|
Tighten Pro C/C++/Cocoa tool for codesign security, Developer ID, & Mac App Store Receipt Validation
  Tighten Pro - in the Mac App Store
Tighten Pro is now available in the Mac App Store.
Simply click on the icon to the left to purchase directly from Apple.
Or choose PKCS#7Viewer.app by clicking the image to the right.
|
Mac Developer: Amazon Echo recorded household audio, sent it to random contact
Amazon Echo recorded household audio, sent it to random contact: "An Oregon family's Amazon Echo recorded household audio and sent it to an employee of the family's husband, something Amazon blamed on a rare bug that it intends to fix."
Hmmm. Labels: security fail, security leak
Mac Developer: Encryption key for iPhone 5s Touch ID exposed, opens door to further research
Encryption key for iPhone 5s Touch ID exposed, opens door to further research: "The tool and hack is not for the inexperienced. The outputs of the tool are binaries of the kernel and related software regulating the communications between the Touch ID sensor and Secure Enclave —but not any information transmitted presently or in the past between the Touch ID sensor and the Secure Enclave."
If this was a movie, it could be called The Legacy of Bunnie Huang. Labels: security, security exploit, security leak
Mac Developer: 32TB of Windows 10 internal builds, core source code leak online • The Register
32TB of Windows 10 internal builds, core source code leak online • The Register: "The leaked code is Microsoft's Shared Source Kit: according to people who have seen its contents, it includes the source to the base Windows 10 hardware drivers plus Redmond's PnP code, its USB and Wi-Fi stacks, its storage drivers, and ARM-specific OneCore kernel code."
Bad for Microsoft but possibly great for Linux compatibility in the future. Labels: security leak
Mac Developer: Apple Airport not on latest 'Vault 7' list of gear susceptible to factory firmware hack by CIA
Apple Airport not on latest 'Vault 7' list of gear susceptible to factory firmware hack by CIA: "The latest dump of "leaked" documents from WikiLeaks reportedly from the CIA details the "Cherry Blossom" firmware modification program, which allowed intelligence agencies to change firmware in a networking company's factories —but Apple Airport hardware appears to be unaffected by the effort."
Dango tango wango! Labels: 1984, security leak
Mac Developer: Fearing Shadow Brokers leak, NSA reported critical flaw to Microsoft | Ars Technica
Fearing Shadow Brokers leak, NSA reported critical flaw to Microsoft | Ars Technica: "Four weeks later, MS17-010 was released. And precisely 28 days after that, the Shadow Brokers published EternalBlue, DoublePulsar, and dozens more hacking tools."
Hmmmm. Labels: security leak, security policy
Mac Developer: Como–D'oh! Infosec duo exploits OCR flaw to nab a website's HTTPS cert • The Register
Como–D'oh! Infosec duo exploits OCR flaw to nab a website's HTTPS cert • The Register: "Two European security researchers exploited Comodo's crappy backend systems to obtain a HTTPS certificate for a domain they do not own."
Security is hard and it's getting harder.
Labels: security leak, security policy, security research
Mac Developer: Apple briefly allows, pulls jailbreak app on iOS App Store
Apple briefly allows, pulls jailbreak app on iOS App Store: "The "PG Client" app billed itself as a better client for the service that allows graphic artists to share works. However, when opened, the app was a Chinese version of the Pangu jailbreak tool.
The app was made available by the developer on Sunday at some point. By 3:30 p.m. Eastern, Apple had disabled the download, and by 4:00 p.m. had stricken the webpage for the app leading to the App Store download as well."
Those incorrigible jailbreakers! Labels: security leak, security policy
Mac Developer: Oops: Microsoft leaks its Golden Key, unlocking Windows Secure Boot and exposing the danger of backdoors
Oops: Microsoft leaks its Golden Key, unlocking Windows Secure Boot and exposing the danger of backdoors: "Microsoft has demonstrated why the FBI's desire for "Golden Key" backdoors allowing "good guys" to bypass security is such a bad idea: it inadvertently released its own keys to Windows tablets, phones, HoloLens and other devices using UEFI Secure Boot."
Wow. Secure boot no more. Labels: security fail, security leak
Mac Developer: Russian spies claim they can now collect crypto keys—but don’t say how | Ars Technica
Russian spies claim they can now collect crypto keys—but don’t say how | Ars Technica: "Russia's intelligence agency the FSB, successor to the KGB, has posted a notice on its website claiming that it now has the ability to collect crypto keys for Internet services that use encryption. This meets a two-week deadline given by Vladimir Putin to the FSB to develop such a capability. However, no details have been provided of how the FSB is able to do this."
Lots of clever ASM coders in Russia. Labels: security flaw, security leak, security policy
Mac Developer: TeamViewer users are being hacked in bulk, and we still don’t know how | Ars Technica
TeamViewer users are being hacked in bulk, and we still don’t know how | Ars Technica: "For more than a month, users of the remote login service TeamViewer have taken to Internet forums to report their computers have been ransacked by attackers who somehow gained access to their accounts."
Uh-oh. Labels: security leak
Mac Developer: Apple pulls popular Instagram client 'InstaAgent' from iOS App Store after malware discovery
Apple pulls popular Instagram client 'InstaAgent' from iOS App Store after malware discovery Before being yanked from the App Store, InstaAgent was a chart-topping free app in multiple countries including Canada and the UK, suggesting thousands of unsuspecting users unwittingly handed over their Instagram credentials. Hard numbers are currently unavailable, but the developer guesses as many as 500,000 users downloaded the app. The metric matches up with InstaAgent's performance on the Google Play app store, which removed the title earlier today.
Hmmm. Labels: security flaw, security leak
Mac Developer: Tor browser co-creator: Experian breach shows encryption may not be security panacea | VentureBeat | Security | by Mark Sullivan
Tor browser co-creator: Experian breach shows encryption may not be security panacea | VentureBeat | Security | by Mark Sullivan “Experian had a reason to have the credit card info, perhaps to check account balances, and that means that Experian has systems and applications that decrypt the encrypted information. If the hackers stole information using those systems, then the hackers would see the decrypted credit card numbers.”
It's a difficult problem. Experian probably has some karma coming. Labels: security flaw, security leak
Mac Developer: Malware swipes 225,000 Apple accounts through jailbroken iPhones
Malware swipes 225,000 Apple accounts through jailbroken iPhones: "Researchers have discovered a strain of iOS malware, nicknamed KeyRaider, that has stolen over 225,000 Apple IDs from jailbroken devices. The software takes advantage of Chinese app repositories that let people directly upload and share their own titles. If you happen to download the code, it'll either scoop up your Apple account data (to give rogue users 'free' apps) or hold your phone for ransom."
As they say, you get what you pay for. Labels: security leak
Mac Developer: Hacking Team, the company that sells snooping software to governments, gets hacked | VentureBeat | Security | by Paul Sawers
Hacking Team, the company that sells snooping software to governments, gets hacked | VentureBeat | Security | by Paul Sawers: "Based out of Milan, Italy, Hacking Team has been known for a while, but it hit the headlines last year after security experts revealed the extent to which its software gives law enforcement and intelligence agencies remote access to mobile operating systems. It lets them access texts, phone calls, location data, and other forms of digital communications."
I guess, "Physician, heal thyself!" Labels: security leak
| |
|