Recent Posts

Pages: [1] 2 3 ... 10
1


Last month, we covered an unofficial utility that lets Windows users upgrade from one Windows edition, say Home to Pro, without going through a clean installation. The utility is called "Helper-Tool für Windows 10/11 Inplace-Upgrades und Editionswechsel" which translates to "Helper tool for Windows 10/11 inplace upgrades and edition changes". You can read about it in full in our dedicated coverage.

However, those who don't want to fiddle around with an unofficial app and would much rather prefer safely tweaking with the Registry instead are in for a treat. Windows enthusiast and X (formerly Twitter) user Bob Pony has shared the way to do this. The same user recently shared a one-click trick to bypass the Windows 11 system requirements check on LTSC.

Switching the Edition using the Registry Editor involves changing the value of the subkey EditionID to "Core." On a system that is already running Windows 11/10 Pro, the value of EditionID is set to "Professional."

The CurrentVersion Registry key address is given below:

Quote
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion





Again, tweaking the Registry must be done safely and it's best to create a backup before proceeding with the Registry Editor (regedit) in case something goes wrong.

While we are on the topic of Registry tweaks, Microsoft, last week, published its official mitigation enabler for Spectre variant 2 security vulnerability that is rearing its head up again. If you have an Intel 6th Gen (Skylake) and newer CPU, you can find those details here.

source
2

Windows 11   Windows 10   Windows 8.1

Back up the registry manually

1. Select Start, type regedit.exe in the search box, and press Enter. If you are prompted for an administrator password or confirmation, type the password or provide confirmation.

2. In Registry Editor, locate and click the registry key or subkey you want to back up.

3. Select File > Export.

4. In the Export Registry File dialog box, select the location to which you want to save the backup copy, and then type a name for the backup file in the File name field.

5. Select Save.

Restore a manual backup

1. Select Start, type regedit.exe, and then press Enter. If prompted for an administrator password or confirmation, type the password or provide confirmation.

2. In Registry Editor, click File > Import.

3. In the Import Registry File dialog box, select the location to which you saved the backup copy, select the backup file, and then click Open.

source
3
Reportedly one of the biggest ever monthly updates only fixes issues with the latest Windows 11 as the clock ticks on Windows 10.


Windows 11 update (Image: Microsoft/Getty)

This week, Microsoft pushed out a big update for Windows 11 that an expert has claimed breaks a worrying record for the most bugs and flaws fixed in any Windows update since 2017, with 147 different gremlins addressed. Some of the fixes were for bugs that meant hackers could have remotely accessed devices and other vulnerabilities Microsoft listed as ‘critical’, a sure sign the company was worried about users’ security.

147 is a large number of bugs to fix but if you are running Windows 11 then you’re safe, as Microsoft has pushed out the update to your PC. It’s yet another reason to think about upgrading from Windows 10, as the older operating system’s end-of-life date is rapidly approaching.

Windows 10 will stop receiving any software or security updates on 14 October 2025, despite recent data from Statista showing it is the most popular Windows version in use still with a staggering 68 percent of Windows users globally on it. That’s compared to a comparatively meager 27 percent using Windows 11.

Some people cannot upgrade to Windows 11 if their Windows 10 PC is not powerful enough to run the latest operating system. Here are the full requirements for Windows 11:

   • Processor: 1 gigahertz (GHz) or faster with two or more cores on a compatible 64-bit processor or system on a chip (SoC).

   • RAM: 4 gigabytes (GB) or greater.

   • Storage: 64 GB or greater available storage is required to install Windows 11.

   • Graphics card: Compatible with DirectX 12 or later, with a WDDM 2.0 driver.

   • TPM: Trusted Platform Module (TPM) version 2.0.

But others may be holding back from upgrading so as not to change the look, feel, or performance of their Windows 10 computer. That is understandable, but it looks as though Microsoft is forcing those customers into a corner by rapidly updating Windows 11 and planning to leave Windows 10 behind.

It has also been reported that a Windows 10 update pushed out several months ago is still broken and causing people issues.

source
4
ANDROID owners have been urged to delete three dangerous apps that have been masquerading as messengers in the Google Play store.

Cyber researchers at ESET have rung the alarm on a trio of nasty apps that aim to steal Android owners' personal information - and even their banking credentials.


While Google is generally very good at detecting and removing malicious apps - some do slip
through the cracks Credit: Getty


These apps are posing as messaging services and offer basic, but functional services as bait.

At surface level, they work and appear legitimate - but they're not.

Behind the scenes, they are hiding open-source XploitSPY malware.

Hackers have been advertising these apps - and others that are similar - on websites and on the Google Play store.

While Google is generally very good at detecting and removing malicious apps - some do slip through the cracks.

The apps exist to steal contact lists, camera files, location, download data, as well as your WhatsApp and Telegram.

Android owners have been urged to check their devices for these three apps:

   ► Dink Messenger

   ► Sim Info

   ► Defcom

If you have downloaded one of these apps, it is advised to delete them immediately.

They have since been removed from the Google Play store, but may still be lurking on your phone.

They form part of a targeted campaign, which began in November 2021, to distribute malware onto Android phones primarily in India and Pakistan, according to ESET.

source
5


Going through my usual scanning of all the "-next" Git subsystem branches of new code set to be introduced for the next Linux kernel merge window, a very notable addition was just queued up... Linux 6.10 is set to merge the NTSYNC driver for emulating the Microsoft Windows NT synchronization primitives within the kernel for allowing better performance with Valve's Steam Play (Proton) and Wine of Windows games and other apps on Linux.

The past several months have seen much work on the NTSYNC kernel driver for allowing better Wine (Windows) gaming/app performance on Linux. The code has gone through several revisions and has shown very promising results:



Wine currently emulates the Windows API in user-space but the NT synchronization primitives have been a hassle to properly emulate in user-space and incurs significant performance overhead. But now with the NTSYNC driver, the situation is a big improvement. The NTSYNC module provides kernel support for emulating of Windows NT synchronization primitives and is exposed as a misc character device by the kernel.

Quote
"ntsync uses a misc device as the simplest and least intrusive uAPI interface.

Each file description on the device represents an isolated NT instance, intended to correspond to a single NT virtual machine."

The driver currently provides NTSYNC_IOC_CREATE_SEM for matching the Windows NT system call of NtCreateSemaphore() and NTSYNC_IOC_SEM_POST for matching the NtReleaseSemaphore() behavior found on Windows. CodeWeavers' Elizabeth Figura has been leading this effort with CodeWeavers collaborating with Valve and other stakeholders.



It was very exciting to see this morning that Greg Kroah-Hartman has queued the NTSYNC patches into char/misc's char-misc-next branch. With the patches now residing there, they will be submitted for the Linux 6.10 merge window opening up in May and then debuting as stable this summer -- barring any last-minute issues or objections raised by Linus Torvalds.

Very exciting year for Linux gamers with NTSYNC going mainline, ongoing work around HDR and other display improvements, and all of the Wayland advancements being made, among the usual Linux hardware support advancements and other common kernel milestones being seen in 2024.

source
6
The affected Microsoft products include a wide range of software, encompassing Microsoft Windows, Microsoft Office, Developer Tools, Azure, Browser, System Center, Microsoft Dynamics, and Exchange Server.

In a recent announcement, the Indian Computer Emergency Response Team (CERT-In), operating under the Ministry of Electronics & Information Technology, highlighted significant vulnerabilities in various Microsoft products. These vulnerabilities pose serious risks, potentially enabling attackers to access sensitive information, bypass security measures, and even trigger denial-of-service (DoS) conditions on targeted systems.

The affected Microsoft products include a wide range of software, encompassing Microsoft Windows, Microsoft Office, Developer Tools, Azure, Browser, System Center, Microsoft Dynamics, and Exchange Server.

CERT-In cautioned that these vulnerabilities could empower attackers to exploit elevated privileges, gain access to confidential data, evade security protocols, execute remote code, perpetrate spoofing attacks, or orchestrate DoS incidents. The warning underscores the urgent need for users to take proactive measures to safeguard their systems.

Specifically addressing vulnerabilities within Microsoft Windows, CERT-In identified shortcomings in access restrictions within the proxy driver and deficiencies in the implementation of the Mark of the Web (MotW) feature as key areas of concern.

To mitigate these risks, users are strongly advised to promptly implement the necessary security updates outlined in the company's update guide. By doing so, they can effectively fortify their systems against potential threats.

In addition to the Microsoft vulnerabilities, CERT-In also alerted users to security flaws in Android and Mozilla Firefox web browsers. These vulnerabilities, if exploited, could similarly result in the unauthorized access of sensitive data, execution of arbitrary code, and initiation of DoS attacks.

According to the advisory, versions including 'Android 12, 12L, 13, 14', as well as 'Mozilla Firefox versions before 124.0.1 and Mozilla Firefox ESR versions before 115.9.1', are susceptible to these vulnerabilities.

source
7
Huawei / Huawei building vast chip equipment R&D center in Shanghai
« Last post by javajolt on April 13, 2024, 04:08:24 PM »
China tech company spending billions, snapping up talent in battle against U.S. crackdown


Huawei is spending billions on a research and development base in Shanghai as part of efforts to
counter a U.S. crackdown. (Official WeChat account of Qingpu District, Shanghai Municipality)
CHENG TING-FANG, Nikkei Asia chief tech correspondent April 11, 2024, 11:58 JST
Huawei Technologies is building a massive semiconductor equipment research and development center in Shanghai as the Chinese tech titan continues to beef up its chip supply chain to counter a U.S. crackdown.

The center's mission includes building lithography machines, and vital equipment for producing cutting-edge chips. Washington's export controls have sharply reduced Huawei's access to this equipment, whose production is dominated by just three companies: ASML of the Netherlands and Japan's Nikon and Canon.

To staff the new center, Huawei is offering salary packages worth up to twice as much as local chipmakers, industry executives and sources briefed on the matter told Nikkei Asia. The company has already hired numerous engineers who have worked with top global chip tool builders like Applied Materials, Lam Research, KLA, and ASML, they said, adding that chip industry veterans with more than 15 years of experience at leading chipmakers like TSMC, Intel and Micron are also among recent and potential hires.

Washington's tighter export controls over the past few years have also impacted the job market in China, including by making it more difficult for Chinese citizens to work for foreign chip companies in the country. This has left more top-chip talent available for Huawei and other local companies to choose from.

But while Huawei's compensation package is generous, its working culture can be challenging, according to chip industry managers.

"Working with them is brutal. It's not 996 -- meaning working from 9 a.m. to 9 p.m., six days a week. ... It will be 007 -- from midnight to midnight, seven days a week. No days off at all," one Chinese chip engineer told Nikkei Asia. "The contract will be for three years, [but] the majority of people can't survive till renewal."

Semiconductor equipment, like chips themselves, have been caught in the crosshairs of U.S. export controls. Washington has lobbied allies Japan and the Netherlands to implement similar restrictions on the export of advanced chip tools to limit China's access to them.

These restrictions have spurred many Chinese chipmakers to seek domestic alternatives wherever possible. Naura, China's leading supplier of semiconductor equipment, has seen its revenue more than quadruple since 2018 and is expected to report another record year in 2023.

Huawei, too, has responded to the U.S. crackdown by aggressively beefing up its domestic capabilities.

Its new R&D center is located in the Qingpu district of west Shanghai, sources briefed on the matter said, on a spacious campus that also houses a major chip development center and the new headquarters of HiSilicon Technologies, Huawei's chip design unit. There are also research centers for wireless technologies and smartphones on the premises.

Total investment for the entire R&D base will come to about 12 billion yuan ($1.66 billion), according to the Shanghai government, which listed it as one of the city's top projects for 2024.

The campus covers about 224 football fields in the area and is almost twice as big as the company's renowned Ox Horn Campus, a European village-style site in the Chinese city of Dongguan. Like Ox Horn, the Shanghai campus will include trains for commuting between buildings on the campus. When completed, it will be able to accommodate more than 35,000 high-tech workers, according to the People's Government of Qingpu District of Shanghai Municipality.

Huawei said it had no comments in response to Nikkei Asia's request for comment on its chip equipment efforts and referred questions about its R&D campus to the Shanghai government.


The look of Huawei's Ox Horn Campus in the Chinese city of Dongguan is modeled after a European village.
(Photo by Cheng Ting-Fang)
Huawei's R&D spending in 2023 reached a record high of 164.7 billion yuan, representing 23.4% of its total revenue.

Before the U.S. added Huawei to its trade blacklist, the company focused mainly on chip design and partnered with global production partners like TSMC and Globalfoundries for manufacturing. After its access to American technologies was curbed, Huawei turned to Chinese chipmaker SMIC and local chip developers. It is now venturing into chip production itself with partners backed by local governments in multiple Chinese cities, such as Shenzhen, Qingdao and Quanzhou, Nikkei first reported. It has also invested in many local providers of chip materials.

Huawei has been one of the most aggressive Chinese companies in terms of using local suppliers and investing in domestic alternatives, analysts say.

Brady Wang, a semiconductor analyst with Counterpoint, said Huawei has worked hard to localize its chip-related sources and switch to local components from suppliers such as BOE Technology and Omnivision. "They've invested more in HiSilicon and introduced chips for phones and servers," Wang said. "They will strive to localize a greater portion of their semiconductor supply chain. However, realizing these efforts, particularly those related to chip manufacturing and equipment, will be a time-intensive undertaking."

source
8
Do you want to use two or more operating systems on your desktop computer? Then there are three options: a parallel installation, a virtual PC, and booting from a live DVD or USB stick.


Image: IDG

Do you normally use Windows 11 and just want to have a quick look at a Linux distribution such as Linux Mint or start the computer with a rescue system to remove a malware infection, for example? Then booting the system with a live DVD or from a USB stick is a good option.

The advantage: You don’t have to install anything and no changes are made to the Windows configuration — the live system therefore leaves no traces: If you remove the DVD or USB stick, your PC will boot the permanently installed operating system, such as Windows 10 or 11, after the restart.

If, on the other hand, you want to try out Linux Mint (or another operating system) properly and also install applications, then a virtual computer may be the better choice as a first step.

A virtual computer behaves more or less like a real PC and you can even exchange data with the host (usually your Windows computer) or other devices in the network. However, as the virtual Windows or Linux guest is isolated from the host and network by default, it is primarily suitable for software tests and surfing potentially dangerous websites. Good: You can freeze the system status and return to a backup point at a later time with the click of a mouse.

Another option is the parallel installation of two or more operating systems on a hard drive or SSD, known as multiboot. After switching on the PC, you select which operating system should start in the boot manager.

This allows you to use Windows 11 and Linux Mint on an equal footing and access stored data — regardless of whether it is available locally or on a network share.

Advantages and disadvantages of virtual PCs


Hardware as desired: A virtual machine set up in VirtualBox can be reconfigured at any time, for
example, for more RAM or an additional hard disk as data storage. Image: Sam Singleton


You can learn more about virtual machine tools in our guide on the subject.

We would like to take this opportunity to explain the main advantages: Virtualization technology has been part of everyday life in company networks and data centers since the 2000s. It allows the number of dedicated computers to be reduced and the existing hardware to be optimally utilized. Many other virtual servers can run independently of each other on a host server. This saves energy and administration costs.

For home users, desktop virtualization solutions offer a sophisticated way of testing different operating systems without a large PC base, using Linux under Windows or even Windows under Linux.

But virtualization has its limits: While virtualization environments can translate the commands of the guest operating system to CPUs and memory with little loss of speed, this is not so easy with other hardware components. The graphics performance is not sufficient for complex games. The memory in the virtualization software is usually limited to 128MB — even if much more is available.

The biggest advantage of virtualization: You always have a clean guest system, no matter what you do with it. Ideally, your host system remains completely untouched in the event of accidents and infections in the virtual machine.

You can also change the settings within the virtual machine to your heart’s content and try out tips. With one click, you can return to the original state — on a real PC, a major crash can result in costly repair measures under certain circumstances.

Advantages and disadvantages of Multiboot


Installation: If Linux Mint is installed alongside Windows, select the desired system when booting. Image: IDG

With multiboot — whether with a live system or a permanently installed operating system — you utilize the available resources of the PC. Processor, RAM, and graphics memory are available without restriction — as are all other hardware components such as printer, webcam, and scanner.

A multiboot system can be used in combination with Windows 10 and Linux Mint, for example, if the installation of Windows 11 fails due to the lack of hardware requirements. In addition, typical work on the PC can be separated and PCs can be divided for private and business use. The disadvantage is the double administration effort.

This article was translated from German to English and originally appeared on pcwelt.de.

source
9

Yubico issues a security alert to Windows YubiKey users AFP VIA GETTY IMAGES
When it comes to user authentication, there are many options available, from passwords at the weaker end of the security spectrum to hardware keys at the other. But what if the hardware security key you use could leave your operating system exposed to attack? Yubico, the security vendor behind the range of YubiKey products, has issued a security advisory warning of just that scenario for Windows users.

Yubico Security Advisory YSA-2024-01

Yubico is quite rightly considered to have one of the most secure authentication products in its YubiKey hardware security key range. If proof is needed you only have to look at the Yubico security advisories page entries for the last three years where there are none listed for 2022, one for 2023 and one for 2024. It’s the last of these that impacts Windows users, although not those who use Edge as their web browser client of choice.

Yubico security advisory YSA-2024-01 concerns the YubiKey Manager software which has a vulnerability that could lead to an escalation of privileges attack for Windows users. The vulnerability is listed as CVE-2024-31498 and has a Common Vulnerability Scoring System rating of 7.7 which means this is a high-risk issue rather than a critical one.

Yubico says, “If a user runs the YubiKey Manager GUI as Administrator, browser windows opened by the YubiKey Manager GUI may be opened as Administrator, which could be exploited by a local attacker to perform actions as Administrator.” If this sounds worrying that’s because it is. An attacker, who would already need to have local access to the Windows machine concerned, could use this privilege escalation to further compromise that system. “This issue can be used by an attacker to escalate local attacks and increase the impact of browser-based attacks,” Yubico warns.

Affected Software And Systems

CVE-2024-31498 affects versions of YubiKey Manager prior to 1.2.6 and those Windows users who are not using Edge as their default browser. Yubico explains that it only impacts Windows users as the operating system requires admin privileges to interact with FIDO authenticators such as the YubiKey. On other operating systems, this level of elevated permissions is not required. Windows users are, therefore, advised to click on the About menu in the software and check to see what version they are using. Anything before 1.2.6 should be updated accordingly. The latest version of YubiKey Manager can be downloaded directly from the Yubico website or GitHub.

Other Mitigations For The YubiKey Manager Vulnerability

The Fast IDentity Online Alliance is an open standard for authentication that, in its FIDO2 guise, can provide passwordless single-factor authentication as well as two and multi-factor authentication options among other things. Yubico advises that users not requiring the FIDO features do not need to run YubiKey Manager GUI as an elevated privilege user. Windows users can also configure Microsoft Edge as their default web browser, as this already includes mitigations that prevent admin permissions from being inherited when initiated the way this vulnerability enables. That said, I would not recommend switching to Edge from your preferred browser; take the software update route instead, and then there’s no need.

source
10


The complete shutdown of the long-running E3 video game trade show in 2023 was not exactly a surprise but was still a disappointment for many gaming fans who have enjoyed the event over the decades. Earlier this year, the gaming and entertainment media site IGN announced plans for an in-person event, IGN Live, in LA. Now we have a little more info on this possible replacement for E3.

IGN's site stated that IGN Live will be held June 7-9 and it will take place in downtown LA, similar to most of the past E3 shows. However, IGN Live won't be held in the big LA Convention Center like the majority of E3 shows but rather at Magic Box, an event center that's located not too far from E3's old convention center location.

IGN says the event will include a "stage show with developers, publishers, creators, and more across gaming and entertainment". It will also have other activities for the people who attend, including "exclusive reveals, trailers, gameplay, panels, interviews, episodes of IGN shows, and more". The site will also stream content from IGN Live as well.

There's no word on what game publishers will be participating in IGN Live. There's also no word on when tickets for the live event will take place or how much they will cost.

Aside from IGN Live, it looks like a lot of the game industry will be using that same early June 2024 time frame to hold streaming events for announcements and game reveals. Microsoft has already confirmed that it will hold its big Xbox Game Showcase sometime In June. Rumors have already been hitting the internet that it will officially reveal the next Gears of War game, among other titles.

Ubisoft has confirmed it will stream its Ubisoft Forward event on June 10 from LA. The latest Summer Game Fest event will also be streamed from LA on June 7. The Future Games Show is set for its 2024 summer streaming event on June 8, and the PC Gaming Show's summer event is promised for sometime in June. It's likely that more gaming streaming events will be revealed for around that same time frame in the very near future.

source
Pages: [1] 2 3 ... 10