collectively taking on the Wall Street establishment. But individual investors looking to make trades have faced multiple issues on trading sites and apps over recent days, with many experiencing service disruptions, according to Bloomberg. The frenzy over GameStop stock has led to TD Ameritrade restricting certain trades, while Robinhood froze any new purchases of particular stocks (GameStop and AMC, among others). It also led to the Wall Street Bets subreddit temporarily getting locked and a Discord server getting shut down for violating terms of service. Watch this: What does GameStop’s skyrocketing stock have to do with…10:15On Thursday morning, Twitter users began posting screenshots of their Robinhood app that showed a message appended to the stocks of GameStop, AMC, Nokia and Bed, Bath and Beyond: “This stock is not supported on Robinhood.”Editors’ top picksSubscribe to CNET Now for the day’s most interesting reviews, news stories and videos.Yes, I also want to receive the CNET Insider newsletter, keeping me up to date with all things CNET.By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.Robinhood explained the move in a blog post Thursday morning, just before the stock exchanges opened: “In light of recent volatility, we are restricting transactions for certain securities to position closing only, including $AMC, $BB, $BBBY, $EXPR, $GME, $KOSS, $NAKD and $NOK.”The @wsbmod Twitter account (which is tied to the Wall Street Bets subreddit community driving recent trades), responded in a tweet: “Individual investors are being stripped of their ability to trade on [the Robinhood app]. Meanwhile, hedge funds and institutional investors can continue to trade as normal.”

Source: Robinhood, TD Ameritrade restrict trading of GameStop, AMC stock – CNET

Here comes the slander: Discord Bans r/WallStreetBets For Hate Speech Violations

After kicking off a historic rally around GameStop stock that has incited the ire of hedge fund tycoons and the SEC, the r/wallstreetbets channel was banned from Discord on Wednesday over apparent hate speech violations.

While some on Reddit were quick to speculate that the server had been taken down by hackers as part of a covert attempt to disrupt their push to drive the stock’s price higher, a Discord spokesperson told Gizmodo that the channel had been banned “for continuing to allow hateful and discriminatory content after repeated warnings.” On both Discord and Reddit, wallstreetbets users frequently refer to themselves collectively as “retards” and “autists,” and have been known to deploy the kinds of racial slurs and deliberately offensive language that have become commonplace in 4chan-style posting forums.

This is slightly disengenious at the very least. Just saying “shit” somewhere puts you in this category.

Here’s the full statement from Discord:

The server has been on our Trust & Safety team’s radar for some time due to occasional content that violates our Community Guidelines, including hate speech, glorifying violence, and spreading misinformation. Over the past few months, we have issued multiple warnings to the server admin.

Today, we decided to remove the server and its owner from Discord for continuing to allow hateful and discriminatory content after repeated warnings.

To be clear, we did not ban this server due to financial fraud related to GameStop or other stocks. Discord welcomes a broad variety of personal finance discussions, from investment clubs and day traders to college students and professional financial advisors. We are monitoring this situation and in the event there are allegations of illegal activities, we will cooperate with authorities as appropriate.

Moments after confirmation of the Discord ban surfaced online, the official r/wallstreetbets subreddit was set to private by its moderators, but has since been made public again. In a new post, moderators for r/wallstreetbets argued that the staggering growth of the community in just a few days’ time had made moderating it effectively impossible, and blamed Discord and Reddit’s software for any shortcomings in cracking down on offensive language.

Source: Discord Bans r/WallStreetBets For Hate Speech Violations

Note there is no statement from anyone from wallstreetbets. I recommend you read the  reddit yourself.

Very poor reporting, Gizmodo.

Solar material can ‘self-heal’ imperfections, new research shows

A material that can be used in technologies such as solar power has been found to self-heal, a new study shows.The findings—from the University of York—raise the prospect that it may be possible to engineer high-performance self-healing materials which could reduce costs and improve scalability, researchers say.The substance, called antimony selenide (Sb2Se3), is a solar absorber material that can be used for turning light energy into electricity.Professor Keith McKenna from the Department of Physics said: “The process by which this semi-conducting material self-heals is rather like how a salamander is able to re-grow limbs when one is severed. Antimony selenide repairs broken bonds created when it is cleaved by forming new ones.

Source: Solar material can ‘self-heal’ imperfections, new research shows

Firefox 85 removes support for Flash and adds protection against supercookies

Mozilla has released Firefox 85 ending support for Adobe Flash Player plugin and has brought in ways to block supercookies to enhance a user’s privacy. Mozilla, in a blog post, noted that supercookies are store user identifiers, and are much more difficult to delete and block. It further noted that the changes it is making through network partitioning in Firefox 85 will “reduce the effectiveness of cache-based supercookies by eliminating a tracker’s ability to use them across websites.”

“Trackers can abuse caches to create supercookies and can use connection identifiers to track users. But by isolating caches and network connections to the website they were created on, we make them useless for cross-site tracking,” Mozilla noted.

It explained that the network partitioning works by splitting the Firefox browser cache on a per-website basis, a technical solution that prevents websites from tracking users as they move across the web. Mozilla also noted that by removing support for Flash, there was not much impact on the page load time. The development was first reported by ZDNet.

[…]

Source: Firefox 85 removes support for Flash and adds protection against supercookies – Technology News

Update Your iPhone and iPad Right Now

Do you have an iPhone or iPad? You should update your device right now to iOS 14.4. No, not later today or after lunch or whatever. Update now.Why is it so crucial to update your iOS software as soon as possible? As TechCrunch first reported, Apple is reporting three security vulnerabilities that “may have been actively exploited” by hackers.We don’t have any real details yet, but Apple rarely has to admit such stunning vulnerabilities. The researchers who reported the security flaws have been granted anonymity by Apple.As Apple explains: Kernel Available for: iPhone 6s and later, iPad Air 2 and later, iPad mini 4 and later, and iPod touch (7th generation) Impact: A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited. Description: A race condition was addressed with improved locking. CVE-2021-1782: an anonymous researcher WebKit Available for: iPhone 6s and later, iPad Air 2 and later, iPad mini 4 and later, and iPod touch (7th generation) Impact: A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited. Description: A logic issue was addressed with improved restrictions. CVE-2021-1871: an anonymous researcher CVE-2021-1870: an anonymous researcher

Source: Update Your iPhone and iPad Right Now

Decade-old bug in Linux world’s sudo can be abused by any logged-in user to gain root privileges

Security researchers from Qualys have identified a critical heap buffer overflow vulnerability in sudo that can be exploited by rogue users to take over the host system.

Sudo is an open-source command-line utility widely used on Linux and other Unix-flavored operating systems. It is designed to give selected, trusted users administrative control when needed.

The bug (CVE-2021-3156) found by Qualys, though, allows any local user to gain root-level access on a vulnerable host in its default configuration. Qualys is disclosing its findings in a coordinated release with operating systems vendors, and has bestowed the errant code with the memorable name of the mythical mischief-maker Baron Samedi.

The following versions of sudo are affected: 1.8.2 through 1.8.31p2 and 1.9.0 through 1.9.5p1. Qualys developed exploits for several Linux distributions, including Ubuntu 20.04 (Sudo 1.8.31), Debian 10 (Sudo 1.8.27), and Fedora 33 (Sudo 1.9.2), and the security biz believes other distributions are vulnerable, too.

Ubuntu and Red Hat have already published patches, and your distro may have as well, so get to it.

In their write-up, Qualys researchers explain, “set_cmnd() is vulnerable to a heap-based buffer overflow, because the out-of-bounds characters that are copied to the ‘user_args’ buffer were not included in its size.”

[…]

The bug was introduced in July 2011 (commit 8255ed69) and has persisted unfixed until now.

[…]

Source: Decade-old bug in Linux world’s sudo can be abused by any logged-in user to gain root privileges • The Register

Fedora’s Chromium maintainer suggests switching to Firefox as Google yanks features in favour of Chrome

Fedora’s maintainer for the open-source Chromium browser package is recommending users consider switching to Firefox following Google’s decision to remove functionality and make it exclusive to its proprietary Chrome browser.The comments refer to a low-key statement Google made just before the release of Chrome 88, saying that during an audit it had “discovered that some third-party Chromium-based browsers were able to integrate Google features, such as Chrome sync and Click to Call, that are only intended for Google’s use… we are limiting access to our private Chrome APIs starting on March 15, 2021.”Tom Callaway (aka “spot”), a former Fedora engineering manager at Red Hat (Fedora is Red Hat’s bleeding-edge Linux distro), who now works for AWS, remarked when describing the Chromium 88 build that: “Google gave the builders of distribution Chromium packages these access rights back in 2013 via API keys, specifically so that we could have open-source builds of Chromium with (near) feature parity to Chrome. And now they’re taking it away.”The reasoning given for this change? Google does not want users to be able to ‘access their personal Chrome Sync data (such as bookmarks)… with a non-Google, Chromium-based browser.’ They’re not closing a security hole, they’re just requiring that everyone use Chrome.”Features in Chromium like data sync depend on Google APIs which are soon to be blockedFeatures in Chromium like data sync depend on Google APIs which are soon to be blockedCallaway predicted that “many (most?) users will be confused/annoyed when API functionality like sync and geolocation stops working for no good reason.” Although API access is not yet blocked, he has disabled it immediately to avoid users experiencing features that suddenly stop working for no apparent reason.He said he is no longer sure of the value of Chromium. “I would say that you might want to reconsider whether you want to use Chromium or not. If you want the full ‘Google’ experience, you can run the proprietary Chrome. If you want to use a FOSS browser that isn’t hobbled, there is a Firefox package in Fedora,” he said.Ahem, just ‘discovered’ this?There is more information about these APIs on the Chromium wiki. Access to the APIs is documented and Google’s claim that it has only just “discovered” this is an oddity. The APIs cover areas including sync, spelling, translation, Google Maps geolocation, Google Cloud Storage, safe browsing, and more.The situation has parallels with Android, where the Android Open Source Project (AOSP) is hard to use as a mobile phone operating system because important functions are reserved for the proprietary Google Play Services. The microG project exists specifically as an attempt to mitigate the absence of these APIs from AOSP.Something similar may now be necessary for Chromium if it is to deliver all the features users have come to expect from a web browser. It is not a problem for companies in a position to provide their own alternative services, such as Microsoft with Chromium-based Edge, but more difficult for Linux distros like Fedora.There are other ways to look at Google’s move, though. “Some people might even consider the removal of this Google-specific functionality an improvement,” commented a Fedora user. Microsoft reportedly removed more than 50 Google-specific services from Chromium as used in Edge, including data sync, safe browsing, maps geolocation, the Google Drive API, and more.Users who choose Chromium over Chrome to avoid Google dependency may not realise the extent of this integration, which is likely now to reduce. The Ungoogled Chromium project not only removes Google APIs but also “blocks internal requests to Google at runtime” as a failsafe measure.

Source: Fedora’s Chromium maintainer suggests switching to Firefox as Google yanks features in favour of Chrome • The Register

Apple hit with another European class action over throttled iPhones

A third class action lawsuit has been filed in Europe against Apple seeking compensation — for what Italy’s Altroconsumo consumer protection agency dubs “planned obsolescence” of a number of iPhone 6 models.The action relates to performance throttling Apple applied several years ago to affected iPhones when the health of the device’s battery had deteriorated — doing so without clearly informing users. It later apologized.The class action suit in Italy is seeking €60 million in compensation — based on at least €60 in average compensation per iPhone owner. Affected devices named in the suit are the iPhone 6, 6s, 6 Plus and 6s Plus, per a press release put out by the umbrella consumer organization Euroconsumers, which counts Altroconsumo as a member.The suit is the third to be filed in the region over the issue — following suits filed in Belgium and Spain last month.A fourth — in Portugal — is slated to be filed shortly.The tech giant settled similar charges in the U.S. last year — where it was accused of intentionally slowing down the performance of older iPhones to encourage customers to buy newer models or fresh batteries — shelling out $500 million, or around $25 per phone, to settle that case (while denying any wrongdoing).“When consumers buy Apple iPhones, they expect sustainable quality products. Unfortunately, that is not what happened with the iPhone 6 series. Not only were consumers defrauded, and did they have to face frustration and financial harm, from an environmental point of view it is also utterly irresponsible,” said Els Bruggeman, Euroconsumers’ head of policy and enforcement, in a statement.

Source: Apple hit with another European class action over throttled iPhones | TechCrunch

Dutch COVID-19 patient and testing data sold on the criminal underground

Dutch police have arrested two individuals on Friday for allegedly selling data from the Dutch health ministry’s COVID-19 systems on the criminal underground.

The arrests came after an investigation by RTL Nieuws reporter Daniel Verlaan who discovered ads for Dutch citizen data online, advertised on instant messaging apps like Telegram, Snapchat, and Wickr.

The ads consisted of photos of computer screens listing data of one or more Dutch citizens.

The reporter said he tracked down the screengrabs to two IT systems used by the Dutch Municipal Health Service (GGD) — namely CoronIT, which contains details about Dutch citizens who took a COVID-19 test, and HPzone Light, one of the DDG’s contact-tracing systems.

Verlaan said the data had been sold online for months for prices ranging from €30 to €50 per person.

Buyers would receive details such as home addresses, emails, telephone numbers, dates of birth, and a person’s BSN identifier (Dutch social security number).

Two men arrested in Amsterdam within a day

In a press release today, Dutch police said they started an investigation last week when they learned of the ads and arrested two suspects within 24 hours of the complaint.

Both men were arrested in Amsterdam on Friday, and were identified as a 21-year-old man from the city of Heiloo and a 23-year-old man from the city of Alblasserdam. Their homes were also searched, and their computers seized, police said.

According to Verlaan, the two suspects worked in DDG call centers, where they had access to official Dutch government COVID-19 systems and databases.

Source: Dutch COVID-19 patient data sold on the criminal underground | ZDNet

It turns out you can buy searched subsets of the information, eg people from Amsterdam or search by name.

Millions of people – basically everyone who’d ever had a corona test – were affected.

Original sauce: Illegale handel in privégegevens miljoenen Nederlanders uit coronasystemen GGD (RTL news)

It also turns out that the GGD was warned repeatedly of their poor security measures over the years and nothing was done about it. Andre Rouwvoet, the boss of the GGD was also warned and says it’s one of those things that couldn’t be helped. This is simply not true. The most obvious questions are:

  1. Why wasn’t the data deleted after no longer being relevant (it’s kept  for traceability of other people exposed and so loses relevance after 10 – 14 days)
  2. Why could helpdesk people access all of this huge database?
  3. Why wasn’t there a system op alarms in place to shout out when people were bulk exporting data?

 

Myopia correcting ‘smart glasses’ from Japan to be sold in Asia – Snake Oil or …?

Can a pair of unique spectacles banish nearsightedness without surgical intervention? Japan’s Kubota Pharmaceutical Holdings says its wearable device can do just that, and it plans to start releasing the product in Asia, where many people grapple with myopia.

The device, which the company calls Kubota Glasses or smart glasses, is still being tested. It projects an image from the lens of the unit onto the wearer’s retina to correct the refractive error that causes nearsightedness. Wearing the device 60 to 90 minutes a day corrects myopia according to the Japanese company.

Kubota Pharmaceutical has not disclosed additional details on how the device works. Through further clinical trials, it is trying to determine how long the effect lasts after the user wears the device, and how many days in total the user must wear the device to achieve a permanent correction for nearsightedness.

[…]

Kubota began clinical trials on the device last July after confirming the therapeutic effect of the mechanism using a desktop system. It is also developing a contact lens-type myopia correction device.

Kubota, which made its debut on the Tokyo Stock Exchange’s Mothers market for startups in December 2016, develops drugs and devices for the treatment of vision problems.

Source: Myopia correcting ‘smart glasses’ from Japan to be sold in Asia – Nikkei Asia

A Telegram Bot Is Selling Stolen Facebook User Info (500m of them1) for $20 a Pop

The phone numbers (and corresponding site IDs) of some 500 million Facebook users now appear to be for sale on a dark web cybercrime forum.

The criminal or group of criminals responsible have constructed a Telegram bot to act as a search function for the data. Potential buyers can now use the bot to sift through the data to find phone numbers that correspond to user IDs—or vice versa—with the full information being unlocked after paying for query “credits.” Those credits start at $20 for a single search and get cheaper if bought in bulk.

The activity was discovered by Alon Gal, co-founder and CTO of cybersecurity firm Hudson Rock, who posted about the scheme on his Twitter account, and reported by Joseph Cox, at Motherboard.

An insecure Facebook server containing account information on millions of users appears to be the source of the data for sale here—though that vulnerability was discovered by researchers in 2019 and Facebook has since fixed it. Gal has claimed that the vulnerability was exploited to create “a database containing the information 533m users across all countries.” (For reasons unknown, the bot itself only claims to sell information for users in 19 countries.)

Source: A Telegram Bot Is Selling Stolen Facebook User Info for $20 a Pop

Yay centralised databases

Tucows closes its once-popular software download site

It was inevitable, really. In the early days of the internet, Tucows was known as a reliable place to find and download new software. Today, however, most people are happy to use a modern App Store — Microsoft and Apple both run their own — or navigate to developer websites directly. And if you’re looking for inspiration, there’s always Product Hunt. Tucows has decided, therefore, to finally shut down Tucows Downloads. “Tucows Downloads is old,” Elliot Noss, CEO of Tucows said. “Old sites are a maintenance challenge and therefore a risk.“

It’s a decision that the team has been mulling for some time. “We talked about shutting the site down before,” Noss explained. But the site’s history, combined with a sense of sentimentality, gave them pause. In 2016, the company decided to treat Tucows Downloads as a public service, rather than a legacy moneymaker. It stripped the site of ads, admitting that the site had become “less relevant when looking at the balance sheet” anyway. Now, though, the company is ready to move on. It has enough work as a domain registrar, domain name seller and the company behind Ting, an internet service provider in the US.

Source: Tucows closes its once-popular software download site | Engadget

Apple warns against putting an iPhone 12 too close to your pacemaker

You probably don’t need someone to tell you that magnets and life-saving medical devices don’t mix, but Apple wants to make that patently clear. MacRumors has learned that Apple recently updated a support document to warn against keeping the iPhone 12 and MagSafe accessories too close to pacemakers, defibrillators and other implants that might respond to magnets and radios. You should keep them at least six inches away in regular use, or at least a foot away if the iPhone is wirelessly charging.

The company maintained that the extra number of magnets shouldn’t increase the risks compare to past iPhone models. Still, the notice comes days after doctors reported that the new phones could interfere with implants. In a test, they found that an iPhone 12 kicked a defibrillator implant into a suspended state when it got near.

[…]

Source: Apple warns against putting an iPhone 12 too close to your pacemaker | Engadget

Reading tables from images with magick

There are many times where someone shares data as an image, whether intentionally due to software constraints (ie Twitter) or as a result of not understanding the implications (image inside a PDF or in a Word Doc). xkcd.com jokingly refers to this as .norm or as the Normal File Format. While it’s far from ideal or a real file format, it’s all too common to see data as images in the “wild”. I’ll be using some examples from Twitter images and extracting the raw data from these. There are multiple levels of difficulty, namely that screenshots on Twitter are not uniform, often of relatively low quality (ie DPI), and contain additional “decoration” like colors or grid-lines. We’ll do our best to make it work!

[…]

Source: The Mockup Blog: Reading tables from images with magick

Clop ransomware gang clips sensitive files from Atlantic Records’ London ad agency The7stars, dumps them online

A London ad agency that counts Atlantic Records, Suzuki, and Penguin Random House among its clients has had its files dumped online by a ransomware gang, The Register can reveal.

The7stars, based in London’s West End, filed [PDF] revenues of £379.36m up from £326m, gross billing of £426m and net profit of £2.1m for the year ended 31 March 2020.

In the same accounts filed with UK register Companies House, it boasted of its position as the “largest independently owned media agency in the UK by a significant factor”, making it a juicy target for the Clop ransomware extortionists.

The attack appears to have happened after 15 December, when The7stars’ annual return was prepared for filing with Companies House. While the document talks in length about its healthy financial performance, it mentions nothing about cyber risks or attacks.

Screenshots published on the Clop gang’s Tor website show scans of passports, invoices, what appears to be a photo from a staff party and, ironically, a “data protection agreement.”

Publication of stolen files on a ransomware crew’s website is typically an indicator that a ransom demand has been rebuffed, though more aggressive tactics seen in the last year include pre-emptive leaking of stolen data as an apparent incentive for marks to pay up quickly.

The agency’s client list includes Led Zeppelin’s former label Atlantic Records, Japanese motorbike maker Suzuki, and British train operating companies including Great Western Railway, among others. It is very unlikely that those companies will have been directly affected, though it appears Clop wants to give the impression that it has stolen commercially sensitive documents relating to The7stars’ clients.

[…]

Source: Clop ransomware gang clips sensitive files from Atlantic Records’ London ad agency The7stars, dumps them online • The Register

GameStop Stock Breaks Records As Reddit Traders War With Short Sellers

Struggling retailer GameStop’s stock curiously hit an all time high today. But it’s not because Sony, Microsoft, and Nintendo suddenly decided to stop selling their games digitally. And it’s not because a new set of Funko Pops has taken the internet’s imagination by storm.

No, the stock price jumped to an all-time high because some institutional investors bet on the company to fail, and a bunch of amateurs on social media decided to call their bluff and try getting rich in the process.

GameStop has struggled to reinvent itself as video games have increasingly gone digital. Now, established investors and Reddit day-traders are going to war over its future, and making the company’s stock price do ridiculous things in the process.

At the beginning of the year, GameStop’s stock was trading at just under $20 a share. In the weeks since, it’s more than tripled in value reaching just over $73 at its highest point today. “GameStop is up 174% in January to date, with its average daily rolling 10-day volatility peaking at the highest level in the nearly two decades the stock has been trading,” Bloomberg reported.

[…]

As Ars Technica reported earlier this week, some investors spent last fall shorting GameStop’s stock, effectively speculating that it was overvalued and would implode, possibly making them a bunch of money in the process.

[…]

Meanwhile, people hanging out on subreddits like Wallstreetbets (self-described as “Like 4chan found a Bloomberg Terminal”) and the finance influencer realm of TikTok (nicknamed FinTok) started putting their money behind GameStop’s longevity.

[…]

“[E]ssentially, people on WallStreetBets, along with several YouTube and TikTok investors guessed as long as a year ago that if they bought shares of GameStop at a low price, the short sellers would eventually be forced to cover their short en masse, which would drive the price up,” wrote Vice in another great explainer published this week.

Shorting seemed like a sensible bet considering months of bad news and poor financial reports coming out of GameStop. But then, as Vice pointed out, Reddit finance personalities began musing about how they thought GameStop was actually a great investment opportunity. The logic was based on how many other investors were already short selling it. Just today, CNBC reported that GameStop is “the single most shorted name in the U.S. stock market.”

If someone shorts a stock, i.e. sells it and gives the original owner an IOU, and then that original owner needs the stock back, they need to “cover” the short by buying additional stock. This helps pump up the price of the stock even further, making it more valuable and potentially creating a feedback loop where it just goes up and up and up as everyone scrambles to buy back from the same limited pool of shares.

One of the GameStop short sellers is Andrew Left, called “Wall Street’s Bounty Hunter” by The New York Times because of his reputation for shorting companies he considers weak and following up by publishing research about why the company is going to fail, or, in some cases, alleging outright fraud. Yesterday, Left put out a six and a half minute video on YouTube making his case for why GameStop is doomed. WallStreetBets in turn organized what finance pundit Jim Cramer called “an ambush,” pumping up up GameStop’s stock in a coordinated campaign to “squeeze” Left, forcing him to buy tons of stock of his own to “cover” his position and in turn making their shares worth even more. Jim Cramer is an absolute goon, but if anything fits the bill of “Mad Money” it’s this.

[…]

As with everything on the internet, what may have started as some people trying to (and succeeding at) making a bunch of quick cash has become much more, including a sort of crusade against Left as well as an unlikely source of GameStop fandom.

Earlier this month, GameStop announced Ryan Cohen would be taking a seat on its board. Cohen is formerly the CEO of the pet food website Chewy.com, but he’s already become a golden boy meme in the world of GameStop stocks. Search his name on Twitter and you’ll find people tweeting things like “Papa Cohen will take us all to mars suit up homies it will be a bumpy ride to the [rocket emoji] so u don’t fall off.”

[…]

Source: GameStop Stock Breaks Records As Reddit Traders War With Short Sellers

Hackers Leak Data of 2.28 Million MeetMindful Users

Millions of users of the dating site MeetMindful got some unpleasant news on Sunday. ZDNet reported that the hacker group ShinyHunters, the same group who leaked millions of user records for the company that listed the “Camp Auschwitz” shirts, has dumped what appears to be data from the dating site’s user database. The leak purportedly contains the sensitive information of more than 2.28 million of the site’s registered users.

[…]

According to ZDNet, the 1.2 gigabyte file was shared as a free download “on a publicly accessible hacking forum known for its trade in hacked databases.” It included troves of sensitive and identifiable user information, including real names, email addresses, city, state, and ZIP code details, birth dates, IP addresses, Facebook user IDs, and Facebook authentication tokens, among others. Messages, however, were not exposed.

[…]

According to its Crunchbase profile, MeetMindful is a dating site platform for “people who are into health, well-being, and mindfulness.” It was founded in 2013, is based in Denver, Colorado, and is still active.

Here’s where it starts to get a little strange, though. The site’s listed social media channels have been inactive for months, which is interesting considering that major dating apps have been growing during the pandemic. I mean, don’t they want to encourage their users to date (safely)? From the outside, the service seems like dead zone. Who knows though, it could be all the rage inside the site itself.

[…]

Source: Report: Hackers Leak Data of 2.28 Million MeetMindful Users

£30-million injection for UK’s first uncrewed fighter aircraft

The uncrewed combat aircraft will be designed to fly at high-speed alongside fighter jets, armed with missiles, surveillance and electronic warfare technology to provide a battle-winning advantage over hostile forces. Known as a ‘loyal wingman’, these aircraft will be the UK’s first uncrewed platforms able to target and shoot down enemy aircraft and survive against surface to air missiles.

In a boost for Northern Ireland’s defence industry, Spirit AeroSystems, Belfast, have been selected to lead Team MOSQUITO in the next phase of the Project. Utilising ground-breaking engineering techniques, the team will further develop the RAF’s Lightweight Affordable Novel Combat Aircraft (LANCA) concept, with a full-scale vehicle flight-test programme expected by the end of 2023.

[…]

This game changing research and development project will ensure the final aircraft design will be capable of being easily and affordably updated with the latest technology so we remain one step ahead of our adversaries. The aircraft’s flexibility will provide the optimum protection, survivability and information as it flies alongside Typhoon, F-35 Lightning, and later, Tempest as part of our future combat air system.

[…]

ANCA originated in 2015 in Dstl to understand innovative Combat Air technologies and concepts that offer radical reductions in cost and development time and is a RAF Rapid Capabilities Office led project under the Future Combat Air System Technology Initiative (FCAS TI). The UK MOD’s Defence Science and Technology Laboratory (Dstl) provides the project management and is the MOD’s technical authority for LANCA and Project Mosquito on behalf of the RCO.

Source: £30-million injection for UK’s first uncrewed fighter aircraft – GOV.UK

DNSPOOQ breaks dnsmasq allowing for cache poisoning, remote code execution and more

The JSOF research labs are reporting 7 vulnerabilities found in dnsmasq, an open-source DNS forwarding software in common use. Dnsmasq is very popular, and we have identified approximately 40 vendors whom we believe use dnsmasq in their products, as well as major Linux distributions.

The DNS protocol has a history of vulnerabilities dating back to the famous 2008 Kaminsky attack. Nevertheless, a large part of the Internet still relies on DNS as a source of integrity, in the same way it has for over a decade, and is therefore exposed to attacks that can endanger the integrity of parts of the web.

DNSpooq

The Dnspooq vulnerabilities include DNS cache poisoning vulnerabilities as well as a potential Remote code execution and others. The list of devices using dnsmasq is long and varied. According to our internet-based research, prominent users of dnsmasq seem to include Cisco routers, Android phones, Aruba devices, Technicolor, and Red-Hat, as well as Siemens, Ubiquiti networks, Comcast, and others listed below. Depending on how they use dnsmasq, devices may be more or less affected, or not affected at all.

[…]

The DNSpooq vulnerability set divides into 2 types of vulnerabilities:

  1. DNS cache poisoning attacks, similar to the Kaminsky attack, but different in some aspects.
  2. Buffer overflow vulnerabilities that could lead to remote code execution.

[…]

The DNSpooq cache poisoning vulnerabilities are labeled:
CVE-2020-25686, CVE-2020-25684, CVE-2020-25685

[…]

These [buffer overflow] vulnerabilities are labeled:
CVE-2020-25687, CVE-2020-25683, CVE-2020-25682, CVE-2020-25681

[…]

Source: DNSPOOQ – JSOF

This site posted every face from Parler’s Capitol Hill insurrection videos

Late last week, a website called Faces of the Riot appeared online, showing nothing but a vast grid of more than 6,000 images of faces, each one tagged only with a string of characters associated with the Parler video in which it appeared. The site’s creator tells WIRED that he used simple, open source machine-learning and facial recognition software to detect, extract, and deduplicate every face from the 827 videos that were posted to Parler from inside and outside the Capitol building on January 6, the day when radicalized Trump supporters stormed the building in a riot that resulted in five people’s deaths. The creator of Faces of the Riot says his goal is to allow anyone to easily sort through the faces pulled from those videos to identify someone they may know, or recognize who took part in the mob, or even to reference the collected faces against FBI wanted posters and send a tip to law enforcement if they spot someone.

[…]

Aside from the clear privacy concerns it raises, Faces of the Riot’s indiscriminate posting of faces doesn’t distinguish between lawbreakers—who trampled barriers, broke into the Capitol building, and trespassed in legislative chambers—and people who merely attended the protests outside. A recent upgrade to the site adds hyperlinks from faces to the video source, so that visitors can click on any face and see what the person was filmed doing on Parler. The Faces of the Riot creator, who says he’s a college student in the “greater DC area,” intends that added feature to help contextualize every face’s inclusion on the site and differentiate between bystanders, peaceful protesters, and violent insurrectionists.

He concedes that he and a co-creator are still working to scrub “non-rioter” faces, including those of police and press who were present. A message at the top of the site also warns against vigilante investigations, instead suggesting users report those they recognize to the FBI, with a link to an FBI tip page.

[…]

Despite its disclaimers and limitations, Faces of the Riot represents the serious privacy dangers of pervasive facial recognition technology, says Evan Greer, the campaign director for digital civil liberties nonprofit Fight for the Future. “Whether it’s used by an individual or by the government, this technology has profound implications for human rights and freedom of expression,” says Greer, whose organization has fought for a legislative ban on facial recognition technologies.

[…]

The site’s developer counters that Faces of the Riot leans not on facial recognition but facial detection. While he did use the open source machine-learning tool TensorFlow and the facial recognition software Dlib to analyze the Parler videos, he says he used that software only to detect and “cluster” faces from the 11 hours of video of the Capitol riot; Dlib allowed him to deduplicate the 200,000 images of faces extracted from video frames to around 6,000 unique faces

[…]

The Faces of the Riot site’s creator initially saw the data as a chance to experiment with machine-learning tools but quickly saw the potential for a more public project. “After about 10 minutes I thought, ‘This is actually a workable idea and I can do something that will help people,'” he says. Faces of the Riot is the first website he’s ever created.

[…]

But McDonald also points out that Faces of the Riot demonstrates just how accessible facial recognition technologies have become. “It shows how this tool that has been restricted only to people who have the most education, the most power, the most privilege is now in this more democratized state,” McDonald says.

The Faces of the Riot site’s creator sees it as more than an art project or demonstration

[…]

Source: This site posted every face from Parler’s Capitol Hill insurrection videos | Ars Technica

WhatsApp Private Groups + user phone numbers Were Accessible Again to Anyone Searching on Google – a yearly event now

WhatsApp groups are showing up on Google search yet again. As a result, anyone could discover and join a private WhatsApp group by simply searching on Google. This was first discovered in 2019, and was apparently fixed last year after becoming public. Another old issue, which also appeared to have been fixed but seems to be cropping up again, is user profiles showing up through search results. People’s phone numbers and profile pictures could be surfaced through a simple a Google search, because of the issue.

By allowing the indexing of group chat invites, WhatsApp is making several private groups available across the Web as their links can be accessed by anyone using a simple search query on Google — although we are not sharing the exact details, this was verified by Gadgets 360. Someone who finds these links can join the groups and would also be able to see the participants and their phone numbers alongside the posts being shared within those groups.

Update: WhatsApp replied to say, “Since March 2020, WhatsApp has included the ‘noindex’ tag on all deep link pages which, according to Google, will exclude them from indexing.” Gadgets 360 was able to confirm that the search results are no longer visible on Google anymore; however, WhatsApp’s statement did not mention this fix. The full statement is at the end of this story. Rajshekhar Rajaharia, who informed about the indexing issue, commented on the statement given by WhatsApp and said, “Adding the ‘noindex’ tag is not a proper solution as links surface again on search results in a a few months. Big tech companies like WhatsApp should look for a proper solution if they really care users’ privacy.”

Source: WhatsApp Private Groups Were Accessible Again to Anyone Searching on Google | Technology News

Private groups on WhatsApp are usually only accessible by those who have been sent an invite link by a moderator. However, these links were indexed by Google, making them discoverable by everyone. The same issue was exposed in February last year.

Following the latest privacy breach, WhatsApp said it has resolved the problem with Google.

“Since March 2020, WhatsApp has included the “noindex” tag on all deep link pages which, according to Google, will exclude them from indexing. We have given our feedback to Google to not index these chats,” the Facebook-owned messaging app said in a statement.

WhatsApp also warned users not to post group chat invite links on publicly accessible websites.

Source: WhatsApp private group chat links appear in Google search again

Cybersecurity researcher Rajshekhar Rajaharia tweeted that WhatsApp Web users’ data was being indexed on Google again, pointing out that this was the third time the issue had occurred.

When information is indexed, it can be found in a search engine and made public. As such, companies generally take measures to prevent private data from being indexed.

He had pointed out a similar issue earlier on Jan 11, where users’ profiles and invitations to join group chats were exposed on Google, which enabled strangers to potentially find users’ phone numbers or even join chats.

[…]

In regards to the latest leak, Rajshekhar noted that WhatsApp was using a “Robots.txt” file and a “disallow all” setting, to instruct Google not to index anything.

Though a Robots.txt, or robots exclusion protocol, is generally used to instruct web crawlers (which index pages) to stay away, Google was still indexing WhatsApp user data.

Rajshekhar explained why this was still occurring: Google requires page owners not to use Robots.txt when using the “noindex” tag, as stated in its search indexing help page.

This is because the features clash, with Google unable to detect the “noindex” tag if it was being stopped by Robot.txt.

Source: WhatsApp users’ phone numbers and chats exposed on Google

AWS has been doing things that are ‘just NOT OK since 2015,’ says Elastic as firm yanks Apache 2.0 licence – FOSS blues

Elastic CEO and co-founder Shay Banon has attacked AWS for what he claims is unacceptable use of the open-source Elasticsearch product and trademark.

Banon’s post is part of the company’s defence of its decision to drop the open-source Apache 2.0 licence for its ElasticSearch and Kibana products and instead use the copyleft SSPL or restrictive Elastic licence – though the plan is to add provisions to mitigate this by having code revert to the Apache 2.0 licence after a period of up to five years.

The new rant makes explicit that the purpose of the licence change is to make it harder for AWS to use Elastic’s code. According to Banon, AWS has been “doing things that we think are just NOT OK since 2015.” Banon said that “we’ve tried every avenue available including going through the courts,” presumably a reference to this lawsuit [PDF], the outcome of which is not yet determined.

Banon wants to prevent “companies from taking our Elasticsearch and Kibana products and providing them directly as a service without collaborating with us.” The issue is not clear-cut, though, since permissive open-source licences like Apache 2.0 specifically include the right to modify and distribute the product.

Well yes, but the modified bits are supposed to go back into the product, which AWS isn’t doing. They are selling the product and their own addons and not bringing the addons back to the Open Source project and community. Basically they steal the idea and code and then throw more money at it than any FOSS developer can and close that up.

The company has also protected its investment by releasing some features only under the Elastic licence. Elasticsearch is based on Apache Lucene so Elastic itself is vulnerable to accusations of benefiting from open source while now trying to lock down its products for commercial advantage.

And very strange it is that AWS can commercialise but Elasticsearch can’t.

The Elasticsearch trademark is another matter, and Banon also claims that AWS has not been honest with customers about its fork called Open Distro for Elasticsearch, which underlies the Amazon Elasticsearch Service. AWS CTO Werner Vogels announced this on Twitter with a now-deleted tweet calling it “a great partnership between @elastic and AWS.” According to Banon, there was no collaboration.

“Over the years, we have heard repeatedly that this confusion persists,” Banon said. He also claimed that proprietary features in Elasticsearch are “serving as ‘inspiration’ for Amazon.”

In March 2019, Adrian Cockcroft, Amazon’s VP of cloud architecture strategy, said that the motivation for the Open Distro for Elasticsearch was that “since June 2018, we have witnessed significant intermingling of proprietary code into the code base” and complained about “an extreme lack of clarity as to what customers who care about open source are getting and what they can depend on.” According to Cockcroft, AWS offered “significant resources” to support a community version of Elasticsearch but this was refused. “The whole idea of open source is that multiple users and companies can put it to work and everyone can contribute to its improvement,” he said.

So it would nice if AWS actually gave back.

In February 2020, AWS added security features to its Elasticsearch service, in partnership with Floragunn GmbH, whose Search Guard product is a third-party security add-on for Elasticsearch. Floragunn’s product is also subject of litigation [PDF] from Elastic, which claims in the court filing that it is a “knowing and willful infringement of Elastic’s copyright in the source code for Elastic’s X-Pack software.”

Andi Gutmans, VP of analytics and ElastiCache at AWS, said in the same month last year: “We want to make the community aware that AWS performed our own due diligence prior to partnering with Floragunn and found no evidence that Search Guard misappropriated any copyrighted material.” He added that “this kind of behavior is misaligned with the spirit of open source.”

And here come the FOSS fundamentalists

Yestrday, Charlie Hull, co-founder of UK open-source search consultancy Flax, said: “Although Elasticsearch creator Shay Banon is always at pains to point out his personal commitment to ‘open,’ what that means in practice has shifted several times as his company has grown, taken investment and gone public. Elastic’s actions over the years, such as deliberately mixing Apache 2 and Elastic licensed code, have shown it was shifting away from a true open source model.”

According to Hull, Elastic’s new terms are unlikely to affect third-party services that do not directly expose Elasticsearch, such as a library book search. But he did add that “the boundaries of what constitutes a ‘Prohibited SaaS Offering’ are not entirely clear,” and that “those considering Elasticsearch for new projects will have to consider how important they regard the freedoms of a true open source license and perhaps examine alternatives.”

This guy doesn’t code, doesn’t contribute but points people at FOSS products as a ‘consultant’. But he does have an opinion on how people should program for free so he can point them at their products.

Linux developer Drew DeVault said of the licence change: “Elasticsearch belongs to its 1,573 contributors, who retain their copyright, and granted Elastic a license to distribute their work without restriction… Elastic has spit in the face of every single one of 1,573 contributors, and everyone who gave Elastic their trust, loyalty, and patronage. This is an Oracle-level move.”

And another developer who has their salary paid and so doesn’t have to worry about their product being used by everyone on the planet whilst you as programmer of the product are making barely enough to get by whilst working crazy hours and having shit piled on you by self rightous people. It’s a comfortable position to be an idealist from.

Source: AWS has been doing things that are ‘just NOT OK since 2015,’ says Elastic as firm yanks Apache 2.0 licence • The Register

I spoke about the problems of FOSS in 2017 and with the importance of the products increasing with the complexity whilst the pay and conditions are miserable makes this still very very relevant