3 ms·
> You know, I'm always astonished to which length people go to defend Apple! The reason this is a serious problem and not equivalent to any other situation whe
by throwaway287391 5y ago
> You know, I'm always astonished to which length people go to defend Apple!
The reason this is a serious problem and not equivalent to any other situation where you can get people to click an arbitrary link wasn't immediately obvious to me either. I'm glad the question was asked and answered. I'm not a diehard Apple defender, just someone who's not immersed in this phishing stuff on a daily basis. shrug
- Grustaf 5y agoSorry, but what is the answer? I still don't get it.
- johnday 5y agoThe answer is that a link provided by an Apple AirTag is expected to be secure. Indeed, a page on an apple domain is expected to have been vetted entirely by Apple, and therefore earns a degree of trust by the good samaritan. As it stands, a malicious user can replace the entire website, still under an apple.com domain, with content of their own devising. This content can, for example, pretend to be an Apple login page, and exfiltrate entered credentials. I hope it's obvious why this form of attack is more malicious and more dangerous than simply putting up an arbitrary QR code.