Cisco Learning Network Store Promotions Page
Showing posts with label Safari. Show all posts
Showing posts with label Safari. Show all posts

1.27.2016

Apple's Safari browser crashing for some users worldwide: The Verge

A man tests a mobile phone, an iPhone 6 by Apple in a shop in Munich, Germany, January 27, 2016.
REUTERS/MICHAELA REHLE
Apple Inc's Safari search browser is crashing for some users when they run a search from the address bar in both iOS and OS X devices, the Verge reported.

The problem appears to be affecting iOS and OS X devices worldwide, the Verge reported on Wednesday.

Apple's iPhones and iPads run on iOS, while its Mac computers operate on OS X.

The problem, which is related to Safari's search suggestions feature, can be rectified temporarily by disabling the feature or using the private mode option in the browser, the Verge reported, citing an iOS developer Steven Troughton-Smith. (bit.ly/1SiXArK)

Apple was not immediately available for comment.

Apple forecast its first revenue drop in 13 years and reported the slowest-ever increase in iPhone shipments on Tuesday.

~ Lehar Maan

9.09.2015

Apple to live stream September 9 event: How you can watch

For the first time in a while, Windows 10 users can also watch the live event.

Apple's almost ready to reveal what it's been working on for the past year.
 
At the event on September 9, Apple will lift the lid on its new smartphone at the Bill Graham Civic Auditorium in San Francisco.
 
Almost everything has leaked so far. Don't expect that many surprises here. We've got a good primer of what's most likely to arrive. It's also possible that other hardware and software bits will also be announced at the event.
 
As usual, the company will stream the event live, featuring Apple chief executive Tim Cook and other senior executives.
 
Apple will offer the video stream of the keynote at 10 am PT (1 pm in New York; 6 pm in London).
 
If you are around to watch the hour-long keynote, viewers must watch the stream online with Safari 6.0.5 or later on OS X 10.8.5 or later, or Safari on iOS 7 or later. If you're watching through Apple TV, it requires the second- or third-generation set-top box with software 6.2 or later.
 
And, for the first time in a long time, Windows users can watch live as well if they're running the Edge browser on Windows 10.
 
As always, if you're at work or away from the screens, you can keep up to date with ZDNet throughout the morning and the afternoon, wherever you are.
 
 

5.29.2015

Adware makers turn their sights on OS X

 
Hot on the heels of news that OS X topped the vulnerabilities charts in April comes Dr. Web's virus activity review for May which shows increasing quantities of adware and unwanted applications targeting the Apple operating system.
 
The company reports several programs aimed at OS X that either install adware, install other applications or inject JavaScript code into webpages.
 
Adware.Mac.InstallCore.1 cannot only install unwanted programs on the user's computer but also change the browser home page and the search engine used by default. The program incorporates debugging functions too -- once launched, it scans the system for the presence of virtual machines, anti-virus tools, and some other applications. If the scan returns positive results, the malware will not prompt the user to install additional programs.
 
There's similar functionality in Mac.Trojan.Crossrider which is distributed in the guise of an installation package (Safari Helper). Crossrider trojans may be familiar to Windows users but this variant specifically targets Apple systems. Running it triggers a stealthy installation of the FlashMall extension for Safari, Chrome, and Firefox. It also adds two applications to the system startup list: "WebSocketServerApp" and "Safari Security". The first is responsible for communication with the command and control server and the second one installs browser extensions. In addition the malware modifies the startup scripts for the browser extensions to be updated in the future.
 
Apple users may like to know they're not the only ones that are coming under attack. Linux.Kluh.1, developed by a Chinese hacker group, infects routers with the purpose of launching DDoS attacks. Linux.Iframe.4 is a malicious plug-in for the Apache web server that injects code into web pages browsed by users redirecting the victim to the web page run by cybercriminals.
 
Trojans continue to be the big threat to Windows systems with an overall increase of 14.9 percent in the amount of malware and riskware detected in May. Android users aren't safe either with an increase in numbers of banking and SMS trojans as well as the emergence of new ransomware.
 
There's been a big increase in malicious websites too with 221,346 URLs being added to Dr. Web's database in May. Many of these use social engineering techniques like sending bulk SMS messages informing the recipient that they have won a car. The message contains a link to a wesbite which tries to get visitors to part with their financial details.
 
More information on these and other threats is available on the Dr. Web site.
 
Photo Credit: Stephen Finn/Shutterstock
 
~ Ian Barker

3.21.2015

Fully patched versions of Firefox, Chrome, IE 11 and Safari exploited at Pwn2Own hacking competition

 
As in years past, the latest patched versions of the most popular web browsers around stood little chance against those competing in the annual Pwn2Own hacking competition. The usual suspects – Apple Safari, Google Chrome, Mozilla Firefox and Microsoft Internet Explorer – all went down during the two-day competition, earning researchers a collective total of $557,500 in prize money.
 
The event, which took place at the CanSecWest conference in Vancouver, was sponsored by the Hewlett-Packard Zero Day Initiative. During the first day, HP awarded $317,500 to researchers that exploited flaws in Adobe Flash, Adobe Reader, Internet Explorer and Firefox.
 
eWeek notes that the first reward, paid to a hacker by the name of ilxu1a, was for an out-of-bounds memory vulnerability in Firefox. It took less than a second to execute which earned him a cool $15,000.
 
Firefox was exploited twice during the event. Daniel Veditz, principal security engineer at Mozilla, said the foundation was on hand during the event to get the bug details from HP. Engineers are already working on a fix back at home, he added, that could be ready as early as today.
 
Another security researcher, JungHoon Lee, managed to demonstrate exploits against Chrome, IE 11 and Safari. As you can imagine, he walked away with quite a bit of money: $75,000 for the Chrome bug, $65,000 for IE and $50,000 for the Safari vulnerability. He also received two bonuses totaling $35,000.
 
 

~ Shawn Knight

3.04.2015

Apple plans fix next week for newly uncovered Freak security bug

The Apple logo is pictured on the front of a retail store in the Marina neighborhood in San Francisco, California April 23, 2014.  

Credit: Reuters/Robert Galbraith
 
(Reuters) - An Apple Inc (AAPL.O) spokesman said on Tuesday that the company plans to release a fix next week to mitigate the newly uncovered 'Freak' security flaw affecting Safari browsers on its iOS and OS X operating systems for mobile devices and Macs.
 
The vulnerability in web encryption technology could enable attackers to spy on communications of users with vulnerable software, including Apple's Safari browser and Google Inc's (GOOGL.O) Android browser, according to researchers who uncovered the flaw.
 
A representative for Google said he had no immediate comment. 
 
The Washington Post reported that the bug left users of Apple and Google devices vulnerable to cyberattack when visiting hundreds of thousands of websites, including Whitehouse.gov, NSA.gov and FBI.gov. http: 
 
Whitehouse.gov and FBI.gov have been fixed, but NSA.gov remains vulnerable, the paper cited Johns Hopkins cryptographer Matthew D. Green as saying. 
 
A group of nine researchers discovered that they could force web browsers to use an form of encryption that was intentionally weakened to comply with U.S. government regulations that ban American companies from exporting the strongest encryption standards, according to the paper. 
 

Once they caused the site to use the weaker encryption standard, they were then able to break the encryption within a few hours. That could allow hackers to steal data and potentially launch attacks on the sites themselves by taking over elements on a page, the newspaper reported.
 
The group of researchers dubbed the flaw Freak, for "Factoring RSA-EXPORT Keys," according to a website where they described the vulnerability.
  

~ Jim Finkle

10.21.2014

Apple seeks to allay concerns over Yosemite Spotlight data collection

Summary: Apple is ruffling features by collecting search and location data from OS X Yosemite users through Spotlight features that some argue should be off by default.
 
 
Apple's quest to be known as a company that makes products with built-in privacy hit another snag on Monday amid concern over query and location data it's collecting through Spotlight in iOS 8 and OS X Yosemite.
 
Spotlight for OS X Yosemite, as reported in the Washington Post on Monday, contains a little surprise for users, with the search tool now sending queries and location data to Apple. And thanks to a deal between Microsoft and Apple to display Bing results in Spotlight, it's also sending some data to Microsoft.
 
The feature update has annoyed some users, including developer Landon Fuller, who posted details at fix-macosx.com on how to restore privacy in OS X, chiefly by disabling several Spotlight settings in not just Spotlight but Apple's Safari browser too.
 
While Apple does outline Spotlight's new features in its documentation, Fuller doesn't like that the potentially invasive features are on by default — which he considers a break from past versions of OS X.
 
Apple explains in its "about" section for Spotlight that search queries and any Spotlight suggestions it offers are sent to Apple, while search results are not. Apple will also collect a user's location when users make a search and location data is on.
 
In response to the kerfuffle over the privacy implications of the feature, it's also published a separate support note explaining how to deactivate the features.
 
Apple issued a statement to iMore outlining that it doesn't retain the IP addresses of users' devices and "blurs" the location of the device so that Apple doesn't see the exact location. Also, the device identifier it does collect changes every 15 minutes, preventing it or third-parties from creating a profile based on search history. It also clarified that Apple only forwards commonly searched terms and city-level location information to Bing, while Microsoft doesn't store search queries or receive a user's IP address.
 
The company explains as much in its page about built-in privacy, pointing out that before Spotlight provides suggestions, it "considers things like context and location while protecting your privacy by using an anonymous identifier that refreshes every 15 minutes. You can always opt out of Suggestions and continue to use Spotlight solely for local search on your device."
 
Apple has attempted to distinguish itself from rivals, in particular Google, by claiming its business doesn't rely much on the collection of user data for advertising. It's also stepped up that messaging in response to concerns its products have backdoors and that it works with government agencies — a concern that held up the iPhone 6 and 6 Plus launch in China as regulators there extracted promises from Apple that its device was not a security and privacy risk. The third major privacy issue it's faced in recent months, of course, is Celebgate.
 
~ Liam Tung

6.27.2014

New privacy enhancements coming to iOS 8 in the fall

Summary: iOS 8 adds a number of new user controls that keeps your private information (like contacts and location) out of the hands of increasingly data-hungry apps. 
 
Apple rolled out lots of privacy settings in iOS 7 in 2013, and now it's adding even more granular controls to iOS 8 in order to keep your personal information private.
 
Although it doesn't ship to the masses until this fall (likely in September or October), Apple distributed copies of iOS 8 to developers at WWDC earlier this month and began educating them on what to expect in the new OS. At WWDC14 Apple detailed significant changes that it's making in iOS 8 to protect your data and privacy.
 
Apple's WWDC session 715 ("User Privacy on iOS and OS X") details some of the most important privacy changes that are coming to iOS 8 in the fall. Apple posted the complete video from the session (scroll down to "User Privacy") and the corresponding 109-page slide deck (PDF) for anyone to download.
 
Here are some important new privacy enhancements that are coming to iOS 8 in the fall:

App Privacy Settings

Possibly the most important new privacy setting in iOS 8 is the ability to see and modify an app's individual privacy settings on an app-by-app basis.
 
iOS 7 app privacy settings are controlled in Settings > Privacy sorted by the access it requires. For example, you need to touch Settings > Privacy > Contacts to see a list of the apps that have access to your contacts and Settings > Privacy > Microphone to see apps that have access to your microphone, etc.
 
(Image: ZDNet)
In iOS 8 Apple's consolidating all of an app's Privacy settings in one location: Settings > AppName. This means that if you want to see how much access a certain app has to your data, you'll be able to touch Settings > AppName > Privacy, instead of having to burrow through Settings > Privacy > Location, Contacts, Calendar, Reminders, Photos and so on. As a nice touch, Apple's still keeping the iOS 7 behavior too, so you can easily audit all of the apps with access to your Contacts, Location or Microphone in the old location.

App Notification Settings


Just like the new app privacy settings above, iOS 8 now includes an app's Notification settings in the same panel as the new Privacy settings in Settings > AppName. This give users a second – and more convenient – way to mute a pesky app's notifications. In iOS 7 you have to drill down through Settings > Notification Center > AppName to make changes to an offending app's Notifications settings.

Limiting Access to Location

In iOS 7 it was easy to grant an app access to your location on a permanent location. While this makes sense for apps like Maps, Weather and Camera (if you want to geo-tag your photos, for example), does Evernote really need to know your location all the time? Probably not. Changes to the the iOS 8 Location Services APIs give users even more control over how apps use their location. For example, apps that have permanent access to your location will occasionally re-prompt you for access to location in iOS 8, with a dialog that looks like this:

(Image: ZDNet)
This "location shaming" is a huge privacy win for consumers that blindly grant access to everything an overbearing app asks for upon first launch – referred to as the permission "conga line." Location shaming will force developers to reconsider whether they really need full-time access to a user's location because a user that's startled by an app the dialog above is more likely to click on "Don't Allow" and even uninstall the offending app.

(Image: Jason O'Grady)
But wait, there's more. In addition to location shaming, iOS 8 will also notify a user that an app is using their location in the background with a new, brightly colored, double-height status bar – similar to the one's used for phone calles, navigation, and the Voice Memos apps in iOS 7 (above) – to notify a user that an app's using their location in the background. The new double-height status bar is a welcome addition to iOS 8 that will garner more attention than the "purple triangle" did in iOS 7.
 
In iOS 7 you can audit which apps have access to your location in Settings > Privacy > Location Services. And you're familiar with the behavior of the purple arrow, right?

Safari Cookies

iOS 8 includes a new Safari third-party cookie policy includes an option to block all third-party cookies on the Safari browser, 'regardless of whether the user has visited the site previously." in iOS 7, the options in Settings > Safari > Block Cookies are:
  • Always
  • From third-parties and advertisers (My recommendation)
  • Never
(Image: ZDNet)
In iOS 8 Apple has changed the choices to:
  • Always
  • Not from current website (My recommendation)
  • Not from previously visited
  • Never
Takeaway: iOS 8 will allow users to block cookies from everywhere except the "current website." It's not enabled by default, but when checked it results in a net increase in cookie privacy for the end user because "third-parties and advertisers" is not specific enough. Questionable developers could mis-identify their cookies to get around the iOS 7 setting. If an iOS 8 user selects "Not from current website" all cookies not from that domain will be automatically blocked.

People Picker

(dev settings) The new "People Picker" in iOS 8 allows app developers to request access to only a selected contact instead of having to request access to access to your entire Contacts list. This new option only gives the app a temporary (or "static") copy of a contact rather than full-time access to all contacts, including changes, in perpetuity.
 
I hate it when iOS apps request access to my Contacts (ostensibly to "let me know when my friends join the service" or some similar garbage) because this usually means that the developer copies my entire contact list to its server, at will, where it's stored indefinitely. Once your contacts are on someone else's server, they're vulnerable to abuse (internally) and to hacking (externally). I almost always deny Contacts access and encourage you to do the same. Let's all encourage developers to only request access to Contacts using the People Picker on an as-needed basis.
 
An example of how this could be used is AnyList, an excellent list sharing app that I use often. When I installed it, I granted the app Contacts access so that I could share a grocery list with my wife. I checked Settings > Privacy > Contacts and sure enough, AnyList had full-time and permanent access to my contacts when all it need was access to one contact at one time. I hope that AnyList adopts Apple's new People Picker in iOS 8 out of respect for its customer's privacy.
 
In addition to the five major privacy changes in iOS 8 listed above, Apple's also increasing privacy options in the following areas:
  • Send Location To Apple When Battery Reaches Low Level
  • DuckDuckGo Search
  • Auto-Delete Messages
  • Home data settings
Stay tuned for more.
 
~ Jason D. O'Grady

3.09.2014

Best Web Browser (Part 3)

Safari 5.1.7

Apple abandoned it, and so should you
 
The last time Apple updated its Safari browser for Windows desktops was in May 2012, and that was just a minor housekeeping patch. Apple left Windows users behind when it introduced Safari 6 for Mac OS X 10.8 Mountain Lion, and while the Cupertino outfit hasn’t explicitly stated Safari will never make a return to Microsoft’s OS, there’s little reason to believe it will. Safari was never able to carve out a significant share of the browser market anyhow, though both NetMarketShare and StatCounter agree that there are more web surfers on Safari than Opera, so leaving Windows users behind might not have been the best long-term decision.

What’s New

Though Apple has turned a blind eye to Windows users, the latest version of Safari is still available to download. Prior to abandonment, Safari’s Reading List feature alone was reason to consider the browser. What it does is let you save web pages you don’t have time to read and return to them later, online or offline. Think of it as a temporary bookmarks feature that self-destructs once you’ve brought up a saved page.
 
Safari Reader is another element of the browser we liked. It strips web pages to the bare essentials, removing most ads and preventing pop-ups.

Security

Safari’s biggest security feature is running web processes in a restricted environment, otherwise known as sandboxing. Pretty snazzy, except that it only runs that way on Mac OS, so it’s a feature that’s of absolutely no benefit to Windows users—boo! On the plus side, it’s rather easy to disable JavaScript, pop-up windows, and plugins from the Security tab in Preferences. Safari will also warn users when visiting a website it deems fraudulent.

Privacy

Safari blocks third-party cookies by default, a feature that’s found in the browser’s Privacy panel. It also contains an option to remove all website data with a couple of mouse clicks. In the same panel is an option to limit website access to location services. Some websites use information about your location to enable certain features and services, but if you’d rather keep that information private, you can disable it altogether or be prompted when a website requests your whereabouts.

Performance

In the majority of benchmarks, Safari came in dead last, especially when testing for JavaScript performance. The dated browser supports limited hardware acceleration in Windows, but it wouldn’t even run two of the three Microsoft test demos.
Click the Reader button in the address bar to de-clutter noisy websites and side-step pop-up ads.

Internet Explorer 11

An old browser reborn and bred for Windows 8
 
It wouldn’t make sense for Microsoft to rebuild Windows without also revamping the parts that integrate with it, and so what we have in Internet Explorer 11 is a vastly different browser compared to previous releases. Yes, it will probably be available for Windows 7 by the time you read this, but it’s really intended to complement the vision Microsoft set out for Windows 8, which includes a heavy dose of touch interaction and interoperability across a range of Windows devices and screen sizes.
 
While the version we’re testing is a Preview release, it’s very close to what the final build will be like, unlike an early beta, which could be missing key features and/or suffer from stability issues.

What’s New

When firing it up from the Start screen, IE11 looks and feels like a brand-new browser rather than an upgrade of an existing one. That’s not really surprising since the same could be said of Windows 8 compared to previous versions. The first thing you’ll notice is that Microsoft moved the address bar to the bottom of the browser. It hides out of view to give you a full-screen browsing experience, though you can bring it back up with a right-click or swipe up from the bottom. If you have a touchscreen, you’ll also use swiping gestures to navigate forward and backward.
 
Outside of touch controls, the feature we’re most excited about is side-by-side browsing. While Windows 8 insists on running applications in full-screen mode, the side-by-side feature in IE11 allows you to view multiple websites at the same time, and you can resize the width of each one. This is handy for comparison shopping, among other uses.
 
We’re only scratching the surface here. Microsoft lifted the limit of open tabs from 10 to 100 per window, which appear as scrollable tiles just above the address bar. Non-active tabs are suspended so they don’t drag down your PC’s performance or adversely affect battery life. Microsoft also implemented hardware-accelerated 3D web graphics through WebGL, plug-in-free HTML5 video support, and the ability to pin websites as live tiles on the Start screen—phew!

Security

By default, IE11 turns on Enhanced Protected Mode (EPM), which only allows compatible add-ons like toolbars, browser helper objects (BHOs), and extensions to load. Furthermore, EPM shoves untrusted web content into a restricted environment sort of like a sandbox.
 
Instead of letting WebGL content run wild, it’s put through a pre-screening stage in IE11. It also runs on top of DirectX, so if malicious content bombards the GPU and takes it out, it will reset rather than crash the entire system.

Privacy

Microsoft was the first browser maker to turn on its Do Not Track feature by default, and that setting is retained in IE11. New to IE11, however, is a User-Granted Exceptions option so that users can grant permission to websites to use cookies that request it.
 
InPrivate browsing mode is still available in IE11, though it’s not obvious when surfing from the Start screen. You can use the keyboard shortcut (Ctrl+Shift+P) or bring up the Tabs menu and press the Tab tools button on the right-hand side.

Performance

IE11 posted the best SunSpider score in this roundup, which measures JavaScript performance. It was also the fastest in Microsoft’s 3D demos, especially Lawn Mark 2013, a benchmark Microsoft claims “uses emerging HTML5 techniques.” We’re a bit skeptical of the discrepancy in scores, as are Chrome developers, one of which stated in a Chromium forum that the benchmark is “running intentionally slow JavaScript in all browsers besides IE.” Still, it shows that IE11 is able to render 3D graphics at a fast clip, and surfing the web certainly feels fast as well.

Power-User Tips

1. To add a website as a live tile, click the Star icon (Favorites) and then the Pin icon.
 
2. You can pin the address bar permanently to the bottom of the screen by bringing up the Charms menu (swipe or press Windows Key+C) and selecting Settings > Options. Under the Appearance heading, flip the dial to On.
 
3. Sites not showing up correctly? Fire up IE11 in Desktop and press Alt. Select Tools > Compatibility View settings.
 
1) Side-by-side allows you to view multiple pages in separate, resizable Windows.
 
2) It’s not the least bit obvious, but those three dots designate the Tab tools option. Click or tap to initiate an InPrivate browsing session.
 
3) You’re no longer limited to just 10 open tabs. In IE11, you can have as many as 100 per window. Equally cool is the preview view of each one, which you can scroll through.
 
4) Microsoft relocated the address bar to the bottom of the browser where it’s better optimized for touch. Just swipe up from the bottom (or right-click your mouse) to make it appear.
 
 
~ Paul Lilly