Tim Cook og Kina – Pixel Envy

https://pxlnv.com/linklog/that-was-tim/

The Tim Cook story at Apple is an almost poetic arc. Upon arrival, he fundamentally overhauled the way its products would be made, primarily by moving manufacturing to Japan, Taiwan, and China. This groundwork is what allowed him to transform the company when he arrived as CEO, growing it into a global behemoth and working within China to create the best and most precise electronics manufacturing chain anywhere. And that became a problem for him. The Chinese government was able to use that as leverage, and the tie-up became politically untenable in the United States, too. Cook’s precise supply chain management directly led to his appeasement of strongmen.

Ruters egne tester viser: Oslos elbusser kan fjernstyres – NRK

https://www.nrk.no/stor-oslo/ruters-egne-tester-viser_-oslos-elbusser-kan-fjernstyres-1.17629321

Ruter tok bussene fra hverandre og undersøkte dem i et rom der signaler ble isolert.

Der fant de ut at de kinesiske elbussene kan tas kontroll over av produsenten.

Ifølge Ruter har produsenten fjerntilgang til dette på hver enkelt buss:

  • Pogramvareoppdatering
  • Diagnostikk
  • Styringssystem for batteri- og kraftforsyning

«I teorien kan bussen derfor stoppes eller gjøres ubrukelig av produsenten,» melder Ruter.

U.S. officials urge Americans to use encrypted apps amid cyberattack

https://www.nbcnews.com/tech/security/us-officials-urge-americans-use-encrypted-apps-cyberattack-rcna182694

Amid an unprecedented cyberattack on telecommunications companies such as AT&T and Verizon, U.S. officials have recommended that Americans use encrypted messaging apps to ensure their communications stay hidden from foreign hackers.

The hacking campaign, nicknamed Salt Typhoon by Microsoft, is one of the largest intelligence compromises in U.S. history, and it has not yet been fully remediated. Officials on a news call Tuesday refused to set a timetable for declaring the country’s telecommunications systems free of interlopers. Officials had told NBC News that China hacked AT&T, Verizon and Lumen Technologies to spy on customers.

Ekspert advarer mot kinesiske elbiler – Forsvaret har ingen begrensninger – NRK

https://www.nrk.no/innlandet/ekspert-advarer-mot-kinesiske-elbiler-_-forsvaret-har-ingen-begrensninger-1.17138704

Mange tusen kinesiske biler ruller nå på norske veier. Sikkerhetsekspert advarer om potensialet for overvåkning som finnes i disse bilene.

I prosjektet de kaller «Lion Cage», som har fått omtale både internasjonalt og i Norge, har de gått grundig gjennom hvordan bilen fungerer, hva slags data den samler inn og hvor den sender dem.

– Vi finner forbausende mye datatrafikk mellom bilen og Kina. Det var en overraskelse. Vi hadde ikke forventa det, sier han.

Prosjektet har funnet ut at bilen kommuniserer med USA, Canada, Kina, men også Russland og Australia.

– Og så ser vi også hvor mye data som sendes. Det er ganske interessant. Selv om bilen er slått av, så vil bilen kommunisere.

Årsaken til at sikkerhetsekspertene har sett så grundig på de kinesiske bilene er den kinesiske etterretningsloven.

Den tolkes av mange som at ethvert kinesisk selskap må samarbeide med myndighetene når de blir bedt om det.

We hacked a robot vacuum — and could watch live through its camera - ABC News

https://www.abc.net.au/news/2024-10-04/robot-vacuum-hacked-photos-camera-audio/104414020

The largest home robotics company in the world has failed to fix security issues with its robot vacuums despite being warned about them last year.

Without even entering the building, we were able to silently take photos of the (consenting) owner of a device made by Chinese giant Ecovacs.

Ecovacs initially said its users “do not need to worry excessively” about Giese’s findings.

After he first revealed the vulnerability in public, the company’s security committee downplayed the issue, saying it requires “specialised hacking tools and physical access to the device”.

It’s hard to square their statement with the reality. All it had taken was my $300 smartphone, and I hadn’t even laid eyes on Sean’s robot until after hacking into it.

Ecovacs eventually said it would fix this security issue. At the time of publication, only some models have been updated to prevent this attack.

Several models — including the latest flagship model released in July this year — remain vulnerable.

Company worker in Hong Kong pays out £20m in deepfake video call scam | The Guardian

https://www.theguardian.com/world/2024/feb/05/hong-kong-company-deepfake-video-conference-call-scam

Police investigate after employee tricked into transferring money to fraudsters posing as senior officers of her firm

Apple AirDrop leaks user data like a sieve. Chinese authorities say they’re scooping it up. | Ars Technica

https://arstechnica.com/security/2024/01/hackers-can-id-unique-apple-airdrop-users-chinese-authorities-claim-to-do-just-that/

Chinese authorities recently said they’re using an advanced encryption attack to de-anonymize users of AirDrop in an effort to crack down on citizens who use the Apple file-sharing feature to mass-distribute content that’s outlawed in that country.

TikTok Editorial Analysis – Schneier on Security

https://www.schneier.com/blog/archives/2024/01/tiktok-editorial-analysis.html

TikTok seems to be skewing things in the interests of the Chinese Communist Party.

Sellafield nuclear site hacked by groups linked to Russia and China |The Guardian

https://www.theguardian.com/business/2023/dec/04/sellafield-nuclear-site-hacked-groups-russia-china

It is still not known if the malware has been eradicated. It may mean some of Sellafield’s most sensitive activities, such as moving radioactive waste, monitoring for leaks of dangerous material and checking for fires, have been compromised.

Sources suggest it is likely foreign hackers have accessed the highest echelons of confidential material at the site, which sprawls across 6 sq km (2 sq miles) on the Cumbrian coast and is one of the most hazardous in the world.

Sellafield covers 6 sq km on the Cumbrian coast and is one of the most hazardous nuclear sites in the world. Photograph: David Levene/The Guardian
The full extent of any data loss and any ongoing risks to systems was made harder to quantify by Sellafield’s failure to alert nuclear regulators for several years, sources said.

‘The Problem With Jon Stewart’ Is Ending – Pixel Envy

https://pxlnv.com/linklog/problem-with-jon-stewart-ending/

Apple is a big, sprawling conglomerate. If it cannot handle Stewart’s inquiries about China or our machine learning future, I think it should ask itself why that is, and whether those criticisms have merit.

Utah sues TikTok for getting children ‘addicted’ to its algorithm – The Verge

https://www.theverge.com/2023/10/10/23911803/utah-tiktok-child-addiction-china-deception-lawsuit

Utah’s consumer protection division alleges that TikTok misrepresents itself as independent of China and is designed to ‘hook users’ into its endless feed.

Chinese programmer ordered to pay 1m yuan for using virtual private network | The Guardian

https://www.theguardian.com/world/2023/oct/09/chinese-programmer-ordered-to-pay-1m-yuan-for-using-virtual-private-network

A programmer in northern China has been ordered to pay more than 1m yuan to the authorities for using a virtual private network (VPN), in what is thought to be the most severe individual financial penalty ever issued for circumventing China’s “great firewall”.

The programmer, surnamed Ma, was issued with a penalty notice by the public security bureau of Chengde, a city in Hebei province, on 18 August. The notice said Ma had used “unauthorised channels” to connect to international networks to work for a Turkish company.

Chinese communist party ‘accessed Hong Kong protesters’ TikTok data’ | The Guardian

https://www.theguardian.com/technology/2023/jun/07/communist-party-accessed-hong-kong-protesters-tiktok-data-former-executive-says

A former executive at TikTok’s parent company, ByteDance, has alleged that the Chinese Communist party accessed user data from the social video app belonging to Hong Kong protesters and civil rights activists.

Yintao Yu, a former head of engineering at ByteDance’s US operation, claimed in a legal filing that a committee of Communist party members accessed TikTok data that included the users’ network information, Sim card identifications and IP addresses in a bid to identify the individuals and their locations.

The claims, in a wrongful dismissal lawsuit brought by Yu in a California court and reported by the Wall Street Journal, also allege the party accessed TikTok users’ communications, monitored Hong Kong users who uploaded protest-related content and that Beijing-based ByteDance maintained a “backdoor channel” for the party to access US user data.

Yu alleges in the filing that members of a Communist party committee inside ByteDance had access to a “superuser” credential which was also called a “God credential” and allowed them to view all data collected by ByteDance.

TikTok Creators’ Sensitive Financial Information Stored In China

https://www.forbes.com/sites/alexandralevine/2023/05/30/tiktok-creators-data-security-china/

TikTok has stored the most sensitive financial data of its biggest stars — including those in its “Creator Fund” — on servers in China. Earlier this year, CEO Shou Chew told Congress “American data has always been stored in Virginia and Singapore.”

Android phones are vulnerable to fingerprint brute-force attacks

https://www.bleepingcomputer.com/news/security/android-phones-are-vulnerable-to-fingerprint-brute-force-attacks/

Researchers at Tencent Labs and Zhejiang University have presented a new attack called ‘BrutePrint,’ which brute-forces fingerprints on modern smartphones to bypass user authentication and take control of the device.

Brute-force attacks rely on many trial-and-error attempts to crack a code, key, or password and gain unauthorized access to accounts, systems, or networks.

The attacker needs physical access to the target device to launch a BrutePrint attack

AI image generation puts video game illustrators out of work - Rest of World

https://restofworld.org/2023/ai-image-china-video-game-layoffs/

Recent breakthroughs in AI image generation have created widespread anxiety in China’s video game art industry.

Given the high quality of AI-produced artwork, many illustrators are losing their jobs to AI image generators such as Stable Diffusion and DALL-E 2.

The gaming industry’s job market was already precarious after the Chinese government’s licensing freeze in 2021 threw thousands of game developers out of business.

Android app from China executed 0-day exploit on millions of devices - Ars Technica

https://arstechnica.com/information-technology/2023/03/android-app-from-china-executed-0-day-exploit-on-millions-of-devices/

Fast-growing e-commerce app Pinduoduo had an EvilParcel stow-away.

Android apps digitally signed by China’s third-biggest e-commerce company exploited a zero-day vulnerability that allowed them to surreptitiously take control of millions of end-user devices to steal personal data and install malicious apps, researchers from security firm Lookout have confirmed.

Safari Safe Browsing Blocks GitLab in Hong Kong

https://mjtsai.com/blog/2023/01/30/safe-browsing/

The lights have been on at a Massachusetts school for over a year because no one can turn them off

https://www.nbcnews.com/news/us-news/lights-massachusetts-school-year-no-one-can-turn-rcna65611

The lighting system was installed at Minnechaug Regional High School when it was built over a decade ago and was intended to save money and energy. But ever since the software that runs it failed on Aug. 24, 2021, the lights in the Springfield suburbs school have been on continuously, costing taxpayers a small fortune.

Paul Mustone, president of the Reflex Lighting Group, said the parts they need to replace the system at the school have finally arrived from the factory in China and they expect to do the installation over the February break.

TikTok Spied On Forbes Journalists

https://www.forbes.com/sites/emilybaker-white/2022/12/22/tiktok-tracks-forbes-journalists-bytedance/

An internal investigation by ByteDance, the parent company of video-sharing platform TikTok, found that employees tracked multiple journalists covering the company, improperly gaining access to their IP addresses and user data in an attempt to identify whether they had been in the same locales as ByteDance employees.

According to materials reviewed by Forbes, ByteDance tracked multiple Forbes journalists as part of this covert surveillance campaign, which was designed to unearth the source of leaks inside the company following a drumbeat of stories exposing the company’s ongoing links to China.