Rainbow Six Siege fans, Operation Deep Freeze update (Y8S4) is delayed unfortunately

In the anticipated Operation Deep Freeze update for R6, a delay has been confirmed, earmarked for additional testing. This news leaves the release date for Year 8 Season 4 (Y8S4) currently up in the air, with no specific information on when further updates might bring new elements to the game.

Rainbow Six Siege maintains its robust presence in esports, and its frequent updates are crucial in keeping casual gamers’ interest alive. Introducing fresh changes to the game’s dynamics, especially after a considerable time since its launch, presents a unique challenge.

Although postponing Operation Deep Freeze might be disappointing for fans, prioritizing a flawless release is essential. Given the lack of detailed information in the latest announcement, it appears that the upcoming update might be addressing some significant issues. Players, therefore, may need to brace for a bit of a wait before they can dive into the new features.

R6 Operation Deep Freeze update details

The Operation Deep Freeze update was poised to bring fresh excitement to Rainbow Six Siege with the introduction of the new operator, Tubarão, and a new map named Lair. Given the substantial volume of new content, it’s conceivable that the complexity of integrating these elements contributed to the delay.

Particularly intriguing is Tubarão’s unique gadget, the Zoto canister, a throwable device that disperses a freezing compound. This innovative mechanic, while exciting, might have presented technical challenges necessitating further refinement.

This concept, despite the wait, holds promise. The potential for Tubarão to become a viable character in the game is significant, especially as Rainbow Six Siege continues its commitment to diverse and representative character options. The introduction of Tubarão and the Lair map are eagerly anticipated features that could enrich the gaming experience.

R6 Y8S4 release date, currently unknown…

The recent delay of Operation Deep Freeze in Rainbow Six Siege comes as a surprise, especially following the release of a teaser for the upcoming map, Lair, just last week. This development has piqued the curiosity of the gaming community.

Lair, with its seemingly straightforward interior layout, doesn’t immediately suggest the need for extensive tweaks. The map’s art design stands out with a captivating theme, and the reveal panel from a couple of weeks ago showcased some impressive lines of sight that players were looking forward to exploring.

Rainbow Six Siege DOWNLOAD

The unexpected postponement, therefore, raises questions about what specific aspects of the update required additional fine-tuning. Fans are left to wonder about the intricacies behind the scenes that led to this decision.

Will we ever watch Tom Hiddleston as Loki again, hear from himself

Loki’s journey within the Marvel Cinematic Universe has undeniably crafted a more intricate and compelling storyline than most of the Avengers’ adventures. This narrative thread has meandered through six films and a Disney+ TV series. However, in a recent interview, Tom Hiddleston dropped hints that his tenure as Loki might not be ending anytime soon.

Disney+ DOWNLOAD

In a conversation with BBC Radio 1‘s Ali Plumb after the conclusion of Loki season 2, Tom Hiddleston, who initially portrayed Loki in 2011’s Thor, reflected on the significance of the character in his career. When Plumb playfully asked Hiddleston if he’d contemplate returning to the role, Hiddleston replied with a quick and confident “Certainly.” He then intriguingly added, “In fact, I think I still am, in some way,” accompanied by a sly smile.

Hiddleston’s cryptic response suggests that he may not be ready to retire Loki’s iconic horned helmet just yet. With Marvel’s exploration of the multiverse, it leaves the door wide open for the possibility of encountering a different version of the Norse god in the not-so-distant future.

Tom Hiddleston, in discussing the important costume change for his character in Loki season 2, highlights a significant shift during the finale. As Loki bravely sacrifices himself for his allies, his standard TVA attire transforms, revealing a new costume more fitting of a deity, complete with an updated horned helmet.

Discussing the evolution of the costume, Hiddleston reflects on his collaboration with the costume director. “I talked with Christine Wada, our costume director, about it and it was actually our first fitting,” he shared. From the outset, they envisioned the character’s final look.

The actor then sheds light on the conceptual shift behind the new design. “It was kind of about being sort of monastic and humble,” he points out, drawing a distinction from Loki’s traditionally ornate, gold-adorned costumes.

Finally, Hiddleston underscores the deeper thematic resonance of the new attire. “This was about something more utilitarian and sort of [portraying] this lonely, solitary figure at the end of time,” he explains, suggesting an intentional focus on vulnerability in the character’s latest depiction.

Hiddleston improvised the season finale

In the aftermath of Loki’s season finale, a notable point of discussion has been Tom Hiddleston’s improvisation of his character’s concluding lines, echoing a memorable moment from the 2011 film Thor.

Hiddleston recalled the genesis of those lines. “It wasn’t written, I felt it,” he stated, acknowledging the significance of that moment in the production timeline.

The actor detailed the lead-up to the improvisation. “[Directors] Aaron Moorhead and Justin Benson turned to me and said ‘I think in about 30 minutes, we’re downstairs and it’s on you, before you go out there [for your final scene],’” he recounted. Aaron encouraged Hiddleston to ponder the character’s final words, offering him time to reflect.

During this period, Hiddleston ventured for a jog around the Pinewood Studios, with film scores accompanying him. It was Patrick Doyle’s music from Thor that sparked a pivotal recollection of a scene where Loki, fraught with emotion, tells his father, “I could’ve done it father, I could’ve done it. For you, for all of us,” before an apparent fatal fall.

“This evoked an idea,” Hiddleston added, sharing his epiphany with Aaron, Justin, and producer Kevin Wright: “Guys, I think I’ve got it. Here’s what he should say: ‘I know what I want. I know what kind of God I need to be. For you, for all of us.’”

Disney+ DOWNLOAD

Hiddleston concluded, recalling the directors’ affirming response to his suggestion: “And they opened their eyes and they went ‘Yes.’”

You can watch the full interview of BBC 1 Radio 1 below:


All images used in this post, including the featured image, are courtesy of Marvel Studios 2021.

Amazon Q AI, yet another chatbot, could save companies from bankrupt

Amazon Q AI, the latest innovation from AWS, has been unveiled by AWS CEO Adam Selipsky at AWS re:Invent. This revolutionary chat tool empowers businesses to seek tailored answers to their specific queries. Serving as an AI assistant, Amazon Q AI allows users to tap into their data for insights.

For instance, employees can leverage Amazon Q AI to inquire about the latest brand logo guidelines or decipher a fellow engineer’s code for app maintenance. Instead of laboriously sifting through numerous documents, Q AI efficiently surfaces the required information.

Amazon Shopping DOWNLOAD

Is Amazon Q AI available now?

Accessing Amazon Q AI is a breeze, as users can utilize it via the AWS Management Console, their company’s documentation pages, developer environments such as Slack, and various third-party applications. Selipsky made it clear that the questions posed on Amazon Q AI “will not be used to train any foundation models.”

Amazon Q AI seamlessly integrates with any of the models available on Amazon Bedrock, AWS’s repository of AI models, which encompasses Meta’s Llama 2 and Anthropic’s Claude 2, among others. Customers who frequently utilize Q AI have the flexibility to select the model that aligns best with their needs. They can establish a connection to the Bedrock API for the chosen model, utilize it to gain insights into their data, policies, and workflow, and subsequently deploy Amazon Q AI.

AWS has underlined that Amazon Q AI draws upon 17 years’ worth of AWS knowledge, making it a valuable resource for addressing AWS-specific queries. It excels in recommending the optimal AWS services for various projects.

Presently, Amazon Q AI is exclusively accessible to Amazon Connect users, AWS’s service tailored for contact centers. However, the company has plans to extend its availability to other services, such as Amazon Supply Chain, designed to facilitate supply chain management tracking, and Amazon QuickSight, a platform dedicated to business intelligence. Notably, Amazon Q AI for supply chain and business intelligence is currently available in preview.

In an interview with The Verge, Dilip Kumar, Vice President for AWS Applications, explained that each instance of Amazon Q AI on AWS services will exhibit unique characteristics. For instance, on Amazon Connect, Q AI operates in real-time and actively listens to customer calls, extracting essential information like account details. It then provides contact center agents with pertinent answers to inquiries, eliminating the need for agents to search for information themselves.

“We wanted to pair the technology with the services that make the most sense first, and for contact centers, supply chain, and business intelligence, AI is a natural fit,” Kumar stated.

Amazon Q AI offers a compelling solution for businesses seeking efficient and tailored responses to their queries. AWS CEO Adam Selipsky’s announcement at AWS re:Invent has shed light on the promising capabilities of Amazon Q AI. This chat tool, which integrates seamlessly with models on Amazon Bedrock, empowers users to harness the power of AI to gain insights into their data, policies, and workflows. It represents a significant leap forward in the quest for streamlined information retrieval, sparing employees from the arduous task of manual document searching.

Amazon Q AI’s deep knowledge, drawn from 17 years of AWS expertise, positions it as a valuable resource for addressing AWS-specific inquiries and recommending optimal AWS services. While currently exclusive to Amazon Connect, AWS’s contact center service, it is slated for expansion to other services like Amazon Supply Chain and Amazon QuickSight.

In terms of pricing, Amazon Q AI in Connect is competitively priced at a starting rate of $40 per agent per month, and users have the opportunity to try it “for no charge until March 1, 2024,” according to AWS’s Connect website. Selipsky has emphasized that Amazon Q AI prioritizes security, respecting the parameters set by customers to ensure that unauthorized personnel cannot access sensitive information.

It’s worth noting that other companies have also ventured into similar territory with products like Microsoft’s Copilot, Dropbox’s Dash, and Notion’s AI-powered notes search feature.

Amazon Shopping DOWNLOAD

As an additional announcement, AWS will offer Bedrock users the capability to implement guardrails around the models they use to build AI-powered applications. Currently in preview, these guardrails enable companies to enforce data privacy and responsible AI standards, a critical consideration for highly regulated industries like finance and healthcare. Furthermore, AWS plans to include the ability to redact personally identifiable information from customers’ end users as part of these guardrails, although this feature is not immediately available.

Tesla sues Swedish agency over licensing rights

Tesla took legal action against the Swedish transport agency. The lawsuit stems from what Tesla describes as a “discriminatory attack” following a strike that has hindered the process of issuing license plates for its new vehicles in Sweden. The strike, now extending over five weeks, sees Swedish Tesla employees advocating for collective bargaining rights.

The labor action, initiated by IF Metall, a prominent union with over 300,000 members across various Swedish industries, has sparked a series of sympathy strikes. These secondary strikes involve unions representing postal workers, dock workers, electricians, and painters, among others, showing solidarity with the Tesla workers’ cause.

Elon Musk, Tesla‘s chief executive, expressed his frustration, particularly with the secondary strike at PostNord, the postal service. He labeled the situation as “insane,” highlighting the direct impact of the strike on Tesla’s operations, particularly the delay in delivering license plates to newly manufactured Tesla cars.

Tesla sues Sweden, but why really?

In a notable legal confrontation, Tesla sues Sweden, alleging that the Swedish Transport Agency’s refusal to issue license plates for its new vehicles amounts to a discriminatory attack. Tesla’s lawsuit asserts that the agency’s actions are not only illegal but also unfairly targeted, with the decision to withhold license plates being influenced more by the ongoing labor dispute rather than any legal rationale.

Tesla DOWNLOAD

Tesla is pushing for a court ruling that would oblige the Transport Agency to provide license plates for its new vehicles. Additionally, the company is seeking compensation for the financial losses it has suffered as a result of these actions.

In response, the Swedish Transport Agency insists that its stance is both lawful and justified. The agency’s primary concern revolves around the safety implications of Tesla’s Autopilot driver-assistance system. Citing potential risks to road safety, the agency argues that a thorough investigation into the Autopilot system is essential before it can proceed with the issuance of license plates for Tesla models equipped with this technology.

What’s more?

The legal tussle involving Tesla and the Swedish Transport Agency extends its significance well beyond the confines of the automotive sector. This dispute casts a spotlight on the intricate balancing act between upholding labor rights and adhering to workplace safety regulations, especially when it comes to cutting-edge technologies like autonomous driving systems.

The resolution of this conflict could potentially pave the way for handling similar labor disputes in the future. Moreover, it could play a crucial role in shaping the regulatory framework governing the deployment and use of autonomous vehicle technologies.

Tesla DOWNLOAD

This situation underscores the importance of establishing clear guidelines and protocols that align technological advancements with labor welfare and public safety, ensuring a harmonious integration of innovation into societal structures.

Guess who is Starlink’s new competitor

Huawei has recently joined the elite group of companies venturing into the realm of low Earth orbit (LEO) satellite internet networks, a domain where SpaceX’s Starlink has been a prominent player. This development signals Huawei’s aspirations to potentially launch a satellite internet service, initially focusing on the Chinese market.

The Starlink system, recognized as the world’s most extensive LEO constellation, owes much of its growth to the frequent launches by SpaceX’s Falcon 9 rocket, a symbol of modern rocketry’s integration into daily life.

Huawei AppGallery DOWNLOAD

Huawei is preparing to compete with Starlink

In a significant step, Huawei‘s foray into this sector was unveiled through a Weibo post, showcasing presentation slides that highlighted the success of their LEO satellite test.

Notably, the test demonstrated remarkable download speeds, peaking at an astonishing 660 Mbps, surpassing Starlink’s maximum of 300 Mbps and its typical user experience of around 220 Mbps. This achievement marks a significant milestone in Huawei’s journey in satellite internet technology.

During the Aerospace Information Industry International Ecosystem Event in Chongqing, China, which took place earlier this month, Wang Jun, the chief scientist at Huawei’s 6G wireless technology laboratory, shared detailed insights into Huawei’s LEO satellite internet test. This presentation underscored the company’s commitment to integrating satellite connectivity into its technological ecosystem.

Huawei’s interest in satellite technology extends beyond just internet services. This is evident in the development of their smartphones, such as the Mate 60 Pro, which boasts the ability to connect with geostationary (GEO) satellites. This feature highlights Huawei’s innovative approach to enhancing mobile connectivity, blending traditional cellular capabilities with advanced satellite communication technologies. Such advancements position Huawei at the forefront of a new wave of integrated communication solutions, bridging terrestrial and extraterrestrial networks.

Satellite communication is marked by the distinct characteristics of geostationary (GEO) and low Earth orbit (LEO) satellites. GEO satellites, unlike their LEO counterparts, orbit at considerably higher altitudes.

This presents a unique set of challenges in the development of smartphones capable of connecting with them, given the typical size and design constraints of these devices. Furthermore, the high altitude at which GEO satellites operate often leads to limitations in connection speeds. This limitation is a key driver behind the push by companies like SpaceX to develop LEO satellite constellations, which promise enhanced connectivity.

Huawei AppGallery DOWNLOAD

LEO satellites offer several advantages over GEO satellites, including their smaller size, which leads to shorter manufacturing times and less complexity. These factors not only contribute to higher network speeds but also to environmental sustainability. In case of malfunctions, LEO satellites are designed to safely disintegrate in Earth’s atmosphere, minimizing space debris. This aspect of LEO satellites reflects a growing consideration for ecological impacts in the field of satellite technology, balancing technological advancement with environmental responsibility.

YouTube says not enough gaming platforms, unveils Playables

YouTube is now offering its Premium subscribers a unique gaming experience, we’ll check how to play games on YouTube below, but let’s talk about the details first.

Meet YouTube Playables

This feature, aptly named Playables, allows users to engage in a variety of online games directly through YouTube’s mobile and desktop apps. This innovative addition, initially trialed with a select group of users in September, has recently been announced to all Premium members.

The concept is simple yet revolutionary: 37 mini-games are embedded within YouTube itself, eliminating the need for separate downloads or installations.

The range of games offered under Playables is designed to appeal to a broad audience, featuring easy-to-play titles like Angry Birds Showdown, Brain Out, Daily Solitaire, and The Daily Crossword, along with several arcade classics. However, this gaming venture may be a temporary one. As per the notification sent to Premium users, these games are set to be available only until March 28th, 2024. For the moment, Premium subscribers can explore and enjoy the entire collection of games in the Playables section located under the Explore tab on YouTube.

YouTube’s venture into gaming with Playables places it among numerous tech giants who have ventured into the gaming sector, with varied degrees of success. This trend of diversification has seen tech companies, traditionally not associated with gaming, attempt to carve out a niche in this lucrative market. The path, however, has been fraught with challenges. A notable example is Google’s Stadia, a much-hyped project that ultimately met its demise in January. Similarly, Amazon recently scaled back its ambitions in gaming, cutting over 130 jobs in its free games division and shifting its focus.

The gaming endeavors of other tech firms have also had their ups and downs. TikTok, for instance, initially announced a significant push into gaming, only to have its parent company ByteDance lay off about 1,000 employees from its gaming unit. Despite these setbacks, other companies remain undeterred. Meta, for example, continues to invest in its Instant Games platform, a project that has been evolving for nearly seven years.

Recently, it introduced a new model allowing developers to beta test their games directly on Facebook. Netflix, too, has been actively releasing games, focusing exclusively on mobile platforms. While reviews are mixed, the streaming giant is ambitiously looking to branch out into cloud gaming, though it might be some time before these offerings become widely available.

This pattern of trial, error, and persistence reflects the tech industry’s recognition of gaming’s vast potential and its willingness to adapt and innovate in this dynamic field.

How to play games on YouTube?

Engaging with games on YouTube is now an exciting reality, thanks to the introduction of “Playables.” If you’re a YouTube Premium subscriber, you can easily access this feature. Here’s a simple guide on how to get started:

Accessing Playables on mobile devices:

  • Open the YouTube app on your iOS or Android device.
  • Navigate to the ‘You’ tab.
  • Tap the ‘Settings’ icon in the top right corner.
  • Select ‘Try new features’.
  • Enable the ‘Play games on YouTube’ option.

Accessing Playables on the web:

  • Visit www.youtube.com on your web browser.
  • Click your profile picture located in the top right corner.
  • Choose ‘Your Premium benefits’.
  • Here, you’ll find the option to enable ‘Play games on YouTube’.

Exploring the Playables:

  • On mobile, tap the ‘explore’ icon, scroll down, and select ‘Playables’.
  • On the web, click the hamburger icon on the top left to open the Explore menu, then find ‘Playables’.
  • A wide array of games will be displayed, ready for you to dive into.

List of available games on YouTube Playables

Enjoy a diverse selection of games including strategy, puzzles, sports, and more. Some of the highlights include:

  • State.io
  • Brain Out
  • 8 Ball Billiards Classic
  • Color Burst 3D
  • Stack Bounce
  • Daily Crossword
  • Daily Solitaire
  • Color Pixel Art
  • Carrom Clash
  • Cannon Balls 3D
  • Basketball FRVR
  • Angry Birds Showdown
  • Cube Tower
  • Crazy Caves
  • Scooter Extreme

YouTube’s foray into interactive gaming with “Playables” is part of a broader strategy where the platform often introduces experimental features to its Premium subscribers before making a final decision on their integration. This initiative is not just about appealing to the gaming community but more about enhancing the value of its subscription service.

With the recent increase in the cost of the Premium plan, along with similar price hikes by other streaming giants like Netflix and Apple, these additional features like Playables and the conversational AI tool for interactive video queries become crucial. They may not be the sole reason for users to opt for YouTube Premium, but they certainly add an enticing element that could sway those contemplating whether to maintain their subscriptions.

You might want to disable NameDrop on your iPhone, police warns

Following a recent update, the iPhone NameDrop warning has become a topic of concern among law enforcement agencies, prompting them to advise iPhone users to exercise caution.

Notably, the Middletown Division of Police in Ohio took to Facebook to alert parents about the potential risks associated with the NameDrop feature that’s part of the iOS 17 update. This move highlights the need for awareness and vigilance among iPhone users regarding new features and their implications for privacy and security.

iOS 17 DOWNLOAD

Where is NameDrop in iPhone settings?

The iPhone NameDrop warning concerns a feature that can be toggled on or off in the AirDrop settings. This function facilitates the effortless sharing of contact information between an iPhone or an Apple Watch simply by bringing the devices into close proximity.

Once the devices establish a connection, users have the option to either share their own information or receive details from the other device. Additionally, users can abort the transfer at any moment either by locking their phone or by moving the devices apart before the sharing process is complete, as explained by Apple.

The Middletown Division of Police took to Facebook, issuing an advisory specifically to parents. “PARENTS: Don’t forget to change these settings on your child’s phone to help keep them safe,” they cautioned in their post. This highlights the need for parents to be proactive in managing the settings on their children’s devices to ensure their safety.

Adding to the chorus of caution, the Oakland County Sheriff’s Office in Michigan also raised concerns about this feature. They pointed out that with the latest update, NameDrop is enabled by default, which might catch many users off guard.

The sheriff’s office noted, even though you can refuse to share your info, “many people do not check their settings and realize how their phone works.” This statement underlines a common oversight among users, emphasizing the importance of familiarizing oneself with new features and their default settings.

iOS 17 DOWNLOAD

How to disable NameDrop in iOS 17?

To disable the NameDrop feature in iOS 17, follow these straightforward steps:

  • Open the “Settings” app on your iPhone.
  • Scroll down and tap on “General” to access general settings.
  • In the General settings, find and click on “AirDrop.”
  • Look for the “‘Bringing Devices Together” option within the AirDrop settings.
  • Toggle this option to the off position to disable NameDrop.

By following these simple steps, you can easily turn off NameDrop, addressing concerns related to the iPhone NameDrop warning.

How to beat Persona 5 Tactica Quest 5?

Right from the outset, Persona 5 Tactica challenges players with its intricate quests, each serving as a crucible to test and refine their mastery of the game’s mechanics. Quest 5, aptly titled ‘Operation BOOM,’ epitomizes this challenge. Players are tasked with strategically employing explosive barrels to corral and defeat enemies.

The catch? The quest demands this be achieved within a mere three turns. Precision and strategic positioning of the Phantom Thieves become essential as players navigate through this demanding quest in Persona 5 Tactica, ensuring every action contributes to the ultimate goal of vanquishing all adversaries within the tight timeframe.

Persona 5 Tactica DOWNLOAD

Beating Persona 5 Tactica’s Operation BOOM (Quest 5)?

Mastering Persona 5 Tactica’s Quest 5, ‘Operation BOOM,’ hinges on cleverly leveraging multi-target attacks and environmental elements. Utilizing characters like Erina and Ryuji, who wield guns capable of hitting multiple targets, becomes a game-changer. For example, their shots can detonate nearby barrels, effectively repositioning enemies and potentially triggering the ‘one more’ action — a critical tactic given the limited number of turns.

Persona 5 Tactica Quest 5

For a successful strategy, Ryuji is indispensable. Start by moving him to the right, where he can shoot an explosive barrel surrounded by foes. This move not only scatters the enemies but also makes them more susceptible to subsequent attacks. Following this, position Erina on the left. Her task is to fire at a strategically placed barrel, causing an explosion that sets up another enemy for follow-up attacks. This move is timed perfectly for Morgana’s turn. Crucially, Erina’s chosen spot also offers her cover, protecting her from the aftermath of the blast. In this high-stakes mission of Persona 5 Tactica, every move and positioning is key to conquering ‘Operation BOOM.’

Continuing with the strategic maneuvers in Persona 5 Tactica’s Quest 5, ‘Operation BOOM,’ Morgana’s role becomes pivotal. Move Morgana to the left, close to an explosive barrel, and target the enemy exposed by Erina’s earlier attack. This action should activate the ‘one more’ opportunity. Utilize this to approach another Legionnaire, left vulnerable by Ryuji’s earlier maneuver, and secure an additional ‘one more.’ Then, strategically position Morgana as illustrated in the third image, making use of the ‘Triple Threat’ ability to eliminate multiple enemies simultaneously.

In the next phase, it’s crucial to reposition Ryuji. He should aim to hit the large Legionnaire, the exposed Legionnaire, and the barrel behind them in a single shot, as depicted in the first image. This tactic not only gains another ‘one more’ but also allows Ryuji to move near an explosive barrel and fire, targeting another hidden Legionnaire.

Persona 5 Tactica Quest 5

Morgana should then focus on the big Legionnaire to obtain ‘one more.’ Subsequently, switch control to Erina, moving her to strike the Legionnaire in cover near barrels with “Shining Partisan.” This positions everyone ideally for Mona to unleash “Triple Threat.”

Persona 5 Tactica DOWNLOAD

Following the enemy’s move, which results in the large Legionnaire inadvertently causing its own demise in an attempt to damage Ryuji, Erina should be poised to take down the final Legionnaire with “Great Partisan,” thereby concluding the battle in Persona 5 Tactica’s challenging Quest 5.

Dell, Lenovo, Microsoft… Fingerprint sensor vulnerabilities on leading laptops

In a recent investigation, a team from Blackwing Intelligence uncovered significant vulnerabilities in the fingerprint sensors of popular laptop models including the Dell Inspiron, Lenovo ThinkPad, and Microsoft Surface Pro X. This discovery was part of a project initiated by Microsoft’s Offensive Research and Security Engineering (MORSE), focusing on the integrity of widely used embedded fingerprint sensors in Windows Hello authentication systems.

The research effort, led by Blackwing’s Jesse D’Aguanno and Timo Teräs, concentrated on the embedded fingerprint sensors produced by ELAN, Synaptics, and Goodix. These sensors, integral to the security mechanisms of the Microsoft Surface Pro X, Lenovo ThinkPad T14, and Dell Inspiron 15, were found to have exploitable flaws, raising questions about the robustness of biometric security in these devices.

GAMER! PLAY WITH OPERA GX AND SAVE 80% MORE RAM

A FREE Gaming Browser that consumes 80% LESS RAM, Built-in FREE VPN, Twitch & Discord integrated and much more!

How researchers compromised these devices?

The fingerprint sensors in question, all being Match-on-Chip (MoC) varieties, are designed with their own microprocessor and storage. This design enables secure, internal fingerprint matching within the chip itself. However, a significant limitation emerged in this setup.

While MoC sensors effectively prevent the misuse of stored fingerprint data for authentication, they are not inherently designed to block a compromised sensor from imitating the communication patterns of a legitimate sensor. This flaw could result in false signals of successful user authentication or the replay of past interactions between the sensor and the host system.

In response to these potential vulnerabilities, Microsoft introduced the Secure Device Connection Protocol (SDCP). This protocol aimed to confirm the integrity and trustworthiness of the fingerprint device, as well as safeguard the data exchange between the fingerprint sensor and the host on these specific laptops.

Despite these measures, the researchers from Blackwing Intelligence managed to navigate around the Windows Hello authentication system on all three laptop models. They employed man-in-the-middle (MiTM) attacks, utilizing a custom setup involving a Raspberry Pi 4 running Linux. Their approach involved a mix of software and hardware reverse engineering, cracking cryptographic weaknesses in the Synaptics sensor’s custom TLS protocol, and deciphering and replicating proprietary communication protocols.

In the case of the Dell and Lenovo laptops, the security breach was accomplished through a method of identifying valid user IDs and substituting the attacker’s fingerprint for that of a legitimate Windows user. This was possible because the Synaptics sensor in these devices relied on a unique TLS stack for securing USB communication, rather than using Microsoft’s Secure Device Connection Protocol (SDCP).

For the Microsoft Surface device, which was equipped with an ELAN fingerprint sensor lacking SDCP safeguards, the situation was different. This sensor communicated in cleartext over USB and lacked authentication protocols. The researchers managed to imitate the fingerprint sensor by disconnecting the Surface’s Type Cover, which housed the sensor, and then sending valid login confirmations from this spoofed device.

The researchers pointed out a critical oversight in the implementation of security protocols by device manufacturers. “Microsoft did a good job designing SDCP to provide a secure channel between the host and biometric devices, but unfortunately device manufacturers seem to misunderstand some of the objectives,” they stated. They also highlighted a significant limitation of SDCP, noting, “Additionally, SDCP only covers a very narrow scope of a typical device’s operation, while most devices have a sizable attack surface exposed that is not covered by SDCP at all.” This statement underscores the gap between the design and implementation of security measures in these devices.

The investigation by Blackwing Intelligence revealed a critical oversight: the Secure Device Connection Protocol (SDCP), a key security feature, was not activated on two of the three laptops they examined. This finding led to a significant recommendation from the Blackwing team. They urged vendors of biometric authentication technologies to not only incorporate SDCP but also ensure it is actively enabled. The effectiveness of SDCP in deterring cyber attacks is nullified if it remains unused.

Avast DOWNLOAD

Reflecting on the broader context of biometric security, Microsoft had previously shared some enlightening statistics. Three years ago, the tech giant reported a notable shift in user behavior on Windows 10 devices. The proportion of users opting for Windows Hello biometric login over traditional passwords had surged to 84.7 percent, up from 69.4 percent in 2019. This marked increase underscores the growing reliance on biometric solutions for securing devices, making the findings of Blackwing Intelligence especially pertinent for both users and manufacturers.

Firefox 120 comes with convenient security features

Mozilla’s latest update, Firefox 120, is now available across all supported platforms. This new version brings a host of features including the option to copy links free of tracking parameters, comprehensive privacy controls that signal to websites your preference against data sharing, and a specialized cookie banner blocker for users in Germany. Additionally, it enhances the picture-in-picture functionality and introduces several other improvements.

Mozilla Firefox DOWNLOAD

What does Firefox 120 bring to the table?

Firefox 120 introduces a novel feature called “Copy Link Without Site Tracking” in its context menu, ensuring that links copied no longer carry tracking information. Enhancing user privacy, Firefox’s private windows and Enhanced Tracking Protection (ETP)-Strict mode now include Fingerprinting Protection for Canvas APIs.

In a move to streamline browsing experiences in Germany, Firefox has activated a Cookie Banner Blocker by default in private windows. This functionality automatically refuses cookies and dismisses intrusive cookie banners on supported sites. Additionally, for German users, Firefox now automatically removes non-essential URL query parameters, commonly used for user tracking, in private windows.

A significant privacy feature in Firefox 120 is the support for Global Privacy Control. Located in the Preferences → Privacy & Security section, this opt-in setting communicates to websites that the user prefers not to have their data shared or sold.

The update also sees Firefox importing TLS trust anchors, such as certificates, from the operating system root store. This feature, set as the default on Windows, macOS, and Android, can be deactivated in the settings if desired.

For improved credential management, keyboard shortcuts for editing and deleting selected credentials have been added to about:logins. Users on Ubuntu Linux can now import data from Chromium when both are installed as Snap packages.

Lastly, the Picture-in-Picture feature on Windows and Linux now supports corner snapping. This can be activated by holding the Ctrl key while moving the PiP window.

Mozilla Firefox DOWNLOAD

Firefox conveniently updates itself automatically between restarts, ensuring users always have the latest features and security enhancements. However, if you want to immediately access the newest update, you can manually initiate the process. Simply visit the ‘About’ section found in the main menu to force-install the latest version of Firefox. This ensures you’re up-to-date with all the new improvements and security measures introduced in Firefox 120.