The Linkielist

Linking ideas with the world

A Literal Tree Illustration Shows How Languages Are Connected

Did you know that most of the different languages we speak today can actually be placed in only a couple of groups by their origin? This is what illustrator Minna Sundberg has captured in an elegant infographic of a linguistic tree which reveals some fascinating links between different tongues. Source: This Amazing Tree That Shows Read more about A Literal Tree Illustration Shows How Languages Are Connected[…]

Closed source corporate DRM for money grabbers is forced onto open source web with flimsiest of excuses

The trouble with DRM is that it’s sort of ineffective. It tends to make things inconvenient for people who legitimately bought a song or movie while failing to stop piracy. Some rights holders, like Ubisoft, have come around to the idea that DRM is counterproductive. Steve Jobs famously wrote about the inanity of DRM in Read more about Closed source corporate DRM for money grabbers is forced onto open source web with flimsiest of excuses[…]

SVR Tracking leaks info for hundreds of thousands of vehicles. Turns out they have been tracking you even when your car wasn’t stolen.

Researchers discovered a misconfigured Amazon AWS S3 bucket that was left publically available. The breach has exposed information about their customers and re-seller network and also the physical device that is attached to the cars. The repository contained over a half of a million records with logins / passwords, emails, VIN (vehicle identification number), IMEI Read more about SVR Tracking leaks info for hundreds of thousands of vehicles. Turns out they have been tracking you even when your car wasn’t stolen.[…]

Equifax fooled again! Blundering credit biz directs hack attack victims to parody site

When news of the hack was published on September 7, over a month after its scale had been discovered, Equifax set up a website for worried customers to check if they had been affected – equifaxsecurity2017.com – rather than setting it up on the equifax.com domain. As a bit of fun security researcher Nick Sweeting Read more about Equifax fooled again! Blundering credit biz directs hack attack victims to parody site[…]

Ccleaner infection: what happened? Turns out it was targeting companies & had been running for longer than thought

Ccleaner v5.33, software that allows you to clean up the cruft that comes with use and with newly installed machines, was infected with Floxif malware which installed itself on peoples machines together with the ccleaner. Floxif is a malware downloader that gathers information about infected systems and sends it back to its Command & Control Read more about Ccleaner infection: what happened? Turns out it was targeting companies & had been running for longer than thought[…]

SEC’s EDGAR database hacked, hackers use data for insider trading.

In August 2017, the Commission learned that an incident previously detected in 2016 may have provided the basis for illicit gain through trading. Specifically, a software vulnerability in the test filing component of the Commission’s EDGAR system, which was patched promptly after discovery, was exploited and resulted in access to nonpublic information. It is believed Read more about SEC’s EDGAR database hacked, hackers use data for insider trading.[…]

Attention adults working in the real world: Do not upgrade to iOS 11 if you use Outlook, Exchange

Apple’s latest version of iOS, namely version 11, may struggle or flat-out fail to connect to Microsoft Office and Exchange mailboxes. That’s a rather annoying pain for anyone working in a typical Windows-based work environment. The Cupertino idiot-tax operation admitted this week that iOS 11 contains a bug that potentially leaves users locked out of Read more about Attention adults working in the real world: Do not upgrade to iOS 11 if you use Outlook, Exchange[…]

Popular GO Android alternate Keyboard is spying on millions of Android users

Security researchers from Adguard have issued a warning that the popular GO Keyboard app is spying on users. Produced by Chinese developers GOMO Dev Team, GO Keyboard was found to be transmitting personal information about users back to remote servers, as well as “using a prohibited technique to download dangerous executable code.” Adguard made the Read more about Popular GO Android alternate Keyboard is spying on millions of Android users[…]

EU Paid For Report That Said Piracy Isn’t Harmful — And Tried To Hide Findings

According to Julia Reda’s blog, the only Pirate in the EU Parliament, the European Commission in 2014 paid the Dutch consulting firm Ecorys 360,000 euros (about $428,000) to research the effect piracy had on sales of copyrighted content. The final report was finished in May 2015, but was never published because the report concluded that Read more about EU Paid For Report That Said Piracy Isn’t Harmful — And Tried To Hide Findings[…]

Holdout ISPs Ziggo and XS4ALL forced to censor the web by high court in the name of – money!

The courts in the Hague has forced ISPs to block the Pirate Bay. Surprisinly they haven’t foced a block of Google and Bing, that also link to copyrighted materials. Anyhway, this is on the insistence of BREIN, who – like the RIAA – think they should be getting the income from music so that they Read more about Holdout ISPs Ziggo and XS4ALL forced to censor the web by high court in the name of – money![…]

HP pushes third-party ink blocking printer firmware update (again)

Hewlett Packard (HP) released a new firmware for the company’s Officejet printers that appears to block third-party ink from functioning correctly. The company caused quite the uproar a year ago when it released a firmware for some of its printer families that blocked non-HP cartridges in company printers. HP released a firmware update a month Read more about HP pushes third-party ink blocking printer firmware update (again)[…]

Equifax another breach: had ‘admin’ as login and password in Argentina

Cyber-crime blogger Brian Krebs said that an online employee tool used in the country could be accessed by typing “admin” as both a login and password. He added that this gave access to records that included thousands of customers’ national identity numbers. Last week, the firm revealed a separate attack affecting millions in the US. Read more about Equifax another breach: had ‘admin’ as login and password in Argentina[…]

AI’s can generate fake reviews indistinguishable from real reviews for both humans and fake review detectors

Fake reviews used to be crowdsourced. Now they can be auto-generated by AI, according to a new research paper shared by AmiMoJo: In this paper, we identify a new class of attacks that leverage deep learning language models (Recurrent Neural Networks or RNNs) to automate the generation of fake online reviews for products and services. Read more about AI’s can generate fake reviews indistinguishable from real reviews for both humans and fake review detectors[…]

Companies use software limitations to screw customers over more and more often, kill competition

What began with printers and spread to phones is coming to everything: this kind of technology has proliferated to smart thermostats (no apps that let you turn your AC cooler when the power company dials it up a couple degrees), tractors (no buying your parts from third-party companies), cars (no taking your GM to an Read more about Companies use software limitations to screw customers over more and more often, kill competition[…]

ProtonVPN: Secure and Free VPN service for protecting your privacy

We believe privacy and security are fundamental human rights, so we also provide a free version of ProtonVPN to the public. Unlike other free VPNs, there are no catches. We don’t serve ads or secretly sell your browsing history. ProtonVPN Free is subsidized by ProtonVPN paid users. If you would like to support online privacy, Read more about ProtonVPN: Secure and Free VPN service for protecting your privacy[…]

Moneyback leaks 500k tourists to Mexico customer records: passports, credit cards, IDs.

Have you been to Mexico in the last year as a tourist and applied for a tax refund on the money you spent while shopping there? If you have, chances are your passport, credit card, or other identification might have been leaked online. The Kromtech Security Research Center has discovered a misconfigured database with nearly Read more about Moneyback leaks 500k tourists to Mexico customer records: passports, credit cards, IDs.[…]

A.I. can detect the sexual orientation of a person based on one photo, research shows

The Stanford University study, which is set to be published in the Journal of Personality and Social Psychology and was first reported in The Economist, found that machines had a far superior “gaydar” when compared to humans. The machine intelligence tested in the research could correctly infer between gay and straight men 81 percent of Read more about A.I. can detect the sexual orientation of a person based on one photo, research shows[…]

Flip-flop qubits: Radical new quantum computing design invented

Tosi’s conceptual breakthrough is the creation of an entirely new type of qubit, using both the nucleus and the electron. In this approach, a qubit ‘0’ state is defined when the spin of the electron is down and the nucleus spin is up, while the ‘1’ state is when the electron spin is up, and Read more about Flip-flop qubits: Radical new quantum computing design invented[…]

DolphinAttack allows control of voice activated devices without you knowing it

Using a technique called the DolphinAttack, a team from Zhejiang University translated typical vocal commands into ultrasonic frequencies that are too high for the human ear to hear, but perfectly decipherable by the microphones and software powering our always-on voice assistants. This relatively simple translation process lets them take control of gadgets with just a Read more about DolphinAttack allows control of voice activated devices without you knowing it[…]

Amazon was tricked by a fake law firm into removing a hot product, costing this seller $200,000

Shortly before Amazon Prime Day in July, the owner of the Brushes4Less store on Amazon’s marketplace received a suspension notice for his best-selling product, a toothbrush head replacement. The email that landed in his inbox said the product was being delisted from the site because of an intellectual property violation. In order to resolve the Read more about Amazon was tricked by a fake law firm into removing a hot product, costing this seller $200,000[…]

Equifax loses 143 million US, UK and Canadian customer records in data breach.

September 7, 2017 — Equifax Inc. (NYSE: EFX) today announced a cybersecurity incident potentially impacting approximately 143 million U.S. consumers. Criminals exploited a U.S. website application vulnerability to gain access to certain files. Based on the company’s investigation, the unauthorized access occurred from mid-May through July 2017. The company has found no evidence of unauthorized Read more about Equifax loses 143 million US, UK and Canadian customer records in data breach.[…]

Flat UI Elements Attract Less Attention and Cause Uncertainty

In an eyetracking experiment comparing different clickability clues, weak and flat signifiers required more user effort than strong ones. […] We conducted a quantitative experiment using eyetracking equipment and a desktop computer. We recruited 71 general web-users to participate in the experiment. Each participant was presented with one version of the 9 sites and given Read more about Flat UI Elements Attract Less Attention and Cause Uncertainty[…]

Apache REST / Struts easily exploitable through browser

Servers and data stored by dozens of Fortune 100 companies are at risk, including airlines, banks and financial institutions, and social media sites. A critical security vulnerability in open-source server software enables hackers to easily take control of an affected server — putting sensitive corporate data at risk. The vulnerability allows an attacker to remotely Read more about Apache REST / Struts easily exploitable through browser[…]

Yet another AWS config fumble: Time Warner Cable exposes 4 million subscriber records

Researchers with security company Kromtech said freelancers who handled web applications for TWC and other companies had left one of its AWS S3 storage bins containing seven years’ worth of subscriber data wide open on the ‘net. That data included addresses and contact numbers, information about their home gateways, and account settings. Just before the Read more about Yet another AWS config fumble: Time Warner Cable exposes 4 million subscriber records[…]

After years of IBAN, only 1 NL bank has just figured out how to check the name with an account.

The Rabobank has started warning users when the name doesn’t match an IBAN account. A trivial function that used to work before IBAN but apparently was so hard to implement that users have had to wait for years to get. If you put in the wrong number – then sorry, you were screwed! Now for Read more about After years of IBAN, only 1 NL bank has just figured out how to check the name with an account.[…]