Skip to main content

Security

See All Stories

T2 exploit team demos a cable that hacks Mac without user intervention [U]

T2 exploit demo

Update at the bottom: Another team with another cable able to hijack a Mac, among other devices.

The T2 exploit team who found a way to take over the security chip in modern Macs has demonstrated a way to do so without user intervention — using nothing more than a modified USB-C cable.

The ad-hoc team, who call themselves Team t8012 after Apple’s internal name for the chip, believe that nation-states may already be using this approach.

Expand Expanding Close

T2 security chip on Macs can be hacked to plant malware; cannot be patched

T2 security chip can be hacked

Speculation that the T2 security chip on modern Macs can be hacked has been confirmed by the team behind the research. A combination of two different exploits would give a hacker the ability to modify the behavior of the chip, and even plant malware like a keylogger inside it.

All Macs sold since 2018 contain the T2 chip, and because the attack uses code in the read-only memory section of the chip, there is no way for Apple to patch it …

Expand Expanding Close
Twitter security includes physical security keys for staff

Twitter security: physical security keys for staff; election protection measures

Twitter security made the headlines for all the wrong reasons back in July, when a major hack saw many high-profile accounts taken over to post a cryptocurrency scam. Affected accounts included Apple, Elon Musk, Joe Biden, and Barack Obama.

The company has now implemented a range of security measures in response, including physical security keys for two-factor authentication of staff with access to accounts …

Expand Expanding Close

Feature Request: Allow our Apple Watch to unlock our iPhone and iPad

Apple Watch to unlock an iPhone or iPad

Update: Apple implemented this request in iOS 14.5 and watchOS 7.4.

Face ID is normally a completely seamless way to unlock an iPhone and iPad: just swipe up and it unlocks automatically. At a time when we’re frequently wearing masks, however, it’s rather less seamless.

So we’d like to see Apple allow an unlocked Apple Watch to automatically unlock an iPhone and iPad …

Expand Expanding Close

iOS 14 introduces privacy ‘nutrition labels’ for apps, here’s how developers can prepare

Apple app privacy details nutrition labels developer support document

After announcing new iOS privacy requirements back at WWDC in June, Apple has shared a new detailed document for developers as they prepare to create privacy “nutrition labels” for apps. The new iOS 14 feature will apply for all apps that are available in Apple’s App Stores with the goal to better inform consumers with a clear overview of an app’s privacy practices.

Expand Expanding Close

Apple battles Mac malware disguised as Adobe Flash after accidental notarization

While Apple’s devices are typically more secure than the competition, that doesn’t mean they’re immune to flaws. In the case of the Mac, a new report highlights how Apple accidentally approved one of the most common malware threats to run on recent versions of macOS. While the original flaw was quickly fixed, another similar one has popped up.

Read more

Can police demand you unlock your phone? NJ court says yes.

Can police demand you unlock your phone

Can police demand you unlock your phone if they want to examine it for evidence? Courts in different states have given different answers to this question, but New Jersey’s Supreme Court has ruled that the answer is yes. The court decided that a suspect can be forced to use his passcode to unlock his phone.

Despite the ruling coming from the state’s Supreme Court, however, that may not be the final, definitive answer …

Expand Expanding Close

New ‘unpatchable’ exploit allegedly found on Apple’s Secure Enclave chip, here’s what it could mean

One of the major security enhancements Apple has brought to its devices over the years is the Secure Enclave chip, which encrypts and protects all sensitive data stored on the devices. Last month, however, hackers claimed they found a permanent vulnerability in the Secure Enclave, which could put data from iPhone, iPad, and even Mac users at risk.

Expand Expanding Close

Twitter hack: Suspect identified; why Trump’s account wasn’t hacked; more

Twitter hack latest

There have been significant developments in the Twitter hack which saw the takeover of many high-profile accounts, among them Apple, Joe Biden, Elon Musk, Jeff Bezos, Bill Gates, Mike Bloomberg, Kayne West, Uber, Floyd Mayweather, Warren Buffett, and Barack Obama.

Twitter said yesterday that passwords were not compromised, but it subsequently locked all accounts where there was an attempted password change within the past 30 days …


Expand
Expanding
Close

US AG Barr alleges Apple and other tech companies are collaborating with China

AG Barr

In the latest accusation from the US Attorney General against Apple and other major tech companies, today William Barr alleged a number of American companies are “all too willing to collaborate” with China. In particular, Barr accused Apple of making it easier for China to crack iPhone encryption to be able to keep doing business there.


Expand
Expanding
Close

Apple and Google asked to warn users about ‘national security risks’ of apps

Apple should warn app users about potential national security risks

Apple and Google should warn users about the ‘national security risks’ of apps developed by foreign entities, says the chairman of the congressional Subcommittee on National Security, Rep. Stephen Lynch.

Lynch has written to both tech giants arguing that apps by ‘our adversaries’ could be used to gather sensitive information on American citizens …


Expand
Expanding
Close

Is TikTok a national security threat? In an abstract way, say experts …

Is TikTok a national security threat

Earlier this week, the White House suggested that it might declare TikTok a national security threat, with Secretary of State Mike Pompeo stating that the administration was ‘looking at’ the possibility of banning the video sharing app from the US.

Experts have now weighed in on the question, concluding that it’s not a direct threat, but might be an indirect one …


Expand
Expanding
Close