Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Siris Lockscreen Bypass A Growing Privacy Issue For iOS Users
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
kaysharbortechnology
kaysharbortechnology,
User Rank: Apprentice
8/31/2016 | 12:08:54 PM
Tushar Jain @ Kays Harbor Technologies
The write up has been framed properly about the security threat that IOS users are facing due to the Siri lockscreen Bypass. To know about the details of the threat, one must give a read.
Joe Stanganelli
Joe Stanganelli,
User Rank: Ninja
11/25/2015 | 11:17:37 PM
Silly
There really does need to be a better balance here.  on the one hand, I don't want to have to unlock my device to use the voice assistant every time I want to make a phone call or do a basic search.  On the other hand, "What's my name?" or "What's my email address?" on a locked device should yield no information without first having to unlock it.
RyanSepe
RyanSepe,
User Rank: Ninja
11/25/2015 | 11:47:16 AM
Re: Voice Recognition or High Degree of Siri Granularity
If there were more options you could decide to not have any restrictions if you wanted...but for those who would choose to keep some information restricted that would be there as well. It's an option that would benefit both sides.
Dr.T
Dr.T,
User Rank: Ninja
11/24/2015 | 11:56:29 AM
Re: Apple is correct
Another thing I just wanted to point out, I am wondering when we will start feeling more comfortable about our PII. Most are already available in Google with our picture attached, I wonder what would Siri tell us that others not already knowing? :--))

 
Dr.T
Dr.T,
User Rank: Ninja
11/24/2015 | 11:53:35 AM
Re: Voice Recognition or High Degree of Siri Granularity
 I agree mainly but I do not want Siri having restriction on information she could provide.
Dr.T
Dr.T,
User Rank: Ninja
11/24/2015 | 11:52:12 AM
Re: Voice Recognition or High Degree of Siri Granularity
Agree, at the same time voice recognition could easily be compromised. 
Dr.T
Dr.T,
User Rank: Ninja
11/24/2015 | 11:50:50 AM
Re: Apple is correct
Agree, one other option would be a two factor authentication on Siri, so you have a key fob in your hand unless it is in closed proximity Siri on lock screen does not work.
Dr.T
Dr.T,
User Rank: Ninja
11/24/2015 | 11:47:57 AM
Disable Siri on Lock Screen
Why is this not a reasonable solution? If you want it accessed by lock screen that simply means it is exposed to outside world. Unless there is real voice recognition which always work there is no alternative and that is not even secure. If you want to put a chip in your body so Siri can recognize you that is possible, that is not what I want tough. :--))
slivingston
slivingston,
User Rank: Apprentice
11/23/2015 | 9:59:08 AM
Re: Apple is correct
That is exactly what I thought. It is just like in business, you have to evaluate the risk and provide security accordingly. You are not going to have the same security on a Yugo as you would a Bugati.
RyanSepe
RyanSepe,
User Rank: Ninja
11/19/2015 | 2:04:12 PM
Voice Recognition or High Degree of Siri Granularity
I think voice recognition software would be helpful not only to security but would most likely improve the functionality of Siri. But I think the cost behind that may be extensive. I think an easier option that may be more secure would be to add more granularity to Siri's Options in Settings. You could restrict what Siri has access to and by doing that you could ensure that certain data elements remain private. Currently the options for Siri are scarce.
Page 1 / 2   >   >>


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Machine Learning, AI & Deep Learning Improve Cybersecurity
Machine intelligence is influencing all aspects of cybersecurity. Organizations are implementing AI-based security to analyze event data using ML models that identify attack patterns and increase automation. Before security teams can take advantage of AI and ML tools, they need to know what is possible. This report covers: -How to assess the vendor's AI/ML claims -Defining success criteria for AI/ML implementations -Challenges when implementing AI
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2022-41828
PUBLISHED: 2022-09-29
In Amazon AWS Redshift JDBC Driver (aka amazon-redshift-jdbc-driver or redshift-jdbc42) before 2.1.0.8, the Object Factory does not check the class type when instantiating an object from a class name.
CVE-2022-3364
PUBLISHED: 2022-09-29
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3.
CVE-2022-39232
PUBLISHED: 2022-09-29
Discourse is an open source discussion platform. Starting with version 2.9.0.beta5 and prior to version 2.9.0.beta10, an incomplete quote can generate a JavaScript error which will crash the current page in the browser in some cases. Version 2.9.0.beta10 added a fix and tests to ensure incomplete qu...
CVE-2022-40472
PUBLISHED: 2022-09-29
ZKTeco Xiamen Information Technology ZKBio Time 8.0.7 Build: 20220721.14829 was discovered to contain a CSV injection vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the Content text field of the Add New Message module.
CVE-2022-36068
PUBLISHED: 2022-09-29
Discourse is an open source discussion platform. In versions prior to 2.8.9 on the `stable` branch and prior to 2.9.0.beta10 on the `beta` and `tests-passed` branches, a moderator can create new and edit existing themes by using the API when they should not be able to do so. The problem is patched i...