Made with Love

Our online connected world & what's in the future

  • Thread starter Thread starter Warl0ck
  • Start date Start date
W

Warl0ck

Guest
Most you are not aware, but Amazon Web Services "S3" went down today. Web Services is "the Cloud" as you've heard about. They had a massive failure of some sort. Anyway, had reports of IoT (internet of things) light bulbs, thermostats and household tools not working because of the outage.


If you're one of those people who has to get "Alexa" or "Siri" for your house, phone etc, maybe thing again. Nothing good can come of this.
 
Warl0ck said:
Most you are not aware, but Amazon Web Services "S3" went down today. Web Services is "the Cloud" as you've heard about. They had a massive failure of some sort. Anyway, had reports of IoT (internet of things) light bulbs, thermostats and household tools not working because of the outage.


If you're one of those people who has to get "Alexa" or "Siri" for your house, phone etc, maybe thing again. Nothing good can come of this.

While I love the idea of a connected home I can not get past the lack of security in the devices.
I recommend not even using a SMART TV.
 
God said:
Kind of late for that. What's with the SMART TV's?.

Same thing that's happening with the teddy bears and the dolls and the refrigerators ...
 
f3f633589f8979acf1c31a385dc43b5d.jpg
 
Update: The major internet outage across the United States earlier this week was not due to any virus or malware or state-sponsored cyber attack, rather it was the result of a simple TYPO.

Amazon on Thursday admitted that an incorrectly typed command during a routine debugging of the company's billing system caused the 5-hour-long outage of some Amazon Web Services (AWS) servers on Tuesday.

The issue caused tens of thousands of websites and services to become completely unavailable, while others show broken images and links, which left online users around the world confused.

How A Simple Command Typo Took Down Amazon S3 and Big Chunk of the Internet



I bet the techie who did it got called into the office for a little talk. :SayWhat?:
 
Trump's New FCC Chairman Lets ISPs Sell Your Private Data Without Your Consent

Bad News for privacy concerned people!

It will be once again easier for Internet Service Providers(ISPs) to sell your personal data for marketing or advertisement purposeswithout taking your permission.

Last October, the United States Federal CommunicationsCommission (FCC) passed a set of privacy rules on ISPs that restrict them fromsharing your online data with third parties without your consent and requirethem to adopt "reasonable measures" to protect consumers' data fromhackers.

However, now the FCC suspended privacy rules before they cameinto effect.

The reason? President Donald Trump's newly appointed FCCchairman Ajit Pai, a Republican and ex-Verizon lawyer.

Ajit Pai, who has openly expressed his views against netneutrality in the past, just last week said during a speech at Mobile WorldCongress that Net Neutrality was "a mistake" and indicated that theCommission is now moving back to internet regulations.

Now, Pai suspends privacy rules on ISPs, arguing that theyfavored companies like Google and Facebook, which are regulated by the FederalTrade Commission (FTC), over internet providers like Comcast and Verizon.

Pai wants the FCC, and the Federal Trade Commission shouldtreat all online entities the same way. So those new privacy policies should bescrapped.

"All actors in the online space should be subject tothe same rules, and the federal government shouldn’t favor one set of companiesover another," FCC said in a statement.

"Therefore, he has advocated returning to atechnology-neutral privacy framework for the online world and harmonizing theFCC’s privacy rules for broadband providers with the FTC’s standards for othersin the digital economy."

The FCC will now likely pass a new set of standards in theway the FTC regulates websites. It's like, if the FTC requires sites like Facebookand Google to seek explicit permission before selling your data, the FCC mayfollow suit for ISPs.

In other words, the FCC will keep a hold on new privacyrules. Since FTC would never hurt advertising business model of Google andFacebook, FCC would never restore those suspended rules on ISPs.

How does this Move Affect You?


If you are unaware, your internet service provider knowsyour most intimate and personal online activities.

Unlike Google which uses encryption to prevent anyone fromseeing your online searches, your ISP can see your search queries, whatwebsites you visit, when you visit them, and what apps you use.

The ISPs then share this data with other companies foradvertisements, marketing or other purposes. And with this information in hands,it's very easy for any advertising company to know users' interests based ontheir online behaviors and serve them targeted ads.

Not surprisingly, the broadband industry applauded the FCC'snew move, calling it "a welcome recognition that consumers benefit mostwhen privacy protections are consistently applied throughout the Internetecosystem."

But privacy advocates are not at all happy with the FCC'saction, arguing that suspending the privacy rules favor the Internet providerslike Comcast and Verizon since the ISPs do not need the same data securityrules the FTC requires of websites.

Trump's New FCC Chairman Lets ISPs Sell Your Private Data Without Your Consent
 
Google increases bug bounty payouts by 50% and Microsoft just doubles it

Well, there's some good news for hackers and bug bounty hunters!

Both tech giants Google and Microsoft have raised the value of the payouts they offer security researchers, white hat hackers and bug hunters who find high severity flaws in their products.

While Microsoft has just doubled its top reward from $15,000 to $30,000, Google has raised its high reward from $20,000 to $31,337, which is a 50 percent rise plus a bonus $1,337 or 'leet' award.

In past few years, every major company, from Apple to P*rnHub and Netgear, had started Bug Bounty Programs to encourage hackers and security researchers to find and responsibly report bugs in their services and get rewarded.

But since more and more bug hunters participating in bug bounty programs at every big tech company, common and easy-to-spot bugs are hardly left now, and if any, they hardly make any severe impact.

Sophisticated and remotely exploitable vulnerabilities are a thing now, which takes more time and effort than ever to discover.

So, it was needed to encourage researchers in helping companies find high-severity vulnerabilities that have become harder to identify.

Until now, Google offered $20,000 for remote code execution (RCE) flaws and $10,000 for an unrestricted file system or database access bugs. But these rewards have now been increased to $31,337 and $13,337, respectively.

For earning the top notch reward of $31,337 from the tech giant, you need to find command injections, sandbox escapes and deserialization flaws in highly sensitive apps, such as Google Search, Chrome Web Store, Accounts, Wallet, Inbox, Code Hosting, Google Play, App Engine, and Chromium Bug Tracker.

Types of vulnerabilities in the unrestricted file system or database access category that can earn you up to $13,337 if they affect highly sensitive services include unsandboxed XML eXternal Entity (XXE) and SQL injection bugs.

Since the launch of its bug bounty program in 2010, Google has paid out over $9 Million, including $3 Million awarded last year.
Microsoft has also increased its bug bounty payouts from $20,000 to $30,000 for vulnerabilities including cross-site scripting (XSS), cross-site request forgery (CSRF), unauthorized cross-tenant data tampering or access (for multi-tenant services), insecure direct object references injection, server-side code execution, and privilege escalation bugs, in its Outlook and Office services.

Both the tech giants are trying their best to eliminate any lucrative vulnerability or backdoor into their software and products to avoid any hacking attempts and make them more secure.

Hackers will get the payout reward after submitting the vulnerabilities along with a valid working proof-of-concept.

So, what are you waiting for? Go and Grab them all!

Google Increases Bug Bounty Payouts by 50% and Microsoft Just Doubles It!
 
Back
Top Bottom