Vue normale
-
BleepingComputer
- Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse
Chrome sécurise votre session dans une puce, Firefox dit non
Voici une bonne nouvelle du côté de Chrome puisque ce dernier a commencé à enfermer la clé qui signe votre session dans la puce de sécurité de votre machine, c'est-à-dire le TPM sous Windows, ou la Secure Enclave sous macOS. Le serveur envoie un défi, le navigateur le signe, et la clé privée ne sort jamais du silicium. Ainsi, un cookie de session recopié ailleurs ne suffit donc plus à entrer dans votre compte.
Ça s'appelle DBSC, pour device-bound session credentials et comme le résume Scott Helme, qui vient de déployer le protocole chez Report URI : "*L'attaquant peut voler le cookie, mais il ne peut pas répondre à un défi DBSC en le signant avec la clé privée, qui reste en sécurité sur votre appareil *".
Depuis que la double authentification et les passkeys se généralisent, voler un mot de passe ne rapporte plus grand-chose et c'est pour cela que les attaquants sont passés au cookie de session, un bout de texte qui prouve au site que vous êtes déjà bien connecté.
Ils le récupèrent avec un infostealer, ou avec une page de phishing qui relaie votre vraie connexion, comme le faisait la plateforme Tycoon 2FA démantelée par Europol . Ensuite ils collent le cookie dans leur navigateur et héritent de votre session. Et votre bonne vieille 2FA n'y change rien, puisqu'elle est déjà passée.
Donc ce DBSC c'est une bénédiction, surtout que côté utilisateur, il n'y a rien à activer.
Google a basculé ses propres comptes dessus fin mai, sur Chrome pour Windows, et il n'existe ni réglage administrateur ni réglage utilisateur pour le couper. Pour le reste du web, il faut évidemment que le site ait implémenté le protocole de son côté, et Chrome ne l'ouvre encore qu'à une partie des utilisateurs (dispo à partir de la version 147 sous Windows et 150 sous macOS).
Pour vérifier si c'est en place chez vous, ouvrez les outils de développement (F12) sur un site où vous êtes connecté, votre compte Google par exemple, onglet Application, et cherchez "device bound sessions". Si la ligne apparaît, c'est que c'est actif. Sinon, c'est que le site, votre version de Chrome ou votre machine ne suivent pas encore, et Chrome retombe alors sur la session classique sans rien casser.
Sur Firefox, en revanche, il ne faudra pas l'attendre car Mozilla a acté début août une position officielle négative sur le sujet. Les deux reproches que fait Mozilla c'est que DBSC laisse une fenêtre ouverte pendant laquelle un cookie volé reste utilisable, et que son flux de réauthentification est un protocole ad hoc qui ne colle pas à la gestion normale des cookies.
Mozilla craint aussi qu'on finisse par exiger des sites une attestation matérielle, ce qui limiterait le choix du matos... Google répond que rien de tel n'est prévu, et que faire signer chaque requête s'est révélé infaisable à grande échelle. Mais bon, cette position négative n'interdit pas une implémentation future... On verra bien. Apple, elle, n'a jamais tranché, mais a prévenu que DBSC risquait de compliquer la restauration d'un appareil depuis une sauvegarde.
Bref, aujourd'hui, ça se joue donc sur Chrome, et seulement là où le site a implémenté DBSC, mais je pense que ça s'étendra de plus en plus à l'avenir.
![]()
Qui possède vos médias préférés ?
Aujourd'hui, je tiens à vous présenter cette extension navigateur qui colle le nom du propriétaire à côté des résultats Google dont le média est référencé, aussi bien dans la recherche Web que dans l'onglet Actualités. Ça s'appelle "Qui possède ?" et sa base de référence contient 584 médias français.
Une fois le propriétaire identifié, le badge reste affiché quand vous arrivez sur le site du média.
Au survol du badge, la chaîne de détention se déroule alors en entier, du média jusqu'au propriétaire final, avec la source de l'info. Les données viennent de l'open data d'Acrimed et du Monde diplomatique + les propres recherches de l'auteur de l'extension. Ensuite, les propriétaires sont répartis dans 7 catégories : milliardaire, famille ou propriétaire privé, groupe de presse, banque ou fonds, public, religieux, et indépendant.
Bien sûr, Korben.info est dedans, chez les indépendants, avec moi comme seul propriétaire ^^.
La base est embarquée dans l'extension, disponible sur Chrome, Firefox et Firefox Android et les permissions de celle-ci se limitent au stockage local, à 6 domaines Google et aux sites des médias référencés. Aucun serveur tiers n'est donc appelé et en plus c'est gratuit.
Et s'il manque un média, un bouton apparaîtra même dans les résultats pour le proposer. Bref, installez-la sur Chrome ou Firefox , et signalez les médias qui manquent.
Merci REDMAMBA l'auteur de l'extension pour le partage !
![]()
The Pixel 11’s Coolest New Feature Is Actually 10 Years Old
The Pixel 11 lineup arrived this week with a genuinely great redesign. The camera bar is 40 percent thinner, the glass runs edge to edge, and for the first time in a while a Pixel actually looks like it evolved instead of just got a new coat of paint. And then there’s HiLight, the one piece of new hardware Google actually wants you to talk about. A small LED cluster tucked into the corner of that same camera bar, ready to glow when Gemini is thinking or when someone you love is calling.
It is, in essence, Google finally admitting it missed the old Nexus notification LED and bringing it back. Five colors, a glow for Gemini, a glow for your favorite caller, and that’s the whole feature list on day one. Nothing to complain about here, except that Nothing exists. The London phone brand has spent years turning its own version of this idea into an actual playground, mini-games, custom widgets, an SDK anyone can build on. Google clearly has the engineering muscle to do something just as ambitious with HiLight down the line. It just chose not to, at least not yet.
Designer: Google
![]()
Before we get into that though, credit where it’s due. Hold a Pixel 11 next to a Pixel 10 and the difference is immediate, not the kind that only shows up in marketing photos. The bar sits almost flush now, and Google’s claim that it’s basically bumpless with a case on actually checks out in person. Under that glass, Tensor G6 lands on a 2nm node, Google’s first, promising 25 percent faster browsing, 15 percent quicker app launches, and on-device AI running up to 3.5 times faster while using less power. The Pixel 11 gets a new 48MP main sensor with 56 percent more light sensitivity and a telephoto stretching to 30x Super Zoom. This is a very complete phone before you even get to the Pro models.
![]()
The Pro and Pro XL push further with a 50MP main sensor, a redesigned 48MP telephoto, Portrait Mode at 5x, and 120x Pro Zoom, sitting under a 3,600-nit display that Google claims is twice as scratch resistant as last year’s. Titan M3 adds quantum-safe boot security on top. The Pixel 11 Pro Fold deserves its own mention here too. It shed almost 10 percent of its weight and a millimeter of thickness, down to 10.1mm closed, while Google claims triple the durability thanks to a redesigned gearless hinge. The crease is genuinely harder to spot than last year’s, and the whole thing folds flat enough to stop feeling like a novelty. If you told me a year ago Google would have the most convincing foldable in its own lineup, I would not have believed you.
![]()
Now, the part everyone will bring up regardless of how the rest of this goes: RAM. The Pro and Pro XL start at 12GB in their base 256GB configs, down from 16GB last year, and Google is blaming this on a supplier RAM shortage hitting the entire industry. Memory manufacturers have been shifting production capacity toward AI server chips, and consumer RAM and NAND prices have spiked hard enough this year that people are half-jokingly calling it RAMageddon. It is a real problem, and Google is far from the only phone maker feeling it. Storage doubling to 256GB as a base softens the blow a little, but a $100 price bump alongside a RAM cut is still a hard sell. Fair enough on the supply chain excuse. Less fair asking Pro buyers to pay more for less unless they climb a storage tier.
![]()
Back to HiLight, because it deserves the real estate. That LED cluster sits right where the temperature sensor used to live on older Pixels, which is a strange trade to make for something this limited. Google’s official pitch is that HiLight keeps you informed without the distraction of staring at a screen, which is a very polished way of saying there weren’t enough ideas to fill the space. Glowing when Gemini talks and flashing a color for favorite callers is a fine start, not an entire feature. Compare that to what’s happening across the pond. Nothing’s Glyph Matrix on the Phone (3) packs 489 individually lit LEDs into what functions as a tiny secondary screen, complete with an open SDK that lets anyone build their own widgets and games. People made a working ball maze. A tilt-controlled Magic 8 Ball. A contact dialer you can use without touching the main display. None of it is essential, but all of it is fun, and fun counts for something when you’re asking someone to pay a premium for a light.
![]()
Google clearly has the horsepower for something bigger here. Tensor G6 alone proves the company isn’t short on engineering muscle, and the camera bar redesign shows the industrial design team knows exactly what it’s doing right now. HiLight feels like the output of a team that had a great idea, then stopped one meeting short of making it good. I want to see where this goes in a year or two, because the foundation Google just built, the hardware, the placement, even the name, is genuinely solid. It just needs an actual reason to exist beyond telling you Gemini is thinking.
The post The Pixel 11’s Coolest New Feature Is Actually 10 Years Old first appeared on Yanko Design.
-
Yanko Design

- Google’s Pixel Tag is making the same ‘boring’ design mistake that Apple, Samsung, and Xiaomi made
Google’s Pixel Tag is making the same ‘boring’ design mistake that Apple, Samsung, and Xiaomi made
![]()
The Pixel Tag comes in exactly one color, a grey green called Fog, wrapped around stainless steel with a G logo stamped right on the front. It’s the same script Apple wrote with the AirTag and Samsung copied with the SmartTag2. A tracker spends its entire life clipped to your keys or your dog’s collar or tucked into a backpack pocket, which makes it one of the most personal objects you own. Google, of all companies, knows how to make hardware feel less like hardware. It just didn’t bother here.
Somebody at DJI figured out that a $60 microphone could come with snap-on decals, because apparently even a tiny accessory deserves a little personality. Motorola figured out something similar with the Moto Tag, which actually ships in sage green and a soft blue instead of the usual black or white default. So it’s not like nobody in tech has thought about this. It’s just that almost nobody applies it to trackers, and now Google has joined the long list of companies that had the chance and passed.
Designer: Google
![]()
The excuse I keep hearing, and I use that word deliberately, is durability. Metal survives drops, fabric doesn’t, case closed. Except my phone survives daily abuse inside a woven case, and so does yours, and so does every rugged Kevlar sleeve sold by the millions for devices far more fragile than a coin sized tracker. Nobody worries their phone case is going to disintegrate because it has some texture on it. A tracker being too delicate for color or grip is not a real constraint. It’s a decision that got dressed up as one.
![]()
Underneath that decision is genuinely solid engineering, for what it’s worth. The Pixel Tag measures 1.8 by 1.1 inches and just 5.4mm thick, which makes it noticeably slimmer than the AirTag’s 8mm body. It runs on a replaceable CR2032 battery rated for about a year, carries an IP67 rating for dust and water, and pairs instantly over Fast Pair with any Android 9 device or newer. The headline feature is Ultra Wideband combined with Bluetooth Channel Sounding, which gives you a literal on-screen arrow and distance reading instead of a vague “getting warmer” signal, though that trick needs Android 16 and Bluetooth 6.0 to actually work. It taps into Find Hub, Google’s network of over a billion Android phones, so a lost item can get spotted even when it is nowhere near your own devices. You can share access with up to ten people, ring it from a Pixel Watch, or ask Gemini through your Pixel Buds to ring it for you. All of that ships November 11 for $29, or $99 for a four pack.
![]()
Google already knows how to wrap good engineering in an object people actually want to look at, because it solved the exact same brief years ago with its speakers. The Nest Mini gets a soft, woven top because Google understood people don’t want to display a hunk of bare plastic on their kitchen counter. The Nest Audio does the same thing, fabric front, rounded edges, an object designed to belong in a room rather than announce itself as a gadget in one. That instinct exists inside the same company that just shipped a keychain accessory in one shade of grey with a logo dead center, like it needed to remind you it’s tech.
![]()
A tracker’s entire job is to sit quietly on the stuff you actually care about. It should feel like something you chose, not something you tolerated because the tech underneath happened to be good. Find Hub integration, UWB precision finding, a battery that lasts a year, all of that is genuinely solid work. But solid engineering wrapped in a logo stamped on steel isn’t a finished product. It’s half of one, and Google, weirdly, is the company with the least excuse for stopping there.
The post Google’s Pixel Tag is making the same ‘boring’ design mistake that Apple, Samsung, and Xiaomi made first appeared on Yanko Design.
Google Rolls Out August Android 17 Update With Pixel 10 Stability Fixes
Google's August Android 17 update fixes Pixel 10 gaming, GPU, and touchscreen issues while bringing the latest security patch to supported Pixel devices.
The post Google Rolls Out August Android 17 Update With Pixel 10 Stability Fixes appeared first on TechRepublic.
Android App Advertising SDK Location Data Sharing Explained
Android app teams can inherit location-sharing behavior from advertising SDKs even when consent screens and Play disclosures do not reflect it.
The post Android App Advertising SDK Location Data Sharing Explained appeared first on TechRepublic.
-
Articles on TechRepublic
- Google Pixel 11 Leak Reveals ‘HiLight’ Notification Feature, Raises Questions About Charging Claim
Google Pixel 11 Leak Reveals ‘HiLight’ Notification Feature, Raises Questions About Charging Claim
Leaked Google Pixel 11 marketing materials suggest a new HiLight notification feature, while a five-minute charging claim raises questions ahead of Google's launch.
The post Google Pixel 11 Leak Reveals ‘HiLight’ Notification Feature, Raises Questions About Charging Claim appeared first on TechRepublic.
Gmail’s New Feature Warns You Before Revealing You Were BCC’d
Gmail now warns BCC recipients before they reply all, helping prevent accidental exposure of their involvement and email address.
The post Gmail’s New Feature Warns You Before Revealing You Were BCC’d appeared first on TechRepublic.
Chrome to Block Policy-Abusing Extensions on Personal Devices
Google is developing Chrome protections that could block policy-installed extensions from hijacking New Tab pages and search settings on personal devices.
The post Chrome to Block Policy-Abusing Extensions on Personal Devices appeared first on TechRepublic.
Fitbit Data Can Now Sync Directly With Apple Health
Google Health now sends Fitbit workouts, sleep, steps, and vitals to Apple Health, removing the need for third-party syncing apps.
The post Fitbit Data Can Now Sync Directly With Apple Health appeared first on TechRepublic.
Google Got 800,000 Sign-Ups for an AI App — Then Canceled It
Google canceled its AI Studio mobile app one day before launch despite 800,000 pre-registrations and plans to move app-building features into Gemini.
The post Google Got 800,000 Sign-Ups for an AI App — Then Canceled It appeared first on TechRepublic.
Google Blogger locks hundreds of blogs in malware false positive
Google Chrome may soon block New Tab hijacker extensions by default
Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical
Google Chrome 151 patches 370 security flaws, including seven Critical vulnerabilities. Users on Windows, macOS, and Linux should update now.
The post Google Chrome 151 Patches 370 Vulnerabilities, Including 7 Critical appeared first on TechRepublic.
Google Plans Global Rollout of Privacy-Focused Age Signals API
Google plans to expand its Play Age Signals API globally, helping Android developers tailor app experiences without collecting exact birth dates.
The post Google Plans Global Rollout of Privacy-Focused Age Signals API appeared first on TechRepublic.
-
Articles on TechRepublic
- Google Pixel 11 Explained: What Google Has Confirmed and What the Rumors Say
Google Pixel 11 Explained: What Google Has Confirmed and What the Rumors Say
Google will unveil the Pixel 11 on Aug. 12. Here's what Google has confirmed, what reputable reports suggest, and what remains unknown ahead of launch.
The post Google Pixel 11 Explained: What Google Has Confirmed and What the Rumors Say appeared first on TechRepublic.
5 Google Docs Grammar Check Alternatives Compared for 2026
G Suite Basic, Business, and Enterprise users can now check grammar in Google Docs. Here's a quick look at how well the feature performs compared to alternatives.
The post 5 Google Docs Grammar Check Alternatives Compared for 2026 appeared first on TechRepublic.
Chrome tourne enfin sur Raspberry Pi (si vous savez où cliquer)
Si vous avez un Raspberry Pi et que Chromium commence à vous fatiguer, le VRAI Chrome, celui des chads que vous êtes, est enfin dispo en ARM64 !! Enfin, dispo... Si vous savez où chercher, parce que la page de téléchargement de Google vous propose toujours l'installeur amd64, qui ne tournera jamais sur votre machine. C'est Joey Sneddon, d'OMG! Ubuntu, qui a trouvé la combine en bidouillant l'URL depuis son Pi 5.
Avant toute chose, vérifiez que vous êtes bien en 64 bits, parce qu'un système 32 bits refusera le paquet :
dpkg --print-architecture
Si ça répond arm64, le fichier est là , 126 Mo. Il s'installe comme n'importe quel .deb local, en laissant apt gérer les dépendances :
wget https://dl.google.com/linux/direct/google-chrome-stable_current_arm64.deb
sudo apt install ./google-chrome-stable_current_arm64.deb
Le RPM existe aussi pour les distributions qui préfèrent, en remplaçant la fin du nom par aarch64.rpm.
J'ai ouvert le paquet pour regarder ce qu'il y avait dedans. Son fichier de contrôle annonce google-chrome-stable en version 150.0.7871.186, architecture arm64, un peu plus de 400 Mo une fois installé. Soit exactement la même version que le paquet x86 poussé le même soir. Le même Chrome, à la même révision.
Et le canal stable n'est pas seul. Le dépôt de Google sert aussi la beta (151.0.7922.47), la dev (152.0.7967.2) et la canary (152.0.7974.0) pour les puces ARM, et son fichier Release déclare noir sur blanc les deux architectures. Les quatre canaux ont été publiés dans la même minute que leurs équivalents x86.
Est-ce qu'on se retrouve coincé sur cette version, à re-télécharger le .deb à la main tous les mois ? Non. Le script de post-installation contenu dans le paquet ajoute le dépôt Google en précisant l'architecture, et les cinq paquets y sont indexés en arm64 exactement comme en x86. Les mises à jour ont donc de quoi arriver par apt, comme d'habitude.
Alors pourquoi s'embêter, puisque Chromium tourne sur ARM depuis des années ? Pour deux trucs. D'abord ma synchro du compte Google, qui ramène favoris, mots de passe et extensions. Et ensuite, Widevine, le module DRM, qui est ici un vrai binaire aarch64 et pas une couche de compatibilité comme l'émulateur FEX financé par Valve . Netflix et les autres plateformes à DRM s'ouvriront enfin sur un SBC !!!
Mais avec une nuance à connaître avant de vous réjouir qui est que sous Linux, Widevine reste au niveau "Software Secure". Cela veut dire que sur Netflix, la qualité plafonnera entre 720p et 1080p. De la HD donc et pas de la 4K. Désoléééé !
Google avait promis tout ça en mars, pour le deuxième trimestre et son billet annonçait même une installation via chrome.com/download pour les autres distributions, ce qui est malheureusement le morceau qui manque aujourd'hui.
Cela veut dire aussi que rien ne garantit que ce paquet soit considéré comme étant prêt par ses auteurs donc si votre machine doit rester stable, laissez passer quelques semaines avant de vous y essayer.
Manque plus que quelqu'un chez Google ait le courage d'appuyer sur "publier".
![]()


