Live data from Hacker News

iOS Privacy: Easily get a user's Apple ID password, just by asking

krausefx.com

161–170 of 326 posts

Re: iOS Privacy: Easily get a user's Apple ID password, just by asking

#161
post #88

Earlier quoted context omitted.

You sure about that? The screenshots in the article don't show the keyboard being a different color with a legitimate pop-up.

On my iPhone it does. It goes from a light grey (normal keyboard) to a dark grey (system password entry keyboard).

Try it in a few more apps it's the choice of the app dev so basically random.

Not that a user should have to know "only enter your password into the black keyboard", which can also be faked mind.

Re: iOS Privacy: Easily get a user's Apple ID password, just by asking

#162

Isn't this one of the oldest tricks in the book? the following story is completely made up... When I was in college me and a friend re-made the win2000 login sequence in visual basic to play pranks on people. After typing username and password it pretended to load and then just quit itself so the desktop would show so it looked like everything was fine. We'd then go in and do the classic "take a screenshot of your de…

If you had enough access to run your Visual Basic program, didn't you already have enough access to change the wallpaper and hide the icons even without the victim's password?

Re: iOS Privacy: Easily get a user's Apple ID password, just by asking

#163
post #93

Earlier quoted context omitted.

An aside, but wouldn’t you be better off with each person having their own Apple ID and using family sharing to share apps and such?

There's one annoying omission from family sharing: no IAP are included. And almost every kids game has one. Not talking freemium but just ones with one free level that gets kids hooked.

IAP = In App Purchases

Re: iOS Privacy: Easily get a user's Apple ID password, just by asking

#164
post #160

Can anyone parse this sentence? I have no idea what it's trying to say: Nope, actually, that's how the system dialog looks like, the . is within the "string notation, so I designed the phishing dialog to also include this little, but very important design detail

If you look at the dialog, there is a '.' (period) at the end of the email address, inside the quotation ("). The author replicated this, even though it seems strange.

Re: iOS Privacy: Easily get a user's Apple ID password, just by asking

#165
post #160

Can anyone parse this sentence? I have no idea what it's trying to say: Nope, actually, that's how the system dialog looks like, the . is within the "string notation, so I designed the phishing dialog to also include this little, but very important design detail

If you look carefully at the screenshot, it shows

`"email@email.com."` inside the quotation markers.

He's saying he knows it looks weird, but you have to get that detail right to look exactly like the system dialog

Re: iOS Privacy: Easily get a user's Apple ID password, just by asking

#166

Earlier quoted context omitted.

I have a joke with my family that I am forced to enter iTunes password on at least one iOS device - daily. We share one iTunes account, and when you enter the password on one device, all the others prompt for a password when unlocked. It's mildly frustrating when you have kids, and multiple iOS devices. The scenario goes like this: One of my kids' Messages app stops working (thanks Apple!). I am forced to turn off/on…

An aside, but wouldn’t you be better off with each person having their own Apple ID and using family sharing to share apps and such?

Family Sharing has its own annoying issues. A spent one entire Saturday trying to work through everything just so my son could way Frozen on his iPad. This was the most frustrating experience I've had in a long time. You'd think it would be easy, but it wasn't.

In the end, I just let him watch it on my device and he was happy. Myself? I'm of the opinion that whoever design Apple Family Sharing should be ashamed. It's a horribly convoluted system that was either a) never tested by a real family (or they were completely ignored) or b) designed to be horrible on purpose.

Re: iOS Privacy: Easily get a user's Apple ID password, just by asking

#167
post #160

Can anyone parse this sentence? I have no idea what it's trying to say: Nope, actually, that's how the system dialog looks like, the . is within the "string notation, so I designed the phishing dialog to also include this little, but very important design detail

He's saying on native dialogues, when it lists your Apple ID email address, it includes a full stop at the end. The address and the full stop both happen to be in double quotation marks. Many phishers would place the full stop after the quotation marks, or omit it entirely.

legit -> "bill@apple.com." not-legit -> "bill@apple.com"

But you're right, it's a terrifically difficult sentence to read.

Re: iOS Privacy: Easily get a user's Apple ID password, just by asking

#168
post #93

Earlier quoted context omitted.

An aside, but wouldn’t you be better off with each person having their own Apple ID and using family sharing to share apps and such?

There's one annoying omission from family sharing: no IAP are included. And almost every kids game has one. Not talking freemium but just ones with one free level that gets kids hooked.

Oh, interesting. I hadn't encountered that, but that's very annoying.

Re: iOS Privacy: Easily get a user's Apple ID password, just by asking

#169

Earlier quoted context omitted.

An aside, but wouldn’t you be better off with each person having their own Apple ID and using family sharing to share apps and such?

I'm sure there is a better way, but it would probably require a "weekends worth" of time to convert my entire iOS empire . When we started with Apple, "family sharing" and "ask to buy" wasn't a thing (so I'm not locked into the shared model) but I will definitely check it out - I didn't know I could create an Apple ID for my child AND share apps among all family members. For those interested: https://support.apple.co…

I set up Family Sharing this weekend and you are correct for a family of five it is like a half day effort including figuring out unique usernames, being asked to use the same secret questions and then fixing the settings on each iOS device. If you have a toddler hanging on you and a curious 9 old, it is exhausting. Still it seems worth it as with each iOS update iMessages is re-enabled, which would lead to embarrassment if my vigilance wavers. Also, I like the idea of the kids having their own iCloud sync/backups.

Re: iOS Privacy: Easily get a user's Apple ID password, just by asking

#170
post #87
post #23

Earlier quoted context omitted.

I wrote this email to sjobs@apple.com back in 2011. Never heard back :-/ Dear Steve, There's one thing that's always bothered me about MacOS security. When a MacOS dialog pops up (e.g. to ask you for your password), there'sno way to tell for sure that it's MacOS that owns the dialog. A similar problem exists on the iPhone when I am asked for my iTunes password. I wanted to write and suggest an easy fix, that would ma…

Prescient of you! Although I’m skeptical that users will really be alerted by the absence of a thing. The users I work with wouldn’t. But I would prefer it. The inability to use the home button on the dialogues has become second nature to me out of healthy distrust/ paranoia.

I mean this flaw has been known for years. How long have we been pressing ctrl-alt-delete to log in to Windows?
Post reply on HN