×
Security

Millions Experience Browser Problems After Long-Anticipated Expiration of 'Let's Encrypt' Certificate (zdnet.com) 94

"The expiration of a key digital encryption service on Thursday sent major tech companies nationwide scrambling to deal with internet outages that affected millions of online users," reports the Washington Examiner.

The expiring certificate was issued by Let's Encrypt — though ZDNet notes there's been lots of warnings about its pending expiration: Digital Shadows senior cyber threat analyst Sean Nikkel told ZDNet that Let's Encrypt put everyone on notice back in May about the expiration of the Root CA Thursday and offered alternatives and workarounds to ensure that devices would not be affected during the changeover. They have also kept a running forum thread open on this issue with fairly quick responses, Nikkel added.
Thursday night the Washington Examiner describes what happened when the big day arrived: Tech giants — such as Amazon, Google, Microsoft, and Cisco, as well as many smaller tech companies — were still battling with an endless array of issues by the end of the night... At least 2 million people have seen an error message on their phones, computers, or smart gadgets in the past 24 hours detailing some internet connectivity problems due to the certificate issue, according to Scott Helme, an internet security researcher and well-known cybersecurity expert. "So many people have been affected, even if it's only the inconvenience of not being able to visit certain websites or some of their apps not working," Helme said.

"This issue has been going on for many hours, and some companies are only just getting around to fixing it, even big companies with a lot of resources. It's clearly not going smoothly," he added.

There was an expectation before the certificate expired, Helme said, that the problem would be limited to gadgets and devices bought before 2017 that use the Let's Encrypt digital certificate and haven't updated their software. However, many users faced issues on Thursday despite having the most cutting-edge devices and software on hand. Dozens of major tech products and services have been significantly affected by the certificate expiration, such as cloud computing services for Amazon, Google, and Microsoft; IT and cloud security services for Cisco; sellers unable to log in on Shopify; games on RocketLeague; and workflows on Monday.com.

Security researcher Scott Helme also told ZDNet he'd also confirmed issues at many other companies, including Guardian Firewall, Auth0, QuickBooks, and Heroku — but there might be many more beyond that: "For the affected companies, it's not like everything is down, but they're certainly having service issues and have incidents open with staff working to resolve. In many ways, I've been talking about this for over a year since it last happened, but it's a difficult problem to identify. it's like looking for something that could cause a fire: it's really obvious when you can see the smoke...!"

Digital certificates expert Tim Callan added that the popularity of DevOps-friendly architectures like containerization, virtualization and cloud has greatly increased the number of certificates the enterprise needs while radically decreasing their average lifespan. "That means many more expiration events, much more administration time required, and greatly increased risk of a failed renewal," he said.

Earth

Microsoft Joins a Linux Foundation Nonprofit's Effort to Decarbonize the Grid (zdnet.com) 50

"Microsoft has joined forces with LF Energy, a Linux Foundation nonprofit working to accelerate the energy transition of the world's grids and transportation systems through open source," reports ZDNet: Microsoft has become a strategic member of the foundation and Audrey Lee, senior director of energy strategy at Microsoft, was elected to serve on the LF Energy Foundation Governing Board. Dr. Shuli Goodman, executive director of LF Energy, told ZDNet that the foundation believes Microsoft will play an important role in helping to advance their mission of decarbonization of the power grid, transportation and the built environment.

"LF Energy Foundation is thrilled to have Microsoft join our organization as a General member. Through Microsoft's commitment to a carbon negative position they are directly encouraging the tech sector to look for more efficient ways to purchase and consume power," Goodman said.

"LF Energy nurtures the most cutting edge of all open source projects focused on improving automation, control, security, virtualization, and interoperability of power systems. Our members contribute valuable code, tooling, resources and expertise to increase the velocity of these projects...."

Goodman called Microsoft a "force multiplier" and said having the company backing LF Energy will help propel their projects forward at a rapid pace.

Microsoft

Microsoft Puts PCs in the Cloud With Windows 365 (theverge.com) 190

Microsoft is putting Windows in the cloud. Windows 365 is a new service that will let businesses access Cloud PCs from anywhere, streaming a version of Windows 10 or Windows 11 in a web browser. From a report: While virtualization and remote access to PCs has existed for more than a decade, Microsoft is betting on Windows 365 to offer Cloud PCs to businesses just as they shift toward a mix of office and remote work. Windows 365 will work on any modern web browser or through Microsoft's Remote Desktop app, allowing users to access their Cloud PC from a variety of devices.

"Windows 365 provides an instant-on boot experience," according to Wangui McKelvey, a general manager for Microsoft 365. This instant access lets workers stream their Windows session with all of their same apps, tools, data, and settings across Macs, iPads, Linux machines, and Android devices. "You can pick up right where you left off,âbecause the state of your Cloud PC remains the same, even when you switch devices," explains McKelvey.

Cellphones

Ask Slashdot: How Secure Is a Cellphone's eSIM? (pcmag.com) 41

A few months ago PC Magazine explained eSIMs: You almost certainly have a SIM card: a thumbnail-sized chip that sits in your mobile phone, telling it which carrier and what phone number you use. Now those SIMs are going digital (or "e") and moving your information to a reprogrammable, embedded chip.

A SIM card is a "subscriber identity module." Required in all GSM, LTE, and 5G devices, it's a chip that holds your customer ID and details of how your phone can connect to its mobile network... An eSIM takes the circuitry of a SIM, solders it directly to a device's board, and makes it remotely reprogrammable through software... There are some minor consumer downsides, though. With eSIMs, it's harder to switch one plan between devices — you can't just swap the physical card around — and they can make it harder for you to temporarily remove your SIM if you don't want to be tracked by a carrier.

Google's Pixels have had eSIMs since 2017, and Apple's iPhones have had them since 2018...

Now let's see how long-time Slashdot reader shanen feels about them: Shopping for a new smartphone due to premature battery swelling of a cheapie, but surprised to find out I can't just plug the SIM into a new phone. There ain't no SIM here, but rather the dying phone has an eSIM.... Quick research indicated it's only software, so my obvious question is "How secure can an eSIM be?" (The obvious search results also fail to produce "fresh" results.)

But the black hats have already had a couple of years to work on the problem, and it seems intrinsically difficult to do anything securely if you're only using software. My probably obsolete understanding is that part of the basis of SIM security is that you'd have to destroy the SIM to save its data, but is there an actual security expert in the house?

Related question based on my surprise. How would you even know if you're using an eSIM? Especially since it appears to be possible to use an eSIM on a phone with a SIM.

Share your own thoughts and opinions in the comments.

How secure is an eSIM?
Microsoft

Microsoft Awarded $13.6 Million To Security Researchers in the Past 12 Months (therecord.media) 9

Microsoft awarded $13.6 million to security researchers in the past 12 months, From a report: Microsoft said it awarded more than $13.6 million as monetary rewards to security researchers through its public bug bounty programs over the past 12 months. According to Microsoft:
The funds were awarded for 1,261 bugs reported by 341 security researchers across 17 bug bounty platforms between July 1, 2020 and June 30, 2021.

The highest awarded bounty was $200,000 for a vulnerability reported in Hyper-V, Microsoft's OS virtualization technology.
The average bounty was more than $10,000 per valid bug report across all programs.
Most bug reports came from researchers residing in China, the US, and Israel.
The company said it plans to announce the 2021 Most Valuable Security Researcher next month.
The sum awarded this year is identical to what Microsoft reported one year ago when the company said it awarded $13.7 million to 327 security researchers for 1,226 vulnerability reports across 15 bug bounty programs in the previous 12 months (July 1, 2019 to June 30, 2020).

Businesses

Dell Announces Long-Awaited Spinoff of VMware (siliconangle.com) 27

Dell has announced the long-expected spinoff of VMware, the computing virtualization company it has majority-owned since it bought then-owner EMC Corp. in 2016. From a report: The computing giant said it will spin off its 81% equity ownership in VMware, creating two standalone companies when the move is completed in the fourth quarter of this year. That timing depends on conditions such as a favorable Internal Revenue Service opinion that the transaction qualifies for tax-free status for Dell shareholders. The idea is to simplify the companies' capital structures, since arguably investors have valued both companies' stocks lower than they might have because of the uncertainties related to the complex capital structures. Dell's shares rose about 9% in after-hours trading, while VMware's shares rose about 1.6% in late trading. Under the spinoff, which Dell had signaled last year, VMware will distribute a cash dividend of about $11.5 billion to $12 billion to shareholders, which of course include publicly held Dell itself. Chairman and Chief Executive Michael Dell, along with financial partner Silver Lake Partners, own 60% of Dell shares. Dell will get $9.3 billion to $9.7 billion of that dividend, which the company said will help it get more investment-grade ratings and enable it to pay down debt it has gradually been reducing since buying EMC.
Open Source

Open-Source App Lets Anyone Create a Virtual Army of Hackintoshes (vice.com) 31

samleecole writes from a report via Motherboard: MacOS is generally intended as a desktop operating system, and while it's a very functional operating system, Apple expects it to run on a single piece of hardware. As any developer or infrastructure architect can tell you, virtualization is an impressive technique that allows programmers and infrastructure pros to expand reach and scale things up far beyond a single user. A Github project that has gotten a bit of attention in recent months aims to make MacOS scalable in ways that it has basically never been.

Its secret weapon is a serial code generator: Docker-OSX has the ability to generate serial codes for unique pieces of MacOS hardware, and its main developer, an open-source developer and security researcher who goes by the pseudonym Sick Codes, recently released a standalone serial code generator that can replicate codes for nonexistent devices by the thousands. Just type in a command, and it will set up a CSV file full of serial codes.

"You can generate hundreds and thousands of serial numbers, just like that," Sick Codes, who used a pseudonym due to the nature of his work, said. "And it just generates a massive list." A valid serial code allows you to use Apple-based tools such as iMessage, iCloud, and the App Store inside of MacOS. It's the confirmation that you're using something seen as valid in the eyes of Apple. "I actually went through, and I've got like 15 iMac Pros in my Apple account now, and it says that they're all valid for iMessage," the creator said.

Bug

How DNSpooq Attacks Could Poison DNS Cache Records (zdnet.com) 9

Earlier this week security experts disclosed details on seven vulnerabilities impacting Dnsmasq, "a popular DNS software package that is commonly deployed in networking equipment, such as routers and access points," reports ZDNet. "The vulnerabilities tracked as DNSpooq, impact Dnsmasq, a DNS forwarding client for *NIX-based operating systems."

Slashdot reader Joe2020 shared Help Net Security's quote from Shlomi Oberman, CEO and researcher at JSOF. "Some of the bigger users of Dnsmasq are Android/Google, Comcast, Cisco, Red Hat, Netgear, and Ubiquiti, but there are many more. All major Linux distributions offer Dnsmasq as a package, but some use it more than others, e.g., in OpenWRT it is used a lot, Red Hat use it as part of their virtualization platforms, Google uses it for Android hotspots (and maybe other things), while, for example Ubuntu just has it as an optional package."

More from ZDNet: Dnsmasq is usually included inside the firmware of various networking devices to provide DNS forwarding capabilities by taking DNS requests made by local users, forwarding the request to an upstream DNS server, and then caching the results once they arrive, making the same results readily available for other clients without needing to make a new DNS query upstream. While their role seems banal and insignificant, they play a crucial role in accelerating internet speeds by avoiding recursive traffic...

Today, the DNSpooq software has made its way in millions of devices sold worldwide [including] all sorts of networking gear like routers, access points, firewalls, and VPNs from companies like ZTE, Aruba, Redhat, Belden, Ubiquiti, D-Link, Huawei, Linksys, Zyxel, Juniper, Netgear, HPE, IBM, Siemens, Xiaomi, and others. The DNSpooq vulnerabilities, disclosed today by security experts from JSOF, are dangerous because they can be combined to poison DNS cache entries recorded by Dnsmasq servers. Poisoning DNS cache records is a big problem for network administrators because it allows attackers to redirect users to clones of legitimate websites...

In total, seven DNSpooq vulnerabilities have been disclosed today. Four are buffer overflows in the Dnsmasq code that can lead to remote code execution scenarios, while the other three bugs allow DNS cache poisoning. On their own, the danger from each is limited, but researchers argue they can be combined to attack any device with older versions of the Dnsmasq software...

The JSOF exec told ZDNet that his company has worked with both the Dnsmasq project author and multiple industry partners to make sure patches were made available to device vendors by Tuesday's public disclosure.

Microsoft

AWS Engineer Puts Windows 10 on Arm on Apple Mac M1 -- and It Thrashes Surface Pro X (zdnet.com) 107

An Amazon Web Services (AWS) virtualization engineer has shown what Windows 10 on Arm could be like if Microsoft licensed its Arm-based OS to the public rather than just to Windows 10 manufacturers. From a report: With Apple's new M1 Arm-based system on chip, Mac users who need to use Windows 10 can't run Microsoft's Arm-based version of Windows using Apple's Bootcamp. The key obstacle is that Microsoft doesn't license Windows 10 on Arm to any entities other than its own Surface group and Windows 10 on Arm OEMs like HP, Asus and Lenovo. Technically, there's nothing stopping owners of the M1 MacBook Air, MacBook Pro 13-inch or Mac mini from running Windows 10 on Arm, as Apple's software engineering chief Craig Federighi recently pointed out. [...]

But Microsoft's reluctance to create a license for Windows 10 on Arm for end users hasn't stopped creative engineers from putting together a working example of what things could be like if it did. AWS principal engineer Alexander Graf did just that, using the open-source QEMU virtualization software for Windows on Arm. QEMU emulates access to hardware such as the CPU and GPU. [...] "Who said Windows wouldn't run well on #AppleSilicon? It's pretty snappy here," Graf wrote in a tweet. Graf previously worked on the Kernel Virtual Machine (KVM) for Linux distribution SUSE for over a decade. Now he's a KVM developer at AWS, which this week announced new Mac instances for AWS Elastic Compute Cloud (EC2) based on Nitro System, an AWS hypervisor for EC2 instances. [...] A developer using the handle @imbushuo on Twitter has posted Geekbench versions 4 and 5 scores that compare Windows 10 on Arm on an M1 computer with the Microsoft-made Surface Pro X. Windows on an M1 got a single-core score of 1,288 and multi-core score of 5,685 whereas the Surface Pro X's scores were roughly 800 and 3,000 in those respective benchmarks.

The Internet

Comcast Working Toward 10Gbps To Your Home Using Cable (zdnet.com) 136

Comcast has achieved a 10Gbps "technical milestone" that can deliver gigabit-plus download and upload speeds over existing cable wires, not fiber. ZDNet reports: Comcast has achieved a 10Gbps technical milestone by delivering 1.25Gbps upload and download speeds over a live production network using Network Function Virtualization (NFV) combined with the latest Data Over Cable Service Interface Specification (DOCSIS) hardware. This is being done with DOCSIS 4. With this cutting-edge cable internet technology, you can expect to see up to 10Gbps speeds downstream and up to 6Gbps upstream capacity over a hybrid fiber-coaxial (HFC) network. In its first real-world test, to a home in Jacksonville, Fla., technicians achieved its Gigabit plus speed using upon Comcast's Distributed Access Architecture (DAA). This is an edge-based computing model. This architecture has a suite of software-powered networking technologies, including digital fiber optics, "Remote PHY" digital nodes, and a cloud-based, virtualized cable modem termination system platform (vCMTS). The result? Comcast's team consistently measured speeds of 1.25Gbps upload and 1.2Gbps download over the connection.

According to a study by Dr. Raul Katz of Telecom Advisory Services, 10Gbps internet will generate at least $330 billion in total economic output and create more than 676,000 new jobs over the next seven years. It will do by enabling not just 8K video streams for everyone living in your home, but by enabling 5G access points, virtual reality applications, and telehealth. It's not just hardware that's making this possible. Comcast is a major open-source developer and user. As Comcast notes, "The trial was made possible not by a single technological innovation, but rather by a series of interrelated technologies that Comcast continues to test and deploy in its network, all powered by a DAA ecosystem. These include our increasingly virtualized, cloud-based network model." Comcast is working on the "10G" initiative along with NCTA, CableLabs, and SCTE, and other telecom and cable operators from around the world. In addition, Comcast and Charter Communications have worked closely to align on their approaches to 10Gbps and are driving technology standards and architectures to benefit everyone.

Microsoft

Microsoft Submits Linux Kernel Patches to Make Linux Run as Root Partition on Hyper-V (zdnet.com) 40

"Microsoft has submitted a series of patches to Linux kernel developers," reports ZDNet, "requesting that Linux run as the root partition on the Hyper-V, its hypervisor software for running Windows and non-Windows instances on hardware." Microsoft "wants to create a complete virtualization stack with Linux and Microsoft Hypervisor", according to Microsoft principle software engineer Wei Liu. Liu has proposed an RFC or request for comment that for now merely implements what are only the "absolutely necessary components to get things running... There will be a subsequent patch series to provide a device node (/dev/mshv) such that userspace programs can create and run virtual machines. We've also ported Cloud Hypervisor over and have been able to boot a Linux guest with Virtio devices since late July." Cloud Hypervisor is an experimental open-source hypervisor implementation from Intel written in the Rust programming language. It's a virtual-machine monitor that runs on top of KVM, the Kernel-based Virtual Machine hypervisor in the Linux kernel that's designed for cloud workloads...

Liu points out three more changes beyond amendments to the Hyper-V Top-Level Functional Specification. For example, Microsoft wants Linux to set up existing Hyper-V facilities differently. It also wants Linux kernel developers to change the kernel's behavior when accessing hardware memory in a way that affects driver access to the GPU and CPU that's being managed by an operating system memory manager. It's this issue that Microsoft engineers are least confident about and are asking for Linux developer support, according to Liu....

As Microsoft's executive VP of the cloud and enterprise group, Scott Guthrie, told ZDNet last year, Microsoft's shift to Linux and open source started over a decade ago when it open-sourced ASP.NET. "We recognized open source is something that every developer can benefit from. It's not nice, it's essential. It's not just code, it's community," explained Guthrie.

Microsoft

Microsoft Submits Linux Kernel Patches For a 'Complete Virtualization Stack' With Linux and Hyper-V (theregister.com) 105

Microsoft has submitted a series of patches to the Linux kernel with its aim being "to create a complete virtualization stack with Linux and Microsoft Hypervisor." The Register reports: The patches are designated "RFC" (Request for comments) and are a minimal implementation presented for discussion. The key change is that with the patched kernel, Linux will run as the Hyper-V root partition. In the Hyper-V architecture, the root partition has direct access to hardware and creates child partitions for the VMs it hosts. "Just think of it like Xen's Dom0," said Microsoft principal software engineer Wei Liu. Hyper-V's architecture is more similar to Xen than it is to KVM or to VMware's ESXi, and Liu acknowledged that "we drew inspiration from the Xen code in Linux," specifically for code handing interrupts. Until now, the Hyper-V root partition had to run Windows.

Microsoft has also ported Intel's open-source Cloud Hypervisor, a Virtual Machine Monitor (VMM) written in Rust that normally runs on KVM, the hypervisor that is built into the Linux kernel. Cloud Hypervisor itself is currently in "very early pre-alpha stage." Even when Linux is the root partition, it will still run on top of Microsoft's hypervisor, a thin layer running with ring -1 privileges. It will no longer be necessary to run Windows on that hypervisor, though, enabling Microsoft to call the new arrangement "a complete virtualization stack with Linux."

Linux

Linus Torvalds: Linux 5.8 "One of our Biggest Releases of All Time" (techrepublic.com) 61

This week saw the release Linux 5.8, which Linus Torvalds called "one of our biggest releases of all time," reports TechRepublic: The new version of the Linux kernel brings a number of updates to Linux 5.7 spanning security, core components, drivers, memory management, networking and improvements to the kernel's design, amongst others. This includes updates for Microsoft's Hyper-V virtualization platform, Intel Tiger Lake Thunderbolt support, improvements to Microsoft's exFAT file system, and support for newer Intel and ARM chips.

Torvalds said the kernel had received over 15,000 merge requests and that around 20% of all the files in the kernel source repository had been modified. "That's really a fairly big percentage, and while some of it is scripted, on the whole it's really just the same pattern: 5.8 has simply seen a lot of development," Torvalds said.

Translated into numbers, Linux 5.8 includes over 800,000 new lines and over 14,000 changed files. It also received one of the biggest number of merge requests during its merge window — over 14,000 non-merge commits and more than 15,000 including merges, according to Torvalds. "5.8 looks big. Really big," he added.

Businesses

Linux Company SUSE Outbids Competitors for Fast-growing Startup Rancher Labs (cnbc.com) 15

SUSE, a Linux distribution company controlled by private equity firm EQT, has agreed to acquire Rancher Labs, a start-up with technology that helps organizations run software in virtual containers across many servers. From a report: The companies announced the deal Wednesday but didn't disclose the terms. Two people familiar with the deal said SUSE is paying $600 million to $700 million. The transaction suggests that even during a recession, demand remains high for technology that can enable companies to operate more efficiently. Talks between the companies began in the spring, and the process became competitive with additional bids, Ursheet Parikh, a partner at Rancher backer Mayfield Fund, told CNBC on Tuesday. There were "lots of Zoom calls," Parikh said. In the past few years, with the rise of start-ups such as Docker, containers became a trendy alternative to more traditional virtualization technology for running applications on each computer server in a company data center. Amazon, Microsoft and other cloud providers came out with services that developers can use to place code in containers, and in 2017 SUSE introduced its own service for managing containers. The companies haven't finalized integration plans as the deal still faces regulatory approval.
Windows

Apple's ARM Switch Will Be the End of Boot Camp (imore.com) 216

Apple has confirmed that switching to its own, ARM-based Apple silicon will signal the end of Boot Camp support. From a report: Apple will start switching its Macs to its own ARM-based processors later this year, but you won't be able to run Windows in Boot Camp mode on them. Microsoft only licenses Windows 10 on ARM to PC makers to preinstall on new hardware, and the company hasn't made copies of the operating system available for anyone to license or freely install. On John Gruber's WWDC Talk Show, Craig Federighi confirmed that Apple would not support Boot Camp on ARM Macs: "We're not direct booting an alternate operating system. Purely virtualization is the route. These hypervisors can be very efficient, so the need to direct boot shouldn't really be the concern."
IOS

Apple Will Let You Emulate Old Apps, Run iOS Apps on ARM Macs (techcrunch.com) 213

At the WWDC 2020 keynote today, Apple announced that the company is going to switch from Intel chips to Apple's own silicon, based on ARM architecture. They also announced that iPad and iPhone apps will be able to run natively on ARM-powered Macs. TechCrunch reports: First, you'll be able to compile your app to run both on Intel-based Macs and ARM-based Macs. You can ship those apps with both executables using a new format called Universal 2. If you've been using a Mac for a while, you know that Apple used the same process when it switched from PowerPC CPUs to Intel CPUs -- one app, two executables. As for unoptimized software, you'll still be able to run those apps. But its performances won't be as good as what you'd get from a native ARM-ready app. Apple is going to ship Rosetta 2, an emulation layer that lets you run old apps on new Macs.

When you install an old app, your Mac will examine the app and try to optimize it for your ARM processor. This way, there will be some level of optimization even before you open the app. But what if it's a web browser or a complicated app with just-in-time code? Rosetta 2 can also translate instructions from x86 to ARM on the fly, while you're running the app. And if you're a developer working on code that is going to run on servers, Apple is also working on a set of virtualization tools. You'll be able to run Linux and Docker on an ARM Mac.

As a bonus, users will also be able to access a much larger library of apps. "Mac users can for the first time run iOS and iPadOS apps on the Mac," Apple CEO Tim Cook said. While the company didn't share a lot of details, Apple isn't talking about Catalyst, its own framework that makes it easier to port iOS apps to macOS. You should be able to download and run apps even if the developer never optimized those apps for macOS.

Google

Google Partners With Parallels To Bring Windows Apps To Chrome OS (engadget.com) 13

For years, Parallels has provided virtualization software so you could run full Windows installs on a Mac, but today they're tackling a new OS. From a report: The company just announced that it is partnering with Google to work on bringing full Windows application support to Chrome OS enterprise devices. That's a big deal for the many businesses out there that run various pieces of legacy Windows software -- or just any business that wants to run Microsoft's Office software natively. It could Chrome OS devices a lot more viable in a variety of workspaces that may have previously had to rely on Windows hardware, though of course that'll depend on how well it is implemented. How exactly this will work remains to be seen; Parallels only said that partnership would "seamlessly add full-featured Windows apps, including Microsoft Office, to Chromebook Enterprise devices."
Google

Playing Around With the Fuchsia OS (quarkslab.com) 102

Security and software development company Quarkslab played around with Google's new Fuchsia operating system, which could one day replace Android on smartphones and Chrome OS on laptops. The researchers "decided to give a quick look at Fuchsia, learn about its inner design, security properties, strengths and weaknesses, and find ways to attack it." Here's what they concluded: Fuchsia's micro kernel is called Zircon. It is written in C++. [...] Contrary to every other major OS, it appears rather difficult to target the Zircon kernel directly. A successful RCE (Remote Code Execution) on the world-facing parts of the system (USB, Bluetooth, network stack, etc) will only give you control over the targeted components, but they run in independent userland processes, not in the kernel. From a component, you then need to escalate privileges to the kernel using the limited number of syscalls you can access with the handles you have. Overall, it seems easier to target other components rather than the kernel, and to focus on components that you can talk to via IPC and that you know have interesting handles.

Overall, Fuchsia exhibits interesting security properties compared to other OSes such as Android. A few days of vulnerability research allowed us to conclude that the common programming bugs found in other OSes can also be found in Fuchsia. However, while these bugs can often be considered as vulnerabilities in other OSes, they turn out to be uninteresting on Fuchsia, because their impact is, for the most part, mitigated by Fuchsia's security properties. We note however that these security properties do not -- and in fact, cannot -- hold in the lowest layers of the kernel related to virtualization, exception handling and scheduling, and that any bug here remains exploitable just like on any other OS. All the bugs we found were reported to Google, and are now fixed.

Again, it is not clear where Fuchsia is heading, and whether it is just a research OS as Google claims or a real OS that is vowed to be used on future products. What's clear, though, is that it has the potential to significantly increase the difficulty for attackers to compromise devices.

The Internet

Are We on the Cusp of a Metaverse, the Next Version of the Internet? (washingtonpost.com) 69

The Washington Post describes it as "the next internet." Wikipedia defines it as "a collective virtual shared space...including the sum of all virtual worlds, augmented reality, and the Internet." But it was Neal Stephenson who named it "the metaverse" in his 1992 science fiction novel Snow Crash.

Are we closer to seeing it happen? The Washington Post reports: In the past month, office culture has coalesced around video chat platforms like Zoom, while personal cultural milestones like weddings and graduations are being conducted in Nintendo's Animal Crossing: New Horizons. The Metaverse not only seems realistic — it would probably be pretty useful right about now. The Metaverse reality is still years, possibly decades, away. But Epic Games CEO Tim Sweeney has been publicly pushing for its creation, and he isn't alone in his desire to push for the Metaverse, where the online world echoes and fulfills real-world needs and activities. Constructing the virtual Internet space is Silicon Valley's macro goal, many of whom are obsessed with Neal Stephenson's 1992 book, "Snow Crash," which defined the term.

In recent years, Facebook, Google and Samsung have all made heavy investments in cloud computing and virtual reality companies in anticipation of a Metaverse... But it's Epic Games, with Fortnite, that has the most viable path forward in terms of creating the Metaverse, according to an essay by venture capitalist and former Amazon executive Matthew Ball... [The article also notes other "traits" of the metaverse in Minecraft and Roblox.] The most widely agreed core attributes of a Metaverse include always being live and persistent — with both planned and spontaneous events always occurring — while at the same time providing an experience that spans and operates across platforms and the real world. A Metaverse must also have no real cap on audience, and have its own fully functioning economy... Fortnite hasn't reached Metaverse status yet. But Fortnite as a social network and impossible-to-ignore cultural phenomenon, Ball says, provides Epic Games a key advantage for leading in the Metaverse race. Fortnite draws a massive, willing and excited audience online to engage with chaotically clashing intellectual properties... "This organic evolution can't be overemphasized," Ball writes in his essay. "If you 'declared' your intent to start a Metaverse, these parties would never embrace interoperability or entrust their IP. But Fortnite has become so popular and so unique that most counterparties have no choice but to participate... Fortnite is too valuable a platform...."

The current swarm to an online-only social and capitalist economy has only highlighted the current Internet's failings, and what the Metaverse needs to do, Ball said. Big sites like Facebook, Google and Amazon continue to dominate online activity, as do larger streaming services like YouTube and Netflix. But each location requires its own membership and has separate ecosystems. "Right now, the digital world basically operates as though every restaurant and bar you go to requires a different ID card, has a different currency, requires their own dress codes and has their own units [of service and measurement]," Ball said. "It is clear that this really advantages the biggest services. People are just sticking to the big games, really. However there's a clear argument that reducing network lock-in can really raise all boats here."

Sweeney said as much in his DICE Summit keynote speech February. If the game industry wants to reshape the Internet and move away from Silicon Valley's walled gardens, Sweeney stressed that publishers need to rethink economies in the same way email was standardized... "We need to give up our attempts to each create our own private walled gardens and private monopoly and agree to work together and recognize we're all far better off if we connect our systems and grow our social graphs together.

Neal Stephenson answered questions from Slashdot readers back in 2004.
Virtualization

VMware Embraces Kubernetes in Its Biggest Product Blitz in a Decade (siliconangle.com) 27

Hailing it as its most significant update to its vSphere virtualization manager in a decade, VMware today is overhauling its portfolio of products to include native support of the Kubernetes orchestration manager for software containers along with a host of new tools for shifting and managing applications across multiple on-premises and cloud infrastructure stacks. From a report: The announcement continues VMware's multiyear odyssey from a supplier of virtualization software for on-premises data centers to an enabler of cloud migration and multicloud management. It also showcases the rapid integration of several acquisitions the company made last year. VMware was once seen as a prime potential victim of containers, which are portable and self-contained software environments bundled with applications, but it has responded by embracing the technology and is now building the red-hot Kubernetes manager into its flagship platform. "In the early days of virtualization VMware was a layer that lived across multiple environments; they're looking now to do the same in the cloud," Stu Miniman, senior analyst at Wikibon, a sister research firm to SiliconANGLE, said.

Slashdot Top Deals