While Equifax Victims Sue, Congress Limits Financial Class Actions
An anonymous reader quotes a local NBC news report:
Stories are starting to pour in about those impacted by last month's massive Equifax data breach, which compromised the private information of more than 140 million people. Katie Van Fleet of Seattle says she's spent months trying to regain her stolen identity, and says it has been stolen more than a dozen times. "I kept receiving letters from Kohl's, from Macy's, from Home Depot, from Old Navy saying 'thank you for your application,'" she said to CNN affiliate KCPQ. But she says she's never applied for credit from any of those places. Instead, Van Fleet and her attorney Catherine Fleming say they believe her personal data was stolen during the massive Equifax security breach... Fleming has filed a class-action lawsuit against Equifax, saying they were negligent in losing private information on more than 140 million Americans... "Countless people, I mean, I've really, truly lost count, and the stories that like Katie's, the stories I hear are heart-wrenching," Fleming said.
But are things about to get worse? Marketwatch reports:
It will become harder for consumers to sue their banks or companies like Equifax... The Senate voted Tuesday night to overturn a rule the Consumer Financial Protection Bureau worked on for more than five years. The final version of the rule banned companies from putting "mandatory arbitration clauses" in their contracts, language that prohibits consumers from bringing class-action lawsuits against them. It applies to institutions that sell financial products, including bank accounts and credit cards. Consumer advocates say it's good news for companies like Wells Fargo or Equifax, which have both had class-action lawsuits filed against them, and bad news for their customers... Lisa Gilbert, the vice president of legislative affairs at Public Citizen, a nonprofit based in Washington, D.C., said the Senate vote shouldn't impact cases that are already ongoing. However, there will "certainly" be more forced arbitration clauses in contracts in the future, and fewer cases brought against companies, she said.
Read more of this story at Slashdot.
Source: http://rss.slashdot.org/~r/Slashdot/slashdot/~3/tyfrnJrULi0/while-equifax-victims-sue-congress-limits-financial-class-actions
Portuguese ISP Shows What The Net Looks Like Without Net Neutrality
"In Portugal, with no net neutrality, internet providers are starting to split the net into packages," argues a California congressman -- retweeting a stunning graphic. An anonymous reader quotes BoingBoing's Cory Doctorow:
Since 2006, Net Neutrality activists have been warning that a non-Neutral internet will be an invitation to ISPs to create "plans" where you have to choose which established services you can access, shutting out new entrants to the market and allowing the companies with the deepest pockets to permanently dominate the internet... the Portuguese non-neutral ISP MEO has mistaken a warning for a suggestion, and offers a series of "plans" for its mobile data service where you pay €5 to access a handful of messaging services, €5 more to use social media; and €5 more for video-streaming services.
The congressman notes this arrangement offers "a huge advantage for entrenched companies, but it totally ices out startups trying to get in front of people, which stifles innovation."
Read more of this story at Slashdot.
Source: http://rss.slashdot.org/~r/Slashdot/slashdot/~3/6J4YhdYYggc/portuguese-isp-shows-what-the-net-looks-like-without-net-neutrality
TechCrunch Argues Social Media News Feeds 'Need to Die'
"Feeds need to die because they distort our views and disconnect us from other human beings around us," argues TechCrunch's Romain Dillet:
At first, I thought I was missing out on some Very Important Content. I felt disconnected. I fought against my own FOMO. But now, I don't feel anything. What's going on on Instagram? I don't care. Facebook is now the worst internet forum you can find. Twitter is filled with horrible, abusive people. Instagram has become a tiny Facebook now that it has discouraged all the weird, funny accounts from posting with its broken algorithm. LinkedIn's feed is pure spam.
And here's what I realized after forgetting about all those "social" networks. First, they're tricking you and pushing the right buttons to make you check your feed just one more time. They all use thirsty notifications, promote contrarian posts that get a lot of engagement and play with your emotions. Posting has been gamified and you want to check one more time if you got more likes on your last Instagram photo. Everything is now a story so that you pay more attention to your phone and you get bored less quickly -- moving pictures with sound tend to attract your eyes... [F]inally, I realized that I was missing out by constantly checking all my feeds. By putting my phone on 'Do Not Disturb' for days, I discovered new places, started conversations and noticed tiny little things that made me smile.
He concludes that technology has improved the way we learn, communicate, and share information, "But it has gone too far...
"Forget about your phone for a minute, look around and talk with people next to you."
Read more of this story at Slashdot.
Source: http://rss.slashdot.org/~r/Slashdot/slashdot/~3/E8dmuznuoHs/techcrunch-argues-social-media-news-feeds-need-to-die
Study Links Rapid Ice Sheet Melting With Distant Volcanic Eruptions
schwit1 quotes UPI:
New research suggests volcanic eruptions can trigger periods of rapid ice sheet melting... "Over a time span of 1,000 years, we found that volcanic eruptions generally correspond with enhanced ice sheet melting within a year or so," Francesco Muschitiello, a postdoctoral researcher at Columbia University's Lamont-Doherty Earth Observatory, said in a news release. The volcanoes of note weren't situated next-door, but thousands of miles from the ice sheet, a reminder of the unexpected global impacts of volcanic activity.
The new research -- detailed this week in the journal Nature Communications -- suggests ash ejected into the atmosphere by erupting volcanoes can be deposited thousands of miles away. When it's deposited on ice sheets, the dark particles cause the ice to absorb more thermal energy and accelerate melting... Some scientists have even suggested melting encouraged by volcanic eruptions could trigger even more eruptions, a positive feedback loop. As glaciers and ice sheets melt, pressure is relieved from the planet's crust, allowing magma to rise to the surface.
Read more of this story at Slashdot.
Source: http://rss.slashdot.org/~r/Slashdot/slashdot/~3/iVsWHGY0zRI/study-links-rapid-ice-sheet-melting-with-distant-volcanic-eruptions
Purism Now Offers Laptops with Intel's 'Management Engine' Disabled
"San Francisco company Purism announced that they are now offering their Librem laptops with the Intel Management Engine disabled," writes Slashdot reader boudie2. Purism describes Management Engine as "a separate CPU that can run and control a computer even when powered off."
HardOCP reports that Management Engine "is widely despised by security professionals and privacy advocates because it relies on signed and secret Intel code, isn't easily alterable, isn't fully documented, and has been found to be vulnerable to exploitation... In short, it's a tiny potentially hackable computer in your computer that you cannot totally control, nor opt-out of, but it can totally control your system."
Purism writes:
Disabling the Management Engine is no easy task, and it has taken security researchers years to find a way to properly and verifiably disable it. Purism, because it runs coreboot and maintains its own BIOS firmware update process, has been able to release and ship coreboot that disables the Management Engine from running, directly halting the ME CPU without the ability of recovery... "Disabling the Management Engine, long believed to be impossible, is now possible and available in all current Librem laptops. It is also available as a software update for previously shipped recent Librem laptops," says Todd Weaver, Founder & CEO of Purism.
Read more of this story at Slashdot.
Source: http://rss.slashdot.org/~r/Slashdot/slashdot/~3/Ozu-YnTGPx0/purism-now-offers-laptops-with-intels-management-engine-disabled
America's F-35s Can't Fly 22% of the Time, Repair Facilities Six Years Behind Schedule
"[N]early 200 F-35s might permanently remain unready for combat because the Pentagon would rather buy new aircraft than upgrade the ones the American people have already paid for," according to one defense news site. And now Bloomberg reports:
The Pentagon is accelerating production of Lockheed Martin Corp.'s F-35 jet even though the planes already delivered are facing "significantly longer repair times" than planned because maintenance facilities are six years behind schedule, according to a draft audit. The time to repair a part has averaged 172 days -- "twice the program's objective" -- the Government Accountability Office, Congress's watchdog agency, found. The shortages are "degrading readiness" because the fighter jets "were unable to fly about 22 percent of the time" from January through August for lack of needed parts.
The Pentagon has said soaring costs to develop and produce the F-35, the costliest U.S. weapons system, have been brought under control, with the price tag now projected at $406.5 billion. But the GAO report raises new doubts about the official estimate that maintaining and operating them will cost an additional $1.12 trillion over their 60-year lifetime.
Slashdot reader schwit1 writes, "This is akin to buying an exotic car you can barely afford, without also budgeting for insurance, repairs, and tuneups."
Read more of this story at Slashdot.
Source: http://rss.slashdot.org/~r/Slashdot/slashdot/~3/OeP7nA5rols/americas-f-35s-cant-fly-22-of-the-time-repair-facilities-six-years-behind-schedule
Apple Fires Engineer After His Daughter's iPhone X Video Goes Viral
"In a brutal reminder of the secrecy tech companies enforce on employees, Apple recently fired an employee after his daughter posted a video of the iPhone X," writes long-time Slashdot reader HockeyPuck. Engadget reports:
His daughter took down the video as soon as Apple requested it, but the takedown came too late to prevent the clip from going viral, leading to seemingly endless reposts and commentary... [I]t's important to stress that this wasn't a garden variety iPhone X. As an employee device, it had sensitive information like codenames for unreleased products and staff-specific QR codes. Combine that with Apple's general prohibition of recording video on campus (even at relatively open spaces like Caffe Macs) and this wasn't so much about maintaining the surprise as making sure that corporate secrets didn't get out. Apple certainly didn't want to send the message that recording pre-release devices was acceptable. All the same, it's hard not to sympathize -- the [radiofrequecy] engineer had poured his heart into the iPhone X, only to be let go the week before the handset reaches customers.
In a new follow-up video, the former Apple engineer's daughter says "I had no idea this was a violation," adding that her father "takes full reponsibility for letting me film his iPhone X." Here's some more quotes from her video.
Read more of this story at Slashdot.
Source: http://rss.slashdot.org/~r/Slashdot/slashdot/~3/nX3573Gm0iw/apple-fires-engineer-after-his-daughters-iphone-x-video-goes-viral
Why Do Web Developers Keep Making The Same Mistakes?
An anonymous reader quotes HPE Insights:
Software developers and testers must be sick of hearing security nuts rant, "Beware SQL injection! Monitor for cross-site scripting! Watch for hijacked session credentials!" I suspect the developers tune us out... The industry has generated newer tools, better testing suites, Agile methodologies, and other advances in writing and testing software. Despite all that, coders keep making the same dumb mistakes, peer reviews keep missing those mistakes, test tools fail to catch those mistakes, and hackers keep finding ways to exploit those mistakes. One way to see the repeat offenders is to look at the Open Web Application Security Project Top 10, a sometimes controversial ranking of the 10 primary vulnerabilities, published every three or four years by the Open Web Application Security Project... It boggles the mind that a majority of top 10 issues appear across the 2007, 2010, 2013, and draft 2017 OWASP lists...
It's sad that eight out of 10 of the issues from 2013 are still top security issues in 2017. In fact, if you consider that the draft 2017 list combined two of the 2013 items, it's actually nine out of 10. Ouch...
What can you do? Train everyone better, for starters. Look at coding and test tools that can help detect or prevent security vulnerabilities, but don't consider them silver bullets. Do dynamic application security testing, including penetration testing and fuzz testing. Ensure admins do their part to protect applications. And finally, make sure you establish a culture of security-aware programming and deployment.
Read more of this story at Slashdot.
Source: http://rss.slashdot.org/~r/Slashdot/slashdot/~3/ecJtur8w9gs/why-do-web-developers-keep-making-the-same-mistakes
Captain Crunch (and Steve Wozniak) Write New Book: 'Beyond the Little Blue Box'
Slashdot reader blottsie shares a new article about the legendary Captain Crunch -- which includes Steve Wozniak's memory that Steve Jobs "started avoiding Crunch...afraid that it would put us too close to getting arrested." The Daily Dot reports:
Wozniak and Jobs, of course, would go on to found the most successful tech company in the world. But Draper is far from being just an important footnote in Apple's history. He's the original hacking prankster, a purist driven by curiosity and craftsmanship, with a lifetime of exploits that have pushed technological and legal boundaries. And according to Jobs, in a rare 1994 interview, without him there wouldn't have been Apple. Now, for the first time, Draper is looking to publish his story with Beyond the Little Blue Box, an autobiography for which he's about to launch a Kickstarter campaign...
[H]e anonymously called in a national emergency directly to a furious President Richard Nixon on the Oval Office phone line, reporting that the West Coast had run out of toilet paper. He also claims he once bypassed the Iron Curtain to call Moscow in the Soviet Union. There's a playful mischief about him, but he's serious when it comes to his craft, relaying technical, intricate details about the systems he worked to hack... For many tinkering young coders and internet activists, Draper is still considered a folk hero, one whose apolitical infatuation with complex systems and compulsion to expose their limits made him a target -- especially where that curiosity crossed with corporate interests.
"Experiences like that taught us the power of ideas," Steve Jobs said in a 1994 interview. "The power of understanding that if you could build this box, you could control hundreds of billions of dollars around the world, that's a powerful thing." Steve Wozniak -- who writes the book's foreword -- remembers how Jobs ended that interview. "Steve Jobs said -- and I agree -- that without the blue box there might never have been an Apple."
Draper's Kickstarter campaign includes a "2600 Club" Bronze level, while people who pledge over $199 will receive an actual blue anonabox. And there's also a $10,000 "Super Phreak" level which includes a "VIP one-to-one meeting" with 74-year-old John Draper himself.
Read more of this story at Slashdot.
Source: http://rss.slashdot.org/~r/Slashdot/slashdot/~3/06maGpEJqMY/captain-crunch-and-steve-wozniak-write-new-book-beyond-the-little-blue-box
Did Amazon Really Lower Whole Foods' Prices?
While Whole Foods "strategically marked down select items like avocados and almond milk, overall prices have dropped very slightly -- about 1 percent -- since Amazon ownership, according to an analysis by research firm Gordon Haskett." An anonymous reader quotes Bustle:
This hardly seems like big savings, and Gordon Haskett noted that since the initial price cuts in August, the cost of some items have been slowly ticking back up. "The price of frozen foods, for example, was 7 percent higher on Sept. 26 than on Aug. 28, when Amazon officially took over," Abha Bhattarai reported for the Post, which is owned by Amazon. "Snack items had risen 5.3 percent in that period, while dairy and yogurt were up 2 percent. (Among categories where prices are lower: Beverages, down about 2.8 percent; bread and bakery, down 6.8 percent; and produce, down 0.5 percent...)"
For shoppers like me who buy mostly fresh fruits and vegetables, it did feel like I was saving money. However, one industry insider said there is a strategy behind how prices are cut. "The whole game is that you want the 100 most recognizable things -- milk, apples, bananas -- to be cheaper," Jan Rogers Kniffen, an industry consultant and former department store executive, told the Post. "If you can do that, you can build a perception that the whole store is competitively priced."
From July through September, Whole Foods brought in $1.3 billion in sales for Amazon.
Read more of this story at Slashdot.
Source: http://rss.slashdot.org/~r/Slashdot/slashdot/~3/CEmLrPQcoAo/did-amazon-really-lower-whole-foods-prices
Can Science Make Alcohol Safer?
Long-time Slashdot reader Zorro was the first to spot this story. Scientific American reports:
Could there be a "liver-friendly" vodka? One company claims its proprietary blend of additives reduces stress on the body... The researchers concluded that consuming the alcohol with the additives -- glycyrrhizin, derived from licorice; D-mannitol, a sugar alcohol; and potassium sorbate, a preservative -- may support improved liver health compared with drinking alcohol alone. Marsha Bates, a distinguished research professor and director of the Center of Alcohol Studies at Rutgers University, said the study design "seemed appropriate." But, she added, study itself was small, with only 12 healthy men and women, and "doesn't really provide any information of what the long-term effects of consuming alcohol with this additive would be. It's a positive preliminary study but certainly does not provide a firm basis for speculating about long-term impact."
Functional or not, Harsha Chigurupati needs approval from federal regulators before he can tout curative powers on a label... Specifically, Chigurupati is seeking approval to make the claim that his blend, known as NTX for "No Tox," provides "antioxidant and inflammatory support" and "reduces the risk of alcohol-induced liver diseases," among other claims... Chigurupati said his goal is not to enable people to drink more, but to drink with less physical harm.
The claim "leaves some experts deeply skeptical," adds the article, while 33-year-old Chigurupati admits that an earlier formula "tasted terrible and it actually burned my mouth." But his company later developed a formula which he says tasted good and is easier on the liver. "I don't believe in abstinence," Chigurupati told the Wall Street Journal. "What I do believe in is using technology to make life better. I'm not going to stop drinking, so why not make it safer?"
Read more of this story at Slashdot.
Source: http://rss.slashdot.org/~r/Slashdot/slashdot/~3/d4uSvVgiHbg/can-science-make-alcohol-safer
India, China, and Japan Are All Planning Moon Missions
schwit1 shares an article from UPI:
India will make its second mission to the moon in 2018, the Indian Space Research Organization (ISRO) announced this week. The Chandrayaan 2 spacecraft consists of an orbiter, lander and rover configuration "to perform mineralogical and elemental studies of the lunar surface," the ISRO said... Several other countries, including China and Japan, are planning lunar expeditions in the coming years -- partly to better understand the moon's environmental conditions for the potential of human settlements...
According to Popular Mechanics, the ISRO is attempting to make the lunar landing on a budget of $93 million, which is about the same cost of SpaceX's Falcon Heavy rocket that's scheduled for launch by the end of this year. The Falcon rocket, though, is only going into orbit -- and a $93 million price tag for a lunar landing could have impact on other countries' space plans.
India landed a spacecraft on the moon in 2008, and plans to complete this second lunar landing by March.
Read more of this story at Slashdot.
Source: http://rss.slashdot.org/~r/Slashdot/slashdot/~3/EEOtucLc14I/india-china-and-japan-are-all-planning-moon-missions
Open Source Data Sets? Linux Foundation Introduces 'Community Data License Agreements'
"In open source philosophy, you share source code. Why not share data?" writes Slashdot reader princelobga. Linux Insider reports on the Linux Foundation's new Community Data License Agreement, "a new framework for sharing large sets of data required for research, collaborative learning and other purposes."
CDLAs will allow both individuals and groups to share data sets in the same way they share open source software code, the foundation said. "As systems require data to learn and evolve, no one organization can build, maintain and source all data required," noted Mike Dolan, VP of strategic programs at The Linux Foundation. "Data communities are forming around artificial intelligence and machine learning use cases, autonomous systems, and connected civil infrastructure," he told LinuxInsider. "The CDLA license agreements enable sharing data openly, embodying best practices learned over decades of sharing source code."
A principal analyst at Pund-IT told the site that the new data license "reflects the growing importance of information as a resource for big data analytics, machine learning and artificial intelligence."
Read more of this story at Slashdot.
Source: http://rss.slashdot.org/~r/Slashdot/slashdot/~3/BMnRmm_O_BI/open-source-data-sets-linux-foundation-introduces-community-data-license-agreements
After 12 Years, Mozilla Kills 'Firebug' Dev Tool
An anonymous reader quotes InfoWorld:
The Firebug web development tool, an open source add-on to the Firefox browser, is being discontinued after 12 years, replaced by Firefox Developer Tools. Firebug will be dropped with next month's release of Firefox Quantum (version 57). The Firebug tool lets developers inspect, edit, and debug code in the Firefox browser as well as monitor CSS, HTML, and JavaScript in webpages. It still has more than a million people using it, said Jan Honza Odvarko, who has been the leader of the Firebug project. Many extensions were built for Firebug, which is itself is an extension to Firefox... The goal is to make debugging native to Firefox. "Sometimes, it's better to start from scratch, which is especially true for software development," Odvarko said.
Read more of this story at Slashdot.
Source: http://rss.slashdot.org/~r/Slashdot/slashdot/~3/s3jR7EWo3EM/after-12-years-mozilla-kills-firebug-dev-tool
Google To Remove Public Key Pinning (PKP) Support In Chrome
An anonymous reader writes: Late yesterday afternoon, Google announced plans to deprecate and eventually remove PKP support from the Chromium open-source browser, which indirectly means from Chrome... According to Google engineer Chris Palmer, low adoption and technical difficulties are among the reasons why Google plans to remove the feature from Chrome. "We would like to do this in Chrome 67, which is estimated to be released to Stable on 29 May 2018," Palmer says. The proposal is up in the air, and users can submit opinions against Google's intent to deprecate, but seeing how little PKP was adopted, it's most likely already out the door. A Neustar survey from March 2016 had PKP deployment at only 0.09% of all HTTPS sites. By August 2017, that needle had barely moved to 0.4% of all sites in the Alexa Top 1 Million.
Read more of this story at Slashdot.
Source: http://rss.slashdot.org/~r/Slashdot/slashdot/~3/uVCrz71j-pI/google-to-remove-public-key-pinning-pkp-support-in-chrome
Source: https://slashdot.org/