Firefox 86 Introduces ‘Total Cookie Protection’ Privacy Feature

Firefox 86, introduced recently by Mozilla, adds a new privacy feature called Total Cookie Protection.

Total Cookie Protection works by maintaining a separate “cookie jar” for each website you visit. Any time a website, or third-party content embedded in a website, deposits a cookie in your browser, that cookie is confined to the cookie jar assigned to that website, such that it is not allowed to be shared with any other website.

Mysterious ‘Silver Sparrow’ Malware Confuses Researchers

Over the weekend we got news of a mysterious piece of malware called Silver Sparrow. It has infected 30,000 machines so far and there is a version of it built for M1 Macs. But security researchers can’t figure out its purpose.

Once an hour, infected Macs check a control server to see if there are any new commands the malware should run or binaries to execute. So far, however, researchers have yet to observe delivery of any payload on any of the infected 30,000 machines, leaving the malware’s ultimate goal unknown. The lack of a final payload suggests that the malware may spring into action once an unknown condition is met.

Chrome OS Passes macOS to Become Second Most Popular Desktop OS

New data shows that Chrome OS has overtaken macOS to become the second most popular desktop OS. Chrome OS rose from 6.4% in 2019 to 10.8% in 2020.

Despite the fact that macOS landed in third, viewing this as an example of Google beating out Apple directly might not be accurate. Rather, it’s likely that Chrome OS has been primarily pulling sales and market share away from Windows at the low end of the market. Mac market share actually grew from 6.7 percent in 2019 to 7.5 percent in 2020.

Password Manager Bitwarden Adds Touch ID to Browser Extension

Password manager Bitwarden announced the addition of a couple of new features. One feature adds support for Touch ID and Windows Hello to its browser extensions.

Browser extensions will now be able to access this authentication inside the Desktop application. This allows a more streamlined integration with hardware that does not require a unique browser-level integration. Biometric authentication requires macOS users to download the Mac App Store version.

Buffer Overflow Bug Found in SUDO Dubbed ‘Baron Samedit’

Tracked as CVE-2021-3156, a heap overflow bug found in sudo and dubbed “Baron Samedit” has been found recently. It allows an unprivileged user to gain root privileges on a vulnerable machine using a default sudo configuration.

The vulnerability itself has been hiding in plain sight for nearly 10 years. It was introduced in July 2011 (commit 8255ed69) and affects all legacy versions from 1.8.2 to 1.8.31p2 and all stable versions from 1.9.0 to 1.9.5p1 in their default configuration.

2020-02-03: Looks like macOS is affected after all.

MindNode Update Adds Editable Outlines

MindNode updated its mind mapping app recently with a feature many users have wanted. Along with editing maps, outlines can also be edited. Nodes can be added, removed, indented/outdented, and reorganized directly. Other features include: Improved color pickers in the Inspector; Improved support for files from other apps that use Markdown; Fixed an issue where the Inspector would close when the icon of the open section was clicked. The update is currently available for the Mac app, but updates to MindNode for iOS/iPadOS are sure to follow.