Friday, 23 December 2016

The new Barnes & Noble Nooks come with free malware

Barnes & Noble began outsourcing its Nook e-readers a few years ago after a partnership with Samsung and their latest $50 Nook 7 android tablet, announced last month, shows us how that has worked out for them. Their latest e-reader includes ADUPS, a firmware that sends user data back to the manufacturer or an interested hacker. This is the same malware that researchers found on cheap Blu tablets and phones last month.
The manufacturer claims to have patched the malware in current products but it seems the new B&N Nooks are still running the old software. ADUPS allows for full data access on the device and command and control privileges including remote software installation and automatic updates without use permission.
How bad is it?
These devices actively transmitted user and device information including the full-body of text messages, contact lists, call history with full telephone numbers, unique device identifiers including the International Mobile Subscriber Identity (IMSI) and the International Mobile Equipment Identity (IMEI). The firmware could target specific users and text messages matching remotely defined keywords. The firmware also collected and transmitted information about the use of applications installed on the monitored device, bypassed the Android permission model, executed remote commands with escalated (system) privileges, and was able to remotely reprogram the devices… The firmware that shipped with the mobile devices and subsequent updates allowed for the remote installation of applications without the users’ consent and, in some versions of the software, the transmission of fine-grained device location information.
The Digital Reader is recommending that users return their Nooks and notes that B&N has a holiday return policy that lets you send items back until January 31.

Uber stops San Francisco self-driving pilot as DMV revoked registrations

Uber has confirmed that it will stop its self-driving pilot in San Francisco, following a meeting today with the California DMV and Attorney General’s office. The DMV revoked the registration on 16 self-driving test vehicles Uber was using in its pilot.
The DMV tells TechCrunch that it invited Uber to complete its permitting process at the same time it revoked it the vehicle registrations. Uber told TechCrunch that it will instead be looking to deploy the vehicles elsewhere for the time being. Here’s Uber’s statement on the matter in full:
We have stopped our self-driving pilot in California as the DMV has revoked the registrations for our self-driving cars. We’re now looking at where we can redeploy these cars but remain 100 percent committed to California and will be redoubling our efforts to develop workable statewide rules.
Uber had begun updating self-driving Volvo X90 SUVs in San Francisco on December 14, providing service to randomly selected uberX customers in the area. It chose not to pursue the permit the state issues to companies for testing autonomous vehicles on public roads, arguing that its cars didn’t require such permits as they could not operate completely autonomously at this stage.
While initially Uber continued its pilot even in the face of regulatory objections, both the DMV and California’s Attorney General’s office said that Uber would face legal repercussions, including injunctive action, if they maintained the active service.
Uber currently operates another trial of its self-driving technology, in Pittsburgh, where its Advanced Technology Group is based. Those trials, which began earlier this year, use Ford Focus vehicles retrofitted with autonomous sensors and onboard computing, and will continue.

Blog Archive