2025 iPad Air hands-on: Why mess with a good thing?

There’s not much new in Apple’s latest refresh of the iPad Air, so there’s not much to say about it, but it’s worth taking a brief look regardless.

In almost every way, this is identical to the previous generation. There are only two differences to go over: the bump from the M2 chip to the slightly faster M3, and a redesign of the Magic Keyboard peripheral.

If you want more details about this tablet, refer to our M2 iPad Air review from last year. Everything we said then applies now.

From M2 to M3

The M3 chip has an 8-core CPU with four performance cores and four efficiency cores. On the GPU side, there are nine cores. There’s also a 16-core Neural Engine, which is what Apple calls its NPU.

We’ve seen the M3 in other devices before, and it performs comparably here in the iPad Air in Geekbench benchmarks. Those coming from the M1 or older A-series chips will see some big gains, but it’s a subtle step up over the M2 in last year’s iPad Air.

That will be a noticeable boost primarily for a handful of particularly demanding 3D games (the likes of Assassin’s Creed Mirage, Resident Evil Village, Infinity Nikki, and Genshin Impact) and some heavy-duty applications only a few people use, like CAD or video editing programs.

Most of the iPad Air’s target audience would never know the difference, though, and the main benefit here isn’t necessarily real-world performance. Rather, the upside of this upgrade is the addition of a few specific features, namely hardware-accelerated ray tracing and hardware-accelerated AV1 video codec support.

This isn’t new, but this chip supports Apple Intelligence, the much-ballyhooed suite of generative AI features Apple recently introduced. At this point there aren’t many devices left in Apple’s lineup that don’t support Apple Intelligence (it’s basically just the cheapest, entry-level iPad that doesn’t have it) and that’s good news for Apple, as it helps the company simplify its marketing messaging around the features.

https://arstechnica.com/gadgets/2025/03/hands-on-with-the-2024-ipad-air-slightly-better-slightly-faster/




RCS texting updates will bring end-to-end encryption to green bubble chats

One of the best mostly invisible updates in iOS 18 was Apple’s decision to finally implement the Rich Communications Services (RCS) communication protocol, something that is slowly helping to fix the generally miserable experience of texting non-iPhone users with an iPhone. The initial iOS 18 update brought RCS support to most major carriers in the US, and the upcoming iOS 18.4 update is turning it on for a bunch of smaller prepaid carriers like Google Fi and Mint Mobile.

Now that Apple is on board, iPhones and their users can also benefit from continued improvements to the RCS standard. And one major update was announced today: RCS will now support end-to-end encryption using the Messaging Layer Security (MLS) protocol, a standard finalized by the Internet Engineering Task Force in 2023.

“RCS will be the first large-scale messaging service to support interoperable E2EE between client implementations from different providers,” writes GSMA Technical Director Tom Van Pelt in the post announcing the updates. “Together with other unique security features such as SIM-based authentication, E2EE will provide RCS users with the highest level of privacy and security for stronger protection from scams, fraud and other security and privacy threats. ”

https://arstechnica.com/gadgets/2025/03/rcs-texting-updates-will-bring-end-to-end-encryption-to-green-bubble-chats/




Apple risolve un bug 0-day di WebKit già sfruttato


Apple ha rilasciato ieri un importante aggiornamento di sicurezza per risolvere un bug 0-day presente nel componente WebKit del browser Safari. 

Il bug, tracciato come CVE-2025-24201, è un problema di scrittura out-of-bound che consente a un attaccante di sfruttare un contenuto web creato ad hoc per uscire dalla sandbox del browser.

Secondo quanto riportato dalla compagnia, la vulnerabilità sarebbe stata già sfruttata in attacchi “estremamente sofisticati” contro dispositivi iOS con versioni precedenti alla 17.2. “Questo è un fix supplementare per un attacco che è stato bloccato in iOS 17.2” ha aggiunto Apple. La patch introduce dei controlli aggiuntivi per bloccare l’esecuzione di azioni non autorizzate.

Apple bug

Il fix è disponibile nelle versioni iOS 18.3.2 e iPadOS 18.3.2 per iPhone XS e successivi, iPad Pro da 12 pollici, iPad Pro da 12.9 pollici di terza generazione e successive, iPad Air di terza generazione e successive, iPad di settima generazione e successiva e iPad mini di quinta generazione e successiva.

La patch è inoltre disponibile in Safari 18.3.1 per macOS Ventura e Sonoma, in macOS Sequoia 15.3.2, in visionOS 2.3.2 per Vision Pro e in tvOS 18.3.1 per le Apple TV 4K di terza generazione.

Giusto un mese fa Apple aveva rilasciato un fix per un altro bug 0-day, anche in quel caso giù sfruttato. La vulnerabilità (CVE-2025-24200) permette a un attaccante di disabilitare USB Restricted Mode e scaricare le informazioni dell’utente.

La modalità disabilita le connessioni dati via cavo dopo 60 minuti di inattività del dispositivo, ma alcuni cybercriminali sono riusciti a bypassare il meccanismo di sicurezza e sferrare attacchi mirati. Il fix è stato rilasciato nella versione  18.3.1 di iOS e iPadOs.

La compagnia non ha condiviso dettagli sugli attacchi individuati, né per l’ultimo bug né per il precedente. Apple invita gli utenti ad aggiornare il prima possibile i propri dispositivi per proteggersi dalla minaccia.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2025/03/12/apple-risolve-un-bug-0-day-di-webkit-gia-sfruttato/?utm_source=rss&utm_medium=rss&utm_campaign=apple-risolve-un-bug-0-day-di-webkit-gia-sfruttato




Apple refuses to break encryption, seeks reversal of UK demand for backdoor

Although it wasn’t previously reported, Apple’s appeal was filed last month at about the time it withdrew ADP from the UK, the Financial Times wrote today.

Snoopers’ Charter

Backdoors demanded by governments have alarmed security and privacy advocates, who say the special access would be exploited by criminal hackers and other governments. Bad actors typically need to rely on vulnerabilities that aren’t intentionally introduced and are patched when discovered. Creating backdoors for government access would necessarily involve tech firms making their products and services less secure.

The order being appealed by Apple is a Technical Capability Notice issued by the UK Home Office under the 2016 law, which is nicknamed the Snoopers’ Charter and forbids unauthorized disclosure of the existence or contents of a warrant issued under the act.

“The Home Office refused to confirm or deny that the notice issued in January exists,” the BBC wrote today. “Legally, this order cannot be made public.”

Apple formally opposed the UK government’s power to issue Technical Capability Notices in testimony submitted in March 2024. The Investigatory Powers Act “purports to apply extraterritorially, permitting the UKG [UK government] to assert that it may impose secret requirements on providers located in other countries and that apply to their users globally,” Apple’s testimony said.

We contacted Apple about its appeal today and will update this article if we get a response. The appeal process may be a secretive one, the FT article said.

“The case could be heard as soon as this month, although it is unclear whether there will be any public disclosure of the hearing,” the FT wrote. “The government is likely to argue the case should be restricted on national security grounds.”

Under the law, Investigatory Powers Tribunal decisions can be challenged in an appellate court.

https://arstechnica.com/tech-policy/2025/03/apple-appeals-uks-secret-demand-for-backdoor-access-to-encrypted-user-data/




Apple’s M4 MacBook Air refresh may be imminent, with iPads likely to follow

Aside from the M4’s modest performance improvements over the M3, it seems likely that Apple will add a new webcam to match the ones added to the iMac and MacBook Pros. The M4 can also support up to three displays simultaneously—two external, plus a Mac’s internal display. The M3 supported two external displays, but only if the Mac’s built-in screen was turned off.

Gurman also indicates that refreshes for the basic 10.9-inch iPad and the iPad Air are coming soon, though they’re apparently not as imminent as the M4 MacBook Airs. The report doesn’t indicate which processors either of those refreshes will include; the current iPad Air lineup uses the M2, so either the M3 or M4 would be an upgrade. If Apple wants to bring Apple Intelligence to the 10.9-inch iPad, that would limit it to either the A17 Pro (like the 7th-gen iPad mini) or a variant of the Apple A18 (like the iPhone 16e). Apple Intelligence requires a chip with at least 8GB of RAM.

The iPad Air was refreshed a little less than a year ago, but the 10.9-inch iPad is due for an update. Apple gave it a price cut in 2024, but its hardware has been the same since October of 2022.

https://arstechnica.com/apple/2025/03/report-m4-macbook-air-as-early-as-this-week-new-ipads-shortly-after/




Brutto momento per la crittografia in Europa: la privacy vacilla


In Europa la sicurezza della crittografia sembra avere le ore contate. Le ultime notizie dalla Francia e dal Regno Unito hanno sollevato molte preoccupazioni e proteste da parte di utenti, provider di telecomunicazioni e compagnie orientate a preservare la privacy degli utenti.

Dopo l’annuncio di Apple dell’eliminazione di Advanced Data Protection per gli utenti del Regno Unito, in Francia il governo sta esaminando un emendamento per introdurre delle backdoor nelle comunicazioni cifrate.

crittografia

La Francia propone una backdoor nella crittografia

È notizia degli ultimi giorni che in Francia si sta valutando un emendamento alla legge “Narcotrafic” che costringe i provider di comunicazioni a implementare delle backdoor nelle loro applicazioni.

“La Francia sta per emendare una legge contro il traffico di droga, la legge “Narcotrafic”, che obbligherà le app di messaggistica criptata come Signal e WhatsApp a inserire una backdoor nelle comunicazioni crittografate per poter consegnare i messaggi di chat decriptati di sospetti criminali entro 72 ore dalla richiesta” si legge in un post di Tuta, un provider tedesco di servizi email fortemente orientato alla privacy. L’emendamento è stato approvato dal Senato e ora è stato sottoposto all’Assemblea Nazionale.

Sia Tuta che altri nomi impegnati nel mondo della privacy hanno espresso la loro preoccupazione verso questa decisione, sostenendo che si tratta di una grave violazione della sicurezza delle comunicazioni digitali. “Imponendo le backdoor, il governo francese non sta compromettendo solo la sicurezza di tutti gli utenti – cittadini e business in egual misura – ma questa legge “Narcotrafic” emendata va in contraddizione anche con le leggi europee per la protezione dei dati come la GDPR, l’IT Security Act e il TKG” continua Tuta.

L’inserimento della backdoor non va a danno soltanto dei criminali, ma anche degli utenti: dal momento che esiste un canale di accesso alle comunicazioni, non solo i governi e i provider possono usarlo, ma anche cyberattaccanti e intelligence di altre nazioni. Come sottolinea Tuta, una volta che la crittografia è compromessa, è difficile distinguere tra chi può trarne vantaggio e chi no. È impossibile, in sostanza, creare una backdoor “solo per i buoni”.

crittografia

Apple elimina Advanced Data Protection per il Regno Unito

La notizia dell’emendamento alla legge francese arriva quasi contestualmente all’annuncio di Apple di eliminare l’opzione Advanced Data Protection (ADP) per gli utenti del Regno Unito.

ADP utilizza la crittografia end-to-end per proteggere dati sensibili quali i backup dei messaggi, le note, le foto, i preferiti del browser, i dati del Wallet e molto altro, sincronizzandoli con iCloud. Introdotta nel 2022, la feature da adesso non è più disponibile per gli utenti che risiedono nel Regno Unito.

Stando a quanto rivelato da Apple, uno dei principali motivi dietro questa decisione sta nell’aumento di data breach contro gli utenti. iMessagi, FaceTime, iCloud Keychain e Health, insieme ad altre categorie di dati in cloud, rimarranno comunque crittografati; per il resto, l’opzione non sarà più disponibile.

Secondo quanto riportato dalla CNN, la scelta dipenderebbe piuttosto dall’ordine del governo britannico di accedere a materiale cifrato per questioni di sicurezza nazionale. Il governo avrebbe chiesto ad Apple di inserire una backdoor nei propri servizi; la compagnia, non volendo accettare la proposta, sarebbe stata quindi costretta a fare un passo indietro sulla sua offerta di crittografia, pur non dichiarandolo esplicitamente nel suo annuncio. “Non abbiamo mai creato una backdoor o una master key per nessuno dei nostri prodotti o servizi e non lo faremo mai” ha specificato Apple.

Ora il timore è che anche altri stati europei seguano l’esempio di Regno Unito e Francia e compromettano la privacy degli utenti, pur mossi da motivi di sicurezza. La risposta dei provider di servizi di comunicazione non è tardata ad arrivare: tra i tanti, Meredit Whittaker, CEO di Signal, sta valutando di interrompere l’erogazione del servizio in Svezia dopo che il governo del Paese ha annunciato di voler accedere alla cronologia dei messaggi di utenti sospetti.

Mentre la tensione tra governi europei e provider sale, la crittografia rischia di essere stravolta per sempre.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2025/02/28/brutto-momento-per-la-crittografia-in-europa-la-privacy-vacilla/?utm_source=rss&utm_medium=rss&utm_campaign=brutto-momento-per-la-crittografia-in-europa-la-privacy-vacilla




Microsoft brings an official Copilot app to macOS for the first time

It took a couple of years, but it happened: Microsoft released its Copilot AI assistant as an application for macOS. The app is available for download for free from the Mac App Store right now.

It was previously available briefly as a Mac app, sort of; for a short time, Microsoft’s iPad Copilot app could run on the Mac, but access on the Mac was quickly disabled. Mac users have been able to use a web-based interface for a while.

Copilot initially launched on the web and in web browsers (Edge, obviously) before making its way onto iOS and Android last year. It has since been slotted into all sorts of first-party Microsoft software, too.

The Copilot app joins a trend already spearheaded by ChatGPT and Anthropic of bringing native apps to the macOS platform. Like those, it enables an OS-wide keyboard shortcut to invoke a field for starting a chat at any time. It offers most of the same use cases: translating or summarizing text, answering questions, preparing reports and documents, solving coding problems or generating scripts, brainstorming, and so on.

Copilot uses OpenAI models like GPT-4 and DALL-E 3 (yes, it generates images, too) alongside others like Microsoft’s in-house Prometheus. Microsoft has invested significant amounts of money into OpenAI in recent years as the basis for Copilot and basically everything in its AI strategy.

Like Apple’s own built-in generative AI features, Copilot for macOS requires an M1 or later Mac. It also requires users to run macOS 14 or later.

https://arstechnica.com/ai/2025/02/microsoft-brings-an-official-copilot-app-to-macos-for-the-first-time/




Apple pulls end-to-end encryption in UK, spurning backdoors for gov’t spying

“We are gravely disappointed that the protections provided by ADP will not be available to our customers in the UK given the continuing rise of data breaches and other threats to customer privacy,” Apple said. “Enhancing the security of cloud storage with end-to-end encryption is more urgent than ever before.”

For UK Apple users, some data can still be encrypted. iCloud Keychain and Health, iMessage, and FaceTime will remain end-to-end encrypted by default. But other iCloud services will not be encrypted, effective immediately, including iCloud Backup, iCloud Drive, Photos, Notes, Reminders, Safari Bookmarks, Siri Shortcuts, Voice memos, Wallet passes, and Freeform.

In the future, Apple hopes to restore data protections in the UK, but the company refuses to ever build a backdoor for government officials.

“Apple remains committed to offering our users the highest level of security for their personal data and are hopeful that we will be able to do so in the future in the United Kingdom,” Apple said. “As we have said many times before, we have never built a backdoor or master key to any of our products or services, and we never will.”

https://arstechnica.com/tech-policy/2025/02/apple-pulls-data-protection-tool-instead-of-caving-to-uk-demand-for-a-backdoor/




Apple, Lenovo lead losers in laptop repairability analysis

“When consumers can easily access information on how to fix devices, it makes it easier for people who can’t afford the latest and greatest technology to still be able to access the tools they need,” Nersisyan added.

Apple lags but shows some improvement

Apple’s MacBook repairability scores placed it at the lowest grade of the US PIRG’s list, save for Lenovo.

US PIRG laptop repairability scores
Credit: US PIRG

However, Apple’s overall repairability score improved from 4.3 last year to 5.1 this year. It gained a quarter of a point in this year’s score because it supported right-to-repair legislation in California within the last year. Apple’s support was a divergence from previous repairability stances from Apple, which had fought right-to-repair efforts for a decade before its about-face on California legislation starting in August 2023. Some have suggested that the change was due to Apple wanting input in legislation that, at the time, seemed likely to pass (California’s bill did eventually pass). Apple has also made notable self-repairability efforts lately, though, including launching and expanding a Self Service Repair program.

Still, Apple has room to grow, with the manufacturer earning the lowest total disassembly score (97)—besides Lenovo, whose score (14) only included one device. Apple also had the lowest disassembly average score (4.9 versus an average of 7.4) out of brands examined. Last year, Apple had an average disassembly score of 4.

In a deeper breakdown of the scores below, Apple’s disassembly scores improved compared to 2024 (9.7 versus 8), as did its parts pricing score (10.9 versus 9.8). However, parts availability declined (13.2 versus 12.8), per US PIRG.

Credit: US PIRG

Overall, Apple wasn’t able to compete with Asus and Acer, last year’s and this year’s winners. According to the report, “Asus and Acer continue to manufacture the most repairable laptops due largely to their ease of disassembly.”

Looking ahead, tariffs and other things impacting laptop availability and pricing, like the supply-chain disruptions witnessed during the COVID-19 pandemic, could drive demand for more easily repairable PCs.

“When [laptops and electronics] cost more or are harder to get, I’d expect shoppers to want to keep them in use for as long as possible and value their repairability,” Gutterman said.

https://arstechnica.com/gadgets/2025/02/macbooks-lagging-behind-pc-rivals-when-it-comes-to-repairability-report/




Microsoft warns that the powerful XCSSET macOS malware is back with new tricks

“These enhanced features add to this malware family’s previously known capabilities, like targeting digital wallets, collecting data from the Notes app, and exfiltrating system information and files,” Microsoft wrote. XCSSET contains multiple modules for collecting and exfiltrating sensitive data from infected devices.

Microsoft Defender for Endpoint on Mac now detects the new XCSSET variant, and it’s likely other malware detection engines will soon, if not already. Unfortunately, Microsoft didn’t release file hashes or other indicators of compromise that people can use to determine if they have been targeted. A Microsoft spokesperson said these indicators will be released in a future blog post.

To avoid falling prey to new variants, Microsoft said developers should inspect all Xcode projects downloaded or cloned from repositories. The sharing of these projects is routine among developers. XCSSET exploits the trust developers have by spreading through malicious projects created by the attackers.

https://arstechnica.com/security/2025/02/microsoft-warns-that-the-powerful-xcsset-macos-malware-is-back-with-new-tricks/