Apple’s legal woes mount as vulnerability threatening crypto security comes to light

Apple’s legal woes mount as vulnerability threatening crypto security comes to light
ôîòî ïîêàçàíî ñ : cryptoslate.com

2024-3-24 22:41

Academic researchers have unearthed a significant vulnerability within Apple’s M-series computing chips, potentially jeopardizing the security of private crypto keys.

On the same day, the US Department of Justice (DOJ) filed an antitrust case against the iPhone maker, alleging monopoly practices detrimental to consumers, developers, and competitors.

The vulnerability

The research team identified the chips’ data memory-dependent prefetcher (DMP) vulnerability.

Crypto analyst George explained that DMP is a hardware optimization that anticipates and preloads data into the CPU cache ahead of demand. However, it faces an issue where it occasionally confuses sensitive data, such as encryption keys, for memory addresses.

This phenomenon, known as “dereferencing pointers,” creates a vulnerability known as “side-channel attacks.”

The researchers demonstrated the capability to extract various encryption keys — including RSA, Diffie-Hellman, Kyber, and Dilithium — within 1 to 10 hours using a GoFetch attack. However, this exploit needs malicious and targeted crypto apps to operate on the same CPU cluster.

For the attack to succeed, the malicious app must provide inputs to the crypto app and prompt it to execute operations, thereby gradually leaking the key. This exploit is interactive rather than passive and must bypass macOS security measures to perform on the system.

Unfortunately, rectifying this flaw is not straightforward as it originates from the microarchitectural design of the chips, rendering it unpatchable. However, implementing defensive measures within third-party encryption software can mitigate the risk.

Legal trouble

US authorities, supported by 16 state attorney generals, filed legal actions against Apple for its “walled garden” business model, which helped establish an allegedly illegal monopoly in the smartphone market.

The lawsuit alleged that Apple implemented “shapeshifting rules and restrictions in its App Store guidelines and developer agreements that would allow Apple to extract higher fees, thwart innovation, offer a less secure or degraded user experience, and throttle competitive alternatives.”

They added that these suppressive rules were implemented across varying products, including text messaging, smartwatches, and digital wallets, among many others.

Crypto community members have highlighted the importance of this lawsuit to the industry, with Hish Bouabdallah, the founder of Tribes Protocol, saying:

“If Apple loses this battle, it could pave the way for crypto payments in the U.S., enabling seamless transactions using services like Coinbase Wallet with just a double tap and FaceID.”

The post Apple’s legal woes mount as vulnerability threatening crypto security comes to light appeared first on CryptoSlate.

origin »

Bitcoin price in Telegram @btc_price_every_hour

SherLOCK Security (LOCK) íà Currencies.ru

$ 0 (+0.00%)
Îáúåì 24H $0
Èçìåíåèÿ 24h: 6.06 %, 7d: -9.29 %
Cåãîäíÿ L: $0 - H: $0
Êàïèòàëèçàöèÿ $0 Rank 99999
Öåíà â ÷àñ íîâîñòè $ 0.1387 (-100%)

security apple crypto vulnerability filed case doj

security apple → Ðåçóëüòàòîâ: 74


Brave Partners With iOS Firewall Developer, Guardian For Privacy-Enhanced Internet Browsing

Brave Software partners with iOS VPN creator Guardian Firewall + VPN, to integrate their technology to build the safest, fastest, and most private web browser on Apple devices. The privacy-focused firms aim at providing maximum security for your data and unwavering control over your data while using the “Brave Firewall + VPN, powered by Guardian”. […]

2020-7-27 20:41


Ôîòî:

New iPhone Update Shows TikTok, Others Could Be Snooping on Bitcoin Addresses

Popular iOS apps like TikTok might be snooping on sensitive user information such as Bitcoin addresses and bank passwords, security publication ArsTechnica reported earlier this week. Snooping on Bitcoin Addresses Reports from this week confirm last week’s release of Apple’s iOS 14 developer beta for iPhone alerts users when mobile apps “read” data from one’sRead MoreRead More.

2020-7-1 22:07


Ôîòî:

Apple steps in to automatically remove Zoom’s risky software from Macs

Apple has pushed a silent update to Mac users to remove the web server sneakily installed by popular video conference app Zoom, TechCrunch reports. Earlier this week, a disclosure by security researcher Jonathan Leitschuh revealed how Zoom installed a secret local web server on Mac devices — with an intent to save an extra click — but left users vulnerable by making it possible for an attacker to hijack their webcams.

2019-7-11 08:41


Important security lessons learned from Apple’s creepy FaceTime bug

Earlier this month, I woke up to a disastrous security bug in Apple’s FaceTime that could let anyone easily eavesdrop on iOS and macOS devices. In case you haven’t heard about it yet, FaceTime, the audio and video conferencing app that comes preinstalled on all iPhones, iPads, and Mac computers, had a major security flaw that could let a caller hear the audio from the device they were calling before the person on the other end accepted or rejected the call.

2019-2-13 15:16


Newly launched Bitcoin/XRP/Ethereum/Litecoin/Bitcoin Cash-trading exchange already has serious security vulnerabilities

DX.Exchange, a crypto-based asset trading platform has lately been making positive noise in the news cycle due to its January 7th launch. The exchange has been marketed as the platform that will bridge the gap between cryptocurrencies and real-world stocks, as investors can purchase tokenized versions of Apple, Facebook and Apple stocks, as well as […] The post Newly launched Bitcoin/XRP/Ethereum/Litecoin/Bitcoin Cash-trading exchange already has serious security vulnerabilities appeared first on CaptainAltcoin.

2019-1-11 08:21


Ôîòî:

Apple confirms its T2 chip will block some third-party repairs

Apple yesterday confirmed that its new security chip T2 – which it uses in MacBooks launched this year – will prevent third-party repairs to some degree. Responding to a query from The Verge, the company verified that parts like the logic board and Touch ID components for the new Macbooks can’t be replaced by a third-party repair shop – and so you’ll have to visit an authorized Apple service center to get your laptops fixed.

2018-11-13 09:39


Ôîòî:

The free internet makes us the product — we need to stop it

The bad headlines continue to stack up for Facebook this year: from the Cambridge Analytica scandal, to the New York Times report that Facebook gave Apple, Samsung, and other mobile device makers access to its users personal data without permission, to the revelation that the firm routinely gives user information and preferences to several Chinese telecommunications firms, to last week’s security breach in which hackers took control of 50 million user accounts as well as any third-party sites those users logged into via Facebook.

2018-10-6 19:30


Ôîòî:

Yenom drives Bitcoin funds forms book room completed in Apple’s iOS-language Swift

Technology & Security This week the developers of the Bitcoin Cash-centric mobile wallet called Yenom have introduced a new Bitcoin Cash Kit (BCK) for BCH developers. Also Read: The Bitcoin Cash Network Processed 687,000 Transactions on August 1st Yenom Developers Launch Bitcoin Cash Kit Bitcoin Cash protocol development has been on fire lately as there’s a

2018-8-3 11:23


Report: Apple’s iPhone 6 has the highest failure rate among iPhones — but Samsung is worse

A recent study of the past five years’ worth of iPhone releases saw that the iPhone 6 was, hands down, the worst Apple handset release in recent memory. Both the iPhone 6 and 6s models (regular and Plus) topped the chart of least reliable Apple handsets, according to the “State of Mobile Device Repair & Security“ report issues by Blancco, a data erasure and security firm.

2018-7-14 01:59