Cellphones

Carriers Agree To Start Sharing Vertical Location Data For 911 Calls (xda-developers.com) 23

The three major carriers in the U.S. have now agreed to start providing vertical location data for 911 calls, which will help first responders quickly locate 911 callers in multi-story buildings. XDA Developers reports: The FCC wrote in its announcement, "FCC Acting Chairwoman Jessica Rosenworcel today announced breakthrough agreements with America's three largest mobile phone providers to start delivering vertical location information in connection with 911 calls nationwide in the coming days. This information will help first responders quickly locate 911 callers in multi-story buildings, which will reduce response times and ultimately save lives."

The FCC first announced in 2015 that carriers would be required to start sharing vertical location data. The original deadline was June 2nd, 2021, but AT&T, T-Mobile, and Verizon wanted an 18-month extension (allegedly due to issues testing the functionality during the COVID-19 pandemic). With the deadline rapidly approaching, the FCC began an investigation in April to find out what was taking carriers so long. All three major carriers have now agreed to start providing vertical location data to 911 call centers within the next seven days, and each company will pay a $100,000 settlement. The agreement also increases the scope of the vertical location data; instead of the data only being provided in select areas, vertical location information will be provided by carriers across the entire United States. However, it will likely take longer than a week for the vertical data to be used in most 9-1-1 call centers, as the change will require updated software and (possibly) additional training for emergency dispatchers.

Wireless Networking

Samsung Will Shut Down the v1 SmartThings Hub This Month (arstechnica.com) 86

Samsung is killing the first-generation SmartThings Hub at the end of the month, kicking off phase two of its plan to shut down the SmartThings ecosystem and force users over to in-house Samsung infrastructure. "Phase one was in October, when Samsung killed the Classic SmartThings app and replaced it with a byzantine disaster of an app that it developed in house," writes Ars Technica's Ron Amadeo. "Phase three will see the shutdown of the SmartThings Groovy IDE, an excellent feature that lets members of the community develop SmartThings device handlers and complicated automation apps." From the report: The SmartThings Hub is basically a Wi-Fi access point -- but for your smart home stuff instead of your phones and laptops. Instead of Wi-Fi, SmartThings is the access point for a Zigbee and Z-Wave network, two ultra low-power mesh networks used by smart home devices. [...] The Hub connects your smart home network to the Internet, giving you access to a control app and connecting to other services like your favorite voice assistant. You might think that killing the old Hub could be a ploy to sell more hardware, but Samsung -- a hardware company -- is actually no longer interested in making SmartThings hardware. The company passed manufacturing for the latest "SmartThings Hub (v3)" to German Internet-of-things company Aeotec. The new Hub is normally $125, but Samsung is offering existing users a dirt-cheat $35 upgrade price.

For users who have to buy a new hub, migrating between hubs in the SmartThings ecosystem is a nightmare. Samsung doesn't provide any kind of migration program, so you have to unpair every single individual smart device from your old hub to pair it to the new one. This means you'll need to perform some kind of task on every light switch, bulb, outlet, and sensor, and you'll have to do the same for any other smart thing you've bought over the years. Doing this on each device is a hassle that usually involves finding the manual to look up the secret "exclusion" input, which is often some arcane Konami code. Picture holding the top button on a paddle light for seven seconds until a status light starts blinking and then opening up the SmartThings app to unpair it. Samsung is also killing the "SmartThings Link for Nvidia Shield" dongle, which let users turn Android TV devices into SmartThings Hubs.

Iphone

New Study Backs Up Finding That MagSafe Can Interfere With Medical Devices (gizmodo.com) 63

Back in January, researchers warned that the iPhone 12 lineup and MagSafe accessories could potentially deactivate implanted medical devices. Now, the American Heart Association has released a study that corroborates these findings on a larger scale, noting that several devices from three major companies were "found to have magnetic susceptibility." Gizmodo reports: The initial study published in HeartRhythm was done on a single patient with a Medtronic implantable cardioverter-defibrillator (ICD). It was an important finding in terms of awareness, but raised questions as to whether this would impact ICDs from all device makers if the iPhone 12 lineup posed a greater risk than other magnetized devices, and what the impact on pacemakers might be. The AHA's study offers a few preliminary insights into what those answers might be. In the study, researchers observed the impact of an iPhone 12 Pro Max on both ICDs and pacemakers from multiple device makers, as well as conducted both in vivo and ex vivo tests. In vivo refers to tests done on actual patients with an implanted medical device, while the ex vivo tests were done on 11 unboxed devices. The devices tested came from Medtronic, Abbot, and Boston Scientific. (You can see exactly which ICDs and pacemakers were tested in the study itself.)

In 100% of the three in vivo tests, the iPhone 12 Pro Max triggered the devices' magnet reversion mode. That said, the Boston Scientific pacemaker was found to be less susceptible as it only triggered a temporary response. In ex vivo testing, magnetic interference was detected in 8 out of 11 devices, or 72.7%. There are a few things to note here. How seriously a device is impacted may depend on the sensors or components used. The study notes that magnetic interference can occur when medical devices are exposed to magnetic fields as little as 10G. According to the researchers, the iPhone 12 Pro Max has a magnetic field strength of over 50G. However, the ex vivo devices tested didn't respond uniformly. Some were only temporarily disrupted, others had sustained asynchronous pacing, and three weren't impacted at all. The researchers suggest that in the case of a Boston Scientific Accolade MRI pacemaker, the device may not have been affected because it requires a magnet stronger than 70G.
After the HeartRhythm study was published, Apple issued additional guidance urging consumers with implanted medical devices to keep iPhone 12 devices more than 6 inches away, or more than 12 inches if wirelessly charging. It also recommended those people consult with both their physician and device manufacturer.
Cellphones

Man Dies Inside Spanish Dinosaur Statue After Trying To Retrieve His Phone (theguardian.com) 215

According to The Guardian, a man in Catalonia died after becoming trapped inside a large dinosaur statue while trying to retrieve his smartphone. From the report: Officers were called to the statue in Santa Coloma de Gramenet, a satellite town of Barcelona, after a man and his son noticed something inside the papier-mache stegosaurus on Saturday afternoon. A spokeswoman for the regional police force, the Mossos d'Esquadra, said the death of the 39-year-old man was not being treated as suspicious.

"A father and son noticed that there was something inside and raised the alarm," she said. "We found the body of a man inside the leg of this dinosaur statue. It's an accidental death; there was no violence. This person got inside the statue's leg and got trapped. It looks as though he was trying to retrieve a mobile phone, which he'd dropped. It looks like he entered the statue head first and couldn't get out." "We're still waiting for the autopsy results, so we don't know how long he was in there, but it seems he was there for a couple of days," she added.
Slashdot reader shanen submitted this story with the following commentary: Not sure what the technology link is. Smartphones make people stupid? Dinosaurs are scientific, but this is ridiculous? It would be funny, but it's too gruesome. But I guess I'll go ahead and submit it in the Darwin Awards category. Maybe a better title is man kills himself with dinosaur and smartphone? Death by paper mache?
Cellphones

How Samsung 'Ruined' iFixit's Upcycling Program (arstechnica.com) 24

Last week, Kevin Purdy of iFixit published a blog post telling the story of "how Samsung announced a 'revolutionary' upcycling program in 2017, delayed it for years, and eventually gutted it before shipping a pale imitation of the original idea," reports Ars Technica. "iFixit was actually involved in the initial 2017 announcement, and the repair outfit says that after endorsing the original idea with its brand and stamp of approval, Samsung never delivered on its promises." From the report: Despite the 2017 announcement of an upcycling program, the code didn't ship until April 2021, when Samsung finally launched a beta version of "Galaxy Upcycling at Home." This program lets users turn end-of-life Samsung phones into smart home sensors that could be paired with Samsung's SmartThings ecosystem. iFixit was initially given an inside look at the project back in 2017, liking it so much that it endorsed the project and lent its name to the marketing materials. To hear iFixit tell the story, bootloader unlocking was actually the original plan. Samsung was going to let users replace the shipping Android OS with whatever they wanted, like builds of LineageOS or some other custom OS. Samsung was also going to launch an open source marketplace where users could submit ideas and software for repurposing old Galaxy devices. iFixit called the original plan "novel" and "revolutionary."

"We were so excited," iFixit writes, "that when Samsung asked us to help launch the product in the fall of 2017, we jumped at the chance. You'll see iFixit's name and logo all over Samsung's original Galaxy Upcycling materials." iFixit went to Samsung HQ in South Korea to see prototypes of the project, and after testing working software, iFixit CEO Kyle Wiens actually helped announce the project on stage at Samsung's developer conference in 2017. Despite all the pomp and circumstance, iFixit says, "The actual software was never posted. The Samsung team eventually stopped returning our emails. Friends inside the company told us that leadership wasn't excited about a project that didn't have a clear product tie-in or revenue plan."

iFixit calls the version of the program that launched in April "nearly unrecognizable" to what it originally endorsed. What used to be an ambitious plan now barely makes any sense financially. iFixit rightfully points out that if you really want something as simple as a light sensor or sound monitor, at this point you're better off selling the phone and buying a purpose-built sensor. Samsung's on-rails functionality is so simple that it can be replicated by a $30 sensor, and you're sure to get more than that from a working device on the secondary market, especially due to another limitation of the program: it only extends back to the 3-year-old Galaxy S9.

Communications

US-Backed Consortium Beats China's for Massive 5G Contract Blanketing Ethiopia (livemint.com) 87

"A U.S.-backed consortium beat out one financed by China in a closely watched telecommunications auction in Ethiopia — handing Washington a victory in its push to challenge Beijing's economic influence around the world," reports the Wall Street Journal: The East African country said Saturday it tapped a group of telecommunications companies led by the U.K.'s Vodafone Group PLC to build a nationwide, 5G-capable wireless network.

The group had won financial backing for the multibillion-dollar project from a newly created U.S. foreign-aid agency. The agency offers low-interest loans, but the financing comes with a condition: the money won't be used to buy telecom equipment from China's Huawei Technologies Co. and ZTE Corp. Washington considers both a spying threat, an accusation the companies deny...

The telecom license auction in Ethiopia took on wider geopolitical significance amid heightened competition between the U.S. and China over key technological pursuits, from the rollout of 5G to chip manufacturing. "The U.S. and China are fighting a proxy war in Ethiopia for influence," said Zemedeneh Negatu, chairman of Fairfax Africa Fund LLC, a U.S.-based investment firm that focuses on Africa. After all but shutting out Huawei in the U.S., Washington has become more assertive about challenging Beijing's economic footprint overseas. It is using new financial tools to win influence and ensure that strategic assets in foreign countries stay in friendly hands...

Backing the Vodafone bid was the International Development Finance Corp., or DFC. The U.S. government-funded agency was created in December 2019 with a goal of offering alternatives to cheap, Chinese financing for foreign infrastructure projects... U.S. law also prohibits its loan from being used to buy Huawei or ZTE equipment, though one person familiar with the matter said it is possible the Vodafone-led bid could still buy some Chinese gear because of the project's size and cost.

Wireless Networking

Weak Wi-Fi Password May Have Led UK Police to Bust an Innocent Couple (bbc.co.uk) 109

Slashdot reader esm88 shares the BBC's story about a couple who experienced "a knock on the door from the police" investigating child abuse images posted online. "The couple insisted they had nothing to do with it. But the next few months were 'utter hell' as they attempted to clear their names," before their case was finally dropped in March: In February, a conversation with a friend who worked in cyber-security alerted them to the possibility that their router, supplied by their broadband provider Vodafone, might hold clues to what had happened. They had not changed the default passwords for either the router itself or the admin webpage, leaving it susceptible to brute force attacks. "We think of ourselves as competent users but we are not IT experts," said Matthew. "No-one told us to change the password and the setting up of the router didn't require us to go on to the admin menu, so we didn't.

"It came with a password, so we plugged it in and didn't touch anything."

Ken Munro, a security consultant with Pen Test Partners, told the BBC that it can take "a matter of minutes" for criminals to piggyback on insecure wireless connections... "So what I guess has happened here, is that the hacker has cracked the wi-fi password and then made changes to the router configuration, so their illicit activities on the internet appear to be coming from the innocent party." In March, when the couple's devices were returned and the case closed, the police officer assigned to liaise with them seemed to corroborate that unauthorised use of their wi-fi was to blame. But it couldn't be proved... The problem is industry-wide, points out Mr Munro.

"Internet service providers have started to improve matters to make these attacks harder, by putting unique passwords on each router. However, it will take years for all of the offending routers to be replaced," he said.

Operating Systems

Google and Samsung Are Merging Wear OS and Tizen (theverge.com) 44

Today, Google and Samsung announced that they are merging Wear OS and Tizen in an effort to better compete against Apple's watchOS. "The resulting platform is currently being referred to simply as 'Wear,' though that might not be the final name," notes The Verge. From the report: Benefits of the joint effort include significant improvements to battery life, 30 percent faster loading times for apps, and smoother animations. It also simplifies life for developers and will create one central smartwatch OS for the Android platform. Google is also promising a greater selection of apps and watch faces than ever before. "All device makers will be able to add a customized user experience on top of the platform, and developers will be able to use the Android tools they already know and love to build for one platform and ecosystem," Google's Bjorn Kilburn wrote in a blog post.

Wired has more details on what's to come, including the tidbit that Samsung will stick with its popular rotating bezel on future devices -- but it's finished making Tizen-only smartwatches. There will also be a version of Google Maps that works standalone (meaning without your phone nearby) and a YouTube Music app that supports offline downloads. Oh, and Spotify will support offline downloads on Wear smartwatches, as well. Samsung confirmed that its next Galaxy Watch will run on this unified platform. And future "premium" Fitbit devices will also run the software.

The Internet

NBN Replaces 10,000 Modems After Lightning 'Fries' Devices Across Blue Mountains (theguardian.com) 72

An anonymous reader writes: NBN Co has been forced to replace 10,000 faulty broadband devices in homes across the Blue Mountains west of Sydney after residents reported the technology was frequently struck by lightning and in one instance led to blue sparks flying out of a modem in a family's home. About 20,000 of the more than 32,000 homes in the Blue Mountains and Emu Plains have been connected to the national broadband network via fibre-to-the-curb (FttC) technology, which was set up under the Coalition government's multi-technology mixed model. That means fibre runs all the way to the edge of the property and connects to the home via the existing copper wire lead-ins from the curb.

Electrical storms in the Blue Mountains have wreaked havoc on the boxes that link the fibre to the copper. When lightning strikes the distribution boxes outside the house, sparks are sent flying up the copper lines, in turn frying the modems in people's homes. Guardian Australia understands the company has replaced 10,000 -- or half -- of devices inside the home that the company has identified as being prone to be affected by lightning. A spokesman for NBN Co confirmed that the company had found issues with the devices in areas of hard ground like sandstone. Sandstone is more resistant to electrical conduction than other soft earths. He said the devices fail in a safe way but the company nevertheless is issuing replacement devices people can install themselves. "We are now deploying a strengthened [device] that is much less likely to fail in these conditions.

Businesses

Alexa/Echo Owners Become Part of Amazon's Massive 'Sidewalk' Mesh Network By Default (inc.com) 168

A tech columnist for Inc. noticed that on June 8th Amazon will finally power up its massive "Sidewalk" mesh network (which uses Bluetooth and 900MHz radio signals to communicate between devices). And millions and millions of Amazon customers are all already "opted in" by default: The idea behind it is actually really smart — make it possible for smart home devices to serve as a sort of bridge between your WiFi connection and one another. That way, if your Ring doorbell, for example, isn't located close to your WiFi router, but it happens to be near an Echo Dot, it can use Sidewalk to stay connected.

The same is true if your internet connection is down. Your smart devices can connect to other smart devices, even if they aren't in your home. The big news on this front is that Tile is joining the Sidewalk network on June 14. That means that if you lose a Tile tracker, it can connect to any of the millions of Echo or Ring devices in your neighborhood and send its location back to you.

That's definitely a nice benefit, but it's also where things get a little murky from a privacy standpoint. That's because other people's devices, like your neighbor's, can also connect to your network. Amazon is pretty clear that Sidewalk uses three layers of encryption so that no data is shared between say, someone's Tile tracker and your network. The signal from the Tile is encrypted all the way back to the Tile app on your iPhone or Android smartphone... [But] whether or not you want your device connecting to other devices, or want your neighbors connecting to your WiFi, Amazon went ahead and made Sidewalk opt-out.

Opt out (for all your devices) using Alexa app's More tab (at the bottom): Settings > Account Settings > Amazon Sidewalk > Enabled.
Businesses

Peter Thiel Helps Fund an App That Tells You What to Do (bbc.com) 152

"How would you feel about being able to pay to control multiple aspects of another person's life?" asks the BBC.

"A new app is offering you the chance to do just that." When writer Brandon Wong recently couldn't decide what takeaway to order one evening, he asked his followers on social media app NewNew to choose for him. Those that wanted to get involved in the 24-year-old's dinner dilemma paid $5 (£3.50) to vote in a poll, and the majority verdict was that he should go for Korean food, so that was what he bought...

NewNew is the brainchild of Los Angeles-based entrepreneur Courtne Smith. The app, which is still in its "beta" or pre-full release stage, describes itself as "a human stock market where you buy shares in the lives of real people, in order to control their decisions and watch the outcome". For many of us that sounds a bit ominous, but the reality is actually far less alarming. It is aimed at what it calls "creators" — writers, painters, musicians, fashion designers, bloggers etc. It is designed as a way for them to connect far more closely with their fans or followers than on other social media services and, importantly, monetise that connection...

Whenever a vote is cast the creator gets the money minus NewNew's undisclosed commission... In addition to voting, followers can also pay extra — from $20 — to ask a NewNew creator to do something of their choosing, such as naming a character in a book after them. But the creator can reject all of these "bids", and if they do so then the follower doesn't have to part with the money...

Co-founder and chief executive Ms Smith, a 33-year-old Canadian, has big plans for NewNew, and has some heavyweight backers. Investors include Peter Thiel, the billionaire co-founder of PayPal, and the first outside person to put money into Facebook. Others with a stake in the business include leading US tech investment fund Andreessen Horowitz, and Hollywood actor Will Smith (no relation to Courtne). Snapchat has also given technical support.

Cellphones

Huawei Could Eavesdrop on 6.5 Million Dutch Cellphone Users Without their Knowledge (theconversation.com) 100

"Chinese technology provider Huawei was recently accused of being able to monitor all calls made using Dutch mobile operator KPN," writes the Conversation. Long-time Slashdot reader schwit1 shares their report: The revelations are from a secret 2010 report made by consultancy firm Capgemini, which KPN commissioned to evaluate the risks of working with Huawei infrastructure. While the full report on the issue has not been made public, journalists reporting on the story have outlined specific concerns that Huawei personnel in the Netherlands and China had access to security-essential parts of KPN's network - including the call data of millions of Dutch citizens - and that a lack of records meant KPN couldn't establish how often this happened... KPN essentially granted Huawei "administrator rights" to its mobile network by outsourcing work to the Chinese firm.

Legislation is only now catching up to prevent similar vulnerabilities in telecoms security...

Lower revenues force operators to carefully manage costs. This means that operators have been keen to outsource parts of their businesses to third parties, especially since the late 2000s. Large numbers of highly skilled engineers are an expensive liability to have on the balance sheet, and can often appear underused when things are running smoothly... , outsourcing by mobile operators is widespread. And firms in the UK and across Europe have often turned to Huawei to provide IT services and to help build core networks.

In 2010, Huawei was managing security-critical functions of KPN's core network.

Cellphones

Wealthy Install Location-Tracking Apps to Establish Proof-of-Residency for Tax Purposes (nytimes.com) 193

The New York Times shares the dilemma of Jeff Sheu, managing director of a private equity firm, who is "exactly the type of high earner California does not want to lose. When people in his tax bracket leave, the state is likely to audit them to make sure they really have left."

But fortunately, there's an app for that: With the May 17 tax filing deadline approaching, people who have moved to another state or are working more remotely need to be extra vigilant with their tax documents. For Mr. Sheu, that involves an app on his smartphone that uses location services to track him all the time. What he is sacrificing in privacy, he is gaining in peace of mind, knowing he will be able to show exactly when and where he was in a particular state, should California's tax authority come after him... "I'm never apart from my phone," Mr. Sheu said... "It feels to me like a pretty undebatable way to track where I am...."

Tax apps like TaxBird — which Mr. Sheu uses — and TaxDay and Monaeo were created years ago... "We've seen a fourfold increase in our app without any advertising in the past year," said Jonathan Mariner, founder and president of TaxDay, who was himself audited when he worked for Major League Baseball in New York but lived in Florida. "When people are concerned about privacy, I say you probably have a dozen apps on your phone that are tracking you, and you don't even know it...." Monaeo makes a point of describing how the data is cataloged — city, state and country, but without specific locations. It also says upfront that it does not share any data. (All three of the apps are vigilant about that.) While each tax app has different levels of precision and features to upload supporting documents, they all fulfill the basic need to prove your location to a tax authority. When it comes time to file taxes, users download reports detailing where they worked with varying degrees of specificity, from a simple day count to more detailed location information...

With hundreds of millions of dollars at stake, states in need of revenue are not going to let the money go without a fight. "This has the potential to become as messy as you can envision it," said Dustin Grizzle, a tax partner at MGO, an accounting firm. "States are going to say, 'Hey you're just using Covid to give you the ability to work remotely.'"

Science

Exxon Uses Big Tobacco's Playbook To Downplay the Climate Crisis, Says Study (cnn.com) 134

An anonymous reader quotes a report from CNN Business: For decades, ExxonMobil has deployed Big Tobacco-like propaganda to downplay the gravity of the climate crisis, shift blame onto consumers and protect its own interests, according to a Harvard University study published Thursday. The peer-reviewed study found that Exxon (XOM) publicly equates demand for energy to an indefinite need for fossil fuels, casting the company as merely a passive supplier working to meet that demand. The study used machine learning and algorithms to uncover trends in more than 200 public and internal Exxon documents between 1972 and 2019. "These patterns mimic the tobacco industry's documented strategy of shifting responsibility away from corporations -- which knowingly sold a deadly product while denying its harms -- and onto consumers," the study concludes. "ExxonMobil has used language to subtly yet systematically frame public discourse."

The Harvard study described "propaganda tactics of the fossil fuels industry" aimed at downplaying the climate crisis. For example, the authors said that after the 1999 merger of Exxon and Mobil, the companies began saying in public documents such as paid "advertorials" that "climate change was a 'risk,' rather than a reality." Prior to the merger, "risk" of climate change was only mentioned once in Exxon's public communications, the study said. From 2000 and beyond, it appeared 46 times, the study found, adding that no other term was more associated with climate change in the company's public statements. The study notes that "this scientific hedging strategy" was repeatedly used by the tobacco industry in the 1990s.

Moreover, the study found that Exxon has framed the debate around consumer energy "demand" to build a "fossil fuel savior" framework that "downplays the reality and seriousness of climate change, normalizes fossil fuel lock-in and individualizes responsibility." [Geoffrey Supran, a Harvard research associate and one of the study's authors] told CNN Business this strategy is "effectively gaslighting the public into thinking there is no alternative, making the blame pill that Exxon is feeding the public easier to swallow." Supran said it's "certainly true" that modern society continues to rely mostly on fossil fuels, but added that Exxon's decades-long "disinformation" campaign is a central reason why it still does. "We are passively guilty, born into a fossil fuel society," he said. "But companies like Exxon are actively guilty for working to keep society the way it is."

Power

Researchers Have Developed a Way To Wirelessly Charge Vehicles On the Road (jalopnik.com) 146

An anonymous reader quotes a report from Jalopnik: [R]esearchers at Cornell University, led by Associate Professor of Electrical and Computer Engineering Khurram Afridi, have developed technology that would allow vehicles to be charged on the road while in motion. It would essentially turn U.S. roadways into wireless chargers. Afrindi says he has been working on the tech for the last seven years. Here's how it would work, according to Afrindi via Business Insider: "'Highways would have a charging lane, sort of like a high occupancy lane,' Afridi told Insider. 'If you were running out of battery you would move into the charging lane. It would be able to identify which car went into the lane and it would later send you a bill.' The science behind Afridi's project goes back over 100 years to Nikola Tesla, the inventor who used alternating electric fields to power lights without plugging them in. Afridi's technology would embed special metal plates in the road that are connected to a powerline and a high frequency inverter. The plates will create alternating electric fields that attract and repel a pair of matching plates attached to the bottom of the EV.No need to worry about stopping to charge unless you're down for the night. They have run into a problem, however. They can't seem to find the parts that can handle the high levels of power needed to charge vehicles enough while they are in motion. It would have to be a material that's not only weatherproof but able to withstand high voltage and heat from the passing vehicles."
Wireless Networking

Tech Industry Quietly Patches FragAttacks Wi-Fi Flaws That Leak Data, Weaken Security (theregister.com) 37

An anonymous reader quotes a report from The Register: A dozen Wi-Fi design and implementation flaws make it possible for miscreants to steal transmitted data and bypass firewalls to attack devices on home networks, according to security researcher Mathy Vanhoef. On Tuesday, Vanhoef, a postdoctoral researcher in computer security at New York University Abu Dhabi, released a paper titled, "Fragment and Forge: Breaking Wi-Fi Through Frame Aggregation and Fragmentation" [PDF]. Scheduled to be presented later this year at the Usenix Security conference, the paper describes a set of wireless networking vulnerabilities, including three Wi-Fi design flaws and nine implementation flaws. Vanhoef, who in 2017 along with co-author Frank Piessens identified key reinstallation attacks (KRACKs) on the WPA2 protocol (used to secure Wi-Fi communication), has dubbed his latest research project FragAttacks, which stands for fragmentation and aggregation attacks.

The dozen vulnerabilities affect all Wi-Fi security protocols since the wireless networking technology debuted in 1997, from WEP up through WPA3. [...] In total, 75 devices -- network card and operating system combinations (Windows, Linux, Android, macOS, and iOS) -- were tested and all were affected by one or more of the attacks. NetBSD and OpenBSD were not affected because they don't support the reception of A-MSDUs (aggregate MAC service data units). [...]

Patches for many affected devices and software have already been deployed, thanks to a nine-month-long coordinated responsible disclosure overseen by the Wi-Fi Alliance and the Industry Consortium for Advancement of Security on the Internet (ICASI). Linux patches have been applied and the kernel mailing list note mentions that Intel has addressed the flaws in a recent firmware update without mentioning it. Microsoft released its patches on March 9, 2021 when disclosure was delayed tho Redmond had already committed to publication. Vanhoef advises checking with the vendor(s) of Wi-Fi devices about whether the FragAttacks have been addressed. "[F]or some devices the impact is minor, while for others it's disastrous," he said.

Privacy

Can Apple's AirTags Be Used to Track Another Person? (cnn.com) 38

As Mother's Day approached, CNN Business Editor Samantha Murphy Kelly clipped a keychain with one of Apple's tiny new "AirTag" Bluetooth trackers onto her son's book bag, in an experiment that "highlighted how easily these trackers could be used to track another person." Location trackers aren't new — there are similar products from Samsung, Sony and Tile — but AirTags' powerful Ultra Wideband technology chip allows it to more accurately determine the location and enables precise augmented reality directional arrows that populate on the iPhone or iPad's screen. While AirTags are explicitly intended for items only, Apple has added safeguards to cut down on unwanted tracking. For example, the company does not store location data, and it will send an alert to an iOS device user if an AirTag appears to be following them when its owner is not around. If the AirTag doesn't re-tether to the owner's iOS device after three days, the tracker will start to make a noise.

"We take customer safety very seriously and are committed to AirTag's privacy and security," the company said in a statement to CNN Business. "AirTag is designed with a set of proactive features to discourage unwanted tracking — a first in the industry — and the Find My network includes a smart, tunable system with deterrents...." The safeguards are a work in progress as the software rolls out and users begin interacting with the devices. When my babysitter recently took my son to an appointment, using my set of keys with an AirTag attached, she was not informed that she was carrying an AirTag — separated from my phone. (She hadn't yet updated her phone's software to iOS 14.5.) Non-iPhone users can hold their phones close to the AirTags and, via short-range wireless technology, information pops up on how to disable the tracker, but that's if the person knows they're being tracked and locates it. In addition, three days is a long time for an AirTag to keep quiet before making a noise....

Apple said one of the main reasons it spent so much time developing safeguards was the sheer size of its Find My app network. But it's the AirTags' reliance on that broader network that creates much of the need for the safeguards in the first place, said Albert Fox Cahn, founder and executive director of the Surveillance Technology Oversight Project and a fellow at the NYU School of Law. "That's because Apple is turning more than a billion iOS devices into a network for tracking AirTags, while Tile will only operate when in range of the small number of people using the Tile app.... The benefits of finding our keys a bit quicker isn't worth the danger of creating a new global tracking network."

United States

Capitol Rioters Identified Using Facial Recognition Software, Cellphone Records - and Social Media Posts (nbcnews.com) 352

NBC News reports more than 440 Americans have now been charged with storming the U.S. Capitol building on January 6th, with charges now filed against people from 44 of America's 50 states. They describe it as "one of the largest criminal investigations in American history." The largest number come from Texas, Pennsylvania, and Florida, in that order. Men outnumber women among those arrested by 7 to 1, with an average age of 39, according to figures compiled by the Program on Extremism at George Washington University in Washington, D.C. A total of 44 are military veterans.
Hundreds of arrests happened because rioters later bragged online: In nearly 90 percent of the cases, charges have been based at least in part on a person's own social media accounts.

A New York man, Robert Chapman, bragged on the dating app Bumble that he'd been in the Capitol during the riot. The person he was seeking to date responded, "We are not a match," and notified the FBI.

In fact, the investigative agency has now received "hundreds of thousands" of tips from the public, and has even posted photos of people who participated in the riots online asking for the public's help to identify them.

But NBC also reports that technology is being used to identify participants:
  • "Investigators have also used facial recognition software, comparing images from surveillance cameras and an outpouring of social media and news agency videos against photo databases of the FBI and at least one other federal agency, Customs and Border Protection, according to court documents."
  • Investigators "have also subpoenaed records from companies providing cellphone service, allowing agents to tell whether a specific person's phone was inside the Capitol during the siege."

China

How China Turned a Prize-Winning iPhone Hack Against the Uyghurs (technologyreview.com) 38

An attack that targeted Apple devices was used to spy on China's Muslim minority -- and US officials claim it was developed at the country's top hacking competition. An anonymous reader shares an excerpt from an MIT Technology Review article: The Tianfu Cup offered prizes that added up to over a million dollars. [It was held in November 2018, shortly after the Chinese banned cybersecurity researchers from attending overseas hacking competitions.] The $200,000 top prize went to Qihoo 360 researcher Qixun Zhao, who showed off a remarkable chain of exploits that allowed him to easily and reliably take control of even the newest and most up-to-date iPhones. From a starting point within the Safari web browser, he found a weakness in the core of the iPhones operating system, its kernel. The result? A remote attacker could take over any iPhone that visited a web page containing Qixun's malicious code. It's the kind of hack that can potentially be sold for millions of dollars on the open market to give criminals or governments the ability to spy on large numbers of people. Qixun named it "Chaos."

Two months later, in January 2019, Apple issued an update that fixed the flaw. There was little fanfare—just a quick note of thanks to those who discovered it. But in August of that year, Google published an extraordinary analysis into a hacking campaign it said was "exploiting iPhones en masse." Researchers dissected five distinct exploit chains they'd spotted "in the wild." These included the exploit that won Qixun the top prize at Tianfu, which they said had also been discovered by an unnamed "attacker." The Google researchers pointed out similarities between the attacks they caught being used in the real world and Chaos. What their deep dive omitted, however, were the identities of the victims and the attackers: Uyghur Muslims and the Chinese government.

Shortly after Google's researchers noted the attacks, media reports connected the dots: the targets of the campaign that used the Chaos exploit were the Uyghur people, and the hackers were linked to the Chinese government. Apple published a rare blog post that confirmed the attack had taken place over two months: that is, the period beginning immediately after Qixun won the Tianfu Cup and stretching until Apple issued the fix. MIT Technology Review has learned that United States government surveillance independently spotted the Chaos exploit being used against Uyghurs, and informed Apple. (Both Apple and Google declined to comment on this story.) The Americans concluded that the Chinese essentially followed the "strategic value" plan laid out by Qihoo's Zhou Hongyi; that the Tianfu Cup had generated an important hack; and that the exploit had been quickly handed over to Chinese intelligence, which then used it to spy on Uyghurs. The US collected the full details of the exploit used to hack the Uyghurs, and it matched Tianfu's Chaos hack, MIT Technology Review has learned. (Google's in-depth examination later noted how structurally similar the exploits are.) The US quietly informed Apple, which had already been tracking the attack on its own and reached the same conclusion: the Tianfu hack and the Uyghur hack were one and the same. The company prioritized a difficult fix.

Iphone

Apple is Reportedly Working on a Foldable iPhone for 2023 (engadget.com) 30

Rumors about a foldable iPhone have bubbled up before, but a new one has more credibility. From a report: Reliable analyst Ming-Chi Kuo told investors that Apple plans to launch an 8-inch foldable iPhone by 2023, according to documents seen by Engadget. The report, based on an "industry survey," predicts that Apple plans to sell 15-20 million units in 2023. Kuo said already revealed the possibility of a folding iPhone in March, but his latest report has more detail on suppliers. It predicts that the QHD+ flexible OLED will be supplied by Samsung Display, while the DDI display controller will come from Samsung Foundry. It also notes that Apple will use silver nanowire touch tech supplied by TPK, "because of its several advantages over [Samsung's] Y-Octa technology."

Slashdot Top Deals