Feedback & Followups
- OpenAI follow Anthropic with their own plans for ‘watermarking’ the text generated by their AI chat bot — www.bleepingcomputer.com/…
- OpenAI’s full announcement — 📣 openai.com/…
- 🇪🇺 OpenAI are only enabling the feature by default in the EU, not worldwide like Anthropic announced recently
- There are good reasons to be skeptical about the effectiveness of these kinds of watermarks — John Gruber on daringfireball.net/… (A little snarkier than I would be, but I can’t disagree with the facts)
- More misbehaving AI Agents:
- OpenAI pauses work on top AI models after agent bypasses internet restrictions — cyberinsider.com/… (at least they are now watching their models well enough to notice them escaping in real time!)
- OpenAI Shelves GPT 61 Astra After Tests — thehackernews.com/… (Failed safety & alignment tests)
- Wikimedia: Rogue OpenAI agents behind unauthorized Wikipedia edits — www.bleepingcomputer.com/… & Wikimedia Says OpenAI Agents Tried To — thehackernews.com/…
- 🇺🇸 🇨🇦 AI agents attempted to hack US and Canadian government websites — cyberinsider.com/… (appears to be an alignment issue rather than an intentional hacking attempt — AI Agents don’t understand that denial of service is wrong!)
- Anthropic Cuts Live Internet Access For Internal AI Tests After Claude Exploits Injection Flaws — thehackernews.com/… (about time!)
- It’s not all bad news for AI, though:
- Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws — thehackernews.com/…
- Anthropic Launches Free AI Vulnerability Scanner for Open-Source Projects — thehackernews.com/…
- It’s opt-in, and many projects, already inundated with low-quality and/or duplicate bug reports, are likely to give it a miss, at least for now.
- Good option to offer, though, and over time it’s likely to make a big difference.
- Related: Google have completely paused their bug bounty program — www.bleepingcomputer.com/… (this is a stronger reaction than we’ve seen from others like Apple who responded with monthly quotas for security researchers)
Listener Questions
Full Disk Access Query from Steven Goetz
I read that Apple is changing “Full Disk Access” because apps like Muse were doing things like reading messages without being granted access to messages by the user. My question is, why would Apple not be encrypting our messages at rest on our machines?
Note: Steven is referring to a message Apple sent to developers warning that there will be changes coming, but providing no details — appleinsider.com/…
On modern versions of macOS, your entire disk is encrypted at rest by default using Apple’s full disk encryption. The purpose of encryption at rest is to prevent access when the device is not running and signed in. When the device is running, the data needs to be available, so the disk needs to be decrypted. When you enter your password to log into your Mac, you are unlocking the disk; hence, you can actually use your Mac and access your data.
Without Apple’s extra protections around apps, every app you run can do anything you can do.
Apple added a whole system to rein apps in — their App Sandbox.
Sandboxed apps need to ask for permissions to access data outside of their own folders. Apps can ask for fine-grained permissions, or they can ask for full access to all your files. That’s what Full Disk Access means. So, by allowing an app to access everything you can access, you are trusting that app not to abuse that access to read things it promised not to read. The moment you grant an app Full Disk Access, you are expressing the greatest possible trust in that app. You are allowing that app to access all the files you can access.
Few apps asked for that level of trust in the past, and those that did were aimed at the kinds of power users who understood just how much trust those apps are asking for. Now, Meta is asking regular users for this extreme level of trust, and then utterly violating it. Users are blaming Apple for selling them a proverbial house without locks, where what has actually happened is that a con artist has convinced these users to hand over their keys.
Apple are getting the blame, so they have let it be known that they are going to change something about how these permissions will work some time in the future. We have no idea what Apple will change, or when. For now, all we know is that people don’t understand how powerful Full Disk Access is, and are granting it without informed consent, and Apple are going to try to rectify that situation.
Deep Dive 1 — Apple Explains its new ‘Reference Image’ Photograph Verification System
Apple have published a detailed description of how their new Reference Image system works on their security blog. The technical details are interesting, and most importantly, impressive. Apple have developed a very robust process for cryptographically verifying the authenticity of images shot on iPhones.
What’s more interesting than the technical details is their explanation of their choice to develop their own system rather than adopting the open C2PA (Coalition for Content Provenance and Authenticity) standard Apple actually contributed to.
C2PA has two fundamental problems that make it a bad fit for iPhones:
- It’s architected around the assumption that images start in the firmware of a sensor that cannot be tampered with.
- It’s built on the Public Key Infrastructure, so it can’t be anonymous.
A phone is nothing like a traditional camera. It’s a multi-purpose device that runs software installed by the user. It is inevitable that, from time to time, malware will make it onto a phone. If it’s possible for malware to intercept the pixels between the sensor and initial digital signature, then fake images can be falsely verified!
The Architecture Problem — Phones with Cameras are not Cameras
Were it the case that modern phones use single lenses with single sensors to capture images, then it would be possible to implement C2PA using a dedicated hardware chip similar in concept to the Secure Enclave that physically separates private keys from the core OS and all apps. But that’s not how modern computational photography works! The original image on a modern iPhone is the result of data from anywhere from one to three sensors being merged together and processed through a complex processing pipeline. An initial C2PA digital signature could only be applied after all that processing has been done. Protecting the pixels every step of the way between the multiple sensors and the very end of that pipeline is not something C2PA was designed to do, so it simply can’t, meaning all C2PA implementations on existing smartphones are a lot less robust than I realised — malware on any of the existing Android phones that implement C2PA could falsely verify fake images.
The Anonymity Problem
The Public Key Infrastructure, or PKI, is designed to cryptographically connect something to an identity. The place you most often encounter the PKI is secure websites. When a website supports HTTPS, the certificate will cryptographically prove that the HTML, JavaScript, CSS, images, and videos you are looking at really did come from the domain name the certificate belongs to. In this case, the identity is a domain name.
When you pay extra for an OV or EV certificate for your website, the certificate will cryptographically bind your content not just to your domain name, but to your corporate identity.
For example, examine the details of the certificate for https://idp.mu.ie/`. This is Maynooth University's Identity Provider, that is to say, the server that vouches for all university staff and students when they log in as guests to other academic institutions anywhere on earth using the EduGate system. Universities at the other end of the world can't possibly know whether or notmu.ie` really is associated with Maynooth University, so a certificate that just associates a login request with a domain name is not enough. That’s why this is an OV cert, or an Organisation Validation Certificate, it cryptographically connects the domain name to the following:
- Country or Region: Ireland
- Locality: Maynooth
- Organisation: Maynooth University
- Common Name:
idp.mu.ie(PKI jargon for the digital identity the certificate authenticates, in other words, the server’s domain name)
The same system is used for S/MIME email signatures, but in that case the certificate ties the content of emails to email addresses.
C2PA is built around the KPI too, cryptographically connecting photographs to specific cameras owned by specific identities.
Large media organisations would obviously opt to get OV certificates to connect their cameras to their corporate identities, and content creators would use regular certificates to connect their cameras to their domain names.
With C2PA, you can’t verify an image’s authenticity without exposing your identity. Not only does that mean you can’t be anonymous, it means you need to have at the very least your own domain name to even be able to use C2PA at all! Also, it means that with C2PA images, you can always connect all images taken with the same camera together, so a sequence of images taken over time acts as a tracker for the location of that camera over time.
For media work, this is usually not a problem. For creators, there is a barrier to entry in getting your certificate, but no major concerns beyond that, but regular folk simply can never use C2PA!
But of course, one of the most important places to get verifiably real images in dangerous places with repressive governments, in those situations, C2PA is a literal liability!
What Apple Have Done
Firstly, Apple have added hardware-separated chips (secure exclaves and enclaves) to the sensors used to capture the raw pixels on iPhones 18 Pro. Secondly, to actually use Reference Images, you need to enable a special mode, and that special mode securely signs the initial pixel data from all sensors, then sends that raw data to Private Cloud Compute, where the image processing pipeline then gets applied on servers Apple knows are not running unauthorised code, and Apple then digitally sign the final result before returning it to the iPhone.
Secondly, Apple can cryptographically verify that the pixel data is from an iPhone running unaltered firmware, but not which iPhone it is, so the resulting digital signatures are anonymous, and images taken with the same phone can never be reconnected to each other.
In other words, when a Photographer uses Apple’s Reference Image option, anyone viewing the image can cryptographically prove:
- That the image was captured by a physical camera, and not altered since capture
- That the image was captured on an iPhone
But not:
- Which iPhone
- Whose iPhone
- Whether or not it was the same iPhone as any other Reference Image
Links
- Apple’s detailed description: Apple Reference Image: A New Approach for Verified Photography — security.apple.com/…
- An excellent overview: Apple Reference Image is a mammoth effort to combat AI-edited photos — appleinsider.com/…
Deep Dive 2 — Apple’s New Impersonation Risk Protection Feature
Allison asked me to give my opinion on a new feature Apple added to iOS and iPad OS 27 — Impersonation Risk Protection. This feature is off by default, so if it sounds interesting to you, you’ll need to enable it under Settings → Privacy & Security.
The feature uses on-device AI to try to determine how likely it is that what you’re doing at any given moment is the result of having fallen victim to an impersonation scam of some kind.
Apps that do sensitive things like transfer money or other valuable assets can use an API to ask the OS for its current estimate of how likely it is that you have fallen for a scam. The API will return one of three possible risk levels to the app, and the app can use that information to present additional warnings, or to temporarily block your activity.
The three possible risk levels are:
- Unknown — there’s no evidence that anything untoward is going on.
- Medium — there’s some evidence that something suspicious may be going on.
- High — there’s substantial evidence that something suspicious is going on.
Presumably to stop attackers from gaming the system, Apple are not providing any fine-grained details on how the risk level is computed. It also seems very likely that Apple will be constantly tweaking the algorithms and/or AI models used, since the so-called threat landscape is ever-changing.
This is what Apple does tell us:
- Apple analyzes interaction patterns, timing, context, and basic sensor data to generate the risk level. This information is analyzed on-device, so Apple never receives the data used to generate the risk level.
- Apple never analyzes the content of your Photos, Messages, or Mail.
- Apple learns the type of action you attempted in the app when the app requests the risk assessment.
There is also built-in transparency, with a log showing every app that requested a risk score, including a justification provided by the app. If you don’t like how an app is using the feature, you can disable it on an app-by-app basis.
Key points:
- Apps have to explicitly support this feature by calling the relevant API.
- Apps only learn the current risk level, not how it was determined.
- All the evaluations are carried out on-device, so your privacy is fully preserved.
- Off by default, at least for now, and even when you turn it on, you can exclude any apps you wish.
I don’t see any reason to advise against turning it on. Personally, I have enabled it.
For (a little) more information, see Apple’s support page for the feature.
❗ Action Alerts
- Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950) — isc.sans.edu/…
- Started as actively exploited zero-day
- Public Proof-of-Concept released, so risk is rapidly increasing — thehackernews.com/…
- LibreOffice and OpenOffice Flaws Let — thehackernews.com/… (patches available)
Worthy Warnings
- Reminder that the most common way malware gets onto Macs remains tricking users into infecting themselves: Fake Zoom installer tricks Mac users into bypassing Gatekeeper — www.cultofmac.com/…
- Reminder that unrealistically cheap devices, especially Android devices (popular free GUI OS that runs on mobile chips), are usually funded by malware: Low-cost Android phones ship with residential proxy malware — www.bleepingcomputer.com/…
- ⚠️ Proton Mail Users: The Proton webmail client is not succeeding in making look-alike domains that abuse characters that look similar to traditional Latin characters visible to users, making it possible for malicious domains that use these strange characters to send convincing-looking fake email — cyberinsider.com/…
- ⚠️ MikroTik router owners: CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS — www.bleepingcomputer.com/…
- Lack of clarity on which OS versions are and are not safe
- CISA offers practical advice for owners
Notable News
- The cat-and-mouse game appears to be continuing: Graykey Might Have a Workaround for Apple’s iPhone Reboot Protection — appleinsider.com/…
- This is not a full decryption of the iPhone; it’s a possible mechanism for keeping the iPhone in it’s less-strongly-protected state like you get when you lock your phone without powering it down.
- A few years ago Apple added functionality that aimed to push phones from that state into their powered-down state, which is even more secure, after a certain amount of time, and it appears GreyKey have found a way of blocking that feature.
- New Spectre v2 attack variant leaks Linux root password hash in minutes — www.bleepingcomputer.com/…
- Because it can affect JIT compilers which are commonly used in some browsers, this one affects regular users and can be exploited remotely over the web.
- Patches have already been merged into the Linux kernel, and are making their way into the distros now.
- 🇺🇸 Four more US states sue router maker TP-Link for breaching state consumer protection laws by misleading consumers about the depths of their links to China, and the security of their products — cyberinsider.com/… & thehackernews.com/… (Florida, Iowa, Nebraska & Montana join Texas who filed suit in February)
- 🇮🇪 Good security research continues: Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland — www.bleepingcomputer.com/…
- Some small changes to help make us all a little bit more secure:
- Signal brings encrypted local backups to iPhone and desktop — cyberinsider.com/…
- Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools — thehackernews.com/… (Locks down a mechanism many malicious apps abuse to snoop on user keystrokes)
- Surfshark adds post-quantum server authentication on iOS and macOS — cyberinsider.com/…
Palate Cleansers
- From Allison: 🎦 The Cable that Changed the World: How Instant Global Communication Began in 1858 — www.openculture.com/… Fascinating 11-minute video starting with the Nollet’s 1746 electric shock experiment and Chappe’s semaphore towers through Volta’s battery, Morse code to the undersea cables we depend on today.
- From Bart: 🎦 The Storytelling Genius Of Steve Jobs — The Art of Storytelling on YouTube/… (20 minute video exploring Jobs’ unique skills, and why his many imitators all fall short)
- From NosillaCastaway Kantor (on Slack): The people holding up the internet — sheets.works/…
Legend
When the textual description of a link is part of the link, it is the title of the page being linked to; when the text describing a link is not part of the link, it is a description written by Bart.
| Emoji | Meaning |
|---|---|
| 🎧 | A link to audio content, probably a podcast. |
| ❗ | A call to action. |
| flag | The story is particularly relevant to people living in a specific country, or, the organisation the story is about is affiliated with the government of a specific country. |
| 📊 | A link to graphical content, probably a chart, graph, or diagram. |
| 🧯 | A story that has been over-hyped in the media, or, “no need to light your hair on fire” 🙂 |
| 💵 | A link to an article behind a paywall. |
| 📌 | A pinned story, i.e., one to keep an eye on that’s likely to develop into something significant in the future. |
| 🎩 | A tip of the hat to thank a member of the community for bringing the story to our attention. |
| 🎦 | A link to video content. |
