Android

Google Play Store Is Bringing Back the App Permissions List (9to5google.com) 11

An anonymous reader quotes a report from 9to5Google: With the addition of the developer-generated Data safety section this year, Google Play removed the old list of app permissions. The Play Store is now reversing this decision in response to user feedback and will have both coexist. In a short thread this morning, Android Developers (@AndroidDev) on Twitter said it "heard your feedback that you find the app permissions section in Google Play useful, and we've decided to reinstate it." It will be "back shortly," but the company did not specify if this will be done through a server-side change or whether a new version of the Play Store app is required: "The Data safety section provides users with a simplified view of how an app collects, shares, & secures user data, but we also want to make app permissions information easily viewable for users to understand an app's ability to access specific restricted data & actions too."

As Google summarizes, the Play permissions list is "based on the install-time permissions that an app declares in its manifest," and "represents an app's ability to access specific data." Data safety is focused on what an app collects and shares with third parties, similar to Apple's App Store. As of July 20, Google is directly warning "non-compliant new app submissions and app updates" that don't completely fill out the Data safety form. Developers have until August 22 to comply or they won't be able to publish new apps or updates. After that, applications might be removed from the Play Store.

XBox (Games)

Xbox Becomes First Game Console To Formally Support Discord Voice Chat (arstechnica.com) 20

After trying, and failing, to acquire the popular chat platform Discord for $10 billion, Microsoft has opted for the next-best thing: directly integrating Discord's voice-chat capabilities into Xbox consoles. Ars Technica reports: The news arrived on Wednesday on Xbox Blog, and it clarified that for the time being, Discord access would be exclusive to the optional "Xbox Insider" tier of early, beta, and preview console OS updates. That update is already going live in waves to Xbox Insiders today, and it adds a new tooltip to the system's "chat" sidebar: "Try Discord Voice on Xbox today!"

[...] Sadly, this week's rollout of Discord on Xbox is a bit limited. The biggest issue is that there is no formal Discord app or interface on Xbox. You will need to keep a smartphone handy to initiate a "handoff" of your Discord session. Get ready for an annoying first-time setup process. Should you have an updated Xbox on the Insider OS track, its new "Try Discord Voice" prompt will initiate an account-sync process, which requires using a mobile Discord app to take a photo of a QR code displayed by your Xbox. (You'll need to re-do this if you've done so before, due to it adding a new level of credential for voice chat.) With this in place, when you are about to join a voice channel on Discord, a new "try voice chat on console" prompt will appear. Tapping through this will then, ugh, create another handover to Microsoft's dedicated Xbox app on either iOS or Android. Yes, if you want this to work, you need to install the Xbox app on your mobile device (and Discord will suggest you do so, if you haven't yet). This facilitates the key technical aspect of forwarding all Discord audio to your Xbox hardware.

With all that in place, presto: You can now talk to any participants in the Discord voice channel you chose directly on your Xbox. Its menu interface supports either muting or changing the volume level of every other user in the voice chat channel you chose, which is appreciated as a quickly accessible option during frantic gameplay. A one-button toggle in the menu allows chatters to switch between Discord voice chat and a particular game's dedicated voice-chat channel. (This is useful when you're talking to friends while in the midst of random online matchmaking, then need to turn on in-game voice chat for a second to confirm a strategy to your current teammates before going back to discussing souffle recipes with buddies.) All greater Discord control, sadly, goes back to your smartphone...

Security

Russia Released a Ukrainian App For Hacking Russia That Was Actually Malware (vice.com) 19

Russian government hackers tried to trick Ukrainian and international volunteers into using a malicious Android app disguised as an app to launch Distributed Denial of Service (DDoS) attacks against Russian sites, according to new research published by Google on Tuesday. Motherboard reports: Since the beginning of the Russian invasion, Ukraine has resisted not only on the ground, but also online. A loose collective of technologists and hackers has organized under an umbrella quasi-hacktivist organization called the IT Army, and they have launched constant and persistent cyberattacks against Russian websites. The Russian government tried to turn this volunteer effort around to unmask Ukrainian hackers, in a smart, but ultimately failed attempt.

Google researchers wrote in the report that the app was created by the hacking group known as Turla, which several cybersecurity companies believe works for the Kremlin. [Shane Huntley, the head of the Google research team Threat Analysis Group] said that they were able to attribute this operation to Turla because they have tracked the group for a long time and have good visibility into their infrastructure and link it to this app. The hackers pretended to be a "community of free people around the world who are fighting russia's aggression" -- much like the IT Army. But the app they developed was actually malware. The hackers called it CyberAzov, in reference to the Azov Regiment or Battalion, a far-right group that has become part of Ukraine's national guard. To add more credibility to the ruse they hosted the app on a domain "spoofing" the Azov Regiment: cyberazov[.]com.

The app actually didn't DDoS anything, but was designed to map out and figure out who would want to use such an app to attack Russian websites, according to Huntely. "Now that they have an app that they control, and they see where it came from, they can actually work out what the infrastructure looks like, and work out where the people that are potentially doing these sorts of attacks are," Huntley said. Google said the fake app wasn't hosted on the Play Store, and that the number of installs "was miniscule." Still, it was a smart attempt to trick unknowing Ukrainians or people interested in working with Ukrainians to fall into the trap.

Google

Google Will Let European Developers Use Their Own Billing Systems (theverge.com) 19

Google will start allowing the developers of non-gaming apps in the European Economic Area (EEA) to offer alternate payment systems. In a blog post, Google outlines its plans to comply with the Digital Markets Act (or DMA), a piece of legislation aimed at regulating big tech. From a report: The DMA passed through the European Parliament earlier this month, but it isn't expected to go into force until spring 2023. But Google is rolling out the changes ahead of time to make sure that its plans "serve the needs" of users.

The legislation requires "gatekeepers," or companies with a market capitalization of $75.8 billion or over, to follow a set of rules meant to promote competition among digital platforms. Failing to comply could lead to fines of up to 10 percent of a firm's global revenue or 20 percent in case of repeat offenses. Android developers who choose to use an alternate payment processor will still have to pay Google a service fee for each transaction on the first $1 million they make within one year. However, Google says it will reduce this fee by 3 percent, meaning the company will take a 12 percent or lower cut from every transaction. If developers make more than $1 million in one year, Google will charge developers a 27 percent fee on transactions (3 percent less than the standard 30 percent).

Android

Android Removes Much of Fuchsia-Related Code As Starnix Project Progresses (9to5google.com) 10

A big chunk of Fuchsia-related code has been removed from the Android Open Source Project (AOSP) this week, but Google's two operating systems are still set to have an intertwining relationship. In its place, we have a lone "TODO" message, suggesting that Google may be building up something new in its place. The developer responsible for the change primarily works on Fuchsia's "Starnix" project. 9to5Google reports: In its most public form, Google's in-house operating system, Fuchsia, powers two of the company's smart displays, the Nest Hub and Nest Hub Max. But having watched it develop over the last few years, we know that Google has much larger ambitions for the Fuchsia project. Easily the most ambitious of these is a clear intention for some Fuchsia devices to be able to run apps from other operating systems like Android and Linux. This could -- in theory! -- allow a Fuchsia-powered device to seamlessly replace a Chromebook or Android phone, keeping older apps running as normal. [...]

First shared in early 2021 as a proposal, Starnix is designed to make it possible for Fuchsia to "natively" run apps and libraries that were built for Linux or Android. To do this, Starnix would act to translate the low-level kernel instructions from what Linux expects to what Fuchsia's Zircon kernel expects. It's now been over a year since the Starnix proposal was accepted and work began. In that time, the Fuchsia team has made significant progress in making Linux programs capable of running on Fuchsia devices. In fact, a dedicated Starnix shell was briefly available for testing in builds of Fuchsia's "workstation" -- an experience designed to let developers and enthusiasts play with the operating system. Notably, this shell was not simply Linux but actually a "small Android distribution included in the system." More recently, this was replaced with the ability to access Fuchsia and Starnix's Android capabilities through the adb command, just like you would any other Android device. Looking ahead, it seems Fuchsia's Starnix team is focused on steadily making the operating system compatible with Android and its applications. [...]

Cellphones

Are Lock Screens About to Change? (cnet.com) 75

"The lock screen is about to change," writes CNET — both for iOS and Android devices. Apple's iOS 16 update, which launched in public beta on Monday, will bring more customization options and new widgets to the iPhone's lock screen when it arrives this fall. You'll be able to see more information quickly and apply stylistic effects to lock screen photos similar to the iPhone's Portrait Mode photography feature.... Like the Apple Watch, the new lock screen should make it easier to see crucial pieces of information without having to dig into apps or even unlock your phone.
And for Android phones: Glance, a Google-backed subsidiary of mobile ad tech company InMobi, also reiterated its plans to bring its lock screen platform to the U.S. [though the company also says there's "no definitive timeline."] And Google is reportedly planning to incorporate more bits of information into its own lock screen widget for Pixel phones.... Glance's lock screen will appear in the form of what it calls "spaces," which are essentially curated lock screens designed to fit specific themes. A fitness-oriented lock screen, for example, would show statistics such as calories burned and exercise goals alongside a music player. A news "space" would show headlines and the weather, while a music version could surface live concerts....

The TechCrunch report about Glance's US arrival sparked concerns that advertisements would be coming to the lock screen, too. Glance's business page shows examples of advertisers that have used its platform to reach potential customers on the very first screen they see when picking up their phone. Intel, Zomato and Garnier are among the listed case studies. But Rohan Choudhary, vice president and general manager of the Glance feed, told CNET the US version would be ad-free. "We are very clear that in the US, we will not have ads on the lock screen at all," he said....

The company says it plans to monetize its service through news subscriptions and commerce links from shopping platforms that are surfaced through Glance.

Glance's motto? "Transforming lock screens into smart surfaces."
Android

Google Play Hides App Permissions In Favor of Developer-Written Descriptions (arstechnica.com) 33

An anonymous reader quotes a report from Ars Technica: Google's developer deadline for the Play Store's new "Data Safety" section is next week (July 20), and we're starting to see what the future of Google Play privacy will look like. The actual Data Safety section started rolling out in April, but now that the developer deadline is approaching... Google is turning off the separate "app permissions" section? That doesn't sound like a great move for privacy at all.

The Play Store's new Data Safety section is Google's answer to a similar feature in iOS 14, which displays a list of developer-provided privacy considerations, like what data an app collects, how that data is stored, and who the data is shared with. At first blush, the Data Safety entries might seem pretty similar to the old list of app permissions. You get items like "location," and in some ways, it's better than a plain list of permissions since developers can explain how and why each bit of data is collected.

The difference is in how that data ends up in Google's system. The old list of app permissions was guaranteed to be factual because it was built by Google, automatically, by scanning the app. The Data Safety system, meanwhile, runs on the honor system. Here's Google's explanation to developers of how the new section works: "You alone are responsible for making complete and accurate declarations in your app's store listing on Google Play. Google Play reviews apps across all policy requirements; however, we cannot make determinations on behalf of the developers of how they handle user data. Only you possess all the information required to complete the Data safety form. When Google becomes aware of a discrepancy between your app behavior and your declaration, we may take appropriate action, including enforcement action."

Google

Google Files a Lawsuit That Could Kick Tinder Out of the Play Store (engadget.com) 59

Google has counter-sued Match seeking monetary damages and a judgement that would let it kick Tinder and the group's other dating apps out of the Play Store, Bloomberg has reported. Engadget reports: Earlier this year, Match sued Google alleging antitrust violations over a decision requiring all Android developers to process "digital goods and services" payments through the Play Store billing system. Following the initial lawsuit in May, Google and Match reached a temporary agreement allowing Match to remain on the Play Store and use its own payments system. Google also agreed to make a "good faith" effort to address Match's billing concerns. Match, in turn, was to make an effort to offer Google's billing system as an alternative.

However, Google parent Alphabet claims that Match Group now wants to avoid paying "nothing at all" to Google, including its 15 to 30 percent Play Store fees, according to a court filing. "Match Group never intended to comply with the contractual terms to which it agreed... it would also place Match Group in an advantaged position relative to other app developers," the document states. Match group said that Google's Play Store policies violate federal and state laws. "Google doesn't want anyone else to sue them so their counterclaims are designed as a warning shot," Match told Bloomberg in a statement. "We are confident that our suit, alongside other developers, the US Department of Justice and 37 state attorneys general making similar claims, will be resolved in our favor early next year."

Microsoft

Microsoft's xCloud Game Streaming Looks Worse On Linux Than Windows (arstechnica.com) 35

As noted by a Reddit user and confirmed by Ars Technica, Microsoft's xCloud game streaming looks noticeable worse when running on Linux than Windows. From the report: With the Linux User-Agent, edges are generally less sharp and colors are a little more washed out. The difference is even more apparent if you zoom in on the Forza logo and menu text, which shows a significant reduction in clarity. Interestingly, the dip in quality seems to go away if you enable "Clarity Boost, an Edge-exclusive feature that "provid[es] the optimal look and feel while playing Xbox games from the cloud," according to Microsoft. That's great for Linux users who switched over to Microsoft Edge when it launched on Linux last November. But Linux users who stick with Firefox, Chrome, or other browsers are currently stuck with apparently reduced streaming quality.

That Linux quality dip has led some to speculate that Microsoft is trying to reserve the best xCloud streaming performance for Windows machines in an attempt to attract more users to its own operating system. But using a Macintosh User-Agent string provides streaming performance similar to that on Windows, which would seem to be a big omission if that theory were true. Microsoft also hasn't published any kind of "best on Windows"-style marketing in promoting xCloud streaming, which would seemingly be a key component of trying to attract new Windows users. (The quality difference could be a roundabout attempt to get Linux users to switch to the Edge browser, where Clarity Boost offers the best possible quality. But that still wouldn't fully explain why Windows users on other browsers, without Clarity Boost, also get better streaming quality than their Linux brethren.)

Others have suggested that the downgrade could simply be a bug caused by Microsoft's naive parsing of the User-Agent strings. That's because the User-Agent strings for Android browsers generally identify themselves as some version of Linux ("Linux; Android 11; HD1905," for example). Microsoft's xCloud code might simply see the "Linux" in that string, assume the user is running Android, then automatically throttle the streaming quality to account for the (presumably) reduced screen size of an Android phone or tablet.

Advertising

An Ad Company Is Teaming Up With US Carriers To Take Over Your Lock Screen (androidpolice.com) 126

A Google-backed ad company called Glance is looking to launch in the US, and it brings media content, news, and casual games to Android lock screens. Android Police reports: If you're not familiar with Glance, you can count yourself lucky. The lock screen platform is part of the pre-installed software on many, if not most, Android phones sold in India and other Asian markets, and it has also made its way to the EU on a few select brands. Glance says that since it was launched in 2019, it has become part of over 400 million sold smartphones. The service has taken it upon itself to monetize the lock screen, pushing news and ad feeds right into people's faces before they even unlock their phones. It's a subsidiary of Indian advertising behemoth InMobi, focusing on mobile-first ads.

According to a TechCrunch report, the service is looking to launch in the US within the next two months. The company is negotiating with US carriers to look into partnerships and to become part of the out-of-the-box experience of "several smartphone models by next month." In contrast to Asia, where the company is working directly with smartphone manufacturers, Glance seems to focus on carriers in the US. This makes sense, given the iron grip mobile operators have on the smartphone market.

Based on my experience with Glance on a few Vivo review units (like the Vivo X80 Pro), the lock screen feed tries hard to become part of your routine. Occasional notifications and swipe suggestions on the lock screen nudge you to interact with it. Once you give in and open the feed, it will override your lock screen wallpaper with its content, making you change back to your preferred wallpaper manually. [...] As for the US launch, there is no word on what exactly the feed is going to look like. We would expect a healthy middle ground between the Indian and the European version in the beginning as to not put off people, though it wouldn't be surprising if the company quickly turns things up given that consumer protection is weaker in the US than in the EU. One thing is certain: An entry in the US market will give Glance the opportunity to access users with more money to spend than many in Asian countries. This should allow Glance to ask advertisers for higher prices, allowing the company to grow even faster.

Android

HTC Quietly Announced a New Android Tablet, and Nobody Noticed (theverge.com) 26

HTC, the once-impressive Android smartphone manufacturer, has a surprise tablet to accompany its bizarre metaverse-focused Desire 22 Pro. From a report: The new A101 is an Android tablet with a 10.1-inch display, entry-level specs, and a design that's straight out of the middle of the last decade. The device, which we spotted via AndroidPolice, appears to have been quietly announced last month -- according to the Wayback Machine -- and is aimed at the African market. It follows the A100 tablet, which was released in Russia last year to a similar non-reaction. Given that the tablet appears to be marketed solely at emerging markets, I don't want to be too snarky about its specs or design. But it's still just plain weird to see HTC -- makers of literally the first-ever Android phone and a company that Google once entrusted to build a Nexus-branded tablet (the Nexus 9) -- producing forgettable devices like this. The A101 even runs 2020's Android 11 out of the box, rather than Android 12 or the big-screen focused Android 12L.
Google

Google To Pay $90 Million To Settle Legal Fight With App Developers (reuters.com) 12

Google has agreed to pay $90 million to settle a legal fight with app developers over the money they earned creating apps for Android smartphones and for enticing users to make in-app purchases. Reuters reports: The app developers, in a lawsuit filed in federal court in San Francisco, had accused Google of using agreements with smartphone makers, technical barriers and revenue sharing agreements to effectively close the app ecosystem and shunt most payments through its Google Play billing system with a default service fee of 30%.

As part of the proposed settlement, Google said in a blog post it would put $90 million in a fund to support app developers who made $2 million or less in annual revenue from 2016-2021. "A vast majority of U.S. developers who earned revenue through Google Play will be eligible to receive money from this fund, if they choose," Google said in the blog post. Google said it would also charge developers a 15% commission on their first million in revenue from the Google Play Store each year. It started doing this in 2021.
"There were likely 48,000 app developers eligible to apply for the $90 million fund, and the minimum payout is $250," notes Reuters.
Android

BMW Is Switching Gears From Linux To Android Automotive Next Year (androidpolice.com) 54

This week, BMW confirmed that some of its future models would run on a next-gen version of its in-house operating system built on top of Android Automotive. Android Polic reports: It's a big change from previous Linux-based versions, though the company says some of its cars will stay on its legacy build. So far, the automaker has yet to confirm which of its models will get Automotive support, though work on supporting it won't begin until March of 2023.

Automotive's biggest selling point for car manufacturers is its flexibility and customization options. Outside of some built-in Google apps -- Assistant, Maps, the Play Store -- don't expect to notice these BMW cars running Android immediately. Instead, the company will almost certainly rely on a skin to make the experience feel more in line with previous vehicles, as well as that Linux-based OS the company plans to keep developing.

Chrome

Google Consolidates Its Chrome and Android Password Managers (techcrunch.com) 6

Google today announced an update to its password manager that will finally introduce a consistent look-and-feel across the service's Chrome and Android implementations. From a report: Users will soon see a new unified user experience that will automatically group multiple passwords for the same sites or apps together, as well as a new shortcut on the Android home screen to get access to these passwords. In addition to this, Google is also now adding a new password-related feature to Chrome on iOS, which can now generate strong passwords for you (once you set Chrome as an autofill provider). Meanwhile, on Android, Google's password check can now also flag weak and re-used passwords and help you to automatically change them, while Chrome users across platforms will now see compromised password warnings.
Facebook

Meta Sparks Anger By Charging For VR Apps (arstechnica.com) 32

An anonymous reader quotes a report from the Financial Times: Meta is facing a growing backlash for the charges imposed on apps created for its virtual reality headsets, as developers complain about the commercial terms set around futuristic devices that the company hopes will help create a multibillion-dollar consumer market. [...] But several developers told the Financial Times of their frustration that Meta, which is seen as having an early lead in a nascent market, has insisted on a charging model for its VR app store similar to what exists today on smartphones. This is despite Meta chief Mark Zuckerberg being strongly critical in the past of charging policies on existing mobile app stores.

"Don't confuse marketing with reality -- it's good marketing to pick on Apple. But it doesn't mean Meta won't do the exact same thing," said Seth Siegel, global head of AI and cyber security at Infosys Consulting. "There is no impetus for them to be better." The "Quest Store" for Meta's Quest 2, by far the most popular VR headset on the market, takes a 30 percent cut from digital purchases and charges 15-30 percent on subscriptions, similar to the fees charged by Apple and Android. "Undoubtedly there are services provided -- they build amazing hardware and provide store services," said Daniel Sproll, chief executive of Realities.io, an immersive realities start-up behind the VR game Puzzling Places. "But the problem is that it feels like everybody agreed on this 30 percent and that's what we're stuck with. It doesn't feel like there's any competition. The Chinese companies coming out with headsets are the same. Why would they change it?"

Meta defended its policies, pointing out that unlike iPhone owners, Quest users can install apps outside its official store through SideQuest, a third-party app store, or make use of App Lab, its less restricted, more experimental app store. "We want to foster choice and competition in the VR ecosystem," Meta said. "And it's working -- our efforts have produced a material financial return for developers: as we announced earlier this year, over $1 billion has been spent on games and apps in the Meta Quest Store." Developers welcome these alternatives but say their impact is limited. SideQuest has been downloaded just 396,000 times, versus 19 million for the Oculus app, according to Sensor Tower. App Lab, meanwhile, still takes a 30 percent cut of purchases.
Developers are also frustrated with Meta's shift to a more restrictive approach to allowing apps on its VR app store.

Chris Pruett, Meta's content ecosystem director, said Meta found that lax standards resulted in too many users being frustrated by low-quality content, so the company has opted to play more of a gatekeeper role. But developers said the resulting barriers could lack transparency.

"Getting something on the Quest store is painful," said Lyron Bentovim, chief executive of the Glimpse Group, an immersive experiences group. "It's significantly worse than getting on Apple or Android stores."
Iphone

Apple Exec Says Samsung Copied iPhone and Simply 'Put a Bigger Screen Around It' (macrumors.com) 129

In a new documentary about the evolution of the iPhone, Apple's marketing chief Greg Joswiak was seen calling Samsung "annoying" and accusing them of poorly copying Apple's technology. "They were annoying," said Joswiak. "And they were annoying because, as you know, they ripped off our technology. They took the innovations that we had created and created a poor copy of it, and just put a bigger screen around it. So, yeah, we were none too pleased." MacRumors reports: Samsung launched the Galaxy S4 with a 5-inch display in early 2013, at a time when the iPhone 5 had a 4-inch display. Apple did eventually release its first larger smartphones with the 4.7-inch iPhone 6 and 5.5-inch iPhone 6 Plus in 2014, and the devices were met with strong demand and went on to be among the best-selling iPhone models ever.

Apple sued Samsung in 2011 for patent infringement, alleging that Samsung copied the iPhone's design with its own Galaxy line of smartphones. Apple was initially awarded around $1 billion in damages, but the amount was lowered in a subsequent retrial. In 2018, Apple finally settled with Samsung and reiterated the following statement: "We believe deeply in the value of design, and our teams work tirelessly to create innovative products that delight our customers. This case has always been about more than money. Apple ignited the smartphone revolution with iPhone and it is a fact that Samsung blatantly copied our design. It is important that we continue to protect the hard work and innovation of so many people at Apple. We're grateful to the jury for their service and pleased they agree that Samsung should pay for copying our products."
The full documentary can be watched on The Wall Street Journal's website.
Hardware

Arm's Immortalis GPU is Its First With Hardware Ray Tracing for Android Gaming (theverge.com) 65

Arm is announcing its new flagship Immortalis GPU today, its first to include hardware-based ray tracing on mobile. As PCs and the latest Xbox Series X and PS5 consoles are all gradually moving toward impressive ray-traced visuals, Immortalis-G715 is designed to be the Arm's first GPU to deliver the same on Android phones and tablets. From a report: Built on top of Mali, a GPU that's used by the likes of MediaTek and Samsung, Immortalis is designed with 10-16 cores in mind and promises a boost of 15 percent over the previous generation premium Mali GPUs. Arm sees Immortalis as the start of a transition to ray tracing on mobile following its success with the 8 billion Mali GPUs that have shipped to date.

"The challenge is that Ray Tracing techniques can use significant power, energy, and area across the mobile system-on-a-chip (SoC)," explains Andy Craigen, director of product management at Arm. "However, Ray Tracing on Immortalis-G715 only uses 4 percent of the shader core area, while delivering more than 300 percent performance improvements through the hardware acceleration."

It's not clear if a 3x speedup over software-based ray tracing will be enough to tempt game developers, but when Nvidia introduced hardware accelerated ray tracing in its RTX 2080, it advertised a 2x-3x boost at the time. "It's the right performance point for now to get this technology into the market," says Arm's Paul Williamson, adding that it may also come in handy in augmented reality applications where RT could be used to match virtual lighting to the real-world environment around you. Arm is already delivering software-based ray tracing in last year's Mali-G710, but the promise of hardware support means we will start to see flagship smartphones with this chip at the beginning of 2023. Samsung also announced its Exynos 2200 chip with hardware-based ray tracing earlier this year, so manufacturers are getting ready for the games to arrive.

Security

Google Warns ISPs Helped Distribute Hermit Spyware (engadget.com) 15

Google is warning of a sophisticated new spyware campaign that has seen malicious actors steal sensitive data from Android and iOS users in Italy and Kazakhstan. Engadget reports: On Thursday, the company's Threat Analysis Group (TAG) shared its findings on RCS Labs, a commercial spyware vendor based out of Italy. On June 16th, security researchers at Lookout linked the firm to Hermit, a spyware program believed to have been first deployed in 2019 by Italian authorities as part of an anti-corruption operation. Lookout describes RCS Labs as an NSO Group-like entity. The firm markets itself as a "lawful intercept" business and claims it only works with government agencies. However, commercial spyware vendors have come under intense scrutiny in recent years, largely thanks to governments using the Pegasus spyware to target activists and journalists.

According to Google, Hermit can infect both Android and iOS devices. In some instances, the company's researchers observed malicious actors work with their target's internet service provider to disable their data connection. They would then send the target an SMS message with a prompt to download the linked software to restore their internet connection. If that wasn't an option, the bad actors attempted to disguise the spyware as a legitimate messaging app like WhatsApp or Instagram.

What makes Hermit particularly dangerous is that it can gain additional capabilities by downloading modules from a command and control server. Some of the addons Lookout observed allowed the program to steal data from the target's calendar and address book apps, as well as take pictures with their phone's camera. One module even gave the spyware the capability to root an Android device. Google believes Hermit never made its way to the Play or App stores. However, the company found evidence that bad actors were able to distribute the spyware on iOS by enrolling in Apple's Developer Enterprise Program. Apple told The Verge that it has since blocked any accounts or certificates associated with the threat. Meanwhile, Google has notified affected users and rolled out an update to Google Play Protect.

Advertising

T-Mobile Has Started Selling Your App Data To Advertisers (androidpolice.com) 30

T-Mobile has just officially launched its new ad platform, known as T-Mobile Advertising Solutions. That innocuous name hides a rather sketchy business model -- it aggregates your mobile application usage and sells it to advertisers. Android Police reports: The specifics of the program will sound familiar to anyone who has followed the ebb and flow of browser tracking. T-Mobile uses network-level tools to track the apps that people use on their phones, and it then anonymizes and aggregates that data to lump you into various "personas," or "cohorts" as other platforms would call it. For example, if you regularly use Expensify and airline apps on your phone, T-Mobile could identify you as a business traveler for advertising purposes. This program has been in testing for the past year as "T-Mobile Marketing Solutions," according to The Verge, but it is now live with its new name.

There is some good news (but less of it for Android fans). T-Mobile does not currently collect app data on iOS users, fearing it could run afoul of Apple's privacy rules. But we Android users are fair game, apparently. However, you can opt-out of T-Mobile's program using its official "Magenta Marketing Platform Choices" app. Alternatively, the Digital Advertising Alliance offers an app that lets you opt-out of numerous trackers, including T-Mobile Advertising Solutions, which is listed under its old name of T-Mobile Marketing Solutions.

Bitcoin

Solana Launches Web3-Focused Smartphone Saga To Improve Crypto-Mobile Relationship (techcrunch.com) 52

An anonymous reader quotes a report from TechCrunch: The co-founder and CEO of Solana, Anatoly Yakovenko, had a Steve Jobs moment when he stood in front of an auditorium in New York City and announced the launch of Saga, an Android web3-focused smartphone. "This is something that I fundamentally believe the industry needs to do," Yakovenko said. "We didn't see a single crypto feature at the Apple developer conference 13 years after Bitcoin was alive." People will pull out their laptops in the middle of dates so they don't miss an NFT minting opportunity, Yakovenko joked. "So I think it's time for crypto to go mobile," Yakovenko added.

Saga aims to implement digital asset products and services, so users can easily transact with their cryptocurrency through the device, opposed to a laptop browser. In addition to the announcement of Saga, Yakovenko shared the launch of the Solana Mobile Stack, or SMS, which is a web3 layer for Solana built on the phone. SMS will consist of a number of products including a seed vault, a custody solution, a mobile wallet adapter, Solana Pay for Android and its decentralized application (dApp) store. It "provides a new set of libraries for wallets and apps, allowing developers to create rich mobile experiences on Solana," a press release said.

A number of crypto companies including FTX, Phantom and Magic Eden will partner with SMS and there is also a $10 million developer fund for people who build apps on it. "The builders are coming and they are higher quality than before," Raj Gokal, COO at Solana Labs said. "They're ready for the next leg of user growth." The $1,000 device will have 512 GB of storage with a 6.67-inch OLED display and is available for preorder with a $100 deposit and deliveries will occur in Q1 2023, Yakovenko said.

Slashdot Top Deals