Big Tech is Finally Moving Toward Security Features - Threat Wire

Quick Overview

Big Tech companies like Apple, Meta, and Microsoft are increasing their focus on security features, with Apple limiting location tracking via cell towers, Microsoft phasing out the NTLM protocol in favor of Kerberos, and Meta introducing a 'Strict Account Settings' mode for high-risk WhatsApp users, while the open-source community faces risks from supply chain attacks like the XZ Utils backdoor and the end-of-life announcement for Ingress NGINX.

Key Points: Apple is rolling out a new privacy feature to limit the precision of location data shared with cellular networks, restricting tracking distance from cell towers. Microsoft is phasing out the New Technology LAN Manager (NTLM) authentication protocol in favor of stronger Kerberos-based alternatives, providing a plan for organizations to transition before Windows Server end-of-life support for NTLM. Meta introduced 'Strict Account Settings' for WhatsApp, a lockdown-style security mode aimed at protecting high-risk users, such as journalists and activists, from advanced spyware attacks. A former Google engineer was convicted on seven counts of economic espionage and theft of trade secrets for stealing thousands of documents related to AI supercomputer orchestration software and custom machine learning chips to build a startup in China. The Ingress NGINX open-source project announced its end-of-life date for March 2026, meaning no more bug fixes or patches will be released, urging users to migrate to alternatives like Gateway API. The XZ Utils backdoor, which aimed to create a backdoor allowing authentication bypass on Linux systems, was successfully mitigated because the community, including a Slack user, flagged the suspicious activity, preventing widespread compromise. The DDoSecrets group changed its primary domain from .com to .org following domain renewal failures, prompting an official notice to its audience.

Context: This episode of Threat Wire, hosted by Ally Diamond, covers several recent cybersecurity and privacy developments involving major tech companies and open-source projects. The main segments focus on new security measures being implemented by Apple, Meta, and Microsoft, alongside critical vulnerabilities and incidents affecting open-source software like XZ Utils and Ingress NGINX, highlighting ongoing efforts by both corporate giants and the open-source community to enhance digital security.

Raw markdown version of this recap