Skip to main content

Security

See All Stories

AirDrop flaw can easily reveal your phone number and email address to strangers

Site default logo image

An AirDrop flaw means that doing nothing more than opening an iOS or macOS sharing pane within Wi-Fi range of a stranger can enable them to see your phone number and email address. You do not have to initiate an AirDrop transfer to be at risk.

The security researchers who discovered the vulnerability say that they disclosed it to Apple way back in May 2019, but the company still hasn’t provided a fix to the 1.5 billion affected devices …

Expand Expanding Close

Signal uses an iPhone SE to hack Cellebrite phone-cracking software

Cellebrite phone-cracking software hacked by Signal

Secure messaging company Signal has successfully used an iPhone SE to hack Cellebrite‘s phone-cracking software. The company says that anyone could place a file on their iPhone that effectively renders useless any data extraction performed on the phone, and that it will be doing this for Signal users.

Signal says that the file could also compromise all past and future reports generated from the Cellebrite Windows app …

Expand Expanding Close

Senior Apple anti-fraud engineer suggests App Store checks are grossly inadequate

Apple anti-fraud engineer suggests App Store checks do not work

Internal documents released as part of the Epic Games lawsuit reveal an Apple anti-fraud engineer suggesting that App Store checks were grossly inadequate.

Epic cited two particularly damning quotes from Eric Friedman, head of the company’s Fraud Engineering Algorithms and Risk unit, in internal documents …

Expand Expanding Close

Researcher gets $100,000 after finding Safari exploit at Pwn2Own 2021 event

How to use private browsing on Mac with Safari

The Pwn2Own 2021 event is promoted by the Zero Day Initiative as a way to encourage developers and researchers to report zero-day vulnerabilities to the affected companies instead of selling these breaches to malicious hackers. This year, systems researcher Jack Dates was paid $100,000 after finding a new exploit in Apple’s Safari web browser.

Expand Expanding Close

Facebook will tell you if a page is satire, but not if your data was leaked

Site default logo image

Facebook will tell you if a page is satire, as well as if it isn’t, in a new initiative. When a satirical page uses the name of a politician, for example, it will be labeled “Satire Page” to ensure that people don’t mistake it for the real person.

Conversely, posts by politicians will be labeled as “Public Official” …

Expand Expanding Close

Instagram rolling out message restrictions to protect young users

Instagram is taking several steps to make the service safer for its youngest users. Rolling out starting this month, adults won’t be able to send direct messages to teens who don’t follow them. On the flip side, Instagram will give warning alerts to teens before sending messages to adults who have a history of “suspicious behavior.”

Expand Expanding Close

Researchers demonstrate new browser-based side-channel attack that affects Intel and M1 Macs

How to revive and restore M1 Macs

A group of researchers has uncovered what looks to be the first browser-based side-channel attack that’s built entirely from CSS and HTML. The JavaScript-free attack has been found to work across most modern CPUs including Intel, AMD, Samsung, and Apple Silicon. Interestingly, the findings say Apple’s M1 and Samsung’s Exynos chips can sometimes be more susceptible to these novel attacks.

Expand Expanding Close

Tested: Aegis Secure Key 3nxc is a great privacy-protecting USB-C key

Aegis Secure Key 3nxc review

The Aegis Secure Key 3ncx is designed to provide a solution to a problem that remains common even in today’s cloud-based world: balancing convenience with security when it comes to USB keys.

If we all lived in the always-connected, high-speed, cloud-based world, the ads would have us believe, USB keys would be as obsolete as floppy disks. The reality, however, is that they still have a role to play today …

Expand Expanding Close

Report: Side effect of Apple’s increasing garden walls is better hiding places for elite hackers

Stainless Steel Facade

A new report today in the MIT Technology Review dives into Apple’s continued work on device and software security and the potential unintended consequences. While almost all experts agree that the walled garden approach to iPhone has solved major security issues, some are sharing the concern that it’s also giving the world’s top hackers a better place to hide.

Expand Expanding Close

Apple acts to prevent further spread of Silver Sparrow Mac malware

Apple says that it has taken steps to prevent further spread of the Mac malware known as Silver Sparrow. The malware was notable for the fact that it runs natively on the M1 chip.

Apple says that it has revoked the security certificates of the developer accounts used to sign the packages, which will prevent it being installed on any further Macs…

Expand Expanding Close

Apple launches 2021 Platform Security guide with iOS 14, macOS Big Sur, Apple Silicon deep dive

Apple has published its 2021 update to its Platform Security guide today along with refreshing the Apple Platform Security landing page. The latest guide goes in-depth on the new and updated security features that have arrived with iOS 14, macOS 11 Big Sur, Apple Silicon Macs, watchOS 7, and more. Apple has also launched an all-new Security Certifications and Compliance Center website and guide.

Expand Expanding Close

Fraudulent Website Warning gets privacy boost in iOS 14.5

Site default logo image

Apple’s Fraudulent Website Warning is designed to alert you when you’re about to visit a website that is known to host malware, or that is believed to be a phishing site. Previously, that check consulted a database hosted on a Google server, but as of iOS 14.5 it instead uses an Apple proxy to better protect user privacy.

That adds an extra layer of privacy to the protection Apple was already employing …

Expand Expanding Close