The Linkielist

Linking ideas with the world

Asus Bezel-Free Kit uses illusion to hide bezels in multimonitor setups

The concept is simple. Thin lenses are placed along the seams where screens meet; they contain optical micro-structures that refract light, bending it inward to hide the bezels underneath. […] The kit’s optical obfuscation is designed to work at a specific angle. We selected 130° because it offered the best balance of comfort and immersion Read more about Asus Bezel-Free Kit uses illusion to hide bezels in multimonitor setups[…]

OnePlus suspends credit card transactions after fraud

Over the weekend, members of the OnePlus community reported cases of unknown credit card transactions occurring on their credit cards post purchase from oneplus.net. We immediately began to investigate as a matter of urgency, and will keep you updated. […] As a precaution, we are temporarily disabling credit card payments at oneplus.net. PayPal is still Read more about OnePlus suspends credit card transactions after fraud[…]

Skygofree: Serious offensive Android malware, since 2014

At the beginning of October 2017, we discovered new Android spyware with several features previously unseen in the wild. In the course of further research, we found a number of related samples that point to a long-term development process. We believe the initial versions of this malware were created at least three years ago – Read more about Skygofree: Serious offensive Android malware, since 2014[…]

Hospital injects $60,000 into crims’ coffers to cure malware infection

The crooks had infected the network of Hancock Health, in Indiana, with the Samsam software nasty, which scrambled files and demanded payment to recover the documents. The criminals broke in around 9.30pm on January 11 after finding a box with an exploitable Remote Desktop Protocol (RDP) server, and inject their ransomware into connected computers. Medical Read more about Hospital injects $60,000 into crims’ coffers to cure malware infection[…]

300 Dutch customers fell for fake popular website ring. Perps picked up and given a few months of prison time.

BCC and MediaMarkt are large electronics stores in NL. Ziggo is a large internet ISP. By linking to fake pages through marktplaats.nl (the Dutch ebay / Craigslist equivalent) people were able to shop for products on the fake sites, which were never delivered. Using a chat interface, the crims tried to gain access to the Read more about 300 Dutch customers fell for fake popular website ring. Perps picked up and given a few months of prison time.[…]

Microsoft wants to patent mind control – show how stupid the patent system really is

Microsoft has applied to patent a brain control interface, so you’ll be able to “think” your way around a computer device, hands free.Last year, Facebook claimed to have 60 engineers engaged in BCI [brain computer interface] but Microsoft isn’t going to take this sitting down. It’s erm, sitting down and thinking really hard.The application Changing Read more about Microsoft wants to patent mind control – show how stupid the patent system really is[…]

All Intel laptops open to unlocking with ctrl-P and “admin”. Another fatal flaw in Intel Management Engine.

F-Secure reports a security issue affecting most corporate laptops that allows an attacker with physical access to backdoor a device in less than 30 seconds. The issue allows the attacker to bypass the need to enter credentials, including BIOS and Bitlocker passwords and TPM pins, and to gain remote access for later exploitation. It exists Read more about All Intel laptops open to unlocking with ctrl-P and “admin”. Another fatal flaw in Intel Management Engine.[…]

Let’s Encrypt plugs hole that let miscreants grab HTTPS web certs for strangers’ domains

Let’s Encrypt – a SSL/TLS certificate authority run by the non-profit Internet Security Research Group (ISRG) to programmatically provide websites with free certs for their HTTPS websites – on Thursday said it is discontinuing TLS-SNI validation because it’s insecure in the context of many shared hosting providers. TLS-SNI is one of three ways Let’s Encrypt’s Read more about Let’s Encrypt plugs hole that let miscreants grab HTTPS web certs for strangers’ domains[…]

Adult Themed Virtual Reality App spills Names, Emails of Thousands

Researchers at the firm Digital Interruption on Tuesday warned that an adult-themed virtual reality application, SinVR, exposes the names, email and other personal information via an insecure desktop application – a potentially embarrassing security lapse. The company decided to go public with the information after being frustrated in multiple efforts to responsibly disclose the vulnerability Read more about Adult Themed Virtual Reality App spills Names, Emails of Thousands[…]

Wait, what? The Linux Kernel Mailing List archives lived on ONE PC? One BROKEN PC?

Spare a thought for Jasper Spaans, who hosts the Linux Kernel Mailing List archive from a single PC that lives in his home. And since things always happen this way the home machine died while he was on holiday. The archive was therefore unavailable for much of the weekend, although Linux developers could still use Read more about Wait, what? The Linux Kernel Mailing List archives lived on ONE PC? One BROKEN PC?[…]

EMC, VMware security bugs throw gasoline on cloud security fire

While everyone was screaming about Meltdown and Spectre, another urgent security fix was already in progress for many corporate data centers and cloud providers who use products from Dell’s EMC and VMware units. A trio of critical, newly reported vulnerabilities in EMC and VMware backup and recovery tools—EMC Avamar, EMC NetWorker, EMC Integrated Data Protection Read more about EMC, VMware security bugs throw gasoline on cloud security fire[…]

Okay, Google: why does Chromecast clobber Wi-Fi connections?

Wi-Fi router vendors have started issuing patches to defend their products against Google Chromecast devices.TP-Link and Linksys were first out of the blocks with firmware fixes, and TP-Link has posted this explanation of the issue. The bug is not in the routers, but in Google’s “Cast” feature, used in Chromecast, Google Home, and other devices. Read more about Okay, Google: why does Chromecast clobber Wi-Fi connections?[…]

BAE Magma aircraft controls aircraft orientation without moving parts but blown air

Together with The University of Manchester, we have successfully completed the first phase of flight trials with MAGMA – a small scale unmanned aerial vehicle (UAV), which will use a unique blown-air system to manoeuvre the aircraft – paving the way for future stealthier aircraft designs. The new concept for aircraft control removes the conventional Read more about BAE Magma aircraft controls aircraft orientation without moving parts but blown air[…]

DARPA looking for Innovative Ideas for Swarm Drone Systems in Urban Environments

DARPA’s OFFensive Swarm-Enabled Tactics (OFFSET) program envisions future small-unit infantry forces using small unmanned aircraft systems (UASs) and/or small unmanned ground systems (UGSs) in swarms of 250 robots or more to accomplish diverse missions in complex urban environments. By leveraging and combining emerging technologies in swarm autonomy and human-swarm teaming, the program seeks to enable Read more about DARPA looking for Innovative Ideas for Swarm Drone Systems in Urban Environments[…]

When It Comes to Gorillas, Google Photos Remains Blind – it’s hard to take an AI to account

In a third test attempting to assess Google Photos’ view of people, WIRED also uploaded a collection of more than 10,000 images used in facial-recognition research. The search term “African american” turned up only an image of grazing antelope. Typing “black man,” “black woman,” or “black person,” caused Google’s system to return black-and-white images of Read more about When It Comes to Gorillas, Google Photos Remains Blind – it’s hard to take an AI to account[…]

With the “Forever Battery,” Ossia’s Cota AA system Promises True Wireless Charging

The Forever Battery comes in a AA form factor, and houses electronics (including an antenna) within its shell. Ossia’s Cota system uses a transmitter that beams electricity along direct paths through the air to the antenna in the battery, charging it from distances of up to 30 feet, with nary a wire to be seen Read more about With the “Forever Battery,” Ossia’s Cota AA system Promises True Wireless Charging[…]

The Vuzix Blade Is What Google Glass Always Wanted to Be

The thing that always rubbed me the wrong way about Google Glass though, was how after an underwhelming debut, the company seemingly forgot about its moonshot tech. The only thing that remains of the project are enterprise-only models focused more on assisting business complete specialized tasks than expanding the tech as a whole. It’s a Read more about The Vuzix Blade Is What Google Glass Always Wanted to Be[…]

US House reps green-light Fourth Amendment busting spy program

The US House of Representatives has passed a six-year extension to the controversial Section 702 spying program, rejecting an amendment that would have required the authorities to get a warrant before searching for information on US citizens. The 256-164 vote effectively retains the status quo and undermines a multi-year effort to bring accountability to a Read more about US House reps green-light Fourth Amendment busting spy program[…]

OnePlus Android mobes’ clipboard app caught phoning home to China

OnePlus has admitted that the clipboard app in a beta build of its Android OS was beaming back mystery data to a cloud service in China. Someone running the latest test version of OnePlus’s Oreo-based operating system revealed in its support forums that unusual activity from the builtin clipboard manager had been detected by a Read more about OnePlus Android mobes’ clipboard app caught phoning home to China[…]

WhatsApp Security Design Could Let an Infiltrator Add Members to Group Chats

Only admins can add new members to private groups. But the researchers found that anyone in control of the server can spoof the authentication process, essentially granting themselves the privileges necessary to add new members who can snoop on private conversations. The obvious examples that come to mind are hackers who manage to gain access Read more about WhatsApp Security Design Could Let an Infiltrator Add Members to Group Chats[…]

Wall Street Analysts Are Embarrassingly Bad At Predicting The Future, Study Finds

The researchers looked at a database of long-term growth forecasts made for all domestic companies listed on a major stock exchange. The forecasts are made in December each year, and predict how well a company’s stocks will do over the next three to five years. From 1981 to 2016, they found that the top 10 Read more about Wall Street Analysts Are Embarrassingly Bad At Predicting The Future, Study Finds[…]

Stop us if you’ve heard this one: Apple’s password protection in macOS can be thwarted

An Apple developer has uncovered another embarrassing vulnerability in macOS High Sierra, aka version 10.13, that lets someone bypass part of the operating system’s password protections.This time, a vulnerable dialog box was found in the System Preferences panel for the App Store settings. The bug, reported by developer Eric Holtam to the Open Radar bug Read more about Stop us if you’ve heard this one: Apple’s password protection in macOS can be thwarted[…]

Violating a Website’s Terms of Service Is Not a Crime, Federal Court Rules

the federal court of appeals heeded EFF’s advice and rejected an attempt by Oracle to hold a company criminally liable for accessing Oracle’s website in a manner it didn’t like. The court ruled back in 2012 that merely violating a website’s terms of use is not a crime under the federal computer crime statute, the Read more about Violating a Website’s Terms of Service Is Not a Crime, Federal Court Rules[…]

Boffins tweak audio by 0.1% to fool speech recognition engines

a paper by Nicholas Carlini and David Wagner of the University of California Berkeley has explained off a technique to trick speech recognition by changing the source waveform by 0.1 per cent. The pair wrote at arXiv that their attack achieved a first: not merely an attack that made a speech recognition SR engine fail, Read more about Boffins tweak audio by 0.1% to fool speech recognition engines[…]