All iSpy conspiracy bullshit aside, you are probably more interested in what your iPhone does with location data. Well, if you opt-in to the iPhone's location services, detailed—but anonymized—location data is transmitted back to Apple on a regular basis.
Gadget Lab reminds us of a letter Apple general counsel Bruce Sewell sent to a couple of Congressman last year explaining how and why Apple collects location data. (Wired's hosting the letter here.) Basically, if you've got Location Services turned on, whenever you request current location data (like via an app), Apple collects info about nearby cell towers and Wi-Fi hotspots. If you happen to be using GPS, it'll collect the GPS coordinates too. That data's then transmitted to Apple every 12 hours over "secure" Wi-Fi networks, anonymized with a "random identification number generated every 24 hours by an iOS device," so neither Apple nor anybody can personally identify you.
If you remember, Apple started doing its own location services last year (from iOS 3.2 onward), instead of using Google or Skyhook's location data. So, it needs to build and maintain its own database of known tower locations and Wi-Fi hotspots—that's where this info comes in. You're an official location scout for Apple, in other words. When your device asks where it's at, it hits up this database before zeroing in with GPS.
Not too crazy, though it doesn't make the ease with which your location history can be extracted from your Mac or iPhone any less unnerving. Also, it makes the lack of a purge after the data's transmitted to Apple seem more and more like a mere oversight.
More on this is at Gadget Lab: [Gadget Lab] via [Gizmodo]
Showing posts with label Apple. Show all posts
Showing posts with label Apple. Show all posts
Thursday, 28 April 2011
Thursday, 24 March 2011
Adobe, Apple Release Urgent Security Updates
It was Patch Tuesday for the second time this month — except this week it’s Adobe and Apple, not Microsoft, products that have urgent security updates.
Adobe yesterday released updates for its Acrobat and Reader applications and Flash Player browser plug-in to patch a dangerous vulnerability reported last week.
Bad guys had already been using the hole to attack PC users via Excel files infected with bad Flash objects.
The vulnerability affects all major PC operating systems (Windows, Mac and Linux), plus a minor one (Oracle’s Solaris) and Android OS smartphones, as well as all browsers.
Google’s Chrome got a jump on the Flash Player patch a few days earlier, thanks to a tight relationship with Adobe. Users running Chrome will still have to patch other browsers and the stand-alone Reader and Acrobat applications.
As has been the case for years, Internet Explorer requires a separate Flash Player plug-in from the other browsers.
Apple iOS devices will not need a patch; Steve Jobs’ ban on Flash for the iPhone and iPad seems to extend to Acrobat and Reader as well. (iOS reads PDF files natively.)
All patches are available from Adobe’s website here.
Slightly less urgent, but no less comprehensive, is Apple’s latest and possibly final major update to its Snow Leopard version of OS X.
This one bumps the version number up to 10.6.7 and patches 40 vulnerabilities in Apple and open-source apps and services, many related to the handling of image files.
Sophos’s Naked Security blog notes that the update also boosts Apple’s Safari browser to 5.0.4, which patches another 60 or so security holes.
Similar security upgrades are also available for OS X 10.5 Leopard, the last version of OS X to run on PowerPC-based Macs.
Apple’s OS X 10.7 Lion is scheduled to come out this summer.
Apple’s Software Update should automatically download the updates and prompt users to install them. If not, the updates can be found here.
[SecurityNewsDaily]
Adobe yesterday released updates for its Acrobat and Reader applications and Flash Player browser plug-in to patch a dangerous vulnerability reported last week.
Bad guys had already been using the hole to attack PC users via Excel files infected with bad Flash objects.
The vulnerability affects all major PC operating systems (Windows, Mac and Linux), plus a minor one (Oracle’s Solaris) and Android OS smartphones, as well as all browsers.
Google’s Chrome got a jump on the Flash Player patch a few days earlier, thanks to a tight relationship with Adobe. Users running Chrome will still have to patch other browsers and the stand-alone Reader and Acrobat applications.
As has been the case for years, Internet Explorer requires a separate Flash Player plug-in from the other browsers.
Apple iOS devices will not need a patch; Steve Jobs’ ban on Flash for the iPhone and iPad seems to extend to Acrobat and Reader as well. (iOS reads PDF files natively.)
All patches are available from Adobe’s website here.
Slightly less urgent, but no less comprehensive, is Apple’s latest and possibly final major update to its Snow Leopard version of OS X.
This one bumps the version number up to 10.6.7 and patches 40 vulnerabilities in Apple and open-source apps and services, many related to the handling of image files.
Sophos’s Naked Security blog notes that the update also boosts Apple’s Safari browser to 5.0.4, which patches another 60 or so security holes.
Similar security upgrades are also available for OS X 10.5 Leopard, the last version of OS X to run on PowerPC-based Macs.
Apple’s OS X 10.7 Lion is scheduled to come out this summer.
Apple’s Software Update should automatically download the updates and prompt users to install them. If not, the updates can be found here.
[SecurityNewsDaily]
Wednesday, 23 March 2011
Mac OS X 10.6.7 fixes security vulnerabilities
Apple today released Mac OS X 10.6.7 which increases the stability, compatibility, and security of your Mac.

AirPort
A divide by zero issue existed in the handling of Wi-Fi frames. When connected to Wi-Fi, an attacker on the same network may be able to cause a system reset. This issue does not affect systems prior to Mac OS X v10.6.
Apache
Apache is updated to version 2.2.17 to address several vulnerabilities, the most serious of which may lead to a denial of service.
AppleScript
A format string issue existed in AppleScript Studio's generic dialog commands ("display dialog" and "display alert"). Running an AppleScript Studio-based application that allows untrusted input to be passed to a dialog may lead to an unexpected application termination or arbitrary code execution.
ATS
A heap buffer overflow issue existed in the handling of OpenType, TrueType and Type 1 fonts. Viewing or downloading a document containing a maliciously crafted embedded font may lead to arbitrary code execution.
Multiple buffer overflow issues existed in the handling of SFNT tables. Viewing or downloading a document containing a maliciously crafted embedded font may lead to arbitrary code execution.
bzip2
An integer overflow issue existed in bzip2's handling of bzip2 compressed files. Using the command line bzip2 or bunzip2 tool to decompress a bzip2 file may result in an unexpected application termination or arbitrary code execution.
CarbonCore
When used with the kTemporaryFolderType flag, the FSFindFolder() API returns a directory that is world readable. This issue is addressed by returning a directory that is only readable by the user that the process is running as.
ClamAV
Multiple vulnerabilities exist in ClamAV, the most serious of which may lead to arbitrary code execution. This update addresses the issues by updating ClamAV to version 0.96.5. ClamAV is distributed only with Mac OS X Server systems.
CoreText
A memory corruption issue existed in CoreText's handling of font files. Viewing or downloading a document containing a maliciously crafted embedded font may lead to arbitrary code execution.
File Quarantine
The OSX.OpinionSpy definition has been added to the malware check within File Quarantine.
HFS
An integer overflow issue existed in the handling of the F_READBOOTSTRAP ioctl. A local user may be able to read arbitrary files from an HFS, HFS+, or HFS+J filesystem.
ImageIO
A heap buffer overflow issue existed in ImageIO's handling of JPEG and XBM images. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.
A buffer overflow existed in libTIFF's handling of JPEG encoded TIFF images and CCITT Group 4 encoded TIFF images. Viewing a maliciously crafted TIFF image may result in an unexpected application termination or arbitrary code execution.
An integer overflow issue existed in ImageIO's handling of JPEG-encoded TIFF images. Viewing a maliciously crafted TIFF image may result in an unexpected application termination or arbitrary code execution. This issue does not affect systems prior to Mac OS X v10.6.
Image RAW
Multiple buffer overflow issues existed in Image RAW's handling of Canon RAW images. Viewing a maliciously crafted Canon RAW image may result in an unexpected application termination or arbitrary code execution.
Installer
A URL processing issue in Install Helper may lead to the installation of an agent that contacts an arbitrary server when the user logs in. The dialog resulting from a connection failure may lead the user to believe that the connection was attempted with Apple. This issue is addressed by removing Install Helper.
Kerberos
Multiple cryptographic issues existed in MIT Kerberos 5. Only CVE-2010-1323 affects Mac OS X v10.5.
Kernel
A privilege checking issue existed in the i386_set_ldt system call's handling of call gates. A local user may be able to execute arbitrary code with system privileges. This issue is addressed by disallowing creation of call gate entries via i386_set_ldt().
Libinfo
An integer truncation issue existed in Libinfo's handling of NFS RPC packets. A remote attacker may be able to cause NFS RPC services such as lockd, statd, mountd, and portmap to become unresponsive.
libxml
A memory corruption issue existed in libxml's XPath handling. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.
A double free issue existed in libxml's handling of XPath expressions. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This issue does not affect systems prior to Mac OS X v10.6.
Mailman
Multiple cross-site scripting issues existed in Mailman 2.1.13. These issues are addressed by updating Mailman to version 2.1.14.
PHP
PHP is updated to version 5.3.4 to address multiple vulnerabilities, the most serious of which may lead to arbitrary code execution.
PHP is updated to version 5.2.15 to address multiple vulnerabilities, the most serious of which may lead to arbitary code execution.
QuickLook
A memory corruption issue existed in QuickLook's handling of Excel files. Downloading a maliciously crafted Excel file may lead to an unexpected application termination or arbitrary code execution. This issue does not affect systems prior to Mac OS X v10.6.
A memory corruption issue existed in QuickLook's handling of Microsoft Office files. Downloading a maliciously crafted Microsoft Office file may lead to an unexpected application termination or arbitrary code execution.
QuickTime
Multiple memory corruption issues existed in QuickTime's handling of JPEG2000 images. Viewing a maliciously crafted JPEG2000 image with QuickTime may lead to an unexpected application termination or arbitrary code execution.
An integer overflow existed in QuickTime's handling of movie files. Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution. For Mac OS X v10.5 this issue was addressed in QuickTime 7.6.9.
A memory corruption issue existed in QuickTime's handling of FlashPix images. Viewing a maliciously crafted FlashPix image may lead to an unexpected application termination or arbitrary code execution. For Mac OS X v10.5 this issue was addressed in QuickTime 7.6.9.
A cross-origin issue existed in QuickTime plug-in's handling of cross-site redirects. Visiting a maliciously crafted website may lead to the disclosure of video data from another site. This issue is addressed by preventing QuickTime from following cross-site redirects.
A memory corruption issue existed in QuickTime's handling of panorama atoms in QTVR (QuickTime Virtual Reality) movie files. Viewing a maliciously crafted QTVR movie file may lead to an unexpected application termination or arbitrary code execution. For Mac OS X v10.5 this issue was addressed in QuickTime 7.6.9.
Ruby
An integer truncation issue existed in Ruby's BigDecimal class. Running a Ruby script that uses untrusted input to create a BigDecimal object may lead to an unexpected application termination or arbitrary code execution. This issue only affects 64-bit Ruby processes.
Samba
A stack buffer overflow existed in Samba's handling of Windows Security IDs. If SMB file sharing is enabled, a remote attacker may cause a denial of service or arbitrary code execution.
Subversion
Subversion servers that use the non-default "SVNPathAuthz short_circuit" mod_dav_svn configuration setting may allow unauthorized users to access portions of the repository. This issue is addressed by updating Subversion to version 1.6.13. This issue does not affect systems prior to Mac OS X v10.6.
Terminal
When ssh is used in Terminal's "New Remote Connection" dialog, SSH version 1 is selected as the default protocol version. This issue is addressed by changing the default protocol version to "Automatic". This issue does not affect systems prior to Mac OS X v10.6.
X11
Multiple vulnerabilities existed in FreeType, the most serious of which may lead to arbitrary code execution when processing a maliciously crafted font. These issues are addressed by updating FreeType to version 2.4.3.
AirPort
A divide by zero issue existed in the handling of Wi-Fi frames. When connected to Wi-Fi, an attacker on the same network may be able to cause a system reset. This issue does not affect systems prior to Mac OS X v10.6.
Apache
Apache is updated to version 2.2.17 to address several vulnerabilities, the most serious of which may lead to a denial of service.
AppleScript
A format string issue existed in AppleScript Studio's generic dialog commands ("display dialog" and "display alert"). Running an AppleScript Studio-based application that allows untrusted input to be passed to a dialog may lead to an unexpected application termination or arbitrary code execution.
ATS
A heap buffer overflow issue existed in the handling of OpenType, TrueType and Type 1 fonts. Viewing or downloading a document containing a maliciously crafted embedded font may lead to arbitrary code execution.
Multiple buffer overflow issues existed in the handling of SFNT tables. Viewing or downloading a document containing a maliciously crafted embedded font may lead to arbitrary code execution.
bzip2
An integer overflow issue existed in bzip2's handling of bzip2 compressed files. Using the command line bzip2 or bunzip2 tool to decompress a bzip2 file may result in an unexpected application termination or arbitrary code execution.
CarbonCore
When used with the kTemporaryFolderType flag, the FSFindFolder() API returns a directory that is world readable. This issue is addressed by returning a directory that is only readable by the user that the process is running as.
ClamAV
Multiple vulnerabilities exist in ClamAV, the most serious of which may lead to arbitrary code execution. This update addresses the issues by updating ClamAV to version 0.96.5. ClamAV is distributed only with Mac OS X Server systems.
CoreText
A memory corruption issue existed in CoreText's handling of font files. Viewing or downloading a document containing a maliciously crafted embedded font may lead to arbitrary code execution.
File Quarantine
The OSX.OpinionSpy definition has been added to the malware check within File Quarantine.
HFS
An integer overflow issue existed in the handling of the F_READBOOTSTRAP ioctl. A local user may be able to read arbitrary files from an HFS, HFS+, or HFS+J filesystem.
ImageIO
A heap buffer overflow issue existed in ImageIO's handling of JPEG and XBM images. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.
A buffer overflow existed in libTIFF's handling of JPEG encoded TIFF images and CCITT Group 4 encoded TIFF images. Viewing a maliciously crafted TIFF image may result in an unexpected application termination or arbitrary code execution.
An integer overflow issue existed in ImageIO's handling of JPEG-encoded TIFF images. Viewing a maliciously crafted TIFF image may result in an unexpected application termination or arbitrary code execution. This issue does not affect systems prior to Mac OS X v10.6.
Image RAW
Multiple buffer overflow issues existed in Image RAW's handling of Canon RAW images. Viewing a maliciously crafted Canon RAW image may result in an unexpected application termination or arbitrary code execution.
Installer
A URL processing issue in Install Helper may lead to the installation of an agent that contacts an arbitrary server when the user logs in. The dialog resulting from a connection failure may lead the user to believe that the connection was attempted with Apple. This issue is addressed by removing Install Helper.
Kerberos
Multiple cryptographic issues existed in MIT Kerberos 5. Only CVE-2010-1323 affects Mac OS X v10.5.
Kernel
A privilege checking issue existed in the i386_set_ldt system call's handling of call gates. A local user may be able to execute arbitrary code with system privileges. This issue is addressed by disallowing creation of call gate entries via i386_set_ldt().
Libinfo
An integer truncation issue existed in Libinfo's handling of NFS RPC packets. A remote attacker may be able to cause NFS RPC services such as lockd, statd, mountd, and portmap to become unresponsive.
libxml
A memory corruption issue existed in libxml's XPath handling. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution.
A double free issue existed in libxml's handling of XPath expressions. Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution. This issue does not affect systems prior to Mac OS X v10.6.
Mailman
Multiple cross-site scripting issues existed in Mailman 2.1.13. These issues are addressed by updating Mailman to version 2.1.14.
PHP
PHP is updated to version 5.3.4 to address multiple vulnerabilities, the most serious of which may lead to arbitrary code execution.
PHP is updated to version 5.2.15 to address multiple vulnerabilities, the most serious of which may lead to arbitary code execution.
QuickLook
A memory corruption issue existed in QuickLook's handling of Excel files. Downloading a maliciously crafted Excel file may lead to an unexpected application termination or arbitrary code execution. This issue does not affect systems prior to Mac OS X v10.6.
A memory corruption issue existed in QuickLook's handling of Microsoft Office files. Downloading a maliciously crafted Microsoft Office file may lead to an unexpected application termination or arbitrary code execution.
QuickTime
Multiple memory corruption issues existed in QuickTime's handling of JPEG2000 images. Viewing a maliciously crafted JPEG2000 image with QuickTime may lead to an unexpected application termination or arbitrary code execution.
An integer overflow existed in QuickTime's handling of movie files. Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution. For Mac OS X v10.5 this issue was addressed in QuickTime 7.6.9.
A memory corruption issue existed in QuickTime's handling of FlashPix images. Viewing a maliciously crafted FlashPix image may lead to an unexpected application termination or arbitrary code execution. For Mac OS X v10.5 this issue was addressed in QuickTime 7.6.9.
A cross-origin issue existed in QuickTime plug-in's handling of cross-site redirects. Visiting a maliciously crafted website may lead to the disclosure of video data from another site. This issue is addressed by preventing QuickTime from following cross-site redirects.
A memory corruption issue existed in QuickTime's handling of panorama atoms in QTVR (QuickTime Virtual Reality) movie files. Viewing a maliciously crafted QTVR movie file may lead to an unexpected application termination or arbitrary code execution. For Mac OS X v10.5 this issue was addressed in QuickTime 7.6.9.
Ruby
An integer truncation issue existed in Ruby's BigDecimal class. Running a Ruby script that uses untrusted input to create a BigDecimal object may lead to an unexpected application termination or arbitrary code execution. This issue only affects 64-bit Ruby processes.
Samba
A stack buffer overflow existed in Samba's handling of Windows Security IDs. If SMB file sharing is enabled, a remote attacker may cause a denial of service or arbitrary code execution.
Subversion
Subversion servers that use the non-default "SVNPathAuthz short_circuit" mod_dav_svn configuration setting may allow unauthorized users to access portions of the repository. This issue is addressed by updating Subversion to version 1.6.13. This issue does not affect systems prior to Mac OS X v10.6.
Terminal
When ssh is used in Terminal's "New Remote Connection" dialog, SSH version 1 is selected as the default protocol version. This issue is addressed by changing the default protocol version to "Automatic". This issue does not affect systems prior to Mac OS X v10.6.
X11
Multiple vulnerabilities existed in FreeType, the most serious of which may lead to arbitrary code execution when processing a maliciously crafted font. These issues are addressed by updating FreeType to version 2.4.3.
Sunday, 13 March 2011
Apple issues mammoth security update for Safari browser
Apple has released Safari 5.0.4 - the latest version of Apple's browser software for Windows and Mac users - patching an eye-watering 62 security vulnerabilities in the process.
The vulnerabilities, described in an Apple knowledgebase article, were disclosed at the same time as a host of security holes in the iOS software used by the iPhone, iPad and iPod touch were also revealed by the company.
What this means is, just like their iPhone/iPod touch/iPad-owning cousins, people who run Safari on their Mac or Windows computers would be wise to check out the latest available security updates as soon as possible.
Apple doesn't like to assign severity levels to the security vulnerabilities found in its products, but the bugs in Safari look pretty critical to me. 57 of the 62 bugs can be exploited just by a user visiting a maliciously-crafted website.
If that's not a reason to install a security update to your Safari browser, I'm not sure what is.
You can download Safari 5.0.4 from Apple's website for Mac OS X 10.5 (Leopard), Mac OS X 10.6 (Snow Leopard), Windows XP, Windows Vista and Windows 7.
SophosLabs see tens of thousands of legitimately websites that have been infected by malware every single day, so it's really important to keep your browser up-to-date with the latest security patches.
[NakedSecurity]
The vulnerabilities, described in an Apple knowledgebase article, were disclosed at the same time as a host of security holes in the iOS software used by the iPhone, iPad and iPod touch were also revealed by the company.
What this means is, just like their iPhone/iPod touch/iPad-owning cousins, people who run Safari on their Mac or Windows computers would be wise to check out the latest available security updates as soon as possible.
Apple doesn't like to assign severity levels to the security vulnerabilities found in its products, but the bugs in Safari look pretty critical to me. 57 of the 62 bugs can be exploited just by a user visiting a maliciously-crafted website.
If that's not a reason to install a security update to your Safari browser, I'm not sure what is.
You can download Safari 5.0.4 from Apple's website for Mac OS X 10.5 (Leopard), Mac OS X 10.6 (Snow Leopard), Windows XP, Windows Vista and Windows 7.
SophosLabs see tens of thousands of legitimately websites that have been infected by malware every single day, so it's really important to keep your browser up-to-date with the latest security patches.
[NakedSecurity]
Subscribe to:
Posts (Atom)