Security

Prison Inmates Catfished $560,000 Out of Military Service Members in Sextortion Scam, NCIS Says (gizmodo.com) 165

Hundreds of military service members reportedly got caught up in a sextortion scam run by prison inmates using cellphones, according to a release issued by the Naval Criminal Investigative Service (NCIS). From a report: Military agents from multiple criminal investigation groups have served summons and issued warrants for arrests related to the scheme. According to the NCIS, South Carolina and North Carolina prison inmates, assisted by outside accomplices, sought out service members through dating sites and social media, then took on false identities, feigned romantic interest, and exchanged photos.

Once the inmates had successfully catfished their targets, they would then pose as the father of the fake persona, insisting their child was underage and that the target had therefore committed a crime by exchanging photos. In some situations, the "father" claimed he wouldn't press charges if the target gave him money. Sometimes the catfisher would pose as law enforcement requesting money for the family.

Android

Google Is Adding Android Support For Foldable Screens (techcrunch.com) 22

At its Android Developer Summit today, Google detailed plans to bake support for folding phones into the mobile operating system. One of the first Android phones to hit the market with a foldable display looks to be from Samsung with a launch date of "early next year." TechCrunch reports: "You can think of the device as both a phone and a tablet," Android VP of Engineering Dave Burke explained. "Broadly, there are two variants -- two-screen devices and one-screen devices. When folded, it looks like a phone, fitting in your pocket or purse. The defining feature for this form factor is something we call screen continuity."

Among the additions here is the ability to flag the app to respond to the screen as it folds and unfolds -- the effect would likely be similar to the response of applications as handsets switch between portrait and landscape modes.

The Almighty Buck

EU Court Rules Hungary's State Monopoly Over Mobile Payments Is Illegal (reuters.com) 120

Hungarian state's monopoly over national mobile payment services has been ruled illegal by the European Court of Justice. "The ruling would require the end of exclusive control over Hungarian mobile payments exercised since July 2014 by state-owned firm Nemzeti Mobilfizetesi Zrt," reports Reuters. "This exclusive operation 'is contrary to EU law,' the bloc's top court said in a statement."

"Even if the services provided under that system constitute services of general economic interest, their supply cannot be reserved to a state monopoly," the court added.
Android

Samsung Will Put Notches On Its Future Phones (theverge.com) 125

Samsung is one of the biggest smartphone makers to hold off on releasing smartphones with display notches. But at the company's developer conference today, Samsung confirmed that it's soon going to join in on the trend. "A slide during the keynote showed several notch designs that are almost certainly coming to Samsung-branded devices in 2019 and beyond," reports The Verge. From the report: Hassan Anjum, a director of product marketing at Samsung, took the stage to highlight Samsung's previous breakthroughs in reducing bezels and maximizing display size year after year. "We're going to keep going. The bezels are going to shrink even further," Anjum said. "We're going to push the limits with our new lineup: the Infinity U, V, and O displays. These are new concepts that are just around the corner, and I can't wait to tell you more about them."

Infinity U: This basically looks identical to the Essential Phone's notch design. It's a small half oval that cuts down into the top middle of the display.
Infinity V: Similar to Infinity U, but with four edges instead of a curved half-oval.
Infinity O: This is a full circular cutout of the display and not so much a "notch" the top edge of the screen. Still, it seems like an eyesore and it's hard to imagine reaction to this being very positive. What's gained by that little area of display above it? Asus seems to be exploring a similar idea for its ZenFone 6, and feedback has been overwhelmingly bad.
New Infinity: This looks to be a completely notchless display. Anjum didn't discuss this one onstage, and the technology isn't quite there to allow for this design just yet. That said, Samsung could be exploring the idea of a slider phone that would house the selfie camera and other components somewhere outside their usual location.

Google

Google Sends Final Software Update To Legacy Nexus 5X, Nexus 6P Phones (hothardware.com) 107

Google has pushed out the final "guaranteed" official software update for Nexus devices. According to Hot Hardware, the November update for both the Nexus 5X and Nexus 6P "carries the final build number of OPM7.181105.004, running Android 8.1 Oreo." From the report: The last Nexus smartphones to launch from Google were the Nexus 5X and Nexus 6P, which debuted in late 2015. Under Google's three-year update policy, both smartphones have received two major Android releases (Android 7.0 Nougat in 2016 and Android 8.0 Oreo in 2017) along with three years of monthly security updates. The monthly security updates should have ended in September, but Google out of nowhere provided a two-month reprieve through November 2018.
Power

It's Not Your Imagination: Smartphone Battery Life Is Getting Worse (washingtonpost.com) 160

An anonymous reader quotes a report from The Washington Post: For the last few weeks, I've been performing the same battery test over and over again on 13 phones. With a few notable exceptions, this year's top models underperformed last year's. The new iPhone XS died 21 minutes earlier than last year's iPhone X. Google's Pixel 3 lasted nearly an hour and a half less than its Pixel 2. Phone makers tout all sorts of tricks to boost battery life, including more-efficient processors, low-power modes and artificial intelligence to manage app drain. Yet my results, and tests by other reviewers I spoke with, reveal an open secret in the industry: the lithium-ion batteries in smartphones are hitting an inflection point where they simply can't keep up.

"Batteries improve at a very slow pace, about 5 percent per year," says Nadim Maluf, the CEO of a Silicon Valley firm called Qnovo that helps optimize batteries. "But phone power consumption is growing up faster than 5 percent." Blame it on the demands of high-resolution screens, more complicated apps and, most of all, our seeming inability to put the darn phone down. Lithium-ion batteries, for all their rechargeable wonder, also have some physical limitations, including capacity that declines over time -- and the risk of explosion if they're damaged or improperly disposed. And the phone power situation is likely about to get worse. New ultrafast wireless technology called 5G, coming to the U.S. neighborhoods soon, will make even greater demands on our beleaguered batteries.
If you want a smartphone that excels in battery life, you pretty much have two options: Samsung's Galaxy Note 9 and Apple's iPhone XR. According to The Washington Post's tests, the iPhone XR and Note 9 topped the list with times of 12:25 and 12:00, respectively.
Cellphones

Study of Cellphone Risks Finds 'Some Evidence' of Link To Cancer, At Least In Male Rats (nytimes.com) 153

An anonymous reader quotes a report from The New York Times: For decades, health experts have struggled to determine whether or not cellphones can cause cancer. On Thursday, a federal agency released the final results of what experts call the world's largest and most costly experiment to look into the question. The study originated in the Clinton administration, cost $30 million and involved some 3,000 rodents. The experiment, by the National Toxicology Program, found positive but relatively modest evidence that radio waves from some types of cellphones could raise the risk that male rats develop brain cancer. But he cautioned that the exposure levels and durations were far greater than what people typically encounter, and thus cannot "be compared directly to the exposure that humans experience." Moreover, the rat study examined the effects of a radio frequency associated with an early generation of cellphone technology, one that fell out of routine use years ago. Any concerns arising from the study thus would seem to apply mainly to early adopters who used those bygone devices, not to users of current models.

The lowest level of radiation in the federal study was equal to the maximum exposure that federal regulations allow for cellphone users. That level of exposure rarely occurs in typical cellphone use, the toxicology agency said. The highest level was four times higher than the permitted maximum. The rodents in the studies were exposed to radiation nine hours a day for two years -- far longer even than heavy users of cellphones. For the rats, the exposures started before birth and continued until they were about 2 years old. Some 2 to 3 percent of the male rats exposed to the radiation developed malignant gliomas, a deadly brain cancer, compared to none in a control group that received no radiation. Many epidemiologists see no overall rise in the incidence of gliomas in the human population.
"The study also found that about 5 to 7 percent of the male rats exposed to the highest level of radiation developed certain heart tumors, called schwannomas, compared to none in the control group," the NYT reports.

It's worth nothing that the rats were exposed to radiation at a frequency of 900 megahertz, the frequency used in the second generation of cellphones that prevailed in the 90s, when the study was first conceived. For comparison, fourth generation (4G) and fifth generation (5G) phones employ much higher frequencies, which are "far less successful at penetrating the bodies of humans and rats," the NYT reports.
Crime

CIA Vault7 Leaker To Be Charged For Leaking More Classified Data While in Prison (zdnet.com) 94

US prosecutors are preparing new charges against a former CIA coder who was indicted earlier this year in June for leaking classified CIA material to WikiLeaks, in what later become known as the Vault7 leaks. From a report: According to new court documents filed late Wednesday, October 31, US prosecutors plan to file three new charges against Joshua Schulte for allegedly leaking more classified data while in detention at the New York Metropolitan Correctional Center (MCC). Prosecutors say they first learned of Schulte's behavior back in May, when they found out that "Schulte had distributed the Protected Search Warrant Materials to his family members for purposes of dissemination to other third parties, including members of the media." The prosecution held a court hearing in May and initially warned the suspect about his actions, a warning they found Schulte ignored. The US government says that "in or about early October 2018, the Government learned that Schulte was using one or more smuggled contraband cellphones to communicate clandestinely with third parties outside of the MCC." A search of his housing unit performed by FBI agents revealed "multiple contraband cellphones (including at least one cellphone used by Schulte that is protected with significant encryption); approximately 13 email and social media accounts (including encrypted email accounts); and other electronic devices."
Communications

Nobody's Cellphone Is Really That Secure, Bruce Schneier Reminds (theatlantic.com) 80

Earlier this week, The New York Times reported that the Russians and the Chinese were eavesdropping on President Donald Trump's personal cellphone and using the information gleaned to better influence his behavior. This should surprise no one, writes Bruce Schneier. From a story: Security experts have been talking about the potential security vulnerabilities in Trump's cellphone use since he became president. And President Barack Obama bristled at -- but acquiesced to -- the security rules prohibiting him from using a "regular" cellphone throughout his presidency. Three broader questions obviously emerge from the story. Who else is listening in on Trump's cellphone calls? What about the cellphones of other world leaders and senior government officials? And -- most personal of all -- what about my cellphone calls?

There are two basic places to eavesdrop on pretty much any communications system: at the end points and during transmission. This means that a cellphone attacker can either compromise one of the two phones or eavesdrop on the cellular network. Both approaches have their benefits and drawbacks. The NSA seems to prefer bulk eavesdropping on the planet's major communications links and then picking out individuals of interest. In 2016, WikiLeaks published a series of classified documents listing "target selectors": phone numbers the NSA searches for and records. These included senior government officials of Germany -- among them Chancellor Angela Merkel -- France, Japan, and other countries.

Other countries don't have the same worldwide reach that the NSA has, and must use other methods to intercept cellphone calls. We don't know details of which countries do what, but we know a lot about the vulnerabilities. Insecurities in the phone network itself are so easily exploited that 60 Minutes eavesdropped on a U.S. congressman's phone live on camera in 2016. Back in 2005, unknown attackers targeted the cellphones of many Greek politicians by hacking the country's phone network and turning on an already-installed eavesdropping capability. The NSA even implanted eavesdropping capabilities in networking equipment destined for the Syrian Telephone Company. Alternatively, an attacker could intercept the radio signals between a cellphone and a tower. Encryption ranges from very weak to possibly strong, depending on which flavor the system uses. Don't think the attacker has to put his eavesdropping antenna on the White House lawn; the Russian Embassy is close enough.

Education

Should Parents End 'Screen Time' For Children? (indianexpress.com) 178

The New York Times reports that in Silicon Valley, "a wariness that has been slowly brewing is turning into a regionwide consensus: The benefits of screens as a learning tool are overblown, and the risks for addiction and stunting development seem high." One Facebook engineer doesn't allow his own kids to have any screen time, according to this article shared by schwit1, and even Chris Anderson, the former editor of Wired, believes screen time is addictive for children. "On the scale between candy and crack cocaine, it's closer to crack cocaine," Mr. Anderson said of screens. Technologists building these products and writers observing the tech revolution were naive, he said. "We thought we could control it. And this is beyond our power to control. This is going straight to the pleasure centers of the developing brain... I didn't know what we were doing to their brains until I started to observe the symptoms and the consequences... We glimpsed into the chasm of addiction, and there were some lost years, which we feel bad about...."

Tim Cook, the C.E.O. of Apple, said earlier this year that he would not let his nephew join social networks. Bill Gates banned cellphones until his children were teenagers, and Melinda Gates wrote that she wished they had waited even longer. Steve Jobs would not let his young children near iPads. But in the last year, a fleet of high-profile Silicon Valley defectors have been sounding alarms in increasingly dire terms about what these gadgets do to the human brain. Suddenly rank-and-file Silicon Valley workers are obsessed. No-tech homes are cropping up across the region. Nannies are being asked to sign no-phone contracts....

John Lilly, a Silicon Valley-based venture capitalist with Greylock Partners and the former C.E.O. of Mozilla, said he tries to help his 13-year-old son understand that he is being manipulated by those who built the technology. "I try to tell him somebody wrote code to make you feel this way-- I'm trying to help him understand how things are made, the values that are going into things and what people are doing to create that feeling," Mr. Lilly said. "And he's like, 'I just want to spend my 20 bucks to get my Fortnite skins.'"

What do Slashdot's reader think? Should parents end 'screen time' for children?
China

Worried About Trump iPhone Eavesdroppers? China Recommends a Huawei (reuters.com) 109

China's foreign ministry has some suggestions for the Trump administration if it is worried about foreign eavesdropping on the U.S. president's iPhones: use a Huawei handset instead. Or just cut all forms of modern communication with the outside world. From a report: The riposte came after the New York Times reported that American intelligence reports indicated that Chinese and Russian spies often listen in on President Donald Trump when he uses his Apple cellphones to chat with old friends. Aides have repeatedly told him that his cellphone calls are not secure, but although the president has been persuaded to use his secure White House landline more often, he has refused to give up the phones, the Times said. Trump called the Times report incorrect on Thursday, and dismissed it as "long and boring." "I only use Government Phones, and have only one seldom used government cell phone. Story is soooo wrong!" Trump wrote on Twitter. In a later tweet, he said, "I rarely use a cellphone, & when I do it's government authorized. I like Hard Lines. Just more made up Fake News!"
China

China, Russia Are Listening To Trump's Phone Calls, Says NYT Report (thehill.com) 423

Rick Zeman writes: According to The New York Times, the Chinese are regularly listening to Donald Trump's cellphone calls (Warning: source may be paywalled; alternative source). While he has two NSA-hardened iPhones, and a secure landline, he insists on using a consumer-grade iPhone -- even while knowing he's being eavesdropped upon -- because it has his contact list on it. "White House officials say they can only hope he refrains from discussing classified information when he is on them," reports the New York Times. But, officials were also confident that "he was not spilling secrets because he rarely digs into the details of the intelligence he is shown and is not well versed in the operational specifics of military or covert activities"; in other words, security through ignorance. The article mentions the rationale is to be able to listen to his calls to find out what and whom influences him, and that the Russians also listen in, albeit with less frequency because of his unique relationship with Vladimir Putin.
Communications

Prank Calls Brought ICE Hotline To a Standstill, Internal Emails Show (theverge.com) 457

An anonymous reader quotes a report from The Verge: When ICE launched an immigration crime hotline last year, the Trump administration pitched it as a way to provide resources to victims, but activists saw something else: an attack on the immigrant community. The hotline was part of the Victims Of Immigration Crime Engagement (VOICE) Office, an outfit established in February 2017. When the office first launched a line for its services the following April, protestors flooded the hotline to call in pranks and slow down response times. The plan picked up even more steam as the protestors shared the hotline number online, encouraging others to call in with fake tips.

According to internal emails and documents obtained by The Verge under the Freedom of Information Act, prank calls fully upended the system, leaving operators unable to answer more than 98 percent of incoming calls during the protest as the media relations team attempted to contain the narrative. In reports and emails produced in the first days of operation, ICE officials described an "overwhelming" amount of calls. The day after the launch, the office received more than 16,400. Of those, only a little more than 2,100 were placed into a queue, and only 260 answered. Callers in the queue waited as long as 79 minutes to reach an operator. An official noted that, should the rate of calls continue, they would need an additional 400 operators to field the hotline.

Android

Some Google Pixel Owners' Camera Photos Aren't Saving (theverge.com) 47

Some users on Reddit and Google's support forums are reporting an issue in which taking a photo using Google Camera occasionally fails to save. The issue appears to be widespread, "affecting original Pixel phones as well as the Pixel 2 / 2 XL," reports The Verge. From the report: The issue occurs specifically in cases when the user takes a photo with Google Camera, and switches to another app or locks the phone immediately after. Users are able to see a thumbnail of the photo in the Camera gallery circle, but upon tapping it, the photo disappears. In some occasions, the photo doesn't appear at all at first, but it will reappear in their gallery a day later.

There's also some reports of Galaxy S9, Moto Z2, Moto E4, and Nexus 5X owners experiencing the issue after using Google Camera, so it's unclear whether the issue is limited to Pixel phones or if it's connected to a larger Android bug. For now, users have come up with a workaround for an issue they believe is related to HDR photo processing time. Reddit user erbat suggests leaving the camera app open until HDR processing completes or turning off the HDR function completely.

Android

Palm Is Back With a Mini Companion Android Phone That's Exclusive To Verizon (droid-life.com) 101

A couple months ago, it was reported that the dearly departed mobile brand known as Palm would be making a comeback. That day has finally come. Yesterday, Palm announced The Palm, a credit card-sized Android smartphone that's supposed to act as a second phone. Droid Life reports: The Palm, which is its name, is a mini-phone with a 3.3-inch HD display that's about the size of a credit card, so it should fit nicely in your palm. It could be put on a chain or tossed in a small pocket or tucked just about anywhere, thanks to that small size. It's still a mostly fully-featured smartphone, though, with cameras and access to Android apps and your Verizon phone number and texts.

The idea here is that you have a normal phone with powerful processor and big screen that you use most of the time. But when you want to disconnect some, while not being fully disconnected, you could grab Palm instead of your other phone. It uses Verizon's NumberSync to bring your existing phone number with you, just like you would if you had an LTE smartwatch or other LTE equipped device.
Some of the specs of this Verizon-exclusive phone include a Snapdragon 435 processor with 3GB RAM, 32GB storage, 12MP rear and 8MP front cameras, 800mAh battery, IP68 water and dust resistance, and Android 8.1. As Kellen notes, "It does cost $350, which is a lot for a faux phone..."

We've already seen a number of gadget fans perplexed by this device. Digital Trends goes as far as calling it "the stupidest product of the year."
Communications

Our Reliance on Cellphones Began 35 Years Ago This Week (qz.com) 123

With 95% of Americans owning a cellphone, it can feel like we've been calling, texting, and tweeting on the go forever. But the infrastructure supporting our cellphones has actually not been around that long. From a report: While we're now on 4G networks, it was only 35 years ago this week that Ameritech (now part of AT&T) launched 1G, or the first commercial cell phone network. That network, called the Advanced Mobile Phone System (AMPS), went online on October 13, 1983, allowing people in the Chicago area to make and receive mobile calls for the first time. Ameritech president Bob Barnett, who made the first call, decided to make the historic moment count by ringing Alexander Graham Bell's grandson. A little more than a year later, UK's Vodafone hosted its first commercial call on New Year's Day. Israel's Pelephone followed suit in 1986, followed by Australia in 1987.

Cellphone technology had been around for quite a while before that. AMPS was in development for around 15 years, and engineers made the first mobile call on a prototype network a decade before the first commercial network call. It took that long to troubleshoot the various hardware, software, and radio frequency issues associated with setting up a fully functional commercial network.

Cellphones

Samsung Says Its Foldable Phone Will Be a Tablet You Can Put In Your Pocket (cnet.com) 38

The CEO of Samsung's mobile business, D.J. Koh, said you'll be able to use its upcoming foldable smartphone as a tablet that you can put in your pocket. While the phone has been teased and hyped up for several months, Koh stressed that it will not be a "gimmick product" that will "disappear after six to nine months after it's delivered." It'll reportedly be available globally. CNET reports: However, the foldable Samsung phone, like the Galaxy Round, will be Samsung's testbed device to see how reviewers and the market react. The Galaxy Round, which bowed vertically in the middle, was Samsung's first curve-screen phone. It's a direct ancestor to the dual curved screens we see on today's Galaxy S9 and Note 9 phones. The larger screen is important, Koh said. When Samsung first released the original Galaxy Note, he said, competitors called its device dead on arrival. Now, after generations of Notes phones, you see larger devices like the iPhone XS Max and the Pixel 3 XL, proving that consumers want bigger screens. A foldable phone would let screen sizes extend beyond 6.5 inches.
Android

Razer Phone 2 Launches With Notch-less Display, Wireless Charging, and RGB Lighting (anandtech.com) 72

Last November, Razer unveiled a smartphone designed for gamers who value performance and power over bells and whistles like waterproofing and wireless charging. At an event Wednesday night, Razer took the wraps off its successor, aptly named Razer Phone 2, which sports a brighter, notch-less, 5.72-inch IGZO LCD display with a 2560x1440 resolution and HDR, wireless charging, IP67 water- and dust-resistance rating, and RGB lighting behind the Razer logo on the rear. Given the addition of waterproofing and wireless charging, the Razer Phone 2 appears to be much more well-rounded than its predecessor, making the decision all the more difficult when shopping for a premium, high-end smartphone. AnandTech reports: This display is rated at 645 nits peak, up to 50% higher than the previous Razer Phone, and also supports HDR. Razer states that the display also has wide color gamut, which turns out to be 98.4% of DCI-P3. Also on the front, it has two front facing speakers in identical positions to the previous generation, and it has a front facing camera and sensor (albeit with swapped positions). That front camera is an 8MP f/2.0 unit, capable of recording at 1080p60, a user-requested feature for streaming and selfie recording. The front of the device is Corning Gorilla Glass 5, an upgrade from GG3 in the last generation.

When we move to the rear, things change much more noticeably. Instead of the aluminum rear, Razer has a full Gorilla Glass 5 back, which helps enable Qi Wireless Charging, a much requested feature. This is alongside QuickCharge 4+ through a Type-C cable. On the rear we have the dual cameras, this time placed in the center just above the logo. This time around Razer has gone with a 20MP Sony IMX363 f/1.75 main camera with OIS, and an 8MP Sony IMX 351 f/2.6 telephoto camera to enable some extra zoom functionality. Below the cameras is the Razer logo, which has a full 16.8million color RGB LED underneath which users can adjust through the onboard Chroma software.
The Razer Phone 2 is still very much power-focused, as it features Qualcomm's latest Snapdragon 845 CPU with a "vapor chamber cooling" which can allow the phone to draw 20-30% more power than other flagships. There's 8GB of LPDDR4X memory, 64GB of UFS storage with support for a microSD card, and a whopping 4,000mAh. Razer says their new smartphone will be priced at $799 and will start shipping in mid-November.
AI

Google's Human-Sounding Phone Bot Is Coming To the Pixel Next Month (wired.com) 26

Google's human-sounding AI software that makes calls for you is coming to Pixel smartphones next month in select markets, like New York, Atlanta, Phoenix, and the San Francisco Bay Area. Google Duplex, as it is called, will be a feature of Google Assistant and, for now, will only be able to call restaurants without online booking systems, which are already supported by the assistant. Wired reports: A Google spokesperson told WIRED that the company now has a policy to always have the bot disclose its true nature when making calls. Duplex still retains the human-like voice and "ums," "ahs," and "umm-hmms" that struck some as spooky, though. Nick Fox, the executive who leads product and design for Google search and the company's assistant, says those interjections are necessary to make Duplex calls shorter and smoother. "The person on the other end shouldn't be thinking about how do I adjust my behavior, I should be able to do what I normally do and the system adapts to that," he says.

Fox, the Google exec leading the project, pitches Duplex as a win-win. Google users will be freed from having to make phone calls to plan their outings; restaurants without online booking systems will gain new customers. "Those businesses lose out because people say 'Unless I can book this online I'm not going to book,'" he says. Some people closer to the restaurant business worry that Duplex might make calling restaurants too easy for Google users. Gwyneth Borden, executive director of the Golden Gate Restaurant Association, a trade group for Bay Area restaurants, says people may use the technology to book multiple reservations and then flake out, or call restaurants over and over. Restaurants can opt out of receiving Duplex calls by speaking up during a call from Duplex, or through the website where businesses can manage listing information shown in Google's search and maps services. When calls go awry -- Fox says the "overwhelming majority" work out fine -- the software will alert an operator in a Google call center who takes over.

Cellphones

Greg Kroah-Hartman: Outside Phone Vendors Aren't Updating Their Linux Kernels (linux.com) 86

"Linux runs the world, right? So we want to make sure that things are secure," says Linux kernel maintainer Greg Kroah-Hartman. When asked in a new video interview which bug makes them most angry, he first replies "the whole Spectre/Meltdown problem. What made us so mad, in a way, is we were fixing a bug in somebody else's layer!" One also interesting thing about the whole Spectre/Meltdown is the complexity of that black box of a CPU is much much larger than it used to be. Right? Because they're doing -- in order to eke out all the performance and all the new things like that, you have to do extra-special tricks and things like that. And they have been, and sometimes those tricks come back to bite you in the butt. And they have, in this case. So we have to work around that.
But a companion article on Linux.com notes that "Intel has changed its approach in light of these events. 'They are reworking on how they approach security bugs and how they work with the community because they know they did it wrong,' Kroah-Hartman said." (And the article adds that "for those who want to build a career in kernel space, security is a good place to get started...")

Kroah-Hartman points out in the video interview that "we're doing more and more testing, more and more builds," noting "This infrastructure we have is catching things at an earlier stage -- because it's there -- which is awesome to see." But security issues can persist thanks to outside vendors beyond their control. Linux.com reports: Hardening the kernel is not enough, vendors have to enable the new features and take advantage of them. That's not happening. Kroah-Hartman releases a stable kernel every week, and companies pick one to support for a longer period so that device manufacturers can take advantage of it. However, Kroah-Hartman has observed that, aside from the Google Pixel, most Android phones don't include the additional hardening features, meaning all those phones are vulnerable. "People need to enable this stuff," he said.

"I went out and bought all the top of the line phones based on kernel 4.4 to see which one actually updated. I found only one company that updated their kernel," he said. "I'm working through the whole supply chain trying to solve that problem because it's a tough problem. There are many different groups involved -- the SoC manufacturers, the carriers, and so on. The point is that they have to push the kernel that we create out to people."

"The good news," according to Linux.com, "is that unlike with consumer electronics, the big vendors like Red Hat and SUSE keep the kernel updated even in the enterprise environment. Modern systems with containers, pods, and virtualization make this even easier. It's effortless to update and reboot with no downtime."

Slashdot Top Deals