4 ms·
Wow. That's almost inexcusable, especially due to the requirement of forcing iOS apps to implement this. If they didn't extend the window (from originally April
by cfors 6y ago
Wow. That's almost inexcusable, especially due to the requirement of forcing iOS apps to implement this. If they didn't extend the window (from originally April 2020 -> July 2020) so many more apps would have been totally exploitable from this.
After this, they should remove the requirement of Apple Sign in. How do you require an app to implement this with such a ridiculous zero day?
- thephyber 6y agoI’m of the mind that just about any security bug is “excusable” if it passed a good faith effort by a qualified security audit team and the development process is in place to minimize such incidents. The problem I have is that I can’t tell what their processes are beyond the generic wording on this page[1] [1] support.apple.com/guide/security/introduction-seccd5016d31/web
- resfirestar 6y agoEven if there was clear evidence that this system underwent a proper security audit, with a failure this basic you would have to ask why it didn't work. What is going on inside Apple that brought them to the point of releasing a lock that simply opens with any key, despite the efforts of their state of the art lock design process and qualified lock auditors?
- Areading314 6y agoWriting some test cases for "can anyone generate a valid token" or "does an invalid token allow access" should be the first thing to do when writing an auth system.
- thephyber 6y agoYour test cases make sense, but they ignore an obvious hypothetical possibility: The OIDC implementation was a well-tested core feature (with the tests that you mention), but the email proxy feature was a bolt on that was somehow not considered risky (so it could easily have bypassed a full, renewed security audit). Also, it's not sufficient to "have a test case". The intent and the implementation must be coherent.
- yreg 6y agoI believe the deadline is June 30. [0] [0] - https://developer.apple.com/news/?id=03262020b https://developer.apple.com/news/?id=03262020b
- driverdan 6y ago> That's almost inexcusable No, it's completely inexcusable. There should never be such a simple, major security vulnerability like this. Overlooking something this basic is incompetence.