Why T-Mobile needs Wi-Fi calling: its network can’t match AT&T and Verizon

T-Mobile’s “data strong network.” T-Mobile T-Mobile US’ latest “Un-carrier” move is just about the most amazing thing ever, CEO John Legere said last week. “This is like adding millions of towers to our network in a single day,” Legere boasted in a press release . “The difference between us and the traditional carriers is that they’ll do everything they can to make more money off you. We’ll do everything we can to solve your problems.” The innovation is actually something that T-Mobile has had since 2007: Wi-Fi calling. It makes sense for T-Mobile to promote Wi-Fi calling now, given that Apple is adding the capability to iPhones in iOS 8. The initiative has some nice benefits for customers—T-Mobile offered to upgrade all customers to phones that can make Wi-Fi calls and is giving out a free “Personal CellSpot,” a Wi-Fi router that prioritizes voice calls. Read 22 remaining paragraphs | Comments

Read this article:
Why T-Mobile needs Wi-Fi calling: its network can’t match AT&T and Verizon

Android Browser flaw a “privacy disaster” for half of Android users

Thanks to a bug in the Android Browser, your cookies aren’t safe. Surian Soosay A bug quietly reported on September 1 appears to have grave implications for Android users. Android Browser, the open source, WebKit-based browser that used to be part of the Android Open Source Platform (AOSP), has a flaw that enables malicious sites to inject JavaScript into other sites. Those malicious JavaScripts can in turn read cookies and password fields, submit forms, grab keyboard input, or do practically anything else. Browsers are generally designed to prevent a script from one site from being able to access content from another site. They do this by enforcing what is called the Same Origin Policy (SOP): scripts can only read or modify resources (such as the elements of a webpage) that come from the same origin as the script, where the origin is determined by the combination of scheme (which is to say, protocol, typically HTTP or HTTPS), domain, and port number. The SOP should then prevent a script loaded from http://malware.bad/ from being able to access content at https://paypal.com/. Read 9 remaining paragraphs | Comments

View post:
Android Browser flaw a “privacy disaster” for half of Android users

Watch out, California’s self-driving car permits take effect today

Audi On Tuesday, permits for self-driving cars issued by the California Department of Motor Vehicles (DMV) took effect for the first time. Applications for the permits began in May 2014. Only the Volkswagen Group (which includes Volkswagen and Audi cars among others), Mercedes Benz, and Google have been issued permits for their 29 total vehicles. Overall, that represents a miniscule fraction of all 32 million registered cars in the Golden State. Bernard Soriano, a DMV spokesman, told Ars that Tuesday also marked the first time those numbers had been disclosed outside of the agency. “There are a handful of different companies that are completing their application,” he added, noting that the DMV expected to issue more permits soon. “They’re all large automakers.” Read 6 remaining paragraphs | Comments

Continue reading here:
Watch out, California’s self-driving car permits take effect today

Hacker exploits printer Web interface to install, run Doom

Doom on a printer’s menu screen! Personally, we can’t wait until someone makes Descent playable on a toaster. Context Internet Security On Friday, a hacker presenting at the 44CON Information Security Conference in London picked at the vulnerability of Web-accessible devices and demonstrated how to run unsigned code on a Canon printer via its default Web interface. After describing the device’s encryption as “doomed,” Context Information Security consultant Michael Jordon made his point by installing and running the first-person shooting classic  Doom on a stock Canon Pixma MG6450. Sure enough, the printer’s tiny menu screen can render  a choppy and discolored but playable version of id Software’s 1993 hit, the result of Jordon discovering that Pixma printers’ Web interfaces didn’t require any authentication to access. “You could print out hundreds of test pages and use up all the ink and paper, so what?” Jordon wrote at Context’s blog report about the discovery , but after a little more sniffing, he found that the devices could also easily be redirected to accept any code as legitimate firmware. A vulnerable Pixma printer’s Web interface allows users to change the Web proxy settings and the DNS server. From there, an enterprising hacker can crack the device’s encryption in eight steps, the final of which includes unsigned, plain-text firmware files. The hacking possibilities go far beyond enabling choppy, early ’90s gaming: “We can therefore create our own custom firmware and update anyone’s printer with a Trojan image which spies on the documents being printed or is used as a gateway into their network,” Jordon wrote. Read 4 remaining paragraphs | Comments

Read More:
Hacker exploits printer Web interface to install, run Doom

US gov’t threatened Yahoo with $250K daily fine if it didn’t use PRISM

Yahoo reports that it is on the verge of releasing 1,500 pages of documents related to a long court battle over its participation in the PRISM program, a National Security Agency program revealed last summer as part of the Snowden leaks. A leaked top-secret slide about PRISM shows that Yahoo was one of the first participants, having begun contributing to the database in March of 2008. It did so under severe duress. Company executives believed the government’s demand for data was “unconstitutional and overbroad” and fought it in court. “Our challenge, and a later appeal in the case, did not succeed,” explained Yahoo General Counsel Ron Bell in a blog post published today. “The Foreign Intelligence Surveillance Court (FISC)… ordered us to give the U.S. Government the user data it sought in the matter.” Read 5 remaining paragraphs | Comments

View post:
US gov’t threatened Yahoo with $250K daily fine if it didn’t use PRISM

A big chunk of the Sierra Nevada caught fracturing on video

If you like geology, you’re used to relying on an active imagination. Most geologic processes occur too slowly to see them play out for yourself. Many of the exceptions are dangerous enough that you might not want a front row seat or rare enough that the odds of being there to witness it are disheartening. Sometimes, though, the Earth throws us a bone—or in this case, a gigantic slab of granite. One interesting way that rocks weather and crumble apart is called “exfoliation.” Like the skin-scrubbing technique, this involves the outermost layers of exposed igneous or metamorphic bedrock sloughing off in a sheet. Over time, this tends to smooth and round the outcrop—Yosemite’s Half Dome  providing a spectacular example. We’re not entirely sure just what drives the peeling of an outcrop’s skin like this, but the classic explanation is that it’s the result of bringing rocks that formed at great pressure up to the surface. Once there, the outer layers can expand slightly, creating a physical mismatch with the layers below them. Read 2 remaining paragraphs | Comments

Read More:
A big chunk of the Sierra Nevada caught fracturing on video

Cable companies want to unbundle broadcast TV, and broadcasters are angry

Iain Watson A Congressional proposal to let cable and satellite customers choose which broadcast TV channels they pay for has led to a battle between small cable companies and broadcasters. While cable companies usually are opponents of mandates to sell channels individually instead of in bundles , in this case they are fighting for à la carte and against the broadcasters. The “Local Choice” proposal by US Sen. Jay Rockefeller (D-WV) and Sen. John Thune (R-SD) affects local broadcast stations such as affiliates of NBC, CBS, ABC, and Fox. A group called TVfreedom.org that represents local broadcasters and other organizations today criticized the American Cable Association (ACA) for supporting Local Choice. “We believe ‘Local Choice’ represents a frontal assault on free and local TV broadcasting,” TVfreedom Public Affairs Director Robert Kenny wrote . “It would tilt television’s balance of power in favor of pay-TV providers at the expense of broadcasters invested in localism. It would cost consumers more on their monthly bills, and do nothing to address shoddy pay-TV service or the deceptive billing practices of cable and satellite TV providers.” TVfreedom is composed of “local broadcasters, community advocates, network television affiliate associations, multicast networks, manufacturers and other independent broadcaster-related organizations” and says its mission is to make sure “cable and satellite TV providers [are] held accountable for stifling innovation and repeatedly using their own customers as bargaining chips while increasing their record profits.” The group chided the ACA for supporting à la carte pricing this year despite arguing in a previous case that “Current technology costs make à la carte a financial impossibility for ACA member systems, the business model is entirely unproven, and no lawful basis exists for imposing regulated a la carte.” Read 10 remaining paragraphs | Comments

Read More:
Cable companies want to unbundle broadcast TV, and broadcasters are angry

Oculus targets $200 to $400 range for consumer version of VR headset

Kyle Orland When Oculus eventually releases a consumer version (CV1) of its Rift virtual reality headset, the company wants to “stay in that $200-$400 price range,” founder Palmer Luckey told Eurogamer in a recent interview. That lines up roughly with the $350 currently being charged for the second Development Kit (DK2) version of the Rift, which began shipping to developers recently. Luckey warned Eurogamer, though, that the consumer version price range “could slide in either direction depending on scale, pre-orders, the components we end up using, business negotiations…” One thing that won’t be sliding around anymore is the technical specs for the CV1. “We know what we’re making and now it’s a matter of making it.” Luckey wouldn’t be pinned down on the specifics of those consumer specs, but he said to expect a jump in resolution above the DK2, similar to the 720p to 1080p jump we saw between the first development kits (DK1) and DK2. Luckey also teased improvements to 90Hz “or higher” refresh rate (up from 75Hz in DK2) and lowered weight and size for the consumer headset. Read 2 remaining paragraphs | Comments

View post:
Oculus targets $200 to $400 range for consumer version of VR headset

Appeals court says Yelp’s ad sales tactics don’t extort small businesses

Robyn Lee On Tuesday, a California appeals court ruled that Yelp’s ad sales strategies do not extort small businesses and merely amount to “hard bargaining” by the company. Yelp lets anyone review a business, and businesses can’t opt out of being reviewed. So when Yelp’s ad sales team began calling around asking companies to buy advertising in exchange for displaying good reviews more prominently, some storefronts cried foul. In 2010, four small business owners banded together to sue Yelp for extortion after they refused to buy advertising from Yelp and allegedly found that bad reviews were displayed more prominently. Two of the business owners also alleged that Yelp authored negative reviews to induce them to advertise or in retaliation after the business declined to buy advertising. Read 8 remaining paragraphs | Comments

See more here:
Appeals court says Yelp’s ad sales tactics don’t extort small businesses

Los Angeles cops do not need to hand over license plate reader data, judge finds

This LAPD patrol car is equipped with a LPR unit, mounted just in front of the light bar on the roof of the vehicle. Steve Devol A Los Angeles Superior Court judge will not force local law enforcement to release a week’s worth of all captured automated license plate reader (ALPR, also known as LPR) data to two activist groups that had sued for the release of the information, according to a decision issued on Thursday. In May 2013, the American Civil Liberties Union of Southern California and the Electronic Frontier Foundation sued the Los Angeles Police Department (LAPD) and the Los Angeles Sheriff’s Department (LASD) in an attempt to compel the agencies to release a week’s worth of LPR data from a certain week in August 2012. The organizations have not determined yet whether they will file an appeal. The organizations had claimed that these agencies were required to disclose the data under the California Public Records Act . In late July 2012, the ACLU and its affiliates sent requests to local police departments and state agencies across 38 states to request information on how LPRs are used. Read 15 remaining paragraphs | Comments

Read More:
Los Angeles cops do not need to hand over license plate reader data, judge finds