Andrew Orr's photo

Andrew Orr

Since 2015 Andrew has been writing about Apple, privacy, security, and at one point even Android. You can find him most places online under the username @andrewornot.

Get In Touch:

NordPass Password Manager Adds Biometric Authentication for Mac

NordPass is introducing biometric authentication to Windows and macOS applications. This new feature, which previously was available on mobile devices only, will add flexibility and convenience to the login process. Instead of typing in their master password, users will be able to use their fingerprint or face ID to sign in. According to a report published by NordPass, the most common password is 123456. and relying more on biometrics would help eliminate such weak passwords. But many cybersecurity professionals note that biometric authentication on its own is not enough. The best way to ensure maximum security for your accounts is to use it along with multi-factor authentication (MFA).

Coinbase Puts a SPELL Token on You By Supporting More Cryptos

Coinbase recently added support for a bunch of cryptocurrencies. These include IDEX (IDEX), Moss Carbon Credit (MCO2), Polkastarter (POLS), ShapeShift FOX Token (FOX), Spell Token (SPELL) and SuperFarm (SUPER).

Moss Carbon Credit (MCO2) is an Ethereum token for carbon credits. The project’s goal is to combat climate change. Burning one MCO2 token on the Moss Carbon Credit platform is equivalent to offsetting one ton of CO2 footprint, which is made possible by purchasing and protecting land in the Amazon rainforest.

Get Unclutter's App Bundle Before it Expires in 72 Hours

I’m resharing my article of Unclutter’s app bundle called “The Applaudables.” The team informs me today that the deal expires in 72 hours.

Here’s how it works: You can pick any apps you like for half the price (50% OFF). Or you can get them all together at 78% OFF. Everyone is free to choose the apps they need. Pick one or more products and have them for half the price.

Telegram Adds DRM Lock for Content in Latest Update

Encrypted chat app Telegram has been updated with new features, including DRM for certain content.

With this update, we’re helping creators protect the content they publish on Telegram and ensure that it is available only for their intended audience.

Group and Channel owners who want to keep their content members-only can restrict message forwarding from their chat, which also prevents screenshots and limits the ability to save media from posts.

Does Apple Have Too Much Control Over Your iPhone?

Recode is working on a series that examines Big Tech and antitrust. Sara Morrison covers Apple in the first installment, asking “How much control should Apple have over your iPhone?” One paragraph in particular grabbed my attention:

In her book Monopolies Suck, antitrust expert Sally Hubbard described Apple as a “warm and fuzzy monopolist” when compared to Facebook, Google, and Amazon, the other three companies in the so-called Big Four that have been accused of being too big. It doesn’t quite have the negative public perception that its three peers have, and the effects of its exclusive control over mobile apps on its consumers aren’t as obvious.

Co-Founder of Swiss SMS Giant 'Mitto AG' Accused of Government Surveillance

Swiss tech company Mitto AG is trusted by companies such as Twitter and Google to deliver SMS security codes to users, appointment reminders, sales promotions, and more. It’s co-founder and COO Ilja Gorelik has been accused of selling access to Mitto’s networks for surveillance.

The existence of the alternate service was only known to a small number of people within the company, these former employees said. Gorelik sold the service to surveillance companies which in turn contracted with government agencies, according to the employees.

1inch Now Available on Ledger Live to Swap Your Cryptocurrencies

Ledger has recently added crypto swapping service 1inch to the Ledger Live app. It offers competitive transaction fees across the largest available liquidity pools.

1inch is a DeFi aggregator spanning over 120 DEXs across Ethereum, Polygon, Binance Smart Chain and Optimistic Ethereum. It provides you with competitive swapping rates across the biggest available liquidity pools. For instance, you’ll get competitive rates when you swap ETH for Tether, or AAVE for UNI. So far, these options are exclusively available on the Ethereum protocol through Ledger Live.

Safari Now Supports Wide Color Gamut 2D Graphics Using HTML Canvas

The WebKit team is out with a blog post today discussing how Safari handles color gamuts such as sRBG and Display P3.

One notable omission in wide gamut color support, until now, has been in the HTML canvas element. The 2D canvas API was introduced before wide gamut displays were common, and until now has only handled drawing and manipulating sRGB pixel values. Earlier this year, a proposal for creating canvas contexts using other color spaces was added to the HTML standard, and we’ve recently added support for this to WebKit.

Microsoft Seizes Domains From Chinese Group 'NICKEL' Used to Attack Governments

NICKEL is a China-based threat actor that targets governments, diplomatic entities, and NGOs around the world. Microsoft’s Digital Crimes Unit has disrupted their operation.

MSTIC has observed NICKEL actors using exploits against unpatched systems to compromise remote access services and appliances. Upon successful intrusion, they have used credential dumpers or stealers to obtain legitimate credentials, which they used to gain access to victim accounts. NICKEL actors created and deployed custom malware that allowed them to maintain persistence on victim networks over extended periods of time.

WhatsApp Users Can Enable Disappearing Messages by Default

WhatsApp is now letting users turn on disappearing messages for all chats by default.

Prior to Monday’s update, users had to manually enable ephemerality for each new chat with another individual. WhatsApp is additionally also giving users the option to have their messages disappear after 24 hours or 90 days, in addition to the seven-day period it originally introduced the feature with last year.

Verizon Automatically Tracks Your Data in New Update

In a new program called Verizon Custom Experience, the company is automatically opting customers in to track their data. But you can opt out.

A new program innocuously titled the “Verizon Custom Experience” is sold to users as a way for the company to “personalize our communications with you, give you more relevant product and service recommendations, and develop plans, services and offers that are more appealing to you.” To accomplish this, all a Verizon subscriber needs to do is… allow the company access to all the websites you visit, apps you use, as well as see everyone you happen to call and text.

Hundreds of Tor Servers From 'KAX17' Threaten to Deanonymize Users

Security researcher ‘Nusenu’ has uncovered hundreds of Tor servers belonging to an entity tracked as KAX17.

Grouping these servers under the KAX17 umbrella, Nusenu says this threat actor has constantly added servers with no contact details to the Tor network in industrial quantities, operating servers in the realm of hundreds at any given point.

KAX17’s focus on Tor entry and middle relays led Nusenu to believe that the group, which he described as “non-amateur level and persistent,” is trying to collect information on users connecting to the Tor network and attempting to map their routes inside it.