Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Mobile & Wireless

Apple’s iOS 6 to Enforce Strict Data Permissions

A story published by online Mac OS-related news site Mac Rumors outlines a new requirement for applications running on iOS 6 – strict privacy enforcement. The requirements were explained in the release notes for iOS 6, and seem to address some of the privacy issues Apple has had to contend with lately.

A story published by online Mac OS-related news site Mac Rumors outlines a new requirement for applications running on iOS 6 – strict privacy enforcement. The requirements were explained in the release notes for iOS 6, and seem to address some of the privacy issues Apple has had to contend with lately.

According to the Mac Rumors report, starting with iOS 6, apps will be required to get explicit user permission before they can access calendars, reminders, contacts, and photos.

iOS 6 Logo“For contact, calendar, and reminder data, your app needs to be prepared to be denied access to these items and to adjust its behavior accordingly. If the user has not yet been prompted to allow access, the returned structure is valid but contains no records. If the user has denied access, the app receives a NULL value or no data. If the user grants permission to the app, the system subsequently notifies the app that it needs to reload or revert the data,” the developer notes explain.

Such privacy features would have been useful to users of the LinkedIn application that was found to be harvesting calendar information. The information collection was part of an opt-in feature, but most users were unaware of the data collection or that they could opt out. However, going forward, issues such as this should be prevented.

In related news, Apple recently released a document that examines the security technology and features implemented within iOS itself. While none of the information is new or unknown, the guide is noteworthy, if only because it offers an official basic list of best practices to organizations wishing to deploy Apple devices. Some of the items discussed in the guide will be discussed this summer at the Black Hat Security Conference in Las Vegas. Dallas De Atley, manager of the Apple platform security team, is slated to give a talk on iOS security according to conference materials.

Source: MacRumors.com  

Advertisement. Scroll to continue reading.
Written By

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.