Various thoughts from an educational professional & geek.
Hackers have finally breached Apple's security but your iPhone's probably safe (for now) ...
Get link
Facebook
X
Pinterest
Email
Other Apps
Cyber security experts recently discovered that the almost impenetrable Apple App Store had been hacked. While cyber break-ins have become routine news for many companies, Apple has long prided itself on providing technology for its phones and tablets that was incredibly secure.
This was done by controlling how developers – the people who create your apps on your device – not only create their code but also upload it on to the app store. Steve Jobs ensured that Apple would check each app before it entered the marketplace, as well as the developers themselves, and the firm has enforced tight controls on what the devices could access.
This meant that Apple mobile products arguably were (and probably still are) the most secure you could buy. However a new attack dubbed XCodeGhost has done a great job of undermining Apple’s otherwise strong security.
The attack method used was cunning and, in a technical sense, impressive. Rather than attack the devices or the App Store, the hackers compromised the Xcode framework, the underlying programming system used by developers to create the apps. This is akin to poisoning a city’s water supply at its source rather than attacking the settlement’s buildings or army directly.
App developers use a suite of software known as Xcode to create programs for Apple devices. Within this is a large library of functions that enable each created app to talk to the underlying phone or tablet. Each library function has different roles, from allowing you to share your location to making your phone sound like a light sabre when you wave it around.
The hackers created a malicious program (malware) that used the internet to seek out Mac computers with Xcode installed, gambling on the possibility that some of these devices were used to create apps for the Apple App store. It then dropped contaminated code library features into the Xcode system. These will appear to do what the app developers programmed them to do but also capture and send personal data from your device back to the hackers.
Malicious intentShutterstock
Security experts are concerned that this innovative attack leaves Apple open to future attacks. It attacks anyone who has this coding environment installed on their computer system and compromises the code before it enters the secured systems offered by Apple.
Not only is this embarrassing for the company, as their checks clearly missed this compromise. It is also embarrassing for the many developers affected as their own internal security and anti-malware processes have been compromised.
What does this mean for you?
If you are the owner of an iPhone or iPad, there is nothing you can do. Apple has never offered Apple device owners the opportunity to protect their own technology. Apple has owned this, controlled this and until recently has been very successful in protecting its products.
Android-powered devices have historically been relatively vulnerable to an excess of 40,000 types of malware. The equivalent number for Apple devices remains very low. However, this new and interesting attack means that attackers have established an alternative route into your device, through the framework used by app developers. They only need one compromised app from one compromised developer machine to be successful.
Different experts have already found multiple apps, such as Angry Birds 2, that are infected. Many of these apps are being updated in earnest by their creators to patch the security breach and new versions are automatically being installed on your iPhone or iPad. If you are ultra concerned you can delete the app and re-install in a few days time when you know it has been secured.
In order to prevent further breaches, Apple must review its security policies and how it checks all code before it enters their App Store. It also means that the onus is on all developers to improve the way they scan their own systems. Otherwise, Apple will refuse to allow them to participate in this otherwise very successful and secure system.
Ok, this is not a scientific study, the audience participation is likely to be from a self selecting group etc. So lets call this a poll amongst friends, followers and like minded. A question that is structural to my research is ... Do you think simulation can replace real hardware, when teaching networking? To remain fair, I am not going to share my opinion as it is biased and please don't try and answer this to please me (as I really don't know who will be answering and if you know me, you will know that it won't). Please take a look at the top left of this blog and based on your personal opinion, answer either yes or no. You do not have to be an expert, or an academic or even a teccie, everyone's opinion in this context counts. The opinions below are valid view points, but must not contribute to your own independent decision, please complete the question before reading these. =================================...
Ok, for many who read my blog, you may be aware that I dabble with many geeky projects, some count as work. As a fan of the shiny world of Mac, I have produced a couple of creative commons resources over the years for the Cisco Academy community, covering how Packet Tracer may be ported to a Mac. Looks like we now have a potentially tidy version three offering, moving from Virtual Machine, to Play on Mac now to a fully 'bottled' app, I have this working on v 5.3.3 and v6.0 (beta) To download please follow this link and download the app for 5.3.3, it looks like it will work on .... Snow Leopard, Lion and Mountain Lion, but this I would like to see tested. Multiuser seems to work, but you MUST set a rule in your firewall to allow this, otherwise your Mac will ignore any connection attempts. Yes you will need to unzip the contents of the folder to a location that you wish to run this, I may work on a DMG file, but lets do one step at a time. Please also note, it is 2...
Last night I deliberately started a debate on a ‘teachers of programming’ forum to gauge response. As expected those who were ‘interested’ in sticking to their ideas responded. I asked the question … I am of the view that Pascal is best kept in the past, where anyone who says that they are still teaching current programming skills using this language, worries me. Am I being unreasonable? The response was defensive and encouraged those who feel that it is something they must teach to self-acknowledge this fact. My concerns regarding Pascal stem from many positions: Old technology, being taught now …. If this were current in any way I would have less of an issue. It concerns me that some still teach C, but its structure is such that it does help programmers learn something that many systems use. But Pascal’s verbose structure is from a time gone, so why? Is it being used in anger? There is a place for scratch and greenfoot in getting stude...
Comments
Post a Comment