Tag: bug

  • Apple admits to SIM bug on iPhone 14 line

    Apple admits to SIM bug on iPhone 14 line

    Apple is admitting in an internal memo that there is a problem with the iPhone 14 series that results in a pop-up message that says, “SIM Not Supported” which is often followed by the freezing of the device. While Apple said that it is investigating the issue, it did rule out the possibility that it is a hardware problem. The company is asking its customers to make sure that they keep their software up to date.
    You can always check to see if there is a system update for your iPhone by going to Settings > General > Software Update. Meanwhile, Apple is also recommending that those who see the “SIM Not Supported” pop-up message wait a few minutes to see if the message disappears. Now here is the important thing to remember. If you do get the message about the SIM card and it doesn’t go away, do not try to restore the device.
    If you’re in this situation and the message persists, you need to head over to the nearest Apple Store or authorized service provider and arrange to have the issue fixed. Apple has already had to deal with several bugs since the release of the iPhone 14 series including one issue that made the iPhone 14 Pro models shake and grind when users recorded video on them over third-party apps like Instagram, TikTok, and Snapchat.
    Late last month Apple released iOS 16.0.2 to exterminate that bug and several others. A week ago, iOS 16.0.3 was disseminated by Apple and among the issues it fixed was one that allowed a bad actor to send an email using two double quotation marks in the “from” field instead of the first part of a valid email address. The recipient, upon opening this email in the Apple Mail app, would see the app crash and the user would also get locked out of his Apple Mail account.
    Apple is currently working on iOS 16.1 and has a beta program underway with the stable version of the build expected to be released at the end of this month. Will it contain a patch to fix the issue of the SIM pop-up screen? After all, Apple has admitted that this is a real thing and not everyone is going to feel like heading to the Apple Store or an authorized repair center to get the issue fixed.
    Additionally, with Apple reminding users to stay up to date with the software on their phones it sure sounds like the company might be working to exterminate this bug via a software update. Stay tuned.
    We should remind everyone that Apple put the kibosh on physical SIM cards with the iPhone 14 series. Instead, the 2022 iPhone models feature eSIM (embedded SIM) which is a chip that gets soldered to the phone’s motherboard. With an eSIM, switching networks is easier requiring just a phone call or a visit to a website. Up to five virtual eSIM cards can be stored on a single eSIM at a time. If your usual network is down for some reason, you can quickly switch to another one.
    You can also have the same advantage that dual-SIM phones offer; the ability to have two numbers on a single handset. One number can be for work and another for play. You’ll be able to receive phone calls and texts on both numbers all of the time while you’ll choose which number to use to make calls, send texts, or use data.

    Using an eSIM also gives the phone manufacturer more internal room to work with because the SIM card tray is no longer needed.

  • Apple needs to exterminate bug causing AirTags stalking false alarms

    Apple needs to exterminate bug causing AirTags stalking false alarms

    With all of the publicity that is generated when a rogue Apple AirTag is used to stalk unsuspecting victims, Apple is now having issues with AirTags that result in alerts being sent to users who aren’t being stalked at all. While the device was designed to help people keep tabs on small items that they are apt to lose such as key chains, the AirTags have been used by criminals to follow the whereabouts of certain car models that bring high returns in the stolen car market.
    And to prevent iPhone users from becoming victims of criminal AirTag users, they are alerted when being followed by someone else’s AirTags. That’s what happened recently at Disney World when a mother and daughter were leaving the park and the daughter received a notification on her iPhone saying that she was being tracked by another person’s AirTag. Luckily, nothing ever came of the incident although it frightened both of them..
    What is happening more and more is that iPhone users are receiving such frightening alerts even if they aren’t being tracked at all. The Journal says that some of these warnings are coming in the middle of the night and are scaring those who are receiving the notifications. In most cases, the rogue AirTags are not in the path of the concerned iPhone users at all, and could be from a bug or a glitch.
    The bogus reports have created “confusion and concern, and have led recipients on wild goose chases” according to the Wall Street Journal. And graphs tracking these bogus AirTag alerts create patterns that are not realistic. These patterns are showing the erratic movements of these AirTags moving in nonsensical directions.
    Ryan McClain, a 25-year-old marketer in Indianapolis, received a notification one-morning last month that said he was being tracked. His response was a combination of bewilderment, fear, and concern. “It was a shock to my morning,” he said. “I thought, ‘Who would want to stalk me? Who would want to hurt me?” McClain and his fiance spent the next day looking in vain for the offending AirTags.
    Toronto-based consumer researcher Marcus Geisler found the pattern of movement generated by the AirTags to be strange. “The AirTag’s pattern of movement on the map looked super weird,” said Geisler.” “I thought maybe my neighbor’s dog accidentally swallowed it,” He also was unable to find any rogue AirTags.
    Another iPhone user, 24-year-old Natalia Garcia, received a notification telling her that an “AirTag (was) Found Moving With You.” She received the message after an evening in downtown Chicago. “It was scary,” Garcia said, “I checked my purse, looked all around to make sure no one put an AirTag on me,” she said. She tried to force the tracker to ring its alarm but the Find My app just would say “AirTag Not Reachable.”
    So what should you do if you’re getting bombarded with bogus notifications? Should you turn the notifications off? Not al all says John DeCarlo, director of the master’s program in criminal justice at the University of New Haven and a former Branford, Conn., police chief. “Getting false alarms with technology is a common occurrence,” DeCarlo said. “If you turn the notifications off, it leaves you without the benefits.”
    If the bogus notifications are from a bug, it will be up to Apple to try and exterminate it just to keep users from feeling that an unseen stalker constantly has his eyes on them even if that isn’t true at all.
    It just reveals what a sad state the world is in that a device meant to help people find missing objects becomes a scary product used to attack people just minding their own business.
  • Serious Safari bug reveals iPhone, iPad, and Mac users’ personal data

    Serious Safari bug reveals iPhone, iPad, and Mac users’ personal data

    Security firm FingerprintJS published a report on Friday about a bug found in the iOS 15 version of the Safari mobile browser. The report states that this bug “lets any website track your internet activity and even reveal your identity.” A bug found in an Application Programming Interface (API) used and supported by most browsers could be used by attackers to find out many things about you.
    An API is used by programmers to connect parts of the software to other software making it easier to develop programs. One such API, called IndexedDB, is supported by most major browsers and holds what the report calls “a significant amount of data.”

    The bug in the iOS 15, iPadOS 15, and macOS allows random websites to know what other sites a user is visiting on other windows and tabs. That is possible because sites like YouTube, Google Calendar, and Google Keep use “unique user-specific identifiers” in their database names. As a result, authenticated users can be identified as the aforementioned sites create databases that include the  Google User ID belonging to the user, and databases are opened for all the accounts being used.

    The Google User ID leads an attacker to a wealth of personal data. Each one can be used to identify a specific Google account and in combination with Google APIs, it can, at the least, reveal your profile picture to a hacker. It also could help the attacker grab much more personal information and unravel “multiple separate accounts” owned by the same user.

    Unfortunately, learning your personal information doesn’t require you to perform any specific action as the report states “A tab or window that runs in the background and continually queries the IndexedDB API for available databases, can learn what other websites a user visits in real-time. Alternatively, websites can open any website in an iframe or popup window in order to trigger an IndexedDB-based leak for that specific site.”

    FingerprintJS checked with Alexa’s top 1,000 visited sites and found that 30 interact with indexed databases right on their homepage, without any interaction or authentication required by the user. Even if a person is using the private mode in Safari, if he visits multiple websites using the same tab, all databases interacted with are leaked to the sites the user subsequently visits.

    There isn’t much that a Safari user can do if he is running iOS 15 or iPadOS 15. One suggestion is to block all JavaScript by default and only allow it on sites that are 100% trusted. Mac users can switch browsers to escape this bug, but this is not a solution on iOS 15 or iPadOS 15. We should point out that the bug was submitted by FingerprintJS to the WebKit Bug Tracker on November 28, 2021, as bug 233548.

    If you want to check this out on your iPhone or iPad, open Safari and point it at safarileaks.com and follow the simple directions. Quickly (too quickly), the name of the last site you visited appears (if it was one of the sites listed on the Demo page) and your unique Google User ID can be accessed.

    Frankly, the only solution that you have is to wait for Apple to update the iOS and iPadOS software and make sure to install it as soon as it is released. Again, if you’re using a Mac, changing browsers is a valid option although that is not the case with iOS and iPadOS. And keep in mind that users don’t need to perform any specific action in order to set off the bug.

  • Apple is giving out a special iPhone that can lead to a $1 million reward

    Apple is giving out a special iPhone that can lead to a $1 million reward

    Apple is giving out special versions of the iPhone to security researchers who have the opportunity to collect as much as $1.5 million from Apple. Announced last week at the Black Rock cybersecurity conference in Las Vegas (where ironically Apple earlier this year put up a billboard reading “What happens on your iPhone stays on your iPhone”), the tech giant is giving these experts the task of hacking into the iPhone to find vulnerabilities and security flaws. Apple security chief Ivan Krstic says that these special iPhones come with “advanced debug capabilities.” Unlike the units sold to consumers, these will allow researchers to access parts of iOS that are off-limits to most users.

    The so-called iOS Security Research Device Program will get underway next year and while anyone can apply to receive one of the special iPhone units, Apple says that there will be a limited amount handed out. Most likely only qualified security researchers will be able to obtain one of these devices. Even though they will be much more open than a store-bought iPhone, the researchers won’t have the same access that Apple’s own internal security team has on their iPhones.

    Companies like Apple and Google pay these researchers to find flaws as an incentive. In addition, Apple would prefer that a security expert who finds a vulnerability tell the company about it instead of selling it or using it for their own evil intentions. Flaws found on iOS are said to bring researchers as much as $1 million from hackers willing to pay that much. Apple announced last week that a researcher can receive $1 million by finding a flaw allowing him or her to take over full control of an iPhone without the owner touching the handset. Other flaws can also handsomely reward a researcher as Apple is willing to pay up to $500,000 for the information. Google announced last month that it will pay up to $30,000 to a researcher finding flaws in its Chrome browser while paying $150,000 if it is told about a flaw that can compromise its Chrome OS.

    “We want to attract some of the exceptional researchers who have thus far been focusing their time on other platforms. Today many of them tell us they look at our platform and they want to do research but the bar is just too high. We have by far the highest maximum payouts in the industry, and we have the iOS security research device program for exceptional researchers that are new to our platform”-Ivan Krstic, head of security engineering and architecture, Apple

    Researchers who find a vulnerability in code found on beta software will receive a 50% bonus from Apple. That is to reward an expert who has identified a problem before the bug is passed along to the public, and brings the top possible award handed out by Apple to $1.5 million. As the company’s security chief points out, “The second-best reason to have a bug bounty is to find out about a vulnerability that’s already in the users’ hands and fix it quickly. The number one best reason is to find a vulnerability before it ever hits a customer’s hands.”

    Apple’s new program might have received more applause if it wasn’t for the limited number of special iPhones it is handing out. As iOS security researcher Will Strafach noted, “It’s a huge step, but I do think it would be great if there were a bit more wide availability of the devices.” Apple might be concerned that the wider availability of these units might lead to several ending up in the wrong hands, creating more problems for the company. Still, with all this money at stake, regular iPhone owners should benefit from the incentives that Apple is throwing at security experts.

  • Skype automatically answers calls on Android due to a bug

    Skype automatically answers calls on Android due to a bug

    If you’re using Skype for your day to day communication with friends, co-workers or business partners, there’s a high chance that you’ve been affected by a nasty bug that makes the app automatically answer all calls on Android devices.

    Microsoft is probably the only one that can tell for sure when exactly the issue started to manifest for the first time, but reports go back as far as January, probably soon after the developers updated the app. Sadly, it appears that the issue now affects even more users, as we’re seeing lots of recent reports posted on Microsoft’s support forum.

    For the time being, there’s no workaround to prevent Skype from answering calls that you want to ignore, so the only way to avoid the issue is to uninstall the app until Microsoft fixes it. Not even having the “Answer incoming calls automatically” option disabled will not stop Skype from doing just that.

    The good news is Microsoft has already identified the issue and managed to patch it, but only in the latest Skype preview app. If you want to continue to use the app without being affected by the bug, you can download the beta until the final version gets updated later this month.

  • Audi’s Electric SUV Faces Four Week Delay Due to Software Issues

    Audi’s Electric SUV Faces Four Week Delay Due to Software Issues

    Audi’s first electric sport utility vehicle (SUV) will hit showrooms four weeks later than planned because of a software development issue, a spokesman for the German luxury car brand said on Sunday. The spokesman said Audi’s e-tron midsize SUV faced delay because the carmaker needs new regulatory clearance for a piece of software that was modified during the development process.

    Audi staged a global launch of the e-tron in San Francisco last month as part of its effort to expand the market for premium electric vehicles and grab a share from California-based Tesla, which has had the niche largely to itself.

    The e-tron delays were first reported by German newspaper Bild am Sonntag, citing sources close to the company. The paper said delivery could be delayed by several months. The paper also said Audi was locked in price negotiations with LG Chem, the South-Korean supplier of batteries for its electric vehicles, which wants to increase prices by about 10 percent because of high demand.

    LG Chem supplies electric vehicle batteries for Audi, its parent Volkswagen and Daimler. An LG Chem official declined to comment on the report, citing the confidentiality of its relationship with a client. The Audi spokesman also declined to comment on price negotiations with LG Chem.

  • World catches the Chinese holiday shopping bug

    World catches the Chinese holiday shopping bug

    Elena Zhang, sales manager of Xi’an Silk Road Crafts Co, said the company started receiving overseas orders for Spring Festival in July last year.

    One order last month came from Spain, for more than 1,000 red hanging lanterns made of Chinese fabric.

    Orders for various products related to Chinese New Year had come in from Canada, France, Germany and Russia, she said. AliExpress, a website that sells made-in-China products to overseas customers, is by far the most used online shop.

    Our China Dream series of lanterns are the bestsellers among overseas Chinese this year. It belongs to Alibaba, China’s largest e-commerce player. “Fabric lanterns priced between $1.50 and $4.30 (£1-3) each were the most popular items this year,” Ms Zhang said.

    “Overseas buyers usually place their Spring Festival orders in summer. But we have had orders at the end of the year, too. Enthusiasm overseas in Chinese New Year shopping seems to be increasing, and e-commerce is helping increase sales.”

    Sales by AliExpress to overseas consumers from the city of Yiwu, Zhejiang province, well-known as a centre for small commodities, have risen sharply since the company began to ship worldwide on Dec 31.

    To the end of January it had shipped more than one million parcels overseas. One of the companies making full use of this new service is Yiwu Wonderful Lantern Co.

    Xia Rongwang, the company’s manager, said many overseas orders had been placed since the middle of January, especially from overseas Chinese in countries such as Malaysia.

    Some buyers said the lanterns make them feel as though they are back home celebrating new year

    “Our China Dream series of lanterns are the bestsellers among overseas Chinese this year. Some buyers have said the lanterns make them feel as though they are back home celebrating the new year.”

    Apart from Spring Festival-related items such as lanterns, overseas consumers are buying other products made in China selling at bargain prices in the holiday period and just before it. DHgate, a Chinese online wholesale marketplace, said sofa and bed cushions are particularly popular among Canadian shoppers.

    Russians are said to be the most numerous overseas buyers. AliExpress says they love buying clothes made in China, their keenness to shop online spurred by a depreciating rouble. Consumers in countries where winters tend to be very cold buy made-in-China down jackets and other winter-wear.

    Felix Zhang, sales manager for Shaoxing Goldson Dress Co in Zhejiang province, said Chinese down jackets in the $40 to $47 price range are popular among buyers in Kazakhstan, Estonia and Latvia. “We offer discounts of up to $500 for buyers who order more than 10,000 down jackets. The reason is obvious: Online selling means we cut the costs resulting from going through intermediaries.”