Deals of the Day (9-09-2016)

Deals of the Day (9-09-2016)

Lenovo’s ThinkPad X1 Carbon notebooks are incredibly thin and light, while retaining some distinctive ThinkPad features like a no-nonsense carbon fiber-reinforced black case and a TrackPoint system with a pointing nub in the center of the keyboard.

Right now Lenovo is selling the latest ThinkPad X1 Carbon laptops for $952 and up, which isn’t a bad price for a 2.6 pound, 14 inch laptop with an Intel Skylake processor.

But if you’re cool with buying a refurbished 2014 model, Woot is currently offering a pretty great one for just over half the price.

Continue reading Deals of the Day (9-09-2016) at Liliputing.

Deals of the Day (9-09-2016)

Lenovo’s ThinkPad X1 Carbon notebooks are incredibly thin and light, while retaining some distinctive ThinkPad features like a no-nonsense carbon fiber-reinforced black case and a TrackPoint system with a pointing nub in the center of the keyboard.

Right now Lenovo is selling the latest ThinkPad X1 Carbon laptops for $952 and up, which isn’t a bad price for a 2.6 pound, 14 inch laptop with an Intel Skylake processor.

But if you’re cool with buying a refurbished 2014 model, Woot is currently offering a pretty great one for just over half the price.

Continue reading Deals of the Day (9-09-2016) at Liliputing.

Panama Papers: Denmark to pay $1.3M-plus for leaked data to probe tax evasion

Danish move may help make public interest whistleblowing more acceptable.

Enlarge (credit: Tim Bartel)

Tax officials in Denmark are reportedly paying an unknown source around £1 million for secret financial information on hundreds of Danish nationals.

Their names appear in the Panama Papers, leaked earlier this year, which consist of 11.5 million files from the database of Mossack Fonseca—the world's fourth biggest offshore law firm.

This is the first time, according to Danish newspaper Politiken, that Denmark has agreed to buy information on possible tax evaders in this way. Denmark also seems to be the first country to admit that it's acquiring data from a source with access to the leaked Mossack Fonseca documents. [Update: apparently Iceland made an earlier deal—see comment below.]

Read 7 remaining paragraphs | Comments

DAB+: Bundesrat will Verkauf von reinen UKW-Radios stoppen

Der Kulturausschuss des Bundesrates will keine reinen UKW-Radios mehr zum Verkauf zulassen. Das Telekommunikationsgesetz (TKG) soll dafür geändert werden, DAB+ soll unterstützt werden. (ARD, Internet)

Der Kulturausschuss des Bundesrates will keine reinen UKW-Radios mehr zum Verkauf zulassen. Das Telekommunikationsgesetz (TKG) soll dafür geändert werden, DAB+ soll unterstützt werden. (ARD, Internet)

FAA still maintains shampoo can be more dangerous than exploding Note 7

FAA: Don’t “turn on or charge these devices on board aircraft.”

(credit: Sean MacEntee)

The Federal Aviation Administration is announcing new air passenger carry-on guidelines. Sadly, though, the authorities are not altering the terrorism-repelling edict prohibiting fliers from carrying on shampoo or other liquids and gels in containers larger than 3.4 ounces.

The FAA, however, announced late Thursday that it will still allow you to bring your exploding Note 7 onboard—albeit with a few caveats. Samsung issued a Note 7 global recall last week of the 2.5 million units it had shipped amid reports that the phablet's batteries could explode or catch fire.

In response, the FAA said it doesn't want you to use or charge the Note 7 while flying, and the agency doesn't want you to put the device in your checked bags, either.

Read 5 remaining paragraphs | Comments

Facebook accused of censorship after removal of iconic “napalm girl” photo

Norway’s PM wades in as Zuck is described as “world’s most powerful editor.”

Enlarge (credit: Eric Lalmand/AFP/Getty Images)

Facebook has been accused of censorship by Norway's prime minister, Erna Solberg, in a growing spat about the free content ad network's removal of a post featuring the Pulitzer Prize-winning historic Vietnam War image of "napalm girl."

The social media network deleted a post made by the Norwegian newspaper Aftenposten based on the fact that the image contained child nudity. On Friday morning, the editor-in-chief of the paper published an open letter to Mark Zuckerberg, in which he described the Facebook chief as "the world's most powerful editor"—a sticky note increasingly being slapped on the multibillionaire's back, even as he continues to refuse to accept any such tag.

Just last week, Zuckerberg wryly said at a Facebook event in Germany: "we're a tech company, we're not a media company."

Read 5 remaining paragraphs | Comments

Researcher Finds Critical Vulnerabilities in Hollywood Screener System

A prominent security researcher has discovered serious vulnerabilities in a system that allows awards voters to watch the latest movie screeners online. Chris Vickery, who previously gained access to the ‘World-Check’ terror, crime and sanctions database, informed TF of his discovery last month after an unsecured database was left open to the public.

Source: TF, for the latest info on copyright, file-sharing, torrent sites and ANONYMOUS VPN services.

oscartorrentsSo-called screener copies of the latest movies are some of Hollywood’s most valuable assets, yet every year and to the delight of pirates, many leak out onto the Internet.

Over the years, Hollywood has done its best to limit the leaks, but every 12 months without fail, many of the top titles appear online in close to perfect quality.

With that in mind, the studios have been testing Netflix-like systems that negate the need for physical discs to be sent out.

One such system has been made available at Awards-Screeners.com. Quietly referenced by companies including 20th Century Fox, the site allows SAG-AFTRA members and other industry insiders to view the latest movies in a secure environment. At least, that’s the idea.

awards-screeners

Late August, TorrentFreak was contacted by security researcher Chris Vickery of MacKeeper.com who told us that while conducting tests, he’d discovered an exposed MongoDB database that appeared to be an integral part of Awards-Screeners.com.

“The database was running with no authentication required for access. No username. No password. Just entirely exposed to the open internet,” Vickery told TF.

The researcher’s discovery was significant as the database contained more than 1,200 user logins. Vickery did not share the full database with TF but he did provide details of a handful of the accounts it contained. Embarrassingly, many belong to senior executives including:

– Vice President of International Technology at Universal Pictures
– ‎Director of Content Technology & Security at Disney
– Vice President of Post-Production Technology at Disney
– Executive Director, Feature Mastering at Warner Bros
– Vice President of Global Business & Technology Strategy at Warner Bros
– Director of Content Protection at Paramount Pictures
– VP of corporate communications and publicity for 20th Century Fox

While the hashed passwords for the above would be difficult to crack, the database itself was publicly offering admin-level access, so it was a disaster from a security perspective.

“Any of the values in the database could have been changed to arbitrary values, i.e. create-your-own-password,” Vickery said.

awards-passwords

According to the researcher, this vulnerability had the potential to blow a hole in the screener system and could’ve had huge piracy and subsequent law enforcement implications.

“Theoretically, it would have been possible for a malicious person to log into any of the 1,200+ user accounts, screencap an unreleased film, and torrent it to the world,” he explained.

“There’s also supposedly video watermark technology that makes it possible to trace which account it came from. So basically you could have framed any of the users for the distribution as well by using their account to do it.”

The screenshot below shows Vickery’s view of the database, in this case highlighting the availability of a screener copy of the soon-to-be-released Oliver Stone movie, Snowden.

awards-snowden

Vision Media Management, which claims to be the largest Awards screener fulfillment operation in the world, is the outfit in charge of the system. It’s described in the company’s promotional material as a “Secure Digital Screener” platform “selected by the MPAA major studios as the preferred secure content delivery method for Awards voters.”

Like all responsible data breach hunters, Vickery did his research and decided to inform Awards-Screeners.com and Vision Media Management of his findings. Initially, they appeared somewhat grateful.

“During my telephone conversation with Vision Media Management, which consisted of me, their lead counsel (Tanya Forsheit), and their CTO (Doug Woodard), they were very surprised and worried. They didn’t understand how this could happen and claimed that the system should have nothing loaded into it currently and was purged months ago,” Vickery said.

“This is not believable due to time stamps of activity in the database. In the ‘Snowden’ screenshot, for example, you can see that the entry was updated on 7/13/2016.”

vison-media

Vickery also informed the MPAA of his discoveries and was told by the organization’s Office of Technology that it was “currently working diligently” with Vision to “evaluate the situation and take appropriate remedial action.”

Meanwhile, conversations between Vickery and Vision Media Management continued. The researcher says that the company tried to downplay his findings with claims that the database had been secure and contained only test data.

awards-screeners-userHowever, when Vickery asked if he could release the database, he was advised it was too sensitive to be made public. The company then began a drive to convince the researcher that security at Amazon, one of Vision’s vendors, was to blame for the leak. Vision’s lawyer also suggested that Vickery had “improperly downloaded” the database.

In a follow-up mail, Vickery made it clear to Vision that allegations of “improper downloading” were incompatible with the fact that the database had been published openly to the public Internet. And, after all, he had done the responsible thing by informing them of their security issues.

“I have cooperated with and contributed to data breach-related investigations conducted by the FTC, FBI, US Navy, HHS/OCR, US Secret Service, and other similar entities,” he told the company. “Not a single regulatory or government agency I have interacted with has even suggested that what I do, downloading publicly published information, is improper.”

In subsequent discussion with Vickery, Vision Media asked for time to assess the situation but by September 4, the researcher had more bad news for the company.

Emails shared with TF show Vickery informing Vision of yet more security holes in its system, specifically a pair of publicly exposed S3 buckets located on Vision resources at Amazon. Vickery says these contained development and release builds of Vision’s Android app, development and deployment meeting notes, plus some unexplained references to Netflix.

In the run-up to this piece, Vickery advised Vision Media that a public disclosure would be likely so in an effort to provide balanced reporting, TorrentFreak reached out to Vision Media’s CEO for a statement on the researcher’s findings. At the time of publication, nothing had been received.

And after several conversations with Vision via email and on the phone, Vickery was drawing a blank this week too.

“Vision has not gotten back to me today, and we were very clear last week that they would be contacting me again by Thursday,” Vickery told TF. “I even sent them a little reminder earlier and asked if we were still planning to talk. No response all day.”

In the absence of an official statement from Vision Media, it’s impossible to say how many people accessed the Awards-Screener database before Vickery, or what their intentions were. Perhaps only time will tell but one thing is clear – a move to the digital space might not be the perfect solution for screener distribution.

Check out Chris Vickery’s report on MacKeeper

Source: TF, for the latest info on copyright, file-sharing, torrent sites and ANONYMOUS VPN services.

HTTPS: Google Chrome will vor unverschlüsselten Webseiten warnen

Wie umgehen mit unverschlüsselten Webseiten? Google will in Chrome künftig warnen, wenn unverschlüsselte Webseiten Passwörter und Kreditkartendaten abfragen. Doch das ist nur der Beginn der Planungen. (Chrome, Google)

Wie umgehen mit unverschlüsselten Webseiten? Google will in Chrome künftig warnen, wenn unverschlüsselte Webseiten Passwörter und Kreditkartendaten abfragen. Doch das ist nur der Beginn der Planungen. (Chrome, Google)

FAA warns passengers not to use Galaxy Note 7 while flying (maybe you should take advantage of that voluntary recall)

Samsung says only a relatively small percentage of the 2.5 million Galaxy Note 7 smartphones sold to date suffer from a defect that can cause the battery to explode and catch fire. But the company has issued a voluntary recall and will either replace p…

FAA warns passengers not to use Galaxy Note 7 while flying (maybe you should take advantage of that voluntary recall)

Samsung says only a relatively small percentage of the 2.5 million Galaxy Note 7 smartphones sold to date suffer from a defect that can cause the battery to explode and catch fire. But the company has issued a voluntary recall and will either replace phones you send in with either a new, non-exploding version or a Galaxy S7 series phone.

Need another reason to consider taking Samsung up on its offer to replace your phone?

Continue reading FAA warns passengers not to use Galaxy Note 7 while flying (maybe you should take advantage of that voluntary recall) at Liliputing.

Raspberry Pi sells over 10 million computers

The single-board computer is a great British success story.

(credit: Wired)

Four years since it first went on sale to eager developers, the credit card-sized Raspberry Pi computer has sold an impressive 10 million units.

It remains the UK's best-selling computer ever—and a reminder that you don't have to be a Silicon Valley heavyweight to create a successful slice of tech.

Dreamed up by the Raspberry Pi Foundation charity as a way to bring computer science and coding back into schools, the Welsh-built Raspberry Pi has not only found its way into thousands of schools across the globe but has also taken on a life of its own as a hobbyist device.

Read 6 remaining paragraphs | Comments

Opposition: Breitband-Milliarden sollen massiv nur in 50 MBit/s fließen

Laut der Grünen Tabea Rößner und dem Bundesrechnungshof fördert Deutschland statt der Gigabitgesellschaft hauptsächlich 50 MBit/s-Zugänge. Die Förderkriterien seien so ausgestaltet, dass höhere Geschwindigkeiten in keiner Weise belohnt würden. (Glasfaser, Telekom)

Laut der Grünen Tabea Rößner und dem Bundesrechnungshof fördert Deutschland statt der Gigabitgesellschaft hauptsächlich 50 MBit/s-Zugänge. Die Förderkriterien seien so ausgestaltet, dass höhere Geschwindigkeiten in keiner Weise belohnt würden. (Glasfaser, Telekom)