×
Intel

Can Intel's 'Management Engine' Be Repurposed? 139

Long-time Slashdot reader iamacat writes: Not a day goes by without a story about another Intel Management Engine vulnerability. What I get is that a lot of consumer PCs can access network and run x86 code on top of UNIX-like OS such as Minix even when powered off.

This sounds pretty useful for tasks such as running an occasional use Plex server. Like I can have a box that draws very little power when idle. But when an incoming connection is detected, it can power itself and the media drive on and serve the requested content.

The original submission ends with an interesting question. "if Intel ME is so insecure, how do I exploit it for practically useful purposes?"
Businesses

Apple: iPhones Are Too 'Complex' To Allow Unauthorized Repair (vice.com) 305

Jason Koebler writes: Apple's top environmental officer made the company's most extensive statements about the repairability of Apple hardware on Tuesday: "Our first thought is, 'You don't need to repair this.' When you do, we want the repair to be fairly priced and accessible to you," Lisa Jackson, Apple's vice president of policy and social initiatives said at TechCrunch Disrupt in San Francisco. "To think about these very complex products and say the answer to all our problems is that you should have anybody to repair and have access to the parts is not looking at the whole problem."

Apple has lobbied against "Fair Repair" bills in 11 states that would require the company to make its repair guides available and to sell replacement parts to the general public. Instead, it has focused on an "authorized service provider" model that allows the company to control the price and availability of repair.

Communications

Ask Slashdot: What Can You Do With Old Coaxial Cable? 384

Long-time Slashdot reader Theaetetus writes: I recently bought a house and the previous owner left some coax (mostly RG59) running between rooms for cable distribution. I'm a cord cutter and don't need cable, and I've already run CAT6e everywhere. But before I pull the RG59 out and try to seal the various holes he left, I figured I'd pick Slashdot's brain: can anyone think of a good non-cable use for spare coax lines?
Leave your best answers in the comments. What can you do with old coaxial cable?
Printer

100x Faster, 10x Cheaper: 3D Metal Printing Is About To Go Mainstream (newatlas.com) 119

Big Hairy Ian shares an article from New Atlas: Desktop Metal -- remember the name. This Massachussetts company is preparing to turn manufacturing on its head, with a 3D metal printing system that's so much faster, safer and cheaper than existing systems that it's going to compete with traditional mass manufacturing processes... Plenty of design studios and even home users run desktop printers, but the only affordable printing materials are cheap ABS plastics. And at the other end of the market, while organizations like NASA and Boeing are getting valuable use out of laser-melted metal printing, it's a very slow and expensive process that doesn't seem to scale well.

But a very exciting company out of Massachusetts, headed by some of the guys who came up with the idea of additive manufacture in the first place, believes it's got the technology and the machinery to boost 3D printing into the big time, for real. Desktop Metal is an engineering-driven startup whose founders include several MIT professors, and Emanuel Sachs, who has patents in 3D printing dating back to the dawn of the field in 1989. The company has raised a ton of money in the last few months, including some US$115 million in a recent Series D round that brings total equity investments up over US$210 million. That money has come from big players, too, including Google Ventures... And if Desktop Metal delivers on its promises -- that it can make reliable metal printing up to 100 times faster, with 10 times cheaper initial costs and 20 times cheaper materials costs than existing laser technologies, using a much wider range of alloys -- these machines might be the tipping point for large scale 3D manufacturing.

Operating Systems

32TB of Windows 10 Internal Builds, Core Source Code Leak Online (theregister.co.uk) 201

According to an exclusive report via The Register, "a massive trove of Microsoft's internal Windows operating system builds and chunks of its core source code have leaked online." From the report: The data -- some 32TB of installation images and software blueprints that compress down to 8TB -- were uploaded to betaarchive.com, the latest load of files provided just earlier this week. It is believed the data has been exfiltrated from Microsoft's in-house systems since around March. The leaked code is Microsoft's Shared Source Kit: according to people who have seen its contents, it includes the source to the base Windows 10 hardware drivers plus Redmond's PnP code, its USB and Wi-Fi stacks, its storage drivers, and ARM-specific OneCore kernel code. Anyone who has this information can scour it for security vulnerabilities, which could be exploited to hack Windows systems worldwide. The code runs at the heart of the operating system, at some of its most trusted levels. In addition to this, hundreds of top-secret builds of Windows 10 and Windows Server 2016, none of which have been released to the public, have been leaked along with copies of officially released versions.
Advertising

Home Improvement Chains Accused of False Advertising Over Lumber Dimensions (consumerist.com) 548

per unit analyzer writes: According to Consumerist, an attorney has filed a class-action lawsuit charging Home Depot (PDF) and Menards (PDF) with deceptive advertising practices by selling "lumber products that were falsely advertised and labeled as having product dimensions that were not the actual dimensions of the products sold." Now granted, this may be news to the novice DIYer, but overall most folks who are purchasing lumber at home improvement stores know that the so-called trade sizes don't match the actual dimensions of the lumber. Do retailers need to educate naive consumers about every aspect of the items they sell? (Especially industry quirks such as this...) Furthermore, as the article notes, it's hard to see how the plaintiffs have been damaged when these building materials are compatible with the construction of the purchaser's existing buildings. i.e., An "actual" 2x4 would not fit in a wall previously built with standard 2x4s -- selling the something as advertised would actually cause the purchaser more trouble in many cases.
Hardware

Ask Slashdot: What Would Happen If You Were To Put a Computer Inside a Fridge? 181

dryriver writes: This is not asking what would happen if you were to place your iMac inside your kitchen fridge. Rather, what if a computer casing for a high-powered graphics workstation with multiple CPUs and GPUs, lets say, worked just like a small fridge or freezer, cooling your hardware down without using any CPU fans or liquid cooling and similar. How much would such a fridge-casing cost to make and buy, how much electricity would it consume, how much bigger would it be than a normal PC casing, and would it be a practical solution to the problem of keeping high-powered computer hardware cool for extended periods of time? Bonus question: Is such a thing as a fridge-casing or "Fridgeputer" sold anywhere on the world market right now? Linus Tech Tips tackled this question in a video a couple of years ago, titled "PC Build in a Fridge - Does it Work?"
Microsoft

Microsoft Accidentally Released Internal Windows 10 Development Builds (theverge.com) 76

Microsoft is apologizing for mistakenly releasing some confidential and internal Windows 10 builds to the public. "Builds from some of our internal branches were accidentally released for PC and Mobile," reveals Dona Sarkar, Microsoft's head of its Windows Insiders program. "This happened because an inadvertent deployment to the engineering system that controls which builds / which rings to push out to insiders." The Verge reports: Microsoft says it quickly reverted the issue and put blocks in place to ensure these development builds didn't reach more people, but a "small portion" of Windows 10 users still received them. Worryingly, the accidental mobile build even reached retail devices outside of Microsoft's Windows Insiders testing. If Windows 10 testers installed the mobile build it forced phones into a reboot loop and bricked the device. Testers will have to recover and wipe the device using the Windows Device Recovery Tool. Windows 10 testers that installed the PC build, an internal Edge branch, will have to wait for Microsoft to publish a newer build or roll back using the recovery option in Windows 10 settings.
Microsoft

Microsoft Announces Windows 10 Fall Creators Update, the Next Major Update To Desktop OS (betanews.com) 121

At its developer conference on Thursday, Microsoft announced that the next major update to its desktop operating system will be called Windows 10 Fall Creators Update. It will be made available in September later this year. The update will come with several new features: Timeline, Pick Up Where You Left Off, Clipboard, OneDrive Files On-Demand, and Story Remix app among others. Timeline is a new feature that improves the Task View area to provide a list of apps and workspaces that you were using previously or on other devices. Think of it like a time machine for resuming old sessions. Timeline also combines with a new Pick Up Where You Left Off feature to let you resume sessions and apps on multiple devices. A report adds: "With Files On-Demand, you can access all your files in the cloud without having to download them and use storage space on your device. You don't have to change the way you work, because all your files -- even online files -- can be seen in File Explorer and work just like every other file on your device," says Jeff Teper, corporate vice president, Office, OneDrive and SharePoint teams. [...] Windows 10 Fall Creators Update will continue the use of Project Neon, which now has an official name of "Microsoft Fluent Design System." It is important to note that this design focus is not a Windows 10 FCU feature, but something Microsoft intends to implement in apps across platforms and device types. End users should start to experience it more with FCU, however. [...] Windows 10 Fall Creators Update will come with a new app called "Windows Story Remix." This app is designed to help users transform their existing photos and videos. This tool can be used to create stories from content in a fun way.
Desktops (Apple)

Modern 'Hackintoshes' Show That Apple Should Probably Just Build a Mac Tower (arstechnica.com) 219

An anonymous reader shares an excerpt from a report written by Andrew Cunningham via Ars Technica: Apple is working on new desktop Macs, including a ground-up redesign of the tiny-but-controversial 2013 Mac Pro. We're also due for some new iMacs, which Apple says will include some features that will make less-demanding pro users happy. But we don't know when they're coming, and the Mac Pro in particular is going to take at least a year to get here. Apple's reassurances are nice, but it's a small comfort to anyone who wants high-end processing power in a Mac right now. Apple hasn't put out a new desktop since it refreshed the iMacs in October of 2015, and the older, slower components in these computers keeps Apple out of new high-end fields like VR. This is a problem for people who prefer or need macOS, since Apple's operating system is only really designed to work on Apple's hardware. But for the truly adventurous and desperate, there's another place to turn: fake Macs built with standard PC components, popularly known as "Hackintoshes." They've been around for a long time, but the state of Apple's desktop lineup is making them feel newly relevant these days. So we spoke with people who currently rely on Hackintoshes to see how the computers are being used -- and what they'd like to see from Apple.
Software

Canonical Helps Launch A Snap Store For The Orange Pi Community (ubuntu.com) 55

"Developers can distribute their applications packaged as snaps to Orange Pi owners," explains a new blog post from Canonical, bragging that "hackers and tinkerers can install complex IoT and server projects in seconds." An anonymous reader quotes Ubuntu's Insights blog: Orange Pi maker Shenzhen Xunlong Software Co. Ltd is launching an app store in partnership with Canonical to foster an active community of developers and users. Through this app store, developers gain a simple mechanism to share their applications, projects and scripts between themselves and with the wider Orange Pi community...

With snaps developers can distribute their application in a secure, confined package bundled with all its dependencies, so users can install applications that could take half an hour to install in just a few seconds. The Orange Pi App Store uses the whitelabel app store offering from Canonical, which lets them distribute applications to the Orange Pi community under its own brand. The store is a place for developers to share their Orange Pi specific applications. It also benefits from the wealth of applications available in the Ubuntu snap store, also available through the store.

Are there any Slashdot readers who are actually using snaps? Or -- for that matter -- are there any Slashdot readers developing with the Orange Pi?
Robotics

New Kit Turns A Raspberry Pi Into A Robot Arm (raspberrypi.org) 36

An anonymous reader writes: A new kit turns your Raspberry Pi into a robotic arm. It's controlled by an on-board joystick, or even a web browser, and "because it's connected to the Pi you can program it through any of the various programming languages that already run on the Pi," according to its creators. "There's also free software available which lets you program it through a web interface using drag and drop programming environments like Scratch and Blockly or with Python and Javascript for the more experienced."

They explain in a video on Kickstarter that "Our mission is to get children excited about technology through building and programming their own robots," and they've already raised three times their original $12,411 fundraising goal. The Raspberry Pi blog describes it as "a great kit for anyone wanting to step into the world of digital making."

Long-time Slashdot reader bjpirt adds that "It's completely open source and hackable."
Open Source

Raspberry Pi Gets Competitors (hackaday.com) 115

Hackaday reports that Asus has "quietly released their Tinker board that follows the Pi form factor very closely, and packs a 1.8 GHz quad-core ARM Cortes A17 alongside an impressive spec At £55 (about $68) where this is being written it's more expensive than the Pi, but Asus go to great lengths to demonstrate that it is significantly faster."

And though the Raspberry Pi foundation upgraded their Compute Module, Pine64 has just unveiled their new SOPINE A64 64-bit computing module, a smaller version of the $15 Pine64 computer. An anonymous reader quotes ComputerWorld: At $29, the SOPINE A64 roughly matches the price of the Raspberry Pi Compute Module 3, which ranges from $25 to $30. The new SOPINE will ship in February, according to the website. The SOPINE A64 can't operate as a standalone computer like the Pine64. It needs to be plugged in as a memory slot inside a computer. But if you want a full-blown computer, Pine64 also sells the $15 SOPINE Baseboard Model-A, which "complements the SOPINE A64 Compute Module and turns it into a full single board computer," according to the company...

The original Pine64 was crowdsourced and also became popular for its high-end components like a 64-bit chip and DDR3 memory... It has 2GB RAM, which is twice that of Raspberry Pi's compute module. SOPINE also has faster DDR3 memory, superior to DDR2 memory in Raspberry Pi Compute Module 3 board.

Microsoft

Microsoft To Enhance User Privacy Controls In Upcoming Windows 10 Update (hothardware.com) 183

MojoKid writes: When Microsoft first launched Windows 10, it was generally well-received but also came saddled with a number of privacy concerns. It has taken quite a while for Microsoft to respond to these concerns in a meaningful way, but the company is finally proving that it's taking things seriously by detailing some enhanced privacy features coming to a future Windows 10 build. Microsoft is launching what it calls a (web-based) privacy dashboard, which lets you configure anything and everything about information that might be sent to back to the mothership. You can turn all tracking off, or pick and choose, if certain criteria don't concern you too much, like location or health activity, for example. Also, for fresh installs, you'll be given more specific privacy options so that you can feel confident from the get-go about the information you're sending Redmond's way. If you do decide to send any information Microsoft's way, the company promises that it won't use your information for the sake of targeted advertising.
Microsoft

Windows 10 Will Soon Let You Opt-Out of Automatic Driver Updates (pcworld.com) 156

An anonymous reader quotes a report from PCWorld: Microsoft is giving users some more control over Windows 10 updates, with a new beta build of its operating system released Monday. The build allows folks with the Windows 10 Professional, Education, and Enterprise versions to defer new updates for up to 35 days. In addition, the company will allow those users to decide whether or not they want to include driver updates when they want to update Windows. It's a move that helps respond to one of the key criticisms of Windows 10: that Microsoft's regime of forced, cumulative updates has caused problems for users with some configurations. This way, users can steer clear of updates they don't want to install yet and dodge problematic driver updates. The newly-minted update changes are just one part of the improvements added to Windows 10 with the build released Monday. Microsoft is also working on making the initial Windows 10 setup more accessible using Cortana. The company's virtual assistant can ask users questions at setup -- when they speak languages that it can understand -- and use those answers to configure devices. A small number of beta users will also begin to see a battery life experiment pop up on their devices. Microsoft is also giving users an easier way to connect to a virtual private network. Once Windows 10 has a user's VPN settings loaded, it's possible to activate the connection with the tap of a button without opening up VPN settings.
Desktops (Apple)

Raspberry Pi's Linux-Based PIXEL Desktop Now Available For PC and Mac (betanews.com) 50

From a report on BetaNews: If you own a Raspberry Pi, you're probably familiar with PIXEL. The desktop environment is included in the Raspbian OS. The Raspberry Pi Foundation describes PIXEL as the "GNU/Linux we would want to use" and understandably so. It offers a smart, clean interface, a decent selection of software, the Chromium web browser with plug-ins, and more -- and from today it's available for PC and Mac. The version of Debian+PIXEL for x86 platforms is described as "experimental" but having taken it for a spin, it seems pretty stable to me. To run PIXEL on your PC or Mac, download the image, burn it onto a DVD or flash it onto a USB memory stick, and boot from it. The desktop environment will load ready for use.
Android

Google Is Rolling Out Android 7.1.1 (engadget.com) 75

Google is rolling out Android 7.1.1 for Pixel and Nexus smartphones, including the Nexus 6, Nexus 5X, Nexus 6P, Nexus 9, Pixel, Pixel XL, Nexus Player, Pixel C and General Mobile 4G (Android One). You can download it over-the-air when it becomes available "over the next several weeks" or flash it yourself. Engadget details some of the new features found in Android 7.1.1: As for what you can find from a feature perspective, Google has added support for its "image keyboard" that lets you easily find and send pictures and GIFs without leaving your messaging app of choice. Google says it'll work inside of Hangouts, Allo, and the default Messaging app. Ironically enough, the feature has been available in the Gboard iOS keyboard that Google launched in the spring, but it's good to see it coming to more Android phones now. Android 7.1.1 also includes Google's latest set of more diverse emoji, specifically focused on showing a "wider range of professions" for women. And it also contains the excellent app shortcut feature that originally launched on the Pixel -- if you press and hold on an app's icon, a sub-menu of shortcuts will show up. You'll be able to quickly send a message to a specific contact or navigate to a saved location using these shortcuts, for example. They're very much like the "force touch" shortcuts found on the iPhone, but that doesn't make them any less useful.
Businesses

Why MakerBot Didn't Kickstart A 3D Printing Revolution (backchannel.com) 274

Bre PettisâS once said MakerBot gave you a superpower -- "You can make anything you need." But four years later, mirandakatz writes that though MakerBot promised to revolutionize society, "That never happened." At Backchannel, Andrew Zaleski has the definitive, investigative account of why the 3D printing revolution hasn't yet come to pass, culled from interviews with industry observers, current MakerBot leadership, and a dozen former MakerBot employees. As he tells it, "In the span of a few years, MakerBot had to pull off two very different coups. It had to introduce millions of people to the wonders of 3D printing, and then convince them to shell out more than $1,000 for a machine. It also had to develop the technology fast enough to keep its customers happy. Those two tasks were too much for the fledgling company."
Security

Holding Shift + F10 During Windows 10 Updates Opens Root CLI, Bypasses BitLocker (bleepingcomputer.com) 138

An anonymous reader quotes a report from BleepingComputer: Windows security expert and infrastructure trainer Sami Laiho says that by holding SHIFT + F10 while a Windows 10 computer is installing a new OS build, an attacker can open a command-line interface with SYSTEM privileges. This CLI debugging interface also grants the attacker full access to the computer's hard drive data, despite the presence of BitLocker. The CLI debugging interface is present when updating to new Windows 10 and Windows 10 Insiders builds. The most obvious exploitation scenario is when a user leaves his computer unattended during the update procedure. A malicious insider can open the CLI debugger and perform malicious operations under a root user, despite BitLocker's presence. But there are other scenarios where Laiho's SHIFT + F10 trick can come in handy. For example when police have seized computers from users who deployed BitLocker or when someone steals your laptop. Windows 10 defaults help police/thieves in this case because these defaults forcibly update computers, even if the user hasn't logged on for weeks or months. This CLI debugging interface grants the attacker full access to the computer's hard drive, despite the presence of BitLocker. The reason is that during the Windows 10 update procedure, the OS disables BitLocker while the Windows PE (Preinstallation Environment) installs a new image of the main Windows 10 operating system. "This [update procedure] has a feature for troubleshooting that allows you to press SHIFT + F10 to get a Command Prompt," Laiho writes on his blog. "The real issue here is the Elevation of Privilege that takes a non-admin to SYSTEM (the root of Windows) even on a BitLocker (Microsoft's hard disk encryption) protected machine." Laiho informed Microsoft of the issue and the company is apparently working on a fix.
Bug

Malicious Video Link Can Cause Any iOS Device To Freeze (9to5mac.com) 53

A new bug in iOS has surfaced that will cause any iOS device to freeze when trying to view a certain .mp4 video in Safari. YouTube channel EverythingApplePro explains the bug in a video titled "This Video Will CRASH ANY iPhone!" 9to5Mac reports: As you'll see in the video below from EverythingApplePro, viewing a certain video in Safari will cause iOS to essentially overload and gradually become unusable. We won't link the infectious video here for obvious reasons, but you can take our word for it when we say that it really does render your device unusable. It's not apparently clear as to why this happens. The likely reason is that it's simply a corrupted video that's some sort of memory leak and when played, iOS isn't sure how to properly handle it, but there's like more to it than that. Because of the nature of the flaw, it isn't specific to a certain iOS build. As you can see in the video below, playing the video on an iPhone running as far back as iOS 5 will cause the device to freeze and become unusable. Interestingly, with iOS 10.2 beta 3, if you let an iPhone affected by the bug sit there for long enough, it will power off and indefinitely display the spinning wheel that you normally see during the shutdown process. If someone sends you the malicious link and you fall for it, this is luckily a pretty easy problem to fix. All you have to do is hard reboot your device. For any iPhone but the iPhone 7, this can be done by long-pressing the power and Home buttons at the same time. The iPhone 7, of course, uses a new non-mechanical Home button. In order to reboot an iPhone 7, you must long-press the power button and volume down button at the same time.

Slashdot Top Deals