Are smart devices cyber secure?

0
[ad_1]

Cyber Security Hub takes a deep dive into smart devices and whether they can hold up against cyber attacks targeting them.

In December 2022, Cyber Security Hub asked a range of experts to predict what threats would dominate the cyber security threat landscape in 2023. Tina Grant, quality assessor at UK-based aerospace company Aeorspheres, predicted that cyber attacks targeting smart devices would rise.

As artificial intelligence (AI) and machine learning (ML) have developed, the technologies have been integrated more fully into smart devices, from lightbulbs and speakers to cars and doorbells. With a predicted 75.4 billion Internet of Things connected devices installed worldwide by 2025, it is no surprise that smart devices are predicted to increase as a cyber attack target throughout 2023.

This article will explore the ways in which malicious actors can target smart devices and how companies are attempting to fight against them.

Contents:

Smart speakers can be used as wiretaps

In December 2022, cyber security blogger Matt Kune was awarded US$107,500 from Google after discovering and reporting a bug that meant Google Home smart speakers could be essentially turned into wiretap devices.

Using a Google Home mini, Kune discovered that any attacker close enough to wirelessly connect to a Google Home speaker could “install a ‘backdoor’ account on the device, enabling them to send commands to it remotely over the Internet, access its microphone feed, and make arbitrary HTTP requests within the victim’s LAN (which could potentially expose the Wi-Fi password or provide the attacker direct access to the victim’s other devices)”.

Using the ‘routines’ feature in the Google Home app, Kune was able to set up malicious routines, including calling any device linked to the Google Home account (e.g. a potential victim’s mobile phone) at specified times. Once the phone call was accepted, Kune was able to listen to himself speaking via the Google Home microphone. 

While Kune said this was “pretty cool” in isolation and when enacted on himself by himself, he noted that malicious parties could use this vulnerability to spy on victims if they gained access to their Google Home network. He suggested that they may be able to do this if victims were targeted with a social engineering attack which prompted them to download a malicious app, which would allow hackers to link their device with the victim’s Google Home.

Next, Kune tested to see if hackers could gain access to a victim’s Google Home network without the need for a social engineering attack. So, he attempted to force the smart speaker to disconnect from the Wi-Fi network by “launch[ing] a deauth[entication] attack” against the router. Also known as deauth attacks, this attack vector targets the deauthentication frames of a device, which are not encrypted. By targeting these frames, attackers can force the device to disconnect from its Wi-Fi network.

After forcing the smart speaker to disconnect from the Wi-Fi router, Kune discovered that the speaker immediately made its own separate network.

“I connected to the network and used netstat to get the router’s IP (the router being the Google Home) and saw that it assigned itself the IP 192.168.255.249. I issued a local API request to see if it would work. I was shocked to see that it did! With this information, it’s possible to link an account to the device and remotely control it,” Kunes explained.

Discover more about Kune’s investigation here.

These issues have since been fixed by Google, however, the potential ramifications from unsecured smart devices should not be dismissed. 

Targeting smart speakers connected to smart networks

Once an attacker has access to a victim’s smart speaker, depending on how many other smart devices they have connected to their network, malicious parties can set up any number of disruptive routines including calling their or other household member’s mobile phones, loudly playing music or even disrupting other smart devices such as TVs or lights.  

If a victim has further smart technology integrated into their home such as a smart climate control system or thermostat, smart home security system or smart cameras, this could allow hackers to lock or unlock doors and windows, severely heat or cool their home or even film and/or broadcast footage of them within their home.

An example of this was seen in 2019 in the US state of Wisconsin when hackers gained access to and took over a Milwaukee couple’s smart home via their Google Nest account. Samantha Westmoreland discovered that the system had been hacked after her smart thermostat was used to turn the home’s temperature up to 90 degrees Fahrenheit (32 degrees Celsius) and “vulgar” music was played through a smart speaker. Westmoreland also reported that a voice began speaking to her and her husband through the Nest security camera that was installed in their kitchen.

Google said that the hack was the result of Westmoreland using a password for the Google Nest account that had been compromised in a data breach, allowing hackers access to any number of accounts also using the same credentials. The company recommended that those with smart home capabilities use Google’s “additional tools and automatic security protections such as Suspicious activity detection, 2-Step Verification and Security Checkup” to prevent attacks such as these.

Westmoreland was deeply affected by the attack, noting that the smart home system had been bought to make her house feel more secure, and instead she “didn’t feel safe”.

While the smart device attack against the Westmorelands appears to be an untargeted attack, it should be noted that malicious parties can use cyber attacks to gain access to smart device networks to target specific victims.

UK-based domestic abuse organization Refuge notes that smart devices can be used by abusers to cause distress to their victims. With 48 percent of those surveyed by Refuge unable to name a single device that could be vulnerable to hacking, the need for education around securing home networks is clear.

Smart doorbells can be used to spy on victims

In December 2022, two men were charged with participating in a swatting spree after they allegedly hacked into the smart doorbells of dozens of people. 

The pair, James Thomas Andrew McCarty and Kya Christian Nelson, who went by the aliases Aspertaine and ChumLul, respectively, were accused of stealing the login credentials to victim’s smart doorbells to log into their video recording capacity, then using this video recording capacity to stream footage of the victims getting swatted.  

According to the Department of Justice (DoJ) for the Central District of California, the pair allegedly acquired login credentials of Yahoo email accounts belonging to victims across the US, then used the credentials to find out if the owners of said accounts had a Ring doorbell, and used the same login credentials to attempt to log in to victim’s Ring accounts, using the video monitoring feature to gain further information about their victims and to stream the footage of the victim’s houses being raided by SWAT teams in response to their false reports.

The DoJ gave an example of a swatting attack allegedly carried out by the pair, stating: “On November 8, 2020, Nelson and an accomplice accessed without authorization Yahoo and Ring accounts belonging to a victim in West Covina. A hoax telephone call was placed to the West Covina Police Department purporting to originate from the victim’s residence and posing as a minor child reporting her parents drinking and shooting guns inside the residence of the victim’s parents.

“Nelson allegedly accessed without authorization a Ring doorbell camera, located at the residence of the victim’s parents and linked to the victim’s Ring account, and used it to verbally threaten and taunt West Covina Police officers who responded to the reported incident.”

The spree of attacks even prompted the FBI to issue a warning to those with Ring doorbells, urging them to “practice good cyber hygiene by ensuring they have strong, complex passwords or passphrases for their online accounts, and should not duplicate the use of passwords between different online accounts”, and to reset their passwords frequently.

Owner of the Ring company, Amazon, took immediate steps to protect customers once news of the hacking and attacks broke. To combat the attacks, Amazon made two-step verification mandatory and now conducts regular scans for Ring passwords compromised in non-Ring data breaches as well as investing in cyber security solutions to harden its own defenses against attacks.

What is swatting?

“Swatting” refers to the practice of malicious actors making false reports of extreme violence, kidnapping or terrorism to the police and giving them the victim’s address with the sole purpose of sending armed officers to their home. These attacks can have devastating consequences. 

In 2017, Andrew Finch of Kansa, America was fatally shot by a police officer during a swatting attack after it was claimed that Finch was armed and dangerous.

Finch was an unintended victim of the attack, which was instigated by online gamer Casey Viner. The swatting’s target was intended to be fellow gamer Shane Gaskill, as the pair had argued over a $1.50 bet on a Call of Duty: WWII game which culminated in Viner threatening to swat Gaskill. Gaskill, however, gave him a false address, which actually belonged to Andrew Finch and his family.

Viner hired serial swatter Tyler Raj Barriss to carry out the attack. Barriss called Wichita police, posing as a man named Brian, and claimed that he had shot his father, was currently holding the remaining members of his family hostage and was preparing to self-immolate. When police arrived at the address supplied by Barriss, Finch exited the house to investigate why they were there and was shot by an officer. He later died in hospital. Finch had no relation to Viner or Gaskill, or Call of Duty: WWII.

Barriss was arrested in connection with the crime and later plead guilty to involuntary manslaughter. He was sentenced to 20 years imprisonment. Viner was jailed for 15 months and banned from playing video games for two years.

Smart cars can be hacked into and remotely controlled

In her prediction, Grant forecast that cyber attacks targeting smart devices will predominantly affect autonomous devices with multiple points of attack, for example smart cars.

Grant said: “Today’s automobiles come equipped with automatic features including airbags, power steering, motor timing, door locks, and adaptive cruise control aid systems. These vehicles use Bluetooth and Wi-Fi to connect, which exposes them to a number of security flaws or hacking threats. 

“With more autonomous vehicles on the road in 2023, it is anticipated that attempts to take control of them or listen in on conversations will increase. Automated or self-driving cars employ an even more complicated process that demands stringent cybersecurity precautions,” she explains.

The dangers of this have already been explored by David Columbo, a cyber security researcher and founder of cyber security software company Columbo Tech. 

In a series of tweets in January 2022, Columbo explained that he had hacked into and gained remote access to “over 20 Tesla’s[sic] in 10 countries” allowing him to “remotely run commands on 25+ Tesla‘s[sic] in 13 countries without the owners’ knowledge”. While Columbo did not have “full remote control” – meaning he could not remotely control steering, acceleration or braking – he noted that even some remote-control access was dangerous. 

To demonstrate this, Columbo joked about using his newfound abilities to prank the affected Tesla owners by playing Rick Astley’s ‘Never Gonna Give You Up’ through their speakers. He then acknowledged that while this may seem innocuous, the ability to remotely play loud music, open windows or doors or flash a car’s headlights repeatedly could put not only the driver’s but other motorists’ lives in danger, especially if the car was driving at speed or in a busy area. 

If drivers are distracted, this can have fatal consequences; The US Department of Transportation found that in 2019, over 3,100 people were killed and about 424,000 were injured in crashes involving a distracted driver. One in five of those killed by distracted drivers were not motorists themselves and were pedestrians, cyclists or not inside a vehicle for any other reason.

After Columbo alerted Tesla of the vulnerability, the company investigated the issue, then notified him that they had immediately revoked the access tokens and notified the owners of the issue.

Smart device producers should learn from past vulnerabilities

Smart devices are targets for hackers because of their ability to wreak havoc if they are compromised. If someone has multiple, interconnected smart devices, this not only opens up more points of attack for hackers to target, but also means that hackers can gain access to all their smart devices if one is compromised.

While companies work rapidly to patch and rectify any vulnerabilities they are alerted to, the fact remains that it may not always be white hat hackers that discover these vulnerabilities. In the case of Ring doorbells, multiple people had already been terrorized by the time Amazon became aware of the issue. 

Relying on ethical hackers to discover issues, or rapidly addressing security flaws after they have been found by black hat hackers is not good enough both in terms of threat defense security strategy and in terms of keeping those who own smart devices safe.

While smart devices may always be an attractive target to hackers, companies who make them should look at vulnerabilities that have been exploited in the past at the forefront of their software design to ensure they are as secure as possible before they are released to the public. While these vulnerabilities may not always be detectable, if it becomes apparent that they can be exploited by malicious actors, companies should work as rapidly as others have in the past to solve these issues before too much damage is done. 


[ad_2]
Source link

A pretty phone with a pretty big drawback

0
[ad_1]

Chinese OEM OnePlus has made a name for itself over the years in the budget smartphone market- as in actual budget phones, not flagship killers. The latest entry in its OnePlus Nord line of affordable smartphones is the OnePlus Nord N300. This phone promises to bring some nice specs to the sub $300 Market.

Android headlines had the opportunity to review this device and see if it’s worth the money, no matter how inexpensive it is. So, should this phone be your next device, or should you pass it out? Let’s find out in this review of the OnePlus Nord N300.

OnePlus Nord N300: Build quality and design

The OnePlus Nord N300 is one of those phones that feels a lot more expensive than it actually is. When you pick up this phone, you can tell that it’s not quite a $1,000 flagship smartphone. However, that does not mean that it feels cheap.

The phone feels really solid in the hand. Picking it up, you can feel that it’s solidly built. It has a thick metal frame and the back plastic is also pretty sturdy. The phone itself is unapologetically thick, and that’s always a great sign if you’re looking for a phone that can take a drop or two.

Some of the charm goes away once you turn your attention toward the camera bump. The camera sensors are housed in a plastic housing, not glass like more expensive phones. That does subtract from the feeling of the phone just a bit.

Nord N300 Pictures 18

As for the design itself, this is definitely a pretty-looking phone. I tested the black version of it, and it has an extremely sleek look. The design is pretty toned down with a rather bear back. The camera package sits on the top left and it has a dual-tone look to it.

Turning to the front, some of that charm goes away once you look at the display. The display gives this phone a dated look with the teardrop notch up top. Along with the notch, there’s a pretty significant chin bezel on the bottom. From the front, the device doesn’t look too great, admittedly.

OnePlus Nord N300: Display

Let’s dive deeper into this display. This is an LCD panel. Now, you’d expect an LCD display on a sub-$300 phone to look bad. However, it’s the opposite. I was surprised at how nice the display looked. Let’s rip off the Band-Aid, this is a 720p display in the year 2022. Sure, this is a $228 phone, but the $258 TCL Stylus comes with a 1080p+ display.

Regardless of the resolution, the display has some really beautiful colors. The colors aren’t as saturated as what you would get on an AMOLED display, but they’re still vibrant for an LCD display. Out of the box, the color leans a bit toward the cooler side.

OnePlus Nord N300 3

As for the contrast, the story is the same. You don’t get the inky blacks like you would get with an OLED display, but the contrast is still rather impressive. I can tell that OnePlus prioritized the display on this phone. You should have no issues using this as your primary media-watching phone.

The only complaint that I have with the display will be the brightness. It’s not quite the dimmest display, but I would say that it’s just below average. This makes outside viewing a bit of a hassle. Just know that if you’re using this phone outside, you might need to find some shade.

OnePlus Nord N300: Speakers

Moving on to the speakers, they’re not going to blow you away. Keeping the phone below $300 required some heavy compromise, and the speakers definitely had to get the short end of the stick.

The speakers lack depth and immersion. Listening to them at higher volumes only leads to heavy distortion and a tinny sound. So, if you want to use this as a replacement for your Bluetooth speaker, you’re not going to have a great time. They do get plenty loud, but they’re not great to listen to.

OnePlus Nord N300 4

OnePlus Nord N300: Camera

The camera on this phone is a mixed bag. Let’s start off with the good: the main camera. This phone comes with a 48-megapixel camera, and that’s pretty good for a phone in this price range. I know that megapixel count isn’t the most important aspect of a camera, but this phone was able to utilize it pretty well.

In well-lit conditions, this camera was able to produce some pretty nice images. The colors weren’t overly saturated, but they were pleasantly juicy. The green in the grass and the plants really pops out. Also, the dynamic range is impressive. I took a picture of the ground with a harsh shadow, and it was exposed pretty nicely. So, if using the main camera oh, then you should be fine.

Hi-res mode

As with all cameras with high megapixel counts, this phone uses pixel binning. This means that you’re getting about a 12-megapixel image when you use it out of the box. However, there is a high-resolution mode that utilizes the full 48 megapixels of the sensor.

Using the high-resolution mode, I was able to take sharper images, and they actually look a bit better. I noticed more detail and the grain of the image and less pixelation. This is a change of pace from other cameras who’s high-resolution modes lead to a picture with a watercolor appearance of them.

Low light

Moving into low light, the results aren’t fantastic. They were able to illuminate the scene and bring out some additional detail. Using the night mode, the phone took a longer exposure. The only issue is that the results came out very grainy and noisy. You’ll be able to take brighter images, but they will not be aesthetically pleasing.

Stabilization

The stabilization on this camera is really bad. When using it, I could see every slight movement of my hands, and the camera couldn’t really do anything to compensate. This came to a head when I tried recording a video. Walking down on a flat sidewalk, trying my best to keep the phone steady, still led to very shaky and jittery video.

Overall, if you want to use this phone for a regular point-and-shoot camera in good lighting conditions, then you’ll get some pleasing results. They definitely look good on the phone’s display. However, using any of the other functions like the low-life, video, portrait mode, etc won’t yield the best results. The company prioritized the results for the main sensor, but the other features fell by the wayside.

OnePlus Nord N300: performance

If it’s one area that this phone fails in, it’s the performance. Honestly, I think that the performance is inexcusable at most points. There are times when I’m able to easily glide through the software with no issue. However, once I started using the phone, the performance tanks. There were heavy stutters in the software just going from the app to the home screen and vice versa. There will be times when I would swipe up to go back to the home screen, and have to wait several seconds for it to even register.

There are other times when the phone would lock up just minimizing an app. Apps would fail to function and freeze for a while before registering any commands. It doesn’t only feel like the phone is slow, it feels as though it can’t even support its own software.

OnePlus Nord N300 7

It’s using the MediaTek Dimensity 810 SoC. People tend to associate the brand MediaTek with low performance. However, the TCL Stylus was able to get much better performance using the MediaTek 700 chip. Maybe future updates will help iron out these performance issues.

Gaming

When it comes to gaming, the OnePlus Nord N300 was able to handle simple 2D titles. That’s to be expected. Jumping into 3D games, we start to see stutters and hiccups, but it’s not too drastic for most games. I was able to run the graphically pleasing Sky: Children Of Light very well. There were definitely stutters and lag in the software but it was more than playable.

Cutting right to the chase, I downloaded and ran Genshin Impact just to see how hard I can push this device. Well, it was not able to pass the test. Genshin Impact was not playable, and that was to be expected. If the game looks like it’ll be graphically intensive, just know that you may definitely experience some lag.

OnePlus Nord N300 2

OnePlus Nord N300: Battery

One of the main strengths of this phone is its battery life. It comes with a large 5000mAh battery, and I was able to test it out. The battery was able to survive my initial test hands down. I got over 8 hours of screen-on time from this phone.

You’ll have no issue using this phone for more than a day and a half with moderate usage. If you need to charge the phone, this one comes with a respectable 33W charger. With this, I was able to get about 51% battery on a 30-minute charge. Charging it from 0% to 100% took about 1 hour and 15 minutes. That’s not too bad considering that the battery is so big.

OnePlus Nord N300: software

This phone is running on OnePlus’ Oxygen OS version 12. It’s a heavily-skinned version of Android and it definitely shows. However, this is a good thing, as OnePlus was able to bring a bunch of customization options to Android.

OnePlus Nord N300 1

There are so many options for customizing the UI to your liking that it’s tough to list them all. You have deep customizations when it comes to personalizing your home screen. This includes adjusting the size and shape of the icons, the transition effects, layout, animation speed, and much more.

Some of my favorite bits from the software include being able to manually adjust the size and shape of the app icons and the one-handed mode. Swiping up from one side of the screen will compress all of the app icons down to the bottom of the screen, and you can just slide your finger over to the icon you want to use

Overall, I love the software and the amount of options you have for customizing the phone to your liking.

OnePlus Nord N300: Conclusion

Overall, giving the final rating on this phone is tough. There are several really good aspects of this phone. The display has great colors and contrast, the battery life is amazing, and the camera is decent. However, the extremely sluggish performance drags everything down. It’s bad to the point where other mid-range devices are lapping it in terms of performance.

OnePlus Nord N300 3

You should buy this phone if:

  • You like to watch movies/TV shows
  • You want a nice point-and-shoot camera experience
  • You want a phone with excellent battery life
  • You want a phone with customizable software

You shouldn’t buy this phone if:

  • You want a phone with good performance
  • You want a phone that’s good when it comes to gaming
  • You want a phone with good camera stabilization
  • You want to phone with good speakers

[ad_2]
Source link

India’s Largest Truck Brokerage Company Leaking 140GB of Data

0
[ad_1]

The misconfigured server is still exposing the data, and there has been no response from the company since their only contact email address available to the public is bouncing back all emails.

India’s largest truck brokerage and freight delivery company, FR8, is facing a serious data leak problem. According to the IT security researcher Anurag Sen working with Italian cyber security firm FlashStart, the organization has exposed more than 140 gigabytes of data, which is available to the public without any password or security authentication.

According to Hackread.com, the leaked data includes sensitive information such as customer records, invoices, and payment details across India. Not only that, but it also contains other personal information, such as names, addresses, and contact numbers of both customers and employees.

FR8 claims to be “India’s largest truck transport service company,” currently operating in over 60 cities across the country.

Anurag discovered the server on Shodan while searching for misconfigured cloud databases on January 30th, 2023. The researchers informed FR8 about the leak, but they did not receive any response. Their only contact email address available to the public is bouncing back all emails.

For your information, Shodan is an OSINT tool and a specialized search engine used by cybersecurity researchers to locate vulnerable Internet of Things (IoT) devices, including servers and misconfigured databases on the internet.

As for FR8, what is worse, at the time of writing, the server is still live and is exposing the following details:

  • Full name
  • Mobile number
  • Internal document
  • Delivery Full address
  • Bank payment details
  • Delivery Vehicle Details
  • Internal employee details
India's Largest Truck Brokerage Company Leaking 140GB of Data

India has a server misconfiguration issue

With a population of over 1.4 billion people, India is a lucrative place for businesses to invest and for cybercriminals to target. The more investment there is, the more widespread and vulnerable the IT infrastructure becomes.

Just a couple of weeks ago, Hackread.com exclusively reported on how an Enterprise Resource Planning (ERP) software provider had exposed half a million Indian job seekers’ data.

Last year, several top data exposure-related incidents involving tens of millions of victims were reported from India. These included Covid antigen test resultsIndian Federal Police and banking recordsMyEasyDocs, online packaging marketplace Bizongo, and more.

Impact

Since the server is live and there has been no response from the company, the chances of misuse and abuse of data are high if it gets into the hands of a third party with malicious intent.

While the data can be exploited to carry out identity theft-related fraud, hackers can hold the company’s server or data for ransom and leak it on cybercrime forums if their demands are not met.

Misconfigured Databases – Threat to Privacy

As we know, misconfigured or unsecured databases have become a major privacy threat to companies and unsuspecting users. In 2020, researchers identified over 10,000 unsecured databases that exposed more than 10 billion (10,463,315,645) records to public access without any security authentication.

In 2021, the number of exposed databases increased to 399,200. The top 10 countries with the most database leaks due to misconfiguration in 2021 included the following:

  • USA – 93,685 databases
  • China – 54,764 databases
  • Germany – 11,177 databases
  • France – 9,723 databases
  • India – 6,545 databases
  • Singapore – 5,882 databases
  • Hong Kong – 5,563 databases
  • Russia – 5,493 databases
  • Japan – 4,427 databases
  • Italy – 4,242 databases
  1. Hackers selling 13TB of Domino’s India data
  2. Hackers leak millions of Airtel India user data
  3. Hackers leak 9 million Indian job seekers’ data
  4. Hacker claims to steal 8.2TB of MobiKwik data
  5. India’s COVID-19 surveillance tool leaked user data

[ad_2]
Source link

Consent to gather data is a misguided solution, study reveals

0
[ad_1]

There’s a flaw in the notice-of-consent approach, and this is evident in the stark gap in knowledge noted by a recent study by the Annenberg School for Communication in Pennsylvania.

When researchers from the University of Pennsylvania’s Annenberg School for Communication conducted a survey to see if “informed consent” practices are working online with regard to user data gathering, the results revealed weaknesses in a framework that, for decades, has served as the basis for online privacy regulation in the US. This framework, which is commonly known as “notice of consent,” usually allows organizations to freely collect, use, keep, share, and sell customer data provided they inform them about their data-gathering practices and get their consent. However, as the New York Times noted, the survey results add another voice to “a growing body of research suggesting that the notice-of-consent approach has become obsolete.”

“Informed consent is a myth”

The report, entitled “Americans Can’t Consent to Companies’ Use of Their Data,” contains the results, expert analyses, and interpretation of survey results. The authors not only give attention to the gap in American users’ knowledge of how companies use their data but also reveal their deep concern about the consequences of its use yet feel powerlessness in protecting it. Believing they have no control over their data and that trying would be pointless is what the authors call “resignation,” a concept they introduced in 2015 in the paper, “The Tradeoff Fallacy.”

As the Annenberg School report said:

“High percentages of Americans don’t know, admit they don’t know, and believe they can’t do anything about basic practices and policies around companies’ use of people’s data.”

The authors define genuine consent as people having “knowledge about commercial data-extraction practices as well as a belief they can do something about them.” The survey finds that Americans have neither.

“We find that informed consent at scale is a myth, and we urge policymakers to act with that in mind,” the report said.

The New York Times noted a handful of regulators agreeing to the report’s findings.

“When faced with technologies that are increasingly critical for navigating modern life, users often lack a real set of alternatives and cannot reasonably forgo using these tools,” said Lina M. Khan, a chairperson of the Federal Trade Commission, in a speech last year.

Digital consent has had critics as early as 1999, denoting that its weakness remained unaddressed for almost 25 years. Paul Schwartz, a professor at the University of California and author of the paper “Privacy and Democracy in Cyberspace,” had warned that consent that was given via privacy policy notices was “unlikely to be either informed or voluntarily given.” The notices were “meaningless,” he said, as most people ignore them, were written in a vague and legalistic language that very few people understand, and “fail to present meaningful opportunities for individual choice.”

Neil Richards and Woodrow Hartzog, authors of the paper “The Pathologies of Digital Consent,” give strength to this argument by recognizing a form of consent they call “unwitting consent,” which occurs when people do not really understand “the legal agreement,” “the technology being agreed to,” and “the practical consequences or risks of agreement.” Previous work of two of the authors of the study also shows people misunderstanding and confusing the meaning behind the term “privacy policy,” believing it is a promise that the company asking for consent will protect the privacy of the one giving consent.

Robert Levine’s argument is also in parallel with Richards and Hartzog. He expressed that people must have understanding and autonomy before they can make informed choices. That said, a person must understand corporate practices and policies (including legal protection), surrounding the data that companies want to gather about users. A person must also believe that companies will give them the freedom to decide whether to give up their data and when, Levine said. If one of these isn’t satisfied, the consent to data collection “is involuntary, not free, and illegitimate.”

‘F’ for Fail

The study presupposes that in order to give consent, US consumers must satisfy two things: they must be informed about what is going to happen to their data, and they must have the ability to give (or withdraw) consent. To test these, 2,000 US survey participants are provided a set of 17 basic true/false questions about internet practices and policies. They can also answer “I don’t know,” the median option.

The overall survey results are worrying.

A majority (77 percent) of survey takers got nine or fewer correct answers out of 17 questions, which could be interpreted as an ‘F’ grade. Only one participant got an ‘A’ grade, scoring 16 correct answers. Below are the most notable insights from the results:

* Only around 1 in 3 Americans know it is legal for an online store to charge people different prices depending on where they are located.

* More than 8 in 10 Americans believe, incorrectly, that the federal Health Insurance Portability and Accountability Act (HIPAA) stops apps from selling data collected about app users’ health to marketers.

* Fewer than one in three Americans know that price-comparison travel sites such as Expedia or Orbitz are not obligated to display the lowest airline prices.

* Fewer than half of Americans know that Facebook’s user privacy settings allow users to limit some of the information about them shared with advertisers.

Furthermore, 80 percent of Americans believe Congress must act urgently to regulate how companies use personal information. Joseph Turow, one of the authors of the study, worries though that the longer the government waits to enforce change, the more difficult it will be to control user data.

“For about 30 years, big companies have been allowed to shape a whole environment for us, essentially without our permission,” Turow said. “And 30 years from now, it might be too late to say, ‘This is totally unacceptable.'”


We don’t just report on threats—we remove them

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.


[ad_2]
Source link

Samsung Galaxy S23 vs Google Pixel 7

0
[ad_1]

If you find the Galaxy S23 Ultra and Pixel 7 Pro to be too big for your liking, luckily they have smaller siblings. In this article, we’ll compare the Samsung Galaxy S23 vs Google Pixel 7. These are also flagship-grade smartphones, even though they are technically inferior to their larger siblings. To those of you who prefer more compact devices, these may be ideal alternatives, though.

As per usual, we’ll first list the spec sheets of the two smartphones, and will then move on to compare them across a number of categories. We’ll first compare their designs, and will then move on to displays, performance, battery life, cameras, and audio performance. There is a lot to talk about here, so… let’s get started.

Specs

Samsung Galaxy S23Google Pixel 7
Screen size6.1-inch fullHD+ flat AMOLED display (120Hz refresh rate, 1,750 nits peak brightness)6.3-inch fullHD+ flat AMOLED display (90Hz refresh rate, 1,400 nits peak brightness)
Screen resolution2340 x 10802400 x 1080
SoCQualcomm Snapdragon 8 Gen 2Google Tensor G2
RAM8GB (LPDDR5X)8GB (LPDDR5)
Storage128GB (UFS 3.1)/256GB (UFS 4.0)/512GB (UFS 4.0), non-expandable128GB/256GB, non-expandable (UFS 3.1)
Rear cameras50MP (f/1.8 aperture, 24mm lens, 1.0um pixel size, OIS, Dual Pixel PDAF)
12MP (ultrawide, f/2.2 aperture, 13mm lens, 120-degree FoV, 1.4um pixel size)
10MP (telephoto, f/2.4 aperture, 70mm lens, 1.0um pixel size, OIS, 3x optical zoom, PDAF)
50MP (Samsung ISOCELL GN1 sensor, 1.2um pixel size, f/1.85 aperture, 82-degree FoV, Super Res Zoom up to 8x)
12MP (ultrawide, 1.25um pixel size, f/2.2 aperture, 114-degree FoV, lens correction)
Front cameras12MP (f/2.2 aperture, 26mm lens, Dual Pixel PDAF)10.8MP (1.22um pixel size, f/2.2 aperture, 92.8-degree FoV, Fixed Focus)
Battery3,900mAh, non-removable, 25W wired charging, 15W wireless charging (Qi/PMA), reverse wireless charging
Charger not included
4,355mAh, non-removable, 21W wired charging, 23W wireless charging, reverse wireless charging
Charger not included
Dimensions146.3 x 70.9 x 7.6mm155.6 x 73.2 x 8.7mm
Weight168 grams197 grams
Connectivity5G, LTE, NFC, Bluetooth 5.3, Wi-Fi, USB Type-C5G, LTE, NFC, Bluetooth 5.2, Wi-Fi, USB Type-C
SecurityIn-display fingerprint scanner (ultrasonic)Face Unlock
In-display fingerprint scanner (optical)
OSAndroid 13
One UI 5.1
Android 13
Price$799/$849/TBA$599/$699
BuySamsungGoogle

Samsung Galaxy S23 vs Google Pixel 7: Design

Both of these phones are made out of aluminum and glass, though they both look and feel different. The Galaxy S23 has more rounded corners, and is actually considerably more compact than the Pixel 7. It is almost 10mm shorter, and over 2mm narrower than the Pixel 7. It’s also about a millimeter thinner. Unsurprisingly, the Galaxy S23 also weighs less at 168 grams, compared to 197 grams. None of that is surprising, as the Pixel 7 does include a noticeably larger display.

Both smartphones have flat displays, and a centered display camera hole. The bezels are quite thin on both phones, but the Galaxy S23 has uniform bezels, unlike Google’s phone. If we flip them around, you’ll notice that their camera modules look considerably different. The Galaxy S23 has three cameras in the top-left corner, which are vertically-aligned. These cameras protrude directly from the backplate. The Pixel 7, on the other hand, has a large camera strip on the back, which is covered by aluminum, and hides two cameras on the inside.

Both of these smartphones are quite slippery, so using a case may be a good idea. They do feel quite premium in the hand, though. The Galaxy S23 is much easier to use with one hand, due to its smaller footprint. Both smartphones do offer IP68 certification for water and dust resistance. That will give you some peace of mind, that’s for sure.

Samsung Galaxy S23 vs Google Pixel 7: Display

The Samsung Galaxy S23 features a 6.1-inch fullHD+ (2340 x 1080) Dynamic AMOLED 2X display. That panel is flat, and it offers a 120Hz refresh rate. It supports HDR10+ content, and it also gets quite bright at 1,750 nits of peak brightness. This panel has a 19.5:9 aspect ratio, and it is protected by the Gorilla Glass Victus 2. The screen-to-body ratio is higher here than on the Pixel 7.

google pixel 7 AM AH 10 1

The Google Pixel 7, on the other hand, has a 6.3-inch fullHD+ (2400 x 1080) AMOLED display. This panel is also flat, and it offers a 90Hz refresh rate. It also supports HDR10+ content, and gets up to 1,400 nits of peak brightness. We’re looking at a 20:9 display aspect ratio here, and the Pixel 7’s panel is protected by the Gorilla Glass Victus.

So, the Galaxy S23’s display does look better on paper, and it actually is in real life. The vast majority of you really won’t care about the differences, though. Both panels do offer great viewing angles, vivid colors, deep blacks, and are more than sharp enough. The Galaxy S23 does have an edge in smoothness, due to its higher refresh rate, and it also gets noticeably brighter in direct sunlight. Those are two of its major advantages. The touch response is really good on both phones.

Samsung Galaxy S23 vs Google Pixel 7: Performance

The Galaxy S23 is fueled by the Snapdragon 8 Gen 2 SoC in all markets. Samsung opted not to use its Exynos chip this time around. The phone includes 8GB of LPDDR5X RAM, and either UFS 3.1 or 4.0 flash storage. Do note that only the 128GB base storage model has UFS 3.1 storage. The Pixel 7, on the other hand, is fueled by the Google Tensor G2 SoC, Google’s second-gen smartphone chip. The phone comes with 8GB of LPDDR5 RAM and UFS 3.1 storage in both its 128GB and 256GB storage flavors.

When it comes to regular, everyday performance, both phones do a great job. They can open and close apps really fast, the same goes for multitasking. They’re great for browsing, consuming multimedia, and various other actions. They’re buttery smooth in all those aspects. The differences do become obvious when it comes to gaming, though. The Galaxy S23 is the better phone for gaming out of the two. The Pixel 7’s Tensor G2 chip is not made for gaming, and Google never claimed it will. It will do good with most games, but if you fire up the most demanding games you can find, it may struggle.

Samsung Galaxy S23 vs Google Pixel 7: Battery

The Samsung Galaxy S23 sports a 3,900mAh battery on the inside. The Pixel 7, on the flip side, has a 4,355mAh battery. So, how do they compare, battery-wise? Well, first and foremost, the Galaxy S23 does offer considerably better battery life than the Galaxy S22, which was really bad in that regard. It’s around 25% better, if we had to give you a ballpark improvement. It’s not yet as good as some other flagship phones are, but it will be more than good enough for most people.

You should be able to get over 5 hours of screen-on-time on the Galaxy S23 (maybe even considerably more), though that will all depend on your usage, what apps you have installed, location, and so on. The Pixel 7 does include a larger battery, and combined with its chip and lower screen refresh rate, it does manage to offer more in the battery department. Getting around 6-7 hours of screen-on-time is possible with the Pixel 7. Even more than that, at times. Your mileage may vary, of course.

When charging is concerned, they both offer both wired and wireless charging. The Galaxy S23 supports 25W wired, 15W wireless, and 4.5W reverse wireless charging. The Pixel 7 supports 20W wired, 20W wireless, and 5W reverse wireless charging. Do note that both smartphones come without a charger in the box, though.

Samsung Galaxy S23 vs Google Pixel 7: Cameras

The Samsung Galaxy S23 features three cameras on the back. It includes a 50-megapixel main camera, a 12-megapixel ultrawide unit, and a 10-megapixel telephoto camera. The Pixel 7 has two cameras on the back, a 50-megapixel main unit, and a 12-megapixel ultrawide camera. A 12-megapixel selfie camera sits on the front side of the Galaxy S23, while a 10.8-megapixel unit can be found on the front side of the Pixel 7.

google pixel 7 AM AH 08 1

The camera results these two phones provide are entirely different. The images from the Galaxy S23 are a lot warmer, while the Pixel 7 provides cooler-looking images. The Pixel 7 also offers those contrasty images that we’re used to seeing from Pixel phones in general. Truth be said, the Galaxy S23 camera results are noticeably better than what the Galaxy S22 offered. The images are sharper, and balanced better at the same time. The Pixel 7 is still the king of dynamic range, though.

The same can be said for both daylight and nighttime images, you’ll notice the difference in color temperature, but both phones do a great job. I’d still take the Pixel 7 for still, mainly due to the overall look of Pixel images, excellent dynamic range, and the way the phone makes those sunset photos look. As I said, though, the Galaxy S23 is a considerable improvement over the Galaxy S22. Depending on the scene, it can beat the Pixel 7, especially if you love those warmer tones. Its images even end up being sharper in low light most of the time, though a bit too yellow at times. The telephoto results are better from the Pixel 7, without a doubt, while the ultrawide camera performance tries to be in line with the main cameras, though it’s a step below in both cases.

Selfies do end up looking a bit more lifelike on the Galaxy S23, and also warmer at the same time. The Pixel 7 provides more contrasty selfies, so in line with the rear cameras, actually. The video performance is good on both devices, but also quite different. It all depends on what you prefer, but both provide good, stable shots.

Audio

Both the Galaxy S23 and Pixel 7 include a set of stereo speakers. What they do not have is an audio jack. Those speakers sound good on both phones, as good as you’d expect. There are better speakers out there for sure, but these do get both loud enough and detailed enough. Not many people will have complaints.

When it comes to headphones, you can either hook them up with a Type-C port on either phone, or utilize Bluetooth. The Galaxy S23 is equipped with Bluetooth 5.3, while the Pixel 7 includes Bluetooth 5.2 support.


[ad_2]
Source link

Huawei Dynamic Island feature might launch with the Nova 11 series

0
[ad_1]

Apple set a trend with Dynamic Island, and Huawei might borrow this idea. The Chinese tech giant might be working on its own Dynamic Island feature. This is said to be a bit different from that which Apple debuted with the iPhone 14 Pro series.

Regardless, it is obvious that Huawei is going to take inspiration from the iPhone 14 Pro series. This inspiration will help them develop their version of the Dynamic Island feature. But what are the details regarding this coming feature that is coming to Huawei devices?

Apple’s iPhone 14 Pro series will inspire the Huawei Dynamic Island feature

After years of sticking to the notch design, Apple finally decided to try something new. With their iPhone 14 Pro series launched last year, the company introduced what they call Dynamic Island. This feature adds functions (media controls, notifications, and so much more) to the center pill front-facing camera cutout.

After Apple released this feature, other smartphone manufacturing companies like Xiaomi and Honor adopted the pill-shaped center selfie camera cutout. But none of these companies added any functions to the pill-shaped cutout. Now, Huawei is stepping up to introduce its own Dynamic Island feature.

According to the available reports, this feature will make an appearance with the Nova 11 series. Some devices in this series from Huawei will use a pill-shaped selfie camera cutout. Since this series will run on HarmonyOS it will be easy for Huawei to integrate features into the pill-shaped selfie camera cutout.

In-depth details on this coming feature are not available at this moment. But the Huawei Nova 11 series is expected to launch in the coming months. Asides from the Huawei Dynamic Island feature, this series might also spot the XMAGE photography system. Details on this device will become available as its launch date draws closer.

Once available, this feature will attract lots of attention from the smartphone community. Other brands might also adopt the Dynamic Island feature on their devices. One company that might give this feature a try is Xiaomi with their coming flagship series.


[ad_2]
Source link

WhatsApp adds new features to your status updates

0
[ad_1]

Although an app with a very large and broad user base, WhatsApp can still leave a lot to be desired when it comes to its features. Competing apps such as Signal and Telegram have, for years, outshined the Meta-owned application in that respect; However, WhatsApp is now stepping things up and adding a set of new features to the status section.

WhatsApp announced via a blog post that the company will be adding more options to the status section of the app, which is often used to convey fleeting information with friends and close contacts. These statuses are available for 24 hours and can contain a variety of media, including photos, videos, animated GIFs, etc. Here’s a summary of the new features you can expect:
  • Private Audience Selector: Every status update you post might not be appropriate for all of your contacts all of the time, so WhatsApp will now have the ability to update your privacy settings on a per-status basis so that you can choose who sees each new version of the status that you post. The audience that you most recently selected will be remembered and used as the default for your subsequent status update.
  • Voice Status: You will soon be able to record and share voice messages on WhatsApp status that are up to 30 seconds long. Voice status allows for the sending of more personal updates, which is especially useful if you find that expressing yourself verbally rather than through typing is more comfortable for you.
  • Status Reactions: You can now respond to any status in a flash by swiping up and selecting one of eight different emojis from the menu that appears. It goes without saying that you can still respond to a status update with a text message, voice message, stickers, or any number of other options. Status reactions have been one of the most requested features since the debut of Reactions a year ago. 
  • Status Profile Rings for New Updates: When a contact of yours shares an update to their status, a ring will appear around their profile picture. This will be viewable in the chat lists, the participant lists for groups, as well as the contact information, thus making it easier to never miss a status update from a friend or family member again.
  • Link Previews on Status: When you send a message or post a link on your status, you will now see an automatic visual preview of the message or link’s content, just as you do when you send a message. Visual previews not only improve the appearance of your status updates but also provide your contacts with a clearer picture of the content of the link before they choose to click on it.
These updates have begun to be made available to users all over the world, and they will be accessible to absolutely everyone in the coming weeks. As usual, just like your personal chats and calls, your WhatsApp status is protected by end-to-end encryption so that you can share in a private manner without compromising your safety.

[ad_2]
Source link

Hackers Aim at Crypto Wallets with Hacked Namecheap Phishing Emails

0
[ad_1]

Namecheap users should remain cautious, as hackers are using its inbox to scam users through phishing emails designed to appear as if they were sent from DHL or MetaMask cryptocurrency hot wallet.

For your information, Namecheap is a popular domain name registrar with more than 15 million domains issued thus far.

According to the company, the incident may have occurred due to a supplier-related issue. Namecheap released its official statement regarding the hack on Sunday, confirming that its upstream system was abused to send out malicious emails.

This means a third party is involved in “mailing unsolicited emails to our clients.” “As a result, some unauthorized emails might have been received by you,” the statement read.

The DHL emails inform the recipient that they need to pay a delivery fee for receiving their parcel, whereas the MetaMask email urges the recipient to complete the Know-Your-Customer (KYC) process. The email then warns victims that if the due process is not completed, they may lose access to their wallets.

Namecheap Watch: Hackers Targeting Employees with DHL Phishing
Screenshot of the phishing email shared by a Twitter user @h4x0r_dz

MetaMask took to Twitter to ensure that it doesn’t collect KYC information and would never send an email to get details of its users’ accounts. Hence, the company suggested that users shouldn’t enter the Secret Recovery Phrase on any website server and ignore any emails from Namecheap or MetaMask.

Namecheap assured its customers that its internal systems weren’t breached and that their personal information and account-related data were secure. However, the company has urged customers to avoid clicking on any links.

The company stated that it has temporarily suspended all emails. This includes emails delivering authentication codes, password resetting, and verifying trusted devices.

“We are glad to let you know that the mail delivery has been restored, so you should receive emails from Namecheap as usual from now on,” Namecheap CEO, Richard Kirkendall, confirmed. However, the CEO didn’t name the upstream system that was compromised. 

Speculation is rife that it could be SendGrid’s email delivery service. However, it is worth noting that the third party has denied being compromised. Twilio, which owns SendGrid and got hacked last year, said that the incident isn’t a result of a compromise of the Twilio network, but they are investigating it and will provide additional details over time.

  1. PayPal Notifies 35,000 Users of Data Breach
  2. Geo Targetly URL Shortener Abused in Phishing Scam
  3. Reddit Hacked After Employee Bites on Phishing Scam
  4. Sophisticated SMS Phishing scam Dupes Zendesk Staff
  5. Scammers Using Microsoft Team GIFs in Phishing Scam

[ad_2]
Source link

Proof that the tablet is not dead

0
[ad_1]

The tablet market is in a really tough spot now, and that leads people to think that manufacturers have put less effort into their tablets. While the market is overrun with cheapo tablets you can get at Walmart, companies like Samsung and Apple continue to pour heart and soul into producing their flagship tablets. However, it’s not just about them. Lenovo also makes its line of premium tablets.

Android Headlines had the opportunity to review the Lenovo Tab P11 Pro. This is a premium tablet from Lenovo, and it promises to bring a top-notch Android tablet experience. Is this tablet worthy competition to the likes of Samsung and Apple, or does it fall flat? Let’s find out in this review.

Lenovo Tab P11 Pro: Build quality and design

When you pick up this tablet, nothing about it screams cheap. Everything from the front panel to the frame is made from high-quality materials. When you grab the device, you know you’re picking up a quality piece of hardware. It’s not extremely heavy, but it does have a decent amount of heft to it, which is reassuring.

Lenovo Tab P11 Pro 9

The tablet has a two-tone glass back panel that feels great to the touch. However, it can be rather slippery. The two-tone glass gives it a nice appearance and is rather elegant. The back of the tablet is pretty bare-bones with a small camera package occupying the top right corner. Other than that, the back is pretty bare-bones with the exception of the Lenovo branding on the top left.

The Lenovo Tab P11 Pro has a thick metal frame that keeps everything together. That frame houses the power and volume buttons, the four speakers, the SIM card tray, the microphones, and the USB-C charging port. It’s a very good-looking tablet, but it does not have a headphone jack, unfortunately.

Overall, this is a very snazzy and sleek-looking device with top-notch build quality. You will not feel like you’re grabbing a cheap device at all.

Lenovo Tab P11 Pro: Display

Moving on to the display, the Lenovo Tab P11 Pro has a nice 11.5-inch display with a resolution of 1600 x 2560. This puts the resolution at above 1440p, and that’s great if you want to watch high-definition content. Along with the pixel density, this display has the benefit of being an OLED display. This means that you’ll get punchier colors than with an LCD display. Also, the contrast is amazing with inky blacks.

I will say that, while the display is nice, it feels a few steps behind that of a Samsung display. Sure, the colors are punchy and it has great contrast, but it’s not much better than that of a high-quality LCD display. For example, it’s quite similar to the LCD display on the Honor Pad 8.

It’s not bad by any stretch of the imagination, but it’s not exactly jaw-dropping. It’s a really good display, and you’ll enjoy watching content on it.

Lenovo Tab P11 Pro 11

One thing the display has going for it is the fluid 120Hz refresh rate. Another good aspect of the display is the brightness. It can get plenty bright, and that means great sunlight visibility. If you happen to take this tablet outside, you’ll have no issue using it in the sun.

The display sits within some appropriately-sized bezels. These give you enough room to place your thumbs without interfering with the screen.

Lenovo Tab P11 Pro: Speakers

If it’s any department that can be better, it’s definitely the speaker department. The Lenovo Tab P11 Pro comes with a set of four speakers, and they flank the device when you hold it in landscape mode. For starters, they are definitely loud. They get loud enough to fill a room, so if you’re watching content, you will have no issue hearing it.

However, the quality of the speakers is nothing to write home about. Tablet speakers aren’t quite the replacement for Bluetooth speakers, but they usually come with a fair amount of depth. The speakers on though on the Lenovo Tab P11 Pro don’t have much depth to them. They’re not quite immersive.

Lenovo Tab P11 Pro 7

There is a respectable amount of bass, but it sadly doesn’t add much depth to the sound. Also, the higher frequencies definitely suffer. I say that the speakers are better suited for movies and TV shows. However, when it comes to music, you will definitely hear the lack of speaker quality.

Lenovo Tab P11 Pro: Performance

I had no issues with performance while using this tablet. You’ll be able to fly through the UI smoothly and without any stuttering. Of course, the typical tasks like browsing the web, going through social media, and writing were no issue at all. I have no complaints about the performance.

Gaming

When it comes to gaming, the story is much the same. For starters, 2D games are no problem at all. The tablet ran them all perfectly smoothly. As for 3D games, I also had a pretty good experience. Graphically intensive games such as Sky: Children Of Light ran perfectly. Also, games such as Dragon Ball Legends had no issues.

Lenovo Tab P11 Pro 6

But, what about the big fish? I ran Genshin Impact on this tablet and, the story was not really the same. Using the game’s normal graphic settings, it lagged and stuttered a lot. I had to turn the graphics down to it their lowest settings. After that, the game ran perfectly smoothly. My guess is that the motion blur effect kept it from running smoothly. So, you’ll be able to play most titles smoothly with the exception of the top-tier games.

Lenovo Tab P11 Pro: Battery

The Lenovo Tab P11 Pro has pretty decent battery life for a tablet. I ran it through the battery test which consisted of two hours of video watching, 2 hours of gaming, and 2 hours of social media, and the tablet lasted about 5 hours and 51 minutes before calling it quits. That’s not too bad, especially if you’re going to be using your tablet sparingly. You shouldn’t worry too much about bringing this tablet out for a workday.

If you do need to charge the tablet, you can charge it from 0 to 100% in about 2 hours and 14 minutes. That’s definitely a while, but not too bad when it comes to tablets.

Lenovo Tab P11 Pro: Software

This tablet’s software ss pretty close to stock Android. You have the Material You flare with the round and bubbly aesthetic. The notification shade and quick settings are a mirror image of what you will get on a Pixel Device. However, Lenovo did manage to add its own influence into the software in several locations.

For starters, the wallpaper picker is very different. What’s unfortunate is that you have less customization options for the dynamic theming. Also, the system settings have their own flair as well. If you want a more familiar stock Android aesthetic, this tablet does a fair job of bringing Google’s familiar software aesthetic and mixing it with its own flare.

Lenovo Tab P11 Pro 12

One of the features that stuck out to me was the Productivity Mode. This basically turns the tablet into a desktop computer. It will disable the swipe gestures, and there will be a small task bar at the bottom with your currently open apps, navigation buttons, status bar, and shortcut to access your apps.

Also, when you open an app, it will open as a floating window. This means that you’ll be able to open multiple apps at the same time and use them side-by-side. This is perfect if you’re trying to get serious work done, and it works well on the tablet.

Lenovo Tab P11 Pro: The pen

One of the most spectacular features of this tablet is the stylus support. This puts it in closer competition with the Galaxy Tabs from Samsung. Lenovo provided a Lenovo Precision Pen 3 to test on the tablet, and it works amazingly. It’s not merely a stylus, it’s a connected device. This means that the tablet can detect the pen even when it’s not making contact with the display. Also, there is an action button on the stylus that can perform different tasks.

As for the precision, it’s also top-notch. As you’d expect, this tablet comes with a built-in suite of note-taking applications. Using them, I felt that the pen was extremely accurate. Also, it is pressure-sensitive. This means that if you want to use this tablet for art, you will have a very natural experience.

Lenovo Tab P11 Pro 2

The pen pairs to your tablet and charges by attaching magnetically to the back. And, it does not take long to charge.

Lenovo Tab P11 Pro: Conclusion

Lenovo did a fantastic job with this tablet. Everything from the design to the software just screams quality, and it performs exceptionally well. You will have no issues with this tablet as your work device, especially if you like to draw or sign documents. The screen is really nice, but the speakers could definitely use some work. Also, you should have no issues using this as your main gaming device.

You should buy this tablet if you

  • Want to game on It
  • Want to use it for art
  • Want to use it for business
  • Want a tablet with a quality build
  • When a tablet with a great stylus experience
  • When a tablet with a nice display
  • Want a tablet with a near-stock Android experience

You shouldn’t buy this tablet if you:

  • I want the best audio experience

[ad_2]
Source link

Multiple 0-Day Attacks in The PyPI Packages

0
[ad_1]
PyPI Packages

Recently, the FortiGuard Labs team made a groundbreaking discovery of several new zero-day attacks in the PyPI packages. The source of these attacks was traced back to a malware author known as “Core1337.” This individual had published a number of packages.

Here below we have mentioned the packages that are published by Core1337:-

  • 3m-promo-gen-api
  • Ai-Solver-gen
  • hypixel-coins
  • httpxrequesterv2
  • httpxrequester

Between the 27th of January and the 29th of January 2023, these attacks were published. The recent discovery made by the FortiGuard Labs team revealed that each of the packages published by the malware author “Core1337” had only one version with an empty description. 

However, what was alarming was the fact that all of these packages contained similar malicious code. This raises the question of the level of sophistication and the intentions behind these attacks. 

Technical Analysis of the Packages

First of all, cybersecurity analysts have noticed something that looks like a URL for a webhook in its setup[.]py file:-

  • hxxps://discord[.]com/api/webhooks/1069214746395562004/sejnJnNA3lWgkWC4V86RaFzaiUQ3dIAG958qwAUkLCkYjJ7scZhoa-KkRgBOhQw8Ecqd

There is a similar code in each package’s setup.py file except for the URL of the webhook that is sent from each package. It appears that the URL in question may have a connection to the infamous “Spidey Bot” malware. 

This particular strain of malware is notorious for its ability to pilfer personal information via Discord, as highlighted in a recent blog post by the organization. The blog, entitled “Web3-Essential Package,” delves into the dangers posed by the “Spidey Bot.”

Experts in the field have discovered potential malicious behaviors in a recent static analysis that was conducted by reviewing the setup.py script. During this process, the experts meticulously examined the code and were able to identify several key indicators that point toward malicious intent.

Experts in the field of malware analysis have gained a general understanding of the behavior of a particular strain of malware by carefully examining its primary function. 

According to their findings, this malware may attempt to extract sensitive information from various browsers and the Discord platform and then store it in a file for later exfiltration.

In order to gain a better understanding of the inner workings of this piece of malware, experts have focused their attention on the “getPassw” function. This function is specifically designed to gather user and password information from the browser and then save it to a text file.

The malware has a self-proclaimed title of “Fade Stealer,” which it prominently displays in the form of its name being written at the top of its accompanying text file.

As for its ‘getCookie’ function, the behavior is similar to the one seen in its other functions. Based on the functions of “Kiwi,” “KiwiFile,” and “uploadToAnonfiles,” it appears that the malware is programmed to scan specific directories and select specific file names for the purpose of transferring them through a file-sharing platform:- 

All these packages have one thing in common – they possess similar codes that are created for the purpose of launching attacks. While all these packages may have different names, the underlying intention and code structure is the same, which indicates the work of a single author.

Network Security Checklist – Download Free E-Book


[ad_2]
Source link