Security
By MacRumors Staff
Security How Tos
How to Check iCloud Keychain Password Security
Using iCloud Keychain, Apple's Safari browser stores and syncs all the passwords you use for different websites and apps through iCloud. And in iOS 14 and later, Apple provides security recommendations that warn you if a password you're using is putting your accounts at risk.
Safari securely monitors your saved passwords using strong cryptographic techniques, and regularly checks derivations ...
Read Full Article
How to Use Firefox Private Network to Encrypt Your Web Traffic
Mozilla this week began piloting its own browser-based VPN service, and if you're located in the U.S. you can start testing it for free right away.
Called the Firefox Private Network, the service promises Firefox users a more secure, encrypted path to the web that prevents eavesdroppers from spying on your browsing activity and hides your location from websites and ad trackers.
In that...
How to Encrypt a USB Flash Drive in macOS Mojave
In macOS Mojave, you can choose to encrypt and decrypt disks on the fly right from the desktop. Using this convenient Finder option, we're going to show you how to encrypt a USB flash drive (or "thumb drive"), which is useful if you're traveling light and want to take sensitive data with you for use on another Mac.
Finder uses XTS-AES encryption, the same encryption that FileVault 2 uses to...
How to Use Secure Code AutoFill in iOS 12 and macOS Mojave
Most readers will have at some point received a two-factor authentication code delivered to them by SMS text message. Many apps and websites send the one-time codes to confirm that the person attempting to log in to an account is the legitimate account holder, and not just someone using a stolen password.
Depending on how notifications are set up on your iPhone, receiving a code via text...
How to Secure Your Apple ID Using Two-Factor Authentication
Apple introduced two-factor authentication (2FA) in 2015 to provide an enhanced level of security when accessing Apple ID accounts. With 2FA enabled, you'll be the only person who can access your account, regardless of whether someone learns your password – as the result of a hack or a phishing scam, for example – so it's well worth taking the time to enable the feature. In this article,...
Security Articles
What You Need to Know About Mac Malware 'Backdoor.MAC.Eleanor'
Internet security software company Bitdefender's research lab has disclosed new malware targeting Macs called Backdoor.MAC.Eleanor [PDF]. Learn more about the malware and how to keep your Mac protected against attackers.
What is Backdoor.MAC.Eleanor?
Backdoor.MAC.Eleanor is new OS X/macOS malware arising from a malicious third-party app called EasyDoc Converter, which poses as a...
Google Simplifies 2-Step Verification Process With iOS Search App Prompt
Google is making the two-factor authentication process to log into a user account a simpler affair by integrating it into the company's iOS search app.
Two-factor authentication adds an extra layer of security to users' Google Apps accounts by requiring them to enter a verification code in addition to their username and password when signing into their account. The two-step verification...
Adobe Issues 'Emergency' Flash Player Security Update for OS X to Address Ransomware Attacks
Adobe has issued Flash Player security updates for OS X, Windows, Linux, and Chrome OS to address "critical vulnerabilities that could potentially allow an attacker to take control of the affected system" by way of ransomware.
Ransomware is a type of malware that encrypts a user's hard drive and demands payment in order to decrypt it. These type of threats often display images or use...
Researchers Uncover Multiple OS X and Safari Exploits at Pwn2Own 2016
The sixteenth annual CanSecWest security conference is underway in downtown Vancouver, British Columbia, and researchers participating in the Pwn2Own computer hacking contest have already discovered multiple vulnerabilities in OS X and the Safari web browser on the desktop.
On day one of the event, independent security researcher JungHoon Lee earned $60,000 after exploiting both OS X and...
Adobe Releases Flash Player Update for 'Critical' Security Vulnerability on Mac
Adobe has released security updates for Flash Player that address critical vulnerabilities that "could potentially allow an attacker to take control of the affected system." Adobe is aware of "limited, targeted attacks" on OS X, Windows, and Linux.
Adobe lists the affected Flash Player and AIR versions in a security bulletin on its website. Mac or PC users running an affected version should...
Apple Acquired Firmware Security Company LegbaCore Last November
Apple acquired firmware security company LegbaCore in November 2015, according to security researcher Trammell Hudson, who revealed the acquisition in his presentation at the 32C3 conference in December. LegbaCore's goal, according to founder Xeno Kovah, is "to help build systems that are as secure as we know how to make."
In November, Kovah and fellow LegbaCore founder Corey Kallenberg reveale...
Apple's Strict Bluetooth LE Security Requirements Slowing Rollout of HomeKit Accessories
While it has been more than a year since Apple launched HomeKit, a software framework for communicating with and controlling light bulbs, thermostats, door locks and other connected accessories in the home, only five HomeKit-approved products have been released to date: the Ecobee3, Elgato Eve, iHome iSP5 SmartPlug, Insteon Hub and Lutron Caseta Wireless Lighting Starter Kit.
The slow rollout...
iOS and OS X Security Flaws Enable Malicious Apps to Steal Passwords and Other Data
A team of six researchers from Indiana University, Georgia Tech and Peking University have published an in-depth report exposing a series of security vulnerabilities that enable sandboxed malicious apps, approved on the App Store, to gain unauthorized access to sensitive data stored in other apps, including iCloud passwords and authentication tokens, Google Chrome saved web passwords and more.
...
Apple Issues Security Updates Fixing 'FREAK' Security Flaw
Just under a week after researchers uncovered a security flaw referred to as "FREAK" (Factoring Attack on RSA-EXPORT Keys) that left many devices vulnerable to hacking attempts, Apple has issued fixes for all of its platforms.
The fix is available in Apple TV 7.1 for Apple TV 3rd generation and later, iOS 8.2 for iPhone 4s and later, iPod touch 5th generation and later and iPad 2 and later....
OS X 10.10.2 Includes Fix for 'Thunderstrike' Hardware Exploit Affecting Macs
Apple is readying a fix in OS X 10.10.2 for the so-called "Thunderstrike" hardware exploit targeting Macs equipped with Thunderbolt ports, iMore has learned. According to the report, Apple patched the vulnerability by making code changes in the upcoming software update that prevent a Mac's bootrom from being replaced or rolled back to a previous state in which it could be attacked.To secure...