Cellphones

Trump Team Considers Nationalizing America's 5G Network (axios.com) 383

JoeyRox writes: "Trump national security officials are considering an unprecedented federal takeover of a portion of the nation's mobile network to guard against China, according to sensitive documents obtained by Axios." This is based on a PowerPoint presentation Axios has in their possession. Two options are described -- a national 5G network funded and built by the Federal government, or a mix of 5G networks built by existing wireless providers. A source suggests the first option is preferred and essential to protect against competition from China and "bad actors". The presentation suggests that a government-built network would then be leased out to carriers like AT&T, Verizon, and T-Mobile.
The PowerPoint presentation was produced by a senior National Security Council official, and argues that the move is necessary because "China has achieved a dominant position in the manufacture and operation of network infrastructure," and "China is the dominant malicious actor in the Information Domain."

It also suggests America could export its secure 5G technology to protect its allies, and "Eventually this effort could help inoculate developing countries against Chinese neo-colonial behavior."
Government

Washington Bill Makes It Illegal To Sell Gadgets Without Replaceable Batteries (vice.com) 384

Jason Koebler writes: A bill that would make it easier to fix your electronics is rapidly hurtling through the Washington state legislature. The bill's ascent is fueled by Apple's iPhone-throttling controversy, which has placed a renewed focus on the fact that our electronics have become increasingly difficult to repair.

Starting in 2019, the bill would ban the sale of electronics that are designed "in such a way as to prevent reasonable diagnostic or repair functions by an independent repair provider. Preventing reasonable diagnostic or repair functions includes permanently affixing a battery in a manner that makes it difficult or impossible to remove."

Operating Systems

Apple Prepares MacOS Users For Discontinuation of 32-Bit App Support (arstechnica.com) 180

Last year, Apple announced that macOS High Sierra "will be the last macOS release to support 32-bit apps without compromise." Now, in the macOS High Sierra 10.13.4 beta, Apple is notifying users of the impending change, too. "To prepare for a future release of macOS in which 32-bit software will no longer run without compromise, starting in macOS High Sierra 10.13.4, a user is notified on the launch of an app that depends on 32-bit software. The alert appears only once per app," Apple says in the beta release notes. Ars Technica reports: When users attempt to launch a 32-bit app in 10.13.4, it will still launch, but it will do so with a warning message notifying the user that the app will eventually not be compatible with the operating system unless it is updated. This follows the same approach that Apple took with iOS, which completed its sunset of 32-bit app support with iOS 11 last fall. Developers and users curious about how this will play out will be able to look at the similar process in iOS for context. On January 1 of this year, Apple stopped accepting 32-bit app submissions in the Mac App Store. This June, the company will also stop accepting updates for existing 32-bit applications. iOS followed a similar progression, with 32-bit app submissions ending in February of 2015 and acceptance of app updates for 32-bit apps ending in June of 2015.
Cellphones

Jack White Bans Cellphones At Concerts For '100% Human Experience' (nme.com) 294

Singer and guitarist Jack White has banned the use of mobile phones at upcoming live shows. NME reports that the policy will be strictly enforced, requiring concert-goers to lock up their smartphones in pouches." From the report: White embarks on a tour of the U.S. from April, with a statement announcing that shows would be "phone-free," confirming: "No photos, video or audio recording devices allowed." "We think you'll enjoy looking up from your gadgets for a little while and experience music and our shared love of it IN PERSON," the statement adds. "Upon arrival at the venue, all phones and other photo or video-capturing gizmos will be secured in a Yondr pouch that will be unlocked at the end of the show. You keep your pouch-secured phone on you during the show and, if needed, can unlock your phone at any time in a designated Yondr Phone Zone located in the lobby or concourse." "For those looking to do some social media postings, let us help you with that. Our official tour photographer will be posting photos and videos after the show... Repost our photos & videos as much as you want and enjoy a phone-free, 100% human experience."
Cellphones

Study Links Decline In Teenagers' Happiness To Smartphones (pressherald.com) 158

An anonymous reader quotes a report from Press Herald: In a study published Monday in the journal Emotion, psychologists from San Diego State University and the University of Georgia used data on mood and media culled from roughly 1.1 million U.S. teens to figure out why a decades-long rise in happiness and satisfaction among U.S. teenagers suddenly shifted course in 2012 and declined sharply over the next four years. Was this sudden reversal a response to an economy that tanked in 2007 and stayed bad well into 2012? Or did it have its roots in a very different watershed event: the 2007 introduction of the smartphone, which put the entire online world at a user's fingertips?

In the new study, researchers tried to find it by plumbing a trove of eighth-, 10th- and 12th-graders' responses to queries on how they felt about life and how they used their time. They found that between 1991 and 2016, adolescents who spent more time on electronic communication and screens -- social media, texting, electronic games, the internet -- were less happy, less satisfied with their lives and had lower self-esteem. TV watching, which declined over the nearly two decades they examined, was similarly linked to lower psychological well-being. By contrast, adolescents who spent more time on non-screen activities had higher psychological well-being. They tended to profess greater happiness, higher self-esteem and more satisfaction with their lives. While these patterns emerged in the group as a whole, they were particularly clear among eighth- and 10th-graders, the authors found: "Every non-screen activity was correlated with greater happiness, and every screen activity was correlated with less happiness."

Operating Systems

Fitbit Will End Support For Pebble Smartwatches In June (arstechnica.com) 93

Today, Fitbit announced that it will extend its support of the Pebble smartwatch ecosystem, including devices, software, and forums, until June 30, 2018. "During this time, we invite the Pebble community to explore how familiar highlights from the Pebble ecosystem are evolving on the Fitbit platform, from apps and clock faces to features and experiences," the company's blog post states. Ars Technica reports: Fitbit's invitation is a hopeful one for the company itself. After the buyout, members of the Pebble team helped Fitbit develop its own smartwatch OS that debuted on the $300 Fitbit Ionic last year. Fitbit is likely hoping that diehard members of the Pebble community, many of which developed apps and programs for the smartwatch platform, will try making similar programs for Fitbit's new wearable operating system. The Fitbit SDK is already quite accessible, allowing developers to sign up and start building programs using all-online tools. But in addition to the accessibility of the SDK, Fitbit wants to entice Pebble users with a discount: users with a valid Pebble device serial number can get $50 off a Fitbit Ionic smartwatch. It's currently the only device that runs Fitbit OS, and it's useful to have if you want to test out any apps made with the SDK. But for those who want nothing to do with Fitbit OS development and only care about how long their Pebbles will last, this news is bittersweet. According to Fitbit's announcement, Pebble devices will continue to work after June 30, but these features will stop working: the Pebble app store, the Pebble forum, voice recognition features, SMS and email replies, timeline pins from third-party apps (although calendar pins will still function), and the CloudPebble development tool.
Medicine

Apple Adds Medical Records Feature For iPhone (cnbc.com) 101

On Wednesday, Apple released the test version of a new product that lets users download their health records, store them safely and show them to a doctor, caregiver or friend. "We view the future as consumers owning their own health data," Apple COO Jeff Williams said in an interview with CNBC. From the report: It all works when a user opens the iPhone's health app, navigates to the health record section, and, on the new tool, adds a health provider. From there, the user taps to connect to Apple's software system and data start streaming into the service. Patients will get notified via an alert if new information becomes available. In June, CNBC first reported on Apple's plans, including early discussions with top U.S. hospitals. The company confirmed that it has contracts with about a dozen hospitals across the country, including Cedars-Sinai, Johns Hopkins Medicine, Penn Medicine and the University of California, San Diego. The medical information available will include allergies, conditions, immunizations, lab results, medications, procedures and vitals. The information is encrypted and protected through a user's iPhone passcode.
Android

Android Can Now Tell You How Fast Wi-Fi Networks Are Before You Join Them (theverge.com) 44

Today, Google announced that Android 8.1 Oreo will now display the speed of nearby open Wi-Fi networks to help you decide whether they're even worth the effort of connecting to. The Wi-Fi settings menu will now display one of four speed labels: Very Fast, Fast, OK, or Slow. The Verge reports: The difference between Very Fast and Fast, according to Google, is that you can stream "very high-quality videos" on the former and "most videos" on the latter. Most coffee shop dwellers should be fine with the OK level, as that's enough for web browsing, social media, and Spotify streaming. Private Wi-Fi networks that require passwords don't display any speed data since it's really none of your business and Google can't randomly test them, but they do continue to indicate signal strength. Google says network administrators can also opt out of Android's Wi-Fi Assistant showing speed info by using a "canary URL."
Iphone

iPhone X Purchase Leads To Police, Battering Ram, and Handcuffs (cbslocal.com) 411

An anonymous reader quotes CBS SFBayArea: On one recent morning, Rick Garcia and his wife Shannon Knuth woke up to a posse of San Francisco police officers at their front door. "I peered through the peephole and I saw a police officer and a battering ram," Garcia said. "We heard 'SFPD' and 'warrant,' and I was like 'what's going on?'" Knuth remembers. It felt like a nightmare yet it was real. Garcia says that within seconds he was dragged into the hallway of his apartment complex, handcuffed, then whisked away to the Taraval Station.... Meanwhile Knuth, who had just got out of the shower, was ordered to sit on the couch... After rifling through the apartment Knuth says the officers finally told her what they were looking for: Her husband's iPhone X.

According to the warrant, it was stolen but Knuth showed them the receipt which proved her husband bought it. Once the officers realized their mistake they called the police station and a squad car brought Garcia home. "They gathered their pry bar and their battering ram and they left," he said. So how could a mistake like that happen? It's still unclear but it turns out Garcia and Knuth bought the iPhone at an Apple store at Stonestown Galleria just a few weeks after 300 iPhone Xs were stolen from a UPS truck in the mall parking lot.

One former police chief says the way it was handled "kind of boggles the mind...

"This was clearly an incident that should have just been a knock and talk, a couple detectives come to the door, knock on the door and they would have gathered the same info that they gathered after they put him in handcuffs and hauled him off to jail."
Electronic Frontier Foundation

EFF: Thousands of People Have Secure Messaging Clients Infected By Spyware (eff.org) 35

An anonymous reader quotes the EFF: The Electronic Frontier Foundation (EFF) and mobile security company Lookout have uncovered a new malware espionage campaign infecting thousands of people in more than 20 countries. Hundreds of gigabytes of data has been stolen, primarily through mobile devices compromised by fake secure messaging clients. The trojanized apps, including Signal and WhatsApp, function like the legitimate apps and send and receive messages normally. However, the fake apps also allow the attackers to take photos, retrieve location information, capture audio, and more.

The threat, called Dark Caracal by EFF and Lookout researchers, may be a nation-state actor and appears to employ shared infrastructure which has been linked to other nation-state actors. In a new report, EFF and Lookout trace Dark Caracal to a building belonging to the Lebanese General Security Directorate in Beirut. "People in the U.S., Canada, Germany, Lebanon, and France have been hit by Dark Caracal. Targets include military personnel, activists, journalists, and lawyers, and the types of stolen data range from call records and audio recordings to documents and photos," said EFF Director of Cybersecurity Eva Galperin. "This is a very large, global campaign, focused on mobile devices. Mobile is the future of spying, because phones are full of so much data about a person's day-to-day life."

Dark Caracal apparently gets installed through carefully-targeted spearphishing attacks, accoridng to the EFF. "Several types of phishing emails directed people -- including military personnel, activists, journalists, and lawyers -- to go to a fake app store-like page, where fake Android apps waited. There is even evidence that, in some cases, Dark Caracal used physical access to people's phones to install the fake apps."
Iphone

Apple Might Discontinue the iPhone X This Summer (bgr.com) 181

BGR shares a startling prediction from Ming-Chi Kuo, the Apple analyst at KGI securities: Kuo -- who we should note has an exemplary track record with respect to iPhone rumors -- adds that Apple may opt to discontinue the current iPhone X entirely if sales are underwhelming. "KGI also expects a trio of iPhone models in the fall of 2018," AppleInsider notes. "He predicts the iPhone X will be 'end of life' in the summer of 2018, instead of being retained as a lower-cost option in the following year." If Kuo's projection pans out, this would represent a marked shift in Apple's iPhone sales strategy. Going back nearly a decade, Apple has always positioned older iPhone models around as a wallet-friendly alternative for users who weren't keen on paying a premium for Apple's latest and greatest.
The Internet

Ajit Pai's FCC Can't Admit Broadband Competition Is a Problem (dslreports.com) 109

An anonymous reader quotes a report from DSLReports: While the FCC is fortunately backing away from a plan that would have weakened the standard definition of broadband, the agency under Ajit Pai still can't seem to acknowledge the lack of competition in the broadband sector. Or the impact this limited competition has in encouraging higher prices, net neutrality violations, privacy violations, or what's widely agreed to be some of the worst customer service of any industry in America. The Trump FCC had been widely criticized for a plan to weaken the standard definition of broadband from 25 Mbps down, 3 Mbps up, to include any wireless connection capable of 10 Mbps down, 1 Mbps up. Consumer advocates argued the move was a ham-fisted attempt to try and tilt the data to downplay the industry's obvious competitive and coverage shortcomings. They also argued that the plan made no coherent sense, given that wireless broadband is frequently capped, often not available (with carrier maps the FCC relies on falsely over-stating coverage), and significantly more expensive than traditional fixed-line service.

In a statement (pdf), FCC boss Ajit Pai stated the agency would fortunately be backing away from the measure, while acknowledging that frequently capped and expensive wireless isn't a comparable replacement for fixed-line broadband. "The draft report maintains the same benchmark speed for fixed broadband service previously adopted by the Commission: 25 Mbps download/3 Mbps upload," stated Pai. "The draft report also concludes that mobile broadband service is not a full substitute for fixed service. Instead, it notes there are differences between the two technologies, including clear variations in consumer preferences and demands." That's the good news. The bad news: the FCC under Pai's leadership continues to downplay and ignore the lack of competition in the sector, and the high prices and various bad behaviors most people are painfully familiar with.

Wireless Networking

Google Releases Fix For Chromecast Wi-Fi Crashes (zdnet.com) 32

An anonymous reader quotes a report from ZDNet: Google on Wednesday said it will release an update Jan. 18 to fix a bug in Cast software on Android phones that dramatically slows down WiFi networks. Reports have been circulating this week that the Google Home Max speaker can knock the TP-Link Archer C7 router offline. In a support page, Google explains a bug caused the Cast software that connects with Chromecast devices to send a large amount of network traffic routers can't handle. Google said the update will roll out via a Google Play services update. Until the update is released, Google advises users to try rebooting their Android phone, and check that their WiFi router is updated with the latest firmware. Google didn't list specific routers impacted by the bug, but reports have indicated routers from Linksys and Synology are seeing network crashes as well.
Operating Systems

Google's Fuchsia OS On the Pixelbook (arstechnica.com) 72

An anonymous reader quotes a report from 9to5Google: Our early look at Fuchsia OS last May provided a glimpse into a number of new interface paradigms. Several months later, we now have an updated hands-on with Google's future operating system that can span various form factors. This look at the in-development OS eight months later comes courtesy of Ars Technica who managed to get Fuchsia installed on the Pixelbook. The Made by Google Chromebook is only the third officially supported "target device" for Fuchsia development. As our last dive into the non-Linux kernel OS was through an Android APK, we did not encounter a lockscreen. The Ars hands-on shows a basic one that displays the time at center and Fuchsia logo in the top-left corner to switch between phone and desktop/tablet mode, while a FAB (of sorts) in the opposite corner lets users bring up WiFi controls, Login, and Guest.

Only Guest is fully functioning at this stage -- at least for non-Google employees. Once in this mode, we encounter an interface similar to the one we spotted last year. The big difference is how Google has filled in demo information and tweaked some elements. On phones and tablets, Fuchsia essentially has three zones. Recent apps are above, at center are controls, and below is a mixture of the Google Feed and Search. The controls swap out the always-displayed profile icon for a Fuchsia button. Tapping still surfaces Quick Settings which actually reflect current device battery levels and IP address. Impressively, Ars found a working web browser that can actually surf the internet. Google.com is the default homepage, with users able to visit other sites through that search bar. Other examples of applications, which are just static images, include a (non-working) phone dialer, video player, and Google Docs. The Google Calendar is notable for having subtle differences to any known version, including the tablet or web app.

Security

'Text Bomb' Is Latest Apple Bug (bbc.com) 60

An anonymous reader quotes a report from the BBC: A new "text bomb" affecting Apple's iPhone and Mac computers has been discovered. Abraham Masri, a software developer, tweeted about the flaw which typically causes an iPhone to crash and in some cases restart. Simply sending a message containing a link which pointed to Mr Masri's code on programming site GitHub would be enough to activate the bug -- even if the recipient did not click the link itself. Mr Masri said he "always reports bugs" before releasing them. Apple has not yet commented on the issue. On a Mac, the bug reportedly makes the Safari browser crash, and causes other slowdowns. Security expert Graham Cluley wrote on his blog that the bug does not present anything to be particularly worried about -- it's merely very annoying. After the link did the rounds on social media, Mr Masri removed the code from GitHub, therefore disabling the "attack" unless someone was to replicate the code elsewhere.
Businesses

Tim Cook Says Power Management Feature In Older iPhones Will Be Able To Be Turned Off In Future Update (macrumors.com) 162

In an interview with Rebecca Jarvis of ABC News, Apple CEO Tim Cook touched on the ongoing controversy over power management features in older iPhones. He says that a future update will allow customers to turn off the power management feature that has caused older iPhones to slow down. Mac Rumors reports: According to Cook, when the power management features were first introduced in iOS 10.2.1, Apple did explain what was going on, but following the controversy, he believes Apple should have been clearer. The company did indeed mention that the shutdown issue was caused by uneven power delivery and explained that its power management system had been tweaked, but there was no clear notice that it could cause devices to operate more slowly at times. Cook says Apple "deeply apologizes" to customers who thought the company had other motivations. Apple is introducing better battery monitoring features in a future iOS update, and Cook says Apple will also allow customers to turn off the power management feature, which is new information that the company has not previously shared. The majority of the interview was focused on the announcements that Apple made today. The company plans to contribute $350 billion in the U.S. economy over the next five years, as well as issue employees a bonus of $2,500 of restricted stock units following the introduction of the new U.S. tax law.
Security

Many Enterprise Mobile Devices Will Never Be Patched Against Meltdown, Spectre (betanews.com) 104

Mark Wilson shares a report from BetaNews: The Meltdown and Spectre bugs have been in the headlines for a couple of weeks now, but it seems the patches are not being installed on handsets. Analysis of more than 100,000 enterprise mobile devices shows that just a tiny percentage of them have been protected against the vulnerabilities -- and some simply may never be protected. Security firm Bridgeway found that just 4 percent of corporate phones and tablets in the UK have been patched against Spectre and Meltdown. Perhaps more worryingly, however, its research also found that nearly a quarter of enterprise mobile devices will never receive a patch because of their age. Organizations are advised to check for the availability of patches for their devices, and to install them as soon as possible. Older devices that will never be patched -- older than Marshmallow, for example -- should be replaced to ensure security, says Bridgeway.
Wireless Networking

Google Home and Chromecast Could Be Overloading Your Home Wi-Fi (theverge.com) 129

Google Cast products could be to blame for your wonky internet connection. According to TP-Link, "The Cast feature normally sends packets of information at regular intervals to keep a live connection with products like Google Home," reports The Verge. "However, if the device is awakened from a 'sleep' mode, it will sometimes send a burst of information at once, which can overwhelm a router. The longer a Cast device has been in 'sleep' mode, the more information it might send at once." The engineer says that could exceed over 100,000 packets, an amount that "may eventually cause some of [the] router's primary features to shut down -- including wireless connectivity."

TP-Link has reportedly fixed the issue in its C1200 router, but a broader fix from Google's end has not been found.
The Almighty Buck

OnePlus Customers Report Credit Card Fraud After Buying From the Company's Website (androidpolice.com) 63

If you purchased a OnePlus smartphone recently from the official OnePlus website, you might want to check your transactions to make sure there aren't any you don't recognize. "A poll was posted on the OnePlus forum on Thursday asking users if they had noticed fraudulent charges on their credit cards since purchasing items on the OnePlus site," reports Android Police. "More than 70 respondents confirmed that they had been affected, with the majority saying they had bought from the site within the past 2 months." From the report: A number of FAQs and answers follow, in which OnePlus confirms that only customers who made credit card payments are affected, not those who used PayPal. Apparently, card info isn't stored on the site but is instead sent directly to a "PCI-DSS-compliant payment processing partner" over an encrypted connection. [...] OnePlus goes on to say that intercepting information should be extremely difficult as the site is HTTPS encrypted, but that it is nevertheless carrying out a complete audit. In the meantime, affected customers are advised to contact their credit card companies immediately to get the payments canceled/reversed (called a chargeback). OnePlus will continue to investigate alongside its third-party service providers, and promises to update with its findings as soon as possible.

According to infosec firm Fidus, there is actually a brief window in which data could be intercepted. Between entering your card details into the form and hitting 'submit,' the details are apparently hosted on-site, which could give attackers all the time they need to steal those precious digits and head off on a spending spree. Fidus also notes that the company doesn't appear to be PCI-compliant, but that directly contradicts OnePlus' own statement. We'll have to wait until more details emerge before we pass judgment.
Here's OnePlus' official statement on the matter: "At OnePlus, we take information privacy extremely seriously. Over the weekend, members of the OnePlus community reported cases of unknown credit card transactions occurring on their credit cards post purchase from oneplus.net. We immediately began to investigate as a matter of urgency, and will keep you updated. This FAQ document will be updated to address questions raised."
Communications

The Tech Failings of Hawaii's Missile Alert 232

Over the weekend, Hawaii incorrectly warned citizens of a missile attack via their phones. According to The Washington Post, the error was a result of a staffer picking the wrong option -- missile alert instead of test missile alert -- from a drop down software menu. Hawaiian officials say they have already changed protocols to avoid a repeat of the scenario. The report goes on to add: Part of what worsened the situation Saturday was that there was no system in place at the state emergency agency for correcting the error, HEMA (Hawaii Emergency Management Agency) spokesman Richard Rapoza said. The state agency had standing permission through FEMA to use civil warning systems to send out the missile alert -- but not to send out a subsequent false alarm alert, he said. Though the Hawaii Emergency Management Agency posted a follow-up tweet at 8:20 a.m. saying there was "NO missile threat," it wouldn't be until 8:45 a.m. that a subsequent cellphone alert was sent telling people to stand down. Motherboard notes that new regulations require telecom companies to offer a testing system for local and state alert originators, but because of lobbying by Verizon and CTIA, this specific regulation does not go into effect until March 2019.

In a piece, The Atlantic argues that the 90-character messages sent by the system aren't suited to the way we use our devices.

Slashdot Top Deals