What if we make you feel special and offer a $100 Amazon gift card for your valuable feedback on these new features?
No thanks. I never go for offers like that. If it looks to good to be true it usually is.
What if we make you feel special and offer a $100 Amazon gift card for your valuable feedback on these new features?
Who installs apps from non official app stores?? I never did that even when I had an Android.
Also more importantly... Why would you answer a text/email from someone you do not know?
And that's fine. What I was saying is that this can apply to anyone. Anyone can certainly choose what they do or don't do, but it's not limited to someone who jailbreaks, or to someone that uses their device in an enterprise environment or anything like that. It might not be something that you end up doing, as is the case for many other things I'm sure, but that doesn't mean much as far as what many others do or might do, or what that means as far as this issue being in existence and/or needing to be addressed in some way.
Honestly, that truly is the point here. Anyone of the best, most tech savvy users can inadvertently click such an unthreatening prompt.
Actually lots of legitimate betas out there for different apps, so nothing really wrong with people deciding to use those (with or usually without any compensation). Generally nothing that looks too good for most of those.No thanks. I never go for offers like that. If it looks to good to be true it usually is.
Actually lots of legitimate betas out there for different apps, so nothing really wrong with people deciding to use those (with or usually without any compensation). Generally nothing that looks too good for most of those.
With iOS 8 one or at most two prompts, and they might very well be fully expected if someone is installing some beta or preview app, which is generally quite legitimate and quite a few people do.You have to click on a few prompts... Inadvertently? And then not realize one of your Apps got wiped and didn't get what you clicked for. On the other side, someone needs and enterprise profile signed by Apple (not revoked).
They probably need to fix the installation of one app overwriting an other without the knowledge of the user (so someone at least don't get one of their apps replaced maliciously), but for the rest, not sure what Apple can do more than their doing now. Even if they exposed the profiles to the users and got them to click to accept... It would still just one more click the users would possibly do... This wouldn't stop them.
Sure, again, we understand, not you, but again, quite a few others. All of this isn't to say that you would do anything, it's to point out that with these things there's no particular environment to be in and no particular "too good to be true" catch that would necessarily be obvious--it can be part of fairly regular things that at least some people do.Nope not me. I didn't even go for the Tapatalk beta. I don't do betas on my phone. Period. I'm much pickier about what goes on my phone because I need it to work as a phone and not doing anything that would make it less stable or reliable.
Nothing has to come to an end for there to still be an issue that needs to be addressed. Plenty of less obvious and even less problematic security issues get discovered everywhere all the time and get patched. The more secure a system is typically seen to be and is made out to be the more discussion there would typically be for any exploit that could be found for it. Doesn't mean the world is ending or anything like that, but it still means there's an issue that people should know about and more importantly that should be addressed.So we have another malware that will utilize Apple approved technical approaches to install a fake Gmail app, which will ask your permission to trust an untrusted certification, so that it can finally do something bad.
Wow the world is coming to an end.
So we have another malware that will utilize Apple approved technical approaches to install a fake Gmail app, which will ask your permission to trust an untrusted certification, so that it can finally do something bad.
Wow the world is coming to an end.
You have to click on a few prompts... Inadvertently? And then not realize one of your Apps got wiped and didn't get what you clicked for. On the other side, someone needs and enterprise profile signed by Apple (not revoked).
They probably need to fix the installation of one app overwriting an other without the knowledge of the user (so someone at least don't get one of their apps replaced maliciously), but for the rest, not sure what Apple can do more than their doing now. Even if they exposed the profiles to the users and got them to click to accept... It would still just one more click the users would possibly do... This wouldn't stop them.
Nothing has to come to an end for there to still be an issue that needs to be addressed. Plenty of less obvious and even less problematic security issues get discovered everywhere all the time and get patched. The more secure a system is typically seen to be and is made out to be the more discussion there would typically be for any exploit that could be found for it. Doesn't mean the world is ending or anything like that, but it still means there's an issue that people should know about and more importantly that should be addressed.
Heh..the world is coming to an end but not because of this stuff. Climate catastrophe and Ebola or some other plague will wipe out humanity soon enough.
I was think the Walking Dead.![]()
So this is proof of concept vs. an actual exploit that is out in the wild? When you install an enterprise app there are no prompts asking if you want to provision first and no alerts afterward? This exploit goes beyond regular enterprise app permissions and gets root access? If no then how does it intercept email and texts? Thanks.
It seems that the profile can get installed transparently essentially simply as part of the app installation, at least in iOS 8.You first have to install the enterprise profile (click on a link with a stolen cert signed by Apple (that hasn't been revoked) for your enterprise), then you have to click another link and then accept the installation of the app of name X.
One of the issue is that app name X replaces App Y without telling you it does that (because it was claiming it was app X). So, if you use app Y, well if its agile enough to imitate it, you could give info your not supposed too to that app (they're probably only imitating the logging screen anyway to get your password).
Of course, since app X is now installed as App Y, you actually didn't get App X at all. That should give you a clue there is a problem... That and probably seeing App Y with the download bar on its icon when it shouldn't have it.
You first have to install the enterprise profile (click on a link with a stolen cert signed by Apple (that hasn't been revoked) for your enterprise), then you have to click another link and then accept the installation of the app of name X.
One of the issue is that app name X replaces App Y without telling you it does that (because it was claiming it was app X). So, if you use app Y, well if its agile enough to imitate it, you could give info your not supposed too to that app (they're probably only imitating the logging screen anyway to get your password).
Of course, since app X is now installed as App Y, you actually didn't get App X at all. That should give you a clue there is a problem... That and probably seeing App Y with the download bar on its icon when it shouldn't have it.
It seems that the profile can get installed transparently essentially simply as part of the app installation, at least in iOS 8.
When iOS's SA/QC teams even failed to get the native apps work right, what can we expect about defending (or fixing) aasholes? I mean backholes.
I didn't just disappoint about iOS 8, it is indeed the first version of iOS I hate.
If we can vote for the Apple CEO, I vote Elon Musk over Tim Cook. At least he sounds much visionary in future technology, as a contrast to Tim's shortsighted U2 and Beat business decisions...![]()
JGRE said:What I learned from this video is:
don't install apps from unknown sources
do not use G-Mail.
Yup, a few people confirmed it. Basically just one pop up to install or not install and potentially one when running the app for the first time to trust the developer or not. But rather transparent profile installation and it seems it can stay on even if the app is removed without user knowledge essentially since in iOS 8 there's no way to see those profiles on the device itself.You're sure that it doesn't need a separate click? Since the profile install doesn't need user input if the certificate is OK, I guess it could get installed at the same and then you'd only need to click twice instead of 3 times.
I'd wait for someone to confirm that first.
But, as I said, it wouldn't matter much anyway, people would click anyway even if the profile had a big warning in bright red letters.
Ideally, provisioning should probably be turned on by company IT on a phone by phone basis by putting a corporate certificate specific to the phone before being given to the user. A phone should only accept certificates from specific companies or not at all (disable provisioning).
----------
7 is almost like 8 from a user point of view, so not sure what you're talking about. Elon Musk is a gasbag who is one big bad decision from going bankrupt. Not sure I'd want that at Apple. As for tech, Tesla is much better at marketing itself than at tech...