9 ms·
Hacking the Apple Webcam (Again)
- shp0ngle 5y agoThis does not relate to "webcam" at all? This allows to inject any script to any source, that seems more scary than "just" hacking a webcam? Also it makes me reconsider using Safari, seeing all these "special cases" of iCloud and iPhoto URLs being allowed.
- twox2 5y agoBugs of this nature exist in all major browsers, not just Safari.
- tomaskafka 5y agoApple: "Safari is the most locked down and secure browser that never runs anything without user's permission." Also Apple: "We have built in a long list of exceptions for Apple services, because it's impossible for an Apple service to have an exploit."
- leokennis 5y agoNew https://support.apple.com https://support.apple.com article incoming: > "We advise users not to store sensitive info and files on their computers, to prevent nefarious actors from being able to steal these sensitive items"
- sabujp 5y agocongrats
- throwaway81523 5y ago> "This research resulted in 4 0day bugs (CVE-2021-30861, CVE-2021-30975, and two without CVEs), 2 of which were used in the camera hack. I reported this chain to Apple and was awarded $100,500 as a bounty." Writing a secure browser for today's web appears to be a technological challenge comparable to a level 5 self-driving car. It has not been shown to be feasible. So such cars are not permitted to be deployed on the world's roads. Today's web sites and browsers should similarly not be deployed on the world's infobahns.
- spicybright 5y agoTo be fair level 5 self driving car failing is much more catastrophic than a browser being hijacked. But I generally agree with your sentiment. Unfortunately the only way to find these modes of failure is to have them actually fail. It's impossible to design and release an error free system without real world usage from real people. It doesn't mean we should just give up and go back to HTML1 though. It just means exploits should be fixed as soon as possible to minimize damage.
- throwaway81523 5y agoThere is no need to fall back to HTML1. Before HTML5 and even before HTML4, there was a web markup language that was much more powerful than HTML1, was widely deployed and used, did everything we needed, and worked fine. It was called HTML3 and it was great. That is where we should be right now.
- smoldesu 5y agoMaybe if vendors were more open to allowing third-party applications on their platform, people wouldn't be so motivated to increasing the capabilities of the web. Instead, app distribution has turned into a living nightmare, so it's unsurprising to see the web evolved into the monster it is today.
- spicybright 5y agoYou might be wearing rose colored glasses here... The old web I remember had exploits from flash, java applets, active-x, shockwave, other sketchy plugins people willingly downloaded to access sites, and poorly sandboxed javascript that could take control of your browser window to resize, move, and spam as many popups as it wanted among other worse things. And downloaded "toolbars", https being rarely used, etc. Even ad blockers and other "power user" extensions (if your browser even offered that) were extremely primitive. etc. There were websites that could execute user land code through exploits just by visiting a website depending on your browser. And that wasn't uncommon. It would be completely insane if that was still the case today. But we fixed those issues and evolved. OP's post shows a major issue obviously. But I would absolutely turn off the entire api with a forced update until it was fixed if I had the power to. But these sorts of exploits happened back in the day to a worse degree with HTML3 + 4 (can't speak for 1 or 2 though, maybe someone can chime in). Viewing the bigger picture, the web is way more secure now than back then. And exploits like these are much more rare now.
- alexk307 5y agoThis is incredible and terrifying. Well done.
- dmitriid 5y ago> While this bug does require the victim to click "open" on a popup from my website, it results in more than just multimedia permission hijacking. That's why I'm so wary of browsers (well, a certain browser) adding more and more APIs that hide behind permission popups. People will blindly click them. And I fully agree with a sibling comment: "Writing a secure browser for today's web appears to be a technological challenge comparable to a level 5 self-driving car", https://news.ycombinator.com/item?id=30078738 https://news.ycombinator.com/item?id=30078738
- moooo99 5y agoReading articles like that always blows my mind. I can't even imagine how people can come up with exploit chains like that. Congratulations, well deserved bounty!
- lodovic 5y agoSuch a good write up, well done!
- nathanganser 5y agoAbsolutely! Was really enjoyable to read! Thanks for this!
- Mougatine 5y agoA $100,500 bounty seems pretty cheap compared to the severity of the issue, or is it common?
- runjake 5y agoIt's the most that Apple's paid out for a bug bounty, as far as I know. The previous highest was $500 less ($100,000).
- tptacek 5y agoIt's also an interaction-required bug, apparently.
- ffhhj 5y agoNow imagine how much money they saved by not researching those bugs themselves.
- jtbayly 5y agoNow imagine how much the researcher gave up by not selling it to Cellebrite.
- saagarjha 5y agoCellebrite doesn't really have a use for a browser vulnerability.
- tptacek 5y agoYou mean to say someone like NSO Group, not Cellebrite. But you should know that it's possible driving up the price of bugs helps companies like NSO, rather than hurting them. They're middlemen, taking a cut of the value of transactions between exploit developers and downstream customers. Those downstream customers, for shops like NSO, are overwhelmingly government agencies that aren't especially price-sensitive to the cost of individual bugs.
- user3939382 5y agoI’m a fan of OpenBSD where I run ‘ps -ax’ and get a list of about 10 processes, all of whose purpose is obvious. On macOS I spend the first few days disabling several dozen junk processes I didn’t ask for and don’t want. This includes classroom tools (??) and all kinds of syncing/ sharing daemons I have no use for. This exploit reinforces what we already know — computers are impossible to secure, you should reduce attack surface where possible. If you get a little privacy and performance out of it all the better.
- cryptoegorophy 5y agoI literarily just use safari and excel. Is there a guide on how to disable the rest of the junk such as classroom tools?
- astrange 5y agoPlease don't turn off random stuff and expect your computer to still work/be supported/anyone to ever fix your crash reports.
- Sirened 5y agoI suspect this is 10% of the reason why System Integrity Protection exists. Yes, it's great to stop malware, but it's even better to save your frontline support from having to deal with people who decided that it'd be a good idea to delete the dyld shared cache because it's 15GB and ""doesn't look useful"" https://discussions.apple.com/thread/250117852 https://discussions.apple.com/thread/250117852
- christopherwxyz 5y agoCongrats, Ryan! Well deserved.
- daddysnake 5y agoLucky for me my MacBook camera isn’t being detected.
- fortran77 5y agoWhy does this keep happening to Apple?
- Sirened 5y agocongrats :) I've always suspected you could use iCloud Sharing as a great one-click vector but I never quite cracked it. I wonder if apple will ever kill the webarchive UXSS—it's been public for almost five or six years at this point and it violates so many assumptions LOL.