Wendy’s is using Google’s AI language model for food orders

0
[ad_1]

Out of all Google’s announcements at Google I/O 2023 this past week, most of them revolved around AI, but chances are you never would have guessed that any of the announcements would include the fast food chain Wendy’s.

During Google I/O, the official Google for Developers Twitter account confirmed that Wendy’s is now using the PaLM AI language model to help people place orders. Based on the tweet, this appears to work from inside the Wendy’s app. So that’s something you’ll need to have installed on your phone.

Once you open the app, you can load the new ‘talk-to-menu’ feature. At this point a friendly voice will greet you and say “welcome to Wendy’s. What would you like today?” You can then speak back to the app and tell it what you want, and the talk-to-menu feature will then add the food to your bag. Proceed to pay for your food, then you can go pick it up.

Now this isn’t too much different than just tapping the menu items you want to add them to your order. But thanks to the inclusion of the PaLM AI language model, it makes the entire transaction more lifelike and conversational. Just like you were sitting at the drive-thru.

Wendy’s may not be the last food app to use the Google AI language model

Wendy’s definitely appears to be the first fast food app to use the AI language model. But it probably won’t be the last.

It comes off as an organic way to play the order and wouldn’t be surprising to see other apps do the same thing. Basically any food app from a restaurant chain could make use of it. And it would make a whole lot of sense for others to start working with the tool.

In fact, Google confirmed on Wednesday that developers can now sign up for access to the PaLM API and Maker Suite. Both of which are tools that will allow for the same kind of implementation Wendy’s is using.


[ad_2]
Source link

TikTok launches #NewMusic hub to connect artists’ new music with their fans

0
[ad_1]
TikTok, the popular social media platform, has launched a new music discovery hub called #NewMusic. The hub aims to connect music lovers with new and emerging artists from around the world. The launch features two popular artists, the Jonas Brothers and Miguel, who will be showcased on the platform.The NewMusic hub provides a dedicated space for music discovery, allowing users to explore new genres, discover emerging artists, and stay up to date with the latest music trends. The platform also provides tools for artists to share their music, connect with fans, and collaborate with other creators.

The Jonas Brothers and Miguel, both Grammy-nominated artists, will be featured on the platform as part of the launch. Their music will be highlighted in playlists, challenges, and other content, providing users with a unique opportunity to discover new music from these talented musicians.

TikTok has become a popular platform for music discovery, with many users sharing their favorite songs and creating viral dance challenges to popular tracks. The NewMusic hub aims to build on this trend by providing a dedicated space for music discovery and curation.
The elephant in the room is, of course, how this will affect (if at all) legislation that is currently being debated in congress about whether TikTok should be allowed to exist in the U.S. with several states getting on board. This isn’t a new thing, as both the Trump and Biden administrations have repeatedly called on ByteDance, the company that owns TikTok, to spin off the U.S. operations of the platform to an American company. In the meantime, many US universities and government agencies have banned TikTok from their devices.

It will be interesting to see if anything changes in regards to a possible TikTok ban in the general U.S. and possibly other countries, but meanwhile TikTok is banking on continuing to add features and launching services such as #NewMusic. Having the support of established artists such as the Jonas Brothers and Miguel, the #NewMusic hub is poised to become a major player in the music discovery space, offering a unique and engaging experience for music lovers everywhere.


[ad_2]
Source link

Millions of Android Phones Comes Pre-Infected with Malware

0
[ad_1]
Android Phones Pre-Infected Malware

Researchers from Trend Micro at Black Hat Asia claim that criminals have pre-infected millions of Android devices with malicious firmware before the devices ever leave their manufacturing.

The manufacturing of the gadgets is outsourced to an original equipment manufacturer (OEM). According to the researchers, this outsourcing makes it possible for someone in the manufacturing process, like a firmware provider, to infect devices as they are shipped out with malicious code.

The team at Trend Micro termed the issue “a growing problem for regular users and enterprises.” Thus use it as a combined warning and reminder.

Viruses started to be introduced as the cost of mobile phone firmware decreased. Distributors of firmware finally found themselves in such fierce competition with one another that they could not demand payment for their goods.

The senior Trend Micro researcher Fyodor Yarochkin responded, “But of course, there’s no free stuff,” He explained that because of this competitive environment, the firmware has started to include undesired features like silent plugins. 

The team searched through several firmware images for malicious software. Over 80 plugins were discovered, though many were not extensively used.

Notably, the most significant plugins had a business model developed around them, were bought and sold illegally, and were openly promoted on websites like Facebook, blogs, and YouTube.

Malware’s Goal Is To Steal Information Or Use It To Gain Money

The malware’s goal is to steal information or to profit from the collection or delivery of information.

The infection turns the devices into proxies used to monetize through advertisements and click fraud, steal and sell SMS messages, hijack social media and online messaging accounts, and steal contacts.

Further, proxy plugins are one form of a plugin that lets the criminal rent out devices for up to five minutes at a time. For instance, people renting the device’s control could learn about keystrokes, location, IP address, and more.

“The user of the proxy will be able to use someone else’s phone for 1200 seconds as an exit node,” said Yarochkin.

Likewise, he said that the team discovered a Facebook cookie plugin employed to gather data from the Facebook app.

The researchers determined from telemetry data that there are at least millions of infected devices worldwide, primarily in Southeast Asia and Eastern Europe. The researchers claimed that the perpetrators themselves had self-reported a figure of 8.9 million.

Although the word “China” appeared numerous times in the presentation, including in an origin narrative tied to the creation of the dodgy firmware, the duo refused to address where the dangers were coming from. 

Yarochkin advised the audience to consider the locations of the majority of the world’s OEMs and draw their conclusions. 

He added that it is challenging to determine precisely how this infection gets into this mobile phone because we are unsure of when it entered the supply chain.

“Big brands like Samsung, like Google, took care of their supply chain security relatively well, but for threat actors, this is still a very lucrative market,” said Yarochkin.

Struggling to Apply The Security Patch in Your System? – 
Try All-in-One Patch Manager Plus


[ad_2]
Source link

Best PS5 Accessories – May 2023

0
[ad_1]

The PS5 launch is just around the corner and with the console purchase, you’re going to want some accessories to enhance your gameplay, so we’ve picked out the best ones to consider whether you need a headset or something to help charge your controllers.

Everyone plays games differently. So what makes a great gaming experience for one may not be the same for another. With that said, the PS5 accessories on this list are not just some of the best ones out there but they’re varied enough that everyone should be able to find something useful to them.

This is a list that will be updated frequently, so as more PS5 accessories come out, we’ll find the best ones and ad them to the list while swapping out others. Keep an eye out for new accessories to make their way in.

Best PS5 Accessories Summary

Below you’ll find a summary table of everything we have picked for our list of must-have accessories. If you’re short on time or just want to grab what you want and go, the summary table below has all of our picks along with the price and buy links.

PS5 Accessory Cost Where To Buy
Sony Pulse 3D Wireless Headset $99 Amazon, B&H, Best Buy
Sony DualSense Controller $49 Amazon, PlayStation, B&H, Best Buy, Target, GameStop, Adorama, ABT
Sony DualSense Charging Station $29.99 Amazon, B&H, Best Buy
Sony HD Camera $59 Amazon, B&H, Best Buy
Sony PS5 Media Remote $29.99 Amazon, B&H, Best Buy
SteelSeries Arctis Nova Pro Wireless $349.99 Amazon, Best Buy, SteelSeries
Western Digital WD_Black SN850 NVMe SSD From $84.30 Amazon, Walmart, Newegg, Western Digital
Master & Dynamic MG20 $449 Amazon, Master & Dynamic
KontrolFreek Performance Thumbsticks $16.99 Amazon, Walmart
Seagate 2TB Game Drive For PS4 From $69.99 Amazon, Various Retailers
Razer Wolverine V2 Pro $249.99 Razer

Best PS5 Accessories List

In the list below you’ll find all of our picks for best PS5 accessories along with short descriptions about each item. You’ll also find buy links to each item in the event you decide to pick something up.

Sony Pulse 3D Wireless Headset

PS5 Pulse 3D Headset

There is without a doubt likely not going to be a better headset for the PS5 than the PULSE 3D wireless headset that comes straight from Sony. At least not right away. In time there may be, but for now this looks like a pretty comfortable headset, and it might be a much better design than Sony’s official PS4 wireless headsets.

You’ll also be assured that this will take advantage of all of the PS5’s 3D audio features to the fullest extent. It supports voice chat with friends and has a battery life of up to 12 hours. While the battery life leaves a little to be desired, it’s easy enough to charge it, and the design matches the console which is a big plus if you like your hardware to match.

You can also connect it up to the PSVR if you have one of those, meaning you don’t have to have a separate headset just for that.

While you may not always want to play with a headset on, there are sure to be times where playing with a headset is a good option, whether to experience better audio in a game or so you don’t wake others up if you play late. Making this one of the best PS5 accessories on this list and a must-have for most PS5 gamers.

Sony DualSense Controller

Sony DualSense Controller for PS5

You obviously can’t play games on the PS5 without the DualSense controller. The PS5 does come with one controller, but if you want to play with a friend or family member, then you’ll need an extra.

If you’re like me, then you simply like to have a backup controller or two with full batteries ready to go. If you ever have one die on you, then you have one with a full charge that you can pick up and connect in seconds. Meanwhile you can toss the other controller onto the charging station or plug it in with a USB-C cable and charge it back up.

This is a nifty setup to have, because you will always have a controller ready to use. The DualSense controller offers things like adaptive triggers, the touch pad of the DualShock 4, new and improved thumbsticks, and a slightly larger design than the DualShock 4 too.

It’s obviously a required accessory for the PS5, but also one of the best accessories for the PS5, since there aren’t really any aftermarket PS5 controllers yet. Though you should expect there to be some before too long.

Sony DualSense Charging Station

Sony DualSense Charging Station

Speaking of controllers and charging them up, the DualSense charging station is the next accessory on our list of best PS5 accessories.

You can charge the controller with a USB-C cable if you wish. But the charging station will keep things wireless and a lot less disorganized. It’ll help keep your desk or entertainment center clutter-free, or at least make for less clutter than usual.

It also has one major benefit over charging with the USB-C cable. The ability to charge two DualSense controllers at once. The PS5 only has one USB-C port. So if you want to charge with a USB-C to USB-C cable, you can only charge one controller at a time.

You could probably charge another DualSense controller with a USB-C to USB-A cable plugged into one of the USB ports on the back. But why deal with all that hassle when the charging station can make things much easier on you. It’s also possible that will charge the controller slower.

Plus, you might already have those USB ports in back taken up. And if you do then you’ll have to rely on unplugging something every time you want to charge a controller.

Sony HD Camera

Sony PS5 HD Camera

Sony’s new HD Camera for the PS5 is just as sleek as the rest of the official accessories and is a perfect accessory to have (also one of the best) if you plan to stream your gameplay.

The PS5 makes it really easy to stream your gameplay to friends and viewers, making for a whole new experience that you can share with others.

The HD Camera offers 1080p capture, letting you snap quick still shots of yourself during really exciting, funny, or haunting moments, or you can use it to broadcast yourself to let others follow along with you as you explore your current game.

It also has a built-in stand so it shouldn’t be too troublesome to set up and keep in place. Sony baked in some background removal tools too. Now not everyone cares to remove the background from the broadcasting. But some do prefer to have only the image of themselves show up in the stream.

This also proves useful as it takes up less of the gameplay that can be seen behind you. Which means viewers can see more of the game UI and that’s never a bad thing.

Sony PS5 Media Remote

Sony PS5 Media Remote

If you had a PS4 and used it to watch streaming TV content, but didn’t get a media remote to control stuff, you probably know the pain of navigating using the DualShock 4 instead.

While it does work, it’s not as enjoyable or as convenient as using a remote. So don’t make the same mistake with the PS5. Enter the PS5 Media Remote that not only has a more natural feeling set of buttons for the purpose of watching TV, but also dedicated buttons for a few of the top streaming services.

This includes a button for Disney+ (so you can easily get caught up on the Mandalorian), Netflix, and YouTube. It also has a Spotify button if you want to pull up some music while you play games.

Of course it also has pause/play buttons, volume up and down buttons, a mute button, a mic button, and buttons for skipping tracks or seeking through your video content. All in all, this is one of the best PS5 accessories to have if you plan to watch video content on the console.

SteelSeries Arctis Nova Pro Wireless

SteelSeries Arctis Nova Pro Wireless 1

Next up is one of the clear contenders for the best overall headset. The SteelSeries Arctis Nova Pro Wireless. As the successor to the Arctis Pro Wireless, the Nova Pro Wireless has a lot to live up to. But it seems that it manages to surpass the older model with some pretty great upgrades.

For starters, it now comes with Active Noise Cancellation and a transparency mode. So you can either choose to block out anything but your game or let a little bit more sound in. The retractable mic also now sits flush with the headset earcup.

SteelSeries also got rid of the ski goggle headband and has made the headset extendable. It even comes with a slightly smaller gaming DAC than the last model. Which still lets you connect to two devices at once. So you can plug it into your PS5 and your PC. Best of all, it comes with two hot-swappable batteries so you can always keep one charged and never have to worry about the headset battery dying on you in the middle of a game.

All that said, the headset is certainly pricey. But you get what you pay for. And you’re paying for quality here. If you want one headset for basically everything, this should do the trick. You can also pick up the wired model for Xbox and save $100. Whether you go with wireless or wired, this is one of the best PS5 gaming headsets out there.

SteelSeries Arctis Nova Pro Wireless

Western Digital WD_Black SN850 NVMe SSD

WD Black SN850 With Heatsink

 

Now that Sony has officially opened up support for expandable storage on the PS5 with the NVMe SSD slot (for beta software users only), you’re going to want an SSD that fits within the recommended/required specifications. There should be more than a few options, and one of the best ones you could get is the WD_Black SN850 from Western Digital.

It comes in a minimum of 500GB and can go up to 2TB. And you can get it without a heatsink or with a heatsink. Without will be cheaper, but Sony recommends that you either have an SSD with one already attached, or that you attach one yourself.

So unless you already have a compatible heatsink you can use, you’re better off just buying one that comes with it. In this case, you can grab the 500GB model on Amazon. If you want the 1TB model though, buy elsewhere. As currently the only available 1TB model with a heatsink comes from a shady reseller charging triple the price.

Thankfully, you can get also get the 1TB model with a heatsink from Western Digital directly.

Master & Dynamic MG20

Master Dynamic MG20 Gaming Headphones PS5

 

Xbox Series X|S has the Beoplay Portal headset, and now PS5 has its own luxury gaming headset in the Master & Dynamic MG20. While pricey at $449, you’re paying a premium for a super high-quality gaming headset that comes with just the right features. And trust us, you’re getting every single damn thing you pay for here.

For starters, Master & Dynamic is using materials like magnesium earcups, lambskin leather earpads, and an Alcantara and canvas-coated headband. Additionally, it comes with a detachable boom mic which comes with a pop filter, and it has a second built-in mic for voice calls or chat in a more casual setting.

It also comes with a low-latency adaptor, a premium carry pouch, and it uses USB-C for charging. There’s 7.1 surround sound onboard as well, and it comes with up to 22 hours of battery life. I could go on. As there are many more features that make this headset worth it. Sure, it’s $50 less than the Disc Edition of the PS5 console itself. But, you’ll be glad you picked it up if you want a more premium experience in your games.

KontrolFreek Performance Thumbsticks

KontrolFreek Galaxy White Thumbstick Grips

There are many reason to consider getting thumbstick grips from KontrolFreek. The biggest reason why you’d want to is so you have better control and accuracy in your games.

But another great reason is because it can help protect the longevity of the grips in their original state. After years and years of use, the grips will eventually break down. And maybe the rubber will even start to peel off after tearing.

You can avoid this with these thumbsticks. KontrolFreek makes a variety of different types, all with unique designs and various colors. These ones in particular will look great with the DualSense and PS5 color scheme.

Also worth noting is that while these say FPS on them, they’re great for more than just FPS games. And, KontrolFreek has confirmed that these will fit the DualSense controller thumbsticks.

Seagate 2TB Game Drive For PS4

Segate Game Drive For PS4 PS5

The Seagate Game Drive 2TB External HDD for PS4 was an easy way for PS4 owners to expand their storage. With it they could store and play games on the console.

Sony has confirmed that this drive is compatible with the PS5 as well. You can only use it to store PS5 games though as the new console won’t play PS5 games from external drives. Meaning you’d have to move games back over when you want to play them.

You can however use it to play all of your PS4 games. Because the PS5 will support the drive for storing and playing PS4 games directly. Which means you can use the PS5 internal storage for PS5 games. Since you can’t actually expand the internal storage yet, this is a great accessory to have.

Razer Wolverine V2 Pro

Razer Wolverine V2 Pro

  • Price: $249.99
  • Where To Buy: Razer

The Razer Wolverine V2 Pro is Razer’s version of a pro controller for the PS5. Unlike other controllers in this space, this isn’t just a modded DualSense controller. It has a slightly different shape and adds things like Razer’s signature Chroma RGB lighting.

It also has the mecha-tactile action buttons, an 8-way microswitch dpad, and the HyperTriggers. The HyperTriggers will be your best friend in games like Call Of Duty: Modern Warfare II. Where speed is crucial to getting off the shot first. To amp things up even further, the controller has four remappable buttons on the back, and two remappable buttons on the top next to the left and right triggers.

Other things like the textured performance grip, and the HyperSpeed wireless tech round this controller to help provide you a big advantage in any game you play.


[ad_2]
Source link

AI-generated Frank Ocean songs got scammers over $10,000 last month

0
[ad_1]

In recent reports, a scammer walked away with over $10,000 by selling AI-generated Frank Ocean songs. This isn’t the first time that the internet is getting such news, as scammers are now blending in with the new era. Artificial intelligence is taking the world by storm, and some bad actors are now finding new ways to fully utilize its potential fraudulently.

Asides from the Grammy-winning singer and songwriter, Frank Ocean, scammers have also tried this trick on other stars. Sometime last month, Drake and The Weekend made the headlines after an AI-generated hit streaming platform. The song was said to be a new piece from the two singers and gathered over 15 million views on its first upload.

Although the song is no longer on most streaming platforms, it brings to light the abuse of artificial intelligence. Now this rather silly bait has caught up with Frank Ocean as a scammer has made a few bucks off the singer’s name. This trick proved to work effectively on fans expecting an album from Frank Ocean anytime soon.

Details on the AI-generated Frank Ocean songs making the rounds on the internet

It is no longer news that artificial intelligence can now compose music. This was one of the takeaways from the Google I/O event, where Bard AI thrilled the audience with AI-generated music for the event. This feature has been available for quite a while, and some scammers are putting it to use by making fake music attributed to real musicians.

The scammer responsible for the AI-generated Frank Ocean songs goes by the username mourningassasin. They spoke with sources explaining in detail how they were able to pull off this stunt. These individuals relied fully on the power of artificial intelligence and the eagerness of fans wanting to hear something new from Frank Ocean.

Mourningassasin simply hired someone familiar with generative AI to make about nine Frank Ocean songs. These songs borrow some elements from “very high-quality vocal snippets” from one of the singer’s songs. The song in question is “Thinkin Bout You” and it formed the tools which the generative AI model worked with.

Once the generative AI model used was done with the tracks, the scammer then proceeded to share them. To do this, mourningassasin took to a leaked-music forum and was able to convince members of the AI-generated song’s authenticity. Members of the forum then contacted the scammer, offering to pay a huge amount of money for the music. To see people paying over $4,000 per song shows that it was hard to spot the difference between a real Frank Ocean song and an AI-generated Frank Ocean song.


[ad_2]
Source link

Elon Musk announces new Twitter CEO, Linda Yaccarino, will start in six weeks

0
[ad_1]

UPDATE: Elon Musk has officially confirmed Linda Yaccarino as his CEO pick.

The original story continues below.
Elon Musk recently announced that a new CEO will be taking over Twitter in six weeks. Although he did not disclose the name of the new CEO, a report from the Washington Post reveals that his pick is likely NBCUniversal ad sales chief Linda Yaccarino, who recently stepped down in her role at the media and entertainment company.
In his announcement via Tweet, Musk expressed his excitement at the new acquisition and explained that he will be transitioning out of the CEO role and into a more of an overseer. This decision follows multiple calls for Musk to step down as CEO and relinquish control to someone less controversial.
Although not specifically named, rumors that Yaccarino would become the next Twitter CEO followed after reports that she was in talks with Elon Musk to fill the position. However, despite the uncertainty surrounding Yaccarino’s appointment, many are hopeful that she will be able to bring a fresh perspective to the company and help Twitter overcome its challenges. Yaccarino is widely respected in the advertising industry, and her experience in media and technology could be valuable assets in leading Twitter into the future.
The appointment of a new CEO could also signal a shift in Twitter’s approach to how it handles advertising opportunities and content management. Additionally, the social media company has faced pressure from users and influential figures to improve its policies and address issues such as harassment and misinformation.

It remains to be seen what changes the new CEO will bring to the company, and whether she will be able to address the platform’s ongoing challenges. However, Musk’s announcement has sparked speculation about who the new CEO could be, since Yaccarino hasn’t been confirmed, and what her priorities will be.

That said, the appointment of a new CEO, whoever she is, could mark a new chapter for Twitter. It will be interesting to see how she navigates the platform’s complex landscape in the coming months and years.

[ad_2]
Source link

WordPress Plugin Flaw Let Attackers Hijack 1m Websites

0
[ad_1]
Elementor plugin Flaw

The widely-used Elementor plugin, “Essential Addons for Elementor,” has been discovered to have a security flaw that enables unauthorized users to gain administrative control, potentially impacting millions of WordPress websites.

PatchStack recently uncovered a critical unauthenticated privilege escalation vulnerability, tracked as CVE-2023-32243, in versions 5.4.0 to 5.7.1 of the Elementor plugin “Essential Addons for Elementor,” enabling potential attackers to reset passwords and gain unauthorized access to administrator accounts.

Elementor

A Flaw in Essential Addons for Elementor

The vulnerability arises from the lack of password reset key validation, allowing direct modification of a user’s password without proper authentication.

This critical vulnerability (CVE-2023-32243) presents severe repercussions such as unauthorized data access, website tampering, malware dissemination, trust loss, and legal compliance issues. Still, a malicious password reset requires knowledge of a targeted system’s username.

To avoid suspicion, the attacker must input random values for ‘page_id’ and ‘widget_id’ while also providing the correct nonce value (‘eael-resetpassword-nonce’) to validate the password reset request and set a new password (‘eael-pass1’ and ‘eael-pass2’) in the exploit process.

PatchStack highlights the availability of the essential-add-ons-element or nonce value on the WordPress site’s front-end page, as it is stored in the $this->localize_objects variable by the load_commnon_asset function. With a valid username set on the ‘rp_login’ parameter, the attacker can effectively gain control of the targeted user’s account by changing their password.

The security firm suggests that the plugin vendor effectively addressed the issue by implementing a function to validate the presence and legitimacy of password reset keys in reset requests, releasing the fix in Essential Addons for Elementor version 5.7.2, urging all users to update to the latest version promptly.

The vendor addressed the vulnerability by implementing a simple patch, utilizing the ‘eael_resetpassword_rp_data_*’ value to verify the password reset process, as the code directly reset a user password without proper verification of the reset key’s authenticity.

Vulnerability

Disclosure timeline

Here below, we have mentioned the complete disclosure timeline:-

  • 08 May, 2023 – We found the vulnerability and contacted the plugin vendor.
  • 11 May, 2023 – Essential Addons for Elementor version 5.7.2 was published to patch the reported issues.
  • 11 May, 2023 – Added the vulnerabilities to the Patchstack vulnerability database.

To ensure the secure execution of certain actions in WordPress, it’s crucial to implement access control and nonce checks and utilize the check_password_reset_key function, especially for login, registration, password reset/recovery, and database interaction.

Struggling to Apply The Security Patch in Your System? – 
Try All-in-One Patch Manager Plus


[ad_2]
Source link

Twitter enables encrypted messaging for verified users

0
[ad_1]

Twitter‘s long-promised encrypted messaging feature is finally here. The initial version of the feature is very much bare-bones, but the company is just getting started. Future updates should address the limitations of DM (direct messages) encryption on Twitter. Elon Musk previously said that the plan is to make encryption strong enough that he couldn’t see your messages even if someone puts a gun to his head.

Twitter rolls out encrypted messaging with several major limitations

For starters, encrypted messaging on Twitter is currently only available for verified users, including Twitter Blue subscribers and accounts affiliated with a verified organization. Both the sender and receiver need to be verified for conversations between them to be encrypted. Additionally, the feature will only work if the recipient follows the sender or has sent a message to the sender previously, or has accepted a DM request from the sender before. Both parties need the latest version of the Twitter app as well or should be using the web client.

On top of limited availability, encryption doesn’t appear to be enabled by default for eligible users either. Twitter says that you’ll have to manually flip the “encrypted messaging” toggle on top of the screen before starting a new conversation. All subsequent messages to eligible recipients should be encrypted, which is indicated by a “lock icon” on the avatar of the recipient.  An option to “start an encrypted message” is also available on the conversation info page. You can access this page by tapping the information icon on the top-right corner of any conversation on Twitter.

Twitter’s DM encryption currently doesn’t work in group chats. It also doesn’t support any media (photos, videos) and attachments. Only text messages, message reactions, and links are encrypted. You cannot send via an encrypted conversation. Moreover, Twitter doesn’t encrypt message metadata either. So details like the recipient and creation time of a message are still not secure. The company does plan to expand encryption to cover group chats and other message details in the future, though.

Encrypted messages don’t sync across multiple devices

Another major limitation is that you cannot continue an encrypted conversation on a new device. If you log in to the same Twitter account on a new device or reinstall the app on the same device, your existing encrypted messages won’t sync with it. You’ll have to start again. You can send encrypted messages from the same account through a total of ten devices. Once you have registered ten devices, encryption won’t work for you on a new device. You cannot remove a registered device to add a new one either.

Twitter also notes that it currently doesn’t offer “protections against man-in-the-middle attacks”. That essentially means it’s still possible for a third person to see encrypted messages between two Twitter users. This includes the company itself. Neither the sender nor receiver would know if someone accessed their messages in the middle. Other limitations include the lack of forward secrecy, key transparency, and message reporting in encrypted conversations. Hopefully, Twitter will patch these limitations sooner than later.


[ad_2]
Source link

The EU issues new rules for Microsoft, Google & Amazon cloud services

0
[ad_1]

Microsoft, Google, and Amazon cloud services have been on the European Union’s radar for quite some time. Now they will be required to collaborate with other EU cloud service providers (CSPs) as they carry out their work. This collaboration might be a move that these big tech firms might not be willing to go into, but they don’t have a choice.

Well, for now, the bill to force these firms into this collaboration is still a draft. It aims to protect the sensitive data of citizens that are domiciled in the European Union and its regions. Because Microsoft, Google, and Amazon are non-European firms, the EU believes that they need to be under supervision.

To do this, the said bill will make these cloud service providers (CSPs) work closely with other European cloud service providers. Well, this might sound a bit bizarre to those hearing it, but it doesn’t even stop there. This article covers the necessary and available information regarding this issue and how it affects both parties.

Microsoft, Google, and Amazon cloud services will operate under the close supervision of the EU

Some sources were able to lay hands on the draft containing this requirement from the European Union. This draft contains all the requirements and restrictions that the European Union will place on foreign cloud service providers. All of this is in a bid to protect the sensitive data of those residing in any member state of the European Union.

What the European Union is saying is that only firms within their geographical boundaries can handle sensitive data. If any cloud service provider from outside the region, like Microsoft, Google, and Amazon wishes to do business, they must undergo certain procedures. Some of which include collaborating with some European cloud service providers.

More to this, the workers from firms like Microsoft, Google, and Amazon cloud services need to reside in the EU’s region. This might give the European Union the ability to keep a watchful eye on how the workers treat sensitive data. Also, all operations and maintenance of the hosting cloud service equipment must come from within the EU’s region.

So what happens if there is a breach in the data held by these cloud service providers? According to the draft, there will be some strict penalties from the cloud service provider. These requirements will put Microsoft, Google, and Amazon in a tight corner, and it will affect how they work.

For now, this bill is still a draft and might not be passed into law. But if it gets passed into law, Microsoft, Google, and Amazon would need to buckle up for a long and bumpy ride. More information on this draft concerning Microsoft, Google, and Amazon cloud services will be made available in the coming months.


[ad_2]
Source link

Risks of Leaving USB Devices & Critical Enterprise Data Unmonitored

0
[ad_1]
Leaving USB Devices

A USB device is a popular choice for storing data and information and, alas, a popular data theft target for hackers. In this article, we’ll cover the challenges for sysadmins and how these are addressed utilizing an often overlooked security strategy, file shadowing, that can safeguard your network.

To err is human, and to top it with a pinch of unpredictability is a perfect recipe for a colossal disaster.

– Sysadmins worldwide  

Delving into the lives of a sysadmin, it’s wise to stay a step ahead in today’s security-laden environment.

Firefighting is not an ideal solution for sysadmins; instead, being strategic and dynamic reduces uncertainties about the best way to counter cyber threats faced by the organization.

Managing myriads of devices in an organization, handling ad-hoc but “priority” tasks, and pulling all-nighters to handle security concerns are typical tasks for a sysadmin.

The tedious aspects of the job make it hard for anyone to remain continually upbeat. While that is the case with most professions, the risks in the sysadmin’s role come with a price, equivalent to a goalie’s momentary lapse that leads to an opponent’s advantage.

An oversight or error can cost your organization dearly!

Now, cast your eyes on the quote again. Associating it with a dedicated sysadmin shows how sysadmins juggle multiple tricky tasks. From an organization’s standpoint on security, the sysadmin roles allow no room for error.

Sysadmins design the organization’s network infrastructure to manage how a USB device is utilized. While controlling USB devices is pivotal, the information accessed by the devices is often sporadically managed.

It is crucial to ensure the USB devices are granted the appropriate permissions before they are provided access to the organization’s sensitive data. 

In a nutshell, we’ve defined the role of USB devices and discussed a key repercussion, file loss, resulting from improper device management.

Blocking all device access isn’t practical, as productivity would take a wild hit. If the tech-savvy world has taught us anything, it is to trust no one on the security front. So, what are we left with?

The silver bullet to this issue, file shadowing, creates a copy of the file that is deemed vital, thus protecting the file when a USB device tries to access it.

Whether creating a file copy in a network path of your convenience, excluding a file type/extension of your choice, or specifying the file size, ManageEngine Device Control Plus is your one-stop solution.

How is file shadowing different from a backup?

On the surface, file shadowing might seem more like the concept of a backup, and while it walks a similar lane, it is quite the contrary.

File shadowing helps track changes to the file, while a backup keeps a duplicated copy of the original file.

Device Control Plus provides a practical approach for framing your organization’s file shadowing policy.

This easy-to-utilize software solution breaks the concept into simpler parts for maximum customization, saving sysadmins considerable time and effort.

File shadowing in Device Control Plus can be configured in five steps

Nominate a USB device of your choice

Any USB device is eligible for file shadowing. The policy can be applied to particular devices so that only the file activities on those devices will be replicated.

Control the nature of the file to be shadowed.

The limiter for file size and file types or extensions for exclusion can be set for file shadowing. This narrowed approach ensures that only specific file types of the specified size are replicated instead of every file. 

Design the safe house for your critical files

The path in which the shadowed file resides can be configured for a user role or a group of user roles. While the user knows the file’s disk space, having a dedicated location for storing the copies is vital.

The path that is configured for a device will contain the copied file. The domain credentials to access the remote share where the shadowed data is stored can also be configured for added security.

Utilize Custom Groups to streamline policy enforcement

With a device control policy in place, applying it to a group rather than individual users makes sense. Custom Group groups users/user roles and endpoints relevant to the device control policy.

Voila! The report

Extensive audits will be generated in real-time as soon as the file shadowing policies are applied. The logs include details such as the devices, endpoints, and users involved in the operation, the file name, and the time it was shadowed. The logs are readily available and are used to analyze file shadow actions performed across the organization.

The kryptonite of file shadowing

File shadowing requires disk space and considerable bandwidth to store the shadowed data in a remote share folder. It uses file extension and size filters to ensure the shadowing is relevant.

However, files can be tracked with file tracing, regardless of the file size and extensions. However, with file tracing, regardless of the file size and extensions, files can be tracked.

Benefits 

  • Be it an accidental or intentional data loss, the file shadowing/data mirroring feature ensures that the shared folder can still be accessed and utilized, provided the data is transferred beforehand. The missing files are cross-referenced from the shared folder.
  • After extracting information from a system, any file that gets corrupted or goes missing while being transported in the USB device can be swiftly retrieved from the network share folder and restored to a location where authorized employees can regain access.
  • Critical and confidential files, such as passwords, financial records, or protected personal information, require a lot of effort and time by sysadmins when a user tries to access them.
  • Instead of frequently granting and revoking access as the file resides in a vault, with Device Control Plus, users can be granted access to the replicated data stored in network file archive remote share, a security benefit.

While this article advocates file shadowing, other features are designed to optimize peripheral device management.

With Device Control Plus, you can enforce a Zero Trust policy and only let the devices you choose have their way around the network by creating a list utilizing role-based access control.

This is a method for defining user rules based on their roles, or in other words, a hierarchical approach to manage the logs, and file tracing reports, to name a few.

Feel free to explore the features of Device Control Plus.

Struggling to Apply The Security Patch in Your System? – 
Try All-in-One Patch Manager Plus


[ad_2]
Source link