iOS mail exploit might let phishers snatch your Apple ID credentials

By

A new day, a new iOS bug...
A new day, a new iOS bug...
Photo: Jim Merithew/Cult of Mac

iOS security researchers Jan Souček has discovered a new bug in iOS’s mail client that could trick users into accidentally giving attackers their AppleID and password.

The Mail app exploit was discovered at the beginning of 2015, and Apple’s engineers were quickly notified of its existence, but a fix for the bug hasn’t been released in any of the updates following iOS 8.1.2. According to Souček, the bug allows remote HTML content to be loaded, making it possible to build a password collector that looks just like an iCloud sign-in prompt.

Here’s a video of the bug in action:

Tim Cook: ‘Morality demands’ security with privacy

Tim Cook addresses the White House Summit on Cybersecurity and Consumer Protection. Photo: White House
Tim Cook addressed the White House Summit on Cybersecurity and Consumer Protection in February.

In a speech to nonprofit research firm Electronic Privacy Information Center (EPIC) at its annual “Champions of Freedom” awards dinner last night, Apple head Tim Cook had some strong words about online security, government monitoring, and corporate data mining.

Cook was the first business leader to receive recognition from EPIC, which lauded his “corporate leadership” on matters of maintaining Apple customers’ privacy.

Jumpstart a new career in IT management and security with 4 essential exam trainings [Deals]

original_2033_UltimateIT_SecurityBundle_MF-Primary

Thinking about a new career in IT management and security, but not sure where to start? We’ve made it easy. This bundle from iCollege packages together four essential certification courses that train you exactly on what you need to know. Get it for $59 at Cult of Mac Deals today—at 94% off, a deal this good doesn’t come around often.

How to hide your location from Facebook stalkers

Facebook may be telling people where you are.
Facebook may be telling people where you are.
Photo: Jim Merithew/Cult of Mac

Anyone you exchange messages with via Facebook Messenger could know where you’ve been at any point. Chatted with your boss? He could use a newly discovered hack to figure out your sick days weren’t spent at home.

Facebook intern Aran Khanna found he could figure out where his friends were going daily with a bit of code, based solely on whether he had Facebook Messenger conversations with them. It even worked with people he wasn’t Facebook friends with if he had been in the same Facebook Messenger chat group.

He calls this code Marauders Map, and anyone can use it. Luckily, it’s fairly simple to hide your location from potential stalkers.

Yes, Google can wiretap your Hangouts for the government

This text isn't the only message that's insecure. Photo: Evan Killham/Cult of Mac
This text isn't the only message that's insecure. Photo: Evan Killham/Cult of Mac

If you’re looking to plan a heist, you’d probably best stay clear of Hangouts: Google has inadvertently confirmed that its chat platform is susceptible to police and government monitoring.

While the tech giant usually keeps quiet about Hangouts’ security features, the revelation (of sorts) came out of an “Ask Me Anything” session Friday on Reddit that included members of Google’s public policy department and legal team. Its proposed topic was “the current status of U.S. government surveillance law reform and how Google thinks about these issues,” but the questions were less about laws or reform and more about Google’s practices.