Google

android-tv-has-access-to-your-entire-account—but-google-is-changing-that

Android TV has access to your entire account—but Google is changing that

It’s all just Android —

Should sideloading Chrome on an old smart TV really compromise your entire account?

Android TV has access to your entire account—but Google is changing that

Google

Google says it has patched a nasty loophole in the Android TV account security system, which would grant attackers with physical access to your device access to your entire Google account just by sideloading some apps. As 404 Media reports, the issue was originally brought to Google’s attention by US Sen. Ron Wyden (D-Ore.) as part of a “review of the privacy practices of streaming TV technology providers.” Google originally told the senator that the issue was expected behavior but, after media coverage, decided to change its stance and issue some kind of patch.

“My office is mid-way through a review of the privacy practices of streaming TV technology providers,” Wyden told 404 Media. “As part of that inquiry, my staff discovered an alarming video in which a YouTuber demonstrated how with 15 minutes of unsupervised access to an Android TV set-top box, a criminal could get access to private emails of the Gmail user who set up the TV.”

The video in question was a PSA from YouTuber Cameron Gray, and it shows that grabbing any Android TV device and sideloading a few apps will grant access to the current Google account. This is obvious if you know how Android works, but it’s not obvious to most users looking at a limited TV interface.

The heart of the issue is how Android treats your Google account. Since the OS started on phones, every Android device starts with the assumption that it is a private, one-person device. Google has built on top of that feature with multiuser support and guest accounts, but these aren’t part of the default setup flow, can be hard to find, and are probably disabled on many Android TV boxes. The result is that signing in to an Android TV device often gives it access to your entire Google account.

Android has a centralized Google account system shared by a million Google-centric background and syncing processes, the Play Store, and nearly all Google apps. When you boot an Android device for the first time, the guided setup asks for a Google account, which is expected to live on the device forever as the owner’s primary account. Any new Google app you add to your device automatically gets access to this central Google account repository, so if you set up the phone and then install Google Keep, Keep automatically gets signed in and gains access to your notes. During the initial setup, where you might install 10 different apps that use a Google account, it would be annoying to enter your username and password over and over again.

This centralized account system is hungry for Google accounts, so any Google account you use to sign in to any Google app gets sucked into the central account system, even if you decline the initial setup. A common annoyance is to have a Google Workspace account at work, then sign into Gmail for work email and then have to deal with this useless work account showing up in the Play Store, Maps, Photos, etc.

For TVs, this presents a unique gotcha because, while you will still be forced to log in to download something from the Play Store, it’s not obvious to the user that you’re granting this device access to your entire Google account—including to potentially sensitive things like location history, emails, and messages. To the average user, a TV device just shows “TV stuff” like your YouTube recommendations and a few TV-specific Play Store apps, so you might not consider it to be a high-sensitivity sign-in. But if you just sideload a few more Google apps, you can get access to anything. Further confusing matters is Google’s OAuth strategy, which teaches users that there are things like scoped access to a Google account on third-party devices or sites, but Android does not work that way.

In the video, Gray simply grabs an Android TV device, goes to a third-party Android app site, then sideloads Chrome. Chrome automatically signs in to the TV owner’s Google account and has access to all passwords and cookies, which means access to Gmail, Photos, Chat history, Drive files, YouTube accounts, AdSense, any site that allows for Google sign-in, and partial credit card info. It’s all available in Chrome without any security checks. Individual apps like Gmail and Google Photos would immediately start working, too.

As Gray’s video points out, Android TV devices can be dongles, set-top boxes, or code installed right into a TV. In businesses and hotels, they can be semi-public devices. It’s also not hard to imagine a TV device falling into the hands of someone else. You might not worry too much about forgetting a $30 Chromecast in a hotel room, or you might sign in to a hotel TV and forget to delete your account, or you might throw out a TV and not think twice about what account it’s signed in to. If an attacker gets access to any of these devices later, it’s trivial to unlock your entire Google account.

Google says it has fixed this problem, though it doesn’t explain how. The company’s statement to 404 says, “Most Google TV devices running the latest versions of software already do not allow this depicted behavior. We are in the process of rolling out a fix to the rest of the devices. As a best security practice, we always advise users to update their devices to the latest software.”

Many Android TV devices, especially those built-in to TV sets, are abandonware and run an old version of the software, but Google’s account system is updatable via the Play Store, so there’s a good chance a fix can roll out to most devices.

Android TV has access to your entire account—but Google is changing that Read More »

google-can’t-quit-third-party-cookies—delays-shut-down-for-a-third-time

Google can’t quit third-party cookies—delays shut down for a third time

This post was written in Firefox —

Google says UK regulator testing means the advertising tech will last until 2025.

Extreme close-up photograph of finger above Chrome icon on smartphone.

Will Chrome, the world’s most popular browser, ever kill third-party cookies? Apple and Mozilla both killed off the user-tracking technology in 2020. Google, the world’s largest advertising company, originally said it wouldn’t kill third-party cookies until 2022. Then in 2021, it delayed the change until 2023. In 2022, it delayed everything again, until 2024. It’s 2024 now, and guess what? Another delay. Now Google says it won’t turn off third-party cookies until 2025, five years after the competition.

A new blog post cites UK regulations as the reason for the delay, saying, “We recognize that there are ongoing challenges related to reconciling divergent feedback from the industry, regulators and developers, and will continue to engage closely with the entire ecosystem.” The post comes as part of the quarterly reports the company is producing with the UK’s Competition and Markets Authority (CMA).

Interestingly, the UK’s CMA isn’t concerned about user privacy but instead is worried about other web advertisers that compete with Google. The UK wants to make sure that Google isn’t making changes to Chrome to prop up its advertising business at the expense of competitors. While other browser vendors shut down third-party cookies without a second thought, Google said it wouldn’t turn off the user-tracking feature until it built an alternative advertising feature directly into Chrome, so it can track user interests to serve them relevant ads. The new advertising system, called the Topics API and “Privacy Sandbox,” launched in Chrome in 2023. Google AdSense is already compatible.

The UK is worried that Chrome’s new ad system might give Google’s ad division an unfair advantage. Google and the UK CMA are talking it out, and Google says it’s “critical that the CMA has sufficient time to review all evidence, including results from industry tests, which the CMA has asked market participants to provide by the end of June.” Google has a public testing suite for Chrome’s new ad system to allow for feedback. Given all the testing data that needs to be pored over, Google says, “We will not complete third-party cookie deprecation during the second half of Q4.” We’ll check back next year!

Google can’t quit third-party cookies—delays shut down for a third time Read More »

first-real-life-pixel-9-pro-pictures-leak,-and-it-has-16gb-of-ram

First real-life Pixel 9 Pro pictures leak, and it has 16GB of RAM

OK, but what if I don’t care about generative AI? —

With 16GB of RAM, there’s lot of room for Google’s AI models to live in memory.

OnLeak's renders of the <a href='https://www.mysmartprice.com/gear/pixel-9-pro-5k-renders-360-degree-video-exclusive/'>Pixel 9 Pro XL</a>, the <a href='https://www.91mobiles.com/hub/google-pixel-9-design-render-exclusive/'>Pixel 9 Pro</a>, and the <a href = 'https://www.91mobiles.com/hub/google-pixel-9-renders-design-exclusive/'>Pixel 9.</a>” src=”https://cdn.arstechnica.net/wp-content/uploads/2024/03/pixel-9-lineup-800×446.jpg”></img><figcaption>
<div>
<p><a data-height=Enlarge / OnLeak’s renders of the Pixel 9 Pro XL, the Pixel 9 Pro, and the Pixel 9.

OnLeaks / 91Mobiles / MySmartPrice

The usual timeline would put the Google Pixel 9 at something like five months away from launching, but that doesn’t mean it’s too early to leak! Real-life pictures of the “Pixel 9 Pro” model have landed over at Rozetked.

This prototype looks just like the renders from OnLeaks that first came out back in January. The biggest change is a new pill-shaped camera bump instead of the edge-to-edge design of old models. It looks rather stylish in real-life photos, with the rounded corners of the pill and camera glass matching the body shape. The matte back looks like it still uses the excellent “soft-touch glass” material from last year. The front and back of the phone are totally flat, with a metal band around the side. The top edge still has a signal window cut out of it, which is usually for mmWave. The Pixel 8 Pro’s near-useless temperature sensor appears to still be on the back of this prototype. At least, the spot for the temperature sensor—the silver disk right below the LED camera flash—looks identical to the Pixel 8 Pro. As a prototype any of this could change before the final release, but this is what it looks like right now.

The phone was helpfully photographed next to an iPhone 14 Pro Max, and you might notice that the Pixel 9 Pro looks a little small! That’s because this is one of the small models, with only a 6.1-inch display. Previously for Pixels, “Pro” meant “the big model,” but this year Google is supposedly shipping three models, adding in a top-tier small phone. There’s the usual big Pixel 9, with a 6.7-inch display, which will reportedly be called the “Pixel 9 Pro XL.” The new model is the “Pixel 9 Pro”—no XL—which is a small model but still with all the “Pro” trimmings, like three rear cameras. There’s also the Pixel 9 base model, which is the usual smaller phone (6.03-inch) with cut-down specs like only two rear cameras.

Rozetked.” data-height=”1056″ data-width=”1408″ href=”https://cdn.arstechnica.net/wp-content/uploads/2024/04/4.jpg”>The Pixel 9 Pro prototype. It's small because this is the Rozetked.” height=”735″ src=”https://cdn.arstechnica.net/wp-content/uploads/2024/04/4-980×735.jpg” width=”980″>

Enlarge / The Pixel 9 Pro prototype. It’s small because this is the “small Pro” model. There are more pictures over at Rozetked.

Rozetked says (through translation) that the phone is  “similar in size to the iPhone 15 Pro.” It runs a Tensor G4 SoC, of course, and—here’s a noteworthy spec—has a whopping 16GB of RAM according to the bootloader screen. The Pixel 8 Pro tops out at 12GB.

Anything could change between prototype and product, especially for RAM, which is usually scaled up and down in various phone tiers. A jump in RAM is something we were expecting though. As part of Google’s new AI-focused era, it wants generative AI models turned on 24/7 for some use cases. Google said as much in a recent in-house podcast, pointing to some features like a new version of Smart Reply built right into the keyboard, which “requires the models to be RAM-resident”—in other words, loaded all the time. Google’s desire to keep generative AI models in memory means less RAM for your operating system to actually do operating system things, and one solution to that is to just add more RAM. So how much RAM is enough? At one point Google said the smaller Pixel 8’s 8GB of RAM was too much of a “hardware limitation” for this approach. Google PR also recently told us the company still hasn’t enabled generative AI smart reply on Pixel 8 Pro by default with its 12GB of RAM, so expect these RAM numbers to start shooting up.

The downside is that more RAM means a more expensive phone, but this is the path Google is going down. There’s also the issue of whether or not you view generative AI as something that is so incredibly useful you need it built into your keyboard 24/7. Google wants its hardware to be “the intersection of hardware, software, and AI,” so keeping all this ChatGPT-like stuff quarantined to a single app apparently won’t be an option.

One final note: It’s weird how normal this phone looks. Usually, Pixel prototypes have a unique logo that isn’t the Google “G,” and often they are covered in identifying patterns for leak tracing. This looks like a production-worthy design, though.

First real-life Pixel 9 Pro pictures leak, and it has 16GB of RAM Read More »

youtube-puts-third-party-clients-on-notice:-show-ads-or-get-blocked

YouTube puts third-party clients on notice: Show ads or get blocked

Blocking the ad blockers —

Google would really like it if everyone just paid for YouTube Premium instead.

YouTube app icon on a TV screen.

Getty Images | Chris McGrath

YouTube is putting third-party ad-blocking apps on notice. An ominous post on the official YouTube Community Help forum titled “Enforcement on Third Party Apps” says the company is “strengthening our enforcement on third-party apps that violate YouTube’s Terms of Service, specifically ad-blocking apps.” Google would really like it if you all paid for YouTube Premium.

YouTube has been coming down on third-party apps, which often enable YouTube ad blocking. The company shut down one of the most popular third-party apps, “YouTube Vanced,” in 2022. Vanced was open source, though, so new alternatives sprung up almost immediately. Vanced takes the official YouTube Android client and installs a duplicate, alternative version with a bunch of patches. It turns on all the YouTube Premium features like ad-blocking, background playback, and downloading without paying for the Premium sub. It also adds features the official app doesn’t have, like additional themes and accessibility features, “repeat” and “dislike” buttons, and the ability to turn off addictive “suggestions” that appear all over the app.

Another popular option is “NewPipe,” a from-scratch YouTube player that follows the open source ethos and is available on the FOSS-only store F-Droid. NewPipe wants a lightweight client without the proprietary code and million permissions that YouTube needs, but it also blocks ads.

Rather than going after the projects, Google says it’s going to start disrupting users who are using these apps. The post writes, “Viewers who are using these third-party apps may experience buffering issues or see the error ‘The following content is not available on this app’ when trying to watch a video.” The company continues: “We want to emphasize that our terms don’t allow third-party apps to turn off ads because that prevents the creator from being rewarded for viewership, and Ads on YouTube help support creators and let billions of people around the world use the streaming service.”

If you remember back to when Google aggressively fought to keep third-party YouTube apps off of Windows Phone, the company seemed to take a similar stance against all third-party YouTube clients, even if they wanted to integrate ads. Today Google says that’s no longer the case, and it would allow third-party YouTube clients provided “they follow our API Services Terms of Service.” We don’t know of any apps that are actually taking Google up on that offer, though.

YouTube puts third-party clients on notice: Show ads or get blocked Read More »

the-pixel-9-reportedly-gears-up-for-satellite-sos-support

The Pixel 9 reportedly gears up for satellite SOS support

Android’s testbed, for better or worse —

No one wants to build an Android satellite phone, so Google is going to do it.

The smaller Pixel 9, with three cameras?!

Enlarge / The smaller Pixel 9, with three cameras?!

Google has been doing a lot of work in Android to support satellite-based messaging, and it sure would be nice if someone actually shipped some hardware it could use. Despite the feature launching with the iPhone 14 in 2022, Android manufacturers haven’t been super receptive to copying the idea of satellite messaging. Qualcomm and satellite company Iridium built a working solution and incorporated it into Qualcomm’s Snapdragon chips, only for zero Android manufacturers to support the feature, leading to the dissolution of the partnership. If Google wants an Android satellite SMS phone to play with, it seems like it will need to build the device itself.

Reliable leaker Kamila Wojciechowska over at Android Authority says Google is working on doing just that. It looks like the Pixel 9 will be getting emergency satellite SOS. Since the Pixel 6, Pixel phones have been the rare devices that don’t use Qualcomm modems. Google partners with Samsung and bases its Pixel Tensor chips on Samsung Exynos chips, and that means using Samsung’s (usually much maligned) modems, too. Citing a source, Wojciechowska says the Pixel 9 would use the new Exynos Modem 5400, along with its optional NTN (non-terrestrial network) capabilities, allowing the phone to be “the first to support Android’s native satellite implementation.” The initial service provider would be T-Mobile (just like the good old days).

The move would make sense. The whole original point of the Nexus/Pixel line was to give Google something to build Android on. By incorporating the latest hardware features into the next Pixel, Android gets a target to program for and test on. Otherwise, we’d have a chicken-and-egg problem where no one makes the hardware because there’s no software support, and no one makes software because there’s no hardware to program for. Google just does it all at once.

As for who would be powering T-Mobile’s satellite network, the company has a high-profile partnership with SpaceX, but those are LTE towers in space and work on regular devices with no special software (the recent demo was on a regular set of iPhones). The whole point of Android’s satellite implementation is dealing with traditional satellite problems like aiming at a far-away satellite, compressing the message a ton to actually make it to the satellite, and dealing with an unreliable connection. That’s not really relevant to the SpaceX partnership since that is trying to be a next-generation solution of “regular LTE in space,” designed around the world’s largest rocket and satellite network.

We’re just speculating here, but a better target for a “current-generation” system would be Skylo, which resells service from traditional satellite companies like Viasat and Inmarsat, so it would need all that aiming and unreliable connection software. In a wild coincidence, Skylo already has a press release out saying it has certified the Samsung Exynos Modem 5400 for use on its network. Skylo already has a relationship with T-Mobile, and the company powered the Motorola Satellite Link hotspot.

The Pixel 9 reportedly gears up for satellite SOS support Read More »

google-mocks-epic’s-proposed-reforms-to-end-android-app-market-monopoly

Google mocks Epic’s proposed reforms to end Android app market monopoly

Google mocks Epic’s proposed reforms to end Android app market monopoly

Epic Games has filed a proposed injunction that would stop Google from restricting third-party app distribution outside Google Play Store on Android devices after proving that Google had an illegal monopoly in markets for Android app distribution.

Epic is suggesting that competition on the Android mobile platform would be opened up if the court orders Google to allow third-party app stores to be distributed for six years in the Google Play Store and blocks Google from entering any agreements with device makers that would stop them from pre-loading third-party app stores. This would benefit both mobile developers and users, Epic argued in a wide-sweeping proposal that would greatly limit Google’s control over the Android app ecosystem.

US District Court Judge James Donato will ultimately decide the terms of the injunction. Google has until May 3 to respond to Epic’s filing.

A Google spokesperson confirmed to Ars that Google still plans to appeal the verdict—even though Google already agreed to a $700 million settlement with consumers and states following Epic’s win.

“Epic’s filing to the US Federal Court shows again that it simply wants the benefits of Google Play without having to pay for it,” Google’s spokesperson said. “We’ll continue to challenge the verdict, as Android is an open mobile platform that faces fierce competition from the Apple App Store, as well as app stores on Android devices, PCs, and gaming consoles.”

If Donato accepts Epic’s proposal, Google would be required to grant equal access to the Android operating system and platform features to all developers, not just developers distributing apps through Google Play. This would allow third-party app stores to become the app update owner, updating any apps downloaded from their stores as seamlessly as Google Play updates apps.

Under Epic’s terms, any app downloaded from anywhere would operate identically to apps downloaded from Google Play, without Google imposing any unnecessary distribution fees. Similarly, developers would be able to provide their own in-app purchasing options and inform users of out-of-app purchasing options, without having to use Google’s APIs or paying Google additional fees.

Notably, Epic filed its lawsuit after Google removed the Epic game Fortnite from the Google Play Store because Epic tried to offer an “Epic Direct Payment” option for in-game purchases.

“Google must also allow developers to communicate directly with their consumers, including linking from their app to a website to make purchases and get deals,” Epic said in a blog post. “Google would be blocked from using sham compliance programs like User Choice Billing to prevent competing payment options inside an app or on a developer’s website.”

Unsurprisingly, Epic’s proposed injunction includes an “anti-retaliation” section specifically aimed at protecting Epic from any further retaliation. If Donato accepts the terms, Google would be violating the injunction order if the tech giant fails to prove that it is not “treating Epic differently than other developers” by making it “disproportionately difficult or costly” for Epic to develop, update, and market its apps on Android.

That part of the injunction would seem important since, last month, Epic announced that an Epic Games Store was “coming to iOS and Android” later this year. According to Inc, Epic told Game Developers Conference attendees that its app-distribution platform will be the “first ever game-focused, multiplatform store,” working across “Android, iOS, PC and macOS.”

Google mocks Epic’s proposed reforms to end Android app market monopoly Read More »

google-kills-“one”-vpn-service,-says-“people-simply-weren’t-using-it”

Google kills “One” VPN service, says “people simply weren’t using it”

The Venn diagram of “I want a VPN” and “I trust Google” has no overlap —

Did anyone want a VPN from the Internet’s largest data collector?

Google kills “One” VPN service, says “people simply weren’t using it”

Aurich Lawson

Another day, another dead Google product. The Google One VPN service we complained about last week is headed to the chopping block. Google’s support documents haven’t been updated yet, but Android Authority reported on an email going out to Google One users informing them of the shutdown. 9to5Google also got confirmation of the shutdown from Google.

The Google One VPN launched in 2020 as a bonus feature for paying Google One subscribers. Google One is Google’s cloud storage subscription plan that allows users to buy extra storage for Gmail, Drive, and Google Photos. In 2020, the plan was exclusive to the expensive 2TB tier for $10 a month, but later, it was brought down to all Google One tiers, including the entry-level $2-per-month option.

By our count, Google has three VPN products, though “products” might be too strong a word since they are all essentially the same thing—VPN market segments? There’s the general Google One VPN for Android, iOS, Windows, and Mac—this is the one that’s dying. There’s also the “Pixel VPN by Google One,” which came with Pixel phones (the “Google One” branding here makes no sense since you didn’t have to subscribe to Google One) and the Google Fi VPN that’s exclusive to Google Fi Android and iOS customers.

The Google One VPN settings.

Enlarge / The Google One VPN settings.

Google

The Google One VPN that’s shutting down was by far the most flexible, with the widest platform support, and its shutdown represents Google ending VPN support for Windows and Mac. The Pixel and Fi VPNs will keep running, possibly with new branding.

A Google spokesperson told 9to5Google the Google One VPN is shutting down because “people simply weren’t using it.” The Windows client was also super buggy, and it’s probably easier to shut it down rather than fix it. There’s no shutdown date yet, but a message on this page says the VPN will be phased out “later in 2024.”

Google kills “One” VPN service, says “people simply weren’t using it” Read More »

google-cloud-rolls-out-self-designed-arm-chips-in-its-data-centers

Google Cloud rolls out self-designed Arm chips in its data centers

This post hosted by AWS —

Google Axion-based VMs will be out in preview in the coming months.

A Google Axion Processor.

Enlarge / A Google Axion Processor.

Google

Google is joining the custom Arm data center chip trend. Google Cloud, the cloud platform division that competes with Amazon Web Services and Microsoft Azure, is following in the footsteps of those companies and rolling out its own Arm-based chip designs. Google says its new “Google Axion Processors” are “custom Arm-based CPUs designed for the data center” and offer “industry-leading performance and energy efficiency.”

Google has been developing custom data center accelerators for things like AI and video transcoding, but this is the first time the company is making a CPU. Google says it’s seeing “50% better performance and up to 60% better energy-efficiency than comparable current-generation x86-based instances.

Google’s “Axion” chip is based on the Arm Neoverse V2 CPU, so just like the ARM chips we see on mobile devices, by making “custom” chips, these companies are closely following a lot of blueprints that Arm makes available. Google says it did include a custom microcontroller called “Titanium,” which it says handles networking, security, and storage I/O.

This is Google Cloud, so you won’t be buying anything with an “Axion” chip in it. You can pay for cloud processing that uses the new CPU, with Google naming “Google Compute Engine, Google Kubernetes Engine, Dataproc, Dataflow, Cloud Batch, and more” as services that will use the new chip. Some of these services bill by “vCPU” usage, so theoretically a faster CPU could lead to lower prices, but Google doesn’t spell that out in the post. Internally Google is also moving BigTable, Spanner, BigQuery, Blobstore, Pub/Sub, Google Earth Engine, and the YouTube Ads platform from its current Arm servers to this new custom one soon.

It’s a bit strange to tout a new cloud infrastructure CPU when the whole point of services like AWS and Google Cloud is that you don’t have to worry about the server. The services you were running will continue to run, while companies like Google, Amazon, and Microsoft can take care of all that complicated hardware and network data center stuff. Google says that Axion VMs will be available as a “preview” in “the coming months” and that Cloud customers can sign up for access.

Google Cloud rolls out self-designed Arm chips in its data centers Read More »

“google-vids”-is-google’s-fourth-big-productivity-app-for-workspace

“Google Vids” is Google’s fourth big productivity app for Workspace

Please don’t bore your co-workers —

Google’s “video editor” feels more like a souped-up version of Google Slides.

  • Is that Google Slides? Nope it’s Google Vids, the new video editor that seems to just make souped-up slideshows.

    Google

  • Google’s demo starts with an existing slideshow and then generates an outline.

    Google

  • Choose a theme, which all look like PowerPoints.

    Google

  • Write a script, preferably with the help of Google Gemini.

    Google

  • You can record a voiceover, or pick from Google’s robot voices.

    Google

  • This is a Google Workspace app, so there’s lots of realtime collaboration features, like these live mouse cursors that were brought over from Slides.

    Google

  • Comments work too.

    Google

  • It’s interesting you get a “stock media” library while apps like Slides would use generative AI images here.

    Google

  • Record a talk from your webcam.

    Google

  • Embed your video in the slideshow.

    Google

If you had asked me before what Google’s video editor app was, I would say “YouTube Studio,” but now Google Workspace has a new productivity app called “Google Vids.” Normally a video editor is considered a secondary application in many productivity suites, but Google apparently imagines Vids as a major pillar of Workspace, saying Vids is an “all-in-one video creation app for work that will sit alongside Docs, Sheets and Slides.” So, that is an editor for documents, spreadsheets, presentations, and videos?

Google’s demo of the new video editor pitches the product not for YouTube videos or films but more as a corporate super slideshow for things like training materials or product demos. Really, this “video editor” almost looks like it could completely replace Google Slides since the interface is just Slides but with a video timeline instead of a slideshow timeline.

Google’s example video creates a “sales training video” that starts with a Slides presentation as the basic outline. You start with an outline editor, where each slideshow page gets its own major section. Google then has video “styles” you can pick from, which all seem very Powerpoint-y with a big title, subheading, and a slot for some kind of video. Google then wants you to write a script and either read it yourself or have a text-to-speech voice read the script. A “stock media” library lets you fill in some of those video slots with generic corporate imagery like a video of a sunset, choose background music, and use a few pictures. You can also fire up your webcam and record something, sort of like a pre-canned Zoom meeting. After that it’s a lot of the usual Google productivity app features: real-time editing collaboration with visible mouse cursors from each participant and a stream of comments.

Like all Google products after the rise of OpenAI, Google pitches Vids as an “AI-powered” video editor, even though there didn’t seem to be many generative AI features in the presentation. The videos, images, and music were “stock” media, not AI-generated inventions (Slides can generate images, but that wasn’t in this demo). There’s nothing in here like OpenAI’s “Sora,” which generates new videos out of its training data. There’s probably a Gemini-powered “help me write” feature for the script, and Google describes the initial outline as “generated” from your starting Slides presentation, but that seemed to be it.

Google says Vids is being released to “Workspace Labs” in June, so you’ll be able to opt in to testing it.

Listing image by Google

“Google Vids” is Google’s fourth big productivity app for Workspace Read More »

android’s-bluetooth-trackers-are-finally-shipping-in-late-may

Android’s Bluetooth trackers are finally shipping in late May

Just merge the networks already —

The one-year wait for Apple’s cross-platform safety measures is almost over.

  • Chipolo’s trackers. The keychain tracker takes a CR2023 battery; the card is not rechargeable.

  • Pebblebee’s trackers are all rechargeable.

  • Google’s “Find My Device” app.

    Google

After an announcement that ended up being a year early, Android’s version of Tile/AirTags is ready to launch. Google has been gearing up on the software side of things to enable a Bluetooth tracking network on Android, and the company’s two tracking tag hardware partners, Pebblebee and Chipolo, now have ship dates. The two companies each have a press release today, with Pebblebee saying its trackers will ship in “late May,” while Chipolo says it will ship “after May 27th.” Google has a blog post out, too, promising “additional Bluetooth tags from Eufy, Jio, Motorola and more” later this year.

Both sets of devices have been up for preorder for a year now, and it doesn’t seem like anything has changed since. Both companies are offering little Bluetooth trackers in a keychain tag or credit card format, and Pebblebee has a third stick-on tag format. They’ll all be anonymously tracked by Android’s 3 billion-device Bluetooth tracker network, and the device owner will be able to see them in Google’s “Find my device” app.

Chipolo’s “One Point” key chain tag is the only thing that takes a CR2032 coin cell battery, while the company’s credit card tracker is not rechargeable. Pebblebee’s key chain, credit card, and stick-on tracker all have rechargeable batteries, including the wallet card, which is very rare! Nothing has UWB for precise location tracking—everything uses a speaker. Both companies sell multiple SKUs of what look like the exact same product but are locked to Google’s or Apple’s network—no switching allowed.

These were all supposed to come out in 2023 originally. Google’s patch notes say that the tracking network shipped in Android in December 2022, even though nothing is using it. The company has actually been waiting on Apple. In May 2023, Google and Apple announced a joint standard for “unknown tracker” alerts. While the two networks will not be compatible, they will team up to alert users if a tracker is being used to stalk them. All this hardware was announced a week later, but in July 2023, Google shipped what a spokesperson called, “a custom implementation” for AirTags (enabling Android phones to alert users to an unknown AirTag), and the company said it wouldn’t enable its tracking network until the joint tracking detection standard with Apple was ready. It looks like Apple will do that in iOS 17.5. iOS 17.5 is expected to be out—you guessed it—at the end of May, so these tags can finally ship.

9: 00pm update: A Google spokesperson told us Google’s July release of Android’s unwanted AirTag detection is “a custom implementation” and not the joint standard.

Listing image by Chipolo

Android’s Bluetooth trackers are finally shipping in late May Read More »

android’s-airtag-competitor-gears-up-for-launch,-thanks-to-ios-release

Android’s AirTag competitor gears up for launch, thanks to iOS release

Definitely not slow-rolling this —

Google promised to wait for Apple to launch cross-platform “unwanted tag” detection.

Pebblebee's Android trackers.

Enlarge / Pebblebee’s Android trackers.

Will Google ever launch its “Find My” network? The Android ecosystem was supposed to have its own version of Apple’s AirTags by now. Google has had a crowd-sourced device-tracking network sitting dormant on 3 billion Android phones since December 2022. Partners have been ready to go with Bluetooth tag hardware since May 2023! This was all supposed to launch a year ago, but Google has been in a holding pattern. The good news is we’re finally seeing some progress after a year of silence.

The reason for Google’s lengthy delay is actually Apple. A week before Google’s partners announced their Android network Bluetooth tags, Google and Apple jointly announced a standard to detect “unknown” Bluetooth trackers and show users alerts if their phone thinks they’re being stalked. Since you can constantly see an AirTag’s location, they can be used for stalking by just covertly slipping one into a bag or car; nobody wants that, so everyone’s favorite mobile duopoly is teaming up.

Google did its half of this partnership and rolled out AirTag detection in July 2023. At the same time, Google also announced: “We’ve made the decision to hold the rollout of the Find My Device network until Apple has implemented protections for iOS.” Surely Apple would be burning the midnight oil to launch iOS Android tag detection as soon as possible so that Google could start competing with AirTags.

It looks like iOS 17.5 is the magic version Google is waiting for. The first beta was recently released to testers, and 9to5Mac recently spotted strings for detecting “unwanted” non-Apple tracking devices that were suddenly following you around. This 17.5 update still needs to ship, and the expectation is sometime in May. That would be 11 months after Google’s release.

Just like AirTags, and the Tile network before it, the goal of the project is to enable helpful little Bluetooth tracking tags that can tell you where your stuff is. These Bluetooth tags are super low-power and aim to last for a year on a small battery, which means they don’t have the power to spare for GPS. They can still report their location, though, because they manage to “borrow” the GPS chip of any compatible smartphones in range. Your phone scans for any Bluetooth tags, even ones you don’t own, then notes their approximate location and uploads it to the cloud. This is all done anonymously, and only the owner of the tag can see its location, but everyone in the network pitches in to create a crowdsourced, worldwide thing-tracking network.

Tile started the whole idea by having any user with the Tile app running do anonymous location uploads for every other Tile in earshot. Nothing can compete with the scale of Apple’s version, though, which runs on every iThing out there, and the bigger size of the network makes it a lot more reliable. Android will have an even bigger network if it ever launches. In an ideal world, Android and iOS would just work together to perfectly track every Bluetooth tracker regardless of make and model, but they’re only teaming up for stalking detection.

Google gears up for launch

With the impending iOS release, Google seems to be getting its ducks in a row as well. 9to5Google has a screenshot of the new Find My Device settings page that is appearing for some users, which gives them a chance to opt out of the anonymous tracking network. That report also mentions that some users received an email Thursday of an impending tracking network launch, saying: “You’ll get a notification on your Android devices when this feature is turned on in 3 days. Until then, you can opt out of the network through Find My Device on the web.” The vast majority of Android users have not gotten this email, though, suggesting maybe it was a mistake. It’s very weird to announce a launch in “days remaining” rather than just saying what date something will launch, and this email went out Thursday, which would mean a bizarre Sunday launch when everyone is off for the weekend.

The official announcement could come at any time, but Google said it wanted to wait for Apple, and that means at least a few weeks for actual functionality to be turned on. We also need a launch date from those poor hardware partners that presumably have had tracking tags sitting around in a warehouse for a year. Google’s partners, Chipolo and Pebblebee, have both been taking preorders for Android tracking tags for the past year and don’t have any launch updates.

And speaking of hardware, Google was supposed to be building a first-party tracking tag once upon a time. January 2023 was when we first heard of a device codenamed “Grogu,” which was supposed to have a speaker, UWB compatibility, and Bluetooth LE. Is that still happening? There’s probably time to have made a second-generation device by now. Apple’s May iOS release would be great timing for a Google I/O announcement, but we were also expecting an announcement at the last I/O, so who knows.

Android’s AirTag competitor gears up for launch, thanks to iOS release Read More »

google-sues-two-crypto-app-makers-over-allegedly-vast-“pig-butchering”-scheme

Google sues two crypto app makers over allegedly vast “pig butchering” scheme

Foul Play —

Crypto and other investment app scams promoted on YouTube targeted 100K users.

Google sues two crypto app makers over allegedly vast “pig butchering” scheme

Google has sued two app developers based in China over an alleged scheme targeting 100,000 users globally over four years with at least 87 fraudulent cryptocurrency and other investor apps distributed through the Play Store.

The tech giant alleged that scammers lured victims with “promises of high returns” from “seemingly legitimate” apps offering investment opportunities in cryptocurrencies and other products. Commonly known as “pig-butchering schemes,” these scams displayed fake returns on investments, but when users went to withdraw the funds, they discovered they could not.

In some cases, Google alleged, developers would “double down on the scheme by requesting various fees and other payments from victims that were supposedly necessary for the victims to recover their principal investments and purported gains.”

Google accused the app developers—Yunfeng Sun (also known as “Alphonse Sun”) and Hongnam Cheung (also known as “Zhang Hongnim” and “Stanford Fischer”)—of conspiring to commit “hundreds of acts of wire fraud” to further “an unlawful pattern of racketeering activity” that siphoned up to $75,000 from each user successfully scammed.

Google was able to piece together the elaborate alleged scheme because the developers used a wide array of Google products and services to target victims, Google said, including Google Play, Voice, Workspace, and YouTube, breaching each one’s terms of service. Perhaps most notably, the Google Play Store’s developer program policies “forbid developers to upload to Google Play ‘apps that expose users to deceptive or harmful financial products and services,’ including harmful products and services ‘related to the management or investment of money and cryptocurrencies.'”

In addition to harming Google consumers, Google claimed that each product and service’s reputation would continue to be harmed unless the US district court in New York ordered a permanent injunction stopping developers from using any Google products or services.

“By using Google Play to conduct their fraud scheme,” scammers “have threatened the integrity of Google Play and the user experience,” Google alleged. “By using other Google products to support their scheme,” the scammers “also threaten the safety and integrity of those other products, including YouTube, Workspace, and Google Voice.”

Google’s lawsuit is the company’s most recent attempt to block fraudsters from targeting Google products by suing individuals directly, Bloomberg noted. Last year, Google sued five people accused of distributing a fake Bard AI chatbot that instead downloaded malware to Google users’ devices, Bloomberg reported.

How did the alleged Google Play scams work?

Google said that the accused developers “varied their approach from app to app” when allegedly trying to scam users out of thousands of dollars but primarily relied on three methods to lure victims.

The first method relied on sending text messages using Google Voice—such as “I am Sophia, do you remember me?” or “I miss you all the time, how are your parents Mike?”—”to convince the targeted victims that they were sent to the wrong number.” From there, the scammers would apparently establish “friendships” or “romantic relationships” with victims before moving the conversation to apps like WhatsApp, where they would “offer to guide the victim through the investment process, often reassuring the victim of any doubts they had about the apps.” These supposed friends, Google claimed, would “then disappear once the victim tried to withdraw funds.”

Another strategy allegedly employed by scammers relied on videos posted to platforms like YouTube, where fake investment opportunities would be promoted, promising “rates of return” as high as “two percent daily.”

The third tactic, Google said, pushed bogus affiliate marketing campaigns, promising users commissions for “signing up additional users.” These apps, Google claimed, were advertised on social media as “a guaranteed and easy way to earn money.”

Once a victim was drawn into using one of the fraudulent apps, “user interfaces sought to convince victims that they were maintaining balances on the app and that they were earning ‘returns’ on their investments,” Google said.

Occasionally, users would be allowed to withdraw small amounts, convincing them that it was safe to invest more money, but “later attempts to withdraw purported returns simply did not work.” And sometimes the scammers would “bilk” victims out of “even more money,” Google said, by requesting additional funds be submitted to make a withdrawal.

“Some demands” for additional funds, Google found, asked for anywhere “from 10 to 30 percent to cover purported commissions and/or taxes.” Victims, of course, “still did not receive their withdrawal requests even after these additional fees were paid,” Google said.

Which apps were removed from the Play Store?

Google tried to remove apps as soon as they were discovered to be fraudulent, but Google claimed that scammers concocted new aliases and infrastructure to “obfuscate their connection to suspended fraudulent apps.” Because scammers relied on so many different Google services, Google was able to connect the scheme to the accused developers through various business records.

Fraudulent apps named in the complaint include fake cryptocurrency exchanges called TionRT and SkypeWallet. To make the exchanges appear legitimate, scammers put out press releases on newswire services and created YouTube videos likely relying on actors to portray company leadership.

In one YouTube video promoting SkypeWallet, the supposed co-founder of Skype Coin uses the name “Romser Bennett,” which is the same name used for the supposed founder of another fraudulent app called OTCAI2.0, Google said. In each video, a completely different presumed hired actor plays the part of “Romser Bennett.” In other videos, Google found the exact same actor plays an engineer named “Rodriguez” for one app and a technical leader named “William Bryant” for another app.

Another fraudulent app that was flagged by Google was called the Starlight app. Promoted on TikTok and Instagram, Google said, that app promised “that users could earn commissions by simply watching videos.”

The Starlight app was downloaded approximately 23,000 times and seemingly primarily targeted users in Ghana, allegedly scamming at least 6,000 Ghanian users out of initial investment capital that they were told was required before they could start earning money on the app.

Across all 87 fraudulent apps that Google has removed, Google estimated that approximately 100,000 users were victimized, including approximately 8,700 in the United States.

Currently, Google is not aware of any live apps in the Play Store connected to the alleged scheme, the complaint said, but scammers intent on furthering the scheme “will continue to harm Google and Google Play users” without a permanent injunction, Google warned.

Google sues two crypto app makers over allegedly vast “pig butchering” scheme Read More »