Security News

High-risk Google account owners can now use their iPhone as a security key
2020-01-15 13:07

Google users who opt for the Advanced Protection Program to secure their accounts are now able to use their iPhone as a security key. In May 2019, Google made it possible to exchange the physical security key with one's Android device.

Google Says it Will Phase Out Web-Tracking 'Cookies'
2020-01-14 20:09

The online giant said its "Sandbox" program would still allow advertisers the ability to deliver targeted messages, while also sparing people from being tracked by snippets of code called "Cookies" when they use its Chrome web browser. "We are confident that with continued iteration and feedback, privacy-preserving and open-standard mechanisms like the Privacy Sandbox can sustain a healthy, ad-supported web in a way that will render third-party cookies obsolete," Chrome director of engineering Justin Schuh said in a post.

Google to Nix Chrome Support for Third-Party Cookies by 2022
2020-01-14 19:08

Google has set an aggressive two-year deadline for dropping support for third-party tracking cookies in its Chrome web browser. Justin Schuh, engineering director for Google Chrome, said in a post Tuesday that the phasing out of third-party cookies was in response to evolving attitudes about online privacy.

Google Researchers Detail Critical iMessage Vulnerability
2020-01-14 18:51

Google Project Zero security researchers have published technical details on an iMessage vulnerability addressed last year, which could be exploited remotely to achieve arbitrary code execution. Tracked as CVE-2019-8641, the vulnerability is considered Critical, featuring a CVSS score of 9.8, and was discovered by Google Project Zero security researchers Samuel Groß and Natalie Silvanovich.

Fleeceware is back in Google Play – massive fees for not much at all
2020-01-14 15:45

The treachery lies in the payment model - the fleeceware we identified back in September 2019 didn't charge a fee for the app, but instead sold you a subscription to go along with the app. The app's free, don't forget; it's the subscription that you're being charged for, and Google permits app developers to ask that sort of money.

Google tests biometric authentication for Android autofill
2020-01-14 11:31

Google is testing out a feature to make Android's built-in password manager safer, according to online sleuths who have picked apart its software. You could use it to take autofill input from third-party password managers, or if you wanted to keep everything in your Google account, you could use autofill with Google's own password management service.

Joker Android Malware Snowballs on Google Play
2020-01-13 21:04

Google has removed 17,000 Android apps to date from the Play store that have been conduits for the Joker malware - and in an analysis of the code, said that Joker's operators have "At some point used just about every cloaking and obfuscation technique under the sun in an attempt to go undetected." The internet giant said that having three or more active variants of Joker in circulation at the same time using different approaches or targeting different carriers is the norm; and at peak times of activity, up to 23 different apps from the Joker family have been submitted to Play in one day.

Privacy activists beg Google to ban un-removable bloatware from Android
2020-01-13 17:53

For much of Android's existence, Google has adopted a relatively hands-off approach that lets manufacturers ship units with pre-installed bloatware which, in many cases, cannot be easily removed. "Android Partners - who use the Android trademark and branding - are manufacturing devices that contain pre-installed apps that cannot be deleted, which can leave users vulnerable to their data being collected, shared and exposed without their knowledge or consent," the letter states.

Google urged to tame privacy-killing Android bloatware
2020-01-13 11:18

These pre-installed apps can have privileged custom permissions that let them operate outside the Android security model. This means permissions can be defined by the app - including access to the microphone, camera and location - without triggering the standard Android security prompts.

Google Removes Trove of Risky 'Bread' Apps From Play Store
2020-01-12 14:52

Google has removed roughly 1,700 unique applications from its Google Play app store that were part of a family of potentially unwanted programs. Over time, the developers of the applications have focused on finding new cloaking and obfuscation techniques to evade Google Play Store's new policies and Play Protect's evolving defenses and remain undetected.