Windows

Microsoft's CEO Looks To a Future Beyond Windows, iOS, and Android (theverge.com) 53

The future of the next 46 billion devices. From a report: "What do you think is the biggest hardware business at Microsoft?" asked Microsoft CEO Satya Nadella last week during a private media event. "Xbox," answered a reporter who had been quizzing Nadella on how the company's hardware products like Surface and Xbox fit into the broader ambitions of Microsoft. "No, it's our cloud," fired back Nadella, explaining how Microsoft is building everything from the data centers to the servers and network stack that fit inside. As the reporter pushed further on the hardware point, a frequent question given Microsoft's focus on the cloud, Nadella provided us with the best vision for the modern Microsoft that moves well beyond the billion-or-so Windows users that previously defined the company.

"The way I look at it is Windows is the billion user install base of ours. We continue to add a couple of hundred million PCs every year, and we want to serve that in a super good way," explained Nadella. "The thing that we also want to think about is the broader context. We don't want to be defined by just what we achieved. We look at if there's going to be 50 billion endpoints. Windows with its billion is good, Android with its 2 billion is good, iOS with its billion is good -- but there is 46 billion more. So let's go and look at what that 46 billion plus 4 [billion] looks like, and define a strategy for that, and then have everything have a place under the sun."

Security

Here Is the Technical Report Suggesting Saudi Arabia's Prince Hacked Jeff Bezos's Phone (vice.com) 63

A report investigating the potential hack of Jeff Bezos' iPhone indicates that forensic investigators found a suspicious file but no evidence of any malware on the phone. Motherboard: It also says that investigators had to reset Bezos's iTunes backup password because investigators didn't have it to access the backup of his phone. The latter suggests that Bezos may have forgotten his password. The report, obtained by Motherboard, indicates that investigators set up a secure lab to examine the phone and its artifacts and spent two days poring over the device but were unable to find any malware on it. Instead, they only found a suspicious video file sent to Bezos on May 1, 2018 that "appears to be an Arabic language promotional film about telecommunications." That file shows an image of the Saudi Arabian flag and Swedish flags and arrived with an encrypted downloader. Because the downloader was encrypted this delayed or further prevented "study of the code delivered along with the video." Investigators determined the video or downloader were suspicious only because Bezos' phone subsequently began transmitting large amounts of data. "[W]ithin hours of the encrypted downloader being received, a massive and unauthorized exfiltration of data from Bezos' phone began, continuing and escalating for months thereafter," the report states.

"The amount of data being transmitted out of Bezos' phone changed dramatically after receiving the WhatsApp video file and never returned to baseline. Following execution of the encrypted downloader sent from MBS' account, egress on the device immediately jumped by approximately 29,000 percent," it notes. "Forensic artifacts show that in the six (6) months prior to receiving the WhatsApp video, Bezos' phone had an average of 430KB of egress per day, fairly typical of an iPhone. Within hours of the WhatsApp video, egress jumped to 126MB. The phone maintained an unusually high average of 101MB of egress data per day for months thereafter, including many massive and highly atypical spikes of egress data. The digital forensic results, combined with a larger investigation, interviews, research, and expert intelligence information, led the investigators "to assess Bezos' phone was compromised via tools procured by Saud al Qahtani," the report states.

Privacy

US Cops Have Wide Access To Phone Cracking Software, New Documents Reveal (medium.com) 40

Many police departments across the United States already have the ability to crack mobile devices, including the iPhone. From a report: Over the past three months, OneZero sent Freedom of Information Act (FOIA) requests to over 50 major police departments, sheriffs, and prosecutors around the country asking for information about their use of phone-cracking technology. Hundreds of documents from these agencies reveal that law enforcement in at least 11 states spent over $4 million in the last decade on devices and software designed to get around passwords and access information stored on phones. OneZero obtained documents from law enforcement agencies in New York, California, Florida, Texas, Washington, Colorado, Illinois, Ohio, Michigan, New Mexico, and Massachusetts.

These agencies included district attorneys' offices, local police departments, and county sheriffs' offices. The number of offices with access to phone-cracking tools across the country is likely far greater than what OneZero uncovered. Not all agencies responded to OneZero's request for documents. Some departments and offices claimed the records were exempt from public release. Others told OneZero they would need several months and thousands of dollars to provide the information.

Communications

Smart Scale Goes Dumb As Under Armour Pulls the Plug On Connected Tech (arstechnica.com) 133

An anonymous reader quotes a report from Ars Technica: Today's example of smart stuff going dumb comes courtesy of Under Armour, which is effectively rendering its fitness hardware line very expensive paperweights. The company quietly pulled its UA Record app from both Google Play and Apple's App Store on New Year's Eve. In an announcement dated sometime around January 8, Under Armour said that not only has the app been removed from all app stores, but the company is no longer providing customer support or bug fixes for the software, which will completely stop working as of March 31.

Under Armour launched its lineup of connected fitness devices in 2016. The trio of trackers included a wrist-worn activity monitor, a smart scale, and a chest-strap-style heart rate monitor. The scale and wristband retailed at $180 each, with the heart monitor going for $80. Shoppers could buy all three together in a $400 bundle called the UA HealthBox. The end of the road is nigh, it seems, and all three products are about to meet their doom as Under Armour kills off Record for good. Users are instead expected to switch to MapMyFitness, which Under Armour bills as "an even better tracking experience." The company also set the UA Record Twitter account to private, effectively taking it offline to anyone except the 133 accounts it follows. Current device owners also can't export all their data. While workout data can be exported and transferred to some other tracking app, Record users cannot capture weight or other historical data to carry forward with them.

Privacy

Amazon Boss Jeff Bezos' Phone 'Hacked By Saudi Crown Prince' (theguardian.com) 73

According to the Guardian, Amazon CEO Jeff Bezos had his phone "hacked" in 2018 after receiving a WhatsApp message from the personal account of the crown prince of Saudi Arabia. From the report: The encrypted message from the number used by Mohammed bin Salman is believed to have included a malicious file that infiltrated the phone of the world's richest man, according to the results of a digital forensic analysis. This analysis found it "highly probable" that the intrusion into the phone was triggered by an infected video file sent from the account of the Saudi heir to Bezos, the owner of the Washington Post.

The two men had been having a seemingly friendly WhatsApp exchange when, on May 1 of that year, the unsolicited file was sent, according to sources who spoke to the Guardian on the condition of anonymity. Large amounts of data were exfiltrated from Bezos's phone within hours, according to a person familiar with the matter. The Guardian has no knowledge of what was taken from the phone or how it was used. [...] The disclosure is likely to raise difficult questions for the kingdom about the circumstances around how U.S. tabloid the National Enquirer came to publish intimate details about Bezos's private life -- including text messages -- nine months later. It may also lead to renewed scrutiny about what the crown prince and his inner circle were doing in the months prior to the murder of Jamal Khashoggi, the Washington Post journalist who was killed in October 2018 -- five months after the alleged "hack" of the newspaper's owner.

Open Source

Tuxedo's New Manjaro Linux Laptops Will Include Massive Customization (forbes.com) 17

Tuxedo Computers "has teamed up with Manjaro to tease not one, not two, but several" Linux laptops, Forbes reports:
The Tuxedo Computers InfinityBook Pro 15...can be loaded with up to 64GB of RAM, a 10th-generation Intel Core i7 CPU, and as high as a 2TB Samsung EVO Plus NVMe drive. You can also purchase up to a 5-year warranty, and user-installed upgrades will not void the warranty...

Manjaro Lead Project Developer Philip Müller also teased a forthcoming AMD Ryzen laptop [on Forbes' "Linux For Everyone" podcast]. "Yes, we are currently evaluating which models we want to use because the industry is screaming for that," Müller says. "In the upcoming weeks we might get some of those for internal testing. Once they're certified and the drivers are ready, we'll see when we can launch those." Müller also tells me they're prepping what he describes as a "Dell XPS 13 killer."

"It's 10th-generation Intel based, we will have it in 14-inch with a 180-degree lid, so you can lay it flat on your desk if you like," he says.

The Manjaro/Tuxedo Computers partnership will also offer some intense customization options, Forbes adds.

"Want your company logo laser-etched on the lid? OK. Want to swap out the Manjaro logo with your logo on the Super key? Sure, no problem. Want to show off your knowledge of fictional alien races? Why not get a 100% Klingon keyboard?"
Google

It's Not Just You: Google Added Annoying Icons To Search On Desktop (theverge.com) 70

Kim Lyons, writing for The Verge: Google added tiny favicon icons to its search results this week for some reason, creating more clutter in what used to be a clean interface, and seemingly without actually improving the results or the user experience. The company says it's part of a plan to make clearer where information is coming from, but how? In my Chrome desktop browser, it feels like an aggravating, unnecessary change that doesn't actually help the user determine how good, bad, or reputable an actual search result might be. Yes, ads are still clearly marked with the word "ad," which is a good thing. But do I need to see Best Buy's logo or AT&T's blue circle when I search for "Samsung Fold" to know they're trying to sell me something? Google says the favicon icons are "helping searchers better understand where information is coming from, more easily scan results & decide what to explore."

If you don't care for the new look, Google has instructions on how to change or add a favicon to search results. Lifehacker also has instructions on how to apply filters to undo the favicon nonsense.
Android

Xiaomi Spins Off POCO as an Independent Company (techcrunch.com) 6

Xiaomi said today it is spinning off POCO, a sub-smartphone brand it created in 2018, as a standalone company that will now run independently of the Chinese electronics giant and make its own market strategy. From a report: The move comes months after a top POCO executive -- Jai Mani, a former Googler -- and some other founding and core members left the sub-brand. The company today insisted that POCO F1, the only smartphone to be launched under the POCO brand, remains a "successful" handset. The POCO F1, a $300 smartphone, was launched in 50 markets. Xiaomi created the POCO brand to launch high-end, premium smartphones that would compete directly with flagship smartphones of OnePlus and Samsung. In an interview in 2018, Alvin Tse, the head of POCO, and Mani, said that they were working on a number of smartphones and were also thinking about other gadget categories. At the time, the company had 300 people working on POCO, and they "shared resources" with the parent firm.
The Internet

Every Place is the Same Now (theatlantic.com) 88

With a phone, anywhere else is always just a tap away. From a column: Those old enough to remember video-rental stores will recall the crippling indecision that would overtake you while browsing their shelves. With so many options, any one seemed unappealing, or insufficient. In a group, different tastes or momentary preferences felt impossible to balance. Everything was there, so there was nothing to watch. Those days are over, but the shilly-shally of choosing a show or movie to watch has only gotten worse. First, cable offered hundreds of channels. Now, each streaming service requires viewers to manipulate distinct software on different devices, scanning through the interfaces on Hulu, on Netflix, on AppleTV+ to find something "worth watching." Blockbuster is dead, but the emotional dread of its aisles lives on in your bedroom.

This same pattern has been repeated for countless activities, in work as much as leisure. Anywhere has become as good as anywhere else. The office is a suitable place for tapping out emails, but so is the bed, or the toilet. You can watch television in the den -- but also in the car, or at the coffee shop, turning those spaces into impromptu theaters. Grocery shopping can be done via an app while waiting for the kids' recital to start. Habits like these compress time, but they also transform space. Nowhere feels especially remarkable, and every place adopts the pleasures and burdens of every other. It's possible to do so much from home, so why leave at all?

Cellphones

PinePhone Linux Smartphone Shipment Finally Begins (fossbytes.com) 52

Pine64 will finally start shipping the pre-order units of PinePhone Braveheart Edition on January 17, 2020. Fossbytes reports: A year ago, PinePhone was made available only to developers and hackers. After getting better responses and suggestions, the Pine64 developers planned to bring Pinephone for everyone. In November last year, pre-orders for PinePhone Braveheart Edition commenced for everyone. But due to manufacturing issues coming in the way, the shipment date slipped for weeks, which was scheduled in December last year.

PinePhone Braveheart Edition is an affordable, open source Linux-based operating system smartphone preloaded with factory test image running on Linux OS (postmarketOS) on inbuilt storage. You can check on PinePhone Wiki to find the PinePhone compatible operating system such as Ubuntu Touch, postmarketOS, or Sailfish OS, which you can boot either from internal storage or an SD card.

Wireless Networking

Bruce Schneier on 5G Security (schneier.com) 33

Bruce Schneier comments on the issues surrounding 5G security: [...] Keeping untrusted companies like Huawei out of Western infrastructure isn't enough to secure 5G. Neither is banning Chinese microchips, software, or programmers. Security vulnerabilities in the standards, the protocols and software for 5G, ensure that vulnerabilities will remain, regardless of who provides the hardware and software. These insecurities are a result of market forces that prioritize costs over security and of governments, including the United States, that want to preserve the option of surveillance in 5G networks. If the United States is serious about tackling the national security threats related to an insecure 5G network, it needs to rethink the extent to which it values corporate profits and government espionage over security. To be sure, there are significant security improvements in 5G over 4G in encryption, authentication, integrity protection, privacy, and network availability. But the enhancements aren't enough. The 5G security problems are threefold.

First, the standards are simply too complex to implement securely. This is true for all software, but the 5G protocols offer particular difficulties. Because of how it is designed, the system blurs the wireless portion of the network connecting phones with base stations and the core portion that routes data around the world. Additionally, much of the network is virtualized, meaning that it will rely on software running on dynamically configurable hardware. This design dramatically increases the points vulnerable to attack, as does the expected massive increase in both things connected to the network and the data flying about it. Second, there's so much backward compatibility built into the 5G network that older vulnerabilities remain. 5G is an evolution of the decade-old 4G network, and most networks will mix generations. Without the ability to do a clean break from 4G to 5G, it will simply be impossible to improve security in some areas. Attackers may be able to force 5G systems to use more vulnerable 4G protocols, for example, and 5G networks will inherit many existing problems. Third, the 5G standards committees missed many opportunities to improve security. Many of the new security features in 5G are optional, and network operators can choose not to implement them. The same happened with 4G; operators even ignored security features defined as mandatory in the standard because implementing them was expensive. But even worse, for 5G, development, performance, cost, and time to market were all prioritized over security, which was treated as an afterthought.

EU

Europe Plans Law To Give All Phones Same Charger (zdnet.com) 215

On Monday, members of the European Parliament (MEPs) discussed the idea of introducing "binding measures" that would require chargers that fit all mobile phones and portable electronic devices. The company that would be impacted most by this legislation would be Apple and its iPhone, which uses a Lightning cable while most new Android phones use USB-C ports for charging. ZDNet reports: The EU introduced the voluntary Radio Equipment Directive in 2014, but MEPs believe the effort fell short of the objectives. "The voluntary agreements between different industry players have not yielded the desired results," MEPs said. The proposed more stringent measures are aimed at reducing electronic waste, which is estimated to amount to 51,000 tons per year in old chargers.

Apple last year argued that regulations to standardize chargers for phones would "freeze innovation rather than encourage it" and it claimed the proposal was "bad for the environment and unnecessarily disruptive for customers." Noted Apple analyst Ming-Chi Kuo reckons Apple has a different idea in store: getting rid of the Lightning port and not replacing it with USB-C, which is a standard that Apple doesn't have complete control over. According to the analyst, Apple plans to remove the Lightning connector on a flagship iPhone to be released in 2021. Instead it would rely on wireless charging.

Encryption

iPhones Can Now Be Used To Generate 2FA Security Keys For Google Accounts (9to5google.com) 4

Most modern iPhones running iOS 13 can now be used as a built-in phone security key for Google apps. 9to5Google reports: A built-in phone security key differs from the Google Prompt, though both essentially share the same UI. The latter push-based approach is found in the Google Search app and Gmail, while today's announcement is more akin to a physical USB-C/Lightning key in terms of being resistant to phishing attempts and verifying who you are. Your phone security key needs to be physically near (within Bluetooth range) the device that wants to log-in. The login prompt is not just being sent over an internet connection.

With an update to the Google Smart Lock app on iOS this week, "you can now set up your phone's built-in security key." According to one Googler today, the company is leveraging the Secure Enclave found on Apple's A-Series chips. Storing Touch ID, Face ID, and other cryptographic data, it was first introduced on the iPhone 5s, though that particular device no longer supports iOS 13. Anytime users enter a Google Account username and password, they'll be prompted to open Smart Lock on their nearby iPhone to confirm a sign-in. There's also the option to cancel with "No, it's not me." This only works when signing-in to Google with Chrome, while Bluetooth on both the desktop computer and phone needs to be enabled as the devices are locally communicating the confirmation request and verification.

Android

Google is Working on Native Call Recording For the Phone App, Code Suggests (androidpolice.com) 31

An anonymous reader shares a report: Google's Call Screening service has allowed you to record screened calls for quite some time, but many people have been asking for a native solution letting them save any phone conversation. It looks like Google is working on introducing this functionality to its Phone app. XDA Developers peeked at the code of the current Phone app beta version 43.0.289191107 and found that Google has already added a new layout, an icon, and more assets that hint at call recording through the application. Some strings also point to a new in-call button that should allow you to quickly start saving audio.
Encryption

Apple Responds To AG Barr Over Unlocking Pensacola Shooter's Phone: 'No.' (inputmag.com) 234

On Monday, Attorney General William Barr called on Apple to unlock the alleged phone of the Pensacola shooter -- a man who murdered three people and injured eight others on a Naval base in Florida in December. Apple has responded by essentially saying: "no." From a report: "We reject the characterization that Apple has not provided substantive assistance in the Pensacola investigation," the company said. "It was not until January 8th that we received a subpoena for information related to the second iPhone, which we responded to within hours," Apple added, countering Barr's characterization of the company being slow in its approach to the FBI's needs. However, it ends the statement in no uncertain terms: "We have always maintained there is no such thing as a backdoor just for the good guys." Despite pressure from the government, Apple has long held that giving anyone the keys to users' data or a backdoor to their phones -- even in cases where terrorism or violence was involved -- would compromise every user. The company is clearly standing by those principles.
Power

Samsung's Removable-Battery Smartphone Is Coming To the US For $499 (theverge.com) 120

PolygamousRanchKid shares a report from The Verge: We've already seen Samsung's new rugged smartphone with a removable battery, the Galaxy XCover Pro, because the company revealed it on its Finnish website before taking it down. Today, though, the company is officially announcing the phone and that it's coming to the U.S. for $499. For that price, you're getting a phone with a swappable battery that's a meaty 4,050mAh, and the phone even supports 15W fast charging, as well as with special docks that use pogo pins. The XCover Pro is intended to be used by workers in industrial settings or out in the field, so that huge battery should theoretically let workers use their phones for longer and give them the option to swap in a fresh battery in a pinch.

Otherwise, the phone's specs are mid-range: a 6.3-inch 2220 x 1080 display (which Samsung says you can use when you have gloves on), a 2GHz octa-core Exynos 9611 processor, 4GB of RAM, and 64GB of internal storage (with support for microSD storage up to 512GB). For cameras, the phone has a 13-megapixel front-facing camera in a corner of the screen and two rear cameras: a 25-megapixel camera and an 8-megapixel camera. It'll also ship with the latest Android 10 and Samsung's One UI 2.0, contrary to information from the early reveal that indicated that the XCover Pro was running Android 9 Pie.

Windows

The End of Windows 7 'Marks the End of the PC Era Too' (zdnet.com) 166

ZDNet's UK editor-in-chief Steve Ranger argues the end of Windows 7 "marks the end of the PC era, too." When Windows 7 launched, the iPhone and its app store were around but were still novelties, while the iPad hadn't arrived yet. If you wanted to get work -- or pretty much anything -- done on a computer, you needed a PC. Just over a decade later, the picture is much more complicated.

PC sales have been in decline for the last seven years; a slide which only ended with a small increase last year, largely because businesses needed to buy new PCs to run Windows 10, after bowing to the inevitable and upgrading. In many scenarios and use cases the PC has been superseded by the smartphone, the tablet or digital assistants embodied in various other devices. And it's not just the PC -- Windows is no longer the defining product for Microsoft that it once was.

That's not to say the PC is dead, of course: I'm typing on one now, and it will remain the primary device I use to do my job for the foreseeable future. Many office and knowledge workers will feel the same. But there are now plenty of other options: I could be using a tablet or dictating to my phone... And outside of work I barely touch a PC at all.

And even the definition of the PCs is getting blurry. PC makers have come up with a late burst of creativity that has delivered all manner of weird and occasionally wonderful new shapes and sizes. Microsoft's Surface is a PC that looks a lot like a tablet; Lenovo's X1 Fold is a folding screen that can be a tablet, or a mini laptop or a desktop. Folding and detachable PCs are now mainstream.

Security

SIM Swappers Are Using RDP To Directly Access Internal T-Mobile, AT&T, and Sprint Tools (vice.com) 40

An anonymous reader quotes a report from Motherboard: Hackers are now getting telecom employees to run software that lets the hackers directly reach into the internal systems of U.S. telecom companies to take over customer cell phone numbers, Motherboard has learned. Multiple sources in and familiar with the SIM swapping community as well as screenshots shared with Motherboard suggest at least AT&T, T-Mobile, and Sprint have been impacted. The technique uses Remote Desktop Protocol (RDP) software. RDP lets a user control a computer over the internet rather than being physically in front of it. It's commonly used for legitimate purposes such as customer support. But scammers also make heavy use of RDP. In an age-old scam, a fraudster will phone an ordinary consumer and tell them their computer is infected with malware. To fix the issue, the victim needs to enable RDP and let the fake customer support representative into their machine. From here, the scammer could do all sorts of things, such as logging into online bank accounts and stealing funds.

This use of RDP is essentially what SIM swappers are now doing. But instead of targeting consumers, they're tricking telecom employees to install or activate RDP software, and then remotely reaching into the company's systems to SIM swap individuals. The process starts with convincing an employee in a telecom company's customer support center to run or install RDP software. The active SIM swapper said they provide an employee with something akin to an employee ID, "and they believe it." Hackers may also convince employees to provide credentials to a RDP service if they already use it. Once RDP is enabled, "They RDP into the store or call center [computer] [...] and mess around on the employees' computers including using tools," said Nicholas Ceraolo, an independent security researcher who first flagged the issue to Motherboard. Motherboard then verified Ceraolo's findings with the active SIM swapper.

Android

New LG CEO Won't Give Up on Smartphone Market, Promises Profitability by 2021 (arstechnica.com) 35

LG is still clinging to its dying smartphone business. The company's new CEO, Kwon Bong-seok, (who was appointed just last month!) promised a return to profitability for LG's mobile division by 2021. From a report: "LG Electronics' mobile business is going to be profitable by 2021," Kwon told The Korea Times. "I can say we can make that happen as LG Electronics will expand our mobile lineup and steadily release new ones attached with some wow factors to woo consumers." Kwon didn't share many details on how he plans to resurrect LG's smartphone business, which has lost money for something like 14 quarters in a row now. When asked by the Korea Times, the site said Kwon "only reiterated LG Electronics' plan to expand the phone lineup." LG sold 19 phone models each in 2019 and 2018, according to GSM Arena's database. In 2014, the last time LG Mobile reliably turned a profit, the company produced 44 phone models -- is this correlation or causation?
Verizon

Verizon Will Finally Sell You TV Without a Contract (cnn.com) 44

An anonymous reader quotes a report from CNN: Verizon is changing the way it sells its internet and cable packages as customers are increasingly seeking ways to cut the costly cord. The company is eliminating bundles and contracts, Verizon announced Thursday. Instead, it will sell its Fios TV and internet services separately. Long-term contracts are also being trashed in favor of charging customers month-to-month. That is similar to how streaming services charge customers. Verizon is calling the new offers "Mix and Match on Fios." There are now three internet packages and five Fios TV packages. Notably, Verizon will continue selling Google's YouTube TV for $49.99 per month as a TV option under an agreement the two companies signed last year. A home telephone package will also be sold for $20 per month. The new bundle-free packages offer more price transparency for customers, Verizon claims. Not all surcharges are going away though. "Verizon will continue charging a $15 monthly fee for routers in some of its internet packages and a $12 set-top monthly fee in most of its Fios TV packages," the report adds. "But other fees it previously charged, including for regional sports networks, will now be included in the total Fios TV price."

Slashdot Top Deals