{"id":9746,"date":"2017-10-07T04:45:07","date_gmt":"2017-10-07T12:45:07","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/10\/07\/news-3519\/"},"modified":"2017-10-07T04:45:07","modified_gmt":"2017-10-07T12:45:07","slug":"news-3519","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/10\/07\/news-3519\/","title":{"rendered":"Go Update Your Mac ASAP To Fix Some Serious Vulnerabilities"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/59d81c7210b45f0adcf17634\/master\/pass\/AppleUpdate-FA-539935188.jpg\"\/><\/p>\n<p><strong>Credit to Author: Wired Staff| Date: Sat, 07 Oct 2017 12:00:00 +0000<\/strong><\/p>\n<p data-reactid=\"247\"><span class=\"lede\" data-reactid=\"248\">This week saw <\/span><!-- react-text: 249 -->a tragic start, when late Sunday night a man named Stephen Paddock killed 58 people and wounded hundreds more in Las Vegas. <!-- \/react-text --><a href=\"https:\/\/www.wired.com\/story\/las-vegas-shooting-misinformation-hoaxes-conspiracies\/\" data-reactid=\"250\">Hoaxes and conspiracy theories<\/a><!-- react-text: 251 --> flooded the internet in the immediate aftermath, as did questions\u2014since answered\u2014around how <!-- \/react-text --><a href=\"https:\/\/www.wired.com\/story\/las-vegas-shooting-automatic-rifle\/\" data-reactid=\"252\">Paddock was able to fire at automatic speeds<\/a><!-- react-text: 253 -->. We also <!-- \/react-text --><a href=\"https:\/\/www.wired.com\/story\/smart-guns-mass-shootings\/\" data-reactid=\"254\">took a look at gun-control tech<\/a><!-- react-text: 255 -->\u2014but didn&#x27;t find much that&#x27;s promising.<!-- \/react-text --><\/p>\n<p data-reactid=\"256\"><!-- react-text: 257 -->There&#x27;s at least a little levity\u2014although more tragicomic, really\u2014in Yahoo announcing that its one-billion account leak in 2013 was actually <!-- \/react-text --><a href=\"https:\/\/www.wired.com\/story\/yahoo-breach-three-billion-accounts\/\" data-reactid=\"258\">a three-billion account leak<\/a><!-- react-text: 259 -->. You also might enjoy this handy guide to <!-- \/react-text --><a href=\"https:\/\/www.wired.com\/story\/tell-when-someone-else-tweets-from-realdonaldtrump\/\" data-reactid=\"260\">when Donald Trump is tweeting<\/a><!-- react-text: 261 -->, and when one of his staffers has commandeered his account. Also, the Department of Energy&#x27;s email about <!-- \/react-text --><a href=\"https:\/\/www.wired.com\/story\/leaked-anti-leak-training-email-department-of-energy\/\" data-reactid=\"262\">not leaking leaked<\/a><!-- react-text: 263 -->, so that&#x27;s fun.<!-- \/react-text --><\/p>\n<p data-reactid=\"264\"><!-- react-text: 265 -->OK, back to terrible things. There&#x27;s been an alarming rise in <!-- \/react-text --><a href=\"https:\/\/www.wired.com\/story\/cyberattacks-against-abortion-clinics\/\" data-reactid=\"266\">cyberattacks against abortion clinics lately<\/a><!-- react-text: 267 -->. Another <!-- \/react-text --><a href=\"https:\/\/www.wired.com\/story\/nsa-contractors-hacking-tools\/\" data-reactid=\"268\">NSA contractor let critical data slip<\/a><!-- react-text: 269 -->. The <!-- \/react-text --><a href=\"https:\/\/www.wired.com\/story\/equifax-ceo-congress-testimony\/\" data-reactid=\"270\">Equifax leak took on a terrible new dimensions<\/a><!-- react-text: 271 --> in the form of a Congressional hearing. And <!-- \/react-text --><a href=\"https:\/\/www.wired.com\/story\/john-kelly-hacked-phone\/\" data-reactid=\"272\">Chief of Staff John Kelly&#x27;s personal phone got compromised<\/a><!-- react-text: 273 --> last December, which invites all sorts of potential terrible results.<!-- \/react-text --><\/p>\n<p data-reactid=\"274\">And yet, somehow, there&#x27;s more!  As always, we\u2019ve rounded up all the news we didn\u2019t break or cover in depth this week. Click on the headlines to read the full stories.<\/p>\n<p data-reactid=\"277\">On Thursday, Apple released the first update to High Sierra, the new macOS operating system that debuted at the end of September. And it\u2019s an important one. High Sierra 10.13 had two disappointing credential security bugs at launch, but Apple says that both have been patched in this update. One is a bug that could have let attackers use a third-party app to pilfer usernames and passwords from macOS\u2019s Keychain tool that stores credentials. The other is a flaw that revealed plain text passwords in the password hint for encrypted Apple File Systems volumes. If you added disk encryption with a hint, the plain text of your password would show up in the hint field in the Disk Utility. No bueno. If you already created an encrypted volume before you installed the update, you\u2019ll need to back it up, wipe the drive, reformat the File Systems volume, and then restore from the backup. Either way, use Apple\u2019s \u201cSoftware Update\u201d tool to download the patch. Like&#8230;right now.<\/p>\n<p data-reactid=\"282\"><!-- react-text: 283 -->Google&#x27;s <!-- \/react-text --><a href=\"https:\/\/www.wired.com\/2014\/07\/google-project-zero\/\" data-reactid=\"284\">elite Project Zero team<\/a><!-- react-text: 285 --> of cybersecurity specialists has called out Microsoft for issuing patches inconsistently, and in a manner that could tip off attackers to vulnerabilities in older versions of the operating system. The fix, Google says, is just to apply the same updates across all iterations, so that hackers can&#x27;t infer what vulnerabilities might be hiding where based on a given patch.<!-- \/react-text --><\/p>\n<p data-reactid=\"288\"><!-- react-text: 289 -->Technically this happened last week, but for hopefully understandable reasons we&#x27;re still mentioning here. Authorities recently apprehended Gal Vallerius in connection with selling drugs on the dark web bazaar Dream Market, allegedly under the handle OxyMonster. While Vallerius lives in France, the feds picked him up in Atlanta, as he was traveling to a &quot;world beard-growing championship&quot; in Austin, Texas. The dark web markets have been in a bit of chaos ever since this summer&#x27;s <!-- \/react-text --><a href=\"https:\/\/www.wired.com\/story\/alphabay-hansa-takedown-dark-web-trap\/\" data-reactid=\"290\">Alphabay and Hansa takedowns<\/a><!-- react-text: 291 -->, but have rarely seen such a hairy situation.<!-- \/react-text --><\/p>\n<p class=\"related-cne-video-component__dek\" data-reactid=\"301\">Look, we get it. Remembering dozens and dozens of different passwords for different sites is next to impossible. But that doesn\u2019t mean you should be reusing your passwords. That\u2019s just asking for trouble.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/update-macos-high-sierra-security-patch\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/59d81c7210b45f0adcf17634\/master\/pass\/AppleUpdate-FA-539935188.jpg\"\/><\/p>\n<p><strong>Credit to Author: Wired Staff| Date: Sat, 07 Oct 2017 12:00:00 +0000<\/strong><\/p>\n<p>Las Vegas, another NSA contractor slip-up, and more of the week&#8217;s top security news.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714],"class_list":["post-9746","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/9746","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=9746"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/9746\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=9746"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=9746"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=9746"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}