Infosecurity.US

Information Security & Occasional Forays Into Adjacent Realms

  • Web Log

Apple's Umbrella Factory

June 21, 2019 by Marc Handelman in Hardware Security, Device Security, Information Security, Interesting Read

via EFF writers Jeremy Gillula & Seth Schoen, comes an outstanding piece on Apple Inc.'s (Nasdaq: AAPL) recent decision to restrict ('limits' was the exact term utilized) device tracking. Today's Interesting Read.

"Still, Apple's move is extremely welcome and, to our knowledge, makes Apple the first device maker to have protected its users' privacy this way." - via EFF writers Jeremy Gillula & Seth Schoen

June 21, 2019 /Marc Handelman
Hardware Security, Device Security, Information Security, Interesting Read

SANS DFIR Summit 2018, Cindy Murphy's 'Digital Forensics Truths That Turn Out To Be Wrong'

November 24, 2018 by Marc Handelman in DFIR, SANS, Device Security, Forensication, Forensics Education
November 24, 2018 /Marc Handelman
DFIR, SANS, Device Security, Forensication, Forensics Education

MDM Brute Forced

September 29, 2018 by Marc Handelman in Tor Project, Radio Telephony, MDM, Cellular Telephony, Hardware Security, Device Security, Device Exploitation

via Sean Gallagher, writing at Ars Technica, comes this particularly unfortunate news for Apple Inc. (Nasdaq: AAPL) MDM (Mobile Device Management) bits - especially considering there will be a flood of new devices into many orgs. On the plus side, the flaw has been discovered, and now it's Apple's turn-at-bat to clean up their dusty-bits, as it were. Read all about it at everyones' beloved Ars Technica!.

September 29, 2018 /Marc Handelman
Tor Project, Radio Telephony, MDM, Cellular Telephony, Hardware Security, Device Security, Device Exploitation

iOS: The Trust Jacking Gambit →

April 20, 2018 by Marc Handelman in Operating Systems, Operating System Security, Opposable Thumbs, Information Security, Device Security, Device Exploitation, Vectored Attacks

Roy Iarchy, writing at Symantec's security blog, comes this story of Apple Inc.'s (Nasdaq: AAPL) iOS, Operating System flaws, and the vector - the TrustJacking gambit, all wrapped up in a nice tidy package. Bad news for iOS, good news for Security vendors, eh? And, not surprisingly, users running older devices not patchable by APple are vulnerable to this form of iOS device jacking as Apple's not focused on patching older devices. Today's unfortunate Must Read.

April 20, 2018 /Marc Handelman
Operating Systems, Operating System Security, Opposable Thumbs, Information Security, Device Security, Device Exploitation, Vectored Attacks

Le Rogue →

July 12, 2017 by Marc Handelman in Supply Chain Security, Alternate Attack Vectors, Devices, Information Security, Device Security, Attack Vectors, All is Information

Rogue replacement parts concept. H/T

July 12, 2017 /Marc Handelman
Supply Chain Security, Alternate Attack Vectors, Devices, Information Security, Device Security, Attack Vectors, All is Information