Monday saw Apple chalk up a big legal victory against Fortnite developer Epic Games. As you probably recall, back in 2020 Apple removed Fortnite from the App Store after Epic Games included a link to its own in-app payment platform in the game. The link bypassed Apple’s in-app payment platform which takes up to 30% of in-app purchases. Epic took Apple to court seeking to force Apple to allow Epic’s app store to be available on the iPhone and to force Apple to make changes to its in-app payment platform policies.
The Ninth Circuit Court of Appeals upholds most of the rulings made by the lower court in Apple’s favor
Bloomberg reported on Monday that the U.S. Ninth Circuit Court of Appeals affirmed most of the rulings made by Judge Yvonne Gonzalez Rogers thus rejecting the majority of Epic’s claims. The appeals court upheld Judge Rogers’ rulings in favor of Epic regarding claims made regarding California state law.
The link to Epic’s in-app payment platform that led to the removal of Fortnite from the App Store
While one judge felt that the case should have been sent back to Judge Rogers with some new guidance, the majority opinion agreed with the argument made by Apple that it needs to closely watch the apps that are installed on its devices like the iPhone and iPad to prevent users from downloading malware, spyware, adware, and other potentially dangerous software. The panel wrote, “Apple makes clear that by improving security and privacy features, it is tapping into consumer demand and differentiating its products from those of its competitors — goals that are plainly procompetitive rationales.”
The panel did agree with the lower court ruling that Epic was “injured” by Apple’s resistance to have developers lead users to third-party payment platforms. It also told Judge Rogers to reexamine her ruling that Epic didn’t owe Apple for attorney fees.
Apple has already made a big change to App Store policies by allowing “Reader apps,” which include apps and subscription services such as digital newspapers and magazines, books, and audio and video streaming, to direct users to third-party payment platforms. Games are not covered by this policy. While Fortnite remains out of the App Store, Epic CEO Tim Sweeney has suggested that the title could return to iOS this year.
The EU’s Digital Markets App is forcing Apple to allow sideloading of apps in its 27 member countries
Apple issued a statement via email that said, “The App Store continues to promote competition, drive innovation, and expand opportunity, and we’re proud of its profound contributions to both users and developers around the world. We respectfully disagree with the court’s ruling on the one remaining claim under state law and are considering further review.” The company also characterized the ruling as a “resounding victory” noting that it had nine out of 10 claims decided in its favor.
Epic’s Sweeney tweeted, “Fortunately, the court’s positive decision rejecting Apple’s anti-steering provisions frees iOS developers to send consumers to the web to do business with them directly there. We’re working on next steps.”
Apple is being forced to make changes to its “walled garden” policies in Europe where the EU has passed the Digital Markets Act (DMA). The DMA is forcing Apple to allow third-party apps to be installed on the iPhone via sideloading with the release of iOS 17. This past week, Bloomberg’s Mark Gurman said that Apple will only allow sideloading in the 27 member countries that make up the EU. In the U.S., sideloading will remain blocked by Apple.
The parent firm behind the popular ProtonVPN and ProtonMail has now come up with another privacy venture. As announced recently, Proton has now launched a dedicated password manager – the Proton Pass with end-to-end encryption.
Proton Pass Password Manager Arrives
As announced via a recent blog post, Proton (formerly ProtonMail) has now introduced a secure password manager – Proton Pass – for its subscribers.
Elaborating on the details, Proton stated that it decided to take this step after receiving numerous requests from its users.
The post explained that the firm had previously partnered with SimpleLogin to provide users with “Hide-my-email” aliases. And now, the same team has worked on to develop the password manager with enhanced security and privacy features.
Specifically, the core strength of Proton Pass lies in its default end-to-end encryption (E2EE) implementation. Though, numerous other password managers also apply E2EE, Proton Pass looks different in that it encrypts all web fields unlike other that only encrypt the password field. That includes encrypting usernames, web addresses and other details. With such encryption, Proton Pass strives to prevent user profiling from web tracking elements.
Moreover, it also supports two-factor authentication by default and even allows 2FA autofill. In this way, it even aims to ditch potential keylogging attempts.
Regarding the encryption technology, the tool implements bcrypt password hashing and a hardened Secure Remote Password (SRP) for authentication and preventing MiTM attacks.
To Be Available For The Public In A Year
At the time of announcement, Proton Pass is available in beta for Lifetime and Visionary users. Also, the firm will typically invite users to test the tool, planning to roll out the invitation in a few days. Nonetheless, the firm has pledged to release the tool for the public later this year.
Currently, Proton Pass supports iOS, Android, and desktop systems with Brave and Google Chrome browsers. Mozilla Firefox users need to wait for some time as the service couldn’t approve the add-on before the official release.
Malwarebytes’ researchers have discovered a malvertising scheme that uses adult lures for clickjacking purposes.
Malwarebytes’ researchers have found a malvertising scheme that leads to clickjacking.
Clickjacking is a form of ad fraud which is also referred to as click fraud or click spam. It is a practice performed by certain dubious advertising networks, where they sometimes use automated programs—from simple to sophisticated bots and botnets—to interact with advertisements online. But it can also be done by tricking legitimate users into clicking ads, visiting pages, and (in some cases) creating fake form submissions.
Ad fraud means that the advertiser pays the referrer or the advertising network to show their ads to interested visitors. In reality, the criminal doesn’t care who actually clicks or whether they are interested, as long as the money keeps coming their way.
The campaign
To start things up, visitors are lured to several fake blogs about topics they might find interesting.
This is how the actual blog looks
The original blog however is hidden by an overlay showing blurred explicit content and a button asking the visitor to confirm they are 18+ and asking if they want to enter the website. We have seen a few different overlays on the same website, so there could some fingerprinting involved. Below are a few examples:
Whichever one the visitor sees, clicking the button does nothing other than registering a click on an advertisement. However, that does help the cybercriminals set up this clickjacking scheme.
Above is an example of an advertisement shown to a Dutch IP and, below, a screenshot of the Google ad that was presented to a Canadian IP address.
This is the link behind the version you can see here:
Dragging the button allows the visitor to see where the click will take them
The code behind these attacks is obfuscated.
In this case there is no imminent danger for the website visitor. It is just wasted money for the advertiser. So, if you run into one of these, don’t make them any richer by clicking that 18+ button.
If you are spending money on advertising it is worth looking at what you get for the money your are spending. According to research carried out by BusinessOfApps the total cost of ad fraud in 2022 was around $81 billion, and is predicted to increase to $100 billion by 2023.
If the spending and return on investment are non-transparent, advertisers can also look at solutions that can significantly reduce their advertising costs. You can try some for free for up to 5,000 paid clicks per month on the Google Ads platform.
Malwarebytes removes all remnants of ransomware and prevents you from getting reinfected. Want to learn more about how we can help protect your business? Get a free trial below.
Coming with the Android 13 QPR3 Beta 3 upgrade is a new design for the 3-button navigation system. This change is more noticeable when the user activates the home button assistant activation system. Beta testers have taken note of this feature and brought the changes it features to the spotlight.
The size of the keys in the 3-navigation system with this new Beta testing upgrade sees some design changes. Also, its animation responses when users activate the Google Assistant feature gets a facelift. Users also note that these changes were not available in the previous Beta upgrade version.
In this article, we will take a look at these changes that might make their way to the update’s stable release. According to reliable sources, the stable release should be available by June. But before this release, it’s important to note what features will roll out to the public with this update.
The 3-button navigation gets some design improvements with the Android 13 QPR3 Beta 3 upgrade
If you use 3-button navigation on your Android 13 device, prepare yourself to welcome a new design. This design change or improvement affects all three buttons, but one stands out. The minimize, home, and back buttons are now slightly larger with the Android 13 QPR3 Beta 3 upgrade.
The increase in the size of the three navigation buttons is not so conspicuous. Also, the back key, shaped as a triangle, now has more rounded edges which will make it a bit more appealing to the eyes. But the home button (the circle shape) comes with the most noticeable change among all three keys.
With the QPR3 Beta 3 upgrade, the home button drops off the surrounding ring. Now the home button is just a relatively large circle and still packs its Google Assistant shortcut feature. Holding down this button will pull up the Google Assistant like it already does with the existing Android 13 stable version.
Beta testers note that the home button on the Android 13 QPR3 Beta 3 version gets larger when the assistant feature is disabled. But with the feature turned on from the user’s settings, the home button takes an average size. The pop-up when a user pulls up the Google Assistant stays unchanged.
This change to the 3-button navigation with the Android 13 QPR3 Beta 3 upgrade might also carry into Android 14. But before that, it will first become available for Android 13 devices in a few months. Once the stable update is ready, users will get it via a system update with many features.
According to a new report, Apple won’t allow sideloading apps everywhere, only in markets it’s forced to. In other words, sideloading apps may arrive with iOS 17, but only in Europe, not the US, or any other markets.
Apple may allow sideloading apps, but only in markets in which it’s forced to do so
Why is that? Well, the EU laws are kind of forcing Apple’s hand when it comes to features. The EU law forced Apple to include a Type-C port on the iPhone 15 series. Apple was not planning to do so, but the EU forced the change.
Now, Apple won’t manufacture iPhone 15 units with different ports, of course, so all iPhone 15 units will include Type-C ports, regardless of where they’re being sold. Sideloading apps may be a different story.
This info was shared by Mark Gurman, from Bloomberg, who shared a comment during a MacRumors podcast. Apple seemingly plans to open iPhone up to third-party stores and sideloading, to comply with the EU’s Digital Markets Act.
Only the EU countries will get this change, you still won’t be able to sideload in the US
This will happen only in countries where the DMA is applicable, so only in the EU countries. Gurman suggested that Apple may downplay this feature so much, that it won’t even announce it at the upcoming WWDC.
“They’re not gonna do anything extraneous that would further hurt their grip on the App Store”, said Gurman. He did claim that this was a “major undertaking” on Apple’s part, however. He also added that “there’ll be some sort of review process, even though these apps would be installed outside the App Store”.
So, iOS 17 in Europe and the rest of the world may differentiate a bit, due to this sideloading feature. It remains to be seen how exactly will Apple implement this. WWDC is set to take place in early June, and we’ll see if Apple will mention the change at all. It’s possible it’s going to ignore it altogether, as Gurman suggested.
Google Authenticator, the widely used two-factor authentication app, now allows users to sync their one-time codes in the cloud. This update aims to make it easier for users to switch between devices without losing their authentication data.
The update was announced today via the Google Security Blog and it affects both the iOS and Android app. Previously, users had to manually transfer their codes from one device to another or disable and re-enable two-factor authentication when switching devices. This process could be cumbersome, especially for users who frequently switch between devices, replace their phones, or had their device stolen.
One major piece of feedback we’ve heard from users over the years was the complexity in dealing with lost or stolen devices that had Google Authenticator installed. Since one time codes in Authenticator were only stored on a single device, a loss of that device meant that users lost their ability to sign in to any service on which they’d set up 2FA using Authenticator.
The new cloud sync feature will automatically store users’ authentication data in the cloud, allowing them to access it from any device with the Google Authenticator app installed. To enable Google Account synchronization in Google Authenticator, users will simply need to open the app, tap the menu icon, select “Settings” and tap “Backup to Google Account,” then follow the on-screen instructions to sign in to their Google Account and enable backup.Once backup is enabled, one-time codes will be stored securely in the users’ Google Account, so if their device is lost or stolen, they can be restored simply by signing in on a new device and requesting to “Restore codes.”
Google explains that with this update the company is making one-time codes more resilient by securely keeping them in users’ Google Accounts and therefore improving user lockout protection and allowing services to rely on users maintaining access, which boosts convenience and security.
Google has long promoted a number of methods for safe authentication across the web in addition to one-time codes from Authenticator, such as Google Password Manager and “Sign in with Google” options across the web. Additionally, Google has been collaborating with the FIDO Alliance to facilitate the move to using passkeys, instead of passwords, which will provide users with even more practical and secure authentication options.
An Israeli cybersecurity company, Astrix’s Security Research Group, discovered a 0-day vulnerability in Google’s Cloud Platform (GCP) dubbed Ghosttoken on June 19, 2022, which impacts all Google users.
The “GhostToken” vulnerability could enable threat actors to make a malicious application “invisible and unremovable,” ultimately rendering the victim’s Google account permanently infected with a trojan app.
On April 7, 2023, Google formally issued a patch for the GhostToken vulnerability. The malicious apps could be made invisible by attackers after being authorized and linked to an OAuth token that grants them access to the Google account.
Attackers can hide their malicious application from the victim’s Google account application management page by using the GhostToken vulnerability.
The exploit makes the malicious app unremovable from the Google account. So, the attacker holds a ‘ghost’ token to the victim’s account.
“Since this is the only place Google users can see their applications and revoke their access, the exploit makes the malicious app unremovable from the Google account,” Astrix Security researchers said.
“Since the application is entirely hidden from the victim’s view, they are prevented from even knowing their account is at risk in the first place, and even if they do suspect it – they can’t do anything but create a brand new Google account.”
How is a GhostToken utilized?
Researchers say attackers might be able to read the victim’s private Gmail messages, access their files on Google Drive and Google Photos, view upcoming events on their Google calendar, find them using Google Maps, and give access to the victim’s Google Cloud Platform services depending on the permissions victims grant the malicious app.
In the worst-case scenario, attackers may be able to remove files from Google Drive, send emails from the victim’s Gmail account to undertake social engineering attacks, steal sensitive data from Google Calendar, Photos, or Docs, and more.
Particularly, attackers merely needed to delete the associated GCP project to put the malicious applications authorized by the victims into a “pending deletion” state to conceal them.
However, following the project’s restoration, they would be given a refresh token to retrieve a fresh access token to access the victims’ data.
These actions could be performed endlessly, enabling the attackers to delete and restore the GCP project each time they required access to the victim’s data to conceal the malicious app.
GhostToken Attack Flow
With the help of Google’s patch, GCP OAuth applications in ‘pending deletion’ states can now be removed by users from the ‘Apps with access to your account’ page, thereby preventing account takeover attempts.
Astrix advises Google users to check all authorized third-party apps on their “account’s app management page” to ensure they only have the permissions required to function.
“In today’s world of commonplace attacks,complicated threatt scenarios, and exponentially increased attack surfaces, routine security checks that clear out any unnecessary, unused, or over-privileged 3rd-party access must also look for GhostToken-like vulnerabilities”, researchers say.
This week on Lock and Code, we speak with Courtney Brown about a mental health nonprofit’s use of AI to speak to people suffering emotional distress.
In January, a mental health nonprofit admitted that it had used Artificial Intelligence to help talk to people in distress.
Prompted first by a user’s longing for personal improvement—and the difficulties involved in that journey—the AI tool generated a reply, which, with human intervention, could be sent verbatim in a chat box, or edited and fine-tuned to better fit the situation. The AI said:
“I hear you. You’re trying to become a better person and it’s not easy. It’s hard to make changes in our lives, especially when we’re trying to do it alone. But you’re not alone. There are people here who care about you and want to help you. I’m proud of you for making the decision to try to improve your life. It takes a lot of courage and strength. I send you love and support as you go through this journey.”
This was experimental work from Koko, a mental health nonprofit that integrated the GPT-3 large language model into its product for a short period of time that is now over. In a video demonstration posted on Twitter earlier this year, Koko co-founder Rob Morris revealed that the nonprofit had used AI to provide “mental health support to about 4,000 people” across “about 30,000 messages.” Though Koko pulled GPT-3 from its system after a reportedly short period of time, Morris said on Twitter that there are several questions left from the experience.
“The implications here are poorly understood,” Morris said. “Would people eventually seek emotional support from machines, rather than friends and family?”
Today, on the Lock and Code podcast with host David Ruiz, we speak with Courtney Brown, a social services administrator with a history in research and suicidology, to dig into the ethics, feasibility, and potential consequences of relying increasingly on AI tools to help people in distress. For Brown, the immediate implications draw up several concerns.
“It disturbed me to see AI using ‘I care about you,’ or ‘I’m concerned,’ or ‘I’m proud of you.’ That made me feel sick to my stomach. And I think it was partially because these are the things that I say, and it’s partially because I think that they’re going to lose power as a form of connecting to another human.”
But, importantly, Brown is not the only voice in today’s podcast with experience in crisis support. For six years and across 1,000 hours, Ruiz volunteered on his local suicide prevention hotline. He, too, has a background to share.
Tune in today as Ruiz and Brown explore the boundaries for deploying AI on people suffering from emotional distress, whether the “support” offered by any AI will be as helpful and genuine as that of a human, and, importantly, whether they are simply afraid of having AI encroach on the most human experiences.
Samsung has released the April 2023 Android security patch for the Galaxy S20 FE, Galaxy A31, and Galaxy A32 5G. The latest SMR (Security Maintenance Release) brings fixes for more than 70 vulnerabilities. The original FE model is also picking up a couple of new features with this update.
The April SMR for the Galaxy S20 FE is currently available for the 5G model in Europe. The update is rolling out with the firmware build number G781BXXU5HWCH. Samsung should expand the rollout to more markets, including the US, in the coming days. The new security patch should soon reach the 4G/LTE version of the Galaxy S20 FE as well. This device wasn’t sold in the US.
The Galaxy A31 also didn’t arrive in the US. But Samsung sold it in most other markets. The 2020 mid-range smartphone is not getting the April SMR. According to SamMobile, which first reported this rollout, the update is available for users in a handful of Latin American countries, including Bolivia, Peru, Colombia, Panama, Guatemala, and Mexico. It should reach other markets in the coming days. The new firmware version for this device is A315GDXS2DWD1.
The latest update for the Galaxy A32 5G, meanwhile, is already available a little wider. The same source confirms availability in a host of countries in Latin America, Europe, and Asia. The updated firmware build number is A326BXXS5CWD5. Samsung did sell this phone in the US but it isn’t getting the April SMR yet. The 4G version of the Galaxy A32 is also still missing the latest security patch. The company should cover those all with the April update soon.
Galaxy S20 FE is getting Image Clipper and more with the April update
The April security update for Galaxy devices contains fixes for more than 70 vulnerabilities. These include at least five critical fixes. All three of the aforementioned Galaxy smartphones are receiving these security fixes. Additionally, the Galaxy S20 FE is picking up some goodies with the April update.
Firstly, Samsung is pushing the Image Clipper feature to the original FE model. Introduced with the Galaxy S23 series, this feature lets you instantly crop out subjects from images when viewing in Samsung’s Gallery app. The company has already rolled out this feature to the Galaxy S22 series and a few other models. The April update also brings an option to add the Galaxy Buds widget to the lock screen on supported Galaxy devices. You can add the widget from Settings > Lock screen > Widgets.
If you’re in the market for a new speaker, or two, you should definitely check out Sonos. The company has recently added quite a few new speakers to their lineup, making it easier to get into the ecosystem than ever before. So today, we’re going to go over all of the Sonos speakers and which ones are the best to buy. But first, let’s talk about why you should invest in the Sonos ecosystem.
The Sonos Ecosystem
The big reason why you should jump into the Sonos ecosystem is because, of multi-room audio. Now sure, Amazon Alexa, Google Assistant and even Apple with Siri and Homekit, offer this functionality. But Sonos does it the best. And that’s because it only uses its own speakers, so you won’t have to settle for terrible sounding speakers.
Additionally, if you want to make a great surround sound system, that’s wireless, Sonos is the way. You could get a soundbar from Sonos, along with a couple of other speakers and a sub, providing you with an incredible experience, and no wires (other than plugging them in), needed. It’s also all done with the app. Which allows you to adjust the bass and treble for each speaker.
Finally, on Sonos’ “smart” speakers, they do offer up both Amazon Alexa and Google Assistant. Now, you can’t use both at the same time, but you can switch from one to the other at any time.
Best Sonos Speakers you can buy
Here are the best Sonos speakers that you can buy today.
Best “first” Sonos speaker
Sonos Era 100
The Sonos Era 100 is one of the newer speakers from Sonos, and offers up “next-gen acoustics” as well as new levels of connectivity. With the Era 100, you can transform any room in your home, and of course connect it to other Sonos speakers in your home. It includes WiFi, Bluetooth and a 3.5mm line in – something even your smartphone doesn’t have.
Sonos does offer the Era 100 and all other speakers in two colors: black and white.
This is a collaboration with Ikea and Sonos, and unfortunately, it is only available at Ikea. But this is a bookshelf speaker, with Sonos built-in. Giving you a really great looking bookshelf speaker, and also some great sounding audio here. This is the newer second generation model, with slightly upgraded internals.
The Sonos Five is the best all-around speaker you can buy from Sonos right now. This is a great speaker to put in your living room, office, or even in the kitchen to listen to music. It has two precisely-angled side tweeters which create a great rich and stereo sound for you. You can also pair this with another Sonos Five, for an even better stereo experience. Or you could pair them with a soundbar for a great surround sound system.
The Sonos Roam comes in two flavors, the Roam and the Roam SL. The only real difference is that the Roam SL does not have the microphone included to use with Amazon Alexa and Google Assistant. And because of that, it does drop in price a bit.
The Roam is a really great speaker, and I absolutely love it. It’s small and compact, and because it is angled, it’s easy to fill and entire room with sound, without any issues. It also comes in black and white, and charges via USB-C.
The Sonos Beam is actually one of my favorite soundbars, and I’ve been using it and the now the new Gen 2 for quite a few years. This is a smaller soundbar from Sonos. It’s really meant for those TVs that are around 55-inches or smaller, but it can work just fine with larger ones.
With this new second-generation Beam, you also get Dolby Atmos included. Which makes this an incredible value, especially for it being a Sonos soundbar.
If you want the very best sound experience in your home, then the Sonos Arc is the way to go. Obviously, you’re paying a pretty penny here, but it’s worth the price. This does include Dolby Atmos, as well as support for Google Assistant and Amazon Alexa.
This one will work with your existing TV, and you won’t need a new remote to control it, thanks to eARC. So plug this into your HDMI eARC port, and you can control it with your TVs remote.
One of the first products that Sonos ever came out with was the Sub. And now we’re on Gen 3 of the Sub. It hasn’t changed a whole lot, in the looks department. But it has continued to include better bass, and better sound as a whole. Now this one is quite pricey, luckily there is a cheaper one which we’ll get to next.
This can be paired with any of the soundbars above, as well as other speakers on this list. Making for a really great surround sound experience.
The Sonos Sub Mini is a really great alternative to the $800 Sub that’s listed above. Sure it doesn’t give you as much bass as the regular Sub, but it is really good. I actually use this in my home with the Sonos Beam (Gen 2) and it works really well. With enough bass to make my home shake when needed.
Sonos uses advanced processing here which can further enhance the acoustics and reproduce the full-tuned low frequencies expected from a larger subwoofer.
The Symfonisk Floor Lamp is a really interesting way to get a Sonos speaker into your home. This speaker is about the same as the other Symfonisk Sonos speakers, meaning that it sounds about the same as a Sonos One or the Roam SL. So it’s not super powerful, but it is a nice way to sneak in a surround sound setup into your home, using lamps. Since these will still sync with your existing Sonos speakers and soundbars.