This week: your phone wasn't listening, but your TV is

Also: what a breach number actually counts, Ring's new encryption default, and the Snipping Tool button you have never pressed.

Share

Good morning!

Cox Media Group told advertisers its Active Listening software could pick up conversations through phones, TVs and smart speakers. The FTC found no audio at all and says the service was really reselling email lists bought from data brokers and making up the geotargeting. Three of this week's six main stories got less frightening once I opened the source material. Smart TVs really do sample what's on their screens, and the piece has a table of what the setting is called on each brand and where to look for it.

In this issue:


Cox Media Group told advertisers it was listening to you. The FTC says it never was.

Cox Media Group and two partners sold advertisers a service called Active Listening, pitched as software that could pick up conversations through phones, TVs and smart speakers. The FTC's case says it never collected any audio at all. What it really did was resell email lists bought from data brokers and invent the geotargeting. The $930,000 in redress goes to the small businesses that bought the service, not to anyone whose conversations were supposedly recorded. The tracking that explains the eerie ad is the ordinary kind, and there's a great deal more of it.

Learn


Your smart TV can track what you watch.

The technology is automatic content recognition. Your television samples what's on its own screen, turns it into a fingerprint and matches it against a library, the way Shazam matches a song. Samsung told advertisers its sets take a sample every 500 milliseconds. Researchers at three universities found the traffic still running while a set was being used as an external display, so plugging in a cable box or a console doesn't get you out of it. Every brand calls the setting something different, and the article has a table with the names and where to find them.

Learn


Who is ShinyHunters, and why is that name in every breach letter?

A hacking group claimed it took hundreds of millions of customer records. Somebody loaded the file and counted, and the number came down hard. The first figure in a breach story is almost always a count of rows in a database, and one person can be a hundred rows. Carhartt's 24.9 million came down to 12.9 million once duplicates and test accounts were taken out, and a claimed 14 million Panera records held 5.1 million unique email addresses. The breach still happened either way, and the headline number was never a count of people.

Learn


Ring is throwing away its key to your videos

Ring's new encryption default destroys the company's own copy of your video keys after 24 hours, which closes a door Ring left open for years. Shared clips sit outside that arrangement. The moment a video goes through a share link, the donation tool or Neighbors, it's no longer covered. Police asking Ring for footage get less than they used to, but "Ring can't unlock it" and "police get nothing" are two different sentences. The encrypted file can still be handed over.

News


Does technology make us lonely?

Loneliness gets compared to smoking fifteen cigarettes a day. The researcher behind that number keeps a page on her own website correcting the way people quote it, so I started there. The piece goes through where the figure came from, who the survey data says is loneliest, and what the evidence supports about whether a phone causes any of it. It's the longest thing I've published, and it's a sit-down-with-coffee read rather than a quick one.

Blog


Also this week: a false antivirus warning, an FTC lawsuit over Amazon's ad prices, and 19 browser add-ons gone bad

A Windows pop-up telling you Microsoft Defender Antivirus is turned off is wrong, and Microsoft has confirmed the bug on its own release health page. The FTC and 22 states sued Amazon over a surcharge on ad prices that the states say reaches shoppers; Amazon says there's no evidence of that. Nineteen Chrome and Edge extensions were caught carrying a wallet drainer and a keylogger, five of them bought from their original developers and turned bad in an update. Android 17 adds two network protections, including a carrier-side 2G shutoff aimed at the fake towers behind scam texts.

News


If you only read one: the smart TV piece. It's the one with something to go change tonight, and the control is filed under a different name on every brand.


5-Minute Tech Tip

Windows key + Shift + S dims the screen and lets you drag a box around anything, and the picture goes onto the clipboard ready to paste. That part hasn't changed in years. What's new is the row of buttons across the top of the Snipping Tool: a shape menu that captures one whole window cleanly, a timer for catching a menu before it closes, a Text actions button that pulls the words out of a picture and reads QR codes, and Quick redact, which blacks out email addresses and phone numbers. Windows warns that redact misses street addresses and account numbers, and that warning is correct.


Fresh Trouble

The MyChart results email. An email says your test results are ready, with a sign-in button that opens a copy of the MyChart login page. Epic says a later version tells you to press Windows and R and paste something to unlock the "full report," which installs malware instead. Open the portal from your provider's own site or app. (MyChart)

The parking meter QR code. A sticker carrying somebody else's QR code is pasted over the real one on the meter and sends you to a fake payment page. (FTC)

The dealership with no record of your order. Scammers are copying car dealership websites, taking the deposit, and leaving the buyer to find out at the counter. (FTC)


Scary Headline of the Week

"39 New Methods That Compromise Passkey Authentication"

I've told you to set up passkeys, so a headline counting 39 ways to beat them deserves an answer.

The research is real. A company called Token collected 39 published techniques for getting into an account protected by a passkey.

None of the 39 breaks the cryptography, and the report says so directly. The attacks go after what stands around it: the browser, the password manager, the service that syncs your passkey between devices, the account recovery process, and the person clicking Approve. Most of them are also aimed at corporate logins with an IT department behind them.

Token sells dedicated hardware authenticators, and the report recommends dedicated hardware. The findings stand on their own, and you should know who is making the recommendation.

Verdict: 39 ways to beat a passkey is still not a reason to go back to passwords. Somebody can phish a password out of you in one message, and every one of these 39 needs control of something you own first. Set up passkeys. Then look at how each account lets you recover it, because recovery is the door this research keeps walking through.

Seen a headline this week that scared you? Reply and send it. It might get next week's verdict.


Help Fresh From Cache grow

This newsletter is free and written by one person. If it earns its spot in your inbox, there are two ways to help. Forward this email to one person who might want it, and if it was forwarded to you, subscribe to get your own copy every Tuesday. And if you would rather chip in a few dollars, there is a support page now. Thank you for your support.


Did you go looking for that setting on your TV, and could you find it? Hit reply.

Joel

[ Free every Tuesday, plus the Cache ]
Tech news without having to be tech savvy.
Subscribe ×