Thursday, March 22, 2012

Mac Malware Spreads via Topless Photos of Supermodel

from cio.com

If you should "come across" an image of sexy Russian supermodel Irina Shayk, beware. Bad Guys are using R-rated photos of Ms. Shayk to spread Mac malware.

Didn't your mom tell you not to download pictures of naked ladies? But you didn't listen, did you?
It turns out that a group of hackers is taking advantage of that common mistake and snaring Mac users in a malware trap baited with pictures of a topless Sports Illustrated swimsuit model.
The lady in question is Russian model Irina Shayk; the malware is OSX/Imuler-B, a Trojan horse, according to Graham Cluley, who blogs for Sophos , a security vendor. If you yield to temptation and click the tainted photo of Ms. Shayk, the malware launches an application that opens a backdoor to your computer and uploads private information to a remote Web server, he says. It can also take screenshots and send them to the server, another security firm found.
Although malware that targets Macs isn't as common as Windows malware, Mac users who think they are immune are simply wrong. The Mac OS is not immune to attack, and one of the main reasons it isn't targeted more often is that hackers prefer to attack the platform with the most users. And that's Windows.
The increasing popularity of Macs and mobile devices running Apple's iOS has led to an increase in iOS and Mac attacks. And like attacks directed at Windows, attacks against Macs often use social engineering to snare victims. By social engineering, I mean a ploy that tricks a user into thinking he or she is clicking on a file from a business or person they know, or a trick that plays upon greed (You've won $1 million!) or curiosity, or in this case, lust--or at least a desire to see unclothed females.
It appears that the malware was first discovered by researchers from Intego, a company that specializes in Mac security. "Two samples were found, both in zip archives: 'Pictures and the Article of Renzin Dorjee.zip' and 'FHM Feb Cover Girl Irina Shayk H-Res Pics.zip.' In both cases, an application was included among the various files, with an icon making it look like an image," Intego reported in its security blog. 
The hackers are taking advantage of a default setting in the Mac OS X Finder, whereby file extensions are not displayed. "Users double-click on the application to launch the malware, which quickly deletes itself, replacing the original application with a real JPEG image corresponding to the one that was an application, and displays this image in the user’s default image viewer. There is no visible trace of the application after this point," according to Intego's website.
In addition to the usual advice not to click on stuff from people you don't know, Intego had a very specific tip for Mac users: Go into the Finder's advanced settings and check the box that allows you to view filename extensions.
If you're curious, you can find out all about Irina Shayk with a simple Google search, but do be careful if you come across a site that promises nude photos of the model.

Tuesday, March 20, 2012

Consumer Reports Finds New iPad Gets Warm, Can't Charge Under Heavy Loads

from macrumors.com
Following up on reports from earlier today that the outer shell of the iPad 3 gets warmer than the iPad 2Consumer Reports found that their iPad 3 reached temperatures up to 116 degrees after running Infinity Blade II for 45 minutes. 

The piece did note that the iPad felt "very warm but not especially uncomfortable if held for a brief period" during the testing process. In a statement earlier today, Apple said that the iPad was "operating well within our thermal specifications." 


We ran our test while the new iPad was propped on the iPad Smart Cover, plugged in, and after it had run Infinity Blade II uninterrupted for about 45 minutes. The device's 4G connection was not turned on, though its Wi-fi link was. The ambient room temperature was about 72 degrees. (Apple recommends not using the iPad in environments over 95 degrees.)

When unplugged, the back of the new iPad reached temperatures as high as 113 degrees Fahrenheit. It was only when plugged in that it hit 116 degrees. The hottest areas weren't evenly distributed throughout the iPad's back, but were concentrated near one corner of the display as shown in the images taken from the rear of the device above.
Potentially more interesting is Consumer Reports' note that their new iPad didn't charge at all when the game was running. In fact, the battery continued to drain slightly under the extremely heavy CPU and GPU load from Infinity Blade II. 

It's seems that under extremely heavy processor usage, the iPad is unable to draw sufficient power from its USB connection to both power the device and charge the battery simultaneously. 

Thursday, March 8, 2012

Apple's big lie about job creation, and other bogus claims

from InfoWorld.com


Just look at these statistics!
Suspicious stats are a staple of tech marketing that deserve to be exposed for the flimflammery they are



Apple has created or supported more than 500,000 jobs. Phishing attacks cost the economy $234 billion a year. And giving social and mobile CRM tools to salespeople makes them 26.4 percent more productive. All these preposterous numbers are floating around the Web these days, peddled by PR people who count on easy hooks to sell their products, burnish their clients' images, or advance an agenda.

Apple's attempt at statistical flimflammery is the most offensive because it's a transparent attempt to change the public conversation about Apple from the question of atrocious labor practices in the Chinese factories that make iPhones and iPads to job creation. (Of course, yesterday's announcement of "the new iPad" will help in the diversion as well.)

Apple's bogus labor study
Here's what Apple posted on its website last week: "Throughout our history, Apple has created entirely new products -- and entirely new industries -- by focusing on innovation. As a result, we've created or supported more than 500,000 jobs for U.S. workers: from the engineer who helped invent the iPad to the delivery person who brings it to your door."

Breaking down those stats, Apple says it is responsible for 304,000 current jobs across a wide array of industries, including engineering, manufacturing, and transportation, as well as another 210,000 in the "app economy."

Apple actually employs 47,000 people in the United States, so where did the other 450,000 come from? Multipliers, a standard statistical tool that economists use to derive the effects of spending (or not spending) on the economy. But as you learned a long time ago, garbage in equals garbage out.

Take, for example, this statement: "This figure [the jobs number] also includes workers in Texas who manufacture processors for iOS products, Corning employees in Kentucky and New York who create the majority of the glass for iPhone, and FedEx and UPS employees."

Wow. Sure, delivery companies derive revenue when its drivers drop off your new iPad. But -- duh! -- they'd be working anyway delivering books from Amazon.com and towels from Bed, Bath and Beyond. Do Corning employees do nothing but make glass for the iPhone, and do those folks in the bunny suits in Texas only work to make CPUs for Apple? Obviously not. But those are the kind of assumptions built into that projection. Speaking of projections, Apple assumes that its new headquarters in Cupertino, Calif., will create 7,000 jobs.

Similarly, it assumes that "the 248,000 registered iOS developers in the U.S." develop only for Apple. I seriously doubt that. What's more, the success of iOS has obviously had a very negative effect on developers of other operating systems, such as BlackBerry, and those folks are out of work or now developing for Apple. How big is the actual gain? We can't tell, though I'm sure there is one.

I could go on at some length, but I'm sure you see my point. What's more, the timing of this release makes it all the clearer that Apple is desperately trying to clean up its badly tarnished corporate image.

Apple does create lots of jobs and makes real contributions to our economy. Inflating those numbers for the sake of favorable PR simply makes the company look petty, dishonest, and -- maybe worst of all -- contemptuous of the smarts of its customers. Likewise, security companies make products that are needed, but as their products have become more commoditized, they increasingly rely on scare tactics and bogus studies to sell their services.

If it sounds too good to be true ...
Generally, bogus numbers dazzle us with their sheer size. But there's another tactic to watch out for: amazingly exact numbers.

Witness Nucleus Research, which claims that mobile CRM makes salespeople more productive. It doesn't give just a ballpark estimate; it presents a precise number: 26.4 percent.

I read through the study and saw lots of anecdotal evidence that mobile and social CRM is helpful to salespeople. I believe it -- but how it derived that number is something we simply don't know, nor can we tell who paid for the study. One could guess.

Don't be fooled by the axis of fakery.

Wednesday, February 29, 2012

iPhone photos can be seen by others

from msn.com
Recently, we learned that the iPhone’s Address Book can be sharedwith app developers because of a flaw that Apple says it is working to fix. Now it appears that a user’s photos on the phone can be similarly accessed by various apps without users knowing it.

The photo leakage can happen once a user gives an app permission to access location information on an iPhone (or iPad or iPod Touch), according to The New York Times. The app "can copy the user’s entire photo library, without any further notification or warning, according to app developers."

It is unclear whether any apps in Apple’s App Store are illicitly copying user photos. Although Apple’s rules do not specifically forbid photo copying, Apple says it screens all apps submitted to the store, a process that should catch nefarious behavior on the part of developers. But copying address book data was against Apple’s rules, and the company approved many popular apps that collected that information.

Apple declined to comment to the newspaper; we've also asked Apple about the issue, and will update this post if we hear back.

The newspaper said it "asked a developer, who asked not to be named because he worked for a popular app maker and did not want to involve his employer, to create a test application that collected photos and location information from an iPhone. When the test app, PhotoSpy, was opened, it asked for access to location data. Once this was granted, it began siphoning photos and their location data to a remote server. 
(The app was not submitted to the App Store.)"

Developers know that "this capability exists," the Times said, but they "assumed that Apple would ensure that apps that inappropriately exploited it did not make it into the App Store. Based on recent revelations, phone owners cannot be sure."

Friday, February 24, 2012

Flashback Mac trojan is back with new and improved exploit strategy

from arstechnica.com



The "Flashback" Mac trojan is back, and it's smarter than ever. Mac security company Intego says the latest variant, Flashback.G, uses three new methods in order to make its way onto Macs, though it won't install itself at all if it detects a number of antivirus or anti-malware security programs already installed.
"The malware first tries to install itself using one of two Java vulnerabilities. If this is successful, users will be infected with no intervention," Intego wrote on its Mac Security Blog on Thursday. "If these vulnerabilities are not available—if the Macs have Java up to date—then it attempts a third method of installation, trying to fool users through a social engineering trick. The applet displays a self-signed certificate, claiming to be issued by Apple. Most users won’t understand what this means, and click on Continue to allow the installation to continue."
The Intego team believes the latest Flashback variant won't install when it detects security software in order to avoid detection, instead choosing to move onto the plethora of other Macs that aren't protected. As for what it does, the malware injects code into apps that can access the network and then searches for usernames and passwords to exploit, and can even automatically update itself if its developers decide to push out an update.

Saturday, February 11, 2012

Apple is Stealing Address Books

from gizmodo.com

It's not really a secret, per se, but there's a quiet understanding among many iOS app developers that it is acceptable to send a user's entire address book, without their permission, to remote servers and then store it for future reference. It's common practice, and many companies likely have your address book stored in their database. Obviously, there are lots of awesome things apps can do with this data to vastly improve user experience. But it is also a breach of trust and an invasion of privacy.
I did a quick survey of 15 developers of popular iOS apps, and 13 of them told me they have a contacts database with millons of records. One company's database has Mark Zuckerberg's cell phone number, Larry Ellison's home phone number and Bill Gates' cell phone number. This data is not meant to be public, and people have an expectation of privacy with respect to their contacts.
There are two major questions to ask about this behavior:
First, why does Apple allow iOS apps to access a user's entire address book, at any time, without permission? Even Android requires that apps ask for explicit permission to access local contacts. On iOS, every other seemingly private local data source, like location and the camera roll, have strong protections; apps can't even see photos in the Camera Roll unless the user explicitly selects them from the image picker. There is a huge section of the Settings app dedicated to giving people fine control over which apps have access to location information. That Apple provides no protections on the Address Book is, at best, perplexing.
Second, why do app developers, who know of the potential public backlash if this behavior were publicized (that's why they keep it quiet), continue to upload user address books to their servers? I think this question is easier to answer. Any app is an investment, and, like any investment, there are three outcomes -- success, failure, and mediocrity. The only one that matters on a market like the App Store is success, so fledgling app developers do everything they can to increase their chances. Because Apple provides extremely easy access to address book data, the pro -- that is, using the data to improve user experience, increase virality and growth, etc. -- outweighs the con. To stay on equal footing, larger apps, like Yelp, Facebook, and Foursquare, have to follow along. From a design perspective, it is a concession of user growth at the expense of user trust.
Through the feedback we’ve received from all of you, we now understand that the way we had designed our ‘Add Friends’ feature was wrong. We are deeply sorry if you were uncomfortable with how our application used your phone contacts.
There was similar outrage last year, when Kik was outed. But, after a while, things calmed down. Kik never conceded. Developers continued to stay quiet. Users forgot about it entirely.
Apple's Failure
I fully believe this issue is a failure of Apple and a breach of trust by Apple, not by app developers. The expectation of Address Book privacy is obvious; in fact, one person on Hacker News, in response to learning about Path's use of the data, said, "Apple would never do this to their users." Because Apple has your trust and yet gives this private information freely to developers, Apple does do this to their users. All of them.
Usually, when I am curious about something Apple has done, I try to understand the design thinking that went into the decision. In this case, I can't think of a rational reason for why Apple has not placed any protections on Address Book in iOS. It makes no sense. It is a breach of my privacy, and it has allowed every app I've installed to steal my address book.

Friday, February 3, 2012

iOS Less Stable than Android

from forbes.com
OS stability has always been a big concern when choosing which device you’re going to upgrade to. When it comes to the battle between Android and iOS, Apple fanboys would have you believe that their mobile OS is a smooth and steady as an ocean liner, but as history has taught us, some titans — sink. In my talks with friends and acquaintances on why they’ve chosen iOS over Android, I’ve heard everything from, “It just works,” to the argument that “Android is just too fragmented,” or “Apps constantly force close.”
Well, then you would assume that data gathered from Crittercism — a research startup that analyzes mobile app crashes — would show that iOS suffers from fewer, if any, app crashes when compared to Android. Right? Wrong.
Surprisingly,  Crittercism’s data (gathered from more than 214 million app launches between November and December of 2011) shows that apps on iOS crashed much more frequently than comparable apps on Android. Just take a look at that pie graph. It’s easily dominated by iOS, covering nearly 75% of total crashes. Yup. I was just as blown away as you. Numbers don’t lie.
Now, the reasons for these app crashes are numerous. Everything from iOS 5 being new to the market, problems with hardware, internet connectivity, language support, or just plain ‘ol poorly coded apps. It can even be argued that because there are so many more iOS devices than Andr– oh, wait. I almost forgot. There isn’t.
Even with this newly released data, I almost still don’t believe it. Android. With all the talks of fragmentation, force closes and incompatible apps, could somehow turn out to be more stable than iOS? Well, slap my momma and call me Sally. Who’d-a-thunkit. Now, I’m sure this will come off as the flames of an Android fanboy but I assure you, I’m not hating. Just found this information interesting and felt like sharing. Did this data surprise any of you?