Skip to content
Thoughtful, detailed coverage of everything Apple for 34 years
and the TidBITS Content Network for Apple professionals

Category: Security

Adam Engst 37 comments

How to Detect and Protect Against Updated Flashback Malware

Apple has released an update to its Java runtime engine to, among other things, fix a vulnerability that’s been exploited by variants of the Flashback malware. Doctor Web, an antivirus software developer in Russia, says as many as 600,000 Macs have been infected with the malware. We run down what’s known about Flashback and how you can protect yourself.

Adam Engst 6 comments

New “Take Control of CrashPlan Backups” Explains CrashPlan

We love the CrashPlan backup program and service because of all the places it can store your data, but we’ll be the first to admit that CrashPlan has a somewhat odd interface that benefits from the kind of thorough documentation that only Joe Kissell can provide.

Glenn Fleishman 16 comments

Elcomsoft Criticism of iOS Password Apps Overblown

Security firm Elcomsoft has released a white paper detailing weaknesses when short passwords with mixed characters or longer ones solely made up of numbers are used with many iOS password-keeping apps, including 1Password, LastPass, and mSecure. The impact of these weaknesses is limited to start with, and not a risk unless someone is out to get your passwords in particular.

Adam Engst 4 comments

Back Up Your Google Data with CloudPull

If you use Google Docs heavily or don’t already have a good IMAP-based backup of your Gmail account, look into Golden Hill Software’s CloudPull, which makes local backups of the important data in your Google account.

Adam Engst 7 comments

iOS Apps with Location Permission Can Access Your Photos

Nick Bilton of the New York Times reports that a loophole in iOS’s security infrastructure enables apps you have allowed to determine your current location to access all the photos on your device (presumably due to the location information stored within photos). Although there are no known instances of this capability being abused in the wild, a proof-of-concept app commissioned by the New York Times showed that it could upload photos to a remote server once it had been given location permission. Apple will likely fix this soon; in the meantime, we recommend turning off unnecessary permissions in Settings > Location Services.

TidBITS Staff 6 comments

The Sandbox Conundrum: Security vs. Innovation

For a second time, Apple has extended the deadline for requiring App Store developers to sandbox their apps. Unfortunately, this delay does little to ease the problems that surround the sale of apps that do not fit Apple’s distribution model.

Michael E. Cohen 8 comments

Fixing Find My Mac

Find My Mac was unavailable on Michael Cohen’s iMac ever since the feature was first introduced — until he found the easy fix.

Adam Engst 20 comments

Beware the Morphing Flashback Malware

The Flashback malware, which has evolved significantly since its discovery in September 2011, now uses sufficiently subtle infection methods that non-technical users could easily fall prey to it. Worse, neither Apple’s XProtect malware detection system nor the forthcoming Gatekeeper in Mountain Lion can stop the current Flashback variant.

Agen Schmitz No comments

MacVoicesTV Parenting Panel from Macworld | iWorld

Tonya Engst discusses raising children in the age of screentime as part of the “Parenting in the Mobile Internet Age” panel discussion from Macworld | iWorld 2012, moderated by Chuck Joiner of MacVoicesTV.

Glenn Fleishman No comments

Web Certificate Flaw Not Dangerous

Two sets of researchers revealed that insufficiently random choices of the prime numbers from which encryption keys are derived for Web site SSL/TLS certificates mean that the private parts of the keys can be derived. Fortunately, it’s not a flaw in an algorithm, and seems to affect only a small number of sites. Read the whole explanation in Glenn Fleishman’s account at Boing Boing.

Rich Mogull 25 comments

Gatekeeper Slams the Door on Mac Malware Epidemics

OS X 10.8 Mountain Lion introduces a new security feature to help users install downloaded software only when it comes from trusted sources. This is the first major advance in consumer security to protect users from being tricked into downloading malicious applications.

Adam Engst 24 comments

Mac OS X 10.7.3 Fixes Bugs, Improves Lion Server

On the desktop side, Mac OS X 10.7.3 is just another bug fix update (along with some welcome new language support). But for those using Lion Server, the 10.7.3 update provides new features and an improved interface, along with plenty of bug fixes.

Adam Engst 6 comments

What It’s Like to Experience Email Account Hijacking

In the November issue of The Atlantic, James Fallows shares the story of how his wife’s Gmail account was hijacked and what they went through to recover years of stored messages. It’s a compelling tale that will hopefully bring home the need for secure passwords and offline backups of cloud-based data.

Glenn Fleishman 10 comments

CameraTrace Tracks by Serial Number in Photos

The folks at GadgetTrak have taken their camera-tracing database service out of beta and given it the name CameraTrace. You can search for serial numbers embedded in billions of uploaded photos for free, or pay $10 per camera for an active trace.

Glenn Fleishman 5 comments

New Tool Secures Against DNS Poisoning

A new tool from domain name lookup service OpenDNS secures your Mac’s connection to the firm’s servers when translating a human-readable name into its IP address, as Glenn Fleishman explains at Macworld. This prevents a host of malicious activities that can occur when third parties tamper or poison the values returned for a DNS request. It’s free, and it works with OpenDNS’s free and paid offerings.