Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Apple found ‘no evidence’ Mail flaw was used against iPhone, iPad users
MacDailyNews ^ | Friday, April 24, 2020 | MDN Staff

Posted on 04/25/2020 9:49:20 PM PDT by Swordmaker

Apple said on Thursday it has found “no evidence” a flaw in their Mail app for iPhones and iPads has been used against customers, and that it believes the flaw does “not pose an immediate risk to our users.”

Reuters—iOS email exploitSan Francisco-based cybersecurity firm ZecOps on Wednesday detailed a flaw that it said may have left more than half a billion iPhones vulnerable to hackers. Zuk Avraham, ZecOps’ chief executive, told Reuters he found evidence the vulnerability was exploited in at least six cybersecurity break-ins

On Thursday, Apple disputed Avraham’s evidence that the hack had been used against users.

“We have thoroughly investigated the researcher’s report and, based on the information provided, have concluded these issues do not pose an immediate risk to our users,” Apple said in a statement. “The researcher identified three issues in Mail, but alone they are insufficient to bypass iPhone and iPad security protections, and we have found no evidence they were used against customers.”

MacDailyNews Take: ZecOps maintained it found evidence of related hacks against “a few organizations” and that it would share additional technical information once Apple released its software update to the public which are expected soon.

Regardless, due to the existence of this flaw, we recommend users stop using Mail on iPhone, iPad, and/or iPod touch devices for now and as soon as iOS 13.4.5 and iPadOS 13.4.5 become available, update your devices!


TOPICS: Business/Economy; Computers/Internet; Education
KEYWORDS: applepinglist; iossecurity; iphoneipad
I don’t recommend not using Mail. My analysis show the concatenation of events to allow exploit of this obscure vulnerability, which requires the attacker to seize control of your email server first, is so extreme as to be beyond comprehension. It is entirely speculative, not a real exploit in the wild.
1 posted on 04/25/2020 9:49:20 PM PDT by Swordmaker
[ Post Reply | Private Reply | View Replies]

To: ~Kim4VRWC's~; 1234; 5thGenTexan; AbolishCSEU; Abundy; Action-America; acoulterfan; AFreeBird; ...
Apple has found no evidence ZecOp vulnerability in iOS Mail has escalated to any exploitable level. Deems it not serious. . . just as I analyzed it. —PING!


APPLE iOS Mail Vulnerability PING!

If you want on or off the Apple/Mac/iOS Ping List, Freepmail me.

2 posted on 04/25/2020 9:52:55 PM PDT by Swordmaker (My pistol self-identifies as an iPad, so you must accept it in gun-free zones, you hoplophobe bigot!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker

Thank you.


3 posted on 04/25/2020 9:57:43 PM PDT by Falconspeed
[ Post Reply | Private Reply | To 2 | View Replies]

To: Swordmaker

Thanks!


4 posted on 04/25/2020 10:46:26 PM PDT by BullDog108 (A Smith & Wesson beats four aces!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Swordmaker
Hey Swordmaker,

I finally did it... went online Friday night and ordered the new SE2020 phone, picked it up at a nearby Verizon store yesterday, and shortly after, was able to set my old trusty 5c on the shelf.... well, eh, not quite, it turns out...

Being an IT guy, my phone has upwards of thirty Two-Factor Authentication (2FA, a.k.a. MFA) entries, in three auth apps: Google Auth, Microsoft Auth, Duo Mobile. And while it’s not really surprising, it was annoying to learn that the auth apps’ application data is -not- transferred to a new phone. I guess it makes sense security-wise, but I had hoped that it would transfer and then require some sort of verification to become active on the new device.

Alas, no, I have to re-enter data, regenerate and rescan 25 QR-code images at Amazon AWS, run an Azure Admin re-auth cycle, and run a Duo re-auth cycle. In the meantime, the Google and MS auth apps are still generating valid TOTP 6-digit codes on the OLD phone, so I’m carrying two phones until everything is recreated on the new one.

Word to the wise — 2FA/MFA is a constant PITA. I’ll live, it’s not like losing my contacts (which transferred fine). But I’ll never get those hours back.

And I like the new phone. Very snappy.

5 posted on 04/25/2020 10:54:56 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 2 | View Replies]

To: dayglored

I’ve got an older SE with the home button. Nice phone — inexpensive and small.


6 posted on 04/25/2020 11:15:12 PM PDT by Yardstick
[ Post Reply | Private Reply | To 5 | View Replies]

To: Swordmaker

Thanks SM.


7 posted on 04/25/2020 11:25:13 PM PDT by Mark17 (Father of US Air Force Officer in pilot training. Flew the DA-20 and T-6. One more aircraft to go.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: dayglored
I’ve been thinking about getting the new SE to replace my 6s. I can’t stand the ugly notch on the X and 11, and the idea of having a phone that depends entirely upon gestures doesn’t interest me. The home button just feels to me like it gives more direct control over the phone, and TouchID makes a lot more sense in general for using Apple Pay, and in the age of face masks FaceID is useless anyway. I also don’t want a phone that won’t fit in a pocket and that is hard to hold and operate with one hand. Flagship phones keep growing to the point where it will soon be like trying to hold an iPad mini. I don’t get it.

The reviews I’ve seen have said that the camera on the SE, aside from only having a single lens, produces photos and videos that are nearly indistinguishable from those produced by the 11 and 11 Pro. That, combined with wireless charging, faster performance, and the fact that with the A13 it will be supported for several more years seems to make it a no-brainer at $399.

8 posted on 04/25/2020 11:32:23 PM PDT by noiseman (The only thing necessary for the triumph of evil is for good men to do nothing.`)
[ Post Reply | Private Reply | To 5 | View Replies]

To: noiseman

My reasons for waiting for the SE to reappear for sale are essentially identical to yours. And I am very pleased on all counts.


9 posted on 04/26/2020 12:01:14 AM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 8 | View Replies]

To: Swordmaker

By any chance, have you been following Apple’s interest in its own processor?


10 posted on 04/26/2020 1:27:39 AM PDT by Gene Eric (Don't be a statist!)
[ Post Reply | Private Reply | To 2 | View Replies]

To: dayglored

Thanks for the warning.. hubby wants the new iPhone. I will plan a weekend with the girls.


11 posted on 04/26/2020 3:21:37 AM PDT by momincombatboots (Ephesians 6... who you are really at war with)
[ Post Reply | Private Reply | To 5 | View Replies]

To: momincombatboots

Sounds like a plan. :-)


12 posted on 04/26/2020 8:46:59 AM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 11 | View Replies]

To: dayglored

You didn’t transfer phone numbers to the new SE from the old iPhone 5c? I’ve never had problems with two-factor security when I did the transfer by just transferring phone numbers from the old to the new. Strange... have they changed two-factor since I upgraded from my old IPhoneX to the iPhone11 Pro?


13 posted on 04/26/2020 9:27:21 AM PDT by Swordmaker (My pistol self-identifies as an iPad, so you must accept it in gun-free zones, you hoplophobe bigot!)
[ Post Reply | Private Reply | To 5 | View Replies]

To: dayglored

Oh, Congratulations on the upgrade to the SE.


14 posted on 04/26/2020 9:27:54 AM PDT by Swordmaker (My pistol self-identifies as an iPad, so you must accept it in gun-free zones, you hoplophobe bigot!)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Gene Eric
By any chance, have you been following Apple’s interest in its own processor?

Of course. There are always rumors that Apple will be bringing out Macs based on the A Series processor... soon. That’s the rumor for several “soon” years now. I saw it last week, too. I will give it more credence when they announce one. It would require a major shift in focus for software makers akin to when Apple switch from the PowerPC processor to Intel back in 2001.

They may do it for lower end MacBooks and iMacs at first, but not for higher end, maintaining Windows compatibility for higher end machines, until the A series processor can produce power similar to the Xeon for Mac Pros, plus having a Rosetta like application to run legacy Mac software on A processor Macs to allow a transition over a period of years, again as they did during the PowerPC to Intel Transition.

15 posted on 04/26/2020 9:35:05 AM PDT by Swordmaker (My pistol self-identifies as an iPad, so you must accept it in gun-free zones, you hoplophobe bigot!)
[ Post Reply | Private Reply | To 10 | View Replies]

To: noiseman

Hm, I didn’t realize the new SE kept the home button. That’s something I like about my old SE.


16 posted on 04/26/2020 10:08:51 AM PDT by Yardstick
[ Post Reply | Private Reply | To 8 | View Replies]

To: Swordmaker
The Verizon tech switched the phone number over, and did an iTunes backup/restore to move all the apps and data. But I think the auth apps must read and store something about the physical phone (model, S/N, etc.) that they are installed and run on, and defend against a Bad Guy who got his hands on a backup set and restored it to a different physical phone.

In any case, under the security guidelines of rotating passwords and re-registering security devices periodically, as a security-minded IT Guy, I must admit that it’s overall a good thing despite the transient inconvenience.

I’m already very comfortable with the SE as a replacement for the 5c. Apple did the right thing keeping that form factor alive. Not everybody needs the high-end feature set and larger size. :-)

17 posted on 04/26/2020 10:44:11 AM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government."`)
[ Post Reply | Private Reply | To 13 | View Replies]

To: Swordmaker

>> It would require a major shift in focus for software makers akin to when Apple switch from the PowerPC processor to Intel back in 2001.

Definitely.

I have a variety of gear, and typically capitalize over a 5 year window. I still have another 3 years on a 2017 mac pro cylinder. Not keen on dealing with a processor experiment down the road.


18 posted on 04/27/2020 12:27:16 AM PDT by Gene Eric (Don't be a statist!)
[ Post Reply | Private Reply | To 15 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson