This Week in Security: Code Scanning, Information Gathering, and Seams in the Cloud

GitHub has enabled free code analysis on public repositories. This is the fruit of the purchase of Semmle, almost exactly one year ago. Anyone with write permissions to a repository can go into the settings, and enable scanning. Beyond the obvious use case of finding vulnerabilities, an exciting option is …read more

Continue reading This Week in Security: Code Scanning, Information Gathering, and Seams in the Cloud

The Prototype iPhones That Hackers Use to Research Apple’s Most Sensitive Code

Very few people have heard of them, but “dev-fused” iPhones sold on the grey market are one of the most important tools for the best iOS hackers in the world. Continue reading The Prototype iPhones That Hackers Use to Research Apple’s Most Sensitive Code

How a Low-Level Apple Employee Leaked Some of the iPhone’s Most Sensitive Code

This is how a small group of friends lost control of the leaked iBoot source code. The story behind one of Apple’s most embarrassing leaks. Continue reading How a Low-Level Apple Employee Leaked Some of the iPhone’s Most Sensitive Code