Tag Archive for: iPhone’s

iPhones and Macs get fix for extremely critical “triple handshake” crypto bug

ShellyS

Apple has patched versions of its iOS and OS X operating systems to fix yet another extremely critical cryptography vulnerability that leaves some users open to surreptitious eavesdropping. Readers are urged to install the updates immediately.

The flaw resides in the secure transport mechanism of iOS version 7.1 and earlier for iPhones and iPads and the Mountain Lion 10.8.5 and Mavericks 10.9.2 versions of Mac OS X, according to advisories here and here. The bug makes it possible to bypass HTTPS encryption protections that are designed to prevent eavesdropping and data tampering by attackers with the capability to monitor traffic sent by and received from vulnerable devices. Such “man-in-the-middle” attackers could exploit the bug by abusing the “triple handshake” carried out when secure connections are established by applications that use client certificates to authenticate end users.

“In a ‘triple handshake’ attack, it was possible for an attacker to establish two connections which had the same encryption keys and handshake, insert the attacker’s data in one connection, and renegotiate so that the connections may be forwarded to each other,” Apple’s warning explained. “To prevent attacks based on this scenario, Secure Transport was changed so that, by default, a renegotiation must present the same server certificate as was presented in the original connection.”

Read 4 remaining paragraphs | Comments


Ars Technica » Technology Lab

iBetterCharge Monitors Your iPhone’s Battery from Your Mac

Mac/Windows: If you keep you iPhone in your pocket all day long, it’s easy to lose track of how charged your battery is. iBetterCharge is a desktop app that keeps an eye on your iPhone’s battery level and alerts you when it gets low. iBetterCharge watches …
mac hacker – read more

iPhones may be vulnerable to hacker attack, Apple issues fix – USA TODAY


ZDNet

iPhones may be vulnerable to hacker attack, Apple issues fix
USA TODAY
Security certificates are a basic component of computer security. They are attachments to electronic messages that verify the user sending a message is who he or she says he is. They contain information about the certificate owner, including an
What you REALLY need to know about that Apple security flawKATU

all 384 news articles »

“computer security” – read more

New York Police helping advertise Apple’s new iPhones – Fox News


ABC News

New York Police helping advertise Apple's new iPhones
Fox News
or has been stolen, you can quickly and securely erase all of the data on your device to keep your data from ending up in the wrong hands,” wrote Adrian Ludwig, an Android security engineer with Google, when he announced the feature in early August.
NYPD Promoted Apple Inc. (NASDAQ:AAPL)'s “Find My iPhone” Feature eFinance Hub
Embarrassment for Apple Inc as newest iPhone 5S gets hacked, fingerprint Financial Express
How to remove iOS 7 and install iOS 6Computer News Middle East

all 1,652 news articles »

“android security” – read more