Developer Uses iOS 16 Exploit To Change System Font Without Jailbreak

A developer managed to use an exploit found in iOS 16 to change the default font of the system without jailbreak. 9to5Mac reports: Zhuowei Zhang shared his project on Twitter, which he calls a “proof-of-concept app.” According to Zhang, the app he developed uses the CVE-2022-46689 exploit to overwrite the default iOS font, so that users can customize the system’s appearance with a different font other than the default (which is San Francisco). The CVE-2022-46689 exploit affects devices running iOS 16.1.2 or earlier versions of the operating system, and it basically lets apps execute arbitrary code with kernel privileges. The exploit was fixed with iOS 16.2, which also fixed a bunch of other security breaches found in the previous version of iOS.

Since iOS has its own font format, the developer performed the experiment using only a few fonts, including DejaVu Sans Condensed, Serif, Mono, and Choco Cooky. And in case you’re wondering, Choco Cooky is the weird font that used to come pre-installed by default on Samsung smartphones. Now you can finally have it on your iPhone. Zhang explains that the process should be safe for everyone, since all changes are reversed after rebooting the device. Still, the developer recommends users trying out the app to back up their devices before replacing the default system font. He also details that the change only affects some of the text on iOS, as other parts of the system use different fonts. More details about the project, including its source code, are available on GitHub.

Read more of this story at Slashdot.

The Worst-Selling Microsoft Software Product of All Time: OS/2 for the Mach 20

Raymond Chen, writing for Microsoft DevBlogs: In the mid-1980’s, Microsoft produced an expansion card for the IBM PC and PC XT, known as the Mach 10. In addition to occupying an expansion slot, it also replaced your CPU: You unplugged your old and busted 4.77 MHz 8088 CPU and plugged into the now-empty socket a special adapter that led via a ribbon cable back to the Mach 10 card. On the Mach 10 card was the new hotness: A 9.54 MHz 8086 CPU. This gave you a 2x performance upgrade for a lot less money than an IBM PC AT. The Mach 10 also came with a mouse port, so you could add a mouse without having to burn an additional expansion slot. Sidebar: The product name was stylized as MACH [PDF] in some product literature. The Mach 10 was a flop.

Undaunted, Microsoft partnered with a company called Portable Computer Support Group to produce the Mach 20, released in 1987. You probably remember the Portable Computer Support Group for their disk cache software called Lightning. The Mach 20 took the same basic idea as the Mach 10, but to the next level: As before, you unplugged your old 4.77 MHz 8088 CPU and replaced it with an adapter that led via ribbon cable to the Mach 20 card, which you plugged into an expansion slot. This time, the Mach 20 had an 8 MHz 80286 CPU, so you were really cooking with gas now. And, like the Mach 10, it had a mouse port built in. According to a review in Info World, it retailed for $495. The Mach 20 itself had room for expansion: it had an empty socket for an 80287 floating point coprocessor. One daughterboard was the Mach 20 Memory Plus Expanded Memory Option, which gave you an astonishing 3.5 megabytes of RAM, and it was high-speed RAM since it wasn’t bottlenecked by the ISA bus on the main motherboard. The other daughterboard was the Mach 20 Disk Plus, which lets you connect 5 1/4 or 3 1/2 floppy drives.

A key detail is that all these expansions connected directly to the main Mach 20 board, so that they didn’t consume a precious expansion slot. The IBM PC came with five expansion slots, and they were in high demand. You needed one for the hard drive controller, one for the floppy drive controller, one for the video card, one for the printer parallel port, one for the mouse. Oh no, you ran out of slots, and you haven’t even gotten to installing a network card or expansion RAM yet! You could try to do some consolidation by buying so-called multifunction cards, but still, the expansion card crunch was real. But why go to all this trouble to upgrade your IBM PC to something roughly equivalent to an IBM PC AT? Why not just buy an IBM PC AT in the first place? Who would be interested in this niche upgrade product?

Read more of this story at Slashdot.

Customers React to McDonalds’ Almost Fully-Automated Restaurant

“The first mostly non-human-run McDonald’s is open for business just outside Fort Worth, Texas,” reports the Guardian. CNN calls it “an almost fully-automated restaurant,” noting there’s just one self-service kiosk (with a credit card reader) for ordering food.

McDonalds tells CNN there’s “some interaction between customers and the restaurant team” when picking up orders or drinks. But at the special “order ahead” drive-through lane, your app-ordered bag of food is instead delivered to a platform by your car’s window using a vertical conveyor belt.

CNN reports that it’s targetted to customers on the go. For example, there’s dedicated parking spaces outside for curbside pickup orders, while inside there’s a room with bags to be picked up by food-delivery couriers (who also get their own designated parking spaces outside). But for regular customers, CBS emphasizes that “ordering is done through kiosks or an app — no humans involved there, either.”
But not all customers are loving it. “Well there goes millions of jobs,” one commenter on a TikTok video said about the new restaurant said.

“Oh no first we have to talk with Siri and Google [and] now we have to talk to another computer,” another one opined.

“I’m not giving my money to robots,” another commenter wrote. “Raise the minimum wage!”
Other customers had more personal concerns, expressing worries about how they could get their order fixed if it was incorrectly prepared or how to ask for extra condiments. “And if they forget an item. Who you supposed to tell, the robot? It defeats the purpose of using the drive thru if you have to go inside for it,” one consumer noted….

To be sure, not everyone had negative views about the concept. Some customers expressed optimism that the automated restaurant could improve service and their experience.

Read more of this story at Slashdot.

Did YouTube Pay Too Much to Broadcast Sunday Football Games?

Subscribers to “NFL Sunday Ticket” can watch broadcasts of every Sunday game of American football. But for access next season, “fans will have to Google it…” warns the Associated Press — because Thursday the football league announced plans to distribute their game package on YouTube TV and YouTube Primetime Channels.
Google beat out both Apple and Amazon by offering over $2 billion a year for 7 years — but Yahoo Finance believes it’s more about drawing attention to YouTube’s streaming TV services. “Don’t expect the package to be profitable, one analyst warned.”

“They’re not making money on this — this is a loss leader,” Michael Pachter, managing director of equity research at Wedbush, told Yahoo Finance Live, referencing YouTube TV’s current price point of $64.99. “I don’t think they make a penny at that level….”

“It’s an extremely expensive package of content,” Tim Nollen, analyst at Macquarie Group, previously told Yahoo Finance Live, noting the Sunday Ticket package was not a profitable service for DirecTV [which since 1994 has held the exclusive broadcast rights in the U.S.]

[…] YouTube TV has more than 5 million subscribers and trial users as of July. “Five million subscribers is just not enough,” Pachter stressed. “Even if all 5 million pay the $400 bucks a year…they’re going to barely cover their costs.” Still, despite the lack of profitability and sky-high price tag, Pachter noted YouTube might be best positioned to take advantage of the package, especially as the demand for live sports escalates. “I think they can be smart about how they carve up the content,” Pachter said, suggesting the platform could more easily sell games to bars and restaurants.

Read more of this story at Slashdot.

TikTok Spied On Forbes Journalists

ByteDance confirmed it used TikTok to monitor three journalists’ physical location using their IP addresses, reports Forbes, “to unearth the source of leaks inside the company following a drumbeat of stories exposing the company’s ongoing links to China.”

As a result of the investigation into the surveillance tactics, ByteDance fired Chris Lepitak, its chief internal auditor who led the team responsible for them. The China-based executive Song Ye, who Lepitak reported to and who reports directly to ByteDance CEO Rubo Liang, resigned…. “It is standard practice for companies to have an internal audit group authorized to investigate code of conduct violations,” TikTok General Counsel Erich Andersen wrote in a second internal email shared with Forbes. “However, in this case individuals misused their authority to obtain access to TikTok user data….”

“This new development reinforces serious concerns that the social media platform has permitted TikTok engineers and executives in the People’s Republic of China to repeatedly access private data of U.S. users despite repeated claims to lawmakers and users that this data was protected,” Senator Mark Warner told Forbes….

ByteDance is not the first tech giant to use an app to monitor specific users. In 2017, the New York Times reported that Uber had identified various local politicians and regulators and served them a separate, misleading version of the Uber app to avoid regulatory penalties…. Both Uber and Facebook also reportedly tracked the location of journalists reporting on their apps.

Ironically, TikTok’s journalist-tracking project involved the company’s Chief Security and Privacy Office, according to Forbes, and targeted three Forbes journalists who had formerly worked at BuzzFeed News.

It was back in October that Forbes first reported ByteDance had discussed tracking journallists. ByteDance had immediately denied the charges on Twitter, saying “TikTok has never been used to ‘target’ any members of the U.S. government, activists, public figures or journalists,” and that “TikTok could not monitor U.S. users in the way the article suggested.”

Forbes also notes that in 2021, TikTok became the most visited website in the world. Thanks to long-time Slashdot reader newbie_fantod for submitting the story!

Read more of this story at Slashdot.

NORAD Answers Questions About Their Annual Santa-Tracking Operation

The North American Aerospace Defense Command is a US/Canada organization protecting the air sovereignty of the two nations.

But every year on December 24th, they also tell you where Santa is. From NORADSanta.org:

The modern tradition of tracking Santa began in 1955 when a young child accidentally dialed the unlisted phone number of the Continental Air Defense Command Operations Center upon seeing an newspaper advertisement telling kids to call Santa. The Director of Operations, Colonel Harry Shoup, answered the phone and instructed his staff to check the radar for indications of Santa making his way south from the North Pole…. Each year since, NORAD has dutifully reported Santa’s location on Dec. 24 to millions of children and families across the globe. NORAD receives calls from around the world on Dec. 24 asking for Santa’s location. Children, families and fans also keep track of Santa’s location on the NORAD Tracks Santa® website and our social media platforms.

The page lists the NORAD technologies involved in tracking Santa — including 47 radar installations and geo-synchronous satellites with infrared heat sensors. (“Rudolph’s nose gives off an infrared signature similar to a missile launch…”)
And this year NORAD also produced a special video highlighting the various military fleets protecting Santa. (“He may know when you’re sleeping, he may know when you’re awake… ” it tells viewers. “But for 67 years now, when he takes flight, we’ll know.”)

More from NORADSanta.org:
Canadian NORAD fighter pilots, flying the CF-18, take off out of Newfoundland and welcome Santa to North America. Then at numerous locations in Canada other CF-18 fighter pilots escort Santa. While in the United States, American NORAD fighter pilots in either the F-15s, F16s or F-22s get the thrill of flying with Santa and the famous Reindeer…

Q: How can Santa travel the world within 24 hours?

A: NORAD intelligence reports indicate that Santa does not experience time the way we do. His trip seems to take 24 hours to us, but to Santa it might last days, weeks or even months. Santa would not want to rush the important job of delivering presents to children and spreading joy to everyone, so the only logical conclusion is that Santa somehow functions within his own time-space continuum….

How does Santa get down chimneys?

Although NORAD has different hypotheses and theories as to how Santa actually gets down the chimneys, we don’t have definitive information to explain the magical phenomenon.

Do your planes ever intercept Santa?

Over the past 65 years, our fighter jets (F-16s, F-15s, F-22s and CF-18s) have intercepted Santa many, many times. When the jets intercept Santa, they tip their wings to say, “Hello Santa! NORAD is tracking you again this year!” Santa always waves. He loves to see the pilots…!

How many people support this effort, and are they active duty military personnel?

More than 1,250 Canadian and American uniformed personnel and DOD civilians volunteer their time on December 24th to answer the thousands of phone calls and emails that flood in from around the world. In addition to the support provided by our corporate contributors to make this program possible, NORAD has two lead project officers who manage the program.
How much money is spent on this project?

The NORAD Tracks Santa program is made possible by volunteers and through the generous support of corporate licensees who bear virtually all of the costs.
Corporate contributors include Microsoft (with separate contributions from Microsoft’s search engine Bing and from Microsoft Azure), AWS (and Amazon’s Alexa), Verizon, and HP.

NORADSanta.org also boasts extra features like an “arcade” of online games, a jukebox of Christmas tunes, and a library of online books about Santa. And the site even provides some technical data on the weight of Santa’s sleigh — although the unit of measurement used is gumdrops.

Read more of this story at Slashdot.