How you can get hacked if you are using iPad/Safari/gmail
blog.secpanel.com
How you can get hacked if you are using iPad/Safari/gmail
1–10 of 17 posts
Re: How you can get hacked if you are using iPad/Safari/gmail
#2I guess all this article is trying to say is to use https://google.com/ in iPad. Is there anything else I'm missing here?
Re: How you can get hacked if you are using iPad/Safari/gmail
#3I guess all this article is trying to say is to use https://google.com/ in iPad. Is there anything else I'm missing here?
The google search tab on the right top in Safari/iPad is what a user tends to search in, instead of opening up a new browser tab. This opens up http://google.com, which is the issue.
Re: How you can get hacked if you are using iPad/Safari/gmail
#4Can the session information sent to non-secure Google sites be used on Gmail?
Re: How you can get hacked if you are using iPad/Safari/gmail
#5Can the session information sent to non-secure Google sites be used on Gmail?
Yes. When one is logged in as a gmail user, any google search is done as that user. Therefore the requests will carry session information just as if one were using gmail with http.
Re: How you can get hacked if you are using iPad/Safari/gmail
#6I guess all this article is trying to say is to use https://google.com/ in iPad. Is there anything else I'm missing here?
The google search tab on the right top in Safari/iPad is what a user tends to search in, instead of opening up a new browser tab. This opens up http://google.com , which is the issue.
Is that the workaround? After viewing google on https, close the tab and start a new one for searching?
Or should I always avoid http://google.com while logged into a google property on untrusted networks?
Re: How you can get hacked if you are using iPad/Safari/gmail
#7does safari leak ssl-only cookies?
Re: How you can get hacked if you are using iPad/Safari/gmail
#8a better option: use the iOS mail app (with imaps), and use application-specific passwords. don't log in to your app account from safari. you then get two benefits:
1. session cookie hijacking not possible
2. the iOS mail app supports encrypted email
Re: How you can get hacked if you are using iPad/Safari/gmail
#9I wonder (he said, sitting in the Minneapolis airport with an iPhone in hand) whether Safari exhibits the same flaw on an iPhone?
Re: How you can get hacked if you are using iPad/Safari/gmail
#10As long as gmail uses Secure cookies, then this article is completely wrong. I just checked my own cookie storage and about half of the cookies for mail.google.com are marked as Secure, but I don't know which ones are required to identify your session.