Showing posts with label iPad. Show all posts
Showing posts with label iPad. Show all posts

Monday, February 15, 2016

Browser MetaData Leakage

I read this recent post by Dr. Neal Krawetz with some wonder and amazement.

He followed that one up with another related post, Just Browsing. See also his Invasion of Privacy post for browser fingerprinting and some perspective on “private/incognito” browsing session tracking.

The identification that (in some cases) your cellphone carrier could be adding extra headers to your smart-device information requests is not shocking in this day and age. But that it could contain (leak) your personally identifiable cell phone number was quite a surprise!

From Dr. Krawetz’s post:

Consumer Cellular has agreements to use T-Mobile and AT&T networks. If my cellphone uses the T-Mobile network, then no extra headers are added to my HTTP requests. However, if my phone uses AT&T's network, then AT&T appends a lot of personal information to every HTTP request:

  • X-Att-Imsi: This is my International Mobile Subscribed Identity and is unique to my phone.
  • X-Att-Plmn-Id: This contains my MCC+MNC code; that's the mobile country code (MCC) and mobile network code (MNC). These values identify the country and carrier. For example, MCC 310 is the United States, and MNC 410 in the United States is Cingular Wireless (now AT&T).
  • X-Up-Calling-Line-Id: This contains my cellphone number. Seriously: AT&T sends my direct cellphone number to every website my phone visits. Looking over my web server logs, I see other people who have been through this same path. Thanks to AT&T, I have direct phone numbers for people in Portland, Oregon and Cincinnati, Ohio and Roanoke, Virginia and... I'm actually surprised that my cellphone hasn't received more telemarketer calls.
  • X-Up-Subno: This very-disturbing field includes a timestamp that shows when (down to the second) I signed up with Consumer Cellular.

That got me looking for more information and I didn’t find much.

This circa 2012 post goes into some additional details:

It points to a test web page maintained by the interviewed researcher Collin Mulliner that can show some of your browser headers:

Running several tests with my cellular devices (with Wi-Fi disabled to force the data cross AT&T’s network) came back “clean” of any PII meta data; at least as far as this particular test was able to detect.

More information on the project and issue details here: HTTP Header Privacy info page

It was noted by the post author that the issue was with “medium-price-ranged” phones that needed a Web proxy to reformat Web content. And that iPhones and Androids do not do this.

I do plan to hit this Choices and Controls | AT&T Privacy Policy site with my devices as well to then “opt-out” of several of their analytics services listed there.

Finally, Martin Brinkmann at ghacks.net has an astounding roundup of links related to online privacy checkers.

That one is a keeper in your bookmarks.

Constant Vigilance!

--Claus Valca

Saturday, February 13, 2016

Miscellaneous Apple bites

Looks like I am literally picking low-hanging fruit from my “to-blog” tree branches.

I previously reported this on my the struggles GSD post but am reposting here for topic inclusion.

The takeaway was to quit Process Explorer. I’ve seen a few other software installations where I have needed to close out Process Explorer entirely to make sure it doesn’t get in the way of some installations. Weird.

Of course, iTunes wanted to be updated, so I used the Apple Software Updater but it complained about the “iPod Service” not being able to start so the install kept failing. I then tried to download and run the iTunes package rather than using the updater but that failed at the same point.
I found this post Service ‘iPod Service’ (iPod Service) could not be installed... over in the Apple Support forums and followed “rickybpta” steps.

  • close SysInternals's Process Explorer ( if you have it and it's open )
  • close all Task Manager(s)
  • close Windows Services console ( services.msc )
  • close all command prompts ( cmd.exe )
  • open a cmd.exe as Admin
    • run: sc create "iPod Service" binpath= "C:\Program Files\iPod\bin\iPodService.exe"
    • close all command prompts ( cmd.exe )
  • open Windows Services console ( services.msc )
    • look for "iPod Service", see if it's not Disabled. If so, start it
    • close Windows Services console ( services.msc )
  • Run iTunes.msi again ( previously downloaded via the Apple Software Update's Only Download function )

That did the trick and it went on without any other fuss.

I had purchased a Yeti Blue USB microphone a while back to up my audio recording game. I had hoped to be able to eventually use it with my iPad/iPhone but there were some challenges reported so I’ve just stuck it out with my Windows 7 laptops where it has done a rocking-cool job of upping my audio game. Couple that with Audacity and The Levelator from The Conversations Network and while I am no audio-engineer, I can do a fine good job for most recording needs.

So it was exciting to see this news:

I need to update this post Claus’s iPhone App List - Updated 01/2014 as I’ve gone through some serious changes with the iOS apps I carry. I have purchased more than a few as well…so they must be that good! “Hey Siri! Remind me to update that post!”

Apps of note to get (or are recommended)

Music Memos – Apple – This one looks interesting but I’m not sure it might really meet my audio-recording needs on my Apple gear.

GarageBand for iOS – Apple – This looked good too, but maybe there is a better audio mixing app for “studio” mixing.

Due – Apple App Store – This is the best reminder/count-down timer/recurring event reminder app ever. Period. Buy it.

Round – Apple App Store – Because Due doesn’t currently handle recurring reminder events of less than a day (that I am aware of), you can’t yet use it to set medication dosing reminders. This looks to be designed specifically for that need.

Mighty Timer – Apple App Store – free app to help with brewing your tea. Alvis and her husband gave Lavie and I some very nice porcelain cups along with some fancy Matcha style tea. It has to be brewed very carefully but is super good!

Cheers.

--Claus Valca

Saturday, October 24, 2015

Stuff (being considered or obtained)

I don’t make a whole lot of “hardware” recommendations.

I don’t run ads or product click-through links on the blog that give me any benefit for your purchase.

So with that in mind, these are some recent purchases I’ve made that I have been very pleased with.

Or are links to hardware that I’m reviewing and considering picking up (for my reference).

Just passing them on in case you are interested.

Claus recommended gear:

  • MEKO™ 2Pcs [2 in 1 Precision Series] Disc Stylus/Styli - Amazon.com - As an iPad/iPhone user, there are some applications that my finger tip (or that darned soft-pad tip stylus) just won’t do for, sketching and note-taking apps for example. I found this two-pack for a fine-tip stylus for $10 that was too good not to try. I’m blow away!  The fine-point tip is a weird looking contraption but it works like a dream - even though my Spiegen screen protector.  I love this thing!  It is a dual-tip with the fine-point on one end and the large squishy capacitive fabric tip on the other. With several spare tips included. The only “complaint” I have is that it didn’t come with a pocket clip. I salvaged on off a drafting pen barrel (like the kind you got as a kid to attach to your pencil if you were a geek). That works fine enough on it for my needs.  Seriously, if you use a stylus for an iPad/iPhone, give this one a shot. It’s cheaper than most you can pick up in a store and super-high quality.
  • Kanguru FlashBlu30 (32GB) with Physical Write Protect Switch SuperSpeed USB3.0 Flash Drive ALK-FB30-32G - Amazon.com - My USB 2.0 16 GB Kanguru FlashBlu stick was showing it’s age. I’ve almost maxed out the capacity, lost the cap and broke the little plastic loop on the end. It still works but is battered and I need to check with Kangaru to see if they could send me a replacement clear cap and white loop end. Anyway, the 64 GB was what I really wanted but the price was pretty high for a budget dude like me. So I picked up the 32 GB version as a compromise. USB 3.0 with physical write-protect switch for when I am responding to an infected system. Can’t beat Kanguru brand!
  • Netac U335 USB 3.0 64G Write Protection Flash Drive - Amazon.com - or maybe you can?  This 64 GB write-protected USB 3.0 stick was a crazy $30! Compare that to the $40 32 GB version I bought above.  I picked it up on a whim for the extra capacity and have been very impressed with the quality and performance.  It won’t (quite yet) replace my trusty Kanguru USB’s with their (mostly) aluminum bodies. Only complaint so far was that it didn’t include a lanyard and is could be easy to misplace the cap/ That said, it was an awesome value!

Stuff I’m researching for future upgrades:

I’m still quite pleased with the performance of my D-Link DIR-655 router. Performance is good on our laptops and Apple devices. It has been rock-solid dependable and there are still very occasional firmware updates offered.

That said, I’ve had it so long I don’t know if I would actually be getting better performance on another “modern” device.

On top of that it just WILL NOT authenticate to my first gen Chromecast stick. Not at all. Period. I can see my network on the Chromecast, I can put in my authentication information, but it will NOT authenticate to the WiFi. Grrr.

To get my Chromecast connected to our network, I have to first connect my portable D-Link DAP-1350 Wireless N Pocket Router to my DIR-655 and then connect the Chromecast to that one. Seriously a headache and it prevents me from leaving my Chromecast connected all the time as I don’t leave the DAP-1350 online full time.

Anyway, there is the stuff and what I’m considering.

I’d love to hear your comments or recommendations as well!

Cheers.

--Claus Valca

Monday, May 04, 2015

iOS Security News

It’s hard enough keeping current on just the Windows security ecosystem. Now that we are iOS mobile device users as well, there is a whole second ecosystem to keep a security eye on. Of course, those devices have software and need to communicate so there are those layers as well to monitor for security awareness.

So here are a round of articles and tools involving iOS security findings of late.

Per that second Ars Technica article by Dan Goodin, each are different bugs but both involve components of AFNetworking,

“an open-source code library that allows developers to drop networking capabilities into their iOS and OS X apps. Any app that uses a version of AFNetworking prior to the just-released 2.5.3 may expose data that's trivial for hackers to monitor or modify, even when it's protected by the secure sockets layer (SSL) protocol. The vulnerability can be exploited by using any valid SSL certificate for any domain name, as long as the digital credential was issued by a browser-trusted certificate authority (CA).”

  • SSL MiTM attack in AFNetworking 2.5.1 - Do NOT use it in production! - Minded Security Blog - a more technical breakdown of the security issues. According to the post, the issue has been fixed in a newer 2.5.2 version of their library code. However it still requires developers to update their apps and get them on user’s devices where installed.
  • iOS Code Report - SourceDNA’s searchable database to see if your iTunes Developer has released app(s) that remain vulnerable to the weaker code.
  • SSL Analysis: Now With More Pinning - SourceDNA | Code Transparency for iOS & Android Apps, SDKs - SourceDNA Blog

This database reminded me of the ZAP - Zscaler Application Profiler that I had previously come across. It remains a great tool to look up the security of an iOS (or Android) application before -- or after -- you install it on your device.

From the “About” page link:

About ZAP

Zscaler Application Profiler (ZAP) is web based tool designed to streamline the capture and analysis of HTTP(S) traffic from mobile applications. ZAP is capable of analyzing traffic from both iOS and Android applications and includes the following functionality:

  • Search: View summarized historical results for past scans.
  • Scan: Proxy traffic from a mobile device through the ZAP proxy and the mobile app traffic will be automatically captured and analyzed
  • iPCU: Upload your iOS device configuration file(.deviceinfo) to check risk score of installed application. It will give you overall risk score of your device. The information provided is based on out knowledge base.

ZAP classifies traffic into the following buckets and calculates an overall risk score for the application:

  • Authentication: Username/password sent in clear text or using weak encoding methods.
  • Device Metadata Leakage: Data that can identify an individual device, such as the Unique Device Identifier (UDID).
  • Personally Identifiable Information Leakage: Data that can identify an individual user, such as an email address, phone number or mailing address.
  • Exposed content: Communication with third parties such as advertising or analytics sites.

Zscaler also has a detailed video on this service on their blog: Zscaler Research: Introducing ZAP.

  1. Check their historical report data on apps already researched, or
  2. Connect your device to their proxy to do a scan on a new app/version not already captured historically, or
  3. Upload your own iOS device config file.

Meanwhile on the far side of the globe, web security/developer Troy Hunt has been hard at work finding issues with additional iOS apps down under. His reviews provide great learning material to extend across other iOS application reviews closer to home.

Troy offers a free Pluralsight course to help get into the issues around mobile app security, Hack Your API First – Pluralsight Training

Finally, here is a guide from the Telerik crew on how to use Fiddler to Capture Traffic from iOS Device

Constant Vigilance!

Claus Valca

Monday, February 16, 2015

Tiny iOS News - Outlook for iOS & Firefox mockup

I don’t think this update actually solves a core issue with the Outlook for iOS app. But it does signal to me that the development team for the product is at work so maybe a more secure solution could be coming, eventually.

The other thing (I think) I am waiting for is a Firefox app for iOS. Unfortunately, the way I understand it, third-party iOS browsers still need to use the browser rendering engine from Apple. So even though I use Chrome for iOS, at the core it is still powered the same as Safari for iOS.  Firefox has to comply as well.

There isn’t a good way to tell if the final product will look anything like these images. I’m not really certain I like the result; seems very busy with all the different modal views.

Still, I’ll give it a shot if/when the final product comes out.

I do like the Chrome iOS feature that allows me to synchronize my settings and bookmarks between the iPad and iPhone. That is handy and looking at one of the rows of screenshots, Mozilla will have a similar feature in their release.

Cheers,

--Claus Valca

Sunday, February 08, 2015

Fallout continues on the Outlook mobile app

I didn’t really bring my waders out so I’m remaining on the bank for now but here are some updates to the Outlook (Acompli-based) mobile app chatter.

If you are new to the discussion…maybe refer to this past GSD post: Outlook iOS App – Nice try but with caveats

First, Microsoft has released an update to their app to bring it to 1.0.2. Mostly UI and some feature/bug fixes.

OK, RenĂ© Winkelmeyer hasn’t had any new blog posts on the subject, but remains very (kindly) engaged in the comments on his last blog post on the issue; Updates on the latest Outlook iOS App issues. So keep dropping in there for now to see where the discussion is going.

Apparently the European Union Parliament's IT department has decided that the Outlook app isn’t ready for prime-time use by it’s supported user base.

My 2¢ ?

I continue to use it on my personal phone with a throwaway Outlook.com account just to use for testing the app. I’m still not using it now for any of my core personal email accounts, nor would I even consider using it – no matter how much better the GUI is than the stock iOS mail app – on my work-issued & MDM administered phone.

Cheers,

--Claus Valca

Sunday, February 01, 2015

Outlook iOS App – Nice try but with caveats

This week Microsoft released a “new” iOS app for Outlook.

Microsoft Outlook - App Store on iTunes

As I understand it, it is based on a previous “Acompli” iOS app purchased by Microsoft.

Nevertheless, it is slick, allows you to see multiple email accounts in a unified inbox, does some magic to try to sort mail into various groupings for easy processing, etc.

I downloaded it and it worked great for my Outlook accounts.

Here are more articles and details.

However, there are some potential security concerns..both for those who might like to use it with their corporate Outlook accounts and for standard users as well.

I can’t recommend using it (just yet) with any work-based accounts, nor would I consider using it on a workplace issued iPhone. At least not until more work is done.

If you are curious about the security fuss, take a look at these articles and choose accordingly.

I’m going to play with the the app some more for now with a toss-away Outlook account to get more familiar with the product.

I really like what I see but I’m just not sure about the security concerns just yet. I need to hear more debate and see more data before becoming convinced.

Constant Vigilance!

Clause Valca

Saturday, September 20, 2014

Upgrading to iOS 8 (the long way ‘round)

Unless you totally are not into the Apple scene you may have heard that

Lavie’s 8GB iPhone 4 is getting very sad and tired and she is itchy to upgrade. I think the best deal for her (now out of her 2 year contract) would be to get either a 16 GB iPhone 5s or 5c. I’m leaning to the 5s myself even though it will be more expensive. However her thrifty-ness surprises me sometimes so she might be OK with the 5c.  She is not a power-user of apps or streaming so from a hardware perspective either should be more than adequate after the 4 she has now.

Last night I went ahead and decided to upgrade my 4th gen iPad Retina to iOS 8.  What should have been a quick process went super bad super fast.

It’s a 32 GB model but I have it jammed packed with videos (mostly sysadmin/training videos) and PDF whitepapers of for/sec/admin-related topics to read when I’m between activities.

As such I had < 5 GB of free space so I couldn’t do a WiFi only iOS update. But if you do the upgrade from iTunes you don’t need to have free space on your device.

Mistake #1: Not confirming/taking a backup.

Mistake #2: Plugging the device in to a powered USB hub rather than directly on my system.

I plugged the iPad into a brand-name USB powered hub extender and the iPad was detected ok.

I mis-read the initial prompt about do I want to backup some apps that were on the iPad and not my iTunes and said “no”.  Bad decision.

The update downloaded and began to apply.

As part of the process the iPad rebooted but it would not reconnect automatically to the USB port, which caused the iTunes update to fail.

I repeated again and more fails and each time I retried it said I had to do a device Restore. Yikes!

Finally after hunting down error codes and update failures I switched the cable over to a USB port directly on my laptop.  I did a hard-reset of the device and then the iOS 8 upgrade went on. Yea!

Only it was a (mostly) factory restore.  Somehow, some backup items were found from an older backup (or maybe the device itself?) and restored.

I had to put all my music library, videos, photos, and videos specific to my VLC app library back on manually; a few apps that I hadn’t downloaded to iTunes also had to be restored/reinstalled. That took a very long time. Luckily all my (considerable) ebooks and whitepaper PDFs stored in Adobe Reader and Documents apps were all present and accounted for.

It took a long time (4-5 hours!) for the whole process before I was chilling again on the couch with the iPad but I finally got it tweaked back to the way it was before.  I’m wondering what I haven’t found missing yet because after the upgrade and auto/manual rebuild, I’ve now got around 10 GB of free space.

So this Saturday morning I’ve been busy doing manual iTunes updates (we don’t back up to iCloud) of both our iPhones as well.

I’m not in much hurry to upgrade my iPhone 5 just yet after that iPad update drama and Lavie’s iPhone 4 doesn’t qualify for the iOS 8.

I also figured out how to review and delete a bunch of old iTunes backups to clean house:

The other big headache after the upgrade and restoration was coming to terms with all the new features and setting changes brought by 8.  I had a ton of re-tweaking deep in the Settings to do to ensure it was set to my comfort levels.

Here is a list of iOS 8 items you may want to review before/after you do your iOS 8 journey. Many of these tips and suggestions have been super-helpful to me.

Cheers.

--Claus Valca

Sunday, August 31, 2014

OneNote for iOS

Just like I post “linkfests” here for my archival reference and for sharing, I collect URL’s for family and friends as well.

These typically run much less technical; though admittedly more than fairly geeky.

Common subjects are interior design trends, architecture, recipes, Dr. Who fandom bits, short films, science, and faith/life-balance.

Unlike the GSD blog where they get shoved out on stage and dialog/feedback is relatively rare, these more personal links across the web are chosen with discussion and togetherness in mind. They are random encounters discovered that can be shared and reflected. We need to build out new dreams, wishes, and hopes as we re-discover the Lavie and Claus bond that isn’t centered around Alvis any longer.

The iPad makes a great platform to pull out on the couch when I’m sitting with Lavie. It’s a lot more comfortable (and feels more personal/intimate) than using either of our laptops.

Only sharing the sharing bit is a bit clunky.

I’ll send the URL collection out via email, but when we want to view the links together on the iPad, it requires opening the email client, finding the email (which can be quite buried…so it needs to be tagged/flagged), then clicking an embedded link. From there we review, then we need to return to the email client and hit the next one. Repeat.

It works but is a bit clunky.

What I wanted to do for some time is to select the HTML markup body of the email, paste it into a document editing app, then just use that as the launching place.

Probably because I’m still not very familiar with the iOS app landscape this discovery process has been more of a challenge than it should be.

My first hope was that Notability (App Store on iTunes) could handle embedded HTML markup copied and pasted. Nope.

Neither could Byword (App Store on iTunes) or Documents by Readdle (App Store on iTunes). In all cases it would strip out the HTML markup code and leave me with useless plain text.

Why was it hard to find a note-taking or document app that would keep copied HTML markup?

Eventually I found what I was looking for.

Microsoft OneNote for iPad  and Microsoft OneNote for iPhone (App Store on iTunes)

I’m very familiar with OneNote usage on the Windows desktop (I have an Office 2010 version) but didn’t think about using it on my iDevices.

One “gotcha” is that you will need to log in with a valid account to use the application. Having a Microsoft Outlook Live account makes the process very smooth. There were some extra validations and secret code-pasting required but it was easy to follow.

Once I had the application installed and linked, I tested it by copy/pasting a big block of HTML markup from one of my emails to Lavie and Alvis with tons-o-links into a fresh note page.

Hurrah! It looked like it kept the HTML formatting! I selected one of the links and it opened up quickly and perfectly in Safari.  Solution found!

I then installed the app on my iPhone. This time all I had to do was log in, no additional account validation was required second go round.

I must confess, the iPad version looks and works much more like the Windows desktop version than the iPhone version. However, having quick access to the notes is indeed handy.

To add another major boost to handy-access of things, I quickly discovered I could link the additional OneNote notebooks I have on my desktop via the OneNote 2010 application I use to both the iPad and iPhone apps. It leverages Microsoft’s OneDrive storage platform.

I’m still not ready to drink shoving all my electronic life to the “cloud”, but this is a handy start.

So, if you are looking for a way to keep HTML markup notes -- from web or email snippings -- on your iPad or iPhone, then the free OneNote iOS apps are a great option to consider. And doubly so if you have a Windows client version of OneNote 2010 or higher on your desktop.

Don’t have Microsoft OneNote for Windows desktop? Microsoft offers it for free:

Download OneNote 2013

Other platforms supported are Windows Phone, Mac, Android, Amazon, and the Web

Cheers.

--Claus Valca