Huge Yahoo! authentification security bug


Recommended Posts

A huge bug has been discovered in Yahoo! authentification mechanism affecting third party applications, even those created by Yahoo!A member of the Yahoo! Mail Group has discovered that people having connected third party applications may have a problem if they lose their smartphone. Indeed, despite what Yahoo says, changing the password will not be enough. This will not totally revok access to those third party applications.

Explanations :

Someone using Yahoo! services and owning a smartphone may have have installed the Yahoo Mail application for Android, Yahoo! Messenger on Android and iOS or the Yahoo! Mobile application. Even though those have been developed by Yahoo! those are considered as third party applications just like Yahoo! Messenger for Mac OS X or web services inviting you to connect with your Yahoo! ID like Facebook or Twitterfeed.

Should that person lose his smartphone, he may go ahead and change his Yahoo! password so that no one can actually dig into the address book or read his email. Upon password change, Yahoo! mentions that third party applications access will be revoked, but in truth, the lost/stolen smartphone is not safer that before.

Web user ?sy1bzbn? explains:

What does this mean? It means if you were using the YMail app on your lostphone, then whoever has physical access to it can continue to READ, SEND, and REPLY. If you were using the YMessenger app, then that person can impersonate you until you signed into YMessenger elsewhere.

I myself tested this on the iPhone. After changing my password, a pop-up alerted me that a new authentification was necessary but I could simply tap on it to make it disappear and continue using the Yahoo! Messenger application. I was able to send messages, receive IM notifications, browse my contacts and see who was connected. People?s online status were properly updated live. In fact, I was able to access Yahoo! Messenger, even after rebooting the phone!

The connection was permanently maintained and one has to manually dig into the application options to turn it off. In fact I was able to connect both on my iPhone and on Yahoo! Mail Messenger with the updated password. Two instances were running and the conversations were updating on both screen. Remember ; the two sessions had two different passwords! Only the Yahoo! Voice calls failed to go through.That?s pretty bad for Yahoo!

Source : Clubic.com (French) - translated on Streamlog

if you had an application installed that had access to your account from your mobile device - and you lost one or more of your mobile devices, wouldn't you for starters report the phone lost/stolen and it would be disabled by your phone carrier?

Also wouldn't you just with common sense revoke said applications access to your account? Are you saying the user does not have the ability to revoke applications access to their account once given?

Not a yahoo user myself, but I would think you would have to have the ability to revoke applications access to your account whenever you deemed it fitting.

It does seem like an issue sure - but seems some common sense security measures would clearly mitigate the issue. I would have to think that once it has been pointed to yahoo that they would correct such a flaw posthaste?

@Budman no indeed you cannot really revoked access to those third party apps. Even if you dig in your Yahoo! account and revoke those access + change your password... someone finding your phone will still be able to use those applications with your ID. Those applications need to be manually logged out from the phone...

You tell me it's feature ? i tell you it's a huge bug

Web user ?sy1bzbn? explains:

What does this mean? It means if you were using the YMail app on your lostphone, then whoever has physical access to it can continue to READ, SEND, and REPLY. If you were using the YMessenger app, then that person can impersonate you until you signed into YMessenger elsewhere.

Isnt that stating the obvious. and I like how they say "Web User" haha as if they were some kind of Technology Expert lol

Again I am not a yahoo user, but I think its unfathomable to me that the user would not have the ability to REVOKE an applications access to their account?

On google for example

post-14624-0-72504500-1326837518.jpg

I can see how there could be an issue with just changing your password does not revoke. User would not like the fact that every time they changed their password all applications lost access. That could be a nightmare. But you should be able to REVOKE their access.

But yeah change of email password not revoking application access to me would seem like a feature ;) Users would be dumbfounded why X no longer worked every time they changed their yahoo email password.

I don't see a major issue with that, IF the user can directly revoke access from said application via some method.

edit: ok quick google ;)

http://help.yahoo.com/l/us/yahoo/developer/moreinfo/moreinfoapis.html

Changing Permissions If you previously granted a third-party application access to your data, you may revoke permissions at any time by visiting your Application Management page. Doing so might adversely affect the performance and functionality of installed applications if it requires access to your profile data.

Seems like to me you can revoke access whenever you want.

The above article says the user changed his password, he says nothing about actually revoking access.. So I would have to agree, like I said an application should not be revoked just because you changed your yahoo email password. That would be a big issue for lots and lots of users!!

edit2: I think I might try this, I know I can install yahoo on my blackberry -- I think I will give it a try. Because sofar it seems like this article is pure scaremongering from what I can tell. No **** changing your password on your email should not revoke all applications access, why would anyone think that. And where did they read that from yahoo?

Ok created an yahoo account.. Logged in, then when to change my password - I don't see anything saying my applications access will be revoked?

post-14624-0-82083300-1326838537.jpg

Now I have to leave - the beer after work is calling me ;) But while at the bar I will install yahoo on my phone. And then later I will revoke it and see what happens..

If you want to chat with me at the bar, my new yahoo account is [email protected] ;)

@ChuckFinley : "Isnt that stating the obvious. and I like how they say "Web User" haha as if they were some kind of Technology Expert lol"

And you think you are.... ?

@Budman : Again

I had Yahoo Messenger installed and running on the iPhone.

I quit the app

I changed my password

I got a message telling me that my third party application would not work

I check my iPhone=> Yahoo! Messenger still working

Also manually revoking access to 3rd party apps through the account notification would not do it.

I check my iPhone=> Yahoo! Messenger still working

Not sure how to make it clearer

Again no where on the change password page does it say its going to revoke anything??

I changed my yahoo account password, did not say anything about revoking my apps

here are my apps

post-14624-0-59087300-1326864803_thumb.p

So after I changed my password on my Account I went back to my kindle fire - and says sign in required, and will not let me access my mail. No hitting cancel or backspace, etc.. did not let me in. So from my own testing so far is not matching up with what your saying.

Here is me changing my password -- where are you saying your getting told changing your password will revoke or break your applications?

post-14624-0-78454700-1326865357.png

Now in the morning I will try it on my blackberry and see what happens with messenger app, wouldn't install on my KF but got a IMO app to work with yahoo, but I want to test actually chatting and contacts etc.. and then go in and test.

But so far changing password blocked access on my KF yahoo mail app, and I didn't even revoke access.

@BudMan : "I changed my yahoo account password, did not say anything about revoking my apps"

Really ? ...I did the process again, here is what i get

screenshot20120118at911.png

I went back to my Yahoo! Messenger on the iPhone and here is what i get:

doneme.jpg

Now as stated before, all i have to do is to tap on this notification to continue using the application logged in with a different password (the previous one). And again, as stated before, i can reboot the phone or quit the application so that it's not running in the background... i'll still be able to use it. I have to manually sign out byt going into the options at shown below :

photo180112092142.png

What is "Yahoo! Go Phone" -- I do not think that is the messenger app your using. Which I see here and doesn't seem like its called that

http://itunes.apple....d309219097?mt=8

So ok it revoked app A, does not mean app B will not still work.. Like I said changing your password should really not revoke apps.

I went to go check my blackberry this morning - and it seems our IT dept has blocked by policy messenger ;) Other yahoo app I found was just a mobile frontend not really an app. Wait til my son wakes up and will try on his phone, I know he uses yahoo messenger..

Dude sorry what I am seeing is not matching up with what your saying.. Now go into your apps, see that link there and do you see a messenger link. Revoke THAT, now does you messenger work on your phone?

Well, anyways, I contacted Yahoo! Security a few days ago and they came back to me saying that in some cases they found no problem and in other cases they were able to replicate the problem. I was told that they were working on a fix. That's the good news for Yahoo! users i guess :)

Not sure how this is gonna be deployed. Either though an app update or on their server side...

You find it "unlikely". Seriously, who do you think you are to judge each of my posts like this ?

if I tell this happened, then this happened.

But then you know what. i could as well say that i don't believe what you said earlier. You just photoshoped images and invented a story as well.

It was not an email it was a phone call.

You want to see the previous warning i sent to them ? Sure. Do you read French? here is the first reply

http://img814.images...2789/emailf.jpg

Have fun

I work as a journalist and this French Yahoo! PR contacted Yahoo Security EMEA and Sunnyvale and call me back at lunch time

Do you also want her phone number to check ? Cause i can give it to you if you're still skeptical ? You wanna call her? Let me know i'll PM you her number but then you better record your phone conversation.

Dude I am not judging your posts, I am just saying I could not duplicate anything you were saying.

You post something that could be seen as pure SCARE MONGERING and yahoo bashing -- ie their security is flawed.

Your tests should be very easy for someone to duplicate -- I don't see anyone here in this thread saying they could duplicate your example. Seem I was the only one even attempting to verify your statements. And from my test they did not hold water - sorry!

So have you actually went in and revoked access to messenger?

I really shouldn't have to repeat myself that changing a password does not mean applications that you have given access to should be revoked from said access.

Your post of Go Yahoo when you changed your passed -- that does not seem like "messenger" to me.

So post up your applications -- I posted mine showing messenger and mail applications having access. And all I had to do was change my password and email on my KF instantly required password to re access. But to be honest I should really have to revoke the access directly to cause what it did.

So actually Revoke messanger application from having access and then lets see your access and there might be something to talk about.

You have not shown anything backing up your claim that makes sense, and then you say you contacted Yahoo and they got back to you saying that they duplicated your issue some times, in 2 days they lab this out and got back to you -- come on dude how can someone not be skeptical at such claims.

Again what do you not understand here?

YES i did manually revok those applications and YES again, described in the first post, i was able to access Y! Messenger after that

Yahoo Go Phone is a former java-based Yahoo Mobile app. It is immediately added to my Yahoo account when first signing Yahoo! Messenger on the iPhone which means that Yahoo Go became Yahoo! Messenger

And this is precisely written by the web user in the link i mention in my 1st post.

http://groups.yahoo.com/group/Y-Mail/message/22692

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • 7 Days: Windows 11 turns five, Ford made a mistake, and Starlink plans direct mobile service by Aditya Tiwari 7 Days is a weekly roundup of picks of what's been happening in the world of technology - written with a dash of humor, a hint of exasperation, and an endless supply of (black) coffee. This week's highlights include Apple's $4 billion class-action lawsuit, a smartphone with a 14,000 mAh battery, Google catching up with Anthropic, and the Steam Summer Sale 2026. Let's get started. You can check out the recent issues of the 7 Days weekly roundup. Windows 11 turns five Microsoft's Windows 11 operating system completed five years of existence on June 24 this week. According to the latest data, the controversial operating system now runs on almost 72% of Windows PCs worldwide. The launch of Windows 11 had several dramatic twists and an entire preview build leaked ahead of launch. Ford made a mistake Many would agree that one of the biggest mistakes the automobile industry made was surrendering to the giant touchscreens and removing physical buttons. However, Ford made even more. The company executives said they made a mistake by replacing human engineers with AI. Ford admitted that AI couldn't replace experienced engineers and the company is rehiring veterans to improve quality and cut recall costs. Starlink mobile service Elon Musk's SpaceX wants to use its massive constellation of satellites to power your phone's network. The company is reportedly considering building a terrestrial mobile network to complement Starlink’s satellite coverage and planning to sell mobile phone plans directly to customers in the US as part of a wider expansion of Starlink. Our Features Our coffee-powered team published a platter of editorials, opinion posts, hands-on experiences, and guides. Check them out: Hey Google, these are the Gemini features I want in 2026 You've tried DuckDuckGo and Brave Search, now get serious with SearXNG Why Delta Chat is the best decentralized messenger you have probably never tried We check out the SKG PS700 Neck Massager SKG Hand Massager with Heat OS500 hands on Hands-on with BOOX Tappy: cute little reading accessory Hands-on with the ProtoArc EM25: Affordable ergonomic mouse that focuses on the right things Hands-on with iFlyTek AINote 2 E-Ink tablet: insanely thin and smart This week in software news Catch up on some of the latest software news updates that arrived throughout the week: Firefox 152.02: The latest browser update brought fixes for performance, translation, and cloud storage services. It addressed problems with localization, playback issues with certain MP4 files, and performance issues on websites that perform multiple encryption operations simultaneously. Ubuntu Livepatch: Canonical's zero-downtime service Livepatch arrived on Arm64 devices running Ubuntu Core 26 and Ubuntu 26.04 LTS. Livepatch allows users to apply important kernel updates without any service interruption or rebooting. AMD 26.6.2 driver: The new driver version for Radeon hardware owners brought FSR 4.1 upscaling tech to an entire generation of its products: the RX 7000 series. However, the 26.6.2 FSR driver flew dark clouds over users, breaking many Windows PCs and causing a yellow bang or other launch failures on Windows 10. AMD later pushed the 26.6.3 Hotfix update to fix the issues. Goodbye Notion email: It's been a little over a year since the AI-powered email client launched. The company has announced its shutdown, which will take effect on September 22, and said it doesn't see the point in maintaining a frontend email client when people are moving towards automation. Ventoy version 1.1.14: The biggest change in the Rufus alternative is an updated Secure Boot shim file to resolve the UEFI CA 2023 issue, a compatibility problem that affected Secure Boot environments on some systems. This week in hardware news Image: Valve Catch up on some of the latest software news updates that arrived throughout the week: 14,000 mAh battery: Yes, that's something that iPhone users can only dream of. But a Chinese company is reportedly developing a smartphone with a 14,000mAh battery. If it ever sees daylight, it would be the largest battery ever on a smartphone, possibly offering a week of backup on a single charge. Steam Machine prices: Valve finally confirmed the Steam Machine's pricing. Starting at $1,049 for the 512GB option, storage and the included controller are the biggest differences among the four variants presented. Xbox just got more expensive: Rising costs of storage and memory prompted Microsoft to raise prices. Xbox Series X|S models wth 512GB storage will cost $100 extra, and 1TB models will cost $150 extra. However, the Redmond giant discounted the 2TB models. New NVIDIA supercomputers: The company announced plans to deploy 35 high-performance (HPC) AI supercomputers across Europe this year, primarily at national supercomputer centers, AI factories, and research institutes. Fast fast memory: Samsung built the UFS 5.0 storage solution, which pushes the data transfer speeds to 10.8 GB/s on mobile devices. It can open doors for faster local AI performance, which otherwise doesn't look promising under the current scenario. Custom chips for TikTok: Qualcomm is reportedly in talks with ByteDance to build custom video chips optimized for its massive data center workloads. ByteDance needs hardware that can help it ingest, process, and serve billions of short-form videos daily. OpenAI Jalapeño: The AI giant announced its first custom-designed AI chip developed in partnership with Broadcom. Jalapeño is designed specifically for large language model inference and is the first product from a multi-generation compute platform being developed by OpenAI. Galaxy A27 5G: The new mid-range smartphone from Samsung arrived with a platter of updates over A25 5G, including a 120Hz refresh rate, Infinity-O punch-hole camera design, expanded AI features, and more. Qualcomm takes on NVIDIA: The chipmaker baked the new Dragonfly CPU, High Bandwidth Compute technology, and AI chips to challenge NVIDIA in the AI data center market. Qualcomm said its new lineup improved per-watt performance, token throughput, and total cost of ownership for AI data centers. IBM goes sub-1nm: The company reached a semiconductor milestone by announcing the world's first sub-1-nanometer chip technology, based on a 0.7nm (7-angstrom) node. It can pack nearly 100 billion transistors onto a chip the size of a fingernail. This week in Google News Image: Google Catch up on some of the latest Google news updates that arrived throughout the week: What to expect from the Pixel 11 series: The upcoming lineup is expected to feature four different variants and a price hike due to the global memory shortage. Read our detailed coverage to know about the expected Pixel 11 specs. Stopping Google: The Free Software Foundation Europe urged the European Commission to stop Google from silently reinstalling AI models and requiring registration. Users should be able to fully uninstall AI-based features from Android devices and access interoperability features. Chasing Anthropic: The Claude-maker is making new strides every day in the AI world, but the search giant is struggling to catch up. Google is said to be reshuffling its AI coding "strike team" it created roughly about two months ago, turning it into a broader model-training group amid talent losses at DeepMind. New Google Play billing: Google has faced a long legal battle with Epic Games, and the search giant is rolling out a redesigned Play Store billing and fee structure. Available in the US, UK, and the European Economic Area, it will take effect on June 30. Error-free Sheets? A new feature in Google Sheets allows Gemini to inspect formula errors and apply corrections directly in the spreadsheet. Google said the new feature can handle pretty much everything from basic arithmetic to very complex calculations. Breeze through airports: Google Wallet became the first digital wallet to integrate with TSA PreCheck Touchless ID, a program that enables travelers to move through airport security checkpoints using facial recognition instead of a physical ID or boarding pass. Built-in computer control: Gemini 3.5 Flash got a built-in tool called Computer Use, which allows developers to build agents that navigate browsers, mobile interfaces, and desktop applications. Google Finance: The redesigned platform is now out of beta. Google has added several new features, including portfolio tracking, scheduled market briefings, and a dedicated Android app. An iOS app is planned for later in 2026. This week in Apple News Image: Apple Catch up on some of the latest Apple news updates that arrived throughout the week: Trade secrets reportedly exposed: Apple's manufacturing partner in India, Tata Electronics, confirmed a cybersecurity attack on its systems that may have exposed trade secrets of Apple and Tesla. Hackers reportedly stole up to 630 GB of data and posted up to 200,000 files on the dark web. Grab your payout: Apple is facing a class-action lawsuit in the UK and might end up paying $4 billion (£3 billion) if it loses. The iPhone-maker has been accused of trapping users in iCloud by restricting rivals from fully accessing iOS. The tribunal recently set a full trial date for October 2028. iOS 27 Beta 2: Apple's latest iPhone update is moving forward, and a new beta was pushed this week. While iOS 27 Beta 2 for developers pushed several bug fixes across the system, the AirPort Utility was deprecated; it's no longer available to new users. Price hike: Just like others, Apple has raised prices of several MacBook and iPad models, including the MacBook Neo, which now starts at $699. This comes after reports that this year's iPhone will also become expensive. Second-gen iPhone Fold: While the world is desperate to see Apple's foldable iPhone, leakers have started to talk about its second generation. Apple is expected to launch a successor in Fall 2027, featuring a wider folding display while reusing the same screen found in the first generation. The search for memory: Apple is reportedly looking at blacklisted Chinese companies amid rising memory chip prices. The company is seeking clearance from the Trump administration to purchase memory from ChangXin Memory Technologies (CXMT). This week in Meta news Image: Meta Catch up on some of the latest Meta, WhatsApp, and Instagram updates that arrived throughout the week: WhatsApp gets a new final boss: Mark Zuckerberg announced that CRED's Kunal Shah will become the next global head of WhatsApp, as Will Cathcart steps down and moves to a new role at Meta. The social media giant invested money in CRED through a Series H funding round. AI glasses in 26 styles: A new line of Meta Glasses launched in partnership with EssilorLuxottica. Starting at $299, it comes in more than two dozen styles across different colors, lenses, and frames. More ways to doomscroll: Instagram for TV is now available on Samsung smart TVs launched in 2020 and later years. The company also announced that it's testing several new features on Instagram for TV, bringing it closer to YouTube and Netflix. This week in AI news Image: Microsoft Catch up on the latest artificial intelligence news updates that arrived throughout the week: Water-saving data center: Microsoft is building a gas-powered AI data center with a capacity of 2 gigawatts. The company will deploy a closed-loop cooling system, saying that its total lifecycle water use will be "only a fraction of that consumed annually by a typical fast-food restaurant.” OpenAI beats Claude Mythos: GPT-5.5-Cyber got a limited release for verified defenders. It scored 85.6% on CyberGym, compared with 81.8% for GPT-5.5 and 83.8% for Claude Mythos 5. The AI giant also announced a limited preview of its new GPT-5.6 model series, whose flagship model, GPT-5.6 Sol, is targeted at demanding reasoning and agentic workloads. Proceed with caution: The Trump administration instructed OpenAI to limit the distribution of GPT-5.6 to a small group of government-approved partners rather than the general public, as has happened in the past. Claude Tag: Anthropic launched its new AI teammate for Slack, enabling teams to delegate tasks to Claude directly within Slack channels. What makes it different is that it's designed to operate as a shared assistant for an entire team rather than a single user. Challenging US dominance: The UK government has funded £60 million ($70 million) to Oxford and UCL to keep the country in the AI race by building open-source, low-hardware alternatives. The two organizations will share the money over six years. Paying for AI development: One cost is the loss of human jobs. Oracle laid off about 21,000 employees (13% of its workforce) amid increasing AI adoption. The software giant said that AI advancement and adoption "may continue to result in reductions to our workforce." GitHub strips features: It removed the ability to manually detect an AI model from its Copilot Free and Student plans. In other words, its automatic routing system is the only way to choose a model. Are you a copycat? Anthropic accused Alibaba of creating about 25,000 fraudulent accounts to copy Claude's capabilities at scale. It told US lawmakers that operators linked to Alibaba generated 28.8 million exchanges with Claude between April 22 and June 5, 2026. Reserve my memory: The semiconductor company Micron revealed that AI companies are spending billions to lock up its memory years in advance. Its customers have locked in $22 billion worth of memory supply commitments. Another AI battle: A publisher group that collectively owns 400 newspapers sued OpenAI and Microsoft for scraping their content to build AI chatbots such as ChatGPT and Copilot without compensation. Anthropic AI ban: The US government partially reversed the Anthropic AI ban, allowing it to restore Claude Mythos 5. However, it can only be deployed for a limited set of US organizations that operate and defend critical infrastructure. This week in Microsoft News In some of the hottest stories of the week: Windows 10 quietly gained a year of support and updates, Windows 11 KB5095093 released with a long list of features, and Windows 11 26H2 is finally getting the ability to disable web search results in Windows 11 Search. You can check out Taras's freshly baked Microsoft Weekly roundup to catch up on all the interesting stories this week. This week in science news Image by Pascal Küffer via Pexels Catch up on some of the latest science and out-of-this-world updates that arrived throughout the week: 13 billion-year-old secret: Scientists found that the universe's first molecule (helium hyride) reacted with hydrogen much faster in cold temperatures than previously believed. It's a new breakthrough that changes our understanding of early star formation. Cosmic Living Fossil: Astronomers found CR3, a surprisingly pristine 11.5-billion-year-old galaxy dubbed a "living fossil." It suggests the universe's first generation of stars formed much later than previously assumed. Einstein's 100-year-old theory: Thanks to relativity, researchers calculated that clocks on Mars tick 477 microseconds faster per day than on Earth. This minute gravitational difference is crucial for synchronizing future interplanetary space missions. Don't panic: NASA's James Webb Telescope finally eliminated the threat of asteroid 2024 YR4 striking the moon in 2032. The rocky giant will give us a safe fly-by without causing any harm. This week in gaming? The latest issue of Pulasthi's Weekend PC Game Deals curates several exciting games on sale this week. RollerCoaster Tycoon 3 Complete Edition and Voidwrought have replaced the old titles in this week's Epic Games Store giveaway. For Xbox Free Play Days, the new titles include House Flipper 2, Blades of Fire, and Assetto Corsa Competizione. Steam Summer Sale 2026 kicked off with discounts for everything from the newest games and retro gems to all sorts of DLC packs, until July 9. Meanwhile, NVIDIA GeForce NOW added support for several new titles, including Dark Scrolls, SAND: Raiders of Sophie, and EMPULSE. That said, here are some more stories from the gaming world: Age of Empires Mobile comes to PC, here's how to carry over progress from your phone Xbox Insiders get Xbox 360 achievements and Gamertag character upgrades Grand Theft Auto VI pricing revealed alongside Ultimate Edition and pre-loading details Sony announces Bungie layoffs that will affect "significant number of employees" From the review corner This week, Steven published a review of the TerraMaster F4-425 Pro AI-powered NAS, featuring an all-metal exterior on the lines of the four-bay F4-425 series. Powered by the octa-core Intel Core N350, the TerraMaster F4-425 Pro is highly energy-efficient, operates quietly, and offers three M.2 slots. On the flip side, OpenClaw support requires removing security hardening (SPC), AI requires a paid subscription, the software feels like a beta, and the rubber feet constantly come unstuck. ZimaBoard 2 1664 Starter Kit Another NAS setup reviewed this week is the ZimaBoard 2 by IceWhale Technology. It comes in a small footprint with great modern hardware through a combo of Intel N150 and DDR5 memory support. On the downside, the memory is not upgradeable, ZimaOS is a bit barebones, factory reset requires USB flashing, and there is no automatic backup via the mobile app. Synology's BeeCamera software Christopher wrote his review of the software that powers BeeCamera Plus and said "the BeeCamera app is a great way to add private home monitoring to your network but there are some limitations." It's free with an easy setup process, fast response time, and good AI and detection features. However, there is no desktop version; it only works with Synology cameras, some configurations are difficult to set up on a phone, and it lacks the features of the surveillance station. More price drops! We got you covered with some hot tech deals all week. For some reason, if you missed out on a great discount, here is a summary of some recent deals that are still alive: Onkyo Dolby Atmos AV receivers are really solid deals 4TB TEAMGROUP MP44Q, 2TB T-Force G50, and 2TB WD My Passport SSDs drop to great prices Edifier S3000MKII hi-fi audiophile grade bookshelf speaker is at its lowest price now The best controller for XBOX and PC is down to the lowest price Limited time Prime Day deal cuts price of this Hisense 65" 4K smart TV in half To view all of our recent deals, click here. So, these were some of the biggest tech news and other updates from this week. There will be more issues of our 7 Days series in the coming weeks and months, so stay tuned. You can also support Neowin by registering for a free member account or subscribing to extra member benefits, along with an ad-free tier option. Have a great weekend!
    • Zen Browser 1.21.4b by Razvan Serea Zen Browser is a privacy-focused, open-source web browser built on Mozilla Firefox, offering users a secure and customizable browsing experience. It emphasizes privacy by blocking trackers, ads, and ensuring your data isn't collected. With Zen Mods, users can enhance their browser experience with various customization options, including features like split views and vertical tabs. The browser is designed for efficiency, providing fast browsing speeds and a lightweight interface. Zen Browser prioritizes user control over the browsing experience, offering a minimal yet powerful alternative to traditional web browsers while keeping your online activity private. Zen Browser’s DRM limitation Zen Browser currently lacks support for DRM-protected content, meaning streaming services like Netflix and HBO Max are inaccessible. This is due to the absence of a Widevine license, which requires significant costs and is financially unfeasible for the developer. Additionally, applying for this license would require Zen to be part of a larger company, similar to Mozilla or Brave. Therefore, DRM-protected media won't be supported in Zen Browser for the foreseeable future. Zen Browser offers features that improve user experience, privacy, and customization: Privacy-Focused: Blocks trackers and minimizes data collection. Automatic Updates: Keeps the browser updated with security patches. Zen Mods: Customizable themes and layouts. Workspaces: Organize tabs into different workspaces. Compact Mode: Maximizes screen space by minimizing UI elements. Zen Glance: Quick website previews. Split Views: View multiple tabs in the same window. Sidebar: Access bookmarks and tools quickly. Vertical Tabs: Manage tabs vertically. Container Tabs: Separate browsing sessions. Fast Profile Switcher: Switch between profiles easily. Tab Folders: Organize tabs into folders. Customizable UI: Personalize browser interface. Security Features: Inherits Firefox’s robust security. Fast Performance: Lightweight and optimized for speed. Zen Mods Customization: Deep customization with mods. Quick Access: Easy access to favorite websites. Open Source: Built on Mozilla Firefox with community collaboration. Community-Driven: Active development and feedback from users. GitHub Repository: Contribute and review the source code. Zen Browser 1.21.4b changelog: New Features Updated to Firefox 152.0.2 and 152.0.3 Added 'Edit pinned tab' context menu item to manually set a pinned tab's URL Added 'Add Route for Domain' context menu item to quickly add a tab's domain to the Space Routing settings Fixes Prevent sidebar from flickering when moving a tab (#14131) Full-screening while on a glance tab will now expand the glance tab to a normal tab (#11766) Fixed space routing tabs opening in background when it should be in foreground (#14183) Other minor bug fixes and improvements. Download: Zen Browser | 90.2 MB (Open Source) Download: Zen Browser ARM64 | Other Operating Systems View: Zen Browser Home Page | Screenshots 1 | 2 | Reddit Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • I was using searxng for about a year , self hosted, but results were starting to timeout and eventually it became unusable so I switched to degoog. Much better for my needs, more polished and add-ons like maps and calculations etc
    • Fake Superman doing the Anti-Trump PR for us, good man !
  • Recent Achievements

    • One Month Later
      Excellence2025 earned a badge
      One Month Later
    • Week One Done
      Excellence2025 earned a badge
      Week One Done
    • Week One Done
      flexorcist earned a badge
      Week One Done
    • One Month Later
      Woland13 earned a badge
      One Month Later
    • Week One Done
      Woland13 earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      504
    2. 2
      +Edouard
      205
    3. 3
      PsYcHoKiLLa
      149
    4. 4
      Steven P.
      72
    5. 5
      FloatingFatMan
      68
  • Tell a friend

    Love Neowin? Tell a friend!