{"id":3295,"date":"2014-09-28T16:25:24","date_gmt":"2014-09-28T06:25:24","guid":{"rendered":"http:\/\/www.digital-digest.com\/blog\/DVDGuy\/?p=3295"},"modified":"2014-09-28T16:25:24","modified_gmt":"2014-09-28T06:25:24","slug":"weekly-news-roundup-28-september-2014","status":"publish","type":"post","link":"http:\/\/www.digital-digest.com\/blog\/DVDGuy\/2014\/09\/28\/weekly-news-roundup-28-september-2014\/","title":{"rendered":"Weekly News Roundup (28 September 2014)"},"content":{"rendered":"<p>A lot of Linux &#8220;bashing&#8221; this week, as a Bash bug (one old enough to be able to vote) is causing mayhem for admins all around the world. There&#8217;s been a lot of misinformation floating around, mostly being distributed by the mass media, so I thought I would spend a bit of time trying to clear a few things up.<\/p>\n<div id=\"attachment_3303\" style=\"width: 260px\" class=\"wp-caption alignright\"><a href=\"http:\/\/www.digital-digest.com\/blog\/DVDGuy\/wp-content\/uploads\/2014\/09\/bash_shellshock.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-3303\" class=\"size-medium wp-image-3303\" src=\"http:\/\/www.digital-digest.com\/blog\/DVDGuy\/wp-content\/uploads\/2014\/09\/bash_shellshock-250x140.jpg\" alt=\"Bash Shellshock Bug\" width=\"250\" height=\"140\" srcset=\"http:\/\/www.digital-digest.com\/blog\/DVDGuy\/wp-content\/uploads\/2014\/09\/bash_shellshock-250x140.jpg 250w, http:\/\/www.digital-digest.com\/blog\/DVDGuy\/wp-content\/uploads\/2014\/09\/bash_shellshock-1024x575.jpg 1024w, http:\/\/www.digital-digest.com\/blog\/DVDGuy\/wp-content\/uploads\/2014\/09\/bash_shellshock-300x168.jpg 300w, http:\/\/www.digital-digest.com\/blog\/DVDGuy\/wp-content\/uploads\/2014\/09\/bash_shellshock.jpg 1362w\" sizes=\"auto, (max-width: 250px) 100vw, 250px\" \/><\/a><p id=\"caption-attachment-3303\" class=\"wp-caption-text\">The Bash &#8220;Shellshock&#8221; bug in action<\/p><\/div>\n<p><strong>So what is Bash?<\/strong> It&#8217;s a shell for Unix\/Linux based systems (including OS X). <strong>What is a shell?<\/strong> A shell is a command processor, basically something that lets you do everything from listing files and directories, to\u00a0running programs and piping outputs from them to other programs,\u00a0to running scripts. When you see hackers in unrealistic Hollywood movies, they&#8217;re usually typing a bunch of commands on a black screen with white\/green text &#8211; then they&#8217;re typing on an (most likely made up) shell (with an extremely large\u00a0font). So just to make it clear, <a href=\"http:\/\/theconcourse.deadspin.com\/local-tv-tries-to-cover-shellshock-bug-fails-miserably-1639616402\" target=\"_blank\">the bug is not called Bash<\/a>.\u00a0Bash is the software\u00a0that has the bug. The bug itself has been called the Bash bug (which I think is where the confusion comes from), although many\u00a0are calling it by the rather catchy name of Shellshock.<\/p>\n<p><strong>So what is the Shellshock bug?<\/strong> It&#8217;s basically a rather silly bug\u00a0that allows instructions to execute commands\u00a0to be added to environment variables. It turns a fairly innocuous function\u00a0that doesn&#8217;t really do much into one that can basically do everything.<\/p>\n<p>So instead of running a command which simply set the variable\u00a0&#8220;MyName = Sean&#8221;, hackers can instead set the value of the variable &#8220;MyName&#8221; to be &#8220;Sean&#8221; plus some command to execute. So instead &#8220;MyName = Sean&#8221;, they can do &#8220;&#8221;MyName = Sean;\u00a0Plus run commands that sends\u00a0all the password and credit card data on this server\u00a0to the hacker&#8217;s server\u00a0and then delete all the files on this server&#8221;, and this stupid bug will actually allow all of the\u00a0latter instructions to be executed.<\/p>\n<p>On the surface, a shell bug might not be all that damaging &#8211; one would have to already have gained access to the system before you can access the shell. The problem is that many\u00a0internet-facing parts of a server that runs Bash,\u00a0including the parts that\u00a0render web pages and scripts, call upon shells like Bash to perform certain actions, including setting\u00a0environment variables. This means that, with only a little bit of knowledge, one can potentially execute\u00a0almost any program\u00a0on a\u00a0vulnerable server, programs that could allow the hacker to delete files, steal information, or just about anything really.<\/p>\n<p><strong>So why is this bug so serious?<\/strong> For starters, 60% of all web servers have the bug &#8211; a much higher rate than the Heartbleed bug because Bash is more\u00a0integral to these servers &#8211; it&#8217;s such a basic part of the system, and such an old part of it, that nobody though it could possibly be buggy &#8230; until now. It also appears that OS X is vulnerable, although most OS X installs are not configured to allow attacks from outside.\u00a0Most worryingly, it&#8217;s\u00a0not just web servers that can be affected &#8211;\u00a0any device running some\u00a0version of Linux and has Internet access *could be* affected, including smartphones, routers, even things like Blu-ray players and in-car entertainment systems. Many of these Internet-of-things devices are also difficult\/impossible to update in order to fix the vulnerability, and as there are so many of these devices and so many versions of them, even the manufacturers (if they still exist) probably\u00a0won&#8217;t know which\u00a0devices\/versions are\/aren&#8217;t vulnerable.\u00a0To make matters worse, the first set of patches that went out to various server versions were incomplete, giving admins a false sense of security if they didn&#8217;t notice that there were subsequent updates.<\/p>\n<p>So basically, it&#8217;s a bug that&#8217;s very commonly found, easy to exploit, can\u00a0potentially do a huge amount of damage and\u00a0hard to fix for some devices &#8211; so yep, very serious.<\/p>\n<p><strong>So why is this bug not\u00a0as serious as some in the media are reporting it to be?<\/strong>\u00a0While there are probably billions of devices that run some variant of Unix\/Linux, not all of them include Bash. Embedded devices such as routers prefer the lightweight\u00a0BusyBox, which uses ash and not Bash, for example. So luckily\u00a0iOS*, Android* and a lot of devices aren&#8217;t vulnerable to the bug, but\u00a0that still leaves maybe a few hundred millions\u00a0devices that are still vulnerable. But even if these\u00a0devices are vulnerable, it takes a combination of different things (web accessible script that uses Bash to\u00a0change environment variables) for something malicious to be\u00a0done, and so while\u00a0a few hundred million devices may have this bug, a much smaller number can actually be exploited successfully.<\/p>\n<p>* Rooted devices that may have had Bash installed, may be vulnerable.<\/p>\n<p>Hope that clears up a few things. Sorry for spending so much time on this, but it&#8217;s not as if I have a lot of other things to\u00a0write about this week, as you&#8217;ll find out\u00a0below.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" title=\"Copyright\" src=\"http:\/\/www.digital-digest.com\/blog\/DVDGuy\/wp-content\/uploads\/2008\/04\/copyright.gif\" alt=\"Copyright\" width=\"160\" height=\"35\" \/><\/p>\n<p>A follow-up to a story from a few weeks ago (edit: it was actually last week &#8230; jeez, I have no sense of time these days), <a href=\"http:\/\/www.theguardian.com\/media\/2014\/sep\/25\/google-hits-back-news-corp-piracy-claims\" target=\"_blank\">Google has hit back<\/a>\u00a0in the war (of open letters) between itself and Rupert Murdoch&#8217;s News Corp. News Corp labeled the search engine a &#8220;platform for piracy&#8221;, and Google has now hit back with its own open letter\u00a0titled <a href=\"http:\/\/googlepolicyeurope.blogspot.co.uk\/\" target=\"_blank\">Dear Rupert<\/a>\u00a0and cites all of the company&#8217;s herculean efforts in fighting the piracy problem (222 million web pages removed from Google&#8217;s indexes, for example). It&#8217;s almost a line-by-line debunking of all the claims made in the now infamous News Corp letter, well worth a read if you want Google&#8217;s take on the whole &#8220;is Google taking over the world a good thing or not&#8221; debate.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" title=\"High Definition\" src=\"http:\/\/www.digital-digest.com\/blog\/DVDGuy\/wp-content\/uploads\/2008\/04\/highdef.gif\" alt=\"High Definition\" width=\"219\" height=\"35\" \/><\/p>\n<p>I probably watch more Netflix than the average person, mainly because I like having certain shows on in the background while I&#8217;m working on the computer at home (yes it&#8217;s distracting, but in a good way!). I&#8217;ve already streamed through The Office twice this way, and I&#8217;m currently doing The Fresh Prince of Bel-Air via Mexican Netflix (as they have all the seasons). So the news that <a href=\"http:\/\/www.digital-digest.com\/news-64009-Average-Netflix-Viewing-up-350-since-2011.html\">the average Netflix subscriber now watches 1.5 hours of content every day<\/a> didn&#8217;t\u00a0really strike me as surprising &#8211; I watch that much between lunch and afternoon tea.<\/p>\n<div id=\"attachment_3304\" style=\"width: 171px\" class=\"wp-caption alignright\"><a href=\"http:\/\/www.digital-digest.com\/blog\/DVDGuy\/wp-content\/uploads\/2014\/09\/three_fugitives_poster.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-3304\" class=\"size-medium wp-image-3304\" src=\"http:\/\/www.digital-digest.com\/blog\/DVDGuy\/wp-content\/uploads\/2014\/09\/three_fugitives_poster-161x250.jpg\" alt=\"Three Fugitives Poster\" width=\"161\" height=\"250\" srcset=\"http:\/\/www.digital-digest.com\/blog\/DVDGuy\/wp-content\/uploads\/2014\/09\/three_fugitives_poster-161x250.jpg 161w, http:\/\/www.digital-digest.com\/blog\/DVDGuy\/wp-content\/uploads\/2014\/09\/three_fugitives_poster-300x465.jpg 300w, http:\/\/www.digital-digest.com\/blog\/DVDGuy\/wp-content\/uploads\/2014\/09\/three_fugitives_poster.jpg 580w\" sizes=\"auto, (max-width: 161px) 100vw, 161px\" \/><\/a><p id=\"caption-attachment-3304\" class=\"wp-caption-text\">You too can influence how Netflix decides what movies to add to their library (Not Intended to Be a Factual Statement)<\/p><\/div>\n<p>But if you actually analyse what people are actually watching, I think you&#8217;ll find it&#8217;s more The Nanny, than\u00a0The Wolf of Wall Street or any other high profile movie releases. This is because most top movies are simply not available on Netflix. New research shows that only 16% of popular and acclaimed\u00a0films are actually on Netflix at the moment, compared to 94% on sell-through platforms like iTunes.<\/p>\n<p>The latter, 94%, <a href=\"http:\/\/torrentfreak.com\/most-top-films-are-not-available-on-netflix-research-finds-140926\/\" target=\"_blank\">has been used by the MPAA<\/a> to suggest that availability is not a huge issue when it comes to causes for piracy, but in reality, it&#8217;s the former 16% that may still be fueling the desire to download. It would be interesting to see what the piracy rate is for movies that do make it to Netflix, compared to movies that have never been on the platform &#8211;\u00a0surely this should provide us with more valuable insight than simply saying &#8220;94%&#8221;.<\/p>\n<p>Speaking of Netflix,\u00a0I may have found a way\u00a0to influence\u00a0how Netflix decides which flicks to add\u00a0to their\u00a0library. For the past few months, whenever I have the time, I&#8217;ve been doing a\u00a0search on\u00a0Netflix for the delightful Martin Short, Nick Nolte comedy <a href=\"http:\/\/www.imdb.com\/title\/tt0098471\/?ref_=fn_al_tt_2\" target=\"_blank\">Three Fugitives<\/a>. I know it isn&#8217;t there, but I&#8217;m\u00a0searching for it anyway in the hope that the data boffins at Netflix spots\u00a0the numerous searches being made for the movie\u00a0and something gets done. And it&#8217;s worked! The movie\u00a0will be available to stream in early October, thanks to my efforts and my efforts only I can only assume (as I must be\u00a0the only one to be searching for this movie on Netflix, or the Internet in general). A similar thing happened with <a href=\"http:\/\/www.imdb.com\/title\/tt0093148\/?ref_=fn_al_tt_1\" target=\"_blank\">Harry and the Hendersons<\/a>, which I had been furious searching for in the preceding months, and finally watched again on Mexican (or was that Canadian) Netflix this month. So get busy and start searching (obviously a trick that works better for titles that has little\u00a0commercial\u00a0value, then say searching for &#8216;Guardians of the Galaxy&#8217;).<\/p>\n<p>Please note that the above advice contains zero scientific or logical merit, and is solely based on the flimsiest of empirical evidence, if you can even call it that.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" title=\"Gaming\" src=\"http:\/\/www.digital-digest.com\/blog\/DVDGuy\/wp-content\/uploads\/2008\/04\/gaming.gif\" alt=\"Gaming\" width=\"130\" height=\"35\" border=\"0\" \/><\/p>\n<p>And finally in gaming (and semi-copyright) news, <a href=\"http:\/\/hothardware.com\/News\/Valve-Overhauls-Steam-Website-Adds-Personalized-Shopping-and-DRM-Warnings\/\" target=\"_blank\">Steam&#8217;s\u00a0re-design of its web store now more prominently shows the DRM employed<\/a> by the game (if any). A move that will surely be welcomed by gamers,\u00a0tired of\u00a0spending a sizable amount of money on a game, only to find it infected with DRM nonsense. A new notification is now shown on the right hand side of the game&#8217;s page, with a\u00a0clear &#8220;warning: this is something that you probably won&#8217;t like&#8221;\u00a0yellow background to make the DRM warning stand-out. Perhaps this will further discourage publishers from putting in bad DRM, because if we all start treating DRM\u00a0just as something detrimental, such as a bad review or incompatibility problems, then maybe publishers will have less incentive to include them in the future.<\/p>\n<p>&#8212;&#8212;<\/p>\n<p>Alright, that&#8217;s it for this week. See you in seven!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A lot of Linux &#8220;bashing&#8221; this week, as a Bash bug (one old enough to be able to vote) is causing mayhem for admins all around the world. There&#8217;s been a lot of misinformation floating around, mostly being distributed by the mass media, so I thought I would spend a bit of time trying to [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"enabled":false},"version":2}},"categories":[15,10,3,17,9],"tags":[],"class_list":["post-3295","post","type-post","status-publish","format-standard","hentry","category-computing","category-copyright","category-movies","category-news-roundup","category-video_technology"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pzVMv-R9","_links":{"self":[{"href":"http:\/\/www.digital-digest.com\/blog\/DVDGuy\/wp-json\/wp\/v2\/posts\/3295","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.digital-digest.com\/blog\/DVDGuy\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.digital-digest.com\/blog\/DVDGuy\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.digital-digest.com\/blog\/DVDGuy\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/www.digital-digest.com\/blog\/DVDGuy\/wp-json\/wp\/v2\/comments?post=3295"}],"version-history":[{"count":8,"href":"http:\/\/www.digital-digest.com\/blog\/DVDGuy\/wp-json\/wp\/v2\/posts\/3295\/revisions"}],"predecessor-version":[{"id":3305,"href":"http:\/\/www.digital-digest.com\/blog\/DVDGuy\/wp-json\/wp\/v2\/posts\/3295\/revisions\/3305"}],"wp:attachment":[{"href":"http:\/\/www.digital-digest.com\/blog\/DVDGuy\/wp-json\/wp\/v2\/media?parent=3295"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.digital-digest.com\/blog\/DVDGuy\/wp-json\/wp\/v2\/categories?post=3295"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.digital-digest.com\/blog\/DVDGuy\/wp-json\/wp\/v2\/tags?post=3295"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}