iPhone 11 keeps tabs on your whereabouts. Photo: Killian Bell/Cult of Mac
iPhone 11 units are using location services even after access has been blocked by the user, a new report reveals.
Security researchers have discovered that Apple’s latest handsets intermittently seek location information regardless of the user’s privacy settings. Apple says it is “expected behavior.”
Keep your Apple Watch safe with a proper, long, strong passcode. Photo: Chuttersnap/Unsplash
The default passcode length on the Apple Watch is just four digits. And while it’s true that you don’t keep as much sensitive data on the smartwatch as you do on an iPhone, and that your Apple Watch is arguably safer from bad actors because it is always strapped to your wrist, it’s still worth making this passcode more secure. After all, it’s not like you have to enter your strong passcode very often, right?
Today we’ll see how to change your Apple Watch passcode to a longer one. And we’ll also check out a neat feature that lets you skip entering the passcode altogether.
Facebook is quietly using your iPhone’s camera in the background while you scroll through your news feed.
The issue is believed to be a bug that affects devices running certain versions of iOS. It has been replicated on handsets with iOS 13.2.2, but not those still using iOS 13.1.3.
Jamf Now helps keep employees' devices secure and up to date. Photo: Jamf Now
This OS updates and security post is presented by Jamf Now.
Apple’s new operating systems, macOS Catalina and iOS 13, bring innovative capabilities to organizations using them. A streamlined approach to Apple upgrades ensures security measures are met, an accurate systems inventory is maintained and downtime is eliminated. Mobile device management products like Jamf Now help simplify the upgrade process and maintain security of employees’ devices by keeping them up to date.
The iPad version has a toggle directly over the preview image. Photo: Cult of Mac
In iPadOS and iOS 13, long-pressing a link does two things simultaneously. It brings up a contextual menu with options for sharing and so on, and it loads a preview of the linked web page. Apple calls this a link preview.
But what if you don’t want a link preview? Maybe you’re on a cellular connection and you don’t want to waste data by loading pages you won’t read. Or maybe you only need the link, and never want to see the page. What if it’s a link to a huge image, or an MP3? Or perhaps it’s a link in an email, and you want to use the contextual menu to check the URL for scams. In this last case, there’s no way you want that link to load. It could prove disastrous.
The good news is that you can disable link previews in iOS 13 with a single tap.
You know how you can double-press the side button on your Apple Watch, and then wave it over a contactless terminal to pay with your credit card? Wouldn’t it be great if you could do the same with your Mac login password? Instead of having to type your password to authenticate yourself, you’d be able to double-tap the Apple Watch’s side button to do it instantly.
Well, now you can do exactly this — if you’re running macOS Catalina.
Apple’s latest patches for iTunes and iCloud for Windows are out to block potential ransomware attacks.
The software previously contained a vulnerability that allowed malware to piggyback on Apple’s digital signatures and go undetected by antivirus software.
And don’t assume you’re safe if you’ve already uninstalled Apple’s apps.
Scrolling through your Instagram feed in the middle of the night just got a lot easier on the eyes.
Instagram introduced support for iOS 13’s Dark Mode this week along with some new security tools that help people identify phishing attempts from emails that appear to be from Instagram.
iPhone security is no match for Cellebrite. Photo: Ed Hardy/Cult of Mac
Law enforcement agents in New York City have been cracking into locked iPhones since January 2018, according to a new report.
Agencies are using a tool called Universal Forensic Extraction Device (UFED) that’s developed by Israeli firm Cellebrite. It is said to have cost at least $200,000 and allows a full file system extraction.
Safari’s content blockers effectively block trackers and other Bad Stuff on the web, but that only works in Apple’s browser. Any other app you install on your iPhone or iPad can send all kinds of personal information to anyone, without you ever knowing. Your location, the details of your menstrual cycle, how long you spend asleep — pretty much anything.
So how do you stop this? Well, iOS 13 itself can help limit some abuses. But what you really need is an iOS firewall app that can detect and shut down any unauthorized connections.
Keep your iPhone close by. Photo: Ed Hardy/Cult of Mac
A newly-discovered flaw in iOS 13 lets anyone access your contacts without your passcode.
It takes just a few simple steps to bypass your iPhone’s lockscreen and see every phone number, email address, and physical address you have saved. But a fix is already on the way.
Here's how much you can make selling certain exploit chains. Photo: Zerodium
One of the biggest buyers of iOS zero-day exploits says the market is flooded with new iPhone bugs due to weakened security components in Safari and iMessage.
Zerodium, which pays $2 million for iOS exploits, recently announced it’s increasing its payout for Android exploits to $2.5 million. iOS used to be the most locked-down mobile operating system, but the company says Android’s security has improved with every new OS release while iOS has been slacking, leading to a glut of new exploits.
Security flaw made it possible to infect iPhones using malicious code. Photo: Jim Merithew/Cult of Mac
An iPhone exploit which used malicious websites to hack iPhones was used to target Uyghur Muslims in China.
The security exploit was recently disclosed by Google researchers. It involved infecting users with malicious code, allowing an attacker to gain access to their phone. Apple fixed the vulnerability earlier this year, before the news was publicly shared.
Encrypting your disk is way safer than trying to 'secure' erase it. Photo: Charlie Sorrel/Cult of Mac
In the olden days, when you wanted to replace your hard drive with a bigger one, you’d run a “secure erase” on it to completely remove any personal data. This would write zeros to the entire disk, overwriting anything already there.
But now, thanks to advances in storage tech, this no longer does the trick. (Not that you can change your own Mac SSDs now anyway.) The new secure-erase, says Apple, is to just encrypt your disk.
This is what a real hacker looks like. Dry ice is not optional. Photo: Brian Klug/Flickr CC
Apple has historically not been a company in favor of people jailbreaking its devices. So why would Cupertino give hackers special iPhones to help them find weaknesses in iOS? To patch those problems, of course!
According to a new report, Apple will announce plans this week at the Black Hat security conference in Las Vegas to hand out such devices to security researchers. Apple also will introduce a new Mac bug bounty program to reward anyone who finds security problems in macOS.
That's not a great look for AirDrop! Image: Hexway
A Bluetooth LE security flaw could let malicious actors discover people’s iPhone numbers using Apple’s file-sharing AirDrop feature.
An attacker would need to create a phone number database for a specific region. Using a special script, they then could collect information on users who tried to AirDrop a file.
Siri is always listening (depending on your settings). Photo: Charlie Sorrel/Cult of Mac
Apple shares recordings made by Siri with third-party contractors, according to a recent report. The goal is to improve Siri’s responses, but the fact is, you probably didn’t know that this was happening — and almost certainly want it to stop.
Today, I will show you how to prevent these diagnostic recordings from going to Apple. The good news? You can do it using only Apple’s tools. The bad news is that you’ll have to get your hands dirty in the process.
Lockdown secures your iPhone with a firewall. Photo: Charlie Sorrel/Cult of Mac
Lockdown Apps is a new firewall app for iOS. Like Guardian Firewall, which we covered last month, Lockdown uses iOS’ VPN framework to intercept all incoming and outgoing network traffic, and allows you to block connections to any address.
Unlike Guardian Firewall, Lockdown operates entirely on your device. It is also open source.
DuckDuckGo is a private search engine. Unlike Google, it doesn’t track your internet use, save your searches, or track your location. DuckDuckGo’s reason for existing is to protect your privacy on the internet, but it’s also a great search engine. And when it doesn’t find the results you want, it’s easy to run that search in Google.
Today we’ll see how to switch all your searches to DuckDuckGo, and how to add a one-tap Google backup search.
The good news is that you don’t have to do anything weird or difficult to switch to DuckDuckGo. Both iOS and macOS offer it as a default option in their settings. On the Mac, this setting is in Safari. On the iPhone and iPad, you’ll find it under Safari in the Settings app.
These silent updates are security patches that Apple can apply to your Mac automatically, without asking you first. They’re relatively rare, and are a great way for Apple to patch security holes almost instantly. They prove especially helpful for the kind of user that never, ever bothers to run software updates.
But what if you are a Mac nerd? Maybe you want to have a say over this kind of thing. Or perhaps you run IT for a company, and don’t want anything being installed on the business Macs without you checking it first. Can you switch off Apple’s silent updates? Yes, you can. Here’s how.
Don’t install Flash Player. Not even the real one. Photo: Intego
Security researches have discovered new malware that targets macOS users and evades popular antivirus tools.
“CrescentCore” is distributed as a DMG package that’s disguised as Adobe Flash Player. It can now be found on multiple websites — one of which is “a high-ranking Google search result,” according to Intego.
Ivan Krstic last appeared at Black Hat in 2016. Photo: Black Hat
Apple security chief Ivan Krstic will be returning to the Black Hat security conference this summer to discuss iOS 13 and macOS Catalina — as well as the security protections in Apple’s new Find My service.
The 50-minute talk, titled “Behind the scene of iOS and Mac Security,” will take place on August 8. Krstic describes it as the “first public discussion of several key technologies new to iOS 13 and the Mac.”
It takes care of itself. Photo: Killian Bell/Cult of Mac
You can now ask the Google app on iOS to automatically wipe your location and activity history.
The new feature, which was showcased during Google I/O in late May, takes the hassle out of covering your tracks. You only have to set it up once and it will take care of itself going forward. Here’s how to get started.
Anyone with an AirPort Express like this one should install the latest security update. Photo: Apple/Cult of Mac
Apple discontinued the AirPort line of wireless routers last year but continues to support them, including efforts to keep out hackers. The US government’s Cybersecurity and Infrastructure Security Agency (CISA) released a statement urging users of networking equipment to install a new firmware patch to block attacks.