F-Secure Acquires Jonathan Zdziarski's Mac Security App 'Little Flocker'

by

Cyber security company F-Secure has acquired Little Flocker, the behavioral analysis-based monitoring app for Macs, developed by iPhone forensics expert and security researcher Jonathan Zdziarski, who joined Apple last month.

The Helsinki-based firm announced the news in a press release posted to its site, where it revealed that Little Flocker would be built into a new security product it's releasing, called XFENCE.


Little Flocker protects Macs by using advanced behavioral based analysis, and monitors apps that attempt to access confidential files and system resources. It also detects and blocks Mac ransomware. F-Secure will build Little Flocker's next-generation security engine into its new XFENCE technology. XFENCE will complement F-Secure's existing endpoint solutions to provide advanced behavioral Mac protection for both corporate and consumer customers.

F-Secure said that the "myth" of Macs not requiring protection against ransomware, backdoors, and other software was fading away, due to "Apple's popularity among senior-level employees and other high-value targets". By acquiring Little Flocker, it said it hoped to further enhance its products' existing cyber security capabilities for the sophisticated detection of zero-day attacks.

For businesses, the core technology is to be combined with F-Secure’s security cloud and packaged into its Protection Service for Business, a security solution with centrally managed computer, mobile and server security with integrated patch management and mobile device management. Consumer customers can make use of the Flocker technology with F-Secure Safe, the company's multi-device security product.

Little Flocker developer Zdziarski announced in March that he was joining Apple's Security Engineering and Architecture team. Known as "NerveGas" within the jailbreaking community, Zdziarski had provided input on a number of important iOS-related security matters over the years, including Apple's high-profile battle with the FBI over unlocking an iPhone used by a shooter in the 2015 San Bernardino attack.

Top Rated Comments

(View all)
Avatar
45 months ago

I have this app. I'm amazed at what it picks up. For example, App Store wants to access my camera when it starts up, I'd like to know why!

The camera can be used to snap a photo of prepaid/gift card codes so that you don't have to enter a crazy long string of numbers manually. Lots of people pay for their App Store and iTunes purchases this way.
Score: 9 Votes (Like | Disagree)
Avatar
45 months ago

I was unaware of that, do you have any links that detail this?

Thanks

You should check out a site called Mac rumors, they covered it...

https://www.macrumors.com/2016/03/06/mac-ransomware-transmission/
Score: 6 Votes (Like | Disagree)
Avatar
45 months ago

I like Zdziarski so I went to F-Secure and read about it. Sounds useful. Read up on their vpn-service Freedome as well. They offer a vpn-service to private persons and then they use technology to block protocols in their customers traffic. As a customer you will not know this unless your read their fine-print. And logging they do of course.

So from a Privacy-prespective F-Secure suck. I don't like them not being upfront with their vpn-service as well.

I'll scrutinise their EULA for XFence before I decide if it's interesting.
[doublepost=1491497352][/doublepost]

It's an honest question. Be nice :D

Hi, please read https://www.f-secure.com/en/web/legal/privacy/freedome-no-nav for more information about privacy with Freedome. Working at F-Secure, I can say that our company does care a LOT about privacy, and at least I do not consider us sucking so much in that sense :) We jump a few extra hoops to further anonymise the collected data.

Yes, you probably get even more privacy by using something like Tor, but Freedome is offering security as well. Related article here: https://www.opswat.com/blog/malware-spread-tor-exit-node
Without trying to advertise too much, there was also a university research recently (linked in the article), where Freedome was found to be amongst the better VPN clients for security: https://arstechnica.com/security/2017/01/majority-of-android-vpns-cant-be-trusted-to-make-users-more-secure/

Finally, Finland has pretty good privacy laws but like any country, the legislation still pose some requirements for providing these services.
[doublepost=1491810684][/doublepost]

I'm in the same boat. I'm guessing we early adopters get the shaft for supporting him at the beginning. As an Apple employee he pretty much has to wash his hands of the whole affair, and the new corporate overlords aren't going to give a **** about the few of us who knew about it before now.

Hello, one of the corporate overlords here, and giving a world about the few of you. No plans on shafting anyone ;) Instead we have been discussing about how to reach you early adopters to find a way for you to keep running and updating the product. Would love to hear from all of you and get valuable feedback in future too, so stay tuned.
Score: 3 Votes (Like | Disagree)
Avatar
42 months ago

The long way to show hidden Mac OS X files is as follows:
[LIST=1]
* Open Terminal found in Finder > Applications > Utilities.
* In Terminal, paste the following: defaults write com.apple.finder AppleShowAllFiles YES.
* Press return.
* Hold the 'Option/alt' key, then right click on the Finder icon in the dock and click Relaunch.

Well, that is indeed the long way of achieving it.
Try pressing CMD + SHIFT + . (dot) in the Finder.app. It toggles hidden files. Quicker and easier.
Score: 3 Votes (Like | Disagree)
Avatar
45 months ago

Great to hear. Your stock went way up for actually being engaged with the community. I follow Mikko on Twitter, which is how I found out about the acquisition.

Honestly I'm sure the number of Jonathan's paying customers is so small that it might not be worth the effort. But I do appreciate that you at least know we exist. I don't actually think you owe us anything. With Jonathan going to Apple, the product was effectively dead anyway due to their IP and PR policies. I'm just glad the functionality is finding a home where the polish and ease of use can continue to improve for non-bleeding edge users.

Thanks :)

We will be contacting all of you existing LF customers via email hopefully still this week, based on the customer list we were provided. More information in the email, but basically you will have access to F-Secure XFENCE so no worries.
[doublepost=1491990536][/doublepost]

I actually had a reply from Jonathan and he assured me that f-secure would honour existing LF licences, so perhaps if they are watching this forum they could let us know exactly what we need to do ? unless of course he gave them our contact info from the purchase details ...

No need to do anything yet, we have the contact list and as mentioned above, will contact you soon :)
Score: 2 Votes (Like | Disagree)
Avatar
45 months ago

Indeed, Macs are not completely immune but so far we've had no ransomware out in the wild.

Um, Wut!?! To my knowledge there has been Mac Ransomeare. One of them was from downloading Transmission from the source!
Score: 2 Votes (Like | Disagree)

Top Stories

iOS 14 Widgets Offer iPhone Users Creative Home Screen Ideas

Sunday September 20, 2020 8:43 pm PDT by
In iOS 14, Apple introduced ‌the concept of Home Screen‌ widgets, which provide information from apps at a glance. Widgets can be pinned to the Home Screen in various spots and sizes, allowing for many different layouts. Despite the relative lack of 3rd party widgets at launch, iOS users around the...

iPhone 12 Lineup Rumored to Be Named 'iPhone 12 mini,' 'iPhone 12,' 'iPhone 12 Pro,' and 'iPhone 12 Pro Max'

Monday September 21, 2020 5:24 am PDT by
Leaker known as "L0vetodream" has today shared the alleged naming for the upcoming iPhone 12 lineup on Twitter. The tweet proposes that the upcoming iPhone 12 models will be titled "iPhone 12 mini," "iPhone 12," "iPhone 12 Pro," and "iPhone 12 Pro Max." The names likely correspond to the three expected sizes of iPhone 12, with the 5.4-inch model being the iPhone 12 mini, the 6.7-inch model ...

Hands-On With the New Apple Watch Series 6 and Apple Watch SE

Friday September 18, 2020 1:19 pm PDT by
Today's the official launch date for the Apple Watch Series 6 and the Apple Watch SE, both of which Apple announced on Tuesday. We picked up a couple of the new models and thought we'd give them a quick look for MacRumors readers thinking of ordering a new watch. Apple Watch Series 6 & Apple Watch SE Hands-On! When it comes to design, both the $399 Series 6 and the $279 SE look just like...

iOS 14 Picture in Picture No Longer Working With YouTube's Mobile Website in Safari [Without Premium]

Friday September 18, 2020 12:21 pm PDT by
Apple in iOS 14 added Picture in Picture to the iPhone, a feature designed to let you watch a video in a small screen on your device while you continue to do other things on the phone. When Picture in Picture was working with YouTube The YouTube app doesn't support Picture in Picture, but up until yesterday there was a functional workaround that allowed videos from YouTube.com to be watched...

When Will the iPhone 12 Launch? Here's What We Know

Wednesday September 16, 2020 6:12 am PDT by
Yesterday's "Time Flies" Apple event saw the release of the Apple Watch Series 6, Apple Watch SE, iPad 8, and iPad Air 4, but no new iPhone models. Rumors before the event strongly alleged that it would not see the unveiling of new iPhones, with many reports pointing to an October launch. The lack of new iPhone models yesterday seems to confirm that the iPhone 12 lineup will not appear...

Here's How You Can Download iOS 14 and iPadOS 14 Around the World [It's Out]

Wednesday September 16, 2020 2:36 am PDT by
Apple's official public release of iOS 14 and iPadOS 14 dropped on Wednesday, September 16, just a day after the company released the Golden Master to third-party developers. Also set to be made available to the general public for the first time are watchOS 7 and tvOS 14. Getting Started With iOS 14 Video Click image to watch iOS 14 Getting Started While that's left a lot of developers...

AirPods Studio Rumored to Come With U1 Chip, Ultra-Wideband Said to Be Vital to Future Apple Ecosystem

Sunday September 20, 2020 6:17 am PDT by
Proven leaker known as "L0vetodream" has today shared a range of information about the ultra-wideband U1 chip in Apple's upcoming AirTags item trackers and AirPods Studio headphones. The first of a series of tweets shared today simply stated that AirPods Studio will contain an ultra-wideband U1 chip. It seems likely that the U1 chip would be used in AirPods Studio to track the location of...

Kuo: Apple to Accelerate Adoption of Mini-LED Displays in iPad and Mac Notebook Lineups

Sunday September 20, 2020 10:00 pm PDT by
Increased competition among Apple's suppliers for mini-LED display chips will accelerate the company's adoption of the advanced technology in its iPad and MacBook lineups, according to a new research note from analyst Ming-Chi Kuo seen by MacRumors. Kuo says that while Epistar had been predicted to be the exclusive supplier of mini-LED chips for Apple products in 2021, Sanan Optoelectronics...

Top Stories: Apple Event Recap, Apple Watch Series 6, Redesigned iPad Air, and More

Saturday September 19, 2020 6:00 am PDT by
This week's news was obviously dominated by Apple's media event and the launch of iOS 14, but there was a lot to digest, so check out our summary below for the high-level view of the past week. With the exception of the massively redesigned iPad Air, all of the new hardware introduced this week is starting to appear on store shelves and on customers' doorsteps, while all of the new software...

Apple Updates AirPods 2 and AirPods Pro Firmware to Version 3A283

Monday September 14, 2020 11:24 am PDT by
Apple today released new 3A283 firmware updates for the second-generation AirPods and the AirPods Pro. The second-generation AirPods are being updated from the 2D15 firmware they were previously running, while the AirPods Pros are being updated from the 2D27 firmware they had installed previously. Apple does not provide details on what's included in refreshed firmware so we don't know what's ...