Pages

Thursday, 3 January 2019

[TA Deals] Kickstart your YouTube career with the discounted Master Class bundle (97% off)

Jumping off a career on YouTube is everyone’s dream, but it takes a ton of work and skill to actually turn it into anything. If you want to start building up your own brand you might be interested in our YouTube Master Class bundle to teach you everything there is to know to create your […]


Come comment on this article: [TA Deals] Kickstart your YouTube career with the discounted Master Class bundle (97% off)


[TA Deals] Kickstart your YouTube career with the discounted Master Class bundle (97% off) appeared first on http://www.talkandroid.com

Samsung releases long Android Pie update roadmap

Samsung has dropped its Android Pie update roadmap addressing all the devices which will receive it – and disappointingly, many of the company’s customers will be waiting a long time for their slice of Pie. Samsung has a long history of long delays when updating their devices to the newest versions of Android, though they […]


Come comment on this article: Samsung releases long Android Pie update roadmap


Samsung releases long Android Pie update roadmap appeared first on http://www.talkandroid.com

Wednesday, 2 January 2019

Google sat on a Chromecast bug for years, now hackers could wreak havoc

Google was warned of a bug in its Chromecast media streaming stick years ago, but did not fix it. Now, hackers are exploiting the bug — and security researchers say things could get even worse.

A hacker, known as Hacker Giraffe, has become the latest person to figure out how to trick Google’s media streamer into playing any YouTube video they want — including videos that are custom-made. This time around, the hacker hijacked thousands of Chromecasts, forcing them to display a pop-up notice that’s viewable on the connected TV, warning the user that their misconfigured router is exposing their Chromecast and smart TV to hackers like himself.

Not one to waste an opportunity, the hacker also asks that you subscribe to PewDiePie, an awful internet person with a popular YouTube following. (He’s the same hacker who tricked thousands of exposed printers into printing support for PewDiePie.)

The bug, dubbed CastHack, exploits a weakness in both Chromecast and the router it connects to. Some home routers have enabled Universal Plug and Play (UPnP), a networking standard that can be exploited in many ways. UPnP forwards ports from the internal network to the internet, making Chromecasts and other devices viewable and accessible from anywhere on the internet.

As Hacker Giraffe says, disabling UPnP should fix the problem.

“We have received reports from users who have had an unauthorized video played on their TVs via a Chromecast device,” a Google spokesperson told TechCrunch. “This is not an issue with Chromecast specifically, but is rather the result of router settings that make smart devices, including Chromecast, publicly reachable,” the spokesperson said.

That’s true on one hand, but it doesn’t address the years-old bug that gives anyone with access to a Chromecast the ability to hijack the media stream and display whatever they want, because Chromecast doesn’t check to see if someone is authorized to change the video stream. (Google did not respond to our follow-up question.)

Hacker Giraffe sent this YouTube video to thousands of exposed Chromecast devices, warning that their streams could be easily hijacked. (Screenshot: TechCrunch)

Bishop Fox, a security consultancy firm, first found the bug in 2014, not long after the Chromecast debuted. The researchers found that they could conduct a “deauth” attack that disconnects the Chromecast from the Wi-Fi network it was connected to, causing it to revert back to its out-of-the-box state, waiting for a device to tell it where to connect and what to stream. That’s when it can be hijacked and forced to stream whatever the hijacker wants. All of this can be done in an instant — as they did — with a touch of a button on a custom-built handheld remote.

Two years later, U.K. cybersecurity firm Pen Test Partners discovered that the Chromecast was still vulnerable to “deauth” attacks, making it easy to play content on a neighbor’s Chromecasts in just a few minutes.

Ken Munro, who founded Pen Test Partners, says there’s “no surprise that somebody else stumbled on to it,” given both Bishop Fix found it in 2014 and his company tested it in 2016.

“In fairness, we never thought that the service would be exposed on the public internet, so that is a very valid finding of his, full credit to him for that,” Munro told TechCrunch.

He said the way the attack is conducted is different, but the method of exploitation is the same. CastHack can be exploited over the internet, while Bishop Fox and his “deauth” attacks can be carried out within range of the Wi-Fi network — yet, both attacks let the hacker control what’s displayed on the TV from the Chromecast, he said.

Munro said Google should have fixed its bug in 2014 when it first had the chance.

“Allowing control over a local network without authentication is a really silly idea on [Google’s] part,” he said. “Because users do silly things, like expose their TVs on the internet, and hackers find bugs in services that can be exploited.”

Hacker Giraffe is the latest to resort to “Good Samaritan security,” by warning users of the issues and providing advice on how to fix them before malicious hackers take over, where tech companies and device makers have largely failed.

But Munro said that these kinds of attacks — although obnoxious and intrusive on the face of it — could be exploited to have far more malicious consequences.

In a blog post Wednesday, Munro said it was easy to exploit other smart home devices — like an Amazon Echo — by hijacking a Chromecast and forcing it to play commands that are loud enough to be picked up by its microphone. That’s happened before, when smart assistants get confused when they overhear words on the television or radio, and suddenly and without warning purchase items from Amazon. (You can and should turn on a PIN for ordering through Amazon.)

To name a few, Munro said it’s possible to force a Chromecast into loading a YouTube video created by an attacker to trick an Echo to: “Alexa, order an iPad,” or, “Alexa, turn off the house alarm,” or, “Alexa, set an alarm every day at 3am.”

Amazon Echos and other smart devices are widely considered to be secure, even if they’re prone to overhearing things they shouldn’t. Often, the weakest link are humans. Second to that, it’s the other devices around smart home assistants that pose the biggest risk, said Munro in his blog post. That was demonstrated recently when Canadian security researcher Render Man showed how using a sound transducer against a window can trick a nearby Amazon Echo into unlocking a network-connected smart lock on the front door of a house.

“Google needs to properly fix the Chromecast deauth bug that allows casting of YouTube traffic,” said Munro.


Google sat on a Chromecast bug for years, now hackers could wreak havoc was first posted on https://techcrunch.com/gadgets/

You can now make donations directly through Google Assistant and Google Home

  Google wants to make it easier to donate to your favorite charities and organizations, and they started that process by allowing donations directly from the Play Store last year. Now they’re going a step further and adding quick donation options right into Google Assistant and your local Google Home devices. The process really is […]


Come comment on this article: You can now make donations directly through Google Assistant and Google Home


You can now make donations directly through Google Assistant and Google Home appeared first on http://www.talkandroid.com

[TA Deals] Get started writing screenplays with the WriterDuet Pro lifetime sub (58% off)

Writing a screenplay can be tough, but that’s where programs like WriterDuet Pro come in. Instead of wasting time doing everything manually and by hand, you can let WriterDuet streamline the process, eliminate distractions, and help you craft the best product you’re capable of. The program offers real-time live collaboration, easy drafting and outline support, […]


Come comment on this article: [TA Deals] Get started writing screenplays with the WriterDuet Pro lifetime sub (58% off)


[TA Deals] Get started writing screenplays with the WriterDuet Pro lifetime sub (58% off) appeared first on http://www.talkandroid.com

Nokia 9 Pureview details confirmed in leaked press video

    Nokia has been in the Android game for two years now, after being sold by Microsoft to HMD Global – the latter of which comprises of many former Nokia staff. The resurrected Nokia released a slew of mediocre and overpriced phones in 2017, and some genuinely great phones in 2018, including a supposed […]


Come comment on this article: Nokia 9 Pureview details confirmed in leaked press video


Nokia 9 Pureview details confirmed in leaked press video appeared first on http://www.talkandroid.com

See you in Vegas next week!

It’s on like Donkey Kong! We’ll be seeing you next week on January 9, 2019 at 6:00 PM where we’ll mingle and run a full TC pitchoff with a bunch of great hardware companies. I’ve added 40 extra tickets so hurry!

The event will be held at Work In Progress, 317 South 6th Street. Special thanks to those amazing folks who opened their doors to us during one of the busiest weeks in LV.

I’ve contacted the companies that will be pitching via email. If anyone drops out, I’ll choose some more so there is still a chance to pitch.

Very special thanks go out to Shenzhen Valley Ventures, a hardware-focused venture capital firm for engineers, by engineers. They will be on hand to talk about their firm and would love to hear your pitches… and they are paying for the beer and pizza!

See you soon!


See you in Vegas next week! was first posted on https://techcrunch.com/gadgets/