Showing posts with label Apple. Show all posts
Showing posts with label Apple. Show all posts

Sunday, April 6, 2014

iOS 7 security flaw makes it impossible to recover your stolen iPhone

Owners of Apple’s iPhone have the dubious honor of possessing one of thieves’ most sought-after gadgets. In fact, the New York Police Department recently pointed out that thefts of Apple devices were largely responsible for the rise in crime last year. With that in mind, it’s easy to see why lost and stolen device recovery systems such as Apple’s Find My iPhone are hugely important, and we have read several stories about such mechanisms helping people recover their lost devices. But what happens when systems like Find My iPhone can be removed from a stolen iPhone in mere minutes?

A massive security flaw has been discovered in iOS 7 and iOS 7.1 that makes it impossible to recover stolen iPhones.

YouTube user Miguel Alvarado posted a video picked up by 9to5Mac that shows how the flaw works.

Basically, the thief merely has to tap on the toggle next to Find My iPhone and the Delete Account button in iCloud settings at the same time, and then power down the phone. When the phone is turned back on, the thief will be able to remove the iPhone’s associated iCloud account without having to enter a password.

The phone can then be plugged into iTunes, wiped clean and restored without issue.

An important note: The thief needs access to the device’s settings in order to exploit this flaw, so this is yet another reminder of just how important protecting your device with a PIN code, password or TouchID really is.

This isn’t the first time flaws that might prevent people from recovering stolen iPhones have been discovered. Late last year, for example, news spread of an Apple omission that could let thieves easily prevent Find My iPhone from operating unless the iPhone owner manually disabled a default Control Panel feature.

reblogged from BGR

Monday, March 10, 2014

iOS 7.1 now available for download; brings CarPlay support, Touch ID improvements, UI tweaks, and more

iOS 7.1, the first major update to Apple's revamped iOS 7, is now available as a free download over-the-air on iOS 7 devices, as well as via iTunes.

As expected, the update brings support for CarPlay, improvements for Touch ID performance in the iPhone 5s, and a bunch of other fixes and enhancements.

If you are using an iPhone 4 or later, iPod touch (5th generation) or later, iPad 2 or later, running iOS 5 or later, iOS 7.1 should be available as an over-the-air update for your device. Go to Settings > General > Software Update and iOS will automatically check for available updates. According to Apple, available updates download automatically if your device is connected to Wi-Fi and a power source. Tap Download to download the update and after the download has completed tap Install to update your iOS.

If you leave the update to download in the background, once the download has finished you will receive a notification saying an update is available for your device. Tapping Details will take you to Settings > General > Software Update. Tap Install Now to install the iOS update. If you decide to leave the installation for later Settings will display notification badge until the update has been installed.

Alternatively, you can install the update via iTunes by following the instructions at this page.

We strongly recommend you back up your iOS device to iCloud or with iTunes before installing any iOS updates.

Here's the change log of the iOS 7.1 update, as released by Apple.
CarPlay
  • iOS experience designed for the car
  • Simply connect your iPhone to a CarPlay enabled vehicle
  • Supports Phone, Music, Maps, Messages, and 3rd-party audio apps
  • Control with Siri and the car's touchscreen, knobs, and buttons
Siri
  • Manually control when Siri listens by holding down the home button while you speak and releasing it when you're done as an alternative to letting Siri automatically notice when you stop talking
  • New, more natural sounding male and female voices for Mandarin Chinese, UK English, Australian English, and Japanese
iTunes Radio
  • Search field above Featured Stations to easily create stations based on your favorite artist or song
  • Buy albums with the tap of a button from Now Playing
  • Subscribe to iTunes Match on your iPhone, iPad, or iPod touch to enjoy iTunes Radio ad-free
Calendar
  • Option to display events in month view
  • Country specific holidays automatically added for many countries
Accessibility
  • Bold font option now includes the keyboard, calculator, and many icon glyphs
  • Reduce Motion option now includes Weather, Messages, and multitasking UI animations
  • New options to display button shapes, darken app colors, and reduce white point
Other
  • New Camera setting to automatically enable HDR for iPhone 5s
  • iCloud Keychain support in additional countries
  • FaceTime call notifications are automatically cleared when you answer a call on another device
  • Fixes a bug that could occasionally cause a home screen crash
  • Improves Touch ID fingerprint recognition
  • Improved performance for iPhone 4
  • Fixes display of Mail unread badge for numbers greater than 10,000
  • Continued user interface refinements

reblogged: www.ndtv.com

Tuesday, February 25, 2014

Apple's Security Hole: Should You Start Worrying?

Main Entry Image

Apple's security hole is growing wider and wider.

The company divulged on Friday that it found a major vulnerability that would let a hacker intercept email and other secure communication sent from iPhones and iPads on Friday. Hours later, outside experts found the same flaw in the Safari browser on Mac computers.

By Sunday, security expert Ashkan Soltani tweeted that he found the "goto fail" vulnerability -- named after the single line of code responsible for the problem -- embedded in Calendar, Facetime, Keynote, Twitter, Mail and iBooks applications on Macs running the OS X operating system.

The security flaw worried many who said it would allow someone sharing a WiFi network with you -- say, at a coffee shop or an airport -- to see and change messages meant to be sent securely. According to Soltani, even Software Update, the application that installs security fixes on Macs, is vulnerable.

After Apple published a security patch for the iOS problem (just go to "Settings" on your iPhone or iPad and do a software update), the race to find the "goto fail" bug on other Apple products was on.
A few hours later on Friday, researchers at the security startup CrowdStrike replicated the hack on Mac computers running the operating system OS X, finding that supposedly secure messages sent from Safari (but not necessarily from Firefox or Chrome) were vulnerable to be being read and altered mid-flight. After Soltani's find, we know it's affecting many more applications, too.

"We are aware of this issue and already have a software fix that will be released very soon.” an Apple spokesperson told The Huffington Post.

Until then, keep your Mac away from your neighborhood coffee shop's WiFi.

via www.huffingtonpost.com