×
United Kingdom

UK Parliament Passes Online Safety Bill (techcrunch.com) 75

An anonymous reader quotes a report from TechCrunch: Controversial UK legislation that brings in a new regime of content moderation rules for online platforms and services -- establishing the comms watchdog Ofcom as the main Internet regulator -- has been passed by parliament today, paving the way for Royal Assent and the Online Safety Bill becoming law in the coming days. Speaking during the bill's final stages in the House of Lords, Lord Parkinson of Whitley Bay reiterated that the government's intention for the legislation is "to make the UK the safest place in the world to be online, particularly for children." Following affirmative votes as peers considered some last stage amendments he added that attention now moves "very swiftly to Ofcom who stand ready to implement this -- and do so swiftly."

The legislation empowers Ofcom to levy fines of up to 10% (or up to 18 million pounds whichever is higher) of annual turnover for violations of the regime. The Online Safety (nee Harms) Bill has been years in the making as UK policymakers have grappled with how to response to a range of online safety concerns. In 2019 these efforts manifested as a white paper with a focus on rules for tackling illegal content (such as terrorism and CSAM) but also an ambition to address a broad sweep of online activity that might be considered harmful, such as violent content and the incitement of violence; encouraging suicide; disinformation; cyber bullying; and adult material being accessed by children. The effort then morphed into a bill that was finally published in May 2021. [...]

In a brief statement the UK's new web content sheriff gave no hint of the complex challenges that lie ahead -- merely welcoming the bill's passage through parliament and stating that it stands ready to implement the new rulebook. "Today is a major milestone in the mission to create a safer life online for children and adults in the UK. Everyone at Ofcom feels privileged to be entrusted with this important role, and we're ready to start implementing these new laws," said Dame Melanie Dawes, Ofcom's CEO. "Very soon after the Bill receives Royal Assent, we'll consult on the first set of standards that we'll expect tech firms to meet in tackling illegal online harms, including child sexual exploitation, fraud and terrorism." Beyond specific issues of concern, there is over-arching general worry over the scale of the regulatory burden the legislation will apply to the UK's digital economy -- since the rules apply not only to major social media platforms; scores of far smaller and less well resourced online services must also comply or risk big penalties.

Security

Chinese Hackers Have Unleashed a Never-Before-Seen Linux Backdoor (arstechnica.com) 35

Researchers have discovered a never-before-seen backdoor for Linux that's being used by a threat actor linked to the Chinese government. From a report: The new backdoor originates from a Windows backdoor named Trochilus, which was first seen in 2015 by researchers from Arbor Networks, now known as Netscout. They said that Trochilus executed and ran only in memory, and the final payload never appeared on disks in most cases. That made the malware difficult to detect. Researchers from NHS Digital in the UK have said Trochilus was developed by APT10, an advanced persistent threat group linked to the Chinese government that also goes by the names Stone Panda and MenuPass.

Other groups eventually used it, and its source code has been available on GitHub for more than six years. Trochilus has been seen being used in campaigns that used a separate piece of malware known as RedLeaves. In June, researchers from security firm Trend Micro found an encrypted binary file on a server known to be used by a group they had been tracking since 2021. By searching VirusTotal for the file name, ââlibmonitor.so.2, the researchers located an executable Linux file named "mkmon." This executable contained credentials that could be used to decrypt the libmonitor.so.2 file and recover its original payload, leading the researchers to conclude that "mkmon" is an installation file that delivered and decrypted libmonitor.so.2.

The Linux malware ported several functions found in Trochilus and combined them with a new Socket Secure (SOCKS) implementation. The Trend Micro researchers eventually named their discovery SprySOCKS, with "spry" denoting its swift behavior and the added SOCKS component. SprySOCKS implements the usual backdoor capabilities, including collecting system information, opening an interactive remote shell for controlling compromised systems, listing network connections, and creating a proxy based on the SOCKS protocol for uploading files and other data between the compromised system and the attacker-controlled command server.

Transportation

European Governments Shrinking Railways in Favour of Road-Building, Report Finds (theguardian.com) 209

European governments have "systematically" shrunk their railways and starved them of funding while pouring money into expanding their road network, a report has found. The Guardian: The length of motorways in Europe grew 60% between 1995 and 2020 while railways shrank 6.5%, according to research from the German thinktanks Wuppertal Institute and T3 Transportation. For every $1 governments spent building railways, they spent $1.7 building roads. "This is a political choice," said Lorelei Limousin, a climate campaigner with Greenpeace, which commissioned the report. "We see the consequences today with the climate, but also with people who have been left without an alternative solution to cars."

The report found the EU, Norway, Switzerland and the UK spent $1.6tn between 1995 and 2018 to extend their roads -- but just $0.99tn to extend their rail networks. In the four years that followed (2018-21), the average gap in investment in rail and road decreased from 66% to 34%. During that time, seven countries invested more in rail than roads -- Austria, Belgium, Denmark, France, Italy, Luxembourg and the UK -- while the rest spent more on roads than rail.

Earth

Oil Companies Granted Licences To Store Carbon Under the North Sea (theguardian.com) 39

Oil companies have been granted licences by the UK government that it hopes will enable them to store up to 10% of the UK's carbon emissions in old oil and gasfields beneath the seabed. From a report: The government awarded more than 20 North Sea licences covering an area the size of Yorkshire to 14 companies that plan to store carbon dioxide trapped from heavy industry in depleted oil and gasfields. The companies include the oil supermajor Shell, Italy's state-owned oil company ENI, and Harbour Energy, the largest independent oil and gas company operating in the UK's North Sea basin.

The industry's government-backed regulator, the North Sea Transition Authority (NSTA), claims the companies could help store up to 30m tonnes of CO2 a year by 2030, or approximately 10% of UK annual emissions. The plan to develop old oil and gasfields into vast repositories of CO2 is part of the government's plan to develop a carbon capture and storage (CCS) industry to reduce emissions from heavy industry entering the atmosphere and contributing to global heating. Stuart Payne, the NSTA's chief executive, said: "Carbon storage will play a crucial role in the energy transition, storing carbon dioxide deep under the seabed and playing a key role in hydrogen production and energy hubs."

Science

Ian Wilmut, Scientist Behind Dolly the Cloned Sheep, Is Dead at 79 (ed.ac.uk) 22

Ian Wilmut, the British scientist who led the project that cloned a mammal for the first time, Dolly the sheep, died on Sunday at the age of 79. The Roslin Institute, a research center near Edinburgh where Dr. Wilmut had worked for decades, said in a statement that the cause was complications of Parkinson's disease. From the statement: Ian Wilmut was born near Stratford-upon-Avon before the family moved to Yorkshire. It was at school in Scarborough that he first became interested in biology. He went to the University of Nottingham, initially to study agriculture, later switching to animal science. His studies continued with a PhD and fellowship at the University of Cambridge, focused on the preservation of semen and embryos by freezing. This work led to the birth of Frostie, the first calf to be born from a frozen embryo.

Dr Wilmut then moved to the Animal Breeding Research Organisation (ABRO), near Edinburgh, the predecessor to the Roslin Institute. He continued to work with reproductive cells and embryos, and contributed to a project to make genetically modified sheep that could produce milk containing proteins used to treat human diseases. This highlighted that a new, more efficient method of developing sheep with these characteristics was needed. He led efforts to develop cloning, or nuclear transfer, techniques that could be used to make genetically modified sheep. It was these efforts which led to the births of Megan and Morag in 1995 and Dolly in 1996. Polly, the first mammal to be both cloned and genetically modified, was born in 1997. Following the success of the cloning research, Dr Wilmut began to focus on using cloning to make stem cells which could be used in regenerative medicine.

United States

US Behind More Than a Third of Global Oil and Gas Expansion Plans, Report Finds (theguardian.com) 107

An anonymous reader shares a report: The US accounts for more than a third of the expansion of global oil and gas production planned by mid-century, despite its claims of climate leadership, research has found. Canada and Russia have the next biggest expansion plans, calculated based on how much carbon dioxide is likely to be produced from new developments, followed by Iran, China and Brazil. The United Arab Emirates, which is to host the annual UN climate summit this year, Cop28 in Dubai in November, is seventh on the list.

The data, in a report from the campaign group Oil Change International, also showed that five "global north countries" -- the US, Canada, Australia, Norway and the UK -- will be responsible for just over half of all the planned expansion from new oil and gas fields to 2050. Greenhouse gas emissions from all of the oil and gas expansion that is planned in the next three decades would be more than enough to drive global temperatures well beyond the limit of 1.5C above pre-industrial levels that countries agreed in 2021 at Cop26 in Glasgow, the report found.

NASA

Asteroid Behaving Unexpectedly After NASA's Deliberate DART Crash (bbc.co.uk) 36

One year ago NASA crashed its DART spacecraft into the asteroid "Dimorphos" (which orbits around a much larger asteroid named "Didymos"). The BBC calls the mission "part of an experiment to change the space rock's direction and test Earth's defences against asteroids in the future.

"However, a teacher and his class studying the rock have now discovered that since the collision, it has moved in a strange and unexpected way." [U]sing their school telescope, a team of children and their teacher Jonathan Swift at Thacher School in California have found that more than a month after the collision, Dimorphos' orbit continuously slowed after impact... which is unusual and unexpected. As reported in the New Scientist, the team presented their findings at a meeting of the American Astronomical Society.

After discovering the unusual behaviour of Dimorphos, it's likely that Nasa will have to factor in the high school's findings, if they ever launch another asteroid redirection mission in the future... One explanation for the asteroid's orbit continuing to change so long after the Dart collision is that material thrown up by the impact, including rocks several metres across, eventually fell back onto the surface of the asteroid, changing its orbit even more. The European Space Agency is launching a mission called Hera, which will arrive at Dimorphos in 2026 and could reveal more details as to what happened to the asteroid following the impact.

AI

Anthropic Launches Claude Pro, a Subscription AI That May Rival ChatGPT Plus (arstechnica.com) 9

An anonymous reader quotes a report from Ars Technica: On Thursday, AI-maker and OpenAI competitor Anthropic launched Claude Pro, a subscription-based version of its Claude.ai web-based AI assistant, which functions similarly to ChatGPT. It's available for $20/month in the US or 18 pounds/month in the UK, and it promises five-times-higher usage limits, priority access to Claude during high-traffic periods, and early access to new features as they emerge. Like ChatGPT, Claude Pro can compose text, summarize, do analysis, solve logic puzzles, and more.

Claude.ai is what Anthropic offers as its conversational interface for its Claude 2 AI language model, similar to how ChatGPT provides an application wrapper for the underlying models GPT-3.5 and GPT-4. In February, OpenAI chose a subscription route for ChatGPT Plus, which for $20 a month also gives early access to new features, but it also unlocks access to GPT-4, which is OpenAI's most powerful language model. What does Claude have that ChatGPT doesn't? One big difference is a 100,000 token context window, which means it can process about 75,000 words at once. Tokens are fragments of words used while processing text. That means Claude can analyze longer documents or hold longer conversations without losing its memory of the subject at hand. ChatGPT can only process about 8,000 tokens in GPT-4 mode.

Anthropic's primary selling point for the Claude Pro subscription is "5x more usage," but the company doesn't clearly communicate what Claude's free-tier usage limits actually are. Dropping clues like cryptic breadcrumbs, the company has written a support document about the topic that says, "If your conversations are relatively short (approximately 200 English sentences, assuming your sentences are around 15-20 words), you can expect to send at least 100 messages every 8 hours, often more depending on Claude's current capacity. Over two thirds of all conversations on claude.ai (as of September 2023) have been within this length." In another somewhat cryptic statement, Anthropic writes, "If you upload a copy of The Great Gatsby, you may only be able to send 20 messages in that conversation within 8 hours." We're not attempting the math, but if you know the precise word count of F. Scott Fitzgerald's classic, it may be possible to glean Claude's actual limits. We reached out to Anthropic for clarification yesterday and have not received a response by press time.

Oracle

Largest Local Government Body In Europe Goes Under Amid Oracle Disaster (theregister.com) 110

Birmingham City Council, the largest local authority in Europe, has declared itself in financial distress after troubled Oracle project costs ballooned from $25 million to around $125.5 million. The Register reports: Contributing to the publication of a legal Section 114 Notice, which says the $4.3 billion revenue organization is unable to balance the books, is a bill of up to $954 million to settle equal pay claims. In a statement today, councillors John Cotton and Sharon Thompson, leader and deputy leader respectively, said the authority was also hit by financial stress owing to issues with the implementation of its Oracle IT system. The council has made a request to the Local Government Association for additional strategic support, the statement said.

In May, Birmingham City Council said it was set to pay up to $125.5 million for its Oracle ERP system -- potentially a fourfold increase on initial estimated expenses -- in a project suffering from delays, cost over-runs, and a lack of controls. After grappling with the project to replace SAP for core HR and finance functions since 2018, the council reviewed the plan in 2019, 2020, and again in 2021, when the total implementation cost for the project almost doubled to $48.5 million. The project, dubbed Financial and People, was "crucial to an organisation of Birmingham City Council's size," a spokesperson said at the time. Cotton said the system had a problem with how it was "tracking our financial transactions and HR transactions issues as well. That's got to be fixed," he said.

Earlier this year, one insider told The Register that Oracle Fusion, the cloud-based ERP system the council is moving to, "is not a product that is suitable for local authorities, because it's very much geared towards a manufacturing/trading organization." They said the previous SAP system had been heavily customized to meet the council's needs and it was struggling to recreate these functions in Oracle.

United Kingdom

UK Air-Traffic Software Misread Spots on Map To Cause Outage (bloomberg.com) 26

The UK's worst air-traffic outage in a decade was caused by an anomaly in the airspace manager's software system, which confused two geographical checkpoints separated by some 4,000 nautical miles. From a report: The UK's Civil Aviation Authority said Wednesday it will conduct an independent review of the incident, which forced hundreds of flights to be canceled or delayed last week after an error in processing an airline's flight plan. The glitch triggered a shutdown of the software system run by NATS for safety reasons, according to a preliminary report from the public-private partnership formerly called National Air Traffic Services. This forced air-traffic staff to input flight plans manually, drastically reducing the amount of air traffic that could be processed.

The event sent airlines and airports in the UK into turmoil on Aug. 28, leaving planes out of position and passengers stranded. Nearly 800 flights leaving UK airports were canceled, with a similar number of arrivals scrapped, according to analytics firm Cirium. The report by NATS showed that on the day of the incident, an airline entered a plan into the system which led through UK airspace. NATS Chief Executive Officer Martin Rolfe declined to discuss details of the flight, such as its route or the airline involved, saying the specifics weren't pertinent to the outage. While the flight plan wasn't faulty, it threw off the system because the software used by NATS received duplicate identities for two different points on the map. There are an infinite number of flight-plan waypoints in the world, and duplicates remain despite work to remove them, according to Rolfe.

Privacy

UK Pulls Back From Clash With Big Tech Over Private Messaging (ft.com) 20

The UK government will concede it will not use controversial powers in the online safety bill to scan messaging apps for harmful content until it is "technically feasible" to do so, postponing measures that critics say threaten users' privacy. Financial Times: A planned statement to the House of Lords on Wednesday afternoon will mark an eleventh-hour bid by ministers to end a stand-off with tech companies, including WhatsApp, that have threatened to pull their services from the UK over what they claimed was an intolerable threat to millions of users' security. The statement is set to outline that Ofcom, the tech regulator, will only require companies to scan their networks when a technology is developed that is capable of doing so, according to people briefed on the plan. Many security experts believe it could be years before any such technology is developed, if ever.

"A notice can only be issued where technically feasible and where technology has been accredited as meeting minimum standards of accuracy in detecting only child sexual abuse and exploitation content," the statement will say. The online safety bill, which has been in development for several years and is now in its final stages in parliament, is one of the toughest attempts by any government to make Big Tech companies responsible for the content that is shared on their networks.

United Kingdom

UK Government Lifts Ban On Onshore Wind Farms (apnews.com) 118

The British Conservative government has eased planning rules and lifted restrictions that had effectively prohibited the construction of new onshore wind farms in England. The Independent reports: Rules introduced in 2015 by then-Prime Minister David Cameron, who also led a Conservative administration, allowed a single objection to a wind turbine application to block its development. The regulations led to a dramatic decline in the number of new turbines granted planning permission. Some Conservatives pressured the current government to overturn the rules. Lawmaker Alok Sharma, who was president of the 2021 U.N. climate change conference and led the lobbying campaign, called them "outdated" and "not a sensible way for a planning system to operate."

Authorities said Tuesday that the eased restrictions mean that onshore wind projects supported by local residents will get approved more quickly. They said elected local officials will have the ability to make final decisions based on the prevailing view of their communities, not just a small number of objectors. Communities that back wind turbines in their areas will also benefit from cheaper electricity, officials said, adding that the way such energy discounts work would be considered later.

EU

Facebook Is Getting Rid of the News Tab In the UK, France and Germany (cnbc.com) 21

Starting in December, Facebook users in the U.K., France and Germany will no longer see a dedicated section for news articles. CNBC reports: Meta said Tuesday that it is plans to "deprecate" the Facebook News tab in early December for users in those European countries as "part of an ongoing effort to better align our investments to our products and services people value the most." The company added that it plans to spend more time and money on short-form video, as best exemplified by its TikTok-like Reels product.

News represents less than 3% of what people see in their Facebook feeds, Meta said. Meta said it would honor the Facebook News obligations it had made to publishers in those countries, but said it won't enter into new deals and has no plans to offer new products for news publishers.
In June, Meta removed all news content from Facebook and Instagram for users in Canada, following the passage of a bill requiring big tech companies to compensate news businesses when their content is made available on their services.
United States

Australian MPs To Lobby US To Drop Julian Assange Prosecution or Risk 'Very Dangerous' Precedent for Russia and China (theguardian.com) 117

Julian Assange's supporters will urge the US to drop the prosecution of the Australian citizen on the basis the "very dangerous" precedent will be exploited by China and Russia. From a report: Six Australian politicians are expected to focus on freedom-of-speech arguments when they fly to Washington DC later this month to warn against extraditing the WikiLeaks founder from the UK. The MPs and senators from across the political spectrum are aiming to help build momentum for the prime minister, Anthony Albanese, to raise the case in bilateral talks with Joe Biden at the White House in late October. The trip is being funded by the Assange campaign.

Assange remains in Belmarsh prison in London as he fights a US attempt to extradite him to face charges in connection with the publication of hundreds of thousands of leaked documents about the Afghanistan and Iraq wars as well as diplomatic cables. Greg Barns SC, an adviser to the Assange campaign, said on Tuesday that it was "not an ordinary run-of-the-mill extradition case." He said freedom of speech was "an important theme in the US."

"You've got China chasing journalists around the world, and you've got the Russians who have recently arrested journalists," Barns told Guardian Australia. "You've now got China using the Assange case as a sort of moral equivalence argument. So the message [of the Australian delegation] is going to be: this is very dangerous for journalists around the world and a race to the bottom that's going on."

United States

Wanted: Skilled Workers To Combat the Rise in Cyber Crime (ft.com) 82

As a growing number of hackers target companies, organisations and industries with debilitating attacks, more skilled cyber security workers are urgently needed to combat the threat.ÂFrom a report: ISC2, the world's largest association of cyber professionals, estimates that the cyber security workforce in 2022 stood at about 4.7mn people globally. But a further 3.4mn roles remain unfilled. "The gap is massive," says Clar Rosso, ISC2's chief executive. "This shortfall is felt more acutely in countries such as India where digitisation is rapid. But even in the US, only 69 per cent of cyber roles are filled, according to Cyberseek, a website that provides data about the cyber security job market."

Beyond a talent shortfall, existing workers are underskilled. A UK government report this year found that 50 per cent of UK businesses -- some 739,000 in total -- have a basic cyber skills gap, meaning that those in charge of cyber security lack the confidence to carry out the technical measures that protect against the most common digital attacks. Previously, it was thought that a company's IT team could take care of all cyber security concerns. But "over time, it became clear that this needed specialised attention," Rosso says, adding that, after some high-profile ransomware attacks over the past couple of years, "business executives are now paying attention."

Japan

China Accused of 'Coordinated Disinformation Campaign' About Fukushima Waste Water in Multiple Countries (bbc.com) 114

The BBC has an article about Japan's release into the sea of treated waste water from the damaged Fukushima nuclear plant. "Scientists largely agree that the impact will be negligible, but China has strongly protested the release. And disinformation has only fuelled fear and suspicion in China." A report by a UK-based data analysis company called Logically, which aims to fight misinformation, claims that since January, the Chinese government and state media have been running a coordinated disinformation campaign targeting the release of the waste water. As part of this, mainstream news outlets in China have continually questioned the science behind the nuclear waste water discharge. The rhetoric has only increased since the water was released on 24 August, stoking public anger... Japan's foreign ministry even warned its citizens in China to be cautious and to avoid speaking Japanese loudly in public...

Logically's data also showed that, since the beginning of the year, state-owned media have run paid ads on Facebook and Instagram, without disclaimers, about the risks of the waste water release in multiple countries and languages, including English, German, and Khmer. "It is quite evident that this is politically motivated," Hamsini Hariharan, a China expert at Logically, told the BBC. She added that misleading content from sources related to the Chinese government had intensified the public outcry...

Dozens of posts on Chinese social media Weibo showed panicked crowds buying giant sacks of salt ahead of the Fukushima water release. Some worried that future supply would be contaminated. Others believed — falsely — that salt protected them against radiation. A restaurant in Shanghai, in an apparent effort to profit off the hysteria, advertised "anti-radiation" meals with errant claims of reducing skin damage and cell regeneration. A social media user asked wryly, "Why would I pay 28 yuan for tomato with seasoning?"

Transportation

French Error Blamed for UK's Air Control Meltdown Which Left 300,000 Passengers With Cancellations (independent.co.uk) 73

What caused Monday's glitch in the UK's air traffic control system that left thousands of passengers stranded?

Wednesday the Independent reported that it may have been triggered by "an incorrectly filed flight plan by a French airline." Several sources say the issue may have been caused when a French airline filed a dodgy flight plan that made no digital sense. Instead of the error being rejected, it prompted a shutdown of the entire National Air Traffic Services (Nats) system — raising questions over how one clerical error could cause such mayhem... Downing Street has launched an independent review into the incident, which caused more than a quarter of flights at UK airports to be cancelled on Monday...

In his statement, Nats chief executive Martin Rolfe said Nats' systems, both primary and the back-ups, responded to the incorrect flight data by suspending automatic processing "to ensure that no incorrect safety-related information could be presented to an air traffic controller or impact the rest of the air traffic system".

The article also points out that "Passengers hit by the air traffic control meltdown face being stranded abroad for up to a week." Around 300,000 airline passengers have now been hit by flight cancellations since the hours-long failure of the Nats system on bank holiday Monday. The knock-on effect is set to last for several more days, as under-pressure airlines battle the backlog in a week where millions are already returning to the UK from their summer holidays.
Thanks to Slashdot reader Bruce66423 for sharing the article.
Government

IBM Returns To the Facial Recognition Market 17

During the Black Lives Matter protests in 2020, IBM announced that it would no longer offer "general purpose" facial recognition technology due to concerns about racial profiling, mass surveillance, and other human rights violations. Now, according to The Verge and Liberty Investigates, "IBM signed a $69.8 million contract with the British government to develop a national biometrics platform that will offer a facial recognition function to immigration and law enforcement officials." From the report: A contract notice for the Home Office Biometrics Matcher Platform outlines how the project initially involves developing a fingerprint matching capability, while later stages introduce facial recognition for immigration purposes -- described as "an enabler for strategic facial matching for law enforcement." The final stage of the project is described as delivery of a "facial matching for law enforcement use-case." The platform will allow photos of individuals to be matched against images stored on a database -- what is sometimes known as a "one-to-many" matching system. In September 2020, IBM described such "one-to-many" matching systems as "the type of facial recognition technology most likely to be used for mass surveillance, racial profiling, or other violations of human rights."

IBM spokesman Imtiaz Mufti denied that its work on the contract was in conflict with its 2020 commitments. "IBM no longer offers general-purpose facial recognition and, consistent with our 2020 commitment, does not support the use of facial recognition for mass surveillance, racial profiling, or other human rights violations," he said. "The Home Office Biometrics Matcher Platform and associated Services contract is not used in mass surveillance. It supports police and immigration services in identifying suspects against a database of fingerprint and photo data. It is not capable of video ingest, which would typically be needed to support face-in-a-crowd biometric usage."

Human rights campaigners, however, said IBM's work on the project is incompatible with its 2020 commitments. Kojo Kyerewaa of Black Lives Matter UK said: "IBM has shown itself willing to step over the body and memory of George Floyd to chase a Home Office contract. This won't be forgotten." Matt Mahmoudi, PhD, tech researcher at Amnesty International, said: "The research across the globe is clear; there is no application of one-to-many facial recognition that is compatible with human rights law, and companies -- including IBM -- must therefore cease its sale, and honor their earlier statements to sunset these tools, even and especially in the context of law and immigration enforcement where the rights implications are compounding."
Android

Russia Targets Ukraine With New Android Backdoor, Intel Agencies Say (arstechnica.com) 24

An anonymous reader quotes a report from Ars Technica: Russia's military intelligence unit has been targeting Ukrainian Android devices with "Infamous Chisel," the tracking name for new malware that's designed to backdoor devices and steal critical information, Western intelligence agencies said on Thursday. "Infamous Chisel is a collection of components which enable persistent access to an infected Android device over the Tor network, and which periodically collates and exfiltrates victim information from compromised devices," intelligence officials from the UK, US, Canada, Australia, and New Zealand wrote (PDF). "The information exfiltrated is a combination of system device information, commercial application information and applications specific to the Ukrainian military."

Infamous Chisel gains persistence by replacing the legitimate system component known as netd with a malicious version. Besides allowing Infamous Chisel to run each time a device is restarted, the malicious netd is also the main engine for the malware. It uses shell scripts and commands to collate and collect device information and also searches directories for files that have a predefined set of extensions. Depending on where on the infected device a collected file is located, netd sends it to Russian servers either immediately or once a day. When exfiltrating files of interest, Infamous Chisel uses the TLS protocol and a hard-coded IP and port. Use of the local IP address is likely a mechanism to relay the network traffic over a VPN or other secure channel configured on the infected device. This would allow the exfiltration traffic to blend in with expected encrypted network traffic. In the event a connection to the local IP and port fails, the malware falls back to a hard-coded domain that's resolved using a request to dns.google.

Infamous Chisel also installs a version of the Dropbear SSH client that can be used to remotely access a device. The version installed has authentication mechanisms that have been modified from the original version to change the way users log in to an SSH session. [...] The report didn't say how the malware gets installed. In the advisory Ukraine's security service issued earlier this month (PDF), officials said that Russian personnel had "captured Ukrainian tablets on the battlefield, pursuing the aim to spread malware and abuse available access to penetrate the system." It's unclear if this was the vector.

United Kingdom

UK Government Seeks Expanded Use of AI-based Facial Recognition By Police (ft.com) 15

UK's Home Office is looking to increase its use of controversial facial recognition technologies to track and find criminals within policing and other security agencies. From a report: In a document released on Wednesday, the government outlined its ambitions to potentially deploy new biometric systems nationally over the next 12 to 18 months. The move comes after privacy campaigners and independent academics criticised the technology for being inaccurate and biased, particularly against darker-skinned people.

MPs have previously called for a moratorium on its use on the general population until clear laws are established by parliament. The government is calling for submissions from companies for technologies that "can resolve identity using facial features and landmarks," including for live facial recognition which involves screening the general public for specific individuals on police watch lists.

In particular, the Home Office is highlighting its interest in novel artificial intelligence technologies that could process facial data efficiently to identify individuals, and software that could be integrated with existing technologies deployed by the department and with CCTV cameras. Facial recognition software has been used by South Wales Police and London's Metropolitan Police over the past five years across multiple trials in public spaces including shopping centres, during events such as the Notting Hill Carnival and, more recently, during the coronation.

Slashdot Top Deals