'Shrootless' macOS Bug Could Bypass System Integrity Protection

Microsoft reported a macOS vulnerability it calls Shrootless. It could let an attacker bypass SIP and perform arbitrary operations on the device. It has been patched by Apple with the most recent Mac updates this week.

We found that the vulnerability lies in how Apple-signed packages with post-install scripts are installed. A malicious actor could create a specially crafted file that would hijack the installation process. After bypassing SIP’s restrictions, the attacker could then install a malicious kernel driver (rootkit), overwrite system files, or install persistent, undetectable malware, among others.

Twitter 'Super Follows' is Now Available for All iPhone Users

Super Follows is a new Twitter feature that lets creators make money through subscriptions. It has now rolled out to all iPhone users.

The feature launched in September after first being announced in February. Super Follows are another tool for creators to earn money through the social media platform. Eligible accounts are able to set the price for Super Follow subscriptions, with the option of charging $2.99, $4.99 or $9.99 per month. Creators can choose to mark some tweets for subscribers only while continuing to reach their unpaid follower base in regular tweets.

Blockchains Aren't as Private as You Think, But They Could Be

Cybersecurity expert Mashael Al Sabah was recently featured on MIT’s Business Lab podcast. She talks about privacy issues with blockchain technology and how they can be fixed. You can listen to the podcast with the link below (direct link on Apple Podcasts), and.or read the podcast transcript.

A lot of people think that they are completely anonymous when they use Bitcoin, and this gives them a false sense of security. In our research, what we did is that we crawled social media, like there’s popular forum for Bitcoin users called Bitcointalk.org, and we crawled Twitter as well for Bitcoin addresses that users attributed to themselves. In some forums, people share their Bitcoin addressees along with their profile information. So, now you have the public profile information, which includes usernames, emails, age, gender, city.

A Closer Look at Apple's $20 Polishing Cloth

The folks over at iFixIt have done their traditional teardown of the new MacBook Pro. They also took the time to tear apart the $20 polishing cloth Cupertino has begun selling. The cleaning cloth feels like the inner lining of an iPad Smart Cover, they say. That accessory features a thin layer of microfiber on the inside. Both apparently have a synthetic leather feel to them along with a bit of fuzziness

The new Apple Polishing Cloth earns a 0 out of 10 on our repairability scale, for distracting us from a very important MacBook Pro teardown and not going back together after we cut it into pieces with scissors.