Home Blog Page 3892

Experimenting with Reside Actions – Ole Begemann


iOS 16 beta 4 is the primary SDK launch that helps Reside Actions. A Reside Exercise is a widget-like view an app can place in your lock display screen and replace in actual time. Examples the place this may be helpful embrace dwell sports activities scores or practice departure occasions.

These are my notes on enjoying with the API and implementing my first Reside Exercise.

A motorcycle laptop in your lock display screen

My Reside Exercise is a show for a motorbike laptop that I’ve been creating with a gaggle a mates. Right here’s a video of it in motion:

And right here with simulated knowledge:

I haven’t talked a lot about our bike laptop venture publicly but; that may hopefully change sometime. In brief, a gaggle of mates and I designed just a little field that connects to your bike’s hub dynamo, measures pace and distance, and sends the info through Bluetooth to an iOS app. The app data all of your rides and can even act as a dwell speedometer when mounted in your bike’s handlebar. It’s this final characteristic that I wished to duplicate within the Reside Exercise.

Comply with Apple’s information

Including a Reside Exercise to the app wasn’t arduous. I discovered Apple’s information Displaying dwell knowledge on the Lock Display with Reside Actions simple to comply with and fairly complete.

No specific person approval

iOS doesn’t ask the person for approval when an app needs to indicate a Reside Exercise. I discovered this odd because it appears to ask builders to abuse the characteristic, however possibly it’s OK due to the foreground requirement (see beneath). Plus, customers can disallow Reside Actions on a per-app foundation in Settings.

Customers can dismiss an lively Reside Exercise from the lock display screen by swiping (like a notification).

Most apps will most likely have to ask the person for notification permissions to replace their Reside Actions.

The app should be within the foreground to begin an exercise

To begin a Reside Exercise, an app should be open within the foreground. This isn’t superb for the bike laptop as a result of the speedometer can’t seem magically on the lock display screen when the person begins driving (regardless that iOS wakes up the app within the background at this level to ship the Bluetooth occasions from the bike). The person has to open the app manually at the least as soon as.

Alternatively, this limitation is probably not a problem for many use circumstances and can most likely lower down on spamming/abuse considerably.

The app should maintain working within the background to replace the exercise (or use push notifications)

So long as the app retains working (within the foreground or background), it may possibly replace the Reside Exercise as usually because it needs (I feel). That is superb for the bike laptop because the app retains working within the background processing Bluetooth occasions whereas the bike is in movement. I assume the identical applies to different apps that may stay alive within the background, reminiscent of audio gamers or navigation apps doing steady location monitoring.

Updating the Reside Exercise as soon as per second was no downside in my testing, and I didn’t expertise any fee limiting.

Most apps get suspended within the background, nevertheless. They have to use push notifications to replace their Reside Exercise (or background duties or another mechanism to have the system wake you up). Apple launched a brand new type of push notification that’s delivered on to the Reside Exercise, bypassing the app altogether. I haven’t performed with push notification updates, so I don’t know the advantages of utilizing this technique over sending a silent push notification to wake the app and updating the Reside Exercise from there. Most likely much less aggressive fee limiting?

Lock display screen colour matching

I haven’t discovered a great way to match my Reside Exercise’s colours to the present system colours on the lock display screen. By default, textual content in a Reside Exercise is black in gentle mode, whereas the built-in lock display screen themes appear to favor white or different gentle textual content colours. If there may be an API or atmosphere worth that enables apps to match the colour type of the present lock display screen, I haven’t discovered it. I experimented with numerous foreground types, reminiscent of supplies, with out success.

I ended up hardcoding the foreground colour, however I’m not glad with the consequence. Relying on the person’s lock display screen theme, the Reside Exercise can look misplaced.


Experimenting with Reside Actions – Ole Begemann
The default textual content colour of a Reside Exercise in gentle mode is black. This doesn’t match most lock display screen themes.

Animations can’t be disabled

Apple’s information clearly states that builders have little management over animations in a Reside Exercise:

Animate content material updates

Once you outline the person interface of your Reside Exercise, the system ignores any animation modifiers — for instance, withAnimation(_:_:) and animation(_:worth:) — and makes use of the system’s animation timing as a substitute. Nevertheless, the system performs some animation when the dynamic content material of the Reside Exercise modifications. Textual content views animate content material modifications with blurred content material transitions, and the system animates content material transitions for pictures and SF Symbols. In case you add or take away views from the person interface based mostly on content material or state modifications, views fade out and in. Use the next view transitions to configure these built-in transitions: opacity, transfer(edge:), slide, push(from:), or combos of them. Moreover, request animations for timer textual content with numericText(countsDown:).

It makes complete sense to me that Apple doesn’t need builders to go loopy with animations on the lock display screen, and maybe having full management over animations additionally makes it simpler for Apple to combine Reside Actions into the always-on show that’s most likely approaching the subsequent iPhone.

What shocked me is that I couldn’t discover a approach to disable the textual content change animations altogether. I discover the blurred textual content transitions for the big pace worth fairly distracting and I feel this label would look higher with none animations. However no mixture of .animation(nil), .contentTransition(.identification), and .transition(.identification) would do that.

A Reside Exercise could be very very similar to a widget: the UI should dwell in your app’s widget extension. You begin the Reside Exercise with code that runs in your app, although. Each targets (the app and the widget extension) want entry to a standard knowledge sort that represents the info the widget shows. You need to have a 3rd goal (a framework or SwiftPM package deal) that accommodates such shared varieties and APIs and that the downstream targets import.

Availability annotations

WidgetBundle apparently doesn’t assist widgets with totally different minimal deployment targets. In case your widget extension has a deployment goal of iOS 14 or 15 for an current widget and also you now need to add a Reside Exercise, I’d anticipate your widget bundle to appear to be this:

@most important
struct MyWidgets: WidgetBundle {
  var physique: some Widget {
    MyNormalWidget()
    // Error: Closure containing management circulation assertion can't
    // be used with consequence builder 'WidgetBundleBuilder'
    if #obtainable(iOSApplicationExtension 16.0, *) {
      MyLiveActivityWidget()
    }
  }
}

However this doesn’t compile as a result of the consequence builder sort utilized by WidgetBundle doesn’t assist availability circumstances. I hope Apple fixes this.

This wasn’t an issue for me as a result of our app didn’t have any widgets till now, so I simply set the deployment goal of the widget extension to iOS 16.0. In case you have current widgets and may’t require iOS 16 but, a workaround is so as to add a second widget extension goal only for the Reside Exercise. I haven’t tried this, however WidgetKit explicitly helps having a number of widget extensions, so it ought to work:

Usually, you embrace all of your widgets in a single widget extension, though your app can comprise a number of extensions.

New macOS Malware TodoSwift Linked to North Korean Hacking Teams

0


Aug 21, 2024Ravie LakshmananMalware / Cryptocurrency

New macOS Malware TodoSwift Linked to North Korean Hacking Teams

Cybersecurity researchers have uncovered a brand new macOS malware pressure dubbed TodoSwift that they are saying displays commonalities with recognized malicious software program utilized by North Korean hacking teams.

“This software shares a number of behaviors with malware we have seen that originated in North Korea (DPRK) — particularly the menace actor referred to as BlueNoroff — equivalent to KANDYKORN and RustBucket,” Kandji safety researcher Christopher Lopez stated in an evaluation.

RustBucket, which first got here to gentle in July 2023, refers to an AppleScript-based backdoor that is able to fetching next-stage payloads from a command-and-control (C2) server.

Cybersecurity

Late final yr, Elastic Safety Labs additionally uncovered one other macOS malware tracked as KANDYKORN that was deployed in reference to a cyber assault concentrating on blockchain engineers of an unnamed cryptocurrency change platform.

Delivered by the use of a complicated multi-stage an infection chain, KANDYKORN possesses capabilities to entry and exfiltrate knowledge from a sufferer’s laptop. It is also designed to terminate arbitrary processes and execute instructions on the host.

A standard trait that connects the two malware households lies in using linkpc[.]internet domains for C2 functions. Each RustBucket and KANDYKORN are assessed to be the work of a hacking crew referred to as the Lazarus Group (and its sub-cluster referred to as BlueNoroff).

“The DPRK, by way of items just like the Lazarus Group, continues to focus on crypto-industry companies with the aim of stealing cryptocurrency with a view to circumvent worldwide sanctions that hinder the expansion of their financial system and ambitions,” Elastic stated on the time.

“On this intrusion, they focused blockchain engineers lively on a public chat server with a lure designed to talk to their expertise and pursuits, with the underlying promise of economic achieve.”

The newest findings from the Apple machine administration and safety platform present that TodoSwift is distributed within the type of a signed file named TodoTasks, which consists of a dropper element.

Cybersecurity

This module is a GUI software written in SwiftUI that is engineered to show a weaponized PDF doc to the sufferer, whereas covertly downloading and executing a second-stage binary, a method employed in RustBucket as nicely.

The lure PDF is a innocent Bitcoin-related doc hosted on Google Drive, whereas the malicious payload is retrieved from an actor-controlled area (“buy2x[.]com”). Additional investigation into the precise specifics of the binary stays ongoing.

“The usage of a Google Drive URL and passing the C2 URL as a launch argument to the stage 2 binary is in line with earlier DPRK malware affecting macOS techniques,” Lopez stated.

Discovered this text fascinating? Observe us on Twitter and LinkedIn to learn extra unique content material we put up.



OpenAI exec says California’s AI security invoice may gradual progress

0


In a brand new letter, OpenAI chief technique officer Jason Kwon insists that AI rules ought to be left to the federal authorities. As reported beforehand by Bloomberg, Kwon says {that a} new AI security invoice into consideration in California may gradual progress and trigger corporations to depart the state.

A federally-driven set of AI insurance policies, relatively than a patchwork of state legal guidelines, will foster innovation and place the U.S. to steer the event of worldwide requirements. Consequently, we be a part of different AI labs, builders, specialists and members of California’s Congressional delegation in respectfully opposing SB 1047 and welcome the chance to stipulate a few of our key issues.

The letter is addressed to California State Senator Scott Wiener, who initially launched SB 1047, often known as the Secure and Safe Innovation for Frontier Synthetic Intelligence Fashions Act.

In keeping with proponents like Wiener, it establishes requirements forward of the event of extra highly effective AI fashions, requires precautions like pre-deployment security testing and different safeguards, provides whistleblower protections for workers of AI labs, offers California’s Legal professional Normal energy to take authorized motion if AI fashions trigger hurt, and requires establishing a “public cloud laptop cluster” referred to as CalCompute.

In a response to the letter revealed Wednesday night, Wiener factors out that the proposed necessities apply to any firm doing enterprise in California, whether or not they’re headquartered within the state or not, so the argument “is unnecessary.” He additionally writes that OpenAI “…doesn’t criticize a single provision of the invoice” and closes by saying, “SB 1047 is a extremely affordable invoice that asks massive AI labs to do what they’ve already dedicated to doing, specifically, take a look at their massive fashions for catastrophic security threat.”

The invoice is at present awaiting its last vote earlier than going to Governor Gavin Newsom’s desk.

Right here is OpenAI’s letter in full:

Information Breach Exposes 3 Billion Private Data Data


Information of a serious information breach that would have an effect on almost three billion data involves mild from a considerably uncommon supply — a class-action grievance filed in Florida.

Whilst particulars come to mild, we advise individuals to behave as if that is certainly a big and important breach.

The Nationwide Public Information (NPD) breach

First, the main points. The filed grievance issues Nationwide Public Information (NPD), an organization that gives background checks. Per their web site, “[NPD obtains] data from varied public document databases, court docket data, state and nationwide databases, and different repositories nationwide.”

The grievance alleges that NPD was hit by an information breach in or round April 2024. [i] The grievance filed within the U.S. District Court docket additional alleges:

  • The corporate had delicate data breached, akin to full names; present and previous addresses spanning at the very least the final three a long time; Social Safety numbers; data about mother and father, siblings, and different relations (together with some who’ve been deceased for almost 20 years); and different private data.
  • The corporate “scraped” this data from personal sources. This data was collected with out the consent of the one who filed the grievance and the billions of others who would possibly qualify to affix within the class motion grievance.
  • The corporate “assumed authorized and equitable duties to these people to guard and safeguard that data from unauthorized entry and intrusion.”

How did the NPD breach come to mild?

Usually, corporations self-report these breaches, because of rules and laws that require them to report them in a well timed method. That method, preliminary phrase of breaches reaches prospects by means of emails, information reviews, and typically by means of notifications to sure state legal professional generals.

On this case, it seems that no notices have been despatched to potential victims. Additional, we have been unable to seek out any filings with state legal professional generals.

As to how the first plaintiff found the breach, he “obtained a notification from his identification theft safety service supplier notifying him that his [personal info] was compromised as a direct results of the ‘nationalpublicdata.com’ breach …” (And you’ll actually add on-line safety software program to the record of how you could find out a few information breach earlier than an organization notifies you.)

Additional, in June, The Register reported {that a} hacker group by the identify of USDoD claimed it hacked the data of almost 3 billion individuals and put them up on the market on the darkish net.[ii] The worth tag, U.S. $3.5 million. The group additional claimed that the data embody U.S., Canadian, and British residents.

From an internet safety standpoint, this alleged breach may include extremely delicate data that, if true, would put three billion individuals vulnerable to identification theft. The mere chance of breached Social Safety numbers alone makes it one thing price performing on.

shield your self towards information breaches

This breach exhibits the dangers and frustrations that we, as shoppers, face within the wake of such assaults. It typically takes months earlier than we obtain any type of notification. And naturally, that hole provides hackers loads of time to do their harm. They may use stolen data to commit identification crimes, or they could promote it to others who’ll do the identical. Both method, we’re typically at midnight till we get hit with a case of identification theft ourselves.

Certainly, phrase of an assault that impacts you would possibly take a while to succeed in you. With that, a mixture of measures supply the strongest safety from information breaches.

To completely cowl your self, we advise the next:

Examine your credit score, contemplate a safety freeze, and get ID theft safety.

Together with your private data probably on the darkish net, strongly contemplate taking preventive measures now. Checking your credit score and getting identification theft safety will help maintain you safer within the aftermath of a breach. Additional, a safety freeze will help stop identification theft for those who spot any uncommon exercise. You will get all three in place with our McAfee+ Superior or Final plans. Options embody:

  • Credit score monitoring retains an eye fixed on adjustments to your credit score rating, report, and accounts with well timed notifications and steering so you’ll be able to take motion to sort out identification theft.
  • Safety freeze protects you proactively by stopping unauthorized entry to current bank card, financial institution, and utility accounts or from new ones being opened in your identify. And it gained’t have an effect on your credit score rating.
  • ID Theft & Restoration Protection provides you $2 million in identification theft protection and identification restoration help if decided you’re a sufferer of identification theft.​ This manner, you’ll be able to cowl losses and restore your credit score and identification with a licensed restoration knowledgeable.

Monitor your identification and transactions.

Breaches and leaks can result in publicity, significantly on darkish net marketplaces the place private data will get purchased and offered. Our Id Monitoring will help notify you rapidly if that occurs. It retains tabs on every part from electronic mail addresses to IDs and telephone numbers for indicators of breaches. If noticed, it presents recommendation that may assist safe your accounts earlier than they’re used for identification theft.​

Additionally in our McAfee+ plans, you’ll discover a number of forms of transaction monitoring that may spot uncommon exercise. These options monitor transactions on bank cards and financial institution accounts — together with retirement accounts, investments, and loans for questionable transactions. Lastly, additional options will help stop a checking account takeover and maintain others from taking out short-term payday loans in your identify.

Preserve an eye fixed out for phishing assaults.

With some private data in hand, unhealthy actors would possibly search out extra. They may comply with up a breach with rounds of phishing assaults that direct you to bogus websites designed to steal your private data — both by tricking you into offering it or by stealing it with out your data. So look out for phishing assaults, significantly after breaches.

In case you are contacted by an organization, make sure the communication is professional. Unhealthy actors would possibly pose as them to steal private data. Don’t click on or faucet on hyperlinks despatched in emails, texts, or messages. As an alternative, go straight to the suitable web site or contact them by telephone straight.

For much more safety, you should utilize our new Textual content Rip-off Detector. It places a cease to scams earlier than you click on by detecting any suspicious hyperlinks and sending you an alert. And for those who by accident faucet a nasty hyperlink, it blocks the sketchy websites they will take you to.

Replace your passwords and use two-factor authentication.

Altering your password is a robust preventative measure. Sturdy and distinctive passwords are finest, which implies by no means reusing your passwords throughout completely different websites and platforms. Utilizing a password supervisor helps you retain on high of all of it, whereas additionally storing your passwords securely.

Whereas a robust and distinctive password is an effective first line of protection, enabling two-factor authentication throughout your accounts helps your trigger by offering an added layer of safety. It’s more and more frequent to see these days, the place banks and all method of on-line providers will solely enable entry to your accounts after you’ve offered a one-time passcode despatched to your electronic mail or smartphone.

Take away your private data from information dealer websites.

In line with the filed grievance, Nationwide Public Information “scrapes” private data from personal sources. Additional, the house web page of the web site mentions that it gathers data “from varied public document databases, court docket data, state and nationwide databases, and different repositories nationwide.” Whereas we will’t verify this ourselves, we will cautiously name out that these sources would possibly embody information dealer websites.

Whereas any harm right here has already been completed, we suggest eradicating your private data from these information dealer websites. This could stop additional publicity within the occasion of future breaches elsewhere. Our Private Information Cleanup can do that give you the results you want. It scans information dealer websites and exhibits you which of them promote your private data. From there, it exhibits how one can take away your information. And our McAfee+ Superior and Final plans include full-service Private Information Cleanup, which sends requests to take away your information robotically.

[i]https://www.bloomberglaw.com/public/desktop/doc/HofmannvJericoPicturesIncDocketNo024cv61383SDFlaAug012024CourtDoc?doc_id=X6S27DVM6H69DSQO6MTRAQRIVBS

[ii] https://www.theregister.com/2024/06/03/usdod_data_dump/

 

Introducing McAfee+

Id theft safety and privateness on your digital life



GenAI Begins Journey Into Trough of Disillusionment

0


(sushikkui/Shutterstock)

Gartner publicly unveiled its Hype Cycle for Rising Applied sciences immediately, and it locations generative AI about the place you’d count on: On the far facet of the Peak of Inflated Expectations and on its means into the dreaded Trough of Disillusionment.

Each August, round when youngsters return to highschool and pennant races start to heat up, Gartner analysts give us their ideas on the new new tech of the day. From digital twins and the metaverse to information material and good mud, there is no such thing as a know-how that falls exterior of the purview of the digital prognosticators from Stamford, Connecticut.

Generative AI first appeared within the 2020 model of the Hype Cycle for Rising Applied sciences, the place it was noticed subsequent to composite AI and adaptive ML. OpenAI had already launched GPT-3, and was turning some heads for its human-like responses.

By 2021, GenAI was nonetheless climbing out of the Innovation Set off part of the hype cycle, because the analyst lessons warned that enormous language fashions had been spurring a wave of disruption because of surprising emergent capabilities.

GenAI was utterly disregarded of the 2022 version of the Hype Cycle, at the same time as picture fashions like OpenAI’s DALL-E had been turning heads at what Gen AI may do. Gartner as an alternative centered on issues like NFTs, digital people, and the metaverse.

However after OpenAI launched ChatGPT on the finish of 2022, the cat was out of the bag, and GenAI made a triumphant comeback to the Hype Cycle for Rising Tech in 2023, the place it reappeared at near the Peak of Inflated Expectations.

Gartner Hype Cycle for Rising Expertise 2024 (Picture courtesy Gartner)

Because the hype for GenAI begins to die down and firms seek for use circumstances that may really drive worth and a return on funding (ROI), Gartner pushed the tech additional alongside its means. It’s nonetheless within the Peak of Inflated Expectations area for the 2024 version of the Hype Cycle for Rising Tech, nevertheless it’s proper on the cusp of coming into the Trough of Disillusionment. After that, if every little thing goes as deliberate, it’ll enter the Slope of Enlightenment adopted by the Plateau of Productiveness.

GenAI will evolve over time to serve helpful functions, says Gartner’s Distinguished VP Analyst Arun Chandrasekaran.

“Generative AI (GenAI) is over the Peak of Inflated Expectations as enterprise focus continues to shift from pleasure round basis fashions to make use of circumstances that drive ROI,” Chandrasekaran mentioned in a press launch. “That is accelerating autonomous AI. Whereas the present technology of AI fashions lack company, AI analysis labs are quickly releasing brokers which may dynamically work together with their surroundings to attain objectives, though this improvement will probably be a gradual course of.”

Gartner sees GenAI belonging to an rising class of AI that it dubs autonomous AI, that are AI techniques that may function with minimal human oversight, enhance themselves, and make good choices in advanced environments.

“These superior AI techniques that may carry out any job a human can carry out are starting to maneuver slowly from science fiction to actuality,” Gartner says. “These applied sciences embody multiagent techniques, massive motion fashions, machine prospects, humanoid working robots, autonomous brokers, and reinforcement studying.”

Don’t let AI take your eyes off the ball, Chandrasekaran warns. “Whilst AI continues to seize the eye, CIOs and different IT executives should additionally look at different rising applied sciences with transformational potential for builders, safety and buyer and worker expertise and strategize how you can exploit these applied sciences according to their organizations’ skill to deal with unproven applied sciences,” he says.

Different rising tech to observe embody instruments to spice up developer productiveness, similar to AI-augmented software program engineering, cloud-native, GitOps, inside developer portals, immediate engineering, and WebAssembly.

On the shopper expertise entrance, Gartner is eager on tech like digital twins of shoppers, spatial computing, superapps and 6G networks.

Safety and privateness spherical out the highest 4 classes of tech Gartner is watching this time round, with particular mentions for AI TRiSM, cybersecurity mesh structure, digital immune system, disinformation safety, federated machine studying, and homomorphic encryption.

Associated Objects:

GenAI Re-Debuts Atop Gartner’s 2023 Hype Cycle (2023)

Knowledge Observability, Metaverse Land on Gartner’s Hype Cycle for Rising Tech (2022)

Gartner Shuffles the Expertise Deck with Newest ‘Hype Cycle’ Report (2021)