{"id":4007,"date":"2016-06-11T09:22:29","date_gmt":"2016-06-11T03:52:29","guid":{"rendered":"https:\/\/www.qadit.com\/blog\/?p=4007"},"modified":"2016-06-20T17:11:06","modified_gmt":"2016-06-20T11:41:06","slug":"derays-twitter-hack-reminds-us-even-two-factor-isnt-enough","status":"publish","type":"post","link":"https:\/\/qadit.com\/blog\/derays-twitter-hack-reminds-us-even-two-factor-isnt-enough\/","title":{"rendered":"@Deray\u2019s Twitter Hack Reminds Us Even Two-Factor Isn\u2019t Enough"},"content":{"rendered":"\n<p>The Apple ecosystem is well known for very rarely letting any dodgy apps enter it because of the company\u2019s stringent security checks.<\/p>\n<p>&nbsp;<\/p>\n<p>But recently, nearly two dozen malicious pieces of software managed to get hosted on the App Store, and subsequently downloaded by Chinese users. This is because attackers found an unorthodox route to exploit: they targeted some versions of the software used by developers to makes apps for iOS and OS X in the first place.<\/p>\n<p>&nbsp;<\/p>\n<p>The malware was first highlighted by Chinese developers on Weibo, and was then analyzed by researchers from Alibaba. Security company Palo Alto Networks then verified the results.<\/p>\n<p>&nbsp;<\/p>\n<p>The hack all hinges around Xcode, a tool used to create iOS and OS X apps. Typically, Xcode is downloaded directly from Apple for free. However, it is possible to get Xcode from other sources too, such as developer forums. Some versions of Xcode found on Baidu Yunpan, a Chinese file-sharing service, come packaged with extra lines of code. The Alibaba researchers have dubbed these malicious variants \u201cXcodeGhost.\u201d <\/p>\n<p>&nbsp;<\/p>\n<p>Apps constructed with XcodeGhost code will collect a bunch of information about a customer\u2019s device once the app has been downloaded. The data siphoned includes the current time, the name of the device, and the network type\u2014none of which is anything a hacker could really use against you.<\/p>\n<p>&nbsp;<\/p>\n<p>The malware in the App Store itself is not concerning, but there\u2019s a broader issue here: the way in which it got past Apple\u2019s screening process in the first place.<\/p>\n<p>&nbsp;<\/p>\n<p>Read the full article <a href=\"https:\/\/www.wired.com\/2016\/06\/deray-twitter-hack-2-factor-isnt-enough\/\">here<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Apple ecosystem is well known for very rarely letting any dodgy apps enter it because of the company\u2019s stringent security checks. &nbsp; But recently, nearly two dozen malicious pieces of software managed to get hosted on the App Store, and subsequently downloaded by Chinese users. This is because attackers found an unorthodox route to &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/qadit.com\/blog\/derays-twitter-hack-reminds-us-even-two-factor-isnt-enough\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;@Deray\u2019s Twitter Hack Reminds Us Even Two-Factor Isn\u2019t Enough&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false},"version":2}},"categories":[12],"tags":[],"class_list":["post-4007","post","type-post","status-publish","format-standard","hentry","category-itsec"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9AH7Q-12D","_links":{"self":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/4007","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/comments?post=4007"}],"version-history":[{"count":3,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/4007\/revisions"}],"predecessor-version":[{"id":4091,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/4007\/revisions\/4091"}],"wp:attachment":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/media?parent=4007"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/categories?post=4007"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/tags?post=4007"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}