# Big Tech is Finally Moving Toward Security Features - Threat Wire

Source: https://www.youtube.com/watch?v=GXyLby0eyd0
Recap page: https://rapidrecap.app/video/GXyLby0eyd0
Generated: 2026-02-05T14:35:40.497+00:00

---
## Quick Overview

Big Tech companies like Apple, Meta, and Microsoft are increasing their focus on security features, with Apple limiting location tracking via cell towers, Microsoft phasing out the NTLM protocol in favor of Kerberos, and Meta introducing a 'Strict Account Settings' mode for high-risk WhatsApp users, while the open-source community faces risks from supply chain attacks like the XZ Utils backdoor and the end-of-life announcement for Ingress NGINX.

**Key Points:**
- Apple is rolling out a new privacy feature to limit the precision of location data shared with cellular networks, restricting tracking distance from cell towers.
- Microsoft is phasing out the New Technology LAN Manager (NTLM) authentication protocol in favor of stronger Kerberos-based alternatives, providing a plan for organizations to transition before Windows Server end-of-life support for NTLM.
- Meta introduced 'Strict Account Settings' for WhatsApp, a lockdown-style security mode aimed at protecting high-risk users, such as journalists and activists, from advanced spyware attacks.
- A former Google engineer was convicted on seven counts of economic espionage and theft of trade secrets for stealing thousands of documents related to AI supercomputer orchestration software and custom machine learning chips to build a startup in China.
- The Ingress NGINX open-source project announced its end-of-life date for March 2026, meaning no more bug fixes or patches will be released, urging users to migrate to alternatives like Gateway API.
- The XZ Utils backdoor, which aimed to create a backdoor allowing authentication bypass on Linux systems, was successfully mitigated because the community, including a Slack user, flagged the suspicious activity, preventing widespread compromise.
- The DDoSecrets group changed its primary domain from .com to .org following domain renewal failures, prompting an official notice to its audience.

![Screenshot at 00:19: An article overlay detailing Apple's new privacy feature that limits the precision of location data shared with cellular networks on iPhones and iPads, demonstrating one of Big Tech's moves toward enhanced security.](https://ss.rapidrecap.app/screens/GXyLby0eyd0/00-00-19.jpg)

**Context:** This episode of Threat Wire, hosted by Ally Diamond, covers several recent cybersecurity and privacy developments involving major tech companies and open-source projects. The main segments focus on new security measures being implemented by Apple, Meta, and Microsoft, alongside critical vulnerabilities and incidents affecting open-source software like XZ Utils and Ingress NGINX, highlighting ongoing efforts by both corporate giants and the open-source community to enhance digital security.

## Detailed Analysis

The video discusses recent security advancements and threats across the tech landscape. First, Big Tech is actively implementing new security features: Apple is rolling out a feature to limit location tracking precision via cell towers (00:13); Meta introduced 'Strict Account Settings' for WhatsApp users deemed high-risk (1:56); and Microsoft announced plans to phase out the legacy NTLM authentication protocol in favor of Kerberos by the next Windows Server version (1:11). Second, a former Google engineer was convicted for stealing over 2,000 documents containing trade secrets about AI supercomputer orchestration software and custom machine learning chips, intending to benefit Chinese entities (2:56). Third, the open-source community faced alarms as the Ingress NGINX project announced its end-of-life in March 2026, urging users to migrate immediately (6:15). Fourth, the severe XZ Utils backdoor, which allowed remote code execution via a compromised XZ utility, was successfully contained due to community vigilance, though the exact mechanism remains under investigation (5:13). Finally, the group DDoSecrets changed its primary domain from .com to .org after domain squatters exploited a registration lapse (8:15).

### Big Tech Security Moves

- Apple limits location tracking via cell towers (00:13)
- Microsoft phases out NTLM in favor of Kerberos (1:11)
- Meta introduces 'Strict Account Settings' on WhatsApp for high-risk users (1:56)

### Corporate Espionage

- Former Google engineer convicted for stealing AI secrets (2:56)
- Engineer stole over 2,000 documents related to AI supercomputing and custom chips (3:26)
- Engineer planned to use stolen knowledge to build a similar AI infrastructure company in China (3:45)

### Open Source Project Status

- Ingress NGINX project announced end-of-life for March 2026, requiring migration to alternatives like Gateway API (6:15)
- The maintenance team was a small group working in their free time (7:15)

### Critical Vulnerabilities

- The XZ Utils backdoor, a high-CVSS score vulnerability, was discovered and contained due to community vigilance before widespread deployment (5:13)
- The compromise was at the hosting provider level, not in the XZ code itself (5:33)

### Group Operations Updates

- DDoSecrets domain failed to renew, leading to a quick pivot from .com to .org (8:15)
- The group quickly announced the change to its audience (8:29)

### Community Engagement

- The host asks viewers for feedback on the Google engineer's actions and the XZ Utils situation (2:45, 9:47)

![Screenshot at 00:19: Article detailing Apple's new privacy feature limiting location tracking precision via cellular networks.](https://ss.rapidrecap.app/screens/GXyLby0eyd0/00-00-19.jpg)
![Screenshot at 03:07: Illustration depicting an attacker stealing files from filing cabinets, symbolizing the ex-Google engineer convicted for stealing trade secrets.](https://ss.rapidrecap.app/screens/GXyLby0eyd0/00-03-07.jpg)
![Screenshot at 05:12: Wikipedia entry for the XZ Utils backdoor, showing the CVE identifier \(CVE-2024-3094\) and the discoverer \(Andres Freund\).](https://ss.rapidrecap.app/screens/GXyLby0eyd0/00-05-12.jpg)
![Screenshot at 08:15: Important notice from DDoSecrets announcing their domain change from .com to .org due to a registration lapse.](https://ss.rapidrecap.app/screens/GXyLby0eyd0/00-08-15.jpg)
![Screenshot at 08:58: Article headline showing 21,000+ OpenClaw AI Instances Exposed Online due to personal configurations being left publicly accessible.](https://ss.rapidrecap.app/screens/GXyLby0eyd0/00-08-58.jpg)
