Tag Archive for: reminder

Reminder: macOS still leaks secrets stored on encrypted drives

Enlarge (credit: Wardle and Regula)

Unbeknownst to many people, a macOS feature that caches thumbnail images of files can leak highly sensitive data stored on password-protected drives and encrypted volumes, security experts said Monday.

The automatically generated caches can be viewed only by someone who has physical access to a Mac or infects the Mac with malware, and the behavior has existed on Macs for almost a decade. Still, the caching is triggered with minimal user interaction and causes there to be a permanent record of files even after the original file is deleted or the USB drive or encrypted volume that stored the data is disconnected from the Mac. Patrick Wardle and Wojciech Reguła, who are macOS security experts at Digita Security and SecuRing, respectively, said for many people, it’s unnecessarily risky to store snapshots of files related to passwords or other sensitive matters in an unprotected folder. In a blog post published Monday, they wrote:

For a forensics investigation or surveillance implant, this information could prove invaluable. Imagine having a historic record of the USB devices, files on the devices, and even thumbnails of the files…all stored persistently in an unencrypted database, long after the USB devices have been removed (and perhaps destroyed).

For users, the question is: “Do you really want your Mac recording the file paths and ‘previews’ thumbnails of the files on any/all USB sticks that you’ve ever inserted into your Mac?” Me thinks not…

As the researchers note, the caching may cause there to be a permanent record of every drive that connects to a Mac. It also creates a thumbnail image that can leak key details about many of the images stored on the drives, as well as password-protected folders or encrypted volumes. The thumbnails will live on in an SQLite database stored indefinitely in the macOS file system.

Read 3 remaining paragraphs | Comments

Biz & IT – Ars Technica

Meltdown, Spectre, and mobile: A reminder that Android security patches exist

  1. Meltdown, Spectre, and mobile: A reminder that Android security patches exist  Brian Madden
  2. Meltdown Hack and Spectre Bug: How it affects Android & Chrome Users  Android Central
  3. Apple, Android and PC chip problem – why your smartphone and laptop are so at risk  The Independent
  4. Full coverage

android security news – read more

Great Reminder That You Need A Malware Scanner On Your Android Phone – Gizmodo Australia


Gizmodo Australia

Great Reminder That You Need A Malware Scanner On Your Android Phone
Gizmodo Australia
The advisory does list which forms of malware were found on which devices. Most of the devices contained info-stealers and adware. But one phone contained ransomware, which in the right hands and targeting the right company could be a very big deal.
Preinstalled Malware Targeting Mobile Users | Check Point BlogCheck Point Blog

all 12 news articles »

android ransomware – read more

Great Reminder That You Need a Malware Scanner On Your Android Phone – Gizmodo

Great Reminder That You Need a Malware Scanner On Your Android Phone
Gizmodo
Cyber Security firm Check Point has found malware on 38 Android devices from two separate corporate clients. That wouldn't be a huge surprise but what they found worthy of note was that the malware was preinstalled “somewhere along the supply chain,” …

and more »

android security – read more