10 ms·
I'd agree more if he didn't submit — and get approved — a working exploit in their store. Without telling them about it. Edit: Now, I don't disagree that just
by Xuzz 15y ago
I'd agree more if he didn't submit — and get approved — a working exploit in their store. Without telling them about it.
Edit: Now, I don't disagree that just banning him from the program isn't a great idea, and that pulling the app and having someone from the security team send him an email isn't a better one. But it's hard to say this that a bad move on Apple's part.
- mikeash 15y agoThis hardly qualifies as an exploit. While it allows the app to do something it's not supposed to do, the ability to download and execute additional executable code doesn't actually violate security. The new code is still restricted to the app's sandbox and can't do anything that the original app couldn't potentially have done directly.
- humbledrone 15y agoIt easily qualifies as an exploit, given that Apple's app store model is based on the fact that each app is reviewed beforehand to ensure various properties, including the property that the app does not contain spyware, etc. If Apple approved a harmless app, and then said app downloaded code that snooped on the user's calls or asked for their credit card number, that's an exploit.
- ghshephard 15y agoFirst - I think just general manners, as well as established protocol, would have the security researcher let Apple know ahead of time what he would be doing. A simple email sent prior to uploading this code would have been sufficient to cover his bases - I'm surprised he didn't do that. Second - Unless I'm mistaken - his proof of concept was more a violation of Apples TOU, it didn't really attempt to copy credit card numbers, or snoop on users calls - so, in that sense, it wasn't an exploit. Net-Net - nobody comes out of this looking good, but Apple makes it clear that they are prepared to back up the language of their Developer TOU with actions.
- JoachimSchipper 15y agoPart of the security of the app store is the review process. "It's possible to download and execute code" is neat, "it's possible to download and execute code and the app store reviewers don't catch that" is much more impressive.
- ghshephard 15y agoNothing in the App Store review process will allow them to catch a zero-day exploit. Coming up with a zero-day exploit in IOS is very impressive - but, by definition, once you have it, the App Store review process isn't going to catch it.
- mikeash 15y agoApp review ensures no such thing. Put in your spyware with a timer so it doesnt activate for a week. Boom, reviewers don't see it, and users do.
- freemarketteddy 15y agolol...timer!!....really?
- mikeash 15y agoYep. There's no deep check of what your code contains, only a fairly superficial check of what it actually does. You can include nearly anything in your app (perhaps lightly obfuscated) as long as it doesn't show its face during the review.
- freemarketteddy 15y agoyes that is indeed true...but why a timer?....you can just query your own web server and figure out what to do. But yeah if you dont have time to make a small web server the timer idea could also work.
- mikeash 15y agoDepends on your level of paranoia and willingness to rely on the network. The server has the advantage of letting you turn it on and off at will, but a timer will work even if the user has no internet connection or your server gets confiscated by the FBI.
- nookiemonster 15y agoRunning unsigned code is an exploit, my friend.
- mikeash 15y agoWhy? What can you accomplish by running unsigned code that you can't accomplish by embedding a (e.g.) Python interpreter?
- nookiemonster 15y agoCode signining is a control that is intended to restrict the software that can run to only those apps which have been granted the right to run. Your second question is a good one, but given is context, it is unrelated. If apple signs a python interpreter, they do so at their peril, for obvious reasons.
- mikeash 15y agoYes, and it's still only running an app which was granted the right to run, it's just that this app now has some extra code in it. Since Apple doesn't really inspect the contents of the apps it signs anyway, this grants no extra capabilities.
- st3fan 15y agoI think it qualifies as a great exploit. You totally go around the Private API checks that Apple does. And there is a lot you can do with those APIs that is potentially evil. Even in the sandbox.
- mikeash 15y agoIt's trivial to bypass those checks anyway.
- nodata 15y agoSo how do you prove that it's possible to get this kind of exploit into the store unless you submit it to the store?
- Confusion 15y ago^^This. And he [1] probably told them immediately afterwards, since otherwise they still wouldn't have known. As he says: he regularly submits bugs. [1] Or perhaps someone beat him to it: he may not have seen the acceptance mail before someone already noticed the app? I'm not familiar with the exact process: do you need to give final approval or can the app be in the store for a while without you knowing it?
- ubernostrum 15y agoSo how do you prove the DDoS vector exists unless you DDoS someone's site? How do you prove the SQL injection vector exists unless you take over someone's site? etc., etc. This was far from a harmless proof-of-concept app, and "I just wanted to prove I could" isn't sufficient justification for it.
- redthrowaway 15y agoYou prove DDoS vectors exist by DDoSing your own site, or one you have permission to work on. Same with SQLi vulnerabilities. If you want to report a vulnerability you've found to a company, include a working exploit in your report, but don't run it. If the company ignores you or tries to brush the vulnerability off, that's where it gets hairy and responsible disclosure comes into play. We don't know what his level of communication was with Apple, but it doesn't appear that he notified them before testing this exploit. Had they refused to address the issue or otherwise brushed him off, this would be a reasonable escalation. The same story on r/netsec [1] is being linked to a Forbes article [2], which claims he notified Apple three weeks ago. That's not a ton of time. Ultimately, he very much violated their ToS and Apple is well within their rights to give him the boot. Whether that was a smart decision on their part remains to be seen. [1] http://www.reddit.com/r/netsec/comments/m48gx/charlie_miller_gets_kicked_out_of_apples/ http://www.reddit.com/r/netsec/comments/m48gx/charlie_miller... , http://www.reddit.com/r/netsec/comments/m3uwo/mac_hacker_charlie_miller_finds_a_bug_in_ios_that/ http://www.reddit.com/r/netsec/comments/m3uwo/mac_hacker_cha... [2] http://www.forbes.com/sites/andygreenberg/2011/11/07/apple-exiles-a-security-researcher-from-its-developer-program-for-proof-of-concept-exploit-app/ http://www.forbes.com/sites/andygreenberg/2011/11/07/apple-e...
- 16s 15y agoPerhaps he's not the first one to do it? Only the first to tell Apple that he did it.
- jjguy 15y agoFrom Miller's twitter stream last night: For the record, without a real app in the AppStore, people would say Apple wouldn't approve an app that took advantage of this flaw. https://twitter.com/#!/0xcharlie/status/133739410662494208 https://twitter.com/#!/0xcharlie/status/133739410662494208