Showing posts sorted by relevance for query Apple. Sort by date Show all posts
Showing posts sorted by relevance for query Apple. Sort by date Show all posts

iTunes Store Vulnerability Exposed, later Apple fixed that



Apple's iTunes Store had a vulnerability that accepted incorrect passwords from America Online (AOL) users, that could have been exploited by hackers.
Security researcher Joshua Long said he discovered the vulnerability more than six months ago but kept silent until Apple could fix the flaw."Apple recently worked with AOL to fix a vulnerability that has been discovered in the iTunes Store authentication process ... This vulnerability seemed to be a problem in the way Apple integrated AOL user names and passwords into its services," he said in his blog.Before the vulnerability was fixed, he said Apple would accept incorrect passwords from users logging into the store using an AOL Screen Name. Incomplete passwords, passwords with incorrect letter case, passwords with incorrect or extra characters at the end, or a combination of any or all of these, were accepted by Apple. "Knowledge of this vulnerability could potentially have been used by attackers, leading to disclosure of personally identifiable information, identity theft, and fraudulent purchases," he said.Long said the vulnerability took the whole six-month disclosure time limit to be announced.He said Apple was at first unresponsive to the problem and then when it did respond, it was initially unable to reproduce it. "When I discovered this security vulnerability last year, I felt that it was serious enough to warrant submitting it to a responsible third-party vulnerability management organization rather than only to Apple or AOL. I have submitted reports to both companies in the past, and I have found that sometimes it can take them a very long time to respond to a security issue," Long said.He noted that up to now, AOL "still doesn't seem to care about encrypting its Web-based e-mail service, in spite of Firesheep shining a spotlight on the problem last year.""I hoped that bringing in a third party to work with the vendor would help encourage the vendor to take the issue seriously and fix it more quickly," he said.He eventually asked upSploit to help inform the affected parties about the vulnerability and the date on which it will be disclosed to the public. "I believe that upSploit's persistence was a major factor in motivating the vendor to take action and to resolve the issue," he said. 

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Microsoft Opens Up About Mobile Tracking



Microsoft recently responded to questions regarding its storage and use of location data on Windows devices, in marked contrast to Apple and Google as growing controversy over mobile tracking heats up
When asked by CNET if it stores location information on users' phones, Microsoft promptly responded with specifics about how it does so minimally and securely.
The Redmond, Wash.-based company said only user-allowed, location-based apps collect location data from its phones. Those apps' data isn't stored on the phone itself, though, and so can't be hacked by third parties or synced back to the company.
Of course this data is stored somewhere, but only when "the application or user makes a request for location information," the company said.
In technical terms, Microsoft's mobile OS will transmit a Windows Phone device's unique identification number, along with the phone's signal strength, a randomly generated device ID, and GPS coordinates, but only if someone decides to run a location-based app. This information is all encrypted, according to Microsoft.
This differs from Apple's practice of recording the locations of iPhone and iPad devices in an unencrypted file on the device, which can result in more than a year's worth of data being quietly logged, according to two researchers who recently discovered the feature in Apple mobile devices. Google's Android devices collect tracking data, but records only the last few dozen locations.
These practices have resulted in a firestorm of outcry, with senators and House representatives, consumers, and even international governments demanding answers to sensitive questions on what the data is being used for and why it is being gathered in the first place.
Apple is now being sued for violating Fourth Amendment rights as well.
Microsoft's quick, pro-active response contrasts to Apple and Google's relative silence upon being asked similar questions about their tracking policies this week. Google recently responded to the Wall Street Journal to questions, insisting however that the data is anonymized without going into detail about exactly how. But Apple has stayed officially silent on the matter.
The software company's relative openness about its data gathering practices may cast it in a favorable light as attention only intensifies, especially as members of Congress begin to scrutinize privacy issues and demand answers not just from Apple and Google, but other mobile companies.
This, along with burgeoning governmental concerns about data and privacy in general, only means that the question will not go away. Microsoft's response may be its way of opening a conversation on its own terms, and highlights its relative security when it comes to location data collection.
The company could use this good PR about now, as they trail behind competitors Apple and Google. It trails these two companies in a distant third in sales in the smartphone market.
It may be too much to hope Microsoft's relative respect for consumer privacy will boost Windows 7 Phone sales greatly, but the company can perhaps claim some high ground in what continues to be a controversial matter.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Another OS X Malware App Pops Up, But Danger is Still Limited


Cyber criminal community's interest in attacking Apple users is growing, but still lacks discipline
According to a handful of dedicated hackers of Apple, Inc.'s (AAPL) computer operating system, OS X, the OS is actually less secure than Microsoft Corp.'s (MSFT) Windows.  But thanks to the OS's small market share (traditionally 5 percent or less) most cybercriminals haven't felt it worthwhile to target the platform.  Also, some hackers have misgivings about attacking Unix-like operating systems (e.g. Linux, OS X).


Still, Apple's growing market share and boastful claims of security have lead to an increased interest in attacks and some OS X malware has been popping up of late.

The latest malware to target OS X is dubbed "MACDefender".  Attack pages for the new malware exploit the way Apple's default Safari browser handles Javascript, running a script that auto-initiates the download of a script file.  If the user has opted to open "safe" files, the archive will then auto-open and initiate an install dialogue.

The risk is minimal as users must approve of this dialogue and enter an administrative password to complete the installation.  Still it may be a bit more widespread as the attack pages have boosted themselves to near the top of many search results, thanks to search engine optimization (SEO) poisoning.

It is unclear what the software does when active, though it appears to be logging user activities.  Users who accidentally installed the software can still delete it by killing its process and dragging it from the Applications folder to the Trash bin.

Members of the Apple Support community first noted the malware last Saturday.

On Monday, security firm Intego released an advisory, calling the risk of the malware "low".  Intego writes:

When a user clicks a link after performing a search on a search engine such as Google, this takes them to a web site whose page contains JavaScript that automatically downloads a file," Intego said. "In this case, the file downloaded is a compressed ZIP archive, which, if a specific option in a web browser is checked (Open 'safe' files after downloading in Safari, for example), will open.
The malware unfortunately shares its name with a legitimate OS X software firm.  MacDefender is a small software firm that makes geocaching software, including GCStatistic and DTmatrix.  The company has released a statement emphatically saying that it is not affiliated with the rogue software.

The company writes:

IMPORTANT NOTE: As it seams (sic) someone wrote a virus/malware application named mac defender (MacDefender.app) for OS X. If you see an application named like this DO NOT DOWNLOAD/INSTALL it. I would never release an application named like this.
In recent months botnet-forming worms and trojans have targeted OS X.  Most of these pieces of malware have been amateurish efforts, though, or works in progress.  Nonetheless it remains a very real possibility that Apple could one day see a serious attack.

For its part Apple has suggested users get an antivirus program, though it still claims in advertisements that its platform does not suffer from malware like Windows.  Apple has refused to provide customers with free antimalware software like Microsoft does, so security firm Sophos Plc. has picked up the ball offering free basic protection to Mac users.  Some other smaller firms also offer free Mac antimalware suite

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Mac OS X 10.8 Mountain Lion Developer Preview Released By Apple

Mac OS X 10.8 Mountain Lion Developer Preview Released By Apple


Apple released a developer preview of the next major release of its operating system named Mac OS X 10.8 Mountain Lion. If you are a registered Mac developer then you can test the new flavor of Apple. Not to mention in this release Apple has added lost of charming features among them Gatekeeper is really handy one at leat from security point of view. Apple says gatekeeper will "help prevent you from unknowingly downloading and installing malicious software". Some of other features included by apple are iCloud, AirPlay Mirroring, Messages, Reminders, Notification Center, Share Sheets, Twitter Integration, Game Center and so on.
Brief About Gatekeeper:-
The Gatekeeper feature has three levels of security for running applications downloaded from the Internet; "Mac App Store", "Mac App Store and identified developers" and "Anywhere". The first setting only runs applications downloaded from the Mac App Store, in a style similar to the iPhone only running apps from the App Store. Unlike the iPhone though, Gatekeeper lets users allow applications from other sources. The "Mac App Store and Identified Developers" option only allows applications from the store and from developers who have signed their program with an Apple-issued Developer ID, while "Anywhere" allows any program to be downloaded and run. It is unclear how Gatekeeper interacts with software loaded from other media, such as a USB memory stick or CD/DVD.

For More Information & To Download Mac OS X 10.8 Mountain Lion Developer Preview Click Here


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Apple Released Mac OS X Security Update (2011-005) To Stop Certificate Fraud



Apple on Friday issued a security update for Mac OS X 10.7 Lion and 10.6 Snow Leopard, addressing a security issue related to fraudulent online certificates.
Security Update 2011-005 is available to download via Software Update, or as a 15.59MB download for Lion, or 869KB download for Snow Leopard direct from Apple. It is recommended for all Mac users.
The update addresses an issue that could allow an attacker with a privileged network position to intercept user credentials or other sensitive information.
Apple issued the update because fraudulent certificates were issued by multiple certificate authorities operated by DigiNotar. Apple's fix removes DigiNotar from the list of trusted root certificates and from the list of Extended Validation (EV) certificate authorities. The security update also configures the default system trust settings so that DigiNotar's certificates, including those issued by other authorities, are not viewed as trusted.
Another update was also issued by Apple on Thursday for Lexmark printers in the form of Lexmark 2.6 Printer Driver. It includes the latest Lexmark printing and scanning software for both Lion and Snow Leopard, and the 133.99MB update can be downloaded direct from Apple.

-News Source (Apple Insider)


SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

This is the Beginning of the End for the Optical Drive (Apple removed DVD


Shane Richmond says this is the beginning of the end for the optical drive. Apple last week removed DVD drives from its Mac Mini computers
Apple updated some of its computers last week. The MacBook Air and the Mac Mini both got significant processor upgrades and the addition of Thunderbolt ports. While the additions are interesting, it’s something that was removed that is especially telling.
It’s not the MacBook, though Apple did quietly retire its trusty old laptop from service, leaving just the Air and the Pro in the MacBook range. What’s gone is the optical drive on the Mac Mini.
That means neither the Air or the Mini have optical drives anymore. If you want to play a DVD or a CD - or to save data to one - then you’ll need a £66 SuperDrive. The MacBook Pro retains an optical drive for now but it's clear that Apple believes that the disc is living on borrowed time.
Many will argue that it is too soon to ditch the disc. Apple is familiar with that sort of reaction, however, and hasn’t been deterred in the past. There was an outcry, for example, when the iMac was launched in 1998 without a floppy disk drive. Apple's other computers gradually followed suit. Dell didn’t remove floppy drives from its machines until 2003.
If those who genuinely need an optical drive are not yet a minority then they soon will be. My MacBook Pro has an optical drive but I can’t remember the last time I needed to use it. At the end of last year I switched to a MacBook Air for day-to-day use and I’ve never wished that it had an optical drive.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

FBI Agent's Laptop Hacked, 12 Million Apple UDID Stolen By Anonymous (#FFF)

FBI Agent's Laptop Hacked, 12 Million Apple UDID Stolen By Anonymous (#FFF)

#Antisec an Offshoot part of infamous hacker collective Anonymous claims to have stolen a file from an FBI laptop which contained more than 12 million unique Apple device indentity numbers. The hackers declares this hack as part of their Friday rampage (#FFF) though the breach did not took place on Friday
The data which hackers stole came from a laptop belonging to Supervisor Special Agent at the FBI, Christopher K. StanglStangl, who joined the FBI in 2003 after graduating from Monmouth University, has been with the agency for nine and a half years and won an award in 2010 for helping bust a cyber crime ring. He was also sucked into another Anonymous stunt earlier this year when at least one of their supporters breached an FBI conference call that had been discussing Anonymous and LulzSec. Stangl was listed among those invited into the call, in an e-mail that was posted on PastebinIn a video posted to Facebook in 2009 (and which will likely be getting a lot more views in the coming days), Stangl is shown wearing a dark suit and tie, speaking to the camera, and calling for “cyber security experts” to join the FBI.

According to the hacker :-

"During the second week of March 2012, a Dell Vostro notebook, used by Supervisor Special Agent Christopher K. Stangl from FBI Regional Cyber Action Team and New York FBI Office Evidence Response Team was breached using the AtomicReferenceArray vulnerability on Java, during the shell session some files were downloaded from his Desktop folder one of them with the name of “NCFTA_iOS_devices_intel.csv” turned to be a list of 12,367,232 Apple iOS devices including Unique Device Identifiers (UDID), user names, name of device, type of device, Apple Push Notification Service tokens, zipcodes, cellphone numbers, addresses, etc. the personal details fields referring to people appears many times empty leaving the whole list incompleted on many parts. no other file on the same folder makes mention about this list or its purpose."

The data is just part of a larger database of 12,367,232 UDIDs, and personal information such as full names, cellphone numbers, addresses and zipcodes belonging to Apple customers. The data was allegedly stolen via exploiting a Java vulnerability. In a pastebin note, the hacker posted several download links of the hacked database. Several security experts have already stated that the stolen data is correct. For those you are not familiar with the term UDID -Each iOS device (iPhone, iPad, iPod touch) is assigned a unique alphanumeric number known as a UDID. This was previously used by app developers to track data usage for their apps, until Apple decided to reject any apps which sought to gain access to this number in the most recent official iOS update. As well as believing that the FBI was using these identifiers to track people, though AnticSec, in its missive on Pastebin, said it didn't agree with the idea of hardware coded identifiers anyway: "We always thought it (UDIDs) was a really bad idea. That hardware coded IDs for devices concept should be eradicated from any device on the market in the future." To read the full press release of #Antisec click Here




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Apple iOS Devices & Persistent Location Tracking




Last week a big can of worms opened when two security researchers revealed Apple's iOS 4 tracks and stores detailed location data on each user's whereabouts. Many are ready to ditch the iPhone over the news. That may be a little drastic. 

There's reason why Apple, or any mobile device platform, tracks current location. The frightening part is why Apple actually tracks and stores history with no stated purpose. Further, a post on Mac Rumors reveals Steve Jobs denies that the company tracks anyone.
We know that Google and web publishers track user activity online. It also uses notes location. Both activity and location are often used to serve more relevant ads, and also provide demographics to advertisers and other business the publisher has a relationship with. Mobile is an extension of the web mobile mirrors much of this conduct.
Apple is not the only one to track location. Google tracks location on its Android platform and on phones using Google mobile apps such as Google Maps (this includes the iPhone). A provider such as Google or Apple uses location information to provide navigation, provide local search results and yes, serve ads targeted to your location. We hope data doesn't get used for much deeper purposes. The fact that Apple's file keeps data for the life of a phone is alarming. The possibility that a company or person might tap into that file and exploit the data pushes concerns even deeper.
Cell phone carriers such as Verizon, AT&T, Sprint and others also track your location. Your phone constantly checks in with the nearest towers. Carriers use that information to maintain its network and push services back to the subscriber. In certain cases location data can be used to locate someone for rescue purposes.
It shouldn't be a surprise that location data is tracked on your phone. However you shouldn't just accept it and continue business as usual. Pay some attention to the EULA statement or end-use licensing agreement before checking the box. Look into the privacy settings on your mobile device and set it to a level you're comfortable with. Remember that if you turn off a service provider's ability to share your location, you also won't be able to use apps and services that require your location such as Google Maps.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Latest iPad Jailbroken Immediately After Release

Latest iPad Jailbroken Immediately After Release 
The new iPad tablet was released by Apple on Friday but yet again the same history repeated. Though in this release Apple forbids installing applications it has not approved, but hackers have found ways to "jailbreak" devices, or modify the code to allow unauthorized programs from alternative application stores such as Cydia.  But  fail to stop the hacker. The much-awaited device. Reportedly, the next-generation iPad was jailbroken within three hours of its market release on March 16. "Musclenerd," a member of the iPhone Dev Team, posted a screenshot on Twitter on Mar. 16 showing how he got root access on the latest Apple tablet. Another member, Stefan Esser, or @i0nic, posted a video showing an untethered jailbreak for his third-generation iPad. Finally, Grant Paul, or @chpwn, disclosed a third method to get root on the new iPad. There are three different methods to jailbreak the latest Apple iOS 5.1 software, and videos and screenshots posted over the weekend showed the hacks, according to the Dev-Team, which developed the first jailbreak tool.
In January, the tool Absinthe A5 was released, which could jailbreak both the iPhone 4S and iPad running software versions just before iOS 5.1. It took about 10 months to develop due to the difficulty the hacking group GreenPois0n found in trying to find a way to exploit the A5 processor. On the other hand, Apple is very strict about the control it exerts over its products, and iOS device owners have no choice but to buy and use software and content through Apple’s channels without a jailbreak. So it comes down to each users’ preferences: is it better to break the control and run the risk, or stay within Apple’s relatively safe walled garden with fewer choices?




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Finally Facebook Released Their Application for iPad


One year, six months, and seven days after the iPad first went on sale, Facebook has at last released its app for Apple's tablet. "Many of you have been asking about Facebook for iPad," the company said in an understated blog post Monday. "Today, it's finally here." The long-delayed app has the subject of much Silicon Valley chatter. Some rumors suggested that a rift between Facebook CEO Mark Zuckerberg and Apple's executive team over Apple's Ping social network was to blame for the delay. Others claimed that Facebook preferred a Web-based application that bypassed Apple's strict app store rules.
Former Facebook developer Jeff Verkoeyen, the lead engineer on the the iPad app, wrote on his blog recently that he quit the company after Facebook continually delayed the release of the iPad app.
It had been in the works since October 2010 and was essentially completed in May, Verkoeyen said.
"For reasons I won't go into details on the app was repeatedly delayed throughout the summer," Verkoeyen wrote. "Needless to say this was a frustrating experience for me. The experience of working on this app was a large contribution to the reasons why I left Facebook, though that doesn't mean it wasn't a difficult decision."
Verkoeyen, who now works for Google, later updated his blog post to strip out his criticism of Facebook and his comments about the app's delay.
If Verkoeyen's timeline is correct, that means that the Facebook iPad app was stuck in limbo longer than the Apple's notoriously delayed white iPhone 4.
But like the white iPhone, Facebook's iPad app has finally appeared. The application showcases many of the familiar Facebook features, integrating gestures and swipes to help users navigate the social network.
"With the iPad app, you get the full Facebook experience, right at your fingertips," Leon Dubinsky, a Facebook mobile engineer, said in a blog post that he wrote "from the comfort of his couch."
Games, apps, groups and lists appear in a menu on the left-hand side, giving users quick access to their most-frequently used tasks. Messages and notifications appear at the top of each screen, so Facebook users can chat with friends and view updates without jumping back and forth between screens.
The app also allows lets users play full-screen games, watch and record HD videos and stream them to other devices using Apple's Airplay technology.
The app had been noticeably absent from Apple's iTunes app store, considering that Facebook had been among the first to debut an iPhone application in 2007. The social network also said Monday that it made several improvements to the iPhone app and Facebook's mobile site, giving users simplified navigation, faster search and access to more games and apps. 

For more information and to get the application click Here



-News Source (CNN)



 

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Apple releases iOS 5 beta 3

 
Apple on Monday released a new build of its iOS 5 beta software to developers. The new build — iOS 5 beta 3 — is available for all applicable iOS devices including the iPhone 4, iPhone 3GS, iPad 2, iPad, Apple TV, and third and fourth-generation iPod touch devices. Apple also released the third beta of iTunes 10.5 alongside the new iOS release of course, and it will be necessary for developers to install iTunes 10.5 beta 3 in order to load the new iOS beta on their devices. Hit the break for the full change log included with this release.

Notes and Known Issues

The following issues relate to using the 5.0 SDK to develop code.

Accounts

  • When creating an iCloud account you can use any Apple ID provided it is a full email address and not a MobileMe account. If you have a MobileMe account, you can copy data from that account to an iCloud account to use during testing. You can find more information on iCloud at: http://developer.apple.com/icloud
  • When setting up an iCloud or MobileMe account using the setup assistant and leaving Find My iPhone on, it might actually turn Find my iPhone off after the setup. Please verify in Settings/Mail, Contacts, Calendar/YourAccount that Find my iPhone is toggled On after leaving the setup assistant.
  • There is a problem finding a device using Find My iPhone on the MobileMe website (www.me.com) when switching from iCloud back to MobileMe. To workaround this issue:
    • On the device go to Settings->Mail, Contacts, Calendar-><your_account>@me.com and Toggle Find My iPhone off and back on. Now the device should show up on MobileMe website.
  • It is recommended that you disable Bookmarks on multiple accounts. If they are enabled, the results might be undefined.
  • NEW: In this beta the option of “Choosing a security question” is not working during an iCloud account setup.

Air Play

  • Starting in iOS 5, video content in applications and websites are AirPlay-enabled by default.
  • iOS 5 supports AirPlay of video via AV Foundation.
  • FIXED: The Apple TV screen saver may degrade mirroring performance over AirPlay. The screen saver can be disabled in Apple TV settings.

Apple TV

  • Apple TV Software beta enables users to mirror the contents of an iPad 2 to an Apple TV (2nd generation) using AirPlay. This beta software also enables Photo Stream on Apple TV so users can access photos stored in iCloud. Apple TV Software beta is being provided to test the latest AirPlay functionality with your iOS 5 apps and web sites. If you wish to install Apple TV Software beta on your device, you must first register your device UDID in the iOS Developer Program Portal.

Audio

  • Using voice chat in iOS 5 requires setting the kAudioSessionMode_VoiceChat mode on the Audio Session, or setting the AVAudioSessionModeVoiceChat mode on the AVAudioSession object.

CalDav

  • FIXED: After creating a recurring event locally on the device, the device stops syncing after hitting an error on merge. Removing and re-adding the account acts as a workaround for this.

Calendar

  • All MobileMe calendars were duplicated after turning calendar syncing off and back on.
  • If you launch or manually refresh Calendars on an iPad, your calendars might disappear and you will have to tap “Show All Calendars” to display them again.
  • NEW: Restoring from a Seed 1 backup or earlier will cause MobileMe/iCloud calendars not to sync. Subscribed calendars will show up in Calendars but none of your event calendars will appear in MobileCal. To workaround the problem please remove and re-add the account.

Game Kit

  • Match data for turn based matches is currently limited to 4 KB of data.

Game Center

  • If you have an existing Game Center account which has not yet gone through the first-time Game Center flow in iOS 5, you will encounter a crash when signing into a game’s login alert directly. The workaround for this is to launch Game Center to complete the first-time flow.

i-Books

  • iBooks 1.2.2 may fail to display some text or images in books. Please update to iBooks 1.3 in the App Store.

i-Cloud Backup

  • As this is beta software, it is recommended that you do not use the iCloud services to store any critical data or information. If you enable iCloud Backup, automatic backup with iTunes when syncing will be disabled. We suggest you also manually back up your device with iTunes.
  • In the iOS 5 beta, support for data protection in iCloud Backup is unavailable. Apps that have protected files will not have any of their data or metadata backed up as a result.
  • After restoring, you may not be able to back up again because the device still thinks it’s restoring. To workaround this issue try syncing apps or media that are missing form iTunes or try deleting your iCloud account and adding it back.
  • If you delete your backup, the feature will be disabled but settings may still indicate that it is enabled and you will have to toggle the BackUp to Cloud switch in Settings.
  • For compatibility reasons, this version of the iOS 5 beta requires that all files be backed up again, instead of only those files that have changed since your last backup. This may cause a warning that your account is over quota. In case the warning occurs, you can delete your oldest backup to free up space and then initiate a backup.

i-Cloud Storage

  • During the iOS 5 beta period, any documents stored on the servers might be purged periodically before GM. Therefore, it is highly recommended that you do not store any critical documents or information on the servers.
  • If your application is using the NSMetadataQuery class, you must set a predicate, even though the predicate itself is ignored.
  • The Foundation framework doesn’t include the team ID when looking for an app’s mobile documents container. The Team ID must be included at the beginning of the identifier string passed to theURLForUbiquityContainerIdentifier: method.
  • In this beta, the setSortDescriptors: method of NSMetadataQuery is not supported.
  • In this beta, if you want to use iCloud, you have to manually specify various container identifiers (your application’s Display set) within an Entitlements file for both of your Mac OS X and iOS projects.
  • There are issues using the Cloud Storage document API in conjunction with protected data which can lead to data corruption.
  • In this beta, document-based applications cannot always detect when files change, move, or are deleted out from underneath them.
  • NEW: In this beta, file presenters (objects that adopt the NSFilePresenter protocol) do not receive some of the messages that they’re supposed to receive, especially:
    • presentedItemDidChange
    • presentedSubitemDidAppearAtURL:
    • presentedSubitemDidChangeAtURL:
    You can workaround this by implementing the relinquishPresentedItemToWriter: method and checking to see if the writer actually wrote when your file presenter reacquires. You can also use FSEvents to observe file system changes
  • In this beta, messages about changes to files in a directory are not getting delivered to objects that adopt the NSFilePresenter protocol.
  • While reporting a bug related to the iCloud storage interfaces, please include the logs collected during your debugging session. To generate these logs, you must install a special debug profile on your device.The debug profile can be obtained from http://connect.apple.com. This profile enables the generation of debug logs that are needed to diagnose any problems using iCloud storage. The instructions to collect the logs are:
    1. Install the profile. (The easiest way to do this is to mail it to yourself and open the attachment on their device.)
    2. Reproduce the bug.
    3. Sync with iTunes to pull the logs off your device.
    4. Attach the logs to your bug report. You can find the logs in ~/Library/Logs/CrashReporter/MobileDevice/DeviceName/DiagnosticLogs.
    These logs can grow large very quickly, so you should remove the profile after you have reproduced the problem and pulled the logs for the bug report.

i-Message

  • NEW: i-Message beta 3 will be unable to communicate with iMessage users on beta 1. It works between beta 3 and beta 2.
  • NEW: Modal alerts don’t appear for iMessages.

iTunes

  • The version of iTunes that comes with beta 3 cannot sync devices that have the beta 2 software installed. To avoid this problem, do the following:
    1. Sync any devices that have beta 2 installed to the version of iTunes that came with beta 2.
    2. Upgrade iTunes to the version that comes with beta 3.
    3. Connect the device and install the beta 3 software. (Understand that you might see a failure to sync error when you first connect the device.)
    4. After installing the beta 3 software, restore from your the backup you made in step 1.
  • Videos purchased from the iTunes Store do not play on a 2nd generation AppleTV over AirPlay with iTunes 10.5.

MMS

  • Sending an MMS of large videos does not work.

Photo Adjustments

  • If you apply red-eye adjustments in iOS, and import your image into the iPhoto seed build, the red-eye adjustments will not appear on that image in iPhoto. As a result, subsequent syncing of your image back to the iOS device from iPhoto will not show the red-eye adjustments.

Reminders

FIXED: The Reminders application does not send notifications for reminders that are based upon the entry (and/or exit) of a location if there is no date associated with the reminder.

Settings

  • The “Back Up Now” button is enabled without the backup data class being enabled for the account.
  • FIXED: If you bring up the keyboard of the terms in Settings->General->Software Update, you cannot dismiss it. You have to force quit Settings to get out.
  • NEW: In this beta FaceTime icon is missing in Settings on the iPhones.

Simulator

  • NEW: Location services are not functional in iOS 4.3 simulator running on Mac OS 10.7 with Xcode 4.2.

Springboard

  • Push and local notifications for apps appear in the new Notification Center in iOS 5. Notification Center displays notifications that are considered “unread”. In order to accommodate push and local notifications that have no “unread” status, developers can use their application badge count to trigger a clearing of notifications from Notification Center. When an application clears its badge count (by setting it to zero), iOS 5 will clear its notifications from Notification Center.

Twitter

  • NEW: When tweeting your location from Safari and exiting before the location can be established, the location arrow will stay in the status bar. The arrow can be removed by killing Safari from the task switcher.

UI Automation

  • NEW: In iOS 5 beta 3, the first execution of a script after a reboot or erase install will likely fail. Subsequent attempts should succeed until the device is rebooted again.
  • The play and record buttons in the Automation instrument script editor may not work properly after targeting an application that was launched by a trace session and has ended. They may also not work if you target an application that was suspended. If you run into this problem and it persists, you may need to close and reopen the trace document to get back into a functional state.
  • When capturing actions into a script using the Automation instrument, interfaces with web views or table cells that contain a high number of off screen elements may take an extremely long time before returning with an expression.
  • The lock() and unlock() functions of UIATarget have been replaced with the lockForDuration(<seconds>) function.
  • Instruments overwrites the loaded automation script, even if another program is editing it.
  • Starting iOS 5 beta 2, you can now trigger the execution of an UI Automation script on an iOS device from the host terminal by using the instruments tool. The command is:
    • instruments -w <device id> -t <template> <application>

UIKit

  • NEW: Starting in iOS 5 beta 3, the exclusiveTouch property of UIControl has returned to its original default value of NO.
  • Returning nil from the tableView:viewForHeaderInSection: method (or its footer equivalent) is no longer sufficient to hide a header. You must override tableView:heightForHeaderInSection: and return0.0 to hide a header.
  • In the iOS 5 beta, the UITableView class has two methods to move one cell from one row to another with defined parameters. These APIs are:
    • moveSection:toSection:
    • moveRowAtIndexPath:toIndexPath:
  • Using the UIWebView class in Interface Builder, setting transparent background color is possible in iOS 5. Developers compiling against the new SDK can check their XIB for the UIWebView transparent setting.
  • In the iOS 5 beta, the UINavigationBarUIToolbar, and UITabBar implementations have changed so that the drawRect: method is not called on instances of these classes unless it is implemented in a subclass. Apps that have re-implemented drawRect: in a category on any of these classes will find that the drawRect: method isn’t called. UIKit does link-checking to keep the method from being called in apps linked before iOS 5 but does not support this design on iOS 5 or later. Apps can either:
    • Use the customization API for bars that in iOS 5 and later, which is the preferred way.
    • Subclass UINavigationBar (or the other bar classes) and override drawRect: in the subclass.
  • The indexPathForRow:inSection:section, and row methods of NSIndexPath now use NSInteger instead of NSUInteger, so that these types match with methods defined on UITableView.
  • There is a known issue with presenting a UIVideoEditorControllerobject where it doesn’t show the selected video, which appears blank instead. In certain cases it may also crash.
  • Touch events are not getting forwarded to the view in the cameraOverlayView property of UIImagePickerController.
  • The imagePickerController:didFinishPickingMediaWithInfo: method of UIImagePickerController is not returning a URL to the video when recording is complete.
  • NEW: When creating a new appointment in calendar app on a device using 24 hr clock, you cannot select an hour value greater than 12. The date-time picker value sets current weekday to be the same as previous day (e.g: a An appointment on Tuesday will be set as Monday).
  • FIXED: We have changed the behavior of scrollToRowAtIndexPath:atScrollPosition:animated: such that UITableViewScrollPositionTop and UITableViewScrollPositionBottom now adjust for the top and bottom portions of the contentInset property.

WebKit

  • NEW: In iOS 5 beta 2, a new inherited CSS property, -webkit-overflow-scrolling: value, is available. The value touch allows the web developer to opt in to native-style scrolling in an overflow:scrollelement. The default value for this property is auto.
  • The WebKit framework has picked up a newer WebKit engine, which closely matches Safari 5.1. Some areas to be aware of with the new WebKit framework on iOS:
    • There is a new HTML5-compliant parser.
    • Text layout width may change slightly because word-rounding behavior now has floating-point-based precision.
    • There is improved validation of the <input type=number> form field, which includes removing leading zeros and number formatting.
    • Touch events are now supported on input fields.
    • window.onerror is now supported.
    • There is a new user agent that does not have locale information in the User Agent string.

WiFi Syncing

  • In iOS 5 beta 2, wireless syncing is available for the Mac. It requires iTunes 10.5 beta 2 and OS X 10.6.8 or Lion. You will see an option to enable wireless syncing when you connect your device to iTunes with the USB cable. It is recommended you perform your initial sync with a cable after restoring your device.
    • Wireless syncing is triggered automatically when the device is connected to power and on the same network as the paired computer. Or, you can manually trigger a sync from iTunes or from Settings -> General -> iTunes Sync (same network as paired computer required). Be sure your device is plugged into a power source when performing wireless syncs.
    • If you find issues with apps, media and/or photos synced to your device, you can reset then resync. From Settings -> General -> Reset, choose Erase all Content and Settings. Then reconnect to iTunes and sync again.
  • FIXED: In this beta, iTunes may incorrectly report Photos as “Other” in the capacity bar. Photo syncing otherwise works as expected.
  • NEW:In some cases, your device may fail to sync contacts, calendars and account settings, or back up to iTunes. If this happens, reboot your device and re-sync.
  • NEW:In some cases, syncing photos may result in only thumbnails on your device. If this happens, unsync Photos then re-sync again.

Xcode

  • In this beta, device restores using XCode are disabled. Please use iTunes only to back up and restore your device.
  • In some cases, Xcode 4.2 Organizer does not display a device that is in restore mode. As a workaround you can use iTunes to restore.
  • FIXED: On some desktop machines, Xcode’s memory usage inflates incredibly fast while restoring a device or copying an IPSW. As a workaround use iTunes to restore.
  • FIXED: In this beta, crash logs (either unsymbolicated or symbolicated) do not appear in Xcode Organizer. To make them appear in the Xcode Organizer, you will have to rename the device.
  • In iOS 5 beta 2, the iOS Simulator is not compatible with previous releases of the iCloud Developer Seed for OS X. It is highly recommended that you update to the latest iCloud Developer Seed to ensure compatibility.
iOS 5.0 SDK supports both iOS 4.3 and iOS 5.0 simulators.
 
-News Source (BGR)

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Apple Releases 3rd Developer Build of Mac OS X 10.6.8


Apple released the third build of Mac OS X 10.6.8 to developers, who can now download the 1GB file named 10K531. The areas that would be tested in this build are Airport, Mac App Store, Graphics Driver, QuickTime, Networking and VPN. Apple released developer builds of the Mac OS X every week, which started two weeks ago with the first build. The second build was deployed last week. This way the company can come up with a stable version faster than before.
There is no word yet whether the Mac OS X 10.6.8 will feature the fix that would seek and destroy the Mac Defender malware. Apple would most likely release the security patch as a standalone. The company did promise to release an update to the Mac OS X that will solve the issue with the fake antivirus software that would automatically download a phishing scam that would ask for users’ credit card. The Mac Defender first appeared early this month and most security experts downplayed it as just a simple phishing scam rather than a viral attack.
Apple is set to launch the Mac OS X 10.7 Lion this summer. It would contain various features and improvements that are drawn from Apple’s iOS mobile platform. 

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Flashback Trojan Infected Over 600,000 Mac-OS Users, Apple Pushes Out Fix Again

Flashback Trojan Infected Over 600,000 Mac-OS Users, Apple Pushes Out Fix Again 

Russian anti-virus vendor Dr. Web spotted a Trojan affecting nearly 600,000 Macs around the world. The near immune image of the Mac OS X has simply crumbled. So much for Macs being relatively safe against malware attacks. That idea took a punch to the stomach this week when the news broke about the Flashback trojan affecting more than half a million Macs worldwide. Flashback is essentially the malware equivalent of a smash-and-grab thief. Exploiting a Java vulnerability, the code installs and runs when the user visits a compromised or malicious website, intercepting private data, like passwords, and sending it back out over the internet. According to Doctor Web, sources claim that “links to more than four million compromised web-pages could be found on a Google SERP [search results] at the end of March. In addition, some posts on Apple user forums described cases of infection by [the latest variant] BackDoor.Flashback.39 when visiting dlink.com.” The trojan, Backdoor.Flashback.39, can infect computers via an infected web page. The vulnerability itself lies in Java, a product which is not Apple’s
About 57% of infected machines were in the US, 20% in Canada, 13% in UK and 6% in Australia. Apple has already issued patches that curb the vulnerability, but it does not necessarily mean that all users have applied the security patch on their Macs. Even Mozilla has block listed all the older and vulnerable Java plug-in from Firefox. Users are recommended to install the recent Apple Java update to close the hole which allows malicious web pages to drop the trojan onto a system and to always check which application is actually asking for your password when requested.

Update: To detect if a system is infected with Flashback, run each of the following commands in the Mac OS X Terminal:-
defaults read ~/.MacOSX/environment DYLD_INSERT_LIBRARIES
defaults read /Applications/Safari.app/Contents/Info LSEnvironment
defaults read /Applications/Firefox.app/Contents/Info LSEnvironment


If all these commands respond with "The domain/default pair of ... does not exist", then there is no Flashback infection. Otherwise consult the F-Secure advisory for manual removal instructions.

If you’re running Mac OS X v10.6.8, Mac OS X Server v10.6.8, OS X Lion v10.7.3 and Lion Server v10.7.3, be sure to hit up Software Update in your System Preferences.



SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Apple releases iTunes 10.3 with iCloud beta





Apple has released iTunes 10.3 (Download for Mac or Windows), which includes initial support for Apple's new iCloud features. Officially unveiled at the Apple Worldwide Developers Conference yesterday, iCloud is the company's upcoming replacement for MobileMe. While iCloud in its entirety will be available later this year, parts of it are being enabled sooner, including managing currently purchased items on multiple machines as well as previous purchases from the iTunes store.
The new release of iTunes comes with Automatic Download, a feature that ensures that all devices you have running iTunes are updated with music, apps, and books that you purchase, so an item purchased on one Mac will be downloaded on your other Macs running iTunes 10.3.
Ultimately users will have to wait for iTunes 10.5 and OS X 10.7 Lion to fully implement all iCloud features, but for now this will be a convenient introduction. iTunes 10.3 is available for download either at Apple's iTunes, through Software Update, or from the Apple Support Downloads pages (see below), and will be about 75MB in size depending on the version.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Apple Closes Security Hole & Released 5.1.4 of Safari Web-browser

Apple Closes Security Hole & Released 5.1.4 of Safari Web-browser 

Apple closes major security hole and released 5.1.4 of its Safari web browser for Windows and Mac OS X. According to Apple, the maintenance and security update addresses more than 80 vulnerabilities. The update also includes includes various stability and performance improvements as well as fixes for other non-security related bugs. With this release the company also promises an 11 percent boost in JavaScript performance, among other things. A majority of the security holes closed in 5.1.4 were found in the WebKit browser engine used by Safari. These include several cross-site scripting (XSS), cross-origin and HTTP authentication problems, as well as numerous memory corruption bugs that could be exploited by an attacker, for example, to cause unexpected application termination or arbitrary code execution. 
Important Changes:-
  • Improve JavaScript performance up to 11% over Safari 5.1.3* 
  • Improve responsiveness when typing into the search field after changing network configurations, or with an intermittent network connection 
  • Address an issue that could cause webpages to flash white when switching between Safari windows
  • Address issues that prevented printing U.S. Postal Service shipping labels and embedded PDFs 
  • Preserve links in PDFs saved from webpages 
  • Fix an issue that could make Flash content appear incomplete after using gesture zooming
  • Fix an issue that could cause the screen to dim while watching HTML5 video 
  • Improve stability, compatibility, and startup time when using extensions 
  • Allow cookies set during regular browsing to be available after using Private Browsing
  • Fix an issue that could cause some data to be left behind after pressing the “Remove All Website Data” button
For additional information you can prefer to visit Apple official site. TO Download Safari 5.1.4 Click Here. We also like to give you reminder that last moth Apple released the Mac OS X 10.8 Mountain Lion Developer Preview




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Apple Offering A Free DVD of Mac OSX Snow Leopard

Apple Offering A Free DVD of Mac OSX Snow Leopard

You haven’t upgraded to Lion or iCloud because you still haven’t forked out money for Snow Leopard yet?If the answer is yes then we have a great news for you and that is Apple is now giving away Snow Leopard to potential iCloud customers. 
In an article sent to MobileMe customers, Apple has recommended that potential customers get in touch with Apple to receive a free DVD of Snow Leopard so that users can upgrade to Lion and move to iCloud. All you have to do is follow this link, log in to MobileMe with your MobileMe account, and fill out your mailing information. Apple will then send you a Snow Leopard DVD for free. The free Snow Leopard offer was presumably initiated to encourage people to upgrade to iCloud before MobileMe is shut down on June 30th, 2012.




SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

'Dockster' A New Mac Malware Targeting Apple Users Found on Dalai Lama Related Website

'Dockster' A New Mac Malware Targeting Apple Users Found on Dalai Lama Related Website

Researcher at F-Secure blog has identified that A new piece of malicious software targeted at Apple users has been found on a website dedicated to the Dalai Lama. According to blog post by F-Secure -the website related to Dalai Lama is fully compromised and is pushing new Mac malware, called Dockster, using a Java-based exploit. Dockster tries to infect computers by exploiting a vulnerability in Java, CVE-2012-0507. The vulnerability is the same one used by the Flashback malware, which first appeared around September 2011 and infected as many as 600,000 computers via a drive-by download. Flashback was used to fraudulently click on advertisements in order to generate illicit revenue in a type of scam known as click fraud. Apple patched the vulnerability in Java in early April and then undertook a series of steps to remove the frequently targeted application from Macs. Apple stopped bundling Java in the 10.7 version of its Lion operation system, which continued with the company's Mountain Lion release. In October, Apple removed older Java browser plug-ins in a software update.
But still the matter of relief is that current versions of OS X are not vulnerable; users who have disabled the Java browser plug-in are also not vulnerable. F-Secure researcher Sean Sullivan said Dockster is “a basic backdoor with file download and keylogger capabilities.” Meanwhile F-Secure’s Sullivan, also said that the Dalai Lama’s site is also serving a Windows-based exploit for CVE-2012-4681, the Agent.AXMO Trojan. The Trojan exploits a Java vulnerability that allows remote code execution using a malicious applet that is capable of bypassing the Java SecurityManager. 

Please Note That: The gyalwarinpoche.com site doesn't seem to be as "official" as dalailama.com

While talking about Mac malware, then you must remember that earlier also Mac users faced such attacks when mac Trojan OSX.SabPub was spreading through Java exploits In 2011 we have also seen OSX/Revir-B trojan was installed behind a PDF, and giving hackers remote access to MAC computers, not only Revier-B also Linux Tsunami trojan Called "Kaiten"targeted Mac OS users in 2011. Also another malware named "Devil Robber" which was also make MAC users victim while stealing their personal information. In the very decent past we have seen a trojan named 'BackDoor.Wirenet.1'  apparently providing its masters with a backdoor into infected systems. It is also capable of stealing passwords stored in browsers like ChromeChromium,Firefox and Opera. For any kind of cyber updates and infose news, stay tuned with VOGH.





SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Apple releases iOS 5 beta 2, With Wireless Syncronization


Apple today released the second beta version of its iOS 5 mobile operating system to its iOS developer website, as well as the second beta of iTunes 10.5, which is needed to test one of iOS 5′s biggest new features: wireless syncing. And so far, the developer’s reviews give the new feature two big thumbs up. The build number of iOS 5 beta two is listed as 9A5248d. Apple has released a total of nine separate builds of the beta OS: three for iPad 2 (WiFi-only, GSM, CDMA), one for the original iPad, two for iPhone 4 (GSM, CDMA), one for iPhone 3GS and two for the iPod touch (third and fourth generation). No other devices will be able to run iOS 5 when its official release. (Sorry iPhone 3G users).
To use the new wireless syncing features, users must have the newest iOS 5, iTunes 10.5 beta 2, and a Mac running Mac OS X 10.6.8 or OS X Lion. Users must then connect their device to their Mac with a USB cable for the the very last time. This will allow them to choose the wireless sync option. Once that’s done, the USB can be stored safely away.
The iOS 5 beta 2 release also now allows any Apple ID to be used to create an iCloud account. (The beta 1 version required a MobileMe account.) A new version of iMessage is included in beta 2. And that version is not backward-compatible with the iMessage version in beta 1. Also, developers must take note that once the beta 2 version of iOS 5 is installed, they can only update to newer beta versions, and cannot revert back to the first beta version.

In addition to iOS 5 beta 2 and iTunes 10.5 beta 2, Apple also released a second beta version of AppleTV 2.0 software and a developer preview of XCode 4.2.

Apple will officially release iOS 5 to the public sometime this fall.

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

iPhone hacker Nicholas Allegra AKA Comex Hired By Apple


Apple just hired Nicholas Allegra, the world-famous hacker known as "Comex" who created JailbreakMe.com, the easiest way to "jailbreak" your iPhone.
Allegra posted on Twitter last night that he's starting an internship at Apple in two weeks.

Apple is no stranger to hiring members of the iPhone hacker community, but they seem to have hit the jackpot this time. Allegra is one of the most prolific and well known iPhone hackers.
JailbreakMe.com made the act of jailbreaking, which Apple hates, accessible to anyone who knows how to use the web browser on an iPhone. While Allegra has received mostly encouraging responses on Twitter, it's undoubtedly a huge blow to the iPhone hacking community at large. More than 175,000 people follow his Twitter account, which is more than many A-list celebrities can claim. In related news, in June Apple hired Peter Hajas, an iPhone hacker known for creating an elegant new notifications system for jailbroken iPhone.
If you can't beat em, hire em?

-News Source (Business Insider)

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Small Data Breach on Apple Site #Antisec Continues


We’ve heard a few reports in the past that Lulzsec hackers had broken into Apple. Now, however, the WSJ is reporting that the AntiSec hackers that have been joyriding around the internet using SQL injectors to steal username and password have hit Apple’s servers and taken user names and passwords.
The hackers said in a statement posted to Twitter that they had accessed Apple’s systems due to a security flaw used in software used by the Cupertino, Calif.-based gadget maker and other companies. “But don’t worry,” the hackers said, “we are busy elsewhere.” A spokesman for Apple didn’t immediately respond to a request for comment. The posted information comes as part of a two-month campaign of digital heists targeting corporations including Sony Corp. and AT&T Inc., as well as government agencies such as the U.S. Senate, the Central Intelligence Agency and the Arizona Department of Public Safety.
Specifically, they say  they’ve got the user name and passwords from this server:
While this looks to be a pretty harmless server with only local user names, previous postings have claimed a much bigger bounty. 
Click HERE to See the Statement on Pastebin 

SHARE OUR NEWS DIRECTLY ON SOCIAL NETWORKS:-

Related Posts Plugin for WordPress, Blogger...