35 ms·
Sandboxed Mac apps can record screen any time without you knowing
- Exuma 9y agoWhat in the fuck
- oneplane 9y agoI get that this is about the Mac apps, but doesn't this apply to any general OS? On Windows this is trivial, on any Linux distro using X11 too.
- bitwize 9y agoYou can trivially sandbox X11 apps by running them in a nested X server.
- quotheth 9y agoHow many apps do this?
- pdkl95 9y agoI, the user, do that. It's not the app's responsibility.
- quotheth 9y agoGreat, I'm sure everyone else feels safe knowing you manually sandbox your apps.
- wander_homer 9y agoIf you trust an application so far as to properly limit itself in what it can do by requesting a sandboxed environment so you don't have to type a few additional letters you might just as well run it without a sandbox. Hey kind stranger who is supposed to do the garden while I go shopping, I really don't trust you. So to be sure you only do the garden and nothing else, here are the keys to my house, please ensure that every door and window is locked. Thanks. The only other entity who could set it up for you, so every application automatically launches in a sandboxed environment, is the distributor, but then again it's your responsibility to chose a distribution that does that. If you want security you have to do something about it at one point or another.
- quotheth 9y agoI think this is the wrong attitude. No one is better suited to implement a sandbox than the developer of the application. The fact that most developers are not trained to do so is just a reflection of our field's terrible progress re: education devs on secure app dev. Leaving this to the user leaves the vast majority of users unsafe. This is an unacceptable state.
- wander_homer 9y agoWhy should an application developer implement a sandbox? That's a huge waste of time and it's much more efficient if the operating system or the user enforces it instead by using existing sandboxing technologies like firejail. It is also untrustworthy and insecure, since after all you don't trust the application. If an application is responsible for sandboxing itself it can also choose not to sandbox itself properly if it wants to do harm. There is no way around you either taking care of that yourself or you choosing an operating system that enforces it for you, like Qubes OS.
- quotheth 9y ago> Why should an application developer implement a sandbox? Because they are the ones who understand the necessary capabilities of their program and the ones who have access to the source code... > That's a huge waste of time and it's much more efficient if the operating system or the user enforces it instead by using existing sandboxing technologies like firejail. Actually it's a far better sandbox when built into the program. And it doesn't leave users relying on installing arcane operating systems or becoming technically savvy. > It is also untrustworthy and insecure, since after all you don't trust the application. No, trusting the application is implicit since it's installed by the user. The sandbox exists to protect against a compromised application.
- geofft 9y agoAnd a separate user account, otherwise they can just connect to the original X server. (And on almost all existent Linux systems, either running as a separate user isn't trivial or the sandboxing process has root.)
- pritambaral 9y agoIs a separate user account necessary if the Xauthority cookie is shadowed in the sandbox? I think firejail's nested X server setup works this way, without a separate user account.
- geofft 9y agoWhat prevents you from reading the Xauthority cookie out of disk / an existing process's environment / out of an existing process's memory / etc.? You need a sandbox to prevent it fro doing these things, which is certainly doable, but much harder than just opening a new X server. (On a system without Yama enabled, you can also ptrace any other process running as the same user and run code as it, e.g., using gdb, but lots of desktop-focused Linux distros enable Yama to close this particular approach.)
- pritambaral 9y ago> What prevents you from reading the Xauthority cookie out of disk / an existing process's environment / out of an existing process's memory / etc.? The sandbox does. > You need a sandbox to prevent it fro doing these things, which is certainly doable, but much harder than just opening a new X server. Of course. I never said simply running a new X server is sufficient. All I asked is if the sandbox needed to run the program in a separate user account.
- GirlsCanCode 9y agoReally? How can you do this from a Sandboxed app in Windows 10? I presume you're a paid Apple astroturfer
- b4lancesh33t 9y agoI think what's concerning is that advertising that an app is in a sandbox suggests to those out of the know that they can use it safely. They expect that the integrity and privacy of their information will be preserved. That expectation does not exist with ordinary win32 or Linux programs. Are windows store apps sandboxed? If so, is it trivially easy to do this with those? Or is it just win32?
- jchw 9y agoTrue UWP apps are sandboxed and probably can't do this. They have access to a limited version of the Win32 API, I believe.
- Bitcoin_McPonzi 9y agoWindows 10 closed this hole.
- camhart 9y agoHow so? In java I can access all screens without requesting a permission.
- anonymfus 9y agoIn store applications without full trust permissions you can not.
- pritambaral 9y agoStore applications are not the only applications on Windows 10. Closing holes in store applications alone does not close all the holes.
- djsumdog 9y agoThis article is addressing sandboxed applications. Regular applications, yes, you can pretty much do whatever in userspace in Win/Mac/X11. If you're going to create a new sandbox environment for applications (Windows Store/MacOS store) in today's world, it really needs to be locked down with explicit permissions for each type of I/O access.
- chungy 9y agoWindows NT (way back to its original 3.1 release) always had the idea of multiple independent desktops where applications can't cross-interact. If you use runas to run GUI applications under different user contexts, you might notice that some things like drag-and-drop and the clipboard don't work, and also screen recorders won't work ... Most users never use this functionality normally, but you might notice sometimes if you do "Run As Administrator" and the applications don't quite integrate with non-admin apps.
- bitL 9y agoX11 is way worse; any app can subscribe to events of any other app, making keyloggers and other nastyware a piece of cake.
- pdkl95 9y ago> any app can subscribe to events of any other app Yes, that's a feature I have used many times in the past. If you want to sandbox an app, run it through a nested X server.
- noway421 9y agoAFAIK you can't get any hardware acceleration that way.
- badsectoracula 9y agoDepends on the X server, i think Xnest uses just a dumb framebuffer but i think Xephyr can use acceleration just fine.
- TeMPOraL 9y agoIndeed. And for Windows, more than once I wrote stuff that captures or injects keystrokes globally. Being able to do this is a feature that lets you solve problems by making things more interoperable.
- globuous 9y agoWow, i have a lot to learn.... Do you know if these sort of things are still possible on wayland ? What about a Flatpak app on Wayland, does that help ? Because I think I've read somewhere that Flatpak apps on X11 was this way, implying that with Wayland it wasn't. I wish i had more time to dive into this sort of stuff... Flatpak does aggressively isolate apps from the OS though: http://docs.flatpak.org/en/latest/working-with-the-sandbox.html http://docs.flatpak.org/en/latest/working-with-the-sandbox.h...
- Jasper_ 9y ago
- kibwen 9y agoJust goes to show that not all sandboxes are created equal (though I don't think I've ever even used a properly sandboxed Windows or Linux app, so those OSes don't get any points anyway). For example, reading other tabs or processes out of the web browser sandbox isn't possible short of exploits like Spectre and Meltdown, and even seeing something like the history of visited links requires cleverly tricking the user (and coarse guesswork) e.g. https://tinsnail.neocities.org/ https://tinsnail.neocities.org/ and http://lcamtuf.coredump.cx/yahh/ http://lcamtuf.coredump.cx/yahh/ . I imagine the behavior in the OP is impossible on both Android and iOS too?
- abecedarius 9y agoThere was a pre-Spectre proof of concept of a program telling what tabs you have open in your web browser: https://github.com/defuse/flush-reload-attacks https://github.com/defuse/flush-reload-attacks This was a program rather than another webpage, and I haven't bothered to read how it worked beyond the general idea of exploiting a cache side-channel. I expect the bit-rate is low compared to Spectre/Meltdown. But it made me leery of confidentiality in current systems.
- yzmtf2008 9y agoI think you have the idea of sandbox (or at least the idea of sandbox in the context of a web browser) backwards: it means an application (webpage) running inside the sandbox cannot access resources not granted. This side channel access does not run inside a sandbox at all.
- abecedarius 9y agoIf you don't consider an OS process a sandbox at all, why are even talking about security here?
- yzmtf2008 9y agoThat’s not the point of GP though? The whole premise of virtualization is that an OS process is not a perfect sandbox. There’s a hierarchy of sandboxes. Protecting other processes from accessing something inside the sandbox is not the job of a browser sandbox. This actually just goes to show the GP’s point: not all sandboxes are created equal.
- emersion 9y agoOn Linux, Wayland fixes this (+ allows for other security features, e.g. to protect the clipboard).
- _trampeltier 9y agoI was worry about a kind of this too. I was worry an app could steal my passwords from clipboard. I checked, at least a website can't just read from the clipboard. At least in theory .. I still fill the clipboard after the use to transfer a password (often) with random stuff ..
- marcc 9y agoMost good password managers will do this for you automatically. When I copy a password out of 1Password, it doesn’t stay in the clipboard forever and there’s an option to specific the amount of time before clearing it.
- gruez 9y ago>I checked, at least a website can't just read from the clipboard. At least in theory AFAIK the logic is that any user initiated event (click, keystroke, touch, etc) allows the page to see (and modify) clipboard contents for that instance. So if you accidentally click in a rogue page, it's possible for your clipboard contents to be stolen.
- fouc 9y agoAre we ever going to end up with the practice of running every app in their own independent VM? Should anything at all run in the host OS? The advantage of running every app in their own VM means that apps won't get necessarily tossed to the side in this constant arms race of upgrades, especially for apps that don't need internet. Imagine still actively using several perfectly good apps that were last updated 10 or 20 years ago?
- withoutclass 9y agoWe're there, check out Qubes OS
- krisives 9y agoGreat when it works, one of the few variants of Linux that sometimes just doesn't like to run on some hardware still.
- woolvalley 9y agoPermmissions dialogs for rare dangerous behaviors I think can work. You have to do it like apple does it although, not like android. Like how often does software need to do screenshots, not many. Same with most other app permissions. Most only need network access and a folder.
- mcny 9y agoI'm afraid apps will abuse these permissions. For example, Facebook app (or a banking app) shouldn't quit if I refuse it a permission. I can't even use the default native email app (edit: on Android) with exchange without giving the exchange server remote administration access. Makes no sense.
- ndespres 9y agoThe Exchange server requesting remote permission is a "feature" which allows you or your company's Exchange server admins to send remote wipe command to the handset if it's lost or you leave the company. Not the specific fault of the permission model of the phone, it's part of the activesync suite.
- CPLX 9y agoAs an old person my assumption is that a desktop app can basically do whatever it wants with the screen, mouse, keyboard, or audio while it's actually running. Isn't that what apps are for? This just seems like expected behavior. If you don't want apps doing stuff don't run them on your desktop computer.
- comex 9y agoThe sandbox is designed to make that not expected behavior - even if, as demonstrated here, it has holes…
- threeseed 9y agoSince when ? OSX has never outlawed this sort of thing. The sandbox has always been completely different from iOS e.g. it doesn't ask permission to access photos, microphone, webcam.
- igloofoo 9y agoWrong. 1) Your webcam turns a light on. Not permission, but you know what's going on. 2) "People must grant permission for an app to access personal information, including the current location, calendar, contact information, reminders, and photos." https://developer.apple.com/macos/human-interface-guidelines/user-interaction/requesting-permission/ https://developer.apple.com/macos/human-interface-guidelines...
- threeseed 9y agoThose are if you are using the APIs directly. But you can always go straight to the files themselves for cases like Photos and Calendars and also to the SQLite databases that back a lot of user data. And current location is easy to get on OSX. You can simply look up the user's IP address and WiFi networks to triangulate the user's location with about the same accuracy as Apple can do. With webcam you can easily switch the camera on, take the photo and switch it off. Could easily trick people into thinking it was a hardware fault rather than something nefarious with the app. The fact is that none of what I listed above is possible on iOS.
- techrich 9y agoYou are sitting on this OS as an administrator/root and apps can do anything that they want. I dont really see this as an issue. Its always been this way! Go run Qubes OS if you want to protect against this.
- igloofoo 9y agoSo apps need to ask for location but not to see everything you do? WTF
- amerine 9y agoI imagine a world where every application that wanted to read and write to displays was required to go through an authorization-flow before it worked? That sounds terrible. This behavior is how desktop applications are meant to work. I’m surprised this surprised anyone.
- eropple 9y agoA desktop application has need to instruct the OS to draw its window. That can be reasonably unprivileged--an app owns its windows, this is easy. Most applications have no need to read raster data from its window. Even fewer have need to read raster data from the desktop itself. Desktop applications are not "meant to" have access they don't need. They sometimes have that access as an accident of history, but they are not "meant to"; we've known about the principle of least privilege for a long time. And the MacOS sandbox (which, to be honest, doesn't work very well, but that's neither here nor there) is intended to enforce application privileges and reduce escalation.
- igloofoo 9y agoPlease humor me, why in the world does an app need to read/write your screen? It is provided a window for that. If it doesn't need to read/write your screen in order to provide its features, and then does it, wouldn't you agree that something is fishy? Wouldn't you like to know when fishy things are going on? What is the point of security if any app you download can see everything you do?
- badsectoracula 9y ago> Please humor me, why in the world does an app need to read/write your screen? The most obvious answer would be to take screenshots, like GIMP's "Create from screenshot" command or a dedicated program like the snippet tool in Windows. Many graphics tools offer that functionality, even some that you can run from the command line. Other, similarly widely available functionality, is to record the desktop - a common functionality needed for screencasting and video streaming (think Twitch) programs. This also need to capture audio. Also a more niche tool is to create captures directly to GIF files (i have such a tool both in Windows and Linux). Of course less commonly implemented but still very useful functionality is for remote access/remote desktop (in which case you also need to also capture input events but also create fake input events indistinguishable from the user's events). Finally several utilities also benefit from being able to read the screen, like utilities to magnify and perhaps enhance part of a screen (that can be useful for people with sight issues, or for developers to inspect the output of a graphics program at the pixel level without flattening their face on the monitor) or utilities like color pickers or even just funny toys that manipulate the screen contents (i've seen a game at the past grab a screenshot of your desktop and then zoom it out when you launch it). > What is the point of security if any app you download can see everything you do? I'd turn that around: what is the point of security if the apps you download cannot do their job because of it? At the end of the day computers need to be useful, not to be burned and buried in a waste disposal field (where they'd be in their most secure state).
- floatingatoll 9y agoThe login dialog for the Itch.io desktop client is magically excluded from the accessible canvas on my OS X instance.
- kuon 9y agoKnowing its dev, this doesn't surprise me:)
- stratigos 9y agoYou are not a real developer if you code on a Mac. You are a trainee coding on a machine with training wheels. I will never take any programmer seriously if they whip out a macbook. Use linux.
- thanatos_dem 9y agoGolly gee, I can barely hear you all the way up there on your pedestal. I used linux for a good long while. Started with Ubuntu, then on to Mint, then Arch as I became more of a "power user". But you know what? Sometimes I don't want to put in manual effort to get things to work, even if that means I lose some customization. Over my years with linux, I've had driver issues with displays, with the network manager, with mounting remote drives... Basically any interaction with the hardware was a solid kick in the groin. Since switching to a Macbook, everything has been smooth sailing. And especially nowadays with homebrew and docker, all the tools I need are available on a Mac, and it's a more integrated experience, and IMHO it looks better. But if you like linux and it works for you, that's also fine by me. To each their own.
- isostatic 9y agoFunny that. I use Linux because it just works, macs are a pain and windows is just laughable. What annoys me about the last decadeish of Mac developers is the terrible prevalence of things like "curl|bash", custom pacakage managers, unversioned software etc. This could just be the company I work for, but as far as I'm concerned software is not released unless there is a collection of software and instructions on installing. Deb, rpm, even a rat all is fine. Anything that downloads something from a random website is not. Now obviously Mac developers don't enforce this attitude, but it does seem to correlate.
- eknkc 9y agoI used to run Linux before switching to Mac, around 10 years ago. Recently got a Dell XPS 13 and installed Ubuntu (then Mint). Installing stuff on Ubuntu I used a couple of PPAs. How is this any different than curl|bash? You just trust some repo blindly. Also, please refer me to this magical distro that just works cause I have seen these before going back to Mac: - HiDPI scaling does not just work. There are weird issues here and there. - Closing the lid does not reliably put the laptop to sleep. Sometimes when it does, opening it does not just wake it up. - Once in a while, the OS completely forgot that it had a Wi-Fi device. I just restarted and it returned. I don’t have time to test workarounds, read logs, try different distros and shit like that. I never once had to think twice before tossing a MacBook into my pack because it might still be awake? I love Linux on servers, used o love it on my desktop but that was high school / college days. I had too much time to tweak things just perfect.
- debt 9y agoSomething has to give with the Mac ecosystem. The Mac App Store sucks, the Mac has continuously for the past years of been having security issues, serious security issues. I believe Apple is at a crossroads, something needs to be done with the Mac.
- EugeneOZ 9y agoDon't panic.
- TheDong 9y ago> > How can I protect myself as a user? > To my knowledge there is no way to protect yourself as of now. That is the most FUD bit of this. There's a very easy way for a user to protect themselves: don't download any untrusted applications. Only run code you trust. Don't trust the sandbox that much. Vulnerabilities like the android MMS one where anyone could send any number an image and pwn it were "as a user you can't protect yourself". Local roots and things like this require a user to opt-in to being exploited by running a malicious app. That's significantly different and less scary.
- felixkk 9y agoHow can you know the app you’re using hasn’t been compromised? Publishing a blog post about this specific topic next Thursday
- natehouk 9y agoNo shit.
- natehouk 9y ago1password is compromised. Been pointing out flaws for years: https://discussions.agilebits.com/discussion/62449/deleting-family-members-or-vaults-also-removes-their-data https://discussions.agilebits.com/discussion/62449/deleting-... Search me.
- jacksproit 9y agoI remember in the windows xp days there was an app you could run that would show an alert any time a program tried to hook into your keyboard input or display. I wonder why nothing like that exists any more.
- deepfriedbits 9y agoSeems like a nice feature for something like Little Snitch.
- ridiculous_fish 9y agoI was an AppKit engineer when the Mac app sandbox was introduced in 10.7. Much of our effort that release (and in following releases) was dedicated to making Mac features work within sandboxed apps. Think open and save panels, copy and paste, drag and drop, Services menu, Open Recents, etc. We did our best but the fact is that sandboxed apps run more slowly, have fewer features, are more isolated, and take longer to develop. Sometimes this cost is prohibitive (see Coda 2.5). IMO the app sandbox was a grievous strategic mistake for the Mac. Cocoa-based Mac apps are rapidly being eaten by web apps and Electron psuedo-desktop apps. For Mac apps to survive, they must capitalize on their strengths: superior performance, better system integration, better dev experience, more features, and higher general quality. But the app sandbox strikes at all of those. In return it offers security inferior to a web app, as this post illustrates. The price is far too high and the benefits too little. IMO Apple should drop the Mac app sandbox altogether (though continue to sandbox system services, which is totally sensible, and maybe retain something geared towards browsers.) The code signing requirements and dev cert revocation, which has been successfully used to remotely disable malware, will be sufficient security: the Mac community is good at sussing out bad actors. But force Mac devs to castrate their apps even more, and there won't be anything left to protect.
- intelhearts 9y agoI still don't understand why the multitouchframework is private
- tonyedgecombe 9y agoIt does strike me as something that is very difficult to retrofit. I'm not sure Apple should give up on it though, I don't want any old application I download to be able to read through the spreadsheets in my Accounting folder. Perhaps the emergence of Electron is a wake up call for Apple and Microsoft, there is clearly a demand for creating applications with web technologies, OS developers need to respond to that rather than letting a third party eat their lunch.
- javajosh 9y agoOne way to isolate applications, common for server daemons, is to run them under their own user. The real "human" user can sudo into any application account, and does so on application execution. Marketing would have to rename things and slap a GUI over the feature, but I don't see why it wouldn't work for arbitrary Cocoa apps. (And the screen-capture API should be limited to capturing parts of the screen the application is currently drawing to, with overlaps clipped out, etc.)
- wavefunction 9y agoWhy wouldn't we assume that?
- ThomPete 9y agoThe Sandbox became the reason I left the mac app store and instead started selling my directly from my website using Paddle and I haven't looked back since. It's been one of the most catastrophic decisions apple have ever made and IMO is hindering actual progress for desktop apps.
- dep_b 9y agoFelix Krause works for Google these days. Since he got hired he got a bit more critical to the platform. Perhaps no more “I hope this doesn’t piss off Apple” mentality?
- igloofoo 9y agoViewing your screen should be subject to permissions simply because it can supersede all permissions to access sensitive data.
- NietTim 9y agoMaybe Krause can also make an article on the paste board and get some more clicks
- adultSwim 9y agoThis is why I run Qubes. Trusting all software running on my system is unreasonable. Other OS's need to catch up ASAP.