<li>## Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. Apple have released iOS 17.3, which includes the new Stolen Device Protection mode designed to thwart the recent spike in iPhone thefts by thieves who have observed or socially engineered passcodes allowing them […]
Continue readingAuthor: Bart Busschots
Security Bits — 21 January 2024
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. We warned about this then-unpatched flaw a few weeks ago, now there’s a fix: Apple patches security flaw that allowed Magic Keyboard Bluetooth connections to be faked — appleinsider.com/… Kaspersky have developed and released […]
Continue readingSecurity Bits — 3 January 2024 (Bart & Jill from the North Woods)
Deep Dive — Operation Triangulation TL;DR — Kaspersky labs have discovered that they, and Russian government officials, were targeted by very advanced iOS malware that completely took over iOS devices for the last 4 years. Apple have patched all the exploited vulnerabilities, regular users were not targeted, and Kaspersky say there is not enough evidence […]
Continue readingThe World’s Most Expensive Sour Raisins – a Story of Dark Patterns
We’ve mentioned dark patterns a few times on Security Bits over the years, they are commonly used design techniques engineered to be effective at tricking humans. They are the dark side of one of the areas of computer science enjoyed most when studying for my degree back at the turn of the century — HCI […]
Continue readingSecurity Bits — 22 December 2023
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. Push Notification Law Enforcement Requests: shortly after we recorded the previous instalment Apple updated their process for law enforcement to request push notification metadata from Apple, now lining their process up with Google’s to […]
Continue readingSecurity Bits — 10 December 2023
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. Allison was sceptical that Google really would move to eliminate 3rd-party cookies in 2024, but they put a little wood behind the proverbial arrow this week: Google is phasing out ad personalization for some […]
Continue readingSecurity Bits — 26 November 2023
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. The recent wave of malicious Google ads targeting software downloads continues, this time it’s malicious versions of the popular Secure FTP client WinSCP — thehackernews.com/… ❗ Action Alerts Calls to action, if any stories […]
Continue readingGoing Phablet with iPhone 15 Pro Max — Bart Busschots
Bart joins me this week on the show to discuss the tradeoffs he made in buying an iPhone 15 Pro Max. Here are some of the thoughts he’ll share. After decades of resisting big phones, and being ‘that guy’ who was cranky when the iPhone X made the smallest modern phone notably bigger, it’s finally […]
Continue readingSecurity Bits — 12 November 2023
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. Attackers continue to succeed in getting Google to host their malicious ads: Google ads push malicious CPU-Z app from fake Windows news site — www.bleepingcomputer.com/… A final twist in the SolarWinds mega-hack saga: SEC […]
Continue readingSecurity Bits — 29 October 2023
Feedback & Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we’re tracking over time. Passkeys continue to roll out: Google Adopts Passkeys as Default Sign-in Method for All Users — thehackernews.com/… Amazon adds passkey support as new passwordless login option — www.bleepingcomputer.com/… Deep Dive 1 — iLeakage TL;DR […]
Continue reading