APFS encrypted plaintext password found in another log file
mac4n6.com
mac4n6.com
There is a well-known "triangle" of [money, quality, time]. You can fix two factors at most, but that means a third factor will suffer. This decision is made by the management, whether or not they realise this triangle exists.
Most people aren't willing to sacrifice to apple either, since they have a lot of money in the bank.
Then later someone adds a sensitive field to some data structure, and if anything is logging that structure it will pick up the new field.
In a language like C, where I don't think you can write a nice dump_arbitrary(void * data) function, and so if someone wants to log something they have to write a routine specifically to deal with that particular thing, when someone adds a sensitive field to a struct it does not automatically go into logs. It only goes in if someone specifically updates the logging code to know about the new field.
I'm reminded of one such system I did in C#, where I knew ahead of time that some fields passed to the logger may contain user data. I added a [Sensitive] attribute that a property accessor can be tagged with, and the logger reflected upon this and replaced contents with a placeholder if it was there.
So I don't really buy that as too compelling an excuse. People who are mindful, careful about what they are doing, and respectful of the user will engineer, document, and evangelize solutions.
Something like this might happen once. Under Steve, it damned well wouldn't happen twice.
Also, most places, even ones with a lot of money, don't really respect and won't pay for QA. It gets outsourced; they try to get the developers to do it; etc.
In today's environment, there's no overriding incentive.
Back to Jobs; there was an incentive. You didn't want to end up on his shit list.
P.S. I never knew Steve Jobs, although he was involved with an institution I was at, back in our younger years. My impression is from what I've read about him, and how I've seen Apple changing since his death.
Now, I'm starting to wonder.
The hardware gains have been pretty incredible, with the custom ARM systems. The privacy stance seems (because I don't really know it in depth) to be a welcome turn.
But some other aspects are seeming to slip, repeatedly. For one thing, there seem to be more and more complaints and problems with regard to the software.
And it took Apple too long to take ownership of some hardware problems, until they figured out the magnitude of the negative PR.
Jobs wasn't perfect. But his ability to be critical and call BS and say "fix it", was very useful.
(Even if iTunes never benefited. I've never used it, except to help a friend digitize some personal media, one time, where the results landed in iTunes, IIRC. I wasn't thrilled with it (kind of frustrating and limited interface, as I recall), but we were able to get the job done.)
This happened under Jobs as well. "You're holding it wrong"
But damned if I'd let a product ship while it was logging passwords.
Simple QA is to scan log files for anything that shouldn't be there. It requires no more than defining those values, pattern matching, and patience while it churns.
This is actually a testing pattern that fits well into automation. As opposed to a lot of the "how do we hook into the GUI, so we can click stuff" automated QA I've seen.
Anyway. I need to shut up, now.
Vulnerabilities are one thing but these issues are simple enough for non-technical end users to exploit on anyone’s computers.
Security is usually more process than anything else. It seems weird that two OS divisions would really be that different.
It’s not weird. The lack of a first class sandbox model on desktop certainly makes its security properties and threat model “different” than those of the iPhone.
Yes both are built around XNU and both use APFS, but the “surface area” of attacks is far different across the platforms. For all we know, APFS bugs like these exist in iOS but haven’t been found because finding them would require rooting the phone to circumvent the sandbox model.
In High Sierra’s case, it took until the .2 release before we were fine with it.
Keep in mind that IT departments (including myself here) like to have important things to say about software updates, especially when it’s about the OS that requires a lot less IT work. :)
A lot of people have a (completely understandable) weakness for the latest and greatest though.
[ed: not that Debian hasn't had issues. Broken openssl/ssh key generation being perhaps one of the worst security issues in recent memory]
The mobile market has plateaued, so this will harm the company long term. Success defines and then limits you.
And with all the vertical integration going on, it may eat the world.
I somewhat agree with you, but iPhone security is first-in-class.
Now as I've mentioned before the real blame can be attributed to the switch to Agile. There has been a noticeable increase in the frequency of OSX/iOS point releases since then. But also a subsequent decrease in quality.
Apple has realised this which is why there are focusing more on quality and we have seen already the results of this with the last OSX/iOS update where we've never had a X.6 point release for a while.
I have yet to see an Agile/Scrum organization that doesn't have runaway technical debt. The entire Agile/Scrum process discourages the "craft" aspects of development unless they are explicitly included in each sprint, and a very few managers do that because these aspects are hard to tie to a specific customer story.
The article stated that another user could not replicate this issue and the original researcher was also unable to replicate after a possible stealth update.
Digging into the install.log the author found the same sh....stuff.
Has anyone did a public audit of the leaked secure enclave firmware? I know there's that company who sells the black haxx0r boxes for $15k or $30k.
Long question short: do we have a secure cell we can buy/make?
It's hard to tell, but with the application sandboxing in iOS, it is unlikely that any regular app could access log files.
AFAIK, on macOS, sandboxed applications cannot access logs either. But applications are moving out of the app store, because Apple hasn't really accomodated Mac developers.
Nope, and there won't be until there's an (open-source?) baseband that can be audited either.
Can we have a reasonable discussion without fanboy ism about what is the most secure phone right now?
(reply only if you have a security background)
Rogue apps, hackers, law enforcement and state actors are 4 different attack vectors that jump to mind that all have different mitigations.
We'd also have to talk about how usable you expect the phone to be afterwards; for example if to make it secure we have to disable wifi, mobile-data and apps, is there any point in having a smart phone in the first place?
(I'd still be using a Blackberry if they had any decent offerings, however.)