25 March 2019

What Is Formjacking and How Can You Avoid It?


formjacking

2017 was the year of ransomware. 2018 was all about cryptojacking. 2019 is shaping up as the year of formjacking.

Drastic decreases in the value of cryptocurrencies such as Bitcoin and Monero mean cybercriminals are looking elsewhere for fraudulent profits. What better place than to steal your banking information straight from the product order form, before you even hit submit. That’s right; they’re not breaking into your bank. Attackers are lifting your data before it even gets that far.

Here’s what you need to know about formjacking.

What Is Formjacking?

A formjacking attack is a way for a cybercriminal to intercept your banking information direct from an e-commerce site.

According to the Symantec Internet Security Threat Report 2019, formjackers compromised 4,818 unique websites every month in 2018. Over the course of the year, Symantec blocked over 3.7 million formjacking attempts.

Furthermore, over 1 million of those formjacking attempts came during the final two months of 2018—ramping up towards the November Black Friday weekend, and onward throughout the December Christmas shopping period.

So, how does a formjacking attack work?

Formjacking involves inserting malicious code into the website of an e-commerce provider. The malicious code steals payment information such as card details, names, and other personal information commonly used while shopping online. The stolen data is sent to a server for reuse or sale, the victim unaware that their payment information is compromised.

All in all, it seems basic. It is far from it. One hacker used 22 lines of code to modify scripts running on the British Airways site. The attacker stole 380,000 credit card details, netting over £13 million in the process.

Therein lies the allure. Recent high-profile attacks on British Airways, TicketMaster UK, Newegg, Home Depot, and Target share a common denominator: formjacking.

Who Is Behind the Formjacking Attacks?

Pinpointing a single attacker when so many unique websites fall victim to a single attack (or at least, style of attack) is always difficult for security researchers. As with other recent cybercrime waves, there is no single perpetrator. Instead, the majority of formjacking stems from Magecart groups.

The name stems from the software the hacking groups use to inject malicious code into vulnerable e-commerce sites. It does cause some confusion, and you often see Magecart used as a singular entity to describe a hacking group. In reality, numerous Magecart hacking groups attack different targets, using different techniques.

Yonathan Klijnsma, a threat researcher at RiskIQ, tracks the various Magecart groups. In a recent report published with risk intelligence firm Flashpoint, Klijnsma details six distinct groups using Magecart, operating under the same moniker to avoid detection.

The Inside Magecart report [PDF] explores what makes each of the leading Magecart groups unique:

  • Group 1 & 2: Attack a wide range of targets, use automated tools to breach and skim sites; monetizes stolen data using a sophisticated reshipping scheme.
  • Group 3: Very high volume of targets, operates a unique injector and skimmer.
  • Group 4: One of the most advanced groups, blends in with victim sites using a range of obfuscation tools.
  • Group 5: Targets third-party suppliers to breach multiple targets, links to the Ticketmaster attack.
  • Group 6: Selective targeting of extremely high-value websites and services, including the British Airways and Newegg attacks.

As you can see, the groups are shadowy and use different techniques. Furthermore, the Magecart groups are competing to create an effective credential stealing product. The targets are different, as some groups specifically aim for high-value returns. But for the most part, they’re swimming in the same pool. (These six are not the only Magecart groups out there.)

Advanced Group 4

The RiskIQ research paper identifies Group 4 as “advanced.” What does that mean in the context of formjacking?

Group 4 attempts to blend in with the website it is infiltrating. Instead of creating additional unexpected web traffic that a network administrator or security researcher might spot, Group 4 tries to generate “natural” traffic. It does this by registering domains “mimicking ad providers, analytics providers, victim’s domains, and anything else” that helps them hide in plain sight.

In addition, Group 4 regularly alters the appearance of its skimmer, how its URLs appear, the data exfiltration servers, and more. There’s more.

The Group 4 formjacking skimmer first validates the checkout URL on which it is functioning. Then, unlike all other groups, the Group 4 skimmer replaces the payment form with one of their own, serving the skimming form directly to the customer (read: victim). Replacing the form “standardizes the data to pull out,” making it easier to reuse or sell on.

RiskIQ concludes that “these advanced methods combined with sophisticated infrastructure indicate a likely history in the banking malware ecosystem . . . but they transferred their MO [Modus Operandi] toward card skimming because it is a lot easier than banking fraud.”

How Do Formjacking Groups Make Money?

Most of the time, the stolen credentials are sold online. There are numerous international and Russian-language carding forums with long listings of stolen credit card and other banking information. They’re not the illicit, seedy type of site you might imagine.

Some of the most popular carding sites present themselves as a professional outfit—perfect English, perfect grammar, customer services; everything you expect from a legitimate e-commerce site.

magecart formjacking riskiq research

Magecart groups are also reselling their formjacking packages to other would-be cybercriminals. Analysts for Flashpoint found adverts for customized formjacking skimmer kits on a Russian hacking forum. The kits range from around $250 to $5,000 depending on complexity, with vendors displaying unique pricing models.

For instance, one vendor was offering budget versions of professional tools seen the high-profile formjacking attacks.

Formjacking groups also offer access to compromised websites, with prices starting as low as $0.50, depending on the website ranking, the hosting, and other factors. The same Flashpoint analysts discovered around 3,000 breached websites on sale on the same hacking forum.

Furthermore, there were “more than a dozen sellers and hundreds of buyers” operating on the same forum.

How Can You Stop a Formjacking Attack?

Magecart formjacking skimmers use JavaScript to exploit customer payment forms. Using a browser-based script blocker is usually enough to stop a formjacking attack stealing your data.

Once you add one of the script blocking extensions to your browser, you will have significantly more protection against formjacking attacks. It isn’t perfect though.

The RiskIQ report suggests avoiding smaller sites that do not have the same level of protection as a major site. Attacks on British Airways, Newegg, and Ticketmaster suggest that advice isn’t entirely sound. Don’t discount it though. A mom and pop e-commerce site is more likely to host a Magecart formjacking script.

Another mitigation is Malwarebytes Premium. Malwarebytes Premium offers real-time system scanning and in-browser protection. The Premium version protects against precisely this sort of attack. Unsure about upgrading? Here are five excellent reasons to upgrade to Malwarebytes Premium!

Read the full article: What Is Formjacking and How Can You Avoid It?


Read Full Article

How to Use Apple Remote Desktop to Manage Mac Computers


apple-remote-desktop

Apple Remote Desktop is a powerful app that lets you control all your Macs in one handy place. It takes enterprise-level management tools and puts them in your hands. You can use it to screen share, send files, install apps, run scripts, and more.

Take a look and see how Apple Remote Desktop can change how you manage a big group of Macs.

Adding Machines to Apple Remote Desktop

When you open Apple Remote Desktop for the first time, your first task is to find the Macs on your network and add them. If you know their IP addresses, you can easily enter them.

Most people, however, don’t have those written down anywhere, and if you use DHCP, they can change. Fortunately, Apple Remote Desktop has a built-in feature to scan your network for your Macs.

Scanner

Apple Remote Desktop's Scanner Section

The easiest way to do this is with Scanner. Select it on the left-hand side, and you’ll see a dropdown menu with a number of different ways to locate computers on your network. Each item will scan your network and display the hostname, IP address, and other information of devices on your network:

  • Bonjour: Displays all the Macs connected to your network using Bonjour.
  • Local Network: Displays all the devices on your local network, regardless of what they are or how they’re connected.
  • Network Range: Displays all the devices found in-between a certain IP range.
  • Network Address: Displays a device connected to a specific IP.
  • File Import: Import a list of IPs and search your network for them.
  • Task Server and Directory Server: Really only used in an office or enterprise environment, these options let you take a list from a server that you have and scan based on that.

If you’re connecting to a group of Macs at home, you’ll most likely be able to find them all over Bonjour, or Local Network. Keep in mind that Local Network will display all of your network devices, whereas Bonjour will only display the ones that are Bonjour-enabled (like Macs).

Connecting to the Machines

Once you’ve found your machines in Scanner, you should be able to click on their hostname to connect to them. You will then be prompted to type in an administrator’s account and password. You must do this in order to connect to that machine. After you’ve done so, you’ll be able to see that computer under All Computers on the left-hand side.

Now that you have a list of machines, what can you actually do with Apple Remote Desktop?

Observe and Control

The two actions you ‘ll do most with the Apple Remote Desktop client sound Orwellian when said together, but they’re almost exactly the same. Both buttons are in the top-left corner of the main window.

Observe allows you to simply monitor another user’s screen in real-time, while Control lets you use their cursor and keyboard input as well. A third action, Curtain, lets you lock down the user’s machine and display a message explaining why. You will still have full control of the target machine, but the user will only see the message.

The Interact menu bar tab lets you perform even more administrative actions. You can send messages, chat, and lock or unlock the screen.

Send Remote Commands

Use the Manage menu bar item to Open Application, put the computer to Sleep, Wake it up, Log Out Current User, Restart it, or do a Shutdown. Note that you should be careful with remote Shutdown, since you cannot start the machine up again remotely.

You can also use the Unix button to send bash shell commands. This lets you choose to send the commands either as the currently logged-in user, or a user of your choice such as root. If you want to see the output of the command, check the Display all output box, then check the results in the History section on the left-hand side.

See our beginner’s guide to the Mac Terminal if you’re new to this.

Install Packages

The Copy and Install buttons in the main window will allow you to transfer or install files directly on a target machine. You can use this to install the best Mac apps in the /Applications folders of all your machines at once.

Select a machine, hit either button, and choose the file to copy or the package to install. You can see whether or not the transfer succeeded under History.

Install Screen for Apple Remote Desktop

Do a Spotlight Search

If you hit the Spotlight button, you can search the target machine for a certain file, copy it to your computer, or delete it. In the Spotlight Search window, select the Plus button to search for certain criteria.

View Reports

Use the Reports button to get current reports on all your Macs. You can search for a system overview, currently installed software, hardware specs, and more. Once you get the output, you can save the file to refer to later.

Apple Remote Desktops' Report window

Organize Your Computers and Customize Your Preferences

You can use labels to categorize your machines by area or department. Double-click any machine in your list, hit Edit in their info window, and then choose a label color. When you’re done, go to View > View Options, check Label, and then click the Label tab in the main window to organize all your machines by their label colors.

Apple Remote Desktop's Label Features

In Preferences, you can change various settings and customize the appearance.

The most important action you can take is set up a Task Server. You can use a Task Server to set up installations and commands to be performed on Macs that are currently offline.

Apple Remote Desktop will communicate with the Task Server when you run a command and store a copy of the command on the Server. Afterwards, the Server will check in periodically, and run the command on the target machine once it comes back online.

Control All Your Devices Remotely

Now that you’ve gotten a taste for Apple Remote Desktop’s remote control and the power it bestows, you have the power to manage all your computers more easily than ever. If this tool didn’t do it for you, we’ve shown other ways to remote access your Mac too.

Next, why not learn how to control your iPhone from your Mac by utilizing some third-party options to communicate between iOS and macOS? Soon you’ll be able to control all your devices, no matter where you are.

Read the full article: How to Use Apple Remote Desktop to Manage Mac Computers


Read Full Article

What Is Coding and How Does It Work?


whats-coding

Computer code is very important. Almost every electronic device you use relies on code. The way things work can seem quite confusing, but when you break it down it’s actually simple.

People who make code are called programmers, coders or developers. They all work with computers to create websites, apps, and even games! Today you’ll learn what code it, what it is for, and how to start learning code yourself.

What Is Code?

Machine Code Example

Computers have their own language called Machine Code which tells them what to do. As you can see, it doesn’t make a lot of sense to humans!

Each number or letter is telling the computer to change something in its memory. This could be a number or word, or a little part of a picture or video. By themselves, computers don’t know how to do anything. It is the job of the programmer to give them instructions.

It is possible to learn Machine Code, but it would take a long time! Luckily there is an easier way to communicate with computers.

What Is a Programming Language?

Hello World in Python
Now, this looks a little easier to understand! This picture shows how to tell the computer to say Hello, world. Instead of using machine code, it uses a programming language called Python.

Almost all programming languages work the same way:

  1. You write code to tell it what to do: print(“Hello, world”).
  2. The code is compiled, which turns it into machine code the computer can understand.
  3. The computer executes the code, and writes Hello, world back to us.

There are hundreds of different programming languages which can seem confusing, but they all do the same thing. You type in what you want it to do, the compiler turns it into language the computer understands, then the computer does it, which is called executing the code in programming speak!

What Is Coding?

Sometimes Code is Easy to understand

Coding is the process of using a programming language to get a computer to behave how you want it to. Every line of code tells the computer to do something, and a document full of lines of code is called a script.

Each script is designed to carry out a job. This job might be to take an image and change its size. It might play a certain sound or piece of music. When you click like on someone’s post on social media, a script is what makes it happen.

Unlike people, computers will do exactly what you tell them to. This might sound great, but it can cause problems. If you tell a computer to start counting upwards, and don’t tell it to stop, it’ll keep counting forever! Being a good programmer is all about knowing how to tell a computer to act.

What Is a Program?

Scripts by themselves can only do things if they are compiled and then executed. This is useful while you are still working on it, but when you are done, you want people who aren’t programmers to be able to use your script. What you need is to turn your script into a program.

When you are happy with your script, you can compile it into a program. As you already know, compiling changes the code from your programming language into machine code the computer can understand. This time, the machine code is stored in a program which anyone can download and use. Every kind of app, game, or website is a program.

Is Coding Hard?

Code can be like Books in a Library

Coding can be very simple, and anyone can learn the basics. A good analogy is to think of coding like books in a library. Some books use simple language, and the stories are easy to understand. Others use very complex words and have stories that seem to make no sense. Whether they are simple or hard to read, they are all books.

The more books you read, the better you get at it. The complicated language or confusing stories get easier to understand until one day you can read things that you wouldn’t even dream of in the past!

Learning to code is the same. The first time you try to code you will find it hard, but every time you do it you get better. If you find learning a programming language hard, you can still learn the important ideas behind it using a visual coding language. You can even make your own Mario game without typing any code at all!

What Does Code Look Like

Sample Python program

The image above shows a script called hello_name. You’ve already seen that a single line of code can make the computer print to the screen. Let’s say that instead of just saying hello world, you want the user to type in their name, and for the computer to greet them by name? Let’s break down what is happening here.

  1. When the script starts the computer prints a question to the screen.
  2. Next the computer waits for the user to input their name, and saves it.
  3. “Hello” prints to the screen, along with the saved name.
  4. In the Cmder window, the script compiles and executes using Python.
  5. The script ran just the way it was designed to, before exiting.

This example shows you a simple piece of code written in a code editor, and run in Cmder which is a type of terminal window. Don’t worry too much about what either of these things is for now. You now know what Python code looks like and how this script works.

How Code Becomes a Program

Turning a Script into a Program

If you are totally new to code, you might still wonder how scripts like the one above become the kind of programs you are used to using. In the image above, the window on the left is a tool to turn Python scripts into programs. The window on the right has an icon called hello_name.exe. I think you can guess what happens if you were to click on it!

Gif of the working .EXE file

From no code, to a finished program. This example is really simple, but this is how almost all coding works. Every day, people use programming languages they have learned, to write scripts, which will become programs we all use.

Coding Is Cool

Today’s article has taught you what code is, and how some Python code works. There are lots of great websites and apps which can help you learn programming too!

Coding is for everyone, and starting has never been easier. You can even learn to code using Minecraft!

Read the full article: What Is Coding and How Does It Work?


Read Full Article

The 10 Best WordPress Themes for a Photography Portfolio


wp-portfolio-themes

As a photographer, you’re probably using Instagram to showcase your work, but Instagram can’t replace an actual portfolio. However, using WordPress and one of the many WordPress themes available, you can start your own website in minutes.

Not every pre-designed template will make a good backdrop for your photography. Especially not one of the default ones, originally made for blogs. But don’t worry, as we’ve found the best WordPress themes to make your photography portfolio look amazing.

1. Satelite

Satelite, a WordPress photography theme

Satelite is packed with bells and whistles like video backgrounds and sound effects. But if you’re not a fan of all those decorations, you’re free to cut them and put the spotlight on the images.

With a range of options for the homepage, Satellite lets you display your best work in fullscreen mode, set up a smaller carousel, or opt for a classic portfolio grid.

The individual project pages allow you to add titles and short descriptions to provide some context for your photography. And with responsive Retina-ready design, your photos will look perfect on any device.

Download: Satelite ($39)

2. Julie Bernerro

Julie Bernerro, one of the best WordPress themes for a photography portfolio

This theme for a WordPress-based photography portfolio includes several vastly different, but equally gorgeous, designs. The fullscreen mode with large headings begs for colorful fashion shots, and the clean white grids are a good choice for portraits.

But Julie Bernerro is more than a pretty typeface: the template is SEO-friendly, optimized for Retina displays, and fully responsive.

Julie Bernerro is compatible with the WPML translation plugin and integrates with Ecwid, an ecommerce plugin for WordPress. So if you need a portfolio in a language other than English or intend to start a merchandising store, this WordPress theme is a solid choice.

Download: Julie Bernerro ($75)

3. Sonya

Sonya, a portfolio theme for black-and-white photography

If your genre is black-and-white photography, Sonya is a great affordable option for your WordPress-powered portfolio. Its asymmetric grids on a white background with heavy black fonts look good enough with color photography, but truly shine with monochrome shots.

The Sonya theme may not be as well-equipped as others, but it checks the right boxes; it loads quickly, looks good on mobile, and has a simple blog for your news and announcements.

Download: Sonya ($39)

4. WhiteLight

WhiteLight, a portfolio WordPress theme

WhiteLight allows you to play with layouts and makes that easy to do with a drag-and-drop page builder. As the name suggests, it’s white and light, so it lets your photography dictate the look of the website.

One of the best portfolio themes in terms of functionality, WhiteLight comes with a wide range of modules and plugins for rich content, from calendars and maps to pricing tables and bar counters.

Download: WhiteLight ($69)

5. Lima

Lima, a WordPress theme for a photography portfolio

Like most WordPress templates for photography and design, Lima provides a neutral, minimal backdrop for your work. The all-black theme calls for some color in the photos, but you could also make it work for monochrome photography.

As far as layouts are concerned, Lima hits the sweet spot between giving you choice and giving you choice paralysis. The demo includes four layouts for the homepage, several gallery options, and a couple more ways to arrange a project page. All of them are, of course, mobile responsive and Retina-ready.

Download: Lima ($44)

6. Addison

Addison, a WordPress photography theme

Addison is ideal for minimalist photography with a heavy focus on geometry and color. It gives you several styles to choose from, all on a clean white background with heavy black frames on hover.

Addison offers plenty of custom widgets, so your portfolio can have social sharing, a calendar, and even newsletter subscription. And with clean, SEO-friendly code, it’s a good foundation for your self-marketing efforts.

Download: Addison ($75)

7. Photography Phoxy

Phoxy, a WordPress portfolio theme

This photography theme will make you feel like a kid in a candy store. It comes with a staggering 38 portfolio layouts, both in black and in white, so picking just one may take you a while.

All layouts are ready to import and use, and are easy to customize thanks to the visual website builder. Plus, Phoxy is chock full of helpful widgets like an appointment booking calendar, it integrates with WooCommerce so you can start a store, and it boasts fantastic load speed.

Download: Photography Proxy ($48)

8. Kordex

Kordex, a photography theme for WordPress

With inbuilt photo proofing, client management, and the ability to password-protect certain pages, Kordex is more than a portfolio theme. It’s a fully-fledged website for a contract photographer, combining photo galleries with practical tools.

The fully responsive lightbox means your photos will be well-presented even on mobile, and the 20 homepage variations give you plenty of looks to choose from. All of those layouts work regardless of your genre, be it portrait, macro, or landscape photography.

Download: Kordex ($59)

9. Brailie

Brailie, a photography portfolio theme

Brailie comes with endless combinations of gallery layouts and headers, not to mention the options you have for your blog and shop. Over 50 demos are ready to import, and each of them looks better than the other.

Be it full-screen photos framed with black or clean, lightweight grids, Brailie has a look for everyone. They are easy to customize with a visual composer tool, and come optimized for search engines and Retina displays.

Download: Brailie ($59)

10. Kodell

Kodell, a WordPress portfolio theme

Kodell is a WordPress theme that works equally well for photography and graphic design. It’s clean, stylish, and has several grid layouts that look best with minimalist photography.

Like most premium templates, Kodell is compatible with WooCommerce, letting you build your own store with ease. And its responsive design and social media widgets make sure your fans can seamlessly move between your Instagram and your new portfolio.

Download: Kodell ($59)

Start a Photography Portfolio Today

We hope one of these themes tickles your fancy. If you’ve got your mind set on WordPress, but don’t know where to start, here’s the ultimate guide to setting up a WordPress website.

And if creating a WordPress website from scratch sounds daunting, there are plenty of website builders to create an online portfolio.

Don’t have web hosting yet? Use this link for a discount on InMotion WordPress Hosting or this link for a discount on InMotion Shared Web Hosting!

Read the full article: The 10 Best WordPress Themes for a Photography Portfolio


Read Full Article

10 Quick Firefox Tweaks to Maximize Your Online Privacy


firefox-privacy-tips

From Facebook scandals to schools spying on their students through webcams, it seems as if threats to your privacy are everywhere online. But there are some simple steps you can take to stop companies from harvesting your data when you use the Firefox browser.

Today we’ll show you how to make Firefox more private by installing privacy-enhancing extensions and changing a few simple settings.

1. Install the Facebook Container Extension

Firefox Privacy Facebook Container

Facebook may be a popular site, but it has a terrible reputation when it comes to privacy. Facebook tracks you across the internet, recording data about which sites you visit and what type of content you engage with.

If you want to keep using Facebook but avoid the tracking, you can use the Facebook Container extension for Firefox. This will delete the Facebook cookies from your browser and will load all future Facebook content in its own container which does not interact with the rest of your browser.

Whenever you visit Facebook you’ll see a blue line under the tab and a Facebook lock image in the address bar. This way you know the extension is working and you are keeping Facebook separate from your general browsing.

Download: Facebook Container (Free)

2. Do You Need the Privacy Badger Extension?

Firefox Privacy Privacy Badger

Privacy Badger is a one-stop shop for improving your privacy on Firefox. You just have to install the extension and it will automatically block invisible trackers.

It starts off by sending a Do Not Track signal while you browse, which tells websites not to track you via cookies. If a website ignores the Do Not Track, Privacy Badger will learn to block its trackers.

When you click on the badger icon you can see which domains you are interacting with and whether they are tracking you. You can also flip the toggles to allow tracking for particular sites if you want to.

Download: Privacy Badger (Free)

3. Install the uBlock Origin Extension

Firefox Privacy uBlock Origin

Ad blockers are controversial because they cut off an important source of revenue for many websites. Some people even argue that ad blocking browser extensions are killing the internet.

But if you’re concerned about privacy, you’re likely concerned about ads as well. Ads can track your behavior across sites and can hide malicious code, not to mention the annoyance of pop-ups and autoplaying videos.

Installing uBlock Origin will block the large majority of adverts on the internet. But we encourage you to hit the blue power icon to disable the blocking on sites which you trust and value.

Download: uBlock Origin (Free)

4. Consider the Cookie Autodelete Extension

Firefox Privacy Cookie Autodelete

Cookies are small text files saved on your computer which hold information about your browsing. While that sounds immediately worrying, in fact there are reasons to leave cookies enabled on your browser such as being able to log into sites quickly.

The Cookie Autodelete extension gives you the best of both worlds by allowing cookies to be saved while you have a tab open, but immediately deleting the cookies once the tab is closed. Click on Auto-clean disabled in the extension menu to enable this feature.

Download: Cookie Autodelete (Free)

5. Install the Disconnect Extension

Firefox Privacy Disconnect

Disconnect is a popular privacy extension because it’s so broad-ranging and easy to use. Once you’ve installed it, it will prevent sites from tracking you.

It is similar to Privacy Badger, but also gives you visualizations of what trackers have been blocked and which sites they came from. If you want to dig into the details of trackers in more depth, this is the extension to use.

Download: Disconnect (Free)

6. Install the Decentraleyes Extension

Firefox Privacy Decentraleyes

Another extension to remove trackers, Decentraleyes is perfect for people who want a “set it and forget it” style blocker.

There is no configuration or tweaking required. You just install the extension and browse happy in the knowledge that attempts to track you will be foiled.

Download: Decentraleyes (Free)

7. Install the Temporary Containers Extension

Firefox Privacy Temporary Containers

This is similar to the Facebook Container extension, but for any sites that you want.

When you enable container mode, links will open in their own tabs marked by an orange line beneath them. This means sites you browse from this container can’t access your other data, and cookies will be deleted once you close the container.

To open a new temporary container, click the clock icon with a plus sign in the top right of the browser. Or go into the options for the extension and hit enable automatic mode for all your new tabs to be opened in a temporary container for the best privacy protection.

Download: Temporary containers (Free)

8. Use the Private Browsing Feature

Firefox Privacy Private Browsing

If you want to quickly visit a site without your browser saving information such as cookies or passwords, Firefox has a built-in feature to do just this. The private browsing feature opens up a new type of tab in purple. This tab will not save information on which pages you visit or what you search for, cookies, or temporary files.

You can open a private browsing tab by going to the Firefox menu and selecting New Private Window or by pressing Ctrl + Shift + P. Or check out our full guide on how to enable private browsing for more information.

9. Turn On Firefox’s Do Not Track Feature

Firefox Privacy Do Not Track Setting

Within Firefox is a little-known but important option that allows you to send a “Do Not Track” signal while you browse.

If you don’t want to install a new extension but want to make a quick change to stop many sites from tracking you, enable this feature. Open the Firefox menu, then Options > Privacy & Security and look under the Content Blocking heading.

Remember though that not all sites will respect the Do Not Track signal, so some disreputable sites may continue tracking you even when you have this enabled.

10. Change Permissions for Location and Camera

Firefox Privacy Permissions Settings

The idea of a website having access to the camera or microphone on your computer is particularly horrifying and a big privacy concern for many people.

If you’re worried about sites spying on you, there’s an option in Firefox’s settings that will put your mind at ease. You can block website requests for use of your location, camera, and microphone by going to the Firefox menu. Select Options then Privacy & Security and scroll down to the Permissions heading.

Here you can see which sites have requested access to your location, camera, or microphone, then block any which seem suspicious. There’s also an option to Block new requests asking to access your location or your camera and microphone, which you can enable for peace of mind.

Preserve Your Privacy With Anonymous Web Browsing

These extensions and tips will help make Firefox much more private than it is by default, by stopping trackers from following you online and preventing sites from accessing your hardware such as your camera.

However, if you want to take the next step and stay totally anonymous online, then you could also try out a privacy-focused web browser that is completely private such as Tor.

Read the full article: 10 Quick Firefox Tweaks to Maximize Your Online Privacy


Read Full Article

How to watch the live stream for today’s Apple keynote


Apple is holding a keynote today on its campus in Cupertino, and the company is expected to talk about new services. Don’t expect any new device, today’s event should be all about content. At 10 AM PT (1 PM in New York, 5 PM in London, 6 PM in Paris), you’ll be able to watch the event as the company is streaming it live.

Rumor has it that the company plans to unveil multiple new services. The most anticipated one will be a new video streaming service that should compete with Netflix, Amazon Prime Video and others. In addition to that service, Apple will unveil an Apple News subscription to access magazines and premium articles for a flat monthly fee.

But we might also hear about a mysterious credit card and a gaming subscription service. Details are still thin, so it’s going to be interesting to hear Apple talk about all those services.

If you have an Apple TV, you can download the Apple Events app in the App Store. It lets you stream today’s event and rewatch old ones. The app icon was updated a few days ago for the event.

And if you don’t have an Apple TV, the company also lets you live-stream the event from the Apple Events section on its website. This video feed now works in all major browsers — Safari, Microsoft Edge, Google Chrome and Mozilla Firefox.

So to recap, here’s how you can watch today’s Apple event:

  • Your favorite web browser on the Mac or Windows 10.
  • An Apple TV with the Apple Events app in the App Store.
  • Google Chrome on your Android phone.
  • And here’s the link to the live stream.

Of course, you also can read TechCrunch’s live blog if you’re stuck at work and really need our entertaining commentary track to help you get through your day. We have a team in the room.


Read Full Article

24 March 2019

Apple could announce its gaming subscription service on Monday


Apple is about to announce some new services on Monday. While everybody expects a video streaming service as well as a news subscription, a new report from Bloomberg says that the company might also mention its gaming subscription.

Cheddar first reported back in January that Apple has been working on a gaming subscription. Users could pay a monthly subscription fee to access a library of games. We’re most likely talking about iOS games for the iPhone and iPad here.

Games are the most popular category on the App Store, so it makes sense to turn this category into a subscription business. And yet, most of them are free-to-play, ad-supported games. Apple doesn’t necessarily want to target those games in particular.

According to Bloomberg, the service will focus on paid games from third-party developers, such as Minecraft, NBA 2K games and the GTA franchise. Users would essentially pay to access this bundle of games. Apple would redistribute revenue to game developers based on how much time users spend within a game in particular.

It’s still unclear whether Apple will announce the service or launch it on Monday. The gaming industry is more fragmented than the movie and TV industry, so it makes sense to talk about the service publicly even if it’s not ready just yet.


Read Full Article

The ethics of internet culture: a conversation with Taylor Lorenz


Taylor Lorenz was in high demand this week. As a prolific journalist at The Atlantic and about-to-be member of Harvard’s prestigious Nieman Fellowship for journalism, that’s perhaps not surprising. Nor was this the first time she’s had a bit of a moment: Lorenz has already served as an in-house expert on social media and the internet for several major companies, while having written and edited for publications as diverse as The Daily Beast, The Hill, People, The Daily Mail, and Business Insider, all while remaining hip and in touch enough to currently serve as a kind of youth zeitgeist translator, on her beat as a technology writer for The Atlantic.

Lorenz is in fact publicly busy enough that she’s one of only two people I personally know to have openly ‘quit email,’ the other being my friend Russ, an 82 year-old retired engineer and MIT alum who literally spends all day, most days, working on a plan to reinvent the bicycle.

I wonder if any of Lorenz’s previous professional experiences, however, could have matched the weight of the events she encountered these past several days, when the nightmarish massacre in Christchurch, New Zealand brought together two of her greatest areas of expertise: political extremism (which she covered for The Hill), and internet culture. As her first Atlantic piece after the shootings said, the Christchurch killer’s manifesto was “designed to troll.” Indeed, his entire heinous act was a calculated effort to manipulate our current norms of Internet communication and connection, for fanatical ends.

Taylor Lorenz

Lorenz responded with characteristic insight, focusing on the ways in which the stylized insider subcultures the Internet supports can be used to confuse, distract, and mobilize millions of people for good and for truly evil ends:

Before people can even begin to grasp the nuances of today’s internet, they can be radicalized by it. Platforms such as YouTube and Facebook can send users barreling into fringe communities where extremist views are normalized and advanced. Because these communities have so successfully adopted irony as a cloaking device for promoting extremism, outsiders are left confused as to what is a real threat and what’s just trolling. The darker corners of the internet are so fragmented that even when they spawn a mass shooting, as in New Zealand, the shooter’s words can be nearly impossible to parse, even for those who are Extremely Online.”

Such insights are among the many reasons I was so grateful to be able to speak with Taylor Lorenz for this week’s installment of my TechCrunch series interrogating the ethics of technology.

As I’ve written in my previous interviews with author and inequality critic Anand Giridharadas, and with award-winning Google exec turned award-winning tech critic James Williams, I come to tech ethics from 25 years of studying religion. My personal approach to religion, however, has essentially always been that it plays a central role in human civilization not only or even primarily because of its theistic beliefs and “faith,” but because of its culture — its traditions, literature, rituals, history, and the content of its communities.

And because I don’t mind comparing technology to religion (not saying they are one and the same, but that there is something to be learned from the comparison), I’d argue that if we really want to understand the ethics of the technologies we are creating, particularly the Internet, we need to explore, as Taylor and I did in our conversation below, “the ethics of internet culture.”

What resulted was, like Lorenz’s work in general, at times whimsical, at times cool enough to fly right over my head, but at all times fascinating and important.

Editor’s Note: we ungated the first of 11 sections of this interview. Reading time: 22 minutes / 5,500 words.

Joking with the Pope

Greg Epstein: Taylor, thanks so much for speaking with me. As you know, I’m writing for TechCrunch about religion, ethics, and technology, and I recently discovered your work when you brought all those together in an unusual way. You subtweeted the Pope, and it went viral.

Taylor Lorenz: I know. [People] were freaking out.

Greg: What was that experience like?

Taylor: The Pope tweeted some insane tweet about how Mary, Jesus’ mother, was the first influencer. He tweeted it out, and everyone was spamming that tweet to me because I write so much about influencers, and I was just laughing. There’s a meme on Instagram about Jesus being the first influencer and how he killed himself or faked his death for more followers.

Because it’s fluid, it’s a lifeline for so many kids. It’s where their social network lives. It’s where identity expression occurs.

I just tweeted it out. I think a lot of people didn’t know the joke, the meme, and I think they just thought that it was new & funny. Also [some people] were saying, “how can you joke about Jesus wanting more followers?” I’m like, the Pope literally compared Mary to a social media influencer, so calm down. My whole family is Irish Catholic.

A bunch of people were sharing my tweet. I was like, oh, god. I’m not trying to lead into some religious controversy, but I did think whether my Irish Catholic mother would laugh. She has a really good sense of humor. I thought, I think she would laugh at this joke. I think it’s fine.

Greg: I loved it because it was a real Rorschach test for me. Sitting there looking at that tweet, I was one of the people who didn’t know that particular meme. I’d like to think I love my memes but …

Taylor: I can’t claim credit.

Greg: No, no, but anyway most of the memes I know are the ones my students happen to tell me about. The point is I’ve spent 15 plus years being a professional atheist. I’ve had my share of religious debates, but I also have had all these debates with others I’ll call Professional Strident Atheists.. who are more aggressive in their anti-religion than I am. And I’m thinking, “Okay, this is clearly a tweet that Richard Dawkins would love. Do I love it? I don’t know. Wait, I think I do!”

Taylor: I treated it with the greatest respect for all faiths. I thought it was funny to drag the Pope on Twitter.

The influence of Instagram

Alexander Spatari via Getty Images


Read Full Article

Hackers conquer Tesla’s in-car web browser and win a Model 3


A pair of security researchers dominated Pwn2Own, the annual high-profile hacking contest, taking home $375,000 in prizes including a Tesla Model 3 — their reward for successfully exposing a vulnerability in the electric vehicle’s infotainment system.

Tesla handed over its new Model 3 sedan to Pwn2Own this year, the first time a car has been included in the competition. Pwn2Own is in its 12th year and run by Trend Micro’s Zero Day Initiative. ZDI has awarded more than $4 million over the lifetime of the program.

The pair of hackers Richard Zhu and Amat Cam, known as team Fluoroacetate, “thrilled the assembled crowd” as they entered the vehicle, according to ZDI, which noted that after a few minutes of setup, they successfully demonstrated their research on the Model 3 internet browser.

The pair used a JIT bug in the renderer to display their message — and won the prize, which included the car itself. In the most simple terms, a JIT, or just-in-time bug, bypasses memory randomization data that normally would keep secrets protected.

Tesla told TechCrunch it will release a software update to fix the vulnerability discovered by the hackers.

“We entered Model 3 into the world-renowned Pwn2Own competition in order to engage with the most talented members of the security research community, with the goal of soliciting this exact type of feedback. During the competition, researchers demonstrated a vulnerability against the in-car web browser,” Tesla said in an emailed statement. “There are several layers of security within our cars which worked as designed and successfully contained the demonstration to just the browser, while protecting all other vehicle functionality. In the coming days, we will release a software update that addresses this research. We understand that this demonstration took an extraordinary amount of effort and skill, and we thank these researchers for their work to help us continue to ensure our cars are the most secure on the road today.”

Pwn2Own’s spring vulnerability research competition, Pwn2Own Vancouver, was held March 20 to 22 and  featured five categories, including web browsers, virtualization software, enterprise applications, server-side software and the new automotive category.

Pwn2Own awarded a total of $545,000 for 19 unique bugs in Apple Safari, Microsoft Edge and Windows, VMware Workstation, Mozilla Firefox, and Tesla.

Tesla has had a public relationship with the hacker community since 2014 when the company launched its first bug bounty program. And it’s grown and evolved ever since.

Last year, the company increased the maximum reward payment from $10,000 to $15,000 and added its energy products as well. Today, Tesla’s vehicles and all directly hosted servers, services and applications are now in scope in its bounty program


Read Full Article

You Can Now Use Threaded Replies on Messenger


Facebook Messenger can now handle threaded replies. In a nutshell, this means you can reply specifically to one comment in a chat without derailing the whole conversation. Which makes it especially useful for group chats involving multiple people.

How to Use Threaded Replies on Messenger

Creating a threaded reply in Facebook Messenger is extremely simple. All you need to do is press and hold down on the individual message to which you want to reply. Alongside the existing option to add an emoji, you’ll now see a “Reply” button.

Click this, and write your response as normal. When you hit send, your message will be added to the conversation, but with the original message attached as a quote. So while everyone in the chat will be able to see it, they’ll know who you’re addressing.

You could find this useful in a one-on-one chat; if, for example, the conversation has moved on and you want to address something said earlier. However, threaded replies are particularly useful in group chats where multiple subjects are being discussed at once.

Facebook hasn’t formally announced this feature, but it should be rolling out to Messenger’s 1.3 billion users around the world right now. If you can’t yet use a threaded reply in Messenger be sure to update the app to the latest version.

Facebook Plans to Merge Its Messaging Apps

Facebook is working on merging its three messaging apps. This means that eventually, Messenger, WhatsApp, and Instagram would all share the same underlying technology. Which would enable users of one app to communicate with users of another app.

This likely explains why Facebook has added threaded replies to Messenger, and why now. WhatsApp has boasted this feature for some time, and the more features the apps share, the easier it will be for Facebook to merge Messenger, WhatsApp, and Instagram.

Read the full article: You Can Now Use Threaded Replies on Messenger


Read Full Article

Flying taxi startup Blade is helping Silicon Valley CEOs bypass traffic


One year after a $38 million Series B valued on-demand aviation startup Blade at $140 million, the company has begun taxiing the Bay Area’s elite.

As part of a new pilot program, Blade has given 200 people in San Francisco and Silicon Valley exclusive access to its mobile app, allowing them to book helicopters, private jets and even seaplanes at a moments notice for $200 per seat, at least.

Blade, backed by Lerer Hippeau, Airbus, former Google CEO Eric Schmidt and others, currently flies passengers around the New York City area, where it’s headquartered, offering the region’s wealthy $800 flights to the Hamptons, among other flights at various price points. According to Business Insider, it has worked with Uber in the past to help deep-pocketed Coachella attendees fly to and from the Van Nuys Airport to Palm Springs, renting out six-seat helicopters for more than $4,000 a pop.

Its latest pilot seems to target business travelers, connecting riders to the San Francisco International Airport and Oakland International Airport to Palo Alto, San Jose, Monterey and Napa Valley. The goal is to shorten trips made excruciatingly long due to bad traffic in major cities like New York, Los Angeles and San Francisco. Recently, the startup partnered with American Airlines to better establish its network of helicopters, a big step for the company as it works to integrate with existing transportation infrastructure.

Blade, led by founder and chief executive officer Rob Wiesenthal, a former Warner Music Group executive, has raised about $50 million in venture capital funding to date. To launch at scale and, ultimately, to compete with the likes of soon-to-be-public transportation behemoth Uber, it will have to land a lot more investment support.

Uber too has lofty plans to develop a consumer aerial ridesharing business, as do several other privately-funded startups. Called UberAIR, Uber plans to offer short-term shareable flights to commuters as soon as 2023. The company has raised billions of dollars to turn this sci-fi concept to reality.

Then there’s Kitty Hawk, a company launched by former Google vice president an Udacity co-founder Sebastian Thrun, which is developing an aircraft that can take off like a helicopter but fly like a plane for short-term urban transportation. Others in the air taxi or vertical take-off and landing aircraft space, including Volocopter, Lilium and Joby Aviation, have raised tens of millions to eliminate traffic congestion or, rather, to chauffer the rich.

Blade’s next stop is India, the Financial Times reports, where it will conduct a pilot connecting travelers in downtown Mumbai and Pune. The company tells TechCrunch they are currently exploring one additional domestic pilot and one additional international pilot.


Read Full Article