Recent Posts

Pages: 1 ... 8 9 [10]
91
The affected Microsoft products include a wide range of software, encompassing Microsoft Windows, Microsoft Office, Developer Tools, Azure, Browser, System Center, Microsoft Dynamics, and Exchange Server.

In a recent announcement, the Indian Computer Emergency Response Team (CERT-In), operating under the Ministry of Electronics & Information Technology, highlighted significant vulnerabilities in various Microsoft products. These vulnerabilities pose serious risks, potentially enabling attackers to access sensitive information, bypass security measures, and even trigger denial-of-service (DoS) conditions on targeted systems.

The affected Microsoft products include a wide range of software, encompassing Microsoft Windows, Microsoft Office, Developer Tools, Azure, Browser, System Center, Microsoft Dynamics, and Exchange Server.

CERT-In cautioned that these vulnerabilities could empower attackers to exploit elevated privileges, gain access to confidential data, evade security protocols, execute remote code, perpetrate spoofing attacks, or orchestrate DoS incidents. The warning underscores the urgent need for users to take proactive measures to safeguard their systems.

Specifically addressing vulnerabilities within Microsoft Windows, CERT-In identified shortcomings in access restrictions within the proxy driver and deficiencies in the implementation of the Mark of the Web (MotW) feature as key areas of concern.

To mitigate these risks, users are strongly advised to promptly implement the necessary security updates outlined in the company's update guide. By doing so, they can effectively fortify their systems against potential threats.

In addition to the Microsoft vulnerabilities, CERT-In also alerted users to security flaws in Android and Mozilla Firefox web browsers. These vulnerabilities, if exploited, could similarly result in the unauthorized access of sensitive data, execution of arbitrary code, and initiation of DoS attacks.

According to the advisory, versions including 'Android 12, 12L, 13, 14', as well as 'Mozilla Firefox versions before 124.0.1 and Mozilla Firefox ESR versions before 115.9.1', are susceptible to these vulnerabilities.

source
92
Huawei / Huawei building vast chip equipment R&D center in Shanghai
« Last post by javajolt on April 13, 2024, 04:08:26 PM »
China tech company spending billions, snapping up talent in battle against U.S. crackdown


Huawei is spending billions on a research and development base in Shanghai as part of efforts to
counter a U.S. crackdown. (Official WeChat account of Qingpu District, Shanghai Municipality)
CHENG TING-FANG, Nikkei Asia chief tech correspondent April 11, 2024, 11:58 JST
Huawei Technologies is building a massive semiconductor equipment research and development center in Shanghai as the Chinese tech titan continues to beef up its chip supply chain to counter a U.S. crackdown.

The center's mission includes building lithography machines, and vital equipment for producing cutting-edge chips. Washington's export controls have sharply reduced Huawei's access to this equipment, whose production is dominated by just three companies: ASML of the Netherlands and Japan's Nikon and Canon.

To staff the new center, Huawei is offering salary packages worth up to twice as much as local chipmakers, industry executives and sources briefed on the matter told Nikkei Asia. The company has already hired numerous engineers who have worked with top global chip tool builders like Applied Materials, Lam Research, KLA, and ASML, they said, adding that chip industry veterans with more than 15 years of experience at leading chipmakers like TSMC, Intel and Micron are also among recent and potential hires.

Washington's tighter export controls over the past few years have also impacted the job market in China, including by making it more difficult for Chinese citizens to work for foreign chip companies in the country. This has left more top-chip talent available for Huawei and other local companies to choose from.

But while Huawei's compensation package is generous, its working culture can be challenging, according to chip industry managers.

"Working with them is brutal. It's not 996 -- meaning working from 9 a.m. to 9 p.m., six days a week. ... It will be 007 -- from midnight to midnight, seven days a week. No days off at all," one Chinese chip engineer told Nikkei Asia. "The contract will be for three years, [but] the majority of people can't survive till renewal."

Semiconductor equipment, like chips themselves, have been caught in the crosshairs of U.S. export controls. Washington has lobbied allies Japan and the Netherlands to implement similar restrictions on the export of advanced chip tools to limit China's access to them.

These restrictions have spurred many Chinese chipmakers to seek domestic alternatives wherever possible. Naura, China's leading supplier of semiconductor equipment, has seen its revenue more than quadruple since 2018 and is expected to report another record year in 2023.

Huawei, too, has responded to the U.S. crackdown by aggressively beefing up its domestic capabilities.

Its new R&D center is located in the Qingpu district of west Shanghai, sources briefed on the matter said, on a spacious campus that also houses a major chip development center and the new headquarters of HiSilicon Technologies, Huawei's chip design unit. There are also research centers for wireless technologies and smartphones on the premises.

Total investment for the entire R&D base will come to about 12 billion yuan ($1.66 billion), according to the Shanghai government, which listed it as one of the city's top projects for 2024.

The campus covers about 224 football fields in the area and is almost twice as big as the company's renowned Ox Horn Campus, a European village-style site in the Chinese city of Dongguan. Like Ox Horn, the Shanghai campus will include trains for commuting between buildings on the campus. When completed, it will be able to accommodate more than 35,000 high-tech workers, according to the People's Government of Qingpu District of Shanghai Municipality.

Huawei said it had no comments in response to Nikkei Asia's request for comment on its chip equipment efforts and referred questions about its R&D campus to the Shanghai government.


The look of Huawei's Ox Horn Campus in the Chinese city of Dongguan is modeled after a European village.
(Photo by Cheng Ting-Fang)
Huawei's R&D spending in 2023 reached a record high of 164.7 billion yuan, representing 23.4% of its total revenue.

Before the U.S. added Huawei to its trade blacklist, the company focused mainly on chip design and partnered with global production partners like TSMC and Globalfoundries for manufacturing. After its access to American technologies was curbed, Huawei turned to Chinese chipmaker SMIC and local chip developers. It is now venturing into chip production itself with partners backed by local governments in multiple Chinese cities, such as Shenzhen, Qingdao and Quanzhou, Nikkei first reported. It has also invested in many local providers of chip materials.

Huawei has been one of the most aggressive Chinese companies in terms of using local suppliers and investing in domestic alternatives, analysts say.

Brady Wang, a semiconductor analyst with Counterpoint, said Huawei has worked hard to localize its chip-related sources and switch to local components from suppliers such as BOE Technology and Omnivision. "They've invested more in HiSilicon and introduced chips for phones and servers," Wang said. "They will strive to localize a greater portion of their semiconductor supply chain. However, realizing these efforts, particularly those related to chip manufacturing and equipment, will be a time-intensive undertaking."

source
93
Do you want to use two or more operating systems on your desktop computer? Then there are three options: a parallel installation, a virtual PC, and booting from a live DVD or USB stick.


Image: IDG

Do you normally use Windows 11 and just want to have a quick look at a Linux distribution such as Linux Mint or start the computer with a rescue system to remove a malware infection, for example? Then booting the system with a live DVD or from a USB stick is a good option.

The advantage: You don’t have to install anything and no changes are made to the Windows configuration — the live system therefore leaves no traces: If you remove the DVD or USB stick, your PC will boot the permanently installed operating system, such as Windows 10 or 11, after the restart.

If, on the other hand, you want to try out Linux Mint (or another operating system) properly and also install applications, then a virtual computer may be the better choice as a first step.

A virtual computer behaves more or less like a real PC and you can even exchange data with the host (usually your Windows computer) or other devices in the network. However, as the virtual Windows or Linux guest is isolated from the host and network by default, it is primarily suitable for software tests and surfing potentially dangerous websites. Good: You can freeze the system status and return to a backup point at a later time with the click of a mouse.

Another option is the parallel installation of two or more operating systems on a hard drive or SSD, known as multiboot. After switching on the PC, you select which operating system should start in the boot manager.

This allows you to use Windows 11 and Linux Mint on an equal footing and access stored data — regardless of whether it is available locally or on a network share.

Advantages and disadvantages of virtual PCs


Hardware as desired: A virtual machine set up in VirtualBox can be reconfigured at any time, for
example, for more RAM or an additional hard disk as data storage. Image: Sam Singleton


You can learn more about virtual machine tools in our guide on the subject.

We would like to take this opportunity to explain the main advantages: Virtualization technology has been part of everyday life in company networks and data centers since the 2000s. It allows the number of dedicated computers to be reduced and the existing hardware to be optimally utilized. Many other virtual servers can run independently of each other on a host server. This saves energy and administration costs.

For home users, desktop virtualization solutions offer a sophisticated way of testing different operating systems without a large PC base, using Linux under Windows or even Windows under Linux.

But virtualization has its limits: While virtualization environments can translate the commands of the guest operating system to CPUs and memory with little loss of speed, this is not so easy with other hardware components. The graphics performance is not sufficient for complex games. The memory in the virtualization software is usually limited to 128MB — even if much more is available.

The biggest advantage of virtualization: You always have a clean guest system, no matter what you do with it. Ideally, your host system remains completely untouched in the event of accidents and infections in the virtual machine.

You can also change the settings within the virtual machine to your heart’s content and try out tips. With one click, you can return to the original state — on a real PC, a major crash can result in costly repair measures under certain circumstances.

Advantages and disadvantages of Multiboot


Installation: If Linux Mint is installed alongside Windows, select the desired system when booting. Image: IDG

With multiboot — whether with a live system or a permanently installed operating system — you utilize the available resources of the PC. Processor, RAM, and graphics memory are available without restriction — as are all other hardware components such as printer, webcam, and scanner.

A multiboot system can be used in combination with Windows 10 and Linux Mint, for example, if the installation of Windows 11 fails due to the lack of hardware requirements. In addition, typical work on the PC can be separated and PCs can be divided for private and business use. The disadvantage is the double administration effort.

This article was translated from German to English and originally appeared on pcwelt.de.

source
94

Yubico issues a security alert to Windows YubiKey users AFP VIA GETTY IMAGES
When it comes to user authentication, there are many options available, from passwords at the weaker end of the security spectrum to hardware keys at the other. But what if the hardware security key you use could leave your operating system exposed to attack? Yubico, the security vendor behind the range of YubiKey products, has issued a security advisory warning of just that scenario for Windows users.

Yubico Security Advisory YSA-2024-01

Yubico is quite rightly considered to have one of the most secure authentication products in its YubiKey hardware security key range. If proof is needed you only have to look at the Yubico security advisories page entries for the last three years where there are none listed for 2022, one for 2023 and one for 2024. It’s the last of these that impacts Windows users, although not those who use Edge as their web browser client of choice.

Yubico security advisory YSA-2024-01 concerns the YubiKey Manager software which has a vulnerability that could lead to an escalation of privileges attack for Windows users. The vulnerability is listed as CVE-2024-31498 and has a Common Vulnerability Scoring System rating of 7.7 which means this is a high-risk issue rather than a critical one.

Yubico says, “If a user runs the YubiKey Manager GUI as Administrator, browser windows opened by the YubiKey Manager GUI may be opened as Administrator, which could be exploited by a local attacker to perform actions as Administrator.” If this sounds worrying that’s because it is. An attacker, who would already need to have local access to the Windows machine concerned, could use this privilege escalation to further compromise that system. “This issue can be used by an attacker to escalate local attacks and increase the impact of browser-based attacks,” Yubico warns.

Affected Software And Systems

CVE-2024-31498 affects versions of YubiKey Manager prior to 1.2.6 and those Windows users who are not using Edge as their default browser. Yubico explains that it only impacts Windows users as the operating system requires admin privileges to interact with FIDO authenticators such as the YubiKey. On other operating systems, this level of elevated permissions is not required. Windows users are, therefore, advised to click on the About menu in the software and check to see what version they are using. Anything before 1.2.6 should be updated accordingly. The latest version of YubiKey Manager can be downloaded directly from the Yubico website or GitHub.

Other Mitigations For The YubiKey Manager Vulnerability

The Fast IDentity Online Alliance is an open standard for authentication that, in its FIDO2 guise, can provide passwordless single-factor authentication as well as two and multi-factor authentication options among other things. Yubico advises that users not requiring the FIDO features do not need to run YubiKey Manager GUI as an elevated privilege user. Windows users can also configure Microsoft Edge as their default web browser, as this already includes mitigations that prevent admin permissions from being inherited when initiated the way this vulnerability enables. That said, I would not recommend switching to Edge from your preferred browser; take the software update route instead, and then there’s no need.

source
95


The complete shutdown of the long-running E3 video game trade show in 2023 was not exactly a surprise but was still a disappointment for many gaming fans who have enjoyed the event over the decades. Earlier this year, the gaming and entertainment media site IGN announced plans for an in-person event, IGN Live, in LA. Now we have a little more info on this possible replacement for E3.

IGN's site stated that IGN Live will be held June 7-9 and it will take place in downtown LA, similar to most of the past E3 shows. However, IGN Live won't be held in the big LA Convention Center like the majority of E3 shows but rather at Magic Box, an event center that's located not too far from E3's old convention center location.

IGN says the event will include a "stage show with developers, publishers, creators, and more across gaming and entertainment". It will also have other activities for the people who attend, including "exclusive reveals, trailers, gameplay, panels, interviews, episodes of IGN shows, and more". The site will also stream content from IGN Live as well.

There's no word on what game publishers will be participating in IGN Live. There's also no word on when tickets for the live event will take place or how much they will cost.

Aside from IGN Live, it looks like a lot of the game industry will be using that same early June 2024 time frame to hold streaming events for announcements and game reveals. Microsoft has already confirmed that it will hold its big Xbox Game Showcase sometime In June. Rumors have already been hitting the internet that it will officially reveal the next Gears of War game, among other titles.

Ubisoft has confirmed it will stream its Ubisoft Forward event on June 10 from LA. The latest Summer Game Fest event will also be streamed from LA on June 7. The Future Games Show is set for its 2024 summer streaming event on June 8, and the PC Gaming Show's summer event is promised for sometime in June. It's likely that more gaming streaming events will be revealed for around that same time frame in the very near future.

source
96


Recently, X (formerly Twitter) gave away complimentary premium subscriptions to several influential people who hadn't signed up for the premium account based on the number of followers they had. This also gave these users a complimentary blue verification checkmark. Now, X has reportedly removed the option to hide the blue checkmark from user profiles.

According to a fresh report by Engadget, X is sending notifications to its users that "the hide your checkmark feature of X Premium is going away soon." Here is a post shared by X user Nima Owji about this notification.



This change comes soon after X started giving blue verification checkmarks to user profiles with at least 2,500 followers and a premium subscription. As per Elon Musk, the change was supposed to be a "perk," but not everyone is happy about it.

Some of the critics include users who are already verified. They weren't pleased with the blue badge appearing on their accounts, which made it feel as if they were paying for a premium subscription. Because, originally, the blue checkmark was an indication to show that a profile is officially verified and belongs to a public figure such as a celebrity, politician, or journalist.

The blue checkmark was previously free and was awarded to a profile based on certain criteria. However, after Elon Musk's takeover, Twitter became X, and several changes came into place, one of which was this checkmark being a part of the X Premium subscription.

Hence, the move seemingly devalued the blue verification checkmark because now anyone can pay for it and get it on their profiles. Now, with the new update, users won't be able to hide the blue checkmark from their profiles. The update is rolling out gradually, and you may not see it on your account immediately.

source
97


Apple sent security alerts to iPhone users in 92 countries this week, warning them that state-sponsored hackers are actively trying to compromise their devices. In notification emails seen by some media outlets, Apple said it had "high confidence" that individuals were "targeted by a mercenary spyware attack" designed to remotely access their phones.

The sophisticated attacks appeared to target specific people "because of who you are or what you do," Apple said. While the company did not name the spyware involved or attribute the attacks to any government, such mercenary software is typically only used by countries to target human rights activists, journalists, and politicians.

In the past, Apple has identified similar targeted hacking campaigns originating in China, Russia, Iran, and North African countries. This latest global alert affects iPhone owners in over 150 countries.

However, it remains unclear whether users in the United States were among those targeted this time. In its notifications, Apple said it was unable to provide more details about the attacks in order to prevent hackers from evolving their techniques.

Apple claimed "high confidence" in its analysis to encourage users to take action. "We are unable to provide more information about what caused us to send you this notification, as that may help mercenary spyware attackers adapt their behavior to evade detection in the future," the company said to iPhone users.

Nevertheless, the scale of the operation, which involved more than 90 countries across multiple continents, shows that state-sponsored hacking remains a widespread threat.

source
98


We are about 18 months away from the end of mainstream Windows 10 support, but Microsoft thinks it is time to start nagging warning Windows 10 users about the inevitable. Users on Reddit report spotting a new full-screen ad with a notification that Windows 10 is about to reach its end of life in October 2025, even though it is still getting new features (there are even rumors about Microsoft re-opening the Windows Insider Program for Windows 10).

Ironically, there is no escape from Microsoft's latest ad, even for those using PCs that technically do not support Windows 11. It seems that the new banner is specifically designed and targeted for Windows 10 customers who cannot upgrade due to Windows 11's steep hardware requirements. It thanks Windows 10 users for their loyalty and suggests learning more about the end of Windows 10 support and the benefits of Windows 11.

Quote
A New Journey with Windows

We want to thank you for your loyalty as a Windows 10 customer. As the end of support for Windows 10 approaches, we're here to support you on your PC journey.

Your PC is not eligible to upgrade to Windows 11, but it will continue to receive Windows 10 fixes and security updates until support ends on October 14, 2025.


Typically, there is no apparent decline button: you can either postpone the ad or click "Learn more."

Still, it is worth noting that Microsoft should warn Windows 10 users about the upcoming end of support, considering the operating system's massive market share. It is just a bit odd to see Microsoft starting the campaign this early and without a single word about the ability to pay for the Extended Security Program, which, this time, also applies to regular consumers, not just commercial users.

With that said, Microsoft has yet to announce the ESU policies for home users, so we will most likely see a few more iterations of this banner. The approach itself is not new—Microsoft used the same tactic with Windows 7 before it reached the end of mainstream support in early 2020.

source
99
General Discussion / How to see if your internet provider is overcharging you
« Last post by javajolt on April 11, 2024, 04:33:48 PM »
or delivering slower speeds

A new regulation by the FCC requires ISPs to provide information about their services that most consumers never had easy access to.

A new initiative went into effect today compelling internet service providers (ISPs) to break down key information on their plans and associated fees in the format of the nutrition label found on food packaging.

After a lengthy battle with the Federal Communications Commission (FCC) that lasted almost eight years, broadband service providers must now compile and make transparent key metrics about their plans including speeds, data allowances, network management practices, and most importantly, recurring fees in an easy-to-understand format for consumers.

This nutrition label format, the FCC decided, is one of the most widely recognized by consumers in terms of clarity, and conveys its purpose by design.

Having access to all this information at-a-glance certainly makes shopping for broadband internet services easier, as there has never before been one single point where consumers could find a comprehensive (and accurate) list of information on an ISP's key services and their fees upfront. And certainly not in a format that allowed for easy comparisons to competitors.

The new "nutrition" labels will now be displayed to consumers at the point of sale, with key information about monthly charges, data caps, and other fees made available from the beginning, instead of being buried in mountains of promotional or legal speak.


FCC - click image to enlarge
The industry is infamous for misrepresenting connection speeds by posting optimal speeds that are theoretically possible but rarely seen by many consumers, particularly in high-demand areas.

In addition, promotional deals launched by ISPs typically offer competitive first-year monthly fees but jack up the rates after that, catching consumers off guard with little choice to opt out while in a contractual service agreement.

Virtually all ISPs in business across the US such as Comcast, Verizon, and Cox are subject to the FCC's directive now, despite their combined efforts to kill the effort before it became a reality. Industry trade organizations and lobbyists have been campaigning against the proposition since it was first floated, stating that it would be too costly and complicated to provide this information to consumers upfront.

But the effort is part of the Biden administration's executive order on competition promotion across markets, particularly in the telecommunications sector. The order targeted ISPs and net neutrality as well as the right to repair, with an eye kept on monitoring potential tech monopolies.

The new labels might still have some loopholes the ISPs could workaround, however. The FCC order mandates that total prices are made transparent, but they don't necessarily need to be itemized. For example:

Quote
"A provider that opts to combine all of its monthly discretionary fees with its base monthly price may do so and list that total price. In that case, the provider need not separately itemize those fees in the label."

This could open the door for some wiggle room in how prices are listed out, or presented in a way that obfuscates what they're actually for.

Still other consumer advocates criticize the plan for doing too little, too late, saying that service transparency is simply the bare minimum businesses should be expected to provide, pointing to other issues that pose far bigger problems. The most glaring of which is the issue of regional monopolies ISPs have over much of the United States.

Certain regions may only have two -- or even one -- available ISP, in which case there is little to no incentive to offer competitive speeds or pricing structures.

Most of the major national ISPs released nutrition labels ahead of today's official deadline, but small ISPs with fewer than 100,000 lines have until October 10 to do so.

source
100
If you're a digital artist or multimedia creator, and you've always dreamed of having an operating system that can travel with you, Dynebolic is back after a 10-year hiatus.


Screenshot by Jack Wallen/ZDNET]

ZDNET's key takeaways

   • After a 10-year hiatus, Dynebolic is back and can be downloaded and used for free.

   • Dynebolic has everything you need for multimedia creation and runs as a live instance, so it's portable and doesn't make
     any changes to your default operating system.

   • With Dynebolic, it's WYSIWYG, so you don't need to install any other applications.

There are plenty of Linux distributions that are geared toward specific tasks. There are distributions for desktops, servers, firewalls, routers, gaming, containers, file servers, forensics, penetration testing, and more. There are also distributions created specifically to help creatives do their thing.

One of those distributions is Dynebolic, which rose in popularity a decade ago just as it ceased development. The great news for those who used to like Dynebolic is that the distribution is back.

From the official announcement: "Ten years have passed and today we are back with a brand new Dynebolic 4.0 based on Devuan 5 "Daedalus", live-boot, and the Linux kernel 6.8 series."

Ten years is a long time in IT, but Rastasoft is confident it's a return to form for its distribution. With the help of the KDE Plasma desktop, Dyenbolic has become a portable, creative operating system geared specifically for multimedia production, with plenty of audio and video tools to get the job done.

But what does it mean when I say "portable"? You've probably heard of the "live" distribution if you've used Linux. A live distribution allows you to run the operating system and its apps from the system's RAM. You don't have to install the operating system, so it doesn't make a single change to your hard drive. With a live distribution, you can take Linux out for a test drive and, when you're finished, reboot your machine, remove the USB drive, and boot back into your original operating system.

Live distributions are commonplace in Linux and have been around for some time. With Dynebolic opting to take the live route, anyone can boot into the operating system, create multimedia projects, save them to an external drive, and -- when they're finished -- reboot the machine back to the installed operating system.

Consider Dynebolic your on-the-go creative workstation. You could visit a friend's house, boot Dynebolic on their PC, do whatever you need, save your work, reboot, and your friend's computer returns to its original state.

Even better, Dynebolic is 100% free software, and free of charge.

Dynebolic is a self-contained operating system, so the software must have everything you need because you can't install anything extra. Fortunately, you'll find tools for streaming, audio, video, graphics, and publishing, including:

   • Ardour7 - Digital audio workstation

   • Audacity - Sound editor

   • Butt - Streaming tool

   • FFADO Mixer - FireWire audio mixer

   • HDSPConf - Hammerfall DSP control application

   • JAMin - JACK Audio Mastering interface

   • Kdenlive - Video Editor

   • Mixxx - Digital DJ interface

   • OBS Studio - Streaming/recording

   • QJackCtl - JACK control

   • soundKonverter - Audio file converter, CD ripper, and Replay Gain tool

   • TiMidity++ - MIDI sequencer

   • VLC - Media player

   • Darktable - Virtual light table and darkroom

   • GIMP - Image editor

   • Inkscape - Vector graphics editor

   • Scribus - Page layout

   • Konqueror - Web browser

   • Thunderbird - Email

The one application that is missing is an office suite. That's fine as you can also use the cloud to access productivity applications.

I enjoyed creating content in Dynebolic. You can jump in right away with Audacity, creating audio with ease. For more advanced audio needs, there's JACK and Ardour7, both powerful tools.

The one thing to keep in mind, however, is that you'll need an external drive to save your work. As Dynebolic is a live distribution, saved work is lost when you reboot. You can always temporarily save your work to the Dynebolic file system and then upload any or all files to a cloud storage account, which would be a great option. Just remember, multimedia files -- especially video -- can be large, so you'll want a cloud account with plenty of storage space.

Dynebolic is a brilliant take on the multimedia workstation. By making it 100% portable, without the ability to install it on a system's hard drive, you can be certain the operating system will function as expected and you'll have a creative tool that travels well.

You can download the latest ISO of Dynebolic, create a bootable USB drive, and start using this creative workstation wherever you need.

source
Pages: 1 ... 8 9 [10]