{"id":36728,"date":"2026-09-27T12:13:29","date_gmt":"2026-09-27T19:13:29","guid":{"rendered":"https:\/\/www.podfeet.com\/blog\/?p=36728"},"modified":"2026-09-27T12:13:29","modified_gmt":"2026-09-27T19:13:29","slug":"sb-2026-09-27","status":"publish","type":"post","link":"https:\/\/www.podfeet.com\/blog\/2026\/09\/sb-2026-09-27\/","title":{"rendered":"Security Bits \u2014 27 September 2026"},"content":{"rendered":"<h2>Feedback &amp; Followups<\/h2>\n<aside class=\"small-aside\">Listener and community feedback, developments in recently covered stories, and developments in long-running stories we&#8217;re tracking over time.<\/aside>\n<ul>\n<li>After their first attempt received a lot of negative user feedback, Discord has redesigned their age-verification system: <a href=\"https:\/\/cyberinsider.com\/discord-rolls-out-age-checks-that-dont-require-an-id-or-selfie\/\">Discord rolls out age checks that don\u2019t require an ID or selfie \u2014 cyberinsider.com\/\u2026<\/a>\n<ul>\n<li><em>&#8220;The company says more than 90% of users will be assigned an age group automatically, while those who need to confirm they are adults can choose from several methods, including credit cards, Apple App Store or Google Play age-range sharing, Google Wallet, AgeKey, video selfies, or ID scans.&#8221;<\/em> \u2014 Cyber Insider<\/li>\n<\/ul>\n<\/li>\n<li>More AI agent misbehaviour and revelations:\n<ul>\n<li><a href=\"https:\/\/cyberinsider.com\/openai-reveals-its-ai-agents-hid-mistakes-and-bypassed-restrictions\/\">OpenAI reveals its AI agents hid mistakes and bypassed restrictions \u2014 cyberinsider.com\/\u2026<\/a> (more alignment problems)<\/li>\n<li><a href=\"https:\/\/thehackernews.com\/2026\/09\/google-gemini-broke-into-real-company.html?m=1\">Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up \u2014 thehackernews.com\/\u2026<\/a> (not Agent escapes but yet another <em>&#8216;lab leak&#8217;<\/em>)<\/li>\n<li>\ud83c\udde6\ud83c\uddfa <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/openai-hacked-australian-medicare-govt-site-probed-data-providers\/\">OpenAI hacked Australian Medicare govt site, probed data providers \u2014 www.bleepingcomputer.com\/\u2026<\/a><\/li>\n<li><a href=\"https:\/\/www.bleepingcomputer.com\/news\/artificial-intelligence\/openais-ai-agents-accidentally-uploaded-user-provided-images-to-third-party-sites\/\">OpenAI&#8217;s AI agents accidentally uploaded user-provided images to third-party sites \u2014 www.bleepingcomputer.com\/\u2026<\/a> (images real-world users added to prompts!)<\/li>\n<li>Unsurprisingly, OpenAI&#8217;s decision to start advertising has incentivised them to create their own ad-tracker to facilitate targeted ads: <a href=\"https:\/\/cyberinsider.com\/chatgpt-advertising-system-reportedly-tracks-users-across-websites\/\">ChatGPT advertising system reportedly tracks users across websites \u2014 cyberinsider.com\/\u2026<\/a> (they have become just like Google and Meta \ud83d\ude41)<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h2>Listener Questions<\/h2>\n<aside class=\"small-aside\">Submit your questions for future shows to Allison using the contact details at the end of the show, or post them in the <em>security-bits<\/em> channel in the <a href=\"https:\/\/podfeet.com\/slack\" target=\"_blank\">Podfeet Slack<\/a>.<\/aside>\n<h3>Real-world ramifications of macOS 27 login keychain changes? (from Kantor)<\/h3>\n<blockquote><p>\n  Relating to this research by Howard Oakley: what are the real-world ramifications of Apple changing how the macOS Login keychain may be accessed? <a href=\"https:\/\/eclecticlight.co\/2026\/09\/14\/how-can-you-copy-or-restore-keychains\/\">https:\/\/eclecticlight.co\/2026\/09\/14\/how-can-you-copy-or-restore-keychains\/<\/a>\n<\/p><\/blockquote>\n<p><em><strong>TL;DR<\/strong> \u2014 for regular users, I can&#8217;t see any real-world impact.<\/em><\/p>\n<p>If you&#8217;ve never exported and imported your Login Keychain, you won&#8217;t notice anything has changed. Simply opening the Login keychain is now something Apple steer you away from \u2014 in macOS 26 they added an interception pop-up when you launch the Keychain Access utility that suggests you probably want the new Passwords app, and give you a button to open that instead!<\/p>\n<p>The closest thing I can see to a real-world impact is a slight boost in security, protecting device-specific secrets just a little bit more strongly, even from malware that managed to sneak onto your Mac.<\/p>\n<h4>What is the Login Keychain?<\/h4>\n<p>Since before macOS was even called macOS, Apple have provided a built-in encrypted storage mechanism for safely saving secrets. Apps use Apple&#8217;s Keychain APIs to securely store and read things like saved passwords, private keys, API credentials, and security tokens. Keychains are encrypted files, and users unlock them with a password.<\/p>\n<p>Users and apps are free to create their own keychains and set what ever passwords they like on them, but Apple provide some standard keychains.<\/p>\n<p>For as long as we&#8217;ve had keychains there have been at least three standard keychains:<\/p>\n<ol>\n<li>The <strong>System Roots keychain<\/strong> \u2014 this is part of the operating system, and it stores the public keys for all the certificate authorities our Macs trust. The information in this keychain is not actually secret, all they keys are public keys. The point of this keychain is to provide a trusted source for this vitally important information.<\/li>\n<li>The <strong>System keychain<\/strong> \u2014 this is also part of the OS, it contains secrets the OS needs access to in order to function, and the OS handles the locking and unlocking of this keychain automatically. Unless you&#8217;re very keen to break something, you should leave this keychain well and truly alone!<\/li>\n<li>Each account has a <strong>Login keychain<\/strong>. This keychain is connected to the user&#8217;s login password, and when the user logs in, they unlock this keychain.<\/li>\n<\/ol>\n<p>Before there was such a thing as the iCloud Keychain, all secrets from all apps that belonged to a user rather than the system as a whole were stored in the login keychain. Every password you entered into every well-written app, every password you saved in Safari, they all went into this keychain.<\/p>\n<p>But many years ago, Apple added a fourth standard keychain, the iCloud Keychain (now just called the Cloud Keychain). Initially, you had to opt in to using iCloud Keychain, and setting it up involved a lot of faffing about. But over time it&#8217;s become ever simpler to use, and today, you need to go out of your way <strong>not<\/strong> to have a Cloud keychain.<\/p>\n<p>The reason Apple added the iCloud Keychain was to allow secrets to securely synchronise between all your Apple devices. But Apple never intended all secrets to sync to all devices; <strong>some secrets are intended to be device-specific<\/strong>.<\/p>\n<p>A good example of this is that the security of end-to-end encryption depends on each <strong>device<\/strong> having a dedicated public and private key-pair, and for no device to <strong>ever<\/strong> share its private key in any way. That means that even after the introduction of the iCloud keychain, the Login keychain retains a very important role \u2014 it&#8217;s designed to hold device-specific secrets.<\/p>\n<p>Note that whether or not you choose to enable iCloud Keychain sync, you still have a keychain named iCloud Keychain or Cloud Keychain on every device; they&#8217;re just not kept in sync!<\/p>\n<p>So, that means that in versions of OS X and macOS since the introduction of the iCloud Keychain, the <em>&#8216;correct&#8217;<\/em> use of keychains changed \u2014 app developers that follow the guidelines are now expected to choose the appropriate keychain for each secret they store. Device-specific secrets should be stored in the Login keychain, and all other secrets in the Cloud keychain.<\/p>\n<p>That change was never going to happen overnight, and even today there are almost certainly still <strong>some<\/strong> legacy apps hiding somewhere that wrongly store non-device-specific secrets in the Login keychain. But I think that number is now so small it&#8217;s just not relevant for home users.<\/p>\n<p>I think <strong>it&#8217;s now reasonable to assume that any secret stored in your Login keychain was intentionally stored there to bind it to a specific device<\/strong>.<\/p>\n<h4>What did Apple Change?<\/h4>\n<p>Without going into technical details, Apple have cryptographically bound Login keychains to the devices they were created on. You can still export your Login keychain to a file, but that file can&#8217;t be opened without access to the secure enclave on the motherboard of the device it belongs to. That means you can time-shift your Login keychain, but you can&#8217;t move it from one Mac to another. The intended device-binding is now cryptographically enforced!<\/p>\n<p>Typical workflows don&#8217;t depend on exporting Login keychains at all, let alone exporting Login keychains on one Mac and importing them into another. If your workflow does depend on doing that, your workflow will break with macOS 27. I genuinely can&#8217;t conceive of a good reason to do this, but I may just not be imaginative enough.<\/p>\n<p>Finally, iPads and iPhones have had un-exportable Login keychains since the day they launched, and that hasn&#8217;t stopped any of us from backing up and restoring our data, or migrating it from one device to another. The Mac&#8217;s Login keychain will now behave like these devices always have.<\/p>\n<h4>Why did Apple Make the Change?<\/h4>\n<p>Simple \u2014 to boost security.<\/p>\n<p>One of the foundational assumptions for true end-to-end encryption is that private keys <strong>never<\/strong> leave the device they belong to. Before this change, that assumption was cryptographically enforced. Now it is!<\/p>\n<h2>Deep Dive \u2014 Beware Meta&#8217;s new Muse AI Agent<\/h2>\n<p>Meta have launched a new AI agent that lives in the cloud and can be accessed from apps on your phones and computers. Every Muse user gets their own virtual computer in Meta&#8217;s data centre that their specific agent runs in, and that virtual computer has a virtual browser that the agent can use to act on the user&#8217;s behalf any time, regardless of whether or not the user is even online.<\/p>\n<p>If you log the agent into online services, like your webmail interface, then the agent gets access to all that information, and can do anything you can do! That alone is something you should only grant to software that has <strong>really<\/strong> earned your trust. How many humans would you grant that kind of access to?<\/p>\n<p>But if you install the desktop app, you take this trust to a whole new level! The Muse Mac app requests full disk access!<\/p>\n<p>That means Muse can read <strong>everything<\/strong> on your Mac! The iPhone app can&#8217;t do that, it can only read more specific pieces of data that you grant access to one-by-one (all those prompts apps have to give to get to your contacts, calendar, photos, etc.).<\/p>\n<p>There is of course a big difference between permission and consent, especially <strong>informed<\/strong> consent!<\/p>\n<p>Unsurprisingly, Muse is surprising people, in creepy ways. Tech columnist Jason Aten&#8217;s experience with the agent is illuminating, and <a href=\"https:\/\/www.inc.com\/jason-aten\/metas-new-muse-ai-agent-read-my-private-messages-i-never-asked-it-to\/91408202\">Jason explains the problem well<\/a>:<\/p>\n<blockquote><p>\n  An AI agent isn\u2019t especially useful if it can\u2019t see your files, interact with your apps, or understand what you\u2019re working on. Meta says Muse is designed around that reality, while still putting users in control of what it can access.<\/p>\n<p>  \u2026\u00a0yesterday, I was having a conversation with my Primary Technology podcast co-host, Stephen Robles, about the new iPhones. Moments later, I got a push notification from Muse suggesting that the conversation we were having would make for a good column and offered to put together research for me to write about. It even flagged a message from my editor about having a column ready for Monday.<\/p>\n<p>  Not only had I not asked it to do that sort of thing, I never gave it permission to read my messages. In fact, I remember <strong>explicitly choosing not to let it have access to my messages, calendar, and other personal information<\/strong>.<\/p>\n<p>  Stranger still was what happened when I asked Muse how it knew. It told me it didn\u2019t have access to my message history at all. Instead, it said <strong>the Muse app on my Mac was simply passing along the text of incoming notification banners<\/strong>.\n<\/p><\/blockquote>\n<p>Jason did a little more digging, and Muse had actually started ingesting his messages database as a data source.<\/p>\n<p>Muse asked his preferences; he clearly expressed them \u2014 he did not authorise Muse to access his messages, contacts, or calendars, but he did authorise it to read his documents.<\/p>\n<p>However, at a technological level, the Mac app did not use the most restrictive possible API for accessing the data he had authorised; it used the opposite \u2014 the most powerful possible permission \u2014 it requested full disk access!<\/p>\n<p>So, the app was authorised to access his documents, but not his messages, but it had the OS-level permissions to get them anyway, so it did!<\/p>\n<p><strong>Muse asked for Jason&#8217;s trust, and within hours, had betrayed it!<\/strong><\/p>\n<p>My personal feelings on Muse align quite well with those of John Gruber, and he&#8217;s a much more eloquent writer than I am, so I&#8217;ll let <a href=\"https:\/\/daringfireball.net\/2026\/09\/ill_wait\">John explain<\/a>:<\/p>\n<blockquote><p>\n  The Muse iOS app is sandboxed\u2009\u2014\u2009because it has to be. So that\u2019s the only version I\u2019m personally tinkering with. But the Mac app is the more powerful one, because, well, it lets Muse drive your Mac. The fact that the Muse Mac app is so powerful is why it has to be downloaded from the web.<br \/>\n  \u2026<br \/>\n  The way I think about running an agentic AI on my Mac is simple. I would never let an unknown person use my Mac. Not even for a minute, not even with me watching them. Let alone letting them use it nonstop, without my watching them. I\u2019d be uncomfortable letting even a trusted friend use my Mac, logged into my user account. So why would I let an AI robot, no matter the source?\n<\/p><\/blockquote>\n<p>John is experimenting with the iOS version because it has technological barriers stopping it exceeding its authorisation like the Mac app can, and clearly does, but I&#8217;m not even prepared to do that!<\/p>\n<p>The concept of an always-on VM in the cloud acting as your AI agent is a good one, and someday, someone who has earned my trust will implement it, and I will cautiously start to experiment with it, but never with Meta, and not today. It&#8217;s still the absolute wild west of agentic AI, and I&#8217;m not keen on getting into the crossfire of any proverbial gunfights!<\/p>\n<h3>Links<\/h3>\n<ul>\n<li>Meta&#8217;s Overview of the Muse AI Agent \u2014 <a href=\"https:\/\/about.fb.com\/news\/2026\/09\/introducing-muse-personal-ai-agent\/\">about.fb.com\/\u2026<\/a><\/li>\n<li>Jason Aten&#8217;s article outlining his experience: <a href=\"https:\/\/www.inc.com\/jason-aten\/metas-new-muse-ai-agent-read-my-private-messages-i-never-asked-it-to\/91408202\">Meta\u2019s New Muse AI Agent Read My Private Messages. I Never Asked It To \u2014 www.inc.com\/\u2026<\/a><\/li>\n<li>John Gruber eloquently explains why he&#8217;s not installing Muse on his Mac: <a href=\"https:\/\/daringfireball.net\/2026\/09\/ill_wait\">I\u2019ll Wait \u2014 daringfireball.net\/\u2026<\/a> (I agree 100%)<\/li>\n<\/ul>\n<h2>\u2757 Action Alerts<\/h2>\n<aside class=\"small-aside\">Calls to action, if any stories in this section are relevant to you, there is some action you should take.<\/aside>\n<p><em><strong>Programming Note:<\/strong> I&#8217;ve adjusted my criteria for this section \u2014 individual WordPress Core and WordPress plugin vulnerabilities will only be included if they are truly exceptional in some way. If you run WordPress, I strongly advice keeping <strong>all<\/strong> automatic updates enabled, because the risk from rapidly weaponised new vulnerabilities is greater than the risk of a bad buggy update breaking something.<\/em><\/p>\n<ul>\n<li><a href=\"https:\/\/isc.sans.edu\/diary\/rss\/33336\">Apple Updates Everything \u2014 isc.sans.edu\/\u2026<\/a>\n<ul>\n<li>The \uf8ffOS 27 OSes all contain security fixes as well as the new features<\/li>\n<li><a href=\"https:\/\/appleinsider.com\/articles\/26\/09\/14\/apple-didnt-forget-about-updating-older-operating-systems\">Apple didn&#8217;t forget about updating older operating systems \u2014 appleinsider.com\/\u2026<\/a><\/li>\n<\/ul>\n<\/li>\n<li><a href=\"https:\/\/thehackernews.com\/2026\/09\/public-exploits-released-for-four-linux.html\">Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root \u2014 thehackernews.com\/\u2026<\/a> (patches released)<\/li>\n<li>\u26a0\ufe0f <strong>Pixel Phone Users:<\/strong> <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/google-fixes-actively-exploited-android-zero-day-on-pixel-devices\/\">Google fixes actively exploited Android zero-day on Pixel devices \u2014 www.bleepingcomputer.com\/\u2026<\/a><\/li>\n<li>\u26a0\ufe0f <strong>Windows users with Logitech Devices:<\/strong> <a href=\"https:\/\/cyberinsider.com\/logitech-options-flaw-lets-attackers-gain-windows-system-privileges\/\">Logitech Options+ flaw lets attackers gain Windows SYSTEM privileges \u2014 cyberinsider.com\/\u2026<\/a>\n<ul>\n<li>If you have Logitech Options+ installed to configure your device(s), patch it ASAP!<\/li>\n<\/ul>\n<\/li>\n<li>\u26a0\ufe0f <strong>Docker users on macOS:<\/strong> <a href=\"https:\/\/thehackernews.com\/2026\/09\/critical-docker-sandboxes-flaw-lets.html?m=1\">Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files \u2014 thehackernews.com\/\u2026<\/a> (patch!)<\/li>\n<li>\u26a0\ufe0f <strong>D-Link DIR-822A Router Users:<\/strong> <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/d-link-warns-of-max-severity-zero-day-bug-in-dir-822a-routers\/\">D-Link warns of max severity zero-day bug in DIR-822A routers \u2014 www.bleepingcomputer.com\/\u2026<\/a>\n<ul>\n<li>These are obsolete routers, so no patch!<\/li>\n<li>Time to recycle and replace!<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h2>Worthy Warnings<\/h2>\n<aside class=\"small-aside\">Potentially relevant warnings from government organisations, public interest groups, or the security community.<\/aside>\n<p><em><strong>Programming Note:<\/strong> based on listener responses in the <a href=\"https:\/\/podfeet.com\/slack\">Podfeet Slack<\/a>, I&#8217;ve adjusted my criteria for this section \u2014 individual data breaches will only be included if they are truly exceptional in some way. We&#8217;ve now arrived at the stage where we should all behave as if we have been involved in a data breach, because whether we know it or not, we almost certainly have!<\/em><\/p>\n<ul>\n<li>Beware tech documentation and examples that use the common placeholder domain <code>third-party.com<\/code>: <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/placeholder-domain-used-in-dev-docs-now-serves-clickfix-attacks\/\">Placeholder domain used in dev docs now serves ClickFix attacks \u2014 www.bleepingcomputer.com\/\u2026<\/a><\/li>\n<li>\u26a0\ufe0f <strong>Nintendo Switch Users:<\/strong> <a href=\"https:\/\/cyberinsider.com\/nintendo-warns-of-switch-code-execution-flaw-via-on-screen-qr-codes\/\">Nintendo warns of Switch code execution flaw via on-screen QR codes \u2014 cyberinsider.com\/\u2026<\/a><\/li>\n<li>\u26a0\ufe0f <strong>GitLab.com Users:<\/strong> <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/exposed-gitlab-project-email-addresses-let-attackers-push-code\/\">Exposed GitLab project email addresses let attackers push code \u2014 www.bleepingcomputer.com\/\u2026<\/a> (an alternative to GitHub)<\/li>\n<\/ul>\n<h2>Notable News<\/h2>\n<ul>\n<li>\ud83e\uddef<a href=\"https:\/\/arstechnica.com\/security\/2026\/09\/theres-a-new-way-to-break-rsa-thats-faster-than-anything-weve-seen-before\/\">There\u2019s a new way to break RSA that\u2019s faster than anything we\u2019ve seen before \u2014 arstechnica.com\/\u2026<\/a>\n<ul>\n<li><em>\u201cThe practical risk is limited, but still significant. Applying the attack against the deprecated use of 1024-bit keys took a handful of months on an academic CPU cluster, significantly less than the current estimates for 1024-bit factoring that would require resources that only nations or companies with massive resources could achieve. Widely used RSA implementations are also safe.\u201d<\/em> \u2014 Ars Technica<\/li>\n<li>Thankfully, 2048 has been the default key length for some time now<\/li>\n<li>If you are still using any older RSA keys, now would be a good time to replace them with more modern keys<\/li>\n<\/ul>\n<\/li>\n<li>\ud83c\uddea\ud83c\uddfa \ud83c\uddee\ud83c\uddea <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/google-fined-403-million-over-location-data-privacy-violations\/\">Google fined \u20ac403 million over location data privacy violations \u2014 www.bleepingcomputer.com\/\u2026<\/a> (Fine imposed by the Irish Data Protection Commissioner because Google&#8217;s EU HQ is in Dublin; they also have six months to make changes)<\/li>\n<li>Nice little security improvements:\n<ul>\n<li><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/homebrew-700-gets-built-in-gui-better-security-controls\/\">Homebrew 7.0.0 gets built-in GUI, better security controls \u2014 www.bleepingcomputer.com\/\u2026<\/a><\/li>\n<li><em>&#8220;\u2026 a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI graphical interface \u2026&#8221;<\/em> \u2014 Bleeping Computer<\/li>\n<li><a href=\"https:\/\/thehackernews.com\/2026\/09\/wordpress-adds-automated-plugin-reviews.html\">WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution \u2014 thehackernews.com\/\u2026<\/a><\/li>\n<li>This will help protect against supply-chain attacks where legitimate plugins are poisoned with malicious updates, making automatic updates even less likely to cause problems.<\/li>\n<li><a href=\"https:\/\/cyberinsider.com\/signal-tests-account-registration-without-phone-number-on-android\/\">Signal tests account registration without phone number on Android \u2014 cyberinsider.com\/\u2026<\/a><\/li>\n<li>This is the next step on Signal&#8217;s road-map to removing the need to connect a cellphone number to a Signal account.<\/li>\n<li>Face ID is just a little bit more secure on iPhones 18 Pro: <a href=\"https:\/\/appleinsider.com\/articles\/26\/09\/22\/supplemental-image-data-used-in-face-id-authentication-on-iphone-18-pro\">Supplemental image data used in Face ID authentication on iPhone 18 Pro \u2014 appleinsider.com\/\u2026<\/a><\/li>\n<li><a href=\"https:\/\/cyberinsider.com\/operas-free-vpn-now-turns-on-automatically-on-public-wi-fi\/\">Opera\u2019s free VPN now turns on automatically on public Wi-Fi \u2014 cyberinsider.com\/\u2026<\/a><\/li>\n<li><a href=\"https:\/\/cyberinsider.com\/meta-brings-private-processing-privacy-protections-to-ai-glasses\/\">Meta brings Private Processing privacy protections to AI glasses \u2014 cyberinsider.com\/\u2026<\/a><\/li>\n<li><em>&#8220;Meta is expanding its Private Processing infrastructure to AI glasses, allowing cloud-based AI to analyze personal context while preventing Meta itself from accessing the underlying data. The system combines confidential computing, hardware-backed isolation, anonymous routing, remote attestation, and encrypted storage to protect information during processing.&#8221;<\/em> \u2014 Cyber Insider<\/li>\n<li>Sounds good, assuming their implementation is robust \ud83e\udd1e<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h2>Interesting Insights<\/h2>\n<aside class=\"small-aside\">High-quality opinion and editorial content recommended by Bart.<\/aside>\n<ul>\n<li>Unlike most AI tools, Apple allow users to see the system prompts; Glenn Fleishman explains how: <a href=\"https:\/\/tidbits.com\/2026\/09\/23\/see-the-behind-the-scenes-prompts-that-power-siri-ai\/\">See the Behind-the-Scenes Prompts That Power Siri AI \u2014 tidbits.com\/\u2026<\/a>\n<ul>\n<li>A great example of Apple following through on their privacy and transparency promises!<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h2>Just Because it&#8217;s Cool \ud83d\ude0e<\/h2>\n<aside class=\"small-aside\">Stories that are not important, that don&#8217;t require you to do anything, and that you don&#8217;t even have to worry about.<\/aside>\n<ul>\n<li>Ever wonder how Apple gets fully patched versions of iOS onto iPhones built months before launch day? Here&#8217;s how: <a href=\"https:\/\/www.cultofmac.com\/news\/ios-27-onto-18-pro-units-for-launch\">How Apple gets iOS 27 onto millions of iPhone 18 Pro units in time for launch \u2014 www.cultofmac.com\/\u2026<\/a><\/li>\n<\/ul>\n<h2>Palate Cleansers<\/h2>\n<aside class=\"small-aside\">Anything upbeat and nerdy Bart and\/or Allison think you might enjoy.<\/aside>\n<ul>\n<li><strong>From Bart:<\/strong>\n<ul>\n<li><strong>Follow-up:<\/strong> Firefox users who want something like my Litterbox Safari Extension recommendation from last time are in luck: <a href=\"https:\/\/daringfireball.net\/linked\/2026\/09\/14\/dumpster-fire\">Dumpster Fire \u2013 Litterbox-Inspired Extension for Firefox \u2014 daringfireball.net\/\u2026<\/a><\/li>\n<li>The wonderful macOS app-deleting app App Zapper is back, and as zany as ever: <a href=\"https:\/\/appzapper.com\/\">appzapper.com\/\u2026<\/a><\/li>\n<li>John Gruber puts it into context wonderfully: <a href=\"https:\/\/daringfireball.net\/2026\/09\/appzapper_3000\">AppZapper 3000 \u2014 daringfireball.net\/\u2026<\/a><\/li>\n<li>\ud83c\udfa7 A fascinatingly different take on the AI question consuming us all ATM: <a href=\"https:\/\/overcast.fm\/+AAWnAPC3OAg\">Imaginary Worlds: Is Mythology the Key to Understand AI? \u2014 overcast.fm\/\u2026<\/a> (A great podcast in general for geeks!)<\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<h2>Legend<\/h2>\n<p>When the textual description of a link is part of the link, it is the title of the page being linked to, when the text describing a link is not part of the link, it is a description written by <a href=\"https:\/\/bartb.ie\/\">Bart<\/a>.<\/p>\n<table>\n<thead>\n<tr>\n<th align=\"center\">Emoji<\/th>\n<th align=\"left\">Meaning<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td align=\"center\">\ud83c\udfa7<\/td>\n<td align=\"left\">A link to <strong>audio content<\/strong>, probably a podcast.<\/td>\n<\/tr>\n<tr>\n<td align=\"center\">\u2757<\/td>\n<td align=\"left\">A <strong>call to action<\/strong>.<\/td>\n<\/tr>\n<tr>\n<td align=\"center\"><em>flag<\/em><\/td>\n<td align=\"left\">The story is particularly relevant to people living in a <strong>specific country<\/strong>, or, the organisation the story is about is affiliated with the government of a specific country.<\/td>\n<\/tr>\n<tr>\n<td align=\"center\">\ud83d\udcca<\/td>\n<td align=\"left\">A link to <strong>graphical content<\/strong>, probably a chart, graph, or diagram.<\/td>\n<\/tr>\n<tr>\n<td align=\"center\">\ud83e\uddef<\/td>\n<td align=\"left\">A story that has been <strong>over-hyped<\/strong> in the media, or, <em>&#8220;no need to light your hair on fire&#8221;<\/em> \ud83d\ude42<\/td>\n<\/tr>\n<tr>\n<td align=\"center\">\ud83d\udcb5<\/td>\n<td align=\"left\">A link to an article behind a <strong>paywall<\/strong>.<\/td>\n<\/tr>\n<tr>\n<td align=\"center\">\ud83d\udccc<\/td>\n<td align=\"left\">A <strong>pinned<\/strong> story, i.e. one to keep an eye on that&#8217;s likely to develop into something significant in the future.<\/td>\n<\/tr>\n<tr>\n<td align=\"center\">\ud83c\udfa9<\/td>\n<td align=\"left\">A <strong><em>tip of the hat<\/em><\/strong> to thank a member of the community for bringing the story to our attention.<\/td>\n<\/tr>\n<tr>\n<td align=\"center\">\ud83c\udfa6<\/td>\n<td align=\"left\">A link to <strong>video content<\/strong>.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>Feedback &amp; Followups Listener and community feedback, developments in recently covered stories, and developments in long-running stories we&#8217;re tracking over time. After their first attempt received a lot of negative user feedback, Discord has redesigned their age-verification system: Discord rolls out age checks that don\u2019t require an ID or selfie \u2014 cyberinsider.com\/\u2026 &#8220;The company says [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":28385,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_post_was_ever_published":false},"categories":[147,214],"tags":[8413,4927,8412,50,569],"class_list":["post-36728","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog-posts","category-security-bits","tag-login-keychain","tag-meta","tag-muse","tag-security","tag-security-bits"],"jetpack_sharing_enabled":true,"jetpack_featured_media_url":"https:\/\/www.podfeet.com\/blog\/wp-content\/uploads\/2023\/05\/Security-Bits-Logo_1040x520.png","_links":{"self":[{"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/posts\/36728","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/comments?post=36728"}],"version-history":[{"count":2,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/posts\/36728\/revisions"}],"predecessor-version":[{"id":36730,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/posts\/36728\/revisions\/36730"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/media\/28385"}],"wp:attachment":[{"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/media?parent=36728"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/categories?post=36728"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.podfeet.com\/blog\/wp-json\/wp\/v2\/tags?post=36728"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}