Welcome, Guest
You have to register before you can post on our site.

Username
  

Password
  





Search Forums

(Advanced Search)

Forum Statistics
» Members: 20,946
» Latest member: blackopsdlc
» Forum threads: 22,100
» Forum posts: 23,067

Full Statistics

Online Users
There are currently 777 online users.
» 0 Member(s) | 771 Guest(s)
Applebot, Baidu, Bing, Facebook, Google, Yandex

Latest Threads
[DevBlog MS] Build Agenti...
Forum: C#, Visual Basic, & .Net Frameworks
Last Post: xSicKxBot

» Replies: 0
» Views: 0
Headphone Stand 3D Print ...
Forum: Printers & CAD Projects
Last Post: xSicKxBot

» Replies: 0
» Views: 2
[WoW Retail News] Glory o...
Forum: World of Warcraft
Last Post: xSicKxBot

» Replies: 0
» Views: 10
[PS.Blog] God of War Lauf...
Forum: Sony Discussion
Last Post: xSicKxBot

» Replies: 0
» Views: 11
[Ubuntu News] How a missi...
Forum: Linux, FreeBSD, and Unix types
Last Post: xSicKxBot

» Replies: 0
» Views: 10
What is Black Ops 6 Zombi...
Forum: PC Discussion
Last Post: xSicKxBot

» Replies: 0
» Views: 15
[WoW Retail News] Winds o...
Forum: World of Warcraft
Last Post: xSicKxBot

» Replies: 0
» Views: 16
Digital Sundial 3D Print ...
Forum: Printers & CAD Projects
Last Post: xSicKxBot

» Replies: 0
» Views: 18
Modular Mounting System 3...
Forum: Printers & CAD Projects
Last Post: xSicKxBot

» Replies: 0
» Views: 16
Self-Watering Planter (Sm...
Forum: Printers & CAD Projects
Last Post: xSicKxBot

» Replies: 0
» Views: 16

 
  FlatRedBall Engine Review
Posted by: xSicKxBot - 10-07-2020, 06:27 PM - Forum: Game Development - No Replies

FlatRedBall Engine Review

FlatRedBall is an open source C# based game engine with development dating back to 2005. It was originally built to run on-top of Managed Direct X, then was ported to XNA and when XNA was depreciated, it was again ported to run on top of the MonoGame framework.

FlatRedBall provides a layer of APIs and tooling on top of MonoGame designed to simplify the process of creating 2D games. You can currently create games for Windows (and UWP), Android and iOS, with Mac and Linux targets currently a work in progress. The heart of the tooling is Glue, which “glues” together the various other tools, including plugins for tasks such as UI development as well as support for the Tiled 2D map editor.

FlatRedBall is open source with the source code available on GitHub under the flexible and permissive MIT open source license. You can check out FlatRedBall in action in the video below (or here on Odysee). If you are interested in learning more or encounter a problem, they have an active Discord server available here.






https://www.sickgaming.net/blog/2020/10/...ne-review/

Print this item

  Microsoft - New steps to preserve and protect journalism and local newsrooms
Posted by: xSicKxBot - 10-07-2020, 06:27 PM - Forum: Windows - No Replies

New steps to preserve and protect journalism and local newsrooms

Growing up in Newton, Kansas our local newspaper, The Kansan, was the lifeblood of our community. At 3:30 p.m. every afternoon it landed on porches and lawns across the town, and we saw our local culture reflected in its pages: updates about important local events, high school sports scores, who won the local debate competition, and the weather forecasts our farming community depended on for their livelihoods. Years later, as the lawyer for Microsoft’s news and information portal MSN and our news services, I gained an even greater appreciation for high-quality, fact-based journalism and the important role trusted news played in society.

We’ve been looking at ways Microsoft’s technology and resources can help address some of the challenges journalism faces, and today I want to share some of the initial work of our initiative. It includes a new community-based pilot program that looks at ways to provide journalists and newsrooms new tools, technology and capacity, and expand reach for local news outlets. It also includes a new pro bono program, also in pilot form, to provide legal support to journalists and smaller newsrooms, and an expansion of AccountGuard to help protect journalists from cyberattacks. We will build on top of work already under way by Microsoft Research and the Microsoft Defending Democracy team that’s designed to tackle issues such as disinformation.

We’re starting with a very targeted approach. We don’t have all the answers, but we are committed to listening and learning, and we hope our contributions and learnings will be useful to others. We’ll also look to add additional steps and programs to our initiative as we learn more and identify additional opportunities.

The challenges

News and journalism face an accelerating crisis. Changes in digital advertising and in the way people receive their news – news aggregators, search engines and social media – have had a significant impact on journalism and its business model. Over the past 15 years, newsroom employment in the United States has dropped by half and 2,100 newspapers have closed. In recent months, the pandemic has put even more stress on newsrooms as advertisers pulled back. Since January, 11,000 newsroom jobs were cut in the U.S.

Digital technologies create opportunities for innovation and operational efficiencies, but they also create the risk that content can be manipulated and used to spread disinformation, undermining trust in all media. People’s digital literacy – the ability to find, analyze, evaluate and compose information – has not kept pace with technological innovation, making some people susceptible to manipulated content. Around the world, journalists themselves are also under attack, both physically and increasingly as targets for cyberattacks. According to survey conducted by Forrester Consulting, more than half of media and entertainment companies experienced three or more cyberattacks over a 12-month period.

Our approach

We believe there are specific areas where our technology or our resources can help. Initially, our initiative is focused on three areas:

  • Support local newsrooms: Provide tools, technology, expanded distribution and funding for pilot programs
  • Integrity: Use technology to tackle tech-driven threats such as deepfakes and disinformation, and tools to improve media literacy
  • Security & safety: Help to support and protect journalists from threats, including legal and cyberthreats

Our approach is targeted and, in most cases, focused on initial pilots with specific partners and communities. We learned from our TechSpark program the importance of working with a community to understand their priorities, being open about what we don’t know and making a commitment to learning. Like TechSpark, we hope that by working with others, and by innovating and testing, we can play a role in finding sustainable solutions to some of the challenges journalism faces.

Supporting local newsrooms

The first focus area of the initiative is to work in partnership with local community foundations to help support local newsrooms. We hope we can support these newsrooms and journalists as they use the latest tools and technology to tell stories in new ways, experiment with new revenue streams and funding models, and work together with community organizations. We will bring technical expertise to the pilot community newsrooms and will partner with other industry organizations and foundations to share expertise and experience that will further expand the reach and impact of the initiative. Specifically, we will:

  • Provide direct funding to the community foundations for operating costs, to bolster collaboration and attract matching funding and resources from foundations and other local or regional businesses
  • Up-level technology through donations, deeply discounted software products and services from Microsoft and others
  • Build capacity around technology transformation and technical support, business intelligence including customer-based analytics, and modern journalism skills such as data journalism, using AI and machine learning tools and technology built specifically for journalists, audio and video production, and modern storytelling.
  • Expand news distribution to increase their reach and recognition, as well as generate new sources of revenue. Participating newsrooms that aren’t already a Microsoft News partner will have the opportunity to become one. As a partner, they may reach more than 500 million people in 180 countries every month across MSN, Bing, Microsoft Edge, Microsoft News apps and many mobile manufacturers and third-party distribution partners. Over 25 years, we’ve built a worldwide community of 1,200 publishers and 4,500 media brands and are proud to have shared over $1 billion of revenue with them since 2014.
  • Convening experts on new sources of revenue and funding so pilot communities can learn and build on approaches that have worked elsewhere. For example, The Seattle Times will share with the pilot newsrooms its working model and experiences of community-funded journalism.

We are starting this work with pilots in Fresno, Calif.; the El Paso–Ciudad Juárez cross-border region; Jackson, Miss. and the Delta; and Yakima, Wash. These four communities were selected because of the serious challenges their local newsrooms face, the diversity of each community, the strong support of local news by the community, and referrals by third parties working on the future of news.

Addressing the challenges these local newsrooms face requires a new collaborative approach across pilot newsrooms, with community foundation leaders, local and regional academia, and non-profit organizations. We’ve spent the last few months engaged with each of these local communities to help define our approach and where we can be most helpful. These unique networks of local organizations are working together to identify the issues critical to their communities and where additional reporting, support and resources are needed. You can see the list of organizations involved in the pilots here.

Integrity

The second focus area is to begin to restore trust in the news and information people receive. Our efforts in this area draws on work by Microsoft Research and Microsoft’s Defending Democracy team. Tom Burt and Eric Horvitz recently announced a number of new steps to combat disinformation including new technologies such as Microsoft Video Authenticator to help tackle deepfakes, and new Azure-based tools to help detect manipulated content. They also highlighted new partnerships with news organizations, and an expansion of our NewsGuard implementation. It’s clear that public education and media literacy are critical components, and Tom and Eric referenced our work with the University of Washington (UW) Center for an Informed Public, Sensity and USA Today on media literacy, as well as an interactive quiz for consumers.

Security and safety

The third focus area is about using our technology, expertise and partnerships to help with legal issues, safeguard journalists’ digital data and help spot threats. We’re starting with two initiatives:

Legal support: As watchdogs of political systems, government institutions and others in power, journalists rely on legal public records requests to get information for use in their reporting. Government agencies sometimes refuse to agree to these requests and media outlets are faced with filing an expensive and time-consuming lawsuit to have them honored. News outlets are also facing an increasing number of lawsuits by individuals or groups seeking to use the legal system to stop or impede stories they don’t want published.

To begin to address these challenges, in partnership with Davis Wright Tremaine LLP, we are piloting the Protecting Journalists Pro Bono Program in California and Washington. To start, volunteer attorneys from Microsoft and Davis Wright Tremaine will provide legal support to journalists and small news organizations that are not otherwise able to afford legal support across three workstreams: pre-publication review, access to public records and defending journalists against subpoenas for confidential information. We’re currently accepting requests for assistance only through referrals via three non-profit partners: Reporters Committee for Freedom of the Press, First Amendment Coalition and Washington Coalition for Open Government. We’re also working directly with several small news organizations that are focused on underserved communities. As we learn from the pilot, we hope to expand to other regions and add additional partners.

Cyberattacks: Newsrooms and journalists are particularly vulnerable as they deal with large amounts of data and sensitive information from and about sources. We are expanding our Microsoft AccountGuard threat notification service with a new offering AccountGuard for Journalists. AccountGuard is available at no cost to M365 customers to provide notification of nation-state cyberattacks, tracking threat activity on M365 emails and personal accounts, including Outlook.com and Hotmail, of its employees who opt-in. AccountGuard also includes access to cybersecurity training and early access to new security features. It currently protects more than 2 million accounts across 30 countries, and enrollees have received more than 1,500 notifications of nation-state attacks to date. AccountGuard for Journalists will initially be available at no cost to newsrooms participating in the local pilot program and existing Microsoft News publishing partners.

Healthy Journalism

Beyond the work we are doing with others, we believe there are important public policy issues, too. We are committed to using our voice to advocate on issues that matter to news and journalism.  We will work to help advance a national dialogue with a particular focus on protecting the safety of journalists, protecting free speech for journalists and others, and promoting the sustained health of local news.

Healthy democracies require healthy journalism, and we hope our initiative can play a role in helping to support quality journalism locally and nationally, as well as promote trust in news. Over the past 10 months we’ve met with people in newsrooms and across the communities of Fresno, El Paso-Juarez, Jackson and Yakima, and our optimism about local news is stronger than ever. Local newsrooms are the heart of their communities. They not only provide updates about the important local events and high school sports scores that I remember from my childhood but, then and now, provide in-depth local investigations with national importance. Integrity, security and safety are critical to journalists around the globe. We hope our tools will give journalists some ease from worrying about attacks and more time to focus on their essential work. With these global tools, partnerships and local pilot programs, we hope to play a role in supporting journalists, newsrooms and communities as they work to ensure they have healthy journalism for generations to come.

Tags: , , , , ,



https://www.sickgaming.net/blog/2020/10/...newsrooms/

Print this item

  News - Beyond Donkey Kong Digs Deep Into Nintendo’s Often Overlooked Arcade Heritage
Posted by: xSicKxBot - 10-07-2020, 06:27 PM - Forum: Nintendo Discussion - No Replies

Beyond Donkey Kong Digs Deep Into Nintendo’s Often Overlooked Arcade Heritage


Beyond Donkey Kong© Nintendo Life

While Nintendo has long been a major force in the realms of domestic and portable video gaming, it’s important to remember that the release that truly put the Japanese firm on the map was an arcade one: 1981’s Donkey Kong. Shigeru Miyamoto’s first masterpiece transformed Nintendo from a coin-op also-ran into one of the industry’s major players, but its attention quickly shifted to the home arena when it released the Famicom in 1983 to widespread critical and commercial acclaim – the same year that the video game industry in the US was hit with its first crash.

Because of this, many people consider Nintendo’s history in the arcade arena to be a side-note to its triumph in the world of consoles and handhelds, but as Ken Horowitz’s new book – Beyond Donkey Kong – attests, the firm was actually very active in the world of arcades for longer than you might assume.

Donkey Kong was followed by hits like Popeye, Punch-Out!! and the ‘lost’ Sky Skipper, and Nintendo would successfully adapt its NES hardware in the form of the “VS.” arcade system which used modified NES games to pull in quarters. Later still, Nintendo would keep its name alive in amusement arcades all over the globe by working with companies like Midway, Sega and Namco and helping to produce titles like Killer Instinct, Crusin’ USA, F-Zero AX and Mario Kart Arcade GP. Even today, Nintendo’s name is still present in arcades thanks to titles like Crusin’ World.

Horowitz, as you may be aware, runs the excellent Sega-16 website and has previously published books on Sega’s history in both the home and arcade sectors; he brings his usual attention to detail and skill to tell a narrative in Beyond Donkey Kong, and pulls in quotes from exclusive interviews and well-researched sources to create a complete picture of what remains an often overlooked period in Nintendo’s recent history.

(Oh, and I wrote the forward, but don’t let that put you off. It’s a great read for Nintendo fans.)

Please note that some external links on this page are affiliate links, which means if you click them and make a purchase we may receive a small percentage of the sale. Please read our FTC Disclosure for more information.



https://www.sickgaming.net/blog/2020/10/...-heritage/

Print this item

  (Indie Deal) Metro Exodus, Freedom Fighters, THE SOJOURN, Star Wars Sale, GalaQuiz
Posted by: xSicKxBot - 10-07-2020, 10:51 AM - Forum: Deals or Specials - No Replies

Metro Exodus, Freedom Fighters, THE SOJOURN, Star Wars Sale, GalaQuiz

Metro Exodus at 60% OFF for Steam
[www.indiegala.com]
Explore the Russian wilderness at a historical low price with Metro Exodus and more!
https://youtu.be/pDkqQjyI6FY
New Release: THE SOJOURN[www.indiegala.com]
https://youtu.be/Emrfes76tC8
Empire Strikes Back Sale, EMEA ONLY, all titles -75%
[www.indiegala.com]
The 212nd GalaQuiz will be LIVE soon, win up to $50:dollars: in GalaCredit!
[www.indiegala.com]
The GalaQuiz will take place in less than 10 minutes from this announcement
Today's GalaQuiz[www.indiegala.com] hints are up. The theme will be Classic Cartoons Voices Redux.

Stay Inside, Stay Safe and Enjoy Good Games.
Check out IndieGala on Twitter, YouTube & Facebook[www.facebook.com]


https://steamcommunity.com/groups/indieg...3544292859

Print this item

  Microsoft - Annual IoT trends report: impact of COVID-19 and more
Posted by: xSicKxBot - 10-07-2020, 10:51 AM - Forum: Windows - No Replies

Annual IoT trends report: impact of COVID-19 and more

If your business is already harnessing IoT, you likely believe IoT is critical to your long-term success. You are not alone. According to our latest annual report, IoT Signals edition 2 released today, 90 percent of decision makers now believe IoT is critical to their company’s success. The last six months have been tumultuous to say the least, however for many business decision makers it has actually accelerated their work towards a connected and secured future.

On our daily Microsoft Teams calls with customers and partners, we often say that it feels like a year’s worth of digital transformation is happening each and every month in 2020. For IoT, that transformation is providing near real-time visibility into physical assets and environments, enabling increased efficiency, reduced downtime, and keeping employees safe as they return to work during COVID-19.

Customers have shared that they are seeking guidance on what we see happening in IoT around the world in industries like Healthcare, Retail, Manufacturing, Oil and Gas, and Power and Utilities, and how other leaders are navigating rapid transformation.

We learned that looking ahead to the next two years, two out of three organizations are planning to use IoT even more than they do today; from connecting and securing factories, to enabling remote patient monitoring, to optimizing supply chains, and thousands of other scenarios. We’re also seeing a monumental shift in companies moving from simply connecting assets (for example manufacturing equipment), to connecting entire environments; the factories, supply chain, distribution network and more. This shift from connected assets to connected environments provides an order of magnitude increase in the value of IoT to a business.

Learnings from IoT Signals edition 2: IoT has become a critical part of organizations’ business strategies


During April, May, and June of this year, we sought to uncover the current and future trends of IoT to better serve our partners and customers around the world to develop their own IoT strategies. In IoT Signals edition 2, we learned from over 3,000 business and technical decision makers, and developers who are currently making decisions for IoT solutions at their organization. Here are five things to know about IoT in 2020:

1. COVID-19 is accelerating IoT adoption.


The study revealed that 91 percent of organizations have now adopted IoT (up from 85 percent last year). COVID-19 is having an undeniable impact on the world around us, and IoT is no exception. While the pandemic has slowed business across the globe, IoT is an area with upward trajectory in the wake of the virus. One in three decision makers say their organizations will increase their investment in IoT due to COVID-19, while another 41 percent say they’ll maintain the same level of commitment. For the few not intending to strengthen their investment, these organizations tend to be in the earlier stages of IoT—and those already behind may struggle to catch up quickly.

“During the coronavirus we had a problem with the return of empty bottles. We didn’t get any back, everybody kept them at home. So we had to get in touch with the glass manufacturers. It wasn’t easy to fill in the gap but we noticed the gap in the first place because of the data that we had through our IoT solution. The manufacturing plant can automatically adapt to increased demand. We also call it the smart factory, we don’t have to control and adjust things so much.”—ITDM, German Beverage Manufacturing

Those who expect to invest the same or more in IoT have fewer projects in the learn phase:

Breakdown of IoT project investments.

2. Security is integral.
A full 97 percent of IoT decision makers have security concerns when connecting new assets, and data privacy is a top security concern for about half of all organizations. Apart from data privacy, ensuring network-level security and securing endpoints are critical, while security management and managing default passwords is a lower priority.

“Security is extremely important—it’s paramount when we look to implement IoT solutions. We are a big brand, and therefore a big target. Obviously customer data system integrity is very important for us. So we have a very, very talented group of security personnel that are monitoring and developing within IoT all the time. We have different security teams—technical security, physical security, architecture security. It’s an area that we invest in a lot.”—UK Retail ITDM in Fashion Retail

3. AI, Edge Computing, and Digital Twins technologies are becoming mainstream.
However, there is significant room to educate more about these technologies and to test and trial to harness the full potential of IoT. We found that those who incorporate emerging technologies into their IoT solution realize more success with IoT overall, since once the value is proven it’s easier to build buy-in across the organization.

79 percent of organizations adopt AI as part of their IoT solution, and those who do perceive IoT to be more critical to their company’s success (95 versus 82 percent) and are more satisfied with IoT (96 versus 87 percent).

4. IoT projects are evaluated by return on investment, often measured first by how much they move the needle against automation and efficiency goals.
Reduction of operating costs and production efficiency stand out as key benchmarks for determining whether IoT has achieved success—even more so than the number of IoT projects or direct impact on revenue. Not surprisingly, organizations are also adopting IoT as part of a broader culture change to lead new investments for safety and security, rising three spots from IoT Signals edition 1 to the number one reason for IoT adoption in 2020.

Productivity is a top benefit of IoT (79 percent), specifically operations productivity (54 percent) and employee productivity (47 percent). In addition, the top uses of IoT include operations optimization (47 percent) and employee productivity (43 percent).

Common measures of success: cost efficiency, quality, production efficiency, reliability, and security.

“We have to prove the impact of IoT to demonstrate the value. If we can explain how IoT helped prevent a hundred thousand truck rolls this year, then ascribe a cost to every single one of those, that’s when we show impact to the bottom line. And on top of that, I’ve got a hundred thousand customers that didn’t wait for an hour or more. In each of those cases we immediately started to triage with customers versus making them wait.”—US Energy ITDM in Power and Utilities

5. Internal resourcing and complexity continue to be top challenges.
While budget constraints can hold back the pace to progress from testing, through proof of concept, and into full use stage, IoT solutions will truly succeed when solution implementers gain deep internal alignment. Scaling an IoT solution presents a formidable shift for organizations which can create internal systems and technical obstacles. Those who adopt IoT as part of a broader culture change and prioritize investing in the right staff are well positioned to overcome barriers sooner.

“We had a lesson learned and realized we weren’t really going to be ready to go to market when we thought. There was more build to be done as we started to use the tool and started to realize—how do we manage this data?”—US Healthcare provider ITDM in Blood Labs

Interested in developing with Azure IoT?


If you’re interested in developing with Azure IoT there has never been a better time to reach out, find a partner, or build a solution to accelerate your business with IoT. When IoT is a foundational part of your transformation, we’ve seen the positive effects it can have on productivity, growth, safety, customer experiences, and much more.

We are committed to helping you turn your vision into reality with secure, scalable, and open edge-to-cloud solutions.

  1. Develop with choice: Simplify building open and flexible IoT solutions quickly, on your terms.
  2. Secure data everywhere: Trust your data estate is secure from endpoints to the cloud.
  3. Power the edge: Seamlessly move your AI workloads and business intelligence to the edge.
  4. Prepare for future innovation: Integrate continuously enhanced data, AI, mixed reality, and analytics solutions.
  5. Scale globally: Grow effortlessly with the largest IoT ecosystem to unlock global scale.

Download IoT Signals edition 2 and learn more.



https://www.sickgaming.net/blog/2020/10/...-and-more/

Print this item

  News - Nintendo Is Being Sued Over Joy-Con Drift Yet Again, This Time By A Child
Posted by: xSicKxBot - 10-07-2020, 10:51 AM - Forum: Nintendo Discussion - No Replies

Nintendo Is Being Sued Over Joy-Con Drift Yet Again, This Time By A Child


Switch© Nintendo Life

Nintendo is facing yet more trouble over the Joy-Con drift phenomenon as a mother and her 10-year-old child file a class-action lawsuit against the company.

‘Joy-Con drift’ refers to an issue where your Nintendo Switch controller will register movement even when you aren’t applying any pressure to the control stick. The problem has brought about a number of lawsuits, and has even forced Nintendo’s president to issue an apology.

As reported by Wired, this latest lawsuit has been filed by a woman named Luz Sanchez and her son, who say that Nintendo hasn’t done enough to fix an issue it is well aware of.

Sanchez explains that the family console was purchased in December 2018, with Joy-Con drift trouble starting to appear within a month. Within a year, “the Joy-Con drift became so pronounced that the controllers became inoperable for general gameplay use,” the complaint says. A second set of Joy-Con controllers were purchased, but seven months later, they faced the same issue.


Who knew these little things were going to cause so much trouble, huh?© Nintendo Life
Who knew these little things were going to cause so much trouble, huh?

Despite Nintendo’s efforts to fix faulty controllers, the lawsuit argues that Nintendo is in the wrong for selling knowingly faulty products in the first place. The complaint reportedly reads, “Defendant continues to market and sell the Products with full knowledge of the defect and without disclosing the Joy-Con Drift defect to consumers in its marketing, promotion, or packaging.”

It continues, “Defendant has had a financial motive to conceal the defect, as it did not want to stop selling the Products, and/or would need to expend a significant amount of money to cure the defect.”

The plaintiffs are reportedly asking for over $5,000,000 in damages.


Further Reading:



https://www.sickgaming.net/blog/2020/10/...y-a-child/

Print this item

  News - Apple iPhone Event Coming Next Week
Posted by: xSicKxBot - 10-07-2020, 10:51 AM - Forum: Lounge - No Replies

Apple iPhone Event Coming Next Week

Apple has set a date for its anticipated iPhone fall event. The online-only event will take place on October 13 at 10 AM PT / 1 PM ET. The event will be streamed through Apple's website, like the recent Worldwide Developers Conference.

CNET reports that the event is expected to debut the iPhone 12, which is said to feature 5G capabilities. That's backed up by the punny teaser image, which says "Hi, Speed." It's also said to have an outer design more akin to the iPad Pro. It will also likely get the slate of usual upgrades like faster chips and better cameras.

Apple is expected to announce three new models of iPhone. The new iPhone models are expected to replace the current iPhone 11, iPhone 11 Pro, and iPhone 11 Pro Max, which are priced at $800, $1000, and $1100, respectively.

Continue Reading at GameSpot

https://www.gamespot.com/articles/apple-...01-10abi2f

Print this item

  Microsoft - Why we invite security researchers to hack Azure Sphere
Posted by: xSicKxBot - 10-07-2020, 01:48 AM - Forum: Windows - No Replies

Why we invite security researchers to hack Azure Sphere

Fighting the security battle so our customers don’t have to


IoT devices are becoming more prevalent in almost every aspect of our lives—we will rely on them in our homes, our businesses, as well as our infrastructure. In February, Microsoft announced the general availability of Azure Sphere, an integrated security solution for IoT devices and equipment. General availability means that we are ready to provide OEMs and organizations with quick and cost-effective device security at scale. However, securing those devices does not stop once we put them into the hands of our customers. It is only the start of a continual battle between the attackers and the defenders.

Building a solution that customers can trust requires investments before and after deployment by complementing up-front technical measures with ongoing practices to find and mitigate risks. In April, we highlighted Azure Sphere’s approach to risk management and why securing IoT is not a one-and-done. Products improve over time, but so do hackers, as well as their skills and tools. New security threats continue to evolve, and hackers invent new ways to attack devices. So, what does it take to stay ahead?

As a Microsoft security product team, we believe in finding and fixing vulnerabilities before the bad guys do. While Azure Sphere continuously invests in code improvements, fuzzing, and other processes of quality control, it often requires the creative mindset of an attacker to expose a potential weakness that otherwise might be missed. Better than trying to think like a hacker is working with them. This is why we operate an ongoing program of red team exercises with security researchers and the hacker community: to benefit from their unique expertise and skill set. That includes being able to test our security promise not just against yesterday’s and today’s, but against even tomorrow’s attacks on IoT devices before they become known more broadly. Our recent Azure Sphere Security Research Challenge, which concluded on August 31, is a reflection of this commitment.

Partnering with MSRC to design a unique challenge


Our goal with the three-month Azure Sphere Security Research Challenge was twofold: to drive new high-impact security research, and to validate Azure Sphere’s security promise against the best challengers in their field. To do so, we partnered with the Microsoft Security Response Center (MSRC) and invited some of the world’s best researchers and security vendors to try to break our device by using the same kinds of attacks as any malicious actor might. To make sure participants had everything they needed to be successful, we provided each researcher with a dev kit, a direct line to our OS Security Engineering Team, access to weekly office hours, and email support in addition to our publicly available operating system kernel source code.

Our goal was to focus the research on the highest impact on customer security, which is why we provided six research scenarios with additional rewards of up to 20 percent on top of the Azure Bounty (up to $40,000), as well as $100,000 for two high-priority scenarios proving the ability to execute code in Microsoft Pluton or in Secure World. We received more than 3,500 applications, which is a testament to the strong interest of the research community in securing IoT. More information on the design of the challenge and our collaboration with MSRC can be found here on their blog post.

Researchers identify high impact vulnerabilities before hackers


The quality of submissions from participants in the challenge far exceeded our expectations. Several participants helped us find multiple potentially high impact vulnerabilities in Azure Sphere. The quality is a testament to the expertise, determination, and the diligence of the participants. Over the course of the challenge, we received a total of 40 submissions, of which 30 led to improvements in our product. Sixteen were bounty-eligible; adding up to a total of $374,300 in bounties awarded. The other 10 submissions identified known areas where potential risk is specifically mitigated in another part of the system—something often referred to in the field as “by design.” The high ratio of valid submissions to total submissions speaks to the extremely high quality of the research demonstrated by the participants.

Graph showing the submission breakdown and the total amount of money eligible to be received through the bounty system.

Jewell Seay, Azure Sphere Operating System Platform Security Lead, has shared detailed information of many of the cases in three recent blog posts describing the security improvements delivered in our 20.07, 20.08, and 20.09 releases. Cisco Talos and McAfee Advanced Threat Research (ATR), in particular, found several important vulnerabilities, and one particular attack chain is highlighted in Jewell’s 20.07 blog.

While the described attack required physical access to a device and could not be executed remotely, it exposed potential weaknesses spanning both cloud and device components of our product. The attack included a potential zero-day exploit in the Linux kernel to escape root privileges. The vulnerability was reported to the Linux kernel security team, leading to a fix for the larger open source community which was shared with the Linux community. If you would like to learn more and get an inside view of the challenge from two of our research partners, we highly recommend McAfee ATR’s blog post and whitepaper, or Cisco Talos’ blog post.

What it takes to provide renewable and improving security


With Azure Sphere, we provide our customers with a robust defense based on the Seven Properties of Highly Secured Devices. One of the properties, renewable security, ensures that a device can update to a more secure state—even if it has been compromised. While this is essential, it is not sufficient on its own. An organization must be equipped with the resources, people, and processes that allow for a quick resolution before vulnerabilities impact customers. Azure Sphere customers know that they have the strong commitment of our Azure Sphere Engineering team—that our team is searching for and addressing potential vulnerabilities, even from the most recently invented attack techniques.

We take this commitment to heart, as evidenced by all the fixes that went into our 20.07, 20.08, and 20.09 releases. In less than 30 days of McAfee reporting the attack chain to us, we shipped a fix to all of our customers, without the need for them to take any action due to how Azure Sphere manages updates. Although we received a high number of submissions throughout multiple release cycles, we prioritized analyzing every single report as soon as we received it. The success of our challenge should not just be measured by the number and quality of the reports, but also by how quickly reported vulnerabilities were fixed in the product. When it came to fixing the found vulnerabilities, there was no distinction made between the ones that were proven to be exploited or the ones that were only theoretical. Attackers get creative, and hope is not part of our risk assessment or our commitment to our customers.

Our engagement with the security research community


On behalf of the entire team and our customers, we would like to thank all participants for their help in making Azure Sphere more secure! We were genuinely impressed by the quality and number of high impact vulnerabilities that they found. In addition, we would also like to thank the MSRC team for partnering with us on this challenge.

Our goal is to continue to engage with this community on behalf of our customers going forward, and we will continue to review every potential vulnerability report for Azure Sphere for eligibility under the Azure Bounty Program awards.

Our team learned a lot throughout this challenge, and we will explore and announce additional opportunities to collaborate with the security research community in the future. Protecting our platform and the devices our customers build and deploy on it is a key priority for us. Working with the best security researchers in the field, we will continue to invest in finding potential vulnerabilities before the bad guys do—so you don’t have to!

If you are interested in learning more about how Azure Sphere can help you securely unlock your next IoT innovation:



https://www.sickgaming.net/blog/2020/10/...re-sphere/

Print this item

  News - Spooky 3D Platformer Pumpkin Jack Will Haunt Nintendo Switch This Halloween
Posted by: xSicKxBot - 10-07-2020, 01:48 AM - Forum: Nintendo Discussion - No Replies

Spooky 3D Platformer Pumpkin Jack Will Haunt Nintendo Switch This Halloween


Headup has announced that the “comically creepy” 3D platformer Pumpkin Jack will be getting spooky on a Switch near you from 23rd October.

The game, developed by Nicolas Meyssonnier, has you jumping, dodging and carving your way through enemies and puzzles in a battle of evil against good. You’ll come up against a variety of dangerous situations, rollercoaster-like minecarts, and more, and you can even use your trusty owl companion to unleash long-distance attacks. Here’s an official description:

Pumpkin Jack is a spooky scary 3D platformer in which you embody Jack, the Mythical Pumpkin Lord. Dive into an epic adventure through otherworldly landscapes and help the Evil annihilate the Good!
​
Follow the will of the Devil himself and slay your nemesis in an epic quest that will take you on a journey in the Boredom Kingdom, a mythical realm shattered by the curse. You will meet friends along the way, from a haughty owl to a snarky crow!

Discover stunning atmospheres in a colorful yet spooky scary Kingdom. Travel through epic and dramatic settings, with each level having its own eerie atmosphere. Using a vibrant palette and high-quality lighting effects, Pumpkin Jack invents its own unique cartoon universe inspired by the classic PS2 graphic style, made with Unreal Engine 4.


The game is said to offer tight platforming sections, riddles to solve, and “a hair-raising array of gameplay mechanics” that total a playtime of 5-8 hours for one run. If you’re keen on giving it a go, make sure to keep an eye on the eShop later this month.



https://www.sickgaming.net/blog/2020/10/...halloween/

Print this item

  News - Overwatch Is Going Free-To-Play On Switch For A Week In Japan
Posted by: xSicKxBot - 10-07-2020, 01:48 AM - Forum: Nintendo Discussion - No Replies

Overwatch Is Going Free-To-Play On Switch For A Week In Japan

Overwatch Switch

Overwatch will temporarily be made free-to-play for Nintendo Switch Online subscribers in Japan later this month, as part of an ongoing benefit of the service in Nintendo’s home country.

Subscribers will be able to get stuck into the game for free from 13th – 20th October, and even those enjoying free trials of Nintendo Switch Online qualify. Save data from this free version of the game can be carried over to the full version, which will incidentally be discounted by 25% until 27th October (thanks, Japanese Nintendo).

In the past, games like Pokkén Tournament DX, Fire Emblem Warriors, Dead Cells and Celeste have also been offered up in full for a week in Japan, with full-game discounts being put in place to tempt players into a purchase.

It’s worth pointing out that if you happen to have a Japanese account on your Switch with an active Japanese Switch Online subscription, you can enjoy this free version of Overwatch from anywhere in the world.

Would you like to see more full-game trials like this in the west? Let us know in the usual place.



https://www.sickgaming.net/blog/2020/10/...-in-japan/

Print this item