Security Bits — 14 April 2024

Feedback & Followups

  • An excellent writeup detailing the fascinating story of the XZUtils compromise we discussed last time —… (Editorial by Bart: Definitely one of the nearest misses we’ve had in the supply chain for some time, hopefully, it focuses some more eyes on the importance of supporting important open source projects that underpin many systems)
  • 🇺🇸 AT&T have not yet explained how they were breached, but they have now admitted the breach was bigger than they first realised, and have now notified 51M current and past customers —…
  • The Sunbird iMessage client for Android is back, but while the glaring security bugs may be gone, the fundamental problem m remains – you need to give the app your Apple ID users and password for it to work —… (Editorial by Bart: don’t, just don’t!)
  • Supply-chain attacks targeting developed continue – attackers have been discovered gaming the GitHub search rankings to boost their malicious packages up the rankings —… (Editorial by Bart: my advice remains the same, start on the project’s website, don’t search on NPM or GitHub or anywhere like that, you can’t trust the results)
  • When given a choice, Europeans seem to prefer privacy-focused browsers: Report: People are bailing on Safari after DMA makes changing defaults easier —… (Based on reporting and a survey carried out by Reuters)
  • 🧯 There is another new variant of the Spectre 2 attack against the Linux kernel, it is more potent than the original Spectre 2 attacks, but it’s still not relevant to home users, and the major Linux distros used to power the cloud are on it —…

  • A nice overview of Mac malware for the first quarter of 2024 —… (for the most part, not pirating software, steering clear of crypto currency, and being careful in the App Store still keeps you safe)

  • A wonderfully geeky post from The Eclectic Light Company explaining just how macOS decides what app to open when you double-click on a file in the Finder —…

    • A timely XKCD making a point I make over and over again – seeing a 99% total solar eclipse is cool, but it’s absolutely nothing like a total eclipse, if you haven’t experienced totality, you have no idea what an amazing experience it is! —…
      xckd on clouds and eclipses:…
    • 🎧 A short new weekly podcast I’ve been enjoying a lot, and now they’ve tackled a NosillaCast-adjacent topic: The Economics of Everyday Things: 43. Top-Level Domains —…


