Slashdot: Security Researcher Finds a Fundamental Flaw in iOS

Security Researcher Finds a Fundamental Flaw in iOS
Published on October 10, 2017 at 02:04PM
Felix Krause writes: Do you want a user's Apple ID password to get access to their Apple account or to try the same email/password combination on different web services? Just ask your users politely, they'll probably just hand over their credentials, as they're trained to do so. This is just a proof of concept, phishing attacks are illegal! Don't use this in any of your apps. The goal of this blog post is to close the loophole that has been there for many years, and hasn't been addressed yet. For moral reasons, I decided not to include the actual source code of the popup, however it was shockingly easy to replicate the system dialog.

Read more of this story at Slashdot.

Comments

Popular posts from this blog

Slashdot: Justice Department To Be More Aggressive In Seeking Encrypted Data From Tech Companies

Slashdot: 'Sooty Birds' Reveal Hidden US Air Pollution

Slashdot: Nvidia Introduces a Computer For Level 5 Autonomous Cars