|
Tighten Pro C/C++/Cocoa tool for codesign security, Developer ID, & Mac App Store Receipt Validation
  Tighten Pro - in the Mac App Store
Tighten Pro is now available in the Mac App Store.
Simply click on the icon to the left to purchase directly from Apple.
Or choose PKCS#7Viewer.app by clicking the image to the right.
|
Mac Developer: Encryption key for iPhone 5s Touch ID exposed, opens door to further research
Encryption key for iPhone 5s Touch ID exposed, opens door to further research: "The tool and hack is not for the inexperienced. The outputs of the tool are binaries of the kernel and related software regulating the communications between the Touch ID sensor and Secure Enclave —but not any information transmitted presently or in the past between the Touch ID sensor and the Secure Enclave."
If this was a movie, it could be called The Legacy of Bunnie Huang. Labels: security, security exploit, security leak
Mac Developer: Inside the Hunt for Russia's Most Notorious Hacker | WIRED
Inside the Hunt for Russia's Most Notorious Hacker | WIRED: "Werner, as it happened, knew quite a bit about Evgeniy Bogachev. He knew in precise, technical detail how Bogachev had managed to loot and terrorize the world’s financial systems with impunity for years.
A barnburner, terrific article. Labels: malware, security, security is hard
Mac Developer: Pwnfest drops a nasty surprise on VMware • The Register
Pwnfest drops a nasty surprise on VMware • The Register: "The bug scores a critical rating because it could allow a guest to “execute code on the operating system that runs Workstation or Fusion”, the company's advisory says. That's a big no-no in the virtual world: hypervisors are supposed to contain guests and keep the host OS pristine."
Filed under security is hard, and even if you are secure, your VM might be at risk. Labels: security, security exploit
Mac Developer: Every LTE call, text, can be intercepted, blacked out, hacker finds • The Register
Every LTE call, text, can be intercepted, blacked out, hacker finds • The Register: "Ruxcon Hacker Wanqiao Zhang of Chinese hacking house Qihoo 360 has blown holes in 4G LTE networks by detailing how to intercept and make calls, send text messages and even force phones offline."
Best part of this story: she doesn't look anything like Kimdotcom. Labels: assumptions, security, stereotypes
Mac Developer: Microsoft releases open source bug-bomb in the rambling house of C • The Register
Microsoft releases open source bug-bomb in the rambling house of C • The Register: "Key to it is better handling of pointers in C programs. Checked C “allows programmers to better describe how they intend to use pointers and the range of memory occupied by data that a pointer points to,” MS Research explains at its project page."
New features for an old friend. You don't know sizeof like I know sizeof. Labels: security, security exploit
Mac Developer: San Bernardino shooter's iPhone may hold evidence of 'dormant cyber pathogen,' DA says
San Bernardino shooter's iPhone may hold evidence of 'dormant cyber pathogen,' DA says In an application to file an amicus brief with a California court on Thursday, San Bernardino District Attorney Michael A. Ramos intimates an iPhone used by terror suspect Syed Rizwan Farook, and later seized by law enforcement officials, might contain evidence of a "dormant cyber pathogen" threatening the county's data infrastructure.
Nonsense but as all things American media, highly entertaining. Labels: security, security policy
Mac Developer: TrueCrypt is safer than previously reported, detailed analysis concludes | Ars Technica
TrueCrypt is safer than previously reported, detailed analysis concludes | Ars Technica The TrueCrypt whole-disk encryption tool used by millions of privacy and security enthusiasts is safer than some studies have suggested, according to a comprehensive security analysis conducted by the prestigious Fraunhofer Institute for Secure Information Technology.
The rumors of my death have been greatly exaggerated. Labels: security
Mac Developer: Validating Receipts Locally
Validating Receipts Locally
/* For additional security, you may verify the fingerprint of the root certificate and verify the OIDs of the intermediate certificate and signing certificate. The OID in the certificate policies extension of the intermediate certificate is (1 2 840 113635 100 5 6 1), and the marker OID of the signing certificate is (1 2 840 113635 100 6 11 1). */
I suppose the moral of the story is: don't say I didn't warn ya.
Labels: secure coding mac, security, security fix
Mac Developer: Unpatched browser weaknesses can be exploited to track millions of Web users | Ars Technica
Unpatched browser weaknesses can be exploited to track millions of Web users | Ars Technica Over the past decade, there's been a privacy arms race between unscrupulous website operators and browser makers. The former wield an ever-changing lineup of so-called zombie cookies that can't be easily deleted and attacks that sniff thousands of previously visited sites, while browser makers aim to prevent such privacy invasions by closing the design weaknesses that make them possible. Almost as soon as one hole is closed, hackers find a new one.
And of course, the writers of typical desktop software are made to suffer for the ill-behaved at the hand of partially tested security features that don't stop real hackers. Labels: security, security fix
Mac Developer: SHA1 algorithm securing e-commerce and software could break by year’s end | Ars Technica
SHA1 algorithm securing e-commerce and software could break by year’s end | Ars Technica SHA1, one of the Internet's most crucial cryptographic algorithms, is so weak to a newly refined attack that it may be broken by real-world hackers in the next three months, an international team of researchers warned Thursday.
Dang, SHA1, we hardly knew ye.
Labels: secure coding mac, security, SHA1
Mac Developer: Newly Discovered Android Ransomware Communicates Over XMPP, Poses As NSA | Redmond Pie
Newly Discovered Android Ransomware Communicates Over XMPP, Poses As NSA | Redmond Pie
A new strain of Android ransomware, which disguises itself as a legitimate application, has been discovered to be utilizing the Extensible Messaging and Presence Protocol (XMPP) for instant messaging, to receive commands and to communicate remotely with the server that controls the malicious installation.
Exciting new lifeforms in the petri dish of the future. Labels: security, security flaw
Mac Developer: Kaspersky ex-employees say Russian antivirus firm faked malware to harm rivals | VentureBeat | Security | by Reuters
Kaspersky ex-employees say Russian antivirus firm faked malware to harm rivals | VentureBeat | Security | by Reuters: "SAN FRANCISCO (Reuters, Joseph Menn) – Beginning more than a decade ago, one of the largest security companies in the world, Moscow-based Kaspersky Lab, tried to damage rivals in the marketplace by tricking their antivirus software programs into classifying benign files as malicious, according to two former employees.
The heat is on.
Labels: security, security policy, security research
Mac Developer: Lenovo once again reminds everyone why it's better to get a Mac
Lenovo once again reminds everyone why it's better to get a Mac: "Back in February Windows PC manufacturer Lenovo was caught injecting Superfish adware onto some of their laptops, not only exploiting their own customers but leaving those customers open to man-in-the-middle attacks. Now they've been charged with using something akin to a rootkit to make sure their own customers can't cleanly reinstall Windows, not without Lenovo re-intalling updaters, app installers, and system data collectors as well. And yes, this Lenovo hack was also potentially exploitable by malware. "
When shopping for that new PC to run Windows 10 for your WinObjC project, do yourself a favor and get a Dell or use a Mac with bootcamp. I found the Windows 8 to Windows 10 transition on the Dell totally painless. I upgrade the chap to a SSD, used Windows 8 Media Creation to burn an ISO and am now up and running on Windows 10 with VS Community 2015.
I'm totally intrigued by the new HyperV malware protection in Windows and may switch to such a laptop for all my internet related work in the immediate future.
Labels: security, security flaw
Mac Developer: Windows 10 Device Guard: Microsoft's effort to keep malware off PCs • The Register
Windows 10 Device Guard: Microsoft's effort to keep malware off PCs • The Register: "If the Windows 10 kernel, which has control over the PC, is compromised, Device Guard will remain fire-walled off, and cannot be subverted into allowing unauthorized code to run. A hypervisor running beneath the kernel and Device Guard enforces this.
Some interesting developments here.
Labels: sandbox, secure coding mac, security
Mac Developer: Security researchers build on PC vulnerabilities to create first firmware-based Mac worm
Security researchers build on PC vulnerabilities to create first firmware-based Mac worm: "Firmware attacks are possible because many computer manufacturers put few safeguards in place to prevent malicious updates or changes, leaving many computers vulnerable. According to Wired, Apple could have put protections in place to prevent at least one type of attack discovered by the research group, but apparently elected not to."
More O Daeng!
Labels: security, security fix
Mac Developer: The iOS 8.4 jailbreak app is now available on Mac
Mac Developer: Stepson of Stuxnet stalked Kaspersky for months, tapped Iran nuke talks | Ars Technica
Stepson of Stuxnet stalked Kaspersky for months, tapped Iran nuke talks | Ars Technica: "in 2011 Duqu 1.0 attackers compromised computers at NetLock, a Hungarian certificate authority. That hack allowed them to sign their wares with digital stamps trusted by Windows machines."
Fascinating tale. Or "How I learned to stop worrying and love the Nation-state sponsored cyberwars."
Labels: secure coding mac, security, security flaw
Mac Developer: Developer hacks Apple Watch to run native UIKit apps on watchOS 1.0 | 9to5Mac
Developer hacks Apple Watch to run native UIKit apps on watchOS 1.0 | 9to5Mac: "Well-known developer Steve Troughton-Smith, who previously was able to get real UIKit-backed apps running on Apple Watch with watchOS 2.0, now says that he has gotten native UIKit apps running on watchOS 1.0. Smith shared a video showing off the feat, which can be seen via the embed below."
O Daeng!
Labels: security
Mac Developer: Report: Hack of government employee records discovered by product demo | Ars Technica
Report: Hack of government employee records discovered by product demo | Ars Technica: "Those statements may not be entirely accurate. According to a Wall Street Journal report, the breach was indeed discovered in April. But according to sources who spoke to the WSJ's Damian Paletta and Siobhan Hughes, it was in fact discovered during a sales demonstration of a network forensics software package called CyFIR by its developer, CyTech Services."
Will the truth be known? Labels: security
Mac Developer: White House appoints NSA-criticizing computer scientist Ed Felten to key post | VentureBeat | Security | by Dylan Tweney
White House appoints NSA-criticizing computer scientist Ed Felten to key post | VentureBeat | Security | by Dylan Tweney: "White House’s appointment today of Ed Felten, a Princeton computer science professor, as its deputy U.S. chief technology officer."
This looks good.
Labels: security, security law, security policy
| |
|