×
Firefox

PowerPC Fork of Firefox Reaches End of the Road (arstechnica.com) 50

Andrew Cunningham writes via Ars Technica: It has been well over a decade since PowerPC Macs roamed the earth -- so long that the Intel Macs that replaced them are themselves being replaced by something else. But to this day, there's a small community of people still developing software for PowerPC Macs and Mac OS 9. One of those projects was TenFourFox, a fork of the Firefox browser for G3, G4, and G5-based PowerPC Macs running Mac OS X 10.4 or 10.5. Maintained primarily by Cameron Kaiser, the TenFourFox project sprang up in late 2010 after Mozilla pulled PowerPC support from Firefox 4 during its development. And amazingly, the browser has continued to trundle on ever since.

But continuing to backport Firefox features to aging, stuck-in-time PowerPC processors only got more difficult as time went on. And in March of this year, Kaiser announced that TenFourFox updates would be ending after over a decade of development. The final planned release of TenFourFox was earlier this month. Kaiser's full post is long, but it's worth a read for vintage-computer enthusiasts or anyone who works on software -- Kaiser expresses frustration with the realities of developing and supporting a niche app, but he also highlights TenFourFox's impressive technical achievements and ruminates on the nature of the modern Internet and open source software development [...].

Kaiser doesn't intend to fully halt work on the browser, but he is downshifting it into what he calls "hobby mode." He will continue to backport security patches from newer ESR releases of Firefox and post them to the TenFourFox Github page, but anyone who wants to use these will need to build the app themselves. Kaiser also won't commit to providing support for these additions or providing them on any kind of schedule. Other developers are also welcome to continue to release TenFourFox builds on their own.

Programming

Apple Joins Blender's Development Fund To Support 3D Graphics Tool (macrumors.com) 51

Blender today announced that Apple has joined the Blender Development Fund to support continued development of the free open source 3D graphics tool. From a report: Alongside a contribution to the Development Fund, Apple will provide engineering expertise and additional resources to Blender and its broader development community to help support Blender artists and developers, according to the announcement. Blender CEO Ton Roosendaal said the announcement means that "macOS will be back as a complete supported Blender platform."
Android

Apple Argues Against Allowing App Sideloading By Pointing Out Android's Malware Figures (therecord.media) 66

Apple said today that one of the reasons it does not allow app sideloading or the use of third-party app stores on iOS is because of privacy and security reasons, pointing to the fact that Android sees between 15 to 47 times more malware compared to its app ecosystem. The Record reports: Apple says that the reason its iOS devices are locked into the App Store as the only way to install applications is for security reasons, as this allows its security teams to scan applications for malicious content before they reach users. Apple cited statements from multiple sources (DHS, ENISA, Europol, Interpol, NIST, Kaspersky, Wandera, and Norton), all of which had previously warned users against installing apps from outside official app stores, a process known as app sideloading.

Apple's report then goes on to list multiple malware campaigns targeting Android devices where the threat actors asked users to sideload malicious apps hosted on internet sites or third-party app stores. [...] The list includes a host of threats, such as mundane adware, dangerous ransomware, funds-stealing banking trojans, commercial spyware, and even nation-state malware, which Apple said threat actors have spread by exploiting the loophole in Android's app installation process that allows anyone to install apps from anywhere on the internet. Today's 31-page report (PDF) is the second iteration of the same report, with a first version (PDF) being published back in June, shortly after EU authorities announced their investigation.

Iphone

Apple Set to Cut iPhone Production Goals Due to Chip Crunch (bloomberg.com) 27

Apple is likely to slash its projected iPhone 13 production targets for 2021 by as many as 10 million units as prolonged chip shortages hit its flagship product. Bloomberg reports: The company had expected to produce 90 million new iPhone models in the last three months of the year, but it's now telling manufacturing partners that the total will be lower because Broadcom and Texas Instruments are struggling to deliver enough components [...]. The technology giant is one of the world's largest chip buyers and sets the annual rhythm for the electronics supply chain. But even with strong buying power, Apple is grappling with the same supply disruptions that have wreaked havoc on industries around the world. Major chipmakers have warned that demand will continue to outpace supply throughout next year and potentially beyond. Apple gets display parts from Texas Instruments, while Broadcom is its longtime supplier of wireless components. One TI chip in short supply for the latest iPhones is related to powering the OLED display. Apple also is facing component shortages from other suppliers.
Iphone

Robotics Engineer Adds a Working USB-C Port To An iPhone (appleinsider.com) 32

Ken Pillonel, a robotics engineer on YouTube, replaced an iPhone's Lightning port with a working USB-C port. AppleInsider reports: In a YouTube Short titled "World's First USB-C iPhone," Ken Pillonel claims to have installed the component into the iPhone X, replacing Lightning in the process. In the video, the iPhone is said to receive power via the connection, as well as being able to handle data transfers over a USB-C cable. In the description of the video, Pillonel says he reverse-engineered Apple's C94 connector, in order to make a PCB with a female USB-C port. After the schematics were set in place, it then became a challenge to shrink it down and install it into an iPhone.

Pillonel has spent a few months on his creation, with a blog post from May showing the thinking behind the replacement, and the challenges of replacing the Lightning port itself. A video at that time showed a DIY prototype that worked and laid out the work ahead to make it small enough to work within an iPhone enclosure. A late September update advised he had designed and ordered a flexible PCB, a key component in enabling the port switch to occur. He adds a future video is in production, explaining how the board was made and squeezed into the iPhone itself.

Desktops (Apple)

Apple Announces October 18 Event After Months of Mac Rumors (theverge.com) 31

Apple's next hardware event will take place on October 18th, according to invites it sent out today. From a report: The company is widely expected to use its second fall event to launch a pair of new MacBooks, a redesigned higher-end Mac Mini, and possibly a pair of third-generation AirPods. The invite video teases one word: Unleashed.

[...] There have been reports for months that Apple is on the cusp of releasing new 14- and 16-inch MacBook Pro models. The new MacBooks would be the latest step in Apple's transition away from Intel chips, replacing them with an Arm-based processor called the M1X that Apple designs itself. The new chip could boost performance compared to the M1 chip that debuted last year. Other anticipated features include the return of fan-favorite MacBook features like magnetic MagSafe charging, an HDMI port, and an SD card slot. The maligned OLED touch bar, mercifully, could be on the way out. Bloomberg's Mark Gurman recently noted that stock of the company's existing MacBook Pro appears to be running low.

The Courts

Apple Decides Its Victory Against Epic Wasn't Enough -- It Wants a Total Win (cnbc.com) 62

Apple wants another go in its legal battle against Epic Games. From a report: On Friday night, Apple announced it would ask for a stay on a judge's September order saying Apple would have to allow apps to direct customers to external websites. That ruling would let app businesses circumvent Apple's requirement to facilitate payments only inside of apps, where Apple takes up to a 30% cut. Apple is also appealing the ruling. Because Epic Games is also appealing the nine counts it lost, it could take years before the case is resolved and Apple is forced to make any changes to iOS, the operating system for iPhones, as the two companies wrangle through the appeals process in court. The judge is expected to rule on Apple's request for a stay next month.

Apple's move is a surprising turnaround from its tone following the decision in September. While the company always left open the possibility of an appeal, it portrayed the judge's ruling as a resounding legal win for its App Store business model, which has come under fire from technology rivals, international regulators and members of the U.S. Congress. "We are very pleased with the Court's ruling and we consider this a huge win for Apple," Kate Adams, Apple's lawyer, said in September following the ruling. The Friday night announcement inspired a torrent of commentary from Apple critics. They pointed out the move would preserve Apple's App Store profits by preventing apps from using alternative payment systems. One company announced last week that it was already working on a cheaper, web-based alternative to Apple's app payments -- a move made possible only by the ruling that Apple is now appealing.

Iphone

Google Exec Calls on Apple To Adopt Better, More Secure Text Messaging (cultofmac.com) 66

Google executive Hiroshi Lockheimer has called on Apple to adopt the Rich Communication Services (RCS) protocol that would enable improved and more secure messaging between iPhone and Android devices. From a report: RCS brings a number of modern features -- including support for audio messages, group chats, typing indicators and read receipts -- and end-to-end encryption to traditional text messaging. But it's unlikely Apple will play ball.

[...] Lockheimer, senior vice president for Android, has encouraged the company to change its mind. In response to a tweet about how group chats are incompatible between iPhone and Android devices, Lockheimer said, "group chats don't need to break this way. There exists a Really Clear Solution." "Here's an open invitation to the folks who can make this right: we are here to help." Lockheimer doesn't mention Apple specifically, but it's clear that the "folks" he is referring to are those in Cupertino, who have been against RCS.

Apple

Epic Games CEO Tim Sweeney Calls Out Apple for Promoting Its Services in the iPhone Settings Screen (techcrunch.com) 59

Epic Games CEO Tim Sweeney, whose high-profile antitrust lawsuit against Apple is now under appeal, is today calling out the iPhone maker for giving itself access to an advertising slot its competitors don't have: the iPhone's Settings screen. From a report: Some iOS 15 users noticed Apple is now advertising its own services at the top of their Settings, just below their Apple ID. The services being suggested are personalized to the device owner, based on which ones they already subscribe to, it appears. For example, those without an Apple Music subscription may see an ad offering a free six-month trial. However, current Apple Music subscribers may instead see a prompt to add on a service they don't yet have, like AppleCare coverage for their devices.

Sweeney suggests this sort of first-party advertising is an anticompetitive risk for Apple, as some of the services it's pushing here are those that directly compete with third-party apps published on its App Store. But those third-party apps can't gain access to the iPhone's Settings screen, of course --- they can only bid for ad slots within the App Store itself. Writes Sweeney: "New from the guys who banned Fortnite: settings-screen ads for their own music service, which come before the actual settings, and which aren't available to other advertisers like Spotify or Sound Cloud."

OS X

Steve Jobs Tried To Convince Dell To License Mac Software (cnet.com) 42

It's been 10 years since the death of Steve Jobs. Michael Dell talks about his memories of the tech icon, including when Jobs tried to convince Dell to license Mac software to run on Intel-based PCs. CNET reports: Fast forward to 1993. Jobs, ousted from Apple after a fallout with the company's board in 1985, had started a new company, called Next, and created a beautiful (but expensive) workstation, with its own operating system, as well as software called WebObjects for building web-based applications. Dell says Jobs came to his house in Texas several times that year, trying to convince him to use the Next operating system on Dell PCs, by arguing that it was better than Microsoft's Windows software and could undermine the Unix workstation market being touted by Sun Microsystems. The problem, Dell says he told Jobs, was that there were no applications for it and zero customer interest. Still, Dell's company worked a little bit with Next and used WebObjects to build its first online store in the mid-'90s.

In 1997, Jobs rejoined a struggling Apple after it acquired Next for $429 million, and he pitched Dell on another business proposal (as Jobs was evaluating Apple's Mac clone licensing project, which he ultimately shut down). Jobs and his team had ported the Mac software, based on Next's Mach operating system, and had it running on the Intel x86 chips that powered Dell PCs. Jobs offered to license the Mac OS to Dell, telling him he could give PC buyers a choice of Apple's software or Microsoft's Windows OS installed on their machine. "He said, look at this -- we've got this Dell desktop and it's running Mac OS," Dell tells me. "Why don't you license the Mac OS?" Dell thought it was a great idea and told Jobs he'd pay a licensing fee for every PC sold with the Mac OS. But Jobs had a counteroffer: He was worried that licensing scheme might undermine Apple's own Mac computer sales because Dell computers were less costly. Instead, Dell says, Jobs suggested he just load the Mac OS alongside Windows on every Dell PC and let customers decide which software to use -- and then pay Apple for every Dell PC sold.

Dell smiles when he tells the story. "The royalty he was talking about would amount to hundreds of millions of dollars, and the math just didn't work, because most of our customers, especially larger business customers, didn't really want the Mac operating system," he writes. "Steve's proposal would have been interesting if it was just us saying, "OK, we'll pay you every time we use the Mac OS" -- but to pay him for every time we didn't use it ... well, nice try, Steve!" Another problem: Jobs wouldn't guarantee access to the Mac OS three, four or five years later "even on the same bad terms." That could leave customers who were using Mac OS out of luck as the software evolved, leaving Dell Inc. no way to ensure it could support those users. Still, Dell acknowledges the deal was a what-could-have-been moment in history. [...] That different direction led to Jobs continuing to evolve the Next-inspired Mac OS and retooling the Mac product line, including adding the candy-colored iMac in mid-1998.

Apple

Apple App Store Payment Rules Anti-competitive, Dutch Watchdog Finds (reuters.com) 20

The Dutch antitrust authority has found that Apple's rules requiring software developers to use its in-app payment system are anti-competitive and ordered it to make changes, Reuters reported on Thursday, in the latest regulatory setback for the iPhone maker. From a report: Apple's app-store payment policies, in particular its requirement that app developers exclusively use its payment system where commissions range between 15% and 30%, have long drawn complaints from developers. The Dutch investigation into whether Apple's practices amounted to an abuse of a dominant market position was launched in 2019 but later reduced in scope to focus primarily on dating market apps. They included a complaint from Match Group, owner of the popular dating service Tinder, which said Apple's rules were hindering it from direct communications with its customers about payments. The Netherlands' Authority for Consumers and Markets (ACM) last month informed the U.S. technology giant of its decision, making it the first antitrust regulator to make a finding the company has abused market power in the app store, though Apple is facing challenges in multiple countries.
Japan

Apple and Google Under Antitrust Scrutiny in Japan for Mobile OS (nikkei.com) 9

Japan's Fair Trade Commission will investigate whether Apple and Google are leveraging their dominance in the smartphone operating system market to eliminate competition and severely limit options for consumers. From a report: The study will involve interviews and surveys with OS operators, app developers and smartphone users, commission Secretary-General Shuichi Sugahisa told reporters Wednesday. The initiative will explore market conditions not only for smartphones, but for smartwatches and other wearables. The antitrust watchdog will compile a report outlining OS market structure and the reason why competition has remained static. The commission will work with the central government's Digital Market Competition Council, which is moving forward with its own market probe. Practices found to be anticompetitive will be itemized in the report, along with possible violations of Japan's law against monopolies. In February, the government implemented the Act on Improving Transparency and Fairness of Digital Platforms. If officials decide that the law applies to the OS market, OS operators will be told to submit regular reports on transactions to the Ministry of Economy, Trade and Industry. In Japan, Apple's iOS commands a nearly 70% share among smartphone operating systems while Android's share stands at 30%. Any developer of apps -- whether they specialize in music, streaming videos, e-books or mobile games -- need to match the software with specifications of the operating systems if they want to appear on smartphones.
Privacy

Apple Says Apps Must Offer a Way To Delete Your Account Starting In Early 2022 (engadget.com) 23

Apple says that as of January 31st, 2022, all applications will need to offer people a method of deleting their accounts. This applies to all iOS, iPadOS and macOS apps. Engadget reports: The company announced this requirement alongside other App Store guideline changes at the Apple Worldwide Developers Conference in June as part of a push to give users more control over their data. As The Verge notes, Apple is only requiring developers to let people "initiate deletion of their account from within the app," so apps might send you to a website or even a chat with an agent before you can actually close your account.
EU

Apple To Face EU Antitrust Charge Over NFC Chip (reuters.com) 63

Apple will be hit with an EU antitrust charge over its NFC chip technology -- Reuters reported Wednesday, citing people familiar with the matter -- a move that puts it at risk of a possible hefty fine and could force it to open its mobile payment system to rivals. From a report: The iPhone maker has been in European Union antitrust chief Margrethe Vestager's crosshairs since June last year when she launched an investigation into Apple Pay. Preliminary concerns were Apple's NFC chip which enables tap-and-go payments on iPhones, its terms and conditions on how mobile payment service Apple Pay should be used in merchants' apps and websites, and the company's refusal to allow rivals access to the payment system. The European Commission has since narrowed its focus to just the NFC chip, which can only be accessed by Apple Pay, one of the sources said.
Apple

Remembering Steve Jobs, 10 Years Later (wired.com) 187

Jony Ive: Steve was preoccupied with the nature and quality of his own thinking. He expected so much of himself and worked hard to think with a rare vitality, elegance and discipline. His rigor and tenacity set a dizzyingly high bar. When he could not think satisfactorily he would complain in the same way I would complain about my knees.

As thoughts grew into ideas, however tentative, however fragile, he recognized that this was hallowed ground. He had such a deep understanding and reverence for the creative process. He understood creating should be afforded rare respect -- not only when the ideas were good or the circumstances convenient.

Ideas are fragile. If they were resolved, they would not be ideas, they would be products. It takes determined effort not to be consumed by the problems of a new idea. Problems are easy to articulate and understand, and they take the oxygen. Steve focused on the actual ideas, however partial and unlikely.

I had thought that by now there would be reassuring comfort in the memory of my best friend and creative partner, and of his extraordinary vision.

But of course not. Ten years on, he manages to evade a simple place in my memory. My understanding of him refuses to remain cozy or still. It grows and evolves.

Perhaps it is a comment on the daily roar of opinion and the ugly rush to judge, but now, above all else, I miss his singular and beautiful clarity. Beyond his ideas and vision, I miss his insight that brought order to chaos.

It has nothing to do with his legendary ability to communicate but everything to do with his obsession with simplicity, truth and purity.
Steven Levy, writing at Wired: The prudent thing to do would have been to write Steve Jobs'obituary well ahead of his death. We all knew that he did not have much time. For almost a year, even while Apple stuck to the story -- hoping against hope -- that its cofounder and CEO would make it, the body of the world's most iconic executive was telling a different story. It was saying goodbye, and so was he. My own farewell session had come earlier in the year, in the office he occupied on the fourth floor of One Infinite Loop, Apple's headquarters at the time. Fellow journalist John Markoff and I had set up the meeting specifying no agenda, but all three of us knew it was about closure. It was the middle of the work day, and thousands of people were on campus, but not a single call or visitor interrupted our 90-minute conversation. As if he were already a ghost.

Despite that evidence, I could not bring myself to pre-write that obituary. Call it denial. So when I got the call late in the afternoon of October 5, 2011, that Jobs was gone, I was stunned. And I had nothing. For the next four hours, I banged away on the computer that Steve Jobs ushered into the world and told the story of his life and legacy as best I could, in all its glory and gimcrackery. In the last paragraph of the obituary I never wanted to write, I said, "The full legacy of Steve Jobs will not be sorted out for a very long time." I think we're still sorting it out. There will never be a leader, innovator or personality quite like him. And we're still living in his world.

Apple

Apple Finally Lets You Report App Store Scams (theverge.com) 8

Apple will now let you directly report a scammy app from its listing in the App Store with a new-and-improved version of its "Report a Problem" button. The Verge reports: As Richard Mazkewich and scam hunter Kosta Eleftheriou point out on Twitter, the button has not only returned to individual app listings for the first time in years, it now includes a dedicated "Report a scam or fraud" option in the drop-down menu. Until iOS 15, the only way you could find this button was to scroll all the way down to the bottom of the Apps or Games tab in the App Store, get kicked out to a website where you'd need to re-sign in. Then you could pick from "Report suspicious activity," "Report a quality issue," "Request a refundâ or "Find my content." None of the options offered a clear way to report a scam, and the "Report suspicious activity" would redirect you to Apple Support instead. To add insult to injury, Apple would only let you report "a quality issue" if you'd already paid money (and thus fallen for the scam). But now, it seems like every free app with in-app-purchases appears to offer the "Report a Problem" option. I checked a handful of apps I've never paid for (but could have) and they all displayed the button. You'll still get kicked out to a website where you'll need to sign in, but overall this seems like a step forward.
Safari

The Tragedy of Safari 15 for Mac's 'Tabs' (daringfireball.net) 91

John Gruber shares thoughts on the new ways tabs feel and function on Safari for Mac: From a usability perspective, every single thing about Safari 15's tabs is a regression. Everything. It's a tab design that can only please users who do not use tabs heavily; whereas the old tab design scaled gracefully from "I only open a few tabs at a time" all the way to "I have hundreds of tabs open across multiple windows." That's a disgrace. The Safari team literally invented the standard for how tabs work on MacOS. The tabs that are now available in the Finder, Terminal, and optionally in all document-based Mac apps are derived from the design and implementation of Safari's tabs. Now, Apple has thrown away Safari's tab design -- a tab design that was not just best-of-platform, but arguably best-in-the-whole-damn-world -- and replaced it with a design that is both inferior in the abstract, and utterly inconsistent with the standard tabs across the rest of MacOS.

The skin-deep "looks cool, ship it" nature of Safari 15's tab design is like a fictional UI from a movie or TV show, like Westworld's foldable tablets or Tony Stark's systems from Iron Man, where looking cool is the entirety of the design spec. Something designed not by UI designers but by graphic designers, with no thought whatsoever to the affordances, consistencies, and visual hierarchies essential to actual usability. Just what looks cool. This new tab design shows a complete disregard for the familiarity users have with Safari's existing tab design. Apple never has been and should not be a company that avoids change at all cost. But proper change -- change that breaks users' habits and expectations -- is only justifiable when it's an improvement. Change for change's sake alone is masturbatory. That with Safari 15 it actually makes usability worse, solely for flamboyant cosmetic reasons, is downright perverse.
"Google could and should run ads targeting Safari users, with a simple welcoming message: Switch to Chrome, the Mac browser where tabs look like tabs."
Earth

Apple, Amazon, Microsoft, and Disney Among Companies Backing Groups Against Climate Bill (theguardian.com) 175

mspohr writes: Some of America's most prominent companies, including Apple, Amazon, Microsoft and Disney, are backing business groups that are fighting landmark climate legislation, despite their own promises to combat the climate crisis, a new analysis has found. A clutch of corporate lobby groups and organizations have mobilized to oppose the proposed $3.5tn budget bill put forward by Democrats, which contains unprecedented measures to drive down planet-heating gases. The reconciliation bill has been called the "the most significant climate action in our country's history" by Chuck Schumer, the Democratic leader in the US Senate.

Most large US corporations have expressed concern over the climate crisis or announced their own goals to cut greenhouse gases. Jeff Bezos, one of the world's richest people, has said that the climate crisis is the "biggest threat to our planet" and the company he founded, Amazon, has created a pledge for businesses to cut their emissions to net zero by 2040. Microsoft has promised to be "carbon negative" within a decade from now and Disney is aiming to use only renewable-sourced electricity within the same timeframe. But these leading companies, and others, either support or actively steer the very lobby groups that are attempting to sink the bill that carries the weight of Joe Biden's ambitions to tackle the climate crisis, threatening one of the last major legislative efforts that will help decide whether parts of the world plunge into a new, barely livable climatic state.

IOS

Recent Siri Changes Remove Features Used By Low Vision and Blind Users (macrumors.com) 23

With the recent release of iOS 15, Apple appears to have made some changes to Siri functionality that have removed features relied on by low vision and blind iPhone users. MacRumors reports: Several Siri commands that provide details on phone calls, voicemails, and sending emails no longer appear to be working. The following commands used to be functional, but have recently been removed: Do I have any voicemails?, Play my voicemail messages, Check my call history, Check my recent calls, Who called me?, Send an email, and Send an email to [person]. Over the last two weeks, we've received several emails from iPhone users who are missing this key Siri functionality, or their relatives who are attempting to help them navigate the changes. The Siri feature removals have also been documented on the AppleVis forums for blind and low vision users of Apple products. Asking Siri to provide details on recent phone calls or voicemails results in the following response: "I can't help with that, but you can ask me to open the Phone app."

Asking about email garners a similar response about Siri being unable to help. It's worth noting that it's still possible to ask Siri to play the most recent voicemail message that's available, or a voicemail from a specific person, but Siri will not read out a list of all the available voicemails. The Siri commands seem to have disappeared when iOS 15 was released, but iOS 14 users are also not able to use them anymore so it's not an issue tied to iOS 15.

Security

Apple Pay With Visa Hacked To Make Payments Via Unlocked iPhones (threatpost.com) 48

Researchers have demonstrated that someone could use a stolen, unlocked iPhone to pay for thousands of dollars of goods or services, no authentication needed. Threatpost reports: An attacker who steals a locked iPhone can use a stored Visa card to make contactless payments worth up to thousands of dollars without unlocking the phone, researchers are warning. The problem is due to unpatched vulnerabilities in both the Apple Pay and Visa systems, according to an academic team from the Universities of Birmingham and Surrey, backed by the U.K.'s National Cyber Security Centre (NCSC). But Visa, for its part, said that Apple Pay payments are secure and that any real-world attacks would be difficult to carry out.

The team explained that fraudulent tap-and-go payments at card readers can be made using any iPhone that has a Visa card set up in "Express Transit" mode. Express Transit allows commuters around the world, including those riding the New York City subway, the Chicago El and the London Underground, to tap their phones on a reader to pay their fares without unlocking their devices. "An attacker only needs a stolen, powered-on iPhone," according to a writeup (PDF) published this week. "The transactions could also be relayed from an iPhone inside someone's bag, without their knowledge. The attacker needs no assistance from the merchant."

This attack is made possible by a combination of flaws in both Apple Pay and Visa's systems, the academic team noted. "The details of this vulnerability have been disclosed to Apple (Oct 2020) and to Visa (May 2021)," according to the writeup. "Both parties acknowledge the seriousness of the vulnerability, but have not come to an agreement on which party should implement a fix." "Variations of contactless-fraud schemes have been studied in laboratory settings for more than a decade and have proven to be impractical to execute at scale in the real world," Visa said in a statement to the BBC, adding that its fraud-detection systems would flag any suspicious transactions. Apple meanwhile shifted the responsibility to Visa and told the outlet, "We take any threat to users' security very seriously. This is a concern with a Visa system, but Visa does not believe this kind of fraud is likely to take place in the real world given the multiple layers of security in place. In the unlikely event that an unauthorized payment does occur, Visa has made it clear that their cardholders are protected by Visa's zero-liability policy."
The researchers say users can protect themselves by not using Visa as a transport card in Apple Pay, and if they do, by remotely wiping the device if lost or stolen. The bug does not affect other types of payment cards or payment systems.

Slashdot Top Deals