A new vulnerability reportedly exists in Apple’s Secure Enclave chip, described as unpatchable.
A new vulnerability reportedly exists in Apple’s Secure Enclave chip, described as unpatchable.
Apple has continuously improved device security with its Secure Enclave chip, safeguarding sensitive information. Recently, reports surfaced suggesting a lasting flaw within this chip, potentially exposing data from iPhones, iPads, and Macs.
It involves a breach needing direct contact with the device, isn't it? It's not unexpected that someone managed to get past it.
Even when someone has physical access, the method might still let them get the key if the device was turned off and a secure password was used instead of the default code. Current exploits can crack short passcodes, but strong passwords block them. This raises concerns because, for instance, if police seize a phone, such a scenario could become problematic.
Some security firm took advantage of that vulnerability for the US by working with a certain individual recently, after Apple confirmed it wouldn't compromise user privacy. I think this was an intentional back door rather than a design issue. A simple fix would be to avoid phone payments, disable iCloud connections, and keep personal details off the device. Most apps already have secure access, and hacking into a company's servers is much easier these days.
Apple Security no longer exists. Has Apple's protection weakened over the past few years?
Uncertain. This won't stop people from moving to contactless payments via their phones. Apple isn't just saving your card number; it's still safer than pulling out a physical card since it can be read by any NFC device. Someone trying to skim would need another device nearby. However, if you're engaging in fraud, you'd have to be extremely careless with your smartphone.
Yes, but not having NFC on your credit card works best for me. For NFC you need to be in close proximity for a short period to clone it. I don’t rely on any payment service provider, even with strong encryption. I keep a prepaid card handy just in case. The system is secure at home and can’t connect outside that environment. Simpler methods feel safer, but they come with risks.