Live data from Hacker News

iOS Privacy: Easily get a user's Apple ID password, just by asking

krausefx.com

241–250 of 326 posts

Re: iOS Privacy: Easily get a user's Apple ID password, just by asking

#241
post #13

Earlier quoted context omitted.

A solution is to only ask for the password when absolutely necessary. I still don't understand why I need to enter a password (or use touchID) to download a free app. Shouldn't it be enough to login when I want to buy something for the first time in-app? AFAIK that's how android handles it.

It is free in cost, not in terms of your privacy. For example let's say you handed your phone to your kid, they downloaded a free app, gave that app your entire contact list, and then that app spammed everyone you know? For the sake of example let's call that app LinkedIn.

Let's say you already had LinkedIn installed without contact permissions, and your kid flipped that switch and spammed everyone you knew?

Maybe Apple should require authentication to grant those permissions.... Of course, then we're back to the problem of password fatigue.

Re: iOS Privacy: Easily get a user's Apple ID password, just by asking

#242
post #93

Earlier quoted context omitted.

An aside, but wouldn’t you be better off with each person having their own Apple ID and using family sharing to share apps and such?

There's one annoying omission from family sharing: no IAP are included. And almost every kids game has one. Not talking freemium but just ones with one free level that gets kids hooked.

That doesn't appear to be the case for us. We have sharing and my spouse and son make IAPs frequently. For him, I'm alerted to authorize the payment.

Re: iOS Privacy: Easily get a user's Apple ID password, just by asking

#243

Earlier quoted context omitted.

An aside, but wouldn’t you be better off with each person having their own Apple ID and using family sharing to share apps and such?

I tried family sharing with my wife, and it resulted in her being unable to purchase any apps, even though she was set up as an adult user. We ended up turning it off because sharing apps wasn't worth the "Hey, can you buy this app for me?" coordination. And then there was all manner of nonsense after we turned it off, too. I assume there are other weird bugs in family sharing.

Works fine in our household. The only time I'm alerted is when the CC statement arrives. Then I rib her for her CC Saga addiction.

Re: iOS Privacy: Easily get a user's Apple ID password, just by asking

#244
post #227

> But, but, but, why is the . symbol within the ", is this all fake? Fun fact for those who (like me) didn't know for a long time... technically "gmail.com." is actually the domain name for Gmail. It's called the fully qualified domain name (FQDN), akin to an absolute domain name (as opposed to relative to the current subnet).

But this is more related to the American English style of placing punctiation inside the quotes, isn't it? [1] As a German (we don't do this), I also didn't like that when I saw it the first time. [1] http://www.thepunctuationguide.com/british-versus-american-s...

Indeed, and I was not trying to suggest the punctuation was due to them intentionally trying to write an FQDN. I was just mentioning a fun fact that the notation reminded me of.

Re: iOS Privacy: Easily get a user's Apple ID password, just by asking

#245

When the iPhone X notch was first announced I thought it would be a fantastic security UI opportunity: What if the top of the screen was only writable by the system? It would normally be black or show the time, but whenever there is a password dialog, it turns green with a security lock. This is something I've wanted on all computers for a while: fundamentally, any computer where you can get access to the whole scree…

This already exists on Windows (via require Ctrl-Alt-Del) and to a lesser degree on Android (by always being able to show the action bar in fullscreen).

Re: iOS Privacy: Easily get a user's Apple ID password, just by asking

#246

Earlier quoted context omitted.

Do you not have fingers? Or is there some other good reason not to use TouchID outside of the lock screen?

If your password gets compromised, you can change your passwords. If your fingerprint gets compromised, you CANT change your finger (erm... probably. I dunno of any easy way in any case)

It's not your fingerprint that's the issue, it's the data that represents your fingerprint. If that data gets compromised then it's nigh impossible to change your fingerprint. However, I believe there are ways to make this very significantly difficult, and I believe Apple has achieved this level of difficulty by placing the fingerprint data in the secure enclave.

Re: iOS Privacy: Easily get a user's Apple ID password, just by asking

#247

Earlier quoted context omitted.

> iOS should just use fingerprint always ... Some of us don't want to use TouchID so, no, it shouldn't.

Do you not have fingers? Or is there some other good reason not to use TouchID outside of the lock screen?

Not trusting apple with keeping their promise they won't share the finger print in the future is a good reason.

Re: iOS Privacy: Easily get a user's Apple ID password, just by asking

#249
post #245

When the iPhone X notch was first announced I thought it would be a fantastic security UI opportunity: What if the top of the screen was only writable by the system? It would normally be black or show the time, but whenever there is a password dialog, it turns green with a security lock. This is something I've wanted on all computers for a while: fundamentally, any computer where you can get access to the whole scree…

This already exists on Windows (via require Ctrl-Alt-Del) and to a lesser degree on Android (by always being able to show the action bar in fullscreen).

Not really. From the GP

> This is something I've wanted on all computers for a while: fundamentally, any computer where you can get access to the whole screen's buffer means you can fake a logged out screen asking you to log in, or any other number of phishing attacks.

In Windows, I can render the whole screen, so I can put up a fake login dialog. To some extent, Windows users are used to requiring a ctrl-alt-delete before being prompted for a password, but there's no reason why I can't put up a static image of what the screen looks like during a password request. Having a portion of the screen which an application is forbidden from accessing would solve this, but the requirement for full-screen applications that want to write every user-visible pixel means that there's fundamentally no way to prevent this attack.

Re: iOS Privacy: Easily get a user's Apple ID password, just by asking

#250
post #117

Earlier quoted context omitted.

One solution that seems obvious to me is - the OS itself can detect fake popups such as this. It can even be a fast neural net that checks the screen, say, once a second.

A neural net for what could be a simple string comparison?

[deleted]
Post reply on HN