Windows 10 will soon run Edge in a virtual machine to keep you safe

Application Guard extends Virtualization Based Security to protect against browser flaws.

Enlarge / Untrusted sites get a minimal set of Windows Platform Services and no access to the rest of the system. (credit: Microsoft)

ATLANTA—Microsoft has announced that the next major update to Windows 10 will run its Edge browser in a lightweight virtual machine. Running the update in a virtual machine will make exploiting the browser and attacking the operating system or compromising user data more challenging.

Called Windows Defender Application Guard for Microsoft Edge, the new capability builds on the virtual machine-based security that was first introduced last summer in Windows 10. Windows 10's Virtualization Based Security (VBS) uses small virtual machines and the Hyper-V hypervisor to isolate certain critical data and processes from the rest of the system. The most important of these is Credential Guard, which stores network credentials and password hashes in an isolated virtual machine. This isolation prevents the popular MimiKatz tool from harvesting those password hashes. In turn, it also prevents a hacker from breaking into one machine and then using stolen credentials to spread to other machines on the same network.

The Edge browser already creates a secure sandbox for its processes, a technique that tries to limit the damage that can be done when malicious code runs within the browser. The sandbox has limited access to the rest of the system and its data, so successful exploits need to break free from the sandbox's constraints. Often they do this by attacking the operating system itself, using operating system flaws to elevate their privileges.

Read 8 remaining paragraphs | Comments

Liveblog: Elon Musk has revealed the Interplanetary Transport System

The big question: Can Musk build a coalition of government and industry support?

The Interplanetary Transport System.

It's time. After weeks of teasing us with talk of his Interplanetary Transport System and images of his new Raptor engine's test firing, SpaceX founder Elon Musk will finally deliver his much ballyhooed speech on Tuesday at 2:30pm ET (7:30pm UK), during the International Astronautical Congress.

Ars has already previewed the speech, which likely will lay out Musk's preferred architecture for Mars settlement, including spacecraft and a large rocket which will be powered by Raptor engines. For the speech to be a success, Musk must go beyond dazzling space hardware. He must prove to us that his plan is not science fiction, but something achievable. Humans have dreamt of going to Mars for decades—one of Wernher von Braun's first public appearances in the United States involved a presentation on Mars exploration to an El Paso Rotary Club. But we have heretofore lacked both the technology and the will to do so.

Musk undoubtedly has the technology, both in reality (such as the Raptor rocket engine or SuperDraco thrusters to land on Mars) and in concept (such as how to transport hundreds of people safely from Earth to Mars). But whether he can build a coalition of support in the government and private industry without undermining NASA's own Journey to Mars is a big question. Tuesday's speech is the start of that effort, and Ars will liveblog the proceedings with a feature-length analysis afterward.

Read on Ars Technica | Comments

New record extends global temperatures back two million years

Sees major transition at 1.2 million years, questionably high climate sensitivity.

Enlarge (credit: NSIDC/Ted Scambos)

When it comes to understanding the Earth's past climates, we have to understand what the global temperatures were. Instrument readings only go back to the 1800s, so researchers have had to rely on proxies—things we can measure, like tree ring width or oxygen isotopes, that reflect the weather conditions at the time. This has been used to track as far back as the end of the last glacial period.

Beyond that, records are sparse and local. Ice cores, for example, go back over 800,000 years, but these only capture polar conditions. Now, Stanford's Carolyn Snyder has put together the longest global climate record we have for recent times, extending back two million years from the present. The record captures a key transition in the glacial cycles that dominate recent climates.

Snyder also used this record to calculate the sensitivity of the climate to carbon dioxide, coming up with an eye-popping number that bodes very poorly for our future. Several other climate experts, however, suggest that the number Snyder calculated isn't especially relevant.

Read 13 remaining paragraphs | Comments

Survival of the smartest: Superbugs defeated with evolutionary trick

With an old drug, researchers dupe drug-resistant bacteria into tossing resistance.

(credit: Eric Erbe, Christopher Pooley, USDA)

Bacteria are wizzes at developing resistance to our most powerful antibiotics. This unfortunate skill leads to millions of difficult-to-treat infections worldwide and growing fears that bacteria may one day become unstoppable. But these microbes’ evolutionary prowess can just as easily be their downfall, scientists reported last week in Nature Chemical Biology.

By gaming the evolutionary system, researchers have fooled drug-resistant Escherichia coli into tossing their resistance. Then, with a shot of the drug that the bacteria could previously withstand, the E. coli met their end. Though the study was just done in lab dishes, the authors, led by researchers at Harvard, are hopeful that the one-two punch could be useful in reversing drug resistance and restoring the effectiveness of life-saving antibiotics.

This strategy could “add valuable tools to our antimicrobial arsenal,” they conclude.

Read 11 remaining paragraphs | Comments

Trump takes on “Crooked Hillary” with Snapchat geofilter

“Trump vs. Crooked Hillary” banner adorns personal photos, vids.

Want to make Snapchat great again? Donald Trump has given American users of the social media app that chance thanks to the service's first-ever nationwide "geofilter" ad campaign for a politician.

The ad rolled out to American Snapchat users today, just ahead of the 2016 presidential election's first major debate between Trump and Hillary Clinton (the debate starts tonight at 9pm EDT). The ad joins the usual geofilter available to Snapchat users, which usually list the name of a city or a nearby event as determined by GPS and time information.

As shown to the right (featuring me as its puzzled selfie star), the ad stamps a user's photo and video Snaps with a banner phrase reading "Donald J. Trump vs. Crooked Hillary," along with Trump's famed slogan and a note confirming that the candidate paid for the geofilter campaign.

Read 2 remaining paragraphs | Comments

Ars TV Guide: All the new shows you’ll want to check out this fall

Killer robots, dork rappers, time traveling terrorists, jerks in heaven, and more!

Fall TV season is in full swing, but there's still time to figure out what's worth watching from the new crop of shows just underway. At Ars, we've painstakingly evaluated the new fall titles for possible geek-related awesomeness and found a baker's dozen for you to check out. Remember—we've only included new shows, not returning ones that are coming back for a second or twelfth season. But feel free to wax poetic about your love for everything from Homeland to The Walking Dead in the comments.

Drama

StartUp

This intriguing series combines Miami gangster action with the tale of a startup that has created GenCoin, a crypto currency that could save the developing world (or... just allow drug dealers to launder their money faster). Either way, this is probably the season's most unexpected tech thriller, streaming on Crackle with a fantastic cast that includes Martin Freeman, Otmara Marrero, and Adam Brody.

StartUp is a tech series in the vein of Mr. Robot, where hacking isn't just a get-rich-quick scheme for VCs in Silicon Valley—it's also about global politics. In StartUp, building a tech company is a chance for its founders to escape from poverty and to help millions of other people in the world have access to bank accounts via mobile. Unfortunately, their angel investors are drug dealers, and their roadblocks involve eluding FBI investigators. The series started streaming on Crackle on September 6.

Read 14 remaining paragraphs | Comments

YouTube-MP3 Ripping Site Sued By IFPI, RIAA and BPI

A huge coalition of recording labels has sued the world’s leading YouTube ripping site. The IFPI, RIAA, and BPI in the UK say they are taking legal action against YouTube-MP3 to protect the rights of artists and labels. The site has a reported 60 million monthly visitors and is said to be “raking in millions” in advertising revenues.

Source: TF, for the latest info on copyright, file-sharing, torrent sites and ANONYMOUS VPN services.

Two weeks ago, the International Federation of the Phonographic Industry published research which claimed that half of 16 to 24-year-olds use stream-ripping tools to copy music from sites like YouTube.

The industry group said that the problem of stream-ripping has become so serious that in volume terms it had overtaken downloading from ‘pirate’ sites. Given today’s breaking news, the timing of the report was no coincidence.

Earlier today in a California District Court, a huge coalition of recording labels sued the world’s largest YouTube ripping site. UMG Recordings, Capitol Records, Warner Bros, Sony Music, Arista Records, Atlantic Records and several others claim that YouTube-MP3 (YTMP3), owner Philip Matesanz, and Does 1-10 have infringed their rights.

“YTMP3 rapidly and seamlessly removes the audio tracks contained in videos streamed from YouTube that YTMP3’s users access, converts those audio tracks to an MP3 format, copies and stores them on YTMP3’s servers, and then distributes copies of the MP3 audio files from its servers to its users in the United States, enabling its users to download those MP3 files to their computers, tablets, or smartphones,” the complaint reads.

The labels allege that YouTube-MP3 is one of the most popular sites in the entire world and as a result its owner, German-based company PMD Technologies UG, is profiting handsomely from their intellectual property.

“Defendants are depriving Plaintiffs and their recording artists of the fruits of their labor, Defendants are profiting from the operation of the YTMP3 website. Through the promise of illicit delivery of free music, Defendants have attracted millions of users to the YTMP3 website, which in turn generates advertising revenues for Defendants,” the labels add.

And it’s very clear that the labels mean business. YouTube-MP3 is being sued for direct, contributory, vicarious and inducement of copyright infringement, plus circumvention of technological measures.

Among other things, the labels are also demanding a preliminary and permanent injunction forbidding the Defendants from further infringing their rights. They also want YouTube-MP3’s domain name to be surrendered.

“This is a coordinated action to protect the rights of artists and labels from the blatant infringements of YouTube-mp3, the world’s single-largest ‘stream ripping’ site,” says IFPI Chief Executive Frances Moore.

“Music companies and digital services today offer fans more options than ever before to listen to music legally, when and where they want to do so – over hundreds of services with scores of millions of tracks – all while compensating artists and labels. Stream ripping sites should not be allowed jeopardize this.”

Cary Sherman, the Chairman and CEO of the Recording Industry Association of America (RIAA) says that YouTube-MP3 is making money on the back of their business and needs to be stopped.

“This site is raking in millions on the backs of artists, songwriters and labels. We are doing our part, but everyone in the music ecosystem who says they believe that artists should be compensated for their work has a role to play,” Sherman says.

“It should not be so easy to engage in this activity in the first place, and no stream ripping site should appear at the top of any search result or app chart.”

BPI Chief Executive Geoff Taylor says that it’s time for web services and related companies to stop supporting similar operations.

“It’s time to stop illegal sites like this building huge fortunes by ripping off artists and labels. Fans have access now to a fantastic range of legal music streaming services, but they can only exist if we take action to tackle the online black market,” Taylor says.

“We hope that responsible advertisers, search engines and hosting providers will also reflect on the ethics of supporting sites that enrich themselves by defrauding creators.”

TorrentFreak contacted YouTube-MP3 owner Philip Matesanz for comment but at the time of publication we were yet to receive a response.

Source: TF, for the latest info on copyright, file-sharing, torrent sites and ANONYMOUS VPN services.

BlackBerry DTEK60 Android phone hits the FCC

BlackBerry DTEK60 Android phone hits the FCC

BlackBerry’s next Android smartphone is likely coming soon. The company accidentally published details of the unannounced DTEK60 smartphone on its website last week, and although they’ve been removed since then, the phone recently showed up at the FCC website.

While the FCC listing doesn’t tell us much we didn’t already know about the phone, it does confirm that the DTEK60 supports 802.11ac WiFi, Bluetooth 4.2, NFC, and GSM LTE and HSPA+ networks.

Continue reading BlackBerry DTEK60 Android phone hits the FCC at Liliputing.

BlackBerry DTEK60 Android phone hits the FCC

BlackBerry’s next Android smartphone is likely coming soon. The company accidentally published details of the unannounced DTEK60 smartphone on its website last week, and although they’ve been removed since then, the phone recently showed up at the FCC website.

While the FCC listing doesn’t tell us much we didn’t already know about the phone, it does confirm that the DTEK60 supports 802.11ac WiFi, Bluetooth 4.2, NFC, and GSM LTE and HSPA+ networks.

Continue reading BlackBerry DTEK60 Android phone hits the FCC at Liliputing.

Microsoft pushes its three pillars at Ignite—security, intelligence, and cloud

It’s time for everyone to be all in on the cloud.

Enlarge / Atlanta (credit: Microsoft)

ATLANTA—At its Ignite conference today, Microsoft's Scott Guthrie, Executive Vice President for Cloud and Enterprise, explained that the company wants IT professionals to feel empowered and digitally transform the organizations. Accordingly, Microsoft is focusing on three areas to do this: security, intelligence, and the cloud.

The company announced a range of new security and data analytics features designed to make Windows, Office 365, and Azure run better. More importantly, they were designed, at least in part, to specifically make Windows 10 the safest, most secure place to work. Microsoft may be offering its software on more platforms than before, but while you don't have to use Windows, the company is suggesting you probably should.

The strongest example of this was the integration of Windows Defender Advanced Threat Protection (WDATP), which uses big data analysis to detect suspicious behavioral patterns that indicate a hacker or other security issue, and Office 365 Advanced Threat Protection (ATP), which works to trap malicious URLs and attachments.

Read 15 remaining paragraphs | Comments

Plex puts your video into Amazon cloud so it’s always available

Plex Cloud, in limited beta, solves problem of keeping home media server online.

Enlarge / Plex on Amazon Drive. (credit: Plex)

Plex, a service for streaming video and other media from a home PC or NAS device, has teamed up with Amazon to help customers stream their content from the cloud.

Plex is a great tool for making movies, music, and photos available to just about any device, whether you're at home or traveling. But the home computer that holds your Plex content must be powered on and connected to the Internet in order for it to work. A power failure or Internet outage at home could thus leave a Plex user without any streaming content when they're traveling.

Plex Cloud, announced today, could solve that problem. "Plex Cloud eliminates the need to run your own local Plex Media Server and manage an always-on computer or NAS," the announcement said. "Let Amazon worry about nasty stuff like power failure, corruption, and data loss. It turns out they’re pretty good at that stuff!"

Read 6 remaining paragraphs | Comments