4 ms·
I mean, at that point and app could just put up a fake prompt using the UI framework. And I think users would be more hesitant to type a full password than just
by nmgycombinator 1y ago
I mean, at that point and app could just put up a fake prompt using the UI framework. And I think users would be more hesitant to type a full password than just click a button. But if you're talking about a bug similar to mine where an attacker could use the OS's own code against it and make it show a prompt with misleading content, you might be able to report it to Apple Product Security and maybe get a bounty.
- trollbridge 1y agoI mean, a website could display a crafty popup-appearing box and try to get you to type in your username and password. Not really sure how you can prevent that. Vista used the “the background dims quite a bit” to try to deal with that.
- nmgycombinator 1y agoYeah. I think the key thing in my vulnerability is that it abused a legitimate OS prompt and had the consequences of that prompt be applied to something separate from what the prompt text itself said it would.
- EGreg 1y agoI just told you how… it would show your special icon or phrase inside so you’d confirm it before you typed anything. The phrase would be managed through a system screen, like a login screen
- cyral 1y agoProblem is most users will not care or understand it. Someone will spoof the dialog without the special icon or phrase and users would still enter the password.
- trollbridge 1y agoBanks did this years ago, but a few surveys showed nobody actually checked for their key phrase or image.
- sureglymop 1y agoI wonder why they don't add a little led to their laptops that would indicate that it really is the system asking for your password. Kind of like the camera led.
- nmgycombinator 1y agoThat's an interesting idea. I do think it would be nice to have some way of knowing "is this prompt coming from the operating system or some third-party app?". However, I don't think it would have helped in the case of my vulnerability, because it abused a legitimate OS prompt.
- kalleboo 1y agoWhen they had the touchbar on the MacBook Pros, they would put the authentication in there since that was something only the OS could take full control over.
- nmgycombinator 1y agoThat's honestly a pretty smart move.
- kalleboo 1y agoYeah it's a shame it's just such an overengineered/expensive thing.
- saagarjha 1y agoYou can draw arbitrary content into it though?