Bug Lets Audio, Video be Transmitted Without Consent in Apps Like Signal

Google’s Project Zero security team found a bug that lets audio and video be transmitted without user interaction in five messaging apps. These are Signal, JioChat, Mocha, Google Duo, and Facebook Messenger. All bugs have been fixed.

I investigated the signalling state machines of seven video conferencing applications and found five vulnerabilities that could allow a caller device to force a callee device to transmit audio or video data. All these vulnerabilities have since been fixed. It is not clear why this is such a common problem, but a lack of awareness of these types of bugs as well as unnecessary complexity in signalling state machines is likely a factor.

Apple Homepage Marks Martin Luther King Day

Apple’s homepage has been updated to honour Martin Luther King day. The usual images have gone and there is a black-and-white photograph of the civil rights leader. The page also features a quote from him –  “true peace is not merely the absence of tension; it is the presence of justice.”

Where are the Safari 14 WebExtensions?

In 2020 Apple announced it would support browser extensions that used the WebExtensions API. But as Jason Snell points out, we haven’t seen many yet. One developer listed possible barriers for entry:

Limited time, lack of access to Apple hardware, unfamiliarity with Apple’s developer tools, Safari’s incompatibility with some existing extension-development tools, and the requirement to make some code changes in order to fit inside Apple’s security model.

I think another barrier is probably the US$99/year developer program fee. It makes sense if you’re already in the program to build an extension if it makes sense for you, but I don’t think many outside of the program will pay that just to release a new extension. Then again, it’s still in the early days of this new support.

Apple Fitness Boss Jay Blahnik Talks Fitness+

A short interview with Apple’s senior director of fitness Jay Blahnik was shared on the Healthy-ish podcast. They talk about Fitness+, health and fitness in general, and why it’s time to rethink our mentality of working out. “Jay Blahnik is the Senior Director of Fitness Technologies at Apple, so it goes without saying that he knows a thing or two about what gets people up and moving. He shares how Apple Fitness+ taps into this, and also why it might be time to rethink where, when and even how you work out. Because, the world has changed. And your gym membership with it.”

Analysts Say Spotify’s Podcasting Isn’t Working Out

Citi analysts wrote to clients their belief that Spotify’s foray into podcasting hasn’t been working.

The cadence of Premium gross additions (through 3Q20) and app download data (through 4Q20) do not show any material benefit from recent podcast investments (that began in 2019). The firm downgraded the stock to sell from neutral. Spotify’s stock was down more than 6.5% in the afternoon.

Remote Reflections from CES — Mac Geek Gab 853

Your two favorite geeks “went” to CES last week, and have some stories to share. Cool Stuff Found abounds, as well as some thoughts on this year’s trends. Of course, they didn’t leave home, so they still had time to answer your questions, find some Quick Tips, and make a show out of it all. Press play and listen as John and Dave help us all to learn at least five new things!