Secret Meeting Reveals How to Break Apple

Secret Meeting Reveals How to Break Apple's Security

Jamboree, a large celebration or party, typically very lavish and boisterous, is the name given to the secret annual meeting of security researchers who have been working with the CIA. These researchers gather to share their tactics and strategies for exploiting security flaws in household and commercial-grade electronics. And, The Intercept just happened to obtain some top-secret documents in which they report that one of the goals of the meeting was to determine how to break the security of Apple’s iPhones and iPads.

So, what exactly were these researchers getting boisterous about while I assume sipping on 100-year-old wine and snacking on gourmet hors d'oeuvres?

During their research, essential security keys stored on Apple devices, used to encrypt data, were targeted by the use of physical and non-invasive techniques to discover ways to decrypt the Apple-stored data and penetrate Apple’s encrypted firmware. Malicious code could then be planted onto the Apple devices and used to search for other encryption-masked vulnerabilities.

These researchers also claimed that they had modified a version of Xcode, Apple’s proprietary software development tool and the OS X updater, the program used to deliver updates to devices. With the researcher’s version of Xcode, surveillance backdoors could sneak into any apps or programs, enticing and enabling spies to steal passwords and other data. With the modified OS X updater, a keylogger could be installed.

Funding for this near-decade worth of research is said to have come out of the pockets of the CIA; however, the CIA as well as Apple declined to comment.

About the Author

Ginger Hill is Group Social Media Manager.

Featured

  • AI to Help Resolve Non-Emergency Calls Across Utah and Decrease 911 Caller Wait Times

    The Utah Communications Authority (UCA), which oversees the state’s next generation 911 technology services, recently announced that public safety answering points (PSAPs) throughout the state plan to implement Motorola Solutions’ Virtual Response technology to automate the receipt and resolution of 10-digit non-emergency line calls in Utah with the help of AI. Read Now

  • Report Reveals Local Governments Face Surge in Ransomware Attacks with Minimal Resources

    KnowBe4, the cybersecurity platform that comprehensively addresses human risk management, recently released new research highlighting the critical cybersecurity challenges facing state, local, tribal, and territorial (SLTT) governments. The report details how government organizations have become prime targets for cybercriminals while simultaneously facing severe resource constraints. Read Now

  • Video Surveillance Trends to Watch

    With more organizations adding newer capabilities to their surveillance systems, it’s always important to remember the “basics” of system configuration and deployment, as well as the topline benefits of continually emerging technologies like AI and the cloud. Read Now

  • New Report Reveals Top Trends Transforming Access Controller Technology

    Mercury Security, a provider in access control hardware and open platform solutions, has published its Trends in Access Controllers Report, based on a survey of over 450 security professionals across North America and Europe. The findings highlight the controller’s vital role in a physical access control system (PACS), where the device not only enforces access policies but also connects with readers to verify user credentials—ranging from ID badges to biometrics and mobile identities. With 72% of respondents identifying the controller as a critical or important factor in PACS design, the report underscores how the choice of controller platform has become a strategic decision for today’s security leaders. Read Now

  • Overwhelming Majority of CISOs Anticipate Surge in Cyber Attacks Over the Next Three Years

    An overwhelming 98% of chief information security officers (CISOs) expect a surge in cyber attacks over the next three years as organizations face an increasingly complex and artificial intelligence (AI)-driven digital threat landscape. This is according to new research conducted among 300 CISOs, chief information officers (CIOs), and senior IT professionals by CSC1, the leading provider of enterprise-class domain and domain name system (DNS) security. Read Now

New Products

  • Unified VMS

    AxxonSoft introduces version 2.0 of the Axxon One VMS. The new release features integrations with various physical security systems, making Axxon One a unified VMS. Other enhancements include new AI video analytics and intelligent search functions, hardened cybersecurity, usability and performance improvements, and expanded cloud capabilities

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction.