×
Technology

Meta's VR Headsets Have a Sweat-Sharing Problem (bloomberg.com) 52

It's the busiest shopping season of the year, but one item that doesn't appear to be flying off store shelves is Meta Platforms's Quest brand of virtual-reality headsets. Part of the reason is that many shoppers aren't comfortable trying one on in a store. From a report: The headsets are prone to collect dirt and grime and smear your makeup. During the peak of the Covid-19 pandemic, people were especially resistant to put them on in stores, even though Meta paid to have cleaners on hand to sanitize the headsets between each use, said a former Meta employee who wasn't authorized to speak publicly and asked not to be identified.

The health emergency is over, but many people are still weirded out by the idea of putting on a VR headset in public. Meta sells the Quest in the US through the stores of mobile carriers like AT&T, T-Mobile and Verizon. The thinking was, people are already trying out and buying other gadgets there. But picking up a phone that other people have touched feels different than strapping something to your face that other people have strapped to theirs. In-store sales of Quest headsets at mobile carriers' locations are very low, according to former employees of Reality Labs, the division that builds Meta's VR products.

Google

Google Warns China Is Ramping Up Cyberattacks Against Taiwan (bloomberg.com) 15

China is waging a growing number of cyberattacks on neighboring Taiwan, according to cybersecurity experts at Alphabet's Google. From a report: Google has observed a "massive increase" in Chinese cyberattacks on Taiwan in the last six months or so, said Kate Morgan, a senior engineering manager in Google's threat analysis division, which monitors government-sponsored hacking campaigns. Morgan warned that Chinese hackers are employing tactics that make their work difficult to track, such as breaking into small home and office internet routers and repurposing them to wage attacks while masking their true origin.

"The number of groups in China that are performing hacking and trying to get into technology companies or get into cloud customers is huge," Morgan said. "I don't have the exact number, but it is probably over 100 groups that we are tracking just out of China alone." The hackers are going "after everything," including defense sector, government and private industry on the island, she said. Google's findings come as concerns have grown over the prospect of a conflict in Taiwan. The relationship between the US -- Taiwan's top military backer -- and China has deteriorated in recent years over a wide range of issues including Taiwan, human rights and a race to dominate advanced technologies such as chips, quantum computing and artificial intelligence.

Android

Microsoft Phone Link May Soon Let You Use Your Android Phone As a Webcam (androidauthority.com) 35

Microsoft Phone Link, previously known as Microsoft Your Phone, lets you control your Android phone from your computer. Now, the company appears to be working on letting you use your Android phone as a webcam with Windows computers, similar to how you can use your iPhone as a webcam on Mac. Android Authority reports: Microsoft's Link to Windows v1.23102.190.0 for Android app includes code that suggests that the company is working on letting your Android phone provide a video stream to your Windows PC. This would effectively allow it to be used as a webcam. [...] These strings indicate that once Microsoft's Phone Link app is working on both connected devices, users would be able to start a camera stream that lets their phone's camera be available to their Windows PC. The strings do not explicitly mention "webcam," but other clues indicate that the feature would be related to video calls in some ways.

Phone Link can already access your camera and video conferencing apps, but this is just mirroring apps running on your phone. What you see on your phone screen is what you see on the computer. If you record a video, it gets saved to your phone as typical video recordings do. With the new functionality spotted above, Phone Link could potentially compete against Apple's Continuity Camera features. With Continuity Camera, users can mount their iPhone to their Mac and then use the iPhone's camera and microphone for FaceTime or other camera apps.

Transportation

Traffic Pollution Can Cause Rise In Blood Pressure, Study Finds (theguardian.com) 22

An anonymous reader quotes a report from The Guardian: Air pollution from traffic can cause a significant rise in blood pressure that can last up to 24 hours, according to a study via the University of Washington. The spike is comparable to the effect of a high-sodium diet and can contribute to cardiovascular problems. Long-term exposure to vehicle exhaust has been widely linked with respiratory problems such as asthma, especially in children. "Traffic air pollution increases blood pressure within an hour of being in traffic and it stays elevated a day later," said author of the study Joel Kaufman, a physician and professor of environmental and occupational health sciences at the University of Washington.

Sixteen healthy people between the ages of 22 and 45 underwent three separate drives as passengers through Seattle rush hour. Two of those drives were "unfiltered," meaning the road air was allowed to enter the car, as is the case for many drivers on the road today. On the third drive, a Hepa (high efficiency particulate absorbing) filter was installed in the car, with participants unaware which drive had filtration. The researchers measured the blood pressure of the passengers before, during and after the two-hour drive. Breathing unfiltered air resulted in blood pressure increase of more than 4.5mm Hg (millimeters of mercury) compared to filtered air. Most of the pollution came from tailpipe exhaust or the fossil fuel combustion, as well as brake and tire wear. The filters were most effective in reducing ultrafine particles (86% decrease), black carbon, which is mostly from diesel (86%), and PM2.5 (60%) while gasses like carbon dioxide and nitrogen oxide were unaffected.
"The clue here is that these tiniest particles are probably what's responsible for blood pressure difference," Kaufman said.

"If you live in an area that has heavy traffic-related air pollution, you want to keep your windows closed and have air filtration capability in your home."
Canada

Canadian Government Reaches Deal With Google On Online News Act (www.cbc.ca) 50

An anonymous reader quotes a report from the CBC: Google and the federal government have reached an agreement in their dispute over the Online News Act that would see Google continue to share Canadian news online in return for the company making annual payments to news companies in the range of $100 million. Sources told Radio-Canada and CBC News earlier Wednesday that an agreement had been reached. Heritage Minister Pascale St-Onge confirmed the news Wednesday afternoon. "Many doubted that we would be successful, but I was confident we would find a way to address Google's concerns," she told reporters outside the House of Commons.

The federal government and Google agreed on the regulatory framework earlier this week, a government source familiar with the talks told Radio-Canada. The federal government had estimated earlier this year that Google's compensation should amount to about $172 million. Google estimated the value at $100 million. The company said it would not have a mandatory negotiation model imposed on it for talks with Canadian media organizations, preferring to deal with a single point of contact. The new regulations will allow Google to negotiate with a single group that would represent all media, allowing the company to limit its arbitration risk. Google would still be required to negotiate with the media and sign an agreement. The digital giant could also add additional service contributions, which have yet to be specified.

AI

Google DeepMind's New AI Tool Helped Create Over 700 New Materials (technologyreview.com) 28

From EV batteries to solar cells to microchips, new materials can supercharge technological breakthroughs. But discovering them usually takes months or even years of trial-and-error research. Google DeepMind hopes to change that with a new tool that uses deep learning to dramatically speed up the process of discovering new materials. From a report: Called graphical networks for material exploration (GNoME), the technology has already been used to predict structures for 2.2 million new materials, of which more than 700 have gone on to be created in the lab and are now being tested. It is described in a paper published in Nature today.

Alongside GNoME, Lawrence Berkeley National Laboratory also announced a new autonomous lab. In partnership with DeepMind, the lab takes GNoME's discoveries and uses machine learning and robotic arms to engineer new materials without the help of humans. Google DeepMind says that together, these advancements show the potential of using AI to scale up the discovery and development of new materials.

GNoME can be described as AlphaFold for materials discovery, according to Ju Li, a materials science and engineering professor at the Massachusetts Institute of Technology. AlphaFold, a DeepMind AI system announced in 2020, predicts the structures of proteins with high accuracy and has since advanced biological research and drug discovery. Thanks to GNoME, the number of known stable materials has grown almost tenfold, to 421,000. "While materials play a very critical role in almost any technology, we as humanity know only a few tens of thousands of stable materials," said Dogus Cubuk, materials discovery lead at Google DeepMind, at a press briefing.

Windows

Samsung Expands In-house Web Browser To Windows (sammobile.com) 39

An anonymous reader shares a report: The biggest benefit Samsung Internet on a desktop operating system will provide is the syncing of browsing data between your phone and PC, the lack of which has prevented many users from using Samsung Internet as their primary browser app on their phones and tablets. Unfortunately, Samsung hasn't yet implemented full-fledged sync support on Samsung Internet for Windows. While you can log in with your Samsung account, only browsing history, bookmarks, saved pages and open tabs can be synced at this time. Password syncing is not available, which hopefully won't remain the case for long.

The first time you run Samsung Internet on Windows, you can import browsing history, bookmarks/favorites, and search engines from other browsers, including Google Chrome and Microsoft Edge. You can also import bookmarks using an HTML file. As for other features, Samsung Internet on Windows has ad blocker support, a secret (incognito) mode, extension support, light and dark mode themes, and a few others. Since Samsung Internet is based on the open-source Chromium project like Chrome and Microsoft Edge, it should support extensions and add-ons that work on those browsers.

Businesses

Unity Software To Cut 3.8% of Staff In 'Company Reset' (reuters.com) 45

According to Reuters, Unity Software will eliminate 265 jobs or 3.8% of its global workforce as part of a company "reset." It will also end an agreement with Peter Jackson's visual effects company Weta FX. From the report: Tuesday's announcement includes termination of the professional services piece of an agreement Unity struck with movie director Peter Jackson's visual effects company Weta FX in 2021 after Unity purchased the technology and engineering division of Weta FX. As a result, 265 employees whose jobs are related to the agreement will be laid off, the company said. The company has said its total workforce was around 7,000.

In addition, Unity will shut down offices in 14 locations such as Berlin and Singapore, pending employee consultation in some countries, and significantly reduce its office footprint for the remaining offices, including in San Francisco and Bellevue, Washington. Unity will no longer mandate that employees work from offices three a days a week and will reduce "full in-office services" to three days a week in most locations, the company said. More changes are in store to "refocus" Unity's business, Whitehurst told Reuters. "While no additions have been finalized, it's clear that we will reduce the number of things we are doing overall," he said.

Earth

American Airlines To Turn 10K Tons of CO2 Into Buried Carbon Blocks (cnbc.com) 100

American Airlines today announced a deal with Graphyte to purchase "carbon removal credits" to help accelerate its long-term goal to reach net-zero emissions by 2050. According to the announcement, the airline will purchase credits equivalent to 10,000 tons of permanent carbon removal with delivery scheduled for early 2025. From the report: Graphyte uses a process called carbon casting that converts byproducts from the agriculture and timber industries such as wood bark, rice hulls and plant stalks which have captured carbon dioxide through photosynthesis. The plant material is dried to prevent decomposition and then converted into carbon dense bricks that are sealed with a polymer barrier. These bricks are stored in underground chambers and monitored with sensors to make sure the carbon does not escape, according to the company.

Plant byproducts from the agriculture and timber industries are typically burned or left to decompose, which returns carbon dioxide into the atmosphere. This biomass material is equivalent to 3 billion tons of potential carbon dioxide removal annually, according to Graphyte. Graphyte says carbon casting is a cheap, scalable alternative to expensive and technologically intensive methods of carbon capture and removal. The company is backed by Breakthrough Energy Ventures, an investment firm founded by Bill Gates that funds clean energy technologies.

AI

Sports Illustrated Published Articles by Fake, AI-Generated Writers (futurism.com) 45

Futurism has accused Sports Illustrated of publishing AI-generated articles under fake author biographies. The magazine has since removed the articles in question and released a statement blaming the issue on a contractor. From the report: There was nothing in Drew Ortiz's author biography at Sports Illustrated to suggest that he was anything other than human. "Drew has spent much of his life outdoors, and is excited to guide you through his never-ending list of the best products to keep you from falling to the perils of nature," it read. "Nowadays, there is rarely a weekend that goes by where Drew isn't out camping, hiking, or just back on his parents' farm." The only problem? Outside of Sports Illustrated, Drew Ortiz doesn't seem to exist. He has no social media presence and no publishing history. And even more strangely, his profile photo on Sports Illustrated is for sale on a website that sells AI-generated headshots, where he's described as "neutral white young-adult male with short brown hair and blue eyes."

Ortiz isn't the only AI-generated author published by Sports Illustrated, according to a person involved with the creation of the content who asked to be kept anonymous to protect them from professional repercussions. "There's a lot," they told us of the fake authors. "I was like, what are they? This is ridiculous. This person does not exist." "At the bottom [of the page] there would be a photo of a person and some fake description of them like, 'oh, John lives in Houston, Texas. He loves yard games and hanging out with his dog, Sam.' Stuff like that," they continued. "It's just crazy."

According to a second person involved in the creation of the Sports Illustrated content who also asked to be kept anonymous, that's because it's not just the authors' headshots that are AI-generated. At least some of the articles themselves, they said, were churned out using AI as well. "The content is absolutely AI-generated," the second source said, "no matter how much they say that it's not." After we reached out with questions to the magazine's publisher, The Arena Group, all the AI-generated authors disappeared from Sports Illustrated's site without explanation. [...] Though Sports Illustrated's AI-generated authors and their articles disappeared after we asked about them, similar operations appear to be alive and well elsewhere in The Arena Group's portfolio.
An Arena Group spokesperson issued the following statement blaming a contractor for the content: "Today, an article was published alleging that Sports Illustrated published AI-generated articles. According to our initial investigation, this is not accurate. The articles in question were product reviews and were licensed content from an external, third-party company, AdVon Commerce. A number of AdVon's e-commerce articles ran on certain Arena websites. We continually monitor our partners and were in the midst of a review when these allegations were raised. AdVon has assured us that all of the articles in question were written and edited by humans. According to AdVon, their writers, editors, and researchers create and curate content and follow a policy that involves using both counter-plagiarism and counter-AI software on all content. However, we have learned that AdVon had writers use a pen or pseudo name in certain articles to protect author privacy -- actions we don't condone -- and we are removing the content while our internal investigation continues and have since ended the partnership."
Google

The .meme Domain Is Here (theverge.com) 37

Google Registry released a new top-level .meme domain that you can now add to your website. The Verge reports: The new .meme domains are available to register right now as part of an early access period for an "additional one-time fee." If you don't want to pay extra, you can wait until they become publicly available on December 5th at 4PM UTC (12PM ET) to pay just the base annual price. There are already a handful of sites that are embracing the .meme domain, some of which are dedicated to memes from the days of yore, including grumpycat.meme, nyancat.meme, and keyboardcat.meme. The meme tracker knowyour.meme even adopted the new domain. However, some of these .meme sites just direct you to a .com address or point you to another platform.
Google

Google Play Keeps Banning the Same Web Browser Due To Vague DMCA Notices (arstechnica.com) 69

An anonymous reader quotes a report from Ars Technica: App developer Elias Saba has had some bad luck with Digital Millennium Copyright Act (DMCA) takedowns. His Android TV app Downloader, which combines a web browser with a file manager, was suspended by Google Play in May after several Israeli TV companies complained that the app could be used to load a pirate website. Google reversed that suspension after three weeks. But Downloader has been suspended by Google Play again, and this time the reason is even harder to understand. Based on a vague DMCA notice, it appears that Downloader was suspended simply because it can load the Warner Bros. website. [...]

The notice includes a copy of the DMCA complaint, which came from MarkScan, a "digital asset protection" firm that content owners hire to enforce copyrights. MarkScan said in its complaint that it represents Warner Bros. Discovery Inc. A DMCA notice is supposed to identify and describe the copyrighted work that was infringed. But MarkScan's notice about Downloader identifies the copyrighted work only as "Properties of Warner Bros. Discovery Inc." It provides no detail on which Warner Bros. work was infringed by Downloader. A DMCA notice is also supposed to provide an example of where someone can see "an authorized example of the work." In this field, MarkScan simply entered the main Warner Bros. URL: https://www.warnerbros.com/. The Downloader app had been installed over 10 million times before the takedown, according to an Internet Archive capture taken before the latest suspension.

Saba appealed the takedown today, but he told us that the appeal was rejected by Google Play after 24 minutes. Saba said he also submitted a DMCA counter-notice, which gives the complainant 10 business days from today to file a legal action. After his first takedown in May, his app was reinstated after the DMCA complainant didn't take any legal action. Saba also wrote a blog post today about the latest takedown. "Given that my app still does not contain any copyright-infringing content and never has, I've countered this new DMCA takedown which will, hopefully, mean the app will be restored sometime in the coming weeks," he wrote. "In the meantime, you can sideload the app onto your Google TV or Android TV devices by downloading the APK from https://www.aftvnews.com/downloader.apk. Downloader remains available on Fire TV devices directly from the Amazon Appstore."
Saba said it's "absurd that Google seems to make no effort at all to verify the copyright claims being made on my app which is just a web browser that can download files and has no content of any sort in it."

"If loading a website with infringing content in a standard web browser is enough to violate DMCA, then every browser in the Google Play Store including @googlechrome should also be removed," said Saba in May. "It's a ridiculous claim and an abuse of the DMCA."
Google

Google's New Geothermal Energy Project is Up and Running (theverge.com) 28

A first-of-its-kind geothermal project is now up and running in Nevada, where it will help power Google's data centers with clean energy. From a report: Google is partnering with startup Fervo, which has developed new technology for harnessing geothermal power. Since they're using different tactics than traditional geothermal plants, it is a relatively small project with the capacity to generate 3.5 MW. For context, one megawatt is enough to meet the demand of roughly 750 homes. The project will feed electricity into the local grid that serves two of Google's data centers outside of Las Vegas and Reno.

It's part of Google's plan to run on carbon pollution-free electricity around the clock by 2030. To reach that goal, it'll have to get more sources of clean energy online. And it sees geothermal as a key part of the future electricity mix that can fill in whenever wind and solar energy wane. "If you think about how much we advanced wind and solar and lithium ion storage, here we are -- this is kind of the next set of stuff and we feel like companies have a huge role to play in advancing these technologies," says Michael Terrell, senior director of energy and climate at Google.

Transportation

First Transatlantic Flight Using 100% Sustainable Jet Fuel Takes Off (theguardian.com) 106

The first transatlantic flight by a commercial airliner fully powered by "sustainable" jet fuel has taken off from London Heathrow. From a report: Tuesday's Virgin Atlantic flight, partly funded by the UK government, has been hailed by the aviation industry and ministers as a demonstration of the potential to significantly cut net carbon emissions from flying, although scientists and environmental groups are extremely sceptical. Airlines have previously flown on a blend of up to 50% of alternative fuels, called sustainable aviation fuels (SAF), and flight VS100 is operating under special dispensation with no paying passengers, using fuel made mostly from tallow and other waste products.

One of those onboard, the transport secretary, Mark Harper, said: "Today's 100% SAF-powered flight shows how we can decarbonise transport both now and in the future, cutting lifecycle emissions by 70% and inspiring the next generation of solutions." Rishi Sunak said the flight was "a major milestone towards making air travel more environmentally friendly and decarbonising our skies." Virgin Atlantic said the flight to New York would show that SAF was a safe replacement for normal kerosene jet fuel. The Virgin Atlantic founder and president, Sir Richard Branson, also onboard, said: "The world will always assume something can't be done, until you do it."

The Internet

Internet Use Does Not Appear To Harm Mental Health, Oxford Study Finds (ft.com) 80

A study of more than 2 million people's internet use found no "smoking gun" for widespread harm to mental health from online activities such as browsing social media and gaming, despite widely claimed concerns that mobile apps can cause depression and anxiety. From a report: Researchers at the Oxford Internet Institute, who said their study was the largest of its kind, said they found no evidence to support "popular ideas that certain groups are more at risk" from the technology. However, Andrew Przybylski, professor at the institute -- part of the University of Oxford -- said that the data necessary to establish a causal connection was "absent" without more co-operation from tech companies. If apps do harm mental health, only the companies that build them have the user data that could prove it, he said.

"The best data we have available suggests that there is not a global link between these factors," said Przybylski, who carried out the study with Matti Vuorre, a professor at Tilburg University. Because the "stakes are so high" if online activity really did lead to mental health problems, any regulation aimed at addressing it should be based on much more "conclusive" evidence, he added. "Global Well-Being and Mental Health in the Internet Age" was published in the journal Clinical Psychological Science on Tuesday.
In their paper, Przybylski and Vuorre studied data on psychological wellbeing from 2.4 million people aged 15 to 89 in 168 countries between 2005 and 2022, which they contrasted with industry data about growth in internet subscriptions over that time, as well as tracking associations between mental health and internet adoption in 202 countries from 2000-19.
Facebook

Meta Designed Platforms To Get Children Addicted, Court Documents Allege (theguardian.com) 64

An anonymous reader quotes a report from The Guardian: Instagram and Facebook parent company Meta purposefully engineered its platforms to addict children and knowingly allowed underage users to hold accounts, according to a newly unsealed legal complaint. The complaint is a key part of a lawsuit filed against Meta by the attorneys general of 33 states in late October and was originally redacted. It alleges the social media company knew -- but never disclosed -- it had received millions of complaints about underage users on Instagram but only disabled a fraction of those accounts. The large number of underage users was an "open secret" at the company, the suit alleges, citing internal company documents.

In one example, the lawsuit cites an internal email thread in which employees discuss why a 12-year-old girl's four accounts were not deleted following complaints from the girl's mother stating her daughter was 12 years old and requesting the accounts to be taken down. The employees concluded that "the accounts were ignored" in part because representatives of Meta "couldn't tell for sure the user was underage." The complaint said that in 2021, Meta received over 402,000 reports of under-13 users on Instagram but that 164,000 -- far fewer than half of the reported accounts -- were "disabled for potentially being under the age of 13" that year. The complaint noted that at times Meta has a backlog of up to 2.5m accounts of younger children awaiting action. The complaint alleges this and other incidents violate the Children's Online Privacy and Protection Act, which requires that social media companies provide notice and get parental consent before collecting data from children. The lawsuit also focuses on longstanding assertions that Meta knowingly created products that were addictive and harmful to children, brought into sharp focus by whistleblower Frances Haugen, who revealed that internal studies showed platforms like Instagram led children to anorexia-related content. Haugen also stated the company intentionally targets children under the age of 18.

Company documents cited in the complaint described several Meta officials acknowledging the company designed its products to exploit shortcomings in youthful psychology, including a May 2020 internal presentation called "teen fundamentals" which highlighted certain vulnerabilities of the young brain that could be exploited by product development. The presentation discussed teen brains' relative immaturity, and teenagers' tendency to be driven by "emotion, the intrigue of novelty and reward" and asked how these asked how these characteristics could "manifest ... in product usage." [...] One Facebook safety executive alluded to the possibility that cracking down on younger users might hurt the company's business in a 2019 email. But a year later, the same executive expressed frustration that while Facebook readily studied the usage of underage users for business reasons, it didn't show the same enthusiasm for ways to identify younger kids and remove them from its platforms.

Businesses

Broadcom Lays Off VMware Employees After Closing Its $69 Billion Acquisition (businessinsider.com) 51

After acquiring VMware for $69 billion, Broadcom is eliminating several positions at the virtualization technology company. Business Insider reports: Employees whose positions were eliminated received an email on Monday, viewed by Business Insider, that read: "Broadcom recently completed its acquisition of VMware. As part of integration planning, and following an organizational needs assessment, we identified go-forward roles that will be required within the combined company. We regret to inform you that your position is being eliminated and your employment will be terminated."

"We would like to thank you for your dedication and service. We want to make this transition as smooth as possible, including offering you a generous severance package and providing you a non-working paid notice period," the email continued. Currently, it's unclear exactly how many employees will be affected by the cuts.

Security

Researchers Figure Out How To Bypass Fingerprint Readers In Most Windows PCs (arstechnica.com) 25

An anonymous reader quotes a report from Ars Technica: [L]ast week, researchers at Blackwing Intelligence published an extensive document showing how they had managed to work around some of the most popular fingerprint sensors used in Windows PCs. Security researchers Jesse D'Aguanno and Timo Teras write that, with varying degrees of reverse-engineering and using some external hardware, they were able to fool the Goodix fingerprint sensor in a Dell Inspiron 15, the Synaptic sensor in a Lenovo ThinkPad T14, and the ELAN sensor in one of Microsoft's own Surface Pro Type Covers. These are just three laptop models from the wide universe of PCs, but one of these three companies usually does make the fingerprint sensor in every laptop we've reviewed in the last few years. It's likely that most Windows PCs with fingerprint readers will be vulnerable to similar exploits.

Blackwing's post on the vulnerability is also a good overview of exactly how fingerprint sensors in a modern PC work. Most Windows Hello-compatible fingerprint readers use "match on chip" sensors, meaning that the sensor has its own processors and storage that perform all fingerprint scanning and matching independently without relying on the host PC's hardware. This ensures that fingerprint data can't be accessed or extracted if the host PC is compromised. If you're familiar with Apple's terminology, this is basically the way its Secure Enclave is set up. Communication between the fingerprint sensor and the rest of the system is supposed to be handled by the Secure Device Connection Protocol (SCDP). This is a Microsoft-developed protocol that is meant to verify that fingerprint sensors are trustworthy and uncompromised, and to encrypt traffic between the fingerprint sensor and the rest of the PC.

Each fingerprint sensor was ultimately defeated by a different weakness. The Dell laptop's Goodix fingerprint sensor implemented SCDP properly in Windows but used no such protections in Linux. Connecting the fingerprint sensor to a Raspberry Pi 4, the team was able to exploit the Linux support plus "poor code quality" to enroll a new fingerprint that would allow entry into a Windows account. As for the Synaptic and ELAN fingerprint readers used by Lenovo and Microsoft (respectively), the main issue is that both sensors supported SCDP but that it wasn't actually enabled. Synaptic's touchpad used a custom TLS implementation for communication that the Blackwing team was able to exploit, while the Surface fingerprint reader used cleartext communication over USB for communication. "In fact, any USB device can claim to be the ELAN sensor (by spoofing its VID/PID) and simply claim that an authorized user is logging in," wrote D'Aguanno and Teras.
"Though all of these exploits ultimately require physical access to a device and an attacker who is determined to break into your specific laptop, the wide variety of possible exploits means that there's no single fix that can address all of these issues, even if laptop manufacturers are motivated to implement them," concludes Ars.

Blackwing recommends all Windows Hello fingerprint sensors enable SCDP, the protocol Microsoft developed to try to prevent this exploit. PC makers should also "have a qualified expert third party audit [their] implementation" to improve code quality and security.
Businesses

Charter To Reduce Mobile Video Streaming Resolution for Some Customers (lightreading.com) 35

Charter Communications confirmed to Light Reading it will lower the default video streaming resolution for its Unlimited Plus mobile customers to 480p from 720p starting in December. From a report: Charter's default setting for customers on its other By The Gig and Unlimited mobile plans is already set at 480p. The company said its Unlimited Plus mobile customers can change their default streaming setting back from 480p to 720p using the company's My Spectrum App for no extra charge. Further, the change will not affect customers who are connected to Wi-Fi. When customers are on Wi-Fi, the video streaming resolution among Charter's Spectrum Mobile customers is determined by the format of the video content the customer is streaming and the capabilities and settings of their device, according to the company.
Facebook

Russia Puts Spokesman For Facebook-owner Meta on a Wanted List (yahoo.com) 100

Russia has added the spokesman of U.S. technology company Meta, which owns Facebook and Instagram, to a wanted list, according to an online database maintained by the country's interior ministry. From a report: Russian state agency Tass and independent news outlet Mediazona first reported that Meta communications director Andy Stone was included on the list Sunday, weeks after Russian authorities in October classified Meta as a "terrorist and extremist" organization, opening the way for possible criminal proceedings against Russian residents using its platforms.

The interior ministry's database doesn't give details of the case against Stone, stating only that he is wanted on criminal charges. According to Mediazona, an independent news website that covers Russia's opposition and prison system, Stone was put on the wanted list in February 2022, but authorities made no related statements at the time and no news media reported on the matter until this week. In March this year, Russia's federal Investigative Committee opened a criminal investigation into Meta.

Slashdot Top Deals