Live data from Hacker News

I know your name, where you work, and live (Safari v4 & v5)

jeremiahgrossman.blogspot.com

31–40 of 61 posts

Re: I know your name, where you work, and live (Safari v4 & v5)

#34

Since this is a problem in the JS handling (as mention in another comment in this thread, Safari isn't differentiating between keyboard entries that were generated from JS from ones that actually came from a keyboard), that's probably in Webkit itself and therefor fixable by the community, no?

That doesn't help with an actual Safari release though, does it?

If the code is accepted it would, and likely faster than sitting on our hands hoping that Apple will care about this.

Re: I know your name, where you work, and live (Safari v4 & v5)

#36

While this exploit sounds like trouble, what's more disconcerting to me is that in mid-2010 Apple still doesn't have a functioning system in place to handle responsible disclosure.

Email product-security@apple.com or go the extra mile and encrypt it: https://www.apple.com/support/security/pgp/

Re: I know your name, where you work, and live (Safari v4 & v5)

#37
post #11
post #2

(Title sic ). Short summary: Safari autocompletes forms from your private address book, and can be tricked into doing that by Javascript events on form fields named in ways Safari would want to autocomplete; worse, once autocompleted, that data can be read out of the form by the same JS that triggered the event. Long story short, if you browse to a site with Safari and you have autocomplete on, that site can slurp so…

that site can slurp some stuff out of your address book. More specifically, it can slurp some stuff from your personal address card that you've set in AddressBook.app This hack does not allow you to get the address of someone's mother-in-law.

> This hack does not allow you to get the address of someone's mother-in-law.

Unless you're the mother-in-law :).

Re: I know your name, where you work, and live (Safari v4 & v5)

#38
post #17

> These fields are AutoFill’ed using data from the users personal record in the local operating system address book. Sorry, maybe a stupid question, but can someone explain this? I had no idea my OS had an address book. Why does it have this? If it does, how do I put stuff in it? Or delete stuff in it? Is this just on mac, or windows and linux too?

I'm quite sure that Windows has a system-wide address book service managed by the Address Book application as well, or at least does in recent versions.

Re: I know your name, where you work, and live (Safari v4 & v5)

#39
post #28

completely unrelated - didtrade http://news.ycombinator.com/user?id=didtrade has been spamming HN for 21 days now, but they're still not banned?

I was trying to think of how to ask that myself. I guess just auto-deleting whatever they post (if that's actually what's happening) is better than banning them, since a ban would alert them and they can just make a new account. This lets them continue spamming nobody (except showdead folk).

it's really obvious when you're banned.

as an example, I'm banned. enjoy this [dead] post!

Re: I know your name, where you work, and live (Safari v4 & v5)

#40
post #36

While this exploit sounds like trouble, what's more disconcerting to me is that in mid-2010 Apple still doesn't have a functioning system in place to handle responsible disclosure.

Email product-security@apple.com or go the extra mile and encrypt it: https://www.apple.com/support/security/pgp/

Apparently, he did:

> I figured Apple might appreciate a vulnerability disclosure prior to public discussion, which I did on June 17, 2010 complete with technical detail. A gleeful auto-response came shortly after, to which I replied asking if Apple was already aware of the issue. I received no response after that, human or robot.

Post reply on HN