https://twitter.com/patrickwardle/status/912254053849079808
>on High Sierra (unsigned) apps can programmatically dump & exfil keychain (w/ your plaintext passwords) vid: https://player.vimeo.com/video/235313957 #smh
https://twitter.com/patrickwardle/status/912254053849079808
>on High Sierra (unsigned) apps can programmatically dump & exfil keychain (w/ your plaintext passwords) vid: https://player.vimeo.com/video/235313957 #smh
When you go to facebook.com, your device must surely decrypt the keychain to plaintext to prefill the password field so it can send your password to facebook.com - Thats how it works.
So this seems like normal functionality to me, someone has just put it in a command line. Someone has just reverse engineered the keychain decrypt that happens all the time.
Am I missing something?
If "Always Allow" is chosen, then the app will have permanent permission to access _only_ that particular password in the keychain.
This vunerability appears to bypass that dialog entirely and dump the entire keychain in plaintext without requiring the users permisson.
When you go to facebook.com, safari requests access to the facebook.com password via the keychain api. At which point you are supposed to be prompted by the OS, and if you allow it, the keychain api returns the decrypted password only for facebook.com.
The vulnerability being demonstrated is able to decrypt every password in your keychain, without prompting the user in any way.
$ security find-internet-password -s www.facebook.com -g
This one seems to bypass asking for permission somehow.Years ago I moved all of my important passwords to a secondary keychain that remains locked for precisely this reason.
Technically, if you can create another executable binary with the same name and digest, you can access the same keychain item.
The security framework uses some kind of digest / signature to verify that the app hasn't changed if the binary is not code signed. Apple's docs are scarce on details, see eg [1] which just says that the security framework makes sure the app wasn't altered.
But I am pretty sure the app name is ignored. Most macOS services use the bundle identifier.
However, if the app is code signed, the security framework automatically grants newer versions of the app permission if they have been signed with the same certificate.
[1]: https://developer.apple.com/documentation/security/1400622-s...