William Barr Wants You to Accept Encryption Backdoor Security Risks

U.S. Attorney General William Barr suggested that Americans should just accept encryption backdoor security risks (via TechCrunch). Encryption Backdoor Risks In a speech today, William Barr called on tech companies to help the federal government to access devices with a lawful order. In other words, ignore the security risks and put a backdoor into their…

NSO Group Tool Harvests Targeted iCloud Data

Israel-based NSO Group claims it can harvest iCloud data in targeted attacks. It’s said to be a version of the Pegasus spyware.

Attackers using the malware are said to be able to access a wealth of private information, including the full history of a target’s location data and archived messages or photos, according to people who shared documents with the Financial Times and described a recent product demonstration.

When questioned by the newspaper, NSO denied promoting hacking or mass-surveillance tools for cloud services, but didn’t specifically deny that it had developed the capability described in the documents.

Keeper Password Manager 1-Year Subscription: $19.99

We have a deal on Keeper, a password manager for iOS, Mac, Android, Windows, and Linux. With Keeper’s password manager and vault, you can generate, store, and AutoFill strong passwords on all devices while securely storing private documents. It also supports multiple forms of 2FA, including TOTP, SMS, Touch ID, Face ID, and U2F security keys (e.g. Yubikey). A one year subscription is $19.99 through our deal.

iOS 13 Password Bug Gives Unauthenticated Access in Settings

An iOS 13 password bug was discovered in the latest betas that give unauthenticated access to Website & App Passwords in Settings.

As detailed by iDeviceHelp on YouTube, you can access all of the saved usernames and passwords in Settings by repeatedly tapping the “Website & App Passwords” menu and avoiding the Face ID or Touch ID prompt. After several tries, iOS 13 will show all of your passwords and logins, even if you never successfully authenticated with Face ID or Touch ID.

I haven’t been able to replicate the issue, but I’ll keep trying to see.

Open ID Foundation Publishes Letter about Sign in With Apple

The Open ID foundation published an open letter to Craig Federighi regarding Sign in With Apple. Although the foundation praised Apple for the initiative, it worries that it strays too far from Open ID and opens users to security and privacy risks.

The current set of differences between OpenID Connect and Sign In with Apple reduces the places where users can use Sign In with Apple and exposes them to greater security and privacy risks. It also places an unnecessary burden on developers of both OpenID Connect and Sign In with Apple. By closing the current gaps, Apple would be interoperable with widely-available OpenID Connect Relying Party software.

News+: How to Stay Safe and Secure Online

In the latest issue of Mac Format magazine, Adam Banks writes a guide on how to stay safe online. This is a PDF version and on page 66.

Using a Mac makes you safer than average when going online. That’s partly because of Apple’s efforts to secure the operating system; partly because the Mac App Store gives you somewhere to get most of your third-party software safely. It’s also partly because bad actors – in the security industry sense, not the Hollyoaks sense – tend to be less interested in targeting macOS. But that doesn’t mean either you or your Mac can’t get fooled. Know your way around the common risks and basic protections to keep yourself out of harm’s way.

This is part of Andrew’s News+ series, where he shares a magazine every Friday to help people discover good content in Apple News+.

Openly Operated Wants to Improve Privacy Policies

Openly Operated is a certification for apps and services. The certification process ensures that they live up to their privacy and security claims with an audit.

An OO-certified app or site must meet three criteria. First, it needs to demonstrate “a basic level of transparency” by making its code and infrastructure — among other things — public and fully documented. Second, it needs to lay out its policy in the form of “claims with proof,” establishing what user data is collected, who can access it, and how it’s being protected. Third, those claims must be evaluated by an OO-certified auditor who then makes the audit results public.

I’ve complained about privacy policies before, and this sounds like a great idea. I hope it gets traction.

Google Builds HTTPS Directly Into Top Level Domains

More websites have encrypted their traffic than ever, but there is a loophole. Some use a mixture of HTTPS and unsecure HTTP. Google is closing this by building HTTPS protection directly into certain top level domains.

Which means that today, when you register a site through Google that uses “.app,” “.dev,” or “.page,” that page and any others you build off it are automatically added to a list that all mainstream browsers, including Chrome, Safari, Edge, Firefox, and Opera, check when they’re setting up encrypted web connections. It’s called the HTTPS Strict Transport Security preload list, or HSTS, and browsers use it to know which sites should only load as encrypted HTTPS automatically, rather than falling back to unencrypted HTTP in some circumstances. In short, it fully automates what can otherwise be a tricky scheme to set up.