Archive for July 19, 2017

Apple has released updates to iOS, watchOS, tvOS, and macOS…. Here’s Why You Should Care

Posted in Commentary with tags on July 19, 2017 by itnerd

At 1PM EST Apple Apple released iOS 10.3.3, watchOS 3.2.2, tvOS 10.2.2, and macOS 10.2.6. The release notes for all the above basically say some that the focus was performance and security improvements. But the the latter is why you should care. I’ve been browsing the documents that list the security improvements that have been made and these ones jump out at me. I’ll start with iOS 10.3.3:

Available for: iPhone 5 and later, iPad 4th generation and later, and iPod touch 6th generation

Impact: Notifications may appear on the lock screen when disabled

Description: A lock screen issue was addressed with improved state management.

CVE-2017-7058: an anonymous researcher

Lock screen issues are not new to iOS, but this one could have privacy implications.

Available for: iPhone 5 and later, iPad 4th generation and later, and iPod touch 6th generation

Impact: Visiting a malicious website may lead to address bar spoofing

Description: An inconsistent user interface issue was addressed with improved state management.

CVE-2017-2517: xisigr of Tencent’s Xuanwu Lab (tencent.com)

And:

Available for: iPhone 5 and later, iPad 4th generation and later, and iPod touch 6th generation

Impact: Visiting a malicious website may lead to address bar spoofing

Description: A state management issue was addressed with improved frame handling.

CVE-2017-7011: xisigr of Tencent’s Xuanwu Lab (tencent.com)

This is kind of dangerous as it could lead to you and your iDevice getting pwned by hackers through no fault of your own.

Available for: iPhone 5 and later, iPad 4th generation and later, and iPod touch 6th generation

Impact: Processing a maliciously crafted movie file may lead to arbitrary code execution

Description: A memory corruption issue was addressed with improved bounds checking.

CVE-2017-7008: Yangkang (@dnpushme) of Qihoo 360 Qex Team

This is really dangerous. There have been examples of this in the past where it would crash an iOS device. It sounds like this attack vector has become a bit more sophisticated. I should also note that the same thing was fixed in tvOS.

iOS, tvOS, macOS and watchOS share one interesting security fix:

Available for: All Apple Watch models

Impact: An attacker within range may be able to execute arbitrary code on the Wi-Fi chip

Description: A memory corruption issue was addressed with improved memory handling.

CVE-2017-9417: Nitay Artenstein of Exodus Intelligence

I should note that this fix is available for iPhone 5 and later, iPad 4th generation and later, and iPod touch 6th generation. Not to mention macOS users running 10.12.5 and 4th Generation Apple TV users. Which is good as this is not the first time that Apple has fixed an issue where a device could be pwned via WiFi, and the fact that this can be done at all is very serious.

There’s a bunch of interesting tvOS security fixes that look like this:

Available for: Apple TV (4th generation)

Impact: A malicious website may exfiltrate data cross-origin

Description: Processing maliciously crafted web content may allow cross-origin data to be exfiltrated by using SVG filters to conduct a timing side-channel attack. This issue was addressed by not painting the cross-origin buffer into the frame that gets filtered.

CVE-2017-7006: David Kohlbrenner of UC San Diego, an anonymous researcher

There’s of course many other fixes, but none as serious as these. Thus consider updating to the latest version of whatever OS your iDevice runs so that you can protect yourself from the attacks that are sure to come.

 

Android Backdoor ‘GhostCtrl’ Can Silently Record Your Audio, Video and More

Posted in Commentary with tags , on July 19, 2017 by itnerd

Researchers over at Trend Micro have discovered a new Android backdoor that at first glance, seems scary:

The information-stealing RETADUP worm that affected Israeli hospitals is actually just part of an attack that turned out to be bigger than we first thought—at least in terms of impact. It was accompanied by an even more dangerous threat: an Android malware that can take over the device.

Detected by Trend Micro as ANDROIDOS_GHOSTCTRL.OPS / ANDROIDOS_GHOSTCTRL.OPSA, we’ve named this Android backdoor GhostCtrl as it can stealthily control many of the infected device’s functionalities.

There are three versions of GhostCtrl. The first stole information and controlled some of the device’s functionalities without obfuscation, while the second added more device features to hijack. The third iteration combines the best of the earlier versions’ features—and then some. Based on the techniques each employed, we can only expect it to further evolve.

Lovely. The malware distributes itself via illegitimate apps for WhatsApp or Pokemon GO. Trend Micro suggests you keep your Android devices up to date and data backed up regularly. They also recommend using an app reputation system that can detect suspicious and malicious apps. In other words, this is a real and present threat and I am sure that we’ll see threats just like this one in the not too distant future.

#Fail: OnePlus 5 Handsets Allegedly Rebooting When Users Dial 911 or 999

Posted in Commentary with tags on July 19, 2017 by itnerd

Users on Reddit are reporting on a problem that seems kind of troubling. Apparently if you own a OnePlus 5 and if you dial emergency services in the UK via 999 or do the same thing in the US or Canada which is 911, your phone will reboot. One user even took to Facebook to show the fail in action. I for one don’t recommend that you try this at home as the authorities get kind of upset when you needlessly dial your local emergency services.

For its part OnePlus has been spreading the word that they’re working with customers individually to solve the issue. That kind of implies that there is a bug that they need to fix. If you’ve tripped over this, send an email to support@oneplus.net to start the process to get you sorted.

WhatsApp May Be Blocked In China

Posted in Commentary with tags , on July 19, 2017 by itnerd

The New York Times is reporting that popular messaging service WhatsApp appears t be blocked in China:

The blocks against WhatsApp originated with the government, according to a person familiar with the situation who declined to be named because they were not authorized to speak on the record about the disruption. Security experts also verified that the partial disruption in WhatsApp started with China’s internet filters.

“According to the analysis that we ran today on WhatsApp’s infrastructure, it seems that the Great Firewall is imposing censorship that selectively targets WhatsApp functionalities,” said Nadim Kobeissi, an applied cryptographer at Symbolic Software, a cryptography research start-up.

This isn’t trivial as WhatsApp has something in the area of 1.2 billion users worldwide. Thus this is going to get a lot of attention. The question is, will the Chinese government care about the blowback from this? We’ll have to watch and see.

American Demands For Changes In NAFTA May Bring Cheaper Wireless Plans For Canadians

Posted in Commentary with tags , on July 19, 2017 by itnerd

You have to believe that the corner offices in Bell, Rogers, and Telus are not happy places to be right now. I say that because a number of media outlets including The Toronto Star and Global News are reporting that the demands to renegotiate the NAFTA trade agreement between Canada, USA, and Mexico includes demands to allow US telcos to do business in Canada. If that’s the case the result would likely be cheaper cell phone plans for Canadians. After all, Canadians because of the oligopoly of Rogers, Bell, and Telus pay the highest prices for cell phones in the G7. A fact that is highlighted by the Global News article that I linked to.

So, what do I think of this? If you take all of the hysteria that surrounds this out of the mix, I am all for it. Long time readers of this blog know that I have said that Canadians pay way too much for their cell phones which is impossible to escape every time I travel on business to places that have much cheaper prices for cell service. Long time readers will also know that I’ve been saying that we have to let in foreign competition to solve this problem as no “made in Canada” solution exists. It would have to be on the scale of a Verizon or Deutsche Telekom as they’d have to build their own infrastructure from scratch which isn’t cheap. But if they did do that, your wireless bill would nosedive instantly as for the first time, the trio of Bell, Rogers, and Telus would have real competition. If those three carriers were smart, they’d get ahead of this by quickly adjusting the prices of their plans to get into the same universe of what is being offered in the USA and apply it to new and existing customers. But chances are that won’t happen and they’ll likely only do something after changes to NAFTA take place, and when US carriers set up shop in Canada to start scooping up customers by the truckload.

This should be fun to watch.