This Week in Apps: The year and decade in review, gaming acquisitions and a Facebook OS

Welcome back to This Week in Apps, the Extra Crunch series that recaps the latest OS news, the applications they support and the money that flows through it all.

The app industry is as hot as ever, with 194 billion downloads last year and more than $100 billion in consumer spending. People spend 90% of their mobile time in apps and more time using their mobile devices than watching TV. Apps aren’t just a way to waste idle hours — they’re big business, one that often seems to change overnight.
In this Extra Crunch series, we help you to keep up with the latest news from the world of apps, delivered on a weekly basis.

Headlines

The top apps of the year… and the decade

App Annie this week released its list of the year’s top apps. And this time around, it also included the top apps of the past 10 years in its analysis. Outside of games, Facebook dominated the decade, the firm reported. It ran the four most-downloaded apps of the decade, including Facebook (#1), Messenger (#2), WhatsApp (#3), and Instagram (#4). Other communication and social media apps were also among the most popular over the past 10 years, claiming seven out of the 10 top spots, including Snapchat (#5), Skype (#6) and Twitter (#10). Social video platforms TikTok and YouTube also placed on the list at #7 and #9, respectively. And yes, it’s pretty notable that TikTok — an app that only launched outside of China in 2017 — is one of the most-downloaded apps of the past decade. Meanwhile, even though dating app Tinder was the most profitable app this year, Netflix was the No. 1 app by all-time consumer spend over the past decade.

2019 app downloads and consumer spending

Related to its round-up of the top apps, App Annie also offered some preliminary data on downloads and consumer spending in 2019. Its current figures don’t include calculations from third-party app stores in China, (like those referenced above), which App Annie tends to provide in its annual State of Mobile report. Instead, App Annie reports we’re on track to see 120 billion apps from Apple’s App Store and Google Play by the end of 2019, a 5% increase from 2018. Consumer spending was also up 15% year-over-year to reach $90 billion, it says. Expect a full analysis to come in Q1 2020.

Facebook still sat at the top of the charts for 2019. The company’s Messenger app was the most downloaded non-game app of 2019, followed by Facebook’s main app, then WhatsApp. Tinder switched places with Netflix for the No. 1 spot on this chart — last year, it was the other way around. (For more details, TechCrunch’s full review is here.)

2019 in Mobile Gaming

According to a year-end report by GamesIndustry.biz, mobile gaming grew 9.7% year-over-year in 2019 to reach a market value of $68.2 billion. The gaming market as a whole was worth $148.8 billion, the report said. Smartphone games were the biggest piece of this figure, at $54.7 billion, compared with $13.4 billion for tablet games. That means smartphone games are still bigger than PC, browser PC games, boxed and downloaded PC games, and console games.

Big moves in cloud gaming

To beef up its new cloud gaming service Stadia, Google this week bought game development firm Typhoon Studios, who were set to release their cross-platform title and first game, Journey to the Savage Planet. Google had said it wants to build out a few different first-party studios to release content on Stadia, which is where this acquisition fits in. Meanwhile, Facebook this week acquired the cloud gaming startup, PlayGiga, which had been working with telcos to create streaming game technology for 5G.

Stadia has a big mobile component, as its controller can play games on compatible mobile devices like Pixel phones. Gaming has been a big part of Facebook’s mobile efforts, as not only a platform where games can be played, but also a place to watch live game streams, similar to Twitch. But the big gaming trend of the past year (which will continue into 2020) is cross-platform gaming — thanks to games like Fortnite, Roblox and PUBG Mobile, as well as devices like Nintendo Switch, gamers expect to continue playing no matter what screen they happen to be using at the time.

Apple Developer app expands support for China

Apple launched a dedicated mobile app for its developer community in November, with the arrival of the Apple Developer app, which was an upgraded and rebranded version of Apple’s existing WWDC app. The app lets developers access resources like technical and design articles, as well as read news, watch developer videos, and enroll in the Apple Developer program. Now that the program is open to China through the app, Apple announced this week.

From the app, developers in China can start and complete their Apple Developer membership and pay with a local payment method on their iPhone or iPad. They can also renew their membership, to keep their account active. Apple has been heavily investing in growing its international developer community by launching developer academies and accelerators in key regions, among other initiatives. Over the past year, Apple grew its developer community in China by 17%, the company earlier said.

So much for nostalgia, Rewound gets yanked from the App Store

We hope you downloaded this fun app when we told you to in last week’s column! Because now it’s gone.

Rewound, briefly, was a clever music player app that turns your iPhone into a 2000’s era iPod, complete with click wheel nav. The developer was able to sneak the app into the App Store by not including the actual iPod UI, which infringes on Apple’s own product design. Instead, the UI pieces were hosted off-site — on Twitter accounts, for example. Users could find them and download them after they installed the app. Technically, that means the App Store app itself wasn’t infringing, but Apple still kicked it out. The developer also charged a fee to access the Apple Music features, which may have been another reason for its removal.

It’s no surprise Apple took this step, but the developer seems confused as to how the app could be approved then pulled later on, even though it hadn’t changed. That’s actually par for the course for Apple’s subjective, editorial decisions over its App Store, however. Now Rewound, which has 170K+ users after only a few days, will focus on a web app and Android version.

Facebook is building its own OS so it can ditch Android


Source: Tech Crunch

TikTok’s national security scrutiny tightens as U.S. Navy reportedly bans popular social app

TikTok may be the fastest-growing social network in the history of the internet, but it is also quickly becoming the fastest-growing security threat and thorn in the side of U.S. China hawks.

The latest, according to a notice published by the U.S. Navy this past week and reported on by Reuters and the South China Morning Post, is that TikTok will no longer be allowed to be installed on service members’ devices, or they may face expulsion from the military service’s intranet.

It’s just the latest example of the challenges facing the extremely popular app. Recently, Congress led by Missouri senator Josh Hawley demanded a national security review of TikTok and its Sequoia-backed parent company ByteDance, along with other tech companies that may share data with foreign governments like China. Concerns over the leaking of confidential communications recently led the U.S. government to demand the unwinding of the acquisition of gay social network app Grindr from its Chinese owner Beijing Kunlun.

The intensity of criticism on both sides of the Pacific has made it increasingly challenging to manage tech companies across the divide. As I recently discussed here on TechCrunch, Shutterstock has actively made it harder and harder to find photos deemed controversial by the Chinese government on its stock photography platform, a play to avoid losing a critical source of revenue.

We saw similar challenges with Google and its Project Dragonfly China-focused search engine as well as with the NBA.

What’s interesting here though is that companies on both sides are struggling with policy on both sides. Chinese companies like ByteDance are increasingly being targeted and stricken out of the U.S. market, while American companies have long struggled to get a foothold in the Middle Kingdom. That might be a more equal playing field than it has been in the past, but it is certainly a less free market than it could be.

While the trade fight between China and the U.S. continues, the damage will continue to fall on companies that fail to draw within the lines set by policymakers in both countries. Whether any tech company can bridge that divide in the future unfortunately remains to be seen.


Source: Tech Crunch

F5 acquires Shape Security for $1B

F5 got an expensive holiday present today, snagging startup Shape Security for approximately $1 billion.

What the networking company gets with a shiny red ribbon is a security product that helps stop automated attacks like credential stuffing. In an article earlier this year, Shape CTO Shuman Ghosemajumder explained what the company does:

“We’re an enterprise-focused company that protects the majority of large U.S. banks, the majority of the largest airlines, similar kinds of profiles with major retailers, hotel chains, government agencies and so on. We specifically protect them against automated fraud and abuse on their consumer-facing applications — their websites and their mobile apps.”

F5 President and CEO, François Locoh-Donou sees a way to protect his customers in a comprehensive way. “With Shape, we will deliver end-to-end application protection, which means revenue generating, brand-anchoring applications are protected from the point at which they are created through to the point where consumers interact with them—from code to customer,” Locoh-Donou said in a statement.

As for Shape, CEO Derek Smith said that it wasn’t a huge coincidence that F5 was the buyer, given his company was seeing F5 consistently in its customers. Now they can work together as a single platform.

Shape launched in 2011 and raised $183 million, according to Crunchbase data. Investors included Kleiner Perkins, Tomorrow Partners, Norwest Venture Partners, Baseline Ventures and C5 Capital. In its most recent round in September, the company raised $51 million on a valuation of $1 billion.

F5 has been in a spending mood this year. It also acquired NGINX in March for $670 million. NGINX is the commercial company behind the open source web server of the same name. It’s worth noting that prior to that F5 had no made an acquisition since 2014.

It was a big year in security M&A. Consider that in June, 4 security companies sold in one 3-day period. That including Insight Partners buying Recorded Future for $780 million and FireEye buying Verodin for $250 million. Palo Alto Networks bought two companies in the period: Twistlock for $400 million and PureSec for between $60 and $70 million.

This deal is expected to close in mid-2020, and is of course, subject to standard regulatory approval. Upon closing Shape’s Smith will join the F5 management team and Shape employees will be folded into F5. The company will remain in its Santa Clara headquarters.


Source: Tech Crunch

Negotiate for ‘better’ stock in equity-funded acquisitions

For many founders, building and selling a successful venture-backed company for cash is the ultimate goal. However, the reality is that some companies will instead receive an equity-funded acquisition proposal in which equity of another private venture-backed company, rather than cash, represents all or a significant portion of the purchase price.

Because all equity is not created equal, it is important for founders to understand how to negotiate for better equity in the context of such an acquisition proposal. This article explores what better equity looks like and some strategies founders can use to negotiate for that equity.

What is “better” equity?

To know what “better” equity is for the seller, it is necessary to understand what the “worst” and “best” stock is in the context an equity-funded acquisition by a private company buyer. The “worst” stock is plain common stock which does not enjoy any special rights and is subject to contractual restrictions which diminish its liquidity profile. Common stock sits at the bottom of the priority stack (after debt and preferred equity) in the event the company dissolves or is sold — thus, it is least valuable. Variations of transfer restrictions (e.g., a prohibition on private secondary sales) may further diminish the desirability of common stock by making it difficult or impossible for the holder to achieve liquidity outside of an M&A event or initial public offering (IPO).

In contrast, the “best” stock is (1) the acquirer’s most senior series of preferred stock, coupled with (2) additional contractual rights enhancing such stock’s liquidity profile. For our purposes here, we’ll call this “enhanced preferred stock.” All things being equal, founders and VCs should have a strong preference for enhanced preferred stock in an equity-funded acquisition for several reasons:

  • Usually, the most senior series of preferred stock will enjoy a liquidation preference ensuring that a certain amount of proceeds (commonly equal to invested capital) from a sale of the company flow to stockholders of that series before proceeds are distributed to junior preferred and common stockholders.
  • Unique contractual rights not shared by common stockholders, like special voting rights with respect to major events and transactions, unique information rights, pro rata investment rights with respect to future financings, rights of first refusal and co-sale rights, increase the stock’s relative value.
  • Beyond the standard set of rights that are usually enjoyed by all preferred stockholders, additional contractual rights of and reduced restrictions on enhanced preferred stock make it more likely that the holder of such equity will achieve liquidity of some or all of its holdings prior to an M&A event or IPO. Such additional rights may include one or more of the following: time or event-based redemption rights (i.e., the right to force the acquirer to redeem equity at a specified price in the future), other liquidity rights tied to future financings or commercial transactions (e.g., the right to sell stock to the investors in the next equity financing), covenants of the acquirer to permit and support private secondary sales and registration rights (i.e., the right to force the acquirer to register stock with the SEC, thereby allowing for unrestricted resale by the holder).

“Better” stock lies somewhere on the continuum between the common stock and enhanced preferred stock poles, with the type of stock and bundle of rights associated with such equity determining its precise location. Additional contractual rights and reduced restrictions may significantly improve the desirability of common stock and perhaps place the holder in a better position than it would have been as a preferred stockholder. For example, a seller able to negotiate the right to sell a certain amount of common stock to investors in the acquirer’s next preferred stock equity financing could be more favorably positioned than the holder of senior preferred stock without any enhanced preferred rights.

Negotiating for better stock. With a framework for understanding what better stock means, below are several strategies sellers can employ in M&A negotiations to obtain better stock than that initially offered by the buyer.

Avoiding dire situations and preserving leverage. Leverage matters in every negotiation and any strategy that ignores this reality is doomed to fail. To state the obvious, the first strategy to negotiate for better stock in an equity-funded acquisition is the first strategy in preparing for any M&A event: companies should do all they can to avoid being in a dire fire sale situation when a buyer comes knocking on their door. If the seller is a failing company seeking a sale as a last ditch effort to avoid shutting its doors, even the best strategies may be useless in negotiation since as soon as the buyer says “no”, the seller will likely fold its hand and agree to the deal offered.


Source: Tech Crunch

Coral raises $4.3M to build an at-home manicure machine

Coral is a company that wants to “simplify the personal care space through smart automation,” and they’ve raised $4.3 million to get it done. Their first goal? An at-home, fully automated machine for painting your nails. Stick a finger in, press down, wait a few seconds and you’ve got a fully painted and dried nail. More than once in our conversations, the team referred to the idea as a “Keurig coffee machine, but for nails.”

It’s still early days for the company. While they’ve got a functional machine (pictured above), they’re quite clear about it being a prototype.

As such, they’re still staying pretty hush hush about the details, declining to say much about how it actually works. They did tell me that it paints one finger at a time, taking about 10 minutes to go from bare nails to all fingers painted and dried. To speed up drying time while ensuring a durable paint job, it’ll require Coral’s proprietary nail polish — so don’t expect to be able to pop open a bottle of nail polish and pour it in. Coral’s polish will come in pods (so the Keurig comparison is particularly fitting), which the user will be able to buy individually or get via subscription. Under the hood is a camera and some proprietary computer vision algorithms, allowing the machine to paint the nail accurately without requiring manual nail cleanup from the user after the fact.

Also still under wraps — or, more accurately, not determined yet — is the price. While Coral co-founder Ramya Venkateswaran tells me that she expects it to be a “premium device,” they haven’t nailed down an exact price just yet.

While we’ve seen all sorts of nail painting machines over the years (including ones that can do all kinds of wild art, like this one we saw at CES earlier this year), Coral says its system is the only one that works without requiring the user to first prime their nails with a base coat or clear coat it after. All you need here is a bare fingernail.

Coral’s team is currently made up of eight people — mostly mechanical, chemical and software engineers. Both co-founders, meanwhile, have backgrounds in hardware; Venkateswaran previously worked as a product strategy manager at Dolby, where she helped launch the Dolby Conference Phone. Her co-founder, Bradley Leong, raised around $800,000 on Kickstarter to ship Brydge (one of the earliest takes on a laptop-style iPad keyboard) back in 2012 before becoming a partner at the seed-stage venture fund Tandem Capital. It was during some industrial hardware research there, he tells me, when he found “the innovation that this machine is based off of.”

Vankateswaran tells me the team has raised $4.3 million to date from CrossLink Capital, Root Ventures, Tandem Capital and Y Combinator . The company is part of Y Combinator’s ongoing Winter 2020 class, so I’d expect to hear more about them as this batch’s demo day approaches in March of next year.

So what’s next? They’ll be working on turning the prototype into a consumer-ready device, and plan to spend the next few months running a small beta program (which you can sign up for here.)


Source: Tech Crunch

Snopes rolls its own crowdfunding infrastructure to prepare for 2020’s disinformation warfare

2020 will likely be one of the most bitter and hard-fought elections in decades, not just on pulpits and stages, but on the true battleground of modern politics: the internet. And veteran fact-checker Snopes is girding itself for the fight with a crowdfunding effort it hopes will free it from a dependence on internet platforms for which the truth is a secondary consideration.

The last we heard from the company, it was emerging from a — disastrous is too strong a word, but perhaps we could say ineffectual — fact-checking partnership with Facebook. The obvious mismatch in priorities made Snopes think hard about its future and how to guarantee it could pursue its mission without begging for coins from companies that so obviously cared little for what they could provide.

The new plan is to see whether the site’s sizable readership will be willing to put a bit of cash on the table for a service they may have been using for years for free. Right now there’s a standard rewards-based backing scheme ($40 gets you a shirt and mug, etc.), but subscriptions and other means of support are coming soon.

“Everything about the site since its inception has been a long, slow, evolutionary process, from what it looked like to the material we covered to how it was funded. This is just another part of that process,” said founder David Mikkelson. “We’re just going where the road leads us.”

And the last couple of years have made it clear that the road leads nowhere near the sites that actually deliver news to users: Google, Facebook, Apple and so on.

VP of operations Vinny Green, who spearheaded the new direction Snopes is headed, called what those companies are doing right now “credibility theater.”

“The fact that Facebook has more people on their PR staff than there are formal fact checkers in the world demonstrates the disproportionality of the situation,” he said. “Apple News and Google News don’t have the mission or the mandate to ensure we have a healthy discourse online. Someone has to step up who has an interest in making sure the content flowing through the pipes is credible and reliable — so we’re stepping up. But our only access to capital and reach is what we grow ourselves.”

To that end, Green and the team at Snopes have put together their own crowdfunding infrastructure, eschewing the likes of Kickstarter and Patreon to make something that fits their purposes better. The resulting product will be familiar to anyone who has backed a project on those other sites, but is extensible on their side to serve as an all-purpose system for soliciting from and rewarding their community.

They’ve had a thousand backers already since the campaign launched a couple days ago, only half of which wanted anything in return. This first effort is intended to get the word out and shake the bugs out, while subscriptions and new project-specific funding options will appear early in 2020.

“There are fact-checking organizations, but there aren’t a lot of fact-checking businesses,” he said. Companies tend to give their information away or meekly agree to “partnerships” like Facebook’s, where the fabulously rich and influential company paid a pittance of money and attention so it could claim to be taking a stand against disinformation.

“You really have to wonder, why is the multi-billion-dollar platform paying fact checkers, you know, like $30,000 a month to check 30 things?” said Mikkelson. “It’s clear that the primary objective of the Facebook fact-checking partnership was not to curb the appearance or reach of false information on that platform. That was a secondary or tertiary objective. Presenting only credible information is contrary to their business model… while it’s exactly inline with ours.”

The traffic and feedback show that Snopes is valued by many people out there — why can’t it support itself directly?

“2020 is going to be bonkers in terms of debunking this information, but the business model isn’t going to get better,” said Green. “There will be increased traffic and it’ll be bigger in traditional metrics, but I think there will also be an appetite for a venue online where you can consume information without vitriol or spin.”

A browser extension is also planned

To that end they hope that the crowdfunding infrastructure will allow for a few things. First, it could directly support investigative work like the recent report on a fraudulent network of Facebook pages and fake accounts seemingly linked to right-wing outlet the Epoch Times. Facebook today announced it was taking the network down, saying “our investigation linked this activity to Epoch Media Group, a US-based media organization, and individuals in Vietnam working on its behalf.”

No mention of Snopes, though the company points out its email describing the network was opened “hundreds” of times. That should give you an idea of relations between the companies.

Having readers chip in $5 toward a follow-up or expenses related to an investigation like this could be a great way to create small but noticeable change. They could also submit relevant information and tips.

Second, it could justify and power a news aggregator curated by Snopes staff, who sort through an immense amount of information for their work. “It’s not going to be comprehensive, but what we do put in there, we can back,” Green said. An early version will launch in the spring.

Other improvements are on the roadmap, such as a progressive web app version of the site and a better method for feedback and sourcing data from the community.

“We don’t have 2 billion users, we may not be some unicorn company, but damn, we can be something,” he said.

If ad revenue is drying up and the site finds itself in an adversarial relationship with potential funders, what are the other options? With less than a dozen people in its newsroom, Snopes is a pretty small operation. It may be that there’s room in the overtaxed hearts of users for one more subscription, if it’s for a service they’ve been using on and off already for two decades.


Source: Tech Crunch

Do more startups die of indigestion or starvation?

Hello and welcome back to our regular morning look at private companies, public markets and the grey space in between.

Today, we’re weighing a standard bit of startup wisdom that recently reemerged against some surprising, contrasting evidence. Does too much money hurt a startup more than it helps, or is that standard view actually mistaken? We’ll start with the traditional view, which was re-upped this month by venture capitalist Fred Wilson, along with some supporting arguments proffered by a Boston-based venture firm.

Afterwards, we’ll dig into a grip of contrasting data that should provide plenty to chew on over the holidays. Ready?

Fit to burst

Union Square Ventures‘ Fred Wilson wrote earlier in December (citing an excellent Crunchbase News piece by occasional TechCrunch contributor Jason D. Rowley) that he was curious if startups that raise huge ($100 million and greater) early-stage rounds do better or worse than their cohorts that raised only smaller sums.

Underpinning his question is Wilson’s belief that “performance of VC backed companies is inversely correlated to how much money they raise.” This makes good sense. And if anyone has enough anecdotal evidence to support the view, it’s Wilson who has been a venture capitalist since the late 1980s.

The idea that too much money is bad for startups isn’t hard to understand: startups need to focus and run fast; too much money can lead to both bloated operations, diffuse product direction and useless dalliances in cruft.

Startups also die when they have too little money, of course. But the concept that there is a midpoint between insufficient funds and an ocean of capital that is optimal has lots of credibility amongst the venture class. (I believe this is my favorite phrasing of the concept, that “more startups die of indigestion than starvation.”)

A 2016-era TechCrunch article written by some of the folks from Founders Collective makes the point plainly:

By examining the technology IPOs of the past five years, we found that the enriched (well capitalized) companies do not meaningfully outperform their efficient (lightly capitalized) peers up to the IPO event and actually underperform after the IPO.

Raising a huge sum of money is a requirement to join the unicorn herd, but a close look at the best outcomes in the technology industry suggests that a well-stocked war chest doesn’t have correlation with success.

In the spirit of fairness, I’ve long agreed with the above views.

My views on the question of too much money ruining organizations came from a different field, but are worth sharing for context. My father once told me an analogous story about a small poetry magazine, a publication that operated on the proverbial shoestring and was always weeks away from shutting down. But it limped along, barely keeping the lights on as it produced brilliant work.

Then, someone died and left the magazine a pile of money in their will — but the sudden influx of capital wrecked the publication and it eventually shut down.

In many cases, raising too much money too early can hurt a team or cause it to lose track of its mission. But for tech startups, on average, is that really correct?

Maybe not


Source: Tech Crunch

Daily Crunch: Facebook acquires a cloud gaming startup

The Daily Crunch is TechCrunch’s roundup of our biggest and most important stories. If you’d like to get this delivered to your inbox every day at around 9am Pacific, you can subscribe here.

1. Facebook acquires Madrid-based cloud gaming startup PlayGiga

Facebook is building out its gaming business — earlier this year, the company added its Gaming hub to the main navigation menu. And last month, it agreed to buy Beat Games, developer of popular virtual reality title Beat Saber.

PlayGiga, meanwhile has been working with telcos to create streaming game technology for 5G. It also developed a gaming-as-a-service platform, using Intel’s Visual Cloud platform, that will enable telcos and communication service providers to offer streaming games to their customers.

2. TiVo merges with technology licensor Xperi in $3 billion deal

Earlier this year, TiVo said it was preparing to split itself into two — a product and IP business — in order to make itself more attractive to buyers. Today, the company announced those plans have been put on hold as it has instead merged with technology licensor Xperi Corporation, in a $3 billion deal.

3. Spotify prototypes Tastebuds to revive social music discovery

Tastebuds (discovered by reverse engineering master Jane Manchun Wong) is designed to let users explore the music taste profiles of their friends. It will live as a navigation option alongside your Library and Home/Browse sections.

4. Uber’s ride-hailing business hit with ban in Germany

In Germany, Uber’s ride-hailing business works exclusively with professional and licensed private-hire vehicle companies — so the court ban essentially outlaws Uber’s current model in the country.

5. Snackpass snags $21M to let you earn friends free takeout

Sending people Snackpass rewards became a new way to flirt or show gratitude at Yale. And through the Venmo-esque Snackpass social feed, users could keep up with a fresh form of gossip while discovering restaurants.

6. PayPal completes GoPay acquisition, allowing the payments platform to enter China

Though China’s payment market today is led by local players, including eWallet providers like AliPay and WeChat Pay, there’s room for PayPal to grow in a market where digital payments per year are counted in the trillions, not billions, of dollars.

7. Tesla’s record stock price shows its investment in energy storage is finally paying off

A little over a year after sparking a legal firestorm for musing that he would take Tesla private for $420, Elon Musk is probably glad he didn’t. (Extra Crunch membership required.)


Source: Tech Crunch

Anybody can now make HomeKit accessories

Apple has released an open-source version of the HomeKit Accessory Development Kit. You can now fork it on GitHub and play around with it to integrate smart home devices in the Home app and beyond.

Today’s news is related to the Connected Home over IP effort, an industry-wide effort to build an open-source standard for the internet of things. Essentially, Apple, Amazon, Google, the Zigbee Alliance and smart home manufacturers want to work together so that accessories work everywhere.

HomeKit is lagging behind, although Apple arrived early in the connected home space. A ton of accessories now work with Amazon Alexa and Google Assistant, but you can control very few accessories with Siri, as HomeKit adoption has been slow.

By open-sourcing HomeKit, Apple hopes that more smart home manufacturers will try to integrate HomeKit in their prototypes. Everything has been released under the Apache 2.0 license.

As Next INpact noticed, if you want to release a HomeKit-compatible accessory, you still have to work with Apple to get a certification. And of course, manufacturers that work with Apple directly could potentially access unreleased features before they’re unveiled at WWDC.

Developers have already reverse-engineered HomeKit to add HomeKit compatibility to more devices with the Homebridge project. Now let’s see if it leads to more cool projects to make it easier to control your connected objects from your iPhone, iPad and other Apple devices.


Source: Tech Crunch

Over 1,500 Ring passwords have been found on the dark web

A security researcher has found on the dark web 1,562 unique email addresses and passwords associated with Ring doorbell passwords.

The list of passwords was uploaded on Tuesday to DeepPaste, an anonymous dark web text-sharing site, commonly used to share stolen passwords and illicit materials. A security researcher found the cache of email addresses and passwords, which can be used to log in to and access the cameras, as well as their time zone and the doorbell’s location, such as “driveway” or “front door.”

The researcher reported the findings to Amazon — which owns the Ring brand — but Amazon asked that the researcher not discuss their findings publicly.

At the time of writing, the dark web listing is still accessible.

It’s the second reported leak of Ring credentials today. Earlier on Thursday, BuzzFeed News reported that a similar cache of data on more than 3,600 Ring doorbells was posted online. The data appears to be a similar-looking data set to that which BuzzFeed obtained. Anyone with a working email address and password can log into a Ring account and obtain the Ring customer’s address, phone number and some payment information. The credentials also give the user access to the Ring devices in that home, including access to historical video data if the setting is enabled.

The dark web listing (Image: TechCrunch)

It’s not known how the data was exposed. Ring spokesperson Yassi Shahmiri did not return a request for comment. Ring told BuzzFeed that its systems were not breached, but the doorbell maker did not provide evidence for the claim.

TechCrunch contacted a dozen individuals whose information was found on the dark web listing. We provided each person with their password. Of those who responded, all confirmed that it was their password.

On our advice, all changed their passwords, and some enabled two-factor authentication on their accounts.

Nearly all of the passwords we reviewed were relatively simple and potentially easy to guess. It’s possible that the passwords were obtained by password spraying, a technique hackers use to guess passwords, or credential stuffing, where hackers take existing sets of exposed or breached usernames and passwords matched against different websites to access accounts.

It’s the latest security lapse involving Ring security cameras in the past week. News reports emerged last week of how hackers were breaking into Ring cameras around the U.S. Some crime forums are sharing tools to break into Ring accounts. Then earlier this week, Motherboard confirmed that Ring cameras have shoddy security measures — such as not telling users when other people log in, when the cameras are being actively watched and by using a weak form of two-factor authentication. Ring put much of the blame on the users for not using “best practices.” But others panned the response for failing to put in “basic security measures” to protect users.

Ring has also come under fire by lawmakers for its close relationship with law enforcement agencies around the U.S.

It’s not known how many sets of exposed Ring account credentials are floating around the dark web. Users should protect their accounts with strong, unique passwords and enable two-factor authentication.


Source: Tech Crunch