Researchers have devised a new attack strategy to exfiltrate sensitive information from target devices without physical access. The attack methodology presents video-based cryptanalysis, where an attacker may extract the cryptographic keys of target devices from the video footage of their power LED indicators.
Extracting Cryptographic Keys Via Power LED Videos
According to a recent study, it is possible for an adversary to extract the cryptographic keys of a target device merely by analyzing video footage of the device with its power LED visible in it.
Specifically, this video-based cryptanalysis technique relies on detecting the change in power LED light’s brightness. As the CPU performs cryptographic computations, the subsequent power consumption impacts the brightness of the LED lights.
While these brightness fluctuations seem harmless, a smart attacker can detect and analyze the changes to retrieve secret keys. An attacker may simply record the video of the target device, focusing on the power LED. Then, zooming in the video to fill the frame with the power LED allows exploiting the rolling shutter to increase the sampling rate of the LED color by three magnitudes. Next, analyzing the video frames in the RGB space empowers the adversary to decipher the RGB values and retrieve the secret keys.
In their study, the researchers demonstrated two side-channel cryptanalytic timing attacks. First, they extracted the 256-bit ECDSA key of the target smart card by recording and analyzing the video footage of the smart card reader power LED, obtained from a distant (16 meters away) security camera. (Dubbed as the “Minerva” attack.)
Next, they demonstrated a similar attack on a Samsung Galaxy S8 by exploiting the power LED of a Logitech Z120 USB speaker connected to the same USB Hub as that of the Galaxy S8. The researchers recorded the speaker’s power LED via an iPhone 13 Pro Max. (Dubbed as the “HertzBleed” attack.)
The researchers from the Ben-Gurion University of the Negev, Israel, have shared the following video to demonstrate the attack. Besides, they have described their study in detail in their research paper.
Suggested Countermeasures
The researchers explained that the vulnerabilities exploited in this attack don’t exist in the power LED or other device hardware. Instead, the flaws exist in the existing cryptographic libraries. They found at least six smartcard readers from five different vendors and Samsung Galaxy S8 vulnerable to the demonstrated attacks.
Although, the researchers advise using the most updated cryptographic libraries to prevent the vulnerabilities. However, they do not rule out the possible zero-day flaws in the latest libraries that may facilitate such attacks.
Therefore, the basic prevention against Hertzbleed and Minerva attacks is having no power LEDs in the device. Nonetheless, such attacks are still possible by detecting the power LED of connected peripherals (as demonstrated in the case of Samsung Galaxy S8).
The guitar is one of the most fascinating musical instruments. Many people around the world dream of learning the art of playing guitar. But it’s no easy task by any means. It is a very complicated instrument. There lies immense dedication and sincerity to learning this art. Thankfully, your Android smartphone can help you with that.
The Google Play Store is full of Android apps that can help you learn to play guitar. Whether you are a complete newbie or know the basics of playing guitar, there are apps for every type of user. We have tested several such apps and compiled a list of the best Android apps for learning guitar.
Go through the article below for detailed information on each app, including a description, Google Play rating and size, cost of in-app purchases, and screenshots or promo videos, as well as a Google Play Store download link.
Best Android apps for learning Guitar 2023
Below is a quick overview of the best Android apps for learning guitar for 2023, including any download and in-app purchase costs.
Download Cost
In-app cost (per item)
Yousician
✕
$5.99 – $179.99
Guitar Tricks
✕
$14.99 – $179.99
Fender Play
✕
$4.99 – $149.99
Ultimate Guitar
✕
$0.99 – $69.99
Justin Guitar
✕
$2.49 – $299.99
Songsterr
✕
$4.99 – $35.00
BandLab
✕
$3.00 – $149.99
GuitarTuna
✕
$0.99 – $49.99
Guitar Tuner Pro
✕
$1.99 – $49.99
Chordify
✕
$6.99 – $41.99
The Metronome
✕
$4.99 – $59.99
Best Android apps for learning Guitar 2023 downloads
Below is a little more information on each app, including a direct link for easy downloading.
All download links go to the app’s Google Play Store listing. Users are always recommended to download apps from Google Play or an authorized app store.
Yousician
Price: Free to download
In-app purchases: $5.99 – $179.99
Size: 89MB
Google Play rating: 4.1 out of 5 stars
Yousician is an award-winning music app and is one of the best Android apps for learning bass guitar as well as standard guitar. It offers a vast library of video lessons with step-by-step guides, making learning more fun. You get to choose between various learning paths. An instructor will explain the steps and you can practice them along with a song. The app listens to you play and gives instant feedback on your rhythmic accuracy and timing.
The app is easy to navigate and use. It is free to download and offers in-app purchases for several subscription plans that unlock unlimited and uninterrupted playtime across all platforms. In addition to guitar, Yousician also offers video tutorials and step-by-step guides on piano and ukelele.
Guitar Tricks is another award-winning Android app for learning guitar. It uses the Core Learning System which is said to be the best guitar-learning method for beginners. It guides you through a series of short videos that focus on you making music from day one. You get to play guitar by learning actual hit songs from the very start, rather than those “boring drills and exercises.”
Once you learn the basics, you can then choose between different styles of the guitar like Rock, Country, Blues, and more. Active since 1998, Guitar Tricks offers over 11,000 guitar lessons with hundreds of song tutorials that include some massive hits from The Beatles, Ed Sheeran, The Rolling Stones, Eagles, and more. This app also offers several high-quality tools like scale finder, chord finder, and others to speed up the learning process.
The best thing about Fender Play is that you can choose your path from the very beginning. The app will ask you a variety of questions about your preferred genre and style to create a structured learning path that teaches guitar using popular songs. It offers bite-sized guitar lessons so the learning process doesn’t feel exhausting.
Fender Play offers a collection of thousands of popular song lessons in a variety of genres, including rock, pop, country, folk, and blues. New songs are added weekly so you always have something new to learn. Tips and tricks from experienced instructors will make the learning process more fun and enjoyable.
This app also offers a guitar tuner for acoustic, electric, bass, and ukulele. There are contextual chord diagrams, guitar tablature, music notes, and an extensive glossary library as well. A Tone Integration feature allows you to sound like your favorite artist using amp presets.
Ultimate Guitar has the world’s largest catalog of guitar, bass, and ukulele chords, tabs, and lyrics. You can play more than 15,000 popular songs in their original sound with Tonebridge Guitar Effects. Additionally, you get chords, tabs, and lyrics for more than 800,000 songs in this app. You can search for any song by type, difficulty, tuning, and rating. There’s also a collection of songs for particular moments from professional guitarists.
This app features a built-in guitar tuner to help you achieve the right sound. You can jam with over 7,000 HQ tabs that include backing tracks and synchronized lyrics. A “simplify” function further lets you simplify difficult songs so you learn the basics of the song easily. You can also transpose songs to the tone that suits you. Ultimate Guitar also offers a left-handed mode for those who need it.
A venture of reputed Australian guitarist Justin Sandercoe, Justin Guitar offers a huge collection of real guitar songs to practice. You get sequential step-by-step tutorials and interactive exercises for hand-picked guitar songs so you are on the right track from the very first day. This app boasts over 1000 hit guitar songs with real band backing tracks to learn guitar.
Over one million people use Justin’s guitar lessons to learn guitar chords, guitar tabs, guitar strumming, capo, fingerpicking, and playing real guitar songs. This app has over 100 sequential instructional guitar video lessons. There’s also a self-assessment system to track your guitar learning progress over time.
Songsterr boasts a collection of more than 800,000 high-quality guitar, bass, and drum tabs and chords. This app has a very clean user interface and is very easy to use, whether you’re picking up a guitar for the first time or are an advanced learner.
All songs on this app are legally sourced and most songs have tabs for each individual instrument (guitar, bass, drums, and vocal). Songsterr has a multi-speed playback feature so you can slow down the track to learn difficult parts. There’s also a solo mode where you’ll only hear the instrument you’re playing, i.e. the guitar. Mute current track, Loop mode, Offline mode, Count in, History, and Favorites are some other notable features of this app.
BandLab is a community of more than 60 million music and guitar lovers from around the world. It is a mobile digital audio workstation that lets you record, edit, and remix your tunes and share your creative effects, beats, loops, and vocals. You can collaborate with other like-minded people and learn new things every day.
This app also lets you discover and stream millions of tracks made by other emerging music lovers. It has over 180 vocal, guitar, and bass effect presets, a 16-track mix editor, and more than 330 virtual MIDI (Musical Instrument Digital Interface) instruments. BandLab is completely free to use and offers over 15,000 royalty-free sounds and beats for sampling.
GuitarTuna is made by the same team behind Yousician (the first app on this list) and is one of the most popular guitar tuning apps for Android. This app uses the same algorithms for audio recognition as Yousician. It works with both electric and acoustic guitars, as well as other string instruments.
The app’s background noise cancellation technology allows you to achieve perfect tuning in loud areas as well. There are over 100 tunings available, including Standard, Drop-D, Other drop tunings, Open tunings, Half step down, 7-string tunings including drop-A, and 12-string. There are also some advanced tools such as Metronome and Chromatic Tuner.
Guitar Tuner Pro is, as the name suggests, another popular guitar tuning app. It offers a chromatic tuner for all your instruments and you can use it anywhere and anytime, without needing any accessories. The app has some useful features such as an easy switch between automatic mode and manual mode, an audio input level indicator, and auto-lock frequency.
Guitar Tuner Pro promises an accuracy range of +/- 0.5 hundredths and a tuning range from Ab1 (51.91 Hz) to D5 (587.32 Hz). Additionally, you also get over 2,600 chords in this app. You can easily search for a chord, visualize it, and start practicing.
With a catalog of over 22 million songs, Chordify offers you chords for any song you want. Simply search for your favorite song, choose your instrument, and start playing. This app offers seamless integration with YouTube and cross-platform support.
You can download the chords from your favorite songs as a MIDI file for easy audio editing. There’s also a capo feature as well as slow-down and loop functions to keep up if you have difficulty with a specific chord. You can also take a printout of the chords if you prefer it that way.
The Metronome by Soundbrenner is an app that can go a long way in helping you master your tempo, be it for guitar or any other instrument such as piano and drums. It offers powerful customization for rock-solid precision. You get a wide range of speed settings, starting from as low as 20 bpm and going all the way up to 400 bpm. It also lets you select the time signature and subdivision of your choice.
Most of the features in this app are free to use. But you can unlock some advanced features such as USB MIDI, Bluetooth MIDI, and Ableton Link with a paid plan. You might not find a better metronome app than this.
Amidst economic hurdles, 2023 has been the year where almost every company has laid off a significant portion of their workflow. Now, in a recent development, Qualcomm has announced significant job cuts as it aims to reduce expenses in light of a persistent slowdown in smartphone sales.
As per the Worker Adjustment and Retraining Notification Act (WARN) paperwork, the company has not only eliminated 415 positions at its San Diego headquarters but also let go of 84 employees at the Bay Area office. Amongst the layoffs, the engineering department was the most affected, with approximately 300 positions eliminated, as indicated by the WARN notice.
Reasoning for the layoffs
While smartphone and modem sales in the US have remained consistent, soft smartphone sales, particularly in China, have had a substantial impact on Qualcomm’s growth this year. During the latest earnings conference call in May, Qualcomm’s CEO, Cristiano Amon, acknowledged the challenges and stated, “We are actively managing operating expenses and will continue to evaluate additional opportunities to drive greater operating efficiencies without losing sight of the automotive and Internet of Things growth opportunities ahead.”
However, it is important to note that this new round of job cuts comes in addition to two smaller layoffs that Qualcomm announced in December and March, resulting in a total of 232 workers being removed from the San Diego workforce.
Venturing into new areas
Although Qualcomm’s revenue has been slowing amidst economic hurdles, the company has been working on expanding its business, particularly in the automotive industry, where they are focusing on in-vehicle connectivity, digital dashboard/infotainment systems, and autonomous driving technologies. Additionally, the company is also ramping up its efforts to supply technologies for various industries, including in-cabin cameras for trucks, drones, retail and warehouse scanners, and robotics.
“We are on track to meet our commitment of a 5% reduction in non-GAAP operating expenses relative to our fiscal ’22 exit rate. This includes a further reduction of spending in handsets to fund diversification investments,” said Akash Palkhiwala, chief financial officer, at a recent earnings call.
You’ve probably heard of this huge music streaming service called Spotify. It is an app that’s likely to be found on some of the best phones on the market and for good reason: it works.
In recent times, Spotify devs seem to be busy with adding extra features to their service, which the core audience of music and/or podcast lovers don’t really care for. But still though, with the company’s recent financial troubles — including owing millions to the EU — we can’t really blame them for trying out ways to come out on top.
But all of this talk about core-audience, music and extra features brings back to memory a feature, which has been sorely lacking on the service, namely: lossless audio. Audiophiles have already been tempted to join Apple Music precisely because of this option, which grants users higher quality music with a more vibrant soundscape.
So, did you notice how I said money? Well, that was because Bloomberg says that Spotify may be planning to charge for this.
Image credit – PhoneArena
So what, you say? Well, yes, but the elephant in the room is as follows: Apple Music is also offering lossless, but at no extra cost. So do you see how this may be a bit weird? After all, Apple’s streaming service isn’t even limited to iPhones and iPads.
And even if you dislike Apple that much, you can still go with Amazon’s service and enjoy the same benefit at no extra cost.
Backtracking even further, metroidvania style: Spotify promised HiFi audio options two years ago. There were rumors that it might end up costing more on top, but most subscribers hoped that those were just that: rumors.
The allegedly incoming tier and its kind of cringy name: “Supremium” will launch in non-US territories first, but will also make its way overseas by the end of 2023. So one obvious question remains: how much will the price bump cost?
Well, we don’t know. We also don’t know whether it’ll bring along with it new, bonus features for users, which may — possibly — make the jump worth it? But as a proud member of the “average lossless enjoyer community”, I can’t name such a theoretical feature off the top of my head.
So, we get it. Despite being the largest music-streaming platform in the world, Spotify is still operating at a loss. They also owe millions of dollars to huge institutions. But one must ask: is a slight price bump in exchange for a feature that already exists elsewhere for free the way out of this conundrum?
Hackers Attack Linux SSH Servers. An attack campaign has been recently uncovered by AhnLab ASEC, where poorly controlled Linux SSH servers are targeted and infiltrated with the Tsunami DDoS Bot.
In addition to Tsunami, the threat actor installed several other types of malware, including:-
ShellBot
XMRig CoinMiner
Log Cleaner
Most attacks on poorly managed Linux SSH servers involve DDoS bots or CoinMiners being installed.
Tsunami DDoS Malware
Tsunami is a variant of Kaiten (aka Ziggy), a DDoS bot, and it is often distributed alongside Mirai and Gafgyt to attack vulnerable IoT devices.
Although they are all DDoS bots, Tsunami is unique because it functions as an IRC bot and communicates with the threat actor through IRC.
Tsunami’s source code is openly accessible, leading to widespread use by many threat actors.
It is primarily utilized for targeting IoT devices in attacks. Furthermore, it is regularly employed to target Linux servers without fail.
Attack Against Linux SSH Servers
SSH service is commonly installed in Linux servers, making them vulnerable to attacks due to poor management.
It also enables remote login and system control for administrators, requiring them to log in with their registered user account.
Using basic login information (username and password) in a Linux system can let a malicious person get into the system by forcefully guessing or using a pre-made list of common passwords.
When poorly managed Linux SSH servers are targeted, attackers search for exposed servers by scanning specific ports.
They then try known account credentials to perform dictionary attacks and gain unauthorized access.
Here below we have mentioned the addresses that were attacked along with their IDs and passwords:-
Once logged in, the attacker runs a command to download and launch different types of malware. One of the installed malware is a Bash script called the “key” file, which acts as a downloader and installs more malware.
Apart from downloading malware, the “key” file also carries out several initial tasks to gain control over infected systems, such as setting up a secret SSH account as a backdoor.
Here below we have mentioned all the malware that is installed via the executed command and downloader Bash script:-
ShellBot is a DDoS bot that is Perl-based which utilizes the IRC protocol for communication, can set up a reverse shell, and supports:-
Tsunami stays active even after restarting by saving itself in “/etc/rc.local” and disguising itself with common system process names.
Here below we have mentioned all the remote control commands that Tsunami supports:-
Shell command execution
Reverse shells
Collecting system information
Updating itself
Downloading additional payloads from an external source
In order to remove any traces of unauthorized access on compromised computers, MIG Logcleaner v2.0 and Shadow Log Cleaner are utilized, thus delaying the prompt detection of the infection by victims
In these attacks, the malware used by the threat actors is an “ELF” file and gives the threat actor elevated privileges.
Mitigations
Here below we have mentioned all the mitigations offered by the security analysts:-
Linux users should use strong passwords or SSH keys to protect against attacks.
Make sure to disable root login via SSH.
Take the necessary steps to restrict access to the server by allowing only a specific range of IP addresses.
Ensure that you alter the default SSH port to a less common number to evade automated bots and infection scripts.
Instagram is letting users download Reels posted by others. The company’s CEO Adam Mosseri announced this feature on his Instagram broadcast channel yesterday. This ability is currently only available on the mobile app for users in the US. A global rollout may follow soon.
Instagram launched Reels inspired by TikTok, which made short-form social videos popular a few years back. However, the latter has always enjoyed an advantage over the former. Not that it had a head start but it allowed users to download videos posted by others and share them on various social platforms. Since the video has its logo and the username of the creator, it drove people from other platforms to TikTok.
The Meta-owned platform is finally catching up to TikTok. According to a screenshot shared by Mosseri, Instagram users can download Reels from the Share menu. The app has added a new “Download” button to the bottom row of the Share menu where you also find buttons to add the Reel to your story or share it on other platforms as a link. The Download button appears between Copy link and Message/SMS buttons.
You can only download Reels posted from public Instagram accounts
Moserri noted that users can only download Reels posted from public accounts. You cannot download Reels shared by private accounts even if you follow them. This respects the privacy setting of those users. Reels they share are only for people who follow them. Allowing downloads defeats the purpose. Meanwhile, public accounts can also block downloads for other Instagram users from their account settings.
Like other platforms, Instagram will also put a watermark on downloaded Reels. Mosseri didn’t specify that in his broadcast but an accompanying screenshot suggests so. It features the company’s logo and the username of the Reel creator. Note that Instagram stopped recommending or promoting videos/Reels with a watermark of TikTok or other platforms in February 2021 to discourage cross-platform sharing of short videos.
It’s unclear when Instagram plans to bring this feature to other markets. As said earlier, its rivals already allow downloading. This includes YouTube as well, which launched Shorts after TikTok surged in popularity globally. Downloaded YouTube Shorts also feature a logo-based watermark. Keep a close eye on the Share menu for Instagram Reels in the coming months. Always make sure to keep the app updated as well, so you don’t miss out on the new features. You can click here to download the latest version of Instagram from the Google Play Store.
These days, most ISPs have some sort of data cap on their service. Some of them keep the data cap so high that you’d almost never hit it. While others keep it pretty low, to charge you overages. Now, the FCC is getting involved.
The Federal Communications Commission chairperson Jessica Rosenworcel is wanting to open a formal Notice of Inquiry into the impact of internet data caps on consumers. This is according to a new FCC document. Which means that it hasn’t yet started the investigation, but it’s only a matter of time.
They are also looking at whether they should “take action” to ensure that the data caps don’t harm competition, or impact access to broadband services.
Rosenworcel wrote in a statement “Internet access is no longer nice-to-have but need-to-have for everyone, everywhere. When we need access to the internet, we aren’t thinking about how much data it takes to complete a task, we just know it needs to get done. It’s time the FCC take a fresh look at how data caps impact consumers and competition.”
The FCC can’t take any action yet
While this all sounds like good news, the FCC can’t actually take any action yet, since it only has four members. There’s two democrats and two republicans on the commission. And the US Senate refused to confirm President Biden’s first nominee, Gigi Sohn. Who then withdrew her name from consideration. The White House then nominated telecom attorney Anna Gomez. It appears that Gomez does have the support of the telecom industry, and a nomination hearing is set for June 22.
You might remember, that during the pandemic, most of the ISPs including Comcast, Spectrum and AT&T, all lifted their data caps. Since we were all at home, all day, everyday, it made sense to lift those data caps. But some, have added them back. If there was no problem during COVID, why is there a problem with data caps now? The answer is most likely, money. But that’s something the FCC will find out during its inquiry.
How much would you pay to see two of the richest men in the world, both big names in the tech industry, take each other on in a “cage match?” This bout would bring the co-founder and CEO of Meta, Mark Zuckerberg, inside a cage with the richest man in the world (depending on the day of the week), CEO of Tesla, and Twitter owner Elon Musk. According to The Verge, after Musk tweeted Zuckerberg saying that he was “up for a cage fight,” the Meta chief executive replied, “send me location.”
This might sound like a publicity stunt, or just two multi-billionaires blowing off steam. But Meta spokesperson Iska Saric told The Verge that the story “speaks for itself” which is a statement indicating that the two executives are serious about getting into the cage together. And Musk responded to Zuckerberg’s “send me location” tweet by tweeting, “Vegas Octagon.” Musk also wrote that he has a signature move. “I have this great move that I call “The Walrus,” he wrote, “where I just lie on top of my opponent & do nothing.”
Elon Musk says he’s willing to take on Mark Zuckerberg in a cage match
Both Musk and Zuckerberg pummeling each other could produce quite the spectacle. Musk, 51, has talked about being in “real hard-core street fights” while he was growing up in South Africa. Zuckerberg has won Jiu-Jitsu tournaments. As for the tale of the tape, Musk stands 5’11” and weighs 180 pounds. Zuckerberg stands 5’7″ which gives Musk a height advantage and probably a reach advantage as well. And at 154 pounds, Mark is giving up 26 pounds to Elon.
Musk not only has the advantage physically, he has the advantage financially with a net worth estimated at $234.4 billion which is more than double Zuckerberg’s estimated net worth of $100 billion. But unless they plan on hitting each other with their wallets, this difference shouldn’t matter.
This might be a great charitable event as there are probably plenty of people willing to pay to watch two billionaires beat the crap out of each other.
The FTC is going head to head with a DNA testing startup which left consumer data unsecured on Amazon buckets.
DNA testing has long been a hot-button issue for security and privacy. Concerns about everything from law enforcement and data retention to job offers and insurance have all been examined at great length. With millions of people signing up to use these services, it was only a matter of time before something went wrong.
Well, the inevitable legal clash is now here and comes courtesy of the Federal Trade Commission which has made a complaint in relation to an alleged failure to protect client privacy. From the FTC release:
The Federal Trade Commission charged that the genetic testing firm 1Health.io left sensitive genetic and health data unsecured, deceived consumers about their ability to get their data deleted, and changed its privacy policy retroactively without adequately notifying and obtaining consent from consumers whose data the company had already collected.
According to the FTC, close to 2,400 reports about consumers and “raw genetic data” of at least 227 people was at risk. This is because despite claims of rock solid security, sensitive data was being stored in publicly accessible Amazon Web Service buckets. According to the complaint, the data in the storage buckets was not encrypted, no monitoring was taking place with regard to who was accessing it, and there were no access restrictions in place either.
In fact, the company was warned “at least” three times across a two year period about the insecure buckets. When a security researcher contacted the company in 2019 regarding the buckets, the issue was finally investigated and the customers whose data was potentially exposed were notified.
Elsewhere, promises related to destroying retained DNA samples with a consumer’s name or other identifying information were not kept. 1Health—previously known as Vitagene—claimed on its website that DNA was not stored, and that consumers could delete their personal information at any time. When this request occurred, the company said, the data would be scrubbed from the company’s servers and all DNA saliva samples would be similarly destroyed once they had been analyzed.
However, from 2016 the company “did not implement a policy to ensure that the lab that analysed the DNA samples had a policy in place to destroy them”, alleges the FTC. In 2020, the company’s privacy policy was changed to retroactively expand the kinds of third parties that it could potentially share consumer’s data with.
Some examples given are supermarket chains and nutrition/supplement manufacturers. There was no need to notify consumers who had previously shared personal data with the company, nor was there a need to obtain their consent to share it, according to the complaint.
In terms of what happens next, the DNA firm must pay $75,000 which the FTC will use for consumer refunds. Additionally, under the proposed order, the company:
Will be prohibited from sharing health data with third parties—including information provided by consumers before and after its 2020 privacy policy change—without obtaining consumers’ affirmative express consent;
Must ensure any company that purchases all or parts of 1Health’s business agrees by contract to adhere to provisions of the order;
Must notify the FTC about incidents of unauthorised disclosure of consumers’ personal health data; and
Must implement a comprehensive information security program addressing the security failures outlined in the complaint.
All of this is in addition to the DNA deletion requirement.
The consent agreement package will be made live soon, at which point the public can comment for 30 days prior to the decision on whether the proposed consent order is made final.
This may be the case which makes people think twice about handing over valuable DNA data to organisations claiming to use top of the line security measures alongside consumer friendly privacy policies. If major alterations can be applied retroactively, you may be at risk. The FTC has this to say:
“Companies that try to change the rules of the game by re-writing their privacy policy are on notice. The FTC Act prohibits companies from unilaterally applying material privacy policy changes to previously collected data.”
Depending on both your location and that of the company you had your data too, the FTC may not be able to do something about it should something go wrong at a later date.
We don’t just write about threats—we remove them
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
A couple of months back, WhatsApp raised suspicions of spying on its users as many people reported noticing the app using their phone’s microphone even when not in use. Turns out an Android bug was erroneously pushing microphone usage alerts on Privacy Dashboard. The Meta-owned platform wasn’t listening to you all the time, thankfully. Affected users can install the latest version of the app to stop this seemingly creepy behavior that isn’t actually a problem.
WhatsApp users have been reporting this untriggered microphone usage problem since at least March this year. Their Android phone’s Privacy Dashboard showed that the app is continuously using the microphone for several minutes in quick succession. That’s despite the app not running in the background (removed from recent apps), let alone being used actively in the foreground. An update for the messaging service fixed the issue for some but others were out of luck.
Needless to say, this was a major privacy concern. After remaining mum for a few weeks, WhatsApp said in early May that it was an Android bug that was incorrectly reporting microphone usage on Privacy Dashboard. The company assured users that the app isn’t listening to them all the time. WhatsApp added that it has asked Google to investigate and remediate the problem. But not everyone may have come across its statement, so it was still a worry for them.
Moreover, it’s always a privacy concern if your Android phone is showing alerts for untriggered microphone or camera usage, regardless of whether or not any app is actually using it. Thankfully, the latest update for WhatsApp stops those erroneous alerts. For added peace of mind, Google recently acknowledged that the issue was indeed caused by an Android bug. So you can rest assured that WhatsApp wasn’t spying on you.
A recent Android bug affecting a limited number of WhatsApp users produced erroneous privacy indicators and notifications in the Android Privacy Dashboard.
Users can now update their WhatsApp app to address this issue.
We thank WhatsApp for their partnership and apologize…
Google didn’t specify whether it has fixed the Android bug
Interestingly, Google didn’t specify whether it has fixed the bug in the Android Privacy Dashboard or worked on a resolution for WhatsApp triggering the bug to produce erroneous microphone usage alerts. All it said is that the bug affected a limited number of WhatsApp users, and the problem doesn’t exist in the latest version of the app. Android expert Mishaal Rahman says there haven’t been any relevant patches in the source code for the May 2023 Google Play System Updates. Hopefully, the Android maker has patched the bug and there won’t be similar issues with WhatsApp or any other app in the future.