{"id":19504,"date":"2019-10-20T16:29:28","date_gmt":"2019-10-20T23:29:28","guid":{"rendered":"https:\/\/www.podfeet.com\/blog\/?p=19504"},"modified":"2019-10-20T16:29:28","modified_gmt":"2019-10-20T23:29:28","slug":"sb-2019-10-20","status":"publish","type":"post","link":"https:\/\/www.podfeet.com\/blog\/2019\/10\/sb-2019-10-20\/","title":{"rendered":"Security Bits \u2013 20 October 2019"},"content":{"rendered":"<h3>Security Medium 1 \u2014 Apple Card is not Magic<\/h3>\n<p>A story made a lot of news this week because it involved a physical Apple Card being skimmed. It underlines the fact that people do not understand that when they fall back to using the physical card or entering the virtual number into a website manually, they are back to using the obsolete and dangerously insecure credit card infrastructure of old. That&#8217;s why Apple went to so much trouble to make Apple Pay the default way to use the card, and why they describe the physical card and the virtual number as  fallback mechanisms for when Apple Pay can&#8217;t be used.<br \/>\n<!--more--><br \/>\nWe&#8217;ve seen two distinct types of fraud against Apple Card \u2014 cloning attacks against the magnetic strip (not the chip for &#8220;Chip &amp; PIN&#8221;), and leaking of the virtual number after entering it online.<\/p>\n<p>It&#8217;s impossible to protect the magnetic strip \u2014 that&#8217;s why most of the planet abandoned it years ago! This isn&#8217;t a problem with the Apple Card, but with the payment industry!<\/p>\n<p>With the virtual number Apple Pay users have a little more control than users of more traditional cards because they have the power to change the virtual number themselves without having to get a new card issued by their bank.<\/p>\n<p>It&#8217;s also vital to remember that from a legal point of view, customers are not liable for fraudulent transaction on any credit card \u2014 so it&#8217;s American banks that literally pay the price for their own failure to move with the times!<\/p>\n<h4>Links<\/h4>\n<ul>\n<li><a href=\"https:\/\/www.imore.com\/apple-card-user-says-they-were-victim-fraud-despite-never-using-their-physical-card\">Apple Card user says they were a victim of fraud despite never using their physical card \u2014 www.imore.com\/\u2026<\/a><\/li>\n<\/ul>\n<h3>Security Medium 2 \u2014 Safari is Not Sending URLs from Non-Chinese Browsers to Tencent &#x1f9ef;<\/h3>\n<p>Confusion reigned for a while when Apple updated the wording of their Safari privacy statement in a way that could be interpreted as saying they send all browsing data to Chinese firm Tencent as part of their phishing protections. To cut a long story short, no, that&#8217;s not what&#8217;s happening. Chinese iPhones use Tencent for phishing protection, and other iPhones use Google.<\/p>\n<p>This story revolves around an important security protection that&#8217;s enabled by default on all versions of Safari. The feature, named <em>Fraudulent Website Warning<\/em>, protects users from known phishing URLs but putting up a warning when they browse to one.<\/p>\n<p>The feature relies on blacklists maintained by search providers. <a href=\"https:\/\/en.wikipedia.org\/wiki\/Google_Safe_Browsing\">Google&#8217;s Safe Browsing<\/a> API is probably the most comprehensive such blacklist, hence its use by just about every major browser (except Edge). Google&#8217;s API is not available in China, hence Chinese iPhones having to use an alternative service. The most comprehensive Chinese blacklist is the one maintained by Tencent, so it makes sense Apple would use it in China.<\/p>\n<p>Apple have made clear that they only use Tencent in China, but we don&#8217;t have to take their word for it \u2014 security researchers have peeped under Safari&#8217;s bonnet and confirmed that the code does what Apple says it does.<\/p>\n<p>The APIs for these services are also surprisingly privacy-aware. No cookies are sent, and the browser never actually sends the URLs to the blacklist providers for testing.<\/p>\n<p>The way it works is that the browser periodically asks the blacklist provider to send a list of hashes of URL prefixes on which phishing URLs exist. These are hashes of parts of URLs. The browser keeps this list internally, and checks every website the user visits against it. Most of the time the prefix won&#8217;t match so the browser doesn&#8217;t need to do anything more to verify that the site is not blacklisted. If the prefix hash does match the browser asks the blacklist provider for hashes of all the full known-bad URLs with the matching prefix. The browser then checks a hash of the full URL against that more detailed list of hashes.<\/p>\n<p>So, what does the provider know? Just two things: your IP address, and the prefix of a URL you visited, but not the full URL. No cookies are included in the API calls either.<\/p>\n<p>IP addresses make very poor tracking identifiers \u2014 many humans share individual IPs, and individual humans move around between many different IPs. There simply isn&#8217;t a good mapping from single humans to single IP addresses, so they&#8217;re just not suited to reliable tracking!<\/p>\n<p>I can&#8217;t see any scandal here, or indeed any cause for concern. The benefits of phishing protection far outweigh the very small privacy concerns over the purely hypothetical very inaccurate tracking the blacklist providers could deploy.<\/p>\n<h4>Links<\/h4>\n<ul>\n<li><a href=\"https:\/\/www.imore.com\/heres-apples-statement-safari-fraudulent-website-warning-and-tencent\">Here&#8217;s Apple&#8217;s statement on Safari Fraudulent Website Warning and Tencent \u2014 www.imore.com\/\u2026<\/a><\/li>\n<li><a href=\"https:\/\/www.macobserver.com\/news\/tencent-safari-data-region-china\/\">Code Reveals Tencent Only Gets Your Data if Your Device\u2019s Region is Set to China \u2014 www.macobserver.com\/\u2026<\/a><\/li>\n<\/ul>\n<h3>Notable Security Updates<\/h3>\n<ul>\n<li>Patch Tuesday has been and gone yet again with critical updates from Microsoft and Adobe for Windows &amp; Acrobat, including a fix for a nasty vulnerability in the Windows Remote Desktop client \u2014 <a href=\"https:\/\/krebsonsecurity.com\/2019\/10\/patch-tuesday-lowdown-october-2019-edition\/\">krebsonsecurity.com\/\u2026<\/a>, <a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/10\/09\/microsoft-fixes-critical-remote-desktop-bug-on-patch-tuesday\/\">nakedsecurity.sophos.com\/\u2026<\/a> &amp; <a href=\"https:\/\/www.us-cert.gov\/ncas\/current-activity\/2019\/10\/15\/adobe-releases-security-updates-multiple-products\">www.us-cert.gov\/\u2026<\/a><\/li>\n<li>Signal quickly patched a serious bug that was very similar to the recent high-profile FaceTime bug \u2014 <a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/10\/08\/signal-immediately-fixed-facetime-style-eavesdropping-bug\/\">nakedsecurity.sophos.com\/\u2026<\/a><\/li>\n<li>Apple have patched their Windows software and released macOS Catalina \u2014 <a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/10\/08\/signal-immediately-fixed-facetime-style-eavesdropping-bug\/\">nakedsecurity.sophos.com\/\u2026<\/a>\n<ul>\n<li>The bugs patched are now being used in the wild to install ransomware, so patch now! Also, if you installed and later un-installed an Apple product on Windows you may still be vulnerable because the un-installer leaves Bonjour behind, and that&#8217;s where the vulnerability was \u2014 <a href=\"https:\/\/arstechnica.com\/?p=1583285\">arstechnica.com\/\u2026<\/a>, <a href=\"https:\/\/www.imore.com\/itunes-and-icloud-vulnerability-allowed-windows-ransomware-be-installed-undetected\">www.imore.com\/\u2026<\/a> &amp; <a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/10\/15\/update-now-windows-users-targeted-by-itunes-software-updater-zero-day\/\">nakedsecurity.sophos.com\/\u2026<\/a><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h3>Notable News<\/h3>\n<ul>\n<li>A zero-day bug has been found in Android that affects many popular Android handsets (including Google Pixels 1 &amp; 2, Samsung Galaxies S7, S8 &amp; S9). A patch is expected from Google in the October update, and that patch will then have to make its way to user via the relevant manufacturers. The bug is being actively exploited in the wild \u2014 <a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/10\/07\/android-devices-hit-by-zero-day-exploit-google-thought-it-had-patched\/\">nakedsecurity.sophos.com\/\u2026<\/a> &amp; <a href=\"https:\/\/www.zdnet.com\/article\/google-finds-android-zero-day-impacting-pixel-samsung-huawei-xiaomi-devices\/\">www.zdnet.com\/\u2026<\/a><\/li>\n<li>Facebook&#8217;s Libra crypto currency suffers more defections \u2014 with the departure of Visa, Mastercard, eBay &amp; Stripe all major payment processors have now departed \u2014 <a href=\"https:\/\/www.imore.com\/facebook-libra-loses-support-visa-mastercard-ebay-and-stripe\">www.imore.com\/\u2026<\/a> &amp; <a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/10\/15\/facebooks-libra-cryptocurrency-loses-all-but-one-payment-company\/\">nakedsecurity.sophos.com\/\u2026<\/a>\n<ul>\n<li><strong>Related Analysis:<\/strong> <a href=\"https:\/\/uk.reuters.com\/article\/us-facebook-cryptocurrency\/facebooks-libra-faces-support-test-after-big-payment-backers-quit-idUKKBN1WT17D\">Facebook&#8217;s Libra announces board as support shrinks further \u2014 uk.reuters.com\/\u2026<\/a><\/li>\n<\/ul>\n<\/li>\n<li>A flaw has been found in the Galaxy S10&#8217;s fingerprint sensor that results in it being fooled into accepting any fingerprint when used with certain screen protectors. Samsung are working on a fix, but in the mean time users should revert to another unlock mechanism \u2014 <a href=\"https:\/\/www.bbc.com\/news\/technology-50080586\">www.bbc.com\/\u2026<\/a><\/li>\n<li>The <em>Face Unlock<\/em> feature on Google&#8217;s Pixel 4 works even when users eyes are closed (i.e. no attention detection like on iPhones), making it significantly less secure \u2014 <a href=\"https:\/\/www.bbc.com\/news\/technology-50085630\">www.bbc.com\/\u2026<\/a><\/li>\n<li>Twitter have clarified their approach to politicians who break their terms of services \u2013 they still won&#8217;t delete most of their tweets or accounts, but they will put the offending tweets behind a notice users have to click-through to see the tweet \u2014 <a href=\"https:\/\/www.imore.com\/twitter-clarifies-approach-world-leaders-who-post-twitter\">www.imore.com\/\u2026<\/a><\/li>\n<li>Instagram have updated their apps to give users more and easier control over the data shared with third-party services they connect to their Instagram accounts \u2014 <a href=\"https:\/\/www.imore.com\/instagram-improves-controls-sharing-data-third-parties\">www.imore.com\/\u2026<\/a><\/li>\n<li>Microsoft have announced that they&#8217;ll be adding a feature to allow Xbox gamers to filter the messages they receive \u2014 <a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/10\/16\/microsoft-lets-xbox-users-censor-what-they-see\/\">nakedsecurity.sophos.com\/\u2026<\/a><\/li>\n<\/ul>\n<h3>Suggested Reading<\/h3>\n<ul>\n<li>PSAs, Tips &amp; Advice\n<ul>\n<li>&#x2b50;&#xfe0f; An important reminder to be just as suspicious of SMS messages as you are of emails. An SMS that appears to come from your carrier with a link is just as dangerous as an email pretending to be from your bank! \u2014 <a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/10\/18\/phishy-text-message-tries-to-steal-your-cellphone-account\/\">Phishy text message tries to steal your cellphone account \u2014 nakedsecurity.sophos.com\/\u2026<\/a><\/li>\n<\/ul>\n<\/li>\n<li>Notable Breaches &amp; Privacy Violations\n<ul>\n<li>&#x2b50;&#xfe0f; Twitter admits to accidentally using cellphone numbers provided for 2FA for targeted ads \u2014 <a href=\"https:\/\/help.twitter.com\/en\/information-and-ads\">help.twitter.com\/\u2026<\/a> &amp; <a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/10\/10\/twitter-used-2fa-phone-numbers-for-targeted-advertising\/\">nakedsecurity.sophos.com\/\u2026<\/a><\/li>\n<\/ul>\n<\/li>\n<li>News\n<ul>\n<li>&#x2b50;&#xfe0f; Patrick Wardle, a well respected security researcher who focuses on Apple technologies has published details on a trojan Bitcoin app for the Mac being distributed through a front company by a hacking group associated with the North Korean government. The malware provides the attackers remote control of the infected Mac, and is part of an on-going campaign by the group to steal Bitcoins \u2014 <a href=\"https:\/\/www.forbes.com\/sites\/thomasbrewster\/2019\/10\/14\/apple-mac-hack-warning-north-korea-uses-fake-cryptocurrency-companies-to-break-into-macos\/#82098126cc24\">www.forbes.com\/\u2026<\/a><\/li>\n<li>&#x2b50;&#xfe0f; &#x1f1ec;&#x1f1e7; <a href=\"https:\/\/www.bbc.co.uk\/news\/technology-50073102\">UK&#8217;s controversial &#8216;porn blocker&#8217; plan dropped \u2014 www.bbc.co.uk\/\u2026<\/a><\/li>\n<li>Facebook News:\n<ul>\n<li><a href=\"https:\/\/www.imore.com\/facebook-announces-two-year-project-combat-grooming-and-child-exploitation-its-platforms\">Facebook announces two-year project to combat grooming and child exploitation on its platforms \u2014 www.imore.com\/\u2026<\/a><\/li>\n<li><a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/10\/11\/facebook-flags-thousands-of-kids-as-interested-in-gambling-booze\/\">Facebook flags thousands of kids as interested in gambling, booze \u2014 nakedsecurity.sophos.com\/\u2026<\/a><\/li>\n<li><a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/10\/16\/facebooklockout-users-who-report-fake-scam-accounts-locked-out\/\">#FacebookLockout: Users who report fake\/scam accounts locked out \u2014 nakedsecurity.sophos.com\/\u2026<\/a><\/li>\n<\/ul>\n<\/li>\n<li>&#x1f1fa;&#x1f1f8; <a href=\"https:\/\/www.imore.com\/nyc-district-attorneys-office-has-been-able-break-iphones-january-2018\">Report suggests NYC District Attorney&#8217;s office has been able to break into iPhones since January 2018 \u2014 www.imore.com\/\u2026<\/a><\/li>\n<li>&#x1f1fa;&#x1f1f8; <a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/10\/10\/california-outlaws-facial-recognition-in-police-bodycams\/\">California outlaws facial recognition in police bodycams \u2014 nakedsecurity.sophos.com\/\u2026<\/a><\/li>\n<li>&#x1f1fa;&#x1f1f8; <a href=\"https:\/\/www.oregonlive.com\/news\/2019\/10\/oregon-judge-ordered-woman-to-type-in-her-iphone-passcode-so-police-could-search-it-for-evidence-against-her.html\">Oregon judge ordered woman to type in her iPhone passcode so police could search it for evidence against her \u2014 www.oregonlive.com\/\u2026<\/a><\/li>\n<li>&#x1f1eb;&#x1f1f7; <a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/10\/08\/nationwide-facial-recognition-program-underway-in-france\/\">Nationwide facial recognition ID program underway in France \u2014 nakedsecurity.sophos.com\/\u2026<\/a><\/li>\n<\/ul>\n<\/li>\n<li>Opinion &amp; Analysis\n<ul>\n<li>&#x2b50;&#xfe0f; <a href=\"https:\/\/pxlnv.com\/blog\/one-year-after-big-hack\/\">One Year After \u2018The Big Hack\u2019 \u2014 Pixel Envy \u2014 pxlnv.com\/\u2026<\/a>\n<ul>\n<li><strong>Related:<\/strong> while it seems clearer than ever that Bloomberg cried wolf in their sensational story last year, the danger is none-the-less real, as demonstrated by this story: <a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/10\/14\/soldering-spy-chips-inside-firewalls-is-now-a-cheap-hack-shows-researcher\/\">Soldering spy chips inside firewalls is now a cheap hack, shows researcher \u2014 nakedsecurity.sophos.com\/\u2026<\/a><\/li>\n<\/ul>\n<\/li>\n<li>&#x2b50;&#xfe0f; <a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/10\/09\/copy-and-paste-sharing-on-stack-overflow-spreads-insecure-code\/\">Copy-and-paste sharing on Stack Overflow spreads insecure code \u2014 nakedsecurity.sophos.com\/\u2026<\/a><\/li>\n<li>&#x2b50;&#xfe0f; In a briefing note sent to US corporations the FBI warns of common techniques in the use in the wild for bypassing 2FA. SIM swapping tops the list, with real-time phishing attacks that ask for username, password &amp; one-time code and use them instantly being the next biggest danger \u2014 <a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/10\/11\/hackers-bypassing-some-types-of-2fa-security-fbi-warns\/\">nakedsecurity.sophos.com\/\u2026<\/a><\/li>\n<li>Tom Burt, Microsoft VP for Customer Security &amp; Trust shared details of Iranian state-sponsored hacking Microsoft have observed attacking many targets including US Presidential campaigns \u2014 <a href=\"https:\/\/blogs.microsoft.com\/on-the-issues\/2019\/10\/04\/recent-cyberattacks-require-us-all-to-be-vigilant\/\">blogs.microsoft.com\/\u2026<\/a><\/li>\n<li><a href=\"https:\/\/www.nytimes.com\/interactive\/2019\/10\/11\/technology\/flickr-facial-recognition.html\">How Photos of Your Kids Are Powering Surveillance Technology \u2014 www.nytimes.com\/\u2026<\/a><\/li>\n<li><a href=\"https:\/\/www.fastcompany.com\/90416822\/googles-auto-delete-tools-are-practically-worthless-for-privacy\">Google\u2019s auto-delete tools are practically worthless for privacy \u2014 www.fastcompany.com\/\u2026<\/a><\/li>\n<\/ul>\n<\/li>\n<li>Propellor Beanie Territory\n<ul>\n<li><a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/10\/07\/wi-fi-signals-let-researchers-id-people-through-walls-from-their-gait\/\">Wi-Fi signals let researchers ID people through walls from their gait \u2014 nakedsecurity.sophos.com\/\u2026<\/a><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h3>Palate Cleansers<\/h3>\n<ul>\n<li>After many years of trying, security researchers have finally cracked the password used by the famous Unix co-creator Ken Thompson in 1980. It turns out to have been a great password for the time \u2014 hard to guess, but given his love of chess, easy for him to remember: <code>p\/q2-q4!<\/code> (it&#8217;s so-called <em>descriptive notation<\/em> for an opening chess move). Thanks to the same set of ancient hashes we&#8217;ve known for some time that BASH author Stephen Bourne had a much more lax attitude to security since his password was <code>bourne<\/code>, as did Eric Schmidt who used his wife&#8217;s name and some exclamation marks (<code>wendy!!!<\/code>). Finally, we know that famous C-guru and Unix co-creator Brian Kernighan used the secure-looking but utterly insecure <code>\/.,\/.,<\/code> (try type it and you&#8217;ll see it&#8217;s no better than <code>qwerty<\/code>) \u2014 <a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/10\/14\/computing-enthusiast-cracks-ancient-unix-code\/\">nakedsecurity.sophos.com\/\u2026<\/a><\/li>\n<\/ul>\n<p><em><strong>Note:<\/strong> When the textual description of a link is part of the link it is the title of the page being linked to, when the text describing a link is not part of the link it is a description written by Bart.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security Medium 1 \u2014 Apple Card is not Magic A story made a lot of news this week because it involved a physical Apple Card being skimmed. It underlines the fact that people do not understand that when they fall back to using the physical card or entering the virtual number into a website manually, [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":19030,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[147,214],"tags":[46,3612,50,569,3613],"class_list":["post-19504","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog-posts","category-security-bits","tag-apple","tag-apple-card","tag-security","tag-security-bits","tag-tencent"],"jetpack_featured_media_url":"https:\/\/www.podfeet.com\/blog\/wp-content\/uploads\/2019\/08\/security_bits_logo_400px_no_alpha.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/posts\/19504","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/comments?post=19504"}],"version-history":[{"count":1,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/posts\/19504\/revisions"}],"predecessor-version":[{"id":19505,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/posts\/19504\/revisions\/19505"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/media\/19030"}],"wp:attachment":[{"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/media?parent=19504"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/categories?post=19504"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/tags?post=19504"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}