🔺NEW: Apple is expanding Private Cloud Compute (PCC) beyond our data centers. PCC on Google Cloud: NVIDIA Confidential Computing, Intel TDX, and Google's Titan chip, with capabilities that go far beyond a traditional confidential computing deployment. https://t.co/DF2Hw8HUZH
🔺NEW: Formally verified post-quantum ML-KEM and ML-DSA in corecrypto, with correctness proven from the FIPS spec down to hand-optimized ARM64 assembly — a world first at multi-billion device scale. And we're releasing our Isabelle libraries, ARM64 model, and Cryptol-to-Isabelle translator to advance the state of the art in verified cryptography! https://t.co/LZPHFD0ifE
IDA has a plugin manager now! I hope this makes it so much easier for you to try new extensions, like after the Plugin Contest.
https://t.co/Ldksfu9l4n
🍺 Today I'm proud to announce @MacHomebrew 5.0.0 bringing you download concurrency by default, official support for Linux ARM64/AArch64, timescales for deprecating macOS Intel and removing macOS Gatekeeper bypass behaviours.
Read more at https://t.co/KFDwikOJqd
🔺iPhone models announced today include Memory Integrity Enforcement, the culmination of an unprecedented design and engineering effort that we believe represents the most significant upgrade to memory safety in the history of consumer operating systems. https://t.co/ule9gaXzc1
I have often stated that well-implemented memory tagging will be a game changer for memory corruptions. And it seems that with the next iPhone it's finally here: https://t.co/qNGiVxPQdh
Just posted my @defcon slides (talk #1): "Mastering Apple's Endpoint Security for Advanced macOS Malware Detection"
Writing 🍎 security software? You should be using Endpoint Security! But its advanced features are rather nuanced & often misunderstood 🫣
https://t.co/TRn6dRnjV5
🔺New on Apple Security Research blog: a deeply comprehensive Private Cloud Compute security guide, and an unprecedented Virtual Research Environment allowing you to run production PCC software right on your Mac with Apple silicon. And up to a $1M bounty!
https://t.co/a8yyEza8rd
Applications are now open for this year’s Apple Security Research Device through October 31 🎃
The program accepts applications from qualified security researchers — including those who have research experience but are new to iOS. Apply today!
https://t.co/p1cdHZK7aT
The time has come, and with it your reading material for the week.
Phrack #71 is officially released ONLINE! Let us know what you think!
https://t.co/BRnK9lnGjI
Apple deserves a lot of credit today for having the foresight and the willpower to restrict MacOS agents to simpler interfaces. https://t.co/e1z4qIokx7
🔺New on the Apple Security Research blog: introducing PQ3, a groundbreaking post-quantum cryptographic protocol for iMessage. To our knowledge, PQ3 has the strongest security properties of any at-scale messaging protocol in the world. https://t.co/NIyeXjVne6
With iOS 17.2 and macOS 14.2 now released, Contact Key Verification 🔐 is available for everybody to enable. Very proud of the work the team has done to ship this groundbreaking feature and advance the state of iMessage security!
https://t.co/8yq9BhJQxc