Showing posts with label sneaks. Show all posts
Showing posts with label sneaks. Show all posts

Wednesday, 11 September 2013

Apple sneaks in changes to AppleCare+

Alongside Tuesday's iPhone 5c and 5s announcements, Apple snuck in some changes to its AppleCare+ protection plans -- some for the better, some not so much.

First off, dropping your pretty new iPhone just got a bit more expensive, as noticed by TechCrunch's Matthew Panzarino. Although the purchase price of AppleCare+, the special variety of AppleCare for Apple phones and tablets, still costs $99, the price for each accidental-damage iPhone repair has increased from $49 per incident to $79. (You're allowed two such repairs over the two-year life of the plan.) The price of iPad accidental-damage repairs appears to be unchanged at $49 per incident.

[ Also on InfoWorld: All you need to know about the new iPhone. | Get the latest insight on the tech news that matters from InfoWorld's Tech Watch blog. ]

Newly purchased AppleCare+ plans also no longer cover any headphones included with your device. Existing iPhone AppleCare+ plans presumably maintain the coverage and pricing promised at the time of purchase. (We've asked Apple to confirm this; we'll update this article with any information we receive.)

In positive news, the company also brought AppleCare+ to iPod models for the first time on Tuesday -- specifically, the iPod touch and the iPod classic. Apple previously offered standard AppleCare plans for these models for $59 each. The same $59 now buys you AppleCare+ which, as with the iPhone and iPad versions, now covers accidental damage -- although with a lower $29-per-incident fee (again, limited to twice over two years). Unlike the iPhone plan, however, the iPod version appears to cover headphones. Do current iPod touch/classic AppleCare customers get upgraded to AppleCare+, or is that only for new plans? Good question -- we asked Apple about that too.

The iPod touch is a natural candidate for AppleCare+ coverage, thanks to its just-as-easy-to-crack-as-an-iPhone's screen and nearly identical form factor. And the iPod classic, as the one mechanical hard drive-based iPod left, is a natural fit -- it's only a drop away from total failure.

As before, all AppleCare+ plans must be purchased at the same time as your hardware or within 30 days of purchase. The latter requires that you verify your purchase date and submit your iPod for inspection -- for example, at an Apple retail store -- to rule out any pre-existing conditions.

Alas, Apple appears to have dropped AppleCare for the iPod shuffle and nano altogether, though Panzarino notes that Apple has finally brought AppleCare to the UK, France, and Italy on Tuesday.


View the original article here

Monday, 19 August 2013

'Jekyll' test attack sneaks through Apple App Store, wreaks havoc on iOS

Acting like a software version of a Transformer robot, a malware test app sneaked through Apple's review process disguised as a harmless app, and then re-assembled itself into an aggressive attacker even while running inside the iOS "sandbox" designed to isolate apps and data from each other.

The app, dubbed Jekyll, was helped by Apple's review process. The malware designers, a research team from Georgia Institute of Technology's Information Security Center (GTISC), were able to monitor their app during the review: they discovered Apple ran the app for only a few seconds, before ultimately approving it. That wasn't anywhere near long enough to discover Jekyll's deceitful nature.

[ Stay ahead of advances in mobile technology with InfoWorld's Mobile Edge blog and Mobilize newsletter. ]

RELATED:Malicious power-charger can infect Apple iOS devices

The name is a reference to the 1886 novella by Robert Louis Stevenson, called "The Strange Case of Dr Jekyll and Mr Hyde." The story is about the two personalities within Dr. Henry Jekyll: one good, but the other, which manifests as Edward Hyde, deeply evil. 

Jekyll's design involves more than simply hiding the offending code under legitimate behaviors. Jekyll was designed to later re-arrange its components to create new functions that couldn't have been detected by the app review. It also directed Apple's default Safari browser to reach out for new malware from specific Websites created for that purpose.

"Our research shows that despite running inside the iOS sandbox, a Jekyll-based app can successfully perform many malicious tasks, such as posting tweets, taking photos, sending email and SMS, and even attacking other apps all without the user's knowledge," says Tielei Wang, in a July 31 press release by Georgia Tech. Wang led the Jekyll development team at GTISC; also part of the team was Long Lu, a Stony Brook University security researcher.

Some blogs and technology sites picked up on the press release in early August. But wider awareness of Jekyll, and its implications, seems to have been sparked by an Aug. 15 online story in the MIT Technology Review, by Dave Talbot, who interviewed Long Lu for a more detailed account.

Jekyll "even provided a way to magnify its effects, because it could direct Safari, Apple's default browser, to a website with more malware," Talbot wrote.

A form of Trojan Horse malware, the recreated Jekyll, once downloaded, reaches out to the attack designers for instructions. "The app did a phone-home when it was installed, asking for commands," Lu explained. "This gave us the ability to generate new behavior of the logic of that app which was nonexistent when it was installed."


View the original article here