Additional Mac App Store apps caught stealing and uploading browser history
9to5mac.com
9to5mac.com
Edit: I don't understand how Apple didn't catch this in their review process: the exfiltration is clearly visible using a disassembler, as shown in the original forum report[1].
[1]: https://forums.malwarebytes.com/topic/217353-get-rid-of-open...
[1]: https://www.trendmicro.com/en_us/forHome/products/free-tools...
Edit: here's their website for the unarchive tool, seems like it is them: https://www.drcleaner.com/dr-unarchiver/
https://www.buzzfeednews.com/article/nicolenguyen/apple-remo...
In this era of ultra cheap/free software and hardware, even formerly reputable companies are likely to find alternate revenue stream irresistible.
Apple's review process is most likely largely a PR illusion. Just look at all the stories of how inconsistently and arbitrarily they've enforced App Store policies over the last decade. That's not to say that they are not sincerely trying, I'm sure they are. Unfortunately, Apple has become even more opaque about many things (the 'security' obtained via the app review process always seemed a bit hand-wavy and superficial to me). I'm sure they'll continue to improve but the the bad guys will always be a step ahead because they must be.
Privacy on our computers and phones is an empty promise, and we need to radically rethink the way our devices and browsers work if we want to change that. Legislation like the GDPR is one step, but we need to think about ways that make it impossible to collect all that data in the first place.
The macOS sandbox isn't like other sandboxes I've used (JVM, ECMAscript, Tcl, etc). Even if the user hasn't extended it by explicitly selecting a file, and even if the app has no entitlements, there seem to be a lot of holes in it -- and they seem to be intentional. The Mac sandbox can be one piece of a security solution, but you should never count on it to protect you from untrusted applications.
Of course, if you choose your home directory in a file picker, all bets are off.
The matter of user expectations is the main reason I wish Apple would revert the sandbox requirement for the Mac App Store. As a user, it really does seem like the sandbox should protect me from malicious code, just like Safari protects me from malicious JS, but it really doesn't. They want the MAS to seem safe, but it would be better for everyone if they made it clear you still need to trust the app.
This access is going away in macOS Mojave, at least for the built-in system apps, for precisely this reason.
> The macOS sandbox isn't like other sandboxes I've used (JVM, ECMAscript, Tcl, etc). Even if the user hasn't extended it by explicitly selecting a file, and even if the app has no entitlements, there seem to be a lot of holes in it -- and they seem to be intentional.
> Of course, if you choose your home directory in a file picker, all bets are off.
What holes are you talking about? Keep in mind that the examples you mention and the macOS sandbox solve different problems and have different constraints. The ones you've mentioned are meant to execute untrusted code and keep it (almost) completely isolated from the rest of your system. But macOS apps must have much more access by definition.
> The matter of user expectations is the main reason I wish Apple would revert the sandbox requirement for the Mac App Store. As a user, it really does seem like the sandbox should protect me from malicious code, just like Safari protects me from malicious JS, but it really doesn't.
Just curious: how do you feel about the iOS sandbox situation?
What I don’t understand about review processes is that scummy apps and companies are really not that hard to spot. Maybe the really crafty ones are hard to see but I have to wonder how much time Apple really has to spend (sometimes just from descriptions alone) to question what an app is doing.
Meanwhile, I once got rejected because I didn’t have a damned minimize button or something.
I can't imagine it'll take long before there are many and massive class action lawsuits over this incident. The legal bill will be massive.
I can't wait to see how many precedents get created over the total fallout from this event. Should be interesting.
It never happens.
But beyond shutting the companies responsible for selling these applications down, there should be some criminal liability for the executives. Exfiltrating users’ browser history without reasonable consent is a huge privacy violation.
I wonder if it falls under CFAA.
Citation or it didn't happen. No way Apple has "assured" anyone that the app stores are 100% malware free at all times. They've said it's the safest thing out there which is a weaker claim (and still true).
Moving forward with my assertion and based on what others are saying about the Apple testing practices; I'm guessing that this was something that Apple should have caught in their testing, which if true would go towards proving culpability.
Negligence would then be the argument I'm guessing and then liability would follow.
I understand from many other situations it's arguable about whether the company could have foreseen the issue.
Typical breaches like the Dropbox breach which passwords were still hashed and therefore the request to reset the password was proactive. That's an acceptable breach to me and is bound to happen, but negligence such as Apple's or in the case of BA (British Airlines) breaking with known and valid credit card processes should result in conseuqences up to the criminal level depending on the situation.
BA link: “So, about that BA hack …” https://medium.com/the-automator/so-about-that-ba-hack-a82e5...
Hopefully Apple will figure this all out before long-time users who have trusted them completely, start to trust them less.
I'm a fan of the walled-garden, but sometimes the cracks in the facade worry me a little.
It's unfortunate that the ongoing trend of opaqueness in computers is making it easier for things like this to happen. Years ago, blinking network and HDD lights/sound would have provided at least some sign of unusual activity.