×
Google

Google Gets Mixed Reception in High Court Clash With Oracle (bloomberg.com) 74

Alphabet's Google got a mixed reception at the U.S. Supreme Court as it sought to overturn a ruling that could force the company to pay billions of dollars for improperly using Oracle's copyrighted code in the Android operating system. From a report: Holding a low-tech telephone session in one of the biggest software fights in American history, the justices on Wednesday questioned Google's contention that it had no way to replicate the code without forcing millions of software developers to learn a new programming language. Justice Neil Gorsuch told Google's lawyer that Apple and other companies have "come up with phones that work just fine without engaging in this kind of copying." But Gorsuch also raised the possibility of returning the case to a federal appeals court for another look at Google's contention that it engaged in legitimate "fair use" of Oracle's Java programming language. Oracle says it's entitled to at least $8.8 billion in damages. A jury found that Google's code copying was a legitimate fair use, but a federal appeals court reversed that finding.
China

China Says It Won't Approve TikTok Sale, Calls It 'Extortion' (techcrunch.com) 174

The September 20 deadline for a purported TikTok sale has already passed, but the parties involved have yet to settle terms on the deal. ByteDance and TikTok's bidders Oracle and Walmart presented conflicting messages on the future ownership of the app, confusing investors and users. Meanwhile, Beijing's discontent with the TikTok sale is increasingly obvious. From a report: China has no reason to approve the "dirty" and "unfair" deal that allows Oracle and Walmart to effectively take over TikTok based on "bullying and extortion," slammed an editorial published Wednesday in China Daily, an official English-language newspaper of the Chinese Communist Party. The editorial argued that TikTok's success -- a projected revenue of about a billion dollars by the end of 2020 -- "has apparently made Washington feel uneasy" and prompted the U.S. to use "national security as the pretext to ban the short video sharing app." The official message might stir mixed feelings within ByteDance, which has along the way tried to prove its disassociation from the Chinese authority, a precondition for the companies' products to operate freely in Western countries.
China

Trump Says ByteDance Can't Keep Control of TikTok in Oracle Deal (bloomberg.com) 93

President Donald Trump said he might rescind his tentative blessing for a deal between Oracle and ByteDance to create a new U.S.-based TikTok service, casting doubt on the agreement as Chinese state media signaled reluctance in Beijing. From a report: Speaking in an interview on Fox News on Monday, Trump said he wouldn't approve the deal if the Chinese company retains control of TikTok. However, he also indicated that he expected Chinese influence to be diluted by a future public offering of the new company. "They will have nothing to do with it, and if they do, we just won't make the deal," Trump said, referring to ByteDance, which owns TikTok. "It's going to be controlled, totally controlled by Oracle, and I guess they're going public and they're buying out the rest of it -- they're buying out a lot, and if we find that they don't have total control then we're not going to approve the deal." Shortly after Trump's comments, Hu Xijin, editor-in-chief of the China state-affiliated Global Times, tweeted that Beijing would likely reject the deal "because the agreement would endanger China's national security, interests and dignity."
United States

With New Security and Free Internet Issues, What Did the TikTok Deal Really Achieve? (nytimes.com) 116

Though the U.S. government averted a shutdown of TikTok through a new Oracle/Walmart partnership, that leaves much bigger questions unresolved. The biggest issue may be that banning apps "defeats the original intent of the internet," argues the New York TImes. "And that was to create a global communications network, unrestrained by national borders." "The vision for a single, interconnected network around the globe is long gone," Jason Healey, a senior research scholar at Columbia University's School for International and Public Affairs and an expert on cyber conflict. "All we can do now is try to steer toward optimal fragmentation."
But the Times also asks whether the TikTok agreement fails even at its original goal of protecting the app from foreign influence: The code and algorithms are the magic sauce that Beijing now says, citing its own national security concerns, may not be exported to to a foreign adversary... Microsoft's bid went further: It would have owned the source code and algorithms from the first day of the acquisition, and over the course of a year moved their development entirely to the United States, with engineers vetted for "insider threats." So far, at least, Oracle has not declared how it would handle that issue. Nor did President Trump in his announcement of the deal. Until they do, it will be impossible to know if Mr. Trump has achieved his objective: preventing Chinese engineers, perhaps under the influence of the state, from manipulating the code in ways that could censor, or manipulate, what American users see.
Other questions also remain, including America's larger policy towards other apps like Telegram made by foreign countries. Even Amy Zegart, a senior fellow at the Hoover Institution and Stanford's Freeman-Spogli Institute, complains to the Times that "bashing TikTok is not a China strategy. China has a multi-prong strategy to win the tech race. It invests in American technology, steals intellectual property and now develops its own technology that is coming into the U.S... And yet we think we can counter this by banning an app. The forest is on fire, and we are spraying a garden hose on a bush."

And another article in the Times argues that the TikTok agreement doesn't even eliminate Chinese ownership of the app: Under the initial terms, ByteDance still controls 80 percent of TikTok Global, two people with knowledge of the situation have said, though details may change. ByteDance's chief executive, Zhang Yiming, will also be on the company's board of directors, said a third person. And the government did not provide specifics about how the deal would answer its security concerns about TikTok...

A news release published by Walmart on Saturday on its website — then edited later — captured the chaos. "This unique technology eliminates the risk of foreign governments spying on American users or trying to influence them with disinformation," the company said. "Ekejechb ecehggedkrrnikldebgtkjkddhfdenbhbkuk."

United States

Last-Minute TikTok Deal Averts Shutdown (cbsnews.com) 105

"President Donald Trump said Saturday he's given his 'blessing' to a proposed deal that would see the popular video-sharing app TikTok partner with Oracle and Walmart and form a U.S. company," reports CBS News: Mr. Trump has targeted Chinese-owned TikTok for national security and data privacy concerns in the latest flashpoint in the rising tensions between Washington and Beijing. The president's support for a deal comes just a day after the Commerce Department announced restrictions that if put in place could eventually make it nearly impossible for TikTok's legions of younger fans to use the app. Mr. Trump said if completed the deal would create a new company likely to be based in Texas...

TikTok said Oracle and Walmart could acquire up to a cumulative 20% stake in the new company in a financing round to be held before an initial public offering of stock, which Walmart said could happen within the next year. Oracle's stake would be 12.5%, and Walmart's would be 7.5%, the companies said in separate statements. The deal will make Oracle responsible for hosting all TikTok's U.S. user data and securing computer systems to ensure U.S. national security requirements are satisfied. Walmart said it will provide its ecommerce, fulfillment, payments and other services to the new company. "We are pleased that the proposal by TikTok, Oracle, and Walmart will resolve the security concerns of the U.S. administration and settle questions around TikTok's future in the U.S.," TikTok said in a statement.

"According to a source close to the matter, ByteDance would keep the rest of the shares," reports a public TV station in Australia. "But since the Chinese company is 40 per cent owned by American investors, TikTok would eventually be majority American-owned."

Today America's Treasury Department told CBS that the deal still needs to close with Oracle and Walmart, and those documents and conditions then need to be approved by government regulatory. But because of today's announcement, "the department said Saturday that it will delay the barring of TikTok from U.S. app stores until Sept. 27 at 11:59 p.m."
Java

Oracle's Plan to Keep Java Developers from Leaving for Rust and Kotlin (zdnet.com) 90

ZDNet reports: Oracle has released version 15 of Java, the language created 25 years ago by James Gosling at Sun Microsystems, which Oracle snapped up in 2009 for about $7.4bn to gain what it said was the "most important software Oracle has ever acquired". Java 15, or Oracle Java Development Kit (JDK) 15, brings the Edwards-Curve digital signature algorithm, hidden classes, and former preview features that have been finalized, including text blocks, and the Z Garbage Collector, while the sealed-classes feature arrives and pattern matching and records emerge as a second preview...

In July, Java fell out of RedMonk's top two positions for the first time since 2012 and now resides behind JavaScript and Python in terms of popularity. Tiobe in September ranked Java in second position, behind C and ahead of Python.... But Java is still hugely popular and widely used in the enterprise, according to Oracle, which notes it is used by over 69% of full-time developers worldwide... It counts Arm, Amazon, IBM, Intel, NTT Data, Red Hat, SAP and Tencent among its list of notable contributors to JDK 15. Oracle also gave a special mention to Microsoft and cloud system monitoring service DataDog for fixes...

As part of Java's 25th anniversary, Oracle commissioned analyst firm Omdia to assess its six-month release strategy for Java and whether it would be enough to keep millions of Java developers away from memory-safe alternatives such as Kotlin, the language Google has endorsed for Android development, and Rust, a system programming language that was created at Mozilla. "In Omdia's opinion, the work Oracle began a few years ago in moving to a six-month update cycle and introducing a new level of modularity, puts the vendor in good stead with its constituency of approximately 12 million developers," Oracle said in its report on Omdia's analysis.

"However, Oracle and the Java programming language need an ongoing series of innovative, must-have, and 'delightful' features that make the language even more user friendly and cloud capable. These will keep existing Java developers happy while steering potential Java developers away from newer languages like Rust and Kotlin."

China

Trump To Ban US TikTok and WeChat App Store Downloads on September 20 (theverge.com) 206

The US Commerce Department has issued a new order to block people in the US from downloading the popular video-sharing app TikTok as of September 20th, Reuters first reported Friday. From a report: The full order was published by the Department of Commerce on Friday morning. "Any transaction by any person, or with respect to any property, subject to the jurisdiction of the United States, with ByteDance Ltd," the order reads, "shall be prohibited to the extent permitted under applicable law." It is set to take effect on September 20th. Over the last few weeks, TikTok's Chinese parent company, ByteDance, has been engaged in talks with US companies like Microsoft and Oracle to create a new company, TikTok Global, that would meet the Trump administration's concerns over user data security.
China

China Says TikTok Sale Shows US 'Economic Bullying' (bloomberg.com) 180

A senior Chinese official accused the U.S., which forced the sale of TikTok on national security grounds, of "economic bullying," while lambasting European Union restrictions on Huawei Technologies, in comments highlighting Beijing's increasing assertiveness against what it sees as unfair treatment from Western governments. From a report: "What has happened with TikTok in the United States is a typical act of coercive possession," the head of the Chinese Mission to the EU, Zhang Ming, said. "Some American politicians are trying to build a so-called clean network under the cover of fairness and reciprocity and blah, blah, blah," Ambassador Zhang said in an interview with Bloomberg TV. "This is nothing but economic bullying."

The Bytedance-owned company has come under pressure in the U.S., where President Donald Trump's ban has forced a sale of TikTok's American operations. TikTok submitted a proposal to the Treasury Department over the weekend in which Oracle will serve as the "trusted technology provider," the software company said. Zhang's comments represent an oft-repeated refrain from Beijing, which has accused Washington of targeting Huawei without evidence and called the forced sale of TikTok U.S. "state-sanctioned theft."

Oracle

TikTok Picks Oracle Over Microsoft In Trump-forced Sales Bid (www.cbc.ca) 137

Dave Knott quotes the CBC: The owner of TikTok has chosen Oracle over Microsoft as its preferred suitor to buy the popular video-sharing app, according to a source familiar with the deal.

Microsoft announced Sunday that its bid to buy TikTok was rejected, removing a leading suitor for the Chinese-owned app a week before President Donald Trump promises to follow through with a plan to ban it in the U.S.

The Trump administration has threatened to ban TikTok by mid-September and ordered ByteDance to sell its U.S. business, claiming national-security risks due to its Chinese ownership. The U.S. government worries about user data being funnelled to Chinese authorities.

United States

China Would Rather See TikTok US Close Than a Forced Sale (reuters.com) 55

Beijing opposes a forced sale of TikTok's U.S. operations by its Chinese owner ByteDance, and would prefer to see the short video app shut down in the United States, Reuters reported Friday, citing three people with direct knowledge of the matter. From a report: ByteDance has been in talks to sell TikTok's U.S. business to potential buyers including Microsoft and Oracle since U.S. President Donald Trump threatened last month to ban the service if it was not sold. Trump has given ByteDance a deadline of mid September to finalise a deal. However, Chinese officials believe a forced sale would make both ByteDance and China appear weak in the face of pressure from Washington, the sources said, speaking on condition of anonymity given the sensitivity of the situation. ByteDance said in a statement to Reuters that the Chinese government had never suggested to it that it should shut down TikTok in the United States or in any other markets. Two of the sources said China was willing to use revisions it made to a technology exports list on Aug. 28 to delay any deal reached by ByteDance, if it had to.
Social Networks

Jaron Lanier Thinks Things May Have Gotten Better, or Facebook 'Might Have Won Already' (gq.com) 75

Jaron Lanier helped design "Together" mode for Microsoft Teams, "where he has a post as an in-house seer of sorts," according to a recent profile in GQ. ("Initially he'd conceived of Together mode as a way to help Stephen Colbert — in whose house band Lanier sometimes performs when he's in New York — figure out how to host his show in front of a remote audience...")

But Lanier also "might be the last moral man in Silicon Valley," they write, delving into both his support for universal basic income and his harsh view of social media, which they summarize succinctly: "in exchange for likes and retweets and public photos of your kids, you are basically signing up to be a data serf for companies that can make money only by addicting and then manipulating you."

But GQ also writes that Lanier now sees some signs of hope, describing his current work as "to not fuck the future over, you know?" He said he noticed a change in how Facebook was both thought of and written about. Take the congressional hearings that were held in July with Mark Zuckerberg and other big tech leaders. "What struck me," Lanier later told me, "was how alone the four CEOs were — no friends or allies anywhere in politics or society. They've creeped everyone out with their opaque form of influence. Even Big Tobacco had friends...."

I asked him: Had he noticed a change in his own relationship to technology since the pandemic started? He said that he had. "I think people are spending more time in a self-directed way by connecting with others on video chat or things like that than they are passively receiving a feed," he said. "And so I actually think things have gotten a little better." The fact that people were using computers not to pass time in algorithm-driven loops but to talk to one another, and then perhaps go outside, was a source of optimism for him.

Lanier says he also feels that by provoking real and meaningful questions, some social movements are "reintroducing us to reality..." Technology was doing, as it did every once in a while, what Lanier wanted it to do: giving people a chance to be better, to know more, to lead more informed and compassionate lives... So what about the future? I asked. The thing I'd come to talk about. Was the future going to be okay?

Lanier, in effect, said: Maybe...

Every day Google and Facebook and other tech companies become more powerful and sophisticated by analyzing you and your choices... They don't even really acknowledge that you are contributing, as if artificial intelligence came from nowhere, instead of from data derived from you and me. "In the information age," Lanier said, "we're all workers and consumers and entrepreneurs at the same time." What if, Lanier suggested, we got paid for our labor in this system? By recognizing the roles we play in building the future, Lanier said, we might give ourselves a chance to be meaningful participants in it. "When a person is empowered to make a difference, they become more of a full person," he said. "They awaken spiritually."

That would be the best case. All of us building the robot future together, and being compensated for our time and our work while doing it.

And...the worst case? I asked.

"Facebook might have won already, which would mean the end of democracy in this century," Lanier said. "It's possible that we can't quite get out of this system of paranoia and tribalism for profit — it's just too powerful and it'll tear everything apart, leaving us with a world of oligarchs and autocrats who aren't able to deal with real problems like pandemics and climate change and whatnot and that we fall apart, you know, we lose it. That is a real possibility for this century. I'm not saying I think it's what'll happen, but I wouldn't count it out. There's evidence every single day that it's what's happening...." [D]isinformation goes from Twitter to Fox to the social media feeds of the president, and the cycle begins anew. Look at how powerful these platforms could be, to the point where "the sway of media is more powerful than the experience of reality — that people can be watching hundreds of thousands die from this virus and yet believe it's a hoax at the same time, and integrate those two things. That's the food for evil," Lanier said...

But then, here the two of us were. Him in Berkeley, me in Los Angeles, but still somehow together. A modern miracle most modern people have learned to sneer at. Not Lanier, who still sees the wonder, and the potential, of these stupid fucking screens, no matter what.

Java

What's Missing From Oracle's List of the 25 Greatest Java Apps Ever Written? (oracle.com) 44

On the 25th anniversary of Java, Oracle's director of developer content released a list of the 25 greatest Java apps ever written. This week they shared the responses it got.

"The U.S. National Security Agency was secretly pleased we noticed its Ghidra binary decompilation tool..." The tenor of conversation was both positive and polite. That speaks volumes about the excellent character of Java developers, don't you think? But, developers being who they are, opinions on what should have made the list abounded... Another Twitter commenter said I should have included Cassandra, the Spring Framework, Apache Spark, the Hazelcast open source in-memory data grid, and Apache Kafka....

- Reader Victor Duran suggested a Java app called Swish, which, he said, "made the entire Swedish economy go cashless." Swish handled 25 billion Swedish krona in May 2020; that's a little more than 2.8 billion US dollars. According to a company spokesperson, parts of the back end are written in Java.

- There are many Java games to choose from, of course, but I was called out for not including Runescape and Old School Runescape, two popular Java-based applications that entertain millions to this day...

- As a commenter pointed out, mobile apps for both WordPress and Telegram are written in Java — and Telegram's encrypted, self-destruct chat feature makes it one of the most popular apps in the world with more than 400 million active users....

- In the final category, several researchers at CERN pointed out that some Large Hadron Collider (LHC) software and other data analytics software are written in Java. That includes the LHC Logging Service, which captures and stores the LHC data. As you can see in this 2006 paper, the LHC Logging Service has been using Java for many years.

Oracle

Oracle Loses Appeal in $10 Billion Pentagon Contract Fight (bloomberg.com) 23

A U.S. appeals court rejected Oracle's challenges to the Pentagon's disputed $10 billion cloud-computing contract. From a report: Oracle had raised a number of issues, including allegations of conflicts of interest with Amazon.com, and claims the Pentagon violate its own rules when it set up the contract to be awarded to a single firm. The U.S. Court of Appeals for the Federal Circuit affirmed a lower court ruling that Oracle wasn't harmed by any errors the Pentagon made in developing the contract proposal because it wouldn't have qualified for the contract anyway. Oracle was fighting its exclusion from seeking the lucrative cloud-computing deal, known as the Joint Enterprise Defense Infrastructure, or JEDI. The Pentagon awarded the contract to Microsoft in October over market leader Amazon Web Services. The project, which is valued at as much as $10 billion over a decade, is designed to help the Pentagon consolidate its technology programs and quickly move information to warfighters around the world.
Idle

How Bill Gates Celebrated Warren Buffett's 90th Birthday (cnn.com) 40

The seventh-wealthiest man in the world, Warren Buffett, turns 90 today. Famously the tycoon/philanthropist pledged to give away 90% of his wealth, founding with Bill and Melinda Gates "The Giving Pledge," a campaign urging the world's wealthiest individuals to dedicate the majority of their wealth to giving back. Over $1.2 trillion has now been pledged, with participants including Elon Musk, Ted Turner, Mark Zuckerberg and his wife Priscilla Chan, Oracle co-founder Larry Ellison, and Microsoft's other co-founder, Paul Allen.

CNN reports that Gates "offered a sweet and funny video tribute to his billionaire pal," who besides drinking six cans of Coke each day is also "a notorious dessert-a-holic." Doing his best Martha Stewart impression, and with Randy Newman's "You Got a Friend" playing in the background, Gates made a delicious-looking Oreo cake, complete with Buffett's face on the top, drawn in chocolate icing. In the end of the 60-second video, Gates cuts a slice, puts it on a plate with a fork, and leaves the message "Happy 90th birthday Warren" in Oreo dust...

The cake was a special tribute to Gates' friendship with Buffett. In 2016, Gates recounted a story on his blog about how he caught Buffett eating his favorite dessert for breakfast: Oreos. "One thing that was surprising to learn about Warren is that he has basically stuck to eating what he liked when he was six years old," Gates wrote. "I remember one of the first times he stayed at our house and he opened up a package of Oreos to eat for breakfast. Our kids immediately demanded they have some too. He may set a poor example for young people, but it's a diet that somehow works for him."

The editor of Forbes also joined the celebration: Next year will mark a decade for the Forbes 400 Summit on Philanthropy, our annual meeting of 150 or so of the world's biggest givers and greatest problem-solvers. The impact is enormous, and it wouldn't happen without today's birthday boy, 90-year-old Warren Buffett. In 2011, I pitched the most generous philanthropist ever the idea of turning our definitive wealth ranking from a static list into a club for good. Warren being Warren, he embraced it immediately, strategically and wholeheartedly, and the Summit was born...

The highlight each year is a talk that Warren and I have, usually during lunch... For Warren's big birthday, we dug through nine years of Forbes 400 Summit on Philanthropy video archives to find some of his most inspiring and obscure gems, [each] edited down to 90 seconds or so. Happy Birthday, Warren!

Businesses

Walmart Says It Has Teamed up With Microsoft on TikTok Bid (cnbc.com) 44

Walmart said it's teaming up with Microsoft in a bid for TikTok. From a report: The retail giant confirmed to CNBC that it's interested in buying the tech company. TikTok is nearing an agreement to sell its U.S., Canadian, Australian and New Zealand operations in a deal that's likely to be in the $20 billion to $30 billion range, sources say. It has not yet chosen a buyer, but could announce the deal in coming days, sources say. With Walmart's confirmation, it joins several others bidding on the tech company, including Oracle. Walmart is pursuing the acquisition at a time when it's trying to better compete with Amazon. It plans to launch a membership program, called Walmart+, soon. The subscription-based service is the retailer's answer to Amazon Prime, which includes original TV shows and movies. In a statement, the big-box retailer said TikTok's integration of e-commerce and advertising "is a clear benefit to creators and users in those markets." It did not say how it would use TikTok or whether it would be part of Walmart+.
Microsoft

Microsoft's TikTok Deal Reportedly Ballooned After Trump Intervened (cnbc.com) 44

An anonymous reader quotes a report from CNBC: Microsoft's acquisition talks with TikTok and its Chinese parent company ByteDance "ballooned" this summer after President Donald Trump intervened, according to a report from The New York Times, citing people familiar with the situation. ByteDance is being forced to sell TikTok's U.S. business by the Trump administration, which says the app's current ties to China make it a national security threat. An executive order signed by Trump on Aug. 6 means a sale must go through before Sept. 15. However, TikTok sued the U.S. government on Monday, alleging it was deprived of due process. The lawsuit could delay the ban, giving TikTok more time to get a better deal for the sale.

When the deal talks began, Microsoft is said to have been reluctant to do any kind of large TikTok acquisition, due in part to the rising tensions between the U.S. and China, according to the Times report. However, a minority stake in the wildly popular video sharing app was viewed positively as it may lead to TikTok ditching Google Cloud, which it currently uses, and signing up to Microsoft Azure, instantly making it one of Microsoft's largest cloud customers. TikTok could also be integrated with Microsoft's $7 billion advertising business. Microsoft issued a statement on Aug. 2 about its pursuit to buy TikTok's U.S. business. However, on Aug, 3, Trump said he'd rather Microsoft, valued at $1.6 trillion, purchase the app that is used by 100 million Americans in its entirety. "I think buying 30% is complicated," Trump told reporters in the Cabinet Room at the White House. There are now several other bidders competing with Microsoft, with the main one being enterprise software firm Oracle. Netflix and Twitter have also been contacted by bankers and investors, but it's not clear if they're interested, according to the Times. In any case, deal talks between the parties have "morphed into a big, messy, political soap opera," according to the report.

Privacy

Bridgefy, the Messenger Promoted For Mass Protests, Is a Privacy Disaster (arstechnica.com) 80

Bridgefy, a popular messaging app for conversing with one another when internet connections are heavily congested or completely shut down, is a privacy disaster that can allow moderately-skilled hackers to take a host of nefarious actions against users, according to a paper published on Monday. The findings come after the company has for months touted the app as a safe and reliable way for activists to communicate in large gatherings. Ars Technica reports: By using Bluetooth and mesh network routing, Bridgefy lets users within a few hundred meters -- and much further as long as there are intermediary nodes -- to send and receive both direct and group texts with no reliance on the Internet at all. Bridgefy cofounder and CEO Jorge Rios has said he originally envisioned the app as a way for people to communicate in rural areas or other places where Internet connections were scarce. And with the past year's upswell of large protests around the world -- often in places with hostile or authoritarian governments -- company representatives began telling journalists that the app's use of end-to-end encryption (reiterated here, here, and here) protected activists against governments and counter protesters trying to intercept texts or shut down communications.

[R]esearchers said that the app's design for use at concerts, sports events, or during natural disasters makes it woefully unsuitable for more threatening settings such as mass protests. They wrote: "Though it is advertised as 'safe' and 'private' and its creators claimed it was secured by end-to-end encryption, none of aforementioned use cases can be considered as taking place in adversarial environments such as situations of civil unrest where attempts to subvert the application's security are not merely possible, but to be expected, and where such attacks can have harsh consequences for its users. Despite this, the Bridgefy developers advertise the app for such scenarios and media reports suggest the application is indeed relied upon."

The researchers are: Martin R. Albrecht, Jorge Blasco, Rikke Bjerg Jensen, and Lenka Marekova from Royal Holloway, University of London. After reverse engineering the app, they devised a series of devastating attacks that allow hackers -- in many cases with only modest resources and moderate skill levels -- to take a host of nefarious actions against users. The attacks allow for: deanonymizing users; building social graphs of users' interactions, both in real time and after the fact; decrypting and reading direct messages; impersonating users to anyone else on the network; completely shutting down the network; and performing active man-in-the-middle attacks, which allow an adversary not only to read messages, but to tamper with them as well.
"The key shortcoming that makes many of these attacks possible is that Bridgefy offers no means of cryptographic authentication, which one person uses to prove she's who she claims to be," the report adds. "Instead, the app relies on a user ID that's transmitted in plaintext to identify each person. Attackers can exploit this by sniffing the ID over the air and using it to spoof another user."

The app also uses PKCS #1, an outdated way of encoding and formatting messages so that they can be encrypted with the RSA cryptographic algorithm. "This encoding method, which was deprecated in 1998, allows attackers to perform what's known as a padding oracle attack to derive contents of an encrypted message," reports Ars.
Oracle

Trump Expresses Support for Oracle To Buy TikTok (wsj.com) 65

President Trump voiced support on Tuesday for Oracle to buy the U.S. operations of TikTok, adding a fresh wrinkle to the bidding for the Chinese-owned video-sharing app. From a report: Oracle is a new entrant in the negotiations for TikTok, whose owner ByteDance is facing a fall deadline from the Trump administration to divest itself of its U.S. operations. Oracle, a giant in business software, has had preliminary discussions about teaming with some of ByteDance's existing minority investors to buy TikTok's U.S. operations but it isn't clear how advanced the talks are, said people familiar with the matter. Microsoft said earlier this month it was in negotiations with ByteDance, and that it was coordinating with the White House. Twitter is also exploring a bid, The Wall Street Journal previously reported.

Oracle has closer ties to the White House than most other parties involved in the bidding. Larry Ellison, the company's co-founder, chairman and largest shareholder, earlier this year threw a fundraiser at his house for the president. Chief Executive Safra Catz also worked on the executive committee for the Trump transition team in 2016. Asked Tuesday if Oracle would be a good buyer for TikTok, President Trump said, "Well I think Oracle is a great company and I think its owner is a tremendous guy, a tremendous person. I think that Oracle would be certainly somebody that could handle it."

Programming

'Real' Programming Is an Elitist Myth (wired.com) 283

When people build a database to manage reading lists or feed their neighbors, that's coding -- and culture. From an essay: We are past the New York City Covid-19 peak. Things have started to reopen, but our neighborhood is in trouble, and people are hungry. There's a church that's opened space for a food pantry, a restaurant owner who has given herself to feeding the neighborhood, and lots of volunteers. [...] It's a complex data model. It involves date fields, text fields, integers, notes. You need lots of people to log in, but you need to protect private data too. You'd think their planning conversations would be about making lots of rice. But that is just a data point. The tool the mutual aid group has settled on to track everything is Airtable, a database-as-a-service program. You log in and there's your database. There are a host of tools like this now, "low-code" or "no-code" software with names like Zapier or Coda or Appy Pie. At first glance these tools look like flowcharts married to spreadsheets, but they're powerful ways to build little data-management apps. Airtable in particular keeps showing up everywhere for managing office supplies or scheduling appointments or tracking who at WIRED has their fingers on this column. The more features you use, the more they charge for it, and it can add up quickly. I know because I see the invoices at my company; we use it to track projects.

"Real" coders in my experience have often sneered at this kind of software, even back when it was just FileMaker and Microsoft Access managing the flower shop or tracking the cats at the animal shelter. It's not hard to see why. These tools are just databases with a form-making interface on top, and with no code in between. It reduces software development, in all its complexity and immense profitability, to a set of simple data types and form elements. You wouldn't build a banking system in it or a game. It lacks the features of big, grown-up databases like Oracle or IBM's Db2 or PostgreSQL. And since it is for amateurs, the end result ends up looking amateur. But it sure does work. I've noticed that when software lets nonprogrammers do programmer things, it makes the programmers nervous. Suddenly they stop smiling indulgently and start talking about what "real programming" is. This has been the history of the World Wide Web, for example. Go ahead and tweet "HTML is real programming," and watch programmers show up in your mentions to go, "As if." Except when you write a web page in HTML, you are creating a data model that will be interpreted by the browser. This is what programming is. Code culture can be solipsistic and exhausting. Programmers fight over semicolon placement and the right way to be object-oriented or functional or whatever else will let them feel in control and smarter and more economically safe, and always I want to shout back: Code isn't enough on its own. We throw code away when it runs out its clock; we migrate data to new databases, so as not to lose one precious bit. Code is a story we tell about data.

Oracle

Oracle Enters Race To Buy TikTok's US Operations (ft.com) 78

phalse phace writes: Oracle has entered the race to acquire TikTok [Editor's note: the link may be paywalled; alternative source], the popular Chinese-owned short video app that President Donald Trump has vowed to shut down unless it is taken over by a US company by mid-November, people briefed about the matter have said. The tech company co-founded by Larry Ellison had held preliminary talks with TikTok's Chinese owner, ByteDance, and was seriously considering purchasing the app's operations in the US, Canada, Australia and New Zealand, the people said. Oracle was working with a group of US investors that already own a stake in ByteDance, including General Atlantic and Sequoia Capital, the people added.

Microsoft has been the lead contender to buy TikTok since it publicly said in early August that it had held discussions to explore a purchase of the app's US, Canada, Australia and New Zealand businesses. Microsoft has also seriously considered a bid to take over TikTok's global operations beyond the countries it outlined this month, people briefed on the company's thinking have said. The Redmond, Washington-based company is particularly interested in buying TikTok in Europe and India, where the video app has been banned by Narendra Modi, Indian prime minister. ByteDance is opposed to selling any assets beyond those in the US, Canada, Australia and New Zealand, said a person close to the company.

Slashdot Top Deals