Security

Apple Patches a NSO Zero-Day Flaw Affecting All Devices (techcrunch.com) 29

Apple has released security updates for a newly discovered zero-day vulnerability that affects every iPhone, iPad, Mac and Apple Watch. Citizen Lab, which discovered the vulnerability and was credited with the find, urges users to immediately update their devices. From a report: The technology giant said iOS 14.8 for iPhones and iPads, as well as new updates for Apple Watch and macOS, will fix at least one vulnerability that it said "may have been actively exploited." Citizen Lab said it has now discovered new artifacts of the ForcedEntry vulnerability, details it first revealed in August as part of an investigation into the use of a zero-day vulnerability that was used to silently hack into iPhones belonging to at least one Bahraini activist.

Last month, Citizen Lab said the zero day flaw -- named as such since it gives companies zero days to roll out a fix -- took advantage of a flaw in Apple's iMessage, which was exploited to push the Pegasus spyware, developed by Israeli firm NSO Group, to the activist's phone. Pegasus gives its government customers near-complete access to a target's device, including their personal data, photos, messages and location.

Encryption

WhatsApp Will Finally Let Users Encrypt Their Chat Backups in the Cloud (techcrunch.com) 12

WhatsApp said on Friday it will give its two billion users the option to encrypt their chat backups to the cloud, taking a significant step to put a lid on one of the tricky ways private communication between individuals on the app can be compromised. From a report: The Facebook-owned service has end-to-end encrypted chats between users for more than a decade. But users have had no option but to store their chat backup to their cloud -- iCloud on iPhones and Google Drive on Android -- in an unencrypted format. [...] Now WhatsApp says it is patching this weak link in the system.

The company said it has devised a system to enable WhatsApp users on Android and iOS to lock their chat backups with encryption keys. WhatsApp says it will offer users two ways to encrypt their cloud backups, and the feature is optional. In the "coming weeks," users on WhatsApp will see an option to generate a 64-digit encryption key to lock their chat backups in the cloud. Users can store the encryption key offline or in a password manager of their choice, or they can create a password that backs up their encryption key in a cloud-based "backup key vault" that WhatsApp has developed.

Facebook

Facebook Debuts Its Ray-Ban Stories Smart Sunglasses (techcrunch.com) 118

Facebook announced their long-awaited foray into the smart glasses space Thursday morning, launching the Ray-Ban Stories smart glasses in partnership with eyewear giant EssilorLuxottica. From a report: The svelte frames are some of the most low-profile yet available to consumers and will allow users to snap photos and videos with the two onboard 5 MP cameras, listen to music with in-frame speakers and take phone calls. The glasses need to be connected to an iOS or Android device for full functionality, though users can take and store hundreds of photos or dozens of videos on the glasses before transferring media to their phones via Facebook's new View app. The twin cameras will allow users to add 3D effects to their photos and videos once they upload them to the app.

The lightweight glasses weigh less than 50 grams and come with a leather hardshell charging case. The battery lift is advertised as "all-day" which TechCrunch found to be accurate during our review of the frames. Users will be able to control the glasses with a couple physical buttons including a "capture" button to record media and an on-off switch. A touch pad on the right arm of the glasses will allow users to perform functions like swiping to adjust the volume or answering a phone call. An onboard white LED will glow to indicate to the people around the wearer that a video is being recorded.
The glasses will start at $299, with polarized and transition lens options coming in at a higher price point.
Privacy

After Chiding Apple On Privacy, Germany Says It Uses Pegasus Spyware (appleinsider.com) 38

"Germany's Federal Criminal Police Office (BKA) purchased access to NSO Group's Pegasus spyware in 2019 after internal efforts to create similar iOS and Android surveillance tools failed," reports AppleInsider. The news comes less than a month after the Digital Agenda committee chairman of Germany's federal parliament, Manual Hoferlin, declared Apple to be on a "dangerous path" with plans to enact on-device child sexual assault material monitoring. He said the system undermines "secure and confidential communication" and represents the "biggest breach of the dam for the confidentiality of communication that we have seen since the invention of the Internet." From the report: The federal government revealed the agreement with NSO in a closed-door session with the German parliament's Interior Committee on Tuesday, reports Die Zeit. When the BKA began to use Pegasus is unclear. While Die Zeit says the tool was purchased in 2019 and is currently used in concert with a less effective state-developed Trojan, a separate report from Suddeutsche Zeitung, via DW.com, cites BKA Vice President Martina Link as confirming an acquisition in late 2020 followed by deployment against terrorism and organized crime suspects in March.

Officials made the decision to adopt Pegasus in spite of concerns regarding the legality of deploying software that can grant near-unfettered access to iPhone and Android handsets. As noted in the report, NSO's spyware exploits zero-day vulnerabilities to gain access to smartphones, including the latest iPhones, to record conversations, gather location data, access chat transcripts and more. Germany's laws state that authorities can only infiltrate suspects' cellphone and computers under special circumstances, while surveillance operations are governed by similarly strict rules.

BKA officials stipulated that only certain functions of Pegasus be activated in an attempt to bring the powerful tool in line with the country's privacy laws, sources told Die Zeit. It is unclear how the restrictions are implemented and whether they have been effective. Also unknown is how often and against whom Pegasus was deployed. According to Die Zeit, Germany first approached NSO about a potential licensing arrangement in 2017, but the plan was nixed due to concerns about the software's capabilities. Talks were renewed after the BKA's attempts to create its own spyware fell short.

Microsoft

Microsoft Start is a Personalized News Feed Designed for Windows 11, Mobile, and More (theverge.com) 57

Microsoft is launching Microsoft Start today, a personalized news feed that integrates into Windows 11 and is accessible online and on iOS and Android. Microsoft Start is very similar to the MSN feed that exists today and to Microsoft News. Microsoft is rebranding these into Microsoft Start and integrating the feed into the Windows 11 widgets section and the Windows 10 taskbar. From a report: Much like Microsoft News, Microsoft Start includes news and media channels from more than 1,000 publishers. Microsoft uses AI and machine learning algorithms to sort through which news is presented to users and to personalize content based on interests and how you engage with content. There's also some "human moderation" involved, but Microsoft did layoff dozens of journalists and editorial workers at its Microsoft News and MSN organizations last year, so it's not clear how involved editors will be. Microsoft Start will surface top stories, personalized recommendations, and sports scores or the weather in its feed.
IOS

Apple Delays Plans To Roll Out CSAM Detection in iOS 15 (techcrunch.com) 61

Apple has delayed plans to roll out its child sexual abuse (CSAM) detection technology that it chaotically announced last month, citing feedback from customers and policy groups. From a report: That feedback, if you recall, has been largely negative. The Electronic Frontier Foundation said this week it had amassed more than 25,000 signatures from consumers. On top of that, close to 100 policy and rights groups, including the American Civil Liberties Union, also called on Apple to abandon plans to roll out the technology. In a statement on Friday morning, Apple told TechCrunch: "Last month we announced plans for features intended to help protect children from predators who use communication tools to recruit and exploit them, and limit the spread of Child Sexual Abuse Material. Based on feedback from customers, advocacy groups, researchers and others, we have decided to take additional time over the coming months to collect input and make improvements before releasing these critically important child safety features."
Privacy

Apple Will Ask Before it Targets You With Its Ads in iOS 15 (theverge.com) 29

Apple will start asking for permission to enable Personalized Ads in iOS 15, the company's method of serving relevant ads in the App Store and Apple News by analyzing what you read, purchase, and search for on your device. From a report: The company used to collect that information by default, but now it plans to ask for permission. Apple required other developers to seek users' permission with the debut of App Tracking Transparency, so it seems like it's showing that it will hold itself to a similar standard. The Personalized Ads pop-up should show up when you open the App Store if you're running the most recent iOS 15 beta. In the pop-up, Apple writes that the ads will help you discover relevant apps, products, and services while protecting your privacy by using "device-generated identifiers and not linking advertising information to your Apple ID."
Bitcoin

Twitter For iOS Beta Lays Groundwork For Bitcoin Tips (macrumors.com) 29

Twitter's latest beta update introduces support for providing content creators with Bitcoin tips using the "Tip Jar" feature that Twitter introduced earlier this year. MacRumors reports: Bitcoin isn't yet available to select as a tip option for beta users, but code in the beta suggests that Twitter is in the process of rolling it out. When the Tip Jar was first introduced, Twitter allowed users to add Bandcamp, Cash App, Patreon, PayPal and Venmo links to their Twitter profile, but soon, there will be a Bitcoin option.

Details in the latest Twitter beta indicate that users will be directed through a Bitcoin tutorial that includes details on the Bitcoin Lightning Network and custodial and non-custodial Bitcoin wallets. Twitter gives Strike, Blue Wallet and Wallet of Satoshi as examples of custodial wallets and Muun, Breez, Phoenix and Zap as examples of non-custodial wallets. Twitter also informs users that a Strike account is required. "We use Strike to generate Bitcoin Lightning invoices so you'll need to connect your account to accept Bitcoin tips" reads the text.

Privacy

Apple Secures First States To Support Digital Driver's Licenses, But Privacy Questions Linger (techcrunch.com) 100

Apple's plan to digitize your wallet is slowly taking shape. What started with boarding passes and venue tickets later became credit cards, subway tickets, and student IDs. Next on Apple's list to digitize are driver's licenses and state IDs, which it plans to support in its iOS 15 update expected out later this year. From a report: But to get there it needs help from state governments, since it's the states that issue driver's licenses and other forms of state identification, and every state issues IDs differently. Apple said today it has so far secured two states, Arizona and Georgia, to bring digital driver's license and state IDs. Connecticut, Iowa, Kentucky, Maryland, Oklahoma, and Utah are expected to follow, but a timeline for rolling out wasn't given.

Apple said in June that it would begin supporting digital licenses and IDs, and that the TSA would be the first agency to begin accepting a digital license from an iPhone at several airports, since only a state ID is required for traveling by air domestically within the United States. The TSA will allow you to present your digital wallet by tapping it on an identity reader. Apple says the feature is secure and doesn't require handing over or unlocking your phone. The digital license and ID data is stored on your iPhone but a driver's license must be verified by the participating state. That has to happen at scale and speed to support millions of drivers and travelers while preventing fake IDs from making it through. The goal of digitizing licenses and IDs is convenience, rather than fixing a problem. But the move hasn't exactly drawn confidence from privacy experts, who bemoan Apple's lack of transparency about how it built this technology and what it ultimately gets out of it.

Chrome

Chrome 94 Beta Adds WebGPU API With Support For Apple's Metal (9to5mac.com) 36

An anonymous reader quotes a report from 9to5Mac, written by Filipe Esposito: Google this week announced the beta release of Chrome 94, the next update to Google's desktop web browser. In addition to general improvements, the update also adds support for the new WebGPU API, which comes to replace WebGL and can even access Apple's Metal API. As described by Google in a blog post, WebGPU is a new, more advanced graphics API for the web that is able to access GPU hardware, resulting in better performance for rendering interfaces in websites and web apps.

For those unfamiliar, Metal is an API introduced by Apple in 2014 that provides low-level access to GPU hardware for iOS, macOS, and tvOS apps. In other words, apps can access the GPU without overloading the CPU, which is one of the limitations of old APIs like OpenGL. Google says WebGPU is not expected to come enabled by default for all Chrome users until early 2022. The final release of Chrome 94 should enable WebCodecs for everyone, which is another API designed to improve the encoding and decoding of streaming videos.

Businesses

Apple Will Now let App Store Developers Talk To Their Customers About Buying Direct (techcrunch.com) 19

Apple announced today it has reached a proposed settlement in a lawsuit filed against it by developers in the United States. The agreement, which is still pending court approval, includes a few changes, the biggest one being that developers will be able to share information on how to pay for purchases outside of their iOS app or the App Store -- which means they can tell customers about payment options that aren't subject to Apple commissions. The settlement also includes more pricing tiers and a new transparency report about the app review process. From a report: The class-action lawsuit was filed against Apple in 2019 by app developers Donald Cameron and Illinois Pure Sweat Basketball, who said the company engaged in anticompetitive practices by only allowing the downloading of iPhone apps through its App Store. In today's announcement, Apple said it is "clarifying that developers can use communications, such as emails, to share information about payment methods outside of their iOS app. As always, developers will not pay Apple a commission on any purchases taking place outside of their app or the App Stores."
Patents

Apple Wins Patent For Dual-Display MacBook With Virtual Keyboard, Wireless Charging Capabilities (9to5mac.com) 69

The US Patent and Trademark Office has granted a patent to Apple for a dual-display MacBook with a virtual keyboard replacing the traditional keyboard and with the ability to wirelessly charge an iPhone. 9to5Mac reports: As reported by Patently Apple, this patent was submitted three years ago, and only now has Apple won it. With this patent, the company could take a radical path and get rid of a physical keyboard. The interesting thing about this application is that while rumors suggest that Apple will remove the only touchable interface on the MacBook Pro, the Touch Bar, this patent imagines a MacBook with no physical keyboard at all. Patently Apple says this virtual keyboard could be rearranged, swapping the position of the virtual keyboard and trackpad. With a virtual keyboard, Apple could bring gestures from iOS and iPadOS as well, such as pinch, zoom, slide to select, and more. In the patent, Apple says this MacBook includes biometric sensors, which we could interpret as Face ID, fingerprint sensors (aka Touch ID), and a wireless charger, which would be in the left down corner of the notebook.
Iphone

'No Service' Bug Hits Some IOS 14.7.1 Users After Updating Their IPhones (zdnet.com) 26

"What seemed like a small update has, for some, turned into a huge headache," reports ZDNet: Over on Apple's support forum, there are several threads from users complaining that iOS 14.7.1 broke their iPhones, causing a "no service" problem where users are unable to connect to cell service. Ther">e are similar threads on Apple's developer forums as well.

While there doesn't seem to be a pattern to which phones are affected, I've seen reports of everything from the iPhone 6 to iPhone 12 affected, and the cause is clear — upgrading to iOS 14.7.1.

"Users are saying that restarting the phone, removing the SIM, and even resetting network settings didn't help," according to 9to5Mac (in an article shared by long-time Slashdot reader antdude).

Forbes reports the bug appears to happen when you lose your cellular connection and switch to WiFi calling, "so those living in areas with good reception may never see it. Of course, this scenario also helps to mask the scale of iPhones which might be affected." If you haven't upgraded to iOS 14.7.1 yet, this potentially crippling flaw could (understandably) put you off upgrading. The problem is that the release also contains a critical fix for a new zero-day security flaw...
Businesses

Apple's Double Agent (vice.com) 18

For more than a year, an active member of a community that traded in illicitly obtained internal Apple documents and devices was also acting as an informant for the company. An anonymous reader shares a report: On Twitter and in Discord channels for the loosely defined Apple "internal" community that trades leaked information and stolen prototypes, he advertised leaked apps, manuals, and stolen devices for sale. But unbeknownst to other members in the community, he shared with Apple personal information of people who sold stolen iPhone prototypes from China, Apple employees who leaked information online, journalists who had relationships with leakers and sellers, and anything that he thought the company would find interesting and worth investigating. Andrey Shumeyko, also known as YRH04E and JVHResearch online, decided to share his story because he felt that Apple took advantage of him and should have compensated him for providing the company this information.

"Me coming forward is mostly me finally realizing that that relationship never took into consideration my side and me as a person," Shumeyko told Motherboard. Shumeyko shared several pieces of evidence to back up his claims, including texts and an email thread between him and an Apple email address for the company's Global Security team. Motherboard checked that the emails are legitimate by analyzing their headers, which show Shumeyko received a reply from servers owned by Apple, according to online records. Shumeyko said he established a relationship with Apple's anti-leak team -- officially called Global Security -- after he alerted them of a potential phishing campaign against some Apple Store employees in 2017. Then, in mid-2020, he tried to help Apple investigate one of its worst leaks in recent memory, and became a "mole," as he put it. Last year, months before the official release of Apple's mobile operating system iOS 14, iPhone hackers got their hands on a leaked early version.

Privacy

Apple's NeuralHash Algorithm Has Been Reverse-Engineered (schneier.com) 86

An anonymous reader writes: Apple's NeuralHash algorithm (PDF) -- the one it's using for client-side scanning on the iPhone -- has been reverse-engineered.

Turns out it was already in iOS 14.3, and someone noticed:

Early tests show that it can tolerate image resizing and compression, but not cropping or rotations. We also have the first collision: two images that hash to the same value. The next step is to generate innocuous images that NeuralHash classifies as prohibited content.

This was a bad idea from the start, and Apple never seemed to consider the adversarial context of the system as a whole, and not just the cryptography.

Social Networks

Reddit Is Quietly Rolling Out a TikTok-Like Video Feed Button On iOS 12

Reddit is the latest social media platform to roll out a TikTok-like video feed. According to TechCrunch, the discussion-based forum is "making short-form video more pronounced on its iOS app." From the report: According to Reddit, most iOS users should have a button on their app directly to the right of the search bar -- when tapped, it will show a stream of videos in a TikTok-like configuration. When presented with a video, (which shows the poster who uploaded it and the subreddit it's from), users can upvote or downvote, comment, gift an award or share it. Like TikTok, users can swipe up to see another video, feeding content from subreddits the user is subscribed to, as well as related ones. For instance, if you're subscribed to r/printmaking, you might see content from r/pottery or r/bookbinding.

The user interface of the videos isn't new -- Reddit has been experimenting with this format over the last year. But before, this manner of watching Reddit videos was only accessible by tapping on a video while scrolling through your feed -- rather than promoting discovery of other communities, the first several videos recommended would be from the same subreddit. [...] Reddit doesn't yet have a timeline for when the feature will roll out to everyone, but confirmed that this icon first appeared for some users in late July and has continued to roll out to almost all iOS users. But by placing a broader, yet still personalized video feed on the home screen, Reddit is signaling a growing curiosity in short form video.
Software

WhatsApp Gains the Ability To Transfer Chat History Between iOS and Android (techcrunch.com) 4

WhatsApp users will finally be able to move their entire chat history between mobile operating systems -- something that's been one of users' biggest requests to date. From a report: The company today introduced a feature that will soon become available to users of both iOS and Android devices, allowing them to move their WhatsApp voice notes, photos, and conversations securely between devices when they switch between mobile operating systems.

The feature WhatsApp introduced today works with Samsung devices and Samsung's own transfer tool, known as Smart Switch. Today, Smart Switch helps users transfer contacts, photos, music, messages, notes, calendars, and more to Samsung Galaxy devices. Now, it will transfer WhatsApp chat history, too. WhatsApp showed off the new tool at Samsung's Galaxy Unpacked event, and announced Samsung's newest Galaxy foldable devices would get the feature first in the weeks to come. The feature will later roll out to Android more broadly. WhatsApp didn't say when iOS users would gain access.

Government

Apple Says It Will Reject Government Demands To Use New Child Abuse Image Detection System for Surveillance (cnbc.com) 96

Apple defended its new system to scan iCloud for illegal child sexual abuse materials (CSAM) on Monday during an ongoing controversy over whether the system reduces Apple user privacy and could be used by governments to surveil citizens. From a report: Last week, Apple announced it has started testing a system that uses sophisticated cryptography to identify when users upload collections of known child pornography to its cloud storage service. It says it can do this without learning about the contents of a user's photos stored on its servers. Apple reiterated on Monday that its system is more private than those used by companies like Google and Microsoft because its system uses both its servers and software running on iPhones.

Privacy advocates and technology commentators are worried Apple's new system, which includes software that will be installed on people's iPhones through an iOS update, could be expanded in some countries through new laws to check for other types of images, like photos with political content, instead of just child pornography. Apple said in a document posted to its website on Sunday governments cannot force it to add non-CSAM images to a hash list, or the file of numbers that correspond to known child abuse images Apple will distribute to iPhones to enable the system.

Cellphones

Apple Accused of Promoting Scam Apps in Its App Store (arstechnica.com) 17

"Developers are once again publicly highlighting instances in which Apple has failed to keep scam apps off of the app store," reports Ars Technica: The apps in question charge users unusual fees and siphon revenue from legitimate or higher-quality apps. While Apple has previously come under fire for failing to block apps like these from being published, developers complained this week that Apple was actually actively promoting some of these apps...

Apple continues to play whack-a-mole with these apps, but various developers have both publicly and privately complained that the company takes too long. One developer we exchanged emails with claimed that, when they discovered a scam app that stole assets from their own legitimate app and which was clearly designed to siphon users from the real app, Apple took 10 days to remove the app, while Google only took "1-2 days" on the Android side. The app was allowed back on Apple's App Store once the stolen assets were removed. During the long waiting period, the developer of the legitimate app lost a significant amount of users and revenue, while the developer of the illegitimate app profited.

As Apple fights legal battles to prevent third-party app stores from making their way to iOS on the basis that those alternative app stores may be less secure than Apple's own, claims from developers that scam apps are slipping through may undermine Apple's defense.

Medicine

NYC Will Require Vaccines For Entry To Restaurants and Gyms; Requirement Can Be Met With An App (theverge.com) 492

Mayor Bill de Blasio announced today that New York City will become the first major U.S. city to require proof of vaccination to enter all restaurants, fitness centers and indoor entertainment venues. "If you're unvaccinated, unfortunately, you will not be able to participate in many things," de Blasio said. "If you want to participate in our society fully, you've got to get vaccinated." As The Verge reports, "New Yorkers can meet those requirements by carrying their vaccination card or scanning and storing it in one of two authorized mobile apps." From the report: The spread of the highly contagious Delta variant is being cited as a reason to increase restrictions without returning to a full lockdown or other measures. The program is scheduled to launch on August 13th, with enforcement slated to start on September 13th. It doesn't introduce any new documentation; the name is a reference to it serving as a "key" to the city's recovery.

Workers and patrons can confirm their vaccination status (at least one dose administered) in one of three ways: Vaccination card; NYC COVID Safe exposure notification app (iOS, Android); or NYS Excelsior Pass app.

Slashdot Top Deals