Skip to main content

Security

See All Stories
Senate bill would require Apple to build a backdoor into iPhones

US Senate bill would legally require Apple to build a backdoor into iPhones

Update: This bill did not get as far as a vote.

This bill was introduced on June 23, 2020, in a previous session of Congress, but it did not receive a vote.

Although this bill was not enacted, its provisions could have become law by being included in another bill. It is common for legislative text to be introduced concurrently in multiple bills (called companion bills), re-introduced in subsequent sessions of Congress in new bills, or added to larger bills (sometimes called omnibus bills).

A bill proposed in the US Senate would effectively make it a legal requirement for Apple to build a backdoor into iPhones. It would make it illegal for Apple and other tech giants to use strong encryption for either devices or cloud services …

Expand Expanding Close

NSO blocks more clients from using its Pegasus spyware after government pressure

Pegasus spyware suspension

NSO has blocked more clients from using its Pegasus spyware, according to a source within the company, while it investigates reports of misuse.

The Israeli company was reported to have previously blocked five governments from using the malware after conducting a “human rights audit,” and has now suspended access to others …

Expand Expanding Close

iOS security researcher Will Strafach agrees Apple can do more in combating NSO

Combating NSO requires Apple to do more

iOS security researcher Will Strafach agrees with a recent claim that Apple can do more when it comes to combating NSO and others who exploit combat zero-day vulnerabilities in iOS.

It follows a report by Amnesty International that said that NSO spyware Pegasus was being used to mount zero-click attacks against human rights activists, lawyers, and journalists …

Expand Expanding Close

XLoader malware infects Macs now; collects keystrokes, screenshots, and more

XLoader malware has now migrated to Macs

XLoader malware has now migrated from Windows machines to attack Macs too. An evolution of the malware known as Formbook, it lets an attacker log keystrokes, take screenshots, and access other private information.

Worryingly, the malware is sold on the dark web for $49, enabling anyone to deploy it against both Windows and Mac users …

Expand Expanding Close

Apple can and must do more to prevent NSO attacks, says Johns Hopkins security professor

Site default logo image

An associate professor at the Johns Hopkins Information Security Institute has said that Apple can and must do more to prevent NSO attacks.

He argues that while it’s true that it is impossible to completely prevent exploits based on zero-day vulnerabilities, there are two steps that the iPhone maker can take to make NSO’s job much harder …

Expand Expanding Close

You can check your iPhone for Pegasus spyware (unlikely as it is)

Check your iPhone for Pegasus

It’s extremely unlikely that your phone has been hacked using NSO software, but there is now a way to check your iPhone for Pegasus spyware – or, at least, some tell-tale signs.

The spyware was used to target human rights activists, lawyers, journalists, and politicians, and has been linked to assaults and murder of dissidents, so the chances of a random iPhone user being impacted are exceedingly low …

Expand Expanding Close

Apple defends iPhone security amid NSO’s Pegasus zero-click iMessage exploit

Over the weekend, an explosive report from Amnesty International detailed targeted attacks towards target human rights activists, lawyers, and journalists using Apple’s iMessage system as a vector by which to deliver the zero-click attacks. In a new statement provided to the Washington Post, Apple defended its security practices and said it leads the industry in security innovation.

Expand Expanding Close

Report: active zero-click iMessage exploit in the wild targeting iPhones running the latest software, used against activists and journalists

iMessage

An explosive report from Amnesty International interpreted device logs to reveal the scope of targeted malware attacks in active use targeting Android and iPhone devices, since July 2014 and as recently as July 2021. Exploited devices can secretly transmit messages and photos stored on the phone, as well as record phone calls and secretly record from the microphone. The attack is sold by Israeli firm NSO Group as ‘Pegasus’.

Whilst the company claims to only sell the spyware software for legit counterterrorism purposes, the report indicates it has actually been used to target human rights activists, lawyers and journalists around the world (as many have long suspected).

Expand Expanding Close

Zero-day exploit allowed SolarWinds hackers to extract login information from iOS devices

new iOS security bugs

While Apple constantly works to improve the security of its devices, hackers are always looking for new ways to crack the security systems found in the iPhone, iPad, Mac, and other devices. Earlier this year, an exploit found in Apple’s WebKit (which is the Safari engine) allowed hackers to extract login information from iOS devices.

Expand Expanding Close

Feature Request: Create a user-friendly standalone iOS Keychain app

Standalone iOS Keychain app

A couple of disturbing reports revealed the comparative ease with which criminal gangs were able to use stolen iPhones to access the owner’s bank accounts. The initial report didn’t explain the method used, but a subsequent one did: swapping the SIM to a new device in order to reset the Apple ID password.

Apple is already working on one security measure – making it easier for users to remotely wipe data from a stolen iPhone – but the reports also highlight a security weakness that seems worryingly common among non-techies: using the Notes app to store passwords …

Expand Expanding Close

NSO Android and iPhone spyware is linked to assaults and murder of dissidents – Amnesty

NSO Android and iPhone spyware database

Android and iPhone spyware sold by NSO Group enables state terror attacks in multiple countries, according to a new database released by Amnesty International and partner organizations.

NSO uses zero-day exploits to develop spyware for both iPhones and Android smartphones, allowing users to read text messages and emails, monitor contacts and calls, track locations, collect passwords, and even switch on the smartphone’s microphone to record meetings …

Expand Expanding Close
LinkedIn-Data-Breach-700-million-

LinkedIn breach reportedly exposes data of 92% of users, including inferred salaries [U]

Update: PrivacyShark appears to have been the first to report this, and has now obtained a statement from LinkedIn, below.

A second massive LinkedIn breach reportedly exposes the data of 700M users, which is more than 92% of the total 756M users. The database is for sale on the dark web, with records including phone numbers, physical addresses, geolocation data, and inferred salaries.

The hacker who obtained the data has posted a sample of 1M records, and checks confirm that the data is both genuine and up-to-date …

Expand Expanding Close

Comment: Moving beyond passwords will happen much faster thanks to Apple’s latest move

Moving beyond passwords

I’ve argued for years that moving beyond passwords is something that urgently needs to happen from both a security and usability perspective.

The technical framework to make it possible to abandon passwords – WebAuthn – was agreed back in 2018, and Apple added support for it in Safari last year. Adoption is as yet close to zero, but all that looks set to change, thanks to the latest move by Apple …

Expand Expanding Close
TikTok

Biden abandons Trump’s plan to ban TikTok, calls for broader security review instead

Two days ahead of the deadline to finish reviewing Trump’s executive order that was aimed at regulating Chinese-owned TikTok and WeChat, President Biden has officially revoked and replaced it. The new order includes a more comprehensive approach to reviewing apps connected to foreign adversaries and protecting US national security.

Expand Expanding Close