Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Siris Lockscreen Bypass A Growing Privacy Issue For iOS Users
Newest First  |  Oldest First  |  Threaded View
Page 1 / 2   >   >>
kaysharbortechnology
50%
50%
kaysharbortechnology,
User Rank: Apprentice
8/31/2016 | 12:08:54 PM
Tushar Jain @ Kays Harbor Technologies
The write up has been framed properly about the security threat that IOS users are facing due to the Siri lockscreen Bypass. To know about the details of the threat, one must give a read.
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
11/25/2015 | 11:17:37 PM
Silly
There really does need to be a better balance here.  on the one hand, I don't want to have to unlock my device to use the voice assistant every time I want to make a phone call or do a basic search.  On the other hand, "What's my name?" or "What's my email address?" on a locked device should yield no information without first having to unlock it.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
11/25/2015 | 11:47:16 AM
Re: Voice Recognition or High Degree of Siri Granularity
If there were more options you could decide to not have any restrictions if you wanted...but for those who would choose to keep some information restricted that would be there as well. It's an option that would benefit both sides.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/24/2015 | 11:56:29 AM
Re: Apple is correct
Another thing I just wanted to point out, I am wondering when we will start feeling more comfortable about our PII. Most are already available in Google with our picture attached, I wonder what would Siri tell us that others not already knowing? :--))

 
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/24/2015 | 11:53:35 AM
Re: Voice Recognition or High Degree of Siri Granularity
 I agree mainly but I do not want Siri having restriction on information she could provide.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/24/2015 | 11:52:12 AM
Re: Voice Recognition or High Degree of Siri Granularity
Agree, at the same time voice recognition could easily be compromised. 
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/24/2015 | 11:50:50 AM
Re: Apple is correct
Agree, one other option would be a two factor authentication on Siri, so you have a key fob in your hand unless it is in closed proximity Siri on lock screen does not work.
Dr.T
50%
50%
Dr.T,
User Rank: Ninja
11/24/2015 | 11:47:57 AM
Disable Siri on Lock Screen
Why is this not a reasonable solution? If you want it accessed by lock screen that simply means it is exposed to outside world. Unless there is real voice recognition which always work there is no alternative and that is not even secure. If you want to put a chip in your body so Siri can recognize you that is possible, that is not what I want tough. :--))
slivingston
50%
50%
slivingston,
User Rank: Apprentice
11/23/2015 | 9:59:08 AM
Re: Apple is correct
That is exactly what I thought. It is just like in business, you have to evaluate the risk and provide security accordingly. You are not going to have the same security on a Yugo as you would a Bugati.
RyanSepe
50%
50%
RyanSepe,
User Rank: Ninja
11/19/2015 | 2:04:12 PM
Voice Recognition or High Degree of Siri Granularity
I think voice recognition software would be helpful not only to security but would most likely improve the functionality of Siri. But I think the cost behind that may be extensive. I think an easier option that may be more secure would be to add more granularity to Siri's Options in Settings. You could restrict what Siri has access to and by doing that you could ensure that certain data elements remain private. Currently the options for Siri are scarce.
Page 1 / 2   >   >>


COVID-19: Latest Security News & Commentary
Dark Reading Staff 8/10/2020
Pen Testers Who Got Arrested Doing Their Jobs Tell All
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/5/2020
Researcher Finds New Office Macro Attacks for MacOS
Curtis Franklin Jr., Senior Editor at Dark Reading,  8/7/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Changing Face of Threat Intelligence
The Changing Face of Threat Intelligence
This special report takes a look at how enterprises are using threat intelligence, as well as emerging best practices for integrating threat intel into security operations and incident response. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-17448
PUBLISHED: 2020-08-11
Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism, as demonstrated by use of the chat window with a filename that lacks an extension.
CVE-2020-17466
PUBLISHED: 2020-08-11
Turcom TRCwifiZone through 2020-08-10 allows authentication bypass by visiting manage/control.php and ignoring 302 Redirect responses.
CVE-2020-11552
PUBLISHED: 2020-08-11
An elevation of privilege vulnerability exists in ManageEngine ADSelfService Plus before build 6003 because it does not properly enforce user privileges associated with a Certificate dialog. This vulnerability could allow an unauthenticated attacker to escalate privileges on a Windows host. An attac...
CVE-2020-13124
PUBLISHED: 2020-08-11
SABnzbd 2.3.9 and 3.0.0Alpha2 has a command injection vulnerability in the web configuration interface that permits an authenticated user to execute arbitrary Python commands on the underlying operating system.
CVE-2020-15597
PUBLISHED: 2020-08-11
SOPlanning 1.46.01 allows persistent XSS via the Project Name, Statutes Comment, Places Comment, or Resources Comment field.