Android

Samsung's DeX On Note 10 Brings Phone Apps To Your PC (engadget.com) 32

Earlier today at Samsung's Galaxy Note 10 launch event, Samsung announced several new features coming to DeX, an application that transforms your Samsung phone into a "desktop like" interface. The expanded version of DeX on the Note 10 now works with your computer, allowing you to transfer files (including photos), reply to messages and run mobile apps on your Mac or Windows PC. Engadget reports: The Note 10 also touts a Link to Windows option in the phone's Quick Panel that connects to a Windows 10 PC, sharing your phone's notifications on your PC screen with no specialized apps required. This concept also isn't completely new, but it's still helpful if you'd rather not check your phone for a must-see message or app alert. More Microsoft integrations are coming. You'll get to make and receive calls right from your PC (it's not clear if this is just for Samsung phones or for all Android devices). Samsung's Gallery app, meanwhile, will tie into OneDrive to upload photos to cloud storage. If the company has its way, your phone and computer will feel like extensions of each other.
Chrome

Google Expands its Advanced Protection Program To Chrome (venturebeat.com) 30

Google is expanding its Advanced Protection Program to its Chrome browser. From a report: If you're an Advanced Protection Program user and you have sync turned on in Chrome, you will now automatically receive stronger protections against risky downloads. Google didn't go into much detail regarding the protections, likely not to publicly give away how they work. But the company did say that when users attempt to download "certain risky files," Chrome will now show additional warnings, or in some cases even block the downloads outright. The warnings are, however, only available in Chrome for Windows, Mac, and Linux. Google is not rolling out the Advanced Protection Program to Chrome for Android and iOS.
Operating Systems

Why Canonical Views the Snap Ecosystem as a Compelling Distribution-Agnostic Solution (techrepublic.com) 93

Canonical's Martin Wimpress addresses Snaps, Flatpak, and other competing standards, and community unease around Canonical's control of the Snap store. intensivevocoder writes: With these advances in hardware support, the last significant challenge users face when switching from Windows or Mac to a Linux distribution is app distribution and installation. While distribution-provided repositories are useful for most open source software, the release model of distributions such as Ubuntu or Fedora lock in users to a major version for programs for the duration of a particular release. Because of differences in how they interact with the underlying system, certain configuration tasks are different between Snaps or Flatpaks than for directly-installed applications. Likewise, initial commits for the Snap and Flatpak formats were days apart -- while the formats were developed essentially in parallel, the existence of two 'universal' package formats has led to disagreement about competing standards. TechRepublic interviewed Martin Wimpress, engineering manager for Snapcraft at Canonical, about Ubuntu's long term plans for Snaps, its adoption and support in other Linux distributions, Canonical's position as the operator of the Snap Store, and the benefits Snaps provide over Flatpak. An excerpt from the interview: TechRepublic: Practically speaking, there are two competing standards for cross-platform application packaging -- three, if you count AppImage. What's the practical benefit that Canonical's Snap format offers over Flatpak or AppImage?
Martin Wimpress: If you look at the initial commits of both of those projects, Snaps have a lineage back to Click packages, which were developed for [Ubuntu Phone] originally. The Snap project developed out of what had been learned from doing the phones, with a view to solving problems in IoT. So, although technically snapd and xdg-apps -- and consequently Flatpak -- look like they emerged around the same time, Snaps can trace their lineage back to the Click project from several years previous. If we're looking at Flatpak specifically, we can probably include AppImage in most of these comparisons as well. Some of the similarities are that Snaps are self-contained software packages, which is something that Flatpak and AppImage strive to be as well. I think that Flatpak achieves that better than AppImage. I think AppImage still makes some assumptions on what's installed on the host operating system. It doesn't bundle everything inside the AppImage. Similarly, Snaps, Flatpak, and AppImage work across all the major Linux distributions without modification. We haven't all arrived at this solution by accident. We've clearly, independently, all realized that this is a problem that we need to solve in order to encourage software vendors to publish their applications on Linux, because Linux is a very broad platform to target. If you can lower the hurdles... to getting your software in front of users on Linux, then that's a good thing. And we're all aiming to do the same thing there.

Chrome

Chrome 76 Arrives With Flash Blocked By Default (venturebeat.com) 87

An anonymous reader shares a report from VentureBeat: Google today launched Chrome 76 for Windows, Mac, Linux, Android, and iOS. The release includes Adobe Flash blocked by default, Incognito mode detection disabled, multiple PWA improvements, and more developer features. You can update to the latest version now using Chrome's built-in updater or download it directly from google.com/chrome. Google has been taking baby steps to kill off Flash for years. In 2015, Chrome started automatically pausing less important Flash content. In 2016, Chrome started blocking "behind the scenes" Flash content and using HTML5 by default. In July 2017, however, Adobe said it would kill Flash by 2020. With Chrome 76, Flash is now blocked by default. Users can still turn it on in settings, but next year, Flash will be removed from Chrome entirely.
Security

Apple's AWDL Protocol Plagued By Flaws That Enable Tracking and MitM Attacks (zdnet.com) 56

Apple Wireless Direct Link (AWDL), a protocol installed on over 1.2 billion Apple devices, contains vulnerabilities that enable attackers to track users, crash devices, or intercept files transferred between devices via man-in-the-middle (MitM) attacks. From a report: These are the findings of a research project that started last year at the Technical University of Darmstadt, in Germany, and has recently concluded, and whose findings researchers will be presenting later this month at a security conference in the US. The project sought to analyze the Apple Wireless Direct Link (AWDL), a protocol that Apple rolled out in 2014 and which also plays a key role in enabling device-to-device communications in the Apple ecosystem. While most Apple end users might not be aware of the protocol's existence, AWDL is at the core of Apple services like AirPlay and AirDrop, and Apple has been including AWDL by default on all devices the company has been selling, such as Macs, iPhones, iPads, Apple watches, Apple TVs, and HomePods. But in the past five years, Apple has never published any in-depth technical details about how AWDL works. This, in turn, has resulted in very few security researchers looking at AWDL for bugs or implementation errors.
China

Trump Says Apple Will Not Be Given Tariff Waivers or Relief For Mac Pro Parts Made In China (cnbc.com) 210

An anonymous reader quotes a report from CNBC: In a tweet on Friday, President Trump said his administration will not grant Apple any relief on Mac Pro parts made in China. "Apple will not be given Tariff wavers (sic), or relief, for Mac Pro parts that are made in China," President Trump said. "Make them in USA, no Tariffs!" Apple asked for waivers on tariffs on the Mac Pro. Apple said it wanted to be exempt on some parts it uses for the new Mac Pro, including a power supply unit, the stainless-steel enclosure, finished mice and trackpads and circuit boards. "There are no other sources for this proprietary, Apple-designed component," Apple said in a filing. Apple shifted production of the Mac Pro to China in June, saving shipping costs for components that are supplied near Shanghai.
Desktops (Apple)

Dropbox Irks Mac Users With Annoying Dock Icon, Offers Clueless Support (arstechnica.com) 67

An anonymous reader quotes a report from Ars Technica: Dropbox now opens a new file browser and an associated Dock icon every time it starts, even if you don't want it to. If you're not familiar with Macs, the Dock is the line of applications on the bottom of the screen (or the side, if you've moved it in the settings) and serves the same function as the Windows Taskbar. If my computer restarts or if Dropbox restarts, the new Dropbox window that I don't want pops up in the Dock. This isn't a huge deal, as I can quit Dropbox's new file browser and get rid of that Dock icon each time my computer starts up. I'm not going to stop using Dropbox -- I've been paying the company $138 a year for 2TB of storage and for 12 months' worth of file history, which saves all deleted files and revisions to files. (It's going up to $158 next time I get billed, in February.) It's worth it to me because Dropbox still works great, while the alternatives have always been unreliable or disappointing in other ways when I've tried them. I'll get into that more later in this article.

But the Dock icon and window is a major change in how Dropbox presents itself to users. Dropbox has always been the kind of application that is there when you need it and gets out of the way when you don't. Dropbox's syncing and file-sharing features are integrated with the Finder (the Mac file manager), and there's a little icon in the Mac's Menu Bar at the top of the screen for when you need to change a setting. But now, Dropbox wants to be front and center at all times. The company built its own file browser to replace what's already available in the Mac Finder, and it opens that new file manager every time Dropbox starts. We wrote about it last week when Dropbox started rolling it out to more users. I've had it for more than a month since I somehow ended up in Dropbox's Early Access program.
Ars' Jon Brodkin, the author of the article, also discovered that "there are numerous Dropbox support employees who apparently have never used their company's Mac application and do not understand how it works." Specifically, the employees Brodkin talked to didn't know "that it's possible for Mac applications to run without a Dock icon even though that's exactly how Dropbox worked for a decade... And they've been giving bad advice to users who want to change back to the old way of doing things."
Privacy

Bluetooth Exploit Can Track and Identify iOS, Microsoft Mobile Device Users (zdnet.com) 24

A flaw in the Bluetooth communication protocol may expose modern device users to tracking and could leak their ID, researchers claim. From a report: The vulnerability can be used to spy on users despite native OS protections that are in place and impacts Bluetooth devices on Windows 10, iOS, and macOS machines. This includes iPhones, iPads, Apple Watch models, MacBooks, and Microsoft tablets & laptops. On Wednesday, researchers from Boston University David Starobinski and Johannes Becker presented the results of their research at the 19th Privacy Enhancing Technologies Symposium, taking place in Stockholm, Sweden. According to the research paper, Tracking Anonymized Bluetooth Devices, many Bluetooth devices will use MAC addresses when advertising their presence to prevent long-term tracking, but the team found that it is possible to circumvent the randomization of these addresses to permanently monitor a specific device. Android is immune as the OS does not continually send out advertising messages, the researchers said.
Security

Apple Pushes a Silent Mac Update To Remove Hidden Zoom Web Server (techcrunch.com) 62

Apple has released a silent update for Mac users removing a vulnerable component in Zoom, the popular video conferencing app, which allowed websites to automatically add a user to a video call without their permission. TechCrunch reports: The Cupertino, Calif.-based tech giant told TechCrunch that the update -- now released -- removes the hidden web server, which Zoom quietly installed on users' Macs when they installed the app. Apple said the update does not require any user interaction and is deployed automatically. Although Zoom released a fixed app version on Tuesday, Apple said its actions will protect users both past and present from the undocumented web server vulnerability without affecting or hindering the functionality of the Zoom app itself. The update will now prompt users if they want to open the app, whereas before it would open automatically.
Firefox

Firefox 68 Arrives With Darker Reader View, Recommended Extensions, and IT Customizations (venturebeat.com) 69

Mozilla today launched Firefox 68 for Windows, Mac, Linux, Android, and iOS. Firefox 68 includes a darker reader view, recommended extensions, IT Pro customizations, and more. From a report: As part of this release, Mozilla has curated a list of recommended extensions "that have been thoroughly reviewed for security, usability, and usefulness." You can find the list on the Get Add-ons page in the Firefox Add-ons Manager (about:addons). While Firefox has had dark mode for months, the Reader View's dark contrast only covered the text area. Now, when you change the contrast to dark, all sections of the site (including sidebars and toolbars) will be immersed in dark mode.

With Firefox 60, Mozilla introduced an enterprise version of the browser that employers can customize. This let IT professionals configure Firefox for their organization, either using Group Policy on Windows or a JSON file that works across Windows, Mac, and Linux. With Firefox 68, Mozilla has added more enterprise policies -- to configure or remove the new tab page, turn off search suggestions, and so on.

Security

Serious Zoom Security Flaw Could Let Websites Hijack Mac Cameras (theverge.com) 54

Security researcher Jonathan Leitschuh has publicly disclosed a serious zero-day vulnerability for the Zoom video conference app on Macs that could allow websites to turn on user cameras without permission. The Verge reports: He has demonstrated that any website can open up a video-enabled call on a Mac with the Zoom app installed. That's possible in part because the Zoom app apparently installs a web server on Macs that accepts requests regular browsers wouldn't. In fact, if you uninstall Zoom, that web server persists and can reinstall Zoom without your intervention. Leitschuh details how he responsibly disclosed the vulnerability to Zoom back in late March, giving the company 90 days to solve the problem. According to Leitschuh's account, Zoom doesn't appear to have done enough to resolve the issue. The vulnerability was also disclosed to both the Chromium and Mozilla teams, but since it's not an issue with their browsers, there's not much those developers can do. The report notes that you can "patch" the vulnerability by making sure the Mac app is up to date and also disabling the setting that allows Zoom to turn your camera on when joining a meeting. "Again, simply uninstalling Zoom won't fix this problem, as that web server persists on your Mac," reports The Verge. "Turning off the web server requires running some terminal commands, which can be found at the bottom of the Medium post."
Portables (Apple)

Apple May Ditch the Butterfly Keyboard (9to5mac.com) 138

AmiMoJo writes: Apple is apparently set to ditch the butterfly mechanism used in MacBooks since 2015, which has been the root of reliability issues and its low-travel design has also not been popular with many Mac users. A report published today says that Apple will roll out a new keyboard design based on scissor switches, offering durability and longer key travel, starting with the 2019 MacBook Air. The MacBook Pro is also getting the new scissor switch keyboard, but not until 2020. The new scissor switch keyboard is a whole new design than anything previously seen in a MacBook, purportedly featuring glass fiber to reinforce the keys.
Portables (Apple)

Apple Finds Issue With Logic Board In Some 2018 MacBook Airs, Offers Free Repair (9to5mac.com) 42

Apple says a "very small number" of MacBook Air models have an issue with the main logic board and can be replaced at no cost to customers. 9to5Mac reports: Apple's memo to repair staff notes that it has identified "an issue" with the main logic board specifically in Retina, 13-inch, 2018 MacBook Air models with certain serial numbers. Apple will be emailing customers with machines with the serial numbers they've identified as being affected, otherwise customers can take their machine to Apple Stores or authorized repair staff to have their devices checked out. Apple's documents list symptoms as issues with "power," but do not elaborate on what problems users are experiencing exactly. A quick search online for problems with the 2018 MacBook Air logic board shows reports back to when the device first launched with some users' machines not able to power on at all. The affected machines will be covered for four years from the original purchase date. Users that think they might be experiencing the issue can take their MBA to Apple Stores or an Apple authorized service provider.
Chrome

Ask Slashdot: What's Your 'Backup' Browser? (komando.com) 237

Slashdot's gotten over 17,000 votes in its poll about which web browser people use on their desktop. (The current leader? Firefox, with 53% of the vote, followed by Chrome with 30%.)

But Slashdot reader koavf asks an interesting follow-up question: "What's everyone's go-to Plan B browser and why?"

To start the conversation, here's how James Gelinas (a contributor at Kim Komando's tech advice site) recently reviewed the major browsers:
  • He calls Chrome "a safe, speedy browser that's compatible with nearly every page on the internet" but also says that Chrome "is notorious as a resource hog, and it can drastically slow your computer down if you have too many tabs open."

    "Additionally, the perks of having your Google Account connected to your browser can quickly turn into downsides for the privacy-minded among is. If you're uncomfortable with your browser knowing your searching and spending behaviors, Chrome may not be the best choice for you."
  • He calls Firefox "the choice for safety".

    "Predating Chrome by 6 years, Firefox was the top choice for savvy Netizens in the early Aughts. Although Chrome has captured a large segment of its user base, that doesn't mean the Fox is bad. In fact, Mozilla is greatly appreciated by fans and analysts for its steadfast dedication to user privacy... Speedwise, Firefox isn't a slouch either. The browser is lighter weight than Chrome and is capable of loading some websites even faster."
  • He calls Apple's Safari and Microsoft Edge "the default choice...because both of these browsers come bundled with new computers."

    "Neither one has glaring drawbacks, but they tend to lack some of the security features and extensions found in more popular browsers. Speedwise, however, both Edge and Safari are able to gain the upper hand against their competition. When it comes to startup time and functions, the apps are extremely lightweight on your system's resources. This is because they're part of the Mac and Window's operating systems, respectively, and are optimized for performance in that environment."

Finally, he gives the Tor browser an honorable mention. ("It's still one of the best anonymous web browsers available. It's so reliable, in fact, that people living under repressive governments often turn to it for their internet needs -- installing it on covert USB sticks to use on public computers.") And he awards a "dishonorable mention" to Internet Explorer. ("Not only is the browser no longer supported by Microsoft, but it's also vulnerable to a host of malware and adware threats.")

But what do Slashdot's readers think? Putting aside your primary desktop browser -- what's your own go-to "Plan B" web browser, and why? Leave your best answers in the comments.

What's your "backup" browser?


Security

New Mac Malware Abuses Recently Disclosed Gatekeeper Zero-Day (zdnet.com) 53

puddingebola writes: In May, security researcher Filippo Cavallarin made public a vulnerability in macOS's Gatekeeper. The vulnerability can allow an attacker to use a symlink and an NFS server to bypass Gatekeepers authentication and run malicious code. The malware has been named OSX/Linker and has been tied to the same group that operates the OSX/Surfbuyer adware. All macOS versions are affected, including the latest 10.14.5, and Apple has yet to release a patch to this day, a full month after Cavallarin's public disclosure.
Desktops (Apple)

Apple Moves Mac Pro Production To China (cnbc.com) 89

Apple is manufacturing its new Mac Pro computer in China (Warning: source paywalled; alternative source), shifting abroad production of what had been its only major device assembled in the U.S. The Wall Street Journal reports: The tech giant has tapped Taiwanese contractor Quanta Computer Inc. to manufacture the $6,000 desktop computer and is ramping up production at a factory near Shanghai, the people said. Apple can save on shipping costs for components given the proximity of many of its suppliers to Shanghai, rather than having to supply a factory in the U.S. While the Mac Pro isn't one of Apple's higher-volume products, the decision on where to make it carries outsize significance. Apple's reliance on factories in China to manufacture its products has been an issue for the company, especially under President Trump, who has pressured Apple and other companies to make more in the U.S. An Apple spokesman said the new Mac Pro is designed and engineered in the U.S. and includes U.S.-made components. Apple said it supports manufacturing in 30 U.S. states and spent $60 billion last year with more than 9,000 U.S. suppliers.

"Final assembly is only one part of the manufacturing process," the spokesman said, adding that the company's investments support two million American jobs.
Apple

Jony Ive, iPhone Designer, Leaving Apple To Form Independent Company (bloomberg.com) 100

Apple's chief designer Jony Ive is leaving after decades at the iPhone maker to form an independent company -- with Apple as one of its primary clients. Ive was at Apple for more than two decades in which his iconic designs for the Mac, iPod and iPhone turned one of Silicon Valley's faded giants into the world's most valuable company and defined a generation of consumer products. From a report: "Jony is a singular figure in the design world and his role in Apple's revival cannot be overstated, from 1998's groundbreaking iMac to the iPhone and the unprecedented ambition of Apple Park," Chief Executive Officer Tim Cook said in a statement. "Apple will continue to benefit from Jony's talents by working directly with him on exclusive projects, and through the ongoing work of the brilliant and passionate design team he has built." Ive will be replaced by existing Apple designers. Evans Hankey, vice president of Industrial Design, and Alan Dye, vice president of Human Interface Design, will report to Jeff Williams, Apple's chief operating officer, the company said. In an interview with Financial Times, Ive said: "While I will not be an [Apple] employee, I will still be very involved -- I hope for many, many years to come. This just seems like a natural and gentle time to make this change."
Iphone

Apple Hires Key Chip Designer From ARM As Own Efforts Ramp Up (bloomberg.com) 38

Apple has hired one of ARM's top chip engineers as the iPhone maker looks to expand its own chip development to more powerful devices, including the Mac, and new categories like a headset. Bloomberg reports: The company hired Mike Filippo in May for a chip architect position, according to his LinkedIn profile. At ARM, Filippo was a lead engineer behind chip designs that power the vast majority of the world's smartphones and tablets and was leading a new push into parts for computers. ARM, owned by SoftBank, designs microprocessors and licenses technology that is fundamental to the chip development efforts of Apple, Samsung, Qualcomm and Huawei.

Prior to his work at ARM, Filippo was also a key designer at chipmakers Advanced Micro Devices and Intel. For Apple, the hire could help fill the void left by the departure of Gerard Williams III earlier this year. Williams was Apple's head architect of chips used in the iPhone and iPad. Apple's A series chips power its mobile devices using ARM technology. Its Mac computers have used processors from Intel for nearly two decades.

IOS

Apple Releases First Public Betas of macOS Catalina, iOS 13 and iPadOS 61

Apple today seeded the first beta versions of upcoming macOS Catalina update, iOS 13 update, and iPadOS update to its public beta testing group, giving non-developers a chance to try out the software ahead of their fall public release. Beta testers who have signed up for Apple's beta testing program will be able to download the macOS Catalina beta through the Software Update mechanism in System Preferences after installing the proper profile. Those who want to be a part of Apple's beta testing program can sign up to participate through the beta testing website, which gives users access to iOS, macOS, and tvOS betas. Similarly, beta testers who have signed up for Apple's beta testing program will receive the iOS 13 beta update over-the-air after installing the proper certificate on an iOS device. New features in macOS Catalina update includes: macOS Catalina eliminates the iTunes app, which has been a key Mac feature since 2001. In Catalina, iTunes has been replaced by Music, Podcasts, and TV apps. The new apps can do everything that iTunes can do, so Mac users aren't going to be losing any functionality, and device management capabilities are now handled by the Finder app. macOS Catalina has a useful new Sidecar feature, designed to turn the iPad into a secondary display for the Mac. For those with an Apple Watch set up to unlock the Mac, there's now an option to approve security prompts in Catalina by tapping on the side button of the watch. Macs with a T2 chip in them also support Activation Lock, making them useless to thieves much as it does on the iPhone. There's a new Find My app that lets you track your lost devices, and previously, this functionality was only available via iCloud on the Mac. There's even a new option to find your devices even when they're offline by leveraging Bluetooth connections to other nearby devices, something that's particularly handy on the Mac because it doesn't have a cellular connection. For developers, a "Project Catalyst" feature lets apps designed for the iPad be ported over to the Mac with just a few clicks in Xcode and some minor tweaks. Apple's ultimate goal with Project Catalyst is to bring more apps to the Mac.
Programming

Apple's First Four iOS Apps For Mac Are Getting an Upgrade (cnet.com) 35

Apple is counting on apps built for the iPad and the iPhone being converted to the Mac as a way to infuse new energy -- and a lot of new software -- into the granddaddy of its devices. From a report: The party started last year at WWDC 2018 when Apple announced a "sneak peek" at four of its own apps that it converted from iOS to MacOS. Those four were News, Voice Memos, Home and Stocks. But when the apps showed up in MacOS Mojave, they weren't greeted with much enthusiasm from Mac users because all four were rudimentary at best and didn't take advantage of the Mac's extra capabilities. Good news. Apple is fixing them. At WWDC 2019 earlier this month, Apple announced Project Catalyst, which streamlines the process for all software makers to bring their own iOS apps to Mac.

In an interview with CNET at WWDC, Apple software chief Craig Federighi confirmed that the four iOS apps for Mac released last year will get major updates based on the new technology in Project Catalyst. But he also revealed that the apps will get new designs to make them more Mac-like. "They're getting improvements," Federighi said. "The underlying technology has matured...Some of that is super low-level stuff. Some people have dissected those apps and realized that they were sort of two halves: an AppKit half and a UIKit half, literally running in different processes. That's all unified now. This has become much more of a native Mac framework...So automatically, the apps we built last year are upgraded."

Slashdot Top Deals