Raindex Launches On Flare To Power Decentralized CEX-Style Trading

0
[ad_1]

Flare, the blockchain for data, has announced the launch of the Raindex desktop app: a new intents-like DEX that uses the Flare Time Series Oracle (FTSO) to offer the advanced trading operations of centralized exchanges. Users can now set bid and offer prices, activate stop loss and take profit mechanisms, and replicate other traders’ strategies in a trustless, fully-permissionless, decentralized way, on-chain.

The Raindex app utilizes the intuitive Rainlang smart contract language, giving anyone the ability to design, write, deploy and manage customized token trading strategies, while leveraging Flare’s native decentralized price oracle, the FTSO, for reliable and secure asset price triggers.

Raindex achieves this with an intents-like architecture. Users can specify their desired trade outcomes without needing to define how the trade is fulfilled, potentially setting up multiple future trades as part of a strategy deployed in a single transaction. Anybody can then perform the trades on behalf of users, within the constraints of the pre-defined strategy.

For instance, a user can write a strategy to sell assets at a set price triggered by the Flare Time Series Oracle. Under the hood, Raindex facilitates this trade by acting as a matching venue for buyer and seller intents. This frees users from manual order placement and constant market monitoring.

Trusted Real-Time Asset Price Data

The culmination of more than three years of dedicated development, Raindex blends the most compelling advantages of both CEXs and DEXs into a single platform, allowing users to craft and execute Rainlang strategies without intermediaries. It provides a CEX-like trading experience with enhanced DEX-style autonomy and security, so users no longer have to give up control of their digital assets. 

The platform will take advantage of FTSOv2’s new “Fast Updates” capability that delivers asset prices every block (1-2 second intervals), secured by Flare’s novel architecture, guaranteeing both price accuracy and censorship resistance.

Flare offers a unique trust model for the enshrined oracles on their network as the data integrity is secured by the validators themselves. An extension of Rainlang on Flare enables FTSO data to be leveraged for trading strategies, enhancing market responsiveness while eliminating the reliance on third-party, off-chain data oracles.

Josh Hardy, Co-founder of Rain, commented: “Secure, reliable data is an indispensable part of the toolkit for anybody writing trading strategies. We’re super excited to introduce Rainlang and Raindex into Flare’s ecosystem, connect with the DeFi community and see what they create!”

Enhanced Trading Without Intermediaries

Rainlang is an innovative new programming language that’s designed to be simple to read and write. Anyone who can read and write Excel formulas can easily learn to create smart contracts using Rainlang.

Traders will be able to implement their customized strategies, including, but not limited to, dollar-cost averaging (DCA), stop losses, Dutch orders, portfolio rebalancing, market-making liquidity management and trend tracking. 

With the ability to set bids and asks, stop loss, take profit triggers, and copy trade vaults, the platform moves beyond traditional Automated Market Maker (AMM) models, offering unparalleled trade expression freedom with full on-chain execution.

“The recently announced upgrades to the Flare Time Series Oracle will enable up to 1,000 asset prices to be delivered on-chain every second or so, without sacrificing decentralization or security. Combine this with Rain’s intents-like DEX and you enable much of the functionality of a centralized exchange but without the risk of needing to custody your assets with a third party,” said Hugo Philion, Flare Co-founder and Flare Labs CEO. 

The comprehensive Raindex desktop app provides an all-encompassing set of tools for traders to devise and write their strategies, with the ability to simulate its performance before deploying it on-chain. Users can simply express what they want using Rainlang, deposit their tokens into vaults and then deploy their order when the time is right, with Raindex’s app providing real-time performance monitoring. 

To celebrate its launch on Flare and entice the community to show off its trading skills, Raindex is staging a trading contest that will run throughout May 2024, with a total prize pool of $12,000 available for those who can create the most profitable trading strategies using Rainlang. 

About Flare 

Flare is the blockchain for data: an EVM smart contract platform specifically designed to support data-intensive use cases, including Machine Learning/AI, RWA tokenization, gaming and social. With decentralized, enshrined oracles secured at the network layer, Flare is the only smart contract platform optimized for decentralized data acquisition – price & time series data, blockchain event & state data, and web2 API data. By giving developers trustless access to the broadest range of data and data proofs at scale and for minimal cost, Flare expands the utility of blockchain and supports the development of new and improved use cases.

About Raindex

Rainlang is DeFi’s native language on EVM. Entirely on-chain, it promotes accessibility and decentralization by making smart contracts easier to read and write. Raindex, leveraging Rainlang, introduces a new DEX concept where orders are smart contracts, enabling complex, algorithmic trading strategies to be created and executed on-chain. Rain’s mission is to foster innovation and inclusivity in smart contract development and DeFi.

  1. Could Bitcoin Be The Future Of DeFi?
  2. We Need Smarter Smart Contracts To Prevent DeFi Hacks
  3. Blockchain in Identity Management: Securing Personal Data

[ad_2]
Source link

Google Pixel 9 references spotted in Google app

0
[ad_1]

The Google Pixel 9 references have been spotted in the Google app. The news comes from AssembleDebug, who shared the news via The SP Android. Those references were found in the latest Google app beta build, version 15.14.34.29.

The Pixel 9 references end up being spotted in the Google app

The source shared two files that reference the Pixel 9, actually. One of them has an amination file that will likely appear on the upcoming Pixel 9. You can check out both files below, there’s really nothing to write home about here.

Pixel 9 references Google app beta

These are clear Pixel 9 references, and you can see the animation that is expected to appear below this paragraph. It’s kinda nice, but there’s nothing much to talk about here, to be quite honest.

Pixel 9 animation Google app beta

The ‘Pixie’ assistant was not mentioned

The source also notes that there’s no indication of the ‘Pixie’ assistant anywhere in the app. As some of you may know, the ‘Pixie’ assistant was mentioned a while back. That is supposed to become an AI assistant exclusive to Pixel devices. We don’t know much about it, though.

Now, Google is actually expected to deliver three Pixel 9 devices this year. The entry-level model will be called the Pixel 9, while the standard two models will be the Pixel 9 Pro and Pixel 9 Pro XL.

The Pixel 9 Pro and Pixel 9 Pro XL are here to replace the Pixel 8 and Pixel 8 Pro, it seems. The Pixel 9 is a new addition to the lineup, and no, that’s not the Pixel 8a. That’s a completely separate device that will likely arrive next month during Google I/O.

All three Pixel 9 smartphones, on the other hand, are expected to arrive in early October, during Google’s Pixel event. We’re only guessing that’s when it will take place, of course, Google could change its mind and move it to September.


[ad_2]
Source link

ChatGPT was credited at the end of a TV show

0
[ad_1]

Well, it was going to happen eventually; AI technology being used and an industry-level position. According to a new report, ChatGPT was credited at the end of a TV show.

At this point, generative AI technology has become so advanced that it’s scary. It’s able to produce books, scripts, etc., and it’s able to do so with a level of proficiency. Many people working on smaller productions fear that they will easily be booted out in lieu of an AI chatbot. However, one of our main fears is that AI technology will start to make it to professional-level productions like Hollywood movies.

In fact, OpenAI actually showed off Sora, the company’s AI video generator, to Hollywood directors and studios. So, there’s no telling if we will see AI-generated video clips in the next big blockbuster.

ChatGPT was credited at the end of a TV show

The Indian Telugu-language comedy-drama series “Save the Tigers” just ended its second season. This is a TV series that’s hosted on Disney+ Hotstar. In the end credits, under the music team section, we see that ChatGPT was credited for writing the club song lyrics.

ChatGPT credit

Obviously, ChatGPT’s involvement in the show is a bit divisive. Half of the community is disappointed in the show for using AI technology, and the other half gives the show props for its transparency.

While the company did use AI technology in the production of the music, it’s far from the dystopian future we fear where an entire movie soundtrack is generated via AI. There is only one credit to ChatGPT in the music section, but this credit is surrounded by 20 credits from human contributors. So, the music of this show is primarily a human production.

This is still a problem

Regardless, it’s still a bit off-putting that a show with a high production value such as Save The Tigers needs to use ChatGPT at all. While we don’t know the financial situation of the studio that made it, it seems odd that the company could not spare the money to hire a lyricist for one song.

This is the sort of thing that makes people fear AI technology. When creators start their careers, many of them dream of being involved in high-level productions like these. However, now that AI tools are making their way to professional productions, many of those jobs will start to dry up just because studios want to save money.


[ad_2]
Source link

Google Adds V8 Sandbox To Chrome To Fight Against Browser Attacks

0
[ad_1]

A Sandbox is a protective medium that blocks the entire system from any application accessing vulnerable resources. 

Restrictive environments for web content in browsers called sandboxes reduce the impact that can be caused by browser-based attacks such as malicious programs or infected scripts. 

This helps limit, to some extent, the damage attackers can do to the user’s device or data.

After years of development, the V8 Sandbox—a lightweight, in-process sandbox for the V8 JavaScript engine—has advanced enough to be included in Chrome’s Vulnerability Reward Program, marking an important step towards becoming a strong security boundary. 

Google Adds V8 Sandbox

After years in development, the V8 Sandbox – a lightweight, in-process sandbox for V8 JavaScript engine – has advanced enough to be included in Chrome’s Vulnerability Reward Program, marking an important step towards becoming a strong security boundary. 

Though issues remain before full enforcement, Chrome 123 represents a “beta” release showcasing how the sandbox prevents V8 memory corruptions from spreading within the host process.

When number conversion is performed as part of user-defined callbacks, there might be some hidden vulnerability.

Document
Stop Advanced Phishing Attack With AI

Trustifi’s Advanced threat protection prevents the widest spectrum of sophisticated attacks before they reach a user’s mailbox. Stopping 99% of phishing attacks missed by other email security solutions. .

However, this demonstrates why modern JavaScript engines are usually attacked by flawed logic rather than memory corruption-style bugs. 

Consequently, memory-safe languages could help in preventing such problems from happening within handwritten runtime code but do nothing to prevent logic bugs due to optimized JIT compilers generating unsafe code.

The inter-object corruption detection in V8 has no space for tag bits because of pointer compression.

While some specific applications have proven their efficiency, they do not work effectively with complicated logic bugs in JavaScript engines.

Using the sandbox approach like in operating systems where there is a separation between user and kernel allows the use of V8’s memory isolation for preventing potential exploits.

However, the current software-based sandbox does not allow memory access outside of the vulnerable data types as it replaces them.

To create a read/write primitive, the attacker has to manipulate either the size or buffer pointer. 

Outcomes (Source – V8)

With the sandbox active, assuming the buffer resides within, the object is transformed to include a sandbox_ptr_t offset and a sandbox-compatible size. 

Sandbox design (Source – V8)

In contrast, if the buffer is external, the object changes with an external_ptr_t that references the buffer through pointer table indirection like those in memory safety mechanisms such as Unix kernels’ file descriptor table or WebAssembly.Table.

The published post states that the V8 Sandbox, which can be enabled or disabled by the v8_enable_sandbox flag, has to use a 64-bit system at build time because it reserves one TB of virtual address space.

For the past two years, Chrome versions have supported it by default to ensure stability and gather performance data.

These had to be bypassed in recent exploits, providing early security feedback.

The current memory safety limitations are not being prevented by something, but this new mechanism prevents V8 memory corruption from affecting other processes required for optimizing the JavaScript engine.

Secure your emails in a heartbeat! To find your ideal email security vendor, Take a Free 30-Second Assessment.


[ad_2]
Source link

91,000 Smart LG TV Devices Vulnerable to Remote Takeover

0
[ad_1]
91,000 LG TV Devices Vulnerable to Remote Takeover

Cybersecurity researchers from Bitdefender discovered critical vulnerabilities in LG TVs running webOS versions 4 through 7. These vulnerabilities could allow attackers to gain complete control over the TV, steal data, or install malware.

The vulnerabilities were identified by Bitdefender as part of their research into the security of popular IoT devices. They found that attackers could bypass authentication mechanisms and create new user accounts with elevated privileges. This would allow them to take full control of the TV, including injecting malicious code, stealing data, or moving laterally across the smart home network.

Bitdefender responsibly disclosed the vulnerabilities to LG in November 2023. LG confirmed the vulnerabilities in November and released a patch in March 2024. However, Bitdefender waited until today, April 9th, 2024, to publicly disclose the details of the vulnerabilities to raise awareness among users and encourage them to update their TVs.

What LG TV models are affected?

The following LG TV models are affected by these vulnerabilities:

  • LG TVs running webOS 4.9.7 – 5.30.40 (e.g., LG43UM7000PLA)
  • LG TVs running webOS 5.5.0 – 04.50.51 (e.g., OLED55CXPUA)
  • LG TVs running webOS 7.3.1-43 (mullet-mebin) – 03.33.85 (e.g., OLED55A23LA)
  • LG TVs running webOS 6.3.3-442 (kisscurl-kinglake) – 03.36.50 (e.g., OLED48C1PUB.

The first vulnerability, identified as CVE-2023-6317, permits attackers to bypass the authorization mechanism, enabling them to add users to the TV set by manipulating a specific variable.

In a subsequent step, attackers can exploit another vulnerability (CVE-2023-6318) to escalate their access privileges to root, effectively gaining full control over the device.

Furthermore, a third vulnerability (CVE-2023-6319) allows for operating system command injection by tampering with a library responsible for displaying music lyrics. Lastly, the CVE-2023-6320 vulnerability enables attackers to inject authenticated commands through manipulation of the API endpoint.

Most Impacted Countries

A glimpse into Shodan, the search engine designed to uncover misconfigured and exposed Internet of Things (IoT) devices, reveals the most impacted countries in terms of smart device vulnerabilities. South Korea leads the list of 91,938 exposed devices, followed by Hong Kong and the United States in second and third place, respectively.

LG TVs Vulnerable to Critical Attacks, Patch Available
Screenshot: Bitdefender

What should LG TV owners do?

LG released a patch to address these vulnerabilities in March 2024. LG TV owners should update their TVs to the latest software version as soon as possible. You can usually check for updates in the TV’s settings menu.

  1. Say Hello to Ransomware Targeting Smart TV
  2. Hacker Shows How Smart TVs Can Be Remotely Hacked
  3. Critical Vulnerability Found in Samsung’s Tizen-based Smart TV
  4. LG Smart TV Screen Bricked After Android Ransomware Infection
  5. Smart TVs make screenshots every second, send them to the server

[ad_2]
Source link

TikTok takes aim at Instagram with new TikTok Notes app

0
[ad_1]

TikTok is ready to take on Instagram in photo sharing with its new app, TikTok Notes. The company sent out a notification to users, informing them that it would soon be rolling out this new app focused on photo posts. Users’ existing public photo posts on TikTok would be shared in TikTok Notes by default. However, they will be able to opt out of having their images shared on the new platform.

When TechCrunch investigated further, it discovered a temporary website at photo.tiktok.com that showed what the TikTok Notes interface might look like. It appeared that users would be able to upload photos and write captions to accompany their images. This suggests that TikTok Notes is aiming to compete directly with the Meta-owned app.

TikTok Notes targets Instagram with automatic profile imports

In a statement, a TikTok spokesperson confirmed that the company is “exploring ways for creators to showcase photos and text” within its ecosystem. However, they did not provide a timeline for the launch. This is in line with earlier findings from the Android app code, which indicated that TikTok was working on a standalone “TikTok Photos” app last month.

This app was first discovered via an APK deep dive into the latest version of the app. Version 33.8.4 of the TikTok app contained notes that hinted at an app called TikTok Photos. But newer signs suggest it will be called TikTok Notes.

What is Tiktok notes?
byu/killranker5 inTiktokhelp

Now, with in-app notifications and a temporary website, it’s clear that TikTok Notes could be the official name. By pre-populating the new app with users’ existing TikTok photos, TikTok Notes could quickly gain a large initial user base. By allowing it to transfer its audience from TikTok, TikTok Notes also has the potential to compete with Instagram.

Meanwhile, TikTok seems to be incentivizing creators to start posting horizontal videos that are over a minute long. Creators like @candicedchap and @kenlyealtumbiz have received such a request. In the prompt, TikTok says it will “boost” such videos within 72 hours of posting.


[ad_2]
Source link

Thousands Of Internet-Exposed Ivanti VPN Appliances Vulnerable

0
[ad_1]

In a recent cybersecurity revelation, Ivanti, a leading provider of enterprise-grade secure access solutions, has been found to have significant vulnerabilities in its VPN appliances.

The most critical of these, identified as CVE-2024-21894, is a heap overflow vulnerability that could potentially allow remote code execution (RCE) by unauthenticated attackers.

This vulnerability, along with others, poses a severe risk to thousands of internet-exposed Ivanti Connect Secure and Ivanti Policy Secure Gateways.

The discovery was detailed in an advisory published on the Ivanti Community forums, which outlines the specifics of the vulnerabilities and the affected products.

Shadowserver said that approximately 16,500 instances of Ivanti Connect Secure appliances are likely vulnerable worldwide, with around 4,600 located within the United States.

This widespread exposure raises significant concerns for organizations relying on Ivanti’s VPN solutions for remote access and secure connectivity.

Remote Code Execution

CVE-2024-21894 is particularly alarming due to its potential for remote code execution, a type of attack that allows an attacker to run arbitrary code on the affected system.

This could enable unauthorized access to sensitive information, disruption of critical services, and further exploitation of network resources.

The advisory also mentions additional vulnerabilities, including CVE-2024-22052 (a null pointer dereference issue), CVE-2024-22053 (another heap overflow vulnerability), and CVE-2024-22023 (an XML entity expansion or XXE vulnerability), each contributing to the overall risk landscape.

Ivanti has acknowledged the severity of these vulnerabilities and is urging customers to apply the provided patches and mitigations immediately.

The company has released updates and detailed guidance on how to secure affected appliances against potential exploitation.

It is crucial for organizations using Ivanti’s VPN solutions to review their security posture and ensure that all necessary measures are in place to protect against these vulnerabilities.

The implications of these vulnerabilities are far-reaching, affecting not only the security of the organizations directly using Ivanti’s products but also the privacy and integrity of the data and systems they safeguard.

In an era where remote access solutions are more critical than ever, the discovery of such vulnerabilities underscores the importance of continuous vigilance and proactive security practices.

As the cybersecurity community continues to monitor and respond to these developments, the situation serves as a reminder of the ever-present challenges in securing complex IT environments.

Organizations are encouraged to stay informed about the latest security advisories and to prioritize the protection of their digital assets against emerging threats.

Secure your emails in a heartbeat! To find your ideal email security vendor, Take a Free 30-Second Assessment.


[ad_2]
Source link

Quick Share adopts new Material Design 3 animation

0
[ad_1]

Since its launch in 2014, Google has consistently updated its Material Design guidelines. With the introduction of Material Design 3, app developers are advised follow the new standard for UI elements. Although the adoption of these guidelines, even within Google’s own apps and Android system components, can be slow. Now, recent reports show that Quick Share (formerly known as Nearby Share) has started incorporating Material Design 3 progress bars, indicating a wider implementation of the new design philosophy.

Evolution of Material Design

Google introduced Material Design 3 in 2021 to enhance and streamline the design language for a seamless user experience. Since the launch, Google has been consistently enhancing design components to meet the Material Design 3 criteria. Recently, the focus has shifted to improving sliders and progress bars, crucial for user engagement and response.

Google’s approach to progress bars

The new progress bars in Material Design 3 have rounded corner segments and an endpoint indicator. While most Android app developers are slow to adopt these changes, Google’s own apps like Photos and the Play Store have already implemented the updated design elements.

Quick share new material design 3 animation
Image credit: Android Police

Quick Share embraces the Material Design 3

Quick Share is now using the Material Design 3, with progress bars clearly visible during file transfers. The UI now has an indeterminate circular progress bar for “Connecting” and a determinate progress bar for transfer completion status.

Material Design 3 is not limited to Android, it has the potential to expand to other platforms. With the recent release of a desktop client for Quick Share, users are looking forward to a unified design experience on all devices. Google is constantly improving its design language, so users can look forward to more enhancements and standardizations throughout its ecosystem.

Global rollout and implications

Surprisingly, the addition of the Material Design 3 progress bars in Quick Share seems to be enabled by a server-side switch, allowing for a smooth transition without the need for a recent app update. According to the source, the design change is being implemented globally, seen in countries like India and Germany. Although Google aims for improved user experience with Quick Share aligned to the Material Design 3 standards, no specific timeline given.


[ad_2]
Source link

Samsung to get $6 billion US subsidy for chip investment

0
[ad_1]

Samsung will reportedly receive more than $6 billion in subsidies and grants from the US government to expand chip production in the country. In return, the company will invest over $44 billion to construct two manufacturing plants, an advanced packaging facility, and a research and development center. One of the factories is already under construction and is expected to be operational by the end of this year.

US government to offer Samsung $6 billion in chip subsidies

The US government’s CHIPS and Science Act is proving a massive hit. As part of this act, the Biden administration has set aside a $52.7 billion fund to bolster the domestic semiconductor industry, including $39 billion in direct grants to companies for expanding their chip facilities. TSMC, which gets a $6.6 billion subsidy, has already agreed to increase its investment by $25 billion to $65 billion. It will add a third chip factory to its Arizona site by 2030.

Intel also intends to invest more than $100 billion in the American chip industry over the next five years, expanding production in its existing facilities in Arizona. The US government will award it with $8.5 billion in subsidies and $11 billion in loans. Samsung will get the third-biggest amount under the new act. According to a Reuters report, the Korean firm was also offered loans but it does not plan to take any loans.

Samsung already has a chip factory in Austin, Texas. In 2021, it announced plans to construct a new factory in Taylor, Texas. The project was initially estimated to cost $17 billion. However, various market conditions such as inflation have added to the cost. The company may end up spending well over $20 billion on the new factory, which it hopes to be operational later this year. The facility will be used to produce advanced semiconductor chips.

Samsung’s third chip factory in the US will also be located in Taylor. Early estimates have put its cost at around $20 billion. The packaging facility will cost the company $4 billion. Its new R&D center may span across the two factories. Samsung will also reportedly invest some amount in another undisclosed location, though it may not be significant. The total investment will reach $44 billion, more than double what it originally intended to invest.

An official announcement may come next week

Samsung will reportedly announce this expansion project next week, probably on Monday, April 15. Commerce Department Secretary Gina Raimondo will likely unveil the government’s subsidies and grants for the company on the same day, capping off a string of major grants over the past few weeks. Texas Governor Greg Abbott may attend the event.


[ad_2]
Source link

Android Auto now reads a message twice before sending it (bug?)

0
[ad_1]

Android Auto and other hands-free services make driving and interacting with your phone as safe as possible. And these apps often get updated with new features to make your drive even more convenient. Or at least, that’s usually the case. However, 9to5Google now reports Android Auto has gotten a… rather peculiar update (or bug?) recently.

Android Auto now reads a message twice before it sends it


Usually, if you want to send a message using voice with Android Auto, the process is quite simple. After you’ve summoned the Assistant, you say who the message is for and you dictate the message’s content. Google Assistant will then read out the message for you and after you confirm it, it is sent.

However, some users have posted on Reddit that this behavior has now changed. The change is – while Assistant says it’s sending the message, it reads it out loud once again. This second reading of the message doesn’t seem to really serve a purpose though.

So far, there’s no way to change this setting (if it is a setting at all). As for replies, the usual behavior remains so far: the Assistant reads the message, then you can choose if you want to send a message in reply. Then, you hear it out once before it’s sent to confirm.

For some users, Assistant is also disabling dictation too early, but it seems this issue isn’t as widespread as the aforementioned one.

It isn’t clear yet whether this is a bug or intended behavior. Whatever it is though, it doesn’t really add usability, just a couple more seconds to the process (which could be frustrating for some). When we know more, we’ll let you know!


[ad_2]
Source link