Some low-cost Android phones shipped with malware built in

Avast has found that many low-cost, non-Google-certifed Android phones shipped with a strain of malware built in that could send users to download apps they didn&t intend to access. The malware, called called Cosiloon, overlays advertisements over the operating system in order to promote apps or even trick users into downloading apps. Devices effected shipped from ZTE, Archos and myPhone.

The app consists of a dropper and a payload. &The dropper is a small application with no obfuscation, located on the /system partition of affected devices. The app is completely passive, only visible to the user in the list of system applications under ‘settings.& We have seen the dropper with two different names, ‘CrashService& and ‘ImeMess,'& wrote Avast. The dropper then connects with a website to grab the payloads that the hackers wish to install on the phone. &The XML manifest contains information about what to download, which services to start and contains a whitelist programmed to potentially exclude specific countries and devices from infection. However, we&ve never seen the country whitelist used, and just a few devices were whitelisted in early versions. Currently, no countries or devices are whitelisted. The entire Cosiloon URL is hardcoded in the APK.&

The dropper is part of the systemfirmware and is not easily removed.

To summarize:

The dropper can install application packages defined by the manifest downloaded via an unencrypted HTTP connection without the userconsent or knowledge. The dropper is preinstalled somewhere in the supply chain, by the manufacturer, OEM or carrier. The user cannot remove the dropper, because it is a system application, part of the devicefirmware.

Avast can detect and remove the payloads and they recommend following these instructions to disable the dropper. If the dropper spots antivirus software on your phone it will actually stop notifications but it will still recommend downloads as you browse in your default browser, a gateway to grabbing more (and worse) malware. Engadget notes that this vector is similar to the Lenovo &Superfish& exploit that shipped thousands of computers with malware built in.

Write comment (98 Comments)

Facebook today revealed that itchosen not to shut down all political ads because that could unfairly favor incumbents and candidates without resources to buy pricey TV ads. Instead, itnow launching its previously announced &paid for by& labels on political and issue ads on Facebook and Instagram in the US, and its publicly searchable archive of all these politics-related ads that run in the US. That includes ads run by news publishers or others that promote articles with political content.

The labeling won&t just apply to candidate and election ads, but those dealing with political issues such as &abortion, guns, immigration or foreign policy&. Clicking through the labels that appear at the top of these News Feed ads will lead to the archive, which isn&t backdated and will only include ads from early May 2018 and after. The archive will hold them for seven years so they can be searched by keyword or Page who ran them. It will also display the adbudget, the and the number of people who saw it, plus aggregated, anonymized data on their age, gender, and location.

Facebook and Instagram launch U.S. political ad labeling and archive

A look at ads run by Donald Trumpofficial page inside Facebooknew political ad archive

Any advertiser that wants to run political ads must now go through Facebookauthorization process that requires them to reveal their identity and location, and advertisers will only have a weekgrace period starting today before those unauthorized will have their ads paused. Facebook plans to monitor political ads with a combination of artificial intelligence and 3000 to 4000 newly-hired ad reviewers as part of its doubling of its security team from 10,000 to 20,000 this year.

Facebook and Instagram launch U.S. political ad labeling and archive

An example of a &Paid for by& label on an Instagram ad

They reviewers and AI will analyze these ads& images, text, and the outside websites they point to look for political content. They&ll seek to avoid bias in classification by following guidelines on what constitutes one of 20 political issues from the decades-running Comparative Agendas Project. Users may also report unlabeled ads, which will then be reviewed, paused, and archived if they&re deemed political. Their buyer will then be required to go through the authorization process before they can buy more.

As part of work with Facebooknew commission investigating social mediaimpact on elections, it plans to provide a database available via a forthcoming API that will let watchdog groups, academics, and researchers review how ads are being used. These tools will open to other countries in the following months, and Facebook plans to make all ads visible to everyone through a tool launching in June thatnow testing in Ireland and Canada.

Facebookchief product officer Chris Cox writes that &We hope that in aggregate these changes will be a big step to improve the quality of civic engagement in our products, and to keep the public discourse strong.&

Facebook held a conference call to discuss the launch with reporters this morning. Unfortunately it was timed to end just 15 minutes before the news went out, limiting the ability of journalists to write timely, in-depth coverage. You can listen to that call below:

Concerns With FacebookPush For Ad Transparency

While the labels and archive are good step towards transparency, there are still a number of problems with the program. Most specifically, while the political action committees and organizations that often fund political ads can have confusing or misleading names that obscure their true purpose. Simply listing those organizations in the Paid For By labels or archive won&t necessarily give users a lot of information about who the people behind the money are unless they&re willing to go digging across internet themselves.

For example, the notorious conservative political donors the Koch brothers funnel cash through a PAC called Prosperity Action to fund republican candidates like Paul Ryan. Seeing an ad was paid for by Prosperity Action wouldn&t immediately inform most Americans. On the other side, ads to displace Paul Ryan have been bought by a Page called Stand Up America, which many might not immediately know is an anti-Trump group. If Facebook wants to truly give citizens a better understanding of where these political ads come from, it needs to add more info about the donors and political leanings behind PACs and other big spenders.

Facebook and Instagram launch U.S. political ad labeling and archive

Another issue is who will have access to the archive API, since the Cambridge Analytica scandal all started with an academic researcher accessing Facebook data.

&We won&t always get it right. We know we&ll miss some ads and in other cases we&ll identify some we shouldn&t& write Facebook&sGlobal Politics and Government Outreach DirectorKatie HarbathandDirector of Public PolicySteve Satterfield. But Harbath described on the call how even though all the monitoring of political ads will cost more than the revenue the company earns from them, Facebook felt it necessary to &makesure people have a way to express themselves and engage in political discourse in a transparent way.&

Ads With Political Content

Posted by Facebook on Thursday, May 24, 2018

These are the exact kind of tools and labels Facebook should have offered as soon as it began touting its ability to influence elections with its ads over a half decade ago. Better late than never, though. Self-policing in this manner could reduce the urgency of calls to pass the Honest Ads Act that was unveiled last year to bring online advertising disclosures in line with those for television, though Congress has yet to hold a hearing about.

&These changes won&t fix everything, but they will make it a lot harder for anyone to do what the Russians did during the 2016 election and use fake accounts and pages to run ads& CEO Mark Zuckerberg concluded. &I hope they&ll also raise the bar for all political advertising online.&

Write comment (95 Comments)
Google opens its G Suite for Education to home-school co-ops

Google today announcedit is changing the eligibility guidelines of its free G Suite for Education service to include home-school co-ops. Parents and teachers who run home-schoolco-ops will be able to sign up for it in the coming weeks.

G Suite for Education includes all of Googleusual online productivity toolsand then layers a number of education-specific services like Classroom on top of that. Google Classroom, itworth noting, was already available to any G Suite user, but to subscribe to G Suite for Education, you needed to be affiliated with a school or school district. Now, home-school co-ops will be able to verify their status and get access to G Suite for Education, too.

&Through technology, home-school co-op teachers can set and change assignments on the fly, students can work together even if geographically separated, and everyone has a common format for collaboration,& writesDarren Jones of the Home School Legal Defense Association, in todayannouncement. &Itbecause of this potential that I&ve been working closely with Google this year to make sure that home-school co-ops have the same access as other schools to G Suite for Education.&

Google has piloted this program with a number of co-ops in recent months. Given that these groups function a bit like traditional schools, with some being more formal than others, I can see how access to a shared and integrated set of tools would be useful there.

Write comment (100 Comments)

Tech giants put their rivalries aside for two days this week to code for a common cause: protecting children on the internet. Deep inside Facebook Menlo Park headquarters, teams drawn from Uber, Twitter, Google, Microsoft and Pinterest worked through the night to prototype new tools designed to help nonprofits in their fight against child sex trafficking.

Much of their work from Facebookthird annual child safety hackathon is actually too sensitive to publish. To stay one step ahead of the criminals, the specifics of how these tools track traffickers and missing children across websites must be kept secret. But the resulting products, all donated toNGOs like Thorn and the Internet Watch Foundation, could help tech companies rally a united front against those who&d seek to hurt kids.

&The thing with work on safety and security and fighting abuse is itan area where the industry is collaborative,& says Guy Rosen, FacebookVP of product management and one of the eventjudges. &Hackathons are a great way to bring people together to actually bootstrap some of these ideas . . . ensuring that the engineers who have the smart ideas can actually understand the pain points and apply that thinking to these problems.&

Inside Facebookanti-sex trafficking hackathon

The winner of 2016hackathon has grown into an invaluable resource for groups like the National Center for Missing and Exploited Children. The &child finder& tool matches online photos, like those on escort service listings, to NCMECdatabase of missing children. It helps reduce law enforcementresponse time so they can deploy officers in hopes of rescuing these kids.

Speaking in techlanguage of computer code, Facebook engineering manager Cristian Canton Ferrer described the tool saying, &People affected = 1; magnitude of change = enormous; lasting impact of the change = forever.&

While Facebook has recently been criticized for its dominance in social networking and approach to data privacy, its size affords it the resources to spearhead projects like this. And because italready accustomed to hacking on scaled tools, teaming up with NGOs and other web platforms can let the fruits of 10 years of labor around child safety be passed on to those who couldn&t build them themselves.

&It benefits no company if the general perception is that the internet is not a safe place,& says Facebookglobal head of safety Antigone Davis. &All of us have an individual interest as well as the industryinterest in ensuring that not only people perceive it as a safe place but that it is a safe place.&

Inside Facebookanti-sex trafficking hackathon

Amongst the projects at this yearhackathon was a way to use machine vision to identify people and other distinguishing features in photos from sites known to be used for sex trafficking. Artificial intelligence can help take some of the burden off human investigators who can be emotionally taxed by constantly viewing images of the exploited.

The winning project, called &Spotting Trends,& uses clustering analysis to keep tabs on traffickers as they move around the internet. Referring to the recent termination of a popular online prostitution marketplace, Rosen told the hackathon attendees that&Backpage coming down is a big event, but the bad guys are still out there.&

The Spotting Trends team wasn&t awarded a giant novelty check or some golden trophy. Instead, they&ll get the opportunity to present their work at the big Dallas Crimes Against Children Conference, which last year drew more than 4,300 professionals from the safety industry.

Inside Facebookanti-sex trafficking hackathon

&The kind of folks that come to this, they&re really motivated and really proud ofthe work because as internet companies we operate at the scale of hundreds of millions or billions of users. But when youdo this work, you hear those individual stories,& Rosen explains. &Just knowing the things we work on have a real impact on real people is what keeps all these people coming every morning and driven to do really good work.&

Davis concludes, &I think theirs is the quiet behind-the-scenes work that doesn&t get championed nearly enough.&

Write comment (99 Comments)
Dog-sitting startup Rover just raised $155M

Rover, a dog-walking and dog-boarding service that merged with DogVacay around this time last year, is now the second of such startups this year to raise a massive new round of funding with its announcement of a $155 million financing round.

While competitor Wag has become a juggernaut, there seems room for both room for a second player and the potential to outmaneuver Wag even with its massive influx of capital. Both DogVacay and Rover had a very similar model and eventually merged in an all-stock deal, creating a more substantial competitor for Wag. The round consisted of $125 million in equity financingled by funds and accounts advised by T. Rowe Price Associates, with a $30 million credit facility with Silicon Valley Bank. The Wall Street Journal is reporting that the round values Rover at $970 million.

Wag earlier this year picked up $300 million in a massive funding round led by SoftBank. That was, of course, SoftBank — which is investing massive piles of capital into startups and pretty much altering the calculus of venture capital in the process. But it also signaled a huge interest in various dog-care services, including apparently Rover, as a potential business opportunity for the millions of dog owners in the world. If you&ll walk anywhere in San Francisco, you&re destined to run into a very large number of very good dogs, and it makes enough sense that there should be an opportunity to capitalize on dog-ownership as a whole.

Rover connects dog owners with various users that will walk, board, or generally take care of dogs — a critical service for anyone who might be traveling, or just work in a non-dog friendly office. Users just book a dog walker or sitter through the app, which connects them with area sitters. Itan area where Wag has faced a lot of criticism following a major Bloomberg report regarding poor service (and losing dogs). There are, of course, many challenges for any service that offloads some kind of daily need to a third party starting in a similar fashion to Uber.

Rover, interestingly, notes on its website that it &accepts less than 20% of potential sitters,& perhaps a dig at the criticism for Wag or the space in general and as an attempt to soothe concerns from potential users. Rover says it has more than 200,000 sitters throughout North America. The company previously raised $156 million, and previous investors includeA-Grade Investments, Foundry Group, Madrona Venture Group, Menlo Ventures, OMERS Ventures, Petco, and StepStone Group.

Write comment (90 Comments)

Microsoft is celebrating the one-year anniversary of its game streaming service and Twitch competitor,Mixer, with a host of new features, including a refresh of the user experience and the launch of an expanded developer toolkit called MixPlay. The new streamer tools will roll out along with the revamped version of Mixer .com across desktop and mobile web, and will initially be available to Mixer Pro subscribers.

The company claims the service saw more than 10 million monthly active users in December 2017 & a figure, we should point out, may be higher because of holiday sales and the accompanying bump in game downloads and playtime seen across platforms.

However, Microsoft also says that the Mixer viewing audience has grown over four times since its launch, and the number of watched streams has grown more than five times. These are still not hard numbers, but third-party reportshave put Mixer well behind Twitchsizable and still-growing lead in terms of both concurrent streamers and viewers. (Those reports aren&t 100% accurate either, though, because they can&t track Xbox viewership.)

MicrosoftTwitch rival Mixer gets a revamp, including new developer tools for interactive gameplay

Microsoft says the updated Mixer.com rolls out beginning today, with a focus on making it easier for viewers to find the games and streamers they want to watch, as well as those broadcasting in creative communities.

While Pro subscribers will gain access first, they&ll have to opt-in by visiting their Account Settings and turning the new look on manually. (To do so, select the &Site Version& dialog, then the &Feature/UI Refresh& option, Microsoft says.)

The full refresh will arrive to all Mixer users later this summer.

As part of the new experience, the company is also rolling out more tools for developers with the launch of MixPlay.

As Microsoft explains, instead of just adding buttons below a stream, MixPlay lets developers build experiences on top of streams, in panels on the sides of the video, as widgets around the video, or as free-floating overlays & all of which can be designed to mimic the look-and-feel of the streamed content. Basically, this means the entire window is now a canvas, not just a portion of the stream itself.

MicrosoftTwitch rival Mixer gets a revamp, including new developer tools for interactive gameplay

One example of what MixPlay can enable can be seen in Aprillaunch of Mixer&Share Controller& feature, which created a virtual Xbox controller that could be shared by anyone broadcasting from their Xbox One.

This allowed gamers and viewers to play along in real-time from the web.

MicrosoftTwitch rival Mixer gets a revamp, including new developer tools for interactive gameplay

In addition, MixPlay will enable other games that are only playable on Mixer where controls blend into the stream & like Mini Golf, which launched this month and now has 300,000 views, or Truck Stars, for example.

Three new MixPlay-enabled games are launching today, as well, including Earthfall, which lets viewers interact with streamers or even change the game; Next Up Hero, where viewers can help a streamer by taking control or freeze the streamer at the worst possible moment, depending on their mood; and Late Shift, a choose-your-own-adventure crime thriller you control.

MicrosoftTwitch rival Mixer gets a revamp, including new developer tools for interactive gameplay

These sorts of MixPlay experiences shift the idea of Mixer being just another game streaming service to one where viewers can actively participate by playing themselves, or at least guiding the action. That could also serve as a differentiator for Mixer as it tries to carve out a niche for itself in the battle with Twitch and YouTube Gaming.

But MixPlay isn&t just for interactive experiences, Microsoft notes. It can also help developers build experiences that simply enhance streams with additional content, too, like a stats dashboard.

Another update involves the Mixer Create app, which offers mobile support to streamers. Now, streamers can kick of a co-stream by clicking the co-stream button on their Mixer Create profile, then send out invites, among other things.

This is live on Android in beta today, and will launch soon on iOS beta, with a full rollout in early June.

MicrosoftTwitch rival Mixer gets a revamp, including new developer tools for interactive gameplay

In terms of perks, Microsoft is running an &anniversary& promotion offering $5 of Microsoft Store credit along with any Direct Purchase of $9.99 or more. A second promotion is giving away a free, 1-month channel subscription and up to 90 days of Mixer Pro to anyone who reaches Level 10 on their account betweenMay 24th, 2018 at 12:00AM UST and May 28th, 2018 at 11:59PM PDT.

The company additionally announced a new partnership with ESL on esports, which will bring over 15,000 hours of programming from top competitive games to Mixer, includingCounter-Strike: Global Offensive, League of Legends, and Dota 2. These tournaments will take advantage of MixerFTL technology for &sub-second latency,& the company says.

Other announcements around games and esports are mentioned in the Mixer blog post, too.

Write comment (94 Comments)