Tag: privacy

  • App Lock Security Coming to Android 17: A Much-Anticipated Upgrade for User Privacy

    App Lock Security Coming to Android 17: A Much-Anticipated Upgrade for User Privacy

    In a rapidly digitalizing world, smartphones have become the vaults of our sensitive data, often stored within various applications. These applications, at times, require an additional layer of security for optimal safeguarding. Android, despite its Private Space feature, lacks a user-friendly method to secure these apps. However, this could potentially change with the forthcoming major update of Google’s mobile operating system (OS).

    App Lock Feature in Android 17

    In a bid to enhance the security on its platform, Google might finally incorporate a native app lock feature in its Android 17 update. This function is expected to operate at the system level of the OS. Recent investigations into the code of an Android Canary release revealed indications of this feature.

    The code introduced a fresh App Lock Application Programming Interface (API), compatible with any default launcher. This implies that the function will not be exclusive to Pixel phones but will be available across all Android devices.

    Bridging the Gap

    Android users may already be using app locks and might be puzzled by this update. However, it’s essential to note that these locks are not native to the OS. Instead, they are solutions developed independently by Original Equipment Manufacturers (OEMs), such as OnePlus.

    Google’s indigenous solution, known as Private Space, differs significantly from elementary app locking. Apps within Private Space are entirely segregated from the rest of the OS, function under a separate user profile, and are challenging to access.

    On the contrary, an app lock feature merely secures apps, necessitating face unlock, fingerprint authentication, or a passcode for access. Apart from this, the apps stay connected to the rest of the operating system and can be placed on the home screen. Google already provides a similar feature with its Google Photos app.

    Tech giant Apple was one of the first major brands to introduce an app lock feature with its iOS 18. In contrast, Samsung, Google, and Motorola don’t have this feature. Samsung supports a Secure Folder, and Motorola has its own Moto Secure menu containing folders, both of which function similarly to Google’s Private Space.

    A Much-needed Feature

    The introduction of an app lock feature is a move many find surprising it wasn’t implemented earlier in more devices. It strikes the ideal balance between security and convenience, potentially serving a broader user base than any isolated space.

    Questions & Answers

    What is the new feature expected in Android 17?
    There are indications that Android 17 may include a native app lock feature.

    How does the app lock feature differ from Google’s Private Space?
    Unlike the Private Space, which completely isolates certain apps from the rest of the OS, an app lock merely requires face unlock, fingerprint authentication, or a passcode for access, while the apps remain connected to the rest of the operating system.

    Which other major brand has an app lock feature?
    Apple was one of the first major brands that introduced an app lock feature with iOS 18.

  • Coupang Data Breach: Unmasked Details of 33 Million Customers Sparks Privacy Fears

    Coupang Data Breach: Unmasked Details of 33 Million Customers Sparks Privacy Fears

    Increased apprehension has gripped South Korea following a significant data leak at e-commerce giant, Coupang. Officials have indicated that this breach could have been overlooked for an extended period.

    Scale of Data Leakage

    Coupang, a United States-listed merchant, revealed on a recent Saturday that the private information of 33.7 million consumers, essentially its entire client base, had been jeopardized. The vulnerable data encompass names, contact numbers, email addresses, and delivery locations. The company reassured that financial information, credit card specifics, and login details remained untouched.

    Based on Coupang’s findings, unauthorized infiltration into the delivery-related private data seems to have been carried out via foreign servers from June 24 onwards.

    Investigation Update

    Individuals familiar with the situation have shared that the police have pinpointed at least one suspect. The person is allegedly a former Chinese worker of Coupang who has since dissociated from both the company and the nation. The authorities initiated an inquiry after receiving a complaint.

    Coupang confirmed detecting the data leak on November 18 and informed the regulators within the subsequent two days. The corporation initially stated that approximately 4,500 accounts had been impacted.

    Implications of the Breach

    The magnitude of the data exposure, which is now proven to be considerably more extensive and long-standing than initially conveyed, has unsettled consumers. They are apprehensive that their data might be exploited for fraudulent activities or phishing strategies. The event now surpasses the cyber breach at SK Telecom in April, which affected data from 23.2 million users and led to a record penalty of 134.8 billion won.

    The final repercussions could escalate as the investigation progresses. A similar recent incident involving Lotte Card initially denied leakage of financial data following a breach in September. The company had to backtrack two weeks later and admit that credit card numbers and other critical data had indeed been laid bare.

    Questions & Answers

    What type of data has been compromised in the breach at Coupang?
    Names, phone numbers, email addresses, and delivery locations of customers have been exposed.

    Who has been identified as a possible suspect in this data breach incident?
    The police have identified a former Chinese worker of Coupang as a possible suspect.

    What are the possible implications of the data breach at Coupang?
    This breach has unsettled consumers who fear their personal data might be exploited for fraudulent purposes or phishing schemes. There is also a possibility of monetary penalties for the company.

  • Exposed: WhatsApp Flaw Unveils Billions of User Numbers, Is Your Privacy At Risk?

    Exposed: WhatsApp Flaw Unveils Billions of User Numbers, Is Your Privacy At Risk?

    A team of Austrian researchers has reportedly found a way to extract the phone numbers of 3.5 billion WhatsApp users, leaving many to wonder if their own information has been compromised.

    Method of Extraction

    Any user can determine if a number is registered on WhatsApp by performing a simple search within the platform. If the number in question is associated with a WhatsApp account, the searcher will be privy to the account’s profile picture and user name. Scientists from the University of Vienna in Austria employed this very strategy to gather the phone numbers of 3.5 billion WhatsApp users.

    In their search for vulnerabilities within WhatsApp’s end-to-end encryption system, the Austrian team discovered that the application lacked an important security measure known as rate-limiting protection. Such a feature would thwart the abuse of WhatsApp’s number-checking function. By exploiting this absence of protection, the team was able to obtain 30 million WhatsApp numbers registered in the U.S. within just 30 minutes. By the conclusion of their research, they had amassed the WhatsApp numbers of 3.5 billion users worldwide.

    The extraction process was remarkably simple: the researchers merely altered the number sequence. In doing so, they could determine whether a number was registered on WhatsApp. Of the 3.5 billion users whose numbers were collected, approximately 57% had their privacy settings configured to display their profile picture to anyone. Given this, the researchers were able to easily collect these users’ profile pictures. They were also able to view the profile text of 29% of these users.

    A Neglected Flaw

    Interestingly, WhatsApp’s parent company, Meta, was alerted to this vulnerability in 2017 by a different team of researchers. Despite this, Meta failed to address the issue, meaning it remained straightforward to determine whether a number was registered on WhatsApp.

    Earlier this year, the Austrian researchers brought their findings to Meta’s attention, emphasizing the severity of the security risk this flaw presents to WhatsApp users. Their concern is that malicious entities could exploit this loophole to obtain photos and phone numbers of a significant number of WhatsApp users.

    Fortunately, in October of this year, Meta finally implemented a stricter rate-limiting measure on WhatsApp. This has ensured that such large-scale contact discovery is no longer feasible on the platform. The researchers have securely deleted their database containing the extracted phone numbers and associated data.

    Other messaging platforms, such as Signal, already incorporate rate-limiting protection. This means that mass-scale contact discovery, like what previously occurred on WhatsApp, is not possible on these platforms.

    Previous Security Breaches

    This is not the first instance of Meta’s apps coming under scrutiny due to security flaws. Last year, a database containing information on 530 million Facebook users was publicly leaked online. Intriguingly, bad actors exploited a vulnerability akin to the one found in WhatsApp, accessing data by utilising Facebook’s feature that allows users to search profiles by entering a phone number. This allowed them to scrape the personal data of 530 million users.

    WhatsApp may have its benefits, such as being free, supporting end-to-end encryption and accommodating group video calls. However, after learning of its security flaws and data collection practices, some users are considering alternatives. Platforms like Signal, which collects minimal data and provides advanced privacy features, are becoming increasingly popular.

    Questions & Answers

    What are the implications of the Austrian researchers’ findings?

    The research highlights a major flaw in WhatsApp’s security system. This loophole could potentially be exploited by cyber criminals to extract photos and phone numbers of a large number of WhatsApp users.

    Has this flaw been addressed?

    Meta, WhatsApp’s parent company, has taken measures to rectify this flaw. In October of this year, a stricter rate-limiting measure was applied to WhatsApp, preventing such extensive contact discovery from taking place.

    What alternatives exist for WhatsApp users concerned about security?

    Signal is one such alternative. The platform already has rate-limiting protection in place, and it collects almost no data from users. It also offers advanced privacy features, such as concealing your IP address during calls, and preventing others from taking screenshots of your conversations.

  • Apple And Microsoft Challenge Chrome’s Dominance: Unveiling The Privacy Controversy

    Apple And Microsoft Challenge Chrome’s Dominance: Unveiling The Privacy Controversy

    Apple has recently cautioned iPhone users against employing the Chrome browser, citing security risks. This situation may remind one of a previous advertising scenario in 2024 where the tech giant, through creative visuals, illustrated Android users exploring the Chrome Browser in public and being surveilled by transforming cameras. These cameras symbolized internet user trackers, which failed when attempting to spy on users of Apple’s own Safari browser. The underlying message being that Safari provides superior protection of users’ personal information than its counterparts, specifically pointing out the Chrome browser.

    Google’s Privacy Sandbox: A Failed Attempt at Privacy

    In a parallel move, Microsoft attempted to dissuade Windows users from using Chrome. They promoted their own browser, Microsoft Edge, as a trustworthy alternative that operates on the same technology as Chrome. Despite these concerted efforts by Microsoft and Apple to dethrone Chrome, the browser boasts a massive user base of over 3 billion worldwide. However, Google recently dropped a bombshell by announcing the end of its Privacy Sandbox project, its proposed alternative to third-party cookies for the web and Android applications.

    Back in January 2024, Google initiated the process of phasing out third-party cookies from Chrome. The agenda was to replace them with the Privacy Sandbox, aiming to gauge a consumer’s interests without resorting to widespread internet tracking to push personalized advertisements. Such targeted ads typically command higher prices from the advertisers due to their increased effectiveness, thereby contributing to Google’s revenue.

    The Privacy Sandbox was intended to shift ad selection and data processing tasks directly to the user’s browser and device, eliminating the need for third-party trackers to transmit individual user data across the web. Despite initial plans, Google resolved not to discontinue the use of third-party cookies last year, culminating in the current halt to the six-year-old Privacy Sandbox initiative.

    The Future of Chrome Amidst Privacy Concerns

    Although Chrome users may once again be subjected to tracking and personalized advertising, Chrome’s substantial market share is anticipated to remain unaffected. Currently, the browser dominates over 70% of the market, both in mobile and desktop segments. However, emerging competition from AI browsers like Perplexity’s Comet and an upcoming AI browser from Open AI’s parent ChatGPT could potentially pose a threat to Chrome.

    The Privacy Sandbox tools that Google has decided to withdraw include a host of features such as Attribution Reporting API for both Chrome and Android, IP Protection, On-Device Personalization, Private Aggregation, and more.

    An API, or Application Programming Interface, serves as an intermediary enabling two distinct software interfaces to communicate and exchange data. This process can be likened to the functioning of a restaurant, where an app seeking data is the customer, the API is the waiter relaying the order to the kitchen (the server), and then serving the prepared food (data) back to the customer.

    Google’s cancellation of the Privacy Sandbox was attributed to its “low levels of adoption”, indicating that it failed to provide sufficient value to its users.

    Questions & Answers

    Why did Apple caution its users against using Chrome?
    Apple cited security risks as the primary reason for advising its users against using the Chrome browser. The company highlighted through a past advertisement that its own Safari browser offers better protection of personal data.

    What was the purpose of Google’s Privacy Sandbox?
    Google’s Privacy Sandbox was intended to replace third-party cookies in Chrome. It sought to understand consumer interests without having to track user behavior across the internet, facilitating the delivery of personalized ads.

    Why did Google decide to cancel the Privacy Sandbox?
    Google stated that the Privacy Sandbox had not been adopted widely and that it wasn’t providing enough value to its users, which led to its decision to discontinue the project.

  • Google in hot water yet again over data collection and privacy concerns

    Google in hot water yet again over data collection and privacy concerns

    A newly uncovered internal database has shed light on Google’s questionable data collection practices, raising concerns about the tech giant’s commitment to user privacy. The database, spanning from 2013 to 2018, reveals a wide range of incidents where personal data was collected and stored across various Google apps and products, including Waze, YouTube, and AdWords.

    While Google claims to prioritize transparency, the leaked database reportedly paints a different picture. Reports within the database, ranked by priority, detail instances of data collection that were often not publicly disclosed. Some incidents involved sensitive information, such as the recording of children’s voices through Gboard’s microphone and the gathering of license plate information through Street View.

    Although Google maintains that these incidents were resolved, the sheer number and variety of reports raise concerns about the company’s ability to safeguard user data. The leaked database, obtained by 404 Media, highlights the potential risks associated with Google’s vast data collection practices.

    Among the examples of data inappropriately collected or leaked were payment information for employees through travel agency software Sabre, addresses and trips taken through Waze’s carpool feature, and Docs files mistakenly made public.

    In response to the 404 Media report, Google stated that the reports were over six years old and had been reviewed and resolved. However, the company’s confirmation of “aspects” of the dataset suggests that there may be some truth to the allegations.

    This is not the first time Google has faced scrutiny over its data practices. Recent leaks of Google Search API documents, obtained by the same company, have also raised questions about the company’s transparency regarding its search operations. While potentially taking months to fully analyze, Google has not disputed the authenticity of that particular leak when questioned.

    These revelations add to a growing list of privacy concerns surrounding Google’s data collection practices, and it looks like Google has some damage control due ahead. As users become increasingly aware of this leaked material, it remains to be seen how this will impact the company’s reputation and future operations.

  • WhatsApp tests Material Design tweaks on Android to make it look more like its iOS app

    WhatsApp tests Material Design tweaks on Android to make it look more like its iOS app

    WhatsApp has been hard at work lately adding features and applying design tweaks in order to set itself apart from competing products and become more relevant in the U.S. market, where SMS/MMS/RCS and iMessage are king. The latest of these attempts being its apparent attempt to make its iOS and Android apps look more alike than ever.

    In the latest update of WhatsApp Beta on Android (v2.23.13.16), as reported by WaBetaInfo, WhatsApp appears to be experimenting with a bottom navigation bar (also called an action bar) in the style of Material Design 3.
    The navigation bar will replace the current tabbed interface that sits at the top of the chat list. This gives users the option to access Chats, Communities, Status, and Calls from the bottom by cycling through a more clearly labeled navigation system accentuated by its corresponding icons.
    The bottom navigation bar switches between a dark and white color scheme, depending on your theme choice. This is the same navigation bar that is used on the iOS version of WhatsApp, and it is more in line with Google’s design guidelines for Android apps.
    The new bottom navigation bar is currently being tested with a limited number of users, but it is expected to be rolled out to everyone eventually. The change is likely to be welcomed by users who prefer a more simplified interface, and it will also make it easier to use WhatsApp with one hand.

    In addition to the new bottom navigation bar, WhatsApp has also been rolling out Material Design tweaks such as redesigned switches and floating action buttons with rounded menus. It is unclear when these changes will be rolled out to everyone, as they are currently available in beta and to a limited amount of users, but they are all part of WhatsApp’s efforts to improve the app’s user experience.

  • Starbucks, Shake Shack summoned over excessive personal data collection

    Starbucks, Shake Shack summoned over excessive personal data collection

    Chinese regulators in financial hub Shanghai summoned three firms including Starbucks and Shake Shack earlier this week for collecting excessive personal information, the city’s cyberspace regulator said on Wednesday.

    The regulators urged these firms to comprehensively rectify, protect personal information and safeguard the legitimate rights and interests of consumers, Shanghai’s cyberspace regulator said in a statement.

    Currently, two firms including Shake Shack have made initial improvements to the issues, and Starbucks is actively making adjustments, the regulator said

  • McDonald’s Korea fined for breach of customers’ personal data

    McDonald’s Korea fined for breach of customers’ personal data

    McDonald’s Korea was given a fine of 696 million won ($532,110) on Wednesday after the personal data of 4.87 million customers was leaked to hackers due to the firm’s lax data management.

    The Personal Information Protection Commission handed out the fine to the Korean branch of the American fast food chain, along with a financial penalty of about 10 million won for the data breach.

    According to the commission’s findings, McDonald’s Korea did not perform sufficient access control, leaving a backup file containing the personal data of its restaurant and McDelivery customers accessible via protocols for file sharing.

    As a result, the personal data of more than 4.87 million customers was hacked and leaked. McDonald’s Korea was also found to have not destroyed the personal data of 766,846 customers for whom the data retention period had expired, and belatedly notified authorities and customers of the data leakage.

  • Personal Data of Passengers, Employees Stolen in Ransomware Attack on AirAsia

    Personal Data of Passengers, Employees Stolen in Ransomware Attack on AirAsia

    AirAsia, a budget airline that operates out of Malaysia, is dealing with the aftermath of a ransomware attack that saw the personal data of some five million people stolen.

    To add insult to injury, the gang of responsible cyber criminals said they would not follow up on the beleaguered airline due to how “sloppy” its internal organization and management appeared to be.

    The perpetrators of the ransomware attack appear to be “Daixin Team,” a group that is thought to be based in or around China and that has become active enough in recent months to merit an alert from the FBI and CISA. The group has been active since at least June 2022, but previously had shown a strong preference for targeting healthcare and public health facilities via unpatched VPN vulnerabilities.

    The ransomware attack on AirAsia occurred on November 11 and 12, with samples of the stolen personal data being leaked to the group’s dark web site about a week later. The posted samples contain employee personal information as well as passenger booking information. The group says that it has captured “all employees” personal data and an unspecified quantity of passenger data.

    While Daixin Team continues to shake down AirAsia using the stolen personal data, it said there would be no further ransomware attacks on the company due to its “chaotic organization” and poor cybersecurity. However, this did not appear to be out of pity, but at frustration at having to sort through a tangled internal network to find information of value; the group said it would leave it to “newcomers” to pick through the “garbage.” However, the hackers also said they would stop short of locking anything that could be life-threatening, such as air traffic control and radar systems.

    Founded in 1993, AirAsia has the largest fleet in Malaysia and flies to the greatest range of international and domestic destinations. The airline carried a total of about 4.81 million passengers in 2021, indicating that the personal data stolen by the attackers may be limited to bookings taking place within the last year or so. Part of the leak of sample data stolen during the ransomware attack shows a database of passenger names with ID numbers and the total cost of their ticket.

    Ransomware attacks have become both more frequent and more expensive to weather in recent years, but they have also become more dangerous. Attackers have now demonstrated that they are willing to cause real-world damage, potentially even death, if they think it will increase their chances of a payout. That was a red line that was really not crossed before the major attacks on critical infrastructure and hospitals in 2021.

    It is unclear if Daixin Team’s claim that it had access to air traffic control and other sensitive airline applications that could cause physical damage is accurate. This would generally require direct access to an individual airport’s systems rather than an airline’s internal network or booking system. There have been numerous attacks on both airlines and the public-facing portion of airport websites at this point, none of which have yielded that sort of access; about the closest example was an attack on Bristol Airport in 2018 that caused outages of the flight status screens for two days, but did not impact actual aircraft operations. Another attack in India earlier this year disrupted flight scheduling for several days, but did not prevent planes from flying. FedEx’s air shipment service has also been hit by ransomware attacks at least twice, but flight operations are not known to have been impacted.

    Ransomware attacks have been demonstrated to be capable of indirectly causing death at this point, however, in the health care industry that Daixin Team likes to target. In 2020 a German patient being transported by ambulance for emergency services was turned away from a hospital that had its systems shut down by ransomware, and died en route to the next closest facility. And in 2021, a baby in Alabama died after a mother was not given tests that may have saved its life, due to ransomware limiting hospital capabilities at the time. Though hospitals are generally not well-funded, hackers target them due to the wealth of personal data they hold and the fact that they cannot afford to have systems down for any length of time.

    Nick Tausek, Lead Security Automation Architect at Swimlane, notes that this is a risk that all types of organizations now need to consider: “Since June of this year, the Daixin Team has attacked several healthcare organizations, including the OakBend Medical Center in Texas and the Fitzgibbon Hospital in Missouri. Both attacks resulted in the exposure of personally identifiable information (PII) on the dark web and represented a significant threat to patient and employee safety. Now, the Daixin Team seems to be shifting towards new targets – global critical infrastructure. Like prior Daixin Team attacks, the attack on AirAsia has resulted in sensitive data exposure. Unfortunately, AirAsia will most likely face large financial burdens and a crisis of confidence from its consumer base due to this attack.”

    “To mitigate the chances of similar attacks in the future, it is imperative that organizations adopt low-code security automation to help detect and respond to threats in real-time by allowing complete visibility into IT environments. Endpoint security tools that integrate low-code security automation give organizations a cohesive protection strategy that protects customers and employees as well as keeps essential services like air travel up and running,” recommended Tausek.

  • Facebook launches new privacy tools to protect teens

    Facebook launches new privacy tools to protect teens

    Facebook is taking another step toward strengthening teens protection by introducing a new set of privacy tools. The social app announced today some updates to its policy of protecting young people from harm. After releasing similar features last year to restrict adults from messaging teens they aren’t connected to, this year Facebook plans to introduce new ways to protect teens from messaging suspicious adults they aren’t connected to.

    As per Facebook’s statement, a “suspicious” account is one that belongs to an adult that may have recently been blocked or reported by a young person (among other things). Additionally, Facebook introduced another layer of protection by removing the message button on teens’ Instagram accounts when suspicious adults view them. Both these features are now being tested by Facebook and will be made generally available if they prove to be efficient.

    New safety tools have been announced too, in the form of notifications which will prompt teens to report accounts after they block someone, as well as safety notices that contain information on how to navigate inappropriate messages from adults.

    More importantly, Facebook released new privacy defaults for teens using its social app. Starting today, Facebook users under the age of 16 (or under 18 in certain countries) will be defaulted into more private settings when they join the service. Those who are already on the app are encouraged to use these more private settings for:

    • Who can see their friends list
    • Who can see the people, Pages and lists they follow
    • Who can see posts they’re tagged in on their profile
    • Reviewing posts they’re tagged in before the post appears on their profile
    • Who is allowed to comment on their public posts

    Finally, Facebook announced that it’s working with the National Center for Missing and Exploited Children (NCMEC) to create a global platform for teens who are worried intimate images they made might be shared on public online platforms without their consent.

  • Apple iPhone users sue Meta for allegedly stealing their personal data

    Apple iPhone users sue Meta for allegedly stealing their personal data

    When Apple started to allow iPhone users to opt-out of getting tracked by third-party apps with the App Tracking Transparency (ATT) feature last year, Facebook complained the loudest with CEO Mark Zuckerberg shelling out the big bucks it costs to run full-page ads in some big-time newspapers. And as it turned out, Zuckerberg knew exactly what was coming and as he figured, it was a disaster.
    According to the Electronic Frontier Foundation, in the year since the ATT rolled out, Facebook lost $10 billion in potential revenue. There is speculation that Facebook has come up with a way to help it generate the revenue it lost from Apple’s decision to roll out ATT. Just last month, we told you that Felix Krause, a former Google engineer, and a security researcher, alleged that Meta is tracking the keystrokes made by iOS users typing on Facebook’s in-app browser.
    Krause said that Facebook and its Instagram unit could use JavaScript to grab your credit card data, address, passwords, and more without your permission. Now comes word that two class action suits have been filed against Facebook parent Meta by three iOS users who are citing Krause’s allegations. The lawsuits were filed on behalf of all iOS users impacted and accuse Meta of committing several illegal actions, including:
    • The concealing of privacy risks.
    • Ignoring the privacy choices made by iOS users.
    • “Intercepting, monitoring, and recording all activity on third-party websites viewed in Facebook or Instagram’s browser.
    The plaintiffs claim that Meta used the data collected to collect “personally identifiable information, private health details, text entries, and other sensitive, confidential facts.” The users, whose information was allegedly stolen by Meta, had no idea that this was going on. The latest filing was made yesterday by California’s Gabriele Willis and Kerreisha Davis from Louisiana.
    Adam Polk, a lawyer, working for the law firm of Girard Sharp LLP, which is handling the case involving Willis and Davis, said it is important to stop Meta from continuing to hide their continued privacy invasions. The law firm also pointed out that in the past, Facebook (now Meta) had been fined $5 billion by the Federal Trade Commission (FTC).
    Polk said that “Merely using an app doesn’t give the app company license to look over your shoulder when you click on a link. This litigation seeks to hold Meta accountable for secretly monitoring people’s browsing activity through its in-app tracking even when they haven’t allowed Meta to do that.”
    The complaints related to the class action suit “revealed that Meta has been injecting code into third-party websites, a practice that allows Meta to track users and intercept data that would otherwise be unavailable to it.” Researcher Krause has determined that Meta uses code to override the wishes of Facebook users wanting to use their default browser forcing them to use Facebook’s in-app browser instead when using the app.
  • Telegram announces new Premium plan coming in June

    Telegram announces new Premium plan coming in June

    What started as a rumor a few months ago has become reality this week: Telegram is going Premium. Well, the free tier will remain available as is, but a paid tier will also be added which will offer some extra features, resources and speed.

    Telegram’s founder and CEO, Pavel Durov, announced today that his company will introduce a Premium tier this month, but he did not make any mentions regarding the price. Previous rumors pointed to a possible $5/month subscription for those who want Telegram Premium, but the information hasn’t been confirmed yet.

    What we do know is that all existing features will remain free, and even users who don’t subscribe to Telegram Premium will get some of its benefits, such as the ability to view extra-large documents, media and stickers sent by Premium users, as well as the option to tap to add Premium reactions already pinned to a message to react in the same way.

    The addition of a Premium tier is meant to keep existing features free while offering those who want more the chance to acquire those extra features they need, at least according to Telegram. On top of that, a Premium subscription will allow users to support eh app and receive new features before those who use Telegram for free.

    We will probably never know whether the move is meant to simply support the extra resources Telegram will spend to add those new features or the company plans to actually make money to pay the bills. The bottom line is that even Telegram’s CEO believes that the app “should be funded primarily by its users, not advertisers,” which implies that the amount of ads will remain limited.

  • Samsung Internet’s latest release focuses on privacy and security

    Samsung Internet’s latest release focuses on privacy and security

    The 17th iteration of Samsung Internet is finally ready for primetime, the South Korean company confirmed this week. We’ve previously reported about the beta version of Samsung Internet 17.0, but if you missed the news, here is what’s coming in this release.

    As the title says, this release mainly focuses on privacy and security. First off, Samsung Internet 17.0 further improves the AI-powered Smart anti-tracking feature, which is now turned on by default. The privacy function is meant to prevent third parties attempting to track users’ personal information from being successful at that.

    Additionally, Samsung Internet 17.0 offers users an interesting overview of how the browser is protecting their web experience. The updated version of the browser features a visual snapshot of a user’s privacy dashboard via the Quick Access page, which provides a detailed record of weekly activities and settings that can be adjusted.

    The latest version of Samsung Internet now allows users to take advantage of external security or on-device security keys as an alternative for SMS or app-based two-factor authentication.

    Last but not least, Samsung Internet 17.0 comes with several improvements to its overall user experience such as the ability to drag and drop tabs into custom tab groups. Also, the update brings enhanced search experience across bookmarks, history and saved pages. The official version of Samsung Internet 17.0 is now available for download on Google Play and Galaxy Store.

  • Meta’s Privacy Center enables Facebook users to learn more about their privacy settings

    Meta’s Privacy Center enables Facebook users to learn more about their privacy settings

    Meta has announced the Privacy Center, its latest feature where users of services like Facebook can learn how Meta collects their private information. In the Privacy Center, users will also be able to read Meta’s Data Policy and get additional information on how to use the privacy and security controls of the service. Furthermore, the Privacy Center will become Meta’s hub for all privacy and security settings the company has introduced over the years.

    Currently, the Privacy Center has five modules, and each of these modules offers guides and controls for a related privacy matter.

    The five modules are:

    • Security: For setting up two-factor authentication, updating other security settings, and getting additional information about your safety.
    • Sharing: For finding information on how to change the settings for your posts and how to use the Manage Activity tool.
    • Collection: For additional information on what data Meta collects and how to use tools like Access Your Information.
    • Use: For managing and receiving extra information about how Meta uses your data.
    • Ads: For managing the displayed ads through controls like Ad Preferences and for learning how the service decides what ads to show.

    At the moment, the Privacy Center is available only on the desktop version of Facebook to a limited number of users in the US. In the future, the Privacy Center will be accessible on the mobile version of Facebook as well. Meta also announced that it’s planning to roll out the Privacy Center to more users and to more of its apps. Although the Privacy Center currently has five modules, Meta will continue to add more modules and controls to it with time.

  • European carriers seek to block one key iPhone privacy feature

    European carriers seek to block one key iPhone privacy feature

    Last year Apple announced one new key privacy feature for iOS called Private Relay. This new feature is currently in beta in iOS 15, iPadOS 15, and macOS Monterey, and it is available only for users enrolled in the Apple beta software program.

    Even though the feature is still in beta, some major European telecom operators have signed an open letter to protest its future rollout. Carriers including Vodafone, Telefonica, and T-Mobile have voiced concerns that “Private Relay cuts off networks and servers from accessing vital network data and metadata” thus having “significant consequences in terms of undermining European digital sovereignty”.

    The open letter has raised more than a couple of eyebrows since its publication, mainly because Private Relay is a feature not much different from a regular VPN, and those have been around for ages. But let’s see what Private Relay is in more detail.

    When you browse the internet some information can be seen and recorded by your network provider – this includes DNS records, IP addresses, and more. Normally this information is used to build a profile of your browsing activity to be potentially used at a later date (usually for advertising purposes).

    The Private Relay feature is designed to hide all this information from third parties when you browse the net on your Apple device (you must use Safari browser for the feature to work, though). According to Apple, no single party – not even Apple itself – can see both your IP address and the sites that you’re visiting.

    This is done by using two internet relays – the first encrypts your DNS records (the sites you’re visiting), and the second generates a temporary IP address to connect you to the site you want to see. The first relay doesn’t have your DNS records, and the second relay doesn’t have your IP address.

    By using such a method Apple is able to effectively protect users’ privacy from third parties while still managing to offer a fast browsing experience. At the moment, you need to be enrolled in the Apple Beta Program to be able to use this feature. Follow the instructions on the site in order to participate. If you’re already a beta member, you can turn on Privacy Relay by following the next steps.

    How to turn on Private relay on iPhone, iPad, or iPod touch

    • Go to Settings
    • Tap on [your username]
    • Select iCloud
    • Then tap Private Relay.

    Private Relay is off by default in all beta releases so far but Apple has officially announced that when the feature reaches the final rollout phase it will be switched on by default. You can always turn off the Private Relay feature for specific networks by following the next steps: on you iPhone or iPad, go to Settings > Wi-Fi, then tap the More Info button next to the Wi-Fi network, then tap on “Turn off Private Relay.”

    The Telegraph says that telecom operators in the UK also support the open letter, with O2 filing official complaints to regulators in the country. Private Relay is highly dependent on local laws and regulations, and Apple has already restricted the availability of the feature.

    Private Relay won’t be offered in China, Belarus, Colombia, Egypt, Kazakhstan, Saudi Arabia, South Africa, Turkmenistan, Uganda, and the Philippines. It remains unclear whether any European countries will be added to this list.