Feedback & Followups
- After their first attempt received a lot of negative user feedback, Discord has redesigned their age-verification system: Discord rolls out age checks that don’t require an ID or selfie — cyberinsider.com/…
- “The company says more than 90% of users will be assigned an age group automatically, while those who need to confirm they are adults can choose from several methods, including credit cards, Apple App Store or Google Play age-range sharing, Google Wallet, AgeKey, video selfies, or ID scans.” — Cyber Insider
- More AI agent misbehaviour and revelations:
- OpenAI reveals its AI agents hid mistakes and bypassed restrictions — cyberinsider.com/… (more alignment problems)
- Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up — thehackernews.com/… (not Agent escapes but yet another ‘lab leak’)
- 🇦🇺 OpenAI hacked Australian Medicare govt site, probed data providers — www.bleepingcomputer.com/…
- OpenAI’s AI agents accidentally uploaded user-provided images to third-party sites — www.bleepingcomputer.com/… (images real-world users added to prompts!)
- Unsurprisingly, OpenAI’s decision to start advertising has incentivised them to create their own ad-tracker to facilitate targeted ads: ChatGPT advertising system reportedly tracks users across websites — cyberinsider.com/… (they have become just like Google and Meta 🙁)
Listener Questions
Real-world ramifications of macOS 27 login keychain changes? (from Kantor)
Relating to this research by Howard Oakley: what are the real-world ramifications of Apple changing how the macOS Login keychain may be accessed? https://eclecticlight.co/2026/09/14/how-can-you-copy-or-restore-keychains/
TL;DR — for regular users, I can’t see any real-world impact.
If you’ve never exported and imported your Login Keychain, you won’t notice anything has changed. Simply opening the Login keychain is now something Apple steer you away from — in macOS 26 they added an interception pop-up when you launch the Keychain Access utility that suggests you probably want the new Passwords app, and give you a button to open that instead!
The closest thing I can see to a real-world impact is a slight boost in security, protecting device-specific secrets just a little bit more strongly, even from malware that managed to sneak onto your Mac.
What is the Login Keychain?
Since before macOS was even called macOS, Apple have provided a built-in encrypted storage mechanism for safely saving secrets. Apps use Apple’s Keychain APIs to securely store and read things like saved passwords, private keys, API credentials, and security tokens. Keychains are encrypted files, and users unlock them with a password.
Users and apps are free to create their own keychains and set what ever passwords they like on them, but Apple provide some standard keychains.
For as long as we’ve had keychains there have been at least three standard keychains:
- The System Roots keychain — this is part of the operating system, and it stores the public keys for all the certificate authorities our Macs trust. The information in this keychain is not actually secret, all they keys are public keys. The point of this keychain is to provide a trusted source for this vitally important information.
- The System keychain — this is also part of the OS, it contains secrets the OS needs access to in order to function, and the OS handles the locking and unlocking of this keychain automatically. Unless you’re very keen to break something, you should leave this keychain well and truly alone!
- Each account has a Login keychain. This keychain is connected to the user’s login password, and when the user logs in, they unlock this keychain.
Before there was such a thing as the iCloud Keychain, all secrets from all apps that belonged to a user rather than the system as a whole were stored in the login keychain. Every password you entered into every well-written app, every password you saved in Safari, they all went into this keychain.
But many years ago, Apple added a fourth standard keychain, the iCloud Keychain (now just called the Cloud Keychain). Initially, you had to opt in to using iCloud Keychain, and setting it up involved a lot of faffing about. But over time it’s become ever simpler to use, and today, you need to go out of your way not to have a Cloud keychain.
The reason Apple added the iCloud Keychain was to allow secrets to securely synchronise between all your Apple devices. But Apple never intended all secrets to sync to all devices; some secrets are intended to be device-specific.
A good example of this is that the security of end-to-end encryption depends on each device having a dedicated public and private key-pair, and for no device to ever share its private key in any way. That means that even after the introduction of the iCloud keychain, the Login keychain retains a very important role — it’s designed to hold device-specific secrets.
Note that whether or not you choose to enable iCloud Keychain sync, you still have a keychain named iCloud Keychain or Cloud Keychain on every device; they’re just not kept in sync!
So, that means that in versions of OS X and macOS since the introduction of the iCloud Keychain, the ‘correct’ use of keychains changed — app developers that follow the guidelines are now expected to choose the appropriate keychain for each secret they store. Device-specific secrets should be stored in the Login keychain, and all other secrets in the Cloud keychain.
That change was never going to happen overnight, and even today there are almost certainly still some legacy apps hiding somewhere that wrongly store non-device-specific secrets in the Login keychain. But I think that number is now so small it’s just not relevant for home users.
I think it’s now reasonable to assume that any secret stored in your Login keychain was intentionally stored there to bind it to a specific device.
What did Apple Change?
Without going into technical details, Apple have cryptographically bound Login keychains to the devices they were created on. You can still export your Login keychain to a file, but that file can’t be opened without access to the secure enclave on the motherboard of the device it belongs to. That means you can time-shift your Login keychain, but you can’t move it from one Mac to another. The intended device-binding is now cryptographically enforced!
Typical workflows don’t depend on exporting Login keychains at all, let alone exporting Login keychains on one Mac and importing them into another. If your workflow does depend on doing that, your workflow will break with macOS 27. I genuinely can’t conceive of a good reason to do this, but I may just not be imaginative enough.
Finally, iPads and iPhones have had un-exportable Login keychains since the day they launched, and that hasn’t stopped any of us from backing up and restoring our data, or migrating it from one device to another. The Mac’s Login keychain will now behave like these devices always have.
Why did Apple Make the Change?
Simple — to boost security.
One of the foundational assumptions for true end-to-end encryption is that private keys never leave the device they belong to. Before this change, that assumption was cryptographically enforced. Now it is!
Deep Dive — Beware Meta’s new Muse AI Agent
Meta have launched a new AI agent that lives in the cloud and can be accessed from apps on your phones and computers. Every Muse user gets their own virtual computer in Meta’s data centre that their specific agent runs in, and that virtual computer has a virtual browser that the agent can use to act on the user’s behalf any time, regardless of whether or not the user is even online.
If you log the agent into online services, like your webmail interface, then the agent gets access to all that information, and can do anything you can do! That alone is something you should only grant to software that has really earned your trust. How many humans would you grant that kind of access to?
But if you install the desktop app, you take this trust to a whole new level! The Muse Mac app requests full disk access!
That means Muse can read everything on your Mac! The iPhone app can’t do that, it can only read more specific pieces of data that you grant access to one-by-one (all those prompts apps have to give to get to your contacts, calendar, photos, etc.).
There is of course a big difference between permission and consent, especially informed consent!
Unsurprisingly, Muse is surprising people, in creepy ways. Tech columnist Jason Aten’s experience with the agent is illuminating, and Jason explains the problem well:
An AI agent isn’t especially useful if it can’t see your files, interact with your apps, or understand what you’re working on. Meta says Muse is designed around that reality, while still putting users in control of what it can access.
… yesterday, I was having a conversation with my Primary Technology podcast co-host, Stephen Robles, about the new iPhones. Moments later, I got a push notification from Muse suggesting that the conversation we were having would make for a good column and offered to put together research for me to write about. It even flagged a message from my editor about having a column ready for Monday.
Not only had I not asked it to do that sort of thing, I never gave it permission to read my messages. In fact, I remember explicitly choosing not to let it have access to my messages, calendar, and other personal information.
Stranger still was what happened when I asked Muse how it knew. It told me it didn’t have access to my message history at all. Instead, it said the Muse app on my Mac was simply passing along the text of incoming notification banners.
Jason did a little more digging, and Muse had actually started ingesting his messages database as a data source.
Muse asked his preferences; he clearly expressed them — he did not authorise Muse to access his messages, contacts, or calendars, but he did authorise it to read his documents.
However, at a technological level, the Mac app did not use the most restrictive possible API for accessing the data he had authorised; it used the opposite — the most powerful possible permission — it requested full disk access!
So, the app was authorised to access his documents, but not his messages, but it had the OS-level permissions to get them anyway, so it did!
Muse asked for Jason’s trust, and within hours, had betrayed it!
My personal feelings on Muse align quite well with those of John Gruber, and he’s a much more eloquent writer than I am, so I’ll let John explain:
The Muse iOS app is sandboxed — because it has to be. So that’s the only version I’m personally tinkering with. But the Mac app is the more powerful one, because, well, it lets Muse drive your Mac. The fact that the Muse Mac app is so powerful is why it has to be downloaded from the web.
…
The way I think about running an agentic AI on my Mac is simple. I would never let an unknown person use my Mac. Not even for a minute, not even with me watching them. Let alone letting them use it nonstop, without my watching them. I’d be uncomfortable letting even a trusted friend use my Mac, logged into my user account. So why would I let an AI robot, no matter the source?
John is experimenting with the iOS version because it has technological barriers stopping it exceeding its authorisation like the Mac app can, and clearly does, but I’m not even prepared to do that!
The concept of an always-on VM in the cloud acting as your AI agent is a good one, and someday, someone who has earned my trust will implement it, and I will cautiously start to experiment with it, but never with Meta, and not today. It’s still the absolute wild west of agentic AI, and I’m not keen on getting into the crossfire of any proverbial gunfights!
Links
- Meta’s Overview of the Muse AI Agent — about.fb.com/…
- Jason Aten’s article outlining his experience: Meta’s New Muse AI Agent Read My Private Messages. I Never Asked It To — www.inc.com/…
- John Gruber eloquently explains why he’s not installing Muse on his Mac: I’ll Wait — daringfireball.net/… (I agree 100%)
❗ Action Alerts
Programming Note: I’ve adjusted my criteria for this section — individual WordPress Core and WordPress plugin vulnerabilities will only be included if they are truly exceptional in some way. If you run WordPress, I strongly advice keeping all automatic updates enabled, because the risk from rapidly weaponised new vulnerabilities is greater than the risk of a bad buggy update breaking something.
- Apple Updates Everything — isc.sans.edu/…
- The OS 27 OSes all contain security fixes as well as the new features
- Apple didn’t forget about updating older operating systems — appleinsider.com/…
- Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root — thehackernews.com/… (patches released)
- ⚠️ Pixel Phone Users: Google fixes actively exploited Android zero-day on Pixel devices — www.bleepingcomputer.com/…
- ⚠️ Windows users with Logitech Devices: Logitech Options+ flaw lets attackers gain Windows SYSTEM privileges — cyberinsider.com/…
- If you have Logitech Options+ installed to configure your device(s), patch it ASAP!
- ⚠️ Docker users on macOS: Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files — thehackernews.com/… (patch!)
- ⚠️ D-Link DIR-822A Router Users: D-Link warns of max severity zero-day bug in DIR-822A routers — www.bleepingcomputer.com/…
- These are obsolete routers, so no patch!
- Time to recycle and replace!
Worthy Warnings
Programming Note: based on listener responses in the Podfeet Slack, I’ve adjusted my criteria for this section — individual data breaches will only be included if they are truly exceptional in some way. We’ve now arrived at the stage where we should all behave as if we have been involved in a data breach, because whether we know it or not, we almost certainly have!
- Beware tech documentation and examples that use the common placeholder domain
third-party.com: Placeholder domain used in dev docs now serves ClickFix attacks — www.bleepingcomputer.com/… - ⚠️ Nintendo Switch Users: Nintendo warns of Switch code execution flaw via on-screen QR codes — cyberinsider.com/…
- ⚠️ GitLab.com Users: Exposed GitLab project email addresses let attackers push code — www.bleepingcomputer.com/… (an alternative to GitHub)
Notable News
- 🧯There’s a new way to break RSA that’s faster than anything we’ve seen before — arstechnica.com/…
- “The practical risk is limited, but still significant. Applying the attack against the deprecated use of 1024-bit keys took a handful of months on an academic CPU cluster, significantly less than the current estimates for 1024-bit factoring that would require resources that only nations or companies with massive resources could achieve. Widely used RSA implementations are also safe.” — Ars Technica
- Thankfully, 2048 has been the default key length for some time now
- If you are still using any older RSA keys, now would be a good time to replace them with more modern keys
- 🇪🇺 🇮🇪 Google fined €403 million over location data privacy violations — www.bleepingcomputer.com/… (Fine imposed by the Irish Data Protection Commissioner because Google’s EU HQ is in Dublin; they also have six months to make changes)
- Nice little security improvements:
- Homebrew 7.0.0 gets built-in GUI, better security controls — www.bleepingcomputer.com/…
- “… a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI graphical interface …” — Bleeping Computer
- WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution — thehackernews.com/…
- This will help protect against supply-chain attacks where legitimate plugins are poisoned with malicious updates, making automatic updates even less likely to cause problems.
- Signal tests account registration without phone number on Android — cyberinsider.com/…
- This is the next step on Signal’s road-map to removing the need to connect a cellphone number to a Signal account.
- Face ID is just a little bit more secure on iPhones 18 Pro: Supplemental image data used in Face ID authentication on iPhone 18 Pro — appleinsider.com/…
- Opera’s free VPN now turns on automatically on public Wi-Fi — cyberinsider.com/…
- Meta brings Private Processing privacy protections to AI glasses — cyberinsider.com/…
- “Meta is expanding its Private Processing infrastructure to AI glasses, allowing cloud-based AI to analyze personal context while preventing Meta itself from accessing the underlying data. The system combines confidential computing, hardware-backed isolation, anonymous routing, remote attestation, and encrypted storage to protect information during processing.” — Cyber Insider
- Sounds good, assuming their implementation is robust 🤞
Interesting Insights
- Unlike most AI tools, Apple allow users to see the system prompts; Glenn Fleishman explains how: See the Behind-the-Scenes Prompts That Power Siri AI — tidbits.com/…
- A great example of Apple following through on their privacy and transparency promises!
Just Because it’s Cool 😎
- Ever wonder how Apple gets fully patched versions of iOS onto iPhones built months before launch day? Here’s how: How Apple gets iOS 27 onto millions of iPhone 18 Pro units in time for launch — www.cultofmac.com/…
Palate Cleansers
- From Bart:
- Follow-up: Firefox users who want something like my Litterbox Safari Extension recommendation from last time are in luck: Dumpster Fire – Litterbox-Inspired Extension for Firefox — daringfireball.net/…
- The wonderful macOS app-deleting app App Zapper is back, and as zany as ever: appzapper.com/…
- John Gruber puts it into context wonderfully: AppZapper 3000 — daringfireball.net/…
- 🎧 A fascinatingly different take on the AI question consuming us all ATM: Imaginary Worlds: Is Mythology the Key to Understand AI? — overcast.fm/… (A great podcast in general for geeks!)
Legend
When the textual description of a link is part of the link, it is the title of the page being linked to, when the text describing a link is not part of the link, it is a description written by Bart.
| Emoji | Meaning |
|---|---|
| 🎧 | A link to audio content, probably a podcast. |
| ❗ | A call to action. |
| flag | The story is particularly relevant to people living in a specific country, or, the organisation the story is about is affiliated with the government of a specific country. |
| 📊 | A link to graphical content, probably a chart, graph, or diagram. |
| 🧯 | A story that has been over-hyped in the media, or, “no need to light your hair on fire” 🙂 |
| 💵 | A link to an article behind a paywall. |
| 📌 | A pinned story, i.e. one to keep an eye on that’s likely to develop into something significant in the future. |
| 🎩 | A tip of the hat to thank a member of the community for bringing the story to our attention. |
| 🎦 | A link to video content. |
