Skip to content
Thoughtful, detailed coverage of everything Apple for 34 years
and the TidBITS Content Network for Apple professionals

Category: Security

Adam Engst 10 comments

Google’s .zip Provides Another Reason to Beware of Wacky Top-Level Domains

Google's new .zip top-level domain has raised concerns from the security community due to the ease with which it enables ambiguous URLs that could be used in phishing attacks.

Adam Engst 9 comments

Sports and Bugs in tvOS 16.5, macOS 13.4 Ventura, iOS 16.5, iPadOS 16.5, watchOS 9.5, and HomePod Software 16.5

The latest updates to Apple’s operating systems increase the visibility of sports in Apple News and bring four-up multiview sports games to the Apple TV 4K. Otherwise, there are just a few bug fixes and a new Pride Celebration wallpaper and watch face. Most important are the security updates, which explain the Rapid Security Responses and address another zero-day exploit.

Adam Engst No comments

iOS 15.7.6 and iPadOS 15.7.6 Incorporate Rapid Security Response Fixes

Apple has now released iOS 15.7.6 and iPadOS 15.7.6 to address a bunch of security vulnerabilities, three of which are actively being exploited in the wild and two of which were fixed in the new operating systems' Rapid Security Responses. Update immediately.

Adam Engst 5 comments

StorCentric and Drobo in Chapter 7: Start Looking for Drobo Replacements

StorCentric and subsidiary Drobo have recently converted their mid-2022 Chapter 11 bankruptcies to Chapter 7, implying that it's unlikely they'll recover. If you use a Drobo storage device, it's time to look for replacements.

Glenn Fleishman 2 comments

AirTag in the News: NYPD Recommends, Apple and Google Propose Industry Tracking Standard

In response to a surge of car thefts, the New York Police Department recommends the city’s car owners install an AirTag to help with stolen vehicle recovery. Meanwhile, Apple and Google have partnered on a new industry standard to provide consistent anti-tracking protection for devices that can track object locations persistently.

Adam Engst 15 comments

What Are Rapid Security Responses and Why Are They Important?

Apple has released the first Rapid Security Responses to iOS 16.4.1, iPadOS 16.4.1, and macOS 13.3.1. Adam Engst explains what a Rapid Security Response is and why they should see significantly faster adoption than traditional updates.

Adam Engst 75 comments

How a Passcode Thief Can Lock You Out of Your iCloud Account, Possibly Permanently

A follow-up to the Wall Street Journal’s investigation into Apple’s problematic iPhone security design reveals that victims are being locked out of their iCloud accounts.

Adam Engst No comments

iOS 15.7.5 and iPadOS 15.7.5 Address Serious Security Vulnerabilities

Playing catchup with last week's urgent updates, Apple has now released iOS 15.7.5 and iPadOS 15.7.5 to address two concerning security vulnerabilities that are actively being exploited in the wild.

Adam Engst 13 comments

iOS 16.4.1, iPadOS 16.4.1, and macOS 13.3.1 Address Serious Security Vulnerabilities, Fix Bugs

We recommend updating iPhones, iPads, and Macs to protect against two security vulnerabilities that are actively being exploited in the wild. iOS and iPadOS also address issues with Siri, and macOS fixes problems with Auto Unlock with an Apple Watch.

Adam Engst 4 comments

iOS 15.7.4 and iPadOS 15.7.4 Provide Security Fixes

Alongside its current operating systems, Apple has released iOS 15.7.4 and iPadOS 15.7.4 to address a slew of security vulnerabilities, one of which is actively being exploited in the wild.

Adam Engst 58 comments

Apple Releases iOS 16.4, iPadOS 16.4, macOS 13.3 Ventura, watchOS 9.4, tvOS 16.4, and HomePod Software 16.4

It’s update day at Apple again, with updates to all the company’s operating systems. A few changes may be particularly welcome, including Voice Isolation for cellular calls, duplicate handling in an iCloud Shared Photo Library, and Web app notifications.

Adam Engst 36 comments

LastPass Publishes More Details about Its Data Breaches

LastPass was heavily criticized for communicating insufficient details after it lost customer vault data in a breach. A collection of new posts attempt to rectify that mistake—but it’s not enough for Adam Engst, who shares his experiences switching from LastPass to 1Password.

Adam Engst 45 comments

How a Thief with Your iPhone Passcode Can Ruin Your Digital Life

The Wall Street Journal reports on a spate of attacks in which iPhone thieves obtain your passcode and then change your Apple ID password, disable Find My, make purchases with Apple Pay, and more. Some attacks are as simple as the miscreants surreptitiously watching you enter your passcode; others involve violence. Read on to learn how to protect yourself.

Adam Engst 20 comments

iOS 16.3.1, iPadOS 16.3.1, macOS 13.2.1 Ventura, watchOS 9.3.1, tvOS 16.3.2, and HomePod Software 16.3.2 Fix Bugs and Security Vulnerabilities

Responding to a nasty WebKit vulnerability that is being actively exploited in the wild, Apple has released updates to all its current operating systems. We recommend updating soon.

Adam Engst 3 comments

Additional GoTo Data Stolen in the LastPass Breach

The repercussions of the LastPass breach continue to resonate, with parent company GoTo now admitting that data associated with its services Central, Pro, join.me, Hamachi, and RemotelyAnywhere was also stolen. Change your passwords and look for alternatives.