IOS

Pirated App Store Client For iOS Found On Apple's App Store (helpnetsecurity.com) 55

An anonymous reader writes: An app called "Happy Daily English", which has been offered for download via Apple's official App Store, has been revealed to be a fully functional third party App Store client for iOS, offering users in mainland China a way to install modified versions of iOS apps on non-jailbroken devices. Its discovery shows that there are new techniques that can be used to fool Apple reviewers into allowing potentially malicious apps into the App Store, that enterprise certificates can be easily abused, and that there are ways for bypassing Apple's prohibition of apps dynamically loading new code.
Encryption

Why Are Apple's Competitors Staying Silent On the iPhone Unlocking Fight? 301

erier2003 writes: A court order forcing Apple to help the FBI access a terrorism suspect's iPhone has drawn responses from leading tech companies, newspaper editorial boards, and security experts. But one major faction is staying largely silent: the computer and smartphone manufacturers who compete with Apple for business and could be subject to similar orders in the future if the company loses its high-profile case. Silicon Valley software firms have universally backed Apple in its fight against the Justice Department, which won a ruling Tuesday from a California magistrate judge compelling Apple to design custom software to bypass security features on an iPhone used by one of the San Bernardino shooters. But Apple's hardware competitors are staying on the sidelines.
Encryption

Apple: Terrorist's Apple ID Password Changed In Government Custody (buzzfeed.com) 435

An anonymous reader writes: The Apple ID password linked to the iPhone belonging to one of the San Bernardino terrorists was changed less than 24 hours after the government took possession of the device, senior Apple executives said Friday. If that hadn't happened, Apple said, a backup of the information the government was seeking may have been accessible.

Had that password not been changed, the executives said, the government would not need to demand the company create a 'backdoor' to access the iPhone used by Syed Rizwan Farook, who died in a shootout with law enforcement after a terror attack in California that killed 14 people. The Department of Justice filed a motion to compel the company to do that earlier Friday.

Encryption

DoJ Says Apple's Posture on iPhone Unlocking Is Just Marketing (reuters.com) 339

New submitter kruug writes: The U.S. Department of Justice filed a motion seeking to compel Apple Inc to comply with a judge's order for the company to unlock the iPhone belonging to one of the San Bernardino shooters, portraying the tech giant's refusal as a 'marketing strategy.' The filing escalated a showdown between the Obama administration and Silicon Valley over security and privacy that ignited earlier this week. The Federal Bureau of Investigation is seeking the tech giant's help to access the shooter's phone, which is encrypted. The company so far has pushed back, and on Thursday won three extra days to respond to the order. Reader Lauren Weinstein writes of this tack: "The level of DOJ disingenuousness in play is simply staggering."
Crime

3-in-1 Android Malware Acts As Ransomware, Banking Trojan and Info Thief 25

An anonymous reader writes: Why stop at asking ransom for encrypted files when you can also steal personal info, passwords, online banking credentials and credit card details, and sell it or use it to get even more money? Palo Alto researchers have recently analyzed Xbot, a Trojan that is capable of doing all the aforementioned things, and have found it mimicking 22 different Android apps.
Advertising

Mobile Giant Three Group To Block Online Advertising (thestack.com) 94

An anonymous reader writes: Global mobile provider Three has announced that it will shortly begin to block online advertising on all of its six European networks, beginning with the UK and Italy. The company, which also has networks in Hong Kong and Indonesia, will announce its partnership with Israeli network ad-blocking startup Shine at Mobile World Congress in Barcelona, according to sources. Shine's first network ad-block customer was Caribbean provider Digicel last year, but the new Three Group deal seems set to cause massive disruption to web-based publishers — who, it seems, may have to pay for bandwidth and show more respect for user privacy in their ads if they want to continue to operate in the mobile space.
Communications

Good Riddance Payphones: NYC's Free Gigabit Wi-Fi Kiosks Go Live (networkworld.com) 84

alphadogg writes: New York City on Thursday officially launched its payphone booth replacements: shiny new 9-foot-plus-high kiosks, dubbed Links, that offer free Gigabit-speed Wi-Fi as well as free domestic VoIP calls via a tablet app. Mayor Bill de Blasio, joined by vendor partners such as Qualcomm and NYC Department of IT and Telecommunications reps, showed off the first operating LinkNYC kiosks, just over a dozen of which are spread across 3rd Avenue for starters. The spacing of the hotspots will enable users to stay connected as they walk down the street. More than 500 of the advertising-supported kiosks are slated to be installed by mid-year, with promises of secure and private connectivity.
Networking

Bad Karma: WISP Pares Back Its Monthly 4G Hotspot Plan, Again 59

Robotech_Master writes: The ongoing saga of the Neverstop plan shows that Karma Wireless just can't seem to catch a break as far as high-bandwidth plans are concerned. After starting out with a straight pay-per-bandwidth plan, "Refuel," for its $150 wireless hotspot, Karma thought it would innovate with a throttled-but-otherwise-unlimited 4G plan, "Neverstop." However, it soon discovered that users were taking it at its word and using up considerably more bandwidth than Karma expected or could afford. After experimenting with further throttling, Karma subsequently revamped the plan into a $50 per month, 15 GB plan that throttled to dialup speed after it ran out. However, now it turns out even that plan was too optimistic, and Karma has opted to dump the Neverstop plan altogether in favor of tiered monthly plan called Pulse —whose bandwidth costs significantly more. ($40/mo for 5 GB, $75 for 10 GB, $140 for 20 GB.) Karma's "unlimited" users weren't pleased the first time the plan changed, and now they're practically through the roof.
Bug

Apple Says Sorry For iPhone Error 53 and Issues IOS 9.2.1 Update To Fix It (betanews.com) 123

Mark Wilson writes: Apple has a lot of support at the moment for its stance on encryption and refusing the FBI access to an iPhone's contents, but it's only a couple of weeks since the company was seen in a less favorable light. There was quite a backlash when users found that installing an update to iOS resulted in Error 53 and a bricked iPhone. Apple initially said that Error 53 was caused 'for security reasons' following speculation that it was a bid to stop people from using third party repair shops. iFixit suggested that the problem was a result of a failure of parts to correctly sync, and Apple has been rounding criticized for failing to come up with a fix. Today the company has issued an apology, along with an update that ensures Error 53 won't happen again. But there's more good news ... If you were talked into paying for an out of warranty replacement as a result of Error 53, you could be in line to get your money back.
Encryption

John McAfee Offers To Decrypt San Bernardino iPhone For the FBI and Save America (hothardware.com) 364

MojoKid writes: Wondering what John McAfee is up to these days? It's not sniffing bath salts nor is he fleeing foreign countries as a person of interest in a murder investigation and faking heart attacks (been there, done all that) ; instead, he's on a mission to save America. How so? By cracking the code on the San Bernardino iPhone that's causing such a ruckus. McAfee didn't just criticize the FBI; instead he offered a potential solution. Let him and his team of hackers break into the iPhone without any help from Apple. "With all due respect to Tim Cook and Apple, I work with a team of the best hackers on the planet. These hackers attend Defcon in Las Vegas, and they are legends in their local hacking groups, such as HackMiami. They are all prodigies, with talents that defy normal human comprehension," McAfee said. Eccentric rant aside, McAfee's offer is simple - give him three weeks and he will, "free of charge, decrypt the information on the San Bernardino phone" with his team of hackers. He'll do it using mostly social engineering.
Android

Apple Announces New Trade Up With Installments Program (betanews.com) 107

Mark Wilson writes: Today, Apple launched a new program called Trade Up With Installments, which makes it possible to upgrade to the latest iPhone in a more affordable way. As the name suggests, this is more than a straight trade-in program - upgraders can use the trade-in value of their old handset to reduce on-going monthly costs. This is something that will appeal not only to people with older iPhones who are looking to get their hands on a newer model, but also ex-Android fans. Apple is opening up the program, so Android handsets can be traded in and their value offset against the cost of a new iPhone. Windows Phone handsets are also eligible. Trade Up With Installments is slightly different to the existing iPhone Upgrade Program and trade-in option. After handing over your old handset (be it iOS, Windows Phone or Android powered) for part exchange for a new iPhone, you'll then (assuming you qualify) be extended credit and allowed to pay off the remaining balance over 24 months.
Encryption

Stealing Keys From a Laptop In Another Room — and Offline 58

Motherboard carries a report that with equipment valued at about $3,000, a group of Israeli researchers have been able to extract cryptographic keys from a laptop that is not only separated by a physical wall, but protected by an air gap. This, they say, "is the first time such an approach has been used specifically against elliptic curve cryptography running on a PC." From the article: The method is a so-called side-channel attack: an attack that doesn't tackle an encryption implementation head on, such as through brute force or by exploiting a weakness in the underlying algorithm, but through some other means. In this case, the attack relies on the electromagnetic outputs of the laptop that are emitted during the decryption process, which can then be used to work out the target's key. Specifically, the researchers obtained the private key from a laptop running GnuPG, a popular implementation of OpenPGP. (The developers of GnuPG have since released countermeasures to the method. Tromer said that the changes make GnuPG âoemore resistant to side-channel attack since the sequence of high-level arithmetic operations does not depend on the secret key.â)
Government

TP-Link Begins Lockdown of Firmware In Response To FCC 157

An anonymous reader writes: In response to an FCC rule that requires manufacturers to lock down computing devices (routers, PCs, phones) to prevent modification if they have a "modular wireless radio," TP-Link has begun locking down its routers to prevent firmware not signed by TP-Link from being installed. This essentially prevents open source OSs (OpenWRT, for example) from being used on routers. TP-Link may not be a prestige brand, exactly, but the company makes a lot of routers suitable for installing third-party firmware, precisely the sort of thing being locked down makes difficult if not impossible.
Google

New Google Data Shows Dangers of Third-Party App Stores (onthewire.io) 67

Trailrunner7 writes: Google's position in the Internet world is a unique one. In one or another, the company controls or sees much of the traffic on the network and owns one of the larger computing arsenals on the planet. It's also in control of a decent chunk of the mobile world, thanks to Android's popularity, and securing that ecosystem is a tremendous challenge in both complexity and scope. Google scans more than 2 million apps every week for its 1.4 billion Android users. And it collects a lot of data from its users, of course. Some new data from the company shows that using only the Play store is much safer than using third-party app stores. The data Google has collected shows that users who install apps only from the Play store have far fewer potentially harmful apps installed on their devices than users who also sideload apps.
Encryption

Edward Snowden Calls For Google To Side With Apple On Encryption Debate (techinsider.io) 259

An anonymous reader writes: Edward Snowden, the most famous whistle blower in the world, is calling for Google to side with Apple and against the FBI in the "most important tech case in a decade." On Tuesday, the FBI asked Apple to help it crack the password on an iPhone belonging to a shooter in the high profile San Bernardino case. Apple CEO Tim Cook quickly responded with a public letter denying the request, calling it "an unprecedented step which threatens the security of our customers." Google creates Android, the most-used mobile operating system for smartphones in the world. Google has been nowhere near as firm as Apple about its stance on un-compromised encryption - Android is famously an open sourced platform that anyone can modify. Snowden issued his message in a tweet.
Businesses

Uber Losing $1 Billion a Year In China (thestack.com) 105

An anonymous reader writes: Uber CEO Travis Kalanick has revealed that the ride-sharing company is writing off $1 billion a year in order to consolidate its place in the Chinese ride-sharing app market. Kalanick said in a speech at the Vancouver Launch Academy that Uber is deeply engaged in a fight for customers in the Chinese market, and that an unnamed competitor is "buying up market share." Uber's main rival in China is Didi Kuaidi, which invested $100 million in Lyft and Ola to last year in a consolidation effort against Uber's incursion into the market — which many believe to have occurred too late into the development of ride-share schemes in China.
Android

Ringing Bells' India-Only Android Phone To Run About $4 (freedom251.com) 72

An anonymous reader writes: Freedom 251 is the name of a new affordable Android smartphone which is going on sale in India. It features an 4-core 1.3 Ghz Processor, with 1GB RAM and 8GB internal memory, and runs an Android Lollipop 5.1 distribution complete with civilian and government applications for Indian citizens. It is being heavily subsidized to make up for the benefits that it will bring to the people who could never afford a smartphone before. Ars Technica notes that the phone is apparently not carrier-subsidized, but as Pocket Now points out, "[t]he nation's defence minister will be at the launch event, a sign that the government has heavily subsidized the project in line with its developmental prerogatives."
Encryption

Judge Tells Apple To Help FBI Access San Bernardino Shooters' iPhone (engadget.com) 610

An anonymous reader writes: After a couple shot 14 people in San Bernardino, CA before being killed themselves on December 2nd, the authorities recovered a locked iPhone. Since then, the FBI has complained it is unable to break the device's encryption, in a case that it has implied supports its desire for tech companies to make sure it can always have a way in. Today the Associated Press reports that a US magistrate judge has directed Apple to help the FBI find a way in. According to NBC News, the model in question is an iPhone 5c, but Apple has said that at least as of iOS 8 it does not have a way to bypass the passcode on a locked phone.
Power

IETF's Tips For Network Admins On How To Avoid Draining Smartphone Batteries (softpedia.com) 65

An anonymous reader writes: Two engineers from Cisco and Google have raised the problem of IPv6 networks that drain smartphone battery life and issued a series of tips for other network admins on why and how to properly configure their networks. The problem is because of Router Advertisements (RAs). These are periodic messages sent by the router to all network clients telling them its IPv6 address, at which it can be reached. Apparently some networks are sending these as often as every 3 seconds, while the engineers say the proper interval should be 7 per hour. Hence the reason why your battery life is often drained even if your phone is in sleep mode, but connected to a local network.
Cellphones

Apple vs. the Right To Repair (bloombergview.com) 381

retroworks writes: Bloomberg columnist Adam Minter takes on Apple's "Error 53 Code" and the precedents being challenged by the Right To Repair movement. Apple claims that bricking the phone if it's repaired by a non-Apple certified repair shop protects you from tampering with, say, the fingerprint scanner. But the column documents how the number of "certified" repair shops is under attack. If you can't open it, do you really own it?

Slashdot Top Deals