Slashdot

Subskrybuj zawartość Slashdot
News for nerds, stuff that matters
Zaktualizowano: 4 lata 14 tygodni temu

Tether Cuts Commercial Paper, Boosts Treasuries Behind USDT

Czw, 2022-05-19 21:01
Tether, the operator of the world's most used cryptocurrency, said it had reduced the amount of commercial paper in the reserve backing its $74 billion stablecoin, revealing information about its holdings while dollar-pegged assets face tougher scrutiny from regulators. From a report: Tether Holdings had assets totaling at least $82.4 billion as of March 31, along with $82.2 billion in liabilities relating to the digital tokens it issues, according to an assurance from Cayman Islands-based MHA Cayman. Tether is the issuer of USDT, a stablecoin which relies on a reserve of US dollar and dollar-equivalent assets to maintain a one-to-one peg with the currency. The quality of those reserves have previously been called into question for an over-reliance on assets with limited liquidity, with criticism levied at Tether over its lack of transparency on the matter. The crypto company was brought under an intense spotlight over the last week following the collapse of algorithmic stablecoin Terra, which briefly knocked USDT off its peg with the dollar during a period of mass market instability. In a statement on Thursday, Tether noted a 17% decrease in its commercial paper holdings to $20.1 billion compared to the previous quarter, and added that it had completed a further 20% reduction on that amount since April 1, which will be included in its upcoming report for the second quarter. Conversely, Tether said it had increased its investments in money market funds and US Treasury bills, rising more than 13% to a total of $39.2 billion. The average rating of its commercial paper and certificates of deposit has increased from A-2 to A-1, it added, while secured loans have decreased by $1 billion.

Read more of this story at Slashdot.

Microsoft Relaxes Cloud Terms To Avoid Full EU Antitrust Probe

Czw, 2022-05-19 20:25
Microsoft is relaxing business terms for its cloud computing service in an attempt to appease complaints from rivals and avoid a full antitrust probe in Brussels. Financial Times: The move follows concerns from rival cloud providers that Microsoft is using anti-competitive practices to draw customers to its Azure cloud computing platform and away from competitors. On Wednesday, Microsoft president Brad Smith said the tech giant was taking steps that were "very broad but not exhaustive" as he sought to address concerns from regulators and competitors. Smith said the changes being introduced were "grounded in feedback" he had received from multiple cloud providers across Europe. In a blog post, he wrote: "Some of the most compelling feedback for me personally came from a CEO who said that he felt that he 'was a victim of friendly fire in Microsoft's competition with Amazon.' It was hard to hear this -- but he was right." [...] Under the new terms, customers will not be forced to buy an additional licence if they have already purchased Microsoft's cloud services. These new rules only apply if the services are moved to a European cloud provider and not to US rivals such as AWS and Google's cloud services. Smith said that in its fight against AWS, which dominates the cloud market, Microsoft had overlooked the effects some of its business terms were having on its cloud provider clients.

Read more of this story at Slashdot.

Apple Shows Headset To Board in Sign of Progress on Project

Czw, 2022-05-19 19:42
Apple executives previewed its upcoming mixed-reality headset to the company's board last week, indicating that development of the device has reached an advanced stage, Bloomberg News reported Thursday, citing people with knowledge of the matter. From the report: The company's board, made up of eight independent directors and Apple Chief Executive Officer Tim Cook, convenes at least four times a year. A version of the device was demonstrated to the directors during the latest gathering, said the people, who asked not to be identified because the meeting was private. In recent weeks, Apple has also ramped up development of rOS -- short for reality operating system -- the software that will run on the headset, according to other people familiar with the work. That progress, coupled with the board presentation, suggests that the product's debut could potentially come within the next several months. The headset, which combines elements of virtual and augmented reality, is Apple's next big bet.

Read more of this story at Slashdot.

DOJ Says It Won't Prosecute White Hat Security Researchers

Czw, 2022-05-19 19:00
The Department of Justice announced today a policy shift in that it will no longer prosecute good-faith security research that would have violated the country's federal hacking law the Computer Fraud and Abuse Act (CFAA). Motherboard: The move is significant in that the CFAA has often posed a threat to security researchers who may probe or hack systems in an effort to identify vulnerabilities so they can be fixed. The revision of the policy means that such research should not face charges. "Computer security research is a key driver of improved cybersecurity," Deputy Attorney General Lisa O. Monaco said in a statement published with the announcement. "The department has never been interested in prosecuting good-faith computer security research as a crime, and today's announcement promotes cybersecurity by providing clarity for good-faith security researchers who root out vulnerabilities for the common good." The policy itself reads that "the Department's goals for CFAA enforcement are to promote privacy and cybersecurity by upholding the legal right of individuals, network owners, operators, and other persons to ensure the confidentiality, integrity, and availability of information stored in their information systems."

Read more of this story at Slashdot.

TikTok Plans Big Push Into Gaming, Conducting Tests in Vietnam

Czw, 2022-05-19 18:25
TikTok has been conducting tests so users can play games on its video-sharing app in Vietnam, part of plans for a major push into gaming, Reuters reported Thursday, citing four people familiar with the matter. From the report: Featuring games on its platform would boost advertising revenue as well as the amount of time users spend on the app -- one of the world's most popular with more than 1 billion monthly active users. TikTok, which is owned by China's ByteDance, also plans to roll out gaming more widely in Southeast Asia, the people said. That move could come as early as the third quarter, said two of them. A TikTok representative said the company has tested bringing HTML5 games, a common form of minigame, to its app through tie-ups with third-party game developers and studios such as Zynga.

Read more of this story at Slashdot.

Melvin Capital, Hedge Fund Torpedoed By the GameStop Frenzy, is Shutting Down

Czw, 2022-05-19 17:44
Melvin Capital, the hedge fund run by Gabe Plotkin that struggled with heavy losses last year as it reeled from wrong-way bets on GameStop, is shutting down, according to a letter sent to investors on Wednesday that was reviewed by The New York Times. From the report: Mr. Plotkin wrote to his investors that he had decided that the "appropriate next step" was to liquidate the fund's assets and return cash to all investors. Mr. Plotkin, who founded Melvin in 2014, also wrote that he recognized he needed to "step away from managing external capital." Mr. Plotkin, a protege of the hedge fund billionaire and New York Mets owner Steven A. Cohen, had wagered that shares GameStop, AMC Entertainment and other mall mainstays from the 1990s would fall as their businesses shrank. Instead, the stocks skyrocketed when amateur investors, coordinating via Reddit, Twitter and other social media sites and determined to outsmart big Wall Street funds, kept buying up shares and propping up their price. That caused Melvin, which started 2021 with more than $12 billion, to lose 53 percent in January, forcing it to scramble to cover its so-called short positions. It was propped up by a $2.75 billion bailout from the hedge funds Point72, run by Mr. Cohen, and Citadel, as well as fresh capital from new investors.

Read more of this story at Slashdot.

Deadlocked FCC Could Derail Biden's Digital Equity Plans

Czw, 2022-05-19 17:05
The Biden administration has charged the Federal Communications Commission with prohibiting digital discrimination -- but without a third Democratic commissioner to break the agency's partisan deadlock, those plans are in trouble. From a report: One of President Biden's key domestic priorities, improving internet access and affordability, can't advance unless the Senate confirms his FCC nominee. The Federal Communications Commission has been deadlocked at 2 Democrats and 2 Republicans since Biden took office, and his nominee for the third seat, Gigi Sohn, has been awaiting a Senate vote for months amid Republican opposition. The agency is required by the Infrastructure Investment and Jobs Act to craft rules preventing digital discrimination on broadband access. The rules would prohibit internet service providers such as Comcast or Verizon from deployment discrimination based on the income level or predominant race or ethnicity of the people living in an area. A 2020 study of internet access in Oakland, Calif., found that areas that were redlined by banks in the past -- denied loans or investment -- now have less ISP competition and fiber-based services than their wealthier counterparts. FCC Chairwoman Jessica Rosenworcel launched an inquiry in March, with support from the agency's Republicans, on how to create rules preventing digital discrimination and facilitating equal access to high-speed internet. A major question is how the agency will interpret a part of the law that says the rules should take into account issues of "technical and economic feasibility."

Read more of this story at Slashdot.

Court Rules SEC's Internal Judges Are Unconstitutional

Czw, 2022-05-19 16:25
The 5th Circuit Court of Appeals has ruled the Securities and Exchange Commission (SEC) is denying defendants their constitutional right to a jury trial by putting them in front of its own internal judges. From a report: In a 2-1 ruling, the court ruled for George Jarkesy and Patriot28 LLC, who sued the SEC in 2011 after the agency imposed a $300,000 fine and other punishments in a securities fraud case. Judge Jennifer Walker Elrod wrote in the majority opinion that the SEC violated the Seventh Amendment's right to a jury trial by bringing defendants before in-house judges and allowing the agency to "act as both prosecutor and judge." Congress also unconstitutionally delegated power to the SEC to act as a legislative body, Elrod wrote. "'We the People' are the fountainhead of all government power. Through the Constitution, the people delegated some of that power to the federal government so that it would protect rights and promote the common good," Elrod said. "But that accountability evaporates if a person or entity other than Congress exercises legislative power." In a dissenting opinion, Judge Eugene Davis disagreed, saying the right to a jury trial did not pertain to administrative proceedings and that the SEC was enforcing laws and statutes in the public interest.

Read more of this story at Slashdot.

Microsoft Tests Windows 11 Desktop Widgets With Web Search Bar

Czw, 2022-05-19 15:46
Microsoft is adding an optional web search to the Windows 11 desktop in the operating system's latest Insider Preview Build. From a report: The company describes the feature as "lightweight interactive content" -- the first, it says, of many such tools it's considering adding to Windows 11 -- but let's call the thing what it really is: a widget. Not everyone signed up to the latest Windows 11 preview build will see the new search box, but anyone who does and doesnâ(TM)t like it can disable the feature by right-clicking on the desktop, selecting "Show more options," and then toggling "Show search." If you are running the latest preview build, you'll also have to restart your computer to give the search box a chance to show up.

Read more of this story at Slashdot.

TikTokers Are Accused of Starting Forest Fires For Views

Czw, 2022-05-19 15:08
An anonymous reader shares a report: Humaira Asghar, known as "Dolly" to her 11.5 million TikTok fans, faces charges for allegedly setting a forest fire while shooting a TikTok video in Pakistan's capital city Islamabad. In the 11-second clip that has since been taken down, Asghar dramatically walks down a forested hill covered in flames in slow motion with a trending pop song that mentions "setting fire" playing in the background. The caption posted with the video shot in the Margalla Hills National Park reads, "fire erupts wherever I am." Asghar is not the only Pakistani TikToker who has been accused of setting a forest fire for views. Officials say it is an emerging trend in a country that is suffering from a record-breaking heatwave. "Young people desperate for followers are setting fire to our forests during this hot and dry season," tweeted Islamabad Wildlife Management Board chairperson Rina S Khan Satti. "These psychotic young people have to be caught and put behind bars immediately." Earlier this month, a man in Abbottabad city was arrested for intentionally starting a forest fire to use as a backdrop in his video. In another recently released video, two men are seen appearing to start a forest fire then running away from it while music plays in the background.

Read more of this story at Slashdot.

Vast Swath of US At Risk of Summer Blackouts, Regulator Warns

Czw, 2022-05-19 14:00
An anonymous reader quotes a report from NewsNation: Blackouts could plague a number of states in the U.S. this summer, regulators warn, as a combination of drought, heat, potential cyber attacks, geopolitical conflicts and supply chain problems could disrupt the power supply, according to a grim new report (PDF) from the North American Electric Reliability Corporation (NERC). The regulatory body found that large swathes of the U.S. and parts of Canada are at an elevated or high risk of energy shortfalls during the summer's hottest months. The Midwest is at especially high risk due to the retirement of older plants, which has caused a 2.3% decrease in capacity from last summer, as well as increased demand, according to NERC. In the Southwest, plummeting river levels may cripple hydropower production, the group warned, and in Texas drought-related heat events could cause extreme energy demand. A NERC map shows all states in the western half of the continental U.S., including North Dakota, South Dakota, Nebraska, Kansas, Oklahoma and Texas are at least under elevated risk of energy shortfalls, with parts of the northeastern-most states under high risk. Many states under the Midcontinent Independent System Operator (MISO), such as Arkansas, Louisiana, Michigan, Wisconsin, Iowa, Minnesota, Iowa, Illinois and Indiana are either entirely or partly at high risk. "Industry prepares its equipment and operators for challenging summer conditions. Persistent, extreme drought and its accompanying weather patterns, however, are out-of-the-ordinary and tend to create extra stresses on electricity supply and demand," said Mark Olson, NERC's manager of Reliability Assessments. "Grid operators in affected areas will need all available tools to keep the system in balance this summer."

Read more of this story at Slashdot.

Engineers Investigating NASA's Voyager 1 Telemetry Data

Czw, 2022-05-19 11:00
The engineering team with NASA's Voyager 1 spacecraft is trying to solve a mystery: The interstellar explorer is operating normally, receiving and executing commands from Earth, along with gathering and returning science data. But readouts from the probe's attitude articulation and control system (AACS) don't reflect what's actually happening onboard. NASA's Jet Propulsion Laboratory reports: The AACS controls the 45-year-old spacecraft's orientation. Among other tasks, it keeps Voyager 1's high-gain antenna pointed precisely at Earth, enabling it to send data home. All signs suggest the AACS is still working, but the telemetry data it's returning is invalid. For instance, the data may appear to be randomly generated, or does not reflect any possible state the AACS could be in. The issue hasn't triggered any onboard fault protection systems, which are designed to put the spacecraft into "safe mode" -- a state where only essential operations are carried out, giving engineers time to diagnose an issue. Voyager 1's signal hasn't weakened, either, which suggests the high-gain antenna remains in its prescribed orientation with Earth. The team will continue to monitor the signal closely as they continue to determine whether the invalid data is coming directly from the AACS or another system involved in producing and sending telemetry data. Until the nature of the issue is better understood, the team cannot anticipate whether this might affect how long the spacecraft can collect and transmit science data. Voyager 1 is currently 14.5 billion miles (23.3 billion kilometers) from Earth, and it takes light 20 hours and 33 minutes to travel that difference. That means it takes roughly two days to send a message to Voyager 1 and get a response -- a delay the mission team is well accustomed to.

Read more of this story at Slashdot.

Rocket Engine Exhaust Pollution Extends High Into Earth's Atmosphere

Czw, 2022-05-19 08:00
The American Institute of Physics reports via Phys.Org: In Physics of Fluids, researchers from the University of Nicosia in Cyprus assessed the potential impact of a rocket launch on atmospheric pollution by investigating the heat and mass transfer and rapid mixing of the combustion byproducts for altitudes up to 67 kilometers into the atmosphere. The team modeled the exhaust gases and developing plume at several altitudes along a typical trajectory of a standard present-day rocket. They did this as a prototypical example of a two-stage rocket to transport people and payloads into Earth's orbit and beyond. The researchers found the production of thermal nitrogen oxides (NOx), components of the combustion exhaust, can remain high up to altitudes with an ambient atmospheric pressure above or even slightly below the nozzles' exit pressure, i.e., below an altitude of approximately 10 km. At the same time, the emitted mass of carbon dioxide as the rocket climbs 1 kilometer in altitude in the mesosphere is equivalent to that contained in 26 cubic kilometers of atmospheric air at the same altitude. They found the impact on the atmosphere locally and momentarily in the mesosphere can be significant. While air currents will gradually transport and mix the exhaust CO2 throughout the atmosphere, eventually bringing the CO2 back down to its naturally occurring levels, the time scale over which this happens is not clear. The scientists believe a certain number of rocket launches might still exist above which mesospheric carbon dioxide could accumulate over time, thus increasing the naturally occurring levels and affecting our climate. Their results suggest that in the worst-case scenario, sufficient NOx could be produced over the time it takes the rocket to reach an altitude of 10 kilometers to pollute over 2 cubic kilometers of atmospheric air with a NOx concentration that, according to the World Health Organization, would be at a level hazardous to human health.

Read more of this story at Slashdot.

New Bluetooth Hack Can Unlock All Kinds of Devices

Czw, 2022-05-19 04:30
An anonymous reader quotes a report from Ars Technica: When you use your phone to unlock a Tesla, the device and the car use Bluetooth signals to measure their proximity to each other. Move close to the car with the phone in hand, and the door automatically unlocks. Move away, and it locks. This proximity authentication works on the assumption that the key stored on the phone can only be transmitted when the locked device is within Bluetooth range. Now, a researcher has devised a hack that allows him to unlock millions of Teslas -- and countless other devices -- even when the authenticating phone or key fob is hundreds of yards or miles away. The hack, which exploits weaknesses in the Bluetooth Low Energy standard adhered to by thousands of device makers, can be used to unlock doors, open and operate vehicles, and gain unauthorized access to a host of laptops and other security-sensitive devices. [...] [The] attack uses custom software and about $100 worth of equipment. [Sultan Qasim Khan, a principal security consultant and researcher at security firm NCC Group] has confirmed it works against the Tesla Model 3 and Model Y and Kevo smart locks marketed under the Kwikset and Weiser brand names. But he says virtually any BLE device that authenticates solely on proximity -- as opposed to also requiring user interaction, geolocation querying, or something else -- is vulnerable. "The problem is that BLE-based proximity authentication is used in places where it was never safe to do so," he explained. "BLE is a standard for devices to share data; it was never meant to be a standard for proximity authentication. However, various companies have adopted it to implement proximity authentication." Because the threat isn't caused by a traditional bug or error in either the Bluetooth specification or an implementation of the standard, there's no CVE designation used to track vulnerabilities. Khan added: "In general, any product relying on BLE proximity authentication is vulnerable if it does not require user interaction on the phone or key fob to approve the unlock and does not implement secure ranging with time-of-flight measurement or comparison of the phone/key fob's GPS or cellular location relative to the location of the device being unlocked. GPS or cellular location comparison may also be insufficient to prevent short distance relay attacks (such as breaking into a home's front door or stealing a car from the driveway, when the owner's phone or key fob is inside the house)." There's a few countermeasures one can take to mitigate this attack. "One mechanism is to check the location of the authenticating device to ensure that it is, in fact, physically close to the locked car or other device," reports Ars. "Another countermeasure is to require the user to provide some form of input to the authenticating device before it's trusted." The phone's accelerometer could also be used to measure its movements. The advisories published by NCC Group can be found here, here, and here.

Read more of this story at Slashdot.

Solar-Powered Desalination Device Wins MIT $100K Competition

Czw, 2022-05-19 03:02
The winner of this year's MIT $100K Entrepreneurship Competition is commercializing a new water desalination technology. MIT News reports: Nona Desalination says it has developed a device capable of producing enough drinking water for 10 people at half the cost and with 1/10th the power of other water desalination devices. The device is roughly the size and weight of a case of bottled water and is powered by a small solar panel. The traditional approach for water desalination relies on a power-intensive process called reverse osmosis. In contrast, Nona uses a technology developed in MIT's Research Laboratory of Electronics that removes salt and bacteria from seawater using an electrical current. "Because we can do all this at super low pressure, we don't need the high-pressure pump [used in reverse osmosis], so we don't need a lot of electricity," says Crawford, who co-founded the company with MIT Research Scientist Junghyo Yoon. "Our device runs on less power than a cell phone charger." The company has already developed a small prototype that produces clean drinking water. With its winnings, Nona will build more prototypes to give to early customers. The company plans to sell its first units to sailors before moving into the emergency preparedness space in the U.S., which it estimates to be a $5 billion industry. From there, it hopes to scale globally to help with disaster relief. The technology could also possibly be used for hydrogen production, oil and gas separation, and more.

Read more of this story at Slashdot.

Older People Using TikTok To Defy Ageist Stereotypes, Research Finds

Czw, 2022-05-19 02:25
Older TikTok users are using the online platform, regarded as the virtual playground of teenagers, to defy ageist stereotypes of elderly people as technophobic and frail. The Guardian reports: Research has found increasing numbers of accounts belonging to users aged 60 and older with millions of followers. Using the platform to showcase their energy and vibrancy, these TikTok elders are rewriting expectations around how older people should behave both on and off social media. "These TikTok elders have become successful content creators in a powerful counter-cultural phenomenon in which older persons actually contest the stereotypes of old age by embracing or even celebrating their aged status," said Dr Reuben Ng, the author of the paper Not Too Old for TikTok: How Older Adults are Reframing Ageing, and an assistant professor at Yale University. Interestingly, said Ng, most TikTok elders are women who "fiercely resist common stereotypes of older women as passive, mild-mannered and weak, instead opting to present themselves as fierce or even foul-mouthed," he said. [...] The paper looked at 1,382 videos posted by TikTok users who were aged 60 or older and had between 100,000 and 5.3 million followers. In total, their videos, all of which explicitly discussed their age, had been viewed more than 3.5 billion times. Ng found that 71% of these videos -- including those from accounts such as grandadjoe1933, who has 5.3 million followers, and dolly_broadway, who has 2.4 million followers -- were used to defy age stereotypes. A recurring motif was the "glamma", a portmanteau combining "glamorous" and "grandma", with videos including those of a 70-year-old woman joyfully parading around the streets in a midriff-bearing top. Almost one in five of the videos analyzed made light of age-related vulnerabilities, and one in 10 called out ageism among both younger people and their own contemporaries. Other videos positioned older users as superior to younger people. "I may be 86 but I can still drink more than you lightweights" says one clip. "I may be 86 but I can still twerk better than you," says another, showing an octogenarian leaping up from a fall down the stairs with a twerk.

Read more of this story at Slashdot.

Netflix Customers Canceling Service Increasingly Includes Long-Term Subscribers

Czw, 2022-05-19 01:45
Netflix lost 200,000 subscribers last quarter and potentially two million this current period, according to a note to shareholders from last month. Now, new research highlights that the number of long-standing subscribers canceling Netflix rose precipitously in the past few years. 9to5Mac reports: The data provided by the research firm Antenna to The Information shows that people who had been subscribers for more than three years accounted for just 5% of total cancelations at the start of 2022, while it hit 13% in the first quarter of 2022: "Newbie subscribers, meantime, accounted for only 60% of cancellations in the quarter, down from 64% in the fourth quarter. Also in the first quarter, overall cancellations rose to 3.6 million people, compared with around 2.5 million in each of the preceding five quarters. Antenna says it draws its data from a panel of 5 million Americans who anonymously contribute their streaming subscriptions." While Netflix is losing ground, the streaming market as a whole is gaining more subscribers, and Antenna's data suggest a connection between the price increase and Netflix's subscriber losses: "'Consumers vote with their wallets on a monthly basis, and now there are just more viable candidates on the ballot,' said Brendan Brady, media and entertainment lead at Antenna. Also, since many entertainment companies, like NBCUniversal and Disney, have pulled their shows off Netflix and put them on their own services, Netflix has had to rely more on its originals, which have been hit or miss, he said."

Read more of this story at Slashdot.

Apple Reverses Remote Work Policy After Machine Learning Head Decamps To Alphabet

Czw, 2022-05-19 01:02
An anonymous reader quotes a report from Gizmodo: One of Apple's highest-profile return-to-office detractors reportedly landed a new gig at Alphabet's DeepMind, marking the latest drama over Big Tech's remote work scuffles. That move, ironically, comes right around the same time Apple decided to walk back its most recent return-to-office push. In an internal memo viewed by Bloomberg Tuesday, the company said it will delay its three-day in-office work requirement set to take effect on May 23. The memo reportedly cited the recent uptick in covid-19 cases for the delay and didn't provide any hard date for when they'd try again. Apple workers are still required to work in the office two days per week and will now have to wear masks in common areas. At the same time, Ian Goodfellow, Apple's former Director of Machine Learning, who dramatically left the company at least in part over its remote work restrictions, will reportedly join Alphabet's DeepMind. Sources told Bloomberg Goodfellow will join DeepMind as an "individual contributor." He had previously worked as a senior researcher at Google back in 2019. That job switch marks a major blow for Apple, a company that's struggled to appease workers at odds with its return to work strategy. Goodfellow, who's the most senior member known to have jumped ship over remote work so far, reportedly addressed the issue directly in a note to staff obtained by The Verge's Zoe Schiffer. "I believe strongly that more flexibility would have been the best policy for my team," Goodfellow reportedly wrote. The report notes that Alphabet hasn't fully embraced a remote-first office either, "thought previous reports suggest Google more regularly approves remote requests [than Apple]." As office returns accelerate, many workers are willing to give up their jobs over workplace flexibility. According to a survey of 1,000 U.S. adults last year, 39% said they "would consider quitting if their employers weren't flexible about remote work." That figure was 49% among millennials and Gen Z.

Read more of this story at Slashdot.

The Passwords Most Used By CEOs Are Startlingly Dumb

Czw, 2022-05-19 00:20
A recent cybersecurity report shows how immensely idiotic many CEOs and business owners can be, considering the strength of their chosen account passwords. PC Gamer reports: The research comes from NordPass password manager which identified back in 2020 that the general public's most commonly used passwords were sequential numbers like '123456', 'picture1', and yep, you guessed it: 'password'. The more recent research sample consists of 290 million cybersecurity data breaches around the globe, and denotes the job level of those affected. Turns out, when it comes to CEOs and other high-ranking businesses execs, their password choices are much the same as the general public, although many often feature names. Tiffany was spotted in 100,534 breaches; then there was Charlie with 33,699; Michael was found 10,647 times; and Jordan, 10,472 times. The report also ranks mythical creatures and animals as some of the top passwords to have been cracked in data breaches. 'Dragon' was spotted 11,926 times, and 'monkey' comes in at 11,675. I spoke to IT support engineer Ash Smith, who recommends that companies should consider handing out randomly generated passwords as new accounts are created. "Arguably the strongest passwords are 3 random words, something that you can make a story about in your head to help you remember," he says.

Read more of this story at Slashdot.

Google Messages RCS Is Being Abused For Ads In India

Śro, 2022-05-18 23:40
Over the past few weeks, Google Messages users in India have been reporting more and more ads showing up through RCS messaging. 9to5Google reports: While many brands -- even in the US and other countries -- have used messaging apps and SMS texts to advertise new products to former customers, these ads going on in India are not necessarily the result of a user's buying activity. Business messaging on RCS, as Google's Jibe website points out, is supposed to be used for things such as sending copies of your travel tickets or sending links for buying additional products based on a past purchase based on a user's request. [...] That is very much not what is happening in India right now. Brought to our attention by Ishan Argwal on Twitter, RCS ads in Google Messages appear to be coming from "Verified Business" accounts. Google first announced that functionality back in 2020, for the purposes of allowing customers to talk to businesses. Advertising was surely part of the functionality, but it's clearly being abused in India. Android Police says these ads have been going out for almost a year now, citing examples of ads sent by Kotak Mahindra Bank, Bajaj Finserv, Buddy Loan, and PolicyBazaar. From what we can tell from user reports, it appears the frequency of these ads has been picking up over the past few months especially. These ads are not harmless, either, with many of the examples we've seen being for personal loans, a category that tends to be full of predatory practices. One user reports that they were sent one of these ads on a phone that didn't even have an active SIM card in it. Currently, it seems as though this practice is primarily happening in the Indian market, at least in this quantity. What can be done about these ads in Google Messages? The solutions are all not quite ideal, unfortunately. You can report these businesses and block them from sending future messages [...]. Alternatively, you can turn off RCS features entirely within the Google Messages app.

Read more of this story at Slashdot.