Michael Bennet — Colorado senator, also a democrat and a member of Senate Intelligence Committee — wrote a letter to Google and Apple this Thursday, pleading for them to ban TikTok due to concerns over national security.
The New York Times reports that the letter has been addressed to the chief executives of the companies — so, Tim Cook for Apple and Sundar Pichai for Google — and in it, Michael Bennet basically states that it’s not okay for the Chinese government to have access to this much data or the ability to curate media for a third of US population.
The senator elaborated further, stating that he sees the current situation as irresponsible. From his point of view, this is an opportunity for Big Tech to step in on the debate and show where they stand.
Cats are always cute, but you can stumble upon much darker things on TikTok too.
TikTok spokesperson Brooke Oberwetter commented on Michael Bennet’s letter, expressing concern over its subjectivity and how it may be misleading. She stated that the report “totally ignored” the company’s plan — called Project Texas — to assure all of its users in data transparency and security integrity.
TikTok maintains the stance that data is in no way, shape or form, being transferred to the Chinese government. The company submitted a plan back in August, detailing how it intends to prevent China’s access to US data. The social platform is even willing to let the US government oversee its operations in an attempt to prove its claim.
From a political stance, this is yet another sign of a democrat joining in on a typically republican-led battle. This entire ordeal harkens back to 2020 and Trump’s own efforts to get TikTok banned, along with WeChat — another popular Chinese app.
Google and Apple have yet to respond to the senator’s letter, but they may have to. After all, this ordeal marks a point at which over 24 states have chimed in to support the movement to have TikTok banned
Without going too much into detail, the entire thing revolves around a Chinese law loophole, which basically allows the Chinese government to get their hands on data in secret. With the discussion being on the rise, it will be interesting to see if the company manages to prove that it has prevention plans for such a scenario.
Xiaomi Smart Band 7 Pro is a big refresh on what is arguably the best-selling wearable fitness tracker series in the world. Xiaomi’s smart bands are synonymous with fitness trackers for quite some time now. And for good reason, they have the right features, bright colorful displays, and are priced extremely well. Oh and Xiaomi’s Mi Fitness app is as good as things can get in the Android world. Let’s dive into the review to see if the new features on the Smart Band 7 Pro are worthy of your hard-earned cash.
Hardware is a serious upgrade from the previous versions
As soon as you get the Smart Band 7 Pro out of the box you realize that this one is very different from the previous Band series. I mean just look at the size of this thing. Compared to previous devices this is huge. It now looks similar to a regular smartwatch even though it is still very much a fitness tracker.
The device design is clean and simple to keep overall costs down. Thankfully, Xiaomi didn’t skimp on the screen and that is good news for consumers. The frame is plastic, the band is black silicone and there’s a USB-A to dual pogo pin charger. Overall build quality is excellent and the Smart Band 7 Pro has up to 5ATM water resistance.
A thick user manual in multiple languages is the heaviest item in the retail box. The Smart Band 7 Pro weighs 30 grams which is quite light and is comfortable to wear for long periods of time.
In terms of hardware, you have a buzzy haptic motor, a microphone, SpO2, and heart rate sensors. And for the first time, a built-in GPS sensor will give you more accurate readouts in terms of distance traveled while outdoors. Since there is no speaker, the band can’t alert you or play music, or incoming calls. It only communicates via a series of vibrations.
I wish Xiaomi had gone a bit further and included a speaker. Alternately since the Smart Band 7 Pro buzzes a lot, a sturdier vibration motor would have been better than the one in there currently. The onboard haptic motor feels like an old mechanical alarm clock buzzing instead of the crisp clicks you get on modern smartphones.
Best part about this Smart Band 7 Pro is the large AMOLED display
Xiaomi Smart Band 7 Pro has a large 1.64-inch AMOLED display. The display is colorful and bright and text/graphics are crisp and easy to read thanks to a 326 ppi resolution. Auto brightness setting works quite well for the most part including in bright sunny conditions outdoors.
Always on Display is also available and works great. It shows a black and white clock display at all times. You need to tap the screen to see more details. If you do not use AOD then raise to wake also works quite well. In fact, I would say it works better on this Smart Band 7 Pro than other devices I have reviewed in the past.
Using the Smart Band 7 Pro after setup is easy
Pairing the Band 7 Pro out of the box is a bit of an ordeal. For some weird reason, I could not scan the QR code with my Xiaomi smartphone even after multiple tries. On the other hand, downloading the Mi Fitness app and tapping ‘Add Device’ was very easy, and the Smart Band 7 Pro paired with the phone right away.
Using the Smart Band 7 Pro is quite easy. You can raise your hand to wake up the display or if you have AOD then you can see the clock all the time. To access the features you then have to tap it once. You can change the display face with a long press on the main information screen. There are 5 choices available from the Band but you can choose over 150 different ones via the Mi Fitness app.
Swiping down from the home screen shows you the notifications. Conversely, a swipe up from the home screen shows you the pre-installed apps. There aren’t many apps available but what is installed is functional and useful so there’s that. A left swipe from the home screen brings up Alexa, Weather, and music controls. Whilst swiping right from the home screen brings up the quick settings menu.
The UI interface looks clean and derives a lot of heavy inspiration from the Apple Watch. If you can’t beat them, imitate them. I do wish Xiaomi does put their own design language in the layout and icons at some point.
Pairing with your phone is via Bluetooth. And there is no NFC on the Smart Band 7 Pro to enable touchless payments or quick pairing with another smart gadget. But that is expected for a device that is priced under $100.
Not many apps are available but what is pre-loaded works just fine
Xiaomi Smart Band 7 Pro runs custom software so you do not have access to Wear OS apps. Apps are basic and mostly related to fitness tracking, heart rate / SpO2 monitoring, and a couple for sleep and stress tracking.
The apps work fine for what they are supposed to do. Although there is a slight lag sometimes between the input and the response from the Smart Band 7 Pro. Depending on the geographical location you can use Alexa via the Band, for some reason that functionality was not available for me in the USA. The Weather app relays information from your phone to the screen on the Band, it is not functional by itself. The same goes for music controls, those will work only if you have the phone on you.
In addition, you can use the camera app essentially as a trigger to capture pictures or videos. For some reason, this app kept wanting to connect to the phone even though I had paired the Smart Band 7 Pro to my Xiaomi 12T Pro.
The last two apps are Find My Phone and Backup so that you can connect the device to a different phone. Both I believe should be useful depending on the situation.
How good is the fitness tracking on the Smart Band 7 Pro?
I would say, distance, heart rate, and calories are pretty much spot on to my Apple Watch. I think there’s about less than 5% difference between the readings from both devices in a side-by-side comparison.
There are a lot of modes in the running app, akin to what you get on a treadmill for training which I think a lot of people will find useful. Not sure if some of these features are even available on higher-end devices.
And before I forget, Smart Band 7 Pro has 5 ATM waterproof resistance along with the ability to track pool workouts. So this is definitely a great fitness tracking device on land and in the swimming pool.
Is the new GPS sensor any good?
The short answer is yes. I did a workout with the phone and no GPS tracker and another one without the phone. For the workout without the phone, I turned on the activity and within 5 seconds the Smart Band 7 Pro latched onto a strong GPS signal (indicated by the number of green bars). Once I completed the 2+ mile outdoor walk, I got home and synced the Smart Band 7 Pro with the Mi Fitness app on the phone. Then in the workout detail, I could see it captured the route accurately along with the distance traveled.
The only downside I can think of is that there is no workout auto-detection mode available. I discovered this by accident. One day I went out to walk for about a mile but did not turn the tracking on the Smart Band 7 Pro. So, in the end it only showed calories burned and steps traveled. While my Apple Watch gave me a prompt to say, I was walking outdoors and if it should record it as a workout.
Xiaomi Smart Band 7 Pro battery life is great
Battery life is quite good on the Smart Band 7 Pro. Expect to get about 8-10 days with one workout of about half an hour. I don’t think the advertised time of 12 days includes active tracking.
If you turn on the GPS expect to see somewhere around 10-12% battery loss per hour. So if you decide to go on a day hike for about 8 hours and choose to track it via GPS on the Band, expect it to run out by the time you get down from the mountain.
Recharging the Band 7 takes a while, so I just left it overnight on the pogo pin charger one night a week.
Mi Fitness App is a great companion to the Xiaomi Smart Band 7 Pro
Mi Fitness App on the paired smartphone is full-featured, easy to use, and displays information in an easy-to-read format. I am a big fan of the Xiaomi design for this app.
It looks very unique and to some extent better than what you get from Google Fit or Samsung’s Fitness app. In fact, the overall design and color scheme is even better than what Apple has on its Fitness app.
Xiaomi Smart Band 7 Pro Verdict
For the retail MSRP of €99, it is a bit tough to recommend the Xiaomi Smart Band 7 Pro. Because the Smart Band 6 has all the features that this newer version has minus GPS tracking. And it launched for only $40. So at 2.5X the price you are getting a bigger brighter screen and GPS tracking. It seems a bit pricey for just those two features. In fact, I would argue that if you carry your phone with you outdoors then there is no need to get GPS tracking and the smaller screen device will have better battery life.
On the other hand, the large screen is quite nice and the AMOLED screen is bright and colorful. Oh and auto brightness works like a charm. In addition, raise to wake has basically zero errors on the Smart Band 7 Pro in contrast with the Band 6.
Then again there is no speaker, a buzzy haptic motor, and no NFC on the international version making it a bit hard to recommend this for €99. However, a quick glance at Ali Express shows that you can get the nicer white version for about $65. At that price, I think this Smart Band 7 Pro is something easy to recommend.
Using technology powered by AI (Artificial Intelligence), scammers can now take advantage of potential victims looking for love online by deceiving them by using modern hooks.
With the rapid advancement of AI technology, scammers now have a powerful ally in the form of popular AI tools such as ChatGPT. These tools allow scammers to create anything from seemingly harmless intro chats to elaborate love letters in a matter of seconds, making it easier than ever for them to deceive unsuspecting victims.
By leveraging the impressive capabilities of these AI tools, scammers can quickly generate custom-made content designed to prey on their target’s emotions. The use of AI-generated content has made it increasingly difficult to identify and avoid scams.
One of the most common tactics used in online dating and romance scams is the practice of “catfishing.” This involves the creation of a fake online persona to lure unsuspecting victims into a relationship with the sole intention of extracting financial gain.
The term “catfishing” derives from the act of using a fake profile to hook a victim, much like fishing with a bait hook.
Convincing Scam Messages
In a recent research report titled “Modern Love” by McAfee, over 5,000 people from around the world were presented with a sample love letter and asked to determine if it was written by a person or generated by artificial intelligence (AI).
“My dearest, The moment I laid eyes on you, I knew that my heart would forever be yours. Your beauty, both inside and out, is unmatched and your kind and loving spirit only add to my admiration for you. You are my heart, my soul, my everything. I cannot imagine a life without you, and I will do everything in my power to make you happy. I love you now and forever. Forever yours …”
According to a research report by McAfee, when presented with the above sample love letter and asked to determine if it was written by a person or generated by AI, one-third of respondents (33%) believed it was written by a person, while 31% believed it was written by an AI.
While the remaining 36% of participants were unable to determine if the letter was written by a human or a machine. The study aimed to investigate the extent to which AI-generated content is perceived as authentic and genuine in the context of romantic relationships.
User Interaction Data Analysis
A recent survey found that a majority of people (66%) have been contacted by a stranger through social media or SMS and subsequently began chatting with them. Facebook and Facebook Messenger (39%) and Instagram and Instagram direct messages (33%) were cited as the most common platforms used by strangers to initiate conversation.
Unfortunately, many of these interactions eventually led to requests for money transfers. In fact, 55% of respondents reported being asked to transfer money by a stranger.
While the majority of these requests (34%) were for less than $500, a significant number (20%) involved amounts exceeding $10,000.
More concerning, 9% of respondents were asked to provide their government or tax ID number, while 8% were asked to share their account passwords for social media, email, or banking.
Scam Detection
It has been reported that people discovered they had been catfished when they experienced the following scenarios:-
Neither a face-to-face meeting nor a video conference could be arranged. (39%)
Upon finding the scammer’s photo online, they immediately realized that it was a false representation of the scammer. (32%)
During the conversation, the person asked for personal information. (29%)
The individual did not wish to speak on the telephone. (27%)
Several typographical errors and illogical sentences were present. (26%)
If the scammer is asking for money, that is the one and only telling sign that he or she is performing an online dating or romance scam.
This kind of scam usually entails a little story as part of the request, often focusing on a hardship experienced by the scammer.
Mitigations
Here below we have mentioned all the mitigations to avoid getting tangled up in an online dating or romance scam:-
The best way to know if this new love interest is right for you is to speak with someone you trust.
It’s important to take your relationship slowly in the beginning.
If the individual uses a profile picture, try a reverse image search.
Make sure that you do not send money or gifts to anyone who you have not met personally before.
Whenever you receive a friend request from a stranger, say no.
If you have any personal information on any unwanted website, make sure you clean it up.
It is strongly advised that you do not click on any malicious links that have been sent to you by a scammer.
A chatbot like ChatGPT is a very powerful tool, but it is important to keep in mind that it is only a tool, and inherently, there is neither good nor bad about it.
As long as the user decides how to use it, it is then up to them to decide how they will be able to make use of it.
Zoetop Business Company, the firm which owns fast fashion brands SHEIN and ROMWE, has been fined US$1.9mn by the state of New York after failing to disclose a data breach which affected 39 million customers.
The cyber security incident which took place in July 2018 saw a malicious third party gain unauthorized access to SHEIN’s payment systems. According to a statement issued by the state of New York’s Attorney General’s office SHEIN’s payment processor contacted the brand and disclosed that it had been “contacted by a large credit card network and a credit card issuing bank, each of which had information indicating that [Zoetop’s] system[s] have been infiltrated and card data stolen”.
This discovery was made after the credit card network found SHEIN customers’ payment details for sale on a hacking forum. Separate to this issue, the issuing bank for the cards had issued a fraud alert after linking fraud for several customers to payments made to SHEIN.
Following the discovery of the cyber-attack, the payment processor informed SHEIN that they must employ a cyber security forensic investigator to look into the case. The firm employed by Zoetop found that during the cyber-attack malicious actors had gained access to SHEIN’s internal systems and had accessed personal and identifying information for 39 million customers.
The data accessed included “names, city/province information, email addresses and hashed account passwords”. However, the method used to obscure them was vulnerable to hacking, allowing the malicious actors access to customers’ full password details.
Additionally, the login credentials of nearly 7.3 million ROMWE accounts were stolen in the breach and were later found for sale on the dark web in 2020.
An investigation by the New York Attorney General’s (AG) office found that Zoetop did not force any of the 39 million people affected to reset their account passwords. Zoetop instead identified 6.4 million customers of the 39 million affected who had previously placed an order with SHEIN and contacted them directly, suggesting they reset their password. Zoetop reset the passwords for the accounts affected by the ROMWE attack without informing them that they had been exposed in a data breach.
The New York AG also reported that a press release regarding the 2018 breach issued on a FAQ section of the SHEIN website contained misleading data. This included claims that only 6.4 million customers were affected in the breach and that there was “no evidence that [customer] credit card information was taken from [its] systems”, despite being previously informed that credit card data had been stolen in the breach.
The investigation discovered that Zoetop “did not provide the firm access to the compromised systems and a variety of information about [its] data security program”, “failed to adhere to PCI DSS requirements for protecting stored credit card data” and “did not use file integrity monitoring, monitor or analyze log files, retain an audit trail history, or perform quarterly network vulnerability scans”.
The OnePlus 11 is now out, and its set to be one of the best smartphones of 2023. So why not get some great accessories to go with your new OnePlus 11. While the charger is included in the box, this list does have a good charger or two that you could pick up for your OnePlus 11. Along with a smartwatch, extra USB-C cables and much more. So you can really get the best out of your OnePlus 11. If you haven’t already picked up the OnePlus 11, you can do so from here.
Best OnePlus 11 Accessories
In this list, you’ll find truly wireless earbuds, smartwatches, chargers, and much more. Just about everything you can think of to really take full advantage of the OnePlus 11.
While OnePlus does include a charger in the box with the OnePlus 11, it’s still a good idea to pick up another one to use when you’re traveling, or whatnot. And it’s pretty inexpensive at $35 too.
This charger can be used for a number of things, including charging your laptop, if it happens to be USB-C. Which makes this charger even more useful.
The OnePlus Watch isn’t actually new, but it is the only wearable that OnePlus makes and it works the best with a OnePlus smartphone. Making it the perfect fit for your new OnePlus 11.
This watch is able to do the usual things like tracking your fitness, so you can help get in shape. It can also bring notifications to your wrist, so you are touching your phone less.
The PopGrip from PopSockets is a really good accessory for really any phone. And the reason why this is the best PopSocket you can buy right now is because it does allow you to swap out the top. So if you want to change the color, you can do so.
PopGrip is really great because it allows you to hold onto your phone much easier, especially for larger phones, but even works great on smaller ones like the OnePlus 11. But it also doubles as a sort of kickstand for your smartphone. Allowing you to use it on long flights to watch a movie or two, without having to hold your phone the whole time. It’s a really genius invention, and it’s something that everyone should have.
You can attach the PopGrip to your case, so that it doesn’t ruin your phone too.
RAVPower Portable Charger 20000mAh PD 3.0 Power Bank
RAVPower Portable Charger 20000mAh PD 3.0 Power Bank
The RAVPower Portable Charger 20000mAh PD 3.0 Power Bank is a really great option for a battery pack for the OnePlus 11. It offers fast charging, though you likely won’t need that for the OnePlus 11, since it does offer some really good battery life.
It also uses two USB-A ports with fast charging, so you can charge other devices at the same time. RAVPower also includes two more USB-C ports for input, which is really nice, when you need to charge this battery up pretty quickly.
It’s always a good idea to get another USB-C cable or two, to have around your home. While you probably don’t need one at your office right now, since the majority of us are not actually going to work. It is good to have one in the car and other places around your home.
This is a USB-C to USB-C cable that is capable of USB-C PD speeds, so it can charge your phone pretty quickly too. That’s important in this day and age of fast charging.
The OnePlus Buds are a really great pair of truly wireless headphones from the company. And of course, they work really well with the new OnePlus 11. They also were released in a new radiant silver color that looks incredible.
These earbuds will run for around 5 hours on a charge, or 7 hours with ANC off. And with the included charging case, you can get 38 hours of playback which is pretty incredible.
The Fitbit Versa 3 is a great fitness tracker to go along with other accessories for your OnePlus 11. Especially if you’re looking to get in shape this year.
The Versa 3 is the latest in the Versa line for Fitbit. It offers up all of the fitness tracking that you’d expect from Fitbit. Including the ability to track your steps, your workouts, calories burned and much more. It can also deliver some notifications to your wrist.
The Anker PowerPort Atom PD 1 is the perfect USB-C PD charger to use with the Pixel 5. While it does still come with one in the box, it never hurts to have a spare somewhere in your home or at work.
This is a 30W charger – and yes, the OnePlus 11 tops out at 80W but this will work on other devices too. It also uses Gallium Nitride or GaN, which makes this charger a lot smaller than you’re probably used too. Which is why we think it is the best option. Since you can easily toss this into your bag when you’re traveling – if we are ever able to do that again.
This is one of the most interesting looking car mounts out there, and it really doesn’t even look like a car mount.
The Spigen Kuel S40 stealth Car Mount is a minimalist car mount for those that don’t want to use magnets. This is a car mount that folds down when it is not in use. Just open it up and stick your phone in the mount, in landscape mode and you are good to go. It’s a good option, because it is fairly small when it is not in use, so that it is not blocking your view of the road all that much.
Spigen offers the Kuel S40 Stealth car mount in only one color. Which is black and blue, so it can blend in with your car a bit more.
The OnePlus Buds 2 Pro are pretty impressive to pick up for the OnePlus 11. It has pretty punchy and powerful bass included. That’s thanks to the 11mm dynamic drivers that allow the acoustics to come to life. OnePlus Audio ID is included here, so you can hear every note in your playlist.
Battery life here is pretty good, lasting around 39 hours of playback. That’s thanks to the included carrying case. And it also has support for High-Res Audio and Google Fast Pair.
Earlier this month Samsung revealed its latest devices, which included the new Galaxy Book 3 Pro and Galaxy Book 3 Ultra, both of which you can now pre-order. The Galaxy Book series has always been about providing consumers with a premium laptop experience, but this year Samsung took it up a notch. The Galaxy Book 3 Ultra in particular showcases Samsung’s commitment to amping things up.
Not only does it come with 32GB of RAM, but it’s powered by up to a 13th Gen Intel Core i9 CPU and an NVIDIA RTX 4070 GPU. The aim here is likely to capture the creator consumer. Someone who needs a powerful enough laptop for content creation or professional use. But the specs seem to be more than capable of handling other high-load activities, too. Such as gaming.
This begs the question then. Is the Galaxy Book 3 Ultra a good gaming laptop option? Well, it’s not a gaming laptop per se. But it does seem equipped to handle games with decent graphics settings. The better question might be whether or not the cooling is up to the task. And if so, for how long?
Either way, if you’re looking for a premium laptop for, whatever your needs are, Samsung’s latest are up for pre-order through the company directly.
Pre-order the Galaxy Book 3 and get a free storage upgrade
Samsung usually has pre-order offers available for those that jump on their latest products early. And this time is no different. If you pre-order the Galaxy Book 3, you get a free storage upgrade. More specifically, Samsung will sell you the 1TB model for the same price as the 512GB model. So for example, if you pre-order the Galaxy Book 3 Ultra with an Intel Core i9, you can get the 1TB model for $2,499.99. This would normally be $2,999.99. And that’s the price it’ll go up to once the pre-order promotion is over.
The same storage upgrade offer is available for the other two models as well – the Galaxy Book 3 Pro and Galaxy Book 3 Pro 360. You can find all three at Samsung’s website.
Google Assistant is considered by most device users to be the best virtual digital assistant beating out Alexa, Siri, Bixby, and others. But you might have noticed (and in all honesty, it isn’t hard to spot) that on Android, Google Assistant is always in Dark mode even if you have your system setting on Light mode. Back in October, Google said that Light mode is no longer available for Assistant on Android.
Now, Google has issued a support page titled “Assistant Uses Dark Mode By Default” in an attempt to revisit the issue. On the page, Google writes, “Google Assistant regularly tries new ideas to see what works and what could work better. This includes ways to make our products look and feel consistent throughout our product ecosystem.”
The company continues, “To offer a more helpful visual experience across all your devices, including Pixel Watch and Google TV, when you engage with Assistant on mobile Light mode is no longer available – it will now have a dark appearance, even if you have Dark theme turned off in your phone settings.”
The bottom line is that you shouldn’t expect to see Google Assistant in any other theme other than Dark and if you’re not a fan of white text on a black background, you’re SOL (Google it).
Google Assistant, on the bottom of the screen, will show up in Dark mode only on Android
As we told you less than a week ago, Google Assistant will be playing a key part in the new Google Lens feature “Search your screen.” This feature allows users to employ Lens to search photos and videos from websites and messaging and video apps. For example, if someone sends a video to you via your Messages app and you see a landmark in the background that you’re curious about, activate Google Assistant by long-pressing on your Android’s power or home button. Tap on “search screen” to get the info you want.
This feature is part of an update that will be disseminated over the upcoming months.
Perhaps there will be a day in the future when Google gives Android users the ability to decide whether they want to see Google Assistant in Dark Mode or Light Mode. But for right now, if you’re an Android user, you have no choice.
A WiFi 6E-compatible router from Google has been long awaited, and it’s finally here. It’s here at a price that is much less than the competition. For example, the eero 6E is priced at $299 for the same single-pack that Google is charging $199. And that’s actually the least expensive competitor for Google. So this is a big deal.
But the real question is, is the Nest WiFi Pro any good? Typically when a product significantly (by about 33%) undercuts the competition, it’s not very good. So is that the case here? Let’s find out in our Nest WiFi Pro Review.
Google Nest WiFi Pro Review: Unboxing & Setup
I’ll be frank here, when FedEx dropped off the Nest WiFi Pro, I thought maybe something else had been delivered. I was expecting it to be bigger and weigh more. But the Nest WiFi Pro is actually fairly small compared to the eero 6+ that I recently tested out. The Nest WiFi Pro itself is about the same size and height as my Comcast modem. Which is fairly impressive.
In the box, you’ll get the Nest WiFi Pro, an Ethernet cable, power cable and of course some instructions. It’s pretty minimal. To get started, plug it into the wall, and plug your modem into the Nest WiFi Pro.
Setting it up was quite easy. You just open the Google Home app and it should find your Nest WiFi Pro to setup. It took me about 5 minutes to set it up. And the actual input from me was pretty minimal. Making it very easy to do is a big deal. This means that I’d have no regrets about recommending my parents to get the Nest WiFi Pro for their home.
When I initially set it up, I tried to be lazy and just use the same SSID and password as my old network (which was on the eero 6+). That way I wouldn’t have to reconnect every single device in my house. That worked for about two days, until the network stopped allowing new devices to join and even refused to let known devices rejoin. So I had to factory reset it and set it up again, with a different SSID. So just a word of caution to those hoping to take the lazy way out, it might not work.
Otherwise, setup was extremely easy, and I wish all smart home products were this easy to do.
Google Nest WiFi Pro Review: Design
The design is quite polarizing, surprisingly. It’s surprising because it’s a router. But Google wanted to design this router to look nice, so that you won’t hide it away in a cabinet. That’s not a good thing to do with your router, as it will mess up your signal and speeds. It’s always good to put out in the open, and about halfway between the floor and ceiling.
So this router looks like an Easter Egg, and the pastel colors doesn’t help this very much either. I actually don’t mind the color. It matches my Comcast router and Philips Hue Bridge that are all connected to it. But the only issue I have with it is, that it is glossy. The older Nest WiFi is not glossy, and is a matte finish, which looked really nice. For some reason, the Nest WiFi Pro is glossy, which means you’re going to see more dust, dirt, scratches and more on the router. Making the whole “let it be part of your decor” thing, a bit irrelevant.
Nest WiFi Pro colors
Google does offer the Nest WiFi Pro in four colors: Snow, Linen, Fog and Lemongrass.
Google Nest WiFi Pro Review: Managing your network
As mentioned already, the Nest WiFi Pro is all managed within the Google Home app. Which makes things a whole lot easier for controlling all of your smart home devices. Once it is setup, you’ll see a new option at the top for “WiFi”, between Cameras and Routines. Just tap on that to manage your Nest WiFi Pro system.
Within the WiFi section, you’ll see the name of your WiFi at the top, along with how it’s doing. That includes a message telling you that everything is connected and working normally, or not. There’s also indicators for the internet, WiFi devices and then how many devices are connected at this time. Below that, you can see your network and devices. You can run a speed test within the app. Now I like this feature, because it does record your speedtests so you can see how things used to be, if you’re having issues. It does also run speedtests on its own to make sure things are running properly.
Now if you tap on “devices”, you are able to see what’s connected, and what kind of bandwidth they are using. You can prioritize specific devices as well. Google will let you show real-time usage, usage over the past day, week and month. Which can be very useful. This made me realize just how much bandwidth my Nest Cam uses everyday, it was a shocker.
Overall, the app makes it very easy to keep tabs on your network, prioritize devices, and apps you might use (like Zoom or Luna), and to see when you’re having problems.
Google Nest WiFi Pro Review: Should I buy it?
The Google Nest WiFi Pro is a pretty good WiFi 6E router, and definitely going to be future-proof for probably a decade or so from now. So even at $199, it’s a good investment for your home. If you’re still working from home and have a lot of devices on your network, then it’s definitely worth the money.
You should buy the Google Nest WiFi Pro if:
You use a lot of smart home products (light bulbs, thermostats, robot vacuums, etc)
You do some cloud gaming (Luna, NVIDIA GeForce Now, etc)
You have a lot of people in your home
You have a larger home (a single Nest WiFi Pro can cover 2,200 square-feet)
You should not buy the Google Nest WiFi Pro if:
You have slower internet speeds (anything under, I’d say, 200Mbps won’t notice a big difference)
Researchers found two security vulnerabilities in the ImageMagick tool that could trigger denial of service attacks or leak data. The vendors patched the bugs in time, preventing any active exploitation. Users must ensure updating to the latest patched releases to avoid any mishap.
Multiple Vulnerabilities Spotted In ImageMagick Tool
According to a recent post from the cybersecurity firm Metabase Q, their researchers found two security issues in the ImageMagick graphics tool.
ImageMagick is an open-source software for image conversion, designing, and editing. Given its free availability and support for a large number of file formats (200+), ImageMagick is a popular tool among graphic designers and web developers, particularly those dealing with open-source apps.
Specifically, the researchers found the following two vulnerabilities affecting ImageMagick.
CVE-2022-44267: a denial-of-service (DoS) vulnerability that affected the image conversion feature when parsing PNG files. According to the researchers, parsing .png files could “leave the convert process waiting for stdin input.”
CVE-2022-44268: an information disclosure vulnerability that could leak data from arbitrary remote files when parsing PNG images in the resulting image.
Exploiting both vulnerabilities simply required an attacker to upload a malicious PNG image file to the target website using ImageMagick. The researchers have shared a detailed technical analysis of both vulnerabilities in their post.
Vendors Patched The Flaws
Metabase Q’s Ocelot team discovered these images when analyzing the then-latest version of ImageMagick 7.1.0-49. Following this discovery, they promptly reported the matter to ImageMagick developers.
Consequently, the app developers worked on fixing the vulnerabilities, ultimately releasing the patches with the subsequent app release.
Their site now lists the ImageMagick 7.1.0-60 version as the latest release. Hence, to ensure receiving all the feature updates and bug fixes, users must update their websites and systems with this release at the earliest.
The campaign has been active since September 2022, and the recent surge in website infections was noted in January 2023.
Sucuri researchers have reported a backdoor that has successfully infected around 11,000 websites in recent months. Here are the details shared by Sucuri in its technical report.
It is a fact that, lately, several Google products have been exploited and abused to spread malware and other malicious components, including Google Ads, Google Home, and Google Drive.
In fact, a study revealed that Google Drive accounted for 50% of malicious Office document downloads in 2022.
Backdoor Redirecting Visitors to Hacked Sites
According to Sucuri’s research, the backdoor redirects users to sites that show fraudulent views of Google AdSense ads. The company’s SiteCheck remote scanner has detected more than 10,890 infected sites. The activity has further intensified recently, with 70 new malicious domains disguised as legitimate in 2023 and 2,600 infected sites discovered on the web.
All the infected websites detected by Sucuri were using WordPress CMS. These had an obfuscated PHP script injected into the legitimate files on the websites, such as index.php, wp-activate.php, wp-signup.php, and wp-cron.php, etc.
How Does the Attack Work?
In the past two months, Sucuri researchers have identified over 75 pseudo-short URL domains linked with redirected traffic. It must be noted that almost all of the malicious URLs appear to belong to the same URL-shortening service. Some even mimic the names of popular shortening services, such as Bitly.
The visitors are redirected to a range of low-quality websites developed on the Question2Answer CMS, and the discussion topics are mostly related to cryptocurrency or blockchain.
Researchers believe it could be intentional to advertise new cryptocurrencies in a pump-and-dump, ICO fraud. However, researchers are certain that the primary objective of this ad fraud is to inorganically increase traffic to sites that contain the AdSense ID so that Google ads can be displayed for revenue generation.
Image source: Sucuri
How does It Evade Detection?
Some of these malicious sites also inject obfuscated code into “wp-blog-header.php.” This code works as a backdoor to ensure the malware evades disinfection attempts. It performs this by loading itself into files that run as soon as the targeted server is restarted.
“Since the additional malware injection is lodged within the wp-blog-header.php file it will execute whenever the website is loaded and reinfect the website. This ensures that the environment remains infected until all traces of the malware are dealt with.”
The malware hides its presence by suspending redirections when a visitor logs in as an administrator or visits an infected site within 2 to 6 hours. The malicious code is hidden using Base64 encoding.
How URL Shorteners Abused in the Attack?
When the user enters any domain names in their browser, they are redirected to a real URL shortening service, e.g., Cuttly or Bitly, but these are not genuine public URL shorteners. Each domain has a few working URLs that redirect visitors to spammy Q&A sites featuring AdSense monetization.
In a blog post, Sucuri researcher Ben Martin stated that the “backdoors download additional shells and a Leaf PHP mailer script from a remote domain filestacklive and place them in files with random names in wp-includes, wp-admin, and wp-content directories.”
The campaign has been active since September 2022, and the recent surge in website infections was noted in January 2023.
“At this point, we haven’t noticed malicious behaviour on these landing pages. However, at any given time, site operators may arbitrarily add malware or start redirecting traffic to other third-party websites,” researchers noted.