Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror

Submission + - Android Was 2016's Most Vulnerable Product, Oracle the (bleepingcomputer.com)

An anonymous reader writes: According to CVE Details, a website that aggregates historical data on security bugs that have received a CVE identifier, during 2016, security researchers have discovered and reported 523 security bugs in Google's Android OS, winner by far of this "award." The rest of the top 10 is made up by Debian (319 bugs), Ubuntu (278 bugs), Adobe Flash Player (266 bugs), openSUSE Leap (259 bugs), openSUSE (228 bugs), Adobe Acrobat DC (227 bugs), Adobe Acrobat Reader DC (227 bugs), Adobe Acrobat (224 bugs), and the Linux Kernel (216 bugs).

When it comes to software vendors, the company for which the largest number of new CVE numbers have been assigned was Oracle, with a whopping 798 CVEs, who edged out Google (698 bugs), Adobe (548 bugs), Microsoft (492 bugs), Novell (394), IBM (382 bugs), Cisco (353 bugs), Apple (324 bugs), Debian Project (320 bugs), and Canonical (280 bugs).

Submission + - Millions of Websites Vulnerable Due to Security Bug in Popular PHP Script (bleepingcomputer.com)

An anonymous reader writes: A security flaw discovered in a common PHP class allows knowledgeable attackers to execute code on a website that uses a vulnerable version of the script, which in turn can allow an attacker to take control over the underlying server. The vulnerable library is PHPMailer, a PHP script that allows developers to automate the task of sending emails using PHP code, also included with WordPress, Drupal, Joomla, and more.

The vulnerability was fixed on Christmas with the release of PHPMailer 5.2.18. Nevertheless, despite the presence of a patched version, it will take some time for the security update to propagate. Judging by past incidents, millions of sites will never be updated, leaving a large chunk of the Internet open to attacks.

Even if the security researcher who discovered the flaw didn't publish any in-depth details about his findings, someone reverse-engineered the PHPMailer patch, and published exploit code online, allowing others to automate attacks using this flaw, largely still unpatched due to the holiday season.

IOS

WWDC 2015 Roundup 415

Here's an overview of the main announcements and new products unveiled at WWDC today.
  • The latest OS X will be named OS X El Capitan. Features include: Natural language searches and auto-arrange windows. You can make the cursor bigger by shaking the mouse and pin sites in Safari now. 1.4x faster than Yosemite. Available to developers today, public beta in July, out for free in the fall.
  • Metal, the graphics API is coming to Mac. "Metal combines the compute power of OpenCL and the graphics power of OpenGL in a high-performance API that does both." Up to 40% greater rendering efficiency.
  • iOS 9: New Siri UI. There’s an API for search. Siri and Spotlight are getting more integrated. Siri getting better at prediction with a far lower word error rate. You can make checklists, draw and sketch inside of Notes. Maps gets some love. New app called News "We think this offers the best mobile reading experience ever." Like Flipboard it pulls in news articles from your favorite sites. HomeKit now supports window shades, motion sensors, security systems, and remote access via iCloud. Public Beta for iOS 9.
  • Apple Pay: All four major credit card companies and over 1 million locations supporting Apple Pay as of next month. Apple Pay reader developed by Square, for peer-to-peer transactions. Apple Pay coming to the UK next month support in 250,000 locations including the London transportation system. Passbook is being renamed "Wallet."
  • iPad: Shortcuts for app-switching, split-screen multitasking and QuickType. Put two fingers down on the keyboard and it becomes a trackpad. Side by side apps. Picture in picture available on iPad Air and up, Mini 2 and up.
  • CarPlay: Now works wirelessly and supports apps by the automaker.
  • Swift 2,the latest version of Apple’s programing language . Swift will be open source.
  • The App Store: Over 100 billion app downloads, and $30 billion paid to developers.
  • Apple Watch: watchOS 2 with new watch faces. Developers can build their own "complications" (widgets with a terrible name that show updates and gauges on the watch face). A new feature called Time Travel lets you rotate the digital crown to zoom into the future and see what’s coming up. More new features: reply to email, bedside alarm clock, send scribbled messages in multiple colors. You can now play video on the watch. Developer beta of watchOS 2 available today, wide release in the fall for free.
  • Apple Music: “The next chapter in music. It will change the way you experience music forever,” says Cook. Live DJs broadcasting and hosting live radio streams you can listen to in 150 countries. Handpicked suggestions. 24/7 live global radio. Beats Connect lets unsigned artists connect with fans. Beats Music has all of iTunes’ music, to buy or stream. With curated recommendations. Launching June 30th in 100 countries with Android this fall, with Windows and Android versions. First three months free, $9.99 a month or $14.99 a month for family plan for up to six.
Medicine

Video Is the Apple Watch a Useful Medical Device? (Video) 47

Let's kill the suspense right away by answering the title question, 'Probably not.' For one thing, according to interviewee Alfred Poor, the Apple Watch is in no way linked to the Apple Research Kit. Dr. Poor is editor of the Health Tech Insider website, so he follows this kind of thing more carefully than most people. And the Apple watch is not the only device mentioned in this video (or transcript, if you prefer reading to listening). If you want to ruminate about the possibility of direct mind control, for instance, you need to know about the Thync, whose vendor calls it 'A groundbreaking wearable device that enables you to shift your state of mind in minutes.' They say it 'induces on-demand shifts in energy, calm, or focus.' It even has a 'pleasure' setting. Crank that to 11 and you might happily spend your days prone, being fed by a drip and emptied by a catheter, moving only when an attendant turns you over to keep bedsores from developing -- not that you'll care if they do -- as you spend the rest of your life in an artificially-induced joyful stupor.

Submission + - 19,000 French Websites Hit By DDoS, Defaced In Wake Of Terror Attack

An anonymous reader writes: Since the three day terror attack that started in France on January 7 with the attack on satirical newspaper Charlie Hebdo, 19,000 websites of French-based companies have been targeted by cyber attackers. This unprecedented avalanche of cyber attacks targeted both government sites and that of big and small businesses. Most were low-level DDoS attacks, and some were web defacements. Several websites in a number of towns in the outskirts of Paris have been hacked and covered with an image of an ISIS flag. The front pages of the official municipality websites have been covered with the Jihadist militant group's black flag. In a report, Radware researchers noted that Islamic hacker group AnonGhost has also launched a "digital jihad" against France.

Submission + - Revolutionary stretchable implant enables broken spinal cord to function again (robohub.org)

An anonymous reader writes: A team from EPFL and NCCR Robotics lead by Profs Stéphanie Lacour, Grégoire Courtine and Silvestro Micera published an article in Science today describing their e-dura implant that could revolutionise how we think about and treat paralysis. Until now, implants placed beneath the dura mater of the spinal cord have caused significant tissue damage when used over long periods. Research shows that the new e-dura implant is viable for months at a time in animal subjects. The team is now moving on to clinical trials in human subjects and is developing their prototype to take to market.

Comment It takes a while (Score 1) 464

I sit in front of a computer pretty much from the moment I wake up to the moment I go back to bed and I've been wearing progressive lenses for about a year now. The correct for both close up and distance.

At first it was a major hassle as I found myself moving my head more and actively trying to find the correct 'sweet spot' for whatever I was looking at.

I really don't have a problem with them now, I thnk it took about a month for me not to notice the additional head movement.

It might be worth going back to your optometrist and check your glasses have been ground correctly - an eye test with your glasses on should suffice. Mistakes are not common but the can occur

Submission + - How civilisations can spread across a galaxy

kanweg writes: If you look at the milky way at night, it appears not much is changing. But over time, stars get closer and further to each other. Coryn Bailer-Jones, an astrophysicist at Germany’s Max Planck Institute for Astronomy in Heidelberg, found that of 14 stars coming within 3 light years of Earth, the closest encounter is likely to be HIP 85605, which now lies some 16 light years away in the constellation of Hercules. It will get a close as the Oort cloud.
Human or alien civilisations could practice star hopping. Why travel 16 light years through space when you can just wait until a star with a suitable planet gets close and cover only the last stretch with an artificial spaceship? Take your time for a thoughtful response; it will take another 250,000 to 470,000 year before the close encounter.

Submission + - School Defied Google and US Government, Let Boys Program White House Xmas Trees

theodp writes: This holiday season, Google and the National Parks partnered to let girls program the White House Christmas tree lights. While the initiative earned kudos in Fast Company's 9 Giant Leaps For Women In Science and Technology In 2014, it also prompted an act of civil disobedience of sorts from St. Augustine of Canterbury School, which decided Google and the U.S. government wouldn't determine which of their kids would be allowed to participate in the coding event. "We decided to open it up to all our students, both boys and girls so that they could be a part of such an historic event, and have it be the kickoff to our Hour of Code week," explained Debra Knox, a technology teacher at St. Augustine.

Slashdot Top Deals

After all is said and done, a hell of a lot more is said than done.

Working...