|
|||||||
![]() |
|
|
Thread Tools | Search this Thread | Display Modes |
|
|
#1 | ||
|
Safari Autofill Security Issue Permits Access to Personal Information
![]() ![]() Earlier this week, The Register detailed a security vulnerability found in Apple's Safari Autofill feature that could enable malicious websites to extract users' personal information from their Address Book entries. The security researcher, Jeremiah Grossman of WhiteHat Security, followed up with a blog post yesterday detailing the exploit and offering a proof of concept webpage allowing users to see if they are vulnerable. The vulnerability arises from Address Book's usage of simple form text fields to store the user's personal information, paired with Safari's ability to automatically grab that information through its Autofill feature to assist users with filling out web forms. Quote:
Quote:
Article Link: Safari Autofill Security Issue Permits Access to Personal Information |
|||
|
|
0
|
|
|
#2 |
|
Another reason not to use autofill.
__________________
This space intentionally not blank |
|
|
|
0
|
|
|
#3 |
|
|
0
|
|
|
#4 |
|
Dammit, I like autofill.
|
|
|
|
0
|
|
|
#5 |
|
This can be scary. It's surprising no-one has made a big deal about this until now.
__________________
Think beyond horizons Macbook Pro (OS X 10.8.2), iPhone 5 (iOS 6), iPad 3 (iOS 6) |
|
|
|
0
|
|
|
#6 |
|
Self inflicted spam! Ha
__________________
8 Core Mac Pro (2010), 16Gb Iphone 4, 16Gb 3GS, 16Gb Ipad 2, Canon 5D Mark II, Tama Drums, Palystation 3, Hoyt Katera Bow
|
|
|
|
0
|
|
|
#7 |
|
+1 on not using auto fill.
Why are there so many security vulnerabilities showing up all at once for ?
__________________
"Technological progress is like an axe in the hands of a pathological criminal." "Nationalism is an infantile disease. It is the measles of mankind. " -Einstein |
|
|
|
0
|
|
|
#8 | |
|
Quote:
__________________
2011 13" Macbook Pro, 16Gb iPhone 4S, Imac White 2.0 Core Duo, 16 GB Iphone 4 (going to the mother in law), iPad 16 GB (now the wife's) |
||
|
|
0
|
|
|
#9 |
|
Safari. Just use Firefox and you are safer than Windows and almost as safe as Linux.
__________________
Programming is much like blacksmithing. You just keep pounding on it until it looks good. Then you pretend it is done. |
|
|
|
0
|
|
|
#10 |
|
What about passwords autofill? I have that option on.
__________________
LED-Torch (for iPhone 4) |
|
|
|
0
|
|
|
#11 | |
|
Quote:
__________________
I never said that, and you're misquoting me ... or somebody is, but I'm gonna get to the bottom of it. |
||
|
|
0
|
|
|
#12 |
|
1 more reason to use 1Password... =)
__________________
aut deus aut homo malus |
|
|
|
0
|
|
|
#13 |
|
__________________
13.3" UMBP, 2.53 GHz, 8GB RAM (G.Skill), 250GB HD iPhone 4S 32 GB (ATT IMEI Unlocked) iPod Touch 8 GB 2G
|
|
|
|
0
|
|
|
#14 |
|
Been using lastpass on Leo laporte and Steve gibsons recommendation as the only one they trust and it turns off autofill when you install and then uses it's own encrypted autofill.
|
|
|
|
0
|
|
|
#15 |
|
__________________
15" Core i7, 4GB, 500GB @ 7200 HR Glossy Display |
|
|
|
0
|
|
|
#16 |
|
|
0
|
|
|
#17 |
|
__________________
I never said that, and you're misquoting me ... or somebody is, but I'm gonna get to the bottom of it. |
|
|
|
0
|
|
|
#18 |
|
What about that "Other Forms" option. Is that one cool to keep checked? It doesn't have that scary red circle around it.....
|
|
|
|
0
|
|
|
#19 |
|
Convenience and security are two opposite sides of a spectrum.
|
|
|
|
0
|
|
|
#20 |
|
I'm vulnerable...
Correction. I WAS vulnerable. Lastpass works okay?
__________________
Everything should be made as simple as possible, but not simpler. Albert Einstein |
|
|
|
0
|
|
|
#21 |
|
Just disabled it.... Only using Safari anyways since I haven't DL Firefox yet
![]() Then again, the address on this MBP is empty since I haven't synced it yet to my Mini.
__________________
010011110111001001100001011011100110011101100101010100110101011001010100011001110111010101111001 |
|
|
|
0
|
|
|
#22 |
|
|
0
|
|
|
#23 |
|
Another prime example that Apple has a huge hurdle to cross to become as security safe as they alleged. Security through obscurity is slowly dwindeling.
|
|
|
|
0
|
|
|
#24 |
|
Firefox FTW.
plus i simply cannot surf without using the AdBlock extension (every time i use Safari on iPhone i'm reminded of why..) |
|
|
|
0
|
|
|
#25 |
|
Actually, this was something I wondered about.
The email address that the proof of concept web page came up with is a MM alias I rarely use. The last couple of weeks I received 5 or 6 spams to that address. I wondered where they got it from as I rarely used it.
__________________
Everything should be made as simple as possible, but not simpler. Albert Einstein |
|
|
|
0
|
![]() |
|
«
Previous Thread
|
Next Thread
»
| Thread Tools | Search this Thread |
| Display Modes | |
|
|
Similar Threads
|
||||
| thread | Thread Starter | Forum | Replies | Last Post |
| Lion - issue with access to windows/apps | sma1001 | Mac OS X 10.7 Lion | 11 | Sep 25, 2011 03:35 PM |
| Security/Privacy issue with the way iPhone can be synced or backed up | inpulze | iPhone | 3 | Aug 20, 2011 12:36 PM |
| Security Issue | macswitcha2 | Mac Basics and Help | 2 | Feb 16, 2011 12:08 PM |
| Safari AutoFill Security Issue Rears Its Head Once Again | MacRumors | MacRumors.com News Discussion | 47 | Sep 26, 2010 11:30 AM |
| What are security issues for connecting to random wifi? | jackc | General Mac Discussion | 4 | Aug 1, 2004 01:27 PM |
All times are GMT -5. The time now is 12:58 PM.









8 Core Mac Pro (2010), 16Gb Iphone 4, 16Gb 3GS, 16Gb Ipad 2, Canon 5D Mark II, Tama Drums, Palystation 3, Hoyt Katera Bow 
Linear Mode

