Android

Android 14 Still Doesn't Calculate Device Storage Utilization Correctly (androidpolice.com) 22

According to Android specialist Mishaal Rahman, Android miscalculates the storage space taken up by system components, leading to inflated system storage utilization and potentially misleading users. Chandraveer Mathur writes via Android Police. From the report: We usually rely on Android's storage utilization utility to find apps and files eating up storage space, so we can uninstall or delete them if required. However, Android specialist Mishaal Rahman discovered that Google's calculation of the space consumed by Android system components is flawed. He executed shell commands to create a 3GB file in the /data/media/0 storage directory, which isn't a file path used for Android system files. However, the phone's storage breakdown showed a marked 3GB increase under the System heading, suggesting the OS suddenly became bigger.

This happens because Android calculates system storage as the space used up by anything other than what's covered by other categories in the storage breakdown, including audios, videos, images, documents, trash, and games. This means the System heading in the break doesn't just include Android system files. Android 14 also uses this dangerously flawed logic for calculating storage usage. Moreover, the Files app by Google also shows similar storage utilization by Android system components, perhaps because it uses the same incredulous attribution logic. By association, all other Android skins use flawed calculation of used storage space, but Samsung reportedly fixed this issue with the One UI 6 update. After running similar ADB commands as in the previous experiment, Rahman could confirm the increased utilization showed up under the Other files heading in the storage breakdown, instead of the System heading.

Chrome

Google's Cookie Killing Tech Is Now On Almost Every Chrome Browser (gizmodo.com) 68

An anonymous reader quotes a report from Gizmodo: Google's Privacy Sandbox, a controversial set of tools and settings meant to replace third-party cookies, is now on almost every single Chrome browser, according to a company blog post published Thursday. Google says Privacy Sandbox is now available to around 97% of Chrome users, and that number will reach 100% in the next few months. The news comes on the heels of the browser's 15th anniversary, which Google is celebrating by redesigning Chrome to make it look and feel more closely aligned with the design paradigm of Android and the rest of the Google suite. The final step in this process comes in 2024, when Google will disable third-party cookies in Chrome for good, marking the end of their decades-long reign of privacy-violating terror.

Back in 2019, Google said the cookie era was coming to a close. In place of third-party cookies, Privacy Sandbox will implement a long list of new tools for the ad industry. Google, after all, makes all of its money by spying on you and turning the insights into ads, so it's not about to put itself out of business. In fairness, this new system is really more private, though it's private on Google's terms. The biggest change is "Ad Topics," a.k.a. the Topics API if you're a huge nerd who's been following this stuff for years. With Topics, Chrome will keep track of all the websites you're looking at and sort you into a variety of categories. This tracking happens in your browser and the data stays on your device. Neither Google nor anyone else gets to see your browsing history or learn anything about you as an individual throughout this process. Websites and advertising companies will know there's a person interested in a certain Topic, but they won't be able to tell who you are specifically.

There's also an extremely complicated technique websites can use to tag you with subjects they want you to see ads about, called "Site Suggested Ads." Google is also rolling out a tool called "Ad Measurement," which helps companies keep track of how well their ads are working through metrics such as the time of day you saw an ad and whether you clicked on it. Google gives users some control over how these tools are implemented. With the rollout of Privacy Sandbox comes new settings listed as "Ad privacy controls," which you can adjust in Chrome's preferences.
Further reading: Chrome is About To Look a Bit Different
Google

Google is Killing Play Movies and TV, Will Only Have Three Video Stores Left (arstechnica.com) 19

Google is killing off the last vestiges of Google Play Movies & TV, a service that sold premium Hollywood films and TV shows as part of Google's once-cohesive string of Google Play content stores. From a report: The company emailed users of Android TV to say that the "Google Play Movies & TV app will no longer be available on your Android TV device from 05 October 2023. You can continue to buy or rent movies directly through the Shop tab on your Android TV." Play Movies has been going through a slow death as Google shuffles around its media content. The smartphone Play Movies app became "Google TV" in 2022, and that same year, the Play Store app was stripped of movie and TV sales.

On third-party smart TVs (this is a different category than today's Android TV announcement) the app was killed in 2021. On Android TV, the new "Shop" tab seems to just be an OS-integrated Google TV content store. If you think this sounds confusing, you're not alone. Google's support page reflects the ridiculous state of Google's video apps, instructing users that "in Your Library, you can find content that you bought from: Google Play Movies & TV, YouTube, Android TV, Google TV." How any normal person is supposed to understand that pile of Google media brands, and how it works across phones, the web, and various smart TV OSes, is beyond me.

Android

Russia Targets Ukraine With New Android Backdoor, Intel Agencies Say (arstechnica.com) 24

An anonymous reader quotes a report from Ars Technica: Russia's military intelligence unit has been targeting Ukrainian Android devices with "Infamous Chisel," the tracking name for new malware that's designed to backdoor devices and steal critical information, Western intelligence agencies said on Thursday. "Infamous Chisel is a collection of components which enable persistent access to an infected Android device over the Tor network, and which periodically collates and exfiltrates victim information from compromised devices," intelligence officials from the UK, US, Canada, Australia, and New Zealand wrote (PDF). "The information exfiltrated is a combination of system device information, commercial application information and applications specific to the Ukrainian military."

Infamous Chisel gains persistence by replacing the legitimate system component known as netd with a malicious version. Besides allowing Infamous Chisel to run each time a device is restarted, the malicious netd is also the main engine for the malware. It uses shell scripts and commands to collate and collect device information and also searches directories for files that have a predefined set of extensions. Depending on where on the infected device a collected file is located, netd sends it to Russian servers either immediately or once a day. When exfiltrating files of interest, Infamous Chisel uses the TLS protocol and a hard-coded IP and port. Use of the local IP address is likely a mechanism to relay the network traffic over a VPN or other secure channel configured on the infected device. This would allow the exfiltration traffic to blend in with expected encrypted network traffic. In the event a connection to the local IP and port fails, the malware falls back to a hard-coded domain that's resolved using a request to dns.google.

Infamous Chisel also installs a version of the Dropbear SSH client that can be used to remotely access a device. The version installed has authentication mechanisms that have been modified from the original version to change the way users log in to an SSH session. [...] The report didn't say how the malware gets installed. In the advisory Ukraine's security service issued earlier this month (PDF), officials said that Russian personnel had "captured Ukrainian tablets on the battlefield, pursuing the aim to spread malware and abuse available access to penetrate the system." It's unclear if this was the vector.

Google

Google Removes Fake Signal and Telegram Apps Hosted on Play (arstechnica.com) 12

Researchers say they have found fake apps in Google Play that masqueraded as legitimate ones for the Signal and Telegram messaging platforms. The malicious apps could pull messages or other sensitive information from legitimate accounts when users took certain actions. ArsTechnica: An app with the name Signal Plus Messenger was available on Play for nine months and had been downloaded from Play roughly 100 times before Google took it down last April after being tipped off by security firm ESET. It was also available in the Samsung app store and on signalplus[.]org, a dedicated website mimicking the official Signal.org. An app calling itself FlyGram, meanwhile, was created by the same threat actor and was available through the same three channels. Google removed it from Play in 2021. Both apps remain available in the Samsung store.

Both apps were built on open source code available from Signal and Telegram. Interwoven into that code was an espionage tool tracked as BadBazaar. The Trojan has been linked to a China-aligned hacking group tracked as GREF. BadBazaar has been used previously to target Uyghurs and other Turkic ethnic minorities. The FlyGram malware was also shared in a Uyghur Telegram group, further aligning it to previous targeting by the BadBazaar malware family. Signal Plus could monitor sent and received messages and contacts if people connected their infected device to their legitimate Signal number, as is normal when someone first installs Signal on their device. Doing so caused the malicious app to send a host of private information to the attacker, including the device IMEI number, phone number, MAC address, operator details, location data, Wi-Fi information, emails for Google accounts, contact list, and a PIN used to transfer texts in the event one was set up by the user.

Android

ASUS Reportedly Shuts Down Zenfone Division, No More Compact Flagships (androidauthority.com) 15

According to a report from Technews Taiwan, ASUS has shut down its Zenfone division responsible for making some of the best compact Android flagships on the market. The reason is due to "internal restructuring." Employees in the Zenfone division are being moved over to the ROG Phone team and other parts of the business. Android Authority reports: The report further asserts that the Zenfone 10 will be the last phone in the Zenfone series. Since the team no longer exists, there is unlikely to be a successor to this phone. The report follows other incidents around Zenfone. Earlier in the month, ASUS stopped allowing bootloader unlocks for Zenfone owners. The company maintained that they are not stopping the possibility of unlocking, just that the tool is currently unavailable.

A few weeks ago, community members also spotted that ASUS had removed older Zenfone firmwares from its website. Community moderators responded that ASUS no longer provides previous firmware versions or downgrade packages to ensure users remain on up-to-date firmware. Both of these incidents do not directly point to the shutdown of the Zenfone division. But they add the value of hindsight to the report, and we can't help but wonder if the writing was on the wall all this time.

Youtube

YouTube TV Urged To Drop '$600 Less Than Cable' Ad Claim (lightreading.com) 22

An advertising watchdog has recommended that YouTube TV, Google's growing pay-TV streaming service, drops an ad claim that the service is "$600 less than cable." The recommendation from the National Advertising Division (NAD) stems from a complaint lodged by Charter Communications. From a report: NAD, which used an expedited process for single-issue advertising cases in making this decision, found that YouTube TV's pricing claim, which identifies "comparable standalone cable" as the basis of comparison, doesn't hold up. NAD noted that the price calculation underlying the challenged claim includes the cost of two set-top boxes per household for "standalone cable" services," but argued that such a comparison isn't a good fit because operators such as Charter offer pay-TV streaming options that may not require a set-top box. In Charter's case, its Spectrum TV app, billed as a platform that can "stream outside the cable box," is compatible with iOS and Android mobile devices along with several retail streaming devices and/or integrated connected TVs from companies such as Apple, Roku, Google and Samsung. "In the context of the 'cable' comparison, NAD found the claim reasonably conveys the cost of YouTube TV is compared to all cable services," the organization explained.
Chrome

Google Chrome's Useless Reading Mode To Get a Useful Audio Upgrade (androidpolice.com) 13

Google Chrome is adding a read-aloud option to its reading mode, allowing users to have articles read to them like an audiobook. Android Police reports: Google is actively working to bring additional features to its reading mode, and a handy read-aloud option is already on the way for the Chrome browser. As the name suggests, read aloud basically reads out the entire article, as if you're listening to an audiobook, with text-to-speech (TTS) capabilities. Again, a few mainstream browsers and apps like Pocket already have the feature, but Google Chrome is only now rolling it out through the Canary channel.

When you open an article in Chrome Canary's reading mode on the desktop, you will see a new option, as spotted by browser expert Leopeva64. You can use this tiny play button to get the browser to read the article aloud for you. In the video sample shared by the user, you can hear what the narration sounds like -- and it isn't very pleasing. The voice output sounds pretty robotic as it used to be in the early days of TTS conversions, which is especially ironic coming from Google, which has some of the most natural-sounding voice models at its disposal. This clearly indicates that the read-aloud feature is in its early stages of development and will take some time before it becomes ready for prime time.

Google

Google's Dysfunctional AR Division Plans Apple Vision Pro Clone With Samsung (arstechnica.com) 38

A new report from Business Insider (paywalled) describes how Google's employees were "frustrated" at Google's lack of progress when the Vision Pro was unveiled and provides a glimpse of what Google's current plans for an AR product are. Ars Technica reports: The BI report details how Google's latest dead project, Iris, "was beset by a constantly shifting strategy and lack of focus from senior leadership." After "conversations with seven current and former employees close to Google's AR efforts," Business Insider quotes a few of those anonymous employees, with one saying, "Every six months there was a major pivot in the program." At one point Google was working on a pair of custom silicon chips for the glasses' display and compute power and then gave up on the idea of custom chips. That work was apparently near completion, with one person saying, "I think it's weird when you convince yourselves you need to build custom silicon, and then you go and do that -- and then flush it down the toilet."

Display problems led the team to switch from regular eyeglasses to sunglasses and then back again, and the team couldn't settle on a color or monochrome display. Google showed off a pair of Iris glasses at Google I/O that could translate spoken language, then quickly canned the idea. You might think Bavor leaving in February would be good, considering how little traction the AR division managed in the marketplace, but apparently the executive's departure created a "state of chaos" in the division. Google's next AR pivot is a partnership with Samsung, another company that has dabbled in AR/VR for years yet has no current product line. Google, Samsung, and Qualcomm have already vaguely announced an Apple-fighting mixed-reality partnership in February. Plans to actually launch a headset were reportedly delayed in the wake of the Vision Pro unveiling due to the headset not being competitive. The new launch target is sometime around summer 2024, but the report says that "some employees are skeptical [that] will be enough time to launch a product that will wow the public."

According to the report, Samsung wants to follow its usual strategy and "build a headset device similar to Apple's Vision Pro." The project is apparently code-named "Moohan," and if you couldn't already guess from this lineup of companies, it will run Android. Despite acquiring hardware companies like the Micro-LED manufacturer Raxiom and smart glasses-maker North, Google now wants to "pivot to software" and follow the Android model. The partnership with Samsung makes Moohan the most likely project to actually hit the market, but Google still has two other competing XR projects. Raxiom also is apparently still around and works under Paul Greco, Magic Leap's former chief technology officer. Iris' software work has moved to "a new team" and is being turned into a software project codenamed "Betty" that Google wants to pitch to other manufacturers. Samsung doesn't want any of these other parts of Google or other hardware competitors to be privy to its Vision Pro clone, so the three teams are all firewalled off from each other and have to compete for resources. One current employee described the whole situation as "a weird bureaucratic mess."

AI

Microsoft May Bring AI Capabilities To Apps Like Paint and Photos On Windows 11 20

According to Windows Central, Microsoft might be bringing AI capabilities to a handful of Windows 11 apps, including Photos, Snipping Tool, and Paint. "Some of this functionality will require dedicated hardware, such as an NPU (neural processing unit) or VPU (vision processing unit,) while others may not," notes the report. From the report: For the Photos app, Microsoft is working on an AI functionality that would allow the app to identify objects or people in photos and enable the ability to cut out and paste those elements elsewhere. This is a functionality that iOS and Android have had for some time, so it's no surprise to hear that Microsoft is also working to bring it to Windows.

Regarding the Snipping Tool, my sources say the company wants to incorporate OCR (optical character recognition) technology to enable Windows to identify text in screenshots for faster clipboard copying. Microsoft is also working on bringing OCR to the Camera app, allowing users to select text in a photo taken on the device.

Lastly, my sources say Microsoft has also been experimenting with bringing generative AI to the Windows 11 Paint app. Users could ask Paint to create a canvas based on criteria set out by the user, similar to how Bing Image Creator currently works. Sources say the Paint AI integration will be based on that same Bing technology.
Android

Latest Android Runtime (ART) Update Led To Apps Starting 30% Faster (9to5google.com) 13

The latest update to the Android Runtime (ART) -- the "engine behind the Android operating system (OS)" -- has resulted in app startup time "improvements of up to 30% on some devices," says Google. 9to5Google reports: Behind the scenes, "ART is the same for all devices" and: "The ART APEX module is a complex piece of software with an order of magnitude more APIs than any other APEX module. It also backs a quarter of the developer APIs available in the Android SDK. In addition, ART has a compiler that aims to make the most of the underlying hardware by generating chipset-specific instructions, such as Arm SVE." The testing process for Android Runtime updates involves "compiling over 18 million APKs and running app compatibility tests, and startup, performance, and memory benchmarks on a variety of Android devices that replicate the diversity of our ecosystem as closely as possible." There's then a very gradual rollout process.

Google also notes developer improvements with every update "like OpenJDK improvements and compiler optimizations that benefit both Java and Kotlin," with ART 13 resulting in the "fastest-ever adoption of a new OpenJDK [11] release on Android devices." ART 14 is rolling out "in the coming months" with "new compiler and runtime optimizations that improve performance while reducing code size," as well as OpenJDK 17.

Windows

Lenovo's Handheld 'Legion Go' Gaming Computer: Detachable Controls and AR Glasses? (arstechnica.com) 6

To one-up Valve's Steam Deck, Lenovo's handheld gaming device, the "Legion Go," will have "Switch-style detachable controllers," reports Ars Technica" The Legion Go wouldn't be the very first portable PC gaming device with removable controllers; the crowd-funded OneXplayer sported a similar design last year, for instance. But few other PC-based portables have similarly mimicked the Switch Joy-cons in their ability to slide smoothly off from the main screen of the system for detached play.

Combined with a nice, wide kickstand shown in the leaked images, you should be able to give your arms a rest by setting the bulky-looking Legion Go's screen on a tabletop. The slide-off controls also mean you don't need to purchase and/or drag out a separate controller when docking the device to a TV or monitor (which we assume will be a main use case of the device's two USB-C ports). And completely detachable controls for each hand means you can keep your hands as far apart as you want while you hold each "half-controller" separately (one of our favorite unique use cases on the Switch)... The Legion Go also reportedly sports an 8-inch diagonal screen, which is 1 inch larger than Valve's and ROG's devices.

The Legion Go leaks come just months after Lenovo abandoned its button- and cooler-packed Legion line of Android-based gaming phones as part of what it said was a "gaming portfolio consolidation." The Windows 11-based Legion Go — which Windows Central says will be based on AMD's Phoenix processors — should have the high-end PC gaming support that the Legion phones lacked, as well as a more market-proven form factor.

Windows Report believes Lenovo "is preparing to launch an entire gaming ecosystem alongside the Legion Go."

"Among the accessories is a new pair of Legion AR glasses specifically tweaked for gaming." Based on the images we have, the glasses should be small enough to wear through long gaming sessions, with only one USB cable connecting them to any device (most likely for power, which means no standalone battery). The Legion AR Glasess could also feature a high refresh rate and other gaming-specific features, as the Legion branding implies they're made specifically for that...
Cellphones

Do US Teens Hate Android Phones? (msn.com) 218

America's teens hate Android phones, according to a new article from the Wall Street Journal: Melissa Jones, a former teacher in Lebanon, Ind., observes that, among students, it's considered most important to own a new, up-to-date phone. And judging by the copious TikTok content that pits users of the two operating systems against each other — with Android most frequently the butt of the joke — many teens associate Androids with older technology, and older people, no matter how new the phone actually is.

"You're telling me in 2023, you still have a 'Droid?" says 20-year-old online creator Abdoul Chamberlain during a video posted in April. "You gotta be at least 50 years old." The video goes on to say that only parents have Androids, and despite the persistent claims from Android users that features like the cameras or battery life are better on the Android than the iPhone, Chamberlain refuses to get one. Other videos more somberly describe the experience of showing up to high school with an Android phone and being called "broke" or "medieval" by the poster's peers. Still more describe the feeling of being the lone Android user in a group chat of iPhone owners, shamed by texts which, when rendered in Apple's proprietary iMessage platform, appear in a revelatory bright green rather than the cool blue of messages sent between Apple devices.

Apple holds 57% of the phones market versus Android's 42% in the U.S., according to web traffic analysis site Statcounter. The data skews worse for Android when narrowed down to teenagers. According to a survey of 7,100 American teens last year conducted by investment bank Piper Sandler, 87% of teens currently have an iPhone, and 87% plan on sticking with the brand for their next phone.

But the stigma regarding Android phones is mostly an American phenomenon, at least to the degree to which it affects purchase habits. Worldwide, per the same Statcounter report, Androids represent the significant majority of all smartphones, holding a 71% share of sales compared with Apple's 28%.

Two years ago someone asked Reddit's "Ask Teens" forum, do teenagers really hate Android phones? But the responses were a lot more balanced.

"No," replied one (presumably teenaged) Reddit user. "Apple fanboys are just obnoxious, probably because they're knowingly getting scammed."
Google

Google Chrome Will Summarize Entire Articles For You With Built-in Generative AI (theverge.com) 54

Google's AI-powered Search Generative Experience (SGE) is getting a major new feature: it will be able to summarize articles you're reading on the web, according to a Google blog post. From a report: SGE can already summarize search results for you so that you don't have to scroll forever to find what you're looking for, and this new feature is designed to take that further by helping you out after you've actually clicked a link. You probably won't see this feature, which Google is calling "SGE while browsing," right away. Google says it's a new feature that's starting to roll out Tuesday as "an early experiment" in its opt-in Search Labs program. (You'll get access to it if you already opted in to SGE, but if you haven't, you can opt in to the feature on its own.) It will be available first in the Google app on Android and iOS, and the company is bringing it to the Chrome browser on desktop "in the days ahead."
Movies

Netflix Starts Testing Game Streaming on Select Devices, Smart TVs and Desktop Browsers (engadget.com) 13

Netflix is officially bringing its games to more devices. So far, the company's impressive library of games has only been available on iOS and Android. Now, though, Netflix is starting to use its streaming tech to publicly test its titles on TVs and computers. From a report: "Our goal has always been to have a game for everyone, and we are working hard to meet members where they are with an accessible, smooth and ubiquitous service," Mike Verdu, Netflix's vice-president of games, wrote in a blog post. "Today, we're taking the first step in making games playable on every device where our members enjoy Netflix." The test appears to be very limited for now. Just two games will be available at the outset: Oxenfree. The beta is only open to a small number of Netflix subscribers in the UK and Canada on Amazon Fire TV streaming media players, Chromecast with Google TV, LG TVs, NVIDIA Shield TV, Roku devices and TVs, Samsung smart TVs and Walmart ONN. The company will add support for more devices later.
Android

Mozilla To Bring Firefox Desktop Extension To Android Browser (mozilla.org) 30

Scott DeVaney, writing at Mozilla blog: In the coming months Mozilla will launch support for an open ecosystem of extensions on Firefox for Android on addons.mozilla.org (AMO). We'll announce a definite launch date in early September, but it's safe to expect a roll-out before the year's end. Here's everything developers need to know to get their Firefox desktop extensions ready for Android usage and discoverability on AMO.

For the past few years Firefox for Android officially supported a small subset of extensions while we focused our efforts on strengthening core Firefox for Android functionality and understanding the unique needs of mobile browser users. Today, Mozilla has built the infrastructure necessary to support an open extension ecosystem on Firefox for Android. We anticipate considerable user demand for more extensions on Firefox for Android, so why not start optimizing your desktop extension for mobile-use right away?

Privacy

Researchers Watched 100 Hours of Hackers Hacking Honeypot Computers (techcrunch.com) 34

An anonymous reader quotes a report from TechCrunch: Imagine being able to sit behind a hacker and observe them take control of a computer and play around with it. That's pretty much what two security researchers did thanks to a large network of computers set up as a honeypot for hackers. The researchers deployed several Windows servers deliberately exposed on the internet, set up with Remote Desktop Protocol, or RDP, meaning that hackers could remotely control the compromised servers as if they were regular users, being able to type and click around. Thanks to these honeypots, the researchers were able to record 190 million events and 100 hours of video footage of hackers taking control of the servers and performing a series of actions on them, including reconnaissance, installing malware that mines cryptocurrencies, using Android emulators to conduct click fraud, brute-forcing passwords for other computers, hiding the hackers' identities by using the honeypot as a starting point for another attack, and even watching porn. The researchers said a hacker successfully logging into its honeypot can generate "tens of events" alone.

The "Rangers," according to the two, carefully explored the hacked computers, doing reconnaissance, sometimes changing passwords, and mostly leaving it at that. "Our hypothesis is that they are evaluating the system they compromised so that another profile of attacker can come back later," the researchers wrote in a blog post published on Wednesday to accompany their talk. The "Barbarians" use the compromised honeypot computers to try and bruteforce into other computers using known lists of hacked usernames and passwords, sometimes using tools such as Masscan, a legitimate tool that allows users to port-scan the whole internet, according to the researchers. The "Wizards" use the honeypot as a platform to connect to other computers in an attempt to hide their trails and the actual origin of their attacks. According to what Bergeron and Bilodeau wrote in their blog post, defensive teams can gather threat intelligence on these hackers, and "reach deeper into compromised infrastructure."

According to Bergeron and Bilodeau, the "Thieves" have the clear goal of monetizing their access to these honeypots. They may do that by installing crypto miners, programs to perform click fraud or generate fake traffic to websites they control, and selling access to the honeypot itself to other hackers. Finally, the "Bards" are hackers with very little or almost no skills. These hackers used the honeypots to use Google to search for malware, and even watch porn. These hackers sometimes used cell phones instead of desktop or laptop computers to connect to the honeypots. Bergeron and Bilodeau said they believe this type of hacker sometimes uses the compromised computers to download porn, something that may be banned or censored in their country of origin. In one case, a hacker "was downloading the porn and sending it to himself via Telegram. So basically circumventing a country-level ban on porn," Bilodeau told TechCrunch. "What I think [the hacker] does with this then is download it in an internet cafe, using Telegram, and then he can put it on USB keys, and he can sell it."
These types of honeypots could be useful for law enforcement or cybersecurity defensive teams. "Law enforcement could lawfully intercept the RDP environments used by ransomware groups and collect intelligence in recorded sessions for use in investigations," the researchers wrote in the blog post. "Blue teams for their part can consume the [Indicators of Compromise] and roll out their own traps in order to further protect their organization, as this will give them extensive documentation of opportunistic attackers' tradecraft."

Moreover, if hackers start to suspect that the servers they compromise may be honeypots, they will have to change strategies and decide whether the risks of being caught are worth it, "leading to a slow down which will ultimately benefit everyone," according to the researchers.
Google

Google Launches Project IDX, a New AI-Enabled Browser-Based Development Environment (techcrunch.com) 17

An anonymous reader quotes a report from TechCrunch: Google today announced the launch of Project IDX, its foray into offering an AI-enabled browser-based development environment for building full-stack web and multiplatform apps. It currently supports frameworks like Angular, Flutter, Next.js, React, Svelte and Vue, and languages like JavaScript and Dart, with support for Python, Go and others in the works. Google did not build a new IDE (integrated development environment) when it created IDX. Instead, it is using Visual Studio Code -- Open Source as the basis of its project. This surely allowed the team to focus on the integration with Codey, Google's PaLM 2-based foundation model for programming tasks. Thanks to Codey, IDX supports smart code completion, a ChatGPT/Bard-like chatbot that can help developers with general coding questions as well as those related specifically to the code you are working on (including the ability to explain it) and the ability to add contextual code actions like "add comments."

"We spend a lot of time writing code, and recent advances in AI have created big opportunities to make that time more productive," the IDX team explains in today's announcement. "With Project IDX, we're exploring how Google's innovations in AI -- including the Codey and PaLM 2 models powering Studio Bot in Android Studio, Duet in Google Cloud and more -- can help you not only write code faster, but also write higher-quality code." As a cloud-based IDE, it's no surprise that Project IDX integrates with Google's own Firebase Hosting (and Google Cloud Functions) and allows developers to bring in existing code from the GitHub repository. Every workspace has access to a Linux-based VM (virtual machine) and, soon, embedded Android and iOS simulators right in the browser.

Encryption

Google's Messages App Will Now Use RCS By Default and Encrypt Group Chats (techcrunch.com) 72

Speaking of SMSes, Google announced today it's making its Messages by Google app more secure with improvements to RCS, or Rich Communication Services -- a protocol aimed at replacing SMS and is more on par with the advanced features found in Apple's iMessage. From a report: The company says it will now make RCS the default for both new and existing Messages app users. In addition, end-to-end encryption for group chats is now fully rolled out to all RCS users. The latter had launched into an open beta earlier this year after earlier tests, but was not fully launched until now. With this update, all conversations between users in Messages, whether 1:1 or group chats, will now be kept private, Google says.

Since rolling out RCS to U.S. Android users in 2019, Google has been campaigning in an effort to pressure Apple into adopting the technology in its own messaging service, iMessage. It even launched a website last year to explain why RCS benefits consumers, noting "It's not about the color of the bubbles. It's the blurry videos, broken group chats, missing read receipts and typing indicators, no texting over Wi-Fi and more."

Facebook

Meta is Giving Up on Messenger's SMS Feature (theverge.com) 21

Seven years after updating Messenger to allow it to serve as your default Android text messaging app, the company formerly known as Facebook is quietly abandoning the feature. From a report: According to a support page, the feature will disappear after September 28th. I don't know anyone that uses it, but at least it'll be nice to have one fewer screens to tap through during setup.

Slashdot Top Deals