Unsigned apps on High Sierra can programmatically dump and exfil keychain
twitter.com
twitter.com
I haven't tested the beta so this struck me, can someone confirm?
For people unfamiliar with Keychain, the problem as I understand it is not that unsigned apps can do this per se (though I don't think this is a good idea), it's that they can do this without user intervention.
The normal flow for Keychain is that when an app wants access to a keychain item that was not created by that app, it has to ask for user permission to allow once or always allow access. It sounds like this isn't happening in this case.
(Aside: it used to be possible to trivially access all website passwords in Safari too (which I dutifully reported as a bug, because it was a terrible design choice), but Apple thankfully changed this to require authentication in new versions of Safari.)
EDIT: As another commenter pointed out, an app is also only granted access to one key at a time, each requiring an independent confirmation (with password). There is no way (normally) to grant cart-blanche access to the entire keychain.
How safe are unsigned apps anyway? I can imagine it's "all bets are off" level software.
Once the user has installed unauthorized software, the attacker can simply sit and wait for the user to expose more goodies (logins, bank data, 1password access, etc). In many ways, it is game over. If the attacker can leverage that to get your admin password, prompts are not going to save you.
Also if someone gains physical access to your device(s) while you are in the bathroom or what not, if they know your laptop password which is usually something easy to remember, then they have access to all your keychain passwords no matter how complex each of them are.
Still million times better than attempting to memorize custom passwords for each site, since most people will just have one password, and will add a few characters based on the site name/domain which can also easily be cracked.
I have a significantly more complex algorithm than that, but you get the idea.
Every password I have is different, but they're all trivial to remember. This isn't super hardcore security, but it helps me have like 40 passwords that are all different.
But they aren't going to target me specifically? They won't. They just find everyone whose password across multiple breaches is similar (Levenshtein distance or something) and brute force the differences.
Is this possible when the leaked passwords are all only salted hashes?
[1] https://haveibeenpwned.com/PwnedWebsites#LinkedIn
The obvious downside to this approach is if I were ever to be caught in a situation where I MUST log in to some site but do not have access to my PC AND phone, and therefore cannot risk opening the password DB on an alien system. Pretty unlikely scenario though.
What exactly is the product name? What is the website name? Does it include www? What about other subdomains?
These are the same kinds of questions that make security questions so frustrating as designed.
"What was your elementary school?" Hm. Is preschool elementary, or separate? Is the private school I went to for K and 1st an "elementary school" (there was no division between those in that school)? Maybe I should use the first school I attended between K-6 that had such a division? Or maybe just when I started public school, since that one was the first one called elementary...?
"What was your mother's maiden name?" I hardly remember my mother, and when I started being asked her maiden name, I had to guess how to spell it. Is this security question one I answered when I was guessing wrong, before I knew how to spell it for real? Even if it's not, did I decide this time to use the old spelling for consistency, or to add a slight hitch to someone who looked that up and is trying to access my account?
Essentially every answer to these kinds of questions that isn't about a number (and some of those!) comes with so many caveats that it seems unlikely I'll remember which path down this tree I took when I added it. The world is so fuzzy. This is like those "puzzles" where the wording of the puzzle actually admits many possible answers depending on how you interpret words and phrases, but everyone seems to settle on a meaning that's obvious to them, but the most "obvious" answer seems different from day to day for me.
I have friends who do this. They set huge passwords for "security", and then can't type them consistently, or forget them, and have to reset the password. Then they complain about their accounts getting locked.
I can't convince them that a shorter password is still secure, and will remove much of the aggravation.
If it isn't advice, then it's just a bad idea.
This is clearly not remotely executable, it needs to be run on the device that is signed in.
Say you visit facebook.com, your password is in the keychain, so the keychain must be decrypted to return the plaintext password so it can be passed in the password field to facebook.com
This is how keychain works isn't it??
You can view your entire password list in Safari Preferences - it does the same thing.
So this is nothing? Someone has written a command line version of this same tool.
Am I missing something, this seems to be normal functionality of the OS for a signed in user.
$ security find-internet-password -s www.facebook.com -g