Masthash

#LockdownMode

Eingfoan :donor:
4 days ago

11) my #banking app has stopped working. Had to turn off #lockdownMode on #ios #apple and turn it on again to get it working again.

Also #ivory for iOS works great in lockdown mode. No issues. Seriously, I know apple intends #lockdownmode for people who might be in harms way, but it is starting to make a lot of security sense to just try it out and leave it on. You still have control of the decice.

If a website stops working in safari, its the sites problem, not yours.

Jeroen van der Ham
1 month ago

I enabled iOS #lockdownmode but I’m constantly getting alerts about Screen Time sharing, even though #screentime is turned off. Anybody have thoughts about this?

Just started playing with lockdown mode on my iPhone. So far I have not noticed any difference.

#lockdownmode #ios

Eingfoan :donor:
2 months ago

@zak I have turned of #apple #ios #lockdown on my private iPad (mainly because of photo sharing options). I ll keep it for the phone since I carry that around and it is much more exposed.
Company on as well. #apple #lockdownMode

Eingfoan :donor:
2 months ago

10) #apple #lockdownMode on #ios for #iphone or #ipad prevents you from sharing #WiFi with e.g. your iPad until it is unlocked (open)

The original wording Apple has in https://support.apple.com/en-us/HT212650 is:
####
Device connections - To connect your iPhone or iPad to an accessory or another computer, the device needs to be unlocked. To connect your Mac laptop with Apple silicon to an accessory, your Mac needs to be unlocked and explicit approval provided.
#####

I originally thought it is only applicable for #physical #connects. But it seems like it applies to some #virtual connects as well.

Miguel Afonso Caetano
2 months ago

RT @jsrailton
NEW INVESTIGATION: recent Mexican #Pegasus spyware abuses led us to evidence of a trio of zero-click exploits used by #NSO.

Targets? HomeKit & FindMy.

Remarkably, #Apple's #iOS #LockdownMode blocked one of them.

Quick THREAD 1/
https://citizenlab.ca/2023/04/nso-groups-pegasus-spyware-returns-in-2022/

John Scott-Railton ☕
2 months ago

3/ Some details about the #zeroclick #zeroday exploits in #Pegasus #spyware that we found evidence of.

*THREE* #zeroclick #0day chains used by NSO's #Pegasus #spyware in 2022.

First: #PWNYOURHOME: worked against #homekit even if you didn't set up a home.

Apple's changes in iOS 16.3.1 address this.

We also observed #LockdownMode kneecapping it.

MessagesBlostDoorService homed MessagesBlastDoorService (suspected) Figure 2: Three exploit chains released by NSO Group in 2022. To nrotect our continued abilitv to identifv Pecasus infections
3. PWNYOURHOME: An i0S 15 and i0S 16 Zero-Click Exploit

The PWNYOURHOME exploit appears to be a novel two-phase zero-click exploit, with each of the two phases targeting a dif- ferent process on the phone. The first phase of the exploit in- volves the HomeKit functionality built into iPhones (via the homed process), and the second phase of the exploit involves iMessage (via the MessagesBlastDoorService process). PWNYOURHOME appears to succeed against a target even if the target has never configured a “Home” inside HomeKit. However, in some cases, the email address of the PWNYOURHOME attacker is logged and Pegasus fails to delete this email from the HomeKit database.

We obtained logs from multiple devices compromised with PWNYOURHOME. In one case, the attacker’s email address ([REDACTED]@gmail.com) was logged. The phone logs showed that the [REDACTED]@gmail.com email address was added to HomeKit approximately eight minutes before the Pegasus spyware was recorded running on the phone, and an iMessage attachment was deleted.
Phase One: HomeKit Daemon Crashes Logs from another PWNYOURHOME-exploited device from the 2022 global target pool examined in the course of this investi- gation showed the homed process decoding what appears to be an unusual NSKeyedUnArchiver when it crashed. Logs showed that the NSKeyedUnArchiver decoding had been kicked off by the following function:

-[HMDHomeManager _handleHomeDataSync:] (in

HomeKitDaemonLegacy) The NSKeyedUnArchiver decoder invoked the decoder for NSDictionary, which in turn invoked the decoder for an implau- sible class not normally used within HomeKit. Issues with NSKeyedUnArchiver deserialization have been used in pastiOS zero-click exploits targeting iMessage, so we redact the specific class to avoid assisting attackers. We disclosed this issue to Apple, who made several changes to HomeKit in i0S 16.3.1, in- cluding adding a new method, -[HMDHomeManager _should- DecodeMessage:error:], which declines to decode certain HomeKit messages unless they arrive from a plausible source. This check guards the HomeKit code path we saw exploited.
Lockdown Mode Highlights Attack Apple’s Lockdown Mode feature makes signs of an attempted PWNYOURHOME attack visible to the phone’s user by display- ing notifications (Figure 4). We have seen no recent notifica- tions on Lockdown Mode, nor have we seen any evidence of successful PWNYOURHOME compromise on Lockdown Mode. Given that we have seen no indications that NSO has stopped deploying PWNYOURHOME, this suggests that NSO may have figured out a way to correct the notification issue, such as by fingerprinting Lockdown Mode. Friday, September 9 9:41 n Notification Center &) K to access a Home. T}y Iescsymmosconsionpis to access a Home. Figure 4: Illustration derived from victim screenshots illustrating how lockdown mode displayed notifications related to the PWNYOURHOME exploit Additionally, we have not seen any cases of exploitation of i0S versions 16.1 and greater, suggesting that PWNYOURHOME may have been fixed or mitigated around this time.
Eingfoan :donor:
2 months ago

9) @GossiTheDog pointed out that #lockdownmode on #apple also alerts you if you are being targeted

See here:

https://cyberplace.social/@GossiTheDog/110219780412629870

Eingfoan :donor:
2 months ago

8) #apple #ios #lockdownMode blocks incoming #facetime calls

Al3x 👽
2 months ago

Im #LockdownMode gehen die Video auf Mastodon nicht. Download und das Abspielen in einem eigenen Tab geht, aber nicht mehr in der Timeline. Der Lockdown Mode lässt sich aber auch für einzelne Seiten deaktivieren.

Eingfoan :donor:
2 months ago

7) don’t know what that really means #apple #homekit blocks something when using #lockdownMode on iOS

Eingfoan :donor:
2 months ago

6) Focus Sharing is disabled in #ios #lockdownMode

Eingfoan :donor:
2 months ago

@briankrebs ps: #lockdownMode if this is interesting …

Eingfoan :donor:
2 months ago

Is there a #lockdownMode for #android to enhance #opsec ? Since the last 7 days have told us that it is needed for sure (sms rce)….

I told you: this is the year for #mobile #insecurity for several reasons …

By the way: has anyone tried ‪@GrapheneOS‬ for bigger enterprise ? What about mdm compatibility?

#security

Eingfoan :donor:
3 months ago

3) you get a lot of warnings from various apps

#ios #lockdownMode #impactOnUser

Eingfoan :donor:
3 months ago

A thread over time what happens if you turn on #ios #lockdownMode:

This thread should help you identify if it is worth turning on.

Eingfoan :donor:
3 months ago

@zak thanks for clarifying #mdm and #ios #lockdownMode

TimedIn :verified:
5 months ago

Hab jetzt mal den #ios #LockdownMode Aktiviert aber auf einmal sind alle Icons durch (random?) Emojis ersetzt worden. Jemand ne Idee warum??

Bild: JellyFin iOS App

Jellyfin Oberfläche: Alben, Übersicht ⛪️🍴🏀🐭👮
Marco Ivaldi
5 months ago

I think I like #lockdownmode on iOS 16. Been using it for a while now, no major hassles and the reduced attack surface suits me. And if some website that I often visit doesn’t render properly I can always configure an exclusion.

Now waiting for #Apple to enable Advanced Data Protection in my region.

heise online
6 months ago

Microsoft half Apple, macOS' Gatekeeper zu verbessern

Gatekeeper markiert über den Browser heruntergeladene Dateien, damit macOS vor deren Ausführung warnen oder sie verhindern kann. Klingt einfach, ist es nicht.​

https://www.heise.de/news/Microsoft-half-macOS-Gatekeeper-zu-verbessern-7434470.html?wt_mc=sm.red.ho.mastodon.mastodon.-.-

#Achilles #Apple #AppleDouble #Bug #CVE202242821 #Gatekeeper #GatekeeperinMacOSX #LockdownMode #Malware #Microsoft #Proofofconcept #Security #Sicherheitslücken #macOS #News

:verified_gay:
6 months ago

"[#macOS] End-users should apply the fix regardless of their #LockdownMode status," Microsoft said."

https://www.theregister.com/2022/12/20/macos_gatekeeper_flaw_microsoft/

Gatekeeper markiert über den Browser heruntergeladene Dateien, damit macOS vor deren Ausführung warnen oder sie verhindern kann. Klingt einfach, ist es nicht.​
Microsoft half Apple, macOS' Gatekeeper zu verbessern
Andrea Margiovanni
6 months ago
Okay, by now I have a very simple (almost #vanilla I would say) configuration on #iPhone / #iPad / #Macbook, so maybe it depends on that. Anyway, after 4 days of using #LockdownMode on all devices, I can say that the user experience is great.

On #Safari there are the most noticeable "problems" (which I consider features anyway); otherwise the switch has been flawless.

Ok. Let's try it for a while. #LockdownMode #MacOS #iOS

TechHelpKB.com 📚
11 months ago

Tech Wrap-Up for Week 27, the top 10 stories by user engagement. #Cybersecurity threats of tomorrow, new #malware thwarts 50 #antivirus services, new #Linux #malware, #Defender #ransomware protection, #iOS #LockdownMode, & more, all in this week's wrap-up. https://www.techhelpkb.com/tech-wrap-up-week-27-2022/?utm_source=mastodon&utm_medium=toot&utm_campaign=wrapup

TechHelpKB.com 📚
11 months ago

Tech Wrap-Up for July 7, which is #WorldChocolateDay. New #malware thwarts 50+ #antivirus services, #Chrome #performance improvements, #iOS16 #LockdownMode, #Edge 103 updated, #iOS #security limitations, #Safari virtual card support, all in today's wrap-up. https://www.techhelpkb.com/tech-wrap-up-7-7-2022/?utm_source=mastodon&utm_medium=toot&utm_campaign=wrapup

Apple 宣布 Lockdown Mode 将于今年秋天的 iOS 16、iPadOS 16 及 macOS Ventura 发布。此功能可以使用户应对一些最复杂的数字威胁,包括国家资助骇客开发的间谍软件等。开启了 Lockdown Mode 的设备将会在短消息、浏览器、有线网络连接、企业设备管理和 Apple 服务等方面施加额外保护措施。

Apple 亦宣布将奖励在 Lockdown Mode 中找到漏洞的研究者最多 200 万美元,并称这是业界最高的奖励水平。

https://www.apple.com/newsroom/2022/07/apple-expands-commitment-to-protect-users-from-mercenary-spyware/
seealso:
HackerNews:32003756

#Apple #iOS #macOS #Security #LockdownMode

Telegram 原文

11 months ago

RT @RonDeibert: NEW: @apple announces #LockdownMode, a major change to iPhone security that promises to help high risk users other actions to hold the mercenary spyware industry to account https://t.co/30QbGruxi5

My thread w context

God Access :verified:
2 years ago

Good night! Disable biometric logins while sleeping! #Lockdownmode