{"id":61918,"date":"2017-01-25T09:32:21","date_gmt":"2017-01-25T17:32:21","guid":{"rendered":"https:\/\/www.intego.com\/mac-security-blog\/?p=61918"},"modified":"2024-03-21T06:07:26","modified_gmt":"2024-03-21T13:07:26","slug":"month-in-review-apple-security-in-january-2017","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/","title":{"rendered":"Month in Review: Apple Security in January 2017"},"content":{"rendered":"<p><img loading=\"lazy\" class=\"aligncenter size-full wp-image-61969\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/month-in-security-january-2017.png\" alt=\"Month in Review: Apple Security in January 2017\" width=\"600\" height=\"300\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/month-in-security-january-2017.png 600w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/month-in-security-january-2017-150x75.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/month-in-security-january-2017-300x150.png 300w\" sizes=\"(max-width: 600px) 100vw, 600px\" \/><\/p>\n<p>The year has only just begun, and there&#8217;s already plenty to talk about with regard to Apple user security and privacy!<\/p>\n<p>Here are some of the highlights from this past month&#8217;s security news relevant to users of Macs, iPhones, iPads, and other Apple products.<\/p>\n<h3>ClientCapture (Fruitfly, Quimitchin) Malware Discovered<br \/>\n<img loading=\"lazy\" class=\"alignright wp-image-61924 size-medium\" title=\"Fruit fly photo by Arian Suresh, https:\/\/web.archive.org\/web\/20170312115838\/https:\/\/www.flickr.com\/photos\/ansk\/26201092112\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/fruitfly-CC-BY-300x240.jpg\" width=\"150\" height=\"120\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/fruitfly-CC-BY-300x240.jpg 300w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/fruitfly-CC-BY-150x120.jpg 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/fruitfly-CC-BY-768x614.jpg 768w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/fruitfly-CC-BY.jpg 1024w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/fruitfly-CC-BY-657x525.jpg 657w\" sizes=\"(max-width: 150px) 100vw, 150px\" \/><\/h3>\n<p>Two weeks ago, Intego analyzed malware samples discovered by a university IT administrator, found after some strange network traffic had been observed on a Mac Pro. The malware (the components of which <a href=\"https:\/\/www.intego.com\/antivirus-mac-internet-security\">Intego VirusBarrier<\/a> detects as <strong>OSX\/ClientCapture<\/strong>, <strong>Perl\/ClientCapture<\/strong>, and <strong>Java\/ClientCapture<\/strong>) appears to have been part of a targeted attack, and may have existing on the university&#8217;s computer for years before being discovered and submitted to Intego and other companies for analysis.<\/p>\n<p>Apple calls\u00a0the threat &#8220;Fruitfly,&#8221; and it is also known\u00a0as\u00a0&#8220;Quimitchin.&#8221; See Intego&#8217;s writeup for further details: <a href=\"https:\/\/www.intego.com\/mac-security-blog\/targeted-malware-attacks-and-the-importance-of-layered-protection\/\" target=\"_blank\" rel=\"noopener\">Targeted Malware Attacks and the Importance of Layered Protection<\/a>.<\/p>\n<h3>&#8220;Meitu&#8221; Mobile App Has Privacy Risks<\/h3>\n<p><img loading=\"lazy\" class=\"alignright size-full wp-image-61921\" title=\"Meitu iOS app icon\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/Meitu-icon.png\" width=\"100\" height=\"100\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/Meitu-icon.png 175w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/Meitu-icon-150x150.png 150w\" sizes=\"(max-width: 100px) 100vw, 100px\" \/>It was reported last week that an\u00a0iOS and Android app called <strong>Meitu<\/strong>, which morphs selfies into anime characterizations, contains a number of privacy risks. The app, which was developed in China and has been in the App Store\u00a0for several years, has recently gained popularity.<\/p>\n<p>Security researcher\u00a0Jonathan Zdziarski took to Twitter to offer\u00a0his take on Meitu:<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\">\n<p lang=\"en\" dir=\"ltr\">Summary: Meitu is a throw-together of multiple analytics and marketing\/ad tracking packages, with something cute to get people to use it.<\/p>\n<p>&mdash; Jonathan Zdziarski (@JZdziarski) <a href=\"https:\/\/twitter.com\/JZdziarski\/status\/822154173219307520\">January 19, 2017<\/a><\/p><\/blockquote>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p><a href=\"https:\/\/www.wired.com\/2017\/01\/meitu-viral-anime-makeover-app-major-privacy-red-flags\" target=\"_blank\" rel=\"noopener\">Wired reported<\/a>\u00a0Zdziarski had identified &#8220;at least half a dozen&#8221; analytics and tracking packages within the app, and noted, &#8220;You don&#8217;t generally need that many unless you&#8217;re selling data.&#8221;<\/p>\n<p>Another security researcher, Will Strafach, published a brief\u00a0<a href=\"https:\/\/medium.com\/@chronic_9612\/technical-information-regarding-analytics-collection-in-the-meitu-app-for-ios-7f1a165aeee6\" target=\"_blank\" rel=\"noopener\">technical writeup<\/a>\u00a0of Meitu for iOS.<\/p>\n<p><img loading=\"lazy\" class=\"aligncenter wp-image-61927 size-full\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/Meitu-selfie.png\" width=\"300\" height=\"300\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/Meitu-selfie.png 390w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/Meitu-selfie-150x150.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/Meitu-selfie-300x300.png 300w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/p>\n<p style=\"text-align: center;\"><em>Is it really worth sacrificing your privacy for this?<\/em><\/p>\n<h3>Apple Security Updates<\/h3>\n<p>Apple has released <a href=\"https:\/\/support.apple.com\/en-us\/HT201222\" target=\"_blank\" rel=\"noopener\">security updates<\/a> for the following software this month:<\/p>\n<ul>\n<li><strong>macOS Sierra 10.12.3<\/strong>\u00a0(the latest version of &#8220;OS X&#8221;\u00a0for <a href=\"https:\/\/www.intego.com\/mac-security-blog\/what-to-do-if-your-mac-cant-run-macos-sierra\/\" target=\"_blank\" rel=\"noopener\">compatible Macs<\/a>) fixes vulnerabilities described in 11 CVE (Common Vulnerabilities and Exposures) IDs related to PHP, Bluetooth, Help Viewer, Vim, archive file handling, graphics and audio drivers, and the kernel (the operating system&#8217;s core)<\/li>\n<li><strong>Safari 10.0.3<\/strong> (available\u00a0for Macs running Sierra, El Capitan, or\u00a0Yosemite) fixes vulnerabilities described in 12 CVEs, 11 of which are related to the WebKit browser engine, and one of which is specific to Safari and prevents an issue where a malicious site could spoof Safari&#8217;s address bar<\/li>\n<li><strong>iOS 10.2.1<\/strong>\u00a0(for\u00a0iPhone, iPad, and iPod touch) fixes vulnerabilities described in 18 CVEs, including 12 related to the WebKit browser engine, two related to the kernel, and one each related to archive file handling, Contacts (preventing a maliciously crafted contact card from causing application termination), Wi-Fi (preventing an activation-locked device from being manipulated to briefly present the home screen), and Auto Unlock (preventing a device from becoming unlocked while an Apple Watch is off of a user&#8217;s wrist)<\/li>\n<li><strong>watchOS 3.1.3<\/strong>\u00a0(for Apple Watch) fixes vulnerabilities described in 33 CVEs, including nine related to the kernel, two related to font file parsing, two related to audio file processing, two related to WebKit, two related to archive file handling, and a variety of others, the most severe of which could allow a local user to gain root privileges (full administrative rights) on an\u00a0Apple Watch<\/li>\n<li><strong>tvOS 10.1.1<\/strong>\u00a0(for Apple TV) fixes vulnerabilities described in 12 CVEs, including nine related to WebKit, two related to the kernel, and one related to archive file processing<\/li>\n<li><strong>iTunes for Windows 2.5.5<\/strong> and <strong>iCloud for Windows 6.1.1<\/strong> fix vulnerabilities related to WebKit browser engine, described in four CVEs (all of which are fixed for Macs via the Safari 10.0.3 update)<\/li>\n<li>Earlier this month, <strong>GarageBand 10.1.5<\/strong> and <strong>Logic Pro X 10.3<\/strong>\u00a0were released, both of fix a vulnerability described in a single CVE; these\u00a0updates prevent maliciously crafted files from causing arbitrary code execution (i.e. doing bad stuff to your Mac)<\/li>\n<li>Apple also released <strong>Security Update 2016-003 Supplemental (10.11.6)<\/strong>\u00a0for El Capitan users, an update to a December patch, fixing a kernel issue that could cause the OS to become unresponsive (Apple did not identify any additional vulnerabilities patched by this supplemental update)<\/li>\n<\/ul>\n<p>Intego has written more about this week&#8217;s\u00a0updates here: <a href=\"https:\/\/www.intego.com\/mac-security-blog\/apple-releases-macos-sierra-10-12-3-and-more-with-security-fixes\/\" target=\"_blank\" rel=\"noopener\">Apple Releases macOS Sierra 10.12.3 and More with Security Fixes<\/a>.<\/p>\n<p>The bottom line: be sure to\u00a0check for and install updates on all of your Apple devices!<\/p>\n<h3>Scam Site Launched DoS Against Unpatched Macs<\/h3>\n<p>In early January, a scam site (which is no longer online) launched a denial-of-service attack (DoS) against Macs running Safari on older versions of macOS. The site would cause Mail to create a plethora of e-mail drafts with a subject line containing the words, &#8220;Warning! Virus Detected!&#8221; and eventually causing the Mac to crash. Users running the latest versions of macOS and Safari were not affected by this e-mail draft denial-of-service attack; instead, the scam site\u00a0caused a single fake virus warning to appear in the Mac&#8217;s iTunes app. On iOS, the scam site would pop up a single e-mail draft at a time, but would continue presenting a new draft each time the draft window was closed. See Intego&#8217;s writeup for further details: <a href=\"https:\/\/www.intego.com\/mac-security-blog\/denial-of-service-attack-targets-mac-and-ios-users\/\" target=\"_blank\" rel=\"noopener\">Denial of Service Attack Targets Mac and iOS Users<\/a>.<\/p>\n<p>An important lesson here is that it&#8217;s critical to keep your Apple software updated to make it less susceptible to attacks\u2014including, but not limited to, attacks by malicious sites.<\/p>\n<h3>Apple CareKit to Incorporate &#8220;ZeroKit&#8221; Security<\/h3>\n<p><img loading=\"lazy\" class=\"alignright size-thumbnail wp-image-61930\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/CareKit-logo-150x150.png\" alt=\"CareKit logo\" width=\"100\" height=\"100\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/CareKit-logo-150x150.png 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/CareKit-logo.png 200w\" sizes=\"(max-width: 100px) 100vw, 100px\" \/><a href=\"http:\/\/mashable.com\/2017\/01\/11\/apple-zerokit-security-carekit\/\" target=\"_blank\" rel=\"noopener\">Mashable reported<\/a> that Apple&#8217;s open-source CareKit platform will soon incorporate technology called ZeroKit, developed by security firm Tresorit. According to the report, ZeroKit &#8220;will offer user authentication for patients and healthcare workers, end-to-end encryption of health data, and &#8216;zero knowledge&#8217; sharing of health data,&#8221; meaning that data will not be accessible to any other party during transit. The goal of ZeroKit is to make it easier for developers of healthcare apps to provide better security for end users.<\/p>\n<h3>Stay Tuned! Subscribe to The Mac Security Blog<\/h3>\n<p>That&#8217;s it for this month&#8217;s security roundup! Be sure to subscribe to <strong>The Mac Security Blog<\/strong> to stay informed about Apple security.<\/p>\n<p>You may also be\u00a0interested in Intego&#8217;s recent in-depth coverage\u00a0highlighting the\u00a0top Apple security news of 2016:<\/p>\n<blockquote class=\"wp-embedded-content\" data-secret=\"VnCrFSbLWk\"><p><a href=\"https:\/\/www.intego.com\/mac-security-blog\/the-year-in-mac-security-2016\/\">The Year in Mac Security 2016<\/a><\/p><\/blockquote>\n<p><iframe class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; clip: rect(1px, 1px, 1px, 1px);\" title=\"&#8220;The Year in Mac Security 2016&#8221; &#8212; The Mac Security Blog\" src=\"https:\/\/www.intego.com\/mac-security-blog\/the-year-in-mac-security-2016\/embed\/#?secret=VnCrFSbLWk\" data-secret=\"VnCrFSbLWk\" width=\"500\" height=\"282\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe><\/p>\n<p><span style=\"font-size: x-small;\">Image credits: <a href=\"https:\/\/web.archive.org\/web\/20170312115838\/https:\/\/www.flickr.com\/photos\/ansk\/26201092112\" target=\"_blank\" rel=\"noopener\">Fruitfly image by arian.suresh<\/a> (<a href=\"https:\/\/creativecommons.org\/licenses\/by\/2.0\/\" target=\"_blank\" rel=\"noopener\">CC BY 2.0<\/a>)<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The year has only just begun, and there&#8217;s already plenty to talk about with regard to Apple user security and privacy! Here are some of the highlights from this past month&#8217;s security news relevant to users of Macs, iPhones, iPads, and other Apple products. ClientCapture (Fruitfly, Quimitchin) Malware Discovered Two weeks ago, Intego analyzed malware [&hellip;]<\/p>\n","protected":false},"author":14,"featured_media":61981,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false},"categories":[13,5],"tags":[3226,3247,3250],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v17.4 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<meta name=\"description\" content=\"The year has only just begun, and there&#039;s already plenty to talk about with regard to Apple user security and privacy! Here are some of the highlights\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Month in Review: Apple Security in January 2017 - The Mac Security Blog\" \/>\n<meta property=\"og:description\" content=\"The year has only just begun, and there&#039;s already plenty to talk about with regard to Apple user security and privacy! Here are some of the highlights\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/\" \/>\n<meta property=\"og:site_name\" content=\"The Mac Security Blog\" \/>\n<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/JoshLong\" \/>\n<meta property=\"article:published_time\" content=\"2017-01-25T17:32:21+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-03-21T13:07:26+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/Apple-Security-Month-in-Review-Jan-2017.png\" \/>\n\t<meta property=\"og:image:width\" content=\"400\" \/>\n\t<meta property=\"og:image:height\" content=\"260\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@theJoshMeister\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Joshua Long\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\",\"name\":\"Intego\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png\",\"width\":875,\"height\":875,\"caption\":\"Intego\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/Apple-Security-Month-in-Review-Jan-2017.png\",\"contentUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/Apple-Security-Month-in-Review-Jan-2017.png\",\"width\":400,\"height\":260,\"caption\":\"Apple Security Month in Review Jan 2017\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/#webpage\",\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/\",\"name\":\"Month in Review: Apple Security in January 2017 - The Mac Security Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/#primaryimage\"},\"datePublished\":\"2017-01-25T17:32:21+00:00\",\"dateModified\":\"2024-03-21T13:07:26+00:00\",\"description\":\"The year has only just begun, and there's already plenty to talk about with regard to Apple user security and privacy! Here are some of the highlights\",\"breadcrumb\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.intego.com\/mac-security-blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Month in Review: Apple Security in January 2017\"}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/dcf592275ba6edde8d20f1e60029c6b1\"},\"headline\":\"Month in Review: Apple Security in January 2017\",\"datePublished\":\"2017-01-25T17:32:21+00:00\",\"dateModified\":\"2024-03-21T13:07:26+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/#webpage\"},\"wordCount\":1005,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/Apple-Security-Month-in-Review-Jan-2017.png\",\"keywords\":[\"ClientCapture\",\"Meitu\",\"Month in Security\"],\"articleSection\":[\"Security &amp; Privacy\",\"Security News\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/#respond\"]}]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/dcf592275ba6edde8d20f1e60029c6b1\",\"name\":\"Joshua Long\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.intego.com\/mac-security-blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=96&d=mm&r=g\",\"caption\":\"Joshua Long\"},\"description\":\"Joshua Long (@theJoshMeister), formerly Intego\\u2019s Chief Security Analyst, is a renowned security researcher and writer, and an award-winning public speaker. Josh has a master\\u2019s degree in IT concentrating in Internet Security and has taken doctorate-level coursework in Information Security. Apple has publicly acknowledged Josh for discovering an Apple\\u00a0ID authentication vulnerability. Josh has conducted cybersecurity research for well over 25 years, which is often featured by major news outlets worldwide. Keep up with Josh via X\/Twitter, LinkedIn, Facebook, Instagram, YouTube, Patreon, Mastodon, the JoshMeister on Security, and more. \\u2014\",\"sameAs\":[\"https:\/\/security.thejoshmeister.com\",\"https:\/\/www.facebook.com\/JoshLong\",\"https:\/\/www.instagram.com\/thejoshmeister\/\",\"https:\/\/www.linkedin.com\/in\/thejoshmeister\",\"https:\/\/www.pinterest.com\/thejoshmeister\/\",\"https:\/\/twitter.com\/theJoshMeister\",\"https:\/\/www.youtube.com\/@theJoshMeister\"],\"url\":\"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"description":"The year has only just begun, and there's already plenty to talk about with regard to Apple user security and privacy! Here are some of the highlights","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/","og_locale":"en_US","og_type":"article","og_title":"Month in Review: Apple Security in January 2017 - The Mac Security Blog","og_description":"The year has only just begun, and there's already plenty to talk about with regard to Apple user security and privacy! Here are some of the highlights","og_url":"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/","og_site_name":"The Mac Security Blog","article_author":"https:\/\/www.facebook.com\/JoshLong","article_published_time":"2017-01-25T17:32:21+00:00","article_modified_time":"2024-03-21T13:07:26+00:00","og_image":[{"width":400,"height":260,"url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/Apple-Security-Month-in-Review-Jan-2017.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_creator":"@theJoshMeister","twitter_misc":{"Written by":"Joshua Long","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"Intego","url":"https:\/\/www.intego.com\/mac-security-blog\/","sameAs":[],"logo":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2022\/10\/intego-organization-logo-for-google-knowledge-graph-875x875-1.png","width":875,"height":875,"caption":"Intego"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#logo"}},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intego.com\/mac-security-blog\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/#primaryimage","inLanguage":"en-US","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/Apple-Security-Month-in-Review-Jan-2017.png","contentUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/Apple-Security-Month-in-Review-Jan-2017.png","width":400,"height":260,"caption":"Apple Security Month in Review Jan 2017"},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/","name":"Month in Review: Apple Security in January 2017 - The Mac Security Blog","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/#primaryimage"},"datePublished":"2017-01-25T17:32:21+00:00","dateModified":"2024-03-21T13:07:26+00:00","description":"The year has only just begun, and there's already plenty to talk about with regard to Apple user security and privacy! Here are some of the highlights","breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog\/"},{"@type":"ListItem","position":2,"name":"Month in Review: Apple Security in January 2017"}]},{"@type":"Article","@id":"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/#article","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/#webpage"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/dcf592275ba6edde8d20f1e60029c6b1"},"headline":"Month in Review: Apple Security in January 2017","datePublished":"2017-01-25T17:32:21+00:00","dateModified":"2024-03-21T13:07:26+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/#webpage"},"wordCount":1005,"commentCount":0,"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/#primaryimage"},"thumbnailUrl":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/Apple-Security-Month-in-Review-Jan-2017.png","keywords":["ClientCapture","Meitu","Month in Security"],"articleSection":["Security &amp; Privacy","Security News"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intego.com\/mac-security-blog\/month-in-review-apple-security-in-january-2017\/#respond"]}]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/#\/schema\/person\/dcf592275ba6edde8d20f1e60029c6b1","name":"Joshua Long","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/#personlogo","inLanguage":"en-US","url":"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/5ad29f4111ce14911abaa98cbbcdea42?s=96&d=mm&r=g","caption":"Joshua Long"},"description":"Joshua Long (@theJoshMeister), formerly Intego\u2019s Chief Security Analyst, is a renowned security researcher and writer, and an award-winning public speaker. Josh has a master\u2019s degree in IT concentrating in Internet Security and has taken doctorate-level coursework in Information Security. Apple has publicly acknowledged Josh for discovering an Apple\u00a0ID authentication vulnerability. Josh has conducted cybersecurity research for well over 25 years, which is often featured by major news outlets worldwide. Keep up with Josh via X\/Twitter, LinkedIn, Facebook, Instagram, YouTube, Patreon, Mastodon, the JoshMeister on Security, and more. \u2014","sameAs":["https:\/\/security.thejoshmeister.com","https:\/\/www.facebook.com\/JoshLong","https:\/\/www.instagram.com\/thejoshmeister\/","https:\/\/www.linkedin.com\/in\/thejoshmeister","https:\/\/www.pinterest.com\/thejoshmeister\/","https:\/\/twitter.com\/theJoshMeister","https:\/\/www.youtube.com\/@theJoshMeister"],"url":"https:\/\/www.intego.com\/mac-security-blog\/author\/joshlong\/"}]}},"jetpack_featured_media_url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2017\/01\/Apple-Security-Month-in-Review-Jan-2017.png","jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4VAYd-g6G","amp_enabled":true,"_links":{"self":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/61918"}],"collection":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/14"}],"replies":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=61918"}],"version-history":[{"count":23,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/61918\/revisions"}],"predecessor-version":[{"id":100026,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/61918\/revisions\/100026"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/61981"}],"wp:attachment":[{"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=61918"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=61918"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/origin.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=61918"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}