6 ms·
People unfamiliar with the Apple ecosystem of products might not realize what a problem this is. It's not an attack in its own right, but a powerful step in a
by pudquick 13y ago
People unfamiliar with the Apple ecosystem of products might not realize what a problem this is.
It's not an attack in its own right, but a powerful step in a non-elevated attack against Apple products.
If someone were to end up running malicious code (say, due to a recent Flash Player zero day code execution exploit ...), without the need for administrative rights, they could install this plugin into the iTunes environment for that same user.
Why is this a problem?
This plugin successfully MITM attacks an iTunes purchase and extracts your Apple ID and plaintext password. Network proxying at the machine level to attack SSL traffic would normally require admin rights.
Now that the attacker has the Apple ID, they can:
- Send a remote lock or wipe command to the user's Apple devices that are using Find My Mac/iPhone.
- Log in to Messages and receive copies of everything sent to them / they say to everyone. (They will get email notification of a new device, mind you)
- Potentially find out their home address, phone number, and real name information from the Apple service portal if they've ever taken in a device to be worked on (turning it into an identity theft attack of sorts)
Etc.
Just an FYI if you're not familiar with what an Apple ID does for the average Apple user.
Mind you, without admin rights, fake alert software could also be installed on the Mac, prompting a user for credentials of some sort with a dialog specially crafted to imitate the real thing.
The difference here, however, is that it is all legit dialogs. There are no crazy unknown processes listed on the machine that a more paranoid person might notice (once the iTunes plugin is dropped). The iTunes process itself has been made malicious.
I, for one, will be changing ownership and permissions on the plugin folder on my machines to make it non-writeable without elevation.
- nknighthb 13y agoThere are three Macs, five iPhones, and five iPads in active use in my family. Additional Macs, iOS, and iPod devices sit idle or have been given away. I am intimately familiar with the ecosystem. Anyone able to use this detail in an actual "attack" assuredly has many other avenues to carry out such an attack, and will continue to have such avenues unless and until Windows and Mac OS are at least as locked down as iOS.
- pudquick 13y ago... Nothing about this article or my comment said anything about security in iOS. I have no idea what your statement is about.
- nknighthb 13y agoIf you think my comment was about the security of iOS, you need to read it again. Carefully.
- pudquick 13y agoYou're right. I re-read what you wrote. And all you did was echo the lower portions of my own comment where I admitted that "fake alert" style applications could also take these details. And I'm sure other styles of attack as well. The author of the article was trying to make a simple point though: If Apple allows an iTunes plugin such low level access that it can proxy a store transaction - ideally the thing they should be the most paranoid about - then they should probably revisit their plugin architecture (possibly taking a page from web browsing plugin sandboxing). Claiming there will always be problems until the OS is as locked down as iOS is overkill.
- nknighthb 13y agoLet's assume you're right and Apple should revisit it (I don't think they should; I prefer plugins that can, in fact, do anything they wish). How does that lead to the OP's hysterical conclusion? Browser plugin sandboxing is a very new phenomenon. Apple doesn't give a shit about security because... they said they'll investigate doing something that has only recently been done for the first time at all? What?
- teacup50 13y agoThere are a million ways to proxy a store transaction. Guess what else the user can do: - Add trusted CA certificates. - Configure proxy settings. - Launch arbitrary applications. - Delete all the users files. What you're talking about here is sandboxing to protect the user from themselves, and all the lost utility that results. In other words, iOS.
- lstamour 13y agoChanging ownership and permissions on the plugin folder won't help if an end user wants the plugin. Suddenly all iTunes plugins can't be trusted, and shouldn't have been installed in the past. In fact, I now wonder how far that extends -- if I've plugins for Xcode installed, should I worry about my developer account session in Preferences which auto-downloads and can create signing keys for apps? It's a thought...
- pudquick 13y agoIn my situation, I've never used an iTunes plugin and see no need to personally. So the solution helps me, but you're right that it's a stopgap measure that's not universally applicable.