19 Followers
2 Following
179 Posts

Conscientious spectre making a home in the threadiverse.

I also toot as @tojikomori.

An Apple malware-flagging tool is “trivially” easy to bypass.

Background Task Manager can potentially miss malicious software on your machine.... #apple

https://arstechnica.com/security/2023/08/researcher-finds-easy-exploits-for-apples-malware-flagging-tool/

An Apple malware-flagging tool is “trivially” easy to bypass

Background Task Manager can potentially miss malicious software on your machine.

Ars Technica

Hacking Apple's 1994 Set Top Box System

Apple developed the STBs in their Austin, Texas campus. It was based on stripped-down 1993 Quadra 605 hardware with extra silicon for the media features but kept serial, ADB and SCSI connections to allow it to run compatible CD-ROMs, sort of a Pippin before the Pippin, with plans to sell it for $750 [2023 dollars about $1500]… #apple

http://oldvcr.blogspot.com/2023/07/apples-interactive-television-box.html?m=1

Apple's Interactive Television Box: hacking the Set Top Box System 7.1 in ROM

One of the coolest things to come along in the 68K Mac homebrew community is the ROM Boot Disk concept. Classic Macs have an unusually lar...

Unsupported browser, please install Chrome.

You are logged out, please log in or sign up for an account.

To verify your identity, please enter your phone number, a text message will be sent, please enter verification code.

Error, your account has been flagged for further review, please submit 3 different government IDs, with at least 2 containing your photo, and 2 containing your address.

Error, name doesn’t match, if you have changed you name, please submit proof of name change.

Error, no citizenship status detected, please submit birth certificate or naturalization certificate

Please wait 7-14 bussiness days. A phone call will be made to the number you’ve submitted.

Error, missed call. Please wait 30 days for another call.

Error, unsupported operating system, please use Chrome OS, Android, or Google Smart TV OS

Error, Google Smart Home assistant not installed, please purchase one within the next 3 days to avoid losing signup process.

Error, could not confirm identity, please purchase Google 360 cameras to verify identity.

Error, server maintenance in progress, please retry signup at a later time.

Thank you for using Google!

How long will the last Intel Macs be supported? macOS Sonoma gives us some hints

Nearly 20 years of data show how Intel Macs are faring as Apple switches chips. #apple

https://arstechnica.com/gadgets/2023/07/with-macos-sonoma-intel-macs-are-still-getting-fewer-updates-than-they-used-to/

How long will the last Intel Macs be supported? macOS Sonoma gives us some hints

Nearly 20 years of data show how Intel Macs are faring as Apple switches chips.

Ars Technica

Gurman: Apple to add hearing tests, other health features to AirPods

"Likely several months or even years away," after the shift to USB-C:... #apple

https://www.bloomberg.com/news/newsletters/2023-07-02/apple-airpods-plans-hearing-test-body-temperature-cheaper-models-usb-c-ljlfwffu

What’s Next for Apple’s AirPods: Health Tracking, USB-C and Lower Prices

Apple is working on a slew of changes for its popular AirPods earbuds, seeking to expand its wearables business. Also: The company is all-in on hand and eye control for the Vision Pro, and Apple stores are set to get a payment system upgrade.

Bloomberg

Today's iOS, iPadOS, macOS, and watchOS updates address zero-day vulnerabilities

"Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7," the company says when describing Kernel and WebKit vulnerabilities tracked as CVE-2023-32434 and CVE-2023-32435. #apple

https://www.bleepingcomputer.com/news/apple/apple-fixes-zero-days-used-to-deploy-triangulation-spyware-via-imessage/

Apple fixes zero-days used to deploy Triangulation spyware via iMessage

Apple addressed three new zero-day vulnerabilities exploited in attacks installing Triangulation spyware on iPhones via iMessage zero-click exploits.

BleepingComputer

Today's iOS, iPadOS, macOS, and watchOS updates address zero-day vulnerabilities

"Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7," the company says when describing Kernel and WebKit vulnerabilities tracked as CVE-2023-32434 and CVE-2023-32435. #apple

https://www.bleepingcomputer.com/news/apple/apple-fixes-zero-days-used-to-deploy-triangulation-spyware-via-imessage/

Apple fixes zero-days used to deploy Triangulation spyware via iMessage

Apple addressed three new zero-day vulnerabilities exploited in attacks installing Triangulation spyware on iPhones via iMessage zero-click exploits.

BleepingComputer

Their post about the meetings with reddit:

Moderators of r/blind—along with moderators in other communities who use assistive technologies and Reddit users with accessibility expertise—had a Zoom meeting with representatives at Reddit on Friday, June 16, 2023. While the call was promising in that Reddit invited us to be part of continuing dialog and demonstrated some well-conceived accessible designs for Reddit users, we came away with serious concerns which Reddit was either unable or unwilling to address during the meeting.

Reddit is currently prioritizing accessibility for users rather than for moderators, and representatives were unwilling to provide timelines by when Reddit’s moderation tools would be accessible for screen reader users. Further, Reddit representatives seemed unaware that blind moderators rely on third-party applications because Reddit’s moderation tools present significant accessibility challenges. They also seemed unaware that the apps which have so far received exemptions from API pricing do not have sufficient moderation functions. u/NTCarver0 explained that blind moderators will be unable to ensure safety for our communities—as well as for Reddit in general—without accessible moderation systems, and asked Reddit representatives how blind moderators were supposed to effectively moderate our communities without them. Reddit representatives deferred the question, stating they would have to take notes and get back with us. A fellow moderator, u/MostlyBlindGamer, also pointed out that blind moderators who are unable to effectively moderate the subreddit and thus will become inactive may be removed at Reddit’s discretion per policy, and that such removal would leave r/Blind with no blind moderators. Reddit representatives also deferred comment on this issue.

Reddit representatives refused to answer questions concerning the formal certifications, accreditations or qualifications of employees tasked with ensuring universal accessibility. These certifications demonstrate that a professional has the knowledge necessary to create universally-accessible software and/or documents. Because Reddit cannot confirm that employees tasked with universal accessibility hold appropriate certifications or that the company will provide for such training and certification, we have concerns that employees do not have the appropriate knowledge to effectively ensure access for all assistive technology users both at present and in the future. Reddit has also indicated there are not currently any employees who work full-time on accessibility. This is a necessity for any organization as large and influential as Reddit.

Reddit representatives had previously disclosed to r/Blind moderators that an accessibility audit had been performed by a third-party company, however they refused to answer questions as to what company performed the audit or how the audit was conducted. Answers to these questions would have allowed us to determine whether the audit was performed by an accredited organization known for credible and thorough work. Reddit also could not answer questions as to what assistive technologies, such as screen readers, screen magnifiers, dictation softwares, etc., were used during the audit. Bluntly, we cannot know the thoroughness or scope of the audit—and therefore the extent to which Reddit is aware of the accessibility barriers present in their website and apps—without this information.

During the previous meeting, Reddit representatives raised a question regarding perceived disparities between the accessibility of the iOS and Android apps, suggesting the audit did not confirm that the accessibility failings in the iOS app are much more severe than those present in the Android app. During the latest meeting, u/MostlyBlindGamer explained that the iOS app has no labels for the ubiquitous and essential upvote and downvote buttons while the Android app does. This question raises the concern that Reddit representatives may not have a full and actionable understanding of the issues at stake or, in fact, the exact accessibility failings in their apps.

Reddit representatives narrowly defined the scope of the latest meeting less than an hour ahead of it, explicitly excluding third-party apps and API pricing from the conversation. They did acknowledge that this made it difficult to adequately prepare for the meeting.

Reddit refused to define the term “accessibility-focused app,” alleging that this was outside the cope of the meeting. This term is not industry-standard and was instead created when Reddit carved out an exemption in their upcoming API policies for third-party apps used by blind people to access the platform. Without this definition, we are unable to ascertain whether apps that have not been approved but are nevertheless relied upon by community members qualify for an exemption.

Reddit gave no firm commitments as to when accessibility improvements would be rolled out to the website or apps. However, it is obvious that the Reddit website and apps will not be ready for disabled users—and especially moderators—by July 1.

In general, moderators of r/Blind who attended the call came away with mixed impressions. Reddit seems to be somewhat aware of the myriad accessibility barriers present in their applications and website, and the company appears to be laying the groundwork to fix issues which they are aware of. This is excellent news. However, we also feel that Reddit does not know what it does not know, and this lack of knowledge is exasperating, disheartening, and exhausting. We also came away frustrated that Reddit representatives were either unwilling or unable to answer prudent and pertinent questions which would allow us to determine not only how we can best keep our community safe and healthy, but also whether Reddit is truly prepared to commit to ensuring accessibility for all disabled users both now and in the future. Finally, we hope that our concerns—especially those pertaining to moderation—will be addressed expeditiously and satisfactorily, thus assuring that r/Blind can operate effectively well into the future. Despite our concerns, we remain open to continued dialog with Reddit in the hope that it will foster a more accessible platform.

Comment from the MacRumors forum, in case you're hoping it'll solve the problem Joanna Stern reported on:

Unfortunately on iOS, the backup to Face-ID for the iPhone's Keychain or PassKeys is the iPhone's passcode. So anyone that has access to your phone and knows the passcode, can use the phone's passcode to log-in to iCloud or Apple ID with this feature.

iOS 17 and macOS Sonoma Add Passkey Support to Your Apple ID

Unfortunately on iOS, the backup to Face-ID for the iPhone's Keychain or PassKeys is the iPhone's passcode. So anyone that has access to your phone and knows the passcode, can use the phone's passcode to log-in to iCloud or Apple ID with this feature.

MacRumors Forums

iOS 17 and macOS Sonoma Add Passkey to Your Apple ID

Starting with iOS 17, iPadOS 17, and macOS Sonoma, users with an Apple ID will automatically be assigned a passkey, allowing them to sign into their Apple ID with Face ID or Touch ID instead of their password. #apple

https://www.macrumors.com/2023/06/20/ios-17-macos-sonoma-apple-id-passkey/

iOS 17 and macOS Sonoma Add Passkey Support to Your Apple ID

Starting with iOS 17, iPadOS 17, and macOS Sonoma, users with an Apple ID will automatically be assigned a passkey, allowing them to sign into their...

MacRumors