Windows 8.1 Universal Apps Can Run On Desktop, Mobile, and Xbox

It’s a moment we’ve been waiting for for a long time. No, Microsoft’s various operating systems are not merging quite yet, but they’re about to get universal apps that work across all devices. Including the Xbox One. And best of all, you only have to buy each app once and it works everywhere. Read more…        

Continued here:
Windows 8.1 Universal Apps Can Run On Desktop, Mobile, and Xbox

Samsung Galaxy back-door allows for over-the-air filesystem access

Developers from the Replicant project (a free Android offshoot) have documented a serious software back-door in Samsung’s Android phones , which “provides remote access to the data stored on the device.” They believe it is “likely” that the backdoor could provide “over-the-air remote control” to “access the phone’s file system.” At issue is Samsung’s proprietary IPC protocol, used in its modems. This protocol implements a set of commands called “RFS commands.” The Replicant team says that it can’t find “any particular legitimacy nor relevant use-case” for adding these commands, but adds that “it is possible that these were added for legitimate purposes, without the intent of doing harm by providing a back-door. Nevertheless, the result is the same and it allows the modem to access the phone’s storage.” The Replicant site includes proof-of-concept sourcecode for a program that will access the file-system over the modem. Replicant has created a replacement for the relevant Samsung software that does not allow for back-door access. Samsung Galaxy devices running proprietary Android versions come with a back-door that provides remote access to the data stored on the device. In particular, the proprietary software that is in charge of handling the communications with the modem, using the Samsung IPC protocol, implements a class of requests known as RFS commands, that allows the modem to perform remote I/O operations on the phone’s storage. As the modem is running proprietary software, it is likely that it offers over-the-air remote control, that could then be used to issue the incriminated RFS messages and access the phone’s file system. …The incriminated RFS messages of the Samsung IPC protocol were not found to have any particular legitimacy nor relevant use-case. However, it is possible that these were added for legitimate purposes, without the intent of doing harm by providing a back-door. Nevertheless, the result is the same and it allows the modem to access the phone’s storage. However, some RFS messages of the Samsung IPC protocol are legitimate (IPC_RFS_NV_READ_ITEM and IPC_RFS_NV_WRITE_ITEM) as they target a very precise file, known as the modem’s NV data. There should be no particular security concern about these as both the proprietary implementation and its free software replacement strictly limit actions to that particular file. Samsung Galaxy Back-door        

See more here:
Samsung Galaxy back-door allows for over-the-air filesystem access

Android gives you the ability to deny your sensitive data to apps

Android privacy just got a lot better. The 4.3 version of Google’s mobile operating system now has hooks that allow you to override the permissions requested by the apps you install. So if you download a flashlight app that wants to harvest your location and phone ID , you can install it, and then use an app like AppOps Launcher to tell Android to withhold the information. Peter Ecklersley, a staff technologist at the Electronic Frontier Foundation, has written up a good explanation of how this works , and he attributes the decision to competitive pressure from Ios, which allows users to deny location data to apps, even if they “require” it during the installation process. I think that’s right, but not the whole story: Android has also always labored under competitive pressure from its free/open forks, like Cyanogenmod. In the days when Android didn’t allow tethering (as a sop to the mobile carriers, who are the gatekeepers to new phones for many people), Cyanogenmod signed up large numbers of users, simply by adding this functionality . Google added tethering to Android within a couple of versions. Some versions of Cyanogenmod have had the option tell your phone to lie to apps about its identity, location, and other sensitive information — a way to get around the “all or nothing” installation process whereby your the apps you install non-negotiably demand your “permission” to plunder this information. I’m not surprised to see the same feature moving into the main branch of Android. This dynamic is fascinating to me: Google has to balance all kinds of priorities in rolling out features and “anti-features” (no tethering, non-negotiable permissions) in Android, in order to please customers, carriers and developers. Free/open forks like Cyanogenmod really only need to please themselves and their users, and don’t have to worry so much about these other pressures (though now that Cyanogenmod is a commercial operation , they’ll probably need to start playing nice with carriers). But because Android competes with Cyanogenmod and the other open versions, Google can’t afford to ignore the featureset that makes them better than the official version. It’s a unique, and extremely beneficial outflow of the hybrid free/commercial Android ecosystem. In the early days, that model was at an improvement on its major competitor, Apple’s iOS, which didn’t even have a permissions model. But after various privacy scandals, Apple started forcing apps to ask for permission to collect data: first location and then other categories, like address books and photos. So for the past two years, the iPhone’s app privacy options have been miles ahead of Android’s. This changed with the release of Android 4.3, which added awesome new OS features to enhance privacy protection. You can unlock this functionality by installing a tool like App Ops Launcher. When you run it, you can easily control most of the privacy-threatening permissions your apps have tried to obtain. Want to install Shazam without having it track your location? Easy. Want to install SideCar without letting it read your address book? Done.2 Despite being overdue and not quite complete, App Ops Launcher is a huge advance in Android privacy. Its availability means Android 4.3+ a necessity for anyone who wants to use the OS while limiting how intrusive those apps can be. The Android team at Google deserves praise for giving users more control of the data that others can snatch from their pockets. Awesome Privacy Tools in Android 4.3+        

Continue reading here:
Android gives you the ability to deny your sensitive data to apps

Your Next Hyundai or Kia Will Come With Android Baked In

Looks like mobile OS allegiance will soon become part of the car buying decision: Hyundai and Kia will use Android to power in-car entertainment and navigation systems in all new models, starting with the new Kia Soul and Hyundai Genesis coming at the end of the year. Read more…        

Read more here:
Your Next Hyundai or Kia Will Come With Android Baked In

The Price of 500MB of Mobile Data Across the World

Today, nearly half of the world’s total population has potential access to some kind of 3G or 4G network, which is five times the level of mobile coverage we were at just five years ago. Unfortunately, not all mobile broadband is created equal—especially where price is concerned. Read more…        

Link:
The Price of 500MB of Mobile Data Across the World

Watch Every Model of iPhone Get Speed Tested at the Same Time

Ever wonder if your iPhone 4 really was weirdly slow? Or if iOS 7, despite its bells and whistles, just has a longer boot time than your old 3G? Well wonder no longer. You’re about to find out for sure. Read more…        

More:
Watch Every Model of iPhone Get Speed Tested at the Same Time

This Gaming PC Is Smaller Than a Controller But Still Packs a Punch

There are plenty of gaming PCs designed to replace consoles , but if you’re short on space that normally means accepting something underpowered like the Ouya . But this little guy, called the Gigabyte Brix II, is both powerful and petite. Read more…        

Read the article:
This Gaming PC Is Smaller Than a Controller But Still Packs a Punch

Gmail’s Getting a Neat Freak Overhaul for Web and Mobile

Google just announced a new interface for you Gmail based around customizable tabs. The goal? To you help manage your goliath of an inbox. It looks pretty incredible. Read more…        

View article:
Gmail’s Getting a Neat Freak Overhaul for Web and Mobile

Apple can decrypt iPhones for cops; Google can remotely “reset password” for Android devices

Apple apparently has the power to decrypt iPhone storage in response to law-enforcement requests, though they won’t say how. Google can remotely “reset the password” for a phone for cops, too: Last year, leaked training materials prepared by the Sacramento sheriff’s office included a form that would require Apple to “assist law enforcement agents” with “bypassing the cell phone user’s passcode so that the agents may search the iPhone.” Google takes a more privacy-protective approach: it “resets the password and further provides the reset password to law enforcement,” the materials say, which has the side effect of notifying the user that his or her cell phone has been compromised. Ginger Colbrun, ATF’s public affairs chief, told CNET that “ATF cannot discuss specifics of ongoing investigations or litigation. ATF follows federal law and DOJ/department-wide policy on access to all communication devices.” …The ATF’s Maynard said in an affidavit for the Kentucky case that Apple “has the capabilities to bypass the security software” and “download the contents of the phone to an external memory device.” Chang, the Apple legal specialist, told him that “once the Apple analyst bypasses the passcode, the data will be downloaded onto a USB external drive” and delivered to the ATF. It’s not clear whether that means Apple has created a backdoor for police — which has been the topic of speculation in the past — whether the company has custom hardware that’s faster at decryption, or whether it simply is more skilled at using the same procedures available to the government. Apple declined to discuss its law enforcement policies when contacted this week by CNET. It’s not clear to me from the above whether Google “resetting the password” for Android devices merely bypasses the lock-screen or actually decrypts the mass storage on the phone if it has been encrypted. I also wonder if the “decryption” Apple undertakes relies on people habitually using short passwords for their phones — the alternative being a lot of screen-typing in order to place a call. Apple deluged by police demands to decrypt iPhones [Declan McCullagh/CNet] ( via /. )        

Visit link:
Apple can decrypt iPhones for cops; Google can remotely “reset password” for Android devices