Apple lets devs use alternate in-app payment options, still takes commissions

App Store icon on an iPhone screen
Getty Images | NurPhoto

A chapter in the ongoing Epic v. Apple court case closed yesterday when the US Supreme Court declined to hear further arguments from either company. This decision leaves the case where it was after the 9th Circuit Court of Appeals ruled on it in April 2023.

The main issue at hand—to summarize days of arguments and multiple lengthy, technical court rulings in a couple of sentences—was whether Apple could continue to collect the 15–30 percent cut that it takes of all App Store purchases on its platforms and in-app purchases and subscriptions bought inside of those apps. The rulings, largely seen as victories for Apple, didn’t open iOS or iPadOS up to third-party app stores or app sideloading as Epic had originally sought. However, the rulings established that Apple’s so-called “anti-steering” rules—language prohibiting developers from mentioning cheaper or alternative purchasing options that might be available outside of an app—were anticompetitive.

Apple has updated its App Store rules to allow developers to provide external links to other payment options, technically circumventing its normal fee structure. But they come with many extra conditions that developers have to meet. And instead of paying Apple a 15 or 30 percent cut, Apple will collect a 12–27 percent commission. After factoring in the fees from whatever non-Apple payment processor these developers decide to use, the revenue they give up will remain essentially unchanged.

Apple is still taking a cut

The new rules, which apply only to the US App Store, cover something Apple calls a StoreKit External Purchase Link Entitlement. This entitlement comes with a long list of additional requirements, which Apple says are “designed to help protect people’s privacy and security, prevent scams and fraudulent activity, and maintain the overall quality of the user experience.”

Most notably, external links must adhere to Apple’s “design and language requirements,” cannot “mimic Apple’s in-app purchase system,” and can only be displayed in one place in your app. Developers still can’t include language about going directly to their websites for a discounted rate. And whenever users click the external purchase link in your app, they’ll be shown a full-page warning screen explaining that Apple is not responsible for the site’s privacy or security and that you won’t be able to use your Apple account to manage purchases or subscriptions.

Examples of what Apple wants third-party in-app purchase links to look like.
Enlarge / Examples of what Apple wants third-party in-app purchase links to look like.

Developers who don’t get approval from Apple won’t be able to use this link entitlement and will be subject to the same rules and restrictions around external purchasing links as before. Developers who offer external purchasing links will also be required to offer standard in-app purchasing through Apple, and developers “may not discourage end-users from making in-app purchases.”

The new commission reporting requirements may be even more onerous, particularly for small developers. In short, devs who would have owed Apple 15 percent of any in-app purchases will owe Apple a 12 percent commission on any in-app purchases made using a third-party site. Developers who would have owed Apple a 30 percent cut will owe a 27 percent commission instead. Apple says that these commissions “account for the substantial value Apple provides developers, including in facilitating linked transactions.”

To put these rates in context, payment processors generally take a small percentage of all online transactions, plus a small fixed fee. Square and Stripe, to pick two prominent examples, take 2.9 percent of every sale plus an additional 30 cents (NerdWallet has a good comparative list).

The "in-app system disclosure sheet" that crops up when users try to use a third-party payment system in an iOS app.
Enlarge / The “in-app system disclosure sheet” that crops up when users try to use a third-party payment system in an iOS app.

Depending on what a developer is charging for in-app purchases, this could work out to a little under 3 percent or substantially more than 3 percent. Regardless, most developers would struggle to take home more money than they do by using Apple’s built-in payment system, especially once you factor in overhead for complying with Apple’s filing requirements. Developers will be required to file monthly transaction reports with Apple, and they will be invoiced based on those reports. Apple will charge interest on late payments, and if the company ever “develops an API to facilitate reporting,” developers will be required to add support in their apps within 30 days.

Developers who attempt to circumvent any of Apple’s requirements can have their apps removed and developer accounts suspended at Apple’s discretion.

The way Apple has structured this link entitlement is similar to a hypothetical suggested by Judge Yvonne Gonzalez Rogers in the original Epic v. Apple ruling.

“Even in the absence of [in-app purchases,] Apple could still charge a commission on developers. It would simply be more difficult for Apple to collect that commission,” Rodriguez writes, before continuing in a footnote. “In such a hypothetical world, developers could potentially avoid the commission while benefitting from Apple’s innovation and intellectual property free of charge. The Court presumes that in such circumstances that Apple may rely on imposing and utilizing a contractual right to audit developers’ annual accounting to ensure compliance with its commissions, among other methods. Of course, any alternatives to IAP (including the foregoing) would seemingly impose both increased monetary and time costs to both Apple and the developers.”

Regardless of Apple’s intent, it seems clear that most developers will continue on the path of least resistance: use Apple’s first-party in-app payment system, which rolls Apple’s commission fees and payment processing fees up into a flat 15–30 percent payment, doesn’t come with the same restrictions or warnings as Apple’s External Purchase Link Entitlement system, and doesn’t require the same amount of administrative overhead.

And the new rules may open up another chapter in the Epic v. Apple saga. Epic CEO Tim Sweeney called the new rules a “bad-faith compliance plan” and vowed to contest them in district court.

https://arstechnica.com/?p=1996686




What to expect from the Apple Vision Pro in February

The glass front of mixed reality goggles
Enlarge / Apple Vision Pro.

After years of delays, preorders for the Apple Vision Pro are just a few days away. It’s been a long, winding road to get to this point, and the nature of the headset has shifted through numerous rumors, both true and false.

Because of all that, this is a good time to clarify exactly what you can (and can’t) expect from Apple’s most ambitious new product in many years.

Apple showed more or less what it had finally landed on at WWDC in June, and I got some hands-on time with it then, but I still had a lot of questions. Fortunately, a few relevant details have been clarified since.

The Vision Pro is a real gamble for Apple, and its rollout will be an unusual one. There are likely to be relatively few units available on launch day, at least compared to the company’s other products. Apple knows a first-generation product that starts at $3,499 won’t sell as fast as a new iPhone model—not even close.

Until a full review, I won’t know for sure who to recommend it to. But if you’re on the fence about being bold enough to preorder before reviews come in, treat this as a cheat sheet for the next couple of weeks.

The launch (and the price)

Online preorders start on January 19 at 5 am PST. February 2 is the day the device will start arriving on the doorsteps of those who preordered, and it’s also when the device will start being available at all US Apple Store locations. It’s important to clarify that the Vision Pro is launching in the US first; other key regions are expected later in the year.

The base configuration of the Vision Pro will cost a whopping $3,499, far more than the consumer VR or AR headsets we’ve seen in the past. However, there’s a lot more going on with Vision Pro hardware than in those headsets. And Apple has been careful not to call this a VR or AR headset at all; instead, the company dubs it a “spatial computing” device as a way to differentiate it from its predecessors.

Apple has reportedly been giving retail employees intensive training on a special process for selling the device in stores. Expect things like consultations on fitting, prescription lenses, and so on—similar to what I experienced when attending a demo of the device at WWDC. That will all follow a 25-minute demo, according to early reports. Signups for the demos start at 8 am on launch day.

When I tried the device, Apple asked about my vision and glasses prescription, used a 3D scan to measure my head, and more. Those who order online will be able to do all of this remotely, provided they have a recent iPhone or iPad with the TrueDepth sensor array. Apple used an iPhone when it took these readings in person at the demo in June.

There’s not enough room inside the Vision Pro for most people’s glasses, so you’ll have the option to buy corrective lenses as inserts specifically for the device. Fortunately, these aren’t quite as expensive as many of us initially feared: The standard price is $150, with reading lenses costing just $100. That’s still not cheap, but it was easy to imagine worse.

Supply chain analysts have come out and said they expect supply to fall far short of demand, so it’s likely that initial supply will sell out quickly, with potentially long wait times for new orders after that. We’ve seen similar things happen with launches for other Apple products like iPhone and MacBook Pro models before.

The situation could be worse, though; initial reports predicted hundreds of thousands of units, but respected supply chain analyst Ming-Chi Kuo recently said he believes Apple will only produce between 60,000 and 80,000 units for the launch. Demand will obviously be tempered by the very high list price, but it wouldn’t be hard to imagine it being bigger than that relatively small number, so expect delays.

That said, there might be a cap on just how many people are willing to spend that much for a first-generation device. So after the initial rush from enthusiasts and ambitious developers, demand may taper off relatively quickly, with ample supply in later months. You never know for sure, though.

https://arstechnica.com/?p=1995928




Apple AirDrop leaks user data like a sieve. Chinese authorities say they’re scooping it up.

Apple AirDrop leaks user data like a sieve. Chinese authorities say they’re scooping it up.
Aurich Lawson | Getty Images

Chinese authorities recently said they’re using an advanced encryption attack to de-anonymize users of AirDrop in an effort to crack down on citizens who use the Apple file-sharing feature to mass-distribute content that’s outlawed in that country.

According to a 2022 report from The New York Times, activists have used AirDrop to distribute scathing critiques of the Communist Party of China to nearby iPhone users in subway trains and stations and other public venues. A document one protester sent in October of that year called General Secretary Xi Jinping a “despotic traitor.” A few months later, with the release of iOS 16.1.1, the AirDrop users in China found that the “everyone” configuration, the setting that makes files available to all other users nearby, automatically reset to the more limited contacts-only setting. Apple has yet to acknowledge the move. Critics continue to see it as a concession Apple CEO Tim Cook made to Chinese authorities.

The rainbow connection

On Monday, eight months after the half-measure was put in place, officials with the local government in Beijing said some people have continued mass-sending illegal content. As a result, the officials said, they were now using an advanced technique publicly disclosed in 2021 to fight back.

“Some people reported that their iPhones received a video with inappropriate remarks in the Beijing subway,” the officials wrote, according to translations. “After preliminary investigation, the police found that the suspect used the AirDrop function of the iPhone to anonymously spread the inappropriate information in public places. Due to the anonymity and difficulty of tracking AirDrop, some netizens have begun to imitate this behavior.”

In response, the authorities said they’ve implemented the technical measures to identify the people mass-distributing the content.

The scant details and the quality of Internet-based translations don’t explicitly describe the technique. All the translations, however, have said it involves the use of what are known as rainbow tables to defeat the technical measures AirDrop uses to obfuscate users’ phone numbers and email addresses.

Rainbow tables were first proposed in 1980 as a means for vastly reducing what at the time was the astronomical amount of computing resources required to crack at-scale hashes, the one-way cryptographic representations used to conceal passwords and other types of sensitive data. Additional refinements made in 2003 made rainbow tables more useful still.

When AirDrop is configured to distribute files only between people who know each other, Apple says, it relies heavily on hashes to conceal the real-world identities of each party until the service determines there’s a match. Specifically, AirDrop broadcasts Bluetooth advertisements that contain a partial cryptographic hash of the sender’s phone number and/or email address.

If any of the truncated hashes match any phone number or email address in the address book of the other device, or if the devices are set to send or receive from everyone, the two devices will engage in a mutual authentication handshake. When the hashes match, the devices exchange the full SHA-256 hashes of the owners’ phone numbers and email addresses. This technique falls under an umbrella term known as private set intersection, often abbreviated as PSI.

In 2021, researchers at Germany’s Technical University of Darmstadt reported that they had devised practical ways to crack what Apple calls the identity hashes used to conceal identities while AirDrop determines if a nearby person is in the contacts of another. One of the researchers’ attack methods relies on rainbow tables. https://arstechnica.com/?p=1995574




DMA, Marghrethe Vestager incontra i Ceo di Apple (Tim Cook), Alphabet (Sundar Pichai) e Qualcomm (Cristiano Amon)

Margrethe Vestager, la commissaria europea per la concorrenza, ha reso noto di aver incontrato i direttori generali di Apple, di Alphabet e di Qualcomm per discutere della regolamentazione e del rispetto della politica della concorrenza, nei messaggi pubblicati sulla rete sociale X.

La settimana successiva, il consulente in comunicazione di Margrethe Vestager ha annunciato che questi interlocutori porteranno principalmente la regolamentazione numerica europea, in particolare la legislazione sui mercati digitali (DMA) e la politica della concorrenza.

Margrethe Vestager pubblicato i suoi commenti.

Con Tim Cook di Apple, ha detto di aver discusso, tra gli altri, dell’obbligo dell’azienda di consentire la distribuzione delle sue applicazioni al di fuori del proprio AppStore, così come gli affari di concorrenza in corso, come quello interessato è il servizio di streaming musicale di Apple Music.

Con Sundar Pichai, il Ceo di Alphabet e di Google, ha discusso, tra le altre cose, della concezione degli schermi di selezione, dell’autoreferenziazione in rapporto al DMA, così come l’affaire Google adtech che si trova all’attenzione alla concorrenza.

Nel quadro della DMA, le imprese che hanno più di 45 milioni di utenti attivi mensili e una borsa di capitalizzazione di 75 miliardi di euro sono considerate come gatekeepers e classificate come tali.

Dovranno, ad esempio, fare in modo che le loro applicazioni di messaggistica interagiscano con le loro rivali, o ancora lasciare che gli utenti decidano quali applicazioni preinstallare sui loro dispositivi.

Margrethe Vestager non ha dato alcuna precisazione particolare su ciò che è stato discusso con Cristiano Amon, direttore generale di Qualcomm.

https://www.key4biz.it/marghrethe-vestager-incontra-i-ceo-di-apple-tim-cook-alphabet-sundar-pichai-e-qualcomm-cristiano-amon/474905/




Microsoft supera Apple e diventa l’azienda che vale più al mondo (grazie all’AI)

Microsoft supera Apple, diventando l’azienda di maggior valore al mondo con un valore di mercato di 2,87 trilioni di dollari.

• L’aumento è alimentato dal settore in forte espansione dell’intelligenza artificiale, in particolare dal coinvolgimento dell’azienda con ChatGPT di OpenAI.

• Apple, in mancanza di significative iniziative di intelligenza artificiale, vede un declino della sua posizione di mercato a causa del rallentamento delle vendite di iPhone e delle sfide nel mercato cinese.

Microsoft si è presa decisamente il titolo di azienda pubblica di maggior valore al mondo. La valutazione di mercato di Microsoft è salita a ben 2,87 trilioni di dollari, superando Apple le cui azioni sono leggermente diminuite. Questo risultato non è solo una semplice fluttuazione dei prezzi delle azioni; è una testimonianza dei cambiamenti epocali che si stanno verificando nel mondo della tecnologia, in particolare dell’impennata dell’intelligenza artificiale (AI), dove Microsoft è emersa come una forza trainante.

Leggi anche: Perché Apple sta vivendo la sua peggior crisi dai tempi dell’iPod?

Intelligenza artificiale: la nuova frontiera di Microsoft

Il cuore dell’ascesa di Microsoft risiede nel fiorente campo dell’intelligenza artificiale generativa. L’azienda ha cavalcato l’onda dell’entusiasmo per questa tecnologia, notevolmente rafforzata dalla popolarità diffusa del ChatGPT di OpenAI sin dal suo debutto alla fine del 2022. Microsoft, essendo il più importante sostenitore di OpenAI e fornitore di cloud hosting, ha visto le sue fortune strettamente legate all’intelligenza artificiale.

Questo allineamento strategico ha anche visto Microsoft innovare con i chatbot AI nelle sue varie offerte, segnando un cambiamento significativo nel suo modello di business e nella suite di prodotti.

Al contrario, Apple sembra aver perso l’autobus, almeno per il momento, dell’intelligenza artificiale. Questa divergenza di focus è evidente nei recenti movimenti di mercato, con le azioni di Apple che hanno subito un duro colpo a causa delle preoccupazioni per il rallentamento delle vendite di iPhone, soprattutto in mercati chiave come la Cina.

Sabbie mobili: la saga continua dei giganti della tecnologia

La rivalità tra Apple e Microsoft è leggendaria e risale agli anni ’80. È una saga piena di battaglie legali, gare di innovazione e cambiamenti nella leadership di mercato. Apple, per molto tempo, ha avuto il sopravvento, soprattutto con il fenomenale successo dell’iPhone. Tuttavia, la rinascita di Microsoft, in particolare durante la pandemia di COVID-19, ha sottolineato l’agilità dell’azienda e la sua abilità nel trarre vantaggio dalle tendenze tecnologiche emergenti come il cloud computing e ora l’intelligenza artificiale.

L’attuale successo di Microsoft non riguarda solo il sorpasso di Apple; è anche un riflesso dell’orientamento del settore più ampio verso l’intelligenza artificiale. Questo cambiamento è così significativo che anche aziende specializzate come Nvidia, note per i loro chip AI, stanno vedendo un aumento sostanziale del loro valore di mercato, segnalando una tendenza del settore più ampia che favorisce coloro che sono abili nello sfruttare le tecnologie AI.

C’è da dire che Apple non è affatto fuori partita. Stanno puntando sul prossimo visore Vision Pro per innescare una nuova era nel “calcolo spaziale”. Tuttavia, il fermento attorno all’intelligenza artificiale, in particolare il successo di ChatGPT, ha fatto pendere significativamente la bilancia a favore di Microsoft. Non si tratta solo dei prodotti; riguarda le tecnologie sottostanti che stanno rimodellando il panorama tecnologico.

L’ascesa di Microsoft al vertice è molto più di una semplice vittoria numerica; è un indicatore della natura dinamica e in continua evoluzione del settore tecnologico. L’attenzione all’intelligenza artificiale, al cloud computing e alle mutevoli richieste dei consumatori stanno rimodellando il settore in modo profondo.

https://www.key4biz.it/microsoft-supera-apple-e-diventa-lazienda-che-vale-piu-al-mondo-grazie-allai/474796/




Apple venderà Vision Pro negli Usa dal mese prossimo

Il visore per realtà mista è pronto a inaugurare l’era del “calcolo spaziale” nel bel mezzo del rallentamento delle vendite di iPhone. Il visore Vision Pro, con un prezzo iniziale di 3.499 dollari, aggiunge una sovrapposizione digitale al mondo reale, con gli utenti che lo navigano con gli occhi, la voce e mani.

Le cuffie

Le cuffie, che rappresentano il lancio più significativo di un nuovo prodotto di Apple dopo l’Apple Watch nel 2015, saranno rese disponibili online e in tutti i suoi negozi fisici negli Stati Uniti. Le azioni Apple sono scese di quasi il 6% quest’anno dopo che due banche hanno declassato i loro rating la scorsa settimana. Le contrattazioni di lunedì hanno mostrato il primo giorno di guadagni del 2024 per il titolo, con un aumento dell’1,3%. Il lancio del visore Vision Pro lo scorso anno ha riacceso l’entusiasmo delle start-up di realtà virtuale e aumentata che hanno fame di finanziamenti da parte di investitori che hanno preferito scommettere su gruppi di intelligenza artificiale. Il colosso della tecnologia sosteneva che le cuffie avrebbero rivoluzionato il mobile computing, proprio come ha fatto l’iPhone, e inaugurato un’era del “calcolo spaziale”.

Tim Cook, amministratore delegato di Apple, lunedì ha definito le cuffie “il dispositivo elettronico di consumo più avanzato mai creato”. “Vision Pro sarà un prodotto importante per Apple nel lungo termine, ovvero nei prossimi cinque-dieci anni”, ha detto Gene Munster di Deepwater Asset Management. “Le persone non apprezzano il valore del calcolo spaziale finché non ne hanno fatto esperienza”. Munster, tuttavia, ha aggiunto che “il primo anno sarà estremamente lento in termini di unità consegnate”.

Video immersivo

Le cuffie Vision Pro, basate sul nuovo sistema operativo visionOS di Apple, aggiungono una sovrapposizione digitale al mondo reale, con gli utenti che lo navigano con gli occhi, la voce e le mani. Il formato “video immersivo” offrirà agli utenti un’esperienza interattiva a 180 gradi e potranno giocare sui giochi sull’App Store e tramite Apple Arcade. Apple afferma che il dispositivo offre anche lo “spazio di lavoro perfetto” per il multitasking e la collaborazione.

Apple ha presentato le cuffie nel giugno 2023 dopo sette anni di sviluppo. Ma di fronte alla complessità del design, Apple ha tagliato le previsioni di produzione da 1 milione a 400.000 nel 2024. Apple ha rifiutato di commentare quando il dispositivo sarà reso disponibile al di fuori degli Stati Uniti e quante unità l’azienda prevede di spedire nel 2024.

Previsioni di vendita caute

Gli analisti hanno stati cauti nelle loro aspettative sulle vendite di Vision Pro. In una nota di dicembre, gli analisti di UBS affermavano che il dispositivo avrebbe inizialmente un “impatto finanziario limitato”.

La spinta di Apple per il suo Vision Pro arriva mentre le vendite dell’hardware esistente stanno vacillando. La scorsa settimana Barclays e Piper Sandler hanno entrambi declassato i loro rating sulle azioni di Apple, citando preoccupazioni sulla debole domanda di iPhone nel 2024.

Domenica gli analisti di Jefferies hanno affermato che le vendite di iPhone di Apple in Cina, dove deve affrontare la crescente concorrenza di Huawei, sono diminuite del 30%. nella prima settimana del 2024. Apple è particolarmente esposta ai cambiamenti macroeconomici in Cina, non solo in termini di vendite ma anche in termini di catene di fornitura, che sta cercando di diversificare in paesi come India e Vietnam.

https://www.key4biz.it/apple-vendera-vision-pro-negli-usa-dal-mese-prossimo/474176/




Scoperta una vulnerabilità hardware negli iPhone usata in Operation Triangulation


Il Global Research and Analysis Team (GReAT) di Kaspersky ha scoperto una vulnerabilità nel System on a Chip (SoC) di Apple che è stata fondamentale nei recenti attacchi di Operation Triangulation. 

La campagna, scoperta dai ricercatori di Kaspersky, sfruttava quattro vulnerabilità zero-day per distribuire un malware che non necessitava dell’interazione utente per essere eseguito.

Ora il team della compagnia di sicurezza ha scoperto un’ulteriore vulnerabilità sfruttata dagli attaccanti, una funzionalità hardware che sembra fosse destinata solo al test o al debug. Dopo l’attacco iniziale a iMessage e successiva escalation dei privilegi, gli attaccanti hanno sfruttato la funzione per aggirare le protezioni di sicurezza basate su hardware e manipolare il contenuto delle aree di memoria protette, ottenendo in questo modo il controllo totale del dispositivo.

Operation Triangulation - Credits: dontree- Depositphotos

Credits: dontree- Depositphotos

Poiché questa funzionalità non è stata documentata pubblicamente, è stato molto difficile rilevarla coi metodi di sicurezza convenzionali. Il GReAT si è occupato di un meticoloso reverse engineering, analizzando l’integrazione tra hardware e software dell’iPhone e in particolare gli indirizzi Memory-Mapped I/O (MMIO) utilizzati per facilitare la comunicazione tra la CPU e i dispositivi periferici del sistema.

Gli attaccanti hanno utilizzato indirizzi MMIO sconosciuti e difficili da identificare, tanto che il team di Kaspersky ha dovuto analizzare a fondo il funzionamento del SoC e l’interazione col sistema operativo per comprendere la gestione della memoria e i meccanismi di protezione, nel tentativo di trovare qualsiasi riferimento agli indirizzi.

“Non si tratta di una vulnerabilità ordinaria e, a causa della natura chiusa dell’ecosistema iOS, il processo di scoperta è stato impegnativo e ha richiesto una comprensione completa delle architetture hardware e software. Questa scoperta ci insegna ancora una volta che anche le protezioni avanzate basate sull’hardware possono essere rese inefficaci di fronte a un aggressore sofisticato, in particolare quando esistono caratteristiche hardware che consentono di bypassare queste protezioni” ha spiegato Boris Larin, Principal Security Researcher del GReAT di Kaspersky.

Operation Triangulation è attiva dal 2019, quindi è probabile che la vulnerabilità sia stata utilizzata per quattro anni prima di essere individuata dal team di Kaspersky. Apple ha risolto il bug e ha invitato gli utenti con iPhone vulnerabili ad aggiornare il prima possibile i dispositivi.

Condividi l’articolo



Articoli correlati

Altro in questa categoria


https://www.securityinfo.it/2023/12/29/scoperta-una-vulnerabilita-hardware-negli-iphone-usata-in-operation-triangulation/?utm_source=rss&utm_medium=rss&utm_campaign=scoperta-una-vulnerabilita-hardware-negli-iphone-usata-in-operation-triangulation




Researchers come up with better idea to prevent AirTag stalking

Picture of AirTag
BackyardProduction via Getty Images

Apple’s AirTags are meant to help you effortlessly find your keys or track your luggage. But the same features that make them easy to deploy and inconspicuous in your daily life have also allowed them to be abused as a sinister tracking tool that domestic abusers and criminals can use to stalk their targets.

Over the past year, Apple has taken protective steps to notify iPhone and Android users if an AirTag is in their vicinity for a significant amount of time without the presence of its owner’s iPhone, which could indicate that an AirTag has been planted to secretly track their location. Apple hasn’t said exactly how long this time interval is, but to create the much-needed alert system, Apple made some crucial changes to the location privacy design the company originally developed a few years ago for its “Find My” device tracking feature. Researchers from Johns Hopkins University and the University of California, San Diego, say, though, that they’ve developed a cryptographic scheme to bridge the gap—prioritizing detection of potentially malicious AirTags while also preserving maximum privacy for AirTag users.

The Find My system uses both public and private cryptographic keys to identify individual AirTags and manage their location tracking. But Apple developed a particularly thoughtful mechanism to regularly rotate the public device identifier—every 15 minutes, according to the researchers. This way, it would be much more difficult for someone to track your location over time using a Bluetooth scanner to follow the identifier around. This worked well for privately tracking the location of, say, your MacBook if it was lost or stolen, but the downside of constantly changing this identifier for AirTags was that it provided cover for the tiny devices to be deployed abusively.

In reaction to this conundrum, Apple revised the system so an AirTag’s public identifier now only rotates once every 24 hours if the AirTag is away from an iPhone or other Apple device that “owns” it. The idea is that this way other devices can detect potential stalking, but won’t be throwing up alerts all the time if you spend a weekend with a friend who has their iPhone and the AirTag on their keys in their pockets.

In practice, though, the researchers say that these changes have created a situation where AirTags are broadcasting their location to anyone who’s checking within a 30- to 50-foot radius over the course of an entire day—enough time to track a person as they go about their life and get a sense of their movements.

“We had students walk through cities, walk through Times Square and Washington, DC, and lots and lots of people are broadcasting their locations,” says Johns Hopkins cryptographer Matt Green, who worked on the research with a group of colleagues, including Nadia Heninger and Abhishek Jain. “Hundreds of AirTags were not near the device they were registered to, and we’re assuming that most of those were not stalker AirTags.”

Apple has been working with companies like Google, Samsung, and Tile on a cross-industry effort to address the threat of tracking from products similar to AirTags. And for now, at least, the researchers say that the consortium seems to have adopted Apple’s approach of rotating the device public identifiers once every 24 hours. But the privacy trade-off inherent in this solution made the researchers curious about whether it would be possible to design a system that better balanced both privacy and safety.

https://arstechnica.com/?p=1992899




4-year campaign backdoored iPhones using possibly the most advanced exploit ever

iphone with text background

Researchers on Wednesday presented intriguing new findings surrounding an attack that over four years backdoored dozens if not thousands of iPhones, many of which belonged to employees of Moscow-based security firm Kaspersky. Chief among the discoveries: the unknown attackers were able to achieve an unprecedented level of access by exploiting a vulnerability in an undocumented hardware feature that few if anyone outside of Apple and chip suppliers such as ARM Holdings knew of.

“The exploit’s sophistication and the feature’s obscurity suggest the attackers had advanced technical capabilities,” Kaspersky researcher Boris Larin wrote in an email. “Our analysis hasn’t revealed how they became aware of this feature, but we’re exploring all possibilities, including accidental disclosure in past firmware or source code releases. They may also have stumbled upon it through hardware reverse engineering.”

Four zero-days exploited for years

Other questions remain unanswered, wrote Larin, even after about 12 months of intensive investigation. Besides how the attackers learned of the hardware feature, the researchers still don’t know what, precisely, its purpose is. Also unknown is if the feature is a native part of the iPhone or enabled by a third-party hardware component such as ARM’s CoreSight

The mass backdooring campaign, which according to Russian officials also infected the iPhones of thousands of people working inside diplomatic missions and embassies in Russia, according to Russian government officials, came to light in June. Over a span of at least four years, Kaspersky said, the infections were delivered in iMessage texts that installed malware through a complex exploit chain without requiring the receiver to take any action.

With that, the devices were infected with full-featured spyware that, among other things, transmitted microphone recordings, photos, geolocation, and other sensitive data to attacker-controlled servers. Although infections didn’t survive a reboot, the unknown attackers kept their campaign alive simply by sending devices a new malicious iMessage text shortly after devices were restarted.

A fresh infusion of details disclosed Wednesday said that “Triangulation”—the name Kaspersky gave to both the malware and the campaign that installed it—exploited four critical zero-day vulnerabilities, meaning serious programming flaws that were known to the attackers before they were known to Apple. The company has since patched all four of the vulnerabilities, which are tracked as:

Besides affecting iPhones, these critical zero-days and the secret hardware function resided in Macs, iPods, iPads, Apple TVs, and Apple Watches. What’s more, the exploits Kaspersky recovered were intentionally developed to work on those devices as well. Apple has patched those platforms as well. Apple declined to comment for this article.

Detecting infections is extremely challenging, even for people with advanced forensic expertise. For those who want to try, a list of Internet addresses, files, and other indicators of compromise is here.

Mystery iPhone function proves pivotal to Triangulation’s success

The most intriguing new detail is the targeting of the heretofore-unknown hardware feature, which proved to be pivotal to the Operation Triangulation campaign. A zero-day in the feature allowed the attackers to bypass advanced hardware-based memory protections designed to safeguard device system integrity even after an attacker gained the ability to tamper with memory of the underlying kernel. On most other platforms, once attackers successfully exploit a kernel vulnerability they have full control of the compromised system.

On Apple devices equipped with these protections, such attackers are still unable to perform key post-exploitation techniques such as injecting malicious code into other processes, or modifying kernel code or sensitive kernel data. This powerful protection was bypassed by exploiting a vulnerability in the secret function. The protection, which has rarely been defeated in exploits found to date, is also present in Apple’s M1 and M2 CPUs.

Kaspersky researchers learned of the secret hardware function only after months of extensive reverse engineering of devices that had been infected with Triangulation. In the course, the researchers’ attention was drawn to what are known as hardware registers, which provide memory addresses for CPUs to interact with peripheral components such as USBs, memory controllers, and GPUs. MMIOs, short for Memory-mapped Input/Outputs, allow the CPU to write to the specific hardware register of a specific peripheral device.

The researchers found that several of MMIO addresses the attackers used to bypass the memory protections weren’t identified in any so-called device tree, a machine-readable description of a particular set of hardware that can be helpful to reverse engineers. Even after the researchers further scoured source codes, kernel images, and firmware, they were still unable to find any mention of the MMIO addresses.

https://arstechnica.com/?p=1992873




Apple appeals trade commission ban of Apple Watch 9, Apple Watch Ultra 2

Apple Watch Series 9
Enlarge / The Apple Watch Series 9 released in September 2023.

Just before Christmas, Apple pulled two of its latest smartwatches from stores. The cause was not an unwelcome visit from the ghost of mechanical timepieces past but the International Trade Commission, which found that the California-based computer maker had infringed on some patents. Now, Reuters reports that Apple has filed an emergency request for the courts to lift the ban and will appeal the ITC ruling.

Apple’s watch problems started back in January. That’s when a court found that the light-based pulse oximetry sensor (found on the back of the watches) infringed patents held by Masimo, a medical device manufacturer also based in California.

At the time, Apple said since Masimo was not a consumer-focused company, it chose not to collaborate or acquire the medical device maker. Masimo, for its part, said that Apple led it on in discussions then took its idea and hired away Masimo engineers.

In October, the ITC upheld the ruling of infringement and started the process to ban imports of the watches, giving US President Joe Biden’s administration 60 days to review the case and possibly veto the ruling.

But the Biden administration has chosen not to interfere, unlike in 2013 when the Obama administration vetoed a ban on iPhones and iPads during a patent dispute between Apple and Samsung. Although the ITC’s import ban on Apple Watch Series 9 and Ultra 2 models was supposed to go into effect on December 26, Apple pulled the watches from sale a few days early.

“We strongly disagree with the USITC decision and resulting exclusion order, and are taking all measures to return Apple Watch Series 9 and Apple Watch Ultra 2 to customers in the US as soon as possible,” Apple said in a statement.

Apple’s hopes now lie with the US Court of Appeals for the Federal Circuit, which it asked to pause the ban until US Customs and Border Protection decides whether redesigned Apple Watches no longer infringe on Masimo’s patents, a decision that should be reached by January 12. The older Apple Watch SE, which doesn’t use the infringing blood oxygen sensor, remains on sale.

https://arstechnica.com/?p=1992857