MoviePass exposed thousands of unencrypted customer card numbers
MoviePass customer cards are like normal debit cards: they’re issued by Mastercard and store a cash balance, which users who sign up to the subscription service can use to pay to watch a catalog of movies.
We also found records containing customers’ personal credit card numbers and their expiry date — which included billing information, including names and postal addresses. Among the records we reviewed, we found records with enough information to make fraudulent card purchases.
Security researcher Nitish Shah told TechCrunch he also found the exposed database months earlier. “I even notified them, but they [didn’t bother] to reply or fix it,” he said.
600,000 GPS trackers left exposed online with a default password of '123456'
Avast researchers said they found these issues in T8 Mini, a GPS tracker manufactured by Shenzhen i365-Tech, a Chinese IoT device maker.
Avast said the issues also impacted over 30 other models of GPS trackers, all manufactured by the same vendor, and some even sold as white-label products, bearing the logos of other companies.
A hacker can launch automated attacks against Shenzhen i365-Tech's cloud server by going through all user ID's one by one, and using the same 123456 password, and take over users' accounts.
Unfortunately for everyone, the issue persists to this day, as Shenzhen i365-Tech did not respond to Avast's emails when the company tried to warn the vendor. Similar contact attempts made by ZDNet's sister site CNET didn't succeed either.
Allowlist, not whitelist. Blocklist, not blacklist. Goodbye, wtf
Issue 981129 in the Chromium bug log lists a suggestion by Microsoft to “cleanup of potentially offensive terms in codebase” aims to rid the software blueprints of language such as whitelist (change to allowlist), blacklist (change to blocklist), “offensive terms using ‘wtf’ as protocol messages,” and other infelicities.
Googler Rick Byers, a Chromium engineer, gave the issue a cautious welcome, saying: "This sounds like a good strategy to me, thanks for doing this! We certainly have never intended for anything in the codebase to be potentially offensive, but I'm also not aware of anyone making an effort to find them all."
In May, Microsoft announced AI features in Word that, among other features, will emit “advice on more concise and inclusive language such as ‘police officer’ instead of ‘policeman.’"
White House to Relax Energy Efficiency Rules for Light Bulbs
The proposed changes would eliminate requirements that effectively meant that most light bulbs sold in the United States — not only the familiar, pear-shaped ones, but several other styles as well — must be either LEDs or fluorescent to meet new efficiency standards.
Calling the move an “unforced error,” he said, “Wasting energy with inefficient light bulbs isn’t just costly for homes and businesses, it’s terrible for our climate.”
Because of their long life and energy efficiency, an LED bulb can save consumers an estimated $50 to $100 over its several-year lifetime.
Google has secret webpages that feed your personal data to advertisers, report says
The company allegedly relays this information to advertisers using hidden webpages, allowing it to circumvent EU privacy regulations.
Ryan reportedly said he discovered that Google used a tracker containing web browsing information, location and other data and sent it to ad companies via webpages that "showed no content," according to FT.
The Data Protection Commission began an investigation into Google's practices in May after it received a complaint from Brave that Google was allegedly violating the EU's General Data Protection Regulation.
Over half the world is now running Windows 10
It has taken over four years and a hell of a lot of marketing, some good, some dodgy, but it's finally happened - Windows 10 now has over half the operating system market on desktop and laptop machines.
Most of those extra bums-on-seats come from Windows 7 which is now at 30 per cent (-1.49). That's still a big chunk of machines though, nearly a third, which is going to prove an increasing headache as we hit the last few months before the venerable OS is retired in January 2020.
Minecraft players to be helped by AI assistant
Tired of digging all those blocks in Minecraft? Help could be at hand from an artificial intelligence assistant that can dig and build on command.
Video demonstrations show the AI assistant being told to build a circle out of wooden blocks and answering questions about what it is doing, asked by the controlling player.
npm bans terminal ads
After last week a popular JavaScript library started showing full-blown ads in the npm command-line interface, npm, Inc., the company that runs the npm tool and website, has taken a stance and plans to ban such behavior in the future.
However, the JavaScript community didn't react in the way Aboukhadijeh hoped, and his initiative was criticized by most developers, who claimed the ads were polluting application logs.
Gel that makes teeth repair themselves could spell the end of fillings
Tooth enamel can now be made to repair itself by applying a special gel. The product could save people from developing cavities that require dental fillings.
The gel stimulated the growth of new enamel, with microscopy revealing that it had the same highly ordered arrangement of calcium and phosphate crystals as regular enamel.
Doorbell-Camera Firm Ring Has Partnered With 400 Police Forces, Extending Surveillance Reach
The doorbell-camera company Ring has quietly forged video-sharing partnerships with more than 400 police forces across the United States, granting them access to homeowners' camera footage and a powerful role in what the company calls America's "new neighborhood watch."
Ring is owned by Amazon, which bought the firm last year for more than $800 million, financial filings show. Amazon founder Jeff Bezos also owns The Washington Post.