The Latest

We may earn a commission from links on this page.

I always feel tougher after running in the summer heat—until I look at my Garmin Forerunner and see it thinks my fitness has suddenly gotten worse. If you, too, watch your Garmin VO2max number slide down as the temperatures climb, you're not imagining it, and you're definitely not alone. Every summer, comment sections and Reddit threads fill up with people convinced their fitness is falling apart, or their expensive watch is broken, or generally panicking about a stat that's supposed to reflect their aerobic capacity. But there’s no need to panic. Your fitness almost certainly isn't going anywhere. What's actually happening is that your body is adapting to heat, and Garmin's algorithm is struggling to separate "hot weather effort" from "declining fitness."

Why it looks like your VO2max drops during the summer

VO2max estimates are built from your pace, heart rate, and effort during a run. In hot weather, your heart rate rises faster and stays higher for the same pace, because your body is diverting blood flow to your skin to help you cool down, and you're likely sweating more and dealing with some degree of dehydration. To Garmin's algorithm, a higher heart rate at a given pace looks like reduced efficiency, which it interprets as lower fitness. In reality, you're doing the same physical work; your cardiovascular system is just working harder to keep you cool at the same time.

This is why every year, so many runners see their VO2max estimate creep down every summer, only to bounce back once the weather cools off in the fall.

Some Garmin watches account for the heat

Newer Garmin models, including the Forerunner 970, do attempt to factor heat (and humidity) into the VO2max calculation, adjusting the estimate to account for the extra cardiovascular strain. Of the Forerunners, the 745, 945, 955, and 965 all have heat acclimation, along with the 245 and 255 with software updates. And if Garmin's numbering system confuses you, my colleague Beth Skwarecki has got you covered.

If you have one of these newer devices, you may notice the swings are less dramatic than what older models produce. Older Garmins generally don't make this adjustment, which is a big part of why the phenomenon is so widely discussed among long-time Garmin users.

How to fix your VO2max trend

If you understand what's happening and you're fine ignoring the number for a few months, that's my recommendation. Your training is still working, whatever Garmin’s algorithm seems to suggest. But if you'd rather stop the swings altogether, you do have a few practical options.

The most direct fix is to change your activity profile settings so that specific activities don't contribute to VO2 max at all. In the Garmin Connect app, you can go into an activity profile and turn off VO2max calculation for it entirely. A popular approach here is to let your road running profile keep contributing to VO2max, since road paces tend to be more consistent and comparable, while turning it off for trail running, where elevation, terrain, and effort variability already make VO2 max less reliable.

You can even take this a step further by creating a dedicated "hot run" activity profile. Simply copy your existing Run profile, rename it something like "Hot Run," and disable VO2max calculation on that copy. Then, on brutally hot or humid days, switch to that profile before you head out. Your run still gets logged normally with pace, heart rate, and all your usual data, but now it won't skew your overall VO2max trend.

Finally, if you really want to keep your VO2 max estimate clean and consistent year-round, you might have to stick to a treadmill in an air-conditioned gym. Controlled temperature and humidity mean your heart rate response will better reflect your actual fitness rather than heat strain, giving you a more stable number to track over time. However, in pursuit of a perfect number, you'll be sacrificing all the mental and physical gains that come from training in the heat. Don't let your VO2max cause you to lose the plot here.

The bottom line

A dropping VO2 max number in the summer is one of the most common false alarms in the running world. It's always troubling to see a fitness score drop, especially for Garmin fanatics like myself. But during the summer, your body is spending energy adapting to the heat, which is its own form of fitness. Whether you decide to ignore the dip, tweak your activity settings, or move your key efforts indoors, the most important thing is not to let a single algorithm-generated number convince you that months of hard training have suddenly vanished.


from Lifehacker https://ift.tt/lg8fYTh

As one of the biggest tech companies in the world, Google is putting its AI features and platforms into each and every one of its products. As such, it’s no surprise that its wildly popular navigation app, Google Maps, is getting the same treatment. While it's easy to use the app without encountering much AI, if you so choose, you can use Google’s latest AI features to find new restaurants, accommodations, or hot spots in your area. And now, Google is boasting that it is launching new "agentic" features that will even allow the app to order food for you—sort of.

Ask Maps gets an agentic upgrade

Back in March, the company rolled out “Ask Maps,” a chatbot-like interface in Google Maps that taps into Gemini to help you find relevant places on the map. For example, Google says you can “Ask Maps” to find you a restaurant with availability for six at a specific date and time, keeping in mind strict dietary requirements. It’s about what you’d expect from the combination of Gemini and Google Maps: You “chat” with the map to find what you need. 

Now, Google is expanding on these features, introducing new agentic options to reduce the work you actually have to do to pick up lunch (if not by all that much). Starting today, Google says Ask Maps can handle “complex, multi-step tasks," including functions it can handle on your behalf, and the flagship feature is ordering food for you—or, at least, starting an order.

Ask Maps can't actually order food for you

Google says you can launch Ask Maps and type something like “order spicy pad kee mao with seafood for me to pick up on my way home." While you might think such a feature would handle the entire request for you, Ask Maps doesn't quite get there. It will, according to Google, look for open restaurants on your route home, and it can even take into consideration your previous orders and dietary needs. But once it floats options, you still need to choose the restaurant you want to order from. Once you do, the agentic features kick in: Google says that Ask Maps will remember your original request and will begin adding the appropriate items to your cart through services like Square and Toast (with Uber Eats support coming soon). However, Ask Maps won't actually order the food for you. You still need to manually review what's been placed in your cart and approve the order before the restaurant will receive it.

Other agentic features in Ask Maps

As part of this Ask Maps update, you can also ask about hotels and local events. Google suggests asking the feature something like “For next week’s conference in downtown Miami, find me a decently priced, top-rated hotel with an artsy vibe, within walking distance from a gym and restaurants.” That's certainly a complex request, and, according to Google, Ask Maps will be able to compare prices and availability to find an appropriate hotel. The same goes for things like concerts and comedy shows: Ask Maps will surface results based on your request, but you'll need to click through to actually buy tickets yourself.

This isn't yet the agentic future we were promised

I don't have these options on my Google Maps app yet, so I can't personally attest to how well they work, but I'm not sure I'm seeing the vision here. Companies like Google have been promising that agentic features will save us time and rescue us from having to perform tedious or menial tasks. And while this feature does save the 30 seconds or so it takes to building a restaurant order, that's about all it does. Not only do you still have to intervene in multiple aspects of the process (including the actual ordering of the food), it seems like the whole ordeal takes longer than it should. In my view, heading to the restaurant's site, building the order myself, then placing the order (as I'd have to do anyway) is likely more efficient than asking Google's AI to find a restaurant with a specific dish, have it build the order, then have me review it.

Maybe I'll feel differently once I can try it out, and maybe this is just one step into a future where you really can have Google Maps complete a whole order for you. But I'm not sure I'd ever want it to, especially when dealing with ordering multiple items for various people with potential dietary restrictions. Not only would it likely be faster to do it myself, but I'm not sure I'd trust an AI with all those complications. The last thing anyone needs is for an AI to hallucinate and forget to order something with an allergy label.

Other new Ask Maps features

This update also incorporates Google's "Personal Intelligence," which pulls info from your various Google apps to return more personalized results. As such, you could Ask Maps to find you things to do before your afternoon flight. Google Maps should be able to access Gmail and Google Calendar, where it should find that flight's time and location, in order to fulfill your request with more individualized results than a simple search would. This feature is off by default.

There's also a new live data widget for transit instructions, so you can keep tabs on public transit information in real time. You can also suggest Google Maps edits conversationally through Ask Maps, including adding photo attachments.


from Lifehacker https://ift.tt/AOndEhW

If you use iCloud Private Relay, Apple's paid IP address masking service, your internet browsing activity may not actually be private. As 404 Media reports, flaws in Apple’s web browser engine allow IP addresses to be revealed, either maliciously or incidentally, even when they're supposed to be hidden.

How Private Relay is exposing IP addresses

iCloud Private Relay, which is part of Apple's iCloud+ subscription, is supposed to keep both who you are and what sites you visit hidden when you are browsing in Safari. Without it, your network provider and the websites you view can see your IP address and DNS records, which can be used to track your location and browsing history over time. Private Relay is supposed to encrypt DNS records and generate a temporary IP address, keeping any single party, including Apple, from obtaining both.

The issue, discovered by security researchers Talal Haj Bakry and Tommy Mysk, is related to how passkeys work. Web requests are made outside of the browser and the protections of Private Relay, meaning that websites that support passkeys can see users' real IP addresses. Obviously, this impacts Safari traffic, but researchers found the issue in Onion Browser, an iOS app that encrypts traffic through the Tor network. Both 404 Media and TechCrunch verified the issue in their own tests.

The researchers stated that they informed Apple but haven't been given a timeline for when the vulnerability will be addressed. Apple is generally pretty good on privacy issues, but this isn't the first to arise in recent months. In July, "Hide My Email," the company's email masking service, was revealed to have a vulnerability that actually exposed users' real email addresses. Apple reportedly knew about it for over a year and claimed to have patched it—but it hadn't.

While Private Relay can be a useful privacy tool—if it works as intended—it's not a true VPN (Virtual Private Network) because it only provides protection when browsing in Safari. If you want to keep your IP address hidden and your data encrypted across all apps and browsers on your device, you may want to consider a separate VPN service.


from Lifehacker https://ift.tt/CpL0ynr

We may earn a commission from links on this page.

As much as Hollywood has been wringing its hands over franchise fatigue, consider this: In July, a Spider-Man movie made $168 million at the box office in one day, and the top streaming series was a Game of Thrones spinoff.

Fortunately, if you are hungering for something original, you can still catch innovative comedy series like The Bear and Widow's Bay, or tense thrillers like FROM and Cape Fear (well, OK, that last one is a remake of a 1990 Martin Scorsese movie that was a remake of a 1962 Gregory Peck movie that was an adaptation of a book, but the point stands). Here are all of July's most-watched series, according to data from streaming information repository JustWatch.


House of the Dragon

Seems we still aren't sick of dragons and incomprehensible political intrigue: The third season of House of the Dragon, the Game of Thrones prequel based on a fake history tome by George R.R. Martin, came roaring back to the top of the streaming charts. With the season finale landing this weekend, fantasy fans will have to wait until the arrival of season two of A Knight of the Seven Kingdoms for their next Westeros fix. You can stream House of the Dragon on HBO Max.

Silo

Another book adaptation returning for a third season, Apple TV's Silo continues to track the downward spiral of the dregs of humanity, living together underground in a cavernous edifice that goes all the way down. If you've been wondering how things got so bad, this season goes back in time to reveal the source of humanity's downfall. (Unsurprisingly, humans are to blame.) You can stream Silo on Apple TV.

The Bear

Across four seasons, we've watched neurotic chef Carmy (Jeremy Allen White) flame out as an elite chef, return to his humble beginnings in his family's Chicago sandwich shop, try to turn said sandwich shop into a fine dining establishment, experience ups and downs in his business and personal life, and finally, at the end of season four, quit the food industry altogether. Taking place mostly over the course of a single day, the fifth and final season explores the immediate aftermath of that monumental decision—on Carmy, and the rest of the restaurant's partners and kitchen staff. It's a fitting goodbye for one of the most lauded TV series ever. You can stream the final season of The Bear on Hulu.

Widow's Bay

This series from Apple TV has won nearly unanimous praise from both critics and audiences. It's a rare horror-comedy that manages to be genuinely scary and really funny. In the island town of Widow's Bay, literally everything is haunted, cursed, and otherwise beset with unspeakable evil, but Mayor Tom Loftis (Matthew Rhys) still really wants to bring tourism to the island. Mayor Tom is so married to his vision of Widow's Bay as the next Martha's Vineyard, he ignores the sea hags, fog monsters, and serial-killer ghosts surrounding him. The great Stephen Root plays Wyck, an old-timer who's always there to remind everyone that time is short and everyone is doomed. You can stream Widow's Bay on Apple TV+.

Lucky

Based on the bestselling novel by Marissa Stapley, Apple TV's latest hit stars Anya Taylor-Joy as the titular con artist. Her name proves to be a tad ironic after her latest job goes wrong and she finds herself the prime target of both the cops and the dangerous crime boss—who also happens to be her mother-in-law. Annette Bening is clearly having a grand time playing the ruthless Priscilla Masterson, who blames Lucky for the loss of $10 million she and Priscilla's son Cary (Drew Masterson) stole—never mind that Cary eventually ran away with it. With a supporting cast that includes Aunjanue Ellis-Taylor and Timothy Olyphant, it's a fast-moving thriller with a sense of humor and an irresistible lead character. You can stream Lucky on Apple TV.

Ride or Die

This London-set series stars the ultimate odd couple. Octavia Spencer plays Debbie, the American wife of a British politician, and Hannah Waddingham plays her good friend Judith, who happens to be a master assassin. After a hit gone wrong, Judith must go on the run to stay ahead of another assassin working against her, and to avoid running afoul of the ruthless agency (literally called The Agency) that employs her. Obviously, Debbie gets pulled along for the ride. It's a fast, tense, and funny thriller series. You can stream Ride or Die on Prime Video.

I Will Find You

Like Max Cady in Cape Fear, the main character in I Will Find You has been imprisoned for a murder he did not commit. But unlike Max Cady, David Burroughs (Sam Worthington) doesn't set out to murder his lawyer. He was accused of killing his own son, and when he sees evidence that the boy is alive, he escapes prison to find his child. It's a modern take on The Fugitive: with the authorities on his trail, David must unravel a twisting conspiracy to clear his name and bring his child home. I Will Find You is a perfect summertime thriller. You can stream I Will Find You on Netflix.

FROM

The residents of the unnamed town at the center of FROM cannot catch a break. If it's not worms crawling around under their skin, it's the mysterious Man in Yellow stealing people's souls. Season four of this mystery-heavy show from the executive producers of Lost sees the survivors pushed to their limits as the veil between the strange town and the real world gets thinner. You can stream FROM on MGM+.

Cape Fear

Executive-produced by Steven Spielberg and Martin Scorsese, Cape Fear is a 10-episode reimagining of a classic novel that has previously been adapted into two celebrated films. In this extended version, Amy Adams plays Anna Bowden, a defense attorney who unsuccessfully defended murder suspect Max Cady 17 years previously. Turns out he wasn't guilty, and Cady has had nearly two decades to plan his revenge against the woman he blames for putting him behind bars. Javier Bardem brings unsettling energy to the role of Cady, previously played by Robert Mitchum, Robert De Niro, and Sideshow Bob. If you like slow-burn suspense that gradually ratchets up tension, you'll like Cape Fear. You can stream Cape Fear on Apple TV+.

The Agency

The spy thriller returns for its second season. Michael Fassbender plays Brandon Colby (code name Martian), a former CIA field agent who now runs operations for London Station, the agency's home office in the U.K. This season, the spy action grows more intricate, as Martian works to clear the name of his lover (Jodie Turner-Smith) while also going head-to-head with a possible double agent within the Agency's own ranks. You can stream The Agency on Paramount+ With Showtime.


from Lifehacker https://ift.tt/2sMl8EU

Stellar Cyber, the full-cycle AI-native security operations platform company, today released results from an independent study of 124 days of customer trials of its Agentic Auto Triage capability.

Stellar Cyber Agentic Auto Triage

The independent study based on customer trials evaluated 138,475 real security alerts and reached the same verdict as human analysts 99.7% of the time. The findings, drawn from customer-submitted end-of-trial reports, addressed the central question facing every security team weighing autonomous SOC technology: Can AI actually be trusted to make decisions?

AI-driven tools have made it easier than ever for adversaries to design highly convincing phishing and ransomware attacks. In response, organizations have doubled down on security awareness and training, resulting in a surge in reports of potential threats. The World Economic Forum reports potential security threats have surged dramatically over the last two years, with ransomware attacks jumping by up to 48% year-over-year and phishing attempts exploding by 1200% since late 2022. This escalation is largely driven by GenAI-enhanced tactics. Automatic Triage, powered by Agentic AI, levels the playing field for human security analysts by automatically ingesting, correlating, analyzing, and prioritizing suspicious events from the user’s environment.

Finding #1: Auto Triage returns 19 minutes of every hour, translating to 1 day a week of productivity

Across the trials, Auto Triage returned roughly 19 minutes of every analyst hour to higher-value work, including working more cases per shift and dedicating more time to exposure management, anticipating adversary behavior, and closing exposures. This time translates to about one day per week per analyst, or the equivalent of 1.5 full-time analysts reclaimed annually.

By closing out confident false positives and surfacing real threats before a human ever opens them, Auto Triage reduces noise, helps teams move from an alert-centric mode to a case-management mode, and transforms the job of the human security analyst. This shift helps improve MTTD and MTTR while giving analysts time to think like attackers, anticipate likely attack paths, and close visible gaps before they are exploited.

“Security operations have reached a tipping point. The volume and complexity of alerts are simply beyond what human analysts can manage alone,” said Aimei Wei, CTO at Stellar Cyber. “This real-world study proves that our approach of combining machine-speed analysis with human judgment is the right way forward. These results show what that looks like in practice: the AI does the alert work at scale, the analyst stays in control, and they almost always agree—freeing analysts to manage more cases and get ahead of emerging exposure.”

Finding #2: 64% of False Positives closed; 15% of True Positives escalated

Using machine learning models trained on real-world phishing patterns, the platform delivers reliable, actionable verdicts in seconds. Auto Triage assigns each alert a decision through an AI-driven Verdict Signal Check, with human-in-the-loop oversight and a closed-loop learning process that improves accuracy over time.

During the trials, the system analyzed 138,475 alerts, disposing of 64% of them as confident false-positive closures. Auto Triage escalated 15% of the alerts as true positives for human analyst review, and routed the remainder as informational, clearing noise before it reached a person.

“The Agentic AI built into Auto Triage is designed to address one of the most pressing challenges security analysts deal with on a daily basis: tuning out the noise and focusing on legitimate threats to the business,” said Christopher M. Steffen, CISSP, CISA, CCZT, VP of Research, Information Security, Risk, and Compliance Management at EMA. “This study proves that Stellar Cyber’s approach of automatic ingestion and analysis, AI-driven prioritization, and highly accurate decision-making has the power to transform the way analysts work in the enterprise SOC—from processing alerts to managing cases, moving from MTTD and MTTR, towards MTTN – mean time to neutralize, and spending more time proactively reducing exposure.”

Lean security teams at enterprise SOCs and MSSPs face mounting alert volumes without the budget to scale headcount. For MSSPs, reclaimed analyst capacity translates directly into broader coverage, better customer service, and protected margins.

“The results from this study underscore what we’ve experienced in our own SOC. For an MSSP, the math of human-only security operations simply can’t scale against today’s alert volumes,” said Chant Vartanian, CEO, M-Theory Group. “Auto Triage effectively returns a full day of productivity per analyst and successfully closes 64% of false positives. That data is truly transformative for organizations like ours. It allows us to shift our team’s focus to high-value threat investigation and exposure management, work more cases per shift, which directly improves our service margins and enables us to provide broader, more consistent coverage for our clients without the need for costly headcount expansion.”

Auto Triage is available now as part of the Stellar Cyber AI-native SecOps platform. Stellar Cyber will showcase Auto Triage and the results of this independent study live at Black Hat USA (Booth #5542), August 1-6, 2026, in Las Vegas. Book a demo today!


from Help Net Security https://ift.tt/EtqeCxT

We may earn a commission from links on this page.

Amazfit's Cheetah 2 Ultra is a premium titanium-and-sapphire trail running watch, with a $599.99 price that feels pretty steep for a brand otherwise known for its budget options. And while Amazfit's Cheetah line isn't exactly my favorite, the Cheetah 2 Ultra is still an incredibly solid choice for any runner who wants a watch that looks and feels top-of-the-line.

Like with the Cheetah 2 Pro, there's more than meets the eye with this surprisingly feature-rich watch. Here are five features in the Cheetah 2 Ultra that go a bit beyond the manual.

Unlock a secret developer mode in your Amazfit watch

Your Zepp app has a hidden menu you probably wouldn't stumble upon by accident. Go to Profile, then Settings, then About, and tap the Zepp logo seven times in a row. This unlocks developer mode, which lets you dig into device information and debugging options that aren't normally visible in the consumer-facing app. It's not going to unlock secret hardware, but it's a useful place to check firmware details or troubleshoot a stubborn sync issue, and it's fun rabbit hole if you like poking around under the hood.

Developer mode also lets you install custom watch faces, rather than relying on the existing native watch face library and upload a custom face on your computer, scan a generated QR code, and install it directly onto your watch.

Prepare for difficult elevation at a glance on your Amazfit Cheetah 2Ultra

If you're planning a route with serious hills, this is one of the Ultra’s best hacks. The watch includes an elevation overview tool that color-codes slope difficulty across a route, so instead of squinting at a raw elevation profile and trying to guess where the brutal climbs are, you get a more accessible visual for where the terrain gets steep. This feature is easy to miss if you're not a dedicated trail runner, but it's worth pulling up before any route, so you know what you're walking into (before the hill tells you itself, the hard way).

Here's how to use the color-coded elevation glance on your Amazfit Cheetah 2 Ultra:

  1. Create your route: Open the Zepp App, go to the Workout tab, select Create Route, and save your path.

  2. Send the route to your watch: Sync your devices and check that the route successfully transfers to your watch.

  3. Open Trail Mode: On your watch, launch the Trail Run sports profile before you start running.

  4. Activate your route: While in trail mode, go to Settings, select Navigation, choose My Route, and select the route you created. Swipe to the elevation profile to see your color-coded preview.

If you want to see this elevation profile during your run, you can add elevation as a data screen. Here's how to customize your data screens on your Amazfit:

  1. Select Workout on your watch and select your activity (like Outdoor Running).

  2. Go to Settings > More > Data Page.

  3. Tap whichever data field you want to show the elevation. You can swipe through your existing data pages or tap Add Page to create a new one.

Use the flashlight's boost mode when you need extra light (and practice the SOS feature)

Every Ultra user loves their watch's built-in flashlight, but there's even more to get out of it. The Ultra's flashlight includes white, red, SOS, and boost lighting modes, not just a single beam. The boost mode is there for when you need maximum brightness, like scanning a dark trail, while the SOS mode is a safety feature and needs to send a clear flashing signal in the dark. Cycle through the modes with repeated presses rather than assuming it's a one-setting tool.

After you press and hold the top-left button to turn on the flashlight, use the UP or DOWN buttons to cycle through the white brightness settings until you reach the red light mode. You can also swipe down from the watch face to open the Control Center and tap the flashlight icon.

Use your Cheetah 2 Ultra to browse new maps

You might assume your options are limited to whatever maps Amazfit preloads or offers through the Zepp app's map store—which includes plenty of options already. But you can go a little further. The Cheetah 2 Ultra can be used as a map browsing tool when you import OSM (OpenStreetMap) map files, which means if you're headed somewhere obscure that isn't well covered by the default map set, you have a nifty workaround. Just keep in mind the downloaded map needs to actually match your real location to be usable, so this is a plan-ahead hack, not something you sort out mid-trail.

Use the extra storage on your Amazfit Cheetah 2 Ultra to load MP3 files

Even though the Ultra doesn't download music directly from streaming services like Spotify or Amazon Music the way some competitors do, you can manually load MP3 files onto the watch yourself. This is notable because the Cheetah 2 Ultra doubles the Pro's storage to 64GB, which means plenty room for saved running routes, offline maps, and mp3 files for music. It's an extra step compared to a simple streaming sync, but for anyone who wants a truly phone-free long run, it's a hack worth knowing about. To load music, head to your Amazfit Cheetah 2 Ultra device page in your Zepp app > Select "Music" > select .mp3 files from your phone and transfer them to the watch.


from Lifehacker https://ift.tt/TnYrp2N

Malware is everywhere these days. You might expect to find it when downloading strange programs from dark corners of the internet, but these are far from the only locations that can infect your devices. Despite strict review processes, official app marketplaces like Google's Play Store and Apple's App Store can feature apps containing malware. Now, that also extends to smart TV app marketplaces, as well.

Some apps were turning your Samsung TV into a "resproxy" network

As reported by TechCrunch, Samsung recently banned apps that share the users' internet connections with "strangers." Before the ban, "hundreds of millions" of users may have downloaded these apps onto their smart TVs, which put a huge fraction of Samsung's customers in jeopardy. These apps weren't necessarily shady, either. At least one of these apps, a Pac-Man game, was actually promoted by Samsung itself: The company featured it in an "Editor's Choice" area that customers would see on their smart TVs.

The issue, as discovered by security firm Mnemonic, comes from a data collection company called Bright Data. This company's code hides processes that would allow strangers to route their web traffic through your home internet. Once set up, the malicious apps wouldn't even need to be open for outsiders to tap into your network, which they could use for any purpose they wish. As TechCrunch highlights, these "resproxy" networks are being used more frequently for cybercrime, as it makes it difficult to trace this activity. Someone in England could route their activity through your home internet in Arizona, which would make it nearly impossible to discover their actual whereabouts.

It might seem surprising that Samsung would allow such apps on its official app marketplace, but many of these apps had clever tricks to evade capture. Many were extremely simple programs and only contained a handful of lines of code. These apps would pull in content from a remote server, creating the illusion that they were fully functioning apps. But from Samsung's point of view, these apps were simple and safe. This isn't a Samsung issue, either: LG also banned respoxy apps, shortly after it came out that over 40% of the apps on its marketplace added users' smart TVs to proxy networks.

Also complicating matters is that legitimate apps contain Bright Data's code. Play.Works, which licenses games like Pac-Man, but also Space Invaders, Tetris, Doodle Jump, and SpongeBob, included Bright Data's code in their ports. You'd likely assume downloading an official SpongeBob app to your TV would be safe, but, unbeknownst to you, it actually contains this sleeper resproxy code.

How to protect yourself from malicious smart TV apps

The good news in this case is Samsung has banned these apps from its app marketplaces. As such, you shouldn't have to worry about installing apps that will let outsiders tap into your internet connection. The same goes for LG as well. But not all smart TV manufacturers may have caught up yet, which means there is a risk that the apps you download on your TV could be malicious.

Researchers also found that simply installing these apps won't turn your TV into a respoxy device. While the code may load on your TV, you need to explicitly agree to a consent screen before you activate the code and turn your TV into a network node. As such, stay vigilant with any pop-ups on your smart TV apps, and deny consent to anything you either don't understand or don't feel is necessary to the function of the app. In addition, delete any suspicious apps, or any you no longer use: While the code can run without the app open, it gets deleted when you remove the app.

From here, general best practices will go a long way. Before you install an app on your smart TV (or, really, any device), inspect it carefully and exercise skepticism. Look through its app store listing, and make sure the description is free of spelling or grammatical errors. Look at the images, and note whether they appear high or low-quality, or whether they match the description for the app. Scan reviews, both for negative feedback from users, as well as obvious fakes inflating the overall rating. Investigate the app developer: Do they make other apps? Do those apps appear legitimate?

But as far as app marketplaces go, smart TVs have a poor reputation. As a general rule of thumb, it's probably best to avoid smart TV apps as much as possible. While mainstream streaming apps should be safe, there are too many possible loopholes present to say for sure whether various games and utility apps are secure.


from Lifehacker https://ift.tt/GRJe3xc