Tag Archive for: Fatally

Activision Blizzard accused by California watchdog of fostering ‘frat boy’ culture, fatally toxic atmosphere • The Register


California’s Department of Fair Employment and Housing on Thursday sued Activision Blizzard and its subsidiaries, alleging the company fostered a “frat boy” culture that led to lower pay for female employees, sex and race discrimination, and sexual harassment.

According to the lawsuit, as an example of the effects of this toxic culture, a female worker killed herself on a company trip due to a sexual relationship she had with her male boss.

“All employers should ensure that their employees are being paid equally and take all steps to prevent discrimination, harassment, and retaliation,” said dept director Kevin Kish in a statement [PDF]. “This is especially important for employers in male-dominated industries, such as technology and gaming.”

Activision Blizzard, the gaming behemoth forged in 2008 and based in Santa Monica, California, makes popular computer games such as Diablo, Call of Duty, and World of Warcraft, and runs online gaming service Battle.net.

Accusations of sexism, sexual harassment, and pay inequality have dogged the gaming industry for decades, as demonstrated recently by “gamergate” in 2014 and 2015 and harassment claims at UbiSoft in 2020. But as the “#MeToo” movement has shown, workplace hostility toward women extends far beyond electronic entertainment.

An Activision Blizzard spokesperson told The Register in an emailed statement the gaming biz takes these issues seriously and the Department of Fair Employment and Housing (DFEH) allegations don’t reflect its current workplace.

We note that one Blizzard executive identified in the complaint, “so known to engage in harassment of females that his suite was nicknamed the ‘Crosby Suite’ after alleged rapist Bill Crosby,” appears to have quietly left the company around June 2020. A DFEH spokesperson tentatively confirmed that this is a misspelling of “Cosby,”…

Source…

Fatally weak MD5 function torpedoes crypto protections in HTTPS and IPSEC

Enlarge (credit: US Navy)

If you thought MD5 was banished from HTTPS encryption, you’d be wrong. It turns out the fatally weak cryptographic hash function, along with its only slightly stronger SHA1 cousin, are still widely used in the transport layer security protocol that underpins HTTPS. Now, researchers have devised a series of attacks that exploit the weaknesses to break or degrade key protections provided not only by HTTPS but also other encryption protocols, including Internet Protocol Security and secure shell.

The attacks have been dubbed SLOTH—short for security losses from obsolete and truncated transcript hashes. The name is also a not-so-subtle rebuke of the collective laziness of the community that maintains crucial security regimens forming a cornerstone of Internet security. And if the criticism seems harsh, consider this: MD5-based signatures weren’t introduced in TLS until version 1.2, which was released in 2008. That was the same year researchers exploited cryptographic weaknesses in MD5 that allowed them to spoof valid HTTPS certificates for any domain they wanted. Although SHA1 is considerably more resistant to so-called cryptographic collision attacks, it too is considered to be at least theoretically broken. (MD5 signatures were subsequently banned in TLS certificates but not other key aspects of the protocol.)

“Notably, we have found a number of unsafe uses of MD5 in various Internet protocols, yielding exploitable chosen-prefix and generic collision attacks,” the researchers wrote in a technical paper scheduled to be discussed Wednesday at the Real World Cryptography Conference 2016 in Stanford, California. “We also found several unsafe uses of SHA1 that will become dangerous when more efficient collision-finding algorithms for SHA1 are discovered.”

Read 7 remaining paragraphs | Comments

Technology Lab – Ars Technica