Apple iOS 11 security 'downgrade' decried as 'horror show'

Oleg Afonin, a security researcher for password-cracking forensic IT biz Elcomsoft, in a blog post on Wednesday called iOS 11 "a horror story" due to changes the fruit-themed firm made to its mobile operating system that stripped away a stack of layered defenses.
"Once an intruder gains access to the user’s iPhone and knows (or recovers) the passcode, there is no single extra layer of protection left," Alfonin explains in his post. "Everything (and I mean, everything) is now completely exposed. Local backups, the keychain, iCloud lock, Apple account password, cloud backups and photos, passwords from the iCloud Keychain, call logs, location data, browsing history, browser tabs and even the user’s original Apple ID password are quickly exposed."
Wondering why your internal .dev web app has stopped working?

Rather than connecting to private stuff on an internal .dev domain to pick up where they left off, a number of engineers and sysadmins are facing an error message in their web browser complaining it is "unable to provide a secure connection."
Chrome forces connections to all domains ending in .dev (as well as .foo) to use HTTPS via a HTTP Strict Transport Security (HSTS) header. This is part of Google's larger and welcome push for HTTPS to be used everywhere for greater security.
HP stealthily installs new spyware called HP Touchpoint Analytics Client

Dubbed “HP Touchpoint Analytics Service,” HP says it “harvests telemetry information that is used by HP Touchpoint’s analytical services.” Apparently, it’s HP Touchpoint Analytics Client version 4.0.2.1435.
Martin Brinkmann on ghacks has a detailed accounting of the spyware and how to remove it. He gives step-by-step instructions for disabling the HP Touchpoint Analytics Client in your Services listing, as well as deleting the HP Touchpoint Manager.
End of an open source era: Linux pioneer Munich confirms switch to Windows 10

Now Munich will begin rolling out a Windows 10 client from 2020, at a cost of about €50m, with a view to Windows replacing LiMux across the council by early 2023.
Nevertheless, despite Munich running both systems side-by-side for more than a decade, today the council says this dual-system setup is unsustainable, hence the need to return to Windows.
While staff have reported intermittent problems with IT at the council, past surveys have found only a minority of staff wanted to return to Windows and Microsoft Office.
New Firefox Runs Like a Rabbit

"We have a better balance of memory to performance than all the other browsers," said Firefox Vice President for Product Nick Nguyen.
"A significant number of our users are on machines that are two cores or less, and less than 4 gigabytes of RAM," Nguyen explained.
- browser
EA ditches microtransactions in Star Wars Battlefront II

Electronic Arts has announced it is turning off all in-game purchases on Star Wars Battlefront II, on the eve of the game's worldwide launch, after a massive outcry from fans.
Early players soon discovered unlocking top hero characters like Luke Skywalker or Darth Vader could take up to 40 hours, unless players paid-to-play.
But when payments become a major impediment to gameplay, or a game becomes virtually unplayable without forking out cash, gamers are quick to speak up.
Firefox Quantum arrives with faster browser engine, major visual overhaul, and Google as default search engine

The new version, which Mozilla calls “by far the biggest update since Firefox 1.0 in 2004,” brings massive performance improvements and a visual redesign.
The goal is to make Firefox the fastest and smoothest browser for PCs and mobile devices — the company has previously promised that users can expect “some big jumps in capability and performance” through the end of the year.
An Extremely Convincing WhatsApp Fake Was Downloaded More Than 1 Million Times From Google Play

According to Hacker News, the fake WhatsApp was nearly indistinguishable from the real thing thanks to an invisible space placed at the end of the developer’s name.
A search for “WhatsApp” on Google Play currently shows no fewer than seven spoof apps using slight variations on the developer name “WhatsApp Inc.”, including versions with extra spaces, asterisks, or commas.
In prior incidents, security experts or unlucky users have encountered malware in compromised messaging apps, in a line of popular children’s games, and even in fake versions of Pokemon Go.
Hardware has never been better, but it isn't a licence for code bloat

My iPhone 6 recently upgraded itself to iOS 11. And guess what – it's become noticeably slower. This is no surprise, of course, as it's the same on every platform known to man. The new version is slower than the old.
I believe that one overriding reason for the latter is fairly simple: there's no longer a compulsion to write super-efficient code. These days we measure computer RAM in gigabytes, not kilobytes, and CPU clock speeds are in gigahertz, not megahertz. So back in the day you had to write code incredibly defensively if you were to make it work on the hideously constrained hardware available. Algorithms had to be elegant: processors were so slow that a brute-force algorithm just wasn't really an option, and with tiny amounts of RAM you had to be fastidious with data structures.
Denuvo’s DRM now being cracked within hours of release

Those nearly instant Denuvo cracks follow summer releases like Sonic Mania, Tekken 7, and Prey, all of which saw DRM protection cracked within four to nine days of release.
If Denuvo can no longer provide even a single full day of protection from cracks, though, that protection is going to look a lot less valuable to publishers. But that doesn't mean Denuvo will stay effectively useless forever. The company has updated its DRM protection methods with a number of "variants" since its rollout in 2014, and chatter in the cracking community indicates a revamped "version 5" will launch any day now.