Hacker Claims To Have Decrypted Apple’s Secure Enclave Processor Firmware

According to iClarified, a hacker by name of “xerub” has posted the decryption key for Apple’s Secure Enclave Processor (SEP) firmware. “The security coprocessor was introduced alongside the iPhone 5s and Touch ID, ” reports iClarified. “It performs secure services for the rest of the SOC and prevents the main processor from getting direct access to sensitive data. It runs its own operating system (SEPOS) which includes a kernel, drivers, services, and applications.” From the report: The Secure Enclave is responsible for processing fingerprint data from the Touch ID sensor, determining if there is a match against registered fingerprints, and then enabling access or purchases on behalf of the user. Communication between the processor and the Touch ID sensor takes place over a serial peripheral interface bus. The processor forwards the data to the Secure Enclave but can’t read it. It’s encrypted and authenticated with a session key that is negotiated using the device’s shared key that is provisioned for the Touch ID sensor and the Secure Enclave. The session key exchange uses AES key wrapping with both sides providing a random key that establishes the session key and uses AES-CCM transport encryption. Today, xerub announced the decryption key “is fully grown.” You can use img4lib to decrypt the firmware and xerub’s SEP firmware split tool to process. Decryption of the SEP Firmware will make it easier for hackers and security researchers to comb through the SEP for vulnerabilities. Read more of this story at Slashdot.

Read the article:
Hacker Claims To Have Decrypted Apple’s Secure Enclave Processor Firmware

Apple Refuses To Enable iPhone Emergency Settings that Could Save Countless Lives

An anonymous reader shares a report: Despite being relatively easy, Apple keeps ignoring requests to enable a feature called Advanced Mobile Location (AML) in iOS. Enabling AML would give emergency services extremely accurate locations of emergency calls made from iPhones, dramatically decreasing response time. As we have covered before, Google’s successful implementation of AML for Android is already saving lives. But where Android users have become safer, iPhone owners have been left behind. The European Emergency Number Association (EENA), the organization behind implementing AML for emergency services, released a statement today that pleads Apple to consider the safety of its customers and participate in the program: “As AML is being deployed in more and more countries, iPhone users are put at a disadvantage compared to Android users in the scenario that matters most: An emergency. EENA calls on Apple to integrate Advanced Mobile Location in their smartphones for the safety of their customers.” Why is AML so important? Majority of emergency calls today are made from cellphones, which has made location pinging increasingly more important for emergency services. There are many emergency apps and features in development, but AML’s strength is that it doesn’t require anything from the user — no downloads and no forethought: The process is completely automated. With AML, smartphones running supporting operating systems will recognize when emergency calls are being made and turn on GNSS (global navigation satellite system) and Wi-Fi. The phone then automatically sends an SMS to emergency services, detailing the location of the caller. AML is up to 4, 000 times more accurate than the current systems — pinpointing phones down from an entire city to a room in an apartment. “In the past months, EENA has been travelling around Europe to raise awareness of AML in as many countries as possible. All these meetings brought up a recurring question that EENA had to reply to: ‘So, what about Apple?'” reads EENA’s statement. Read more of this story at Slashdot.

Taken from:
Apple Refuses To Enable iPhone Emergency Settings that Could Save Countless Lives

US Hacker Sets Off 156 Sirens At Midnight

“I had the displeasure of being awoken at midnight to the sounds of civil-defense/air-raid sirens, ” writes very-long-time Slashdot reader SigIO, blaming “some schmuck with a twisted sense of humor.” The Dallas News reports: Rocky Vaz, director of Dallas’ Office of Emergency Management, said that all 156 of the city’s sirens were activated more than a dozen times… Dallas officials blame computer hacking for setting off emergency sirens throughout the city early Saturday… It took until about 1:20 a.m. to silence them for good because the emergency system had to be deactivated. The system remained shut down Saturday while crews safeguarded it from another hack. The city has figured out how the emergency system was compromised and is working to prevent it from happening again, he said… The city said the system should be restored Sunday or Monday. City officials reported 4, 400 calls to their 9-1-1 emergency phone number in the first four hours of Saturday morning, with over 800 occurring in that first 15 minutes when all 156 sirens started going off simultaneously. Read more of this story at Slashdot.

Continued here:
US Hacker Sets Off 156 Sirens At Midnight

The best password managers

By Joe Kissell This post was done in partnership with The Wirecutter , a buyer’s guide to the best technology. When readers choose to buy The Wirecutter’s independently chosen editorial picks, it may earn affiliate commissions that support its work. Read the full article here . If you’re not using a password manager, start now. As we wrote in Password Managers Are for Everyone—Including You , a password manager makes you less vulnerable online by generating strong random passwords, syncing them securely across your browsers and devices so they’re easily accessible everywhere, and filling them in automatically when needed. After 15 hours of research and testing, we believe that LastPass is the best password manager for most people. It has all the essential features plus some handy extras, it works with virtually any browser on any device, and most of its features are free. Who should get this Everyone should use a password manager . The things that make strong passwords strong—length, uniqueness, variety of characters—make them difficult to remember, so most people reuse a few easy-to-remember passwords everywhere they go online. But reusing passwords is dangerous: If just one site suffers a security breach, an attacker could access your entire digital life: email, cloud storage, bank accounts, social media, dating sites, and more. And if your reused password is weak, the problem is that much worse, because someone could guess your password even if there isn’t a security breach. If you have more than a handful of online accounts—and almost everyone does—you need a good password manager. It enables you to easily ensure that each password is both unique and strong, and it saves you the bother of looking up, remembering, typing, or even copying and pasting your passwords when you need them. If you don’t already use a password manager, you should get one, and LastPass is a fabulous overall choice for most users. How we picked and tested Although I’d already spent countless hours testing password managers in the course of writing my book Take Control of Your Passwords , for this article I redid most of the research and testing from scratch, because apps in this category change constantly—and often dramatically. I looked for tools that do their job as efficiently as possible without being intrusive or annoying. A password manager should disappear until you need it, do its thing quickly and with minimum interaction, and require as little thought as possible (even when switching browsers or platforms). And the barrier to entry should be low enough—in terms of both cost and simplicity—for nearly anyone to get up to speed quickly. I began by ruling out the password autofill features built into browsers like Chrome and Firefox—although they’re better than nothing, they tend to be less secure than stand-alone apps, and they provide no way to use your stored passwords with other browsers. Next I looked for apps that support all the major platforms and browsers. If you use only one or two platforms or browsers, support for the others may be irrelevant to you, but broad compatibility is still a good sign. This means, ideally, support for the four biggest platforms—Windows, macOS, iOS, and Android—as well as desktop browser integration with at least Chrome and Firefox, plus Safari on macOS. I excluded apps that force you to copy and paste passwords into your browser rather than offering a browser extension that lets you click a button or use a keystroke to fill in your credentials. And, because most of us use more than one computing device, the capability to sync passwords securely across those devices is essential. After narrowing down the options, I tested eight finalists: 1Password, Dashlane, Enpass, Keeper, LastPass, LogmeOnce, RoboForm, and Sticky Password. I tested for usability by doing a number of spot checks to verify that the features described in the apps’ marketing materials matched what I saw in real life. I set up a simple set of test forms on my own server that enabled me to evaluate how each app performed basic tasks such as capturing manually entered usernames and passwords, filling in those credentials on demand, and dealing with contact and credit card data. If my initial experiences with an app were good, I also tried that app with as many additional platforms and browsers as I could in order to form a more complete picture of its capabilities. I did portions of my testing on macOS 10.12, Windows 10, Chromium OS (as a stand-in for Chrome OS), iOS 10, Apple Watch, and Android. Our pick You can access LastPass in a browser extension, on the Web, or in a stand-alone app. Before I get to what’s great about LastPass, a word of context: LastPass , Dashlane , and 1Password are significantly better than the rest of the field. I suspect most people would be equally happy with any of them. What tipped the scales in favor of LastPass was the company’s announcement on November 2, 2016, that it was making cross-device syncing (formerly a paid feature) available for free. Although there’s still a Premium subscription that adds important features (more on that in our full guide ), this change makes LastPass a no-brainer for anyone who hasn’t yet started using a password manager. Even its $12/year premium tier is much cheaper than 1Password or Dashlane’s paid options. LastPass has the broadest platform support of any password manager I saw. Its autofill feature is flexible and nicely designed. You can securely share selected passwords with other people; there’s also an Emergency Access feature that lets you give a loved one or other trusted person access to your data. An Automatic Password Change feature works on many sites to let you change many passwords with one click, and a Security Challenge alerts you to passwords that are weak, old, or duplicates, or that go with sites that have suffered data breaches. LastPass works on macOS, Windows, iOS, Android, Chrome OS, Linux, Firefox OS, Firefox Mobile, Windows RT, Windows Phone—even Apple Watch and Android Wear smartwatches. (Sorry, no BlackBerry, Palm, or Symbian support.) It’s available as a browser extension for Chrome, Firefox, Safari, Internet Explorer, and Microsoft Edge, and it has desktop and mobile apps for various platforms. Upgrade pick for Apple users 1Password offers Mac and iOS users features not found in LastPass, plus a more-polished interface. If you’re a Mac, iPhone, and/or iPad user with a few extra bucks, and you’d like even more bells and whistles in your password manager, 1Password is well worth a look. 1Password has a more polished and convenient user interface than either LastPass or Dashlane. It’s also a little faster at most tasks; it has a local storage option if you don’t trust your passwords to the cloud; it gives you more options than LastPass for working with attached files; and it can auto-generate one-time tokens for many sites that use two-step verification—LastPass requires a separate app for this. 1Password is, however, more expensive than LastPass and doesn’t work on as many platforms: Windows and Chromebook users, especially, are better off with LastPass. This guide may have been updated by The Wirecutter . To see the current recommendation, please go here . Note from The Wirecutter: When readers choose to buy our independently chosen editorial picks, we may earn affiliate commissions that support our work.

Excerpt from:
The best password managers

The NSA sure breaks a lot of "unbreakable" crypto. This is probably how they do it.

There have long been rumors, leaks, and statements about the NSA “breaking” crypto that is widely believed to be unbreakable, and over the years, there’s been mounting evidence that in many cases, they can do just that. Now, Alex Halderman and Nadia Heninger, along with a dozen eminent cryptographers have presented a paper at the ACM Conference on Computer and Communications Security (a paper that won the ACM’s prize for best paper at the conference) that advances a plausible theory as to what’s going on. In some ways, it’s very simple — but it’s also very, very dangerous, for all of us. (more…)

Read More:
The NSA sure breaks a lot of "unbreakable" crypto. This is probably how they do it.

Why Does Asking Siri to Charge Your Phone Call the Cops?

Utter the words—and we don’t suggest you do—“charge my phone 100 percent” to Siri, and your iPhone will try and call the emergency services, after a five-second grace period in which you can cancel it. But why? Read more…

Read the article:
Why Does Asking Siri to Charge Your Phone Call the Cops?

A Huge List of Brands That Come With Lifetime Warranties

When you plan to have something for a long time, it makes sense to pay for quality. And it makes even more sense when companies will replace your item if it wears out or becomes unusable. GOBankingRates rounds up 32 brands with lifetime warranties. Read more…

See the original post:
A Huge List of Brands That Come With Lifetime Warranties

Planes Don’t Carry Tanks Of Oxygen.  So What’s In Your Emergency Mask?

You’re on a plane. The oxygen masks have dropped. While you’re screaming and crying, does it occur to you to wonder where that oxygen comes from? It’s not a scuba tank. Here’s how weed killer, fireworks, and candy destroyers keep you alive. Read more…

View original post here:
Planes Don’t Carry Tanks Of Oxygen.  So What’s In Your Emergency Mask?

Top 10 Backups Everyone Should Have (Not Just Computer Backups)

You’ve heard it a lot, but it bears repeating: you need to back up your computer , because your hard drive will fail one day. Beyond those file backups, though, are many other things we need to have a backup for—ranging from work and finances to personal needs. Read more…

Read More:
Top 10 Backups Everyone Should Have (Not Just Computer Backups)

The Cashless Society? It’s Already Coming

HughPickens.com writes Damon Darlin writes in the NYT that Apple pay is revolutionary but not for the reason you think. It isn’t going to replace the credit card but it’s going to replace the wallet — the actual physical thing crammed with cards, cash, photos and receipts. According to Darlin, when you are out shopping, it’s the wallet, not the credit card, that is the annoyance. It’s bulky. It can be forgotten, or lost. “I’ve learned while traipsing about buying stuff with my ApplePay that I can whittle down wallet items that I need to carry to three”: A single credit card, for places that have not embraced, but soon will, some form of smartphone payment; a driver’s license; and about $20 in cash. Analysts at Forrester Research estimate that over the next five years, US mobile payments will grow to $142 billion, from $3.7 billion this year. “If I were to make a bet, I’d say that 10 years from now the most popular answer from young shoppers about how they make small payments would be: thumbprint. And you’ll get a dull shrug when you ask what a wallet is.” Read more of this story at Slashdot.

Taken from:
The Cashless Society? It’s Already Coming