The Consumer Technology Association (CTA) announced that attendees going to CES 2022 will be required to show proof of COVID-19 vaccination.
Articles by Andrew Orr
Corellium Will Award Researchers to Examine Apple CSAM Scanning Claims
On Tuesday Corellium announced the launch of the Corellium Open Security Initiative. It will support independent public research of mobile security.
Adobe Photoshop for iPad Gets Healing Brush, Magic Select, and Canvas Projection
Adobe has announced updates on Tuesday for its products on iPad and desktop. Photoshop Beta also debuts this month.
Smart Home Cameras, Baby Monitors Affected by Software Bug
A flaw in the ThroughTek “Kalay” network affects millions of IoT devices including smart baby monitors, DVRs, smart cameras, and other products.
this latest vulnerability allows attackers to communicate with devices remotely. As a result, further attacks could include actions that would allow an adversary to remotely control affected devices and could potentially lead to remote code execution.
Due to how the Kalay protocol is integrated by original equipment manufacturers (“OEMs”) and resellers before devices reach consumers, Mandiant is unable to determine a complete list of products and companies affected by the discovered vulnerability.
Mastercard Moves to Phase Out Use of Magnetic Stripe by 2024
Mastercard announced on Monday a plan to phase out usage of magnetic stripes on its cards, and says it is the first payments network to do so.
Based on the decline in payments powered by magnetic stripes after chip-based payments took hold, newly-issued Mastercard credit and debit cards will not be required to have a stripe starting in 2024 in most markets. By 2033, no Mastercard credit and debit cards will have magnetic stripes, which leaves a long runway for the remaining partners who still rely on the technology to phase in chip card processing.
Twitter Hires Crypto Developer for Decentralized Network Project
Twitter has hired crypto developer Jay Graber to lead its efforts to build a decentralized social network, dubbed “bluesky.”
GitHub No Longer Accepts Passwords, Use Security Keys Instead
GitHub will no longer accept passwords when authenticating Git operations and will require the use of strong authentication factors. Yubico also posted about the announcement here, and its 2FA hardware keys are an acceptable solution for GitHub users.
In December, we announced that beginning August 13, 2021, GitHub will no longer accept account passwords when authenticating Git operations and will require the use of strong authentication factors, such as a personal access token, SSH keys (for developers), or an OAuth or GitHub App installation token (for integrators) for all authenticated Git operations on GitHub.com. With the August 13 sunset date behind us, we no longer accept password authentication for Git operations.
Thousands of Wikipedia Pages Vandalized With Swastikas
On Monday morning thousands of Wikipedia pages were vandalized with swastikas. The vandalism was reversed and admins are fixing the issue.
Pearson Settles With SEC, Pays $1 Million Fine Over Data Breach
The U.S. Securities and Exchange Commission announced a settlement with Pearson, a company that provides software to schools, which will pay US$1 million.
Dashlane Password Manager Releases Mac Catalyst App
Dashlane announced on Monday that its Mac app now supports Catalyst, and says it is the first password manager in the Mac App Store to do so.
(Update) T-Mobile Customer Data for Sale Affecting Over 100 Million People
A person in an online forum is offering data for sale that they claim comes from T-Mobile servers. The carrier says it is investigating the accuracy of this alleged breach.
The data includes social security numbers, phone numbers, names, physical addresses, unique IMEI numbers, and driver licenses information, the seller said. Motherboard has seen samples of the data, and confirmed they contained accurate information on T-Mobile customers.
Update: T-Mobile has issued a statement confirming the breach.
Blockchain Project ‘Polygon’ Acquires Hermez, Native Tokens to Merge
Polygon has announced its acquisition of Hermez Network, a ZK-Rollups-based Ethereum scaling solution, for US$250 million.
Smart Home Connectivity Standard ‘Matter’ Delayed to 2022
Matter, a connection standard for smart home devices backed by Apple, Amazon, Google, and others, has delayed its rollout until 2022.
Facebook Adds End-To-End Encryption to Messenger Calls, Instagram DMs
Facebook has begun rolling out end-to-end encryption for Messenger calls and Instagram DMs, bringing greater security and privacy to users.
Reddit Adds Video Feed Button to its iOS App to Highlight User Videos
Reddit is rolling out a video feed button in its iOS app to let users view video content in a TikTok-like feed.
Add a Free COVID-19 Vaccine Passport to Apple Wallet Using VaxYes
Congratulations on being fully vaccinated against COVID-19! Now? Well, you can take a photo of your record or scan it into Files/Apple Notes. And with a service called VaxYes from gogetdoc you can add it to Apple Wallet for greater convenience. You’ll have to give them a picture of your vaccine card as well as a photo of your ID. The company uses AES-256 encryption (referred to as “military grade”) and is fully compliant with HIPAA. Gogetdoc has HIPAA-trained quality control agents and medical staff to ensure appropriate details are collected for verification of the record before issuing a digital vaccine card. Tap on “Get a Free Vaccine Passport” and follow the onscreen instructions. I did it and the process to get the Wallet passport took about 60 seconds. If you live in the UK you can get a passport with this article.
Scrabble-Like Game ‘wurdweb’ Now Available on Apple Arcade
Apple Arcade players who love puzzles should check out the new game wurdweb. Grab words from a list and cross them with words on the board. Puzzle your way towards a Finish Tile, put down enough words, or put down as many
words as you can. In this game, you’ll find: Infinite unique puzzles, generated by an intelligent algorithm; Tangle Mode, where you pick up extra words to put down 15 words; Precise Mode, where puzzles have a single solution; Daily, Weekly and Monthly Mode, where you put down as many words as you can. On top of that, you’ll also find; 20+ word themes, some of which are rather…peculiar; Plenty of puzzle variations to challenge how you play; Cute little characters who walk around in your puzzles doing absolutely nothing. Play with controllers compatible with your device.
Ledger Crypto Wallet Now Supports Staking ETH With Lido
Owners of the Ledger hardware wallet can now stake their ETH through Lido as it transitions to Ethereum 2.0.
By staking ETH with Lido, you don’t need to own 32 ETH to become a network validator. Lido allows users to participate in the network with any amount of ETH. You don’t need to maintain complex infrastructure whilst preserving the liquidity of your ETH. Indeed, for each Ether you’ll stake through LIDO you’ll receive stETH in exchange.
USDC Co-Creator ‘Circle’ Wants to Become a Traditional Bank
Circle, along with Coinbase, operates USD Coin (USDC) a cryptocurrency that has its valued pegged to the US dollar. Coins of this nature are known as stablecoins. Circle has announced its intentions to become a traditional, FDIC-insured bank. Could this pave the way for USDC to become the de facto digital currency of the U.S.? Axios has a good summary.
Circle chief strategy officer Dante Disparte tells Axios that the company hasn’t yet even properly initiated the process of applying to become a bank; it’s just announced its intention to do so. Disparte says they’re willing to do “whatever the policymakers want.”
Researchers Propose New Way to Limit Location Tracking With ‘Pretty Good Phone Privacy’
Researchers have proposed a way to limit smartphone tracking from carriers. It’s called Pretty Good Phone Privacy.
Senators Introduce Bill That Could Force Apple to Allow Third-Party App Stores
U.S. Senators Richard Blumenthal (D-CT), Marsha Blackburn (R-TN), and Amy Klobuchar (D-MN) introduced the Open App Markets Act on Wednesday.
Netflix Bans Residential IP Addresses in Latest Crackdown
Netflix is intensifying its battle to ban users of VPNs and proxies. It now bans residential IP addresses.
Satechi Releases 2021 iMac USB-C ‘Clamp Hub’
On Thursday Satechi unveiled a USB-C hub that clamps onto the 2021 M1 iMac. It’s available to purchase for US$54.99.
Apple Releases iOS 15 Public Beta 5, Omitting Certain Information
On Wednesday Apple released iOS | iPadOS 15 public beta 5 for testers. It includes a host of bug fixes and improvements.