Monday, 1 June 2020

This Dell laptop is the best Windows alternative to the Apple MacBook Pro 16

Let’s be clear, straight off the bat; the 16-inch Apple MacBook Pro is the most powerful lightweight laptop money can buy right now. There is no laptop of this size on the market that boasts 8TB of storage and 64GB of RAM. At just over 16mm in thickness and with a weight of 2kg, it truly is a technological feat.

The Macbook Pro's nearest rival, however, has to be the Dell XPS 15 9500. It doesn’t quite carry the same cachet as Apple’s newest machine, but still has a few cards up its sleeve if you're looking for a Windows 10 PC that's at least in the same ballpark.

Note, this particular XPS 15 model is not currently on offer and is only available in the US. For some reason, Dell thinks the rest of the world doesn't deserve a thin-and-light laptop with 64GB of memory.

Gunning for the MacBook Pro

The top-of-the-range XPS 15 model actually shares a lot of similarities with the MacBook; it has a similar CPU (8-core, 16MB cache and a 45W TDP), 64GB of memory and 2TB PCIe SSD.

It features a smaller 15.6-inch touchscreen display, but it's an OLED model with a 4K resolution, making it sharper than Apple’s. It's powered by an Nvidia Geforce GTX 1650 GPU with 4GB of video memory, which is more than a match for the AMD Radeon Pro 5500M in the MacBook Pro.

As you might expect, Dell has the upper hand when it comes to pricing. At $3,049.99 (around £2,500/AU$4,500) with Windows 10 Home instead of Pro, the XPS 15 undercuts Apple’s equivalent by a staggering 27%, with the equivalent MacBook Pro 16 coming in at $4,199 (roughly £3,370/AU$6,200).

The comparison becomes even less favorable for Apple when you factor in warranty and services. AppleCare+ for the new MacBook Pro costs $379 and includes a three-year warranty, two incidents of accidental damage and 24/7 priority access to Apple experts. Dell, on the other hand, provides 4-year ProSupport Plus (with next business day onsite service and accidental damage service) for $360, which is both better value and cheaper.

The XPS 15 might not garner the same attention and acclaim as Apple's machine, but its many qualities and cheaper price tag make it a serious contender.

Bear in mind

  • If this XPS 15 model is not available in your territory, you may have to use a specialist parcel forwarding service if you want to take advantage of the deal.
  • If you've managed to get hold of a cheaper product with equivalent specifications, in stock and brand new, let us know and we'll tip our hat to you.
https://ift.tt/3csTTgS

This Dell laptop is the best Windows alternative to the Apple MacBook Pro 16

Let’s be clear, straight off the bat; the 16-inch Apple MacBook Pro is the most powerful lightweight laptop money can buy right now. There is no laptop of this size on the market that boasts 8TB of storage and 64GB of RAM. At just over 16mm in thickness and with a weight of 2kg, it truly is a technological feat.

The Macbook Pro's nearest rival, however, has to be the Dell XPS 15 9500. It doesn’t quite carry the same cachet as Apple’s newest machine, but still has a few cards up its sleeve if you're looking for a Windows 10 PC that's at least in the same ballpark.

Note, this particular XPS 15 model is not currently on offer and is only available in the US. For some reason, Dell thinks the rest of the world doesn't deserve a thin-and-light laptop with 64GB of memory.

Gunning for the MacBook Pro

The top-of-the-range XPS 15 model actually shares a lot of similarities with the MacBook; it has a similar CPU (8-core, 16MB cache and a 45W TDP), 64GB of memory and 2TB PCIe SSD.

It features a smaller 15.6-inch touchscreen display, but it's an OLED model with a 4K resolution, making it sharper than Apple’s. It's powered by an Nvidia Geforce GTX 1650 GPU with 4GB of video memory, which is more than a match for the AMD Radeon Pro 5500M in the MacBook Pro.

As you might expect, Dell has the upper hand when it comes to pricing. At $3,049.99 (around £2,500/AU$4,500) with Windows 10 Home instead of Pro, the XPS 15 undercuts Apple’s equivalent by a staggering 27%, with the equivalent MacBook Pro 16 coming in at $4,199 (roughly £3,370/AU$6,200).

The comparison becomes even less favorable for Apple when you factor in warranty and services. AppleCare+ for the new MacBook Pro costs $379 and includes a three-year warranty, two incidents of accidental damage and 24/7 priority access to Apple experts. Dell, on the other hand, provides 4-year ProSupport Plus (with next business day onsite service and accidental damage service) for $360, which is both better value and cheaper.

The XPS 15 might not garner the same attention and acclaim as Apple's machine, but its many qualities and cheaper price tag make it a serious contender.

Bear in mind

  • If this XPS 15 model is not available in your territory, you may have to use a specialist parcel forwarding service if you want to take advantage of the deal.
  • If you've managed to get hold of a cheaper product with equivalent specifications, in stock and brand new, let us know and we'll tip our hat to you.
https://ift.tt/3csTTgS

Sign in with Apple vulnerability could have led to account takeovers

A critical vulnerability in Apple's 'Sign in with Apple' system could have allowed remote attackers to take over targeted user accounts on third-party services and apps.

The company's Sign in with Apple feature, which launched at WWDC 2019, gives users the ability to login to third-party apps and websites using their Apple ID. The feature also helps protect users' privacy as they can use its 'hide my email' function to withhold their email addresses from apps and sites.

Independent security researcher Bhavuk Jain first discovered the bug in Sign in with Apple last month and the company paid him a $100,000 bug bounty after he responsibly disclosed it. In a blog post, Jain explained just how serious this now-patched vulnerability could have been, saying: 

“The impact of this vulnerability was quite critical as it could have allowed full account takeover. A lot of developers have integrated Sign in with Apple since it is mandatory for applications that support other social logins. To name a few that use Sign in with Apple - Dropbox, Spotify, Airbnb, Giphy (Now acquired by Facebook). These applications were not tested but could have been vulnerable to a full account takeover if there weren’t any other security measures in place while verifying a user.”

Sign in with Apple

The Sign in with Apple system works in a similar way to OAuth 2.0 and users can be authenticated by either using a JSON Web Token (JWT) or a code generated by the company's server which is then used to generate a JWT.

Jain discovered that he could request JWTs for any Email ID from Apple and when the signature of these tokens was verified using Apple's public key, they showed as valid. As a result, an attacker could forge a JWT by linking any Email ID to it and this would grant them access to the victim's linked accounts.

After Jain submitted his findings to Apple, the company conducted an investigation of its logs and determined that there was no misuse or account compromise that exploited the vulnerability.

Thankfully Jain disclosed the vulnerability in a timely manner before it could become a zero-day where a flaw is discovered and exploited before a fix for the issue is made available.

Via The Hacker News

https://ift.tt/3eGWOUS

Sign in with Apple vulnerability could have led to account takeovers

A critical vulnerability in Apple's 'Sign in with Apple' system could have allowed remote attackers to take over targeted user accounts on third-party services and apps.

The company's Sign in with Apple feature, which launched at WWDC 2019, gives users the ability to login to third-party apps and websites using their Apple ID. The feature also helps protect users' privacy as they can use its 'hide my email' function to withhold their email addresses from apps and sites.

Independent security researcher Bhavuk Jain first discovered the bug in Sign in with Apple last month and the company paid him a $100,000 bug bounty after he responsibly disclosed it. In a blog post, Jain explained just how serious this now-patched vulnerability could have been, saying: 

“The impact of this vulnerability was quite critical as it could have allowed full account takeover. A lot of developers have integrated Sign in with Apple since it is mandatory for applications that support other social logins. To name a few that use Sign in with Apple - Dropbox, Spotify, Airbnb, Giphy (Now acquired by Facebook). These applications were not tested but could have been vulnerable to a full account takeover if there weren’t any other security measures in place while verifying a user.”

Sign in with Apple

The Sign in with Apple system works in a similar way to OAuth 2.0 and users can be authenticated by either using a JSON Web Token (JWT) or a code generated by the company's server which is then used to generate a JWT.

Jain discovered that he could request JWTs for any Email ID from Apple and when the signature of these tokens was verified using Apple's public key, they showed as valid. As a result, an attacker could forge a JWT by linking any Email ID to it and this would grant them access to the victim's linked accounts.

After Jain submitted his findings to Apple, the company conducted an investigation of its logs and determined that there was no misuse or account compromise that exploited the vulnerability.

Thankfully Jain disclosed the vulnerability in a timely manner before it could become a zero-day where a flaw is discovered and exploited before a fix for the issue is made available.

Via The Hacker News

https://ift.tt/3eGWOUS

Sign in with Apple vulnerability could have led to account takeovers

A critical vulnerability in Apple's 'Sign in with Apple' system could have allowed remote attackers to take over targeted user accounts on third-party services and apps.

The company's Sign in with Apple feature, which launched at WWDC 2019, gives users the ability to login to third-party apps and websites using their Apple ID. The feature also helps protect users' privacy as they can use its 'hide my email' function to withhold their email addresses from apps and sites.

Independent security researcher Bhavuk Jain first discovered the bug in Sign in with Apple last month and the company paid him a $100,000 bug bounty after he responsibly disclosed it. In a blog post, Jain explained just how serious this now-patched vulnerability could have been, saying: 

“The impact of this vulnerability was quite critical as it could have allowed full account takeover. A lot of developers have integrated Sign in with Apple since it is mandatory for applications that support other social logins. To name a few that use Sign in with Apple - Dropbox, Spotify, Airbnb, Giphy (Now acquired by Facebook). These applications were not tested but could have been vulnerable to a full account takeover if there weren’t any other security measures in place while verifying a user.”

Sign in with Apple

The Sign in with Apple system works in a similar way to OAuth 2.0 and users can be authenticated by either using a JSON Web Token (JWT) or a code generated by the company's server which is then used to generate a JWT.

Jain discovered that he could request JWTs for any Email ID from Apple and when the signature of these tokens was verified using Apple's public key, they showed as valid. As a result, an attacker could forge a JWT by linking any Email ID to it and this would grant them access to the victim's linked accounts.

After Jain submitted his findings to Apple, the company conducted an investigation of its logs and determined that there was no misuse or account compromise that exploited the vulnerability.

Thankfully Jain disclosed the vulnerability in a timely manner before it could become a zero-day where a flaw is discovered and exploited before a fix for the issue is made available.

Via The Hacker News

https://ift.tt/3eGWOUS

Sign in with Apple vulnerability could have led to account takeovers

A critical vulnerability in Apple's 'Sign in with Apple' system could have allowed remote attackers to take over targeted user accounts on third-party services and apps.

The company's Sign in with Apple feature, which launched at WWDC 2019, gives users the ability to login to third-party apps and websites using their Apple ID. The feature also helps protect users' privacy as they can use its 'hide my email' function to withhold their email addresses from apps and sites.

Independent security researcher Bhavuk Jain first discovered the bug in Sign in with Apple last month and the company paid him a $100,000 bug bounty after he responsibly disclosed it. In a blog post, Jain explained just how serious this now-patched vulnerability could have been, saying: 

“The impact of this vulnerability was quite critical as it could have allowed full account takeover. A lot of developers have integrated Sign in with Apple since it is mandatory for applications that support other social logins. To name a few that use Sign in with Apple - Dropbox, Spotify, Airbnb, Giphy (Now acquired by Facebook). These applications were not tested but could have been vulnerable to a full account takeover if there weren’t any other security measures in place while verifying a user.”

Sign in with Apple

The Sign in with Apple system works in a similar way to OAuth 2.0 and users can be authenticated by either using a JSON Web Token (JWT) or a code generated by the company's server which is then used to generate a JWT.

Jain discovered that he could request JWTs for any Email ID from Apple and when the signature of these tokens was verified using Apple's public key, they showed as valid. As a result, an attacker could forge a JWT by linking any Email ID to it and this would grant them access to the victim's linked accounts.

After Jain submitted his findings to Apple, the company conducted an investigation of its logs and determined that there was no misuse or account compromise that exploited the vulnerability.

Thankfully Jain disclosed the vulnerability in a timely manner before it could become a zero-day where a flaw is discovered and exploited before a fix for the issue is made available.

Via The Hacker News

https://ift.tt/3eGWOUS

Twitter restricts Republican lawmaker’s Antifa tweet for ‘glorifying violence’

Twitter placed a tweet from a close political ally of the president behind a warning label Monday, citing its policy prohibiting content that promotes violence.

The tweet, from Republican Florida Rep. Matt Gaetz, suggested that the U.S. government “hunt down” anti-fascist activists in the country like it would pursue international terrorists.

“We have placed a public interest notice on this Tweet from @mattgaetz,” a Twitter spokesperson told TechCrunch, linking its platform policy page. Twitter users can still share the tweet with comment, but regular retweets, likes and replies have been deactivated.

Consistent with its previously announced policy concerning tweets from public figures that violate its rules, Twitter left the post up but placed it behind a note.  “We want to make it clear today that the accounts of world leaders are not above our policies entirely,” Twitter wrote in the policy, released last year. “… We will err on the side of leaving the content up if there is a clear public interest in doing so.”

This story is developing.



https://ift.tt/3gIVfHA