Burp Suite New GraphQL API to Detect Hidden Endpoints

0
[ad_1]
Burp Suite GraphQL API

The Burp Scanner’s new GraphQL capabilities allow it to recognize known endpoints, locate hidden endpoints, determine whether introspection or recommendations are enabled, and report when an endpoint fails to validate the content type.

Portswigger, the firm behind the renowned web application security testing tool Burp Suite, has announced that Burp Scanner’s new GraphQL checks will automatically indicate multiple instances of GraphQL vulnerabilities during penetration testing.

In most cases, implementation and design problems lead to GraphQL vulnerabilities. Attacks using GraphQL often take the form of malicious requests that provide the attacker access to data or allow them to carry out unauthorized operations.

These attacks may be quite damaging, especially if the user manages to obtain administrator rights by tampering with queries or using a CSRF vulnerability. Information disclosure problems may also result from GraphQL API vulnerabilities.

Identify GraphQL API Flaws

Burp Scanner makes it easy to find the GraphQL endpoint on websites rather than having to manually search through them.

“We’ve defined some passive and active scan checks to find known endpoints automatically, allowing you to focus on finding the vulnerabilities,” the company stated.

When deploying a GraphQL endpoint to production by accident, for instance, a developer can do so without using it on the website. 

Even if a site isn’t utilizing GraphQL, Burp Suite will search for common endpoints and finds hidden deployments.

Source : portswigger

Given that a vulnerability will likely be discovered if it’s an unintentional deployment, these endpoints might be an invaluable resource for a tester.

Introspection lets you execute a query on the real schema to discover what queries it supports. Because a website might not wish to reveal the inner workings of its API to the public, it is frequently disabled in production. 

Burp will detect whether introspection is enabled; while this isn’t a vulnerability in and of itself, it may be beneficial to a tester to help test the site and to a developer to serve as a reminder to turn it off in production.

Further, the company stated that to assist in creating a proper query, certain GraphQL servers, such as Apollo, will offer recommendations when you submit an incorrect query.

Hence, even with introspection turned off, a tester may still utilize this to identify the underlying schema by using a word dictionary and the suggested answer as an oracle.

A valid schema may be created from a dictionary using a tool like clairvoyance. You may locate endpoints with recommendations enabled and report them using Burp.

A POST method with an application/json content type is used by the majority of GraphQL endpoints.

A browser cannot make this request without utilizing CORS (Cross-origin resource sharing ) if the content type is appropriately verified since sending the proper content type will be impossible.

This protects the endpoint against CSRF (Cross-site request forgery). 

However, it may be feasible to abuse the GraphQL endpoint by forging queries if a site does not check the content type and does not utilize a CSRF token, provided mitigations like SameSite cookies may be disregarded or neutralized due to the SameSite None flag. 

Burp will alert the user if a POST request with application/x-www-form-urlencoding or a GET request to the endpoint may be forged.

Conclusion

One of the most well-liked approaches to creating APIs and data-driven apps is now GraphQL. Traditional REST APIs provide a predetermined set of endpoints and replies, but GraphQL enables clients to query for just the data they want, increasing flexibility and efficiency for both client and server.

Knowing the most recent tools will help penetration testers uncover the most recent vulnerabilities. Today’s websites frequently employ GraphQL APIs, which expose the attack surface for a variety of security problems.

“AI-based email security measures Protect your business From Email Threats!” – Request a Free Demo.


[ad_2]
Source link

Official Nothing Phone (2) images surface ahead of launch

0
[ad_1]

The Nothing Phone (2) will become official in about a week, on July 11. As we’re waiting for that to happen, a handful of official Nothing Phone (2) images surfaced online. These images come from Evan Blass aka @evleaks, one of the most prominent tipsters out there.

A handful of official Nothing Phone (2) images leak ahead of launch

Before we get to it, do note that the design of the phone is not exactly a secret now. Nothing partnered up with MKBHD in order to show off the device, in a hands-on video. These images do give us yet another look at the phone, though.

You’ll get to see both color options that will be on offer here, both a white and a dark gray model. That gray variant is replacing the black Nothing Phone (1) model, for better or worse.

Now, the Nothing Phone (2) may look very similar to the Nothing Phone (1), especially at first glance, but there are some differences. Nothing improved the Glyph system on the back, by adding a lot more LEDs, and giving them more functionality.

The device will be easier to hold and use, while its display camera hole also moved

On top of that, the back glass on the phone is now curved, making the device easier and more enjoyable to hold. The sides on the device are still flat, though, and the back glass is see-through, as expected.

The display camera hole is moved to the centered of the display, and the display is still flat. The phone will be made out of metal and glass, as was its predecessor. Two cameras are still placed on the back.

We do know that the Nothing Phone (2) will be fueled by the Snapdragon 8+ Gen 1 SoC. The device will also include a slightly larger display than its predecessor, while retaining a 120Hz refresh rate.

Android 13 will come pre-installed, with a new version of Nothing OS, version 2.0. That build will bring a number of changes to the OS, and based on teasers, quite notable ones.

You’ll get both wired and wireless charging here, stereo speakers, and more. If you’d like to know more about the phone, check out our Nothing Phone (2) preview.


[ad_2]
Source link

Elderly targeted in car accident scam, kingpin arrested

0
[ad_1]

The head of a criminal network responsible for defrauding hundreds of elderly people has been arrested, Europol has announced.

The head of a criminal network responsible for defrauding hundreds of elderly people has been arrested, Europol has announced.

After a joint operation in Germany, Poland, and the UK, Europol says the suspect was arrested in London from where he ran a network of fraudsters targeting mainly German and Polish citizens. Europol estimates that the overall damage done by the network amounts to around €5 million, and that €1.4 million of losses were prevented thanks to the successful takedown.

The fraudsters pretended to be police officers or impersonated other official authorities, calling targets to tell them one of their relatives had caused something like a car accident which resulted in injuries or the death of someone else. An accomplice, pretending to be the relative, would cry or scream into the phone frantically, begging the target to lend help.

The end goal was to get the target to hand over an amount of money to avoid the fake relative’s detention. The criminals would then send a person to collect the money at the victim’s doorstep. For this part the criminal network recruited unwitting accomplices for this task through online job platforms, in order to minimize exposure and avoid the risk of arrest of the criminals running the operation.

Targeting the elderly is nothing new, sadly. In many forms of phone scams, the perpetrators pose as close relatives of the targeted victims and pretend to have encountered financial, legal or health difficulties in order to fraudulently obtain money. Europol says:

“Crime targeting elderly citizens through scam calls, where individuals impersonate representatives of police and judicial authorities, poses a grave danger and has a profound impact on the victims. Apart from the suffered and often irrecoverable financial damage, it can cause emotional distress and a loss of trust in legitimate authorities.”

Don’t fall for them

It is important to stay vigilant and protect yourself from scam calls by following these guidelines:

  • Don’t share personal or financial information with unknown or unexpected callers
  • If someone is saying they are a relative of yours, check via another way—by calling them back on their own phone or other means to verify it is really them.
  • Keep in mind that law enforcement and other officials will never ask for money or payments over the telephone or in person by showing up at your door.
  • If you receive a call like this, hang up immediately and tell the police.

We’d also like to point out our 9 basic security tips for seniors to help you stay safe.


Malwarebytes EDR and MDR removes all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.

TRY NOW


[ad_2]
Source link

Fake reviewers face big fines

0
[ad_1]

The FTC’s new proposed rule would apply large fines to those found distributing fake reviews online.

The FTC is cracking down on fake reviews. Under the new proposed rules, organisations involved in the buying, selling, and manipulation of reviews could be very much out of pocket. Every time a consumer sees a fake review, it will carry a fine of “up to $50,000” per viewing.

From the FTC release:

Our proposed rule on fake reviews shows that we’re using all available means to attack deceptive advertising in the digital age,” said Samuel Levine, Director of the FTC’s Bureau of Consumer Protection. “The rule would trigger civil penalties for violators and should help level the playing field for honest companies.”

Fake reviews are a huge aggravation online. Quite often they’re not “just” a bogus review that doesn’t really matter. They trick you into buying substandard products. Bogus offers and deals float to the top of a site’s visibility if they have enough positive entries. People are so enamoured of the best scores imaginable that threats can follow on even when a great (and entirely real) review has been left.

Can you be certain that those eBay reviews are genuine? What about that Etsy seller? Is the unusual but one of a kind item on Amazon being floated to the top of the pile with dozens of fake reviews?

These FTC rules aim to help you find out. The range of topics covered are very comprehensive and cover all the bogus review angles you can think of:

  • Selling or obtaining fake consumer reviews and testimonials: The proposed rule would prohibit businesses from writing or selling consumer reviews or testimonials by someone who does not exist, who did not have experience with the product or service, or who misrepresented their experiences. It also would prohibit businesses from procuring such reviews or disseminating such testimonials if the businesses knew or should have known that they were fake or false.
  • Review hijacking: Businesses would be prohibited from using or repurposing a consumer review written for one product so that it appears to have been written for a substantially different product. The FTC recently brought its first review hijacking enforcement action.
  • Buying positive or negative reviews: Businesses would be prohibited from providing compensation or other incentives conditioned on the writing of consumer reviews expressing a particular sentiment, either positive or negative.
  • Insider reviews and consumer testimonials: The proposed rule would prohibit a company’s officers and managers from writing reviews or testimonials of its products or services, without clearly disclosing their relationships. It also would prohibit businesses from disseminating testimonials by insiders without clear disclosures of their relationships, and it would prohibit certain solicitations by officers or managers of reviews from company employees or their relatives, depending on whether the businesses knew or should have known of these relationships.
  • Company controlled review websites: Businesses would be prohibited from creating or controlling a website that claims to provide independent opinions about a category of products or services that includes its own products or services.
  • Illegal review suppression: Businesses would be prohibited from using unjustified legal threats, other intimidation, or false accusations to prevent or remove a negative consumer review. The proposed rule also would bar a business from misrepresenting that the reviews on its website represent all reviews submitted when negative reviews have been suppressed.
  • Selling fake social media indicators: Businesses would be prohibited from selling false indicators of social media influence, like fake followers or views. The proposed rule also would bar anyone from buying such indicators to misrepresent their importance for a commercial purpose.

The really interesting part here is that it isn’t only the fake review posters looking at a whole lot of trouble. It’s the companies sitting in the middle who should have known reviews are fake too. The FTC is tackling this problem on all fronts, potentially reducing the wiggle-room that those involved typically use to get themselves out of trouble. In software land, “rogue affiliates” take the blame all the time and organisations which should likely also be punished get away with a light slap on the wrist. There’s nothing light about $50k per fake review viewing.

As a final warning bell to those tempted to fake it to make it, this isn’t the only financial penalty waiting in the wings. The FTC would also possess the ability to recover money directly for anyone harmed by the fake reviews.

There will be some limits, however. Social media portals and review sites themselves are free of liability unless involved in the creation of the fake reviews. The Washington Post notes that some of the big players are taking the problems caused by fake reviews seriously. Amazon blocked “more than 200 million suspected fake reviews in 2022”. Elsewhere, Yelp flagged 19% of reviews in 2022 as “not recommended”.

All the same, you often don’t have to look hard to find some bogus reviews. Will a combination of large sites continuing to police their backyards and the FTC bringing the proverbial hammer down turn the tide? Perhaps. Even with the new rules on the horizon, areas outside of the FTCs jurisdiction may not play ball. If you’re not in the US, you may experience spammy and fake reviews for some time to come.

Ultimately, as Samuel Levine of the FTC points out to The Washington Post, big review sites may be “running out of excuses”. If they have the most visibility of all of us into these issues on their sites, they’re almost certainly best placed to put an end to it. If they manage to pull it off, they can have all the five star reviews in town.


Malwarebytes EDR and MDR removes all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.

TRY NOW


[ad_2]
Source link

Galaxy Watch 6 series spotted in another certification listing

0
[ad_1]

After picking up the FCC certification last month, Samsung‘s Galaxy Watch 6 series has just surfaced on the Google Play Console website. The listing doesn’t reveal any new information about the upcoming smartwatches but confirms the return of the Classic model. The new watches will debut later this month.

Spotted by 9to5Google, the Google Play Console website lists four model numbers for the upcoming Samsung watches: SM-R930, SM-R940, SM-R950, and SM-R960. We have long known that these are the Bluetooth versions of the 40mm and 44mm Galaxy Watch 6 and the 42mm and 46mm Galaxy Watch 6 Classic, respectively. These sizes aren’t officially confirmed, but the codenames “fresh6bl” and “fresh6bs” refer to large and small models.

As of this writing, the LTE versions of the Galaxy Watch 6 series haven’t appeared on the Google Play Console website. Their model numbers will replace the “0” at the end with a “5”. Apart from LTE connectivity, everything else will remain the same. The watches will come in the same sizes as their Bluetooth counterparts and will not bring any changes to changes to internals and the design.

Speaking of internals, rumors are that Samsung will offer marginally bigger batteries inside the Galaxy Watch 6. The smaller two models will get a 300mAh battery, while the bigger two models feature a 425mAh battery. The Galaxy Watch 5 series featured 284mAh and 410mAh batteries, respectively. Of course, Samsung launched a Galaxy Watch 5 Pro with a bonkers 590mAh battery last year. But it’s now switching to the Classic model with a physical rotating bezel.

The Galaxy Watch 6 series will bring more upgrades

Despite the same size, the Galaxy Watch 6 series is rumored to feature marginally bigger screens, thanks to Samsung shrinking the bezels. The screens are also sharper than before. Additionally, the company is expected to equip the watches with an improved processor (Exynos W930) for faster performance. The Wear OS 4-based One UI Watch 5 should also bring functional improvements. We are expecting a host of new and improved health features as well.

The Galaxy Watch 6 won’t upgrade in one key area, though. The new swatches aren’t getting faster charging. Samsung is keeping them limited to 10W of wireless charging. It has never shown interest in offering blazing-fast charging speeds on its mobile devices. Most of its smartphones are limited to 25W speeds, including the Galaxy S23 flagship. Stay tuned for the official launch of the Galaxy Watch 6 after this month. The watches will debut alongside new foldables and tablets at Samsung’s Galaxy Unpacked event in South Korea.


[ad_2]
Source link

Apple must comply with DMA rules about sideloading apps, in-app payments and more starting March 6th

0
[ad_1]
As per Reuters, five major U.S. tech firms have agreed that they meet the European Union’s (EU) criteria of “gatekeeper” which means that they are subject to tougher rules. The U.S. tech companies that are gatekeepers include Amazon, Apple, Google, Facebook-parent Meta, and Microsoft. Also considered to be gatekeeper companies in the EU are Samsung and TikTok parent ByteDance. The latter firm didn’t agree that it belonged in this classification. Online travel agency Booking.com said that it will be considered a gatekeeper tech firm next year.

Apple, Google, Amazon, Meta, Microsoft, Samsung and ByteDance are considered gatekeepers under the DMA

The reason why it is important whether or not a company is classified as a gatekeeper has to do with the EU’s Digital Markets Act (DMA) which took effect in November. Under the terms of the DMA, companies with more than 45 million monthly active users and a market cap of 75 billion euro ($82 billion) and higher are gatekeepers. As such, the DMA requires these firms to allow their messaging apps to work with rival messaging platforms, and allow consumers to decide which apps will be pre-installed on their devices.

Gatekeeper companies including Apple and Google will not be allowed to favor their own services and apps over those belonging to rivals and users cannot be prevented from deleting apps pre-loaded by gatekeeper companies on their own devices. Companies that fail to follow the DMA can be fined up to 10% of their annual global revenue. In Apple’s case, based on its fiscal 2022 worldwide revenue, Apple could face a fine of $39 billion for failing to comply with DMA rules.
In theory, the DMA could force Apple to allow third-party app stores on the iPhone and also force the company to allow iPhone users to sideload apps from third-party iOS app storefronts. Apple has always said that its walled garden is necessary so that it can watch over all apps downloaded on its devices to reduce the chances that an iPhone or iPad user is loading malware on his/her phone or tablet.

The DMA could force Apple to stop demanding that developers send their customers to Apple’s in-app payment platform

The DMA also could prevent Apple from forcing developers to use its payment system for processing in-app payments and subscriptions. Apple gets a cut of up to 30% on payments that it processes. While Google also takes a similar cut on in-app payments made through its payment processing platform, the company does allow apps to be sideloaded on Android.

The gatekeeper companies will provide the EU with data by September 6th, which will confirm whether they meet the designation. If so, they will have another six months, until March 6th, to comply with the rules. EU industry chief Thierry Breton says, “Europe is completely reorganizing its digital space to both better protect EU citizens and enhance innovation for EU startups and companies.”

ByteDance says that it should not be considered a gatekeeper. While it does meet the qualitative qualifications of a gatekeeper, the Chinese social media company says that it doesn’t meet the requirement calling for it to be an “unavoidable platform to conducting online business in the EU” and to be an “entrenched” gateway between consumers and businesses. Booking.com says that it will meet the qualifications to be labeled a gatekeeper by the end of the year.

Keep in mind that the DMA will only cover devices, apps, and services being purchased in one of the EU member countries. Of course, the U.K. left the EU on January 31st, 2020 which means that devices in the U.K. are not subject to the DMA antitrust legislation. There are 27 member countries in the EU.


[ad_2]
Source link

Galaxy S25 Ultra concept ditches bezels, uses under-display camera

0
[ad_1]

Another interesting concept design has been shared on YouTube, this time around it’s related to the Samsung Galaxy S25 Ultra. It has been shared by the Technizo Concept YouTube channel.

This Galaxy S25 Ultra concept has very thin bezels, and under-display camera

This is just a third-party concept, of course, it’s not a leak or anything of the sort. The designer is sharing his vision for Samsung’s 2025 flagship here. The real deal will likely look much different, though this phone looks outstanding.

If you check out the video that is embedded below the article, you’ll see what we mean. This concept smartphone has razor-thin bezels, not to mention it doesn’t have a display camera hole. The designer envisioned an under-display camera here, one that you can’t exactly see.

The phone does have a boxy shape, with flat top and bottom sides. The back glass is curved, as is the phone’s display, slightly. The frame is made out of metal, while all the physical buttons are located on the right.

The designer envisioned a 150x camera zoom for this phone

There are three cameras included on the back, with some added sensors. The designer also envisioned a 150x periscope zoom for this phone, by the way, as it’s pointed out in the video. The same goes for the Snapdragon 8 Gen 3, though considering this is the Galaxy S25 Ultra concept, it should have been the Snapdragon 8 Gen 4. Someone made a mistake in that regard, the Snapdragon 8 Gen 3 will be in use in the Galaxy S24 series.

The camera array on the back of the phone does look odd, and the main camera is obviously has a much lager sensor than the rest. You’ll also notice an S Pen stylus in the S Pen silo, which is located in the bottom-right corner.

The device is shown in only one color in this video, a beige color of sorts. The video itself lasts about 2 minutes, so if you’d like to check it out, it’s embedded below.


[ad_2]
Source link

Samsung fanboys are the ones keeping the Galaxy foldables afloat

0
[ad_1]

There are a bunch of companies out there making foldable phones, and it seems that more are hopping on this bandwagon. It’s the future, what do you expect!? Among them, Samsung is the top dog. Why is this, though? What force is keeping the Galaxy Z foldables afloat? In short, it’s the Samsung fanboys.

Now, this isn’t a hit piece on Samsung, its fans, or its products. It makes great products. Here at AH, we review Sammy’s phones and tablets highly. Samsung spent four generations honing the design of its foldable phones. It survived the dog days of early foldable growing pains and it continues to pour millions of R&D bucks into its foldable phones.

We also can’t forget that Samsung sells its phones in a lot of markets. Most other foldable phone manufacturers are Chinese, and they’re pretty wary about entering the US market for understandable reasons. Also, Google is precious about which markets to distribute its first-gen foldable. So, we can’t say there’s no reason for these phones to sell.

But, what’s keeping the Galaxy foldables afloat?

The above-mentioned are reasons for the phones to sell, but they’re not what’s keeping the series afloat. Other phones have a lot of R&D put into them, are refined, and are available in many markets. Some sell well while others barely break even. Oftentimes, it’s not the hardware that makes a phone sell, it’s how that hardware hypnotizes the user.

In this case, we’re talking about the diehard Samsung fans. Not the “I think Samsung makes high-quality products” kind; we’re talking about the “Samsung does no wrong! It’s the best company in the world!!” kind. We’re talking about the people who will take any compromise that Samsung makes and won’t fault it or ask the company to do better.

Other companies have left Samsung in the dust

Samsung has been a driving force in the foldable phone market since day one when only it and Huawei dared to build one. Now, much smaller companies like OnePlus are making their own foldable phones. However, these other companies have left Samsung in the dust when it comes to foldable design. Other companies like Oppo and Vivo are creating more exciting and accessible foldable phones than what we’re getting from Samsung.

People, since day one, have dragged Samsung for making a foldable phone that’s so slender. When folded- in its “candy bar” mode- the phone almost has the exact dimensions of an actual candy bar. The display is so thin that you almost always have to open it to get work done. That defeats the purpose of having a notebook foldable in the first place. You know, where it’s both a phone and a tablet.

Oppo defined a new era in foldable phone technology when it unveiled the Oppo Find N in 2021. This phone looked like someone took a Galaxy Foldable and squished it. And, it worked! The wider form factor let people know that they could still use their phones when closed. No matter how impressive the phone is when unfolded, you should still be able to use it as a phone.

Now, other companies have emulated that idea and left Samsung’s form factor behind. We can honestly say that Oppo pushed the foldable phone market forward. It’s just sad that Samsung hasn’t gotten with the program.

Let’s talk about exciting changes… or lack thereof

This is a trend that we’re seeing more with Samsung phones. Back in the day, Samsung was the breath of fresh air we needed after every iPhone launch. Apple would launch a phone that was a carbon copy of the iteration before it, but Samsung would debut a phone with some sort of new “wow” factor, radical new design, and a boatload of new features. We always expected Samsung to bring the “Next big thing”, and it did.

Now, its foldable phones show much the opposite. Each iteration of the company’s foldable phones offers nothing more than minor tweaks, the latest Snapdragon chip, and maybe some boosted specs. Sure, the Z Fold 5 is expected to have IP68 water and dust resistance to protect it from sand, but who’s taking their $1800 phone to the beach?

What else is there to make each generation a reasonable upgrade over the last? I will say this, with those first couple of generations of foldables, Samsung did a lot in terms of making them more durable. So, that’s something that I tip my hat to the company for.

But, we’re past the days when grains of sand and dust ruined phones. Foldable phones from much smaller companies, with far fewer resources and R&B bucks, are pushing their foldable phones with no durability issues. Honor, the underdog that used to be on Huawei’s leash, managed to shrink the number of hinge components to just four with its foldable. That greatly reduces the number of moving parts and the chance of ingress. Samsung can’t bank on the durability aspect anymore to keep the Galaxy foldables afloat.

A pedestal built by the fans

With all that said, Samsung is going to outsell the competition in the foldable market when it launches. Why? Well, those diehard Samsung fans. Other companies are showing that they’re taking the foldable market seriously. They’re adding features, developing amazing designs, and changing those designs. Samsung is sticking its users with basically the same phone they got last year with some updated specs. And they’re okay with that!

They’ll happily pay the $1800 for the same experience they paid $1800 for last year or two years ago. This gives Samsung free reign to repackage and serve the same experience. Other companies like Honor, Motorola, Vivo, Oppo, Xiaomi, etc. have to put a huge focus on making their next foldable phone leagues better than their last. They have to bring that “wow” factor, that excitement to make people part with over $1000. And, we’ve seen some amazing results of that.

Meanwhile, Samsung can comfortably stand by and pump out phones with the same design it’s had for generations. Does that sound familiar? If so, then you’ve seen what Apple does. The company has successfully pushed phones with the same design since the iPhone 11. And you know what, people are still eating it up.

This is the same thing that we’re seeing with the Galaxy foldables. They sit on a pedestal, a pedestal built by the fans, and there’s no motivation to innovate. With every new Samsung product to hit the shelves, the company knows that it has a fanbase built-in that will gladly pay their arms, legs, and first-born children for.

The Apple mentality

This points to a larger issue in the tech industry. Apple seemed to have struck a magical formula among its fans. The company has the ability to sell the same product year-over-year with no opposition from its fans. Try to tell the difference between the iPhone 12, iPhone 13, and iPhone 14. Try to do the same with MacBooks, iPads, etc. You’ll have an easier time learning quantum physics. Yet, Apple still eats up more than half of the global smartphone shipments each year.

I’m sorry to say that the prodigal child Samsung is becoming the same way. Its latest Galaxy S phones show little to no change over previous iterations, and it’s worse for its tablets. It’s selling these phones at exorbitant prices when you can get equally capable devices for hundreds less. Yet, it’s still the highest-selling Android OEM on the planet. Samsung has adopted the Apple mentality, and it shows with its foldable phones. The only question is,  how long can the company keep this up before it starts to see fatigue? This can only keep the Galaxy foldables afloat for so long.


[ad_2]
Source link

How to stay safe on the Google Play Store

0
[ad_1]

Searching for applications for your computer online can be like navigating a minefield. There are tons of threats out there from malware to scam artists that you need to tip-toe around. It can be just as hard to stay safe on an app store like the Google Play Store. That’s right! There are also threats on the Google Play Store.

These threats are, unfortunately, hard to spot sometimes. Malicious actors go through a great deal of trouble making their dangerous apps look innocuous. But, that doesn’t mean that you can’t spot them. With the proper knowledge and preparation, you’ll be able to protect yourself while searching for your next favorite app on the Play Store.

What kind of threats are out there?

Let’s start by talking about what kind of threats are out there. Again, there are more threats out there than you think. While most of the apps you’re being fed by the algorithm are safe, there’s always the chance that you’ll find one that isn’t. What are some of the threats looming on the Play Store?

Malware

Yes, your phone can be infected with malware. If you’re unfamiliar with the term “malware”, most people use the term “virus” to refer to any form of malicious software. A virus is actually a category of malware. The main takeaway should be this: malware is bad.

When you download a bad app, there’s the chance that you’ll also download a bit of software that can get into your system and do all sorts of unwanted actions. It could gain access to sensitive information, cause systems to misbehave, run ads in the background, cause your system to slow down, and more.

Scams

Scams exist in all shapes and forms, so it should come as no surprise that there are scams targeting smartphone users. These are apps that ask for money and promise a large payout or reward for you. Obviously, they don’t deliver. The only thing they payout is sadness.

There are also scams that fool you into watching a torrent of ads to complete different tasks. While you’re not actually paying money, you’re still earning a ton of money for the app developer to pocket and not redistribute.

Imposter apps

Depending on the app, there might not be any devastating consequences, but there’s always that chance that they’re malicious. Imposter apps are disguised to look exactly like another app and fool the user into downloading them. They could have a similar name to a popular app or game and sport a similar logo.

For instance, if you type in “Instagram” and you get results named “Instantgram” or “Instgram”, then those would be imposter apps. Their names are extremely similar to the real deal, and you can miss it if you’re not paying attention.

Apps like these could be harmless in that the developer is cheating to get more people to use their app. However, there’s also the chance that the app could come with malware. Also, there are apps that are just to funnel ads your way. What some apps will do is load a bunch of ads at the very start of the app. By the time you notice that something is up, you’ve already watched several ads.

Sure, a few ads from you isn’t all that much, but millions of people will download that app thinking that it’s the real Instagram.

How to stay safe on the Google Play Store

Now, that’s enough fearmongering. You shouldn’t take this as a sign to stop downloading apps. By all means, download apps, but you’ll want to do so safely. It’s daunting to think about all of the wolves in sheep’s clothing, but we’ll go over some tips to keep in mind when downloading a new app.

Check the name and icon

Safety starts from the moment you lay eyes on the app. Read the app’s name carefully and check the icon. As stated before, imposter apps use extremely similar names and icons to make you think that you’re downloading something completely different.

When you search for an app, make sure that you read the name so that it’s correct. This also goes for the icon. Make sure that it’s not a slightly altered version of the real app’s icon.

The next thing you want to do is check out the company name. Tap on the link that will take you to the company’s page. Look at the other apps that the company produced. If you see that a Snapchat app is made by a company called “Angry Hamster inc”, then that’s a red flag.

Another thing you’ll want to do is check out the number of downloads. If you see an app posing as Twitter, and it has 200,000 downloads, then something might be up

Read the reviews

Next, take a look at the app’s reviews. People use the reviews to talk about what they love and hate about the app. If there’s something fishy about the app, you can bet to hear about it en masse.

When you’re looking through the reviews, look for the lowest reviews because shady app developers will flood the Play Store with false positive reviews. Dive through the reviews and look for the ones that point to any weirdness in the app. If the app hits you with a ton of ads, causes your phone to slow down, or anything else unwanted, you’ll see it in those one-star and two-star reviews.

Review the permissions that the app needs

Now, most apps on the Play Store need certain permissions in order to function properly. Map apps need access to your location, media player apps need access to your files, gallery apps need access to your photos, etc. That’s just the way of the world. However, you need to be aware of what permissions these apps need and whether or not they should access them.

If you download a simple card game, should it be asking for permission to access your contacts? If you download a task manager, should it be asking to access your location?

When you give an app access to something on your phone, you could be placing sensitive information in the hands of the developers. We’re talking about your email address, home address, pictures of you and your family, your geographic location, and more. This is information that you do not want getting into the wrong hands.

When you’re on an app’s Play Store page, tap on the About this app page and scroll down to the App permissions section. There, it will show you all of the permissions that the app will need. Read them carefully.

Research the app online

This might be the last line of defense, but you can also do a quick internet search on the app. If you’re talking about a smaller app on the market, you most likely won’t find anything on it, but apps that have gained more traction will more than likely turn up results.

There are entire websites dedicated to reviewing and warning people about malicious apps. Read the reviews and see whether you should avoid that app. It seems a bit excessive, but it’s necessary.

An ounce of caution…

When you’re on the Google Play Store, Apple App Store, Amazon App Store, or any other store, you need to be careful about what you download. All it takes is one download to turn your world upside down. With these tips, you should be able to more safely hunt down apps.


[ad_2]
Source link

Samsung opens One UI 5.1.1 beta for Galaxy Z Fold 4 & Tab S8

0
[ad_1]

Samsung has opened the One UI 5.1.1 beta program for the Galaxy Z Fold 4 and Galaxy Tab S8 series. It’s a relatively small update over the current version, One UI 5.1, but it still brings a handful of new features and improvements. The stable One UI 5.1.1 should debut with the new Galaxy foldables and tablets later this month.

Samsung usually launches its latest foldables with a new version of One UI. For example, the Galaxy Z Fold 4 and Galaxy Z Flip 4 debuted with One UI 4.1.1 last year. It would be no different this year. Rumors of the Galaxy Z Fold 5, Galaxy Z Flip 5, and Galaxy Tab S9 series debuting with One UI 5.1.1 have been doing rounds on the internet for a few weeks now. And as the launch draws closer, we now have an official beta program too.

As of this writing, the Android 13-based One UI 5.1.1 beta is only available for Galaxy Z Fold 4 and Galaxy Tab S8 users in Samsung’s home country South Korea (via SamMobile). As usual, interested users can sign up through the Samsung Members app. Once enrolled in the program, they will receive an update over the air, like a regular update. Installing it will introduce One UI 5.1.1 to their device, with plenty of changes.

As expected, One UI 5.1.1 mostly brings foldable or tablet-specific features (tailored to big screens). According to the official changelog, it enables easy switching between the pop-up screen and split screen, preserves the screen mode (split screen or pop-up screen) in the Recents screen, lets users check minimized apps using S Pen gestures, shows more recent apps on the taskbar, supports more apps in the Flex Mode Panel, makes media controls easier, and brings many more changes.

Samsung will push the One UI 5.1.1 to more Galaxy devices

It’s unclear if Samsung plans to expand the One UI 5.1.1 public beta to more regions or add more devices to the beta program. The company does seem to be readying a platform upgrade for the Galaxy Z Flip 4, but it could also be the Android 14-based One UI 6.0 update. Nonetheless, it will surely pick up the new One UI version. In fact, all Samsung foldables and flagship tablets launched since 2020 should get this update.

Other devices, meanwhile, may receive some of the features with the One UI 6.0 update. The big platform update is also expected to enter the beta stage later this month. The Galaxy S23 series should be the first in the pipeline, followed by recent foldables and older flagship models. One UI 6.0 beta should be available more widely, including in India, the UK, the US, and a few other European countries. Stay tuned for more information.


[ad_2]
Source link