Businesses

Mitel Buys Polycom For $1.96B In Enterprise Communications Consolidation Play (techcrunch.com) 14

An anonymous reader quotes a report from TechCrunch: Mitel announced that it would acquire Polycom in a cash-and-stock deal with a total value of $1.96 billion, creating a company with combined sales of $2.5 billion and 7,700 employees. Polycom's acquisition by Mitel comes at a key time in the world of enterprise communications and collaboration. On one hand, it is a time of massive change and evolution. For years a lot of the services that companies used were based on legacy networking, but in the last decade there has been a big shift to IP-based networks for many of these services. However, at the same time the whole space has been massively disrupted by startups that are upsetting by tapping into the next phase of digital services -- the internet. Companies like Microsoft by way of services like Skype and Yammer, and smaller startups like Slack, are overturning the whole idea of how people who are not in the same office floor can communicate and collaborate for work. These solutions are way cheaper than a lot of the legacy offerings; they tap into the cloud-based services that are now ubiquitous to share and work on files; and they are also built in very user-friendly ways, based around tech that ordinary consumers are using. Both companies compete against the likes of Cisco and Avaya. Mitel is perhaps best known for its IP telephony solutions, including PBX systems, while Polycom is a leader in conferencing services. They also cover SIP technology, and customers span 82% of Fortune 500 companies.
IOS

Apple Considering Google-Like 'Paid Search' On App Store (bloomberg.com) 49

Apple is considering big changes to the App Store, according to a Bloomberg report. The publication claims that the iPhone maker has a team working on "paid searches" -- something similar to Google's model. Under this, the company will charge its developers for showing their apps among top search results. Apple critic John Gruber writes: This sounds like a terrible idea. The one and only thing Apple should do with App Store search is make it more accurate. They don't need to squeeze any more money from it. More accurate, reliable App Store search would help users and help good developers. It's downright embarrassing that App Store search is still so bad. Google web search is better for searching Apple's App Store than the App Store's built-in search. That's the problem Apple needs to address.
Government

Obama Forms Commission To Bolster US Cyber Security (engadget.com) 53

An anonymous reader writes: President Obama unveiled a commission of private, public and academic experts to bolster the US cyber security sector. The Commission on Enhancing National Cybersecurity will be co-chaired by former IBM CEO Sam Palmisano and Tom Donilon, the President's former national security adviser. Some other notable members include MasterCard CEO Ajay Banga, Microsoft Research VP Peter Lee, Uber's current (and Facebook's former) Chief Security Officer Joe Sullivan, Frontier Communications Executive Chairperson Maggie Wildrotter, and Annie Anton, chair of the School of Interactive Computing at Georgia Tech. The specific goals of the commission are to: "Raise the level of cybersecurity in both the public and private sectors, deter, disrupt, and interfere with malicious cyber activity aimed at the U.S. or its allies and respond effectively to and recover from cyber incidents."
Security

iOS 1970 Bug Is Back, Can Be Exploited Via Rogue WiFi Networks (softpedia.com) 106

An anonymous reader writes: Back in February iOS users noted that setting your phone/tablet's date to January 1, 1970 would permanently brick their devices. After Apple fixed the issue in iOS 9.3.1, two security researchers have now uploaded a video on YouTube showing how to exploit this bug from a remote location, with no access to the user's phone. The setup involves attackers putting up a Wi-Fi network on which they're running a rogue NTP server. This server tells iOS devices syncing their time that it's December 31, 1969, 23:59:00. Twenty minutes later, if the battery didn't catch fire (which is possible with this new exploit), the iPad or iPhone device is permanently and irreversibly bricked.
Communications

FBI Couldn't Tell Apple What Hack It Used, Even If It Wanted To (qz.com) 99

An anonymous reader writes: The US Federal Bureau of Investigation doesn't own the technique used to unlock the San Bernardino iPhone, so it can't reveal the method to Apple even if it wanted to, Reuters reported, citing unnamed White House sources. The Washington Post reported yesterday, citing unnamed sources, that the FBI had paid a hacker a one-time fee to use a piece of hardware that allowed it to access the iPhone 5c belonging to one of the San Bernardino, California assailants. The vendor that supplied the hack is a non-US company, according to Reuters. But according to the Post report, it is not the Israeli firm Cellebrite, which had previously been named. The FBI would require the vendor's cooperation in order to submit the technique it used to Vulnerabilities Equities Process, a mechanism that allows the government to consider whether it should disclose security flaws to manufacturers. It's a move that mirrors Apple's own efforts to create security systems on its phones that even it wouldn't be able to crack, meaning it can't comply with a government order to hand over user data even if it wanted to.
Chrome

Chrome 50 Updates Push Notifications, Drops Support For Old Windows and OS X Versions (venturebeat.com) 168

An anonymous reader quotes a report from VentureBeat: Google today launched Chrome 50 for Windows, Mac, and Linux, adding the usual slew of developer features. You can update to the latest version now using the browser's built-in silent updater, or download it directly from google.com/chrome. As announced in November 2015, Chrome now no longer supports Windows XP, Windows Vista, OS X 10.6 Snow Leopard, OS X 10.7 Lion, nor OS X 10.8 Mountain Lion. Chrome 50 allows sites to include notification data payloads with their push messages. This eliminates the final server check -- the initial version relied on service workers to proactively fetch the information for a notification from the server, leading to problems when there were multiple messages in flight or when the device was on a poor network connection. Push notification payloads must be encrypted. Sites can now detect when a notification is closed by the user, resulting in better analytics and allowing for cross-device notification dismissal. The look of notifications can now be customized with timestamps and icons. Chrome 50 also brings support for declarative preload.
AI

Google Calendar Celebrates 10th Birthday With New Goals Feature (venturebeat.com) 19

An anonymous reader writes: Google Calendar is now 10 years old. What better way to celebrate than by adding a new goals feature to the service? The new feature lets you set a personal goal in Google Calendar, which will then find time in your schedule so you can achieve your goal. The feature is available for mobile-only users in all countries and languages where Google Calendar works. The goal is dependent on two main questions: "how often?" and "best time?" [Once you answer those questions], it will then find the best time slot in your schedule to pencil in your new goal. Goals will automatically adjust their timing throughout the week. Google Calendar will automatically reschedule if you add another event that's a direct conflict with a given goal. You can even defer a goal at any time, in which case Google Calendar will make time for it later. Using machine learning algorithms, Google Calendar gets better at scheduling the more you use it.
Movies

Piracy Fails To Prevent Another Box Office Record (torrentfreak.com) 221

An anonymous reader writes: The movie industry has reported global box office records reached $38.4 billion in 2015, up 5% on 2014's total, according to the MPAA's Theatrical Market Statistics report. The U.S. and Canada turned in $11.1 billion with international box office revenues hitting $27.2 billion. "I'm proud to say that the state of our industry has never been stronger," the former U.S. senator, MPAA chairman and CEO Chris Dodd said. "To paraphrase Mark Twain, the death of the movies has been greatly exaggerated," Dodd said. It begs the question whether or not piracy is truly killing the movie business -- the MPAA insists it is. According to Dodd, the box office would be more healthy to the tune of $1.5 billion if piracy could be brought under control. Some possible theories to achieve such a goal would be based off making content more readily available to the consumer. Napster co-found Sean Parker has a Screening Room project which hopes to bring first-run movies into the home via a set-top box. Though it has a trick up its sleeve: Customers prepared to pay the required $50 to watch at home would get two tickets to watch the movie in the cinema, which could either boost or at least maintain box office attendance. The Art House Convergence (AHC) said it "strongly opposes" the plan, warning it would only fuel torrent sites and piracy. National Assosciation of Theatre Owners chief John Fithian said, "More sophisticated window modeling may be needed for the growing success of a modern movie industry."
Communications

FBI Paid Professional Hackers One-Time Fee To Crack San Bernardino iPhone 149

There's another new wrinkle in the never-ending FBI vs Apple saga. The Washington Post is claiming that FBI did not require Cellebrite's assistance in hacking San Bernardino iPhone. Instead, the report claims, the government intelligence organization bought a previously unknown security bug from a group of professional hackers. According to the report, the hacker group provided FBI with at least one zero-day flaw in the iPhone 5c's security, which enabled FBI to circumvent the lockscreen and other security features. The bug hasn't been disclosed. FBI has previously noted that the technique it utilized in breaking into the iPhone 5c does not work with any new iPhone models (iPhone 5s or newer).
Facebook

Facebook's Account Kit Login System Works Via Phone Numbers, No Passwords Needed (softpedia.com) 116

An anonymous reader writes: At this year's F8 developer conference, Facebook announced a new tool called Account Kit, which can be used by app developers to support phone number-based login systems. Every time the user wants to login, they have to enter their phone number. Facebook will then send them a verification code via SMS, which they have to enter on the site. The system was already tested live, and Facebook expects it to be widely adopted, allowing sites to offer users accounts that don't require them to memorize a new password. Each developer has a 100,000 free confirmation SMS messages per month quota. Facebook claims to support SMS login operations for over 230 countries and regions, and in 40 different languages.
Networking

The Battle Between LTE and Wi-Fi May Have Left LTE-U Out In the Cold (networkworld.com) 60

alphadogg quotes a report from Networkworld: After more than a year of rancor over whether it would hurt Wi-Fi, a technology that lets LTE networks use unlicensed spectrum may have already missed its window of opportunity. LTE-Unlicensed is designed to improve cellular service by tapping into some of the frequencies used by Wi-Fi and other unlicensed technologies. But almost as soon as LTE-U was proposed in late 2014, Wi-Fi supporters pounced. They charged that it would drown out Wi-Fi signals because LTE didn't know how to make room for other users. Now carriers may be getting ready to bypass LTE-U altogether in favor of another system, called LAA (Licensed Assisted Access), that does the same thing but with additional protections for Wi-Fi. The LAA standard is complete, and products are expected to start shipping later this year.
Android

HTC 10 With 5.2-inch QHD Display, Snapdragon 820 SoC, 12MP Camera Launched at $699 (theverge.com) 57

Dan Seifert, writing for The Verge: HTC is today formally announcing the 10, its flagship smartphone for 2016. The HTC 10 follows last year's M9 and blends the design of the M series with the A9 that came last fall. HTC says it spent 12 months designing this phone and integrated feedback from its customers throughout the development process. The 10 has everything you might expect from a flagship Android phone in 2016. There's a 5.2-inch, quad HD Super LCD 5 display that HTC says displays 30 percent more color than last year's phone. The screen is covered in Gorilla Glass with curved edges that blend into the phone's metal frame. You'll be able to find out if that's enough for HTC to compete when the phone ships next month for $699. One interesting feature, which separates HTC 10 from many other Android flagship smartphones, is support for AirPlay. The feature enables the smartphone to stream media content to an Apple TV.
Government

Cellebrite Is Developing Roadside Police 'Textalyzer' Device (arstechnica.com) 188

An anonymous reader writes: Cellebrite, the company many believe helped the FBI crack into the iPhone 5c belonging to a San Bernardino terrorist, is developing a roadside "textalyzer" device to help law enforcement determine whether someone involved in a motor vehicle accident was unlawfully driving while distracted. As reported from Ars Technica: "Under the first-of-its-kind legislation proposed in New York, drivers involved in accidents would have to submit their phone to roadside testing from a textalyzer to determine whether the driver was using a mobile phone ahead of a crash." The textalyzer allegedly would keep conversations, contacts, numbers, photos, and application data private in an effort to get around the Fourth Amendment right to privacy. "Cellebrite has been leading the adoption of field mobile forensics solutions by law enforcement for years, culminating in the formal introduction of our UFED FIELD series product line a year ago," Jim Grady, Cellebrite's CEO, said in a statement. "We look forward to supporting DORCs and law enforcement -- both in New York and nationally to curb distracted driving."
Government

Syrian Government Hacked, 43GB of Data Spilled Online By Hacktivists (softpedia.com) 60

An anonymous reader writes: On April 6, a hacking outfit going by the name of Cyber Justice Team leaked data from multiple Syrian government and private websites. The leak includes the password file from the breached server, along with MySQL host permissions, admin passwords, and a link to the 10GB compressed file, uploaded to the file sharing site MEGA. While some of the data seems to be from older data breaches, some of it is also new. This is one of the biggest leaks of Syrian government data, a regime that has remained protected against such threats due to an aggressive cyber-policy. The government has been known to secretly back the Syrian Electronic Army hacker group, who the US government recently indicted (3 members at least).
Android

Academics Claim Google Android 2FA Is Breakable (theregister.co.uk) 48

totalcaos writes: Attackers who control the [browser on the] PC of a user consuming Google services (Gmail, Google+ etc) can surreptitiously push and activate apps on the user's mobile device, bypassing SMS-based two-factor authentication (2FA) via the phone. How Anywhere Computing Just Killed Your Phone-Based Two-Factor Authentication is a paper that explains the wider issues of phone-based 2FA. Herbert Boss, professor of systems and security at Vrije Unversiteit Amsterdam, who co-authored the mobile security paper with the two PhD students, disclosed the vulnerability to Google but they "still [refuse] to fix it."
Google

Google Fiber Drops Free Basic Service In Its Original City (engadget.com) 98

An anonymous reader writes: When Google Fiber first rolled out in Kansas City, it offered a free 5Mbps service if you were willing to pay a construction fee. As of recent, Google has quietly dropped that free tier in its first Fiber area, and has replaced it with a 100Mbps option that costs $50 per month. Anyone using the free tier has until May 19th to say they want to keep it. Note: Google will still offer the free service in low-income areas. Google Fiber customers in Austin and Provo still have the choice of the free internet option; Atlanta never had it to start with. Recode suggests this may reflect a broader change in strategy: Google has fiercer competition from incumbent carriers, so it may have to offer a fast-but-affordable selection to get those customers for whom the gigabit option is either too costly or sheer overkill.
Network

Over 135 Million Routers Vulnerable To Denial-of-service Flaw (zdnet.com) 115

schwit1 quotes a report from ZDNet: [More than 135 million modems are said to be vulnerable to a flaw that can leave users cut-off from the internet -- just by someone clicking on a trick link.] The problem lies with how a widely-used router, the ArrisSurfBoard SB6141, handles authentication and cross-site requests. Arris (formerly Motorola) said that it has sold more than 135 million of the SurfBoard SB6141 routers. That means the millions of Comcast, Time Warner Cable, or Charter customers who are shipped one of these routers when they subscribe are vulnerable. The flaw is so easy to exploit that anyone on an affected network can be tricked into clicking on a specially crafted web page or email. Security researcher David Longenecker, who found the flaws and posted the write-up on the Full Disclosure list earlier this week, released the "exploit" link after Arris stopped responding to emails he sent as part of the responsible disclosure process. There's no practical fix for the flaw, according to Longenecker. "The simplest solution would be a firmware update such that the web [user interface] requires a username and password before allowing disruptive actions such as rebooting or resetting the modem, and that validates that a request originated from the application and not from an external source," he said. But even if Arris released a fix, he said that the cable modems are not upgradable by their owners, meaning the internet provider would have to roll out the fix.
Iphone

Apple Won't Sue FBI To Reveal Hack Used To Unlock Seized iPhone (appleinsider.com) 43

An anonymous reader quotes a report from ZDNet: Apple will not pursue legal action against the US government to discover how federal agents broke into an iPhone used by one of the San Bernardino shooters. Attorneys for Apple speaking on background during a media briefing call on Friday said that it believed the method used to unlock the iPhone 5c would be short lived. It follows similar comments by FBI director James Comey who said in a speech on Thursday that the hack used to unlock the encrypted phone works on a "narrow slice" of devices. Apple attorneys said that the company is "confident" that the security weakness that the government alleges to have found will have a "short shelf life." The FBI's hack in the San Bernardino case would not help agents access a newer iPhone 5s used by a drug dealer in New York, where Apple faces a similar case against the government.
Encryption

Apple's Fight With US Over Privacy Enters a New Round (bloomberg.com) 62

An anonymous reader shares a report on Bloomberg: Apple Inc.'s fight over privacy with the U.S. isn't over yet, even after the government dropped a demand for the company's help in accessing a California shooter's iPhone because someone else found a way to crack it. The U.S. said it'll keep fighting to get the company's help in getting data off a phone in Brooklyn, New York, that belonged to a drug dealer because Apple provided assistance in accessing such devices earlier. In a court filing Friday, the government said it's going ahead with an appeal of a judge's order denying its request for Apple's help. The battle between the world's most valuable tech company and the U.S. over encryption and data privacy has sparked a national debate, with dozens of companies and organizations siding with Apple, while law enforcement has generally taken the government's side.
Encryption

White House Declines To Support Bill That Would Let Judges Order Tech Companies To Break Encryption (reuters.com) 150

kheldan quotes a report from Consumerist: Senators Richard Burr and Dianne Feinstein are expected to introduce a bill regarding phone encryption as soon as this week, according to Reuters. The draft text will give judges authority to order tech companies to help law enforcement when asked to -- basically, it would be a newer piece of law to fall back on than the All Writs Act of 1789, which is the one that usually sees use for this sort of thing. However, sources tell Reuters that the bill "does not spell out what companies might have to do or the circumstances under which they could be ordered to help," and therefore really doesn't necessarily change the underlying discussions at play, both in the tech world and in government. Nor does the bill specify penalties for failing to comply. The FBI recently briefed Senators Richard Burr and Dianne Feinstein on the methods used to unlock the San Bernardino terrorist's iPhone 5c. According to Reuters, the White House is declining to offer public support for draft legislation Burr and Feinstein are currently working on because the administration is "deeply divided on the issue." The White House has reviewed the text and offered feedback, but it is expected to provide minimal public input, if any, sources familiar with the discussions said.

Slashdot Top Deals