Android

New GriftHorse Malware Infects More Than 10 Million Android Phones (therecord.media) 30

Security researchers have found a massive malware operation that has infected more than 10 million Android smartphones across more than 70 countries since at least November 2020 and is making millions of dollars for its operators on a monthly basis. The Record reports: Discovered by mobile security firm Zimperium, the new GriftHorse malware has been distributed via benign-looking apps uploaded on the official Google Play Store and on third-party Android app stores. If users install any of these malicious apps, GriftHorse starts peppering users with popups and notifications that offer various prizes and special offers. Users who tap on these notifications are redirected to an online page where they are asked to confirm their phone number in order to access the offer. But, in reality, users are subscribing themselves to premium SMS services that charge over $35 per month, money that are later redirected into the GriftHorse operators' pockets.

Zimperium researchers Aazim Yaswant & Nipun Gupta, who have been tracking the GriftHorse malware for months, described it as "one of the most widespread campaigns the zLabs threat research team has witnessed in 2021." Based on what they've seen until now, the researchers estimated that the GriftHorse gang is currently making between $1.5 million to $4 million per month from their scheme.

Windows

Microsoft Knew of Exchange Autodiscover Flaw Five Years Ago (theregister.com) 22

Thomas Claburn writes via The Register: Microsoft Exchange clients like Outlook have been supplying unprotected user credentials if you ask in a particular way since at least 2016. Though aware of this, Microsoft's advice continues to be that customers should communicate only with servers they trust. On August 10, 2016, Marco van Beek, managing director at UK-based IT consultancy Supporting Role, emailed the Microsoft Security Response Center to disclose an Autodiscover exploit that worked with multiple email clients, including Microsoft Outlook. "Basically, I have discovered that it is extremely easy to get access to Exchange (and therefore Active Directory) user passwords in plain text," he wrote. "It doesn't necessarily require any breach of corporate security, and at its most secure, is only as secure as file level access to the corporate website." His proof-of-concept exploit code, which affected Outlook (both Mac and PC), default email apps for Android and iOS, Apple Mail for Mac OS X, and others, consisted of 11 lines of PHP, though he insisted the exploit probably could have been reduced to three lines.

Microsoft acknowledged on August 11, 2016, that it had reproduced the issue in van Beek's report. Then on August 30, 2016, the Windows titan responded to van Beek by saying the report doesn't describe a genuine vulnerability: "Our security engineers and product team have reviewed this report and determined that it is not a security issue to be serviced as part of our monthly Patch Tuesday process. 'Never accept an SSL certificate without a matching host name' is already recommended for clients in the doc cited by your report: [link]. Before you send a request to a candidate, make sure it is trustworthy. Remember that you're sending the user's credentials, so it's important to make sure that you're only sharing them with a server you can trust. At a minimum, you should verify: That the endpoint is an HTTPS endpoint. Client applications should not authenticate or send data to a non-SSL endpoint. That the SSL certificate presented by the server is valid and from a trusted authority."

"This response casually forgets to consider that a hacked web server still retains a perfectly valid certificate -- it just happens to use that trusted tunnel to serve up problems," said van Beek. "Also, I have only found one Exchange client so far which actually checks the hostname against the certificate, which is Microsoft's own test tool." Van Beek said he thought it was incredible that Microsoft confirmed the behavior he reported within hours but does not consider it to be a problem. He suggested three mitigations: changing the order of operations so that DNS gets checked first; never accepting an SSL certificate without a matching host name; and reviewing why and when clients respond to authentication requests.
When asked if the company plans to take any steps to address credential exposure and whether it believes its guidance adequately addresses the problem, a Microsoft spokesperson said: "We are continuing to investigate the specific scenario shared by the researcher."
Chrome

Is 2021 The Year of the Linux Desktop? (pcmag.com) 192

"2021 Is the Year of Linux on the Desktop," writes PC Magazine. "No, really..." Walk into any school now, and you'll see millions of Linux machines. They're called Chromebooks. For a free project launched 30 years ago today by one man in his spare time, it's an amazing feat.... Linux found its real niche — not as a political statement about "free software," but as a practical way to enable capable, low-cost machines for millions...

Chrome OS and Android are both based on the Linux kernel. They don't have the extra GNU software that distributions like Ubuntu have, but they're descended from Linus Torvalds' original work. Chromebooks are the fastest growing segment of the traditional PC market, according to Canalys. IDC points out that Canalys' estimates of 12 million Chromebooks shipped in Q1 2021 are only a fraction of the 63 million notebooks sold that quarter, but once again, they're where the growth is. Much of that is driven by schools, where Chromebooks dominate now. Schoolkids don't generally need a million apps' worth of generic computing power. They need inexpensive, rugged ways to log into Google Classroom. Linux came to the rescue, enabling cheap, light, easy-to-manage PCs that don't have the Swiss Army Knife cruft of Windows or the premium price of Macs...

One great thing about open-source hacker projects is that they can be taken in unexpected directions. Linux isn't controlled, so it can adapt, Darwinian-style. It was a little scurrying mammal in the time of the dinosaurs, and then the mobile-computing asteroid hit. Linux could evolve. Windows couldn't. When you're building something that fits in your hand and has to sip battery, you can't just keep throwing processors and storage at it. Microsoft had a tough time adapting its monstrous megakernel OS to the new, tiny world. But *nix platforms thrive there: Android (based on Linux) and iOS.

"Android and Chrome water down the Linux philosophy," the article argues, "but they are Linux..."

Does this make any long-time geeks feel vindicated? In the original submission wiredog (Slashdot reader #43,288) looks back to 1995, remembering that "my first Linux was RedHat 2.0 in the beige box, running the 0.95(?) kernel and the F Virtual Window Manager...

"It came with 2 books, a CD, and a boot floppy disk."
Open Source

Linux For Apple Silicon Macs Gets Closer To Reality (substack.com) 53

"Asahi Linux for Apple M1 Macs is moving closer to reality," writes Slashdot reader TroysBucket.

An Asahi developer posted a detailed status update on Twitter. Linux enthusiast Bryan Lunduke offers this succinct summary:

- The Asahi Linux team has Linux (Debian, in this case) booting and usable with network support.

- They now have (very early) display drivers which "take full advantage of the display hardware."

- They have at least two base distributions — both Arch and Debian — working and functional (to some extent).

They also have, according to their latest update, "boot picker" support so that you can manually select which OS / Drive to boot from on the M1 Macs... I, for one, can't wait to see the first public, functional release of Asahi Linux — and will be following it extremely closely.

Windows

Microsoft Reportedly Broke Windows 11 By Injecting Ads (xda-developers.com) 147

Yesterday after releasing new Windows 11 builds in the Dev and Beta channels, Insiders reported that their Start Menu and taskbar were crashing. As it turned out, it was caused by Windows 11 delivering ads, as was reported by Daniel Aleksandersen, who dug into the issue. XDA Developers reports: First of all, Microsoft did publish a fix. [If your PC is in an unusable state and you're reading this in an effort to get out of it, the article includes a step-by-step guide to fix the problem.] The ad itself is for Microsoft Teams, and how it's integrated into Windows 11. As with most of the ads that are injected into Windows, this should still pop up as a notification even if you have all notifications turned off.

While we know the cause, the bigger question that Aleksandersen dives into is how the Windows 11 shell can be so fragile that ads can crash it. Windows in 2021 has a ton of components in it that have to grab content from the cloud at any given time, from the Bing lockscreen wallpaper to Windows Update to advertisements that come from Microsoft. It's pretty wild that when one of them isn't functioning correctly, this could happen. There are clearly two issues here. One is that a cloud service can break Windows 11. The other is that Microsoft is injecting ads into the OS in the first place, a sure pain point for many. One thing is for sure; Microsoft isn't going to scale back on its advertisements in Windows any time soon. Instead, it's just going to fix the glitch, and if that makes you draw a parallel to Office Space, that's fine too.

China

Chinese Hackers Behind July 2021 SolarWinds Zero-day Attacks (therecord.media) 13

In mid-July this year, Texas-based software provider SolarWinds released an emergency security update to patch a zero-day in its Serv-U file transferring technology that was being exploited in the wild. From a report: At the time, SolarWinds did not share any details about the attacks and only said that it learned of the bug from Microsoft's security team. In a blog post on Thursday, Microsoft revealed more details about the July attacks. The company said the zero-day was the work of a new threat actor the company was tracking as DEV-0322, which Microsoft described as "a group operating out of China, based on observed victimology, tactics, and procedures." Microsoft said the group targeted SolarWinds Serv-U servers "by connecting to the open SSH port and sending a malformed pre-auth connection request," which allowed DEV-0322 operators to run malicious code on the targeted system and take over vulnerable devices. The OS maker did not go into details about what the intruders did once they breached a target. It is unclear if the hackers were interested in cyber-espionage and intelligence collection or if DEV-0322 was a run-of-the-mill crypto-mining gang.
Windows

Windows 11 Won't Include Android App Support at Launch (theverge.com) 35

Microsoft won't ship support for Android apps on Windows 11 in time for the operating system's launch on October 5th. While Android apps running on Windows 11 is one of the big new features of the OS, Microsoft will only start previewing this feature in the coming months. From a report: "We look forward to continuing our journey to bring Android apps to Windows 11 and the Microsoft Store through our collaboration with Amazon and Intel; this will start with a preview for Windows Insiders over the coming months," says Aaron Woodman, general manager of Windows marketing at Microsoft.
Microsoft

Microsoft Won't Stop You From Installing Windows 11 on Older PCs (theverge.com) 89

Microsoft is announcing today that it won't block people from installing Windows 11 on most older PCs. While the software maker has recommended hardware requirements for Windows 11 -- which it's largely sticking to -- a restriction to install the OS will only be enforced when you try to upgrade from Windows 10 to Windows 11 through Windows Update. From a report: This means anyone with a PC with an older CPU that doesn't officially pass the upgrade test can still go ahead and download an ISO file of Windows 11 and install the OS manually. Microsoft announced its Windows 11 minimum hardware requirements in June, and made it clear that only Intel 8th Gen and beyond CPUs were officially supported. Microsoft now tells us that this install workaround is designed primarily for businesses to evaluate Windows 11, and that people can upgrade at their own risk as the company can't guarantee driver compatibility and overall system reliability. Microsoft won't be recommending or advertising this method of installing Windows 11 to consumers.
Operating Systems

Happy Birthday, Linux: From a Bedroom Project To Billions of Devices in 30 Years (theregister.com) 122

On August 25, 1991, Linus Torvalds, then a student at the University of Helsinki in Finland, sent a message to the comp.os.minix newsgroup soliciting feature suggestions for a free Unix-like operating system he was developing as a hobby. Thirty years later, that software, now known as Linux, is everywhere. From a report: It dominates the supercomputer world, with 100 per cent market share. According to Google, the Linux kernel is at the heart of more than three billion active devices running Android, the most-used operating system in the world. Linux also powers the vast majority of web-facing servers Netcraft surveyed. It is even used more than Microsoft Windows on Microsoft's own Azure cloud. And then there are the embedded electronics and Internet-of-Things spaces, and other areas.

Linux has failed to gain traction among mainstream desktop users, where it has a market share of about 2.38 per cent, or 3.59 per cent if you include ChromeOS, compared to Windows (73.04 per cent) and macOS (15.43 per cent). But the importance of Linux has more to do with the triumph of an idea: of free, open-source software. "It cannot be overstated how critical Linux is to today's internet ecosystem," Kees Cook, security and Linux kernel engineer at Google, told The Register via email. "Linux currently runs on everything from the smartphone we rely on everyday to the International Space Station. To rely on the internet is to rely on Linux." The next 30 years of Linux, Cook contends, will require the tech industry to work together on security and to provide more resources for maintenance and testing.

Android

Samsung Kills the Cameras On the Galaxy Z Fold 3 If You Unlock the Bootloader (xda-developers.com) 78

If you plan on unlocking the bootloader to root your Galaxy Z Flip 3 or Galaxy Z Fold 3 -- Samsung's two newest foldabes announced earlier this month, you should know that the Korean OEM will disable the cameras. Technically, this has only been confirmed for the Galaxy Z Fold 3, but the Galaxy Z Flip 3 likely has similar restrictions. XDA Developers reports: According to XDA Senior Members [...], the final confirmation screen during the bootloader unlock process on the Galaxy Z Fold 3 mentions that the operation will cause the camera to be disabled. Upon booting up with an unlocked bootloader, the stock camera app indeed fails to operate, and all camera-related functions cease to function, meaning that you can't use facial recognition either. Anything that uses any of the cameras will time out after a while and give errors or just remain dark, including third-party camera apps.

It is not clear why Samsung chose the way on which Sony walked in the past, but the actual problem lies in the fact that many will probably overlook the warning and unlock the bootloader without knowing about this new restriction. Re-locking the bootloader does make the camera work again, which indicates that it's more of a software-level obstacle. With root access, it could be possible to detect and modify the responsible parameters sent by the bootloader to the OS to bypass this restriction. However, according to ianmacd, Magisk in its default state isn't enough to circumvent the barrier.

Android

'Android Auto For Phone Screens' Is Shutting Down (9to5google.com) 22

An anonymous reader quotes a report from 9to5Google: Google's ambitions in the car led to Android Auto being redesigned a couple of years ago, mostly to positive feedback. However, the version of Android Auto on phone screens was meant to shut down at the time and has been on life support ever since. Now, that version has stopped working for some users. The aptly named "Android Auto for Phone Screens" was launched in 2019 as Google was forced to delay Google Assistant Driving Mode. That feature, which finally started rolling out in 2020, continued into earlier this year, and has expanded since, was supposed to replace the experience on phone screens. At the time, Google called this app a "stopgap" for users who needed an in-car experience but lacked a vehicle compatible with Android Auto.

In speaking with Google, we are able to confirm that Android Auto for Phone Screens is, indeed, shutting down with the release of Android 12. The experience will not be available for users on Android 12, but still on older versions of the OS. Google says that Assistant Driving Mode will be "the built-in mobile driving experience" on Android 12. Google's full statement follows: "Google Assistant driving mode is our next evolution of the mobile driving experience. For the people who use Android Auto in supported vehicles, that experience isn't going away. For those who use the on phone experience (Android Auto mobile app), they will be transitioned to Google Assistant driving mode. Starting with Android 12, Google Assistant driving mode will be the built-in mobile driving experience. We have no further details to share at this time."

Operating Systems

Google's Fuchsia OS Is Rolling Out Widely To 1st-Gen Nest Hubs (9to5google.com) 40

More owners of the first-generation Nest Hub are receiving the update to Google's Fuchsia operating system as it expands beyond the Preview program. 9to5Google reports: Back in May, Google formally released Fuchsia, its effort to develop a "not Linux" operating system from scratch, which has been years in the making. The first device to receive the new OS was Google's 2018 smart display, the Nest Hub -- not to be confused with the second generation Nest Hub with sleep tracking released earlier this year -- taking it permanently off of the existing Linux based "Cast OS" without negatively affecting the UI or experience. At the time, the rollout of Fuchsia was limited to a select few devices that were enrolled in the "Preview program" available to all devices via the Google Home app. Over time, the number of Nest Hubs running Fuchsia was expanded, with Google no doubt watching carefully for any issues with the upgrade.

Late last week, Google updated a support page to reflect that the Nest Hub has received a new firmware update for both the Preview program and all other devices. Specifically, the first-gen Nest Hub is now receiving firmware version 1.52.260996. Google confirmed to us that this update does indeed include the upgrade to Fuchsia. All goes well, this means in a matter of days, all first-gen Nest Hub devices in households around the world should be running Fuchsia.

Windows

Start11 Brings a Classic Start Menu Back To Windows 11 (theverge.com) 134

Stardock has a new app for Windows 11 that brings back the classic appearance of the Windows Start menu. The Verge reports: "This first beta is designed to regain some of the lost functionality in the current Windows 11 Start menu," says Brad Wardell, Stardock CEO. "We have a lot of exciting new features planned to make the Start menu not just more accessible but also more useful to companies and power users." Start11 includes a configuration UI that will support future Start menu designs, according to Stardock. While the previous Start10 app aimed to bring back the classic Windows 7 Start menu to Windows 10, Start11 will go further in future to add extra features to the Windows 11 Start menu. The Start11 beta is available today, priced at $4.99, and offers the choice between a Windows 7-style Start menu or a more modern one that brings back some of the classic style and features of the Start menu.
Google

The Galaxy Watch 4 Injects Samsung's Capable Hardware With Google Software (theverge.com) 25

Today, Samsung launched the Galaxy Watch 4 and Galaxy Watch 4 Classic -- two new wearables that are "the fruits of Samsung's smartwatch collaboration with Google," writes Becca Farsace via The Verge. From the report: The Watch 4 Classic starts at $349 for the Bluetooth model, rising to $399 for the LTE model, while the Watch 4 is a little less expensive with a starting price of $249 (or $299 with LTE). Both are available to preorder today, and ship August 27th. The big difference between the two models is that the Watch 4 Classic has one of those physical rotating bezels that we've liked so much on Samsung's previous smartwatches, while if you opt for the standard Watch 4, there's a touch-sensitive bezel accessible by swiping at the edges of the screen. The Watch 4 Classic is also made of a more premium stainless steel rather than the aluminum you'll find on the Watch 4. On the right of both watches are a pair of control buttons.

External differences aside, internally both watches share a lot of the same specs. They're both powered by the same 5nm Exynos W920 processor Samsung detailed yesterday, paired with 1.5GB of RAM and 16GB of storage. Battery capacity varies between sizes, but Samsung reckons you'll average around 40 hours of battery life regardless of model. There's LTE on select models, but if you were hoping for 5G, you'll be disappointed -- Samsung says it doesn't think it's worth it because the amount of data smartwatches process is too small.

But the biggest departure from Samsung's previous smartwatches is that the Watch 4 and Watch 4 Classic aren't running its own Tizen operating system. Instead, their software is the result of a collaboration between Samsung and Google, which was announced in May. Samsung is branding the watches' operating system as "Wear OS Powered by Samsung" although Google has called it Wear OS 3. But either way, the hope is that it combines the best of Tizen with the best of Wear OS. On Samsung's watches specifically, the interface you're looking at is One UI Watch, which is effectively Samsung's skin sitting on top of Wear OS. Think of it as Samsung's One UI software on phones, which works with Google's Android. It gives the Watch 4's interface a similar look and feel to Samsung's previous Tizen-powered watches. Google has promised its collaboration with Samsung will lead to a host of high-level benefits for Wear OS, like improved battery life, faster loading apps, and smoother animations.

Hardware

Wear OS Is Getting a Multi-Generational Leap In Power Thanks To Samsung (arstechnica.com) 37

An anonymous reader quotes a report from Ars Technica: Google is cooking up the first major Wear OS release since 2018, and Samsung is abandoning Tizen for smartwatches and going all-in on Wear OS with the Galaxy Watch 4. Last night, Samsung took the wraps off the main SoC for the Galaxy Watch 4, and compared to what Wear OS usually gets, Samsung is shipping a beast of an SoC. The "Samsung Exynos W920" will be a multi-generational leap in performance for Wear OS. Samsung says this is a 5 nm chip with two ARM Cortex A55 cores and an ARM Mali-G68 GPU. For the always-on display mode, there's an additional Cortex M55 CPU, which can keep the watch face ticking along while using minimal power. There's also an integrated LTE modem for on-the-go connectivity.

Compared to Samsung's previous smartwatch chip, the Tizen-only Exynos 9110 (10 nm, 2x Cortex A53), the company is promising "around 20 percent" better CPU performance and "ten times better graphics performance." Remember that the Exynos 9110 is from 2018, so those comparative numbers are inflated, but at 5 nm, this is a more modern chip than Wear OS has ever seen. Wear OS has suffered for years at the hands of Qualcomm, which has been starving the ecosystem of quality SoCs for wearables. Most people's last experience with Wear OS is the Snapdragon Wear 2100 or 3100 SoCs, both of which were ancient Cortex A7 CPUs built on a 28 nm process. Qualcomm introduced a slightly more modern chip, the Wear 4100 in 2020 (a Cortex A53-based, 12 nm chip), but almost no manufacturers actually shipped that chip a year later, and we're still getting Wear 3100 launches today. Qualcomm's answer to Samsung's chip will be the Wear 5100, which isn't due until 2022.
We should know more about Wear OS 3.0 tomorrow when Samsung holds its Aug. 11 "Unpacked" event. Not only are they expected to reveal the Galaxy Watch 4 and the big Wear OS revamp, but they're planning to launch at least two new foldable smartphones -- the Galaxy Z Fold 3 and Galaxy Z Flip 3.
HP

HP Announces New Detachable and All-in-One Chrome OS Computers (theverge.com) 19

HP is announcing two new Chrome OS computers for its consumer-focused lineup. From a report: The first is the Chromebase AiO, an all-in-one desktop computer with a screen that can rotate from landscape to portrait. The second is the Chromebook x2 11, a lightweight detachable that can easily shift from laptop to tablet modes. The company is also announcing a new Works With Chromebook-certified 24-inch USB-C monitor. All three new products are designed for students, families, and general consumers. The Chromebase AiO will be available at HP, Amazon, and Best Buy this month, while the Chromebook x2 11 will be available from Best Buy this month and from HP's website in October. Both computers start at $599.99 for base configurations. The M24fd USB-C monitor will be available in October from HP directly for $249.99.
Operating Systems

SteamVR Beta Lets You Arrange Desktop Windows Inside Your Virtual World (theverge.com) 8

As of its latest beta release, Valve's SteamVR software can add floating desktop windows inside VR games, letting you keep an eye on other apps without leaving VR. The Verge reports: It's a helpful addition, allowing players to keep an eye on anything from Discord, to a Twitch chat, or Netflix during a lower-intensity game. Road to VR suggests you could even watch YouTube during longer flights in Elite Dangerous.

The ability to interact with the rest of your desktop from within SteamVR's dashboard is not a new feature, but recently Valve has been making the system more flexible. Earlier this year it added the option to view individual application windows in the dashboard, and to be virtually attached to VR controllers ingame. This made apps viewable at a glance, but until now it lacked the ability to float windows persistently ingame. With the latest release, you can still opt to have a window attached to your controller, or pull it off to have it float in virtual space. The windows are view-only while you're actually playing a game, but you can open up the SteamVR menu to interact with them using a VR controller as a mouse pointer.

Android

Google Will Kill Off Very Old Versions of Android Next Month (arstechnica.com) 47

An anonymous reader quotes a report from Ars Technica: Google has started emailing users of very old Android devices to tell them it's time to say goodbye. Starting September 27, devices running Android 2.3.7 and lower will no longer be able to log in to Google services, effectively killing a big portion of the on-rails Android experience. As Google puts it in an official community post, "If you sign in to your device after September 27, you may get username or password errors when you try to use Google products and services like Gmail, YouTube, and Maps." Android is one of the most cloud-based operating systems ever. Especially in older versions, many included apps and services were tied to your Google login, and if that stops working, a large chunk of your phone is bricked. While Android can update many core components without shipping a full system update today, Android 2.3.7 Gingerbread, released around 10 years ago, was not so modular.

The individual Google apps started to be updatable through the Android Market/Play Store, but signing in to Google was still a system-level service and is frozen in time. Any Google services wanting to allow sign-ins from those versions would have to conform to 2011-era security standards, which means turning off two-factor authentication and enabling a special "allow less-secure access" setting in your Google account. Really, these old Android versions have to die eventually because they're just too insecure. Google shows active user base breakdowns for Android versions in Android Studio, and Gingerbread has such a low device count that it doesn't even make the list. It's less than 0.2 percent of active devices, behind 14 other versions of Android. Users of these old devices could still sideload a third-party app store and find replacements for all the Google apps, but if you're a technical user and can't get a new device, there's a good chance you could load a whole new operating system with an aftermarket Android ROM. After September 27, the oldest version of Android you'll be able to sign in to is Android 3.0 Honeycomb, which is only for tablets.

Government

The Case for Another Antitrust Action Against Microsoft (theatlantic.com) 209

"Since its own brush with antitrust regulation decades ago, Microsoft has slipped past significant scrutiny," argues a new article from The Atlantic.

But it also asks if there's now a case for another antitrust action — or if we're convinced instead that "The company is reluctantly guilty of the sin of bigness, yes, but it is benevolent, don't you see? Reformed, even! No need to cast your pen over here!" Right now, it's not illegal to be big. It's not illegal to be really big. In fact, it's not even illegal to be a monopoly. Current antitrust law allows for the possibility that you might be the sole player in your industry because you're just that well managed and your product is just that good, or it's just cost-prohibitive for any other company to compete with you. Think power utilities, such as Duke Energy, or the TV and internet giant Comcast. Antitrust law comes into play only if you use your monopoly to suppress competition or to charge unfairly high prices. (If this feels like a legal tautology, it sort of is: Who's to know what's a fair price if there isn't any competition? Nevertheless, here we are...) Yet if bigness alone is enough to draw scrutiny, Microsoft must draw it. Courts have disagreed on what size market share a product or company must own to be considered a monopoly, but the historical benchmark is about 75 percent. Estimates vary as to what percentage of computers run Microsoft's Windows operating system, but Gartner research puts it as high as 83 percent...

Biden, Khan, Senator Amy Klobuchar, and others are asking whether consumers suffer any nonfinancial harm from this lack of competition. Is switching from Windows to Apple's Mac OS unnecessarily hard? Is Windows as good a product as it would be if it faced more robust competition? When Windows has major security flaws, for example, billions of customers and companies are impacted, because of its market share. If we're wondering whether crappy airline experiences are a competition problem, should the same question apply to crappy computer security? In fact, in areas where Microsoft faces strong competition, it's reverting to some of the behaviors that got it sued in the '90s — namely, bundling. Microsoft and Amazon are essentially a duopoly when it comes to cloud services... Microsoft offers its big business customers an "integrated ecosystem" of Windows, Office, and its back-end cloud services; some analysts even point to this as a reason to keep buying Microsoft stock. That's just smart business, right? Yes, unless you're at a disadvantage by not taking the bundle. Some customers have complained that Microsoft charges extra for some Windows licenses if you're not using its cloud-computing business, Azure...

Microsoft does much more that we're happy to call "evil" when other companies are involved. It defied its own workers in favor of contracts with the Department of Defense; it's been quietly doing lots of business with China for decades, including letting Beijing censor results on its Bing search engine and developing AI that critics say can be used for surveillance and repression; it reportedly tried to sell facial-recognition technology to the DEA.

So why does none of it stick? Well, partly because it's possible that Microsoft isn't actually doing anything wrong, from a legal perspective. Yet it's so big and so dominant and owns so much expensive physical infrastructure that hardly any company can compete with it. Is that illegal? Should it be?

It's now the world's second largest tech company by market valuation — over $2 trillion and even ahead of Google, Amazon, Facebook, and Tesla (and behind only Apple). For the three months ended in June, Microsoft's net income rose 47% over the same period a year ago, according to TechCrunch, with a revenue for just those three months of $46.2 billion.

The Atlantic argues Microsoft has successfully rebranded itself as nice and a little boring, while playing up the fact that it lost a decade in consumer markets like smartphones because it was distracted by its last antitrust lawsuit. Yet meanwhile it's acquired major tech brands like LinkedIn, Minecraft, Skype, and even attempted to buy TikTok, Pinterest, and Discord (as well as "almost two dozen game-development studios to beef up its Xbox offerings"). And of course, GitHub.
Android

Google's Wear OS 3 Update Plans Will Leave Most Existing Devices Behind (arstechnica.com) 15

In a post titled "What Wear OS 3 means for you," Google provides a few more details about its upcoming Wear OS update plans, which will be the first major Wear OS update since Wear OS 2 in 2018. Unfortunately, as Ars Technica points out, the list of devices receiving the new update are limited to some of Mobvoi's TicWatch devices and Fossil Group's new generation of devices launching later this year. Older Wear OS devices featuring the Wear 3100 SoC, which makes up almost all the current Wear OS devices, will not support the new update. From the report: We still have next to no information about Wear OS 3, but there are a few tidbits in the upgrade announcement indicating that things will be very different. One line in the announcement lays out the requirement for a mandatory factory reset for any Wear 4100 devices upgrading from Wear OS 2 to version 3. Wear OS 3 is apparently so different that user data can't be ported over, and all local data will need to be wiped. We've certainly heard Google and Samsung talk about how Wear OS 3 will combine the "best of Wear OS and Tizen," indicating that even the base OS might be rebuilt.

Google also vaguely tells 4100 upgraders that "in some limited cases, the user experience will also be impacted." Is this a reference to the 4100 performance or the app selection and features compared to Wear OS 2? It's hard to say. Because Wear OS 3 will be so different, Google says it won't force the upgrade on 4100 users: "We expect that for these reasons, some of you will prefer to keep your current Wear OS experience. Therefore, we will offer the system upgrade on an opt-in basis for eligible devices. We will provide more details in advance of the update so you can make an informed decision. We expect our partners to be able to roll out the system update starting in mid to second half of 2022."

The Samsung Watch with Wear OS 3 is expected to ship sometime in August 2021, so the partner time of "2H 2022" -- potentially a year after Samsung's release -- is surprisingly late. Android has typically been very good at letting partners get early access to code, so (at least the ones that care) can be ready for launch, but this suggests Samsung is getting a huge head start. Google's message that upcoming Fossil watches, launching later this year, will be "eligible for upgrade" to Wear OS 3 also suggests that we might see Wear OS 2 devices launch from other companies after Samsung launches Wear OS 3 next month.

Slashdot Top Deals