Filestream launches OfficioDM

Free for single user license

Filestream has launched a new suite of document management products – OfficioDM and OfficioDM Pro – designed to make storing, indexing and retrieving information quick and easy, regardless of the size of your organisation.

Filestream is offering a single user licence for OfficioDM for free, with no time limits. The software is free for life along with updates.

Delivering 256-bit encryption and password protection, OfficioDM is aimed at individuals or SMEs and can store a maximum of 10,000 documents in up to five cabinets with 4 index fields each.

Charles Hooker, Filestream’s managing director, says, “Most businesses still don’t use document management effectively thereby wasting a huge amount of space, time and money managing their affairs. What is exciting about OfficioDM is that we have now made the benefits of document management available to everyone. With the initial cost removed, individuals and businesses can now experience for themselves the business process efficiencies and cost savings delivered by EDMS solutions. Our EDMS solutions start with OfficioDM and scale from there to cater for all document management needs irrespective of business size or industry.”

For those who want more document capacity, multi user, mobile or cloud capability, OfficioDM can be upgraded to OfficioDM Pro for just £200 per year for three users and scalable to a maximum capacity of 15 staff with the purchase of additional packs of three licences.

www.officiodm.com

Microsoft’s latest acquisition focuses on social education

Flipgrid will help it go beyond arts and sciences.

By Jon Fingas, @jonfingas

Education these days isn’t just about reading, writing and arithmetic — it’s also about learning how to learn. Microsoft wants to be the go-to option for teaching these abilities and is buying Flipgrid, the creator of an educational platform that fosters social-emotional and communication skills. The tech giant hasn’t said how it will integrate Flipgrid with the rest of its line-up, but it’s starting by making the platform free to schools (they can get prorated refunds if they’ve subscribed).

Microsoft has promised that Flipgrid’s offerings will still work with other “partner ecosystems,” so Google-centric classrooms won’t suddenly lose a portion of their curriculum.

The move makes sense given Microsoft’s changing role in schools. The company has lost ground to Google in education on several fronts, including PCs (Chromebooks are increasingly common) and cloud services. While Microsoft is directly challenging Google with new PCs and tools, Flipgrid gives it a foothold in an area where Google doesn’t really compete, regardless of the devices and software the students use.

Live stream every World Cup finals game from anywhere

Use a VPN to watch the World Cup 2018 from anywhere for FREE

By Adam Marshall

Wow! Well it was worth waiting for wasn’t it? The Russia 2018 FIFA World Cup has kicked off in style. There’s been goals galore (from the host-nation Russia, no less), VAR controversy, last gasp winners and an epic Portugal vs Spain first round thriller that will live long in the memory. If you don’t want to miss any more of the action, you can find out how to live stream every last joyous, heart breaking minute of the World Cup absolutely free and regardless of where you live.

Russia is the somewhat controversial host nation of the 2018 FIFA World Cup finals. It will take place over 64 matches, in 16 venues, across 13 cities – from Kaliningrad to Yekaterinburg.

The first game – the hosts Russia vs Saudi Arabia –  kicked off on Thursday June 14 with the tournament lasting a day over one month. The World Cup final takes place in Moscow on Sunday July 15.

This edition of the World Cup tournament sees 32 teams square off for a chance to lift the famous 18 carat gold trophy. Among them are the hosts Russia of course, current champions Germany, previous winners England, France, Spain, Argentina, Brazil and Uruguay, and other favourites including Belgium, Portugal and Croatia.

We’ve got a list of the upcoming Russia 2018 games below (with links to our dedicated live stream guides) and you can scroll to the bottom of this page for more tips about how to enhance your FIFA World Cup joy.

But you probably don’t need too much preamble. You just want to know where you’ll be able to watch the games. We understand. So without any further ado, we’ll tell you exactly where you can watch the FIFA World Cup matches where you live. And if you’re looking for a free live stream, we’ve got that key information for you, too.

THE FIFA WORLD CUP 2018 – WHERE AND WHEN – Click Here

Cortana allowed attacker to bypass Windows 10’s lock screen

By Darren Allan

Windows 10 users will likely be concerned to hear that Cortana had major vulnerabilities, which allowed a malicious party to potentially bypass the lock screen – or easily view sensitive information from it – although the good news is that Microsoft has just patched these issues.

McAfee uncovered and documented the security flaws in a lengthy blog post, with one simple issue being the fact that you could trigger the voice assistant from the lock screen (assuming Cortana is enabled in this respect, on default settings), and bring up a contextual Windows 10 menu simply by typing while Cortana is listening to a query.

And the details of files – and possibly file contents – revealed in that contextual menu could potentially leak sensitive information from the locked laptop.

Beyond that, the security firm found that it was possible to exploit Cortana in order to execute code on the PC from the lock screen, allowing an attacker to trigger a backdoor dropped from, say, a previously successful phishing email attack.

Moreover, McAfee further demonstrated an exploit of the digital assistant that allowed a payload to be locally executed from a USB stick, with the result that the attacker could change the login credentials for the notebook, and get full access to the machine. Highly worrying indeed.

Privilege patch

As mentioned at the outset, Microsoft fixed these issues with its freshly released patch for Windows 10 (out yesterday).

As Windows Latest reports, the company noted: “An Elevation of Privilege vulnerability exists when Cortana retrieves data from user input services without consideration for status. The security update addresses the vulnerability by ensuring Cortana considers status when [retrieving] information from input services.”

So, if you do have Cortana running on the lock screen of your PC, this is a pretty critical security patch to download. And if you haven’t patched yet – as might be the case with business machines, where deployment of patches can be a thornier issue – then obviously it might be a good move to banish Cortana from the lock screen for the time being.

McAfee further observes that it’s just scratching the surface of potential attack vectors that can be leveraged against digital assistants and via vocal commands, and that the firm intends to look much more deeply into finding vulnerabilities along these lines.

It’s obviously an important area to research, as we are inexorably heading towards a world in which AI virtual assistants are increasingly used to help you run many aspects of your devices and operating systems.

Millions of payment cards and customer data records affected

Dixons Carphone hit with major data breach

By Mike Moore

Dixons Carphone has revealed it has been hit by a huge data breach.

The high-street retailer has admitted that over a million personal data records of its customers have been accessed by hackers, with 5.9 million payment cards also affected.

The company says it has informed the ICO and the police of the attack.

The breach was uncovered by Dixons Carphone this week, but apparently took place back in July 2017, when hackers tried to access a processing system used by its Currys PC World and Dixons Travel stores.

The successful hack saw “an attempt to compromise” 5.8 million credit and debit cards, but only 105,000 cards that lacked chip-and-pin protection were leaked, the company said.

However the hackers were able to access the personal data records of 1.2 million customers, with details such as names, addresses and email addresses all leaked.

“Extremely disappointed”

Dixons Carphone says it is now contacting all affected customers to offer advise, and was also toughening up its cybersecurity.

“We are extremely disappointed and sorry for any upset this may cause. The protection of our data has to be at the heart of our business, and we’ve fallen short here,”  Dixons Carphone chief executive Alex Baldock said in a statement.

“We are determined to put this right and are taking steps to do so; we promptly launched an investigation, engaged leading cyber security experts, added extra security measures to our systems and will be communicating directly with those affected.”

“Cyber crime is a continual battle for business today and we are determined to tackle this fast-changing challenge.”

Security researcher discovered data in a plain text file

Millions of email addresses leaked from genealogy site MyHeritage

© 

MyHeritage – a genealogy site specializing in family trees and DNA testing  – is investigating a major security breach after a security researcher found email addresses and hashed passwords belonging to 92 million of its users. Information in the file dated back to October 27 2017, so anyone who registered an account before that date could be affected.

After discovering the email data in a plain text file, the researcher alerted the company, which set its own security staff to work. It also enlisted the help of an independent cybersecurity team

The security experts found no evidence of other user data on the server, and because the passwords were hashed, only the email addresses were readable. MyHeritage also noted that there’s no evidence the data on the server was ever used.

“MyHeritage does not store user passwords, but rather a one-way hash of each password, in which the hash key differs for each customer,” the site said in a blog post. “This means that anyone gaining access to the hashed passwords does not have the actual passwords.”

Relative risks

Other data, including that used to build family trees, is stored separately and wasn’t compromised, and there was no risk of credit card details being stolen because the site processes payments using PayPal exclusively.

The email addresses are valuable though, and such a huge list would be a handy starting point for criminals to launch a phishing campaign.

This leak is particularly embarrassing because its discovery comes immediately after implementation of the EU’s new General Data Protection Regulation(GDPR), which stresses that any company that holds personal information must take care to stop it falling into the wrong hands – information that forms the foundation of sites like MyHeritage.

MyHeritage recommendeds that all its users change their passwords just in case, and notes that it’ll be upgrading to two-factor authentication soon, enabling users to lock down their accounts more tightly – particularly against phishing attacks.

Have you been caught with your pants down?

Millions of Facebook users have accidentally made their private posts completely public

© 

Facebook is warning users to check their recent posts and photo uploads after discovering a bug in its composer that set the default privacy option to ‘public’.

Usually it’s safe to assume that Facebook will use your preferred privacy settings, but unless you’re in the habit of checking every time, you may have inadvertently revealed far more than you intended.

The bug affected posts published between May 18 and 27. Facebook is keen to point out that no privacy settings were changed retroactively, so nothing posted before then will have been exposed to the world without you realizing.

Accidental exposure

Facebook has now fixed the bug, and changed any posts made during that period to your usual privacy settings (though that could be a case of shutting the gate after the horse has bolted, depending on how much fun you had in those 10 days).

If there’s a chance you might have been affected, you’ll see a warning next time you log into Facebook, with an apology and list of posts you made during that period. Hopefully nothing you wouldn’t want your boss, parents or partner to see.

In a statement to TechCrunch, the company said it’s well aware that it needs to be more transparent about its privacy settings, and it’ll publish more of these alerts when things go pear-shaped. Hopefully that won’t be too often.

A friendly reminder: Don’t put passwords in Trello

© John Biggs@johnbiggs

A new bit of research from David Shear at security firm Flashpoint found that there are hundreds if not thousands of open Trello boards containing passwords, login credentials, and other potentially sensitive stuff including employee on-boarding documents. He and Brian Krebsreported the boards to Trello  although some folks have already been notified by well-meaning hackers who wrote “Change your password” on some of these public boards.

“One particularly jarring misstep came from someone working for Seceon, a Westford, Mass. cybersecurity firm that touts the ability to detect and stop data breaches in real time,” wrote Krebs. “But until a few weeks ago the Trello page for Seceon featured multiple usernames and passwords, including credentials to log in to the company’s WordPress blog and iPage domain hosting.”

Another Trello board made at Red Hat  in 2017 offered passwords to a pair of online test servers.

Trello worked with the pair to take down the public boards they found and is working with Google  to remove the cached sites.

“We have put many safeguards in place to make sure that public boards are being created intentionally and have clear language around each privacy setting, as well as persistent visibility settings at the top of each board,” said a Trello spokesperson.

Missteps like these are sadly common. Another rich trove of user data, Github, has been used to find private passwords for years. Anecdotally, a project I was working on suffered a breach when the CTO put a Bitcoin private key into some public Github code. Yeah. Exactly.

So, again, keep your Trello boards private, don’t paste passwords willy-nilly, and maintain at least a basic level of operational security by not pasting passwords into any site that could make it public. It’s hard but definitely worth the effort.

Microsoft’s Data Centre on The Bottom Of The Ocean

© Thomas Tamblyn – The Huffington Post UK

 Just off the coast of Orkney in Scotland, Microsoft has dropped a huge data centre at the bottom of the ocean.

If surrounding hundreds of computers with a large body of water sounds like a terrible idea then wait, there is method to Microsoft’s madness.

Just off the coast of Orkney in Scotland, Microsoft has dropped a huge data centre at the bottom of the ocean.

If surrounding hundreds of computers with a large body of water sounds like a terrible idea then wait, there is method to Microsoft’s madness.

Computers often get warm, data centres on the other hand get scorching hot, and to keep them from overheating companies have to either install vast cooling fans or use supercooled liquid to keep them from melting.

Rather than bringing the cooling to the computer, Project Natick literally places the computers into a naturally cold environment – the North Sea.

Not only do you then get free cooling but you can also place the data centres closer to towns and cities giving the public faster access to the web, video games and even AI-based technologies.

Eventually Project Natick envisages placing these data centres all over coastal regions, connecting them to local renewable energy sources which in turn reduces their running costs to virtually nothing.

These aren’t small capsules either, this trial data centre contains some 864 standard datacenter servers with enough storage for around 5 million movies.

This initial trial capsule has been designed to be self-sustaining for up to five years, however Microsoft believes that if it were rolled out globally each one could have a lifespan of almost a decade. Once it has served its purpose the capsule would be retrieved, the data centre would be recycled and upgraded and then it could be placed back into the ocean for another 10 years.

Microsoft certainly aren’t the first major tech company to find innovative ways to cool its computers. The world’s largest data centre is currently being built in Norway where it will be powered by renewable energy and cooled by the freezing cold temperatures found north of the Arctic Circle.

Other companies such as Facebook have also built their data centres in Norway to take advantage of the country’s naturally colder climate.

GDPR ‘risks making it harder to catch hackers’

BBC News – Technology

A service used to identify and contact website owners has been forced to strip out information on its site to complwith

the EU’s GDPR legislation.

Whois is used by journalists and police to make quick checks into the legitimacy of websites. It no longer shows contact names, email addresses or phone numbers.

 

Icann, the owner of Whois had asked for a delay to comply with GDPR, despite having had years to prepare. The request was turned down.

In a letter to the Wall Street Journal entitled, The EU’s gift to Cybercriminals, lawyers Brian Finch and Steven Farmer claim: “Police will be robbed of ready access to vital data drastically impeding their efforts to identify and shut down illicit activity.”

“The regulatory rubric the EU has created will make it harder than ever to catch computer hackers,” they wrote.

Mr Farmer told the BBC that the lack of guidance given by the EU is making companies extremely cautious about the regulation.

He said that because “the consequences of getting it wrong are so serious”, companies are being “extremely conservative in interpreting the law”.

“It’s regrettable we didn’t have guidance on the key principles,” he said.

Whois was used by cyber-security firms as well as law enforcement.

Nik Whitfield, chief executive of cyber-security company Panaseer, said he had used Whois to help companies spot dodgy emails.

“The service is valuable for protection as it helps provide context around whether an external website is legitimate or potentially unsafe,” he told the BBC.

However, supporters of the new privacy regulation note that cyber-criminals were never likely to have provided accurate contact details for their scam websites, and highlight that the law does provide added protection for legitimate registrants.

At the time of writing, some websites were still presenting non-redacted website information.

Copyright © 2018 BBC. The BBC is not responsible for the content of external sites.