3 ms·
... Nothing about this article or my comment said anything about security in iOS. I have no idea what your statement is about.
by pudquick 13y ago
... Nothing about this article or my comment said anything about security in iOS.
I have no idea what your statement is about.
- nknighthb 13y agoIf you think my comment was about the security of iOS, you need to read it again. Carefully.
- pudquick 13y agoYou're right. I re-read what you wrote. And all you did was echo the lower portions of my own comment where I admitted that "fake alert" style applications could also take these details. And I'm sure other styles of attack as well. The author of the article was trying to make a simple point though: If Apple allows an iTunes plugin such low level access that it can proxy a store transaction - ideally the thing they should be the most paranoid about - then they should probably revisit their plugin architecture (possibly taking a page from web browsing plugin sandboxing). Claiming there will always be problems until the OS is as locked down as iOS is overkill.
- nknighthb 13y agoLet's assume you're right and Apple should revisit it (I don't think they should; I prefer plugins that can, in fact, do anything they wish). How does that lead to the OP's hysterical conclusion? Browser plugin sandboxing is a very new phenomenon. Apple doesn't give a shit about security because... they said they'll investigate doing something that has only recently been done for the first time at all? What?
- teacup50 13y agoThere are a million ways to proxy a store transaction. Guess what else the user can do: - Add trusted CA certificates. - Configure proxy settings. - Launch arbitrary applications. - Delete all the users files. What you're talking about here is sandboxing to protect the user from themselves, and all the lost utility that results. In other words, iOS.
- pudquick 13y ago- Add a trusted CA: will prompt for credentials - Configure proxy settings: prompt for admin credentials - Launch arbitrary: already admitted as much - Delete all users files: yup, that's a problem But the problems I illustrated aren't limited to the single machine that gets infected. Just clarifying.
- nknighthb 13y ago> Add a trusted CA: will prompt for credentials You've already social-engineered your way to getting somebody to download and run an application, ignoring warnings along the way. Prompts for credentials when installing applications are perfectly normal. > Configure proxy settings: prompt for admin credentials ??? Not on my machine. There isn't even a padlock icon in the relevant window.
- teacup50 13y ago> - Add a trusted CA: will prompt for credentials IIRC this isn't protected by the actual keychain file, and can be done by simply editing the file manually. Regardless, peer commentator already noted that password prompts are hardly an issue here. > - Configure proxy settings: prompt for admin credentials Actually, it doesn't. Additionally, browsers have per-user local configuration.