7 ms·
How is this something that can happen? I mean, the only responsibility of an "authentication" endpoint is to release a JWT authenticating the current user. At
by tyrion 6y ago
How is this something that can happen? I mean, the only responsibility of an "authentication" endpoint is to release a JWT authenticating the current user.
At least from the writeup, the bug seems so simple that it is unbelievable that it could have passes a code review and testing.
I suspect things were maybe not as simple as explained here, otherwise this is at the same incompetence level as storing passwords in plaintext :O.
- enitihas 6y agoApple has had more simple "unbelievable" bugs, e.g https://news.ycombinator.com/item?id=15800676 https://news.ycombinator.com/item?id=15800676 (Anyone can login as root without any technical effort required) And to top it off (https://news.ycombinator.com/item?id=15828767 https://news.ycombinator.com/item?id=15828767) Apple keeps having all sorts of very simple "unbelievable" bugs.
- saagarjha 6y agoMore recent example of Apple "undoing" patches: https://www.synacktiv.com/posts/exploit/return-of-the-ios-sandbox-escape-lightspeeds-back-in-the-race.html https://www.synacktiv.com/posts/exploit/return-of-the-ios-sa...
- fishywang 6y agoLast year (or maybe 2018?) my employer hired an external consultant to give engineers security trainings (all are optional, they provide a few sessions on different topics, and engineers can sign up for interested ones). In one of the sessions I signed up, during the pre-session chat (while waiting for everyone signed up show up in the conference room), the external trainer "casually" chatted about "if you have an Android phone, you should throw it out of the window right now and buy an iPhone instead". That's the point I lost all my respect to them. (The session itself was ok-ish. It was some trainings about xsrf, nothing special either) (That incident also triggered me to purchase a sheet of [citation needed] stickers from xkcd to put on my laptop, so the next time this kind of thing happens I can just point to the sticker on my laptop. But I didn't got a chance to do that yet since received the stickers)
- kohtatsu 6y agoThis was pretty true not long ago. It's still a notoriously short window for OEM software patches on Android, whereas Apple's first 64-bit phone, the 5s from Fall 2013 is still getting patches (May 20th was the last one, iOS 12.4.7) Apple pioneered usable security with TouchID and the secure enclave; a lot of Android fingerprint readers were gimmicks for years, same with the face unlocks. https://manuals.info.apple.com/MANUALS/1000/MA1902/en_US/apple-platform-security-guide.pdf https://manuals.info.apple.com/MANUALS/1000/MA1902/en_US/app... They also invest piles of money into privacy https://apple.com/privacy https://apple.com/privacy (1 minute overview), https://apple.com/privacy/features https://apple.com/privacy/features (in-depth with links to whitepapers). I imagine that's where your teacher was coming from.
- enitihas 6y agoFortunately, it seems google has separated security updates from the OEM updates on some newer phones it seems. The phone I bought In November 2018, right now is receiving monthly security updates via Play Services updates, and is right now on the May version for some time.
- saagarjha 6y ago> The phone I bought In November 2018 I think it’s too early to claim anything for that one.
- fishywang 6y agoYes I'm not gonna defend Google's privacy issues, but privacy is totally different from security. People tend to confuse them. I understand it if it's average Joe got confused. But if you are a "security consultant" and you still have no idea what's the difference between them, then that's a big problem. Regarding security, see examples like https://qz.com/1844937/hong-kongs-mass-arrests-give-police-access-to-phones/ https://qz.com/1844937/hong-kongs-mass-arrests-give-police-a...
- fishywang 6y ago
- meowface 6y agoYou can't forget the infamous "goto fail": https://www.imperialviolet.org/2014/02/22/applebug.html https://www.imperialviolet.org/2014/02/22/applebug.html There seems to be kind of a common theme to these: - SSL certificates not validated at all - root authentication not validated at all - JWT token creation for arbitrary Apple ID users not validated at all I think these are all very likely due to error and not malice, but it's pretty crazy how these gaping holes keep being found.
- Jaxkr 6y agoApple has really lost their touch, software quality has declined dramatically
- iphone_elegance 6y agodoes it really matter though?
- hootbootscoot 6y agoSomeone with an AV production studio totalling over $100k in Apple products and a few million in outboard gear whose drivers worked fine before may just care a bit... The whole pro-multimedia production crowd probably cares... (vs the current Apple paramour: the multimedia consumer who wants to order pizza and get back to netflix on their phablet or whatever..)
- SaltyBackendGuy 6y agoAnecdotally, I upgraded my wife's iMac to Catalina and she's experiencing issues (rendering latency) she's never had before (hadn't upgraded the OS since buying it 4 years ago). I figured is was good to get on the latest and greatest for security reasons, now she wont let me touch her computer anymore.
- ksec 6y agoI used to be on the latest and security camp as well. But after all these years I am starting to understand why people dont update. It is extremely frustrating. Especially when Catalina removes features that were working perfectly.
- TheSpiceIsLife 6y agoI’m still on High Sierra, most recent 10.13.6 security update was ~3 days ago. I’ll upgrade when some piece of software I need to use requires it.
- randomfool 6y agoThe only thing I can think of is some 'test mode' override which inadvertently got enabled in production. 1. Don't add these. 2. If you must add something, structure it so it can only exist in test-only binaries. 3. If you really really need to add a 'must not enable in prod' flag then you must also continuously monitor prod to ensure that it is not enabled. Really hoping they follow up with a root-cause explanation.
- saagarjha 6y agoApple? No way.
- donmcronald 6y agoMy guess is that it has to do with that private relay because OAuth isn't too complex by itself. During the OAuth flow they probably collect the user preference, (if needed) go out to the relay service and get a generated email, and POST back to their own service with the preferred email to use in the token. If that's it, it's about as bad as doing password authentication in JavaScript and passing authenticated=true as a request parameter. Edit: Looking at the OAuth picture in the article, my guess would be like adding a step in between 1 and 2 where the server says "what email address do you want here" and the (client on the) user side is responsible for interacting with the email relay service and posting back with a preferred email address. Or the server does it but POSTS back to the same endpoint which means the user could just include whatever they want right from the start. The only thing that makes me think I might not be right is that doing it like that is just way too dumb. AND I'm guessing a bunch of Apple services probably use OAuth amongst themselves, so this might be the worst authentication bug of the decade. The $100k is a nice payday for the researcher, but I bet the scope of the damage that could have been done was MASSIVE. Edit 2: I still don't understand why the token wouldn't mainly be linked to a subject that's a user id. Isn't 'sub' the main identifier in a JWT? Maybe it's just been too long and I don't remember right.
- dwaite 6y ago> Edit 2: I still don't understand why the token wouldn't mainly be linked to a subject that's a user id. Isn't 'sub' the main identifier in a JWT? Maybe it's just been too long and I don't remember right. The details are very sparse in the post, but I believe the "sub" claim is a unique and stable value for the user against a particular relying party (based on that being a requirement in OpenID Connect.) You _should_ be relying on sub rather than email address, which is not guaranteed to be sent every time, to stay stable, or be unique across accounts. So while this was a zero day in terms of providing arbitrary email addresses as verified addresses, it may have not led to any account compromises.
- DethNinja 6y agoThis is basically bad coding, I never used OAuth system but you are supposed to just validate token, not any additional incoming data as number one rule of distributed systems is “never trust the client”. They basically made a huge fundamental design mistake.
- fulldecent2 6y agoI found a customer data leak on their homepage. Took about two years to fix. Gave me credit. No money. I'm not surprised here.
- zelphirkalt 6y agoThey exploited you just like their customers, from whom they take money for overpriced lock-in products.
- mkagenius 6y ago> code review and testing. Sometime code review is just "Please change the name of this function" and testing is just testing the positive cases not the negative ones. Yes, even in companies like apple and google.