Google Store Takes Down App That Removes Chinese Software

Google has removed an app from its Play Store that was designed to help users to detect and delete apps that were made in China.

More Than 1 Million Downloads

The Remove China Apps, which is reported to have been downloaded by more than a million people on its first day has now been removed from Google’s Play Store following complaints from Chinese app makers that the app was clearly a form of market disruption.

The App

The app, which was developed by the Indian company One Touch AppLabs, was designed to help identify and remove any apps of Chinese origin from the user’s phone.  This included identifying extremely popular apps such as TikTok (owned by a Beijing-based company) and Zoom, whose founder was born in China.

If a user chose to delete all the apps that had been identified as being linked to China by Remove China Apps, the user would receive a message on their phone that is reported to have said “Congratulations. You are awesome. No China app found in your system.”

The app was not as successful, however, in being able to identify apps that had been pre-installed on Chinese-made smartphones.

Irony

Despite millions of downloads by Indian people hoping to rid themselves of Chinese apps, most smartphones in India were made in China. Also, some tech commentators have suggested that it may be difficult for Indian developers to make good equivalent apps and that a freeze on investment in India by countries like China (announced in April) could actually hit funding opportunities for Indian start-ups.

Why?

Remove China Apps, which was developed by an Indian company and has the vast majority of its downloads in India appears to have been released in response to tensions between China and India after Chinese troops were reported to have moved into the disputed Kashmir region.  Also, many people in India blame China for the COVID-19 pandemic and the lockdown they have been forced to live under since March.

What Did Google Say?

For Google, it appears to have simply been a matter of removing an app that potentially breached guidelines.

What Does This Mean For Your Business?

Clearly, there is a great deal of anti-Chinese feeling in India at the moment but it’s quite surprising anyway that an app that looks likely to have had a serious effect on competition and access to a large app market for companies simply because of their geographical base and/or origins was able to make it into Google’s Store in the first place.  Google itself is now facing criticism from some Indians for removing the app and, therefore, appearing to some to support China in the argument.  There is currently still a stand-off between the troops of both countries and the argument has also highlighted how many tech products and services used in India come from China, and how popular they are.  This is something that was also discovered by the US government in recent arguments relating to Huawei products. Global tech companies are now often finding themselves involved in global arguments.

Beware Fake Contact Tracer Messages

Just as you thought that cybercriminals had exploited every aspect of the pandemic with phishing, vishing, smishing and more, there are now warnings to beware of fake contact tracer messages.

Contact Tracing in the UK

Here in the UK, NHS contact tracers are now contacting those persons who are believed to have been in close contact with those who have tested positive for COVID-19.  The system works by those who test positive filling in a form (while they are well enough to do so) detailing where they have been plus when and who they have been in contact with.  From there, the NHS tracer contacts those who are believed to have been in close contact (via phone or text) and asks them to self-isolate for 14 days, the period by which symptoms of an infected person should have shown. Close contact is defined as face-to-face contact/close proximity for more than 15 minutes.

This contact tracing service has been put into place before the app, which is designed to automatically do the same thing but has not been released yet.

Scam Messages

The type of scam messages that have already been observed by many people was highlighted by Stuart Fuller, Chairman of Lewes Football Club.  On his Twitter page, Mr Fuller shared a screenshot of a text message from the fraudsters and warned that such messages are not genuine and that clicking on the link in the message would lead to a phishing page.

The screenshot showed a text message which had a recommendation for the recipient to self-isolate because they had been in contact with someone who had tested positive for or showed symptoms of COVID-19.  The message included a link to follow for the recipient to get more information.

How?

On his blog, ethical hacker Jake Davis highlights how the problem with the UK government using SMS during COVID-19 is that people are more vulnerable than ever to fake information and SMS messages can easily be made to look as though they come from the government.  In a blog post, Mr Davis says that making an SMS message appear to come from the government is as simple as inserting “UK_Gov” instead of some digits as the sender.

What Does This Mean For Your Business?

This and other similar types of smishing and phishing attacks are predicted to increase this year, and their success and prevalence is a sign of how vulnerable the COVID-19 outbreak it makes people feel, and how their search for and emotional reactions to information about health and financial matters are playing into the hands of criminals who are happy to exploit anyone.  Companies and organisations need to educate their staff about the threat, while businesses and individuals need to be vigilant and cautious about any unusual SMS messages or unsolicited phone calls, particularly those that offer rewards, create panic, warn of unpleasant consequences, or apply a feeling of pressure to act. Bear in mind that it is relatively easy to fake the source of a text message and although receiving such a message may at first be a shock, it is worth checking that the supposed government/NHS SMS is genuine before thinking about clicking on any links.

Featured Article – A Look at Cookies

Cookies perform functions and provide information that helps website users, businesses, publishers, and advertisers. This article looks at what cookies are, what they do, and the legislation that affects how they are used.

What Are Cookies?

Cookies are text files sent by the website you are on and stored on your browser as a record of your activity on the site. Although most websites use cookies, cookies do not harm devices and cookies do not tell websites who a user is or gather personal details about website visitors.

Current EU legislation states that all websites must let people know when cookies are in use. Website visitors should also be given the option to accept cookies or not and should be allowed to browse a website and experience the functionality even if they choose not to accept the cookies.

What Are Cookies For?

Cookies are supposed to help users to access a website more quickly and easily by telling a website that a visitor has been there before.  For example, cookies can store information that allows a repeat visitor to access a website without logging in, or fill in a form (autofill) without a person having to type all the details in. Cookies can also provide information to help with website shops, analytics and can help advertisers.

Types of Cookies

There are several different types of website cookies. These include:

– First-party cookies. These are set by the website and are used for analytics data gathering (for analytics tools) e.g. the number of visitors, page views, pages visited, and sessions. These cookies provide data to publishers and advertisers for ad targeting.

– Third-Party Cookies. These cookies are used when other, third-party elements e.g. chatbots or social plugins have been added to a website. These cookies, set by domains, can track users, and save data that can be used in ad targeting and behavioural advertising.

– Session cookies, as the name suggests, are temporary, short-lived and expire immediately or shortly after a user leaves a web browser. They are commonly used by e-commerce websites to remember the items have been placed in the shopping cart, to keep users logged in, and to record user sessions to help with analytics.

– Persistent Cookies. These cookies must have a built-in expiration date but can stay on a user’s browser for years (or until a user manually deletes them) in order to track a user and their interaction with a website over time.

– Secure Cookies. Websites with HTTPS set secure cookies. These cookies have encrypted data and are used on payment/checkout pages of e-commerce websites or online banking websites.

What Is The ‘Cookie Law’?

The so-called ‘cookie law’, which began life as an EU Directive, is privacy legislation that requires websites to ask visitors for consent to store or retrieve information on a computer, smartphone, or tablet.

The Cookie Law was widely adopted in 2011, became an update to the UK’s Privacy and Electronic Communications Regulations, and was designed to make people aware of how the information about them is collected online and to give them the opportunity to say yes or no to it.

The introduction of the General Data Protection Regulation (GDPR) in May 2018 with its focus on ensuring that businesses are transparent and protect individual privacy rights means that businesses must be able to prove clear and affirmative consent to process personal data and people must be able to opt-in rather than opt-out.  These aspects have clear implications for cookies.

GDPR Cookie Consent
GDPR requires consent to be gathered from data subjects and the Court Justice of the European Union rules state that this must consent must be explicit.  This means that a website’s users must be presented with a consent banner that is explicit and cannot have pre-checked boxes giving consent on categories of cookies except for those deemed strictly necessary.  Websites using cookies other than those that are strictly necessary for its basic function must present a method for obtaining the cookie consent of users prior to any collection or processing.

Website visitors must also be able to withdraw the consent that they have given before, in a way that is accessible, if they choose to. Also, the data controller must delete any personal data of individuals if that data is not necessary for the original stated purpose.

GDPR Cookie Compliance

One of the key ways in which a business can remain GDPR compliant is to make sure that it obtains prior consent if it provides service or collects personal data about persons in the EU. This means being very clear and explicit in describing the extent and purpose of the data processing in language that is easy-to-understand language to the user, before gathering any personal data from that user. Website users must be able to find out what type of personal data is being collected about them on a website at any time, and it should be easy for users to withdraw consent that has been previously given.

For this to happen, businesses and organisations need to know what kinds of cookies are used by their website and why. This information can be addressed in a cookie policy.

CCPA

For those businesses and organisations worldwide, that handle the personal information of any California residents, they will need to also ensure that their data processing (including cookie use) is compliant with the new California Consumer Privacy Act (CCPA).

A Cookie Policy

Companies and organisations are legally required under GDPR (and CCPA) to make a cookie policy available on their website to users. This cookie policy, which can be included as part of a website’s privacy policy, should be a declaration to users about what cookies are active on the website, what user data is being tracked by those cookies, for what purpose, and where in the world this data is sent.  This cookie policy must also give information about how users can opt-out of the cookies or change their settings regarding the cookies on the website.

Awareness and Challenges

Strengthening of data protection laws in recent years has, therefore, forced businesses to become very familiar with aspects of how they manage data in order to be legally compliant.  This has led to a much greater awareness of cookies and their use and for first-time visitors to a website, cookie consent is the first thing they encounter.

Also, changes that have led to many browsers blocking third party cookies have presented marketing and monetary challenges to publishers and advertisers.

Tech Tip – Stop Background Apps

If you have apps running in the background on Windows 10, they can use up more of your battery power and data.  Here’s an easy way to stop background apps from running:

Go to: Settings > Privacy > Background apps.

To stop all from running, toggle ‘Let apps run in the background’ to ‘Off’.

You also have the option of choosing which apps to run in the background by going down the list individually.

Internet Speed Record

Researchers from Australia’s Monash, Swinburne, and RMIT universities claim to have set a new Internet speed record of 44.2 Tbps.

Fibre Connection

The claim, which is featured in the ‘Nature Communications’ journal (https://www.nature.com/) refers to setting the bandwidth world record for ultra-dense optical data transmission over 75 km of standard optical fibre, with a single chip source.  It has been reported that the fibre connection was run between RMIT’s Melbourne City campus and Monash University’s Clayton campus in order to represent the infrastructure that is used by Australia’s National Broadband Network (NBN).

Micro-Comb

The exceptional speed and bandwidth achieved in the test, enough to download the contents of more than 50 100GB Ultra HD Blu-ray discs in one second, has been attributed not just to the capacity and capabilities of fibre, but also to the addition of micro-combs to the cable fibres.

Micro-combs are optical frequency combs based on micro-cavity resonators, and the researchers report that the ability to phase-lock, or mode-lock, these comb lines were key to breaking this speed record.

Micro-comb technology, therefore, appears to be a highly efficient way to transmit data and micro-combs offer the full potential of their bulk counterparts but in an integrated footprint.

Integrate With Existing Infrastructure

RMIT’s Professor Arnan Mitchell has been quoted as saying that the challenge will now be how to turn the micro-comb technology into something that can integrate with the existing cable infrastructure, and the that the long-term hope is to “create integrated photonic chips that could enable this sort of data rate to be achieved across existing optical fibre links with minimal cost”.

Data Centres First

Communications commentators have suggested that once the new technology is commercialised, data centres are most likely to benefit first from its introduction and that home and business users may have to wait years before they can use it, provided that it is affordable.

What Does This Mean For Your Business?

For communications infrastructure companies, this development means that they can augment the fibres that are already in the ground with this new micro-comb technology, thereby meaning that their existing networks are still good and scalable for the future.

This speed record and the new technology is also good news for the autonomous vehicles industry, gaming industry, medical fields, and other industries, segments, organisations, agencies and businesses that need greater speed and capacity to help them deal with increasing data demands

eBay Port Scanning Causes Alarm

Reports that eBay has been running port scans against the computers of visitors to the platform have caused alarm over potential security issues.

Port Scans

Port scanning is something that many people associate with cyber-attacks and penetration (‘pen’) testing.  Port scanning scripts are used to determine which ports a system may be listening via, by sending packets of information to a user’s machine and varying the destination port. This can help an attacker to determine what services may be running on the system and, therefore, get an idea of the operating system a target user has.

Port scanning can also be used to counter the activities of cybercriminals by scanning for remote-control access ports to detect any criminals that may be logged into a user’s computer in order to impersonate them on various platforms/sites e.g. to make fraudulent purchases.

eBay

In the recent observations of port scanning by eBay according to US-based security researcher Charlie Belmer and recorded on his nullsweep.com blog, Mr Belmer reported that eBay appeared to be looking for VNC services being run on the host (the same thing that was reported for bank sites).  The ports scanned by eBay are generally used for remote access and remote support tools e.g. Windows Remote Desktop, VNC, TeamViewer and others.

Mr Belmer has listed the 14 different ports he observed as being scanned by eBay and has concluded that the port scanning he observed being run from eBay was “clearly malicious behaviour and may fall on the wrong side of the law”.

Advice

On his blog, Mr Belmer urges anyone else who observes this port scanning behaviour to “complain to the institution performing the scans, and install extensions that attempt to block this kind of phenomenon in your browser, generally by preventing these types of scripts from loading in the first place”.

Maybe Just Fighting Fraud

Bearing in mind that there were reports 4 years ago of cybercriminals taking over users’ computers using TeamViewer to make fraudulent purchases on eBay, it may be very likely that the port scanning observed is simply part of eBay’s efforts to fight fraud by trying to detect if a compromised computer is being used to make fraudulent purchases on its platform.

What Does This Mean For Your Business?

Being an auction site, eBay clearly must take measures to ensure that fraudulent purchases cannot be made and to guard against and problems similar to those experienced with TeamViewer four years ago.  It is understandable, however, that a practice often associated with criminal activity and penetration testing may cause alarm among those familiar with the more technical aspects of Internet security. Although the matter has been reported by Mr Belmer on his blog, it is unclear yet what action or statements, if any, are likely to come from eBay.

Each week we bring you the latest tech news and tips that may relate to your business, re-written in an techy free style. 

Archives