Jose Rodriguez, a Spanish Apple enthusiast, has discovered a new security flaw to be aware of. He posted a Proof of Concept video showing the exploit in action.
We’ll say upfront that this is a highly convoluted attack involving more than two dozen discrete steps. A hacker would need to be in possession of the phone to pull it off, so it’s not something that’s likely to become a major threat.
Even so, we’ll provide the details below.
Apple has built in security measures that are designed to prevent someone from tricking Siri into allowing unauthorized access to the phone. Unfortunately, by using a complex series of steps involving both Siri and Apple’s Notes application, it’s possible for a hacker to bypass those security measures, access images stored on the phone, and then change the image associated with a contact or the owner of the phone.
This method is effective on both iOS12 and the iOS 12.1 beta, which means that Apple’s recent patch to their OS does not and will not prevent this exploit from working. Worse, the company has yet to comment on the matter, so at this point, there’s no timetable for a fix.
The independent news site Threatpost has been able to replicate the attack, so we have third-party confirmation.
Fortunately, there’s a simple way to negate the attack entirely while we’re waiting for a patch to close the loophole once and for all. Simply go to Settings – Face ID & Passcode – Touch ID & Passcode, and disable the “Allow access when locked” option for Siri.
Again, it’s important to reiterate that this is a highly complex attack that involves having both physical access to the device and more than two dozen steps, so this is not an issue that’s likely to be widespread. Even so, it pays to take precautions until Apple can roll out a fix.
Change is coming to the way Microsoft handles search across its ecosystem. If you use the home edition of Office, you’re not likely to notice, but if you use Office 365, the changes will be significant.
If you’re one of the relatively few people who use Google+ in something other than an Enterprise setting, be advised that the clock is ticking. Google has just announced that they’re sunsetting the service. It will be going offline for consumers at some point over the next ten months.
Symantec’s most recent statistics have revealed a disturbing trend. Malware designed to compromise checkout pages is seeing a big spike in use, with the company reporting a staggering 248,000 attempts since August 13th of this year, with more than a third of them (36 percent) between September 13th through September 20th. As disturbing as those numbers are, that’s just the tip of the iceberg.
According to this year’s Traveler’s Risk Index, published by The Traveler’s Indemnity Company, a majority of business owners have a somewhat fatalistic view of hacking and data breaches.
Firefox is upping the ante where digital security is concerned, having just announced the release of a new, free service called ‘Firefox Monitor.’ The new service is designed with one specific goal in mind: To assist users in finding out if their accounts were exposed via a data breach.
Windows 10 is far and away the fastest growing version of the OS in the company’s history. It recently hit an installation base of a staggering 700 million devices after about three years on the market.
If you use the GovPayNet portal, be advised that your personal information is currently at risk. Although at this point, there’s no indication that any hacker has made use of it. The portal is run by Government Payment Service, and is used by many Americans to pay fines, fees and bills generated by more than two thousand different government agencies operating in 35 states.
Google is making a small but pivotal change as it relates to calls placed to 911 operators. Having recently finalized a complex partnership with RapidSOS and West (two emergency technology companies) and T-Mobile, Google will now send location data from its “Emergency Location Service” when an Android user places a 911 call.
Google has recently made some changes and improvements to its G-Suite. It introduces new tools designed to allow managers and admins greater visibility into how the people in their organizations use the G-Suite.