Skip to main content

Encryption

See All Stories

HTTPS bug leaves 1,500 iOS apps vulnerable to man-in-the-middle attacks, finds analytics company

Site default logo image

The buggy code highlighted by arsTechnica

A bug in the way that 1,500 iOS apps establish secure connections to servers leaves them vulnerable to man-in-the-middle attacks, according to analytics company SourceDNA (via arsTechnica). The bug means anyone intercepting data from an iPhone or iPad could access logins and other sensitive information sent using the HTTPS protocol.

A man-in-the-middle attack allows a fake WiFi hotspot to intercept data from devices connecting to it. Usually, this wouldn’t work with secure connections, as the fake hotspot wouldn’t have the correct security certificate. However, the bug discovered by SourceDNA means that the vulnerable apps fail to check the certificate … 
Expand
Expanding
Close

All aboard the hyperbole train: Manhattan district attorney says iPhone security helps terrorists

Site default logo image

We’ve heard some pretty outrageous ramblings from the government regarding Apple’s use of encryption in its mobile devices in the past—including a claim from the Department of Justice that some day it will result in the death of a child—but Manhattan district attorney Cyrus Vance, Jr. might have just dethroned the DOJ as king of hyperbole.

Yesterday morning during a radio interview, Vance claimed that Apple’s encrypted software will make the iPhone the communication tool of choice for terrorists:


Expand
Expanding
Close

Snowden: The CIA has been working “for years” to break iPhone, iPad and Mac security

Site default logo image

Update: One of the approaches suggested – modifying Xcode to inject malware – has now been used, though we don’t at this stage know who was responsible.

The Central Intelligence Agency has conducted “a multi-year, sustained effort to break the security of Apple’s iPhones and iPads,” claims The Intercept, referencing new Snowden leaks of a document from the CIA’s internal wiki system.

A presentation on the attempts, focusing on breaking Apple’s encryption of iOS devices, was said to have been delivered at an annual CIA conference called the Jamboree.

Studying both “physical” and “non-invasive” techniques, U.S. government-sponsored research has been aimed at discovering ways to decrypt and ultimately penetrate Apple’s encrypted firmware. This could enable spies to plant malicious code on Apple devices and seek out potential vulnerabilities in other parts of the iPhone and iPad currently masked by encryption.

One route reportedly taken by the CIA was to create a modified version of Xcode, which would allow it to compromise apps at the point at which they are created … 
Expand
Expanding
Close

Tim Cook talks Snowden, Apple Car and Steve Jobs as the best teacher he’s ever had

Site default logo image

Tim Cook appears to be using his international tour, which so far includes Israel, Germany and the UK, to push a second product every bit as hard as the Apple Watch: privacy. In an interview with the German newspaper BILD posted yesterday (paywall), Cook went as far as to praise Edward Snowden for his role in prompting discussion of the issue.

If Snowden did anything for us at all, then it was to get us to talk more about these things. [Apple’s] values have always been the same.

The comments follow a meeting with German Chancellor Angela Merkel, at which data privacy was reportedly a key topic. Cook also told the Telegraph last week that “none of us should accept that the government or a company or anybody should have access to all of our private information.” Cook has in the past resisted FBI pressure to compromise its strong encryption, and was the only tech CEO to attend a recent White House cybersecurity summit.

In the BILD interview, Cook reiterated Apple’s stance on privacy, and also said that as Apple had grown larger, it had taken deliberate decisions to be less secretive about some aspects of its business … 
Expand
Expanding
Close

Tim Cook scheduled to speak at White House cybersecurity summit this Friday

Site default logo image

Apple CEO Tim Cook is scheduled to speak at a White House “cyber summit” at the end of the week, The Hill reported today. The White House is expected to unveil a new cybersecurity program during the summit, and is bringing together leaders in technology and government to address the issue.

Cook’s exact talking points haven’t been revealed, but Apple has previously taken strong stances on issues of customer privacy—putting it in direct conflict with the Department of Justice at times.


Expand
Expanding
Close

1Password for iOS adds one-time password tool for two factor auth, new login creator, more

Site default logo image

The popular secure password management app 1Password is out with a big update today adding new features on both iOS and Mac. Arriving in version 5.2 of 1Password for iOS is a new login creator tool, a one-time password tool for use with two factor auth, new entry fields for pro users, and more. On the Mac side, 1Password version 5.1 was released adding a number of improvements to sync. This includes the ability to sync secondary vaults to iOS over WiFi. More on the major new features below:


Expand
Expanding
Close

British prime minister says he’ll ban encrypted chat apps if he can’t see your messages

Site default logo image

For several months we’ve followed the U.S. government’s attempts to work around encryption in chat apps, even taking the hyperbole to an illogical extreme at one point, but we haven’t yet seen similar threats from other nations… or at least, we hadn’t until today.

British prime minister David Cameron said today that unless the government is given backdoor access to encrypted messaging services, he’s just going to outlaw them:


Expand
Expanding
Close

NY district attorney says Apple’s encryption policy “an issue of public safety” for law enforcement

Site default logo image

Bloomberg reports that a Manhattan District Attorney is challenging recent moves by Apple, Google and other tech companies by suggesting government pass laws that prevent mobile devices from being “sealed off from law enforcement.” In an interview this week, the government official called it “an issue of public safety.”
Expand
Expanding
Close

Department of Justice: iPhone encryption will lead to the death of a child

Site default logo image

Apple and the government have long been engaged in a bitter war of words over encryption and security practices employed in Apple’s iOS devices, but a new Wall Street Journal report indicates that the Department of Justice is really starting to take the rhetoric to the next level.

According to the Journal, a DOJ official actually told Apple executives during a meeting last month that in the future the Cupertino company could eventually be directly responsible for the death of a child.
Expand
Expanding
Close

FBI director continues push against Apple & Google on smartphone encryption (Video)

Site default logo image

FBI Director James Comey isn’t backing down from his position that Apple and Google are wrong to encrypt customer smartphone data preventing law enforcement agencies the possibility of access if requested. After last month sharing that the FBI was in talks with the two companies to discuss concerns with marketing devices as being inaccessible to third-parties including the government, the FBI Director spoke with CBS News in an interview where he continued to make the case against such encryption…
Expand
Expanding
Close

Site default logo image

Talking Schmidt: Google ‘far more secure & encrypted’ than Apple

There’s been an awful lot of Schmidt talk lately with the Google chairman’s new book How Google Works available for your reading and analysis, and Eric Schmidt continued his defense of Google after Apple CEO Tim Cook’s recent comments contrasting the two competitors on privacy. “Someone didn’t brief him correctly on Google’s policy,” Schmidt told CNN adding that Google’s systems “are far more secure and encrypted than anyone else including Apple.” Schmidt did credit Cook for correctly pointing out ads on Gmail, though, so they can at least concede on that point. Video below:


Expand
Expanding
Close

US attorney general latest gov’t official to challenge Apple on smartphone encryption

Site default logo image

United States Attorney General Eric Holder, who announced plans to resign earlier this week pending confirmation of a successor, has criticized Apple and Google for encrypting smartphone data beyond law enforcement official access, Reuters reports.

“It is fully possible to permit law enforcement to do its job while still adequately protecting personal privacy,” Holder said in a speech before the Global Alliance Against Child Sexual Abuse Online.


Expand
Expanding
Close

FBI director says officials have been in talks with Apple, Google over device encryption policies

Site default logo image

Director of the Federal Bureau of Investigation James Comey expressed his concern today over Apple and Google’s decision to encrypt information stored on smartphones, the Huffington Post reports, adding that FBI officials are pushing both companies to change their policies in order to allow law enforcement officials to access data in certain instances.

“I am a huge believer in the rule of law, but I am also a believer that no one in this country is above the law,” Comey told reporters at FBI headquarters in Washington. “What concerns me about this is companies marketing something expressly to allow people to place themselves above the law.”

In the case of the iPhone maker, Apple CEO Tim Cook used the company’s privacy stance as a major marketing point on a number of occasions over the past month.
Expand
Expanding
Close

Site default logo image

Apple releases Safari 7.1 for Mavericks w/ DuckDuckGo search engine, encryption for Yahoo searches

Apple has just released Safari 7.1 to all users of OS X Mavericks following several beta releases in recent weeks. The update adds DuckDuckGo as a default search engine option, which was also just added to Apple’s mobile version of Safari alongside iOS 8. The update also includes a security improvement for Yahoo search engine users: Apple says Yahoo searches from the search field are now encrypted. 

In addition, Apple notes the release improves Reader and AutoFill compatibility with websites.

The release follows OS X 10.9.5 becoming available to all users yesterday with Safari 7.0.6. The Safari 7.1 update is available to users on OS X Mavericks 10.9.5 now through Updates in the Mac App Store. 

Site default logo image

CNN iPhone app exposing login info of its iReporters unencrypted, according to security researchers

Update: Apple tells us CNN submitted fixes for both their iPhone and iPad apps that are now live on the App Store.

Security researchers at Zscaler claim to have found a security flaw in CNN’s iPhone app that exposes personal login and passwords of its users. The CNN app for iPhone, which includes an iReport feature that allows users to sign-up and submit news stories, is reportedly not using SSL encryption for registration/login and SSL certificate pinning like its Android app counterpart and sending the personal user info to and from the app unencrypted. The report notes that CNN’s iPad app is not subject to the same vulnerability as it currently doesn’t have the iReport feature:

The current CNN for iPhone App (verified on Version 2.30 (Build 4948)) has a key weakness whereby passwords for iReport accounts are sent in clear text (unencrypted). While this is always a problem, it’s especially concerning that this relates to functionality which permits people to anonymously submit news stories to CNN. This occurs both when a user first creates their iReport account and during any subsequent logins.

As can be seen, both transmissions are sent in clear text (HTTP) and the password (p@ssword) is sent unencrypted, along with all other registration/login information. The concern here is that anyone on the same network as the user could easily sniff the victim’s password and access their account. Once obtained, the attacker could access the iReport account of the user and compromise their anonymity. The same credentials could be used to access the user’s web based iReport account where any past submissions are also accessible.

Zscaler said it notified CNN of the security flaw on July 15th and that the company confirmed it’s investigating. The CNN app for iPhone received an update today with “bug fixes” listed in the release notes, but the company is yet to confirm if the update was to address the security flaw detailed by Zscaler.

Apple begins encrypting iCloud email sent between providers

Site default logo image

Last month Apple confirmed that it would soon beef up encryption for iCloud email following a report detailing security flaws in major email services. While Apple previously encrypted emails sent between its own iCloud customers, now the company has enabled encryption for emails in transit between iCloud and third-party services for me.com and mac.com email addresses. 

The change is documented on Google’s transparency website that shows the percentage of emails encrypted in transit for both inbound and outbound email exchanges (pictured below):
Expand
Expanding
Close

Review: Wiper encrypted messaging/calling app with neat erase feature (and iOS 8 update details)

Site default logo image

Yes, another secure and ephemeral messaging app. There’s Wickr, Snapchat, Confide, so what makes Wiper Messenger different? I’ve had the chance to play around with the new free chatting app on iOS, and it seems to act as a fusion of WhatsApp, Snapchat, and Wickr. The app prompts you for your email address or phone number in order to create your account, and then you are brought to a fairly simple interface with three tabs across the bottom: Chats, Contacts, and More. Let’s go tab-by-tab:


Expand
Expanding
Close

Box adds secure collaborative notes to its iPhone and iPad apps

Site default logo image

We showed you Box’s big 3.0 rewrite of its iPhone and iPad app earlier this year and today the cloud service is adding a major feature for its users: Box Notes. Box introduced its Notes feature to users last month, and now it is extending support for Box Notes to iPhone and iPad users.

The company says it’s focus on security for business users makes its approach to collaborative note capturing and sharing differently than other offerings. Box’s new Notes feature on iPhone and iPad is presented in the same app as other media stored in the cloud service as it’s a single app to know and manage.


Expand
Expanding
Close

Researcher claims iOS 7 (including current 7.1.1) does not encrypt email attachments, Apple aware of issue

Site default logo image

Security researcher Andreas Kurtz has discovered that versions of iOS 7, including iOS 7.1.1 (the current release), iOS 7.1, and iOS 7.0.4 do not encrypt email attachments in the bundled Mail application. This is an issue itself, but more worrisome as iOS, according to Apple, is supposed to encrypt email attachments. Here’s a page from Apple’s website indicating that:


Expand
Expanding
Close

Site default logo image

Apple reiterates it cannot read user iMessages, has no plans to do so

Update: Fresh Apple statement added

The immunity of iMessages from government surveillance has been cast into doubt by QuarksLab security researchers presenting at the Hack in the Box conference in Kuala Lumpur.

A leaked DEA document had pointed to the impossibility of intercepting iMessages even with a court order, a point that was confirmed by an apparently categorical Apple statement:

Conversations which take place over iMessage and FaceTime are protected by end-to-end encryption so no one but the sender and receiver can see or read them. Apple cannot decrypt that data.

The researchers reverse-engineered the iMessage protocol and confirmed that the claim was true. However, they identified that Apple needed to hold the encryption keys on its own servers, and that simply by changing these keys, it could enable access to the message content.

They can change a key anytime they want, thus read the content of our iMessages.

The researchers were keen to stress that they do not believe Apple is doing, or has ever done, this – but rather that it could do so if the NSA or another government agency were to require it. Only messages sent after Apple changed the keys would be accessible.

Apple has since issued a statement to AllThingsD:

“iMessage is not architected to allow Apple to read messages,” said Apple spokeswoman Trudy Muller said (sic) in a statement to AllThingsD. “The research discussed theoretical vulnerabilities that would require Apple to re-engineer the iMessage system to exploit it, and Apple has no plans or intentions to do so.”

This is, though, merely a weaker version of its earlier statement. Then, it said it couldn’t read iMessages, now it is saying that it could, but it would require work and it has no intention of doing so. That Apple would not willingly do so was never in doubt: the point is that the NSA could force it to. A demonstration from QuarksLab is below:

[youtube=https://www.youtube.com/watch?v=EbqZnTKDVU0]

When the NSA PRISM story broke, it led to a raft of denials in what some security researchers say was carefully-crafted language. Apple, among other companies, was clearly unhappy about the secrecy imposed on it and gained permission to reveal some numbers on government requests for customer data. A meeting was subsequently held at the White House in which Tim Cook and other tech CEOs met with President Obama to discuss the issue. Details of the discussions were not made public.

Passware: Filevault can be brute force cracked during the span of a lunchbreak

Site default logo image

FileVault has been included in Macs by Apple since the release of Panther many years ago. In Apple’s most recent release, OS X Lion, the company included FileVault that brought new ways of encryption. FileVault lets you encrypt your entire drive with a master password to protect key-chain passwords, files, and more. FileVault 2 uses a separate partition to store the FileVault login information.

Cnet pointed us to a new report from password recovery company PassWare, who claimed it can decrypt Apple’s FileVault 2 in under 40 minutes. Obviously, this is a big concern because FileVault contains so much of users’ information.

PassWare decrypts FileVault by going in through the system’s firewire connection and using live-memory analysis to extract the encryption key from the FileVault partition (so the machine must assumedly be running?). From there, a user can uncover keychain files and login passwords that can be used to unlock the whole HDD/SSD.

PassWare conveniently makes PassWare 11.3 available to do this, but you will have to throw down a lofty $995 to get the software. PassWare makes this software primarily available for law enforcement.


Expand
Expanding
Close

Gamers beware: Steam’s database hacked, including encrypted credit card information and passwords

Site default logo image

Popular game platform Steam, owned by Valve, has been hacked (via PC Gamer). Hackers were able to get into a Steam database, which included encrypted credit card information and passwords of many of its users. Steam isn’t sure at this point if the encryption of the credit card numbers or passwords have been obtained, but warns users to be on the look out for malicious activity. Steam’s Gabe Newell said in a statement to users:

Our Steam forums were defaced on the evening of Sunday, November 6. We began investigating and found that the intrusion goes beyond the Steam forums.

We learned that intruders obtained access to a Steam database in addition to the forums. This database contained information including user names, hashed and salted passwords, game purchases, email addresses, billing addresses and encrypted credit card information. We do not have evidence that encrypted credit card numbers or personally identifying information were taken by the intruders, or that the protection on credit card numbers or passwords was cracked.”

Steam is currently keeping their forums closed down while they investigate the situation. The Steam platform hasn’t been knocked down, however. Gabe’s full statement after the break:


Expand
Expanding
Close