I'm surprised to see protection against state sponsored attacks implemented by a company as big as Apple. Is any other 'mainstream' company offering a similar feature? Warrant canary [0] comes to mind, but that is usually a message to all users, as opposed to notifying an individual user. [0]: https://en.wikipedia.org/wiki/Warrant_canary
Gmail does it https://blog.google/threat-analysis-group/updates-about-gove...
Apple will notify users about state-sponsored cybersecurity threats
21–30 of 166 posts
Re: Apple will notify users about state-sponsored cybersecurity threats
#22Source: https://mobile.twitter.com/e_wrzosek/status/1463551631648251...
Re: Apple will notify users about state-sponsored cybersecurity threats
#23I see a lot of pessimism in the comments. But I think this is a great step in the right direction. Other companies should take note. More of this, please!
I received an imminent advanced security threat notification back in January 2019. Urging me to get one of those 2fa dongles (which I did). And just as well, because the next month my account was locked due to an attempted unathorized access.
(whoever works on this at Google, thank you)
Re: Apple will notify users about state-sponsored cybersecurity threats
#24Re: Apple will notify users about state-sponsored cybersecurity threats
#25Re: Apple will notify users about state-sponsored cybersecurity threats
#26I see a lot of pessimism in the comments. But I think this is a great step in the right direction. Other companies should take note. More of this, please!
(I agree that it's great that Apple is finally doing this. But it seems entirely par for the course for them to be a decade late and still get the credit.)
Re: Apple will notify users about state-sponsored cybersecurity threats
#27"If Apple discovers activity consistent with a state-sponsored attack" I am really interested in understanding more about a "state-sponsored attack" as someone who works in Ops and has experience in CyberSec. All these years working in the industry and I had no idea you could identify an "attack" that easily.
> Unlike traditional cybercriminals, state-sponsored attackers apply exceptional resources to target a very small number of specific individuals and their devices, which makes these attacks much harder to detect and prevent.
> State-sponsored attackers are very well-funded and sophisticated, and their attacks evolve over time. Detecting such attacks relies on threat intelligence signals that are often imperfect and incomplete. It’s possible that some Apple threat notifications may be false alarms, or that some attacks are not detected.
Identifying the source of these attacks is often done by analyzing the tools and techniques, in comparison to other known tools and methods, and/or by information gathered in meat space.
Re: Apple will notify users about state-sponsored cybersecurity threats
#28Re: Apple will notify users about state-sponsored cybersecurity threats
#29Earlier quoted context omitted.
https://www.apple.com/legal/transparency/us.html Contains the canary: “To date, Apple has not received any orders for bulk data.”
that appears to only be connected to requests under those specific acts. Otherwise, given their involvement in the PRISM program [1] I don't see how we can take that canary seriously. [1] https://en.wikipedia.org/wiki/PRISM_(surveillance_program)
Re: Apple will notify users about state-sponsored cybersecurity threats
#30I see a lot of pessimism in the comments. But I think this is a great step in the right direction. Other companies should take note. More of this, please!