Skip to main content
  1. Home
  2. Computing
  3. News

Apple’s security trumps Microsoft and Twitter’s, say feds

Add as a preferred source on Google

Apple has long held a reputation for rock-solid security, and now the U.S. government seemingly agrees after praising the company for its security procedures. At the same time, the feds have suggested Microsoft and Twitter need to pull their socks up and make their products much more secure for their users, according to CNBC.

In a speech given at Carnegie Mellon University, Cybersecurity and Infrastructure Security Agency Director Jen Easterly pointed to Apple as a company that took security and accountability seriously, and suggested other companies should take note.

Apple's Craig Federighi speaking about macOS security at WWDC 2022.
Apple

Easterly gave the example of Apple’s iCloud security practices, which enable multi-factor authentication (MFA) by default. As a result, 95% of iCloud users have MFA switched on, greatly improving security.

Recommended Videos

Multi-factor authentication means a unique code is sent to a separate device from the one that is attempting to log in, which can help to thwart hackers who may have gained access to a single device. Easterly said the high rate of iCloud MFA adoption was due to Apple’s proactive approach of “taking ownership for the security outcomes of their users.”

In contrast, Easterly said that companies like Microsoft and Twitter had much lower rates of MFA adoption (only 3% of users in Twitter’s case) and that this was “disappointing.”

‘Radical transparency’

Window's new Microsoft Security Experts program works to protect users from cybercrime using.
Windows

Microsoft and Twitter received praise for at least disclosing how many of their users had MFA enabled, even if it didn’t look great for the companies involved. “By providing radical transparency around MFA adoption, these organizations are helping shine a light on the necessity of security by default,” Easterly explained. “More should follow their lead.”

That said, Twitter has just hidden SMS security authentication behind its Twitter Blue paywall, which could be seen as a backward step when it comes to making your Twitter account more secure. You can still enable Twitter MFA using a third-party authenticator app, though, which is more secure than SMS authentication anyway.

Aside from that, Easterly touched on the idea of new legislation, which should “prevent technology manufacturers from disclaiming liability by contract,” she said. Its goals should also include “establishing higher standards of care for software in specific critical infrastructure entities, and driving the development of a safe harbor framework to shield from liability companies that securely develop and maintain their software products and services.”

Apple’s security prowess doesn’t just come from its enabling MFA by default. Apps are sandboxed so they can’t access critical parts of the operating system, while Apple chips contain a secure enclave to handle sensitive data. It looks like those protections and more convinced the U.S. government that Apple was worth singling out for praise.

Alex Blake
Alex Blake has been working with Digital Trends since 2019, where he spends most of his time writing about Mac computers…
Deepfake bosses are crashing video calls, and researchers are trying to expose them
Seeing your boss on video no longer proves they are real
Researchers at Fraunhofer SIT are fighting against deepfake meeting video calls

Entering into a meeting with your boss and several familiar coworkers inside a video conference is the next area vulnerable to cybercrimes, and it's all because of deepfake technology. Researchers at the Fraunhofer Institute for Secure Information Technology SIT are working on a real-time warning system designed to identify attempted fraud during corporate video conferences.

The report states that criminals are increasingly targeting video meetings for identity theft and financial scams, taking advantage of the trust people place in familiar faces and voices. The intention is to flag suspicious activity while the meeting is still taking place. This gives an employee a chance to stop before following an expensive instruction from an AI-generated executive.

Read more
Apple will finally stop making iPhone-to-Windows copy-paste such a chore
Your iPhone may finally copy and paste with a Windows PC like it should
Apple Universal Clipboard feature

Copying something on an iPhone and pasting it onto a Windows PC should be one of the least remarkable features imaginable. While this simple process seems effortless between an iPhone and Mac, Windows users are still left waiting.

Now, Microsoft is formally asking Apple to provide interoperable clipboard access through the company’s European Union interoperability process. The request, submitted on March 25, argues that iOS restrictions prevent third-party platforms from creating an experience comparable to Apple’s Universal Clipboard. Apple has now reached Phase III and committed to developing a solution.

Read more
Chrome wants more extension reviews, but good ratings won’t keep malware out
Google is testing built-in extension review prompts, but good ratings can still hide malware
malicious-google-chrome-extensions-on-web-store

Google is preparing to add extension review links directly inside Chrome, putting feedback closer to the menus people already use to manage their add-ons.

A Chromium change, first spotted by Windows Report, points to review options in the Extensions menu, the chrome://extensions management page, and extension context menus. Only eligible Chrome Web Store extensions in good standing would qualify, and the feature is still under development.

Read more