🚀🤘Introducing Psylo: A New Kind of Private Browser
After 9 months of development, we're super excited to finally launch Psylo, a new kind of private web browser for iOS and iPadOS.
In Psylo, each tab is its own “silo” with isolated storage, cookies, and even its own IP address. Psylo introduces advanced anti-tracking and anti-fingerprinting features that go beyond what a VPN can offer, thanks to the deep integration between Psylo and our own Mysk Private Proxy Network.
Psylo is backed by years of insights from our privacy research at Mysk. Psylo is available today on the App Store as a monthly or annual subscription with a free 3-day trial.
Read the full announcement blog post on our blog: https://t.co/ff3ZJqGpc1
Small correction: iPhone users were vulnerable to phishing attacks for years, not months.
Apple Passwords had been using insecure HTTP by default since the feature to detect compromised passwords was introduced in iOS 14. The dedicated Passwords app in iOS 18 was essentially a repackaging of the old password manager that was in the Settings, and it carried along all of its bugs.
Since iOS 18 launched, the new Passwords app has been using unencrypted HTTP to download icons for password entries—a potential #security risk. We reported this bug to #Apple in September, and it’s finally fixed in #iOS 18.2 (CVE-2024-54492). Why does this matter? Watch 🎬 :
If you delete the App Store app hoping that you'd force iOS to open App Store links in the browser, you're mistaken. iOS will refuse to open the links in your browser and prompts you to restore the App Store app first. As of iOS 18.2, iPhone users can't view iOS apps without sharing identifiable analytics with #Apple.
Side notes: Deleting the App Store app is a new feature in iOS 18.2 only available to EU users. The App Store website supports mobile browsers as shown in the screenshot taken from an Android device.
#privacy #Apple
In iOS 18.2, EU users will be able to delete the App Store app. You get a warning message before deleting the app. You can re-install the app from the Settings app. A similar but shorter warning message is also shown when deleting an alternative marketplace app.
#iOS#DMA#EU
This is an example of what the App Store app shares with #Apple when you search for an app. Everything you type in the search field is recorded as an event and associated with your Apple ID before it is sent to Apple. When I search for "Google Authenticator," events are recorded as I type character by character. The leap between rows 78 and 79 is when I picked a suggestion. The timestamp of every event is recorded. This means Apple can calculate my typing speed 🙃. If I misspell a word, it will be on my record 🫣.
Data is sent to Apple in near real-time (the difference between the Event Time and the Post Time).
There is no way you can opt out of sending such app Analytics to Apple or request it be anonymous. Visit privacy[.]apple[.]com and request a copy of your data to learn what identifiable data Apple collects about you. ✌️
#Privacy #iOS
🚨 Mainstream media spreads misinformation about Telegram encryption while covering the arrest of Pavel Durov in France.
In this report, CNN puts #Telegram ahead of #WhatsApp in terms of strong encryption 🤯
This will definitely lead many users to pick wrong #privacy options.
Deleting Apple's App Store isn't a viable option in practice. The vast majority of the developers aren't willing to accept the new terms so that they offer their apps on alternative marketplaces. Many popular apps will only be available on the App Store
https://t.co/tQ7MJJ8w88
The community note is inaccurate. The claim "Find My is end-to-end encrypted" generally is misleading. Online devices report their location to Apple without end-to-end encryption even with Advanced Data Protection is on. This makes it possible to look up a device’s location through Find My by logging in to icloud[.]com. We intercepted the HTTPS traffic of Find My on icloud[.]com, and it clearly shows that Apple can see the location of every online device.
End-to-end encryption only applies when offline devices report their location through the Find My network, which relies on other nearby devices reporting their own location.
#Privacy #Cybersecurity #Apple
This feature will be very convenient but it will require users to grant WhatsApp access to the local network. A Meta app wouldn't spare a chance to scan local devices and harvest more information about users. Access to the local network can facilitate device fingerprinting.
🔔 Soon after we published our findings about the App Store collecting exhaustive and identifiable usage data, we were approached by law enforcement in the U.S. to help them navigate through the usage data they obtained from Apple for a suspect. They presented a court order to #Apple. As we showed, there's no way to turn off sharing the App Store usage data with Apple. As every iPhone or iPad user must use the App Store to install apps, Apple maintains this identifiable data about every user.
#iOS #Privacy #PrivacyMatters
Apps installed from alternative marketplaces don't seem to have categories, but the same apps installed from the App Store do 😵💫 This has an impact on Screen Time and parental control. (Limits added on the category "Games" won't apply to games installed from other stores) 🎬
Our recent encounter with Signal has revealed a new face of Signal as a project and team; one of exclusion, dismissal, and denial. We can no longer recommend Signal as a secure chat app.
And we will no longer review, report, or disclose any security bugs related to Signal.
To the unknown future dissident, activist, or freedom seeker whose life will be saved as a result of the enhanced security added to Signal Desktop: You're welcome.
A post by the DoD Cyber Crime Center (DC3 @DC3Forensics) sent in 2021 detailing the method to decrypt and extract Signal Desktop data using the encryption key stored in plain text. Wondering if Signal demanded responsible disclosure in this case.
https://t.co/KDzJFaz6oL
The security bug about storing the encryption key in plain text wasn't considered a bug by Signal in 2018, wasn't considered a bug by Signal's president today, and even demanded responsible disclosure for it. Well, that not bug thing is getting a fix now:
https://t.co/WQKF0kMOOB
Hi Meredith, let me address your points:
1) The issue we highlighted does not require “full” access to the device. Signal desktop stores the chat database in an unprotected area of the file system that’s accessible by any user process. This would allow any program without any special permissions or user prompts to access the database in full. This can be solved by sandboxing, which relies on the OS to prevent any process from accessing data within the sandbox.
2) The issue was reported to Signal by others back in 2018, so we didn’t find anything new. App sandboxing technology had been available for a long time on desktop (Windows AppContainer and macOS App Sandbox). Even if we ignore sandboxing, while Signal encrypts the chat database, it stores the encryption key insecurely in plaintext.
3) We “the posters” didn’t feel the need to reach out to Signal first since the issue had been known to Signal’s developers since 2018. After 6 years without a resolution, we believe it becomes more important to raise awareness than to attempt to directly engage with Signal, or any other vendor. Also, I challenge you to point out any instance of inflammatory language in our posts about Signal.
Finally, Signal has a huge responsibility towards your users, many of whom rely on Signal to be the most secure way of communicating in areas of the world where their lives would be in danger if their messages were to be compromised. This is not hyperbole, and Signal needs to continue to live up to that responsibility.
This video shows that @signalapp (7.15.0) on macOS stores photos and docs sent through the app locally without encryption. Worse, the files are stored in a location accessible by any app or script. However, text messages are stored locally in an encrypted DB.
#privacy#security