Forwarded from vx-underground
Some controversy today as YouTube tech reviewer Marques Brownlee 'Panels' app is getting pretty substantial backlash.
tl;dr Marques Brownlee app, 'Panels', offers high-definition wallpapers from Digital Artists for $49.99/year. People criticized the app for an array of reasons, beside the idea of paying $49.99/year for wallpapers on your cell phone, the app requests tracking information, and contains ads.
Unsurprisingly, and as is tradition, internet nerds quickly began inspecting the app under the metaphorical microscope. Security researcher @I_Am_Jakoby discovered the apps API is wildly insecure. He wrote a simple script which programmatically scrapes every high-definition wallpaper.
Attached image is the script he shared. If you want to experiment with it, just OCR it or something.
tl;dr Marques Brownlee app, 'Panels', offers high-definition wallpapers from Digital Artists for $49.99/year. People criticized the app for an array of reasons, beside the idea of paying $49.99/year for wallpapers on your cell phone, the app requests tracking information, and contains ads.
Unsurprisingly, and as is tradition, internet nerds quickly began inspecting the app under the metaphorical microscope. Security researcher @I_Am_Jakoby discovered the apps API is wildly insecure. He wrote a simple script which programmatically scrapes every high-definition wallpaper.
Attached image is the script he shared. If you want to experiment with it, just OCR it or something.
🤡15👍3
Intel gets multibillion-dollar Apollo offer as Qualcomm circles
Apollo Global Management has offered to invest up to $5 billion in Intel, giving the chipmaker a confidence boost in its turnaround strategy and presenting an alternative to a potential takeover by Qualcomm. Intel has been struggling with declining sales and a loss in stock value, but recent deals, including a multibillion-dollar AI semiconductor partnership with Amazon, signal a potential recovery.
Qualcomm's interest in acquiring Intel could lead to one of the biggest-ever tech M&A deals, but it faces regulatory and financial hurdles. Apollo's investment would help Intel maintain independence and continue its transformation.
🔗 Economictimes
🧑💻 @agamtechtricks
Apollo Global Management has offered to invest up to $5 billion in Intel, giving the chipmaker a confidence boost in its turnaround strategy and presenting an alternative to a potential takeover by Qualcomm. Intel has been struggling with declining sales and a loss in stock value, but recent deals, including a multibillion-dollar AI semiconductor partnership with Amazon, signal a potential recovery.
Qualcomm's interest in acquiring Intel could lead to one of the biggest-ever tech M&A deals, but it faces regulatory and financial hurdles. Apollo's investment would help Intel maintain independence and continue its transformation.
🔗 Economictimes
🧑💻 @agamtechtricks
🤡7
ATT • Tech News
Intel gets multibillion-dollar Apollo offer as Qualcomm circles Apollo Global Management has offered to invest up to $5 billion in Intel, giving the chipmaker a confidence boost in its turnaround strategy and presenting an alternative to a potential takeover…
Intel has lost all of its dedicated GPU market share
Nvidia and AMD saw a strong rise in dedicated desktop GPU sales in Q2 2024, with Nvidia maintaining an 88% market share and AMD holding 12%. Nvidia's shipments jumped 61.9% year-over-year, while AMD saw a 3% rise. In contrast, Intel struggled, with flat sales and no market share gains since its initial Arc Alchemist launch.
Nvidia's RTX 5000 (Blackwell) and AMD's RDNA 4 (Radeon RX 8000) are expected to debut in early 2025. Intel's Arc Battlemage may launch in late 2024, potentially competing if they avoid previous delays.
🔗 Techspot
🧑💻 @agamtechtricks
Nvidia and AMD saw a strong rise in dedicated desktop GPU sales in Q2 2024, with Nvidia maintaining an 88% market share and AMD holding 12%. Nvidia's shipments jumped 61.9% year-over-year, while AMD saw a 3% rise. In contrast, Intel struggled, with flat sales and no market share gains since its initial Arc Alchemist launch.
Nvidia's RTX 5000 (Blackwell) and AMD's RDNA 4 (Radeon RX 8000) are expected to debut in early 2025. Intel's Arc Battlemage may launch in late 2024, potentially competing if they avoid previous delays.
🔗 Techspot
🧑💻 @agamtechtricks
🔥9😢3⚡2
ATT • Tech News
Firefox and Meta develop a mechanism that promises to keep the user's data private in an unyielding ad world Mozilla recently received backlash after shipping an experimental feature — Privacy-preserving attribution, enabled by default, which collects data…
Mozilla Faces Privacy Complaint Over Firefox User Tracking
NOYB has filed a complaint against Mozilla with the Austrian data protection authority for allegedly tracking user behavior without users' consent through a feature called Privacy Preserving Attribution (PPA). NOYB insists that by default, Mozilla enables this tracking feature in Firefox, yet does not properly inform the user, thus violating EU privacy legislation.
Mozilla defended PPA as an attempt at improving advertisement practices with no identification of individuals. NOYB argues that users should have the option to opt in and that data collected should be deleted.
🔗 noyb.eu
🧑💻 @agamtechtricks
NOYB has filed a complaint against Mozilla with the Austrian data protection authority for allegedly tracking user behavior without users' consent through a feature called Privacy Preserving Attribution (PPA). NOYB insists that by default, Mozilla enables this tracking feature in Firefox, yet does not properly inform the user, thus violating EU privacy legislation.
Mozilla defended PPA as an attempt at improving advertisement practices with no identification of individuals. NOYB argues that users should have the option to opt in and that data collected should be deleted.
Please open Telegram to view this post
VIEW IN TELEGRAM
😱23👍5
The Linux kernel with RTL is now fully merged
Last week, September 16, 2024, something very important, at least for us geeks — finally happened: the Linux realtime effort, which was dubbed PREEMPT_RT in its early days and later Real-Time Linux (RTL), finally, finally succeeded! After "only" 20 years, all of the RTL code will soon be in-tree in the upcoming 6.12 Linux kernel.
6.11 was released on 23 Sep 2024, and here's the recent 6.9 patches.
🔗 Kaiwantech
👨💻 @agamtechtricks
Last week, September 16, 2024, something very important, at least for us geeks — finally happened: the Linux realtime effort, which was dubbed PREEMPT_RT in its early days and later Real-Time Linux (RTL), finally, finally succeeded! After "only" 20 years, all of the RTL code will soon be in-tree in the upcoming 6.12 Linux kernel.
6.11 was released on 23 Sep 2024, and here's the recent 6.9 patches.
🔗 Kaiwantech
👨💻 @agamtechtricks
🎉13❤2🔥2
WordPress.org bans WP Engine, blocks it from accessing its resources
WordPress.org banned hosting provider WP Engine from accessing its resources, citing legal claims and trademark violations. WordPress co-creator Matt Mullenweg criticized WP Engine for trying to control the WordPress experience and not contributing enough to the community. WP Engine customers can no longer update plugins or themes via WordPress.org, raising security concerns.
The conflict began when Mullenweg accused WP Engine of profiteering. WP Engine responded with a cease-and-desist letter, leading to legal disputes between the two, with Automattic alleging trademark infringements. The core issue revolves around licensing and contributions to WordPress.
🔗 TechCrunch | Blog Post
🧑💻 @agamtechtricks
WordPress.org banned hosting provider WP Engine from accessing its resources, citing legal claims and trademark violations. WordPress co-creator Matt Mullenweg criticized WP Engine for trying to control the WordPress experience and not contributing enough to the community. WP Engine customers can no longer update plugins or themes via WordPress.org, raising security concerns.
The conflict began when Mullenweg accused WP Engine of profiteering. WP Engine responded with a cease-and-desist letter, leading to legal disputes between the two, with Automattic alleging trademark infringements. The core issue revolves around licensing and contributions to WordPress.
🔗 TechCrunch | Blog Post
🧑💻 @agamtechtricks
👍13
IT'S JOEVER: CVE 9.9 (Remote Code Execution) ISSUED FOR LINUX
A vulnerability in Unix printing service CUPS has been found which allows for remote code execution. Considering this issue is with CUPS, it SHOULD also affect other unix/unix-like OSes (Linux, BSD and all that). This exploit works by sending miscreants on UDP Port 631.
For now, here are the potential mitigation steps:
- Keep CUPS up-to-date and check for updates ASAP
- Disable CUPS entirely
- Block port 631
I'd recommend that unless you need printing, all of you get rid of CUPS IF it's installed on your system.
Windows exploits? Nahh that's baby stuff. But YOU KNOW it's serious when Linux gets an exploit (and that too with a rating of 9.9).
Be safe, y'all.
🔗 Read more
👨💻 @agamtechtricks
A vulnerability in Unix printing service CUPS has been found which allows for remote code execution. Considering this issue is with CUPS, it SHOULD also affect other unix/unix-like OSes (Linux, BSD and all that). This exploit works by sending miscreants on UDP Port 631.
For now, here are the potential mitigation steps:
- Keep CUPS up-to-date and check for updates ASAP
- Disable CUPS entirely
- Block port 631
I'd recommend that unless you need printing, all of you get rid of CUPS IF it's installed on your system.
Windows exploits? Nahh that's baby stuff. But YOU KNOW it's serious when Linux gets an exploit (and that too with a rating of 9.9).
Be safe, y'all.
🔗 Read more
👨💻 @agamtechtricks
👍7🤡6😨2
OpenAI to become for-profit and give Sam Altman equity
OpenAI is working on a plan to restructure its core business into a for-profit benefit corporation. The whole point of OpenAI was to be nonprofit and safety-first, not anymore. ;)
The OpenAI non-profit will continue to exist and own a minority stake in the for-profit company, which would basically have no power now.
Sam Altman, who emphasized that he didn’t have any equity in the company, will also receive equity for the first time, which could be worth $150 billion after the restructuring, in addition to ultimate control over OpenAI.
- Jacob Hilton
🔗 Reuters | Vox
🧑💻 @agamtechtricks
OpenAI is working on a plan to restructure its core business into a for-profit benefit corporation. The whole point of OpenAI was to be nonprofit and safety-first, not anymore. ;)
The OpenAI non-profit will continue to exist and own a minority stake in the for-profit company, which would basically have no power now.
Sam Altman, who emphasized that he didn’t have any equity in the company, will also receive equity for the first time, which could be worth $150 billion after the restructuring, in addition to ultimate control over OpenAI.
If OpenAI were to retroactively remove profit caps from investments, this would in effect transfer billions in value from a non-profit to for-profit investors. Unless the non-profit were appropriately compensated, this would be a money grab.
- Jacob Hilton
Please open Telegram to view this post
VIEW IN TELEGRAM
🥴11👎1👏1🤔1🍌1
EU privacy regulator fines Meta 91 million euros over password storage
The Data Protection Commission (DPC) has levied a €91 million, or around $101.5 million, fine against Meta for maintaining some of its users' passwords without protection or encryption. The inquiry was opened after Meta informed the DPC five years ago, in 2019, that it had maintained passwords in 'plaintext' for many users, adding that they hadn't been accessed by people outside the corporation,
According to the DPC, passwords must not be stored as plaintext, considering the risks of abuse that arise from persons accessing such data. This most recent fine makes the total amount of GDPR fines slapped on Meta to €2.5 billion, including a record €1.2 billion fine in 2023 that Meta is appealing.
🔗 Reuters
🧑💻 @agamtechtricks
The Data Protection Commission (DPC) has levied a €91 million, or around $101.5 million, fine against Meta for maintaining some of its users' passwords without protection or encryption. The inquiry was opened after Meta informed the DPC five years ago, in 2019, that it had maintained passwords in 'plaintext' for many users, adding that they hadn't been accessed by people outside the corporation,
According to the DPC, passwords must not be stored as plaintext, considering the risks of abuse that arise from persons accessing such data. This most recent fine makes the total amount of GDPR fines slapped on Meta to €2.5 billion, including a record €1.2 billion fine in 2023 that Meta is appealing.
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥20🤡5👍4🗿2
The Tor Project Merges with Tails OS
The Tor Project is merging with Tails, a portable Linux-based OS designed for privacy and anonymity. This merger aims to streamline collaboration, improve sustainability, and enhance outreach programs to counter growing digital threats. Tails, which connects to the internet via Tor by default, will now operate under the Tor Project's structure, pooling resources for greater impact.
The Tor Project and Tails share a long history, both focused on privacy in an era of increasing surveillance.
says intrigeri, Team Lead Tails
🔗 Tor | TechCrunch
🧑💻 @agamtechtricks
The Tor Project is merging with Tails, a portable Linux-based OS designed for privacy and anonymity. This merger aims to streamline collaboration, improve sustainability, and enhance outreach programs to counter growing digital threats. Tails, which connects to the internet via Tor by default, will now operate under the Tor Project's structure, pooling resources for greater impact.
The Tor Project and Tails share a long history, both focused on privacy in an era of increasing surveillance.
Running Tails as an independent project for 15 years has been a huge effort, but not for the reasons you might expect. The toughest part wasn't the tech–it was handling critical tasks like fundraising, finances, and HR. After trying to manage those in different ways, I’m really relieved that Tails is now under the Tor Project’s wing. In a way, it feels like coming home."
says intrigeri, Team Lead Tails
🔗 Tor | TechCrunch
🧑💻 @agamtechtricks
🔥35👍6❤3
ATT • Tech News
Microsoft will try the data-scraping Windows Recall feature again in October Microsoft plans to reintroduce its controversial Recall feature to Windows Insider PCs in October. Recall, a service that continuously captures screenshots and text data of user…
Microsoft’s more secure Windows Recall feature can also be uninstalled by users
Recall is now opt-in and can be fully uninstalled, along with the AI models that Microsoft is using to power Recall.
Screenshot processing is now handled within a secure virtual machine, fully separated from the user interface. Data access is secured through Windows Hello authentication, and all memory is wiped clean once the Recall app is closed.
Recall will now also operate only on Copilot Plus PCs with BitLocker, virtualization-based security, boot protections, and kernel DMA protection.
🔗 Windows | The Verge
🧑💻 @agamtechtricks
Recall is now opt-in and can be fully uninstalled, along with the AI models that Microsoft is using to power Recall.
Screenshot processing is now handled within a secure virtual machine, fully separated from the user interface. Data access is secured through Windows Hello authentication, and all memory is wiped clean once the Recall app is closed.
Recall will now also operate only on Copilot Plus PCs with BitLocker, virtualization-based security, boot protections, and kernel DMA protection.
🔗 Windows | The Verge
🧑💻 @agamtechtricks
👏28👍7🤡4😍1
YouTube and YouTube Music missing songs due to expired ‘SESAC’ license
YouTube and YouTube Music in the US have removed many songs due to a licensing dispute with SESAC, which represents songwriters and publishers.
YouTube is in talks with SESAC to reach a new agreement. Artists like Adele, R.E.M., and Bob Dylan are affected, with older albums missing but newer music still available. YouTube states it takes copyright seriously and hopes to resolve the issue soon.
🔗 9to5Google
🧑💻 @agamtechtricks
YouTube and YouTube Music in the US have removed many songs due to a licensing dispute with SESAC, which represents songwriters and publishers.
YouTube is in talks with SESAC to reach a new agreement. Artists like Adele, R.E.M., and Bob Dylan are affected, with older albums missing but newer music still available. YouTube states it takes copyright seriously and hopes to resolve the issue soon.
Officially, YouTube is telling users that its “music license agreement with SESAC has expired without an agreement on renewal conditions despite our best efforts. for this reason, we have blocked content on YouTube in the US known to be associated with SESAC – as in line with copyright law.”
🔗 9to5Google
🧑💻 @agamtechtricks
🤣32👍9🫡3😈2
Arch Linux has entered into a direct collaboration with Valve
Arch Linux has officially partnered with Valve, the creators of Steam and the Steam Deck. Valve chose Arch Linux for SteamOS 3, the Steam Deck's operating system, due to its efficiency and low resource requirements.
Now, Valve is providing backing for two critical Arch Linux projects: a build service infrastructure and a secure signing enclave.
Lead developer Levente Polyak mentioned that this support will enable Arch's development team to focus more on these key projects, rather than relying solely on volunteers, speeding up the resolution of some long-standing issues.
🔗 Arch Linux
🧑💻 @agamtechtricks
Arch Linux has officially partnered with Valve, the creators of Steam and the Steam Deck. Valve chose Arch Linux for SteamOS 3, the Steam Deck's operating system, due to its efficiency and low resource requirements.
Now, Valve is providing backing for two critical Arch Linux projects: a build service infrastructure and a secure signing enclave.
Lead developer Levente Polyak mentioned that this support will enable Arch's development team to focus more on these key projects, rather than relying solely on volunteers, speeding up the resolution of some long-standing issues.
Please open Telegram to view this post
VIEW IN TELEGRAM
🔥56👍2❤1
WhatsApp and Cloudflare Launch Plexi for Enhanced Security
WhatsApp has teamed up with Cloudflare to enhance the security of end-to-end encrypted messages through a new auditing process for Key Transparency. This partnership introduces Plexi, an auditing tool designed to monitor and verify the integrity of public keys used in encryption, ensuring secure user communication.
Plexi functions as an independent auditor, checking the logs of public keys to confirm their accuracy and integrity during transmission. The auditing architecture, illustrated in the attached image, reinforces the trustworthiness of public keys, helping to prevent tampering and maintain secure communication for users.
🔗 WaBetaInfo
🧑💻 @agamtechtricks
WhatsApp has teamed up with Cloudflare to enhance the security of end-to-end encrypted messages through a new auditing process for Key Transparency. This partnership introduces Plexi, an auditing tool designed to monitor and verify the integrity of public keys used in encryption, ensuring secure user communication.
Plexi functions as an independent auditor, checking the logs of public keys to confirm their accuracy and integrity during transmission. The auditing architecture, illustrated in the attached image, reinforces the trustworthiness of public keys, helping to prevent tampering and maintain secure communication for users.
🔗 WaBetaInfo
🧑💻 @agamtechtricks
🤔9👍6🤣5🤡3👎1🆒1
Forwarded from Mishaal's Android News Feed
You probably heard about Epic's latest lawsuit against Google, which alleges they were involved in the decision to make Samsung's Auto Blocker feature be enabled by default in the latest version of One UI.
(Auto Blocker, if you aren't aware, is a feature that, when enabled, blocks sideloading apps from outside the Google Play Store or Samsung Galaxy Store.)
Google is now coming out to say that Epic's lawsuit is a "meritless and dangerous move" and that they did not request Samsung create their Auto Blocker feature. Google goes on to state that "Android device makers are free to innovate and design additional safety features for their devices."
I find the use of the word "create" in Google's statement to be interesting. Epic didn't allege that Google made Samsung create the Auto Blocker feature but rather made them turn it on by default. However, Epic admitted that they don't yet have any proof that there was any collusion. We'll have to see how things go in court.
Edit: And here's Samsung's statement, via The Verge:
(Auto Blocker, if you aren't aware, is a feature that, when enabled, blocks sideloading apps from outside the Google Play Store or Samsung Galaxy Store.)
Google is now coming out to say that Epic's lawsuit is a "meritless and dangerous move" and that they did not request Samsung create their Auto Blocker feature. Google goes on to state that "Android device makers are free to innovate and design additional safety features for their devices."
I find the use of the word "create" in Google's statement to be interesting. Epic didn't allege that Google made Samsung create the Auto Blocker feature but rather made them turn it on by default. However, Epic admitted that they don't yet have any proof that there was any collusion. We'll have to see how things go in court.
Edit: And here's Samsung's statement, via The Verge:
Contrary to Epic Game’s assertions, Samsung actively fosters market competition, enhances consumer choice, and conducts its operations fairly.
The features integrated into our devices are designed in accordance with Samsung’s core principles of security, privacy, and user control, and we remain fully committed to safeguarding users’ personal data. Users have the choice to disable Auto Blocker at any time.
We plan to vigorously contest Epic Game’s baseless claims.
🤣9👀3
This media is not supported in your browser
VIEW IN TELEGRAM
Reddit is making sitewide protests basically impossible
Reddit has introduced a new policy that requires moderators to obtain admin approval before making subreddits private or changing their content types (such as from public to NSFW).
This move comes after last year's protests over API pricing, during which thousands of subreddits went private, causing disruptions to the platform.
Subreddits with fewer than 5,000 members or that are less than 30 days old will have their requests automatically approved. Moderators still have the ability to restrict posts for up to seven days without approval using a new “temporary events” feature.
🔗 The Verge
🧑💻 @agamtechtricks
Reddit has introduced a new policy that requires moderators to obtain admin approval before making subreddits private or changing their content types (such as from public to NSFW).
This move comes after last year's protests over API pricing, during which thousands of subreddits went private, causing disruptions to the platform.
Subreddits with fewer than 5,000 members or that are less than 30 days old will have their requests automatically approved. Moderators still have the ability to restrict posts for up to seven days without approval using a new “temporary events” feature.
Please open Telegram to view this post
VIEW IN TELEGRAM
🤡39🤬3👍2💩1
Forwarded from Winaero
KB5043145, the most recent optional update for Windows 11 to date, causes multiple issues for many users. The most serious one is a blue screen of death that makes the PC unbootable. Microsoft has confirmed the bug and is working on a solution.
After upgrading the device to Windows 11 OS Build 22621.4249, a number of users faced the inability to start the computer. The only solution that was of help for them is to uninstall the update from the recovery environment.
Sometimes, the bug makes Windows 11 to start into the BitLocker recover environment, especially after several failed recovery attempts.
Among the mentioned BSOD issues, users also report that the same update may prevent USB ports from working. As most modern peripheral devices connect via USB, this breaks them. Keyboards, mouses, and webcam stop working. The latter issue mainly affects N6005 and N5105 Intel NUCs, and Asus TUF / ROG laptops, and other gaming products from the same vendor.
If you are affected - then uninstall the buggy update:
After upgrading the device to Windows 11 OS Build 22621.4249, a number of users faced the inability to start the computer. The only solution that was of help for them is to uninstall the update from the recovery environment.
Sometimes, the bug makes Windows 11 to start into the BitLocker recover environment, especially after several failed recovery attempts.
Among the mentioned BSOD issues, users also report that the same update may prevent USB ports from working. As most modern peripheral devices connect via USB, this breaks them. Keyboards, mouses, and webcam stop working. The latter issue mainly affects N6005 and N5105 Intel NUCs, and Asus TUF / ROG laptops, and other gaming products from the same vendor.
If you are affected - then uninstall the buggy update:
wusa.exe /uninstall /kb:5043145. Run the command from WinRE.Winaero
The latest optional update KB5043145 causes BSOD in Windows 11, so be careful
KB5043145, the most recent optional update for Windows 11 to date, causes multiple issues for many users. The most serious one is a blue screen of death
🤡26👍2
Microsoft Paint is getting Photoshop-like generative AI fill and erase features
Paint will introduce tools like Generative Fill and Generative Erase, allowing users to add or remove objects from images using adjustable brushes, much like Adobe Photoshop.
The Photos app will gain Generative Erase and a Super-Resolution feature, which can upscale images by up to 8x, surpassing the 4x upscaling in Adobe Lightroom. Additionally, Microsoft's diffusion model has been upgraded to deliver better quality, faster processing, and improved moderation.
These new AI-powered features will be available on Copilot Plus PCs for free.
🔗 The Verge
🧑💻 @agamtechtricks
Paint will introduce tools like Generative Fill and Generative Erase, allowing users to add or remove objects from images using adjustable brushes, much like Adobe Photoshop.
The Photos app will gain Generative Erase and a Super-Resolution feature, which can upscale images by up to 8x, surpassing the 4x upscaling in Adobe Lightroom. Additionally, Microsoft's diffusion model has been upgraded to deliver better quality, faster processing, and improved moderation.
These new AI-powered features will be available on Copilot Plus PCs for free.
Please open Telegram to view this post
VIEW IN TELEGRAM
Please open Telegram to view this post
VIEW IN TELEGRAM
👍18🔥6❤2