The governor of Louisiana has declared a cybersecurity state of emergency after a series of attacks on school districts.
Security
Stock Trader Robinhood Stored Passwords in Plaintext
Investment and stock trading app Robinhood recently admitted to storing user credentials like passwords in plaintext.
William Barr Wants You to Accept Encryption Backdoor Security Risks
U.S. Attorney General William Barr suggested that Americans should just accept encryption backdoor security risks (via TechCrunch). Encryption Backdoor Risks In a speech today, William Barr called on tech companies to help the federal government to access devices with a lawful order. In other words, ignore the security risks and put a backdoor into their…
NSO Group Tool Harvests Targeted iCloud Data
Israel-based NSO Group claims it can harvest iCloud data in targeted attacks. It’s said to be a version of the Pegasus spyware.
Attackers using the malware are said to be able to access a wealth of private information, including the full history of a target’s location data and archived messages or photos, according to people who shared documents with the Financial Times and described a recent product demonstration.
When questioned by the newspaper, NSO denied promoting hacking or mass-surveillance tools for cloud services, but didn’t specifically deny that it had developed the capability described in the documents.
Bluetooth Low Energy Flaw Affects Apple Devices
Researchers have discovered a Bluetooth Low Energy (BLE) flaw that affects Apple devices and expose them to tracking and data leakage.
Keeper Password Manager 1-Year Subscription: $19.99
We have a deal on Keeper, a password manager for iOS, Mac, Android, Windows, and Linux. With Keeper’s password manager and vault, you can generate, store, and AutoFill strong passwords on all devices while securely storing private documents. It also supports multiple forms of 2FA, including TOTP, SMS, Touch ID, Face ID, and U2F security keys (e.g. Yubikey). A one year subscription is $19.99 through our deal.
iOS 13 Password Bug Gives Unauthenticated Access in Settings
An iOS 13 password bug was discovered in the latest betas that give unauthenticated access to Website & App Passwords in Settings.
As detailed by iDeviceHelp on YouTube, you can access all of the saved usernames and passwords in Settings by repeatedly tapping the “Website & App Passwords” menu and avoiding the Face ID or Touch ID prompt. After several tries, iOS 13 will show all of your passwords and logins, even if you never successfully authenticated with Face ID or Touch ID.
I haven’t been able to replicate the issue, but I’ll keep trying to see.
Apple's Security Evolution, iCloud VPN – TMO Daily Observations 2019-07-15
John Martellaro and Andrew Orr join host Kelly Guimont to talk about Apple’s balance of security and user freedom, and a new iCloud VPN idea.
iOS URL Scheme Open to Highjacking
The iOS URL Scheme is a way for apps to work around the sandbox limitations of the OS. But it can also be taken advantage of.
Apple Disables Walkie Talkie due to Bug
Apple has disabled the Walkie Talkie app on Apple Watch because of a vulnerability that could let someone secretly eavesdrop on your iPhone.
Apple Releases Mac Update to Remove Zoom Web Server
After the controversy surrounding Zoom and its hidden web server, Apple is pushing a hidden Mac update that removes it.
SANNCE Home Security IP Wireless Camera With Night Vision: $44.99
We have a deal on the SANNCE Home Security IP Wireless Camera With Night Vision. This device records in HD, has motion detection and night vision, and it can record 24 hours. It will also pan 355 degrees, and it’s $44.99 through our deal.
New Macs, New Security Flaws – TMO Daily Observations 2019-07-09
Andrew Orr and Dave Hamilton join host Kelly Guimont to talk about the new Mac laptop updates and the latest security flaw courtesy of Zoom.
Open ID Foundation Publishes Letter about Sign in With Apple
The Open ID foundation published an open letter to Craig Federighi regarding Sign in With Apple. Although the foundation praised Apple for the initiative, it worries that it strays too far from Open ID and opens users to security and privacy risks.
The current set of differences between OpenID Connect and Sign In with Apple reduces the places where users can use Sign In with Apple and exposes them to greater security and privacy risks. It also places an unnecessary burden on developers of both OpenID Connect and Sign In with Apple. By closing the current gaps, Apple would be interoperable with widely-available OpenID Connect Relying Party software.
DNS Over HTTPS, New iCloud Login Method – TMO Daily Observations 2019-07-08
Andrew Orr and Bryan Chaffin join host Kelly Guimont to talk new DNS security from Mozilla, and Apple’s new login system coming to iCloud.
News+: How to Stay Safe and Secure Online
In the latest issue of Mac Format magazine, Adam Banks writes a guide on how to stay safe online. This is a PDF version and on page 66.
Using a Mac makes you safer than average when going online. That’s partly because of Apple’s efforts to secure the operating system; partly because the Mac App Store gives you somewhere to get most of your third-party software safely. It’s also partly because bad actors – in the security industry sense, not the Hollyoaks sense – tend to be less interested in targeting macOS. But that doesn’t mean either you or your Mac can’t get fooled. Know your way around the common risks and basic protections to keep yourself out of harm’s way.
This is part of Andrew’s News+ series, where he shares a magazine every Friday to help people discover good content in Apple News+.
Apple Security Chief Ivan Krstic Will Talk at Black Hat 2019
This year the Black Hat 2019 security conference will include a session with Ivan Krstic, head of Apple Security Engineering and Architecture.
Catalina System Volume, ISP Lobbying Budgets – TMO Daily Observations 2019-06-26
John Martellaro and Andrew Orr join host Kelly Guimont to discuss the new macOS read-only volume and ISP budgets for lobbying lawmakers.
OSX/Linker Malware Exploits macOS GateKeeper
Security researchers have discovered a piece of Mac malware called OSX/Linker that can exploit a zero day vulnerability in macOS GateKeeper.
Try Salting Passwords if You Don’t Trust Password Managers
Andrew recently stumbled upon this sweet password trick from Password Bits, and he’s geeking out over the sheer genius of it.
Openly Operated Wants to Improve Privacy Policies
Openly Operated is a certification for apps and services. The certification process ensures that they live up to their privacy and security claims with an audit.
An OO-certified app or site must meet three criteria. First, it needs to demonstrate “a basic level of transparency” by making its code and infrastructure — among other things — public and fully documented. Second, it needs to lay out its policy in the form of “claims with proof,” establishing what user data is collected, who can access it, and how it’s being protected. Third, those claims must be evaluated by an OO-certified auditor who then makes the audit results public.
I’ve complained about privacy policies before, and this sounds like a great idea. I hope it gets traction.
Security 101: What is a Threat Model, and How Do I Create One?
If you hang around privacy or security forums long enough, you’ll eventually come across the term “threat model.” Here’s what they mean.
Security Tool YubiKeys Recalled Over Firmware Flaw
Yubico is recalling its line of YubiKeys, tools used for two-factor authentication that generate one-time passcodes.
Google Builds HTTPS Directly Into Top Level Domains
More websites have encrypted their traffic than ever, but there is a loophole. Some use a mixture of HTTPS and unsecure HTTP. Google is closing this by building HTTPS protection directly into certain top level domains.
Which means that today, when you register a site through Google that uses “.app,” “.dev,” or “.page,” that page and any others you build off it are automatically added to a list that all mainstream browsers, including Chrome, Safari, Edge, Firefox, and Opera, check when they’re setting up encrypted web connections. It’s called the HTTPS Strict Transport Security preload list, or HSTS, and browsers use it to know which sites should only load as encrypted HTTPS automatically, rather than falling back to unencrypted HTTP in some circumstances. In short, it fully automates what can otherwise be a tricky scheme to set up.




