Showing posts with label iPhone Users. Show all posts
Showing posts with label iPhone Users. Show all posts

Tuesday, September 14, 2021

Apple users urged to download Pegasus spyware flaw fix

Apple users were urged Tuesday to update their devices after the tech giant announced a fix for a major software flaw that allows the Pegasus spyware to be installed on phones without so much as a click.

Cybersecurity experts at the Citizen Lab, a research center at the University of Toronto, uncovered the flaw while analyzing the phone of a Saudi activist.

That person is among tens of thousands believed to have been targeted with the Israeli-made Pegasus software, which according to media reports has been used worldwide to intercept the communications of activists, journalists and even heads of state.

Apple said Monday that it had "rapidly" developed a software update after Citizen Lab alerted it to the hole in its iMessage software on September 7. 

"Attacks like the ones described are highly sophisticated, cost millions of dollars to develop, often have a short shelf life, and are used to target specific individuals," the company said.

Citizen Lab said it was urging people "to immediately update all Apple devices".

- Intimate surveillance -

Explosive revelations that governments have spied on people using the hugely invasive software -- which was developed by the NSO Group, a secretive Israeli firm -- have ricocheted around the world since July.

Once Pegasus is installed on a phone, it can be used to read a target's messages, look at their photos, track their movements and even switch on their camera -- all without the person knowing.

The flaw fixed by Apple on Monday is a so-called "zero-click exploit", meaning that it can be installed on a device without the owner needing to do so much as click a button. 

Less sophisticated spyware tools have generally required the target to click on a booby-trapped link or file in order to start tapping the person's communications.

Citizen Lab said it believed the flaw, which it named FORCEDENTRY, had been used to install Pegasus on devices since February 2021 or possibly earlier.

It is a variant of a weak spot in Apple's messaging software that Citizen Lab previously detected on the iPhones of nine Bahraini activists, who were hacked with Pegasus between June 2020 and February this year.

"Popular chat apps are the soft underbelly of device security. They are on every device," tweeted John Scott-Railton, a senior researcher at Citizen Lab who helped uncover the flaw.

The messaging service WhatsApp was previously also allegedly used to infiltrate phones using Pegasus, and its owner Facebook is suing the NSO Group. 

The security of messaging apps "needs to be a top priority," Scott-Railton added, urging his followers: "UPDATE YOUR APPLE DEVICES NOW."

- 'Fighting crime' -

NSO, the company at the heart of the scandal, has denied any wrongdoing and insisted its software is intended for use by authorities only in fighting terrorism and other crimes.

But the company, which says it has clients in 45 countries, did not dispute that Pegasus had prompted Apple's urgent software upgrade.

It said in a statement that it would "continue to provide intelligence and law enforcement agencies around the world with life saving technologies to fight terror and crime."

Citizen Lab, which first uncovered Pegasus alongside cybersecurity firm Lookout five years ago, accuses NSO of selling the software to authoritarian governments that use it for repressive purposes.

Emerging economies such as India, Mexico and Azerbaijan dominated the list of countries where large numbers of phone numbers were allegedly identified as possible targets by NSO's clients. 

Since July, the scandal has prompted calls from rights groups for an international moratorium on the sale of surveillance technology until regulations are put in place to prevent abuses.

That call was backed by United Nations human rights experts last month.

"It is highly dangerous and irresponsible to allow the surveillance technology and trade sector to operate as a human rights-free zone," they said.

Israel's defense establishment has meanwhile set up a committee to review NSO's business, including the process through which export licenses are granted.

Agence France-Presse 

Monday, October 30, 2017

iPhone X brings face recognition (and fears) to the masses


WASHINGTON - Apple will let you unlock the iPhone X with your face -- a move likely to bring facial recognition to the masses, along with concerns over how the technology may be used for nefarious purposes.

Apple's newest device, set to go on sale November 3, is designed to be unlocked with a facial scan with a number of privacy safeguards -- as the data will only be stored on the phone and not in any databases.

Unlocking one's phone with a face scan may offer added convenience and security for iPhone users, according to Apple, which claims its "neural engine" for FaceID cannot be tricked by a photo or hacker.

While other devices have offered facial recognition, Apple is the first to pack the technology allowing for a three-dimensional scan into a handheld phone.

But despite Apple's safeguards, privacy activists fear the widespread use of facial recognition would "normalize" the technology and open the door to broader use by law enforcement, marketers or others of a largely unregulated tool.

"Apple has done a number of things well for privacy but it's not always going to be about the iPhone X," said Jay Stanley, a policy analyst with the American Civil Liberties Union.

"There are real reasons to worry that facial recognition will work its way into our culture and become a surveillance technology that is abused."

A study last year by Georgetown University researchers found nearly half of all Americans in a law enforcement database that includes facial recognition, without their consent.

Civil liberties groups have sued over the FBI's use of its "next generation" biometric database, which includes facial profiles, claiming it has a high error rate and the potential for tracking innocent people.

"We don't want police officers having a watch list embedded in their body cameras scanning faces on the sidewalk," said Stanley.

Clare Garvie -- the Georgetown University Law School associate who led the 2016 study on facial recognition databases -- agreed that Apple is taking a responsible approach but others might not.

"My concern is that the public is going to become inured or complacent about this," Garvie said.

ADVERTISERS, POLICE, PORN STARS

Widespread use of facial recognition "could make our lives more trackable by advertisers, by law enforcement and maybe someday by private individuals," she said.

Garvie said her research found significant errors in law enforcement facial recognition databases, opening up the possibility someone could be wrongly identified as a criminal suspect.

Another worry, she said, is that police could track individuals who have committed no crime simply for participating in demonstrations.

Shanghai and other Chinese cities have recently started deploying facial recognition to catch those who flout the rules of the road, including jaywalkers.

Facial recognition and related technologies can also be used by retail stores to identify potential shoplifters, and by casinos to pinpoint undesirable gamblers.

It can even be used to deliver personalized marketing messages -- and could have some other potentially unnerving applications.

Last year, a Russian photographer figured out how to match the faces of porn stars with their social media profiles to "doxx" them, or reveal their true identities.

This type of use "can create huge problems," said Garvie. "We have to consider the worst possible uses of the technology."

Apple's system uses 30,000 infrared dots to create a digital image which is stored in a "secure enclave," according to a white paper issued by the company on its security. It said the chances of a "random" person being able to unlock the device are one in a million, compared with one in 50,000 for its TouchID.

LEGAL BATTLE BREWING

Apple's FaceID is likely to touch off fresh legal battles about whether police can require someone to unlock a device.

FaceID "brings the company deeper into a legal debate" that stemmed from the introduction of fingerprint identification on smartphones, according to ACLU staff attorney Brett Max Kaufman.

Kaufman says in a blog post that courts will be grappling with the constitutional guarantees against unreasonable searches and self-incrimination if a suspect is forced to unlock a device.

US courts have generally ruled that it would violate a user's rights to give up a passcode because it is "testimonial" -- but that situation becomes murkier when biometrics are applied.

Apple appears to have anticipated this situation by allowing a user to press 2 buttons for 2 seconds to require a passcode, but Garvie said court battles over compelling the use of FaceID are likely.

Regardless of these concerns, Apple's introduction is likely to bring about widespread use of facial recognition technology.

"What Apple is doing here will popularize and get people more comfortable with the technology," said Patrick Moorhead, principal analyst at Moor Insights & Strategy, who follows the sector.

"If I look at Apple's track record of making things easy for consumers, I'm optimistic users are going to like this."

Garvie added it is important to have conversations about facial recognition because there is little regulation governing the use of the technology.

"The technology may well be inevitable," she said.

"It is going to become part of everyone's lives if it isn't already."

source: news.abs-cbn.com

Thursday, May 25, 2017

Facebook aims for broad views in 'trending topics' tweak


WASHINGTON - Facebook on Wednesday unveiled its latest redesign to its "trending topics" feature -- its latest move to give users a variety of sources on important news events.

The huge social network -- which has faced criticism for creating "filter bubbles" that reinforce the views of users, and has been accused of bias in selecting its news sources -- said the new design will offer a "carousel" with a variety of websites.

"You've always been able to click on a topic to see related posts and stories, but we've redesigned the page to make it easier to discover other publications that are covering the story, as well as what your friends and public figures are saying about it," Facebook said in a blog post.

"Now, when you click on a trending topic, you'll see a carousel with stories from other publications about a given topic that you can swipe through."

The blog signed by Facebook product manager Ali Ahmadi and designer John Angelo said the aim is to help people "feel more informed about the news in their region."

They added there would be "no predetermined list of publications" which appear in trending topics and that the update "does not affect how trending topics are identified," after a series of changes.

Earlier this year, Facebook revised its formula for trending news in an effort to weed out "fake news" by tweaking its algorithm to diminish the importance of how much a news story is shared.

Last year, Facebook moved to make its trending topics automated, scaling back human selection after critics complained curators were deliberately omitting stories from conservative news outlets.

Facebook made the changes last year despite arguing that its research discovered no systematic bias in story selection.

The social network, which has nearly two billion users worldwide, is an increasingly important source of news for its members.

Facebook has brushed aside the idea that misinformation spread over its network was a major factor in the 2016 US presidential election, but has stepped up efforts to weed out hoaxes and unverified news.

The new "trending" design is rolling out for iPhone users in the US, and will soon be available for Android and desktop, Facebook said.

source: news.abs-cbn.com

Sunday, April 3, 2016

FBI trick for breaking into iPhone likely to leak, limiting its use


SAN FRANCISCO - The FBI's method for breaking into a locked iPhone 5c is unlikely to stay secret for long, according to senior Apple Inc engineers and outside experts.

Once it is exposed, Apple should be able to plug the encryption hole, comforting iPhone users worried that losing physical possession of their devices will leave them vulnerable to hackers.

When Apple does fix the flaw, it is expected to announce it to customers and thereby extend the rare public battle over security holes, a debate that typically rages out of public view.

The Federal Bureau of Investigation last week dropped its courtroom quest to force Apple to hack into the iPhone of one of the San Bernardino shooters, saying an unidentified party provided a method for getting around the deceased killer's unknown passcode.

If the government pursues a similar case seeking Apple’s help in New York, the court could make the FBI disclose its new trick.

But even if the government walks away from that battle, the growing number of state and local authorities seeking the FBI’s help with locked phones in criminal probes increases the likelihood that the FBI will have to provide it. When that happens, defense attorneys will cross-examine the experts involved.

Although each lawyer would mainly be interested in whether evidence-tampering may have occurred, the process would likely reveal enough about the method for Apple to block it in future versions of its phones, an Apple employee said.

"The FBI would need to resign itself to the fact that such an exploit would only be viable for a few months, if released to other departments," said Jonathan Zdziarski, an independent forensics expert who has helped police get into many devices. "It would be a temporary Vegas jackpot that would quickly get squandered on the case backlog."

In a memo to police obtained by Reuters on Friday, the FBI said it would share the tool "consistent with our legal and policy constraints."

Even if the FBI hoards the information - despite a White House policy that tilts toward disclosure to manufacturers - if it is not revealed to Apple, there are other ways the method could come to light or be rendered ineffective over time, according to Zdziarski and senior Apple engineers who spoke on condition of anonymity.

The FBI may use the same method on phones in cases in which the suspects are still alive, presenting the same opportunity for defense lawyers to pry.

In addition, the contractor who sold the FBI the technique might sell it to another agency or country. The more widely it circulates, the more likely it will be leaked.

“Flaws of this nature have a pretty short life cycle,” one senior Apple engineer said. “Most of these things do come to light.”

The temporary nature of flaws is borne out in the pricing of tools for exploiting security holes in the government-dominated market for “zero-days,” called that because the companies whose products are targets have had zero days’ warning of the flaw.

Many of the attack programs that are sold to defense and intelligence contractors and then to government buyers are purchased over six months, with payments spaced apart in case the flaw is discovered or the hole is patched incidentally with an update from the manufacturer, market participants told Reuters.

Although Apple is concerned about consumer perception, employees said the company had made no major recent changes in policy. Instead, its engineers take pride in the fact that a program for breaking into an iPhone via the web was recently purchased by a defense contractor for $1 million, and that even that program is likely to be short-lived.

They said most iPhone users have more to fear from criminals than from countries, and few crooks can afford anything like what it costs to break into a fully up-to-date iPhone.

(Reporting by Joseph Menn; Editing by Dan Grebler)

source: www.abs-cbnnews.com

Saturday, February 20, 2016

Apple v FBI, is my iPhone safe?


NEW YORK — On Wednesday, a federal judge ordered Apple Inc. to help the FBI hack into an encrypted iPhone used by Syed Farook, who along with his wife, Tashfeen Malik, killed 14 people in December. Specifically, the government wants Apple to bypass a self-destruct feature that erases the phone's data after too many unsuccessful attempts to guess the passcode. Apple has helped the government before in this and previous cases, but this time Apple CEO Tim Cook said no and Apple is appealing the order.

What's the big deal? Why isn't Apple cooperating, and what does this mean for ordinary iPhone users? AP explains:

WHY ALL THE FUSS?

The clash brings to a head a long-simmering debate between technology companies whose business relies on protecting digital privacy (except, ahem, where advertising is concerned) and law enforcement agencies who say they need the ability to recover evidence or eavesdrop on the communications of terrorists or criminals to do their job. This is the first major case that requires the two sides to present their arguments in court, so it could ultimately affect millions of smartphone users.

IT'S JUST ONE IPHONE. AND THIS COULD HELP CATCH TERRORISTS. SO WHAT'S THE BIG DEAL?
While the judge on the case says the government is only asking for help unlocking one, single iPhone, Apple says the case is much bigger than that and sets a dangerous precedent. Cook says the company doesn't have a system to bypass the self-destruct one. And if it creates one, the technology it creates could eventually be used to work against other iPhones. Then everyone's iPhone would potentially be less secure. As Apple CEO Cook said, "Once created, the technique could be used over and over again, on any number of devices. In the physical world, it would be the equivalent of a master key, capable of opening hundreds of millions of locks — from restaurants and banks to stores and homes."


IS MY IPHONE STILL SECURE?

Yes. The technology being debated doesn't even exist yet. So what does this mean for your iPhone? In the short term, nothing. The case is likely to drag on for months — even years, if it works its way through appeals to the Supreme Court. But ultimately, the case could set the standard for just who has access to private data — the private message, photos and other data you store on your phone — and could cause millions of smartphones users to rethink what they store on their phones.

WILL MY DISGRUNTLED EX OR FORMER BOSS BE ABLE TO HACK INTO MY PHONE?

Not likely. Even if the technology is ultimately built and ruled legal, it would only be used by governments, or maybe cybercriminal masterminds. But probably not the average Joe next door — though you might want to watch out for his brilliant, disaffected hacker kid. (Also, all bets are off if you're talking about a phone provided by your employer, who already has the right to any information stored there.)

source: philstar.com

Tuesday, February 18, 2014

Local Apple store vows 'faster' repair for iPhones


MANILA -- Local authorized Apple service provider, Power Mac Center, has introduced a more efficient way for Filipinos to have their iPhones repaired, without having to wait several weeks or have the unit replaced entirely.

Starting this week, Power Mac Center is rolling out its iPhone Same Unit (SUR) program, which will allow iPhone users in the country to have their units repaired by trained Power Mac engineers. The program boasts a vastly improved 72-hour turnaround time.

“We at Power Mac Center are glad to be able to bring to Filipinos the convenience of having iPhone repair service made locally available,” said marketing director Joey Alvarez.

The iPhone SUR program covers iPhone 4, 4S, 5, 5S and 5C units purchased not only from any Power Mac Center location but also from other Apple authorized resellers.

It is also free for all units that are within the standard one-year Apple warranty.

Units that are no longer under warranty, however, will be considered as “billed service,” which will include diagnostic fees, price of parts and labor fees.

Before availing of the SUR program, all iPhone units will be subject to unauthorized modification check to be conducted by Power Mac Center’s mobile device engineers.

These mobile device engineers are mandated to pass the iOS Qualification Exam and adhere to the strictest standards set by Apple.

“Through the iPhone SUR, customers are assured that the replacement parts are genuine Apple parts. Both the parts and the service are of the highest quality to give iPhone users the best value for their money,” Alvarez said.

source: www.abs-cbnnews.com