Live data from Hacker News

Boffins reveal password-killer 0days for iOS and OS X

theregister.co.uk

11–20 of 144 posts

Re: Boffins reveal password-killer 0days for iOS and OS X

#15

So Apple was aware of this for 6 months and are doing NOTHING, not even communicating?! How serious do they take security and fixing it (at least within 6 months) ?

How do you know they was aware if they didn't "not even communicating"?

According to the article, they were aware

Re: Boffins reveal password-killer 0days for iOS and OS X

#16
Quick summary of the keychain "crack":

Keychain items have access control lists, where they can whitelist applications, usually only themselves. If my banking app creates a keychain item, malware will not have access. But malware can delete and recreate keychain items, and add both itself and the banking app to the ACL. Next time the banking app needs credentials, it will ask me to reenter them, and then store them in the keychain item created by the malware.

Re: Boffins reveal password-killer 0days for iOS and OS X

#17
post #9

Anyone have any more information about (or even a source for) "Google's Chromium security team was more responsive and removed Keychain integration for Chrome noting that it could likely not be solved at the application level"? Is this going to happen in an upcoming stable release? What is it being replaced with?

Chromium security issues are not public visible. At least as long as the security issue remains.

Re: Boffins reveal password-killer 0days for iOS and OS X

#18
Well, shit. Finally I feel justified for never (read: rarely) using the "Save password", feature in my web browser.

Does anyone know if Apple have done anything towards resolving this in the 6 month window they requested? Slightly worrying now that this has been published without a fix from Apple. I don't really download apps very often on my Mac, but probably won't for sure now until I know this has been resolved. Annoying.

Re: Boffins reveal password-killer 0days for iOS and OS X

#19
post #18

Well, shit. Finally I feel justified for never (read: rarely) using the "Save password", feature in my web browser. Does anyone know if Apple have done anything towards resolving this in the 6 month window they requested? Slightly worrying now that this has been published without a fix from Apple. I don't really download apps very often on my Mac, but probably won't for sure now until I know this has been resolved. A…

You know this was bound to happen sooner or later. That goes for any encryption technology. Last pass was recently "hacked" as well. You can't trust any crypto tech ;)

Re: Boffins reveal password-killer 0days for iOS and OS X

#20
post #16

Quick summary of the keychain "crack": Keychain items have access control lists, where they can whitelist applications, usually only themselves. If my banking app creates a keychain item, malware will not have access. But malware can delete and recreate keychain items, and add both itself and the banking app to the ACL. Next time the banking app needs credentials, it will ask me to reenter them, and then store them i…

How can malware delete a keychain item if it is not on the ACL?
Post reply on HN