In the latest update on NSA documents leaked by Edward Snowden, The Intercept is reporting on the surveillance establishment's efforts to use the Google Play Store to distribute spyware. Another fun fact from the data dump is that these agencies found and exploited a security hole in the ultra-popular UC Browser for years until an activist group informed its developers about it just about a month ago.
The information comes from a set of slides distributed to agency specialists in 2012 discussing plans for the use of mobile devices in surveillance. Read More
Google has been rolling out updates to Smart Lock over the past months, adding On-body detection and Trusted voice, and while this recent change doesn't bring other options to the table, it does make the feature more user-friendly.
Previously, if you had set your Android phone or tablet to trust a certain place, Bluetooth device, or any of your physical attributes, it would keep your phone unlocked when those variables were in effect, but you'd still come across a secure lock screen if you left your handset untouched for a period of time. Read More
Alarm.com, despite its security-oriented URL, has become a thriving platform for home management hardware and software both defensive and benign. The latest update to the app, version 3.2, adds a handful of small but important features and adjustments that should make it much easier for users of compatible automated home hardware to get stuff done. The updated version appears to be rolling out in the Play Store with no delays, so no need to track down the APK. Read More
In early 2014, Microsoft started providing Office 365 users with the option to secure their accounts with multi-factor authentication. When signing in, folks have to respond to a phone call, text message, or phone notification after entering their password. The feature has since worked on PCs and smartphones, but when Office came to Android tablets, support was absent.
According to the identical changelogs accompanying the latest versions of Microsoft Word, Excel, and PowerPoint for tablets, that has changed. Read More
The increasingly popular team chat platform Slack confirmed in a blog post today that a database containing user profile information had been breached. Slack says the database contained usernames, email addresses, hashed passwords, and information users could connect to their account like Skype names. There's no evidence that the hackers were able to decrypt user passwords, but they did have access to the above-mentioned information.
Slack says it has blocked the unauthorized access, and - in the same blog post - announced the launch of a two-factor authentication option for its users, along with a "password kill switch" for team owners. Read More
The next time you sign into your Twitch account, you're going to have to change your passwords and stream keys. You will also need to reconnect your Twitter and YouTube accounts. Why? The same reason as always. It appears someone may have obtained unauthorized access to some Twitch user account information, and these precautions are for your own good.
Twitch has sent out emails to affected users of the video game streaming service, warning that their usernames, email addresses, encrypted passwords, last IP addresses, phone numbers, addresses, and dates of birth may have been accessed. Read More
We've heard a number of rumors about Google launching its own Mobile Virtual Network Operator (MVNO), codenamed Nova. According to reports, the service will source wireless service from Sprint and T-Mobile, but it will rely on Wi-Fi networks to bear most of the weight of both data and voice services (though VoIP). While the details of this plan still aren't clear, another piece of the puzzle just emerged that indicates Google is going to offer its own virtual private network (VPN) service, and it may be targeted specifically at Nova subscribers. Read More
It's not uncommon for security firms to raise their public profile by publishing analyses of device security and vulnerabilities. However, Bluebox Security really stuck its virtual foot in its mouth this time. After posting what appeared to be a damning exposé of malware shipping on Xiaomi's Mi4 last week, the company has had to post an addendum admitting that it was fooled by a fake and Xiaomi's phones aren't shipping with malware after all. Oops. Read More
Cerberus is a solid little app that makes it easy (or at least easier) to find/lock your phone or tablet if it's lost or stolen. The app has accumulated over a million downloads on the Play Store, so clearly it has earned some loyal users. The update to version 3.1 adds a couple of crucial features: full support for both Android Wear and Android 5.0. If you have either one, you'll appreciate the added functionality. Read More