Entertainment

Netflix Kills Casting From Phones (theverge.com) 95

An anonymous reader writes: Netflix has removed the ability to cast shows and movies from phones to TVs, unless subscribers are using older casting devices. An updated help page on Netflix's website, first reported by Android Authority, says that the streaming service "no longer supports casting shows from a mobile device to most TVs and TV-streaming devices," and instead directs users to navigate Netflix using the remote that came with their TV hardware.
Android

Android's New Dual-Band Hotspot Mode Pairs 6 GHz Speed With 2.4 GHz Compatibility (androidauthority.com) 15

Google is testing a new Wi-Fi hotspot configuration in the latest Android Canary build that pairs the 6 GHz band's superior throughput with the 2.4 GHz band's broad device compatibility, eliminating the trade-off users previously faced when choosing between speed and legacy support. Android's default hotspot setting uses 2.4 and 5 GHz frequencies, omitting 6 GHz because most devices lack support for the newer standard and because U.S. regulations previously prohibited smartphones from creating 6 GHz hotspots. Recent regulatory changes and a Pixel update unlocked standalone 6 GHz hotspots, but that option cuts off older devices entirely. The new "2.4 and 6 GHz" dual-band mode, spotted in Android Canary, is expected to arrive in an upcoming Android 16 QPR3 beta.
Television

Plex Is Now Enforcing Remote Play Restrictions On TVs 77

Plex is beginning to enforce new restrictions on remote streaming for its TV apps, requiring either a Plex Pass or the cheaper Remote Watch Pass to watch media from servers outside your home network. How-To Geek reports: Plex is now rolling out the remote watch changes to its Roku TV app. This means that you will need a Plex Pass or Remote Watch Pass for your Plex account if you want to stream media from a server outside your home. If you're only watching media from your own server on the same local network as your Roku device, or the owner of the server you're streaming from has Plex Pass, you don't have to do anything.

Plex says this change will come to the other TV apps in 2026, such as Fire TV, Apple TV, and Android TV. Presumably, that will happen when the redesigned app arrives on those platforms. Roku was just the first TV platform to get the new app, which caused a wave of complaints from users about removed functionality and a more clunky redesign. Plex is addressing some of those complaints with more updates, but adding another limitation at the same time isn't a great look.

The Remote Watch Pass costs $2 per month or $20 per year, but there's no lifetime purchase option. You can also use a Plex Pass, which normally costs $7 per month, $70 per year, or $250 for a lifetime license. However, there's currently a 40% off sale for Plex Pass subscriptions.
Privacy

Manufacturer Remotely Bricks Smart Vacuum After Its Owner Blocked It From Collecting Data (tomshardware.com) 123

"An engineer got curious about how his iLife A11 smart vacuum worked and monitored the network traffic coming from the device," writes Tom's Hardware.

"That's when he noticed it was constantly sending logs and telemetry data to the manufacturer — something he hadn't consented to." The user, Harishankar, decided to block the telemetry servers' IP addresses on his network, while keeping the firmware and OTA servers open. While his smart gadget worked for a while, it just refused to turn on soon after... He sent it to the service center multiple times, wherein the technicians would turn it on and see nothing wrong with the vacuum. When they returned it to him, it would work for a few days and then fail to boot again... [H]e decided to disassemble the thing to determine what killed it and to see if he could get it working again...

[He discovered] a GD32F103 microcontroller to manage its plethora of sensors, including Lidar, gyroscopes, and encoders. He created PCB connectors and wrote Python scripts to control them with a computer, presumably to test each piece individually and identify what went wrong. From there, he built a Raspberry Pi joystick to manually drive the vacuum, proving that there was nothing wrong with the hardware. From this, he looked at its software and operating system, and that's where he discovered the dark truth: his smart vacuum was a security nightmare and a black hole for his personal data.

First of all, it's Android Debug Bridge, which gives him full root access to the vacuum, wasn't protected by any kind of password or encryption. The manufacturer added a makeshift security protocol by omitting a crucial file, which caused it to disconnect soon after booting, but Harishankar easily bypassed it. He then discovered that it used Google Cartographer to build a live 3D map of his home. This isn't unusual, by far. After all, it's a smart vacuum, and it needs that data to navigate around his home. However, the concerning thing is that it was sending off all this data to the manufacturer's server. It makes sense for the device to send this data to the manufacturer, as its onboard SoC is nowhere near powerful enough to process all that data. However, it seems that iLife did not clear this with its customers.

Furthermore, the engineer made one disturbing discovery — deep in the logs of his non-functioning smart vacuum, he found a command with a timestamp that matched exactly the time the gadget stopped working. This was clearly a kill command, and after he reversed it and rebooted the appliance, it roared back to life.

Thanks to long-time Slashdot reader registrations_suck for sharing the article.
Cellphones

Someone Snuck Into a Cellebrite Microsoft Teams Call and Leaked Phone Unlocking Details (404media.co) 56

An anonymous reader quotes a report from 404 Media: Someone recently managed to get on a Microsoft Teams call with representatives from phone hacking company Cellebrite, and then leaked a screenshot of the company's capabilities against many Google Pixel phones, according to a forum post about the leak and 404 Media's review of the material. The leak follows others obtained and verified by 404 Media over the last 18 months. Those leaks impacted both Cellebrite and its competitor Grayshift, now owned by Magnet Forensics. Both companies constantly hunt for techniques to unlock phones law enforcement have physical access to.

"You can Teams meeting with them. They tell everything. Still cannot extract esim on Pixel. Ask anything," a user called rogueFed wrote on the GrapheneOS forum on Wednesday, speaking about what they learned about Cellebrite capabilities. GrapheneOS is a security- and privacy-focused Android-based operating system. rogueFed then posted two screenshots of the Microsoft Teams call. The first was a Cellebrite Support Matrix, which lays out whether the company's tech can, or can't, unlock certain phones and under what conditions. The second screenshot was of a Cellebrite employee. According to another of rogueFed's posts, the meeting took place in October. The meeting appears to have been a sales call. The employee is a "pre sales expert," according to a profile available online.

The Support Matrix is focused on modern Google Pixel devices, including the Pixel 9 series. The screenshot does not include details on the Pixel 10, which is Google's latest device. It discusses Cellebrite's capabilities regarding 'before first unlock', or BFU, when a piece of phone unlocking tech tries to open a device before someone has typed in the phone's passcode for the first time since being turned on. It also shows Cellebrite's capabilities against after first unlock, or AFU, devices. The Support Matrix also shows Cellebrite's capabilities against Pixel devices running GrapheneOS, with some differences between phones running that operating system and stock Android. Cellebrite does support, for example, Pixel 9 devices BFU. Meanwhile the screenshot indicates Cellebrite cannot unlock Pixel 9 devices running GrapheneOS BFU. In their forum post, rogueFed wrote that the "meeting focused specific on GrapheneOS bypass capability." They added "very fresh info more coming."

Android

Samsung Galaxy XR Is the First Android XR Headset (arstechnica.com) 21

Samsung has officially launched the Galaxy XR, the first Android headset powered by Google's new Android XR platform. Priced at $1,800 without controllers, the device features dual 4.3K Micro-OLED displays, a Snapdragon XR2+ Gen 2 chip, extensive camera tracking, and deep Gemini AI integration. Ars Technica reports: Galaxy XR is a fully enclosed headset with passthrough video. It looks similar to the Apple Vision Pro, right down to the battery pack at the end of a cable. It packs solid hardware, including 16GB of RAM, 256GB of storage, and a Snapdragon XR2+ Gen 2 processor. That's a slightly newer version of the chip powering Meta's Quest 3 headset, featuring six CPU cores and an Adreno GPU that supports up to dual 4.3K displays. The new headset has a pair of 3,552 x 3,840 Micro-OLED displays with a 109-degree field of view. That's marginally more pixels than the Vision Pro and almost three times as many as the Quest 3. The displays can refresh at up to 90Hz, but the default is 72Hz to save power.

Like other XR (extended reality) devices, the Galaxy XR is covered with cameras. There are two 6.5 MP stereoscopic cameras that stream your surroundings to the high-quality screens, allowing the software to add virtual elements on top. There are six more outward-facing cameras for headset positioning and hand tracking. Four more cameras are on the inside for eye-tracking, and they can scan your iris for secure unlocking and password fill (in select apps). Samsung says the Galaxy XR has enough juice for two hours of general use or two and a half hours of video. That's not terribly long, but you may not want to wear the 545 grams (1.2 pounds) headset for even two hours. That's even a little heavier than the Quest 3, which has an integrated battery. However, both pale in comparison to the 800 g (1.7 pounds) second-generation Vision Pro.

Open Source

FSF Announces the LibrePhone Project (phoronix.com) 67

The Free Software Foundation (FSF) has launched the LibrePhone Project, an initiative to create a fully free and open-source mobile operating system that eliminates proprietary firmware and binary blobs. From the FSF: "Librephone is a new initiative by the FSF with the goal of bringing full freedom to the mobile computing environment. The vast majority of software users around the world use a mobile phone as their primary computing device. After forty years of advocacy for computing freedom, the FSF will now work to bring the right to study, change, share, and modify the programs users depend on in their daily lives to mobile phones.
...
Practically, Librephone aims to close the last gaps between existing distributions of the Android operating system and software freedom. The FSF has hired experienced developer Rob Savoye (DejaGNU, Gnash, OpenStreetMap, and more) to lead the technical project. He is currently investigating the state of device firmware and binary blobs in other mobile phone freedom projects, prioritizing the free software work done by the not entirely free software mobile phone operating system LineageOS."
The project site can be found here.
Chrome

Chrome Will Automatically Disable Web Notifications You Don't Care About (theverge.com) 13

Google is introducing a new Chrome browser feature for Android and desktop users that automatically turns off notifications for websites that you're already ignoring. From a report: Chrome's Safety Check feature already provides similar functionality for camera access and location tracking permissions.

This new auto-revocation feature builds on a similar Android feature that already makes it easier for Chrome users to unsubscribe from website notifications they don't care about with a single tap. The feature doesn't revoke notifications for any web apps installed on the device, and permissions will only be disabled for sites that send a lot of notifications that users rarely engage with. Less than one percent of all web notifications in Chrome currently receive any interaction from users, according to Google, often making them more distracting than helpful.

Firefox

Firefox Feature Gets Special Mention In TIME's Best Inventions of 2025 41

Mozilla Firefox's new "Shake to Summarize" feature earned a spot on TIME's Best Inventions of 2025, allowing users to shake their phone to instantly summarize long web pages. Anthony Enzor-DeMeo, general manager of Firefox, calls it a "testament to the incredible work of our UX, design, product, and engineering teams who brought this innovation to life." Neowin reports: Shake to summarize works exactly how you suspect: you physically shake your phone to generate a summary of a long article. This can be quite handy if you are trying to get the gist of a long read without scrolling through the whole thing. Other ways to activate the feature include tapping the thunderbolt icon in the address bar and selecting "Summarize Page" from the three-dot menu.

For now, the feature is limited to iOS users in the US with their system set to English, but Mozilla promises an Android version is in the works. If you have an iPhone 15 Pro or newer running iOS 26, Apple Intelligence generates the summaries on the device. For older iPhones or those on earlier iOS versions, the page text is sent to Mozilla's servers for processing.
You can view the full list of TIME's "Special Mentions" here.
Books

Independent UK Bookshops To Begin Selling eBooks 17

Independent UK bookshops will now be able to sell ebooks via a new platform (Bookshop.org's expansion), keeping 100% of profits and offering a non-Amazon way to reach digital readers. "Bookshops now have an additional tool in their fight against Amazon," said Nicole Vanderbilt, managing director of Bookshop.org UK. "Digital readers don't depend on Amazon's monopoly any more, now that they can find ebooks at the same price on Bookshop.org." The Guardian reports: Bookshop.org launched in the UK in November 2020 as a platform for independent bookshops to sell physical books. Bookshops receive 30% of the cover price from each sale they generate; so far, the UK site has generated 4.5 million pounds for independent bookshops. Customers will also now be able to buy ebooks through a bookshop of their choice. Profits from orders without a specified bookshop will be added to a shared pool, which will be distributed among all participating bookshops on the platform. [...]

The platform will launch with a catalogue of more than a million ebooks from all major publishers. It will be available online via a web browser and through the Bookshop.org apps on Apple and Android. "Due to Amazon's proprietary digital rights management [DRM] software and publishers' DRM requirements, it's not currently possible to buy DRM-protected ebooks from Bookshop.org or local bookshops and read them on your Kindle," said Bookshop.org. However, the site is working with the e-reader company Kobo to support Kobo devices "later this year," and longer term would "love to offer our own eInk device."
Transportation

When This EV Company Went Bankrupt, Its Customers Launched a Nonprofit to Keep Their Cars Running (theverge.com) 23

Cristian Fleming paid around $70,000 for one of Fisker Ocean's electric mid-size crossover SUVs. Seven months later the company filed for bankruptcy in June of 2024, reports the Verge, "having only delivered 11,000 vehicles."

"Early adopters were left with cars plagued by battery failures, glitchy software, inconsistent key fobs, and door handles that did not always open. With the company gone, there was no way to fix any issues." Regulators logged dozens of complaints as replacement parts vanished. Passionate owners who spent top dollar on high-end trims saw their cars reduced to expensive driveway ornaments.

Rather than accept defeat, thousands of Ocean owners have organized into their own makeshift car company. The Fisker Owners Association (FOA) is a nonprofit that's launched third-party apps, built a global parts supply chain, and came together around a future for their orphaned vehicles. It's part car club, part tech startup, part survival mission. Fleming now serves as the organization's president... FOA calls itself the first entirely owner-controlled EV fleet in history. So far, 4,055 Ocean owners have signed up, paying $550 a year in dues that the group estimates will raise around $3 million annually, about 0.1 percent of Fisker's peak valuation. Only verified Ocean owners can become full members, but anyone can donate.

The grassroots effort has precedent — DeLorean diehards and Saab enthusiasts have kept their favorite brands alive after factory closures. But those efforts focused on preserving aging vehicles. FOA is attempting something different: real-time software updates and hardware improvements for a connected, two-year-old EV fleet... The organization has spawned three separate companies. Tsunami Automotive handles parts in North America while Tidal Wave covers Europe, scavenging insurance auctions and contracting with tooling manufacturers to reproduce components. UnderCurrent Automotive, run by former Google and Apple engineers, focuses on software solutions.

UnderCurrent's first product is OceanLink Pro, a third-party mobile app now used by over 1,200 members that restores basic EV features, such as remote battery monitoring and climate control. A companion device called OceanLink Pulse adds wireless CarPlay and Android Auto, with plans for future upgrades including keyless entry. "Those are things you would have expected to be in a $70,000 luxury car," says Clint Bagley [FOA's treasurer]. "But, you know, we're happy to provide what the billion-dollar automaker apparently couldn't."

Cloud

Signal Rolls Out Encrypted Cloud Backups, Debuts First Subscription Plan at $1.99/Month (signal.org) 17

Signal has begun rolling out end-to-end encrypted cloud backups in its latest Android beta release. The opt-in feature allows users to restore message history if their phone is lost or damaged. Free backups include all text messages and 45 days of media attachments. A $1.99 monthly subscription extends media storage to 100GB.

Users generate a 64-character recovery key on their device that Signal's servers never access. Backups refresh daily, excluding view-once messages and those set to disappear within 24 hours. The nonprofit cited storage costs as the reason for its first paid tier. iOS and Desktop support will follow the Android rollout. Signal said it stores backup archives without linking them to specific user accounts or payment information.
Android

Google Refreshes Pixel Lineup With Tensor G5 and Qi2 Charging Across Four Models 9

Google announced its Pixel 10 smartphone lineup today, introducing the Tensor G5 processor and Qi2 magnetic wireless charging across four models priced from $799 to $1,799. The base Pixel 10 adds a 5x telephoto lens for the first time at $799. The Pixel 10 Pro maintains its $999 starting price in a 6.3-inch size while the Pro XL starts at $1,199 for the 6.8-inch variant.

The $1,799 Pixel 10 Pro Fold becomes the first foldable phone to achieve IP68 water and dust resistance through a redesigned gearless hinge. All models feature 3,000-nit peak brightness displays, Android 16, and Google's Material 3 Expressive interface redesign. The Tensor G5 enables on-device AI features including Magic Cue for contextual information retrieval and Camera Coach for photography guidance. Pro models gain 100x hybrid zoom capabilities through computational photography. Preorders begin today for August 28 availability, except the Pro Fold which ships October 9.
Android

Android's pKVM Becomes First Globally Certified Software to Achieve SESIP Level 5 Security Certification (googleblog.com) 32

Protected KVM (pKVM), the hypervisor powering the Android Virtualization Framework, has officially achieved SESIP Level 5 certification (in testing by cybersecurity lab Dekra against the TrustCB SESIP scheme).

Google's security blog called the certification "a watershed moment," and a "new benchmark" for both open-source security — and for the future of consumer electronics. "It provides a single, open-source, and exceptionally high-quality firmware base that all device manufacturers can build upon." This makes pKVM the first software security system designed for large-scale deployment in consumer electronics to meet this assurance bar. The implications for the future of secure mobile technology are profound. With this level of security assurance, Android is now positioned to securely support the next generation of high-criticality isolated workloads. This includes vital features, such as on-device AI workloads that can operate on ultra-personalized data, with the highest assurances of privacy and integrity...

Achieving Security Evaluation Standard for IoT Platforms (SESIP) Level 5 is a landmark because it incorporates AVA_VAN.5, the highest level of vulnerability analysis and penetration testing under the ISO 15408 (Common Criteria) standard. A system certified to this level has been evaluated to be resistant to highly skilled, knowledgeable, well-motivated, and well-funded attackers who may have insider knowledge and access. This certification is the cornerstone of the next-generation of Android's multi-layered security strategy. Many of the TEEs (Trusted Execution Environments) used in the industry have not been formally certified or have only achieved lower levels of security assurance... Looking ahead, Android device manufacturers will be required to use isolation technology that meets this same level of security for various security operations that the device relies on. Protected KVM ensures that every user can benefit from a consistent, transparent, and verifiably secure foundation.

"This achievement represents just one important aspect of the immense, multi-year dedication from the Linux and KVM developer communities and multiple engineering teams at Google developing pKVM and AVF," the post concludes.

"We look forward to seeing the open-source community and Android ecosystem continue to build on this foundation, delivering a new era of high-assurance mobile technology for users."
Android

Nothing's Phone 3 Is Stymied By Contentious Design and Price (ndtvprofit.com) 15

Smartphone maker Nothing's $799 Phone 3 has been "mired in controversy among the same customers who rallied behind the company's past products" since its July launch, Bloomberg reported on Wednesday. Tech enthusiasts have "lambasted the company for the phone's peculiar industrial design and what they perceive to be an unreasonable price."

The Android device lacks the most performant Qualcomm processor chip found in premium Android phones and the camera performance "falls short of other handsets in this price bracket," the publication wrote in a scathing review. The phone costs $200 more than its predecessor and matches pricing with Apple's iPhone 16, Samsung's Galaxy S25, and Google's Pixel 9.

Critics across Reddit and social media have attacked Nothing for removing the signature Glyph Lights from previous models. Comments on Nothing's YouTube channel have been "bruising," focusing on the phone's oddly positioned camera array. "At its current price, the handset is too expensive for what it offers," the review concludes.
Operating Systems

Linux 6.16 Brings Faster File Systems, Improved Confidential Memory Support, and More Rust Support (zdnet.com) 50

ZDNet's Steven Vaughan-Nichols shares his list of "what's new and improved" in the latest Linux 6.16 kernel. An anonymous reader shares an excerpt from the report: First, the Rust language is continuing to become more well-integrated into the kernel. At the top of my list is that the kernel now boasts Rust bindings for the driver core and PCI device subsystem. This approach will make it easier to add new Rust-based hardware drivers to Linux. Additionally, new Rust abstractions have been integrated into the Direct Rendering Manager (DRM), particularly for ioctl handling, file/GEM memory management, and driver/device infrastructure for major GPU vendors, such as AMD, Nvidia, and Intel. These changes should reduce vulnerabilities and optimize graphics performance. This will make gamers and AI/ML developers happier.

Linux 6.16 also brings general improvements to Rust crate support. Crate is Rust's packaging format. This will make it easier to build, maintain, and integrate Rust kernel modules into the kernel. For those of you who still love C, don't worry. The vast majority of kernel code remains in C, and Rust is unlikely to replace C soon. In a decade, we may be telling another story. Beyond Rust, this latest release also comes with several major file system improvements. For starters, the XFS filesystem now supports large atomic writes. This capability means that large multi-block write operations are 'atomic,' meaning all blocks are updated or none. This enhances data integrity and prevents data write errors. This move is significant for companies that use XFS for databases and large-scale storage.

Perhaps the most popular Linux file system, Ext4, is also getting many improvements. These boosts include faster commit paths, large folio support, and atomic multi-fsblock writes for bigalloc filesystems. What these improvements mean, if you're not a file-system nerd, is that we should see speedups of up to 37% for sequential I/O workloads. If your Linux laptop doubles as a music player, another nice new feature is that you can now stream your audio over USB even while the rest of your system is asleep. That capability's been available in Android for a while, but now it's part of mainline Linux.

If security is a top priority for you, the 6.16 kernel now supports Intel Trusted Execution Technology (TXT) and Intel Trusted Domain Extensions (TDX). This addition, along with Linux's improved support for AMD Secure Encrypted Virtualization and Secure Memory Encryption (SEV-SNP), enables you to encrypt your software's memory in what's known as confidential computing. This feature improves cloud security by encrypting a user's virtual machine memory, meaning someone who cracks a cloud can't access your data.
Linux 6.16 also delivers several chip-related upgrades. It introduces support for Intel's Advanced Performance Extensions (APX), doubling x86 general-purpose registers from 16 to 32 and boosting performance on next-gen CPUs like Lunar Lake and Granite Rapids Xeon. Additionally, the new CONFIG_X86_NATIVE_CPU option allows users to build processor-optimized kernels for greater efficiency.

Support for Nvidia's AI-focused Blackwell GPUs has also been improved, and updates to TCP/IP with DMABUF help offload networking tasks to GPUs and accelerators. While these changes may go unnoticed by everyday users, high-performance systems will see gains and OpenVPN users may finally experience speeds that challenge WireGuard.
Communications

Starlink-Powered 'T-Satellite' Service Is Now Live On T-Mobile (theverge.com) 10

T-Mobile has officially launched its Starlink-powered "T-Satellite" service nationwide, offering off-grid text messaging and location-sharing to both customers and non-customers. The service is currently $10/month (soon to be $15), supports over 60 devices, and will expand to include voice and "satellite-optimized" apps. The Verge reports: Your device will automatically connect to T-Satellite if you're in an area with no cellular coverage. As long as there isn't a heavy amount of cloud coverage or trees blocking your view of the sky, you should be able to send and receive text messages, including to 911, as well as share a link that temporarily tracks your location. T-Mobile's support page says the ability to send pictures is available on "most" Android phones, and the company plans on adding support for more devices soon.

T-Mobile is also aiming to enable voice messages and will eventually allow devices to connect to "satellite-optimized" apps, which it previously said could include AllTrails, Accuweather, and WhatsApp. The more than 650 Starlink satellites used by T-Mobile cover the continental US, Hawaii, parts of southern Alaska, and Puerto Rico. The carrier says it's working on offering satellite connectivity while abroad and in international waters as well. [...] In order to use T-Satellite, you'll need to have an unlocked device with support for eSIMs and satellite connectivity.

The Courts

Google Sues Operators of 10-Million-Device Badbox 2.0 Botnet (securityweek.com) 14

Google has filed a lawsuit to dismantle the sprawling Badbox 2.0 botnet, which infected over 10 million Android devices with pre-installed malware. Badbox 2.0 "is already the largest known botnet of internet-connected TV devices, and it grows each day. It has harmed millions of victims in the United States and around the world and threatens many more," Google said in its complaint. SecurityWeek reports: The internet giant cautions that, while it has been used mainly for fraud, the botnet could be used for more harmful types of cybercrime, such as ransomware or distributed denial-of-service (DDoS) attacks. In addition to pre-installing the malware on devices, Badbox 2.0's operators also tricked users into installing infected applications that provided them with further access to their personal devices, Google says. As part of their operation, the individuals behind Badbox 2.0 sold access to the infected devices to be used as residential proxies, and conducted ad fraud schemes by abusing these devices to create fake ad views or to exploit pay-per-click compensation models, the company continues. The internet giant also points out that this is the second global botnet the perpetrators have built, after the initial Badbox botnet was disrupted by German law enforcement in 2023.

According to Google, Badbox 2.0 is operated by multiple cybercrime groups from China, each having a different role in maintaining the botnet, such as establishing infrastructure, developing and pre-installing the malware on devices, and conducting fraud. "The BadBox 2.0 Enterprise includes several connected threat actor groups that design and implement complex criminal schemes targeting internet-connected devices both before and after the consumer receives the device," Google says. "While each member of the Enterprise plays a distinct role, they all collaborate to execute the BadBox 2.0 Scheme. All of the threat actor groups are connected to one another through the BadBox 2.0 shared C2 infrastructure and historical and current business ties," the company continues.

Privacy

Chinese Authorities Are Using a New Tool To Hack Seized Phones and Extract Data (techcrunch.com) 40

An anonymous reader quotes a report from TechCrunch: Security researchers say Chinese authorities are using a new type of malware to extract data from seized phones, allowing them to obtain text messages -- including from chat apps such as Signal -- images, location histories, audio recordings, contacts, and more. In a report shared exclusively with TechCrunch, mobile cybersecurity company Lookout detailed the hacking tool called Massistant, which the company said was developed by Chinese tech giant Xiamen Meiya Pico.

Massistant, according to Lookout, is Android software used for the forensic extraction of data from mobile phones, meaning the authorities using it need to have physical access to those devices. While Lookout doesn't know for sure which Chinese police agencies are using the tool, its use is assumed widespread, which means Chinese residents, as well as travelers to China, should be aware of the tool's existence and the risks it poses. [...]

The good news ... is that Massistant leaves evidence of its compromise on the seized device, meaning users can potentially identify and delete the malware, either because the hacking tool appears as an app, or can be found and deleted using more sophisticated tools such as the Android Debug Bridge, a command line tool that lets a user connect to a device through their computer. The bad news is that at the time of installing Massistant, the damage is done, and authorities already have the person's data.
"It's a big concern. I think anybody who's traveling in the region needs to be aware that the device that they bring into the country could very well be confiscated and anything that's on it could be collected," said Kristina Balaam, a researcher at Lookout who analyzed the malware. "I think it's something everybody should be aware of if they're traveling in the region."
Power

Google Nerfs Second Pixel Phone Battery This Year (arstechnica.com) 29

An anonymous reader quotes a report from Ars Technica: For the second time in a year, Google has announced that it will render some of its past phones almost unusable with a software update, and users don't have any choice in the matter. After nerfing the Pixel 4a's battery capacity earlier this year, Google has now confirmed a similar update is rolling out to the Pixel 6a. The new July Android update adds "battery management features" that will make the phone unusable. Given the risks involved, Google had no choice but to act, but it could choose to take better care of its customers and use better components in the first place. Unfortunately, a lot more phones are about to end up in the trash. [...]

Pixel 4a units contained one of two different batteries, and only the one manufactured by a company called Lishen was downgraded. For the Pixel 6a, Google has decreed that the battery limits will be imposed when the cells hit 400 charge cycles. Beyond that, the risk of fire becomes too great -- there have been reports of Pixel 6a phones bursting into flames. Clearly, Google had to do something, but the remedies it settled on feel unnecessarily hostile to customers. It had a chance to do better the second time, but the solution for the Pixel 6a is more of the same. [...]

When Google killed the Pixel 4a's battery life, it offered a few options. You could have the battery replaced for free, get $50 cash, or accept a $100 credit in the Google Store. However, claiming the money or free battery was a frustrating experience that was rife with fees and caveats. The store credit is also only good on phones and can't be used with other promotions or discounts. And the battery swap? You'd better hope there's nothing else wrong with the device. If it has any damage, like cracked glass, it may not qualify for a free battery replacement.

Now we have the Pixel 6a Battery Performance Program with all the same problems. Pixel 6a owners can get $100 in cash or $150 in store credit. Alternatively, Google offers a free battery replacement with the same limits on phone condition. This is all particularly galling because the Pixel 6a is still an officially supported phone, with its final guaranteed update coming in 2027. Google also pulled previous software packages for this phone to prevent rollbacks. [...] If you have a Pixel 6a, the battery-killing update is rolling out now. You'll have no choice but to install it if you want to remain on the official software. Google has a support site where you can try to get a free battery swap or some cash.

Slashdot Top Deals