4 ms·
I’m not so sure — what if an attacker can just run a test to see if the PIN is valid, and if not they can just shake the PIN entry and ask again like iOS does.
by brirec 3y ago
I’m not so sure — what if an attacker can just run a test to see if the PIN is valid, and if not they can just shake the PIN entry and ask again like iOS does.
And since every app is essentially a full screen modal, this sort of PIN phishing would probably be difficult for a human to detect. I bet you could recreate the iOS passcode prompt in SwiftUI relatively simply.
- szundi 3y agoThis simplicity I never understood. Windows at least does something with the screen when asking for privileges.
- gruez 3y agoWhat can you do with the pin though? Does iOS provide any sort of API that allows you to pass in a pin for verification?
- lxgr 3y agoYes, you can require the user to enter their PIN before allowing usage of a keychain secret, for example: https://developer.apple.com/documentation/security/secaccesscontrolcreateflags/1394326-devicepasscode https://developer.apple.com/documentation/security/secaccess...
- gruez 3y agoBut for that you can't pass in a pin yourself. You're relying on the OS to obtain and verify the pin.
- KMnO4 3y agoWindows doesn’t do anything that you couldn’t replicate in your own program.
- gruez 3y agoIt does, it's called secure desktop. https://en.wikipedia.org/wiki/User_Account_Control#Features https://en.wikipedia.org/wiki/User_Account_Control#Features
- lxgr 3y agoThat’s not the same thing. Secure Desktop solves the problem of trusted input, i.e. you don’t want untrusted user space apps to be able to interact with an OS dialog. (Note that in Secure Desktop, you’re not entering any password; you’re reading a message and allowing or declining a privilege escalation.) For iOS passcode verification, you’d need both secure input (which the UI almost certainly achieves), but also trusted output of at least one bit of information: Whether the user is currently interacting with the OS (or a trusted application) or an (untrusted) application.
- gruez 3y ago>(Note that in Secure Desktop, you’re not entering any password; you’re reading a message and allowing or declining a privilege escalation.) If you're a standard user, you'll be asked for the administrator's username/password on the secure desktop. Also, the secure desktop encompasses other parts of the system as well, like the lockscreen or the password change option on the ctrl-alt-del screen. >For iOS passcode verification, you’d need both secure input (which the UI almost certainly achieves), but also trusted output of at least one bit of information: Whether the user is currently interacting with the OS (or a trusted application) or an (untrusted) application. At least on windows that's provided by the secure attention key sequence. It's not enabled by default, but there's a group policy for it: https://learn.microsoft.com/en-us/windows/security/threat-protection/security-policy-settings/interactive-logon-do-not-require-ctrl-alt-del https://learn.microsoft.com/en-us/windows/security/threat-pr...
- lxgr 3y agoAh, yes, a secure attention sequence works as well for a trusted path! Unfortunately, it's no longer the default on Windows as you mention (presumably because OS-privileged malware is now the norm, so the net benefit is probably small?), and iOS only very rarely and inconsistently uses their secure attention sequence (i.e. the double home/lock button tap used for Apple Pay).
- kr0bat 3y agoThere's still no way for TikTok, or any app, to determine your password hash, so even if they test for validity (by conforming to OS pin restrictions), how would they test for veracity (being given the user's ACTUAL) passcode.