An exploit in the way iOS handles multitasking may allow the touch-equivalent of keylogger-type attacks — where your input is recorded in order to discover your passwords and other data — to work not only on jailbroken iPhones and iPads, but on any device. It would require a malicious app to be created, to get past App Store review, and to get installed onto your device, which is a complex chain and not one anyone has claimed to have actually seen happen yet. But according to Min Zheng, Hui Xue, and Tao Wei of FireEye, it is possible:
We have created a proof-of-concept "monitoring" app on non-jailbroken iOS 7.0.x devices. This “monitoring” app can record all the user touch/press events in the background, including, touches on the screen, home button press, volume button press and TouchID press, and then this app can send all user events to any remote server, as shown in Fig.1. Potential attackers can use such information to reconstruct every character the victim inputs.
There's not a lot of information available yet about how exactly this works, but again, it seems like an attacker would have to make a malicious app, get it through App Store review and into the App Store, and then get you to go to the App Store and install it onto your device. For example, someone emailing you a link to a knock-off app — "Hey John, check out Flappy Bards, it's free and awesome!"
The researchers suggest uber-paranoid users turn off background refresh and kill all background apps to avoid any possibility of exploit. That's so onerous I doubt many will do it. What's probably better is to follow the same old "don't click on links from people or sources you don't trust" (even if they take you to the App Store) advice, and when browsing the App Store on your own, stick to apps from known developers until Apple patches the exploit.
Most importantly, the exploit seems complex right now and no one has presented any evidence of it existing in the wild. Unless and until that changes, I'd recommend the usual caution but no crazy level of concern. Agree or disagree?
Nick Arnott contributed to this article.
Apple's Black Friday iPhone SE sale essentially makes the price $290
The iPhone SE is already an incredible price, even without any discounts, but with Apple's Black Friday sale, you can get one for a song.
Which AirPods should you buy on Black Friday?
Thinking of buying AirPods for Black Friday but can't decide which ones you should get? I've got some advice that should help you decide.
These Nintendo Switch bundles are bound to go fast — Get them at $299 now!
The Nintendo Switch is finally back in stock for its regular retail price of $299. Do not miss your chance to get one right now. The Switch sells out fast and is rarely in stock. You won't regret it.
Your Mac holds your digital life, so make sure to back it up!
One of the most important things you should be doing with your Mac is backing up all of its data. Here are some of our favorite solutions for backing up your most important files, should anything ever happen.