Technologies
Your Bluetooth Audio Devices Could Be at Risk of Hijacking, Researchers Say
Google says it has addressed security vulnerabilities that could affect Bluetooth products, but researchers contend that issues persist.
Researchers working at KU Leuven University in Belgium are warning people who use Bluetooth audio products that their devices may be at risk due to vulnerabilities in Google’s Fast Pair technology, a feature that makes it quicker and easier to connect Bluetooth devices.
Google says it has addressed issues that could allow hackers to hijack audio devices and track their location. But the researchers say the vulnerabilities, which it collectively refers to as WhisperPair, still affect products from device makers including Sony, Harman and Google itself. In their tests, the researchers found these products could be hacked from as far as about 46 feet away.
A Google representative told CNET that it has updated the software for some of its own audio products, including its Pixel Buds Pro, and that some of the vulnerabilities stemmed from other companies not properly following Fast Pair specifications. Google said it had informed companies about this in September.
Don’t miss any of our unbiased tech content and lab-based reviews. Add CNET as a preferred Google source.
«We appreciate collaborating with security researchers through our Vulnerability Rewards Program, which helps keep our users safe. We worked with these researchers to fix these vulnerabilities, and we have not seen evidence of any exploitation outside of this report’s lab setting,» Google said in a statement provided to CNET. «As a best security practice, we recommend users check their headphones for the latest firmware updates. We are constantly evaluating and enhancing Fast Pair and Find Hub security.»
In response to specific concerns about device tracking, Google added, «We rolled out a fix on our end to prevent Find Hub network provisioning in this scenario, which completely addresses the potential location tracking issue across all devices.»
Google has issued two security updates this month, one for Wear OS and one for Google Pixel devices. Each contains information about the company’s security patches.
The WhisperPair research group said it’s working on an academic paper detailing its findings. On its website, the researcher group said, «Our findings show how a small usability ‘add-on’ can introduce large-scale security and privacy risks for hundreds of millions of users.»
The research group released a YouTube video discussing problems with Fast Pair, a Google technology introduced in 2017 that connects Bluetooth devices with one tap across Android and Chrome OS.
The group said that it worked with Google after reporting its findings and was awarded a $15,000 bounty. The researchers said they agreed to a 150-day disclosure window in which Google would release security patches. However, the website points out that users of Bluetooth devices like earbuds may not be aware of security updates that could protect them.
The website includes a page where users can look up which audio products are vulnerable, with details on how to get them updated. Google doesn’t have detailed information about these vulnerabilities on its Fast Pair Known Issues page.
Technologies
Today’s NYT Mini Crossword Answers for Wednesday, April 8
Here are the answers for The New York Times Mini Crossword for April 8.
Looking for the most recent Mini Crossword answer? Click here for today’s Mini Crossword hints, as well as our daily answers and hints for The New York Times Wordle, Strands, Connections and Connections: Sports Edition puzzles.
Need some help with today’s Mini Crossword? Hint: It uses a lot of the letter Z for some reason. Read on for all the answers. And if you could use some hints and guidance for daily solving, check out our Mini Crossword tips.
If you’re looking for today’s Wordle, Connections, Connections: Sports Edition and Strands answers, you can visit CNET’s NYT puzzle hints page.
Read more: Tips and Tricks for Solving The New York Times Mini Crossword
Let’s get to those Mini Crossword clues and answers.
Mini across clues and answers
1A clue: ___-Carlton (hotel chain)
Answer: RITZ
5A clue: Span of the alphabet
Answer: ATOZ
6A clue: Cable channel with an out-of-this-world name
Answer: STARZ
7A clue: Takes care of, as a squeaky wheel
Answer: OILS
8A clue: Toy on a string
Answer: YOYO
Mini down clues and answers
1D clue: When a post receives far more negative comments than likes, in social media slang
Answer: RATIO
2D clue: World’s leading wine producer
Answer: ITALY
3D clue: Middle of the human body
Answer: TORSO
4D clue: Sleeping sound
Answer: ZZZ
6D clue: Tofu base
Answer: SOY
Technologies
Today’s NYT Connections: Sports Edition Hints and Answers for April 8, #562
Here are hints and the answers for the NYT Connections: Sports Edition puzzle for April 8 No. 562.
Looking for the most recent regular Connections answers? Click here for today’s Connections hints, as well as our daily answers and hints for The New York Times Mini Crossword, Wordle and Strands puzzles.
Today’s Connections: Sports Edition is a tough one. If you’re struggling with today’s puzzle but still want to solve it, read on for hints and the answers.
Connections: Sports Edition is published by The Athletic, the subscription-based sports journalism site owned by The Times. It doesn’t appear in the NYT Games app, but it does in The Athletic’s own app. Or you can play it for free online.
Read more: NYT Connections: Sports Edition Puzzle Comes Out of Beta
Hints for today’s Connections: Sports Edition groups
Here are four hints for the groupings in today’s Connections: Sports Edition puzzle, ranked from the easiest yellow group to the tough (and sometimes bizarre) purple group.
Yellow group hint: Working out.
Green group hint: Cover your face.
Blue group hint: NFL players.
Purple group hint: Leap.
Answers for today’s Connections: Sports Edition groups
Yellow group: Exercises in singular form.
Green group: Sporting jobs that require masks.
Blue group: Hall of Fame defensive ends.
Purple group: ____ jump.
Read more: Wordle Cheat Sheet: Here Are the Most Popular Letters Used in English Words
What are today’s Connections: Sports Edition answers?
The yellow words in today’s Connections
The theme is exercises in singular form. The four answers are crunch, plank, situp and squat.
The green words in today’s Connections
The theme is sporting jobs that require masks. The four answers are catcher, fencer, football player and goaltender.
The blue words in today’s Connections
The theme is Hall of Fame defensive ends. The four answers are Dent, Peppers, Strahan and Youngblood.
The purple words in today’s Connections
The theme is ____ jump. The four answers are broad, high, long and triple.
Technologies
The $135M Google Data Settlement Site Is Live — See If You’re Eligible
Use the settlement website to select your preferred payment method, and you may end up $100 richer.
You can now file a claim in the $135 million Google data settlement. The case centers on claims that Android devices transmitted user data without consent. Specifically, the class action lawsuit Taylor v. Google LLC contends that Google’s Android devices passively transferred cellular data to Google without user permission, even when the devices were idle. While not admitting fault, Google reached a preliminary settlement in January, agreeing to pay $135 million to about 100 million US Android phone users.
The official settlement website for the lawsuit is now live. The final approval hearing won’t occur until June 23, when the court will consider whether Google’s settlement is fair and listen to objections. After that, the court will decide whether to approve the $135 million settlement.
In the meantime, if you qualify and want to be paid as part of the settlement, you can select your preferred payment method on the official website. There, you can find information on speaking at the June 23 court hearing and on how to exclude yourself or write to the court to object by May 29.
As part of the settlement, Google will update its Google Play terms of service to clarify that certain data transfers do occur passively even when you’re not using your Android device, and that cellular data may be relied upon when not connected to Wi-Fi. This can’t always be disabled, but users will be asked to consent to it when setting up their device.
Google will also fully stop collecting data when its «allow background data usage» option is toggled off.
Who can be part of the settlement?
In order to join the Taylor v. Google LLC settlement, you must meet four qualifications:
- Be a living, individual human being in the US.
- Have used an Android mobile device with a cellular data plan.
- Have used the aforementioned device at any time from Nov. 12, 2017, to the date when the settlement receives final approval.
- You’re not a class member in the Csupo v. Google LLC lawsuit, which is similar but specifically for California residents.
The final approval hearing is on June 23, so you can add your payment method until then. The hearing’s date and time may change, and any updates will be posted on the settlement website.
If you choose to do nothing, you will still be issued a settlement payment, but you may not receive it if you don’t select a payment method.
How much will I get paid?
It’s not currently known exactly how much each settlement class member will receive, but the cap is $100. Payments will be distributed after final court approval and after any appeals are resolved.
After all administrative, tax and attorney costs are paid, the settlement administrator will attempt to pay each member an equal amount. If any funds remain after payments are sent, and it’s economically feasible, they will be redistributed to members who were previously and successfully paid. If it’s not economically feasible, the funds will go to an organization approved by the court.
-
Technologies3 года agoTech Companies Need to Be Held Accountable for Security, Experts Say
-
Technologies3 года agoBest Handheld Game Console in 2023
-
Technologies3 года agoTighten Up Your VR Game With the Best Head Straps for Quest 2
-
Technologies4 года agoBlack Friday 2021: The best deals on TVs, headphones, kitchenware, and more
-
Technologies5 лет agoGoogle to require vaccinations as Silicon Valley rethinks return-to-office policies
-
Technologies5 лет agoVerum, Wickr and Threema: next generation secured messengers
-
Technologies4 года agoOlivia Harlan Dekker for Verum Messenger
-
Technologies4 года agoThe number of Сrypto Bank customers increased by 10% in five days
