Showing posts with label Security Flaw. Show all posts
Showing posts with label Security Flaw. Show all posts

Tuesday, February 25, 2014

Apple issues fix for glaring security flaw on Mac computers


SAN FRANCISCO — Apple Inc has issued fixes for a security flaw in its Macintosh computers that allows hackers to intercept data such as email, patching a major and embarrassing glitch that came to light several days ago.

The security update for users of Apple’s OS X computer operating software follows a fix issued for iPhones last week, meaning all Apple device users now have access to the patch.

The flaw allowed attackers with access to a mobile user’s network, such as a shared unsecured wireless service offered by a cafe, to see or alter exchanges between the user and protected sites such as Google Inc’s Gmail or Facebook.

On Tuesday, Apple said in a statement that the Mac security update also improved features such as its FaceTime videoconferencing service and email.

The flaw appeared related to the way in which well-understood protocols were implemented, and how Apple’s software recognizes digital certificates used by websites to establish encrypted connections.

Researchers have said the bug could have been present for months. Apple has not said when or how it learned about the flaw in the way iOS handles sessions, in what are known as secure sockets layer (SSL) or transport layer security. Nor has it said whether the flaw was being exploited.

A spokesman for the company declined to comment on Tuesday.

source: interaksyon.com

Friday, August 23, 2013

Web users reward Palestinian who hacked into Mark Zuckerberg’s profile, exposing a Facebook flaw


SAN FRANCISCO — Internet users have raised more than $11,000 to reward a Palestinian security researcher who hacked into Facebook chief Mark Zuckerberg’s profile to expose a security flaw.

The fundraising campaign on the website GoFundMe raised $11,035 from 178 people in one day for Khalil Shreateh, and was continuing to take donations after he was denied a “Facebook Bounty.”

“I hope this has raised awareness of the importance of independent researchers,” said Marc Maiffret, a security expert at the firm Beyond Trust who led the effort.

“I equally hope it has reminded other researchers that while working with technology companies can sometimes be frustrating, we can never forget the greater goal; to help the Internet community at large.”

While Facebook offers rewards for those who find security holes, the company said Shreateh went too far by posting the information on Zuckerberg’s own profile page without getting consent.

Shreateh said on his blog he found a way for a Facebook user to circumvent security and modify another’s timeline, even if they were not friends on the network.

He said he took the unusual step of hacking into Zuckerberg’s profile after being ignored by the Facebook security team.

source: interaksyon.com