Appeals court rules Americans have no legal recourse if hacked by foreign governments

Put aside the matter of Russian interference in our presidential election to instead consider this scenario: If Vladimir Putin ordered his government-employed hackers to plant spyware on your personal computer – stealing all your data and even recording your Skype calls – you would have no access to any legal remedy in the U.S. court system.

Preposterous, you say?

That’s the law, according to the United States Court of Appeals for the District of Columbia Circuit, which yesterday upheld a lower court decision denying even a day in court to an American citizen who moved here from Ethiopia 30 years ago and was victimized by that country’s government in the exact fashion described above.

To read this article in full or to leave a comment, please click here

Network World Paul McNamara

Data breach fear for 26m GP records – The Times (subscription)


The Times (subscription)

Data breach fear for 26m GP records
The Times (subscription)
The Information Commissioner is looking into a potential breach involving 2,700 GP surgeries. It centres on SystmOne, which is used by family doctors. When GPs switch on “enhanced data sharing” so that records can be seen by a hospital, they also can

and more »

data breach – Google News

Virtual machine escape fetches $105,000 at Pwn2Own hacking contest [updated]

Enlarge (credit: Heather Katsoulis)

Contestants at this year’s Pwn2Own hacking competition in Vancouver just pulled off an unusually impressive feat: they compromised Microsoft’s heavily fortified Edge browser in a way that escapes a VMware Workstation virtual machine it runs in. The hack fetched a prize of $ 105,000, the highest awarded so far over the past three days.

According to a Friday morning tweet from the contest’s organizers, members of Qihoo 360’s security team carried out the hack by exploiting a heap overflow bug in Edge, a type confusion flaw in the Windows kernel and an uninitialized buffer vulnerability in VMware, contest organizers reported Friday morning on Twitter. The result was a “complete virtual machine escape.”

“We used a JavaScript engine bug within Microsoft Edge to achieve the code execution inside the Edge sandbox, and we used a Windows 10 kernel bug to escape from it and fully compromise the guest machine,” Qihoo 360 Executive Director Zheng Zheng wrote in an e-mail. “Then we exploited a hardware simulation bug within VMware to escape from the guest operating system to the host one. All started from and only by a controlled a website.”

Read 7 remaining paragraphs | Comments

Technology Lab – Ars Technica

Bay Area law firm sues Yahoo for data breach – KGO-TV


KGO-TV

Bay Area law firm sues Yahoo for data breach
KGO-TV
A lawsuit has been filed against Sunnyvale-based Yahoo one day after it was revealed Russians were behind a massive data breach. (AP Photo/Marcio Jose Sanchez). KGO. Thursday, March 16, 2017 06:01PM. BURLINGAME, Calif. (KGO) –. A lawsuit has …

data breach – Google News