Slashdot Deals: Cyber Monday Sale Extended! Courses ranging from coding to project management - all eLearning deals 20% off with coupon code "CYBERMONDAY20". ×

Australian State Bans Possession of Blueprints For 3D Printing Firearms ( 312

angry tapir writes: Possessing files that can be used to 3D print firearms will soon be illegal in the Australian state of New South Wales after new legislation, passed last week by state parliament, comes into effect. Possessing files for 3D printing guns will be punishable by up to 14 years in prison. The provisions "are targeted at criminals who think they can steal or modify firearms or manufacture firearms from 3D blueprints," NSW's justice minister, Troy Grant, said when introducing the bill in the state's lower house on 27 October. "Those who think they can skirt the law will find themselves facing some of the toughest penalties for firearms offences in this country," Grant said.

How Anonymous' War With Isis Is Actually Harming Counter-Terrorism ( 392

retroworks writes: According to a recent tweet from the #OpParis account, Anonymous are delivering on their threat to hack Isis, and are now flooding all pro-Isis hastags with the grandfather of all 2007 memes — Rick Astley's "Never Gonna Give You Up" music video. Whenever a targeted Isis account tries to spread a message, the topic will instead be flooded with countless videos of Rick Astley circa 1987. Not all are praising Anonymous methods, however. While Metro UK reports that the attacks have been successful, finding and shutting down 5,500 Twitter accounts, the article also indicates that professional security agencies have seen sources they monitor shut down. Rick Astley drowns out intelligence as well as recruitment.

Whistleblowers: How NSA Created the 'Largest Failure' In Its History ( 119

An anonymous reader writes: Former NSA whistleblowers contend that the agency shut down a program that could have "absolutely prevented" some of the worst terror attacks in memory. According to the ZDNet story: "Weeks prior to the September 11 terrorist attacks, a test-bed program dubbed ThinThread was shut down in favor of a more expensive, privacy-invasive program that too would see its eventual demise some three years later -- not before wasting billions of Americans' tax dollars. Four whistleblowers, including a congressional senior staffer, came out against the intelligence community they had served, after ThinThread. designed to modernize the agency's intelligence gathering effort, was cancelled. Speaking at the premier of a new documentary film A Good American in New York, which chronicles the rise and demise of the program, the whistleblowers spoke in support of the program, led by former NSA technical director William Binney."
United States

US and China Setting Up "Space Hotline" ( 15

Taco Cowboy writes: Washington and Beijing have established an emergency 'space hotline' to reduce the risk of accidental conflict. Several international initiatives are already in train to seal a space treaty to avoid a further build-up of weapons beyond the atmosphere. However, security experts say the initiatives have little chance of success. A joint Russia-China proposal wending its way through the UN was not acceptable to the US. An EU proposal, for a "code of conduct" in space, was having diplomatic "difficulties" but was closer to Washington's position.

Blackberry Offers 'Lawful Device Interception Capabilities' ( 137

An anonymous reader writes: Apple and Google have been vocal in their opposition to any kind of government regulation of cell phone encryption. BlackBerry, however, is taking a different stance, saying it specifically supports "lawful interception capabilities" for government surveillance. BlackBerry COO Marty Beard as much at a recent IT summit. He declined to explain how the interception works, but he denied the phones would contain "backdoors" and said governments would have no direct access to BlackBerry servers. The company may see this as a way to differentiate themselves from the competition.

Florida Group Wants To Make Space a 2016 Presidential Campaign Issue ( 118

MarkWhittington writes: According to a story on News 13, an Orlando TV station, Space Florida is working to make space a political issue in the 2016 presidential election. Thus far the campaign for the presidency has been dominated by more mundane issues such as the economy, illegal immigration, and the threat of terrorism. Space Florida, which is "the State of Florida's aerospace economic development agency," is said to be "working with three other battleground states to make sure America's space program is a part of the campaign for president." Presumably one of those states is Texas, which has lots of electoral votes

Sued Freelancer Allegedly Turns Over Contractee Source Code In Settlement 130

FriendlySolipsist writes: Blizzard Entertainment has been fighting World of Warcraft bots for years. TorrentFreak reports that Bossland, a German company that operates "buddy" bots, alleges Blizzard sued one of its freelancers and forced a settlement. As part of that settlement, the freelancer allegedly turned over Bossland's source code to Blizzard. In Bossland's view, their code was "stolen" by Blizzard because it was not the freelancer's to disclose. This is a dangerous precedent for freelance developers in the face of legal threats: damned if you do, damned if you don't.

Comcast Xfinity Wi-Fi Discloses Customer Names and Addresses ( 47

itwbennett writes: Despite assurances that only business listings and not customer names and home addresses would appear in the public search results when someone searches for an Xfinity Wi-Fi hotspot, that is exactly what's happened when the service was initiated 2 years ago — and is still happening now, writes CSO's Steve Ragan. And that isn't the only security issue with the service. Another level of exposure centers on accountability. Ken Smith, senior security architect with K Logix in Brookline, Ma., discovered that Comcast is relying on the device's MAC address as a key component of authentication.

FTC Amends Telemarketing Rule To Ban Payment Methods Used By Scammers 48

An anonymous reader writes: The Federal Trade Commission has approved final amendments to its Telemarketing Sales Rule (TSR), including a change that will help protect consumers from fraud by prohibiting four discrete types of payment methods favored by scammers. The TSR changes will stop telemarketers from dipping directly into consumer bank accounts by using certain kinds of checks and "payment orders" that have been "remotely created" by the telemarketer or seller. In addition, the amendments will bar telemarketers from receiving payments through traditional "cash-to-cash" money transfers – provided by companies like MoneyGram, Western Union, and RIA.

Ex-CIA Director Says Snowden Should Be 'Hanged' For Paris Attacks ( 486

SonicSpike writes with this excerpt from The HIll: A former CIA director says leaker Edward Snowden should be convicted of treason and given the death penalty in the wake of the terrorist attack on Paris. "It's still a capital crime, and I would give him the death sentence, and I would prefer to see him hanged by the neck until he's dead, rather than merely electrocuted," James Woolsey told CNN's Brooke Baldwin on Thursday. Woolsey said Snowden, who divulged classified information in 2013, is partly responsible for the terrorist attack in France last week that left at least 120 dead and hundreds injured. "I think the blood of a lot of these French young people is on his hands," he said.

Donald Trump Obliquely Backs a Federal Database To Track Muslims 594 writes: Philip Bump reports at the Washington Post that Donald Trump confirmed to NBC on Thursday evening that he supports a database to track Muslims in the United States. The database of Muslims arose after an interview Yahoo News's Hunter Walker conducted with Trump earlier this week, during which he asked the Republican front-runner to weigh in on the current debate over refugees from Syria. "We're going to have to do things that we never did before," Trump told Walker. "Some people are going to be upset about it, but I think that now everybody is feeling that security is going to rule." When pressed on whether these measures might include tracking Muslim Americans in a database or noting their religious affiliations on identification cards, Trump would not go into detail — but did not reject the options. Trump's reply? "We're going to have to — we're going to have to look at a lot of things very closely," he said. "We're going to have to look at the mosques. We're going to have to look very, very carefully." After an event on in Newton, Iowa, on Thursday night, NBC's Vaughn Hillyard pressed the point. "Should there be a database system that tracks Muslims here in this country?," Hillyard asked. "There should be a lot of systems, beyond databases" Trump said. "We should have a lot of systems." Hillyard asked about implementation, including the process of adding people to the system. "Good management procedures," Trump said. Sign people up at mosques, Hillyard asked? "Different places," Trump replied. "You sign them up at different places. But it's all about management."
The Courts

Judge: Stingrays Are 'Simply Too Powerful' Without Adequate Oversight ( 111

New submitter managerialslime sends news that an Illinois judge has issued new requirements the government must meet before it can use cell-site simulators, a.k.a. "stingrays," to monitor the communications of suspected criminals. While it's likely to set precedent for pushing back against government surveillance powers, the ruling is specific to the Northern District of Illinois for now. What is surprising is Judge Johnston’s order to compel government investigators to not only obtain a warrant (which he acknowledges they do in this case), but also to not use them when "an inordinate number of innocent third parties’ information will be collected," such as at a public sporting event. This first requirement runs counter to the FBI’s previous claim that it can warrantlessly use stingrays in public places, where no reasonable expectation of privacy is granted. Second, the judge requires that the government "immediately destroy" collateral data collection within 48 hours (and prove it to the court). Finally, Judge Johnston also notes: "Third, law enforcement officers are prohibited from using any data acquired beyond that necessary to determine the cell phone information of the target. A cell-site simulator is simply too powerful of a device to be used and the information captured by it too vast to allow its use without specific authorization from a fully informed court."

File Says NSA Found Way To Replace Email Program ( 93

schwit1 writes: Newly disclosed documents show that the NSA had found a way to create the functional equivalent of programs that had been shut down. The shift has permitted the agency to continue analyzing social links revealed by Americans' email patterns, but without collecting the data in bulk from American telecommunications companies — and with less oversight by the Foreign Intelligence Surveillance Court.

The disclosure comes as a sister program that collects Americans' phone records in bulk is set to end this month. Under a law enacted in June, known as the USA Freedom Act, the program will be replaced with a system in which the NSA can still gain access to the data to hunt for associates of terrorism suspects, but the bulk logs will stay in the hands of phone companies.

The newly disclosed information about the email records program is contained in a report by the NSA's inspector general that was obtained through a lawsuit under the Freedom of Information Act. One passage lists four reasons the NSA decided to end the email program and purge previously collected data. Three were redacted, but the fourth was uncensored. It said that "other authorities can satisfy certain foreign intelligence requirements" that the bulk email records program "had been designed to meet."


Nation-backed Hackers Using Evercookie and Web Analytics To Profile Targets ( 47

chicksdaddy writes: There's such a fine line between clever and criminal. That's the unmistakable subtext of the latest FireEye report on a new "APT" style campaign that's using methods and tools that are pretty much indistinguishable from those used by media websites and online advertisers. The difference? This time the information gathered from individuals is being used to soften up specific individuals with links to international diplomacy, the Russian government, and the energy sector.

The company released a report this week that presented evidence of a widespread campaign (PDF) that combines so-called "watering hole" web sites with a tracking script dubbed "WITCHCOVEN" and Samy Kamkar's Evercookie, the super persistent web tracking cookie. The tools are used to assemble detailed profiles on specific users including the kind of computer they use, the applications and web browsers they have installed, and what web sites they visit.

While the aims of those behind the campaign aren't known, FireEye said the use of compromised web sites and surreptitious tracking scripts doesn't bode well. "While many sites engage in profiling and tracking for legitimate purposes, those activities are typically conducted using normal third-party browser-based cookies and commercial ad services and analytics tools," FireEye wrote in its report. "In this case, while the individuals behind the activity used publicly available tools, those tools had very specific purposes....This goes beyond 'normal' web analytics," the company said.


EU Set To Crack Down On Bitcoin and Anonymous Payments After Paris Attack ( 275

An anonymous reader writes: Home affairs ministers from the European Union are set to gather in Brussels for crisis talks in the wake of the Paris attacks, and a crackdown on Bitcoin, pre-paid credit card and other forms of 'anonymous' online payments are on the agenda. From the article: "According to draft conclusions of the meeting, European interior and justice ministers will urge the European Commission (the EU executive arm) to propose measures to strengthen the controls of non-banking payment methods. These include electronic/anonymous payments, virtual currencies and the transfers of gold and precious metals by pre-paid cards."

FDA Signs Off On Genetically Modified Salmon Without Labeling ( 514

kheldan writes: Today, in a historic decision, the FDA approved the marketing of genetically-engineered salmon for sale to the general public, without any sort of labeling to indicate to consumers they've been genetically altered. According to the article: "Though the Federal Food, Drug, and Cosmetic Act (FD&C Act) gives the FDA the authority to require mandatory labeling of foods if there is a material difference between a GE product and its conventional counterpart, the agency says it is not requiring labeling of these GE fish 'Because the data and information evaluated show that AquAdvantage Salmon is not materially different from other Atlantic salmon.' In this case, the GE salmon use an rDNA construct composed of the growth hormone gene from Chinook salmon under the control of a promoter from another type of fish called an 'ocean pout.' According to the FDA, this tweak to the DNA allows the salmon to grow to market size faster than non-GE farm-raised salmon."
Social Networks

EFF launches Site To Track Censored Content On Social Media ( 39

Mark Wilson writes: There are many problems with the censoring of online content, not least that it can limit free speech. But there is also the question of transparency. By the very nature of censorship, unless you have been kept in the loop you would simply not know that anything had been censored. This is something the Electronic Frontier Foundation wants to change, and today the digital rights organization launches to blow the lid off online censorship. The site, run by EFF and Visualizing Impact, aims to reveal the content that is censored on Facebook, Google+, Twitter, Instagram, Flickr, and YouTube — not just the 'what' but the 'why'. If you find yourself the subject of censorship, the site also explains how to lodge an appeal.
The Media

Reuters Bans RAW Photo Format ( 206

grcumb writes: Reuters is the latest agency to join the ranks of the technically clueless who think that ethical problems can be solved using technical means. They recently issued a circular to their contributors, stating in part: "In future, please don't send photos to Reuters that were processed from RAW or CR2 files. If you want to shoot raw images that's fine, just take JPEGs at the same time. Only send us the photos that were originally JPEGs, with minimal processing...." The problem they claim to be addressing is doctored images, but they don't explain how they plan to ensure that the JPEGs weren't simply exported from RAW files with their EXIF data altered, or heck, just altered as JPEG. They also assert that getting JPEG files straight from the camera is quicker, which is fair enough. Lots of professionals shoot with RAW+JPEG at newsworthy events. They can send the JPEGs off quickly to meet the first deadline, then process the RAW files at leisure for higher quality publications.

YouTube Defending Select Videos Against DMCA Abuse 56

Galaga88 writes: It's not a complete solution, but YouTube is going to begin stepping up to defend select videos in court on fair use terms, including covering court costs. Will this help stem the tide of bad DMCA takedown requests, or just help the select few YouTube doesn't want to lose? From the blog post linked: We are offering legal support to a handful of videos that we believe represent clear fair uses which have been subject to DMCA takedowns. With approval of the video creators, we’ll keep the videos live on YouTube in the U.S., feature them in the YouTube Copyright Center as strong examples of fair use, and cover the cost of any copyright lawsuits brought against them. ... In addition to protecting the individual creator, this program could, over time, create a “demo reel” that will help the YouTube community and copyright owners alike better understand what fair use looks like online and develop best practices as a community.

Chicago Sends More Than 100,000 "Bogus" Camera-Based Speeding Tickets 200

Ars Technica, based on an in-depth report (paywalled) at the Chicago Tribune, says that the city of Chicago has been misusing traffic cameras to trigger automated speeding tickets. In particular, these cameras are placed in places where there are enhanced penalties for speeding, putatively intended to increase child safety. The automated observation system, though, has been used to send well over 100,000 tickets that the Tribune analysis deems "questionable," because they lack the evidence which is supposed to be required -- for instance, many of these tickets are unbacked by evidence of the presence of children, or were issued when the speeding rules didn't apply (next to a park when that park was closed).