Feedback & Followups
- Two weeks ago we talked about the new method of authentication I’d encountered with my bank and you had it too, where you go to log in on a website and it sends you a notification on your phone’s screen, which when tapped opens the app for the website and then does FaceID to authenticate you, and then you’re in on the Mac? The two questions that have come up from that in the last week in our Slack are:
- From Jill – isn’t it quite possible a hacker would try to get into your account, your phone would send you the notification and you’d instinctively tap it and instantly authenticate for them?
- Bart explained that these apps’ implementations (at least Bart and Allison’s) have one more step. After authenticating with your Face/TouchID, there is a request to authorize with a yes or no and telling you the OS and browser making the request and the approximate physical location
- From Steve – if the site (like ours) offers you the option of this dedicated phone-based authenticated method but the other option is an SMS, isn’t your account just as susceptible to SIM swapping as if they didn’t offer the dedicated phone app?
- Short answer is yes – the weakest link is the problem
- The better option is if the institution allows you to disable the SMS option
- From Jill – isn’t it quite possible a hacker would try to get into your account, your phone would send you the notification and you’d instinctively tap it and instantly authenticate for them?
- Apple have begin shipping the special pre-rooted iPhones for security researchers announced last year. These devices mean eligible security researchers no longer need jailbreaks to get full root access to iPhones, making it much easier for them to do their invaluable research — www.imore.com/… & tidbits.com/…
- COVID-related Apps
- Apple have added symptom tracking to their Health app. It’s much broader than the current pandemic, but it may be useful to start tracking your baseline if you normally have COVID-like symptoms for other reasons, that way you have a better chance of noticing a change — tidbits.com/…
- 🇺🇸 Apple have added CDC travel guidance notifications into Apple Maps for US users re-entering the country — www.imore.com/…
- The Google/Apple API Saga continues:
- 🇮🇪 🇬🇧 🇺🇸 Apple’s Google/Apple-based app continues it’s successful launch, and the software company who wrote it are being approached by other health authorities from around the world, including at least one US state. The same company also produced Northern Ireland’s app which is about to be launched. The app has already detected cases in Ireland. — www.theguardian.com/… & www.imore.com/…
- 🇺🇸 The Association of Public Health Laboratories (APHL)will build a national COVID-19 exposure notification server for use by state apps using the Apple/Google’s API. It will be hosted by Microsoft — www.imore.com/…
- 🇦🇺 Despite counter-examples from Europe (Germany, Ireland …), Australia continues to blame Apple or their failure to build an effective app — www.macobserver.com/…
- Social Media Continues to Evolve
- Facebook Messenger for iOS now allows you to use biometrics to lock the app, so handing someone your phone to quickly do or check something doesn’t give them access to your messages — www.imore.com/…
- Facebook adds live broadcasting to Messenger Rooms — www.imore.com/…
Deep Dive 1 — ECJ Ends EU/US Data Privacy Shield
Back in the year 2000, the European Commission created Safe Harbour, a framework that allowed companies to transfer data on EU citizens to the US. The logic was the US and EU law provided similar protections, so the transfer did not compromise EU citizens’ rights. That always stretched credulity, but the whole idea became ever more untenable as the EU moved to add ever more protections and the US didn’t. Even before the GDPR, EU citizens had much better protections than US citizens, and so the Safe Harbour was challenged in the European Court of Justice and overturned. In a bit of a mad scramble, the European Commission replaced Safe Harbour with the EU-US Privacy Shield in 2016. When the GDPR was introduced it seemed like just a matter of time until this too would fall, and that’s what happened this month. The ECJ agreed with Austrian privacy activist Max Schrems that the privacy shield is not compatible with GDPR because US law simply doesn’t provide enough protections.
This doesn’t mean that data on EU citizens can’t be transferred to the US, it just means that the 5,378 organisations that were using the privacy shield to avoid having to actually implement GDPR now have to actually ask users consent before transferring their data. Or, to put it in legalese, they need to use Standard Contractual Clauses, or SCCs.
The most important thing to note is that none of this covers information we as users enter into digital services, it’s about the data those services collect about us. If an EU citizen uploads a photo to Flickr, shares a file via DropBox or posts a Tweet, that can flow all over the world without issue. This is about what happens the data all those trackers infesting the web and our apps are hoovering up all the time.
At the end of the day, as best as I can tell, this won’t have any negative impact on users, and it just might give us all a little more control over our privacy, and at the very least, should shine a little light on some of the stuff these companies get up to.
Links
- EU-US Privacy Shield failed to protect data of EU citizens, court rules — www.imore.com/…
- It’s time to say goodbye to the EU-US Privacy Shield — www.zdnet.com/…
Deep Dive 2 — The Twitter Hack
A small number of very high profile Twitter accounts were taken over and used to spread a bitcoin scam — basically “send me some bitcoin and I’ll send you back twice as much”. We now know attempts were made to take over 130 accounts, and 45 of those attempts succeeded. We also know the attackers attempted to generate GDPR-style full data exports from some of the compromised accounts.
This wasn’t a technical hack, but instead, a social engineering attack. According to media reports, we’re talking about Twitter employees with access to back-end systems being paid to take over the accounts.
Twitter responded promptly and well — locking down all verified accounts who’re passwords had been recently changed, and tweeting updates on their on-going investigation, and producing a quite detailed blog post explaining their findings.
This attack in-and-of-itself doesn’t pose a danger to us regular folk, instead it shines a bright spotlight on just how much power Twitter has in modern political discourse, and underlines the dangers these kinds of massive centralised social media services pose to democratic elections. This attack seems to have been more about the LOLs and making a quick buck, but imagine what a well-resourced nation state could do on US election day were they to get control of Twitter’s back-end system like these attackers did!
Links
- Twitter’s official blog post: An update on our security incident — blog.twitter.com/…
- Crypto scammers hack Elon Musk, Biden, Obama, and Kanye on Twitter | EngadgetEngadgetEngadgetPage 1Page 1ear iconeye iconFill 23text filevr — www.engadget.com/…
- Twitter experiences widespread hack in coordinated cryptocurrency scam — www.imore.com/…
- Twitter limits tweeting as prominent accounts spam out cryptocoin scams — nakedsecurity.sophos.com/…
- Hackers Tell the Story of the Twitter Attack From the Inside — www.nytimes.com/…
- Twitter says 130 accounts targeted, 45 compromised in a security breach — www.imore.com/…
- Twitter says at least one elected official had DMs accessed during breach — www.imore.com
❗ Action Alerts
- Patch now! SIGRED – the wormable hole in your Windows servers — nakedsecurity.sophos.com/…
- ASUS routers could be reflashed with malware – patch now! — nakedsecurity.sophos.com/…
- Apple have patched just about all their OSes, as well as some new features there are of course security updates — arstechnica.com/…
- Adobe pushes critical security updates for Bridge, Photoshop and Prelude — www.dpreview.com/…
Worthy Warnings
- 7 VPNs that leaked their logs – the logs that “didn’t exist” — nakedsecurity.sophos.com/…
- DNA Company ‘GEDmatch’ Hacked in Data Breach — www.macobserver.com/…
- Apple Warns Not to Close Your Laptop Lid With a Webcam Cover — www.macobserver.com/…
Notable News
- 🇺🇸 T-Mobile has announced updated tools for customers to help protect themselves from robocalls and scams. They’re rolling out enhanced caller ID based on STIR/SHAKEN, and adding free call blocking services they’re calling Scam Shield — www.imore.com/…
Top Tips
Excellent Explainers
Interesting Insights
- A good overview of the research into TikTok. TL;DR, it’s a security and privacy train-wreck 🙁 — www.macobserver.com/…
- Related: 🎧 🇺🇸 Reset: Can the government ban TikTok? — overcast.fm/…
- Thanks to the CCPA reporter Thomas Smith was able to see all the third-party companies he uses that share their data on him back to Facebook: Doordash and Thousands of Other Companies Passively Send Your Data to Facebook — onezero.medium.com/…
- Are “Smart Locks” Really that Smart? — www.intego.com/…
- Thinking of a Cybersecurity Career? Read This — krebsonsecurity.com/…
Ie
Palate Cleansers
- From Allison: The EFF’s Atlas of Surveillance — www.eff.org/…
- A new mini-series of RedHat’s Command Line Heroes has started focusing on how to become a coder. The first episode is out: Command Line Heroes: Becoming a Coder — overcast.fm/…
Legend
When the textual description of a link is part of the link it is the title of the page being linked to, when the text describing a link is not part of the link it is a description written by Bart.
Emoji | Meaning |
---|---|
🎧 | A link to audio content, probably a podcast. |
❗ | A call to action. |
flag | The story is particularly relevant to people living in a specific country, or, the organisation the story is about is affiliated with the government of a specific country. |
📊 | A link to graphical content, probably a chart, graph, or diagram. |
🧯 | A story that has been over-hyped in the media, or, “no need to light your hair on fire” 🙂 |
💵 | A link to an article behind a paywall. |
📌 | A pinned story, i.e. one to keep an eye on that’s likely to develop into something significant in the future. |
🎩 | A tip of the hat to thank a member of the community for bringing the story to our attention. |