Register FAQ / Rules Forum Spy Search Today's Posts Mark Forums Read
Go Back   MacRumors Forums > News and Article Discussion > MacRumors.com News Discussion

Reply
 
Thread Tools Search this Thread Display Modes
Old Jul 22, 2010, 10:59 AM   #1
MacRumors
macrumors bot
 
Join Date: Apr 2001
Safari Autofill Security Issue Permits Access to Personal Information






Earlier this week, The Register detailed a security vulnerability found in Apple's Safari Autofill feature that could enable malicious websites to extract users' personal information from their Address Book entries. The security researcher, Jeremiah Grossman of WhiteHat Security, followed up with a blog post yesterday detailing the exploit and offering a proof of concept webpage allowing users to see if they are vulnerable.

The vulnerability arises from Address Book's usage of simple form text fields to store the user's personal information, paired with Safari's ability to automatically grab that information through its Autofill feature to assist users with filling out web forms.
Quote:
All a malicious website would have to do to surreptitiously extract Address Book card data from Safari is dynamically create form text fields with the aforementioned names, probably invisibly, and then simulate A-Z keystroke events using JavaScript. When data is populated, that is AutoFill'ed, it can be accessed and sent to the attacker.
For some reason, fields that begin with numbers such as phone numbers and street addresses are not subject to this vulnerability. A user's name, company affiliation, city/state/country, and email addresses can, however, typically be accessed.
Quote:
Still, such attacks could be easily and cheaply distributed on a mass scale using an advertising network where likely no one would ever notice because it's not exploit code designed to deliver rootkit payload. In fact, there is no guarantee this has not already taken place. What is safe to say is that this vulnerability is so brain dead simple that I assumed someone else must have publicly reported it already, but exhaustive searches and asking several colleagues turned up nothing.
Grossman reports that he submitted information on the vulnerability to Apple on June 17th, but has received nothing more than an automatic acknowledgement of his submission despite an attempted follow-up. Consequently, Grossman is making public disclosure of the vulnerability so that users can take steps to protect themselves by disabling the Autofill feature, which is turned on by default.

Article Link: Safari Autofill Security Issue Permits Access to Personal Information
MacRumors is offline   0 Reply With Quote
Old Jul 22, 2010, 11:02 AM   #2
nwcs
macrumors 6502a
 
Join Date: Sep 2009
Location: Tennessee
Another reason not to use autofill.
__________________
This space intentionally not blank
nwcs is offline   0 Reply With Quote
Old Jul 22, 2010, 11:03 AM   #3
seven2k7
macrumors member
 
Join Date: Jan 2007
Quote:
Originally Posted by nwcs View Post
Another reason not to use autofill.
http://arstechnica.com/security/news...insecurity.ars
seven2k7 is offline   0 Reply With Quote
Old Jul 22, 2010, 11:04 AM   #4
ThunderSkunk
macrumors 65816
 
ThunderSkunk's Avatar
 
Join Date: Dec 2007
Location: On da moon.
Dammit, I like autofill.
ThunderSkunk is offline   0 Reply With Quote
Old Jul 22, 2010, 11:06 AM   #5
applephysci
macrumors regular
 
Join Date: Aug 2008
Location: CA
This can be scary. It's surprising no-one has made a big deal about this until now.
__________________
Think beyond horizons

Macbook Pro (OS X 10.8.2), iPhone 5 (iOS 6), iPad 3 (iOS 6)
applephysci is offline   0 Reply With Quote
Old Jul 22, 2010, 11:06 AM   #6
xxgilxx
macrumors regular
 
Join Date: Jul 2010
Self inflicted spam! Ha
__________________
8 Core Mac Pro (2010), 16Gb Iphone 4, 16Gb 3GS, 16Gb Ipad 2, Canon 5D Mark II, Tama Drums, Palystation 3, Hoyt Katera Bow
xxgilxx is offline   0 Reply With Quote
Old Jul 22, 2010, 11:07 AM   #7
Corrosive vinyl
macrumors 6502
 
Join Date: Sep 2006
+1 on not using auto fill.

Why are there so many security vulnerabilities showing up all at once for ?
__________________
"Technological progress is like an axe in the hands of a pathological criminal."
"Nationalism is an infantile disease. It is the measles of mankind. " -Einstein
Corrosive vinyl is offline   0 Reply With Quote
Old Jul 22, 2010, 11:08 AM   #8
gloomcookie1
macrumors regular
 
Join Date: Jun 2009
Location: WPB, FL
Quote:
Originally Posted by seven2k7 View Post
Though this does not necessarily mean that Apple's software is the most insecure in practice—the report takes no consideration of the severity of the flaws—it points at a growing trend in the world of security flaws: the role of third-party software. Many of Apple's flaws are not in its operating system, Mac OS X, but rather in software like Safari, QuickTime, and iTunes. Vendors like Adobe (with Flash and Adobe Reader) and Oracle (with Java) are similarly responsible for many of the flaws being reported.
__________________
2011 13" Macbook Pro, 16Gb iPhone 4S, Imac White 2.0 Core Duo, 16 GB Iphone 4 (going to the mother in law), iPad 16 GB (now the wife's)
gloomcookie1 is offline   0 Reply With Quote
Old Jul 22, 2010, 11:09 AM   #9
RalfTheDog
macrumors 65816
 
RalfTheDog's Avatar
 
Join Date: Feb 2010
Location: Lagrange Point
Quote:
Originally Posted by Corrosive vinyl View Post
+1 on not using auto fill.

Why are there so many security vulnerabilities showing up all at once for ?
Safari. Just use Firefox and you are safer than Windows and almost as safe as Linux.
__________________
Programming is much like blacksmithing. You just keep pounding on it until it looks good. Then you pretend it is done.
RalfTheDog is offline   0 Reply With Quote
Old Jul 22, 2010, 11:10 AM   #10
ColdCoffee
macrumors member
 
Join Date: Jul 2007
What about passwords autofill? I have that option on.
__________________
LED-Torch (for iPhone 4)
ColdCoffee is offline   0 Reply With Quote
Old Jul 22, 2010, 11:11 AM   #11
Lord Vader
macrumors 6502a
 
Lord Vader's Avatar
 
Join Date: Apr 2010
Location: Death Star
Quote:
Originally Posted by seven2k7 View Post
ArsTechnica is not what is was.
__________________
I never said that, and you're misquoting me ... or somebody is, but I'm gonna get to the bottom of it.
Lord Vader is offline   0 Reply With Quote
Old Jul 22, 2010, 11:12 AM   #12
rKunda
macrumors 65816
 
rKunda's Avatar
 
Join Date: Jul 2008
1 more reason to use 1Password... =)
__________________
aut deus aut homo malus
rKunda is offline   0 Reply With Quote
Old Jul 22, 2010, 11:16 AM   #13
HikariYuki
macrumors member
 
Join Date: Jun 2009
Quote:
Originally Posted by rKunda View Post
1 more reason to use 1Password... =)
+1 for 1password.
__________________
13.3" UMBP, 2.53 GHz, 8GB RAM (G.Skill), 250GB HD
iPhone 4S 32 GB (ATT IMEI Unlocked)
iPod Touch 8 GB 2G
HikariYuki is offline   0 Reply With Quote
Old Jul 22, 2010, 11:16 AM   #14
Nicklaus
macrumors regular
 
Join Date: Jun 2010
Location: The Space Coast
Been using lastpass on Leo laporte and Steve gibsons recommendation as the only one they trust and it turns off autofill when you install and then uses it's own encrypted autofill.
Nicklaus is offline   0 Reply With Quote
Old Jul 22, 2010, 11:16 AM   #15
Novaoblivion
macrumors member
 
Join Date: Jan 2006
Quote:
Originally Posted by rKunda View Post
1 more reason to use 1Password... =)
Indeed 1Password is great!
__________________
15" Core i7, 4GB, 500GB @ 7200 HR Glossy Display
Novaoblivion is offline   0 Reply With Quote
Old Jul 22, 2010, 11:17 AM   #16
Block
macrumors 6502a
 
Block's Avatar
 
Join Date: Jun 2007
Quote:
Originally Posted by Corrosive vinyl View Post
+1 on not using auto fill.

Why are there so many security vulnerabilities showing up all at once for ?
There aren't that many for the operating system itself, it is mostly the third-party software programs that are causing problems.
Block is offline   0 Reply With Quote
Old Jul 22, 2010, 11:17 AM   #17
Lord Vader
macrumors 6502a
 
Lord Vader's Avatar
 
Join Date: Apr 2010
Location: Death Star
Quote:
Originally Posted by rKunda View Post
1 more reason to use 1Password... =)
1Password is bug free?
__________________
I never said that, and you're misquoting me ... or somebody is, but I'm gonna get to the bottom of it.
Lord Vader is offline   0 Reply With Quote
Old Jul 22, 2010, 11:19 AM   #18
Surely
Guest
 
Join Date: Oct 2007
Location: Los Angeles, CA
What about that "Other Forms" option. Is that one cool to keep checked? It doesn't have that scary red circle around it.....
Surely is offline   0 Reply With Quote
Old Jul 22, 2010, 11:20 AM   #19
Mac-Michael
macrumors regular
 
Join Date: Jan 2010
Convenience and security are two opposite sides of a spectrum.
Mac-Michael is offline   0 Reply With Quote
Old Jul 22, 2010, 11:20 AM   #20
Morod
macrumors 65816
 
Join Date: Jan 2008
Location: On The Nickel, over there....
I'm vulnerable...
Correction. I WAS vulnerable.
Lastpass works okay?
__________________
Everything should be made as simple as possible, but not simpler.
Albert Einstein
Morod is offline   0 Reply With Quote
Old Jul 22, 2010, 11:22 AM   #21
OrangeSVTguy
macrumors 68040
 
OrangeSVTguy's Avatar
 
Join Date: Sep 2007
Location: Northeastern Ohio
Just disabled it.... Only using Safari anyways since I haven't DL Firefox yet

Then again, the address on this MBP is empty since I haven't synced it yet to my Mini.
__________________
010011110111001001100001011011100110011101100101010100110101011001010100011001110111010101111001

OrangeSVTguy is offline   0 Reply With Quote
Old Jul 22, 2010, 11:23 AM   #22
Nicklaus
macrumors regular
 
Join Date: Jun 2010
Location: The Space Coast
Quote:
Originally Posted by Morod View Post
I'm vulnerable...
Lastpass works okay?
It works for me if you watch the security now podcast they talk for about 2 hours over two or three of the last episodes all about why they like it.

Convinced me.

And it's free
Nicklaus is offline   0 Reply With Quote
Old Jul 22, 2010, 11:23 AM   #23
WiiDSmoker
macrumors 65816
 
WiiDSmoker's Avatar
 
Join Date: Sep 2009
Location: Hermitage, TN
Another prime example that Apple has a huge hurdle to cross to become as security safe as they alleged. Security through obscurity is slowly dwindeling.
WiiDSmoker is offline   0 Reply With Quote
Old Jul 22, 2010, 11:25 AM   #24
jeffereyj
macrumors member
 
Join Date: Aug 2007
Firefox FTW.

plus i simply cannot surf without using the AdBlock extension (every time i use Safari on iPhone i'm reminded of why..)
jeffereyj is offline   0 Reply With Quote
Old Jul 22, 2010, 11:25 AM   #25
Morod
macrumors 65816
 
Join Date: Jan 2008
Location: On The Nickel, over there....
Actually, this was something I wondered about.
The email address that the proof of concept web page came up with is a MM alias I rarely use. The last couple of weeks I received 5 or 6 spams to that address. I wondered where they got it from as I rarely used it.
__________________
Everything should be made as simple as possible, but not simpler.
Albert Einstein
Morod is offline   0 Reply With Quote

Reply
MacRumors Forums > News and Article Discussion > MacRumors.com News Discussion

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
thread Thread Starter Forum Replies Last Post
Lion - issue with access to windows/apps sma1001 Mac OS X 10.7 Lion 11 Sep 25, 2011 03:35 PM
Security/Privacy issue with the way iPhone can be synced or backed up inpulze iPhone 3 Aug 20, 2011 12:36 PM
Security Issue macswitcha2 Mac Basics and Help 2 Feb 16, 2011 12:08 PM
Safari AutoFill Security Issue Rears Its Head Once Again MacRumors MacRumors.com News Discussion 47 Sep 26, 2010 11:30 AM
What are security issues for connecting to random wifi? jackc General Mac Discussion 4 Aug 1, 2004 01:27 PM


All times are GMT -5. The time now is 12:58 PM.

Mac Rumors | Mac | iPhone | iPhone Game Reviews | iPhone Apps

Mobile Version | Fixed | Fluid | Fluid HD
Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.

Privacy / DMCA contact / Affiliate and FTC Disclosure
Copyright 2002-2013, MacRumors.com, LLC