Security

World's Single-Biggest Ransomware Attack Hit 'Thousands' in 17 Countries (apnews.com) 142

It's now being called "the single biggest global ransomware attack on record," with thousands of victims in at least 17 different countries breached with ransomware Friday, reports the Associated Press, citing new details provided by cybersecurity researchers.

An affiliate of the Russia-linked gang REvil deployed the ransomware "largely through firms that remotely manage IT infrastructure for multiple customers." A broad array of businesses and public agencies were hit by the latest attack, apparently on all continents, including in financial services, travel and leisure and the public sector — though few large companies, the cybersecurity firm Sophos reported... The Swedish grocery chain Coop said most of its 800 stores would be closed for a second day Sunday because their cash register software supplier was crippled. A Swedish pharmacy chain, gas station chain, the state railway and public broadcaster SVT were also hit. In Germany, an unnamed IT services company told authorities several thousand of its customers were compromised, the news agency dpa reported...

CEO Fred Voccola of the breached software company, Kaseya, estimated the victim number in the low thousands, mostly small businesses like "dental practices, architecture firms, plastic surgery centers, libraries, things like that." Voccola said in an interview that only between 50-60 of the company's 37,000 customers were compromised. But 70% were managed service providers who use the company's hacked VSA software to manage multiple customers. It automates the installation of software and security updates and manages backups and other vital tasks...

Dutch researchers said they alerted Miami-based Kaseya to the breach and said the criminals used a "zero day," the industry term for a previously unknown security hole in software. Voccola would not confirm that or offer details of the breach — except to say that it was not phishing. "The level of sophistication here was extraordinary," he said. When the cybersecurity firm Mandiant finishes its investigation, Voccola said he is confident it will show that the criminals didn't just violate Kaseya code in breaking into his network but also exploited vulnerabilities in third-party software...

Kaseya, which called on customers Friday to shut down their VSA servers immediately, said Sunday it hoped to have a patch in the next few days.

The attacks may have been timed to exploit America's three-day weekend celebrating the nation's founding, according to experts interviewed by the Associated Press. America's National Security advisor is now urging all who believed they were compromised to alert the FBI.

"The attack comes less than a month after Biden pressed Russian President Vladimir Putin to stop providing safe haven to REvil and other ransomware gangs whose unrelenting extortionary attacks the U.S. deems a national security threat."

UPDATE: Bleeping Computer notes the exploited vulnerability "had been previously disclosed to Kaseya by security researchers from the Dutch Institute for Vulnerability Disclosure (DIVD), and Kaseya was validating the patch before they rolled it out to customers."

In a statement today, DIVD posted that "During the last 48 hours, the number of Kaseya VSA instances that are reachable from the internet has dropped from over 2,200 to less than 140 in our last scan today... A good demonstration of how a cooperative network of security-minded organizations can be very effective during a nasty crisis."
Facebook

Facebook Rises After Lawsuit Dismissal, Hits $1 Trillion Value (cnbc.com) 49

Facebook shares posted their biggest intraday gain in two months after it won a dismissal of two antitrust cases, pushing its market value above $1 trillion for the first time. The social-media giant jumped as much as 4.4%, the most since April 29 after a judge granted Facebook's request to dismiss the complaints filed last year by the U.S. Federal Trade Commission and state attorneys general. Reader phalse phace writes: A federal court on Monday dismissed the Federal Trade Commission's antitrust complaint against Facebook, dealing a major setback for the agency's complaint that could have resulted in Facebook divesting Instagram and WhatsApp.

"Although the Court does not agree with all of Facebook's contentions here, it ultimately concurs that the agency's complaint is legally insufficient and must therefore be dismissed," reads the filing from U.S. District Court for the District of Columbia. "The FTC has failed to plead enough facts to plausibly establish a necessary element of all of its Section 2 claims -- namely, that Facebook has monopoly power in the market for Personal Social Networking (PSN) Services." The court dismissed the complaint, not the case, meaning the FTC could file its complaint once again.

China

Scholars on LinkedIn Are Being Blocked in China 'Without Telling Them Why' (wsj.com) 62

Affected users say social-networking site owned by Microsoft is obstructing them over 'prohibited content' without further explanation. From a report: Eyck Freymann, an Oxford University doctoral student, was surprised to get a notice from LinkedIn this month telling him his account had been blocked in China. The "Experience" section of his profile, which detailed his career history, contained "prohibited" content, he was informed. The social-networking site owned by Microsoft didn't explain more, but Mr. Freymann said he thought it was because he had included the words "Tiananmen Square massacre" in the entry for his two-year stint as a research assistant for a book in 2015. "LinkedIn is pulling people's material off without telling them why," he said. "It was surprising because I am just a graduate student. I didn't think I would have mattered."

The academic is one of a spate of LinkedIn users whose profiles have been blocked in recent weeks. The Wall Street Journal identified at least 10 other individuals who had their profiles blocked or posts removed from the China version of LinkedIn since May, including researchers in Jerusalem and Tokyo, journalists, a U.S. congressional staffer and an editor based in Beijing who posted state media reports about elephants rampaging across China. A LinkedIn spokeswoman said in a statement that while the company supports freedom of expression, offering a localized version of LinkedIn in China means adherence to censorship requirements of the Chinese government on internet platforms. The company didn't comment on whether its actions were proactive or in response to requests from Chinese authorities. LinkedIn made a trade-off to accept Chinese censorship when it entered China in 2014 and has typically censored human-rights activists and deleted content focused on posts deemed sensitive to the Chinese government. The recent dragnet stands out for having caught several academics in its path, resulting in the deletion of entire profiles instead of individual posts.

Social Networks

A Real Estate Mogul Will Spend $100 Million to Fix Social Media Using Blockchain (msn.com) 93

"Frank McCourt, the billionaire real estate mogul and former owner of the Los Angeles Dodgers, is pouring $100 million into an attempt to rebuild the foundations of social media," reports Bloomberg: The effort, which he has loftily named Project Liberty, centers on the construction of a publicly accessible database of people's social connections, allowing users to move records of their relationships between social media services instead of being locked into a few dominant apps.

The undercurrent to Project Liberty is a fear of the power that a few huge companies — and specifically Facebook Inc. — have amassed over the last decade... Project Liberty would use blockchain to construct a new internet infrastructure called the Decentralized Social Networking Protocol. With cryptocurrencies, blockchain stores information about the tokens in everyone's digital wallets; the DSNP would do the same for social connections. Facebook owns the data about the social connections between its users, giving it an enormous advantage over competitors. If all social media companies drew from a common social graph, the theory goes, they'd have to compete by offering better services, and the chance of any single company becoming so dominant would plummet.

Building DSNP falls to Braxton Woodham, the co-founder of the meal delivery service Sun Basket and former chief technology officer of Fandango, the movie ticket website... McCourt hired Woodham to build the protocol, and pledged to put $75 million into an institute at Georgetown University in Washington, D.C., and Sciences Po in Paris to research technology that serves the common good. The rest of his $100 million will go toward pushing entrepreneurs to build services that utilize the DSNP...

A decentralized approach to social media could actually undermine the power of content moderation, by making it easier for users who are kicked off one platform to simply migrate their audiences to more permissive ones. McCourt and Woodham say blockchain could discourage bad behavior because people would be tied to their posts forever...

Eventually, the group plans to create its own consumer product on top of the DSNP infrastructure, and wrote in a press release that the eventual result will be an "open, inclusive data economy where individuals own, control and derive greater social and economic value from their personal information."

Privacy

Supreme Court Revives LinkedIn Bid To Shield Personal Data 38

The U.S. Supreme Court on Monday gave Microsoft's LinkedIn another chance to try to stop rival hiQ Labs from harvesting personal data from the professional networking platform's public profiles -- a practice that LinkedIn contends threatens the privacy of its users. From a report: The justices threw out a lower court ruling that had barred LinkedIn from denying hiQ access to the information that LinkedIn members had made publicly available. At issue is whether companies can use a federal anti-hacking law called the Computer Fraud and Abuse Act, which prohibits accessing a computer without authorization, to block competitors from harvesting or "scraping" vast amounts of customer data from public-facing parts of a website. The justices sent the dispute back to the San Francisco-based 9th U.S. Circuit Court of Appeals to reconsider in light of their June 4 ruling that limited the type of conduct that can be criminally prosecuted under the same law. In that case, the justices found that a person cannot be guilty of violating that law if they misuse information on a computer that they have permission to access.
Facebook

Facebook Accounts For Over Half of Sex Trafficing Recruitment (cbsnews.com) 135

An anonymous reader quotes a report from CBS News: The majority of online recruitment in active sex trafficking cases in the U.S. last year took place on Facebook, according to the Human Trafficking Institute's 2020 Federal Human Trafficking Report. "The internet has become the dominant tool that traffickers use to recruit victims, and they often recruit them on a number of very common social networking websites," Human Trafficking Institute CEO Victor Boutros said on CBSN Wednesday. "Facebook overwhelmingly is used by traffickers to recruit victims in active sex trafficking cases." In 2020 in the U.S., 59% of online recruitment of identified victims in active cases took place on Facebook alone. The report also states that 65% of identified child sex trafficking victims recruited on social media were recruited through Facebook. The tech giant responded to the report's findings in a statement to CBS News: "Sex trafficking and child exploitation are abhorrent and we don't allow them on Facebook. We have policies and technology to prevent these types of abuses and take down any content that violates our rules."
Cloud

Coalition Including Microsoft, Linux Foundation, GitHub Urge Green Software Development (bloombergquint.com) 136

"To help realize the possibility of carbon-free applications, Microsoft, the consultancies Accenture and ThoughtWorks, the Linux Foundation, and Microsoft-owned code-sharing site, GitHub, have launched The Green Software Foundation," reports ZDNet: Announced at Microsoft's Build 2021 developer conference, the foundation is trying to promote the idea of green software engineering - a new field that looks to make code more efficient and reduce carbon emitted from the hardware it's running on... The foundation wants to set standards, best practices and patterns for building green software; nurture the creation of trusted open-source and open-data projects and support academic research; and grow an international community of green software ambassadors. The goal is to help the Information and Communication Technology sector to reduce its greenhouse gas emissions by 45% before 2030.

That includes mobile network operators, ISPs, data centers, and all the laptops being snapped up during the pandemic. "We envision a future where carbon-free software is standard - where software development, deployment, and use contribute to the global climate solution without every developer having to be an expert," Erica Brescia, COO of GitHub said in a statement. Microsoft president Brad Smith said "the world confronts an urgent carbon problem."

"It will take all of us working together to create innovative solutions to drastically reduce emissions. Microsoft is joining with organizations who are serious about an environmentally sustainable future to drive adoption of green software development to help our customers and partners around the world reduce their carbon footprint."

VentureBeat also points out that Microsoft "recently launched a $1 billion Climate Innovation Fund to accelerate the global development of carbon reduction, capture, and removal technologies."

But Bloomberg explores the rationale behind the new foundation: Data centers now account for about 1% of global electricity demand, and that's forecast to rise to 3% to 8% in the next decade, the companies said in a statement Tuesday, timed to Microsoft's Build developers conference... While it's tough to determine exactly how much carbon is emitted by individual software programs, groups like the Green Software Foundation examine metrics such as how much electricity is needed, whether microprocessors are being used efficiently, and the carbon emitted in networking. The foundation plans to look at curricula and developing certifications that would give engineers expertise in this space. As with areas like data science and cybersecurity, there will be an opportunity for engineers to specialize in green software development, but everyone who builds software will need at least some background in it, said Jeff Sandquist, a Microsoft vice president for developer relations.

"This will be the responsibility of everybody on the development team, much like when we look at security, or performance or reliability," he said. "Building the application in a sustainable way is going to matter."

Operating Systems

Linux 5.13 Reverts and Fixes Problematic University of Minnesota Patches (phoronix.com) 38

An anonymous reader shares a report: One month ago the University of Minnesota was banned from contributing to the Linux kernel when it was revealed the university researchers were trying to intentionally submit bugs into the kernel via new patches as "hypocrite commits" as part of a questionable research paper. Linux kernel developers have finally finished reviewing all UMN.edu patches to address problematic merges to the kernel and also cleaning up / fixing their questionable patches. Sent in on Thursday by Greg Kroah-Hartman was char/misc fixes for 5.13-rc3. While char/misc fixes at this mid-stage of the kernel cycle tend to not be too exciting, this pull request has the changes for addressing the patches from University of Minnesota researchers. [...] Going by the umn.edu Git activity that puts 37 patches as having been reverted with this pull request. The reverts span from ALSA to the media subsystem, networking, and other areas. That is 37 reverts out of 150+ patches from umn.edu developers over the years.
Microsoft

Microsoft's LinkedIn Accused by Noted China Critic of Censorship (bloomberg.com) 67

A prominent critic of China based in the U.K. said Microsoft's LinkedIn froze his account and removed content criticizing the country's government, the latest in a series of allegations that the networking website had censored users -- even outside of the Asian nation -- to appease authorities in Beijing. From a report: Peter Humphrey, a British corporate investigator and former journalist who accesses LinkedIn from his home in Surrey, England, said he received notification from LinkedIn last month that comments he had published on the platform had been removed. The comments, seen by Bloomberg News, called the Chinese government a "repressive dictatorship" and criticized the country's state media organizations as "propaganda mouthpieces."

In late April, Humphrey said LinkedIn sent him several notifications that critical comments he posted about China's government and state-controlled broadcaster China Global Television Network, or CGTN, had been removed, on the grounds that the comments constituted "bullying and harassment" or "spam and scams." On April 26, Humphrey said he couldn't access his LinkedIn profile. When Humphrey tried to log in, he said he was met with a message stating his profile had been "restricted" due to "behavior that appears to violate our Terms of Service." After Bloomberg News contacted LinkedIn for comment last week, the company reinstated Humphrey's account and restored some of his comments. Others were not. "Our team has reviewed the action, based on our appeals process, and found it was an error," said Leonna Spilman, a spokeswoman for LinkedIn. Spilman declined to comment further regarding Humphrey's account.

Wireless Networking

Tech Industry Quietly Patches FragAttacks Wi-Fi Flaws That Leak Data, Weaken Security (theregister.com) 37

An anonymous reader quotes a report from The Register: A dozen Wi-Fi design and implementation flaws make it possible for miscreants to steal transmitted data and bypass firewalls to attack devices on home networks, according to security researcher Mathy Vanhoef. On Tuesday, Vanhoef, a postdoctoral researcher in computer security at New York University Abu Dhabi, released a paper titled, "Fragment and Forge: Breaking Wi-Fi Through Frame Aggregation and Fragmentation" [PDF]. Scheduled to be presented later this year at the Usenix Security conference, the paper describes a set of wireless networking vulnerabilities, including three Wi-Fi design flaws and nine implementation flaws. Vanhoef, who in 2017 along with co-author Frank Piessens identified key reinstallation attacks (KRACKs) on the WPA2 protocol (used to secure Wi-Fi communication), has dubbed his latest research project FragAttacks, which stands for fragmentation and aggregation attacks.

The dozen vulnerabilities affect all Wi-Fi security protocols since the wireless networking technology debuted in 1997, from WEP up through WPA3. [...] In total, 75 devices -- network card and operating system combinations (Windows, Linux, Android, macOS, and iOS) -- were tested and all were affected by one or more of the attacks. NetBSD and OpenBSD were not affected because they don't support the reception of A-MSDUs (aggregate MAC service data units). [...]

Patches for many affected devices and software have already been deployed, thanks to a nine-month-long coordinated responsible disclosure overseen by the Wi-Fi Alliance and the Industry Consortium for Advancement of Security on the Internet (ICASI). Linux patches have been applied and the kernel mailing list note mentions that Intel has addressed the flaws in a recent firmware update without mentioning it. Microsoft released its patches on March 9, 2021 when disclosure was delayed tho Redmond had already committed to publication. Vanhoef advises checking with the vendor(s) of Wi-Fi devices about whether the FragAttacks have been addressed. "[F]or some devices the impact is minor, while for others it's disastrous," he said.

Hardware

'Despite Chip Shortage, Chip Innovation Is Booming' (nytimes.com) 33

The New York Times reports on surprising silver linings of the global chip shortage: Even as a chip shortage is causing trouble for all sorts of industries, the semiconductor field is entering a surprising new era of creativity, from industry giants to innovative start-ups seeing a spike in funding from venture capitalists that traditionally avoided chip makers. Taiwan Semiconductor Manufacturing Company and Samsung Electronics, for example, have managed the increasingly difficult feat of packing more transistors on each slice of silicon. IBM on Thursday announced another leap in miniaturization, a sign of continued U.S. prowess in the technology race. Perhaps most striking, what was a trickle of new chip companies is now approaching a flood.

Equity investors for years viewed semiconductor companies as too costly to set up, but in 2020 plowed more than $12 billion into 407 chip-related companies, according to CB Insights. Though a tiny fraction of all venture capital investments, that was more than double what the industry received in 2019 and eight times the total for 2016. Synopsys, the biggest supplier of software that engineers use to design chip, is tracking more than 200 start-ups designing chips for artificial intelligence, the ultrahot technology powering everything from smart speakers to self-driving cars. Cerebras, a start-up that sells massive artificial-intelligence processors that span an entire silicon wafer, for example, has attracted more than $475 million. Groq, a start-up whose chief executive previously helped design an artificial-intelligence chip for Google, has raised $367 million.

"It's a bloody miracle," said Jim Keller, a veteran chip designer whose resume includes stints at Apple, Tesla and Intel and who now works at the A.I. chip start-up Tenstorrent. "Ten years ago you couldn't do a hardware start-up...."

More companies are concluding that software running on standard Intel-style microprocessors is not the best solution for all problems. For that reason, companies like Cisco Systems and Hewlett Packard Enterprise have long designed specialty chips for products such as networking gear. Giants like Apple, Amazon and Google more recently have gotten into the act. Google's YouTube unit recently disclosed its first internally developed chip to speed video encoding.

And Volkswagen even said last week that it would develop its own processor to manage autonomous driving.

Windows

Microsoft Is Finally Ditching Its Windows 95-Era Icons (theverge.com) 108

Microsoft is now planning to refresh the Windows 95-era icons you still sometimes come across in Windows 10. The Verge reports: Windows Latest has spotted new icons for the hibernation mode, networking, memory, floppy drives, and much more as part of the shell32.dll file in preview versions of Windows 10. This DLL is a key part of the Windows Shell, which surfaces icons in a variety of dialog boxes throughout the operating system. It's also a big reason why Windows icons have been so inconsistent throughout the years. Microsoft has often modernized other parts of the OS only for an older app to throw you into a dialog box with Windows 95-era icons from shell32.dll. Hopefully this also means Windows will never ask you for a floppy disk drive when you dig into Device Manager to update a driver. That era of Windows, along with these old icons, has been well and truly over for more than a decade now. These new changes are part of Microsoft's design overhaul to Windows 10, codenamed Sun Valley. "We're expecting to hear more about Sun Valley at Microsoft's Build conference later this month, or as part of a dedicated Windows news event," notes The Verge.
The Courts

Humble Bundle Creator Brings Antitrust Lawsuit Against Valve Over Steam (arstechnica.com) 90

Indie developer (and Humble Indie Bundle originator) Wolfire Games has filed a proposed class-action lawsuit against Steam creator Valve, saying that the company is wielding Steam's monopoly power over the PC gaming market to extract "an extraordinarily high cut from nearly every sale that passes through its storeâ"30%." Ars Technica reports: The lawsuit, filed in a Washington state federal court, centers on what it considers an illegal tying of the Steam gaming platform (which provides game library management, social networking, achievement tracking, Steam Workshop mods, etc.) and the Steam game store (which processes online payments and delivers a copy of the game). After years of growth, the vast majority of PC gamers are locked into the Steam platform thanks to "immense network effects" and the high switching costs to move to a new PC platform, the suit argues. That makes the platform "a must-have for game publishers," who need access to the players on Steam to succeed. But games that use the Steam platform also have to be sold on the Steam Store, where Valve takes its 30 percent cut of all sales. By leveraging its monopoly platform power into a "gatekeeper role" for the store, Valve "wield[s] extreme power over publishers of PC Desktop Games" that leads to a "small but significant and non-transitory increase in price" for developers compared to a truly competitive market, the suit argues.

The suit includes a laundry list of competitors that have tried to create their own platforms to take on Steam's monopoly, including CD Projekt Red, EA, Microsoft, Amazon, and Epic (not to mention "pure distributors" with platform-free stores like GameStop, Green Man Gaming, Impulse, and Direct2Drive). But the lawsuit argues that Steam's lock-in effects mean none of these stores have been able to make much of a dent in Valve's monopoly position, despite plenty of well-funded attempts. Even the Epic Games Store, which has spent hundreds of millions of dollars securing exclusives and free game giveaways, has a market share of only "a little above 2 percent," according to one cited analysis (in an interview last June, Epic's Tim Sweeney estimated a more robust 15 percent market share for EGS).

"The failure of these companies to meaningfully compete against the Steam Gaming Platform shows it is virtually impossible as an economic matter to compete against the Steam Gaming Platform," the suit argues. "The Steam Gaming Platform has well-cemented dominance in the PC Desktop Gaming Platform Market, and given its unique and strong network effects, that is unlikely to change." The only meaningful way to avoid [Valve's] anticompetitive measures, the suit argues, is "to avoid using the Steam Gaming Platform at all." But Valve's monopoly position means that "there are no economically viable alternatives to the Steam Gaming Platform" for most PC games. While the suit acknowledges a few counterexamples (Riot's League of Legends is cited by name), such titles "typically require a long history of recognition and success before they can attempt to thrive without the Steam Gaming Platform," the suit says.

IT

Mighty's Plan To Reignite the Future of Desktop Computing (mightyapp.com) 219

New submitter oblom writes about Mighty, a new approach to web browsing: In short, server-side web navigation, with client-side rendering. Per Y Combinator founder Paul Graham: "Usually when people talk about grand things like changing "the future of computing," they're full of it. But not this time. Suhail [founder of Mighty] has been working on this for 2 years. There's a good chance it's the new default infrastructure. Suhail writes in a blog post: After 2 years of hard work, we've created something that's indistinguishable from a Google Chrome that runs at 4K, 60 frames a second, takes no more than 500 MB of RAM, and often less than 30% CPU with 50+ tabs open. This is the first step in making a new kind of computer. [...] When you switch to Mighty, it will feel like you went out and bought a new computer with a much faster processor and much more memory. But you don't have [to] buy a new computer. All you have to do is download a desktop app.

To make Mighty work, we had to solve a lot of complex engineering problems, including designing a custom server to keep costs low, building a custom low-latency networking protocol, forking Chromium to integrate directly with various low-level render/encoder pipelines, and making the software interoperate with a long list of macOS features. We are working hard at ramping up server capacity across the world as we roll it out to users. You might be thinking: "Yeah but what about the lag?" Lag would have been a real problem 5 years ago, but new advances since then have allowed us to eliminate nearly all of it: 5 Ghz WiFi bands, H.265 hardware-accelerated low-latency encoders, widespread 100 Mbps Internet, and cheaper, more powerful GPUs. We also designed a new low-latency network protocol, and we locate servers as close to users geographically as possible. As a result, a user with 100 Mbps internet will rarely notice lag while using Mighty. Watch this demo video and see for yourself.

Google

4chan Founder Chris 'Moot' Poole Has Left Google (cnbc.com) 91

Chris Poole, who founded controversial online community 4chan before joining Google in 2016, has left the search giant after jumping among several groups within the company, CNBC has learned. From the report: Poole's last official day at Google was April 13th, according to an internal repository viewed by CNBC, which described his last role as a product manager. Oftentimes, employee shares attached to hiring vest at the five-year mark, though it's unclear if that's a reason for Poole's departure now. Poole, who goes by the moniker "Moot," founded 4chan in 2003 at age 15. It grew into one of the most influential and controversial online communities to date. Rolling Stone famously called him a boy-genius and the "Mark Zuckerberg of the online underground." [...]

Poole revealed in 2016 that he'd joined Google as a continuation of his work, and in a now-removed post, stated he'd use his "experience from a dozen years of building online communities" and "grow in ways one simply cannot on their own." He joined as product manager in the photos and streams unit, which oversaw social networking efforts under VP Bradley Horowitz at the time. That sparked speculation that the company hired him to help it revamp its social media ambitions, some of which aimed to compete with Facebook. Poole jumped between several different roles during his five years. At one point, he reportedly became a partner at Google's in-house start-up incubator, Area 120, which was just getting off the ground in 2016. He then became a product manager in Google's Maps division, according to Crunchbase.

Unix

FreeBSD 13 Released (phoronix.com) 66

"FreeBSD, the other Linux, reached version 13," writes long-time Slashdot reader undoman. "The operating system is known for its stable code, native ZFS support, and use of the more liberal BSD licenses." Phoronix highlights some of the major new improvements: FreeBSD 13.0 delivers on performance improvements (particularly for Intel CPUs we've seen in benchmarks thanks to hardware P-States), upgrading to LLVM Clang 11 as the default compiler toolchain, POWER 64-bit support improvements, a wide variety of networking improvements, 64-bit ARM (AArch64) now being a tier-one architecture alongside x86_64, EFI boot improvements, AES-NI is now included by default for generic kernel builds, the default CPU support for i386 is bumped to i686 from i486, and a variety of other hardware support improvements. Various obsolete GNU tools have been removed like an old version of GNU Debugger used for crashinfo, obsolete GCC 4.2.1 and Binutils 2.17 were dropped from the main tree, and also switching to a BSD version of grep. The release announcement can be found here.
Security

NAME:WRECK Vulnerabilities Impact Millions of Smart and Industrial Devices (therecord.media) 21

Catalin Cimpanu, reporting at Record: Security researchers have found a new set of vulnerabilities that impact hundreds of millions of servers, smart devices, and industrial equipment. Called NAME:WRECK, the vulnerabilities have been discovered by enterprise IoT security firm Forescout as part of its internal research program named Project Memoria -- which the company describes as "an initiative that aims at providing the cybersecurity community with the largest study on the security of TCP/IP stacks." Although never visible to end-users, TCP/IP stacks are libraries that vendors add to their firmware to support internet connectivity and other networking functions for their devices. These libraries are very small but, in most cases, underpin the most basic functions of a device, and any vulnerability here exposes users to remote attacks. The NAME:WRECK research is the fifth set of vulnerabilities impacting TCP/IP libraries that have been disclosed over the past three years, and the third set disclosed part of Project Memoria.
Intel

Intel CEO Calls for 'Moonshot' To Boost US Role in Chipmaking (axios.com) 143

Intel CEO Pat Gelsinger called Monday for the U.S. to spend billions of dollars over the next few years as part of a "moonshot" designed to regain lost ground in semiconductor manufacturing. The goal, he said, is to see the U.S. again account for a third of global output, up from about 12% today. From a report: Investments made now will take several years to bear fruit, so they won't do much to ease the current semiconductor shortage, but are vital to America's long-term economic future and national security, Gelsinger told Axios on Monday. The White House met with tech leaders in a virtual summit on Monday discussing the need for investment in chip manufacturing. With demand for broad categories of chips exceeding supply, makers of everything from cars to computers and networking gear are having to slow factories and cut output. Automakers have been hit especially hard. At the very leading edge, the vast majority of chip production today is done in Taiwan, an island that remains imperiled by China's longstanding claims. "I would argue the most important building block for our economic livelihood and every aspect of human life is now increasingly not in our control," Gelsinger told Axios in an interview after the White House meeting.
Facebook

FTC Urges Courts Not To Dismiss Facebook Antitrust Case (arstechnica.com) 9

The Federal Trade Commission has urged a federal judge in DC to reject Facebook's request to dismiss the FTC's high-stakes antitrust lawsuit. In a 56-page legal brief, the FTC reiterated its arguments that Facebook's profits have come from years of anticompetitive conduct. From a report: "Facebook is one of the largest and most profitable companies in the history of the world," the FTC wrote. "Facebook reaps massive profits from its [social networking] monopoly, not by offering a superior or more innovative product because it has, for nearly a decade, taken anticompetitive actions to neutralize, hinder, or deter would-be competitors." The FTC's case against Facebook focuses on two blockbuster acquisitions that Facebook made early in the last decade. In 2012, Facebook paid $1 billion for the fast-growing startup Instagram. While Instagram the company was still tiny -- it had only about a dozen employees at the time of the acquisition -- it had millions of users and was growing rapidly. Mark Zuckerberg realized it could grow into a serious rival for Facebook, and the FTC alleges Zuckerberg bought the company to prevent that from happening.
Wireless Networking

Broadband Use Surged More Than 30% During Pandemic (cnet.com) 13

Broadband use surged 30% to 40% during the COVID-19 pandemic in the US, and even reached 60% in some areas, an industry group has concluded. CNET reports: The Broadband Internet Technical Advisory Group released data this week that it gathered from internet service providers, broadband analytics firms, and networking companies that help deliver data. We all consumed more downstream data -- the flow from the internet to the home -- but upstream use grew faster. That's an important consideration given that most cable and DSL services offer much higher downstream capacity. All those videoconferences for work meetings and online schooling likely were involved in the upstream data traffic. "Some networks saw more than 300% increase in the amount of video conferencing traffic from February to October 2020," the report said.

Though the internet itself held up well overall, there are problems. "Rural and low-income households have struggled" with broadband access to online services, the report said, and some households suffered with older equipment that couldn't handle heavy traffic or the increase in networked devices in the home. If you're having problems at home, you should consider an Ethernet cable connection to your network router, upgrading to a mesh network with multiple network access points, upgrading your PC or phone, or paying for a faster internet connection if it's available.

Slashdot Top Deals