Skip to content
Thoughtful, detailed coverage of everything Apple for 34 years
and the TidBITS Content Network for Apple professionals

Category: Security

Glenn Fleishman 2 comments

Google Raises Privacy Bar with Its Crowdsourced Tracking Service

Google’s new Find My Device network works nearly identically to Apple’s Find My network with a few exceptions: Google’s design offers more anti-stalking and privacy features than Apple.

Adam Engst 24 comments

Using Apple’s iCloud Passwords Outside Safari

Password managers like 1Password have long provided a deep set of features for creating, storing, and entering passwords and other confidential information. The iCloud Passwords extension for Chromium browsers makes Apple’s built-in password management features available outside Safari, but how do they compare to independent password managers?

Adam Engst 7 comments

Beware of Attacks Using Password Reset Request Notifications

Brian Krebs covers an attack that exploits a vulnerability in the Apple ID password reset process to deluge users with requests to reset the password. Consider yourself forewarned.

Adam Engst 6 comments

macOS 14.4.1 Sonoma and macOS 13.6.6 Ventura Fix Bugs and Vulnerabilities

Apple doesn’t say what has changed for macOS 13.6.6 Ventura, but the bugs fixed in macOS 14.4.1 Sonoma have bedeviled users for the last two weeks.

Adam Engst 2 comments

Apple Releases iOS and iPadOS 17.4.1 and 16.7.7, and visionOS 1.1.1

Release notes for these updates list “important bug fixes and security updates” or just “important security fixes” so they probably address one or more zero-day security vulnerabilities.

Adam Engst 43 comments

Apple Releases macOS 14.4, watchOS 10.4, tvOS 17.4, HomePod Software 17.4, and visionOS 1.1

After the release of iOS 17.4 and iPadOS 17.4 earlier in the week, there was little question that Apple would soon push out updates to the rest of its operating systems. That has now happened, and we recommend updating quickly to protect against several zero-day vulnerabilities.

Adam Engst 21 comments

iOS 17.4 and iPadOS 17.4 Add Podcast Transcripts, Fix Zero-Day Vulnerabilities

Apple has released updates to the last three versions of iOS and iPadOS, adding features and fixing security vulnerabilities in iOS/iPadOS 17, addressing vulnerabilities in iOS/iPadOS 16, and fixing bugs in iOS/iPadOS 15.

Adam Engst 6 comments

Do You Use It? How TidBITS Readers Install macOS Updates

The results of our poll asking how TidBITS readers engage with macOS updates reveal that most people stick with Apple’s default settings and follow our advice about how quickly to install. That’s good!

Adam Engst 7 comments

New iMessage PQ3 Encryption Protocol Protects Against Post-Quantum Attacks

In the upcoming iOS 17, iPadOS 17.4, macOS 14.4 Sonoma, and watchOS 10.4, Apple will start rolling out the PQ3 encryption protocol for iMessage conversations to protect them against attacks made possible by future quantum computers.

Adam Engst No comments

Beware Forged Phishing Messages from TidBITS Talk

Several TidBITS readers have alerted us to phishing messages that purport to be from TidBITS Talk. They’re not, of course, and should be marked as spam, but they serve as a warning for why it’s essential pay attention to email.

Adam Engst 10 comments

Authy Desktop to Reach End-of-Life on 19 March 2024

Twilio, the company behind the Authy two-factor authentication apps, has announced that Authy Desktop for the Mac will reach end-of-life next month. It might be a good excuse to switch to a full-fledged password manager that also supports 2FA codes.

Adam Engst 42 comments

Turn On Stolen Device Protection in iOS 17.3

Apple has made good on its promise to add Stolen Device Protection to iOS 17.3, allowing users concerned about iPhone passcode and snatch-and-run theft to require biometric authentication and sometimes a delay to carry out critical security and financial actions. We look at what it does and doesn’t protect, how to turn it on, and who can’t use it.

Glenn Fleishman 10 comments

How To Avoid AI Voice Impersonation and Similar Scams

The “grandparent scam” goes back almost 20 years, but it and similar frauds are gaining new traction through AI voice impersonation. Protect your family, friends, and colleagues with advance planning.

Adam Engst 21 comments

Eight Secure Ways to Share Sensitive Information over the Internet

Sometimes, you need to share private information—a password, financial details, a confidential document—over the Internet. Adam Engst looks at eight popular methods of transmitting your secrets securely to others.

Adam Engst 24 comments

iOS 17.3 Stands Out from Other OS Updates with Stolen Device Protection

Apple has released a large set of operating system updates, including iOS 17.3, iPadOS 17.3, macOS 14.3 Sonoma, watchOS 10.3, tvOS 17.3, HomePod Software 17.3, macOS 13.6.4 Ventura, macOS 12.7.3 Monterey, iOS 16.7.5 and iPadOS 16.7.5, and iOS 15.8.1 and iPadOS 15.8.1. New features include Stolen Device Protection in iOS 17.3 and Apple Music collaborative playlists.