Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. Correction: — the microphone cut-off switch in the new iPad Pros is not a physical disconnect, but it is completely independent of iOS and can’t be affected by malware because it’s in the T2 […]
Continue readingAuthor: Bart Busschots
Security Bits — 5 April 2020
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. Cloudflare’s WARP VPN Enters Beta for macOS, Windows — www.macobserver.com/… Related: WireGuard, the new and very promising open source VPN protocol that powers WARP VPN has reached 1.0, and has been added to the […]
Continue readingSecurity Bits — 22 March 2020
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. Following on from the iOS clipboard security weakness discussed in the previous instalment, security researchers have now observed many popular iOS apps periodically polling the clipboard for no apparent reason, and it’s not known […]
Continue readingSecurity Bits — 8 March 2020
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. FireFox are continuing their roll-out of DoH, enabling it by default for new installs in the US — nakedsecurity.sophos.com/… Google stops indexing WhatsApp chats; other search engines still at it — nakedsecurity.sophos.com/… HomeKit Router […]
Continue readingSecurity Bits — 23 February 2020
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. Developments in the Avast Browser History Data Sales story: Avast kills off Jumpshot, the subsidiary that sold all your Web data — arstechnica.com/… 🇨🇿 Czech Authorities to Investigate Avast Over Sale of Users’ Browser […]
Continue readingSecurity Bits — 9 February 2020
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. 🧯Intel have released a fix for yet another named bug in performance-enhancing features of their CPUs. This one is named CacheOut because it involves cache evictions. The key takeaway is that like the other […]
Continue readingSecurity Bits — 26 January 2020
Feedback & Followups Following on from Apple’s introduction of support for FIDO2 in iOS 13, Google now allow you to use an iPhone as a hardware security token — nakedsecurity.sophos.com/… 🇺🇸 Following on from YouTube’s recent $170 million fine for breaching COPPA, a bi-partisan bill has been introduced in the US House of Representatives named […]
Continue readingSecurity Bits – 12 January 2020
Commentary by Allison — Bart is testing out a new format which in theory will cut the time it takes him to do Security Bits in half. This week is 4 weeks worth of security news so it’s not the best test case, but the new format is here. We welcome feedback on it as […]
Continue readingSecurity Bits – 22 December 2019
Note: This is the second of two episodes both recorded on the 15th of December 2019, but released over two weeks. Security Medium 1 — An Over-hyped VPN Weakness The internet positively hyper-ventilated when security researchers claimed to have found a bug in the TCP/IP implementation on just about every OS that could compromise just […]
Continue readingSecurity Bits – 15 December 2019
Note: This is the first of two episodes both recorded on the 15th of December 2019, but released over two weeks. 🧯Security Medium Preview 1 — VPNs Not All Hacked We’ll dig into the details in the second part of this two-parter, but for now, I just want to set everyone’s mind at ease — […]
Continue reading