Going to space is hard, but it’s even harder when the program is struggling like this.
512 Pixels
Google+ Shutting Down After Data-Exposing Bug Disclosed ⇢
A security bug allowed third-party developers to access Google+ user profile data since 2015 until Google discovered and patched it in March, but decided not to inform the world. When a user gave permission to an app to access their public profile data, the bug also let those developers pull their and their friends’ non-public profile fields. Indeed, 496,951 users’ full names, email addresses, birth dates, gender, profile photos, places lived, occupation and relationship status were potentially exposed, though Google says it has no evidence the data was misused by the 438 apps that could have had access.
Google should have disclosed this when the bug was patched in March, the company didn’t do that, because it didn’t want to draw comparisons to Facebook, according to an internal memo, shared by The Wall Street Journal:
The document shows Google officials knew that disclosure could have serious ramifications. Revealing the incident would likely result “in us coming into the spotlight alongside or even instead of Facebook despite having stayed under the radar throughout the Cambridge Analytica scandal,” the memo said. It “almost guarantees Sundar will testify before Congress.”
I bet that last line is true here before long.
iOS 12.0.1 ⇢
John Voorhees, writing at MacStories, has the details.
Kbase Article of the Week: PowerBook G4 (12-inch 1.5GHz), PowerBook G4 (15-inch 1.67/1.5GHz), PowerBook G4 (17-inch 1.67GHz): Installing individual applications from iLife ‘05 ⇢
The title is almost as long as the document itself:
iLife 05 is preinstalled on PowerBook G4 (12-inch 1.5GHz), PowerBook G4 (15-inch 1.67/1.5GHz), and PowerBook G4 (17-inch 1.67GHz) computers. However, if you ever need to reinstall certain applications from iLife 05, you can do so. When you go through the installer, you may not be able to select an individual application. (When you try to select just one application, all the applications are checked.) Simply uncheck the applications that you do not want to install.
Liftoff #82: Hubble Trouble ⇢
This week, on Relay FM’s best space podcast:
Jason and Stephen discuss the latest Commercial Crew dates, and emerging issues with the Hubble Space Telescope, as well as exomoons and Jason’s view of the latest SpaceX launch.
Next time, we’ll be detailing Apollo 7 to honor its upcoming 50th anniversary. Don’t miss it.
My thanks to our sponsors this week:
- Squarespace: Make your next move. Enter offer code LIFTOFF at checkout to get 10% off your first purchase.
- RXBAR: Whole food protein bars with simple, real ingredients. Get 25% off with promo code ‘liftoff’.
Facebook Portal ⇢
Jacob Kastrenakes at The Verge:
As Facebook works to contain the fallout from its biggest-ever data breach, the company is introducing a product that will bring a camera and microphone into your living room. Facebook Portal, and the larger Portal Plus, are smart displays that are laser-focused on video chatting.
The first hardware products marketed under the Facebook brand, the Portals can be used to call other Portal users, or anyone who has Facebook or Facebook Messenger. The Portals can play music through Spotify and Pandora, or stream video from Facebook Watch, but these are intentionally limited devices. For better and for worse, you can’t even browse Facebook.
Nope, nope, nope.
Apple to Congress: No Signs of Hack ⇢
This story keeps getting weirder and weirder.
Daniel Jalkut’s Dark Mode Series ⇢
Daniel is a world-class macOS software engineer,1 and I’m looking forward to learning more about Mojave’s new Dark Mode and how it works in this series.
Apple Fires Back ⇢
Apple PR has responded to this Bloomberg report that says Amazon, Apple and others used servers that were compromised — at the hardware level — by China. Here’s a bit from a pretty unusual press release on Apple’s Newsroom site:
The October 8, 2018 issue of Bloomberg Businessweek incorrectly reports that Apple found “malicious chips” in servers on its network in 2015. As Apple has repeatedly explained to Bloomberg reporters and editors over the past 12 months, there is no truth to these claims.
Apple goes on to share the statement it made to the publication. The company is clearly saying this article is inaccurate, at least when it comes to their server infrastructure:
On this we can be very clear: Apple has never found malicious chips, “hardware manipulations” or vulnerabilities purposely planted in any server. Apple never had any contact with the FBI or any other agency about such an incident. We are not aware of any investigation by the FBI, nor are our contacts in law enforcement.
In response to Bloomberg’s latest version of the narrative, we present the following facts: Siri and Topsy never shared servers; Siri has never been deployed on servers sold to us by Super Micro; and Topsy data was limited to approximately 2,000 Super Micro servers, not 7,000. None of those servers have ever been found to hold malicious chips.
Connected #212: NanoHippo ⇢
This week, on a pretty wacky episode of the podcast:
Stephen answered Myke’s PopSocket challenge, and Federico attempts to name all of iOS 12.1’s new emoji.
My thanks to our sponsors:
Apple Watch Faces are a Mess ⇢
Philips Hue App Adds Siri Shortcut Support ⇢
John Voorhees, writing at MacStories:
The Hue app received a major update earlier this year, which significantly improved the creation of scenes. Users can pick from pre-built scenes created by designers to evoke a particular mood or create their own using photos or a color picker to control the color and brightness of a group of Hue bulbs.
With the new Siri Shortcut support, those scenes can be triggered using Siri and incorporated as actions in custom shortcuts using Apple’s Shortcuts app.
I am really excited to play with this.