practices

Winsage
May 15, 2025
Developers are focusing on optimizing applications for the newly launched Copilot+ PCs, which feature advanced system architecture, all-day battery life, and the ability to run AI models directly on the device. The initial Copilot+ PCs are powered by Snapdragon X Elite and X Plus silicon, with AMD and Intel also introducing compatible processors. Microsoft’s App Assure Program provides guidance and technical support to help developers optimize applications for these devices, particularly for Arm-based Snapdragon X Series devices. NordVPN is a notable example of a company that successfully utilized the App Assure program to develop an Arm-optimized version of their application. The program includes the Arm Advisory Service, which allows developers to consult with Microsoft engineers for a smoother development process. Other companies, such as Proton VPN and F-Secure, have also benefited from the App Assure team in optimizing their applications for the Windows on Arm platform.
Winsage
May 14, 2025
Microsoft has addressed a zero-day vulnerability in the Windows Desktop Window Manager (DWM) Core Library, identified as CVE-2025-30400, which allows attackers to gain SYSTEM-level privileges on affected systems. This "Elevation of Privilege" vulnerability, arising from a "use-after-free" memory corruption issue, was actively exploited prior to the release of a patch on May 13, 2025. The vulnerability permits an authorized attacker to execute code with SYSTEM privileges by exploiting improper memory management within the DWM process. Microsoft classified the severity of this vulnerability as "Important" and assigned it a CVSS score of 7.8. Users and administrators are strongly advised to apply the latest updates to mitigate the risk of exploitation.
AppWizard
May 14, 2025
Nextcloud, a European software vendor, has raised concerns about Google's treatment of its Android Files application, which has over 800,000 users. The issue centers on the "All files access" permission, which was revoked by the Play Store in 2024, impairing the app's functionality. Nextcloud argues that alternatives like the Storage Access Framework (SAF) and MediaStore API are inadequate for their needs. The app has been able to read and write all file types since its launch in 2016 without security concerns from Google until the recent revocation. Nextcloud claims that Google's policies are stifling competition and that they have faced bureaucratic inefficiencies in addressing their complaints. Despite having a fully functional version on F-Droid, the Google Play version is restricted. Nextcloud has previously lodged a complaint with the EU regarding Microsoft's anti-competitive behavior, and they express frustration over the lack of action taken. They believe larger tech companies are trying to suppress smaller competitors.
AppWizard
May 13, 2025
Michael Waltz, the former national security adviser, mistakenly included a journalist in a sensitive chat on Signal during a cabinet meeting, raising concerns about communication practices among senior officials. A photograph captured him using a different messaging app that promotes archiving for record-keeping, which raises compliance questions with federal regulations. Visible contacts on his screen included Vice President JD Vance, special envoy Steve Witkoff, Secretary of State Marco Rubio, and Director of National Intelligence Tulsi Gabbard. The use of encrypted messaging apps like Signal complicates the National Archives' role in preserving governmental records, highlighting the tension between secure communication and the need for transparency in government operations.
AppWizard
May 13, 2025
Effective management of a community group involves monitoring posts to ensure alignment with the group's values, promptly approving member requests, engaging with members through comments and insights, using moderation tools like post approvals to maintain a respectful environment, and finding the right balance of control to suit the group's dynamics.
Winsage
May 12, 2025
Microsoft is advocating for the use of React Native to simplify Windows desktop development, promoting it as a viable solution for building native applications. React Native, originally developed by Facebook, allows code written in JavaScript to be rendered natively on iOS and Android, and Microsoft aims to extend these benefits to Windows. The company is addressing developer confusion by providing guidance and resources for integrating React Native into Windows development. Microsoft is also investing in enhancing React Native's capabilities for Windows, including performance improvements and library expansions, to attract and retain developers.
AppWizard
May 10, 2025
A sophisticated ad fraud scheme called Kaleidoscope is affecting over 2.5 million Android devices each month, with India accounting for 20% of the total impacted devices. Other countries experiencing the effects include Brazil, Indonesia, and the Philippines. The scheme spreads through unofficial app stores and direct download links shared on social media and messaging platforms.
Tech Optimizer
May 9, 2025
Antivirus software collects various types of data to protect systems, including system details (operating system version, RAM, CPU type, computer name), network data (local and external IP addresses, DNS server, network name), user data (Windows username, time zone, language, general location), browsing history (if web protection features are enabled), and file-related information (file names, locations, hashes, and sometimes entire files). The AV-Comparatives report indicates that while some antivirus companies manage data responsibly (e.g., F-Secure, G Data, K7), others (e.g., Norton, Panda, McAfee) have been criticized for poor practices. Data sharing can enhance malware detection but poses privacy risks, as seen in AVG's past actions of selling user browsing history. Users can limit data collection by adjusting settings, reviewing installation agreements, avoiding free antivirus software, choosing privacy-conscious vendors (like F-Secure, ESET, G Data), and reading privacy policies. Despite concerns about data collection, antivirus software is essential for protection against cyber threats, and selecting a transparent provider can help safeguard privacy.
Winsage
May 8, 2025
As Windows 10 approaches its End of Life in October 2025, the ‘End of 10’ project advocates for transitioning to Linux for users with older PCs that cannot upgrade to Windows 11. The initiative emphasizes the environmental benefits of extending the lifespan of existing devices, highlighting that computer production accounts for over 75% of carbon emissions during its lifecycle. It also points out that Linux offers greater privacy and control compared to Windows 11, as well as cost efficiency since it is free and future updates remain free if the chosen distribution is supported. While there are concerns about the learning curve and potential software compatibility issues, the project encourages users to seek support from online forums or local repair shops. The Linux community is noted for its willingness to assist newcomers, making it a viable alternative for older PCs that cannot support Windows 11.
AppWizard
May 8, 2025
U.S. National Security Advisor Mike Waltz was seen using a modified version of the messaging app Signal during a Cabinet meeting, despite President Donald Trump's prior discouragement of its use after the "Signalgate" controversy. A photograph showed Waltz with the app active and conversations involving at least six officials, including Vice President JD Vance and Secretary of State Marco Rubio, indicating ongoing discussions. White House spokeswoman Anna Kelly confirmed that Signal is an approved application for government use, and the modified version appeared to be associated with TeleMessage, a company that provides archiving services for messaging applications. This adaptation raises concerns about the integrity of Signal's end-to-end encryption due to potential external storage of messages, which could compromise privacy. TeleMessage has ties to military intelligence and was recently acquired by Smarsh. The use of Signal by Trump administration officials has been controversial in the past, particularly regarding military discussions that inadvertently involved a journalist.
Search