UK ordina ad Apple di sbloccare iCloud, rischi per la sicurezza e la privacy

Il governo del Regno Unito ha recentemente emesso un ordine che impone ad Apple di fornire accesso ai dati crittografati degli utenti archiviati su iCloud, in caso di inchieste rilevanti legalmente autorizzate. Questa richiesta, avanzata ai sensi dell’Investigatory Powers Act del 2016, noto anche come “Snoopers’ Charter”, la carta dello spionaggio, solleva preoccupazioni significative riguardo alla privacy di tutti gli utenti Apple e alla sicurezza dei loro dati. Si tratta quindi di un precedente che potrebbe generare un pericoloso effetto domino.

Da parte di Apple e del Governo, vi è da notare che al momento però non è pervenuta nessuna replica. Vediamo allora insieme quali possono essere i possibili impatti e le conseguenze, qualora Apple decidesse di adeguarsi alla richiesta.

L’Investigatory Powers Act del 2016

L’Investigatory Powers Act è una legge britannica che conferisce alle autorità poteri estesi per raccogliere e accedere a dati elettronici. In particolare, consente al governo di emettere “Technical Capability Notices” (TCN), ordini legali, che obbligano le aziende tecnologiche a fornire mezzi per accedere ai dati degli utenti, anche se crittografati. Queste notifiche possono includere l’obbligo di creare backdoor nei sistemi di crittografia o di fornire chiavi di decrittazione. Con backdoor ci si riferisce invece, a un accesso nascosto o non documentato a un sistema informatico, a un software o a una rete, che permette di aggirare le normali procedure di sicurezza e autenticazione.

La richiesta del Governo britannico ad Apple

Secondo quanto riportato dal Washington Post, il governo britannico ha emesso proprio una TCN intimando ad Apple di creare una backdoor nel suo servizio iCloud, al fine di combattere il terrorismo e la criminalità internazionale. Questa richiesta non si limita agli utenti nel Regno Unito, ma si estende a livello globale, potenzialmente influenzando milioni di utenti Apple in tutto il mondo.

L’istanza del governo britannico ad Apple non è stata improvvisa, ma è il risultato di un processo iniziato anni prima. Già nel 2022, il governo del Regno Unito aveva espresso critiche nei confronti dei piani di Apple per introdurre una crittografia avanzata nel suo servizio cloud, sostenendo che questa misura avrebbe ostacolato le indagini su crimini particolarmente gravi. La situazione si è ulteriormente intensificata nei primi mesi del 2024, quando, secondo alcune indiscrezioni, l’Home Office avrebbe presentato ad Apple una bozza dell’ordine per l’introduzione di una backdoor.

Nel marzo 2024, durante un dibattito parlamentare sugli emendamenti all’Investigatory Powers Act, Apple ha formalmente avvertito il Parlamento britannico, sottolineando che l’adozione della legge avrebbe potuto costringere l’azienda a rimuovere importanti funzionalità di sicurezza per gli utenti nel Regno Unito. Infine, il mese scorso, il governo ha emesso ufficialmente l’ordine sotto forma di una “technical capability notice”, rendendo esplicita la richiesta di accesso ai dati crittografati.

La richiesta del governo britannico non significa però che le autorità inizieranno improvvisamente a setacciare i dati degli utenti Apple. È logico pensare che l’accesso a iCloud sarà richiesto in presenza di un grave rischio per la sicurezza nazionale. In ogni caso, la richiesta delle autorità dovrebbe essere motivata e seguire un procedimento giuridico, sulla base di indagini giudiziarie «autorizzate» e di «ragioni valide». Di contro Apple non può lamentarsene pubblicamente perché la legge britannica in oggetto, glielo impedisce.

La posizione di Apple sui dati iCloud

Apple ha storicamente resistito a richieste governative che potrebbero compromettere la sicurezza e la privacy dei suoi utenti. L’azienda offre una funzione chiamata “Protezione Avanzata dei Dati” per iCloud, che utilizza la crittografia end-to-end, garantendo che solo l’utente possa accedere ai propri dati. Nemmeno Apple ha accesso a queste informazioni.

Di fronte alla richiesta del governo britannico, Apple potrebbe considerare la possibilità di rimuovere la funzione “Protezione Avanzata dei Dati” per i backup iCloud solo nel Regno Unito invece di compromettere gli standard di sicurezza a cui ha abituato i suoi utenti. Questa opzione, tuttavia, non risolverebbe il problema, poiché il governo britannico chiede che l’accesso venga garantito anche per gli utenti al di fuori del territorio del Regno Unito. Si pensi al caso di un individuo indagato per attività sospette e residente in un altro Paese, ma con dati archiviati su iCloud.

Impatto e implicazioni globali

Se Apple dovesse conformarsi, potrebbe affrontare richieste simili da parte di governi di tutto il mondo, inclusi quelli con leggi sulla privacy meno rigorose. Questo solleva preoccupazioni significative riguardo alla privacy globale e alla sicurezza dei dati.

Alcuni esempi di paesi che potrebbero seguire l’esempio britannico:

  • Stati Uniti: L’FBI ha più volte chiesto ad Apple e ad altre aziende tecnologiche di fornire accesso ai dati crittografati per indagini su terrorismo e criminalità organizzata. L’esempio britannico potrebbe fornire agli USA un nuovo argomento per chiedere lo stesso.
  • Unione Europea: Anche se l’UE ha leggi sulla privacy più rigide (come il GDPR), alcuni stati membri potrebbero spingere per ottenere accesso ai dati crittografati in nome della sicurezza nazionale.
  • Cina: Il governo cinese già impone restrizioni severe sulla tecnologia e la privacy. Se Apple concedesse l’accesso al Regno Unito, la Cina potrebbe chiedere lo stesso, aumentando la pressione sulle aziende tecnologiche per fornire strumenti di sorveglianza.
  • Russia e Medio Oriente: Alcuni governi con scarsa trasparenza e rispetto dei diritti umani potrebbero usare questa situazione come scusa per ottenere un maggiore controllo sulle comunicazioni dei loro cittadini.

Ancora, se Apple fosse costretta a creare una backdoor per il Regno Unito, il rischio principale sarebbe che tale vulnerabilità venga sfruttata anche da attori malevoli, tra cui:

  • Hacker e cybercriminali: Una backdoor nei sistemi di Apple potrebbe essere scoperta e utilizzata per accedere ai dati sensibili degli utenti, mettendo a rischio informazioni personali, finanziarie e aziendali.
  • Governi autoritari: Alcuni stati potrebbero sfruttare il precedente per giustificare la vigilanza ed il controllo di massa e la repressione di oppositori politici.
  • Interferenze da parte di intelligence straniere: Servizi segreti di paesi terzi potrebbero cercare di sfruttare le falle create per scopi di spionaggio e guerra informatica.

Una volta che una porta d’accesso viene creata, non è più possibile garantire che venga usata solo dai governi “affidabili”.

Per quanto concerne invece le possibili conseguenze ed effetti sulle aziende tecnologiche e sul mercato globale, si evidenzia che le aziende concorrenti, come Google con Google Drive, Microsoft con OneDrive e Meta con WhatsApp e Messenger, potrebbero trovarsi sotto pressione per adottare misure simili, rischiando di compromettere la sicurezza dei loro utenti. Questo scenario potrebbe generare una perdita di fiducia nei servizi cloud, spingendo molte persone a cercare alternative che offrano una maggiore protezione della privacy.

Allo stesso tempo, le piattaforme che garantiscono una crittografia sicura senza backdoor, come ProtonMail, Signal e i servizi di cloud decentralizzato, potrebbero registrare un aumento significativo della loro base utenti. La vulnerabilità introdotta da una backdoor potrebbe inoltre indebolire la posizione competitiva delle aziende tecnologiche occidentali, favorendo la crescita di soluzioni alternative provenienti da mercati meno regolamentati, come quello cinese. Ciò potrebbe portare a una ridefinizione degli equilibri globali nel settore della sicurezza digitale e della protezione dei dati.

Reazioni e critiche

La richiesta del governo britannico ha suscitato critiche da parte di gruppi per la privacy e i diritti civili. Big Brother Watch, un’organizzazione per la privacy con sede nel Regno Unito, ha definito la mossa come una “erosione storica” della crittografia end-to-end.

Anche altre aziende tecnologiche, come Google e Meta, offrono servizi di archiviazione dati crittografati. Finora, dunque non è chiaro se abbiano ricevuto o meno richieste simili da parte del governo britannico.

Considerazioni legali ed etiche

L’istanza del governo britannico solleva quindi questioni legali ed etiche complesse. Da un lato, le autorità sostengono che l’accesso ai dati crittografati è essenziale per combattere il crimine e il terrorismo. Secondo questa prospettiva, fornire alle forze dell’ordine un accesso regolamentato ai dati degli utenti potrebbe migliorare l’efficacia delle operazioni contro il crimine organizzato, la pedopornografia e il terrorismo, evitando che le tecnologie crittografiche diventino uno strumento per nascondere attività illecite.

Dall’altro lato, gli esperti di privacy avvertono che, come sopra accennato, creare backdoor nei sistemi di crittografia potrebbe compromettere la sicurezza dei dati e violare i diritti alla privacy degli utenti. La crittografia non è solo uno strumento di protezione per criminali, ma anche un mezzo essenziale per difendere la privacy e la libertà di espressione di giornalisti, attivisti, dissidenti politici e cittadini comuni.

Questo crea quindi un delicato equilibrio tra le esigenze di sicurezza nazionale e la protezione dei diritti individuali.

A livello giuridico, la richiesta del governo britannico potrebbe entrare in conflitto con normative internazionali sulla protezione dei dati, come il Regolamento Generale sulla Protezione dei Dati (GDPR) dell’Unione Europea, che garantisce agli utenti il diritto alla riservatezza e impone alle aziende tecnologiche di adottare misure rigorose per proteggere le informazioni personali. Inoltre, l’introduzione di una backdoor potrebbe violare principi sanciti da trattati sui diritti umani, come l’Articolo 12 della Dichiarazione Universale dei Diritti Umani, che tutela la privacy e la protezione contro interferenze arbitrarie nella vita privata. Inoltre, la scelta di Apple potrebbe tradursi in una pericolosa violazione dei diritti digitali a livello globale, trasformando la crittografia da strumento di protezione a potenziale meccanismo di sorveglianza.

Possibili scenari futuri

La situazione attuale evidenzia quindi le sfide in corso nel bilanciare la sicurezza nazionale con la privacy degli utenti. A seconda della risposta di Apple alla richiesta britannica, si possono delineare diversi scenari futuri, ognuno con implicazioni significative. Se Apple dovesse rifiutare di conformarsi, il governo britannico potrebbe reagire imponendo sanzioni o limitando l’accesso a determinati servizi Apple nel Regno Unito. L’azienda potrebbe rispondere lanciando una campagna pubblica a difesa della privacy, coinvolgendo altre imprese tecnologiche e organizzazioni per i diritti digitali. Questo scenario potrebbe anche sfociare in una lunga battaglia legale, con cause nei tribunali per stabilire la legittimità della richiesta governativa.

Se invece Apple accettasse di implementare una backdoor, la decisione potrebbe danneggiare la reputazione di Apple come azienda impegnata nella tutela della privacy, causando una perdita di fiducia da parte degli utenti e, di conseguenza, una diminuzione della clientela. Inoltre, governi meno democratici potrebbero sfruttare questa apertura per intensificare la sorveglianza sui propri cittadini, aggravando ulteriormente il problema della violazione dei diritti digitali.

Un’ulteriore possibilità è che Apple decida di modificare i suoi servizi solo per il Regno Unito, rimuovendo la crittografia end-to-end esclusivamente per gli utenti britannici, mentre nel resto del mondo i servizi rimarrebbero inalterati. Tuttavia, questa soluzione potrebbe rivelarsi insufficiente, dal momento che il governo britannico ha esplicitamente richiesto l’accesso anche ai dati di utenti non residenti nel Regno Unito.

La strada intrapresa da Apple in risposta alla richiesta del governo britannico potrebbe avere implicazioni di vasta portata per il futuro della crittografia e della privacy digitale. Gli utenti e le aziende tecnologiche di tutto il mondo seguiranno da vicino gli sviluppi, consapevoli che le decisioni prese oggi potrebbero influenzare le politiche sulla privacy per gli anni a venire.

Conclusioni

La richiesta del governo britannico ad Apple di fornire accesso ai dati crittografati degli utenti riveste carattere peculiare e solleva questioni fondamentali sulla privacy di miliardi di utenti, la sicurezza e i diritti individuali. Mentre la tecnologia continua a evolversi, sarà infatti necessario trovare delle soluzioni per trovare un bilanciamento, in grado di proteggere sia la sicurezza nazionale che diritto fondamentale alla privacy dei cittadini.

Condividi sui Social Network:

https://www.ictsecuritymagazine.com/notizie/apple-dati-su-icloud/




Apple rilascia un fix per un bug 0-day già sfruttato


Ieri Apple ha rilasciato un fix urgente per un bug 0-day che, come riportato dalla compagnia stessa, sarebbe già stato sfruttato dagli attaccanti. “Apple è a conoscenza del fatto che questa vulnerabilità potrebbe essere stata sfruttata in un attacco estremamente sofisticato contro specifici individui” si legge sull’advisory ufficiale.

Apple bug

La vulnerabilità, tracciata come CVE-2025-24200, consente a un attaccante di disabilitare USB Restricted Mode su un dispositivo per scaricare le informazioni dell’utente.

La funzionalità di sicurezza impedisce a chiavette USB e altri strumenti di accedere a un iPhone o a un iPad bloccato e ottenere i dati salvati sul dispositivo. La feature disabilita le connessioni dati dopo 60 minuti di inattività del dispositivo, rendendo di fatto la porta per il connettore Lightning un’interfaccia di solo caricamento della batteria e non di comunicazione.

Evidentemente però gli attaccanti sono riusciti a bypassare questo meccanismo di sicurezza per scaricare i dati dal dispositivo. A scoprire la vulnerabilità è stato Bill Marczak, ricercatore del The Citizen Lab presso la University of Toronto’s Munk School, che ha avvisato gli utenti con un post su X:

La vulnerabilità colpisce l’iPhone XS e i modelli successivi, l’iPad Pro da 13 pollici, iPad Pro da 12.9 pollici di terza generazione e successiva, l’iPad Pro da 11 pollici di prima generazione e successive, l’iPad Air di terza generazione e successive, l’iPad di settima generazione e successive e l’iPad mini di quinta generazione e successive.

Apple non ha rilasciato dettagli tecnici sul bug, né informazioni sull’exploit o sulle vittime colpite. Vista la natura della funzionalità, gli attaccanti sono riusciti a ottenere accesso fisico ai dispositivi colpiti.

La compagnia ha invitato tutti gli utenti con device vulnerabili ad applicare la patch il prima possibile, disponibile nella versione 18.3.1 di iOS e iPadOs.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2025/02/11/apple-rilascia-un-fix-per-un-bug-0-day-gia-sfruttato/?utm_source=rss&utm_medium=rss&utm_campaign=apple-rilascia-un-fix-per-un-bug-0-day-gia-sfruttato




UK demands Apple break encryption to allow gov’t spying worldwide, reports say

The United Kingdom issued a secret order requiring Apple to create a backdoor for government security officials to access encrypted data, The Washington Post reported today, citing people familiar with the matter.

UK security officials “demanded that Apple create a backdoor allowing them to retrieve all the content any Apple user worldwide has uploaded to the cloud,” the report said. “The British government’s undisclosed order, issued last month, requires blanket capability to view fully encrypted material, not merely assistance in cracking a specific account, and has no known precedent in major democracies.”

Apple and many privacy advocates have repeatedly criticized government demands for backdoors to encrypted systems, saying they would harm security and privacy for all users. Backdoors developed for government use would inevitably be exploited by criminal hackers and other governments, security experts have said.

The UK is reportedly seeking access to data secured by end-to-end encryption with Apple’s Advanced Data Protection, which prevents even Apple from seeing user data. Advanced Data Protection is an optional setting that users can enable for iCloud backups, photos, notes, and other data.

“Rather than break the security promises it made to its users everywhere, Apple is likely to stop offering encrypted storage in the UK,” The Washington Post paraphrased its sources as saying. “Yet that concession would not fulfill the UK demand for backdoor access to the service in other countries, including the United States.”

Apple opposes UK snooping powers

The Technical Capability Notice was reportedly issued by the UK Home Office under the Investigatory Powers Act (IPA). The 2016 law is nicknamed the Snoopers’ Charter and forbids unauthorized disclosure of the existence or contents of a warrant issued under the act.

“Apple can appeal the UK capability notice to a secret technical panel, which would consider arguments about the expense of the requirement, and to a judge who would weigh whether the request was in proportion to the government’s needs. But the law does not permit Apple to delay complying during an appeal,” the Post wrote.

https://arstechnica.com/tech-policy/2025/02/uk-demands-apple-break-encryption-to-allow-govt-spying-worldwide-reports-say/




The Severance writer and cast on corporate cults, sci-fi, and more

The following story contains light spoilers for season one of Severence but none for season 2.

The first season of Severance walked the line between science-fiction thriller and Office Space-like satire, using a clever conceit (characters can’t remember what happens at work while at home, and vice versa) to open up new storytelling possibilities.

It hinted at additional depths, but it’s really season 2’s expanded worldbuilding that begins to uncover additional themes and ideas.

After watching the first six episodes of season two and speaking with the series’ showrunner and lead writer, Dan Erickson, as well as a couple of members of the cast (Adam Scott and Patricia Arquette), I see a show that’s about more than critiquing corporate life. It’s about all sorts of social mechanisms of control. It’s also a show with a tremendous sense of style and deep influences in science fiction.

Corporation or cult?

When I started watching season 2, I had just finished watching two documentaries about cults—The Vow, about a multi-level marketing and training company that turned out to be a sex cult, and Love Has Won: The Cult of Mother God, about a small, Internet-based religious movement that believed its founder was the latest human form of God.

There were hints of cult influences in the Lumon corporate structure in season 1, but without spoiling anything, season 2 goes much deeper into them. As someone who has worked at a couple of very large media corporations, I enjoyed Severance’s send-up of corporate culture. And as someone who has worked in tech startups—both good and dysfunctional ones—and who grew up in a radical religious environment, I now enjoy its send-up of cult social dynamics and power plays.

Employees watch a corporate propaganda video

Lumon controls what information is presented to its employees to keep them in line. Credit: Apple

When I spoke with showrunner Dan Erickson and actor Patricia Arquette, I wasn’t surprised to learn that it wasn’t just me—the influence of stories about cults on season 2 was intentional.

Erickson explained:

I watched all the cult documentaries that I could find, as did the other writers, as did Ben, as did the actors. What we found as we were developing it is that there’s this weird crossover. There’s this weird gray zone between a cult and a company, or any system of power, especially one where there is sort of a charismatic personality at the top of it like Kier Eagan. You see that in companies that have sort of a reverence for their founder.

Arquette also did some research on cults. “Very early on when I got the pilot, I was pretty fascinated at that time with a lot of cult documentaries—Wild Wild Country, and I don’t know if you could call it a cult, but watching things about Scientology, but also different military schools—all kinds of things like that with that kind of structure, even certain religions,” she recalled.

https://arstechnica.com/culture/2025/01/the-severance-writer-and-cast-on-corporate-cults-sci-fi-and-more/




In Apple’s first-quarter earnings, the Mac leads the way in sales growth

Apple fell slightly short of investor expectations when it reported its first-quarter earnings today. While sales were up 4 percent overall, the iPhone showed signs of weakness, and sales in the Chinese market slipped by just over 11 percent.

CEO Tim Cook told CNBC that the iPhone performed better in countries where Apple Intelligence was available, like the US—seemingly suggesting that the slip was partially because Chinese consumers do not see enough reason to buy new phones without Apple Intelligence. (He also said, “Half of the decline is due to a change in channel inventory.”) iPhone sales also slipped in China during this same quarter last year; this was the first full quarter during which the iPhone 16 was available.

In any case, Cook said the company plans to roll out Apple Intelligence in additional languages, including Mandarin, this spring.

Apple’s wearables category also declined slightly, but only by 2 percent.

Despite the trends that worried investors, Apple reported $36.33 billion in net revenue for the first quarter. That’s 7.1 percent more than last year’s Q1. This was driven by the Mac, the iPad, and Services (which includes everything from Apple Music to iCloud)—all of which saw slight upticks in sales. Services was up 14 percent, continuing a strong streak for that business, while the Mac and the iPad both jumped up 15 percent.

The uptick in Mac and iPad sales was likely helped by several new Mac models and a new iPad mini starting shipments last October.

Cook shared some other interesting numbers in the earnings call with investors and the press: The company has an active base of 2.35 billion devices, and it has more than 1 billion active subscriptions.

https://arstechnica.com/gadgets/2025/01/q1-earnings-apple-sees-a-sales-slip-in-china-worrying-investors/




Apple chips can be hacked to leak secrets from Gmail, iCloud, and more

Apple-designed chips powering Macs, iPhones, and iPads contain two newly discovered vulnerabilities that leak credit card information, locations, and other sensitive data from the Chrome and Safari browsers as they visit sites such as iCloud Calendar, Google Maps, and Proton Mail.

The vulnerabilities, affecting the CPUs in later generations of Apple A- and M-series chip sets, open them to side channel attacks, a class of exploit that infers secrets by measuring manifestations such as timing, sound, and power consumption. Both side channels are the result of the chips’ use of speculative execution, a performance optimization that improves speed by predicting the control flow the CPUs should take and following that path, rather than the instruction order in the program.

A new direction

The Apple silicon affected takes speculative execution in new directions. Besides predicting control flow CPUs should take, it also predicts the data flow, such as which memory address to load from and what value will be returned from memory.

The most powerful of the two side-channel attacks is named FLOP. It exploits a form of speculative execution implemented in the chips’ load value predictor (LVP), which predicts the contents of memory when they’re not immediately available. By inducing the LVP to forward values from malformed data, an attacker can read memory contents that would normally be off-limits. The attack can be leveraged to steal a target’s location history from Google Maps, inbox content from Proton Mail, and events stored in iCloud Calendar.

SLAP, meanwhile, abuses the load address predictor (LAP). Whereas LVP predicts the values of memory content, LAP predicts the memory locations where instruction data can be accessed. SLAP forces the LAP to predict the wrong memory addresses. Specifically, the value at an older load instruction’s predicted address is forwarded to younger arbitrary instructions. When Safari has one tab open on a targeted website such as Gmail, and another open tab on an attacker site, the latter can access sensitive strings of JavaScript code of the former, making it possible to read email contents.

https://arstechnica.com/security/2025/01/newly-discovered-flaws-in-apple-chips-leak-secrets-in-safari-and-chrome/




With iOS 18.3, Apple Intelligence is now on by default

As is custom, Apple rolled out software updates to all its platforms at once today. All users should now have access to the public releases of iOS 18.3, macOS Sequoia 15.3, watchOS 11.3, iPadOS 15.3, tvOS 15.3, and visionOS 2.3.

Also, as usual, the iOS update is the meatiest of the bunch. Most of the changes relate to Apple Intelligence, a suite of features built on deep learning models. The first Apple Intelligence features were introduced in iOS 18, with additional ones added in iOS 18.1 and iOS 18.2

iOS 18.3 doesn’t add any significant new features to Apple Intelligence—instead, it tweaks what’s already there. Whereas Apple Intelligence was opt-in in previous OS versions, it is now on by default in iOS 18.3 on supported devices.

For the most part, that shouldn’t be a noticeable change for the majority of users, except for one thing: notification summaries. As we’ve reported, the feature that summarizes large batches of notifications using a large language model is hit-and-miss at best.

For most apps, not much has changed on that front, but Apple announced that with iOS 18.3, it’s temporarily disabling notification summaries for apps from the “News & Entertainment” category in light of criticisms by the BBC and others about how the feature was getting the substance of headlines wrong. The feature will still mess up summarizing your text messages and emails, though.

Apple says it has changed the presentation of summaries to make it clearer that they are distinct from other, non-AI generated summaries and that they are in beta and may be inaccurate.

Other updates include one to visual intelligence, a feature available on the most recent phones that gives you information on objects your camera is focused on. It can now identify more plants and animals, and you can create calendar events from flyers or posters seen in your viewfinder.

https://arstechnica.com/gadgets/2025/01/ios-18-3-disables-controversial-ai-generated-news-app-notifications/




Apple must face suit over alleged policy of underpaying female workers

While some of Apple’s defense was deemed “demonstrably inaccurate” and most of its arguments “insufficient,” Apple did successfully argue against efforts to seize back pay for former female employees no longer working for Apple who were seemingly also impacted by allegedly sexist policies implemented in 2020. That claim must be dropped as the proposed class action moves forward.

Additionally, another claim alleging pay disparity that was linked to racial discrimination was suspended. But the Apple worker suing, Zainab Bori, will have a chance to amend her claim that she was fired as retaliation for filing a discrimination complaint. It could survive if she adds currently missing evidence that “she suffered an adverse employment action” while working under a manager with an alleged “history of negative interactions with African American employees,” Schulman’s order said.

Apple did not immediately respond to Ars’ request for comment.

In a press release sent to Ars, Eve Cervantez, a lawyer representing Apple workers suing, celebrated the court’s ruling.

“I am really pleased with today’s ruling,” Cervantez said. “This start low, stay low practice has been a no-win situation for women working at Apple for years. So, I’m glad they will have their day in court.”

Apple accused of ignoring hostile work environment

For Justina Jong—whom the complaint noted joined Apple in 2013 and has helped lead “cross-functional teams that improve the App Review experience for global app developers”—this week’s win might be particularly encouraging after Apple allegedly refused to take her experience with sexual harassment seriously.

Jong has alleged that in 2019, Blaine Weilert, a senior member of an Apple talent development team, touched her in a sexually suggestive manner without consent. Although Weilert admitted to the act and was disciplined, Apple tried and failed to argue this was a one-time offense that didn’t constitute a hostile work environment or warrant Jong’s repeated requests to be moved away from Weilert in Apple’s offices.

https://arstechnica.com/tech-policy/2025/01/apple-must-face-suit-over-alleged-policy-of-underpaying-female-workers/




iOS 18.3 beta disables news notification summaries after high-stakes errors

In our own extensive testing with Apple Intelligence notification summaries in iOS 18.1 and macOS 15.1, we observed many instances of summaries that were inaccurate or just plain weird. When you’re just getting updates from your Discords or group text threads, errors tend to be pretty low-stakes, at least. But when you’re getting notifications about war, murder, and politics, these kinds of errors have the potential to mislead and misinform.

The iOS 18.1 and 18.2 updates (along with iPadOS 18.2 and macOS Sequoia 15.2) enabled most of Apple’s promised Intelligence features across all the hardware that supports them. For the iPhone, that’s still only 2023’s iPhone 15 Pro and 2024’s iPhone 16 and iPhone 16 Pro.

The iOS 18.3 update is currently in its third beta release. The iOS 17.3, 16.3, and 15.3 updates have all been released in late January, so it’s likely that we’ll see the 18.3 update (and corresponding updates for iPadOS, macOS, and other Apple software) released at some point in the next few weeks.

https://arstechnica.com/apple/2025/01/ios-18-3-beta-disables-news-notification-summaries-after-high-stakes-errors/




Parallels can finally run x86 versions of Windows or Linux on Apple Silicon

Virtualization software like Parallels and VMware Fusion give Mac owners the ability to run Windows and Linux on top of macOS, but for Apple Silicon Macs, that support was limited to the Arm-based versions of those operating systems. And while Windows and Linux both support some level of x86-to-Arm app translation that attempts to maintain compatibility with most software, there are still plenty of things that demand an Intel or AMD processor with the x86 instruction set.

Last week, Parallels released a new update that partially resolves this problem: Users of Parallels Desktop Pro 20.2.0 now have access to x86 operating systems via an “early technology preview” of Parallels’ “proprietary emulation engine.”

The technology preview is currently limited to certain 64-bit versions of Windows 10, Windows 11, and Windows Server 2019 and 2022. Parallels also says it has tested several UEFI-compatible Linux distributions, including Ubuntu 22.04.5, Kubuntu 24.04.1, Lubuntu 24.04.1, and Debian versions 12.4 to 12.8. Fedora will install, but it’s unstable. 32-bit versions of operating systems, as well as older versions of Windows like Windows 7 or 8, aren’t supported.

Parallels running the x86 version of Windows 10 on an M1 MacBook Pro. Parallels’ virtual CPU appears to identify itself as a 5th-generation Intel Core laptop processor. Credit: Parallels

For Windows 11 and supported Linux distros, you can run existing virtual machines using the technology preview, but you can’t set up new ones—useful for anyone migrating from an Intel Mac with virtual machines they’d like to keep. If you’re trying to set up a new virtual machine, the only officially supported operating systems are Windows Server 2022 and Windows 10 21H2, though there are workarounds available for Windows 10 22H2 and Windows Server 2019.

You won’t be able to set up fresh copies of Windows 11 or some versions of Linux because the technology preview doesn’t support SSE4.2, additional CPU instructions that became common in Intel and AMD processors in the early 2010s. This also means that Windows 11 24H2 VMs are entirely unsupported, since the 24H2 update requires these CPU instructions to work at all.

https://arstechnica.com/gadgets/2025/01/parallels-desktop-gains-really-slow-support-for-x86-oses-on-apple-silicon/