3 ms·
I wonder how much of a potential there is for abuse with this system, one thing I thought of during the keynote was: 1. Someone sticks a malicious NFC tag on o
by mdszy 6y ago
I wonder how much of a potential there is for abuse with this system, one thing I thought of during the keynote was:
1. Someone sticks a malicious NFC tag on one of those rental scooters that opens a malicious App Clip
2. The App Clip seems like it could be for the rental service
3. App Clip maliciously takes your money and runs.
Wonder how much something like that could become a problem or if Apple would be good enough about preventing/stopping it.
- codezero 6y agoThat's a bloody clever trick :) I assume Apple is hoping to rely on its curated app store to protect against that, but that is more of a social attack, so maybe we'll see it happen or something similar. The "easy" fix is to make it obvious/hard to hide what the _real_ app clip should look like in-situ.
- jdminhbg 6y agoThe defense here is presumably the same as against a "Starbux" app that faked orders to Starbucks and kept the money: it would either not make it past App Review and into the store or as soon as someone was scammed and complained, it would be taken down.
- deleted 6y ago[deleted]
- r00fus 6y agoIt sounds like this sort of attack would not be widespread (because Apple would revoke the app rather quickly) but be great for spearphishing or high-value targets.
- jonny_eh 6y agoCouldn't this already be done with QR codes linking to a malicious website?
- innagadadavida 6y ago1. App clip needs to be registered with Apple 2. The web domain needs to link the App clip (Apple App Site Association file I'd presume). So this wouldn't work straight off as you describe. The NFC payload is just a url this url is sent back to Apple servers to load the App clip. What could work is someone uses a legit App clip and hijacks the corresponding web site and places a malicious payload and tricks the App clip to load the malicious payload and tricks the user to tap on NFC / QR code and exploits App clip. Even then the last line of defense - sandbox needs to be circumvented. Nevertheless, this is definitely a new attack vector and there will be exploits from NSAs.