Archive for 2020

Sharp Electronics Of Canada Announces Eight New Letter-Sized A4 Printers And MFPs

Posted in Commentary with tags on December 17, 2020 by itnerd

Sharp Electronics of Canada has announced eight new models in its lineup of letter-sized A4 printers for office and home use. The range features compact designs that fit easily into any space, and out-of-the-box copy, print, scan and fax capabilities. These new models are designed with high-performance features typically found on larger machines, delivering the productivity, performance and reliability needed for busy work environments. 

This new expansion of our A4 lineup is complementary to our solid, award winning A3 products and other document solutions we support and provides our channel partners and customers with a one-Sharp solution across their businesses and their home offices; our way of supporting the change in work from home trend.The new models include three monochrome multifunction printers (MFPs): MXB557F, MXB427W and MXB467F; three colour MFPs: MXC357F, MXC407F and MXC507F; and two monochrome Single Function Printers (SFPs): MXB427PW and MXB467P. With speeds ranging from 35-60 pages per minute, these products can integrate seamlessly into any existing office or home environment.

Users will benefit from a compact design with robust technology and advanced workflow features for virtually any sized office. These new products include easy connectivity to your popular public cloud services such as Box, Google Drive, OneDrive and Dropbox. Mobile printing is supported for Chromebooks and for iOS devices via AirPrint. Users can use MS Office Direct to print from USB drives, or send scanned files directly to USB. All of these can be easily navigated by a robust, intuitive and easy to use touch panel display.

Businesses are assessing their needs as they plan returns to their office spaces, but are also considering how to ensure employees have all they need for their offices at home. The new monochrome and colour MPFs from Sharp fit into any space or workflow, supporting our goal to provide Canadian companies with the tools right for them so employees can be productive no matter where they’re working.

All models will be available through authorized Sharp dealers in February 2021.

Guest Post: ESET Discovers Operation SignSight: Supply-chain Attack Against A Certification Authority In Southeast Asia

Posted in Commentary with tags on December 17, 2020 by itnerd

ESET Research discovered another supply-chain attack in Asia, this time on the website of the Vietnam Government Certification Authority (VGCA). The attackers modified two of the software installers available for download on this website by adding a backdoor in order to compromise users of the legitimate application. Supply-chain attacks appear to be a quite common compromise vector for cyberespionage groups. Cybercrime operation SignSight leverages malware known as PhantomNet or Smanager.

“In Vietnam, digital signatures are very common, as digitally signed documents have the same level of enforceability as wet signatures. In addition to issuing certificates, the VGCA develops and distributes a digital signature toolkit. It is used by the Vietnamese government, and probably by private companies, to sign digital documents. The compromise of a certification authority website is a good opportunity for APT groups, since visitors are likely to have a high level of trust in a state organization responsible for digital signatures,” explains Matthieu Faou, one of ESET’s researchers investigating the SignSight operation.

The PhantomNet backdoor is quite simple and is able to collect victim information (computer name, hostname, username, OS version, user privileges [admin or not], and the public IP address) as well as install, remove and update malicious plugins. These additional and more complex plugins are probably only deployed on a few selected machines. By also installing the legitimate program, the attackers make sure that this compromise won’t be easily noticed by end users.

ESET researchers uncovered this new supply-chain attack in early December 2020 and notified the compromised organization and the VNCERT. We believe that the website ceased delivering compromised software installers at the end of August 2020. The Vietnam Government Certification Authority confirmed that they were aware of the attack before our notification and that they notified the users who downloaded the trojanized software.

ESET has seen victims in the Philippines in addition to Vietnam.

For more technical details about operation SignSight, read the blog post “Operation SignSight: Supply- chain attack against a certification authority in Southeast Asia” on WeLiveSecurity. Make sure to follow ESET Research on Twitter for the latest news from ESET Research.

OVHcloud Joins The Open Invention Network

Posted in Commentary with tags on December 17, 2020 by itnerd

OVHcloud, the European leader with a global footprint in the cloud industry, announced today it joined the Open Invention Network (OIN). This engagement affirms OVHcloud’s approach in terms of Open Innovation and will strengthen the company’s ecosystem, by supporting a world-class open source innovation community.

One of the keys to the success of OVHcloud over the years lies in the company’s ability to develop and promote innovation, both in IT itself, but also in its industrial practices. This innovative DNA is core to constantly researching and developing new technologies and optimizing the performance of OVHcloud’s solutions portfolio. By joining OIN, OVHcloud contributes more to the open source community and therefore protects its open ecosystem, on which its always relied to build more flexible and cost effective solutions to support the evolution of its users’ needs. 

The open working methods have always been at the heart of its corporate culture. As a global alternative cloud provider, OVHcloud actively encourages a whole ecosystem of advocates to collaborate, innovate, and deliver to open communities. In accordance with its company values of trust and working together, and its product values of transparency, reversibility and interoperability, OVHcloud has chosen to join OIN in order to accelerate its open innovation strategy, and thus confirms its commitment to digital sovereignty and an open approach to software technology.

OVHcloud is now committed to licensing the OIN community with its current and future Linux System patent portfolio, in order to promote open innovation and preserve the open community.

Open to all, OIN’s community practices patent non-aggression in core Linux and adjacent open source technologies by cross-licensing Linux System patents to one another on a royalty-free basis. Patents owned by Open Invention Network are similarly licensed royalty-free to any organization that agrees not to assert its patents against the Linux System. You can join the OIN community by signing the OIN license online at  http://www.j-oin.net/

TikTok Music 2020: The Full Playlist

Posted in Commentary with tags on December 17, 2020 by itnerd

Freed from the limitations of programmed radio or streaming playlists, a viral song on TikTok can come from any year, any genre, or any artist, fueled by a community eager to find and share new musical obsessions. 

Canadians were a major part of this year’s Year On TikTok – Music 2020 list, from established superstars like Drake, Justin Bieber and The Weeknd (and really what’s more meaningful a Grammy nomination or TikTok’s Top Artists?), to #TBT artists like Avril Lavigne and Nelly Furtado and new emerging artists that attribute their success to TikTok like Curtis Waters, 437Aiden and Tate McRae.

You can find the complete top TikTok – Music 2020 list here. And here’s an overview of what’s inside to help you discover and navigate the categories that will matter most to you: 

What’s Inside: 

  1. Real Quick: The Fastest Songs To A Billion *Drake
  2. Pick Your Sound: Top Genres
  3. They’ve Got The Hits: Top Artist Catalog
  4. The Come Up: Emerging Artists *Curtis Waters, 437Aiden and Tate McRae
  5. Down The Rabbit Hole: Unexpected Hits and Niche Discoveries 
  6. TikTok LIVE: 2020’s Essential Music Moments *The Weeknd
  7. Celebrating Culture With Music
  8. Iconic: Legendary Acts On TikTok
  9. Remember These? Songs Revitalized On TikTok *Simple Plan, Nelly Furtado and Avril Lavigne

Guest Post: Atlas VPN Says That 1 in 5 Employees Fall For Phishing Emails Even After Security Training

Posted in Commentary with tags on December 17, 2020 by itnerd

The year 2020 was challenging for cybersecurity on many levels. The global pandemic brought a wave of cyberattacks exploiting the mayhem, while remote work made employees more vulnerable to such attacks.

In particular, phishing attacks hit record levels, with Google reporting over 2 million phishing sites in 2020 alone. However, even more alarming is that current cybersecurity measures employed by organizations worldwide are inadequate to protect against such threats.

According to the data presented by the Atlas VPN team, one-fifth (19.8%) of employees fell for phishing emails even if they have gone through security awareness training. 

Rachel Welch, COO of Atlas VPN, shares her thoughts on the situation:

“We are in an age where cyberattacks are evolving faster than ever before. However, the data shows that organizations are not doing enough to educate their employees on cybersecurity threats.

Organizations have to realize that just as the cyberthreat landscape is shifting, so should their response to cyberthreats. Otherwise, the organization is left vulnerable to cyberattacks, which have devastating and long-lasting consequences to both the organization itself and its clients.”

Out of the employees who did click on phishing email links, 67.5% also entered their credentials, such as password, on the phishing webpage. It means that overall, 13.4% of employees provided their credentials to phishers. 

The Public Sector is the most vulnerable to phishing attacks

While no sector is immune to phishing attacks, some industries were better educated on recognizing such assaults than the others.

Five industries had above average phishing email click rates, with the public sector being at the top of the list.  A total of 28.4% of employees working in the public sector clicked on a phishing link in an email.

Next up is the Transport industry. Nearly a quarter (24.7%) of employees in the sector fell for phishing emails. 

To read the full report, head over to: https://atlasvpn.com/blog/1-in-5-employees-fall-for-phishing-emails-even-after-a-security-training

So…. Am I The Only Person Who Finds That It’s Weird That Google Had An Extension To Exclude You From Their Ad Tracking?

Posted in Commentary with tags on December 16, 2020 by itnerd

I tripped over an browser add-on that appears to be from Google that has this function according to them:

To provide website visitors with the ability to prevent their data from being used by Google Analytics, we’ve developed the Google Analytics opt-out browser add-on for websites using the supported version of Google Analytics JavaScript (analytics.js, gtag.js). 

If you want to opt out, download and install the add-on for your web browser. The Google Analytics opt-out add-on is designed to be compatible with Chrome, Internet Explorer 11, Safari, Firefox and Opera. In order to function, the opt-out add-on must be able to load and execute properly on your browser. For Internet Explorer, third-party cookies must be enabled. Learn more about the opt out and how to properly install the browser add-on here.

So, if I am not in favor of Google tracking my every activity, I need to install this add-on that I am somehow supposed to trust. That really doesn’t make sense to me as trusting Google to protect my privacy sounds like an oxymoron to me. And does the existence of this add-on mean that options such as Privacy Badger and uBlock Origin aren’t as effective? That isn’t clear. But the existence of this add-on from Google creates more questions than answers.

TikTok Sends Job Applicants Info To China

Posted in Commentary on December 16, 2020 by itnerd

There has to be something shady about this. It has come to light that TikTok routes the personal data of job applicants through servers in China and only discloses this to candidates in certain countries Business Insider has discovered:

US job candidates, notably, are not told their data will be routed through China. Some of the personal information TikTok says it collects about applicants is potentially highly sensitive, with the firm’s own policies stating that it collects medical data; sex and race data; marital status; geolocation data, among many other categories. The revelation is an embarrassment for TikTok, which has spent much of 2020 maintaining that it is separate to its Chinese owner ByteDance, and fending off unproven insinuations by President Trump that it funnels user data to China. After being approached by Business Insider, TikTok said it would no longer store job applicant data in China.

Well, this would be a major disincentive for anyone to apply for a job at TikTok. And the fact that after they were caught doing this they said that they would stop this practice doesn’t change my view on that. Though in a way I am not surprised by this seeing as they are a Chinese company. This is yet another reason why TikTok is suspect at best.

BREAKING: Gmail Is Having Some Sort Of Catastrophic Failure

Posted in Commentary with tags on December 15, 2020 by itnerd

If you’re trying to send an email to a Gmail account, you are likely getting this error message:

550-5.1.1 The email account that you tried to reach does not exist.”

This is to a valid Gmail address that I have been sending email to for years.

I have seen this since early this evening and Google confirms this on its services dashboard, writing at 1:30 PM Pacific that they’re impacting a “significant” number of users. But they also claim that the issues are resolved. However, I’m not seeing that as I still can’t send emails to Gmail users. So maybe Google is as premature as a virgin by declaring this as fixed. I’ll continue to watch this and update accordingly.

UPDATE: Gmail seems to be working as per this Tweet from Proton Mail:

Hyper Scape Coming To Epic Games Store On Thursday, December 17

Posted in Commentary with tags on December 15, 2020 by itnerd

Today, Ubisoft® announced that Hyper Scape will release on Epic Games Store on Thursday, December 17th. In addition, console crossplay is now available alongside Hyper Scape’s Winter Festival. Along with these major updates, new improvements have been made to the Team Deathmatch Mode (Beta)  that was recently added to Hyper Scape, but also to combat, Arcadium free roam mode, and the marketplace as part of the Title Update that released December 10th. Additional details on Title Update 3 can be found here.

CONSOLE CROSSPLAY

Console crossplay is now available for Hyper Scape, allowing matchmaking between PlayStation and Xbox players across all modes of Hyper Scape, including Crown Rush Battle Royale modes and Team Deathmatch. This includes players on both current and next-gen consoles. PC players will be able to party up with console friends in the same squad, in this case the full squad will be placed in the PC matchmaking pool.

EPIC GAMES STORE

Hyper Scape will be available on the Epic Games Store starting December 17th. PC players will now be able to download, install and play Hyper Scape for free on both Ubisoft Connect and the Epic Games Store.

WINTER FESTIVAL

Winter is coming in the Hyper Scape from December 15th to December 29th! Discover a snow-covered Neo-Arcadia and brand new festive cosmetics to partake in the holiday celebrations.

TEAM DEATHMATCH (BETA)

Following a first release on November 18th, improvements have been made to the Team Deathmatch Beta in the December 10th Title Update:

  • Random Map Rotation: Random map rotation available to feature three Team Deathmatch maps (The Foundry, Hillside, Bus Depot)
  • New Score Cap: Kill cap for a match has been increased to 50, and max match length extended to 12 minutes
  • Activated Challenges: Standard challenges are now enabled in Team Deathmatch

For more information about Hyper Scape, please visit: hyperscape.com

Limbitless Solutions Announces New Bionic Arm In Association With Ubisoft

Posted in Commentary with tags on December 15, 2020 by itnerd

Today, Limbitless Solutions announced that beginning in 2021, recipients of 3D-printed prosthetic arms from UCF’s Limbitless Solutions get to choose new bionic designs from the world of Assassin’s Creed® Odyssey. Kassandra, a main character in the universe, is an elite warrior whose resilience and strength enabled her to change the world and Ubisoft and Limbitless Solutions hope the detailed and expressive design will inspire bionic kids and adults to discover their inner strength – just like the Spartan heroine.

Since its founding, Limbitless Solutions’ artistic designs for the bionic arms have been a key focus. In 2019 the first of its kind clinical trials featured unique interchangeable expressive arm designs. When the opportunity arose for a collaboration between Limbitless Solutions and Ubisoft on a new design to empower the users of the bionic arms, the team was excited to bring the design to life.

Developed by Ubisoft Quebec in association with eight other Ubisoft studios, Assassins Creed Odyssey takes players on a heroic voyage through Ancient Greece amidst the Peloponnesian War. 

The unique arm design customization portal allows Limbitless Solutions’ participants to express personal style by selecting different designs and color treatments for unique designs. Each participant received two customized designs when receiving their bionic arm. Different zones on the arm can be uniquely selected for more detailed personalization.

For more information about the Assassin’s Creed collaboration and Limbitless Solutions, please visit https://limbitless-solutions.org.