'Sign in With Apple' Bug Allowed Unrestricted Access
Apple has paid $100,000 reward to a security researcher who discovered a simple but potentially damaging bug. Until it was fixed, the bug could have let hackers take over a user's account.
The problem was with "Sign in with Apple" - a system that lets users sign up to websites via their Apple account rather than having to create specific login details for each site, or go through an email confirmation process it.
As with similar systems from Facebook and Google, it only works on websites that support the "Sign in with Apple" feature. When the user visits the third-party site, it contacts Apple to confirm the user's identity. Once confirmed, Apple issues an authentication token. The third-party site then treats that token like a temporary ID badge - similar to one given to a visitor to a secure building, complete with a validity date.
When the user returns to the site, they can log straight in using their Apple account.
Email Address is All Hacker Needs
As Sophos notes, it's a benefit for both sides: Apple gives users an incentive to create an account, while the third-party website can take advantage of Apple's security system. (Source: sophos.com)
Researcher Bhavuk Jain discovered a major flaw in the way Apple had set the system up. The process involves an exchange of a batch of data that includes the email address the user wants to use as an identifier on the website.
However, Jain found that sending a valid email address to Apple's servers would effectively return an authentication token that granted access to a website that used "Sign in with Apple."
Bug Fixed Before Hackers Strike
In other words, somebody with malicious intent who knew an Apple ID user's email address could theoretically sign into any account they'd created using "Sign in with Apple." Fortunately, Jain reported the bug to Apple, which fixed it before anyone less reputable discovered and exploited the problem. (Source: techradar.com)
This means there's no need for immediate action by Apple ID users. However, it is a reminder that measures which make website logins more convenient can increase security risks if anything goes wrong.
What's Your Opinion?
Do you use the "Sign in with Apple" system or similar systems from Google and Facebook? Are you surprised such a simple setup mistake happened? Is it smart of Apple to offer rewards to incentivise independent researchers to look for such bugs?
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.