Top stories.
- US states sue Meta over claims that it deliberately addicts young users.
- Researchers reverse-engineer French malware used to hack EncroChat.
- An unprecedented number of Apple users received spyware alerts last week.
US states sue Meta over claims that it deliberately addicts young users.
California, Colorado, Kentucky, and New Jersey are suing Meta for $200 billion, alleging that the company intentionally designed Facebook and Instagram to be addictive for children, the New York Times reports. The trial begins today in the US District Court for the Northern District of California, and is expected to last six to eight weeks. Meta will argue that it was truthful to consumers and put safeguards in place to protect children.
The trial is the first bellwether in a series of Federal cases against the company, following several smaller losses by Meta this year involving personal injury cases and consumer protection violations. $200 billion would be the largest penalty in history for a tech company, amounting to nearly fourteen percent of the company's entire stock value.
Researchers reverse-engineer French malware used to hack EncroChat.
Computer Weekly reports that Czech cybersecurity firm Invasys has reverse-engineered the malware French authorities used to hack EncroChat phones in 2020, finding that the French implant relied on the Android "Bad Binder" vulnerability (CVE-2019-2215) and the open-source Frida toolkit. EncroChat was an encrypted phone platform used extensively—but not exclusively—by organized criminal gangs. The 2020 operation led to thousands of convictions in the UK, though details of the hack were previously held by the French government as a matter of national security.
The findings appear to support the position that police obtained messages through device interference rather than by intercepting encrypted communications in transit, which will likely restart a surveillance case before the UK's Investigatory Powers Tribunal looking at the legality of police tactics during the operation.
An unprecedented number of Apple users received spyware alerts last week.
An unusually large number of Apple users received spyware alerts in Cupertino's latest wave of threat notifications, TechCrunch reports. Apple occasionally sends out batches of these notifications to warn users that their devices may have been targeted by state-backed spyware attacks, but last week's batch appears to have been the largest yet.
Mohammed Al-Maskati, director of Access Now, said the nonprofit's Digital Security Helpline is receiving thirty to forty percent more requests than usual following a wave of Apple alerts. Additionally, Citizen Lab researcher John Scott-Railton told TechCrunch, "The scale and geographic diversity of public posts about receiving notifications are pretty unprecedented. For every public notification like this, you can imagine there’s a huge notification iceberg that the public will never learn about. This is a clear indication that something bigger is going on."
Both Al-Maskati and Scott-Railton noted that the increased volume of responses may be due to Apple's new techniques for alerting users: Apple devices now receive spyware alerts on the lock screen, in the Settings app, via email, and on users' Apple Accounts on the web.