Skip to main content

Security

See All Stories

Data center logins for Apple and others obtained by hackers; could have facilitated physical access

Data center logins for Apple | Illustrative shot of a data center

A cybersecurity company has revealed that hackers obtained data center logins for Apple and other major companies. They were also able to access surveillance cameras remotely, and the privileges they had could even have allowed physical access to servers.

Hackers gained access to two third-party data center companies used by many major companies, and from there were able to obtain customer support logins for Apple, Amazon, BMW, Goldman Sachs, Microsoft, and as many as 2,000 other companies …

Expand Expanding Close

Tile follows Apple’s lead with enhanced anti-theft and stalking features, new $1M penalty

Tile is out with a new feature for its item trackers that hopes to reduce trouble with both theft and stalking. The company is calling the new feature Anti-Theft Mode and there are several components to it including an unscannable mode, a new $1 million penalty for misuse, ID verification, and more. The changes follow similar ones made by Apple last year. Here’s how the approaches compare.

Expand Expanding Close

Apple shares 5 security steps you should take ‘right away’ to protect Apple Card

Apple Card security steps

Apple Card has a number of security improvements compared to many credit cards with features like the number/expiration date not being printed on the card, control in the Wallet app on iPhone, and a focus on Apple Pay. Today Apple has shared 5 steps to take “right away” to “protect yourself from fraud and make the most of Apple Card’s security features.”

Expand Expanding Close
TikTok algorithm

TikTok algorithm could be shared with US, as company fights growing bans

The infamous TikTok algorithm, which has been accused of taking users into dangerous rabbit holes, could be shared with US officials, says the company. TikTok owner ByteDance is hoping that the offer of transparency will fend off further bans of the Chinese video sharing app.

Not everyone is convinced that the offer goes far enough, however …

Expand Expanding Close

Apple highlights 8 ways to keep kids safer online with iPhone and iPad

In honor of Safer Internet Day, Apple has shared a list of features and tips to provide a more secure and private experience for kids on devices like iPhone and iPad. Along with 8 ways to stay safer, Apple has highlighted its dedicated educational hub for parents and families plus a new free Today at Apple session called “Your Kids and Their Devices.”

Expand Expanding Close

Pegasus spyware journalists had to take extreme measures to avoid becoming victims

Pegasus spyware journalists | Abstract image

Pegasus spyware journalists Laurent Richard and Sandrine Rigaud were the first to discover an extensive list of specific people being targeted by NSO’s clients. In working on the story, they said they had to take extreme privacy precautions to avoid their own devices being compromised.

One of the major uses of Pegasus has been to silence journalists working on revealing abuses by tyrannical governments, so the risk of their own devices being hacked without their knowledge was very real …

Expand Expanding Close

iOS 16.3 – Hardware Security Keys explained [Video]

Apple rolled out hardware security key support in iOS 16.3, but what are they, and should you consider using them? Watch my hands-on video walkthrough as I explain why Apple added hardware security key support for Apple IDs, showcase how to use hardware security keys, and answer some frequently asked questions.

This written walkthrough explains a lot about security keys, but the video walkthrough embedded in this post is more in-depth, touches on additional platforms like macOS, and showcases features that I don’t touch on here. If you’re keenly interested in security keys, be sure to give it a watch, and perhaps consider subscribing to the channel for more in-depth analysis.

Expand Expanding Close

Anker admits to lying about Eufy security camera encryption; describes future plans

Eufy security camera encryption | Starlight camera shown

Anker has admitted that its statements about Eufy security camera encryption were not accurate. The smart home brand had previously stated that all video footage is end-to-end encrypted, but has now admitted there was an exception to this (which it has now fixed).

The company only finally came clean about the privacy breach after The Verge threatened to post a story about the company’s failure to answer its questions …

Expand Expanding Close

Pegasus spyware defended by NSO’s CEO, as researcher compares it to a nuclear weapon

Pegasus spyware | Nuclear explosion

Pegasus spyware – a zero-click way of remotely hacking an iPhone, and gaining access to all the personal data stored on it – has been defended by the company’s CEO. NSO chief exec said that the company had made “mistakes” in selling it to repressive governments, but claimed that it now sells Pegasus only to countries to whom the US sells weapons.

A security researcher said that the comparison was bogus, stating that a more reasonable comparison would be selling long-range nuclear missiles …

Expand Expanding Close

iOS 16.3 change review: Hardware security keys, HomePod feature updates, and more [Video] 

White HomePod on table with Siri light lit up.

Earlier this week Apple officially released iOS 16.3 updates for iOS, iPadOS, and HomePod. The update brings several noteworthy changes and enhancements to these devices, headlined by support for hardware security keys for Apple IDs and the global rollout of Advanced Data Protection.

iOS 16.3 also paves the way for the new second-generation HomePod, which is scheduled to be released on February 3. But even if you don’t plan on dropping $299 for Apple’s newest smart speaker, you’ll be pleased to learn that iOS 16.3 includes enhancements for the first-generation HomePod and the HomePod mini. Watch my hands-on video walkthroughs for a visual breakdown of what’s new.

Expand Expanding Close

GoTo hack sees attackers get encrypted customer backups, and encryption key

GoTo hack | HTML for login

A GoTo hack related to the LastPass security breach was far worse than initially disclosed. The company, formerly known as LogMeIn, has revealed that attackers obtained not only encrypted backups of customer data, but also an encryption key for at least some of that data.

It’s a similar tale to the LastPass hack, which followed a similar path from low-key initial announcement to revelations that it was significantly worse than initially feared …

Expand Expanding Close

Twitter GodMode still available to all engineers, following hack of Apple and other accounts

Twitter GodMode | 'God rays over a lake'

Twitter GodMode – an internal tool that hackers used to tweet from high-profile accounts, including Apple, back in 2020 – remains available to all of the company’s engineers, according to a new report today.

Twitter had previously said that the security hole had been fixed, but a whistleblower said that aside from changing the name of the tool from GodMode to PrivilegedMode, the company had made only one change – and that still allowed any Twitter engineer to trivially gain uncontrolled access to it …

Expand Expanding Close

Apple account recovery needs an overhaul: Here’s a simple suggestion

Apple account recovery | Keyboard with Touch ID shown

There have been numerous examples of people losing a lifetime’s worth of photos after being locked out of their iCloud account. The Apple account recovery process often proves impossible, especially in cases where an iPhone has been stolen and its owner forced to unlock it.

Just yesterday there was a fresh example, where an unlocked iPhone was stolen at gunpoint by seemingly tech-savvy thieves …

Expand Expanding Close
LastPass security breach | Promo image

Security analyst: LastPass statement on breach includes ‘half-truths and outright lies’

Just before Christmas, LastPass issued an update on its security breach including the news that customer vaults were obtained by the hacker. After digging through all the technical claims, one security researcher says the situation is much worse than the company claims and beleives the statement is “full of omissions, half-truths and outright lies.”

Expand Expanding Close
LastPass security breach | Promo image

LastPass security breach update: Customer password vaults were obtained

LastPass is back today with its latest statement on the damage of its security breach. While the scope of the attack wasn’t clear in early December, now the company has shared that copies of customers’ password vaults were obtained along with names, emails, billing addresses, phone numbers, and more. Here’s what you should know.

Expand Expanding Close

Eufy camera security breach admission leaves many questions unanswered

Eufy camera security breach | Dual-camera doorbell cam

Brand owner Anker has finally responded to proof of a major Eufy camera security breach, but its official statement still leaves a great many questions unanswered.

The company has now admitted that it lied to users about all footage and images being stored locally, and never sent to the cloud, after a security researcher proved that this was not true …

Expand Expanding Close

How to turn on end-to-end encryption for iMessage, iCloud, iPhone backups

How to turn on iPhone end-to-end encryption

Apple launched a big security enhancement with iOS 16.2 that brings the long-requested feature of full encryption for iMessage in iCloud, iPhone backups, and eight other apps/categories. As part of the process, you’ll need to set up a recovery contact/key – here’s how to turn on iPhone end-to-end encryption for iMessage, iCloud, device backups, Notes, Safari, Photos, and more.

Expand Expanding Close