Apple Security

Read Cult of Mac’s latest posts on Apple Security:

Apple’s security chief accused of offering bribe for concealed weapons licenses

By

Apple bribe included iPads for concealed weapon carry licenses.
The Santa Clara Sheriff’s Office was accused of wanting iPads as a kickback to grant Apple’s security chief concealed weapons licenses.
Photo: Cult of Mac

The Santa Clara County District Attorney accused Thomas Moyer, the head of global security for Apple, of bribery. Two officials at the Santa Clara County Sheriff’s Office were also indicted and accused of soliciting the bribe.

The county employees supposedly wanted 200 iPads donated to the Sheriff’s Office in exchange for four licenses to carry concealed firearms.

Apple Activation Lock: Security feature or recycling roadblock?

By

Activation Lock on iPad and iPhone
Activation Lock is apparently a surprisingly controversial security feature.
Photo: Apple

An editorial by an iFixit employee condemns Activation Lock, a security feature of iPhones and recent Macs because it makes these computers hard to recycle.

But Walt Mossberg, well-known journalist formerly of the Wall Street Journal, calls the editorial “outrageous.”

iOS 12.4.1 locks out iPhone jailbreakers

By

iOS 12 jailbreak
iOS 12.4 really can be jailbroken, but Apple apparently just removed the necessary security hole.
Photo: Ed Hardy/Cult of Mac

Apple just introduced an update to iOS 12.4 that likely fixes a security flaw that allowed a jailbreak to be created for this version — the first in years.

There don’t appear to be any other changes in iOS 12.4.1.

If you’re using an AirPort, you should upgrade it ASAP

By

AirPort Express
Anyone with an AirPort Express like this one should install the latest security update.
Photo: Apple/Cult of Mac

Apple discontinued the AirPort line of wireless routers last year but continues to support them, including efforts to keep out hackers. The US government’s Cybersecurity and Infrastructure Security Agency (CISA) released a statement urging users of networking equipment to install a new firmware patch to block attacks.

Cops open locked iPhones with GrayKey all the time

By

GrayKey can bypass iPhone security
iPhone security is no match for Cellebrite.
Photo: Ed Hardy/Cult of Mac

Police around the country are buying and using iPhone unlocking tools like GrayKey. These allow access to the contents of encrypted devices involved in crimes.

GrayKey is fairly expensive, and its maker can’t guarantee how long it will work. It depends on a iOS security flaw known only to its maker, and Apple could close this hole at any time. Nevertheless, law enforcement agencies are taking the risk.

Face value: 7 thoughts about biometrics and the iPhone 8

By

Apple will undoubtedly play it smart when it comes to bringing facial recognition to the iPhone 8.
Apple will undoubtedly play it smart when it comes to bringing facial recognition to the iPhone 8.
Photo: Jeshoots/Pixabay CC

By Joey Pritikin

Over the last five years, biometrics has evolved from the stuff of crime scene investigation and science fiction movies to a broad set of technologies that make our lives easier, more personal, and more secure. Starting with the Touch ID sensor in the iPhone 5s, Apple led the way in the acceptance and adoption of biometrics.

The latest indications are that Apple is embracing a face-recognition approach that goes beyond a standard 2D, visible-light sensor. When used in a situation where there are only a handful of approved users, like a consumer mobile device, the promise is great.

Will Trump be good for Apple? [Friday Night Fights]

By

How will Apple fare in the Trump era?
How will Apple fare in the Trump era?
Image: Ste Smith/Cult of Mac. Original photo: Michael Vadon/Flickr CC

In case you hadn’t noticed, the United States has a new leader — and President Donald Trump has a bone to pick with Apple. Several, actually.

Will Trump’s “America first” stance and pro-business policies help Apple or give Tim Cook a series of premium headaches? Cult of Mac editors Leander Kahney and Lewis Wallace come out swinging in this week’s edition of “Friday Night Fights.”

FBI shares its first iOS and OS X vulnerability tip with Apple

By

google-facebook-and-others-following-apples-lead-on-encryption-image-cultofandroidcomwp-contentuploads201601iPhone-6s-Live-Photos-jpg
What Bizarro World is this where the FBI helps Apple?
Photo: Jim Merithew/Cult of Mac

The FBI has informed Apple of a vulnerability affecting older iPhones and Macs. It’s the first time such information has been shared with Apple by the feds under a White House “Vulnerability Equities Process” intended to disclose security weaknesses when they are discovered.

The Vulnerability Equities Process is designed to act as a balance between the desire of law enforcement and U.S. intelligence services to be able to hack into devices and the public interest in warning companies of weaknesses in their systems that may be exploited by criminals.

Here’s what Apple’s top lawyer will tell Congress tomorrow

By

Tim Cook
Tim Cook and Apple aren't backing down.
Photo: Jim Merithew/Cult of Mac

Apple’s general counsel Bruce Sewell is set to appear before the House Judiciary Committee tomorrow, when he’ll go toe-to-toe with FBI Director James Comey over whether the bureau should be allowed to force Apple to create a backdoor into iOS.

Tim Cook already explained Apple’s argument against the FBI’s orders, but today the company revealed what will be Sewell’s opening remarks before Congress unloads a barrage of questions — and he’s got some pretty big questions of his own for lawmakers to consider.

Apple supporters rally across the U.S. in protest of FBI

By

Protesters gather around the Apple Store in downtown San Francisco.
Protesters gather around the Apple Store in downtown San Francisco.
Photo: Traci Dauphin/Cult of Mac

Apple fans rallied behind their privacy savior in more than 50 cities across the United States today to protest the FBI’s demands that Apple unlock the San Bernardino shooter’s iPhone and compromise the security of millions of users’ data in the process.

Grassroots protests broke out from Albuquerque to Washington, D.C., aiming to raise public awareness about the privacy battle Apple is fighting. The protesters had some harsh words for the FBI.

Read Tim Cook’s entire email to employees regarding FBI battle

By

Tim Cook
Tim Cook was an outspoken Hillary supporter.
Photo: Jim Merithew/Cult of Mac

Tim Cook doubled down on his privacy position this morning, refusing to give in to the FBI’s demands to create an iOS backdoor so the bureau can unlock the San Bernardino shooter’s iPhone.

In an email to employees with the subject line “Thank you for your support,” the Apple CEO says the company’s battle is about much more than a single iPhone or single investigation.

What you need to know about Apple’s privacy battle with FBI

By

Apple Security Jacket
This case is highlighting a major issue concerning iOS security.
Photo: Jim Merithew/Cult of Mac

The case involving San Bernardino shooter Syed Rizwan Farook’s iPhone 5c and whether Apple should help unlock it has brought the company’s stance regarding strong encryption to the forefront.

Since this privacy-versus-security debate isn’t going away anytime soon, here’s what you need to know about it so far — and why it’s a much, much bigger issue than just one legal case.

Apple must unlock the iPhone 5c’s encryption… or else

By

The iPhone 5c might be broken wide open. And what's next?
The iPhone 5c might be broken wide open. And what's next?
Photo: Apple

In December 2015, Syed Rizwan Farook shot up an office party in an apparent terrorist attack in San Bernardino, California. He may have coordinated the attack on an iPhone 5c.

Since then, authorities have been trying to decrypt the device. And now, a U.S. magistrate is trying to force Apple to unlock it.

Everything you need to know about iOS’ crippling ‘Error 53’

By

Error 53 makes gold iPhone  worth s***.
The dreaded "Error 53" can turn an iPhone into a shiny brick.
Photo: Jim Merithew/Cult of Mac

Apple is in the midst of an all-new controversy, thanks to the mysterious “Error 53” message that is bricking iPhones without warning.

The problem can hit DIY types or anybody who has ever had a Touch ID sensor (or other iPhone hardware) replaced by a repair shop not authorized by Apple. When they update iOS, the device locks down, displaying the cryptic Error 53 message and rendering the iPhone virtually worthless.

Apple says Error 53 is actually a security feature of iOS 9 that keeps your personal information secure, but customers aren’t convinced. Cult of Mac talked to iPhone repair and and parts experts to find out what exactly is going on. The truth is that Error 53 has plagued many iPhone owners, not just those who have replaced Touch ID — and it’s not totally clear why.

Apple could face class-action lawsuit over ‘Error 53’

By

touchid
Unauthorized repairs could brick your iPhone.
Photo: Apple

A U.S. law firm is considering filing a class-action lawsuit against Apple for the “Error 53” security measure that permanently disables iPhones that have been fixed by unauthorized repair shops instead of Apple’s Genius Bar.

Controversy surrounding the Error 53 message erupted last week after it was found that repairs involving Touch ID can potentially brick iPhones without any warning. Apple insists Error 53 is a feature of iOS, but many have pointed out that the company appears to be using it as a tool to keep iPhone users from getting their devices repaired by anyone but Apple Stores.

North Korea’s OS X clone is a dictator’s ‘wet dream’

By

A North Korean operating system is seen in this screen shot taken in Seoul December 23, 2015.   REUTERS/James Pearson
You can't complain about North Korea's attention to detail. Especially if you live in the country.
Photo: James Pearson/Reuters

User privacy has been a massive focus for Tim Cook during his time as CEO at Apple, but it’s apparently not an area of much concern for North Korea’s OS X ripoff RedStar OS.

The operating system, which borrows Apple’s “look and feel” but little else, is basically the “wet dream of a surveillance state dictator,” according to security researchers who analyzed RedStar OS.

Super-simple exploit lets malware creep onto your Mac

By

It's really easy to bypass Mac's Gatekeeper.
It's really easy to bypass Mac's Gatekeeper.
Photo: Apple

Apple’s Gatekeeper feature was designed to keep even the most advanced users from accidentally installing malicious software on their computers, but a super-simple exploit lets hackers sneak malware onto your Mac.

The exploit was discovered by Patrick Wardle, director of research at security firm Synack. Wardle found that the exploit is made possible thanks to a key design shortcoming in Gatekeeper that lets an attacker use a binary file already trusted by Apple to execute malicious files.

Here’s how it works:

Thunderstrike 2 worm can infect your Mac without detection

By

12-inch MacBook
Get yours for just $999.
Photo: Jim Merithew/Cult of Mac

Apple has touted the Mac’s resistance to viruses for decades as a selling point over Windows PCs, but a team of researchers have created a new firmware worm for Mac that might just make you want to go back to doing work on good old pencil and paper.

Two white-hat hackers discovered that several vulnerabilities affecting PC makers can also bypass Apple’s renowned security to wreak havoc on Mac firmware. The two created a proof-of-concept of the worm called Thunderstrike 2 that allows firmware attacks to be spread automatically from Mac to Mac. Devices don’t even need to be networked for the worm to spread, and once it’s infected your machine the only way to remove it is to open up your Mac and manually reflash the chip.

Here’s a preview of Thunderstrike 2 in action:

iOS mail exploit might let phishers snatch your Apple ID credentials

By

A new day, a new iOS bug...
A new day, a new iOS bug...
Photo: Jim Merithew/Cult of Mac

iOS security researchers Jan Souček has discovered a new bug in iOS’s mail client that could trick users into accidentally giving attackers their AppleID and password.

The Mail app exploit was discovered at the beginning of 2015, and Apple’s engineers were quickly notified of its existence, but a fix for the bug hasn’t been released in any of the updates following iOS 8.1.2. According to Souček, the bug allows remote HTML content to be loaded, making it possible to build a password collector that looks just like an iCloud sign-in prompt.

Here’s a video of the bug in action:

Safari exploit allows attackers to spoof URLs

By

Whatever, Safari. I'm not believing a thing you say anymore.
Whatever, Safari. I'm not believing a thing you say anymore.
Screenshot: Evan Killham/Cult of Mac

Tech-wizard scientists have discovered a crack in the Safari web browser’s armor that will let evildoers trick it into showing false information in its address bar.

The exploit could lead to users giving up sensitive information when they think they’re just trying to buy some pants or something.