Tagg: Google 74
Fake Signal and Telegram Apps in the Google Play Store - Schneier on Security
Google finds 18 zero-day vulnerabilities in Samsung Exynos chipsets
experienced attackers could easily create an exploit capable of remotely compromising vulnerable devices without triggering the targets’ attention.
Google AI chatbot Bard sends shares plummeting after it gives wrong answer - The Guardian
Google’s riposte to ChatGPT has got off to an embarrassing start after its new artificial intelligence-powered chatbot gave a wrong answer in a promotional video, as investors wiped more than $100bn (£82bn) off the value of the search engine’s parent company, Alphabet.
Google to pay nearly $400 million over deceptive location tracking practices - The Record by Recorded Future
https://therecord.media/google-to-pay-nearly-400-million-over-deceptive-location-tracking-practices/
Google has agreed to pay a $391.5 million settlement with 40 states over revelations that it continued to track users’ locations even when told explicitly not to.
The AP found that Google misled users into believing they could turn location tracking off within their account settings when in fact the company continued to collect location information within its Web & App Activity feature, which is automatically turned on when a user creates a Google account or uses an Android phone.
North Korea-backed hackers have a clever way to read your Gmail - Ars Technica
The malware, dubbed SHARPEXT by researchers from security firm Volexity, uses clever means to install a browser extension for the Chrome and Edge browsers, Volexity reported in a blog post. The extension can’t be detected by the email services, and since the browser has already been authenticated using any multifactor authentication protections in place, this increasingly popular security measure plays no role in reining in the account compromise. The extension isn’t available in Google’s Chrome Web Store, Microsoft’s add-ons page, or any other known third-party source and doesn’t rely on flaws in Gmail or AOL Mail to get installed.
Volexity President Steven Adair said in an email that the extension gets installed “by way of spear phishing and social engineering where the victim is fooled into opening a malicious document.
Report: Mercenary spyware exploited Google Chrome zero-day to target journalists - The Record by Recorded Future
A zero-day vulnerability in Google Chrome was discovered when attackers exploited it to target users in the Middle East, including journalists, cybersecurity firm Avast said Thursday.
The company attributed the attacks to a secretive Israeli firm known as Candiru — named after a notorious parasitic fish — that sells spyware to governments.
Google Says It Will Automatically Delete Location Data Collected From Visits to Health Facilities — Pixel Envy
Messages, Dialer apps sent text, call info to Google • The Register
https://www.theregister.com/2022/03/21/google_messages_gdpr/
Google’s Messages and Dialer apps for Android devices have been collecting and sending data to Google without specific notice and consent, and without offering the opportunity to opt-out, potentially in violation of Europe’s data protection law.
2FA app with 10,000 Google Play downloads loaded well-known banking trojan | Ars Technica
A fake two-factor-authentication app that has been downloaded some 10,000 times from Google Play surreptitiously installed a known banking-fraud trojan that scoured infected phones for financial data and other personal information, security firm Pradeo said.
D.C., Washington, Texas and Indiana sue Google, alleging it deceived customers about location data - The Washington Post
https://www.washingtonpost.com/technology/2022/01/24/google-location-data-ags-lawsuit/
Attorneys general from D.C. and three states sued Google on Monday, arguing that the search giant deceived consumers to gain access to their location data.
The lawsuits, filed in the District of Columbia, Texas, Washington and Indiana, allege the company made misleading promises about its users’ ability to protect their privacy through Google account settings, dating from at least 2014. The suits seek to stop Google from engaging in these practices and to fine the company.
The complaints also allege the company has deployed “dark patterns,” or design tricks that can subtly influence users’ decisions in ways that are advantageous for a business. The lawsuits say Google has designed its products to repeatedly nudge or pressure people to provide more and more location data, “inadvertently or out of frustration.” The suits allege this violates various state and D.C. consumer protection laws.
Google Caught Hackers Using a Mac Zero-Day Against Hong Kong Users
The hackers had set up a watering hole attack, meaning they hid malware within the legitimate websites of “a media outlet and a prominent pro-democracy labor and political group” in Hong Kong. Users who visited those websites would get hacked with an unknown vulnerability—in other words, a zero-day—and another exploit that took advantage of a previously patched vulnerability for MacOS that was used to install a backdoor on their computers, according to Hernandez.
Apple patched the zero-day used in the campaign in an update pushed out on September 23, according to the report.
Apple and Google Remove ‘Navalny’ Voting App in Russia - The New York Times
https://www.nytimes.com/2021/09/17/world/europe/russia-navalny-app-election.html
The app, created by allies of the opposition leader Aleksei Navalny, vanished from online stores, reflecting a new level of pressure against U.S. technology companies in the country.
Friday’s move could embolden the Kremlin as well as governments elsewhere in the world to use the threat of prosecuting employees to gain leverage against the companies. It presents a test of Silicon Valley ideals around free expression and an open internet, balanced not only against profit but against the safety of their workers.
A very brief history of every Google messaging app - The Verge
https://www.theverge.com/2021/6/21/22538240/google-chat-allo-hangouts-talk-messaging-mess-timeline
Google keeps falling into the same cycle, […], one that has repeated itself throughout the years. It’ll build out new services, integrating them into more areas of its product lineup, then try to wipe the slate clean, launch new services that (eventually) replace the old set, and start the cycle anew.
Google’s FLoC Is a Terrible Idea - Electronic Frontier Foundation
https://www.eff.org/deeplinks/2021/03/googles-floc-terrible-idea
Google can choose to dismantle the old scaffolding for surveillance without replacing it with something new and uniquely harmful.
We emphatically reject the future of FLoC. That is not the world we want, nor the one users deserve. Google needs to learn the correct lessons from the era of third-party tracking and design its browser to work for users, not for advertisers.
Why The Web Is Such A Mess - YouTube
Tim Berners-Lee envisioned a “universal information system”. What went wrong?
Google removes Android app that was used to spy on Belarusian protesters - ZDNet
App mimicked a popular anti-government news site and collected location and device owner details.
Google stops responding directly to data requests from Hong Kong government - Reuters
following the enactment of a new national security law imposed by China.
Canadian smart glasses tech will stop working, weeks after company bought by Google - CTV News
Utviklerne av Smittestopp tester nå teknologi fra Apple og Google
https://nrkbeta.no/2020/06/05/utviklerne-av-smittestopp-tester-na-teknologi-fra-apple-og-google/
Norske Simula tester Apple og Googles teknologi for kontaktsporing, men det er ikke klart om dagens app Smittestopp vil bli endret eller erstattet.