Andrew Orr's photo

Andrew Orr

Since 2015 Andrew has been writing about Apple, privacy, security, and at one point even Android. You can find him most places online under the username @andrewornot.

Get In Touch:

Smart Home Cameras, Baby Monitors Affected by Software Bug

A flaw in the ThroughTek “Kalay” network affects millions of IoT devices including smart baby monitors, DVRs, smart cameras, and other products.

this latest vulnerability allows attackers to communicate with devices remotely. As a result, further attacks could include actions that would allow an adversary to remotely control affected devices and could potentially lead to remote code execution.

Due to how the Kalay protocol is integrated by original equipment manufacturers (“OEMs”) and resellers before devices reach consumers, Mandiant is unable to determine a complete list of products and companies affected by the discovered vulnerability.

Mastercard Moves to Phase Out Use of Magnetic Stripe by 2024

Mastercard announced on Monday a plan to phase out usage of magnetic stripes on its cards, and says it is the first payments network to do so.

Based on the decline in payments powered by magnetic stripes after chip-based payments took hold, newly-issued Mastercard credit and debit cards will not be required to have a stripe starting in 2024 in most markets. By 2033, no Mastercard credit and debit cards will have magnetic stripes, which leaves a long runway for the remaining partners who still rely on the technology to phase in chip card processing.

GitHub No Longer Accepts Passwords, Use Security Keys Instead

GitHub will no longer accept passwords when authenticating Git operations and will require the use of strong authentication factors. Yubico also posted about the announcement here, and its 2FA hardware keys are an acceptable solution for GitHub users.

In December, we announced that beginning August 13, 2021, GitHub will no longer accept account passwords when authenticating Git operations and will require the use of strong authentication factors, such as a personal access token, SSH keys (for developers), or an OAuth or GitHub App installation token (for integrators) for all authenticated Git operations on GitHub.com. With the August 13 sunset date behind us, we no longer accept password authentication for Git operations.

(Update) T-Mobile Customer Data for Sale Affecting Over 100 Million People

A person in an online forum is offering data for sale that they claim comes from T-Mobile servers. The carrier says it is investigating the accuracy of this alleged breach.

The data includes social security numbers, phone numbers, names, physical addresses, unique IMEI numbers, and driver licenses information, the seller said. Motherboard has seen samples of the data, and confirmed they contained accurate information on T-Mobile customers.

Update: T-Mobile has issued a statement confirming the breach.

Add a Free COVID-19 Vaccine Passport to Apple Wallet Using VaxYes

Congratulations on being fully vaccinated against COVID-19! Now? Well, you can take a photo of your record or scan it into Files/Apple Notes. And with a service called VaxYes from gogetdoc you can add it to Apple Wallet for greater convenience. You’ll have to give them a picture of your vaccine card as well as a photo of your ID. The company uses AES-256 encryption (referred to as “military grade”) and is fully compliant with HIPAA. Gogetdoc has HIPAA-trained quality control agents and medical staff to ensure appropriate details are collected for verification of the record before issuing a digital vaccine card. Tap on “Get a Free Vaccine Passport” and follow the onscreen instructions. I did it and the process to get the Wallet passport took about 60 seconds. If you live in the UK you can get a passport with this article.

Scrabble-Like Game ‘wurdweb’ Now Available on Apple Arcade

Apple Arcade players who love puzzles should check out the new game wurdweb. Grab words from a list and cross them with words on the board. Puzzle your way towards a Finish Tile, put down enough words, or put down as many
words as you can. In this game, you’ll find: Infinite unique puzzles, generated by an intelligent algorithm; Tangle Mode, where you pick up extra words to put down 15 words; Precise Mode, where puzzles have a single solution; Daily, Weekly and Monthly Mode, where you put down as many words as you can. On top of that, you’ll also find; 20+ word themes, some of which are rather…peculiar; Plenty of puzzle variations to challenge how you play; Cute little characters who walk around in your puzzles doing absolutely nothing. Play with controllers compatible with your device.

Ledger Crypto Wallet Now Supports Staking ETH With Lido

Owners of the Ledger hardware wallet can now stake their ETH through Lido as it transitions to Ethereum 2.0.

By staking ETH with Lido, you don’t need to own 32 ETH to become a network validator. Lido allows users to participate in the network with any amount of ETH. You don’t need to maintain complex infrastructure whilst preserving the liquidity of your ETH. Indeed, for each Ether you’ll stake through LIDO you’ll receive stETH in exchange.

USDC Co-Creator ‘Circle’ Wants to Become a Traditional Bank

Circle, along with Coinbase, operates USD Coin (USDC) a cryptocurrency that has its valued pegged to the US dollar. Coins of this nature are known as stablecoins. Circle has announced its intentions to become a traditional, FDIC-insured bank. Could this pave the way for USDC to become the de facto digital currency of the U.S.? Axios has a good summary.

Circle chief strategy officer Dante Disparte tells Axios that the company hasn’t yet even properly initiated the process of applying to become a bank; it’s just announced its intention to do so. Disparte says they’re willing to do “whatever the policymakers want.”