By msmash from Slashdot's closer-look department
Last week, an app on the Ubuntu Snap Store caused a stir when it was found to be riddled with a script that is programmed to mine cryptocurrency, a phenomenon whose traces has been found in several popular application stores in the recent months. Canonical promptly pulled the app from the store, but offered little explanation at the time. On Tuesday, Ubuntu-maker addressed the matter in detail. From a report: The big question is whether or not this is really malware. Canonical also pondered this and says the following. "The first question worth asking, in this case, is whether the publisher was in fact doing anything wrong, considering that mining cryptocurrency is not illegal or unethical by itself. That perspective was indeed taken by the publisher in question here, who informed us that the goal was to monetize software published under licenses that allow it, unaware of the social or technical consequences," the company wrote in a blog post. "The publisher offered to stop doing that once contacted. Of course, it is misleading if there is no indication of the secondary purpose of the application. That's in fact why the application was taken down in the store. There are no rules against mining cryptocurrencies, but misleading users is a problem," it added. Unfortunately, Canonical concedes that it simply doesn't have the resources to review all code submitted to the Snap Store. Instead, it puts the onus on the user to do their due diligence by investigating the developer before deciding to trust them.Read Replies (0)
By BeauHD from Slashdot's can-you-hear-me-now department
An anonymous reader quotes a report from Engadget: In December of 2017, the office of U.S. Senator Richard Blumenthal sent Google's CEO a letter asking for a detailed explanation of the company's privacy practices around location services. Based on a report at Quartz, the senator's letter had 12 specific questions about how Google deals with location data. In January, Google responded to all of the issues in a lengthy letter signed by Google's VP of public policy, Susan Molinari. Now, apparently unsatisfied with the response, Senators Blumenthal and Edward J. Markey have sent a written request to the FTC to investigate Google's location services, along with "any deceptive acts and practices associated with the product."
While Google's initial response refuted many of the claims made by Quartz, and explained again and again how Google and Android handles sensitive location data, the letter to the FTC again uses the report as its main basis. The crux of the new letter appears to be this: "Google has an intimate understanding or personal lives as they watch their users seek the support of reproductive health services, engage in civic activities or attend places of religious worship," wrote the senators. All it takes to expose users to data collection, say the letter's authors, is to allow an "ambiguously described feature" once and then it is silently enabled across all signed-in devices without an expiration date.Read Replies (0)
By BeauHD from Slashdot's trouble-maker department
schwit1 quotes a report from Bloomberg: A judge scolded Facebook for misconstruing his own rulings as he ordered the company to face a high-stakes trial accusing it of violating user privacy. The social media giant has misinterpreted prior court orders by continuing to assert the "faulty proposition" that users can't win their lawsuit under an Illinois biometric privacy law without proving an "actual injury," U.S. District Judge James Donato said in a ruling Monday. Likewise, the company's argument that it's immune from having to pay a minimum of $1,000, and as much as $5,000, for each violation of the law is "not a sound proposition," he said. Under the Illinois Biometric Information Privacy Act, the damages in play at a jury trial set for July 9 in San Francisco could easily reach into the billions of dollars for the millions of users whose photos were allegedly scanned without consent. Apart from his concerns about the "troubling theme" in Facebook's legal arguments, Donato ruled a trial must go forward because there are multiple factual issues in dispute, including a sharp disagreement over how the company's photo-tagging software processes human faces.Read Replies (0)
By BeauHD from Slashdot's too-good-to-be-true department
An anonymous reader quotes a report from CNET: Notches, it seems, are the new black. Originally seen -- and often criticized -- on the Essential PH-1 and iPhone X in 2017, the trend of adding notches to Android phones has only accelerated this year as phone makers look to maximize the screen size. But the Lenovo Z5 is going the other way: It's truly all-screen, and notch-free. At least, that's according to a sketch shared last Friday by Lenovo VP Chang Cheng on Weibo, a Twitter-like platform in China. Cheng's teaser post says (according to Google Translate) that the Lenovo Z5 is the company's new flagship phone. Besides that, the post leaves it pretty vague.
All-screen phones look cool, but they challenge the manufacturer to find a place to put front cameras, sensors and other hardware. That's why we see bezels on some phones and notches on others. It's not clear what Lenovo plans to do with the front camera on the Lenovo Z5. Cheng's post claims that "four technological breakthroughs" and "18 patented technologies" were made for the phone, but doesn't go into details. One of the first smartphones to launch with an edge-to-edge display was the Xiaomi Mi Mix. It launched with next to no bezel or notch, leaving many to wonder where the earpiece would be. What Xiaomi managed to do was use what it calls "cantilever piezoelectric ceramic acoustic technology." Basically, it's a component that converts electrical energy into mechanical energy to transfer to the phone's internal metal frame, which then vibrates to create sound. It's possible the Z5 relies on a similar technology, or bone conduction technology found in many headphones and some smartphones.
< article continued at Slashdot's too-good-to-be-true department
>Read Replies (0)
By BeauHD from Slashdot's western-vs-eastern-medicine department
"According to The New York Times, the state of California is funding an experiment through The Ceres Community Project to test the influence of a healthy diet on the recovery of state Medicaid patients with long-term serious illnesses," writes Slashdot reader MonteCarloMethod. From the report: Over the next three years, researchers from the University of California, San Francisco, and Stanford will assess whether providing 1,000 patients who have congestive heart failure or Type 2 diabetes with a healthier diet and nutrition education affects hospital readmissions and referrals to long-term care, compared with 4,000 similar Medi-Cal patients who don't get the food.
The California study will build on more modest and less rigorous earlier research. A study in Philadelphia by the Metropolitan Area Neighborhood Nutrition Alliance retroactively compared health insurance claims for 65 chronically ill Medicaid patients who received six months' of medically tailored meals with a control group. The patients who got the food racked up about $12,000 less a month in medical expenses. Another small study by researchers at U.C.S.F. tracked patients with H.I.V. and Type 2 diabetes who got special meals for six months to see if it would positively affect their health. The researchers found they were less depressed, less likely to make trade-offs between food and health care, and more likely to stick with their medications.Read Replies (0)
By BeauHD from Slashdot's not-my-cup-of-tea department
With Google recently rolling out a big revamp of Gmail to mixed reviews, we would like to know which email client you prefer. Are you a firm believe in the "inbox zero" idea -- that is, the approach to email management aimed at keeping the inbox empty, or almost empty, at all times? If you're looking for inspiration, Ars Technica recently published an article highlighting several different email clients used by the editors of the site: Are you the sort of person who needs to read and file every email they get? Or do you delight in seeing an email client icon proudly warning of hundreds or even thousands of unread items? For some, keeping one's email inbox with no unread items is more than just a good idea: it's a way of life, indicating control over the 21st century and its notion of productivity. For others, it's a manifestation of an obsessively compulsive mind. The two camps, and the mindsets behind them, have been a frequent topic of conversation here in the Ars Orbiting HQ. And rather than just argue with each other on Slack, we decided to collate our thoughts about the whole "inbox zero" idea and how, for those who adhere to it, that happens. Some of the clients floated by the editors include: Webmail, Airmail 3, Readdle's Spark, Edison Mail, Sparrow, Inbox by Gmail, and MailSpring.Read Replies (0)
By BeauHD from Slashdot's first-of-its-kind department
hackingbear writes from a report via Xinhua: Chinese scientists demonstrated the first two-dimensional quantum walks of single photons in real spatial space, which may provide a powerful platform to boost analog quantum computing. Scientists at Shanghai Jiaotong University reported in a paper published in the journal Science Advances a three-dimensional photonic chip with a scale up to 49x49 nodes, by using a technique called femtosecond direct writing. Universal quantum computers, under develop by IBM, Google, Alibaba and other American and Chinese rivals, are far from being feasible before error correction and full connections between the increasing numbers of qubits could be realized. In contrast, analog quantum computers, or quantum simulators, can be built in a straightforward way to solve practical problems directly without error correction, and potentially be able to beat the computational power of classical computers in the near future.Read Replies (0)
By BeauHD from Slashdot's epic-fail department
An anonymous reader quotes a report from Wired: The ubiquitous email encryption schemes PGP and S/MIME are vulnerable to attack, according to a group of German and Belgian researchers who posted their findings on Monday. The weakness could allow a hacker to expose plaintext versions of encrypted messages -- a nightmare scenario for users who rely on encrypted email to protect their privacy, security, and safety. The weakness, dubbed eFail, emerges when an attacker who has already managed to intercept your encrypted emails manipulates how the message will process its HTML elements, like images and multimedia styling. When the recipient gets the altered message and their email client -- like Outlook or Apple Mail -- decrypts it, the email program will also load the external multimedia components through the maliciously altered channel, allowing the attacker to grab the plaintext of the message.
The eFail attack requires hackers to have a high level of access in the first place that, in itself, is difficult to achieve. They need to already be able to intercept encrypted messages, before they begin waylaying messages to alter them. PGP is a classic end-to-end encryption scheme that has been a go-to for secure consumer email since the late 1990s because of the free, open-source standard known as OpenPGP. But the whole point of doing the extra work to keep data encrypted from the time it leaves the sender to the time it displays for the receiver is to reduce the risk of access attacks -- even if someone can tap into your encrypted messages, the data will still be unreadable. eFail is an example of these secondary protections failing.Read Replies (0)
By BeauHD from Slashdot's coming-to-a-laptop-near-you department
The three biggest PC OEMs -- Dell, HP, and Lenovo -- are now offering AMD Ryzen PRO mobile and desktop accelerated processing units (APUs) with built-in Radeon Vega graphics in a variety of commercial systems. There are a total of seven new APUs -- three for the mobile space and four for the desktop. As AMD notes in its press release, the first desktops to ship with these latest chips include: the HP Elitedesk G4 and 285 Desktop, the Lenovo ThinkCentre M715, and the Dell Optiplex 5055. ZDNet's Adrian Kingsley-Hughes writes about what makes Ryzen PRO so appealing: Ryzen PRO has been built from the ground up to focus on three pillars -- power, security and reliability. Built-in security means integrated GuardMI technology, an AES 128-bit encryption engine, Windows 10 Enterprise Security support, and support for fTPM/TPM 2.0 Trusted Platform Module. One of the features of Ryzen PRO that AMD hopes will appeal to commercial users is the enterprise-grade reliability that the chips come backed with, everything from 18-moths of planned software availability, 24-months processor availability, a commercial-grade QA process, 36-moth warranty, and enterprise-class manageability.
< article continued at Slashdot's coming-to-a-laptop-near-you department
>Read Replies (0)
By msmash from Slashdot's psa department
Christina Chiou Yeh, writing for Google Registry: On May 1 we announced .app, the newest top-level domain (TLD) from Google Registry. It's now open for general registration so you can register your desired .app name right now. We begin our journey with sitata.app, which provides real-time travel information about events like protests or transit strikes. Looks all clear, so our first stop is the Caribbean, where we use thelocal.app and start exploring. After getting some sun, we fly to the Netherlands, where we're feeling hungry. Luckily, picnic.app delivers groceries, right to our hotel. With our bellies full, it's time to head to India, where we use myra.app to order the medicine, hygiene, and baby products that we forgot to pack. Did we mention this was a business trip? Good thing lola.app helped make such a complex trip stress free. Time to head home now, so we slip on a hoodie we bought on ov.app and enjoy the ride.Read Replies (0)