• April 2, 2023

Tesla Electric Semi Recalled After Just A Few Months On The Road

Tesla’s electric Semi trucks are being recalled over a faulty electronic parking brake, according to a notice posted online by the NHSTA. The recall comes after Tesla made its first deliveries …

How To Ruin Your Kids With A Lousy Estate Plan

Introduction Estate planning is primarily about the transmission of wealth. However, it should be about much more. Many people don’t want to delve into family skeletons or tackle emotionally charged issues. …

Financial Trauma Is Real: Why Black People Should Consider Financial Therapy

April is financial literacy month and the month-long celebration often comes with appeals to low-income and marginalized communities that suggest the silver bullet to their financial woes is financial literacy–and it’s …

iOS 16 is a buggy mess, with Apple releasing a series of dedicated bug fixes that have barely scratched the surface. And now, new research has discovered that arguably the worst problem in iOS is even worse in iOS 16.

Speaking to MacRumors, security researchers Tommy Mysk and Talal Haj Bakry of Mysk reveal that iOS 16 leaks user data when using a VPN. This problem has been ongoing since iOS 13.3.1. What makes it worse is Apple introduced a new ‘Lockdown Mode’ in iOS 16, but the researchers found it leaks even more data than the standard mode. Something which has potentially serious repercussions.

“We confirm that iOS 16 does communicate with Apple services outside an active VPN tunnel. Worse, it leaks DNS requests. #Apple services that escape the VPN connection include Health, Maps, Wallet,” the researchers tweeted along with an explanatory video.

Advertisement

“The Lockdown Mode leaks more traffic outside the VPN tunnel than the ‘normal’ mode,” the researchers added. “It also sends push notification traffic outside the VPN tunnel. This is weird for an extreme protection mode.”

Contrast this with Apple’s description of Lockdown Mode in its support documents:

“Lockdown Mode is an optional, extreme protection that’s designed for the very few individuals who, because of who they are or what they do, might be personally targeted by some of the most sophisticated digital threats. Most people are never targeted by attacks of this nature.”

“When Lockdown Mode is enabled, your device won’t function like it typically does,” Apple continues. “ To reduce the attack surface that potentially could be exploited by highly targeted mercenary spyware, certain apps, websites, and features are strictly limited for security and some experiences might not be available at all.”

There’s a differentiation to be made here between attacks and data retention. Still, it is reasonable to assume that anyone using Lockdown Mode would not expect more data to be leaked via VPN with it enabled than without.

I have contacted Apple about these discoveries and will update this article if/when I receive a response.

___

Follow Gordon on Facebook

More on Forbes

Advertisement

Leave a Reply

Your email address will not be published.