Social Networks

LinkedIn Fined More Than $300 Million in Ireland Over Personal Data Processing (msn.com) 13

Ireland's data-protection watchdog fined LinkedIn 310 million euros ($334.3 million), saying the Microsoft-owned career platform's personal-data processing breached strict European Union data-privacy and security legislation. From a report: The Irish Data Protection Commission in 2018 launched a probe into LinkedIn's processing of users' personal data for behavioral analysis and targeted advertising after its French equivalent flagged a complaint it received from a non-profit organization. Irish officials raised concerns on the lawfulness, fairness and transparency of the practice, saying Thursday that LinkedIn was in breach of the EU's General Data Protection Regulation.

"The lawfulness of processing is a fundamental aspect of data protection law and the processing of personal data without an appropriate legal basis is a clear and serious violation of a data subjects' fundamental right to data protection," said Graham Doyle, deputy commissioner at the Irish Data Protection Commission. In their decision, Irish officials said LinkedIn wasn't sufficiently informing users when seeking their consent to process third-party data for behavioral analysis and targeted advertising and ordered the platform to bring its processing into compliance.

Communications

Boeing-Made Satellite Explodes In Space (cbsnews.com) 95

"Boeing has had a series of issues over the past few years," writes Slashdot reader quonset. "From planes crashing, lost service records, to a recent strike which cost them $6 billion, now comes word a satellite they made has exploded in space." CBS News reports: The Intelsat 33e satellite, which was launched in 2016 and provides communications across Europe, Asia and Africa, experienced "an anomaly" on Saturday, Intelsat said in a news release. Attempts were made to work with Boeing and repair the satellite, but on Monday, the U.S. Space Force confirmed that the satellite had exploded. The satellite's breakup left some customers without power or communications services. Intelsat said it is working with third-party providers to limit service interruptions, and is in communication with customers.

Since the breakup, the U.S. Space Force is now tracking "around 20 associated pieces" of the satellite in space. The agency said that there are "no immediate threats" and routine assessments to ensure safety are ongoing. Russia's space agency, Roscosmos, said it had recorded "more than 80 fragments" of the destroyed satellite. Analysis of the pieces' trajectory determined that the destruction of the satellite was "instantaneous and high-energy," Roscosmos said.

Social Networks

Norway To Increase Minimum Age Limit On Social Media To 15 To Protect Children (theguardian.com) 71

Norway plans to enforce a strict minimum social media age of 15 to protect children from harmful content and the influence of algorithms. The Guardian reports: The Scandinavian country already has a minimum age limit of 13 in place. Despite this, more than half of nine-year-olds, 58% of 10-year-olds and 72% of 11-year-olds are on social media, according to research by the Norwegian media authority. The government has pledged to introduce more safeguards to prevent children from getting around the age restrictions -- including amending the Personal Data Act so that social media users must be 15 years old to agree that the platform can handle their personal data, and developing an age verification barrier for social media.

"It sends quite a strong signal," the prime minister told the newspaper VG on Wednesday. "Children must be protected from harmful content on social media. These are big tech giants pitted against small children's brains. We know that this is an uphill battle, because there are strong forces here, but it is also where politics is needed." While he said he understood that social media could offer lonely children a community, self-expression must not be in the power of algorithms. "On the contrary, it can cause you to become single-minded and pacified, because everything happens so fast on this screen," he added.
"It is also about giving parents the security to say no," said Kjersti Toppe, the minister for children and families. "We know that many people really want to say no, but don't feel they can."
Graphics

Adobe Made Its Painting App Completely Free To Take On Procreate 27

Adobe's Fresco painting app is now free for everyone, in an attempt to lure illustrators to join its creative software suite. The Verge reports: Fresco is essentially Adobe's answer to apps like Procreate and Clip Studio Paint, which all provide a variety of tools for both digital art and simulating real-world materials like sketching pencils and watercolor paints. Adobe Fresco is designed for touch and stylus-supported devices, and is available on iPad, iPhone, and Windows PCs. The app already had a free-to-use tier, but premium features like access to the full Adobe Fonts library, a much wider brush selection, and the ability to import custom brushes previously required a $9.99 annual subscription. That's pretty affordable for an Adobe subscription, but still couldn't compete with Procreate's $12.99 one-time purchase model.

Starting today, all of Fresco's premium features are no longer locked behind a paywall. The app first launched in 2019 and isn't particularly well-known compared to more established Adobe apps like Photoshop and Illustrator that feature more complex, professional design tools. Fresco still has some interesting features of its own, like reflective and rotation symmetry (which mirror artwork as you draw) and the ability to quickly animate drawings with motion presets like "bounce" and "breathe."
Republicans

Internet Users Ask FCC To Ban Data Caps (arstechnica.com) 41

An anonymous reader quotes a report from Ars Technica: It's been just a week since US telecom regulators announced a formal inquiry into broadband data caps, and the docket is filling up with comments from users who say they shouldn't have to pay overage charges for using their Internet service. The docket has about 190 comments so far, nearly all from individual broadband customers.

Federal Communications Commission dockets are usually populated with filings from telecom companies, advocacy groups, and other organizations, but some attract comments from individual users of telecom services. The data cap docket probably won't break any records given that the FCC has fielded many millions of comments on net neutrality, but it currently tops the agency's list of most active proceedings based on the number of filings in the past 30 days.
"Data caps, especially by providers in markets with no competition, are nothing more than an arbitrary money grab by greedy corporations. They limit and stifle innovation, cause undue stress, and are unnecessary," wrote Lucas Landreth.

"Data caps are as outmoded as long distance telephone fees," wrote Joseph Wilkicki. "At every turn, telecommunications companies seek to extract more revenue from customers for a service that has rapidly become essential to modern life." Pointing to taxpayer subsidies provided to ISPs, Wilkicki wrote that large telecoms "have sought every opportunity to take those funds and not provide the expected broadband rollout that we paid for."

In response to Trump-appointed FCC Commissioner Nathan Simington's coffee refill analogy, internet users "Jonathan Mnemonic" and James Carter wrote, "Coffee is not, in fact, internet service." They added: "Cafes are not able to abuse monopolistic practices based on infrastructural strangleholds. To briefly set aside the niceties: the analogy is absurd, and it is borderline offensive to the discerning layperson."
Technology

Arm To Cancel Qualcomm's Chip Design License As Tech Feud Deepens (yahoo.com) 83

Arm has moved to cancel Qualcomm's architectural license agreement, escalating a legal battle that threatens to upend the global smartphone and PC chip markets. The British chip designer issued Qualcomm a 60-day termination notice for the license that allows the U.S. chipmaker to design custom processors using Arm's intellectual property. The cancellation could force Qualcomm to halt sales of products that generate much of its $39 billion annual revenue, Bloomberg reports.

The dispute stems from Qualcomm's $1.4 billion acquisition of chip startup Nuvia in 2021. Arm claims Qualcomm breached contract terms by using Nuvia's designs without permission, while Qualcomm maintains its existing agreement covers the acquired technology. The companies are set for a December trial to resolve Arm's 2022 breach-of-contract lawsuit and Qualcomm's countersuit. Arm is demanding Qualcomm destroy Nuvia designs created before the acquisition.
Transportation

San Francisco Muni's Rail System Will Spend $212 Million To Upgrade From Floppy Disks (govtech.com) 96

San Francisco's Municipal Transportation Agency approved a $212 million contract with Hitachi Rail to modernize the Muni Metro system's outdated train control system, which currently uses floppy disks and wire loops. Government Technology reports: The software that runs the system is stored on floppy disks that are loaded each morning and an outdated type of communication using wire loops that are easily disrupted. It was expected to last for 20 to 25 years, according to Muni officials. It moves data more slowly than a wireless modem, they said. By late 2027 and into 2028, a new communications-based system, which employs Wi-Fi and cell signals to precisely track the locations of trains, will be installed by Hitachi, which will provide support services for 20 years under the agreement.

While the current train control system operates only on the Market Street subway and Central Subway, the new system will control Metro light rail trains on the system's surface lines as well. The Hitachi system is said to be five generations ahead of the current system, said Muni Director of Transit Julie Kirschbaum, who described it as the best train control system on the market.

Transportation

Air Taxis and Other Electric-Powered Aircraft Cleared For Takeoff (theverge.com) 41

The FAA has released final regulations for electric vertical takeoff and landing (eVTOL) vehicles, introducing a new category of aircraft for the first time in nearly 80 years. These rules provide a framework for pilot training and operational requirements, addressing industry concerns while aiming to support the future of advanced air mobility. The Verge reports: The FAA says these "powered-lift" vehicles will be the first completely new category of aircraft since helicopters were introduced in 1940. These aircraft will be used for a variety of services, including air taxis, cargo delivery, and rescue and retrieval operations. The final rules published today contain guidelines for pilot training as well as operational requirements regarding minimum safe altitudes and visibility. [...] Powered lift includes aircraft described by industry watchers as electric vertical takeoff and landing, or eVTOL. Using tilt rotors, eVTOL aircraft are designed to take off and land vertically like a helicopter and then transition into forward flight on fixed wings like a plane.

[...] A new pilot training and qualifications rule was needed because "existing regulations did not address this new category of aircraft, which can take off and land vertically like a helicopter and fly like an airplane during cruise flight," the FAA said. The rule also provides a "comprehensive framework" for certifying the initial group of powered-lift instructors and pilots. According to the agency, the rule would: "Makes changes to numerous existing regulations and establishes a Special Federal Aviation Regulation (SFAR) with new requirements to facilitate instructor and pilot certification and training. Applies helicopter operating requirements to some phases of flight and adopts a performance-based approach to certain operating rules. Allows pilots to train in powered-lift with a single set of flight controls; legacy rules require two flight controls -- one for the student and one for the instructor."
"The regulation published today will ensure the U.S. continues to play a global leadership role in the development and adoption of clean flight," said JoeBen Bevirt, founder and CEO of Joby, in a statement. "Delivering the rules ahead of schedule is testament to the dedication, coordination and hard work of the rulemaking team."
AI

More Than 10,500 Artists Unite in Fight Against AI Companies' 'Unjust' Use of Creative Works (aitrainingstatement.org) 64

More than 10,500 artists and creators -- including ABBA's Bjorn Ulvaeus, actress Julianne Moore, actors Kevin Bacon and F. Murray Abraham, as well as former Saturday Night Live star Kate McKinnon, author James Patterson and Radiohead's Thom Yorke -- signed a statement condemning AI companies' unauthorized use of creative works for training their models. The initiative, led by former AI executive Ed Newton-Rex, demands an end to unlicensed training data collection amid mounting legal challenges against tech firms. "The unlicensed use of creative works for training generative AI is a major, unjust threat to the livelihoods of the people behind those works, and must not be permitted," reads the statement.

The protest comes as major artists and publishers battle AI developers in court. Authors John Grisham and George R.R. Martin are suing OpenAI, while record labels Universal, Sony and Warner have filed lawsuits against AI music creators Suno and Udio. The signatories reject proposed "opt-out" schemes for content scraping, calling instead for explicit creator consent.
United Kingdom

UK Considers New Smartphone Bans for Children (wired.com) 30

The UK parliament is considering clamping down on how young people use smartphones. A bill brought forward by a Labour member of parliament proposes both banning phones in schools and raising the age at which children can consent to social media companies using their data. Wired: Calls for smartphone bans have been growing in the UK, driven by fears that the devices are driving a decline in kids' mental health and ability to focus. Smartphone Free Childhood, a prominent pressure group inspired by Jonathan Haidt's book The Anxious Generation, calls for parents to delay getting smartphones for their children until they are at least 13. Florida has already passed a law that bans under-14s from holding social media accounts, and Australia is considering similar restrictions.

But academics warn that smartphone and social media bans are unlikely to be a catch-all solution to the problems facing young people. Experts on the impact of digital technologies argue that the legislation could end up shutting children out from the potential benefits of smartphones, and that more pressure should be put on social media companies to design better digital worlds for children. The latest proposed clampdown in the UK is thin on details, but the MP bringing the bill, Josh MacAllister, told the radio show Today that it would prevent social media companies making use of young peoples' data until they are 16. "We can protect children from lots of the addictive bad design features that come from social media," he said. The bill would also make a ban on phones in schools legally binding.

Transportation

EVs Are Just Going To Win 522

An anonymous reader shares a post: EVs are still winning. But they haven't won yet; only 4% of the global passenger car fleet, 23% of the bus fleet, and less than 1% of delivery trucks are electrified.

But at this point I think the writing is on the wall. The phenomenon of a superior technology displacing an older, inferior technology is not uncommon, and it generally looks like the EV transition is looking now. When a new technology passes a 5% adoption rate, it almost never turns out to be inferior to what came before; with EVs, that threshold has now been reached in dozens of countries.

In fact, we don't have to rely on trend-based forecasting to understand why EVs are just going to win. There are a number of fundamental factors that make EVs simply better than combustion vehicles. The longer time goes on, the more these inherent advantages will make themselves felt in the market.

The first of these is price. Currently, EVs often require government subsidies in order to be price-competitive with combustion cars. But batteries are getting cheaper and cheaper as we get better and better at building them. The cheaper batteries get, the smaller the subsidies required to get people to switch to EVs. Goldman Sachs reports that this crucial tipping point will be reached in about two years:

[...] Once batteries cross that tipping point, the EV revolution will take on its own momentum. It will simply be cheaper to buy an EV than a combustion car. People will gravitate toward the cheaper option, especially if it comes with other advantages. And in this case it does.

EVs' second advantage is convenience. Most EV owners will almost never have to fill their cars up at a station. This is because they will charge their cars at night, in their own home garages or driveway.
United States

Democrats Press For Criminal Charges Against Tax Prep Firms Over Data Sharing (theverge.com) 62

Democratic senators Elizabeth Warren, Ron Wyden, Richard Blumenthal and Representative Katie Porter are demanding the Justice Department prosecute tax preparation companies for allegedly sharing sensitive taxpayer data with Meta and Google through tracking pixels. The lawmakers' call follows a Treasury Inspector General audit confirming their earlier investigation into TaxSlayer, H&R Block, and Tax Act. The audit found multiple companies failed to properly obtain consent before sharing tax return information via advertising tools. Violations could result in one-year prison terms and $1,000 fines per incident, potentially reaching billions in penalties given the scale of affected users.

In a letter shared with The Verge, the lawmakers said: "Accountability for these tax preparation companies -- who disclosed millions of taxpayers' tax return data, meaning they could potentially face billions of dollars in criminal liability -- is essential for protecting the rule of law and the privacy of taxpayers," the letter reads. "We urge you to follow the facts and the conclusions of TIGTA and the IRS and to take appropriate action against any companies or individuals that have violated the law."
Businesses

If You Want Your Company's Stock To Go Up, Hire Wonkier IT People (ft.com) 44

Companies hiring specialized AI talent are seeing better stock market returns, according to new Barclays research. Analysis shows firms with higher ratios of specialized AI roles to general IT positions outperformed the market, with the top quintile returning 31.78% since October 2023, beating the S&P 500 Equal Weighted index. The findings suggest that targeted recruitment of "wonky IT people" with specific skills in natural language processing, computer vision, and specialized frameworks like TensorFlow could be a subtle indicator of future stock performance, offering investors a new lens for identifying companies poised to capitalize on AI productivity gains.
Encryption

Encrypted Chat App 'Session' Leaves Australia After Visit From Police 87

Session, a small but increasingly popular encrypted messaging app, is moving its operations outside of Australia after the country's federal law enforcement agency visited an employee's residence and asked them questions about the app and a particular user. 404 Media reports: Now Session will be maintained by an entity in Switzerland. The move signals the increasing pressure on maintainers of encrypted messaging apps, both when it comes to governments seeking more data on app users, as well as targeting messaging app companies themselves, like the arrest of Telegram's CEO in August. "Ultimately, we were given the choice between remaining in Australia or relocating to a more privacy-friendly jurisdiction, such as Switzerland. For the project to continue, it could not be centred in Australia," Alex Linton, president of the newly formed Session Technology Foundation (STF) which will publish the Session app, told 404 Media in a statement. The app will still function in Australia, Linton added. Linton said that last year the Australian Federal Police (AFP) visited a Session employee at their home in the country. "There was no warrant used or meeting organised, they just went into their apartment complex and knocked on their front door," Linton said.

The AFP asked about the Session app and company, and the employee's history on the project, Linton added. The officers also asked about an ongoing investigation related to a specific Session user, he added. Linton showed 404 Media an email sent by Session's legal representatives to the AFP which reflected that series of events. Part of Session's frustration around the incident came from the AFP deciding to "visit an employee at home rather than arranging a meeting through our proper (publicly available) channels," Linton said.
Government

One-Third of DHS's Border Surveillance Cameras Are Broken, Memo Says (nbcnews.com) 154

According to an internal Border Patrol memo, nearly one-third of the surveillance cameras along the U.S.-Mexico border don't work. "The nationwide issue is having significant impacts on [Border Patrol] operations," reads the memo. NBC News reports: The large-scale outage affects roughly 150 of the 500 cameras perched on surveillance towers along the U.S.-Mexico border. It was due to "several technical problems," according to the memo. The officials, who spoke on the condition of anonymity to discuss a sensitive issue, blamed outdated equipment and outstanding repair issues.

The camera systems, known as Remote Video Surveillance Systems, have been used since 2011 to "survey large areas without having to commit hundreds of agents in vehicles to perform the same function." But according to the internal memo, 30% were inoperable. It is not clear when the cameras stopped working.Two Customs and Border Protections officials said that some repairs have been made this month but that there are still over 150 outstanding requests for camera repairs. The officials said there are some areas that are not visible to Border Patrol because of broken cameras.

A Customs and Border Protection spokesperson said the agency has installed roughly 300 new towers that use more advanced technology. "CBP continues to install newer, more advanced technology that embrace artificial intelligence and machine learning to replace outdated systems, reducing the need to have agents working non-interdiction functions," the spokesperson said.
The agency points the finger at the Federal Aviation Administration (FAA), which is responsible for servicing the systems and repairing the cameras. "The FAA, which services the systems and repairs the cameras, has had internal problems meeting the needs of the Border Patrol, the memo says, without elaborating on what those problems are," reports NBC News. While the FAA is sending personnel to work on the cameras, Border Patrol leaders are considering replacing them with a contractor that can provide "adequate technical support for the cameras."

Further reading: U.S. Border Surveillance Towers Have Always Been Broken (EFF)
AI

Nicolas Cage Urges Young Actors To Protect Themselves From AI (deadline.com) 41

Actor Nicolas Cage warned young performers about the dangers of AI in film production during his speech at the Newport Beach Film Festival on Sunday. Cage urged actors to protect their craft from employment-based digital replica (EBDR) technology, which allows studios to manipulate performances post-filming. "This technology wants to take your instrument," Cage said. He explained that EBDR enables studios to alter actors' faces, voices, and body language after shooting, potentially compromising artistic integrity. Cage cited his cameo in "The Flash" as an example of EBDR use. He advised actors to consider their rights when approached with contracts permitting EBDR, coining the phrase "MVMFMBMI: my voice, my face, my body, my imagination."
AI

AI 'Bubble' Will Burst 99% of Players, Says Baidu CEO (theregister.com) 75

Baidu CEO Robin Li has proclaimed that hallucinations produced by large language models are no longer a problem, and predicted a massive wipeout of AI startups when the "bubble" bursts. From a report: "The most significant change we're seeing over the past 18 to 20 months is the accuracy of those answers from the large language models," gushed the CEO at last week's Harvard Business Review Future of Business Conference. "I think over the past 18 months, that problem has pretty much been solved -- meaning when you talk to a chatbot, a frontier model-based chatbot, you can basically trust the answer," he added.

Li also described the AI sector as in an "inevitable bubble," similar to the dot-com bubble in the '90s. "Probably one percent of the companies will stand out and become huge and will create a lot of value or will create tremendous value for the people, for the society. And I think we are just going through this kind of process," stated Li. The CEO also guesstimated it will be another 10 to 30 years before human jobs are displaced by the technology. "Companies, organizations, governments and ordinary people all need to prepare for that kind of paradigm shift," he warned.

Transportation

Europe Automakers Launch Cheaper Electric Cars to Compete With China (cnbc.com) 221

"Several of Europe's biggest carmakers unveiled low-cost electric vehicles at the Paris Motor Show this week," reports CNBC. The automakers are "seeking to jump-start a demand slump and recapture some of the market share now held by Chinese brands." "It feels like Europe is fighting back," Julia Poliscanova, senior director for vehicles and e-mobility supply chains at the Transport & Environment campaign group, told CNBC at the Paris Motor Show. "There are so many new models on show, and what is really great is that there are a lot of launches that are more affordable. So, Citroen, Peugeot [and] Renault, they are all showing some smaller affordable models," Poliscanova said. "This is exactly what we need for the mass market, for people to buy those vehicles more, and this is also where the competition from the Chinese is also the hardest," she added...

"The storytelling is that people have cooled off on EVs and there is no consumer demand, [but] this is really not true," Transport & Environment's Poliscanova said. "This year in Europe, we did not have affordable models, so people are not buying those overpriced premium vehicles. However, as soon as vehicles come in the right price range next year ... people will flock to buy them." Poliscanova said the launch of several low-cost EVs means electric car sales could account for up to a 24% market share next year, up from 14% this year. Chinese-made EVs typically cost less than half the prices seen in Europe and the U.S. last year, according to figures published by data firm JATO, underscoring the challenge for Western automakers to keep pace with Beijing...

Pere Brugal, president and managing director of GM Europe, said that the challenges facing Europe's auto industry should be seen as a transitional phase — and not evidence of a crisis. "The adoption of new technologies and new behaviors is never a linear growth story, but the end is full-electric [vehicles]," Brugal told CNBC at the Paris Motor Show.

Meanwhile, GM's CEO "says it will start making money on battery-powered models by the end of the year — becoming the only U.S. automaker aside from Tesla to achieve that feat," reports the New York Times (adding that sales are increasing "and the company just introduced a model that sells for less than $30,000 after a federal tax credit.")

And GM "is still committed to doing away with combustion engine cars in the United States by 2035."
AI

Can We Turn Off AI Tools From Google, Microsoft, Apple, and Meta? Sometimes... (seattletimes.com) 80

"Who asked for any of this in the first place?" wonders a New York Times consumer-tech writer. (Alternate URL here.) "Judging from the feedback I get from readers, lots of people outside the tech industry remain uninterested in AI — and are increasingly frustrated with how difficult it has become to ignore." The companies rely on user activity to train and improve their AI systems, so they are testing this tech inside products we use every day. Typing a question such as "Is Jay-Z left-handed?" in Google will produce an AI-generated summary of the answer on top of the search results. And whenever you use the search tool inside Instagram, you may now be interacting with Meta's chatbot, Meta AI. In addition, when Apple's suite of AI tools, Apple Intelligence, arrives on iPhones and other Apple products through software updates this month, the tech will appear inside the buttons we use to edit text and photos.

The proliferation of AI in consumer technology has significant implications for our data privacy, because companies are interested in stitching together and analyzing our digital activities, including details inside our photos, messages and web searches, to improve AI systems. For users, the tools can simply be an annoyance when they don't work well. "There's a genuine distrust in this stuff, but other than that, it's a design problem," said Thorin Klosowski, a privacy and security analyst at the Electronic Frontier Foundation, a digital rights nonprofit, and a former editor at Wirecutter, the reviews site owned by The New York Times. "It's just ugly and in the way."

It helps to know how to opt out. After I contacted Microsoft, Meta, Apple and Google, they offered steps to turn off their AI tools or data collection, where possible. I'll walk you through the steps.

The article suggests logged-in Google users can toggle settings at myactivity.google.com. (Some browsers also have extensions that force Google's search results to stop inserting an AI summary at the top.) And you can also tell Edge to remove Copilot from its sidebar at edge://settings.

But "There is no way for users to turn off Meta AI, Meta said. Only in regions with stronger data protection laws, including the EU and Britain, can people deny Meta access to their personal information to build and train Meta's AI." On Instagram, for instance, people living in those places can click on "settings," then "about" and "privacy policy," which will lead to opt-out instructions. Everyone else, including users in the United States, can visit the Help Center on Facebook to ask Meta only to delete data used by third parties to develop its AI.
By comparison, when Apple releases new AI services this month, users will have to opt in, according to the article. "If you change your mind and no longer want to use Apple Intelligence, you can go back into the settings and toggle the Apple Intelligence switch off, which makes the tools go away."
Security

How WatchTowr Explored the Complexity of a Vulnerability in a Secure Firewall Appliance (watchtowr.com) 9

Cybersecurity startup Watchtowr "was founded by hacker-turned-entrepreneur Benjamin Harris," according to a recent press release touting their Fortune 500 customers and $29 million investments from venture capital firms. ("If there's a way to compromise your organization, watchTowr will find it," Harris says in the announcement.)

This week they shared their own research on a Fortinet FortiGate SSLVPN appliance vulnerability (discovered in February by Gwendal Guégniaud of the Fortinet Product Security team — presumably in a static analysis for format string vulnerabilities). "It affected (before patching) all currently-maintained branches, and recently was highlighted by CISA as being exploited-in-the-wild... It's a Format String vulnerability [that] quickly leads to Remote Code Execution via one of many well-studied mechanisms, which we won't reproduce here..."

"Tl;dr SSLVPN appliances are still sUpEr sEcurE," their post begains — but the details are interesting. When trying to test an exploit, Watchtowr discovered instead that FortiGate always closed the connection early, thanks to an exploit mitigation in glibc "intended to hinder clean exploitation of exactly this vulnerability class." Watchtowr hoped to "use this to very easily check if a device is patched — we can simply send a %n, and if the connection aborts, the device is vulnerable. If the connection does not abort, then we know the device has been patched... " But then they discovered "Fortinet added some kind of certificate validation logic in the 7.4 series, meaning that we can't even connect to it (let alone send our payload) without being explicitly permitted by a device administrator." We also checked the 7.0 branch, and here we found things even more interesting, as an unpatched instance would allow us to connect with a self-signed certificate, while a patched machine requires a certificate signed by a configured CA. We did some reversing and determined that the certificate must be explicitly configured by the administrator of the device, which limits exploitation of these machines to the managing FortiManager instance (which already has superuser permissions on the device) or the other component of a high-availability pair. It is not sufficient to present a certificate signed by a public CA, for example...

Fortinet's advice here is simply to update, which is always sound advice, but doesn't really communicate the nuance of this vulnerability... Assuming an organisation is unable to apply the supplied workaround, the urgency of upgrade is largely dictated by the willingness of the target to accept a self-signed certificate. Targets that will do so are open to attack by any host that can access them, while those devices that require a certificate signed by a trusted root are rendered unexploitable in all but the narrowest of cases (because the TLS/SSL ecosystem is just so solid, as we recently demonstrated)...

While it's always a good idea to update to the latest version, the life of a sysadmin is filled with cost-to-benefit analysis, juggling the needs of users with their best interests.... [I]t is somewhat troubling when third parties need to reverse patches to uncover such details.

Thanks to Slashdot reader Mirnotoriety for sharing the article.

Slashdot Top Deals