It’s always thrilling to receive feedback from someone you respect, even when they disagree with you. https://t.co/Jj4z9zghfx
Shortly after last month’s publication of my piece on the 1994 Budapest Memorandum for @listeningtother, Professor Stephen Kotkin (one of the foremost academics in the world specialising in Russian and Soviet history) wrote to me with the following provocative assertion:
“Ukraine did not give up ‘its’ nuclear weapons. Ukraine had no such weapons. Russia had nuclear weapons on Ukrainian soil. Ukraine gave up Russia’s ability to fire nuclear weapons from the territory of Ukraine.”
Fair enough – after all, can you “own” something you can’t use?
But I’ve spent the last fortnight exploring this question in greater depth, and realised the story (and ongoing debate) is far richer than I would have imagined.
Check out my findings on Ukraine’s contested nuclear inheritance, and the ambiguous relationship between “ownership” and control, here…
As ever, I am indebted to @mbudjeryn and @steven_pifer for their insights and guidance.
Very pleased that my piece on the Budapest Memorandum has been published on @listeningtother
With special thanks to @mbudjeryn@steven_pifer Attila Demkó @WarIntellectual Oleksandr Zaitsev for all their invaluable help on this project.
https://t.co/svHLCFBzlM
Last night, Google announced that it is piloting a new security feature in Singapore (with consent from its government) to combat financial fraud. This new "enhanced fraud protection", part of Google Play Protect, will "analyze and automatically block the installation of apps that may use sensitive runtime permissions frequently abused for financial fraud [RECEIVE_SMS, READ_SMS, BIND_Notifications, and Accessibility] when the user attempts to install the app from an Internet-sideloading source (web browsers, messaging apps or file managers)."
The SMS and notifications permissions can be abused to intercept OTPs sent via SMS or notifications, while the Accessibility permissions can be abused to read and interact with screen content. While this makes sense, one concern I have is how Play Protect will differentiate between apps that are sideloaded by app stores versus apps sideloaded via "standalone app distribution sources" like web browsers or messaging apps. If they're using the same method that Android 13's restricted settings feature uses to differentiate (ie. whether the app was sideloaded via session-based or non-session-based APIs), then it's possible fraudsters can work around this. This should still prove effective, though.
In addition, Google says that Play Protect's real-time scanning behavior is now deployed in Thailand, Singapore, and Brazil. This feature rolled out to Google Play Services in India in October of last year, and Google says that it has identified 515,000 new malicious apps and issued over 3.1 million warnings or blocks.
Google Play Protect is adding real-time scanning for app installs!
Starting today, Play Protect will prompt users to perform a real-time, code-level scan when users install an app that has never been analyzed before by Google.
This scanning will extract important signals from the app and send them to the Play Protect backend for a code-level evaluation. Once the real-time analysis is done, users will get a result letting them know if the app looks safe to install or is potentially harmful.
Real-time app scanning will help combat malicious polymorphic apps that change their identifiable features to avoid detection. According to Google, Play Protect currently conducts real-time checks to warn users when it identifies an app known to be malicious from previous scans or was identified as potentially harmful from Google's "on-device machine learning, similarity comparisons, and other techniques that [they] are always evolving."
This is starting to roll out to all Android devices with Google Play Services in India first but will expand to all regions "in the coming months." According to the Google System Updates changelog, this feature is available as part of Google Play Store version 37.5.