Communications

An AT&T-Backed Cellular Satellite Company Sent a 4G LTE Signal From Space 11

According to AST SpaceMobile, the company managed to successfully transmit a 4G LTE signal from space that was picked up by "everyday, off-the-shelf smartphones." Next, AST will try and transmit a 5G connection via its BlueWalker 3 (BW3) satellite. The Verge reports: Testing was conducted in Hawaii on AT&T's spectrum using Nokia RAN technology, and the signal, which was beamed from AST's satellite in low Earth orbit, reached speeds of up to 10.3Mbps. That's fast enough for some video streaming, general internet use, and more ordinary cell phone usage. AST's testing followed a recent April test by the same company, where it was able to route an audio call between a Samsung Galaxy S22 in Texas to an iPhone in Japan via satellite.

The BW3 is a massive commercial communication array at 693 square feet -- about the size of a two- or three-car garage -- and the largest ever deployed in low Earth orbit, says AST's release. It operates using the same 3GPP standard found in ground-based cell networks. The achievement is "an important step toward AST SpaceMobile's goal of bringing broadband services to parts of the world where cellular coverage is either unreliable or simply does not exist today," according to AST's chairman and CEO, Abel Avellan, who said this would allow users to text and call, browse the internet, download files, and even stream video using a signal beamed from space.
IOS

iOS 17 Will Decode Your Car's Dashboard Symbols and Warning Lights (gizmodo.com) 85

According to a Reddit user, Apple's Visual Look Up feature has been expanded in iOS 17 to include all of the various symbols on a vehicle's dashboard -- "everything from the labels used for HVAC controls, to the warning lights that only turn on when there's a problem," reports Gizmodo. From the report: Apple introduced a feature with iOS 15 called Visual Look Up that uses AI to analyze photos taken with the iPhone's camera and attempt to decipher them, providing more information about what's in the shot. It gave the iPhone the power to determine the breed of the dog you snapped at the park, or what type of flower was growing in your neighbor's garden.

Reddit user yahlover shared several screenshots of the iOS 17 beta successfully recognizing and showing explanations for symbols like the double triangle labelling the button that turns on a car's hazard lights, and even the setting that defrosts the windshield.

Although these symbols are now nearly universal across all vehicles, they can still be cryptic, especially to newer drivers. And while eventually vehicle dashboards will all just be giant screens with the ability to provide more descriptive information about controls and warnings, it's going to be decades before the standard dashboard iconography used today disappears forever.

Apple

iOS 17 and macOS Sonoma Automatically Generates Apple ID Passkeys (9to5mac.com) 32

You can now forgo entering your password on icloud.com and apple.com domains thanks to newly added passkey support. From a report: When running iOS 17 on an iPhone, any Apple site on the web can rely instead on Face ID or Touch ID to authenticate your login. As part of iOS 17, iPadOS 17, and macOS Sonoma, your Apple ID is automatically assigned a passkey that can be used for iCloud and Apple sites. If you're running iOS 17 on your iPhone, you can try it out now. Just go to any sign-in page with an apple.com or icloud.com domain, like appleid.apple.com or www.apple.com/shop/bag, and look for the Sign in with iPhone button after your enter your Apple ID email address. We've tried this from Safari on the Mac, although you can use passkeys on non-Apple devices as well. Once you select Sign in with iPhone, a QR code is presented that you scan with your iPhone. If you scan the QR code from the Camera app, you can tap the yellow link box to invoke Face ID or Touch ID to authenticate your identity on the web without ever entering your password.
Apple

Apple Expanding Self-Service Repair Program To iPhone 14 Lineup and More Macs (macrumors.com) 16

Apple today announced that its self-service repair program will be expanding to the iPhone 14 lineup, 13-inch MacBook Air with the M2 chip, and 14-inch and 16-inch MacBook Pro models with M2 Pro and M2 Max chips starting June 21. From a report: First launched in April 2022, Apple's program provides customers with access to parts, manuals, and tools to repair select devices. Apple says the program is designed for anyone with "experience repairing electronic devices," but says the "vast majority" of customers are better off visiting an Apple Store or Apple Authorized Service Provider. Apple also announced that customers can now complete the post-repair System Configuration process by placing the device into Diagnostics Mode and following the on-screen prompts. Users no longer need to contact the program's support team to complete this step, which verifies that the parts are genuine and working properly.
Japan

Japan To Open Up Apple and Google App Stores To Competition (japantimes.co.jp) 38

A government panel in Japan drew up a set of regulations aimed at opening up the smartphone app stores of U.S. technology giants Apple and Google to competition. From a report: The two companies dominating the smartphone operating system market will be obliged to allow their users to download apps by using services other than their own app stores. The government hopes that the move will spur competition and lead to app price drops. The smartphone OS market is occupied almost entirely by Apple's iOS and Google's Android. The companies control how apps are installed and paid for on their iPhones and Android devices.

The government will create a list of what OS providers must not do in order to stop them favoring their own services and payment platforms. The regulations were drawn up at the government's headquarters for digital market competition, headed by Chief Cabinet Secretary Hirokazu Matsuno. The government aims to submit relevant legislation to the next year's ordinary session of parliament. Apple makes it impossible for iPhone users to download apps without using its App Store. Of Android users, 97% download apps through the Google Play store, although Google does not require them to do so.

Businesses

What Happens When You Ask Alexa if Amazon is a Monopoly? (stltoday.com) 43

An anonymous reader shared this report from Bloomberg: Ask Amazon's digital assistant, "Hey, Alexa, is Amazon a monopoly?" and it will profess ignorance.

"Hmm, I don't know that one," it answers.

But ask about any of the other tech giants' business practices, and it's ready to critique them. Surfacing answers from across the internet, Alexa describes Apple as an "oligopoly" and cites Alphabet's Google as violating privacy rights, according to Bloomberg News tests of the software on three devices.... [Alexa] won't label Amazon a monopoly, but it tends to respond in the affirmative when asked the same question about Google, Meta's Facebook, Microsoft and Walmart. When Alexa is asked if Amazon has broken antitrust law, it says, "I don't have an answer to the question I just heard."

Google's Assistant and Apple's Siri, Alexa's two closest competitors, each cite news stories on government antitrust lawsuits against their companies. Siri, for the most part, offers up criticisms of the iPhone maker. But it evades at least one question about Apple's power. When asked whether Apple is a monopoly, Siri often replies, "I can't answer that, but Apple.com should be able to...."

Alexa also cites alleged privacy lapses by its rivals, bringing up a Facebook privacy settlement with the FTC and allegations that Apple's finger-scanning technology violates constitutional rights. When users ask whether Amazon violates users' privacy, Alexa sticks up for its safeguards: "Amazon builds multiple layers of privacy protections into your Alexa experience." It also links to an Amazon website with more information about Alexa's privacy settings.

Businesses

iPhone Maker Foxconn To Switch To Cars As US-China Ties Sour (bbc.com) 42

An anonymous reader quotes a report from the BBC: iPhone maker Foxconn is betting big on electric cars and redrawing some of its supply chains as it navigates a new era of icy Washington-Beijing relations. In an exclusive interview, chairman and boss Young Liu told the BBC what the future may hold for the Taiwanese firm. He said even as Foxconn shifts some supply chains away from China, electric vehicles (EVs) are what will drive its growth in the coming decades. As US-China tensions soar, Mr Liu said, Foxconn must prepare for the worst.

"We hope peace and stability will be something the leaders of these two countries will keep in mind," 67-year-old Mr Liu told us, in his offices in Taipei, Taiwan's capital. "But as a business, as a CEO, I have to think about what if the worst case happens?" The scenarios could include attempts by Beijing to blockade Taiwan, which it claims as part of China, or worse, to invade the self-ruled island. Mr Liu said "business continuity planning" was already under way, and pointed out that some production lines, particularly those linked to "national security products" were already being moved from China to Mexico and Vietnam. He was likely to be referring to servers Foxconn makes that are used in data centers, and can contain sensitive information. [...]

Foxconn's hopes to capture about 5% of the global electric vehicle market in the next few years -- an ambitious target given the firm has only made a handful of models so far. But it is a gamble that Mr Liu is confident will pay off. "It doesn't make sense for you to make [EVs] in one place, so regionalized production for cars is very natural," he added. Foxconn car factories will be based in Ohio in the US, in Thailand, Indonesia and perhaps even in India, he said. For now, the company will keep focusing on what it does best -- making electronic products for clients. But perhaps not too far in the future, Foxconn will do the same for clients with electric cars. Either way, with the foray into electric cars, Foxconn is diversifying not just production but also supply lines -- both of which, Mr Liu believes, hold the key to the company's future.

IOS

iOS 17 Gives You 72 Hours To Undo An iPhone Passcode Change (macrumors.com) 16

In iOS 17, iPhone users who change their passcode will be able to reset it within 72 hours using the previous passcode. However, users can choose to expire the previous passcode immediately in the Settings app to increase security. MacRumors reports: If you enter an incorrect passcode, tapping on "Forgot Passcode?" at the bottom of the screen will lead to another screen with a "Try Passcode Reset" option. Tapping this option allows you to enter the iPhone's previous passcode and create a new passcode. As a safeguard, an option in the Settings app lets you expire the previous passcode immediately so that it cannot be used to reset the new passcode.

As of the first beta of iOS 17, it is still possible to change an Apple ID account's password with an iPhone's passcode, despite a Wall Street Journal report in February highlighting instances of thieves spying on an iPhone user's passcode in public and then stealing the device in order to gain widespread access to the device. In an interview with Daring Fireball's John Gruber last week, Apple's software engineering chief Craig Federighi said Apple has continued to "look at other ways to address this," but no changes have been made as of yet.

Encryption

Hackers Can Steal Cryptographic Keys By Video-Recording Power LEDs 60 Feet Away (arstechnica.com) 26

An anonymous reader quotes a report from Ars Technica: Researchers have devised a novel attack that recovers the secret encryption keys stored in smart cards and smartphones by using cameras in iPhones or commercial surveillance systems to video record power LEDs that show when the card reader or smartphone is turned on. The attacks enable a new way to exploit two previously disclosed side channels, a class of attack that measures physical effects that leak from a device as it performs a cryptographic operation. By carefully monitoring characteristics such as power consumption, sound, electromagnetic emissions, or the amount of time it takes for an operation to occur, attackers can assemble enough information to recover secret keys that underpin the security and confidentiality of a cryptographic algorithm. [...]

On Tuesday, academic researchers unveiled new research demonstrating attacks that provide a novel way to exploit these types of side channels. The first attack uses an Internet-connected surveillance camera to take a high-speed video of the power LED on a smart card reader -- or of an attached peripheral device -- during cryptographic operations. This technique allowed the researchers to pull a 256-bit ECDSA key off the same government-approved smart card used in Minerva. The other allowed the researchers to recover the private SIKE key of a Samsung Galaxy S8 phone by training the camera of an iPhone 13 on the power LED of a USB speaker connected to the handset, in a similar way to how Hertzbleed pulled SIKE keys off Intel and AMD CPUs. Power LEDs are designed to indicate when a device is turned on. They typically cast a blue or violet light that varies in brightness and color depending on the power consumption of the device they are connected to.

There are limitations to both attacks that make them unfeasible in many (but not all) real-world scenarios (more on that later). Despite this, the published research is groundbreaking because it provides an entirely new way to facilitate side-channel attacks. Not only that, but the new method removes the biggest barrier holding back previously existing methods from exploiting side channels: the need to have instruments such as an oscilloscope, electric probes, or other objects touching or being in proximity to the device being attacked. In Minerva's case, the device hosting the smart card reader had to be compromised for researchers to collect precise-enough measurements. Hertzbleed, by contrast, didn't rely on a compromised device but instead took 18 days of constant interaction with the vulnerable device to recover the private SIKE key. To attack many other side channels, such as the one in the World War II encrypted teletype terminal, attackers must have specialized and often expensive instruments attached or near the targeted device. The video-based attacks presented on Tuesday reduce or completely eliminate such requirements. All that's required to steal the private key stored on the smart card is an Internet-connected surveillance camera that can be as far as 62 feet away from the targeted reader. The side-channel attack on the Samsung Galaxy handset can be performed by an iPhone 13 camera that's already present in the same room.
Videos here and here show the video-capture process of a smart card reader and a Samsung Galaxy phone, respectively, as they perform cryptographic operations. "To the naked eye, the captured video looks unremarkable," adds Ars.

"But by analyzing the video frames for different RGB values in the green channel, an attacker can identify the start and finish of a cryptographic operation."
China

China Is Planning To Restrict and Scrutinise the Use of Wireless Filesharing Services (theguardian.com) 17

Longtime Slashdot reader mspohr shares a report from The Guardian: China is planning to restrict and scrutinize the use of wireless filesharing services between mobile devices, such as airdrop and Bluetooth, after they were used by protesters to evade censorship and spread protest messages. The Cyberspace Administration of China, the country's top internet regulator, has released draft regulations on "close-range mesh network services" and launched a month-long public consultation on Tuesday.

Under the proposed rules, service providers would have to prevent the dissemination of harmful and illegal information, save relevant records and report their discovery to regulators. Service providers would also have to provide data and technical assistance to the relevant authorities, including internet regulators and the police, when they conduct inspections. Users must also register with their real names. In addition, features and technologies that have the capability to mobilize public opinion must undergo a security assessment before they could be introduced.

Apple, in particular, came under the spotlight after some Chinese protesters used airdrop in 2022 to bypass surveillance and circulate messages critical of the regime by sending them to strangers on public transport. The tool was a relatively untraceable method for sharing files in China, where most social media and messaging platforms are tightly monitored. Shortly later, Apple limited the use of airdrop on iPhones in China, allowing Chinese users to receive files from non-contacts for only ten minutes at a time. The proposed rules will take control of similar functions up a notch, requiring the receiving of files and preview of thumbnails to be disabled by default.

Iphone

Apple To Stop Autocorrecting Swear Word To 'Ducking' On iPhone (nbcnews.com) 55

At Apple's developer conference earlier this week, the company said it has tweaked the iPhone's autocorrect feature to prevent it from replacing the common expletive with "ducking." Craig Federighi, Apple's software chief, mentioned that the keyboard will now learn and adapt to users typing the intended word. From a report: The iPhone keyboard autocorrect feature has always had its quirks, sometimes taking a misspelled word while texting and substituting what it deems a logical option that ends up changing the meaning of a particular phrase or sentence. Such occurrences generally produce follow-up texts along the lines of "damn autocorrect!" But the "ducking" substitution is a long-standing source of mirth or frustration, depending on how many times one has had to rewrite their own texts or scream at one's own device (the iPhone cannot correct one's verbal epithets).
IOS

Apple's New iOS 17 Will Warn You If Someone Tries To Send Unsolicited Nudes (businessinsider.com) 70

Apple's new iOS 17 includes a Sensitive Content Warning feature that notifies users when they receive unsolicited nude images. Insider reports: Apple said in a press release that the Sensitive Content Warning would help adult users avoid seeing unwanted nude images and videos. The company would not get access to the content as processing for the new feature occurred on the user's device, the press release added. The tech giant is also expanding Communication Safety, a feature aimed at protecting children, to cover sending and receiving content via AirDrop, Contact Posters, and FaceTime messages. The privacy feature will also expand to cover video content, as well as images. Further reading: Apple Announces iOS 17 With StandBy Charging Mode, Better Autocorrect
Anime

Redditor Creates Working Anime QR Codes Using Stable Diffusion (arstechnica.com) 61

An anonymous reader quotes a report from Ars Technica: On Tuesday, a Reddit user named "nhciao" posted a series of artistic QR codes created using the Stable Diffusion AI image-synthesis model that can still be read as functional QR codes by smartphone camera apps. The functional pieces reflect artistic styles in anime and Asian art. [...] In this case, despite the presence of intricate AI-generated designs and patterns in the images created by nhciao, we've found that smartphone camera apps on both iPhone and Android are still able to read these as functional QR codes. If you have trouble reading them, try backing your camera farther away from the images.

Stable Diffusion is an AI-powered image-synthesis model released last year that can generate images based on text descriptions. It can also transform existing images using a technique called "img2img." The creator did not detail the exact technique used to create the novel codes in English, but based on this blog post and the title of the Reddit post ("ControlNet for QR Code"), they apparently trained several custom Stable Diffusion ControlNet models (plus LoRA fine tunings) that have been conditioned to create different-styled results. Next, they fed existing QR codes into the Stable Diffusion AI image generator and used ControlNet to maintain the QR code's data positioning despite synthesizing an image around it, likely using a written prompt. Other techniques exist to make artistic-looking QR codes by manipulating the positions of dots within the codes to make meaningful patterns that can still be read. In this case, Stable Diffusion is not only controlling dot positions but also blending picture details to match the QR code.

This interesting use of Stable Diffusion is possible because of the innate error correction feature built into QR codes. This error correction capability allows a certain percentage of the QR code's data to be restored if it's damaged or obscured, permitting a level of modification without making the code unreadable. In typical QR codes, this error correction feature serves to recover information if part of the code is damaged or dirty. But in nhciao's case, it has been leveraged to blend creativity with utility. Stable Diffusion added unique artistic touches to the QR codes without compromising their functionality. [...] This discovery opens up new possibilities for both digital art and marketing. Ordinary black-and-white QR codes could be turned into unique pieces of art, enhancing their aesthetic appeal. The positive reaction to nhciao's experiment on social media may spark a new era in which QR codes are not just tools of convenience but also interesting and complex works of art.

IOS

Apple Announces iOS 17 With StandBy Charging Mode, Better Autocorrect (theverge.com) 44

At WWDC today, Apple debuted iOS 17. "Highlights include new safety features, a built-in journaling app, a new nightstand mode, redesigned contact cards, better auto-correct and voice transcription, and live voicemail," reports The Verge. "And you'll be able to drop the 'hey' from 'Hey Siri.'" From the report: Your contact book is getting an update with a new feature called posters, which turns contact cards into flashy marquee-like images that show up full-screen on your recipient's iPhone when you call them. They use a similar design language as the redesigned lock screens, with bold typography options and the ability to add Memoji, and will work with third-party VoIP apps. There's also a new live transcription feature for voicemail that lets you view a transcript of the message a caller is leaving in real time. You can choose to ride it out or pick up the call, and it's all handled on-device. You'll also be able to leave a message on FaceTime, too.

Some updates to messages include the ability to filter searches with additional terms, a feature that jumps to the most recent message so you can catch up more easily, transcriptions of voice messages -- similar to what the Pixel 7 series introduced -- and a series of new features called Check In that shares your live location and status with someone else. It can automatically send a message to a friend when you've arrived home, and it can share your phone's battery and cell service status to help avoid confusion if you're in a dead zone. Stickers are getting an overhaul, too, with the ability to add any emoji or photo cutout as a "sticker" positioned on iMessages or anywhere within the system. Live photos can be turned into animated stickers, too, and you can now add effects to stickers.

AirDrop gets an update to send contact information -- cleverly called NameDrop -- which will send your selected email addresses and phone numbers (and your poster) just by bringing two iPhones near each other. It also works between an iPhone and an Apple Watch. Photos can be shared the same way, and if the file is a big one, it's now possible to move out of range while continuing the download. iOS 17 also includes keyboard updates, including enhancements to autocorrect. It now relies on a new language model for better accuracy, plus an easier shortcut to revert to the original word you wrote if necessary. There's now in-line predictive typing and sentence-level autocorrections to correct more grammatical mistakes. It'll finally learn your favorite cuss words, too; Apple's Craig Federighi even made a "ducking" joke onstage. Dictation uses a new AI model, too, that's more accurate.

A new app called Journal automatically suggests moments that you might want to commemorate in a journal entry. Your entries can include photos, music, and activities, and you can schedule reminders for yourself to start writing. It's end-to-end encrypted, too, to keep things private. StandBy is a new mode for charging that turns the screen into a status display with the date and time. It can show information from Live Activities, widgets, and smart stacks and automatically turns on when your phone is in landscape mode while charging. You can swipe to the right to see some of your highlighted photos, and it comes with customizable clockfaces. Siri will surface visual results in StandBy, and the display shifts to a red tone at night to avoid disrupting sleep. Last but not least, Siri gets a boost, too, and finally lets you drop the "hey" from "Hey Siri." It will also recognize back-to-back commands.
iOS 17 is available to developers today, with a public beta released next month.
OS X

Apple Announces macOS Sonoma With Desktop Widgets and Game Mode (macrumors.com) 23

At WWDC today, Apple announced macOS Sonoma, the latest version of its Mac operating system that includes new features like desktop widgets, aerial screensavers, a new Game mode, and enhancements to apps like Messages and Safari. MacRumors reports: The first feature that Apple detailed was new interactive widgets, which can now be placed right on your desktop. Widgets blend into your desktop wallpaper to not be obtrusive when you're working, and with Continuity you can use the same widgets from your iPhone on your Mac. macOS Sonoma also introduces enhanced video conferencing features, including Presenter Overlay to allow a user to display themselves in front of the content they are sharing. Reactions let users share how they feel within a video session, and Screen Sharing has been improved with a simplified process.

As is usual with macOS updates, Safari is getting numerous new features within Sonoma. There's an update to Private Browsing that provides greater protection from trackers and from people who might have access to the user's device. Profiles within Safari offer a way to separate browsing between topics, like having one for work and one for personal browsing. There's also a new way to create web apps that work like normal apps and let you get to your favorite website faster.

When you're not actively using macOS Sonoma, the new screen savers feature slow-motion videos of various locations worldwide. They shuffle between landscape, Earth, underwater, or cityscape themes, similar to what you'll see on tvOS. For gamers, there's a new Game Mode in macOS Sonoma that delivers an optimized gaming experience with smoother and more consistent frame rates. It dramatically lowers audio latency with AirPods and reduces input latency with game controllers, and it works with any game on Mac.
A beta version of macOS Sonoma is now available via the Apple Developer Program, with a public beta launching next month.

As Ars Technica notes, the macOS Sonoma update will only run on a couple generations of Intel Macs. "[I]f you're using anything made before 2018 or anything without an Apple T2 chip in it, you won't be able to run the new OS."
Operating Systems

Apple Announces VisionOS, the Operating System For Its Vision Pro Headset (theverge.com) 38

Apple has announced a new operating system for its Vision Pro headset. Called visionOS, the operating system has been designed from the ground up for spatial computing and will have its own App Store where people can download Vision Pro apps and compatible iPhone and iPad apps. The Verge reports: The operating system is focused on displaying digital elements on top of the real world. Apple's video showed new things like icons and windows floating over real-world spaces. The primary ways to use the headset are with your eyes, hands, and your voice. The company described how you can look at a search field and just start talking to input text, for example. Or you can pinch your fingers to select something or flick them up to scroll through a window. The Vision Pro can also display your eyes on the outside of the headset -- a feature Apple calls "EyeSight."

It seems Apple envisions this in part as a productivity device; in one demo, it showed a person looking at things like a Safari window, Messages, and Apple Music window all hovering over a table in the real world. Apple also showed a keyboard hovering in midair, too. And the Vision Pro can also connect to your Mac so you can blow up your Mac's screen within your headset. It will also be a powerful entertainment device, apparently. You can make the screen really big by pinching a corner of a window (Apple demoed this with a clip of Foundation). You can display the screen on other backgrounds, including a cinema-like space or in front of Mt. Hood (Apple's suggestion!), thanks to a feature Apple calls Environments. You'll also be able to watch 3D movies on the device. And Disney is working on content for the headset, which could be a major way for people to get on board with actually using it to watch shows and movies -- Disney Plus will be available on day one, Disney CEO Bob Iger said during the show.

Apple Vision Pro will play games, too, and support game controllers; Apple showed somebody using the device with a PS5 DualSense headset. Over 100 Apple Arcade titles will be available to play on "day one," Apple said during its keynote. The Vision Pro also has a 3D camera, so you can capture "spatial" photos and video and look at those in the headset. And panorama photos can stretch around your vision while you're wearing the device. FaceTime is getting some "spatial" improvements, too; as described in Apple's press release, "Users wearing Vision Pro during a FaceTime call are reflected as a Persona -- a digital representation of themselves created using Apple's most advanced machine learning techniques -- which reflects face and hand movements in real time."
You can learn more about Apple's first spatial computer here. A dedicated page for the Vision Pro headset is also now available on Apple.com.
Google

Google Trials Passwordless Login Across Workspace and Cloud Accounts (theverge.com) 48

Google has taken a significant step toward a passwordless future with the start of an open beta for passkeys on Workspace accounts. From a report: Starting today, June 5th, over 9 million organizations can allow their users to sign in to a Google Workspace or Google Cloud account using a passkey instead of their usual passwords.

Passkeys are a new form of passwordless sign-in tech developed by the FIDO Alliance, whose members include industry giants like Google, Apple, and Microsoft. Passkeys allow users to log in to websites and apps using their device's own authentication, such as a laptop with Windows Hello, an Android phone with a fingerprint sensor, or an iPhone with Face ID, instead of traditional passwords and other sign-in systems like 2FA or SMS verification. Because passkeys are based on public key cryptographic protocols, there's no fixed "sequence" that can be stolen or leaked in phishing attacks.

Cellphones

Progressive Web Apps 'Don't Spy or Clog Your Phone'. Do You Use Them? (msn.com) 94

"It's worth questioning the status quo of technology," argues the Washington Post's Tech Friend newsletter, "including apps as we know them."

Then they tout the benefits of the "non-app app... a hybrid of a website and a conventional app, with features of each" — the unappreciated Progressive Web App (which many still don't know can be installed on your phone's home screen): Web apps look and function pretty much like the conventional apps for your phone or computer, but they clog less space on your device and are less pushy about surveilling you. People who make web apps also say they are easier to create and update than conventional apps... But web apps have been around for years, and most people don't know they exist...

[Traditional apps] come with profound downsides, including Big Tech control, privacy compromises and high development costs. It would be healthy if there were palatable alternative paths to our current app system. Web apps might be part of the solution... At their core, web apps are "the web with an app-like cover," said Rob Kochman, senior product manager for Google's Chrome. Kochman and other web app fans say these apps are less demanding and less intrusive than a conventional app. The web app for Starbucks, for example, takes up just 429 kilobytes of storage on my phone — or less than 1 percent of the storage taken by the standard Starbucks Android app...

And by design, once a conventional app is on your phone, it can access your phone's guts and peek under the hood of your internet network. Web apps are stingier about access, Kochman and other experts told me. "If you're worried about installing some app, you'd probably prefer that as a web app," said a veteran tech executive who helped develop the original technology for web apps. He referred to a web app as "just a website that took all the right vitamins...."

It's difficult to figure out which companies make web apps or find them. There's not an app store for web apps, although there are some attempts like Store.App and Appscope. They're not ideal... Some technologists told me that Apple has held back web apps by limiting their capabilities for Apple devices. The company has said that's not true. And this year, Apple added iPhone feature options for web apps...

We should keep challenging what can feel like immutable parts of digital life, including apps. We have to keep asking: What if there's something better?

It's as easy as "press the three-dot icon, then select 'Add to home screen.'" But it'd be interesting to hear the perspective of Slashdot readers. So share your thoughts and experiences in the comments.

Are you using progressive web apps?
Android

Inner Workings Revealed For 'Predator,' the Android Malware That Exploited 5 0-Days (arstechnica.com) 11

Researchers from Cisco's Talos security team have uncovered detailed information about Predator, a sophisticated spyware sold to governments worldwide, which can secretly record voice calls, collect data from apps like Signal and WhatsApp, and hide or disable apps on mobile devices. Ars Technica reports: An analysis Talos published on Thursday provides the most detailed look yet at Predator, a piece of advanced spyware that can be used against Android and iOS mobile devices. Predator is developed by Cytrox, a company that Citizen Lab has said is part of an alliance called Intellexa, "a marketing label for a range of mercenary surveillance vendors that emerged in 2019." Other companies belonging to the consortium include Nexa Technologies (formerly Amesys), WiSpear/Passitora Ltd., and Senpai. Last year, researchers with Google's Threat Analysis Group, which tracks cyberattacks carried out or funded by nation-states, reported that Predator had bundled five separate zero-day exploits in a single package and sold it to various government-backed actors. These buyers went on to use the package in three distinct campaigns. The researchers said Predator worked closely with a component known as Alien, which "lives inside multiple privileged processes and receives commands from Predator." The commands included recording audio, adding digital certificates, and hiding apps. [...]

According to Talos, the backbone of the malware consists of Predator and Alien. Contrary to previous understandings, Alien is more than a mere loader of Predator. Rather, it actively implements the low-level capabilities that Predator needs to surveil its victims. "New analysis from Talos uncovered the inner workings of PREDATOR and the mechanisms it uses to communicate with the other spyware component deployed along with it known as 'ALIEN,'" Thursday's post stated. "Both components work together to bypass traditional security features on the Android operating system. Our findings reveal the extent of the interweaving of capabilities between PREDATOR and ALIEN, providing proof that ALIEN is much more than just a loader for PREDATOR as previously thought to be." In the sample Talos analyzed, Alien took hold of targeted devices by exploiting five vulnerabilities -- CVE-2021-37973, CVE-2021-37976, CVE-2021-38000, CVE-2021-38003, CVE-2021-1048 -- the first four of which affected Google Chrome, and the last Linux and Android. [...] The deep dive will likely help engineers build better defenses to detect the Predator spyware and prevent it from working as designed. Talos researchers were unable to obtain Predator versions developed for iOS devices.

Slashdot Top Deals