Apple releases iOS 10.3.1 update, offers bug fixes, security fixes

Posted by:
Date: Tuesday, April 4th, 2017, 05:36
Category: Hack, iOS, iPad, iPhone, iPod Touch, News, security, Software

After a major OS update come the fixes.

Apple on Monday released iOS 10.3.1, an update available for its iOS devices available as an over-the-air update or when connected to iTunes via a Mac or Windows PC.

The update, which weighs in at just under 30 megabytes as an OTA download, resolves issues such as a hardware-specific problem wherein iPhone 5 and iPhone 5c handsets had trouble updating over the air.

(more…)

LastPass exploit discovered, company scrambles to repair the vulnerability

Posted by:
Date: Monday, April 3rd, 2017, 05:04
Category: Hack, News, security, Software

A serious vulnerability was recently discovered in the popular LassPass password manager and developers are scrambling to fix the issue which makes it possible for malicious websites to steal user passcodes and in some cases execute malicious code on computers running the program.

The flaw, which affects the most recent version of the browser extension, was briefly described on Saturday, March 25th, by Tavis Ormandy, a researcher with Google’s Project Zero vulnerability reporting team. When people have the LastPass binary running, the vulnerability allows malicious websites to execute code of their choice. Even when the binary isn’t present, the flaw can be exploited in a way that lets malicious sites steal passwords from the protected LastPass vault. Ormandy said he developed a proof-of-concept exploit and sent it to LastPass officials. Developers now have three months to patch the hole before Project Zero discloses technical details.

Ormandy offered the following statement:

“It will take a long time to fix this properly, It’s a major architectural problem. They have 90 days, no need to scramble!”

The blog post describing the issue had LastPass company officials thanking Ormandy for the alert and stating that a fix was on the way. In the meantime, it was suggested that LastPass users protect themselves by by entering stored passwords into websites using the LastPass vault as a launch pad for opening websites and entering passwords and enabling two-factor authentication on sites that offer it.

The attack was described as both unique and highly sophisticated. LastPass, in turn, stated that the company didn’t want to disclose details regarding the vulnerability or the fix to outside parties. Users, in turn, could expect a more detailed post mortem once the work was complete.

The string of vulnerabilities underscores the tradeoff that comes from use of any password manager. Storing dozens, hundreds, or even thousands of passwords in a single place poses catastrophic risks should that resource be breached. Exploits become easier by convenience features that, for example, store encrypted password vaults in Internet-accessible locations or automatically paste passwords into websites. Ultimately, password managers likely make the average user safer because they make it possible to use long, complex, and unique passwords. And that protects people in the event that their password is exposed in website breaches, which are much more common than real-world password manager exploits.

If you use LastPass, please take care and stay tuned for additional details as they become available.

Via Ars Technica, Twitter and blog.lastpass.com

Apple repairs iOS 10.3 vulnerability that caused iOS devices to repeatedly dial 911

Posted by:
Date: Friday, March 31st, 2017, 05:28
Category: iOS, iPad, iPhone, News, security, Software

Following the release of iOS 10.3 earlier this week, a number of users reported that their iOS devices were repeatedly attempting to call 911.

The flaw was discovered by an 18-year old who found a way to use Javascript to remotely cause iOS devices to open popup alerts, open apps, and make phone calls. In an effort to show the severity of the problem, he created a code that caused iPhones to dial 911 repeatedly. All in all, he ended up being arrested and charged with four counts of computer tampering after causing thousands of accidental 911 calls.

It appears that Apple has worked with app developers to examine the issue and close the loophole.

(more…)

Apple clears through almost 350 security vulnerabilities with of iOS, macOS, watchOS and tvOS updates

Posted by:
Date: Wednesday, March 29th, 2017, 05:54
Category: Hack, iOS, macOS, News, security, Software, TvOS, watchOS

Apple cleaned house via a slew of operating system updates on Monday, pinning down nearly 350 known vulnerabilities between its changes to iOS, macOS, watchOS and tvOS.

Starting with iOS 10.3, Apple’s latest version includes Find My AirPods, Apple’s new file system, CarPlay, and a few other small visual tweaks. With nearly every update Apple does, they also include a handful of security fixes that easily go unnoticed by the user. iOS 10.3 is no exception with over 85 different common vulnerabilities and exposures (CVEs) listed.

In one case, the iOS 10.3 update patched a security hole that allowed attackers to spam Safari with a ‘Cannot Open Page’ dialog. Lookout, a cybersecurity company, learned of the attack after one of their users complained of losing control over their browsing experience. The dialog was meant to trick users into eventually paying money to “unlock” their Safari browser.

(more…)

Trump administration looks to carry out electronics travel ban from six Muslim-majority countries

Posted by:
Date: Thursday, March 23rd, 2017, 05:14
Category: Hardware, iPad, News, security

The travel ban now applies to some devices coming into the U.S. from some flights.

The Trump administration has banned devices larger than a smartphone in the passenger cabin of flights coming to the U.S. from several airports in Muslim-dominant countries. The ban restricts iPads and other tablets, Kindle ebook readers, notebooks, and other larger electronic devices to checked luggage over terrorism concerns.

The policy was announced earlier this week and covers direct flights to the U.S. from Cairo, Istanbul, Kuwait City, Doha, Casablanca, Amman, Riyadh, Jeddah, Dubai, and Abu Dhabi. Specific airlines includes in the ban include Royal Jordanian Airlines, Egypt Air, Turkish Airlines, Saudi Arabian Airlines, Kuwait Airways, Royal Air Maroc, Qatar Airways, Emirates, and Etihad Airways.

At present, the airlines have until Friday to comply with the electronics ban.

No specific terrorist threat has been cited by the Trump administration, although it’s been thought that militants may want to disguise bombs in electronic devices. Representatives from the administration have stated that the electronics ban isn’t related to the controversial travel ban being pushed forward regarding the six nations with Muslim-majority populations. These countries presently include Iran, Libya, Syria, Somalia, Sudan, and Yemen.

It’s also been noted that a similar electronics ban being carried out in the U.K. was triggered from intelligence gathered during a U.S. raid in Yemen earlier this year.

Stay tuned for additional details as they become available.

Via The Mac Observer and Reuters

Justice Department files charges against Russian hackers following Yahoo email breaches

Posted by:
Date: Thursday, March 16th, 2017, 05:56
Category: Hack, News, security

They found the people who hacked into more than half a billion Yahoo email accounts.

The Justice Department announced charges Wednesday against two Russian spies and two hackers behind the infamous 2014 hacks, which have been identified as among the most significant digital security breaks in American history.

The four men together face 47 criminal charges, including conspiracy, computer fraud, economic espionage, theft of trade secrets and aggravated identity theft, the Justice Department said in a news release.

(more…)

Apple joins Google, other tech companies in resisting ‘troubling’ FBI search warrant

Posted by:
Date: Wednesday, March 15th, 2017, 05:32
Category: Amazon, Apple, Google, iOS, Legal, Microsoft, News, security

Apple has joined Amazon and Microsoft in a court filing which supports Google’s decision to resist an FBI warrant demanding that it hand over emails stored outside the USA. The tech companies argue that this would set a ‘troubling’ precedent.

As reported, the FBI served search warrants ordering Google to surrender emails belonging to suspects in a criminal investigation. The emails themselves were stored on a server outside the USA. Google, in turn, refused, arguing that a domestic search warrant could not apply to data stored in a foreign country.

A Pennsylvania court both disagreed and instructed Google to comply with the warrant. Google has since appealed the ruling, with Apple, Amazon and Microsoft jointly filing an amicus brief in support of Google.

(more…)

WikiLeaks to share CIA hacking tools with Apple, other firms after security fixes are complete

Posted by:
Date: Friday, March 10th, 2017, 05:36
Category: Hack, iOS, News, privacy, security, Software

Following WikiLeaks’ release of more than 8,000 documents from inside the CIA’s Center for Cyber Intelligence, Apple followed up, saying it had already fixed most of the exploits the agency had found to hack into iPhones.

WikiLeaks founder Julian Assange said Thursday he will share the code, which was withheld from the published documents, with tech companies like Apple.

Per Assange:

“We have decided to work with [tech companies] to give them exclusive access to the additional technological details we have so that fixes can be developed and pushed out,” Assange said in a live-streamed press conference from the Ecuadorian Embassy in London, where he lives. “Once this material is effectively disarmed by us we will publish additional details.”

(more…)

Apple responds to WikiLeaks’ release of CIA-based documents, states that ‘many’ of the iOS-related exploits have already been patched

Posted by:
Date: Wednesday, March 8th, 2017, 05:47
Category: Hack, iOS, News, privacy, security, Software

With any luck, this’ll provide some consolation.

Following up on the revelation that WikiLeaks had intercepted and released what might amount to 8,700+ documents from the CIA’s Center for Cyber Intelligence unit – part of which is devoted to obtaining zero-day exploits for iOS devices – and that the CIA had lost control of the majority of its hacking arsenal, Apple went on record to state that “many of the issues leaked today were already patched” in the most recent version of iOS.

The company offered the following comment:

(more…)

WikiLeaks releases 8,700+ CIA-related documents, show agency efforts towards hacking Android systems, iPhones, operating systems and smart TVs

Posted by:
Date: Wednesday, March 8th, 2017, 05:43
Category: Android, Google, Hack, Hardware, iOS, iPhone, macOS, News, privacy, Samsung, security

This is pretty much one for the ages.

WikiLeaks has released more than 8,700 documents that have apparently originated from the CIA’s Center for Cyber Intelligence, with some of the leaks saying the agency had 24 “weaponized” and previously undisclosed exploits for the Android operating system as of 2016.

Some of the Android-specific exploits were developed by the CIA, while others hailed from the U.S. National Security Agency, U.K. intelligence agency GCHQ, and cyber arms dealers.

Among the smartphone-related tools developed by the CIA were assets that allow the agency to bypass encryption found in WhatsApp, Confide and other applications known to use encryption. These tools, according to WikiLeaks analysis, capture audio and message traffic before encryption has a chance to be applied.

(more…)