3 ms·
The reactions I have regarding the urgency of this are: 1) Have there in fact been any known phishing attacks in Apple's App Store using this method? 2) Would
by hellofunk 9y ago
The reactions I have regarding the urgency of this are:
1) Have there in fact been any known phishing attacks in Apple's App Store using this method?
2) Wouldn't Apple's app review usually notice something like this before allowing it into the store?
- pilif 9y ago> 1) Have there in fact been any known phishing attacks in Apple's App Store using this method? no attacks are known. But that doesn't mean a thing. It's very easy to do this, so you'd have to assume that it is being done. > 2) Wouldn't Apple's app review usually notice something like this before allowing it into the store? no. As the article says, this kind of functionality is incredibly easy to hide.
- bduerst 9y agoRe: 2) What does Apple review when approving apps?
- tomovo 9y agoThey can do review-time checks of system calls that show the popup. Look for keywords in the dialog ("password", "account", "ID" etc). At runtime, check if a password entered in a dialog matches the user's Apple account password. Suspend or remove suspicious apps from the Appstore and advise the affected users.
- dx034 9y agoIt wasn't used as a widespread attack but could've been used in the past for targeted attacks.