iTunes Connect bug logs developers in to other developers’ accounts at random

This morning, a number of developers signed in to Apple’s iTunes Connect service only to be greeted by a list of apps that didn’t belong to them. TechCrunch has a good roundup of tweets from affected developers —it seems that whenever developers signed in with their credentials, they were being granted access to other developers’ accounts at random. As of about noon Eastern today, Apple took the service down to resolve the problem. It also looks like developers won’t be able to submit new apps or invite new testers to TestFlight while iTunes Connect is down. Affected developers can check Apple’s System Status page for developers for updates while they wait for the problems to be resolved (no other developer services appear to be affected by the outage). We don’t yet know whether the outage was caused by some error on Apple’s end or by a security breach like the one that brought all developer systems down  in the summer of 2013 . We’ve asked Apple when the service will be back and what caused the login problem in the first place, and we’ll update this article as we have new details. Read on Ars Technica | Comments

Read More:
iTunes Connect bug logs developers in to other developers’ accounts at random

Apple Remote Desktop admin tool is updated for the first time in forever

There was one other Apple software update that came out yesterday, though it got lost in the shuffle between OS X and iOS system updates and record-breaking financial results . The venerable Apple Remote Desktop (ARD) application has been bumped from version 3.7.2 to version 3.8. Version  3.7.2 was a relatively minor update issued in March of 2014, and version 3.7 goes all the way back to October of 2013. ARD is pretty far off the beaten path, but the short version is that it’s an administrative tool used primarily by IT people to manage large numbers of Macs. It can do standard remote desktop stuff—viewing and taking control of remote Macs’ screens to perform maintenance or help out end users—but it also has a bunch of other handy capabilities. Among other things, administrators can use ARD to push out updates or other software packages to a bunch of Macs at once, run scheduled maintenance, show user and application usage histories, and view hardware and software information for each computer. The biggest addition to version 3.8 is official support for OS X Yosemite, and the update redesigns the app’s icon and UI to mesh better with Yosemite’s new aesthetic. Older versions of ARD supported Yosemite, but performance was quite a bit slower and image quality was visibly poorer than it was for officially supported versions. Improvements to file copying, Full Screen mode, and viewing multiple client desktops at once round out the update. Read 2 remaining paragraphs | Comments

Read the original post:
Apple Remote Desktop admin tool is updated for the first time in forever

iOS 8.1.3 released, reduces the space you need to install updates

Apple has just released iOS 8.1.3, the third patch for iOS 8.1 and the sixth update to iOS 8 since its release. The most significant problem addressed by the new update is that it reduces the amount of free space that you need to install software updates, a problem which has proven especially irritating for owners of 8GB and 16GB iDevices. Currently, users who are using most of their storage either need to delete stuff or connect their phones to iTunes to perform updates, a throwback to pre-iOS 5 releases of the operating system. The update squashes a few other bugs too: it fixes problems keeping some users from entering their passwords for Messages and FaceTime; fixes a problem where Spotlight would stop showing locally installed apps among its search results (this is one we’ve run into); and fixes multitasking gestures for iPad users. Finally, 8.1.3 adds a few configuration options to limit iDevices’ functionality during standardized tests. Read 2 remaining paragraphs | Comments

More here:
iOS 8.1.3 released, reduces the space you need to install updates

Apple releases OS X 10.10.2 with a pile of security, privacy, and Wi-Fi fixes

Apple has just released the final build of OS X 10.10.2, the second major update for OS X Yosemite since its release. Version 10.10.1, published just a month after Yosemite’s release, focused mostly on quick fixes for the new OS’ most noticeable problems. Apple has been issuing betas for 10.10.2 since November, though, and a longer testing period usually implies that there are more extensive fixes. First up, the new release is supposed to fix more of the Wi-Fi problems that some users have been experiencing since Yosemite’s launch. 10.10.1 also included Wi-Fi fixes, though it apparently didn’t resolve the problems for all. The new update will also address “an issue that may cause webpages to load slowly” and improve general stability in Safari, all of which should go a long way toward improving Yosemite’s network and Internet performance. Several privacy and security problems that we’ve reported on have been resolved in 10.10.2, as well. Though Apple will still share limited search and location information with Microsoft to enable Spotlight’s Bing-powered Web searching feature, the company has fixed a bug that caused Spotlight to “load remote e-mail content” even when the setting was disabled in Mail.app itself. Our original report describes why this is a problem: Read 3 remaining paragraphs | Comments

View article:
Apple releases OS X 10.10.2 with a pile of security, privacy, and Wi-Fi fixes

Don’t cry for the Google Play edition program; it was already dead

Earlier this week, the last of the Google Play edition Android phones in Google’s online storefront were listed as ” no longer available for sale .” When contacted for comment, Google had nothing to say, but it’s not hard to read between the lines here. The last new Google Play phone was introduced in the spring of 2014. Plans for a Galaxy S5 GPe phone made it far enough that official press photos leaked out into the wild , but the phone never materialized. The program hit its peak early last year, when a full half-dozen devices were listed all at once: the Galaxy S4 , the HTC Ones M7 and M8 , the first-generation Moto G , the Sony Z Ultra , and the LG G Pad 8.3 . Like doomed kids making their way through Willy Wonka’s factory, they silently dropped out one by one. Now they’re all gone, and it looks a whole lot like the program has wrapped up. If so, it’s a quiet, inconspicuous end to a quiet, inconspicuous program. Normally we’d say that fewer choices for Android shoppers would be a bad thing, but the changes Google has made to Android since the GPe program was introduced had already rendered it mostly irrelevant. Read 13 remaining paragraphs | Comments

Read the original:
Don’t cry for the Google Play edition program; it was already dead

Making ultra-thin materials with holes the size of water molecules

While visiting GE’s China Technology Center, we got to take a look at reverse osmosis membranes. Reverse osmosis is the most energy-efficient means of removing dissolved substances from water. It’s what’s used commercially for desalination, the process of producing drinking water from seawater. The term “membrane” is typically used to mean a thin sheet of some material (in fact, the word “sheet” appears in the definition of the term). But for some of the things GE is using it for, the membranes were thin yet robust tubes, each one capable of supporting the weight of a bowling ball. Despite that toughness, features on the tubes are so fine that they can allow water molecules to pass through but reject many things that are roughly the same size, such as the salt ions found in seawater. This all raises an obvious question: how do you actually produce anything like that? We decided to look into the process of making reverse osmosis membranes. Read 12 remaining paragraphs | Comments

Read More:
Making ultra-thin materials with holes the size of water molecules

Google drops three OS X 0days on Apple

Don’t look now, but Google’s Project Zero vulnerability research program may have dropped more zero-day vulnerabilities—this time on Apple’s OS X platform. In the past two days, Project Zero has disclosed OS X vulnerabilities here , here , and here . At first glance, none of them appear to be highly critical, since all three appear to require the attacker to already have some access to a targeted machine. What’s more, the first vulnerability, the one involving the “networkd ‘effective_audit_token’ XPC,” may already have been mitigated in OS X Yosemite, but if so the Google advisory doesn’t make this explicit and Apple doesn’t publicly discuss security matters with reporters. Still, the exploits could be combined with a separate attack to elevate lower-level privileges and gain control over vulnerable Macs. And since the disclosures contain proof-of-concept exploit code, they provide enough technical detail for experienced hackers to write malicious attacks that target the previously unknown vulnerabilities. The security flaws were privately reported to Apple on October 20, October 21, and October 23, 2014. All three advisories appear to have been published after the expiration of the 90-day grace period Project Zero gives developers before making reports public. Read 1 remaining paragraphs | Comments

Visit link:
Google drops three OS X 0days on Apple

Liveblog: Windows 10 “The Next Chapter” event on January 21st

REDMOND—Microsoft is unveiling the next major beta of Windows 10, the Consumer Preview, with an event at the company’s home in Redmond, Washington. We’ll be on the scene to report on the news and get a first look at the new release. We’re expecting to see the new Continuum feature that adapts the Windows interface on 2-in-1 devices and a new browser that sheds the legacy (and name) of Internet Explorer. Representatives of the Xbox team will also be at the event, with Microsoft having news about Windows gaming—though precisely what that will be is currently a mystery. Read on Ars Technica | Comments

Taken from:
Liveblog: Windows 10 “The Next Chapter” event on January 21st

British spy agency captured 70,000 e-mails of journalists in 10 minutes

The Government Communications Headquarters (GCHQ), the British sister agency of the National Security Agency, captured 70,000 e-mails of journalists in 10 minutes during a November 2008 test. According to The Guardian , which on Monday cited some of its Snowden documents as its source (but did not publish them), the e-mails were scooped up as part of the intelligence agency’s direct fiber taps . Journalists from the BBC, Reuters, The Guardian, The New York Times, Le Monde, The Sun , NBC, and The Washington Post were apparently targeted. Read 2 remaining paragraphs | Comments

More here:
British spy agency captured 70,000 e-mails of journalists in 10 minutes

Google drops more Windows 0-days. Something’s gotta give

Google’s security researchers have published another pair of Windows security flaws that Microsoft hasn’t got a fix for, continuing the disagreement between the companies about when and how to disclose security bugs. The first bug affects Windows 7 only and results in minor information disclosure. Microsoft says, and Google agrees, that this does not meet the threshold for a fix. Windows 8 and up don’t suffer the same issue. The second bug is more significant. In certain situations, Windows doesn’t properly check the user identity when performing cryptographic operations, which results in certain shared data not being properly encrypted. Microsoft has developed a fix for this bug, and it was originally scheduled for release this past Tuesday. However, the company discovered a compatibility issue late in testing, and so the fix has been pushed to February. Read 7 remaining paragraphs | Comments

See the original post:
Google drops more Windows 0-days. Something’s gotta give