May 13, 2016

Five Steps to a Squeaky-Clean Online Identity

Five steps to managing your online identity and ensuring that when someone Googles you, they see the personal brand you build.
By William Arruda
Five_Steps_to_a_Squeaky-Clean_Online_Identity.png


In 2004, I delivered a personal-branding presentation that, for the first time, included a slide that asked the question: “If you don’t show up in Google, do you exist?” That slide got a huge audience reaction and has been in virtually every presentation I have delivered since.
The answer to the question is no, at least as far as hiring managers and executive recruiters are concerned.
But what if you do show up in Google, and what Google reveals is either unflattering or inconsistent with how you want to be known?
Googling (performing a Google search on someone) is quickly becoming the standard reference check in job searches and a key filter hiring managers and executive recruiters use to evaluate and cull candidates. Studies reveal that executive recruiters Google candidates and have eliminated candidates from the running based on their Google results. So knowing what Google says about you is important, and proactively managing your online identity is an essential element in your job-search strategy.
For $100K+ earners like yourself, you don’t have the same concern about beer-funnel photos that younger managers do, but that doesn’t mean that your online profile is squeaky clean.
There could be content online that does not represent who you are and what you have to offer prospective employers. We call this undesirable content “digital dirt.” Digital dirt includes any Web-based content that will prevent you from reaching your goals.
There are two kinds of dirt:

1. Self-posted dirt.
That’s right, you may have muddied up your own profile. The good news is that most of this self-created content can be easily vacuumed up. But it’s important to note what constitutes “dirt.” Remember, it is not just outright negative or inappropriate content that qualifies as dirt; if you have revealed a little too much about your political views or posted a comment to someone’s blog that is replete with typos and misspellings, you might be removing yourself from consideration for some jobs.
Too much content about what you did in a previous life can also impede your prospects. Be sure virtually everything you post on the Web reflects your unique value and positions you for the role you seek to fill.

2. Dirt posted by others.
This is a much more insidious kind of dirt and typically much harder to clean up. I once had a client who was fired from his investment-industry job, and a Wall Street Journal story about the seemingly fraudulent transactions in which his company was involved included his name. In fact, the word “fraud” was only three words away from his name in the Google description! It was a major problem for him since this data showed up as the first item in a Web search on his name. He was unable to get the Wall Street Journal to remove the story from its Web site.
Like it or not, today your Google results are as important as your resume or cover letter. So as you seek your next role, you must focus on building and maintaining an accurate and compelling online profile. Here’s the five-step process for managing your online identity — sweeping up as much digital dirt as possible.

Step 1: Know what’s out there.
The first step to resolving most challenges is to get the right information. In this case, the information you need is available just by Googling yourself (also known as “ego-surfing”). To help make sense of your Google results, use this free tool: www.onlineidcalculator.com. When evaluating your results, focus on the first three pages of results. Those who perform Google searches rarely look beyond Page Three. Once you know what is out there and where you fall on the digital scale, you can make a plan to address it.

Step 2: Know what you want your Google results to say. 
Now that you know what is out there, you need to think about what you want your Google results to look like. You can’t get from here to there if you don’t know what “there” looks like. It’s time to uncover and define your personal brand. You need to answer these questions:
  • What do you want to be known for?
  • What makes you stand out from all your peers?
  • What’s your area of expertise/thought leadership?
  • What words do you want people to use to describe you?
  • What are your greatest accomplishments?
Learn more about personal branding here: http://www.reachpersonalbranding.com/about/personal-branding/.

Step 3: Clean up the dirt and enhance your digital image.
If you posted anything that might be considered inappropriate or perhaps comes from a past life, remove it. If you have dirt that was posted by others, first ask those who posted it if they will remove it. If you can’t wipe your digital identity clean, you must create enough high-ranking content to move that dirt beyond page three (Steps 4 and 5 below); or, you must at least ensure the “clean” sits alongside the dirt so people have a better understanding of who you are.

Step 4: Build your own place on the WWW.
The best way to get people to understand exactly who you are is to tell your own story. First, you must buy your own domain name — e.g., www.williamarruda.com. You can buy domains at www.godaddy.com. Then you can build (or have built for you) a personal Web site. Blogging platforms such as TypePad and WordPress are great tools for building a Web site — even if you choose not to blog. Remember to include:
  • Your bio
  • A professionally taken headshot
  • Links to all relevant content on the Web about you (making it a one-stop shop),
  • Testimonials from people who have worked with you
  • Proof of performance (PDFs of presentations, video, audio clips, and so on.)
  • Links to Web sites and content on the Web that you think are valuable and help showcase your area of expertise or thought leadership.
Ensure your site content and style reflect your personality. Use color, fonts and imagery to bolster your brand attributes.

Step 5: Use Web 2.0 tools to enhance your online ID.
If you aren’t ready for your own Web site or would like to increase your volume of Google results, take advantage of all the social-networking sites that are available — like LinkedIn, Naymz, Ziki and Ziggs (and countless others). Include your branded bio, professional headshot and other relevant information. You need not use the social networking aspects of these sites (in fact, you won’t have the time to be an active participant on all these sites), so use LinkedIn for networking and the others to enhance your online ID.
In addition, find blogs related to your area of expertise (www.technorati.com is a blog search engine that will help you find relevant blogs by keywords), and subscribe to them. Then append relevant comments to blog posts when you have something valuable to contribute. This becomes part of your online identity.
Of course, your Google results change all the time, so you need to be vigilant. I suggest Googling yourself weekly and subscribing to Google Alerts for your name (www.google.com/alerts). Then, every time something shows up on the Web with your name on it, you’ll be the first to know.

William_Arruda.jpgCredited with turning the concept of personal branding into a global industry, William Arruda is the founder of Reach Personal Branding and author of "Career Distinction" and the upcoming book, "Ditch. Dare. Do!" You can learn more about him at www.personalbranding.tv.










Source: http://info.theladders.com/career-advice/5-steps-squeaky-clean-online-identity?utm_source=wednesday_newsletter_email&utm_medium=email&utm_content=guest_article_william_arruda&utm_campaign=wednesday_newsletter

New Attack Reported by Swift Global Bank Network

Thieves have again found their way into what was thought to be the most secure financial messaging system in the world and stolen money from a bank. The crime appears to be part of a broad online attack on global banking.

New details about a second attack involving Swift — the messaging system used by thousands of banks and companies to move money around the world — are emerging as investigators are still trying to solve the $81 million heist from the central bank of Bangladesh in February. In that robbery, the attackers were able to compel the Federal Reserve Bank of New York to move money to accounts in the Philippines.

The second attack involves a commercial bank, which Swift declined to identify. But in a letter Swift plans to share with its users on Friday, the messaging network warned that the two attacks bore numerous similarities and were very likely part of a “wider and highly adaptive campaign targeting banks.”

The unusual warning from Swift, a copy of which was reviewed by The New York Times, shows how serious the financial industry regards these attacks to be. Some banking experts say they may be impossible to solve or trace. Swift said the thieves somehow got their hands on legitimate network credentials, initiated the fraudulent transfers and installed malware on bank computers to disguise their movements.

“The attackers clearly exhibit a deep and sophisticated knowledge of specific operation controls within the targeted banks — knowledge that may have been gained from malicious insiders or cyberattacks, or a combination of both,” Swift said in its warning, which is expected to be posted on a secure part of its website on Friday.
Security experts who have studied the attacks said the thieves probably were lurking inside the bank systems for months before they were detected.

In its warning, Swift pointed to another worrying situation: that the gang of thieves may have been able to recruit bank employees to hand over credentials and other key details.
In both cases, the core messaging system of Swift was not breached; rather, the criminals attacked the banks’ connections to the Swift network. Each bank is responsible for maintaining the security of its connection to Swift. Digital criminals have found ways to exploit loopholes in bank security to obtain login credentials and dispatch fraudulent Swift messages.
“As a matter of urgency, we remind all customers again to urgently review controls in their payments environments,” Swift urges its customers in the letter to be sent on Friday.
Banks — like many major corporations — are constantly under attack by criminals, seeking to find the weak point in their defenses. An attack in the summer of 2014 on JPMorgan Chase compromised the accounts of 76 million households and seven million small businesses, but no money was stolen. Thieves frequently steal bank customer’s A.T.M. and credit card credentials.
But these attacks involving Swift stand out, because millions of dollars were stolen — not from a large number of customers, but from the banks themselves. It is as if the thieves used their hacking skills to reach inside a bank vault.

Emboldened and enriched, the thieves are likely to strike again, security experts predict.
“An event like this changes the risk profile for the banking system, since the attackers will inevitably reinvest some of their profits in new large-scale attacks,” said Paul Kocher, a security and encryption expert who is the president of Cryptography Research, a division of Rambus.
Initially, many banks and security experts dismissed the Bangladesh attacks as brazen, but probably isolated, events in a developing country. A stream of news reports from the capital of Dhaka cited rudimentary technology at Bangladesh Bank, like a $10 router and an absence of firewalls. Bangladesh officials have blamed the New York Fed, saying it failed to block the fraudulent transfers.

On Tuesday, representatives from Swift, the New York Fed and Bangladesh Bank met in Basel, Switzerland, to discuss the breach and the vulnerabilities it exposed in the system.
In a joint statement, the three sides said they had agreed to cooperate in trying to “bring the perpetrators to justice, and protect the global financial system from these types of attacks.”
But the details of the second attack — which Swift said occurred in the last few months — suggested a highly sophisticated threat that did not necessarily hinge on weak digital defenses. Swift declined to say how much money was stolen from the bank, which was not located in Bangladesh.

Somehow the thieves obtained a valid Swift credential that allowed them to “create, approve and submit” messages on the network. Those messages — sent from PCs in the bank’s back offices or from laptops — were then used to move money from one of the bank’s accounts.
Many banks have a system of checks and balances by which they can validate and review transactions to root out fraud.

But in this latest case, the thieves used a form of malware that targeted a PDF reader that the bank used to confirm that payments had been made. The malware, according to Swift, then manipulated the PDF to “remove traces of the fraudulent instructions.”
That the thieves knew that the bank used a PDF program to confirm its payments shows the level of detail gleaned about how the particular system worked. At Bangladesh Bank, Swift transactions were tracked using physical printouts. So the thieves tailored their malware in that attack to interfere with the printer and cover their tracks.
The attacks have been a major headache for the ubiquitous and publicity-shy Swift, an acronym for the Society for Worldwide Interbank Financial Telecommunication. Based in Belgium, Swift is partly owned and overseen by the world’s biggest banks, which have used the technology to facilitate money transfers since the 1970s. It prides itself on not disclosing any information about its users.

After the attacks, Swift has had to walk a fine line trying to shore up confidence in the security of its network among its 11,000 users, while urging those members to take additional security measures to defend against future attacks.

“Your first priority should be to ensure that you have all the preventative and detective measures in place to secure your own environment,” Swift said in its message. “This latest evidence adds further urgency to your work.”Nicole Perlroth contributed reporting.

Source: http://www.nytimes.com/2016/05/13/business/dealbook/swift-global-bank-network-attack.html

May 1, 2016

Hackers’ $81 Million Sneak Attack on World Banking

Michael Corkery


“The trend is moving from opportunistic crime to Hollywood-scale attacks,” said Mr. Nish, whose firm has analyzed the malware believed to have been used in the Bangladesh breach.
In the United States, most banks take special precautions with their Swift computers, building multiple firewalls to isolate the system from the bank’s other networks and keeping the machines physically isolated in a separate locked room.
But elsewhere, some banks take far fewer precautions. And security experts who have analyzed the Swift breach said they had concluded that the Bangladesh bank may have been particularly vulnerable to an attack.

“Swift is a great organization,” said Chris Larsen, the founder of Ripple, a financial technology company that aims to speed up global money transmissions. “But the system is fractured and antiquated. The way it is set up, you cannot totally isolate problems in a place like Bangladesh from the whole network.”

In some ways, Swift is a testament to how technology has helped all countries — including poorer ones — gain access to the financial system. But that broader access has a downside.
The central bank in Bangladesh, by some accounts, employed fewer protections against cyberattacks than many other large banks. The bank, for example, used $10 routers and no firewalls, according to news reports.
The server software that the Bangladesh bank employed was a Swift product called Alliance Access, which connects banks to the central messaging system. In a sign of how seriously Swift regards the breach of Alliance Access, the group issued a “mandatory software update” last week to help its members identify possible irregularities.

The central bank of Bangladesh, in Dhaka, the capital. The heist was timed so that when Federal Reserve officials tried to contact Bangladesh, it was a weekend there and no one was working. By the time central bankers in Bangladesh discovered the theft, it was the weekend in New York and the Fed was closed. Ashikur Rahman/Reuters

“These hackers figured out this was a weak point on the periphery, and they went for it,” said Jeffrey Kutler, editor in chief at the Global Association of Risk Professionals, a trade group. “But they were not able to compromise the core.”

Swift’s core is built on technology that has been evolving for decades. What began in 1973 as a relatively small network of 240 banks in Europe and North America is now a sprawling network of 11,000 users that includes both banks and large corporations. At first, Swift could be used to authorize payments across national borders. But it is now also used to transmit messages related to domestic payments, securities settlements and other transactions.


Swift’s growth in recent years — it set a record for messages in March — reflects the increasingly global and interconnected nature of finance. But it also shows the risk of so many financial instructions running through a single system made up of a patchwork of banks and
companies with varying levels of online protection.


Each bank on the Swift network is identified by a set of codes. And it was the codes assigned to the Bank of Bangladesh that were recognized — correctly — by the Federal Reserve Bank of New York when it transferred $81 million of the Bangladesh bank’s money to the Philippines, not knowing that someone, somewhere, had stolen the credentials of the Bangladesh bank and installed malware to cover his or her tracks.
Initially, the thieves requested the transfer of $951 million into a handful of bank accounts in Sri Lanka and the Philippines — a number that prompted the New York Fed to ask the Bangladesh bank to reconfirm that it indeed wanted to move the money.
In the end, the Fed processed only five of the 35 fraudulent payment requests, after it could not reconfirm with officials in Bangladesh.
The hackers seemed to time the attack perfectly: When officials from the Fed tried to reach out to Bangladesh, it was a weekend there and no one was working. By the time central bankers in Bangladesh discovered the fraud, it was the weekend in New York and the Fed offices were closed.

To conceal the crime, the malware disabled a printer in the Bangladesh bank to prevent officials from reviewing a log of the fraudulent transfers.

Representative Carolyn B. Maloney, Democrat of New York, has called for an investigation into the theft. Robin Caplin/Bloomberg

The money was transferred to accounts in the Philippines and then into the Philippine casino system, which is exempt from many of the country’s anti-money-laundering requirements.
The New York Fed has been criticized for letting the $81 million slip out. Representative Carolyn B. Maloney, a New York Democrat and member of the Financial Services Committee, has called for an investigation, warning that the breach “threatens to undermine the confidence that foreign central banks have in the Federal Reserve, and in the safety and soundness of international monetary transactions.”
The New York Fed said in a statement that “there is no evidence that any Fed systems were compromised” and that the transfer of the money had been “fully authenticated” by Swift.
Swift, which prides itself on its secrecy and low public profile, also put out a statement about the attacks. But its executives declined to speak on the record about the episodes, which are still under investigation. The group’s chairman, Yawar Shah, who is a senior executive at Citigroup, also declined to comment.
In its statement, Swift emphasized that the hackers had been able to breach only some of the banks that communicate over Swift, not the network itself.
“The commonality in what we have seen is that (internal or external) attackers have successfully compromised banks’ own environments,” Swift said.
Even if officials at the Bangladesh bank had employed the highest of security measures, the thieves displayed a level of skill, cunning and determination that may have been able to penetrate a far more secure system.
“If you have an attacker who really wants to get in and knows there is a big prize,” Mr. Nish said, “keeping them out over the long term is really difficult.”

Source: http://www.nytimes.com/2016/05/01/business/dealbook/hackers-81-million-sneak-attack-on-world-banking.html?_r=0

April 29, 2016

How to Completely Anonymize Your BitTorrent Traffic with a Proxy

BitTorrent isn't the quiet haven it once was. These days, everyone's looking to throttle your connection, spy on what you're downloading, or even send you an ominous letter. If you use BitTorrent, you absolutely need to take precautions to hide your identity. Here's how to do that with a simple proxy.

This post originally detailed the setup of a proxy called BTGuard. Since its original publication in 2011, we've changed our recommendation to Private Internet Access due to BTGuard's slow speeds, bad customer service, and other difficulties. If you're still interested in using BTGuard, you can find instructions on their web site.

You have a few different options when it comes to hiding your BitTorrent activity, but we've found that a proxy is the most convenient and easiest to set up, so that's what we're going to cover here. We've talked about proxies a few times before, most notably with our original guide on how to set up BTGuard our guide to safe torrenting post-Demonoid. Unfortunately, BTGuard has never been a great service—it was just the most convenient. Thankfully, Private Internet Access—one of our favorite VPN providers—now provides a proxy very similar to BTGuard, but with faster speeds and better customer service. So we recommend using it instead, using the instructions below. If you don't want to use a proxy, check out the end of the article for a few alternative suggestions.

How a BitTorrent Proxy Works



When you download or seed a torrent, you're connecting to a bunch of other people, called a swarm. All of those people can see your computer's IP address—they have to in order to connect. That's all very handy when you're sharing files with other netizens, but file sharers such as yourself aren't necessarily the only people paying attention. Piracy monitoring groups (often paid for by the entertainment industry either before or after they find violators) also join BitTorrent swarms, but instead of sharing files, they're logging the IP addresses of other people in the swarm—including you—so that they can notify your ISP of your doings.

A proxy (like Private Internet Access) funnels traffic—in this case, just your BitTorrent traffic—through another server, so that the BitTorrent swarm will show an IP address from them instead of you. In this case, Private Internet Access' proxy server is in the Netherlands. That way, those anti-piracy groups can't contact your ISP, and your ISP has no cause to send you a harrowing letter.

But wait, can't the piracy groups then go to the anonymizer service and requisition their logs to figure out what you're downloading? Theoretically, yes, but if you're using a truly good anonymizer, they don't keep logs, so there's no paper trail of activity leading back to you. All the piracy monitors see is a proxy service sharing a file, and all your ISP sees is you connecting to a proxy service. If you encrypt your BitTorrent traffic (which we recommend), your ISP won't even be able to see that you're using BitTorrent.

Sounds too good to be true, right? Well, there are a few downsides. Most notably:

    Anonymity isn't free. Well, at least the ones worth using aren't. Private Internet Access costs $6.95 a month or $39.95 a year. That isn't very expensive, though, and it's well worth it for the privacy you get.
    You'll get slower download speeds. Running your connection through another server inevitably slows you down, though how much depends on what torrent you're downloading, who from, and a lot of other factors. In my experience, more popular torrents stayed at their top speed of 3.4 MB/s (my bandwidth cap) with a proxy, while other less popular torrents slowed down from 1 MB/s to about 500-600 kB/s. Your mileage may vary. I lost significantly less speed with Private Internet Access than I did with BTGuard, though.
    Not every BitTorrent client supports proxies. uTorrent for Windows works great, but Mac and Linux favorite Transmission sadly does not support proxies. You'll have to use something like Vuze or Deluge instead (or try one of the alternatives listed at the end of this article).
    Nothing is foolproof. Using a proxy may bring you increased anonymity, but nothing is guaranteed unless you avoid BitTorrent entirely.

Ready to get started? Here's what you need to do.

How to Set Up the Private Internet Access Proxy

Setting up a proxy is actually very simple, and just involves signing up for a service and checking a few boxes in your BitTorrent client. We'll be using Private Internet Access and uTorrent for Windows for this guide, but you can tweak things to fit your own setup pretty easily.
Step One: Sign Up for Private Internet Access

 Private Internet Access is primarily a VPN provider. We'll talk a bit more about VPNs later in this post, but what we really want is the SOCKS5 proxy that comes with their VPN service. So, head to Private Internet Access' web site and sign up for their VPN service. We recommend starting out with a monthly plan to see if you like it before buying a whole year's subscription.

Once you've signed up, Private Internet Access will email you your username and password. Log into the system with those credentials, and change your password from the client control panel.
Step Two: Generate a Proxy Password

How to Completely Anonymize Your BitTorrent Traffic with a Proxy

Your account credentials are only to manage your account—we'll need a new set of credentials for the Proxy service. In the client control panel, click the "Generate Password" button under "PPTP/L2TP/SOCKS Password." This is what we'll be using to configure our BitTorrent client. Write down the username and password that appears here (it's different than your regular account credentials) and move on to step two.

Step Three: Configure Your BitTorrent Client




Next, open up uTorrent and head to Options > Preferences > Connection. Under Proxy Server, choose Socks5 under "Type" and enter the following information:

    Proxy Type: Socks5
    Proxy Host: proxy-nl.privateinternetaccess.com
    Proxy Port: 1080
    Username: Your Private Internet Access Proxy username (from step two)
    Password: Your Private Internet Access Proxy password (from step two)

Check all of the other boxes under "Proxy" and "Proxy Privacy." Your Connection preferences should look exactly like the image above.

Step Four: See If It's Working






To ensure that it's working, head over to Torguard's IP Checker. This site can tell you what your IP address is, and compare it to the IP address of your torrent client, which will let you know whether your proxy is working correctly. To test it, hit the "Generate Torrent" button, and open the resulting torrent in uTorrent. Then, go back to your browser and hit the Refresh button under the "Check IP" tab. If it's the same as your browser IP—which you'll see next to the Refresh button—then your proxy isn't working, and you'll want to double-check all of the above settings. If it shows a different IP address (which should be in the Netherlands), then Private Internet Access is successfully tunneling all your traffic for you.
Other Ways to Anonymize Your BitTorrent Traffic

A proxy like Private Internet Access is the most convenient way to anonymize your traffic, but it isn't the only way. If you want to try something else, here are a few other tricks we recommend.

Use a VPN
A virtual private network (or VPN) is very similar to a proxy, but instead of rerouting just your BitTorrent traffic, it reroutes all your internet traffic. For some people, that's a good thing—it gives you privacy all over the web. However, it can also be inconvenient, navigating you to different web pages for that VPN's country or causing issues with streaming services. If you have a NAS, you can set up your VPN on it to route only your NAS traffic, which is a perfect option for downloading anonymously. VPNs are about the same price as most proxies, and I personally have found that I get better speeds with most VPNs than I do with a proxy.

So which VPN should you use? Check out TorrentFreak's list of the best VPNs for BitTorrent, as well as our Hive Five on the subject to find a provider that works for you.

Rent a Seedbox

Unlike proxies and VPNs, seedboxes don't route your BitTorrent traffic through another country. Instead, you actually rent a dedicated server that resides in that country, and do all your torrenting through that machine. They usually have insanely fast speeds, and if you're on a private tracker, they'll seed 24/7, giving you a great ratio. Once you download a torrent on your seedbox, you can just connect to it via FTP and download the file as fast as your home connection allows. Note that seedboxes also require a bit of extra setup, and some may require a little command line work to get running.

Seedboxes are more expensive than proxies and VPNs, ranging from entry-level boxes at $10 or $20 a month to fast boxes with more storage at $50 or even $100 a month. But, it offers a lot of advantages over proxies and VPNs—if you have the money to spare and want super fast speeds and a good ratio, we highly recommend getting a seedbox. Providers like Whatbox, Feral, and Bytesized come highly recommended, but a bit of searching can provide you with a ton of options. Shop around and see which one's best for you.

Ditch BitTorrent Altogether

Your last alternative is to try a new file sharing service entirely, like Usenet. It offers encrypted connections and doesn't connect to peers, so others can't track what you're doing. It doesn't always have the selection that BitTorrent has (depending on what you're downloading), but it offers a ton of other advantages, most notably higher speeds and better privacy. Check out our guide to getting started with Usenet to see if it's right for you.

Source: http://lifehacker.com/how-to-completely-anonymize-your-bittorrent-traffic-wit-5863380









February 17, 2016

The CIA Campaign to Steal Apple’s Secrets

RESEARCHERS WORKING with the Central Intelligence Agency have conducted a multi-year, sustained effort to break the security of Apple’s iPhones and iPads, according to top-secret documents obtained by The Intercept.

The security researchers presented their latest tactics and achievements at a secret annual gathering, called the “Jamboree,” where attendees discussed strategies for exploiting security flaws in household and commercial electronics. The conferences have spanned nearly a decade, with the first CIA-sponsored meeting taking place a year before the first iPhone was released.

By targeting essential security keys used to encrypt data stored on Apple’s devices, the researchers have sought to thwart the company’s attempts to provide mobile security to hundreds of millions of Apple customers across the globe. Studying both “physical” and “non-invasive” techniques, U.S. government-sponsored research has been aimed at discovering ways to decrypt and ultimately penetrate Apple’s encrypted firmware. This could enable spies to plant malicious code on Apple devices and seek out potential vulnerabilities in other parts of the iPhone and iPad currently masked by encryption.
The CIA declined to comment for this story.

The security researchers also claimed they had created a modified version of Apple’s proprietary software development tool, Xcode, which could sneak surveillance backdoors into any apps or programs created using the tool. Xcode, which is distributed by Apple to hundreds of thousands of developers, is used to create apps that are sold through Apple’s App Store.

The modified version of Xcode, the researchers claimed, could enable spies to steal passwords and grab messages on infected devices. Researchers also claimed the modified Xcode could “force all iOS applications to send embedded data to a listening post.” It remains unclear how intelligence agencies would get developers to use the poisoned version of Xcode.

Researchers also claimed they had successfully modified the OS X updater, a program used to deliver updates to laptop and desktop computers, to install a “keylogger.”
Other presentations at the CIA conference have focused on the products of Apple’s competitors, including Microsoft’s BitLocker encryption system, which is used widely on laptop and desktop computers running premium editions of Windows.
The revelations that the CIA has waged a secret campaign to defeat the security mechanisms built into Apple’s devices come as Apple and other tech giants are loudly resisting pressure from senior U.S. and U.K. government officials to weaken the security of their products. Law enforcement agencies want the companies to maintain the government’s ability to bypass security tools built into wireless devices. Perhaps more than any other corporate leader, Apple’s CEO, Tim Cook, has taken a stand for privacy as a core value, while sharply criticizing the actions of U.S. law enforcement and intelligence agencies.

“If U.S. products are OK to target, that’s news to me,” says Matthew Green, a cryptography expert at Johns Hopkins University’s Information Security Institute. “Tearing apart the products of U.S. manufacturers and potentially putting backdoors in software distributed by unknowing developers all seems to be going a bit beyond ‘targeting bad guys.’ It may be a means to an end, but it’s a hell of a means.”
Apple declined to comment for this story, instead pointing to previous comments Cook and the company have made defending Apple’s privacy record.

October 13, 2015

Get Android 6.0 Marshmallow Features Without Updating



Google has now launched the latest version of Android, 6.0 Marshmallow, for its Nexus phones. But Android updates don’t roll out to all phones at the same time, especially the non-Nexus ones, and they often take a long time. But you get can some of the Marshmallowy goodness right now — regardless of what phone you have!
Whether you’re on Lollipop, KitKat or older versions, you can get several of Android 6.0 Marshmallow’s best features on your phone right away. Not everything, mind you, but enough of the cool stuff.
It’s easier if you root your Android phone, but even if you haven’t, there are ways to get those features.

Get the Marshmallow Look Right Now

For the first time, Google has released the stock Android launcher for anyone who wants it. The new Google Now Launcher is exactly what Marshmallow ships with, and it supports some cool new features such as:
  • Swipe left to get the new “Google Now homescreen”, which has all the information you need from Google Now cards, complete with offline support.
  • When you’re on the homescreen, just speak quick “OK Google” commands, no taps or activation necessary.
  • The App Drawer now scrolls vertically, and is automatically arranged alphabetically.
  • You can search installed apps through the Search Bar, and it will also give suggestions of other apps you might like.
The Google Now Launcher is pretty impressive and lightweight enough to work fast on low-powered hardware too, so it’s definitely a contender for the best free Android launcher.
Download: Google Now Launcher for Android (Free)

Backup App Data and Restore (No Root)

Marshmallow brings a much-wanted feature, the ability to backup an app with all its data and then restore it to a device, without rooting your phone. Well, you might be surprised to know you can already do that.
We already have a multi-layered plan to backup non-rooted Android devices, but Helium is a core part of that. The app, made by the famous Clockwork Mod team, lets you backup apps complete with their data.
All you need is the Helium app, the companion Carbon app for Windows, Mac, or Linux computers, and a USB cable. Start the app, connect the phone to your computer, and you’re ready to go.
Helium backs up most apps, and it will notify you of which ones it can’t. I suggest you also backup the APK, since it makes restoring easier for some apps that break compatibility with new versions.
When you’re ready to install all this to a new phone again, connect it to your PC, download the app, and restore all your apps. It’s seamless and just works.
Helium Premium will also let you backup to cloud devices and external storage, and it supports apps that the free one doesn’t. Cloud backup makes it easier to sync an Android phone or tablet over WiFi. It’s well worth $4.99, if you ask me, but try out the free app first.
Helium isn’t a perfect solution though. For a full and complete backup of Android, you’ll need a rooted device and Titanium Backup Pro.
Download: Helium for Android (Free)

How to Manage Individual App Permissions

Android-6-Marshmallow-App-Permissions-Manager
Android Marshmallow finally, finally brings the ability to control app permissions on an individual basis. What this means is that if an app asks for permission to read your text messages and your GPS data, you can choose to grant access to location but not your messages.
Controlling individual app permissions helps avoid the seven deadly security risks from apps. If you are using Android 5.x Lollipop or Android 4.3/4.4 KitKat, you can control individual app permissions with App Ops. On Android versions 4.2 and older, you’ll need to root your phone to control permissions.
App Ops is super simple and you’ll be able to toggle the permissions any app uses with a simple switch. That’s exactly how it works in Marshmallow too. So if you’re on Android 4.3 or higher, you’re in luck!
One thing to note: Uninstalling App Ops isn’t as easy as just deleting the app from your phone, you need to download a special App Ops Uninstaller.
Download: App Ops for Android (Free)

Better Cut, Copy, Paste for Android

android-6-marshmallow-features-cut-copy-paste
Mimicking the iOS look, the new Android 6.0 makes it easier to cut, copy, and paste anything by giving you clear options when you select any text or image. However, there’s actually a better way than Marshmallow’s options.
Native Clipboard is probably the best way to improve copy-paste on Android. The app requires deep access to your Android device, but once you grant it those rights, it will copy anything in any text box, and paste any of your recent clipboard copied items to any other box. Double tap an empty box, and it just works.
Even after trying out Marshmallow, I found myself wanting to get this app back, so in this one case, the current systems actually outdo what you’ll get on Android 6.0.
Download: Native Clipboard for Android (Free)

Boost Your Battery Life With Two Apps

android-marshmallow-boost-battery
Marshmallow has two cool features to lengthen your battery life. First, it automatically puts unused apps to sleep. Second, it detects when you aren’t using your phone and stops using data at that time.
But what do you know? You already have a couple apps that will do the same things! You need to download Greenify and JuiceDefender.
Greenify’s auto-hibernation mode (available on Android 4.1 or newer phones) will stop updating apps you aren’t using and prevent them from slowing down your phone. JuiceDefender, on the other hand, is an all-in-one solution for almost any battery-saving tip on Android.
You get a lot of options in the free app, so try it out. I think you’ll be compelled to fork out $4.99 for JuiceDefender Ultimate.
Download: Greenify for Android (Free)
Download: JuiceDefender for Android (Free)

Ditch Chrome Custom Tabs, Get Firefox 42

android-6-marshmallow-features-chrome-tabs
One of the cooler features in Android Marshmallow is Google Chrome’s new Custom Tabs. With this, apps can open an optimized browser tab with saved passwords and other Chrome data intact. Plus, the pages will preload in the background so they seem faster.
Even if you aren’t using Android 6.0, you can get all of this goodness with the new Google Chrome for Android, which includes this feature.
Now, Chrome is the fastest Android browser, so this is great news. But Chrome isn’t necessarily the best browser. Personally, I’d recommend going with the new Firefox 42 Beta for Android.
Firefox 42 has a new awesome “Tab Queuing” feature, which is reason alone to get it. With this, when you are using any app, you can continue using it. When you see a link, tap it and it’s added to a queue, without moving you away from the app. Go to your notifications to find your Tab Queue, and with one tap, open them all in Firefox. It’s fantastic!
Download: Google Chrome for Android (Free)
Download: Firefox 42 Beta for Android (Free)


Source: http://www.makeuseof.com/tag/get-android-6-0-marshmallow-features-without-updating/

October 6, 2015

Android 6.0 Marshmallow features: What's new?

Google has officially announced what the M in Android M stands for, and it's Marshmallow. Here are the features you can expect from Android 6.0.
It’s time to prod the Marshmallow: Android Marshmallow is here. But you still have a while to wait unless you own a Nexus 6, Nexus 5 or Nexus 9, or plan on picking up a Nexus 5X or Nexus 6P.


So, the question: is Android M worth getting excited about? We’ve been spending some quality time with the new software to see what it offers over the Android Lollipop version we’ve been using for what feels like forever.
Here are the features that take Android Marshmallow a step further. Is it enough to steamroll iOS 9 and Windows 10? For now at least, we’ll leave that to you.

The apps menu is crazy-different

One Android Marshmallow change all of you will notice is the way the new apps menu works. It’s totally different to Lollipop and the other previous versions of Android.

Related: When will your phone get Android 6.0 Marshmallow?



androidm 3


This time, instead of a bunch of apps ‘pages’ you flick through horizontally, the apps box is a scroll thumbed through with a smooth vertical movement. It’s a lot more like Windows 10/Windows Phone’s apps menu, or that of the HTC Sense custom Android interface.
Is it better? Is it worse? This is very much a case of being different rather than better, but it does scroll very snappily on the Nexus 6 we’ve been using. Those with big app collections may find it faster. And, as in Android Lollipop, the apps are arranged alphabetically rather than letting you move them about yourself.
As before, there are no app menu folders either. You have to keep these on the home screens, if you want ‘em.

App search bar and favourites

In order to help those who think the new apps menu is worse, and there will be some, there are some extra features to the apps area. First, there’s a search bar up at the top.
This is a text bar you just type words into, and Android Marshmallow searches your app collection for any apps with that name. There’s also an option to use the search term to look for other apps in Google Play.
Related: App Permissions: The Android Marshamallow 6.0 feature that really matters




androidm 33


If your apps library is so massive you can’t remember which apps/games you’ve uninstalled, this bit will let you get them back on-board sharpish.
There are also four special apps slots right at the top of the apps menu. These are filled using an algorithm that picks the most important apps based on those you use most, and have used most recently.
On the Nexus 6 these extra interface elements can feel like a bit of a stretch to reach. But then 95 per cent of people think the phone is that bit too big anyway. The Nexus 6X should feel comfier.

The clock has gone all stylish

Lollipop upped Android’s style game, and Marshmallow tries to take that a step further with a redesigned clock. It’s little more than a font shuffle, but does give the new software a bit of a different, sharper visual personality.
Check it out below. The date text is now written in all-caps, and the font of the time characters seems to be a bit thicker, as if Google has hit the ‘bold’ button.



androidm 5

Google has added a memory manager

One of the complaints about Android Lollipop was that its memory-hungry nature introduced all sorts of performance problems in phones without absolutely loads of RAM.
A new feature lets you check out the memory usage of all your installed apps without using a third-party app.
There’s a whole new ‘Memory’ area in the main Settings menu.
Related: Nexus 5X vs 6P: What's the difference?



androidm 19


However, before you get too excited, it’s mostly about monitoring RAM use and seeing if there are any apps doing things they really shouldn’t rather than tinkering with how much memory apps are allowed. You can see the RAM use over the last 3, 6, 12 or 24 hours, to let you identify when and where things are going wrong without too much active monitoring on your part.
As is so often the case with Android, you’ll still likely have to try uninstalling/reinstalling any apps that are seriously misbehaving.

You can add a lock screen message

A tiny little tweak of Android M is that you can now add a little line of text to your lock screen. Maybe you’ll want to add a little tag to your ‘Jim’s VHS and DVD rental’ small business, or a way to tell you and your other half’s his ’n’ hers Nexus 6s apart.




androidm 7


Unlike the date font, this little extra line is written in lower case, and seems to have opacity of just under 100 per cent, making it a bit less bright than the clock.
It’s basically a custom number plate for your phone: go to town.

Battery optimisation now on a by-app basis

Android only really started to embrace proper a battery-saving mode with Android Lollipop, even though custom skins have had such features for years now. Android Marshmallow adds a whole new battery area called ‘optimisation’.




androidm 25


This tweaks how apps eat energy when not being actively used in order to save battery life. As standard, all apps bar the Android system itself use battery optimisation, and all you can do is make important apps exempt from this feature.
Google hasn’t laid out too clearly exactly what optimisation does, but you can bet part of it is about regulating access to mobile data and how freely they can perform background processes.

The volume controls have changed yet again

One part of Android Lollipop that everyone got quite angry about originally was the volume control. The silent mode was ditched completely. It caused a bit of a fuss.
Related: What is Google Now on Tap?




androidm 37

It has returned, sort of. Android Marshmallow has a Do Not Disturb shortcut in the notifications drop-down that lets you switch off certain alerts for a period of time, or indefinitely. It does feel kind of fiddly still, but is designed to make sure you don’t switch the feature on and then end up missing your early morning alarm.
This new spot for Do Not Disturb lets Android Marshmallow pare down the volume controls a bit. Press the volume button and you’ll see the slider for system notifications. Next to it there’s a drop-down arrow that gives you access to the separate ‘media’ and ‘alarms’ volume dials.

Fingerprint scanners supported as standard

Finger scanners have been found in Android phones for years now. However, it’s only with Android Marshmallow that the system supports the hardware natively. Before now, software for these scanners had to be jammed in by the manufacturer.
image:
androidm 13


Both the Nexus 5X and Nexus 6P have rear fingerprint scanners, and Google calls the system Nexus Imprint. It lets you unlock your phone with a finger-press, as an identification measure in apps and to sign off on Pay wireless payments.
Pay has been around for years now, but more recently Google re-announced it as Android Pay. Hopefully it’ll catch on this time.

Instant Google Now ‘Ok Googling’

Android 6.0 makes the system’s digital assistant way more useful. Where before it was largely consigned to the Google Now area of the phone, it can be accessed to look up things wherever you are, using something called Now on Tap.
Related: Android 6.0 Marshmallow tips and tricks




androidm 21


First of all, you can talk to the assistant whenever the phone is on the home screen just by saying ‘Ok Google’.
Don’t like talking to your phone? One of the neatest parts of Android Marshmallow is that the digital assistant can now be called up everywhere. A long-press on the Home button makes the Google Now assistant scan whatever’s on the screen to find extra info online that might be helpful.
It works absolutely anywhere. One example of a good use we found was looking at Tripadvisor for a local restaurant, then using Google Now to fly straight to that place’s menu URL. Neat, right? The only bit it doesn't seem to do yet is to OCR text in photos to Google Now-ify your photo gallery. Maybe one day, eh Google?




androidm 23

 

 

Permissions are on lock down

Before Android Marshmallow, app permissions were granted at the point of install. You agree to give an app access to, say, your camera, contacts and storage as soon as the app begins installing. This has changed.
From now on, apps will have to ask for your permission to access the camera, at the point where they want to use it. It’ll make things much clearer, letting you see exactly what apps are doing in the background.
For all apps already granted permissions, you’re also given a much clearer round-up of what’s what in the Settings menu. A dedicated section shows you which apps have access to your camera, your contacts and so on, and you can revoke them at the press of a switch.



Android M 11

 

USB Type-C/3.1 support

One important bit of future-proofing is full support for USB-C, which is closely linked to the USB 3.1 standard. We’ve seen this plug already in the OnePlus 2, but it was really just a USB 2.0 port with a different connector.
The big news is the new set of capabilities we’ll see when ‘proper’ USB-C phones arrive, with USB 3.1 support. They’ll be able transmit 40x the power of the current USB connectors, although exactly how much power phones of the future are going to gobble up is something we don’t know yet.
Bandwidth will increase too, but it’s the prospect of even faster-charging batteries that has us excited.

Android M 41

Doze

In a bid to hopefully give your battery life a boost, Android Marshmallow introduces a feature that recognises when the Android device is in a rested state to help conserve power. Google says it has tested it with a Nexus 9 and claims it can help make battery life last two times longer in standby mode by using fewer background services. If you're worried about missing out on alarms and incoming instant messages, Doze will still allow those notifications and modes to be activated.

When will Android 6.0 Marshmallow be available?

Google has announced that the Android Marshmallow launch will be at the beginning of October. Currently, developers can play around with the final Android Marshmallow builds on the Nexus 5 and 6 smartphones plus the Nexus 9 and Nexus Player set-top box. Google has since confirmed that the Nexus 7 will also be among the first devices to the get the Marshmallow treatment.

Read more at http://www.trustedreviews.com/opinions/android-m-features#FedXbvrZ7I8YK93X.99

September 1, 2015

Moto X Pure Edition Review: This Phone Does Android Better Than Google


Moto X Pure Edition Review: This Phone Does Android Better Than Google
When it comes to experiencing Android the way Google intended, you have surprisingly few options. Two, really. Google’s own Nexus smartphone—made by a parade of different hardware partners—and Motorola. The new Moto X Pure Edition is the new unspoiled Android champion. It can do Android even better than Google.

What Is It?

The Moto X Pure Edition is the new 5.7-inch Android flagship smartphone from Motorola, a Google company a Lenovo company. It comes with the latest Android Lollipop software and a few select Moto apps. It’s also the most customizable phone you can buy thanks to Moto Maker, a web app that lets you change the material, texture, and color of the phone before you buy it. Depending on your taste, the Moto X can be anything from eye-popping to subdued, and with Motorola’s universal SIM, you can buy an unlocked version for just $400 that will play nice with any major US cell network.
We’ve often called its predecessors the “Android Phone for Everyone,” and the Moto X more than retains that distinction.
Moto X Pure Edition Review: This Phone Does Android Better Than Google

Why Does It Matter?

Not only is the Moto X Pure Edition great, it’s actually cheaper than any flagship phone Motorola has ever made. Sure, $400 may not sound cheap, but now that US phone subsidies are disappearing and cutting edge smartphones can cost you $750+ out of pocket, $400 for a top-of-the-line Android phone is an amazing deal.
And, perhaps most importantly, it’s a Motorola phone that finally has an excellent camera. Mostly. We’ll get to that.

Design

The whole Moto X design shtick has always been the ability to decide how the phone looks. To pick out the colors of various components, personalize the design, and make it your own.
That being the case, it’s actually pretty hard to gauge the overall eyeball appeal of the new Moto X. Personally, I love the dark wood and gunmetal grey version we received for review. The wood is a little slippery, but nowhere near as bad as the Gorilla Glass on recent Samsung devices, and the sloping back (a Moto X trademark since the beginning) makes the X comfortable to hold.
With a 5.7-inch screen, this is definitely a big phone, but it actually feels manageable thanks to that curve. I never felt like “wow, this is a huge phone” when using it, and I’ve never said that about a phone bigger than 5.5 inches before.
Moto X Pure Edition Review: This Phone Does Android Better Than Google
The Moto X Pure Edition flanked by last year’s 6-inch Nexus 6 (left) and 5.2-inch Moto X (right)
I do have a few gripes, though—the first being a seam between the aluminum camera casing and the back of the smartphone. This pretty minor, but a couple times dirt and other detritus would somehow find its way in that crack and get stuck. I’d have to find something thin, like the SIM tool on my keychain, to actually dig it out. Now, I recognize that I’m almost OCD-level about keeping my gadgets clean—I’m the guy constantly wiping my smartphone with my shirt—but it’s a tiny detail that’s pretty annoying.
The other design frustration is the front-facing LED flash, a new trend for smartphones—and the first on any Moto phone—that aims to make your phone the perfect selfie-taking companion. But here it’s an eyesore, and I hate it. Just look at it. Look. At. It.
Moto X Pure Edition Review: This Phone Does Android Better Than Google
Nope nope nope nope
I understand that we live in a selfie world and a front-facing flash makes perfect sense, but the ugliness it brings to the Moto X, especially with a black bezel, is unjustifiable for me. If you’re a selfie fiend, you may not mind—you may even rejoice—but for the rest of us, it kinda sucks.
Everywhere else, Motorola keeps up with Samsung and Apple in the premium fit-and-finish department. You’ll find aluminum along the edges, your choice of luxurious material on the back. Motorola’s done away with the “ring” flash from last year’s Moto X, which didn’t really work that well anyways, and went with a more traditional layout with the LED underneath the camera sensor.
Okay, one last design gripe: the rear dimple is much smaller, which actually makes it less useful. On the Moto X, and especially the Nexus 6, that dimple helped you grip the larger phone providing better balance. Now, Motorola seems to be retaining the design choice for pure aesthetics rather than function since it’s in no position to comfortably hold, unless I’m holding the phone like an idiot (which I don’t think I am.)
But overall, the Moto X Pure looks great. And since you can pretty much make it look a couple dozen different ways, no doubt one will be to your liking.
Moto X Pure Edition Review: This Phone Does Android Better Than Google

Software

Motorola has always been about simplicity on Android smartphones, and the Moto X Pure runs with that idea. This phone just gets the hell out of the way and lets Android do what it does best. All the best parts of Android Lollipop, including Material Design and super-smooth animations, are all here, and all of Moto’s additional apps actually feel like good ideas. Let’s walk through a few of them, from best to worst:
Moto Display: Easily the Moto X’s best additional feature. Moto Display lets you preview incoming notifications on your lockscreen—no need to unlock the handset. You just press on the icons for a preview of the notification, whether it’s an email or text message or Swarm check-in. It’s really convenient, and I love it. You can also select certain apps to be blocked from Moto Display if you’d rather they stay private.
Moto Voice: Great, if you don’t mind squawking at your phone and drawing inquiring glances in public. You set a phrase that Moto Voice is always listening for, and then you can issue voice commands even if it’s asleep. Since I’ve always considered Starscream my spirit Transformer, my phrase was “Ok, Megatron.”
Say that, and it wouldn’t matter if my phone was off or halfway across the room, it would spring to life. You can use it to set alarms, get hands-free turn-by-turn driving directions, or anything else Google Now can do for you.
Moto X Pure Edition Review: This Phone Does Android Better Than Google
Moto Assist: This feature is cool in theory, and with the right implementation it could be really cool, but it feels a little hollow and half baked. They way Moto Assist works is you designate “places” like home and work or “events” like driving a car, sleeping, or being in a meeting and Moto Assist will intelligently silence your phone, read text messages aloud when you’re driving, even automatically reply to calls.
It mostly works great, but it interpreted a lot of my Google Calendar events as “meetings” when they were actually just reminders about articles I needed to write or other non-meeting things. So I just turned it off completely.
The only great thing that came from Moto Assist was that I got to hear a AI personal assistant say this sentence out loud from one of my Dungeons & Dragons Online guild members:
Just killed me a colossal red dragon on epic ELITE...She was a CR54
My response was “that’s awesome.”

Speakers

Smartphone speakers are a perennially overlooked feature on most smartphones. The big boys like Apple and Samsung seems to slap them on the bottom like an afterthought, and some (I’m looking at you LG) put the on the back where they don’t do any good at all.
But The Moto X Pure display is flanked by two front-facing speakers, and while they’re not as deep and rich as the absolutely wonderful Boomsound speakers you’ll find on some HTC phones, they do one thing well—they let you actually hear things. In one instance, I was trying to show a friend a video documenting the strange phenomena of “chin down, eyes up” cover art on the boxes of popular video games. I loaded up the video and out of instinct went to cup my hand around the speaker so the sound would be directed to our faces. Only this time, I didn’t have to. Even with taxis screeching by and drunk New Yorkers screaming obscenities, I could actually hear the video. It’s a simple thing, but a great thing.

Camera

Then there’s the camera. Motorola has never been accused of having a stellar smartphone camera. In fact, it’s often been the opposite. But this 21-megapixel camera is amazing. Compared with the S6 and the G4, arguably the top two Android cameras right now, it shows you more detail in daylight. Look at this cute dog photo:
Moto X Pure Edition Review: This Phone Does Android Better Than Google
So much detail. You can even see how his eyes say I’ve seen this world. I know its secrets.
Plus, this thing can shoot in 4K, has phase detection autofocus, and is just a champ in normal lighting conditions. It’s when lighting conditions are not-so-normal that things go downhill. Where the Moto X Pure shines in daylight, it stumbles clumsily in low-light. That’s bad, and you can read a more detailed analysis of this unfortunate Achilles heel right here.


Moto X Pure Edition Review: This Phone Does Android Better Than Google
Good light.
Moto X Pure Edition Review: This Phone Does Android Better Than Google
Low light. Yuck.

Like

The best way to describe the Moto X Pure’s display is cinematic. With a bigger 5.7-inch display with QHD resolution and two front-firing speakers, this guy is a great little multimedia champion. Also, stock Android looks best on as many pixels as possible.
The iconic phrase on personal taste is “to each their own,” and the Moto X gives you exactly that. I personally love my dark wood a gunmetal gray smartphone because it matches the contents of my soul, which is primarily dark and black. But maybe you hate it! Luckily, there are a crap ton of different options to choose from, so you can hate my design choice all you’d like (you’d be wrong, but whatever).
Moto X Pure Edition Review: This Phone Does Android Better Than Google
The software is just great. It’s lightweight, beautifully animated, and simple. I don’t have to thumb through a million menus. It feels like an Android phone, which makes sense since that’s what you’re buying.
The price absolutely makes it. At $700+ (what you’d normally pay for a tip-top Android), I’d say there’s too much missing hardware. No wireless charging, no fingerprint sensor. But at a steep $300 discount, I’d say there’s almost too much for the price. It’s just a great deal.

No Like

It doesn’t seem completely futureproof. We know that Google’s next release of Android, Marshmallow, will officially bring fingerprint sensor support to Android. With Android Pay also launching in days or weeks, not having it on the Moto X Pure could be annoying. Moto reps told me that the service will definitely still work on the phone, you’ll just have to authenticate with a pin. Since the whole promise of mobile payments is to be quick and painless, no fingerprint sensor is a definite minus.
While in daylight, the Moto X Pure is simply stunning. Not only does it beat out the S6, which we were completely WOW-ed with, it even beat out the G4. But man, in low-light the camera is like Adam Sandler in Pixels, which is to say real bad. If you find yourself more of a day person, this camera turns out miracles. But if you’re a night hawk—prepare for sadness.
This battery isn’t exactly a dislike per se, but it’s not great either. It’s just OK. Taking off the charger at 8am and plugging in at 10pm, I was usually at about 5 percent battery on a rather mediocre usage diet. That’s not terrible, but not great. If you have a late night or are prone to heavy use (i.e. lots of streaming, web browsing, video recording, etc.), the Moto X is going to die on you. Luckily, it does come with quick charging capability, so if you do find you’re in dire need of some juice, you can get some fast.
While the price is a definite like, that $400 price is for 16GB of storage. For a phone that shoots 4K, that is just not going to cut it. Enough. With. 16GB. Phones.
Moto X Pure Edition Review: This Phone Does Android Better Than Google

Should You Buy It?

If you’re looking for the absolute best value Android smartphone out there: Yep. Yep, you should. The only hesitation you should feel in your heart is that Google will most likely be announcing two Nexus smartphones possibly by the end of the month. A Google Phone means two devices very similar to the Moto X, definitely getting upcoming Marshmallow update first, and ones that could even be a part of Google’s new Project Fi wireless service.
But what Nexus most likely won’t have is a look tailored specifically to you and legitimately useful Moto apps you’ll want to use. Pull the trigger or wait—it’s a win-win.