{"id":15091,"date":"2019-04-13T10:45:05","date_gmt":"2019-04-13T18:45:05","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/04\/13\/news-8840\/"},"modified":"2019-04-13T10:45:05","modified_gmt":"2019-04-13T18:45:05","slug":"news-8840","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/04\/13\/news-8840\/","title":{"rendered":"Julian Assange, a Big Yahoo Fine, and More Security News This Week"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5cb0fda188e8de51beb9f5cb\/master\/pass\/Julian-1136292554.jpg\"\/><\/p>\n<p><strong>Credit to Author: Caitlin Kelly| Date: Sat, 13 Apr 2019 13:00:00 +0000<\/strong><\/p>\n<p><span class=\"lede\">It was another <\/span>busy week in the security world, and perhaps the biggest story was the arrest of <a href=\"https:\/\/www.wired.com\/story\/the-julian-assange-i-met-in-2010-doesnt-exist-anymore\/\">Julian Assange<\/a> in London on Thursday. The WikiLeaks founder is facing <a href=\"https:\/\/www.wired.com\/story\/julian-assange-arrest-indictment-hacking-cfaa\/\">criminal charges<\/a> in the US over allegations that he conspired to help Chelsea Manning hack into Pentagon computer networks nine years ago. It\u2019s hardly an open-and-shut case, which <a href=\"https:\/\/www.wired.com\/story\/julian-assange-arrest-indictment-hacking-cfaa\/\">Andy Greenberg broke down<\/a> shortly after the indictment was unsealed. But it was enough for London police to forcibly remove Assange from the Ecuadorian Embassy where he had been holed up since 2012.<\/p>\n<p>Involuntary ejections of another sort were taking place across the pond, as President Trump instigated a dramatic purge of Department of Homeland Security leadership over a number of days. With Kirstjen Nielsen out as secretary, and more hardline immigration hawks running the show, some former government officials worry that <a href=\"https:\/\/www.wired.com\/story\/trump-homeland-security-purge-worries-cybersecurity-experts\/\">the leadership vacuum means policy chaos<\/a> around issues like cybersecurity and infrastructure security. Elsewhere in Washington DC, Attorney General William Barr told Congress that <a href=\"https:\/\/www.wired.com\/story\/william-barr-mueller-report-congress-testimony\/\">the Mueller Report is coming<\/a>. And the Senate held a hearing about robocalls, but as <a href=\"https:\/\/www.wired.com\/story\/robocalls-spam-fix-stir-shaken\/\">Lily Hay Newman explained<\/a> earlier in the week, this scourge isn\u2019t going away anytime soon.<\/p>\n<p class=\"paywall\">The Kaspersky Security Analyst Summit took place in Singapore this week. Researchers discovered a <a href=\"https:\/\/www.wired.com\/story\/tajmahal-swiss-army-spyware-apt\/\">new spyware framework<\/a>, called TajMahal, and <a href=\"https:\/\/www.wired.com\/story\/atm-hacks-swift-network\/\">new schemes to hack ATMs<\/a>. They detailed <a href=\"https:\/\/www.wired.com\/story\/triton-hacker-toolkit-fireeye\/\">the custom toolkits used by Triton hackers<\/a>, arguably the most dangerous malware in recent history. It turns out the Exodus spyware comes in <a href=\"https:\/\/www.wired.com\/story\/exodus-spyware-ios\/\">an iOS flavor<\/a>, in addition to Android. Want to read something more positive? Check out this heartwarming tale of how Android\u2019s security team <a href=\"https:\/\/www.wired.com\/story\/google-android-chamois-botnet\/\">defeated the epic Chamois botnet<\/a>.<\/p>\n<p class=\"paywall\">Elsewhere on the web, <em>Bloomberg<\/em> <a href=\"https:\/\/www.bloomberg.com\/news\/articles\/2019-04-10\/is-anyone-listening-to-you-on-alexa-a-global-team-reviews-audio\" target=\"_blank\">reported<\/a> that Amazon employs a team of thousands who work to improve Alexa by listening to conversations captured by the company\u2019s Echo devices. If that creeps you out, your surest bet is to make your house a smart-speaker-free zone. But if you\u2019ve grown too attached to your Echo, or Dot, or Blob, or whatever, Lily has some tips for <a href=\"https:\/\/www.wired.com\/story\/alexa-google-assistant-echo-smart-speaker-privacy-controls\/\">making your smart speaker as private as possible<\/a>.<\/p>\n<p class=\"paywall\">And there&#x27;s more! Each week we round up all the news WIRED didn\u2019t cover in depth. Click on the headlines to read the full stories. And stay safe out there.<\/p>\n<p class=\"paywall\">Motherboard reports that a UK court has sentenced the leader of Silk Road 2 to over five years in jail for crimes he committed in part while running the dark web marketplace. Dread Pirate Roberts 2, as he was of course known, is now revealed to be Thomas White, a technologist and privacy activist. As Motherboard points out, <em>WIRED<\/em> included Dread Pirate Roberts 2 on a list of <a href=\"https:\/\/www.wired.com\/2015\/06\/dark-web-drug-lords-got-away\/\">Dark Web drug lords who got away<\/a> in 2015, but it turns out that he was arrested in November 2014; the case just didn&#x27;t attract notice because UK media law prevented reporting on it before its conclusion.<\/p>\n<p class=\"paywall\">The WPA3 Wi-Fi security protocol, which officially launched last fall, has <a href=\"https:\/\/www.wired.com\/story\/wpa3-wi-fi-security-passwords-easy-connect\/\">lots of improvements that make security easier<\/a> for the average user. It also, though, came with a handful of vulnerabilities that researchers disclosed this week, including some that would allow a hacker to steal Wi-Fi passwords. The good news is that WPA3 isn&#x27;t all that common yet, and software patches have been issued. The bad news is that once again, nothing ever works exactly as advertised.<\/p>\n<p class=\"paywall\">NoScript has been a popular Firefox extension for well over a decade, helping people block unwanted JavaScript code from running on their machines. Now you can install it on Chrome, as well, although developer Giorgio Maone acknowledged that he had to drop NoScript&#x27;s XSS filter because of Chromium&#x27;s restrictions. Still, if you&#x27;re looking to quash junk code before it starts, you&#x27;ve now got a solid option on the world&#x27;s most popular browser.<\/p>\n<p class=\"paywall\">In 2016, Yahoo <a href=\"https:\/\/www.wired.com\/2016\/12\/yahoo-hack-billion-users\/\">announced<\/a> that a billion user accounts had been compromised in a 2013 breach. Ten months later, the company <a href=\"https:\/\/www.wired.com\/story\/yahoo-breach-three-billion-accounts\/\">revised that number upward<\/a> a bit, to <em>three billion<\/em> users\u2014a.k.a., every single user the company had at the time. Now Yahoo is trying to reach a class-action settlement over the debacle, and the process has been fittingly messy. The original settlement, <a href=\"https:\/\/news.bloomberglaw.com\/class-action\/yahoo-breach-amended-class-settlement-ups-value-to-117m\" target=\"_blank\">valued at $50 million<\/a>, was rejected by the judge for not being \u201cfundamentally fair, adequate and reasonable.\u201d Now Yahoo has more than doubled the amount. The amended settlement is still awaiting approval, but if it goes through, according to the plaintiffs lawyer it will be the \u201cbiggest common fund ever obtained in a data breach case.\u201d<\/p>\n<p class=\"related-cne-video-component__dek\">Scientists captured and released the first-ever picture of a black hole. WIRED&#39;s Deputy Science Editor Adam Rogers spoke with Harvard&#39;s Michael Johnson and Andrew Chael, two of the members of the research team, to find out what the achievement means for science.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/security-news-julian-assange-wpa3-yahoo\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5cb0fda188e8de51beb9f5cb\/master\/pass\/Julian-1136292554.jpg\"\/><\/p>\n<p><strong>Credit to Author: Caitlin Kelly| Date: Sat, 13 Apr 2019 13:00:00 +0000<\/strong><\/p>\n<p>Plus: Wi-Fi vulnerabilities, Silk Road 2&#8217;s founder, and more of the week&#8217;s top security news.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714,21357],"class_list":["post-15091","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security","tag-security-security-news"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15091","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=15091"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15091\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=15091"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=15091"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=15091"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}