Godlike Productions - Discussion Forum
Users Online Now: 2,192 (Who's On?)Visitors Today: 1,508,042
Pageviews Today: 2,507,169Threads Today: 1,002Posts Today: 17,873
11:23 PM


Rate this Thread

Absolute BS Crap Reasonable Nice Amazing
 

Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months

 
Face Palmer
Offer Upgrade

User ID: 1149868
Germany
06/17/2015 10:16 AM
Report Abusive Post
Report Copyright Violation
Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
Six university researchers have revealed deadly zero-day flaws in Apple's iOS and OS X, claiming it is possible to crack Apple's keychain, break app sandboxes and bypass its App Store security checks so that attackers can steal passwords from any installed app including the native email client without being detected.

The team was able to upload malware to the Apple app store, passing the vetting process without triggering alerts that could raid the keychain to steal passwords for services including iCloud and the Mail app, and all those store within Google Chrome.

Lead researcher Luyi Xing told El Reg he and his team complied with Apple's request to withhold publication of the research for six months, but had not heard back as of the time of writing.

They say the holes are still present in the Apple platforms meaning their work will likely be consumed by attackers looking to weaponise the work.

Apple was not immediately available for comment.

[link to www.theregister.co.uk]
"The world will soon wake up to the reality that everyone is broke and can collect nothing from the bankrupt, who are owed unlimited amounts by the insolvent, who are attempting to make late payments on a bank holiday in the wrong country, with an unacceptable currency, against defaulted collateral, of which nobody is sure who holds title."

Never attribute to malice that which is adequately explained by stupidity.

The woman who is not pursued sets up the doctrine that pursuit is offensive to her sex, and wants to make it a felony. No genuinely attractive woman has any such desire. - H.L. Mencken, In Defense Of Women
Face Palmer  (OP)

User ID: 1149868
Germany
06/17/2015 10:18 AM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
Apples new slogan: Half the security, twice the price.
"The world will soon wake up to the reality that everyone is broke and can collect nothing from the bankrupt, who are owed unlimited amounts by the insolvent, who are attempting to make late payments on a bank holiday in the wrong country, with an unacceptable currency, against defaulted collateral, of which nobody is sure who holds title."

Never attribute to malice that which is adequately explained by stupidity.

The woman who is not pursued sets up the doctrine that pursuit is offensive to her sex, and wants to make it a felony. No genuinely attractive woman has any such desire. - H.L. Mencken, In Defense Of Women
grumpier

User ID: 1189758
China
06/17/2015 10:25 AM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
Apples new slogan: Half the security, twice the price.
 Quoting: Face Palmer


ohyeahscheming
If you think a thread is important enough for others to read, go to page one and click on the green pin!!!
Anonymous Coward
User ID: 69524238
United States
06/17/2015 10:30 PM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
obigbro
Anonymous Coward
User ID: 61554461
United States
06/17/2015 11:13 PM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
no wonder what with all the disgruntled win 7 folks with a stupid win10 icon popping up
First Born

User ID: 69278990
United States
06/17/2015 11:14 PM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
So you download a "free flashlight app"...

Made by some guy in China.

Never mind the fact that the TOS clearly states you may or may not be opening your phone up completely to some guy in China.
Anonymous Coward
User ID: 69535124
United Kingdom
06/17/2015 11:19 PM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
Apples new slogan: Half the security, twice the price.
 Quoting: Face Palmer


Funny as that slogan is it couldn't be further from the truth. Their devices offer the illusion of security with none in reality and at way more than twice the price of its worth for a toy that shares exactly the same os and features of its lowest end product.
Anonymous Coward
User ID: 69535124
United Kingdom
06/17/2015 11:21 PM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
no wonder what with all the disgruntled win 7 folks with a stupid win10 icon popping up
 Quoting: Boris the Cat


You mean fake apple propaganda about disgruntled windows users.
Anonymous Coward
User ID: 69127000
United States
06/17/2015 11:21 PM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
I think most people on GLP finally realized that crApple is over priced shit.
GFX guy

User ID: 66197238
United States
06/17/2015 11:25 PM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
So you download a "free flashlight app"...

Made by some guy in China.

Never mind the fact that the TOS clearly states you may or may not be opening your phone up completely to some guy in China.
 Quoting: First Born


You have a good point! It sounds like a few years ago when so many downloaded that Adobe CS install from pirate bay that was a trojan horse.

The only way to be fully secure is by being insecure.
Anonymous Coward
User ID: 69535124
United Kingdom
06/17/2015 11:34 PM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
So you download a "free flashlight app"...

Made by some guy in China.

Never mind the fact that the TOS clearly states you may or may not be opening your phone up completely to some guy in China.
 Quoting: First Born


You have a good point! It sounds like a few years ago when so many downloaded that Adobe CS install from pirate bay that was a trojan horse.

The only way to be fully secure is by being insecure.
 Quoting: GFX guy


I bet you have yet to realise the true purpose of antivirus.
GFX guy

User ID: 66197238
United States
06/17/2015 11:36 PM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
So you download a "free flashlight app"...

Made by some guy in China.

Never mind the fact that the TOS clearly states you may or may not be opening your phone up completely to some guy in China.
 Quoting: First Born


You have a good point! It sounds like a few years ago when so many downloaded that Adobe CS install from pirate bay that was a trojan horse.

The only way to be fully secure is by being insecure.
 Quoting: GFX guy


I bet you have yet to realise the true purpose of antivirus.
 Quoting: Anonymous Coward 69535124


Just ask John McAfee.
Rodnasty
User ID: 30511334
United States
06/17/2015 11:43 PM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
You miss the point bro, Windows 10 IS Bullshit. It's terrible that they are casting parts aside for this Bullshit helmet. FUCK the helmet. XP UNTIL THE APOCALYPSE
Daughter

User ID: 1482388
06/17/2015 11:43 PM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
With all the other things going on with all of it, forget the banks, the apple whatever and keep everything close to home, off the net.

No information to steal, well that will keep the honest. I am seriously thinking about ways to do just that. You can be on the Internet without being on the Internet with all you have.

We rely on them to much for somethings. Trust has not been earned.
Daughter out with my own way.
Anonymous Coward
User ID: 69514303
Romania
06/18/2015 12:24 AM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
Apple computer tech ceased to be top notch many years ago, when the NVidia low qual soldering on MBP motherboards started to plague tenths of thousands of Apple notebooks worldwide and Apple trying to ignore, diminish the importance, etc, but still their OS's were best.

But, with all the developments lately, this high tech companies adhering to government imposed backdoors policies, it seems also their soft platforms are going downhill, not only the hardware.

It's a big pity.

This writing from an MBP right now:
verysad
Anonymous Coward
User ID: 69514303
Romania
06/18/2015 12:25 AM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
With all the other things going on with all of it, forget the banks, the apple whatever and keep everything close to home, off the net.

No information to steal, well that will keep the honest. I am seriously thinking about ways to do just that. You can be on the Internet without being on the Internet with all you have.

We rely on them to much for somethings. Trust has not been earned.
 Quoting: Daughter


Exactly this was in my mind when I wrote this thread:

Thread: GLP **** help is needed *** Resources and guidelines for paper note taking, paper archival, as it was before WWII
Anonymous Coward
User ID: 35707726
Philippines
06/18/2015 12:44 AM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
APPLE BLOCKS MANY TECHNOLOGIES that compete with their stores LIKE webrtc etc.. people buy apples for ego not for perfromance the IQ of apple users is low and their ego image requirements high.
El Penguino

User ID: 69491941
United States
06/18/2015 12:54 AM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
APPLE BLOCKS MANY TECHNOLOGIES that compete with their stores LIKE webrtc etc.. people buy apples for ego not for perfromance the IQ of apple users is low and their ego image requirements high.
 Quoting: Anonymous Coward 35707726


You mean the starbucks drinking, I listen to bands no ones heard of apple users?

Yes I agree with you
Anonymous Coward
User ID: 52385793
United Kingdom
06/18/2015 01:38 AM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
Just get Ubuntu. All free, no hassle, emulates windows if you want it to, and and is secure. Posting this from 15.04
Anonymous Coward
User ID: 15254859
United Kingdom
06/18/2015 01:44 AM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
And the best part is, they want to handle all your payments through applepay - ahahahahhahhaha
Anonymous Coward
User ID: 67289065
United States
06/18/2015 01:47 AM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
WOAH!!!!!!
Deejay

User ID: 69535556
South Africa
06/18/2015 01:51 AM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
Just get Ubuntu. All free, no hassle, emulates windows if you want it to, and and is secure. Posting this from 15.04
 Quoting: Anonymous Coward 52385793


This might surprise you..
[link to www.gfi.com]
Know Thyself.
Anonymous Coward
User ID: 4736366
United States
06/18/2015 03:05 AM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
Sigh... the apple vs microsoft vs linux vs my ham sandwich is all self correcting. Eventually you will realize that black hats dont give two shits about your OS. They can pwn them all. They go where the money is.

Comical really.
Face Palmer  (OP)

User ID: 69539257
Germany
06/18/2015 03:35 AM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
Just get Ubuntu. All free, no hassle, emulates windows if you want it to, and and is secure. Posting this from 15.04
 Quoting: Anonymous Coward 52385793


This might surprise you..
[link to www.gfi.com]
 Quoting: Deejay


Nothing is safe
"The world will soon wake up to the reality that everyone is broke and can collect nothing from the bankrupt, who are owed unlimited amounts by the insolvent, who are attempting to make late payments on a bank holiday in the wrong country, with an unacceptable currency, against defaulted collateral, of which nobody is sure who holds title."

Never attribute to malice that which is adequately explained by stupidity.

The woman who is not pursued sets up the doctrine that pursuit is offensive to her sex, and wants to make it a felony. No genuinely attractive woman has any such desire. - H.L. Mencken, In Defense Of Women
Anonymous Coward
User ID: 69406164
United States
06/18/2015 04:11 AM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
bsflagbsflag:gaythread2:


I dont believe it for a second. would have heard about it on anti Apple sites LONG before now-
Texas Twister

User ID: 67062213
United States
06/18/2015 04:16 AM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
bump
Face Palmer  (OP)

User ID: 69539257
Germany
06/18/2015 04:34 AM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
bsflagbsflag:gaythread2:


I dont believe it for a second. would have heard about it on anti Apple sites LONG before now-
 Quoting: Anonymous Coward 69406164


I'm sorry about your iPhone bro
"The world will soon wake up to the reality that everyone is broke and can collect nothing from the bankrupt, who are owed unlimited amounts by the insolvent, who are attempting to make late payments on a bank holiday in the wrong country, with an unacceptable currency, against defaulted collateral, of which nobody is sure who holds title."

Never attribute to malice that which is adequately explained by stupidity.

The woman who is not pursued sets up the doctrine that pursuit is offensive to her sex, and wants to make it a felony. No genuinely attractive woman has any such desire. - H.L. Mencken, In Defense Of Women
Anonymous Coward
User ID: 24957083
United States
06/18/2015 05:02 AM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
Apples new slogan: Half the security, twice the price.
 Quoting: Face Palmer


Funny as that slogan is it couldn't be further from the truth. Their devices offer the illusion of security with none in reality and at way more than twice the price of its worth for a toy that shares exactly the same os and features of its lowest end product.
 Quoting: Anonymous Coward 69535124


I didn't used too. Since Jobs demise, the company is going back to its roots of appeasing shareholders and not creating anything of worth to continue staying afloat. This exploitation of its security is proof of that where Apple no longer cares.
Anonymous Coward
User ID: 24957083
United States
06/18/2015 05:12 AM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
Apples new slogan: Half the security, twice the price.
 Quoting: Face Palmer


All these flaws are design issues, not buffer overflows, or cracks. Most of Apples tools come from the opensource world. If it's implemented wrong, sure it's going to be exploitable.
Anonymous Coward
User ID: 33435073
United States
06/18/2015 02:10 PM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
will they be releasing some patches?
Anonymous Coward
User ID: 33435073
United States
06/18/2015 03:45 PM
Report Abusive Post
Report Copyright Violation
Re: Keychains raided, sandboxes busted, passwords p0wned, but Apple silent for six months
bump





GLP