{"id":28132,"date":"2023-04-16T13:40:15","date_gmt":"2023-04-16T20:40:15","guid":{"rendered":"https:\/\/www.podfeet.com\/blog\/?p=28132"},"modified":"2023-04-18T06:36:45","modified_gmt":"2023-04-18T13:36:45","slug":"sb-2023-03-16","status":"publish","type":"post","link":"https:\/\/www.podfeet.com\/blog\/2023\/04\/sb-2023-03-16\/","title":{"rendered":"Security Bits \u2014 16 April 2023"},"content":{"rendered":"<h2>Deep Dive 1 \u2014 Opera&#8217;s &#8216;VPN&#8217; is Useful but Poorly Named<\/h2>\n<p>Opera made some news by expanding out their free in-browser security feature they call a VPN to iOS, this makes the feature truly cross-platform, covering Windows, Mac, Android, and now iOS. This news triggered me to look into the feature before linking to the story, because the name implies this is a VPN service, and that simply toggling a button in the app&#8217;s settings will magically protect you like a true VPN does \u2014 <strong>it does not<\/strong>!<\/p>\n<p>I was deeply suspicious, but it took quite a bit of sleuthing to get a proper understanding of what&#8217;s going on, because almost every news story just slightly re-phrased the official press release, without adding context, detail, or frankly, value.<\/p>\n<p><em><strong>Aside\/Rant:<\/strong> my hunt for details was an eye-opening experience from which I&#8217;ve concluded that a lot of so-called &#8216;journalists&#8217; are very likely to be replaced by Chat GPT soon, because they&#8217;re already useless insight-free noise!<\/em><\/p>\n<p>I had two concerns:<\/p>\n<ol>\n<li>Opera are a for-profit company, how are are they offering a free VPN service that they claim respects privacy?<\/li>\n<li>How could it be technically possible for a browser to contain a true VPN?<\/li>\n<\/ol>\n<p>The few good articles I found on the topic all addressed the <em>&#8216;follow the money&#8217;<\/em> question, and this excerpt from TechCrunch summarises the company&#8217;s response to the question well:<\/p>\n<blockquote><p>\n  &#8220;The company is able to offer free tools to end users because it generates revenue through other channels, including search and ad revenues, as well as technology licensing fees. It\u2019s projecting $370 &#8211; $390 million in revenues for 2023, for instance.&#8221; \u2014 Tech Crunch\n<\/p><\/blockquote>\n<p>Tech Crunch then goes on to point out that despite the company being headquartered in Oslo (Norway), and GDPR compliant, there is some concern over the fact that there are significant Chinese shareholders. Given their HQ is in Oslo I think they&#8217;re probably safe from formal CCP (Chinese Communist Party) interference (I&#8217;m sure they&#8217;re being targeted by espionage just like every other major company in the world!)<\/p>\n<p>But what about the tech? Honestly, I think it&#8217;s disgraceful that the company are using a technical term with a real technical meaning to describe a service that does not meet that technical meaning at all. If you just look at the non-jargon plain-English definitions of the word you can sorta-kinda stretch them to cover what the product does, but I can&#8217;t honestly describe this as anything less than misleading. <strong>This &#8216;VPN&#8217; service does not use any VPN protocols!<\/strong><\/p>\n<p>A true VPN is a low-level networking concept where a virtual network interface is added to the OS \u2014 it looks as if you added an extra ethernet or wifi card! But instead of being a hardware device, this network interface uses software to wrap all the traffic routed through it in strong encryption, and then sends the encrypted packets over the internet to another computer somewhere else in the world where the reverse happens.<\/p>\n<p>What Opera is doing is different, it is using a TLS (basically HTTPS) connection from the browser app to their server to send the browsers DNS &amp; HTTP(S) requests to Opera servers, which then forwards them out to the internet. This means it is the browser&#8217;s traffic that is encrypted <strong>and only the browser&#8217;s traffic<\/strong> that is encrypted.<\/p>\n<p>While the technology is not the same, functionally, this is equivalent to Apple&#8217;s Safe Browsing feature in iCloud Plus, but because they are marketing it as a VPN, it sounds like it does more. The difference is that Apple&#8217;s branding is honest, while Opera&#8217;s is misleading!<\/p>\n<p>Best-case, this is just marketing peeps getting away with too much, but it leaves a really bad taste in my mouth. As I see it, either management are ignorant, spineless, or dishonest, and none of those options are good enough IMO, so I will not be recommending this to anyone.<\/p>\n<h3>Links<\/h3>\n<ul>\n<li><a href=\"https:\/\/techcrunch.com\/2023\/04\/12\/opera-brings-its-free-vpn-to-ios-to-rival-apple-and-googles-paid-alternatives\/\">Opera brings its free VPN to iOS to rival Apple and Google\u2019s paid alternatives \u2014 techcrunch.com\/\u2026<\/a><\/li>\n<li><a href=\"https:\/\/techweez.com\/2023\/04\/12\/opera-brings-free-vpn-to-ios\/\">Opera Brings Free VPN to iOS, But We Still Can\u2019t Recommend It \u2014 techweez.com\/\u2026<\/a><\/li>\n<\/ul>\n<h2>Deep Dive 2 \u2014 What&#8217;s Apple&#8217;s (Relatively) New &#8216;Rapid Security Response&#8217; Feature?<\/h2>\n<p><em><strong>Note:<\/strong> This segment is a special request from Allison, who came across a feature she didn&#8217;t recognise on a popular Apple fan site, and asked that I explain it on the show.<\/em><\/p>\n<p>At last summer&#8217;s WWDC Apple announced an up-coming improvement to how they would handle critical security updates, which they branded <em>Rapid Security Response<\/em>. However, it was one of those features they promised would be coming &#8216;later&#8217;, rather than shipping with the initial releases of macOS 13 &amp; iOS 16. I made a mental note to myself that we needed to talk about <em>Rapid Security Response<\/em> on this segment when it went live, but we never did. Why? Because new of it&#8217;s launch with macOS 13.2 and iOS 16.2 in January 2023 got drowned out by the more dramatic advanced iCloud protections that also went live with those releases.<\/p>\n<p>So, what changed in January? To understand that, let&#8217;s remind our selves about how things worked before January.<\/p>\n<p>OS updates contained a mix of feature releases, bug fixes, and security patches. Automatic software updates were not just supported, but positively encouraged, with Apple nudging users towards turning them on. But, even with automatic updates on, most people&#8217;s devices didn&#8217;t get updated straight away, Apple intentionally staggered the updates over multiple weeks, starting with a small cohort of devices, then ramping up as it became clearer the updates were free from unintended side-effects. This is absolutely fine for new features, and acceptable for bug fixes, but it&#8217;s not nearly good enough for security updates.<\/p>\n<p>What Apple have done now is split the important security updates out into a completely different mechanism, designed to deliver small targeted security fixes quickly, without delay. Because the changes are tightly focuses on fixing specific security vulnerabilities they are much less likely to break things, and of course, they&#8217;re much smaller, so there&#8217;s no need to wait for the device to have a good internet connection before starting the automated download. Also, because they will be more tightly focused, Apple can avoid the need for reboots most of the time.<\/p>\n<p>The feature us on by default, so you don&#8217;t have to do anything to benefit from this enhanced protection. Just know that since January, Apple&#8217;s latest OSes are just that little bit easier to keep secure &#x1f642;<\/p>\n<h3>Links<\/h3>\n<ul>\n<li>The article that piqued Allison&#8217;s interest: <a href=\"https:\/\/9to5mac.com\/2023\/04\/08\/apples-separation-of-security-and-features\/\">Apple\u2019s separation of security and features \u2013 a game-changer for device security \u2014 9to5mac.com\/\u2026<\/a><\/li>\n<li>A good overview of the feature: <a href=\"https:\/\/www.igeeksblog.com\/how-to-enable-rapid-security-response-updates\/\">What is Apple Rapid Security Response update, and how to enable it? \u2014 www.igeeksblog.com\/\u2026<\/a><\/li>\n<\/ul>\n<h2>&#x2757; Action Alerts<\/h2>\n<aside class=\"small-aside\">Calls to action, if any stories in this section are relevant to you there is some action you should take.<\/aside>\n<ul>\n<li><a href=\"https:\/\/nakedsecurity.sophos.com\/2023\/04\/08\/apple-issues-emergency-patches-for-spyware-style-0-day-exploits-update-now\/\">Apple issues emergency patches for spyware-style 0-day exploits \u2013 update now! \u2014 nakedsecurity.sophos.com\/\u2026<\/a> &amp; <a href=\"https:\/\/tidbits.com\/2023\/04\/07\/ios-16-4-1-ipados-16-4-1-and-macos-13-3-1-address-serious-security-vulnerabilities-fix-bugs\/\">iOS 16.4.1, iPadOS 16.4.1, and macOS 13.3.1 Address Serious Security Vulnerabilities, Fix Bugs \u2014 tidbits.com\/\u2026<\/a>\n<ul>\n<li><a href=\"https:\/\/nakedsecurity.sophos.com\/2023\/04\/10\/apple-zero-day-spyware-patches-extended-to-cover-older-macs-iphones-and-ipads\/\">Apple zero-day spyware patches extended to cover older Macs, iPhones and iPads \u2014 nakedsecurity.sophos.com\/\u2026<\/a>, <a href=\"https:\/\/appleinsider.com\/articles\/23\/04\/10\/apple-issues-ios-1575-ipados-1575-macos-monterey-big-sur-security-updates\">Apple issues iOS 15.7.5, iPadOS 15.7.5, macOS Monterey, Big Sur security updates \u2014 appleinsider.com\/\u2026<\/a> &amp; <a href=\"https:\/\/tidbits.com\/watchlist\/safari-16-4-1\/\">Safari 16.4.1 \u2014 tidbits.com\/\u2026<\/a><\/li>\n<li><a href=\"https:\/\/appleinsider.com\/articles\/23\/04\/12\/apple-rolls-out-tvos-1641-and-homepod-software-version-1641\">Apple rolls out tvOS 16.4.1 and HomePod software version 16.4.1 \u2014 appleinsider.com\/\u2026<\/a><\/li>\n<\/ul>\n<\/li>\n<li><a href=\"https:\/\/nakedsecurity.sophos.com\/2023\/04\/12\/microsoft-fixes-a-zero-day-and-two-curious-bugs-that-take-the-secure-out-of-secure-boot\/\">Patch Tuesday: Microsoft fixes a zero-day, and two curious bugs that take the Secure out of Secure Boot \u2014 nakedsecurity.sophos.com\/\u2026<\/a> <\/li>\n<\/ul>\n<h2>Worthy Warnings<\/h2>\n<aside class=\"small-aside\">Potentially relevant warnings from government organisations, public interest groups, or the security community.<\/aside>\n<ul>\n<li><a href=\"https:\/\/techcrunch.com\/2023\/04\/10\/twitter-circle-bug-not-private\/\">Twitter Circle tweets are not that private anymore \u2014 techcrunch.com\/\u2026<\/a> (<strong>Editorial by Bart:<\/strong> my advice is to just assume everything you type into Twitter is probably gonna leak at some stage, even your DMs!)<\/li>\n<li>Owners of Nexx IoT devices (including garage door openers and alarm systems!) need to be aware that the products have catastrophic security design flaws \u2014 <a href=\"https:\/\/nakedsecurity.sophos.com\/2023\/04\/05\/us-government-warning-what-if-anyone-could-open-your-garage-door\/\">nakedsecurity.sophos.com\/\u2026<\/a>\n<ul>\n<li>&#x1f1fa;&#x1f1f8; Official Advisory from the US Cybersecurity &amp; Infrastructure Security Agency (CISA) \u2014 <a href=\"https:\/\/www.cisa.gov\/news-events\/ics-advisories\/icsa-23-094-01\">www.cisa.gov\/\u2026<\/a><\/li>\n<\/ul>\n<\/li>\n<li>&#x1f1fa;&#x1f1f8; <a href=\"https:\/\/appleinsider.com\/articles\/23\/04\/05\/efile-tax-website-served-malware-to-visitors-for-weeks\">eFile tax website served malware to visitors for weeks \u2014 appleinsider.com\/\u2026<\/a> (Officially authorised by the IRS!)<\/li>\n<li><a href=\"https:\/\/nakedsecurity.sophos.com\/2023\/04\/11\/attention-gamers-motherboard-maker-msi-admits-to-breach-issues-rogue-firmware-alert\/\">Attention gamers! Motherboard maker MSI admits to breach, issues \u201crogue firmware\u201d alert \u2014 nakedsecurity.sophos.com\/\u2026<\/a> (It&#8217;s possible they&#8217;ve lost their private keys, so don&#8217;t rely on digital signatures to verify files \u2014 follow MSI&#8217;s advice and only install drivers downloaded directly from their official)<\/li>\n<li><a href=\"https:\/\/appleinsider.com\/articles\/23\/04\/06\/customers-still-cant-access-my-cloud-data-after-western-digital-hack-fallout\">Customers still can&#8217;t access My Cloud data after Western Digital hack fallout \u2014 appleinsider.com\/\u2026<\/a> (WD still investigating, so not clear yet how bad this is)<\/li>\n<\/ul>\n<h2>Notable News<\/h2>\n<ul>\n<li>Citizen Lab have released findings highlighting the existence of another NSO Group-like grey-hat security firm in Israel selling Pagasus-like spyware to governments around the world, this time it&#8217;s <em>Reign<\/em> by <em>QuaDream<\/em> \u2014 <a href=\"https:\/\/appleinsider.com\/articles\/23\/04\/11\/another-pegasus-like-spyware-tool-called-reign-was-used-to-spy-on-iphones\">appleinsider.com\/\u2026<\/a><\/li>\n<li>The US Government has re-issued its previous PSA reminding people to avoid plugging their phone into other people&#8217;s chargers. There&#8217;s no actual new info in the PSA, and nothing has actually happened, but for some reason this mundane PSA triggered a wave of news stories as if there had suddenly been a surge in attacks or something like that: <a href=\"https:\/\/krebsonsecurity.com\/2023\/04\/why-is-juice-jacking-suddenly-back-in-the-news\/\">Why is \u2018Juice Jacking\u2019 Suddenly Back in the News? \u2014 krebsonsecurity.com\/\u2026<\/a>\n<ul>\n<li>Good advice to bookmark and share with friends &amp; family: <a href=\"https:\/\/www.cultofmac.com\/812486\/avoid-juice-jacking-at-public-iphone-charging-stations\/\">6 ways to avoid \u2018juice jacking\u2019 at public iPhone charging stations \u2014 www.cultofmac.com\/\u2026<\/a><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h2>Palate Cleansers<\/h2>\n<aside class=\"small-aside\">Anything upbeat and nerdy Bart and\/or Allison think you might enjoy.<\/aside>\n<ul>\n<li>Some impressive Math nerdery you can get as a cookie cutter: <a href=\"https:\/\/nakedsecurity.sophos.com\/2023\/04\/04\/einstein-tilings-the-amazing-hat-shape-that-never-repeats\/\">Einstein tilings \u2013 the amazing \u201cHat\u201d shape that never repeats! \u2014 nakedsecurity.sophos.com\/\u2026<\/a><\/li>\n<\/ul>\n<h2>Legend<\/h2>\n<p>When the textual description of a link is part of the link it is the title of the page being linked to, when the text describing a link is not part of the link it is a description written by <a href=\"https:\/\/bartb.ie\/\">Bart<\/a>.<\/p>\n<table>\n<thead>\n<tr>\n<th align=\"center\">Emoji<\/th>\n<th align=\"left\">Meaning<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td align=\"center\">&#x1f3a7;<\/td>\n<td align=\"left\">A link to <strong>audio content<\/strong>, probably a podcast.<\/td>\n<\/tr>\n<tr>\n<td align=\"center\">&#x2757;<\/td>\n<td align=\"left\">A <strong>call to action<\/strong>.<\/td>\n<\/tr>\n<tr>\n<td align=\"center\"><em>flag<\/em><\/td>\n<td align=\"left\">The story is particularly relevant to people living in a <strong>specific country<\/strong>, or, the organisation the story is about is affiliated with the government of a specific country.<\/td>\n<\/tr>\n<tr>\n<td align=\"center\">&#x1f4ca;<\/td>\n<td align=\"left\">A link to <strong>graphical content<\/strong>, probably a chart, graph, or diagram.<\/td>\n<\/tr>\n<tr>\n<td align=\"center\">&#x1f9ef;<\/td>\n<td align=\"left\">A story that has been <strong>over-hyped<\/strong> in the media, or, <em>&#8220;no need to light your hair on fire&#8221;<\/em> &#x1f642;<\/td>\n<\/tr>\n<tr>\n<td align=\"center\">&#x1f4b5;<\/td>\n<td align=\"left\">A link to an article behind a <strong>paywall<\/strong>.<\/td>\n<\/tr>\n<tr>\n<td align=\"center\">&#x1f4cc;<\/td>\n<td align=\"left\">A <strong>pinned<\/strong> story, i.e. one to keep an eye on that&#8217;s likely to develop into something significant in the future.<\/td>\n<\/tr>\n<tr>\n<td align=\"center\">&#x1f3a9;<\/td>\n<td align=\"left\">A <strong><em>tip of the hat<\/em><\/strong> to thank a member of the community for bringing the story to our attention.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>Deep Dive 1 \u2014 Opera&#8217;s &#8216;VPN&#8217; is Useful but Poorly Named Opera made some news by expanding out their free in-browser security feature they call a VPN to iOS, this makes the feature truly cross-platform, covering Windows, Mac, Android, and now iOS. This news triggered me to look into the feature before linking to the [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":19030,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[147,214],"tags":[46,5822,5819,5820,5821,5823,50,2239,2388,142],"class_list":["post-28132","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog-posts","category-security-bits","tag-apple","tag-apple-rapid-security-response","tag-opera","tag-opera-vpn","tag-rapid-security-response","tag-securit-bits","tag-security","tag-security-updates","tag-updates","tag-vpn"],"jetpack_featured_media_url":"https:\/\/www.podfeet.com\/blog\/wp-content\/uploads\/2019\/08\/security_bits_logo_400px_no_alpha.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/posts\/28132","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/comments?post=28132"}],"version-history":[{"count":3,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/posts\/28132\/revisions"}],"predecessor-version":[{"id":28148,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/posts\/28132\/revisions\/28148"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/media\/19030"}],"wp:attachment":[{"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/media?parent=28132"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/categories?post=28132"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/tags?post=28132"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}