Android

iOS and Android Combined For Record 99% of Smartphone Sales Last Quarter (macrumors.com) 191

An anonymous reader writes: The research firm Gartner has crunched some numbers and found that Android and iOS accounted for a record 99.1% worldwide market share in the second calendar quarter of 2016, which is compared to 96.8% in the year-ago period. What some may view as even more shocking is that Android accounted for 86.2% of the market share in the second quarter, up from 82.2% a year ago. Meanwhile, iOS lost some ground as it dropped to 12.9% market share from 14.6% in the year-ago period. It's no surprise that Windows and BlackBerry have been losing market share. They dropped to 0.6% and 0.1% market share worldwide respectively. Just six years ago, BlackBerry and Symbian operating systems were industry leaders. Now, they're industry losers. Which third-party operating system has what it takes to take on the establishment?
Android

Companies Can't Legally Void the Warranty For Jailbreaking Or Rooting Your Phone (vice.com) 128

Reader Jason Koebler writes: Manufacturers that threaten to void the warranties of consumers who jailbreak or root their phones are violating federal law.
Under the Magnuson-Moss Warranty Act of 1975, manufacturers cannot legally void your hardware warranty simply because you altered the software of an electronic device. In order to void the warranty without violating federal law, the manufacturer must prove that the modifications you made directly led to a hardware malfunction.
"They have to show that the jailbreak caused the failure. If yes, they can void your claim (not your whole warranty—just the things which flowed from your mod)," Steve Lehto, a lemon law attorney in Michigan, wrote in an email. "If not, then they can't."

AT&T

AT&T Is Boosting Data Plans, Dropping Overage Fees (reuters.com) 71

An anonymous reader quotes a report from Reuters: ATT Inc, the No. 2 U.S wireless provider, said on Wednesday that it would roll out a new data plan that does away with overage fees and reduces data speeds for wireless customers who surpass their data allowance. Beginning Sunday, customers can choose the new Mobile Share Advantage plan and pay for extra data, if needed, or work with slower data speeds instead of paying for overages, the company said in a statement. Its current plan includes a $5 data overage charge per 300 megabytes on its 300-megabyte plan and $15 per 1 gigabyte on other plans. ATT has also revised prices and data bucket sizes. For instance, its larger 25-gigabyte plan now costs $190 per month for four smartphone lines. It previously cost $235. All the new plans include an access charge of $10 to $40 per month for each device, ATT said. The new plans will continue to have features such as unlimited text and talk and rollover data. Plans above 10 gigabytes also include unlimited talk and text to Mexico and Canada and no roaming charges in Mexico. Last month, Verizon introduced a new "Safety Mode" for its data plans that similarly throttles customers who exceed their monthly allotment to avoid overages. While Verizon charges customers on lower tier plans for the feature, ATT notes that it does not apply any extra charges.
Google

Malware That Fakes Bank Login Screens Found In Google Ads (fastcompany.com) 120

tedlistens quotes a report from Fast Company: For years, security firms have warned of keystroke logging malware that surreptitiously steals usernames and passwords on desktop and laptop computers. In the past year, a similar threat has begun to emerge on mobile devices: So-called overlay malware that impersonates login pages from popular apps and websites as users launch the apps, enticing them to enter their credentials to banking, social networking, and other services, which are then sent on to attackers. Such malware has even found its way onto Google's AdSense network, according to a report on Monday from Kaspersky Lab. The weapon would automatically download when users visited certain Russian news sites, without requiring users to click on the malicious advertisements. It then prompts users for administrative rights, which makes it harder for antivirus software or the user to remove it, and proceeds to steal credentials through fake login screens, and by intercepting, deleting, and sending text messages. The Kaspersky researchers call it "a gratuitous act of violence against Android users." "By simply viewing their favorite news sites over their morning coffee users can end up downloading last-browser-update.apk, a banking Trojan detected by Kaspersky Lab solutions as Trojan-Banker.AndroidOS.Svpeng.q," according to the company. "There you are, minding your own business, reading the news and BOOM! -- no additional clicks or following links required." The good news is that the issue has since been resolved, according to a Google spokeswoman. Fast Company provides more details about these types of attacks and how to stay safe in its report.
Intel

Intel Unveils Project Alloy 'Merged Reality' Wireless Headset (hothardware.com) 43

MojoKid writes: Intel CEO Bryan Krzanich took to the stage at the Moscone Center in San Francisco today to kick off this year's Intel Developers Forum. Kyrzanich unveiled a number of new projects and products including a product code-named "Project Alloy." The device is an un-tethered, merged reality Head Mounted Device (HMD) that combines compute, graphics, multiple RealSense modules, various sensors, and batteries into a self-contained headset that offers a full six degrees of freedom. Unlike the Oculus Rift and HTC Vive, Project Alloy does not need to be wired to a PC or other device and it does not require externally mounted sensors to define a virtual space. Instead, it uses RealSense cameras to map the actual physical world you're in while wearing the HMD. The RealSense cameras also allow the device to bring real-world objects into the virtual world, or vice versa. The cameras and sensors used in Project Alloy offer full depth sensing, so obstacles can be mapped, and people and objects within camera range -- like your hand, for example -- can be brought into the virtual world and accurately tracked. During a live, on-stage demo performed by Intel's Craig Raymond, Craig's hand was tracked and all five digits, complete with accurate bones and joint locations, were brought into the the VR/AR experience. Project Alloy will be supported by Microsoft's Windows Holographics Shell framework.
Cellphones

FCC Complaint: Baltimore Police Breaking Law With Use of Stingray Phone Trackers (baltimoresun.com) 108

An anonymous reader writes from a report via Baltimore Sun: Civil rights groups have complained to the FCC over the Baltimore Police Department's use of stingray phone tracking devices. They claim that "the way police use it interferes with emergency calls and is racially discriminatory." Baltimore Sun reports: "The complaint argues that the police department doesn't have a proper license to use the devices and is in violation of federal law. It calls on regulators at the Federal Communications Commission to step in and formally remind law enforcement agencies of the rules. 'The public is relying on the Commission to carry out its statutory obligation to do so, to fulfill its public commitment to do so, and to put an end to widespread network interference caused by rampant unlicensed transmissions made by BPD and other departments around the country,' the groups say in the complaint. Police in Baltimore acknowledged in court last year that they had used the devices thousands of times to investigate crimes ranging from violent attacks to the theft of cellphones. Investigators had been concealing the technology from judges and defense lawyers and after the revelations Maryland's second highest court ruled that police should get a warrant before using a Stingray. The groups argue that surveillance using the devices also undermines people's free speech rights and describe the use of Stingrays as an electronic form of the intrusive police practices described in the scathing Justice Department report on the police department's pattern of civil rights violations."
Cellphones

Former CEO of Angry Birds-Maker Rovio Hired To Revive Nokia's Phone Business (techcrunch.com) 88

An anonymous reader writes: Nokia really started to go downhill after it agreed to sell itself to Microsoft at the end of 2013, going all in with Windows Mobile. When that faltered, "Microsoft folded Nokia into its mobile business, maintaining the Finnish company's brand on feature phones, while offering up smartphones under the newly integrated Microsoft Lumia line," reports TechCrunch. In May of this year, Microsoft sold its feature phone business to Foxconn for $350 million. At around the same time, Nokia essentially licensed its brand to Finnish company HMD global Oy to create phones under the Nokia name, "which would be manufactured and distributed by Foxconn." Now, TechCrunch is reporting that Nokia has hired Pikka Rantala, the once CEO of Angry Birds creator Rovio, who stepped down in 2015 after a rough year with the mobile gaming company. He will be joining the company as Chief Marketing Officer.
Privacy

Tim Cook: Privacy Is Worth Protecting (washingtonpost.com) 120

An anonymous reader writes from InformationWeek: In a wide-ranging interview with The Washington Post, Apple's CEO Tim Cook talks iPhones, AI, privacy, civil rights, missteps, China, taxes, and Steve Jobs -- all without addressing rumors about the company's Project Titan electric car. One of the biggest concerns Tim Cook has is with user privacy. Earlier this year, Apple was in the news for refusing a request from the U.S. Department of Justice to unlock a suspected terrorist's iPhone because Apple argued it would affect millions of other iPhones, it was unconstitutional, and that it would weaken security for everyone. Cook told the Washington Post: "The lightbulb went off, and it became clear what was right: Could we create a tool to unlock the phone? After a few days, we had determined yes, we could. Then the question was, ethically, should we? We thought, you know, that depends on whether we could contain it or not. Other people were involved in this, too -- deep security experts and so forth, and it was apparent from those discussions that we couldn't be assured. The risk of what happens if it got out, could be incredibly terrible for public safety." Cook suggest that customers rely on companies like Apple to set up privacy and security protections for them. "In this case, it was unbelievably uncomfortable and not something that we wished for, wanted -- we didn't even think it was right. Honestly? I was shocked that [the FBI] would even ask for this," explained Cook. "That was the thing that was so disappointing that I think everybody lost. There are 200-plus other countries in the world. Zero of them had ever asked [Apple to do] this." Privacy is a right to be protected, believes Cook: "In my point of view, [privacy] is a civil liberty that our Founding Fathers thought of a long time ago and concluded it was an essential part of what it was to be an American. Sort of on the level, if you will, with freedom of speech, freedom of the press."
Communications

Google Fiber Is Changing Its Strategy as Costs Grow (fortune.com) 160

Google is taking a strategy timeout on its high-speed-internet business. According to WSJ, the Google Fiber unit is -- including Los Angeles, Chicago, and Dallas -- after its initial rollouts proved time-consuming and expensive than anticipated -- is rethinking how to deliver internet connections in about a dozen metro areas (could be paywalled; alternate source). From a Fortune report: Turns out it is very expensive to run wires -- or in Google's case, fiber optic cables -- to each and every house that wants service. Known as the "last mile" problem, the high costs, in turn, make it difficult for companies to earn a solid rate of return on the installation investment. Google's effort, through its unit called Fiber that launched in 2010, is now seeking alternative means to connect to consumers homes or finding other people to pay the cost. Google has sought deals with municipalities and power companies to pay for the connections and is also exploring less expensive wireless technology. Meanwhile, Google has suspended efforts to add new cities such as San Jose, Calif., and Portland, Ore., using its prior strategy of stringing up cables to each customerâ(TM)s home.
Cellphones

Ask Slashdot: Are There Secure Alternatives To Skype? (theguardian.com) 237

How can you make a truly secure phone call? An anonymous Slashdot reader writes: I have a Windows 8.1 phone and mostly use it for Skype calls and chats. A bit of browsing every now and then, and checking public transportation schedules... What can I do to be able to securely chat and place audio/video calls? What do you think is the best device to buy and what apps to use on it?
Skype for Windows Phone will stop working in 2017, and Skype's privacy was already suspect after Edward Snowden leaked evidence of Microsoft's secret collaboration with the NSA. But are there any good alternatives -- especially for a Windows Phone user? Leave your suggestions in the comments. What are the best secure alternatives to Skype?
Government

Can We Avoid Government Surveillance By Leaving The Grid? (counterpunch.org) 264

Slashdot reader Nicola Hahn writes: While reporters clamor about the hacking of the Democratic National Committee, NSA whistleblower James Bamford offers an important reminder: American intelligence has been actively breaching email servers in foreign countries like Mexico and Germany for years. According to Bamford documents leaked by former NSA specialist Ed Snowden show that the agency is intent on "tracking virtually everyone connected to the Internet." This includes American citizens. So it might not be surprising that another NSA whistleblower, William Binney, has suggested that certain elements within the American intelligence community may actually be responsible for the DNC hack.

This raises an interesting question: facing down an intelligence service that is in a class by itself, what can the average person do? One researcher responds to this question using an approach that borrows a [strategy] from the movie THX 1138: "The T-H-X account is six percent over budget. The case is to be terminated."

To avoid surveillance, the article suggests "get off the grid entirely... Find alternate channels of communication, places where the coveted home-field advantage doesn't exist... this is about making surveillance expensive." The article also suggests "old school" technologies, for example a quick wireless ad-hoc network in a crowded food court. Any thoughts?
Security

New Cache Attack Can Monitor Keystrokes On Android Phones (onthewire.io) 36

Trailrunner7 quotes a report from OnTheWire: : Researchers from an Austrian university have developed techniques that allow them to perform cache attacks on non-rooted Android phones that can monitor the keystrokes, screen taps, and even observe code execution inside the ARM processor's TrustZone secure execution environment. The attacks the team developed are complex and rely on a number of individual building blocks. The techniques are similar to some used against Intel x86 processor-based systems, but the team from Graz University of Technology in Austria shows that they can be used on ARM-based systems, such as Android phones, as well.

"Based on our techniques, we demonstrate covert channels that outperform state-of-the-art covert channels on Android by several orders of magnitude. Moreover, we present attacks to monitor tap and swipe events as well as keystrokes, and even derive the lengths of words entered on the touchscreen," the researchers wrote in their paper, which was presented at the USENIX Security Symposium this week.

It's a proof-of-concept attack. But interestingly, another recently-discovered Android vulnerability also required the user to install a malicious app -- and then allowed attackers to take full control of the device.
Google

Google Working On New 'Fuchsia' OS (digitaltrends.com) 146

An anonymous reader writes: Google is working on a new operating system dubbed Fuchsia OS for smartphones, computers, and various other devices. The new operating system was spotted in the Git repository, where the description reads: "Pick + Purple == Fuchsia (a new Operating System). Hacker News reports that Travis Geiselbrech, who worked on NewOS, BeOS, Danger, Palm's webOS and iOS, and Brian Swetland, who also worked on BeOS and Android will be involved in this project. Magenta and LK kernel will be powering the operating system. "LK is a kernel designed for small systems typically used in imbedded applications," reads the repository. "On the other hand, Magenta targets modern phones and modern personal computers with fast processors, non-trivial amounts of RAM with arbitrary peripherals doing open-ended computation." It's too early to tell exactly what this OS is meant for. Whether it's for an Android and Chrome OS merger or something completely new, it's exciting nonetheless.
Democrats

Hacker Publishes Cell Phone Numbers of House Democrats (thehill.com) 82

Another day, another leak. A suspected Russian hacker known as "Guccifer 2.0" has published the phone numbers of House Democrats on his website Friday. The Hill reports: "The document was obtained from the cyberattack on the Democratic Congressional Campaign Committee (DCCC). The hacker also published DCCC shared passwords to several online databases and news networks. The dump also included the memos on the House race for Florida's 18th district, including opposition research on the Republican contenders, which is being vacated by Democrat Patrick Murphy as he vies for the Senate. The hacker also claimed to have breached House Minority Leader Nancy Pelosi's computer and published a memo sent to her about a 2015 fundraiser for Morgan Carroll, who is running for a Colorado House seat against Republican Mike Coffman."
Canada

Local Canadian Police Station Admits To Owning Stingray Surveillance Device (vice.com) 43

The Edmonton Police Service has admitted to Motherboard that it owns a Stingray and that it used the [surveillance] device in the past during investigations. After Vancouver cops admitted to using the phone tracker to investigate an abduction in 2007, Motherboard called up other local police stations in Canada to ask if they had also previously used one. As you can imagine, the other stations kept mum. In the US, Stingrays are a regular part of government and law enforcement agencies' surveillance arsenal. But Vancouver's and Edmonton's police services are the first law enforcement offices in Canada to confirm that they've used the device. Motherboard adds: According an emailed statement from police spokesperson Anna Batchelor, Edmonton's cops have "used the device in the past during investigations," but would not release any additional details in order to "to protect [Edmonton Police Service] operations." Until now, the only law enforcement in the country known to use the devices was the Royal Canadian Mounted Police, the country's analogue to the US Federal Bureau of Investigation. These suitcase-sized surveillance tools have been used in the past by the Vancouver and Toronto police, but the Vancouver police have said they borrowed the Stingray from the RCMP, and in Toronto an RCMP technician was on hand, at least in that incident. The Edmonton police's comment to Motherboard is the first time a local police department in Canada has publicly admitted to owning a Stingray device.
DRM

Cory Doctorow On What iPhone's Missing Headphone Jack Means For Music Industry (fastcompany.com) 394

Rumors of Apple's next iPhone missing a headphone jack have been swirling around for more than a year now. But a report from WSJ a few weeks ago, and another report from Bloomberg this week further cemented such possibility. We've talked about it here -- several times -- but now Cory Doctorow is shedding light on what this imminent change holds for the music industry. Reader harrymcc writes: Fast Company's Mark Sullivan talked about the switch with author and EFF adviser Cory Doctorow, who thinks it could lead to music companies leveraging DRM to exert more control over what consumers can do with their music.From the article:"If Apple creates a circumstance where the only way to get audio off its products is through an interface that is DRM-capable, they'd be heartbreakingly naive in assuming that this wouldn't give rise to demands for DRM," said Doctorow. If a consumer or some third-party tech company used the music in way the rights holders didn't like, the rights holders could invoke the anti-circumvention law written in Section 1201 of the Digital Millennium Copyright Act (DMCA). Steve Jobs famously convinced the record industry to remove the DRM from music on iTunes; is there really any reason to believe the industry might suddenly become interested in DRM again if the iPhone audio goes all digital? "Yes -- for streaming audio services," Doctorow says. "I think it is inevitable that rights holder groups will try to prevent recording, retransmission, etc." Today it's easy to record streamed music from the analog headphone jack on the phone, and even to convert the stream back to digital and transmit it in real time to someone else. With a digital stream it might not be nearly so easy, or risk-free."Doctorow shares more on BoingBoing.
Republicans

Cracking The Code On Trump Tweets (time.com) 330

jIyajbe writes: From Electoral-Vote.com: "A theory has been circulating that the Donald Trump tweets that come from an Android device are from the candidate himself, while the ones that come from an iPhone are the work of his staff. David Robinson, a data scientist who works for Stack Overflow, decided to test the theory. His conclusion: It's absolutely correct. Robinson used some very sophisticated algorithms to analyze roughly 1,400 tweets from Trump's timeline, and demonstrated conclusively that the iPhone tweets are substantively different than the Android tweets. The former tend to come later at night, and are vastly more likely to incorporate hashtags, images, and links. The latter tend to come in the morning, and are much more likely to be copied and pasted from other people's tweets. In terms of word choice, the iPhone tweets tend to be more neutral, with their three most-used phrases being 'join,' '#trump2016,' and '#makeamericagreatagain.' The Android tweets tend to be more emotionally charged, with their three most-used phrases being 'badly,' 'crazy,' and 'weak.'" reifman adds: In an excellent forensic text analysis of Trump's tweets with the Twitter API, data geek David Robinson demonstrates Trump authors his angriest, picture-less, hashtag-less Android tweets often in the morning, while staff tweet from an iPhone with pictures, hashtags and greater joy mostly in the middle of the day. Robinson's report was inspired by a tweet by artist Todd Vaziri. As for why Robinson decided to look into Trump's tweets, he told TIME, "For me it's more about finding a really interesting story, a case where people suspect something, but don't have the data to back it up. For me it was much more about putting some quantitive details to this story that has been going around than it was about proving something about Trump's campaign."
Security

A New Wireless Hack Can Unlock Almost Every Volkswagen Sold Since 1995 (arstechnica.com) 115

Volkswagen isn't having the best of times. Tens of millions of vehicles sold by Volkswagen AG over the past 20 years are vulnerable to theft because keyless entry systems can be hacked using cheap technical devices, reports Wired (alternate source). Security experts of the University of Birmingham were able to clone VW remote keyless entry controls by eavesdropping nearby when drivers press their key fobs to open or lock up their cars. ArsTechnica reports: The first affects almost every car Volkswagen has sold since 1995, with only the latest Golf-based models in the clear. Led by Flavio Garcia at the University of Birmingham in the UK, the group of hackers reverse-engineered an undisclosed Volkswagen component to extract a cryptographic key value that is common to many of the company's vehicles. Alone, the value won't do anything, but when combined with the unique value encoded on an individual vehicle's remote key fob -- obtained with a little electronic eavesdropping, say -- you have a functional clone that will lock or unlock that car. VW has apparently acknowledged the vulnerability, and Greenberg (writer at Wired) notes that the company uses a number of different shared values, stored on different components. The second affects many more makes, "including Alfa Romeo, Citroen, Fiat, Ford, Mitsubishi, Nissan, Opel, and Peugeot," according to Greenberg. It exploits a much older cryptographic scheme used in key fobs called HiTag2. Again it requires some eavesdropping to capture a series of codes sent out by a remote key fob. Once a few codes had been gathered, they were able to crack the encryption scheme in under a minute.
Security

Samsung Pay Hack Lets Attackers Make Fraudulent Payments (theverge.com) 16

jmcbain writes: The Verge reports that a security researcher at DefCon outlined a number of attacks targeting Samsung Pay, Samsung's digital payment system that runs on their smartphones. According to the article, the attack "[focuses] on intercepting or fabricating payment tokens -- codes generated by the user's smartphone that stand in for their credit card information. These tokens are sent from the mobile device to the payment terminal during wireless purchases. [They expire 24 hours after being generated and are single-use only.]" In a response, Samsung said that "in certain scenarios an attacker could skim a user's payment token and make a fraudulent purchase with their card," but that "the attacker must be physically close to the target while they are making a legitimate purchase."
Android

Chrome Is Nearly Ready To Talk To Your Bluetooth Devices (engadget.com) 151

Jon Fingas, writing for Engadget: Don't look now, but your web browser is about to become aware of the devices around you. After months of testing, Google has switched on broader experimental support in Chrome and Chrome OS for Web Bluetooth, which lets websites interact with your nearby Bluetooth gear. You could use a web interface to control your smart home devices, for instance, or send data directly from your heart rate monitor to a fitness coach. At the moment, trying Web Bluetooth requires the stars to align in just the right way. You'll need a pre-release version of Chrome 53, and you'll naturally want to find (or create) a website that uses the tech in the first place.

Slashdot Top Deals