The Latest

Most modern browsers have built-in password management, allowing you to save your credentials and automatically fill them when logging into your accounts on various websites. And while Google Password Manager on Chrome and similar tools in other browsers like Firefox, Brave, and Microsoft Edge certainly simplify the process of storing and using stronger passwords, they have major limitations when it comes to security and functionality. Here's why you should use a dedicated password manager instead.

Browser password managers only work within the browser

If you store your passwords in your browser, it can fill your credentials on websites within the browser itself. (If you're an Android user, Google Password Manager also syncs to your device and works across any browser or app.) But if you use multiple browsers or want to log into apps on your iPhone or PC, you'll have to manually copy and paste your password from the browser into those form fields—not ideal, from a standpoint of both convenience and security.

Browser password managers are more vulnerable to security risks

Browser password management is, on a basic level, secure: Google uses the same AES encryption in transit and at rest that many dedicated password managers do, and allows it you to add biometric authentication for auto-filling credentials. However, they're not zero-knowledge by default: Google manages your encryption key unless you enable on-device encryption so that your vault can only be unlocked on your device, by you, with your Google password or biometrics. Firefox also uses AES-256 encryption and has a "primary password" feature to protect your stored data, without which anyone who has access to your computer or browser profile can view your saved passwords. It's on the user to add these layers of security, as they're not on by default.

As Wired points out, the more serious problem isn't encryption, but rather the risk inherent in storing passwords in a high-value account that could be targeted—either by someone who gains access to your device or as part of a takeover attempt, such as a phishing or credential stuffing attack. This creates a single point of failure, and if someone gets into your Google account or your browser of choice, your passwords for everything else are also compromised.

Browser password managers have only basic features

Browser password managers do basically one thing, which is store your login credentials and fill them in on websites when you visit them in the browser. Google Password Manager will also alert you if your password has been compromised in a breach, but most browsers lack any additional tools and features, such as password customization, secure sharing, email masking, emergency access, and storage for payment cards, identity data, and documents.

Use a dedicated third-party password manager instead

The solution is to opt for a dedicated password manager that works across platforms and devices and offers a layer of protection outside of your browser. There are many excellent password managers to choose from, including free services like Bitwarden and privacy-focused Proton Pass (which also has a decent free tier). The best password managers also have features like secure file storage, encrypted credential sharing, and data breach monitoring, making them useful tools in your privacy and security arsenal.

Of course, even a browser password manager is better than nothing at all, if the alternative is to reuse the same easy-to-remember credentials across your accounts. (It's also likely your reused passwords don't meet basic security standards and can be easily guessed.) Password storage in Chrome, Firefox, and other browsers do reduce the friction of shifting to strong, unique passwords for your accounts, and that alone is a solid step. But a third-party password manager is a superior choice if you're willing to invest a bit of time and energy into setting it up.


from Lifehacker https://ift.tt/uCyQBna

We may earn a commission from links on this page.

Though it was hardly the first show to attempt kitchen-based drama, The Bear’s recipe was pretty unique: With a focus on characters, a willingness to experiment with narrative style, and an intimate knowledge of a world most people don't know much about, it was an ambitious and ultimately successful series.

Carmy, Richie, and Sydney’s stories may have ended with Season 5, but that doesn’t mean you can’t devour more slow-burn kitchen tension set in or around a fine dining establishment. If you’ve watched (and rewatched) The Bear and all the other series that offer similar pleasures, there’s one movie you should check out right away: 2021’s Boiling Point.

Boiling Point also explores a high-pressure kitchen culture

Before Carmy unlocked the doors to Chicago's The Original Beef in the first episode of The Bear, Chef Andy Jones (Stephen Graham) stepped into Jones & Sons in London—and if you loved The Bear best when chaos reigned and the chefs were shouting at each other, strap in for a similar ride. Boiling Point (which was extended into a sequel TV series a few years later) is filmed in one take: a single 90-minute scene of escalating tension, as everything that could possibly go wrong for an alcoholic, emotionally volatile chef and his stressed-out staff does, indeed, go wrong.

Boiling Point is rooted in the same professional kitchen culture as The Bear, and offers a similar dynamic to the early seasons of the show. Andy is a disaster—he secretly drinks on the job, his personal life is a mess, and he’s deeply in debt. The staff at Jones & Sons is top-notch, but they’re all suffering from Andy’s unpredictable moods and their inevitable effects. The restaurant has just been knocked down a health rating, the evening is overbooked, and personalities can’t stop clashing. It all leads to a dynamite climax with real emotional punch.

Another reason fans of The Bear will love Boiling Point is the care the film takes to center food culture. A lot of kitchen dramas treat the cooking and service as set dressing, but this film, like The Bear, knows that what goes into the food and the service is just as important to the story as anything else. Bottom line: You won’t find a closer match to the tone and impact of the celebrated Hulu series in another movie. Bonus: Stephen Graham—now best-known for his incredible performance in Adolescence—is one of the best under-the-radar actors working today, and he brings his A-game to the lead role. Stream Boiling Point on The Roku Channel, Kanopy, or Tubi, or rent it on Prime Video.

More movies like The Bear

Still hungry for kitchen drama? The good news is that restaurants offer infinite material for conflict, and there are plenty of movies to choose from if you want to keep The Bear vibe going.

Big Night (1996)

The Bear really captured the hard work, stress, and constant chaos of trying to make a restaurant into a success. Big Night is all about that. Set in the 1950s, it details the efforts of two Italian immigrants (played by Stanley Tucci and Tony Shalhoub) seeking a miracle to save their struggling Jersey Shore restaurant from failure. This was a time when true ethnic cooking was often rejected by American diners, which adds a twist of tension to the chaos as they try to organize one “big night” to pay off their debts and put their restaurant on the map. Stream Big Night on Paramount Plus or rent it on Prime Video.

Burnt (2015)

Do you think The Bear is all about Carmen Berzatto’s dreamy mix of tortured artistry and hot failure? Then you’ll like Burnt. Like Carmy, Adam Jones (Bradley Cooper) was once a hotshot chef, but his addictions and poor mental health have cost him everything (though he still looks hella good in chef whites). He returns to London with a new sobriety and sense of humility, determined to salvage his career and make amends. There’s a chase for a Michelin Star, and Jones is an appealingly broken genius in the same mold as our beloved Carmy. Stream Burnt on Kanopy, Plex, or Prime Video, or rent it on Fandango.

Hunger (2023)

Few will ever know what it’s like to be one of the best in the world at something, which is one reason why Carmy, Sydney, and Marcus were such compelling characters. If that’s your jam, check out Hunger. This Thai film follows Aoy (Chutimon Chuengcharoensukying) as she cooks at her family’s struggling restaurant. Aoy is way better than her current circumstances, and she’s soon recruited to train under the legendary chef at an exclusive restaurant called Hunger. It’s the chance of a lifetime, but unfortunately it comes with a side order of a wildly toxic workplace. Stream Hunger on Netflix.

Shiva Baby (2021)

If The Bear’s high point for you was Season 2’s Fishes, detailing a particularly chaotic Christmas dinner at the Berzatto house, you’ll love Shiva Baby. While food plays a role in the story, it’s not set at a restaurant and no one is a chef—but it rocks similarly “crazy relatives” vibes, as college senior Danielle (Rachel Sennott) returns home to sit shiva with her family. In the mix are her ex-lover, a sugar daddy, and an extended family with no sense of boundaries. It’s a hilarious film with a dark, emotional core that keeps everything grounded, just like the best episodes of The Bear. Stream Shiva Baby on Kanopy or Hoopla, or rent it on Prime Video.

The Menu (2022)

One reason The Bear stood out is the way it simultaneously acknowledges how weirdly intense and cult-like fine dining can be, while also celebrating the crazy geniuses and unstable personalities that make those dinners so memorable. The Menu is also about this dichotomy, though in a much more horrific way: At a restaurant on a private island run by famous chef Julian Slowik, a group of foodie influencers and celebrities gather for a meal that becomes increasingly horrifying with each course, slowly digging into the madness that drives perfection in the kitchen. Stream The Menu on Fubo or rent it on Prime Video.


from Lifehacker https://ift.tt/6Y0dCRV

TikTok is famous for its addictive algorithm. And while the videos are certainly the app's main focus, I find the most entertainment in the comments. TikTok commenters can be hilarious, especially since they can use both text and photos to make their jokes. Social media comments are often vile, and while TikTok isn't immune to trolls and their ilk, its comments are generally something else. Now, the comments are changing. On Thursday, TikTok announced four new features that will make comments more visual, interactive, and, well, loud. Not all of these features are out quite yet, but by next month, you might not recognize TikTok's comment section.

TikTok will soon support voice comments

Text and photo comments aren't going anywhere, but you may find that the comment section is about to get a bit louder. Starting next month, TikTok will support voice comments up to 60 seconds long, which adds a wholly unique type of comment to the mix. Based on TikTok's press release, you can still attach a text-based comment to your voice comment, similar to how photo comments work.

While friends may post voice comments on each other's videos à la voice memos in a group chat, I'm guessing that commenters in general will use this feature in ways TikTok doesn't necessarily intend. In fact, this may birth a new type of meme, where users spam videos with obnoxious sound effects and reaction sounds. Think the sounds added to meme edits of viral videos, but in comment form. It's going to be messy, and, likely, hysterical.

You can now vote in polls in TikTok comments

Starting this week, you may see a new interactive element to TikTok comments: polls. TikTok says creators can add polls to the comments of their videos, with up to five voting options per poll. Rather than ask for opinions in the comments, creators can use a poll instead. Creators can choose how long voting lasts, and watch votes appear in real time. It's a small change, but one that could be useful to both big and small creators looking for input from their viewers.

You can post Live Photos to comments

You're no longer limited to posting static images in TikTok's comments. TikTok now supports uploading Live Photos to comments, which should also prove interesting. I could see people thinking they're posting a standard image, but accidentally uploading a Live Photo instead. But seeing as users already know how to add GIFs to comments, I'm not sure how many will want to upload Live Photos. This one might be reserved more for friends commenting on friends' videos, but we'll have to see how users react to know for sure.

Post photo carousels as single comments

This last update is perhaps a bit more useful than Live Photo comments. TikTok says it's working on allowing users to upload up to nine photos in one comment, which means the comments section may be literally full of pictures once this launches en masse. Like standard carousels, users will be able to swipe through your photo uploads, including in a full-screen view. This one will roll out over the course of this month.


from Lifehacker https://ift.tt/IaoSs8e

Google has introduced Gemini 3.8 Flash, available to developers today, and a gated sibling, Gemini 3.8 Flash Cyber, reserved for vetted security teams.

Google Gemini 3.8 Flash

“Our 3rd Flash release in just 6 wks,” Google CEO Sundar Pichai said on X, adding that it makes sizable gains over 3.7 Flash in software engineering, agentic work, and multi-step reasoning. On the DeepSWE v1.1 benchmark, Google says it beats most larger frontier models at solving complex engineering problems end to end, at a lower cost.

Tulsee Doshi, Google’s senior director of product management, and Raluca Ada Popa, Gemini Security Lead at Google DeepMind, trace the improvements in part to how the model handles a task.

“3.8 Flash works harder,” the two wrote, citing extra reasoning steps and repeated tool calls before it settles on an answer. Anyone who prioritizes lower cost over depth can reduce the model’s effort setting or stay on 3.7 Flash.

Access to Gemini 3.8 Flash Cyber runs through a new program called Fairwind, built for trusted government authorities, critical infrastructure operators, and software maintainers hunting vulnerabilities in large codebases.

“We have invested in vulnerability fixing from the start,” Doshi and Popa said, placing patching ahead of offensive work like exploitation. Chrome Security reported that 3.8 Flash Cyber produced 2.6 times more correct patches than the best commercial models, while Google’s Cloud Vulnerability Research team says it found a critical foundational vulnerability in under two hours — work that would normally take months.

Standard 3.8 Flash carries safeguards against chemical, biological, radiological, and nuclear misuse, along with restrictions on cyber-offense uses. The Cyber version uses more permissive cybersecurity safeguards, which is why Google kept it behind Fairwind instead of shipping it to every developer.

Doshi and Popa also said the Gemini 3.8 models made a “significant leap” in prompt-injection robustness, citing measurements by AI security company Gray Swan.

Gemini 3.8 Flash launches at the same introductory price as 3.7 Flash, at $0.75 per million input tokens and $3.75 per million output tokens.

The model is available to developers through the Gemini API in Google AI Studio, Google Antigravity, Android Studio, and Stitch. Enterprises can access it through Gemini Enterprise, while Google AI Pro and Ultra subscribers can use it in the Gemini app, AI Mode in Google Search, and Gemini in Google Sheets.


from Help Net Security https://ift.tt/dp8BUZI

Beginning in October 2026, Windows quality updates start enabling memory integrity protection on eligible devices with little or no additional configuration. On machines where Virtualization-based Security is not already running, those same updates enable VBS too.

Windows memory integrity

Memory integrity is the layer that allows only trusted kernel-mode code and drivers to run, which is how it stops an attacker who is trying to compromise the Windows kernel and take control of core operating system functions.

The change arrives as a patch, so the security posture of a fleet can move between one update cycle and the next without anyone filing a change request.

“Existing administrator and user decisions and policies remain in effect. This means that devices where memory integrity has already been disabled won’t be automatically changed by this rollout. If memory integrity is not enabled by default, users and organizations can still review, configure, and enable it using existing Windows security and management tools,” Peter Waxman, Group Program Manager at Microsoft, said.

Windows checks readiness first

Before enabling the protection, Windows evaluates whether a device is ready. The signals are hardware capabilities, compatibility, and performance considerations. That evaluation is why the rollout covers only eligible devices, and it is doing the work a driver inventory would otherwise do for you.

Microsoft does not claim the check catches every incompatible kernel driver in an environment, so if you run anything unusual at kernel level, the safe assumption is that you still own that problem.

There is a second reason to care beyond blocking rootkits. Memory integrity underpins hotpatch updates, the ones that install without a reboot, so a device that stays unprotected is also cut off from the servicing model built on top of it.

Devices the rollout skips can still be brought in by hand. Users and organizations can review, configure, and enable memory integrity with the Windows security and management tools they already have.


from Help Net Security https://ift.tt/cVhrqUA

While many internet scams are obvious enough to easily avoid, they are growing more sophisticated. Even seasoned users may find themselves duped by a clever fake email, text, or phone call. Case in point: If you receive a message from "Amazon," you might have trouble quickly identifying whether or not it's legitimate. That could lead you to either fall for a trap, or, if the message is real, miss an important announcement or alert from the company.

There are plenty of tactics and best practices out there for verifying these messages on your own, of course: You can take a look at the email address or phone number that sent it, and do your own research to see whether it's official contact info for the company (depending on the email address, this might be apparent on its own); you can study the body of the message, looking for grammar and spelling mistakes that would give away a hasty phishing scheme; and you can note any financial requests, or time-sensitive demands, which would raise the stakes and increase the chances that someone would treat the message and its contents as legitimate.

But none of these tactics allows you to confirm directly with the company—in this case, Amazon—whether that outreach is real. A new Alexa tool does just that.

How Alexa for Shopping helps you confirm Amazon messages are legit

On Wednesday, Amazon announced an interesting new initiative aimed at reducing—if not eliminating—the risk of users falling for scams. Starting today, "Alexa for Shopping," Amazon's shopping assistant, will help you verify whether an email, text, or phone call from "Amazon" is actually from the company. The company says you can ask Alexa for Shopping questions like "Did Amazon send me a text about a delivery problem yesterday?" "Is this email about my Prime membership from Amazon real?" or "I got a call about a refund from someone saying they're from Amazon. Was that real?” In addition, you ask Alexa for Shopping for more information about the message or call in question, providing any details that seem relevant (e.g., the email address or phone number the message came from, when you received it, and what it said).

The AI will use these details to figure out whether the message is something Amazon sent itself. What's unique about this new feature is that the bot can actually check your details against the company's record of "every communication it has sent," including sender information, message content, when messages were sent, and exact formatting. Amazon says it completes this check "within seconds," and you'll receive one of the following answers: confirmed from Amazon, not from Amazon, or unable to verify. Amazon says Alexa for Shopping will only confirm a message is real if it has total certainty.

If the message was from Amazon, the company will confirm that the message type, source, date, and time were all consistent with Amazon's message records. You'll also get tips for keeping your account secure—whether you asked for them or not. If the message is not from Amazon, you might get a result like, “This message does not appear to match any official Amazon communication based on the information provided.” Alexa for Shopping may then follow up with recommendations, like checking your orders in the app, contacting Amazon directly, and warnings against clicking links or replying to the message. If it can't confirm the message, Amazon may encourage you to try another verification method.

This isn't the first verification method Amazon has rolled out. The company says it launched an email address, "verify@amazon.com," earlier this year for users to forward messages to. There is also an existing Amazon customer service form that walks you through filing a similar request. Alexa for Shopping will likely point you in these directions if it can't verify your message for whatever reason.

While companies continue to shove AI features into all of their products, this one from Amazon seems potentially quite useful. It's such a simple concept that I'm surprised more companies don't already offer a similar service. Why not automatically check user submissions against your message records to help separate real messages from spam? Perhaps Amazon will be a trailblazer here—assuming the feature actually works, and doesn't hallucinate verifications.


from Lifehacker https://ift.tt/g8Qbprt

We may earn a commission from links on this page.

Running earbuds are an extremely personal category of gear. Every runner has their own non-negotiables. For me, the top priority has always been a secure fit—which is exactly why I've gravitated toward wraparound designs like the Shokz OpenRun models. I like the safety perks of open-ear, bone-conduction listening too: being able to hear traffic, cyclists, and other runners is more important than hearing my music, personally. Unfortunately, that means I've lived with a serious trade-off in sound quality. There are certain stretches of my city runs that my open-ear headphones just can't cut through. Still, every time I've tried a noise-cancelling option, I've always found some other dealbreaker with comfort, fit, or safety. So it says something that, for the first time, I actually like a pair of noise-cancelling sport earbuds: the JLab JBuds Sport ANC 4.

Why I love these noise-cancelling sport earbuds

First things first: As far as running earbuds go, these are a budget pick at $69.99. A few other highlights:

  • 60+ hours of total playtime and IP66 sweat resistance

  • Flexible over-the-ear hooks for a secure fit

  • A well-designed charging case with a built-in USB-C cable and wireless charging support (the one catch: the built-in cable is short, so the case needs to stay close to an outlet)

I tested these on the Williamsburg Bridge—one of the loudest, windiest stretches in my regular rotation, and a place where my go-to open-ear pair, the Shokz OpenRun Pro 2, simply get drowned out. The JBuds Sport ANC 4 handled it admirably. I could actually hear my music along with the foot traffic around me, all without losing the secure fit I need to trust earbuds on a run.

I'm over 30 miles into testing them now, and they haven't shifted once. Fit is always subjective—what locks in for my ears might not work for yours—but this is the first ANC sport earbud that's matched what I get from a wraparound design.

If touch controls are an important consideration for you, JLab did something interesting here: there are two separate touch surfaces, one on the outer shell and one on the hook itself, which supports swipe gestures. Out of the box, the controls are the same for both ears:

  • Single tap: play/pause

  • Double tap: next track

  • Triple tap: previous track

  • Long press: cycle through Noise Cancelling, Be Aware (transparency), and Off

  • Swipe: volume control

Everything is customizable in the app, including setting independent controls per earbud. You can reassign gestures to switch EQ presets, trigger your voice assistant, or control the workout timer.

The "Be Aware" mode (JLab's transparency setting) is fine for quick in-person conversations, but it's not great. It amplifies most ambient sound but struggles with higher frequencies and introduces a noticeable hiss, which makes voices and traffic sound a bit synthetic.

And to be clear: this is an upgrade for running earbuds, not a hi-fi listening upgrade. If premium sound quality is your top priority, look elsewhere.

The bottom line

I wouldn't recommend these to everyone. If pristine sound is what you're after, this isn't your pair. But if you're coming from an open-ear or bone-conduction setup like Shokz and you've hit the same wall I have—where city noise simply overwhelms the open design—then JBuds Sport ANC 4 hits a specific, useful sweet spot. For me, these have enough noise cancellation to make loud routes bearable, a fit secure enough to trust through a hard workout, and a budget price.


from Lifehacker https://ift.tt/hvODQp2