Unauthorized access to cameras in Safari on macOS and iOS
ryanpickren.com
ryanpickren.com
This is amazing work. You’ll never see XFO the same way again.
It says that Safari 13.0.4 (macOS) and earlier is required to reproduce; Safari 13.1 was released last week, so if you’re allowing macOS to stay up to date, you’re okay there. I didn’t see a clear answer for iOS, but if they published, it has likely been fixed in iOS as well (or else they’d miss out on a $75k bounty).
From the write up at https://www.ryanpickren.com/webcam-hacking , the bug chain appears to allow script execution in "arbitrary" domain context, which at first glance seems much bigger than just webcam extraction. Sticking up someone's face is attention grabbing compared to what could be done with that kind of power.
Is it because of the first bug in the chain that only the media-permissions was affected by the context confusion?
For example being able to extract cookies or local storage from other contexts would be a much bigger deal (local storage is sometimes used to store XSRF protection keys or other credentials), so I assume that wasn't at all affected?
Did any other parts of safari use the same broken context awareness as the media permissions or do we know that it was it isolated to media permissions?
> Reports that include a basic proof of concept instead of a working exploit are eligible to receive no more than 50% of the maximum payout amount.
Can someone explain to me what would have counted as a “working exploit” here vs. simple proof of concept? They can’t mean actually finding it in the wild right? The OP’s example seems working enough to me, and this looks like a really bad bug.$150,000. One-click remote broad access to sensitive data.
Only having access to the camera is partial access. It's not full access to the system - I'd agree with that.
Of course, if the bug was reported as a webcam issue then I suppose it could be maybe argued that it's fine that they paid for it as such.
> Reports that include a basic proof of concept instead of a working exploit are eligible to receive no more than 50% of the maximum payout amount.
Hit and miss.
If it can be controlled by the camera's firmware, then it can be controlled by software. All it takes is a bug in the firmware, which is unlikely to ever be updated.
Some camera lights are controlled by the firmware, others are wired onto the data line, so the moment data is going either way, they light up.
However, defeating the light even in the directly wired case is possible, and has been done many times. If you fire up the camera, take a photo, and turn off quickly enough, the light won't be perceived by the victim. (I believe the FBI and the NSA both had tools that did this that became public knowledge a number of years ago).
FWIW, Apple system (OS) updates frequently include firmware updates, not only for the FEP/boot code but other devices as well, especially for security issues. Apple has been pretty good about this.
Not addressing the rest of your comment, just this one point.
PS: don’t know why the phones don’t have a similar indicator for “front camera on” and “speaker mode on”. BOM cost I suppose.
edit: seems I'm wrong from googling
https://support.apple.com/guide/security/hardware-microphone...
"We observed that, on average, fewer than half of our participants (45%) noticed the existing indicator during computer-based tasks. When seated in front of the computer performing a paper-based task, only 5% noticed the indicator."
- Somebody's Watching Me?: Assessing the Effectiveness of Webcam Indicator Lights - https://dl.acm.org/doi/abs/10.1145/2702123.2702164
I imagine that a Black Mirror type of scandal involving this exploit could do many millions if not billions in damage to Apple’s finances. Not to mention what such an exploit might fetch on the black market.
They’ve just gotten used to banking on people taking much less than black market value in order to avoid legal complications.
This isn't a complete remote takeover but accessing a live feed of an unsuspecting person just by them opening a URL seems like a really big deal for a company that is all about privacy.
I really don’t need a webcam on my MacBook at all. Kinda like I don’t need a microphone on my TV. Why are these not optional on devices? How do we know this is really what consumers want?
It feels like a lesson from the “you can have any color as long as it’s black” school of consumer choice.
The problem is I can’t confidently defeat the builtin devices. I would be more comfortable if they just didn’t exist.
I don't know how it is implemented, may be in software, may be done in firmware. It won't be perfect but at least it gives you a visual indication that your mic is (or should be) muted.
The webcam is cheap enough that the cost to make it optional (ie: added manufacturing and logistical complexity of another model variant) would greatly exceed the cost of the part.
Most people (except some high security military/intelligence customers, perhaps) aren’t willing to pay more to not have a webcam.
The reason this isn’t being done more is because of course this leads to people wondering why their camera doesn’t work when the lid is on.
Because according to the seller’s analysis, the probability of marginal profit is not sufficient.
>How do we know this is really what consumers want?
“We” don’t, and short of a worldwide poll, one can only guess. The seller, especially as one of the most profitable entities in the world, is presumed to be able to come up with decent market analysis.
(though the switch isn't labeled as to which direction is on and which is off, which might have changed in current models)
So could you prevent it by revoking all of said priviliges for all websites in Safari's settings?
What it does is not transmit your voice.
If your Preferences > Audio > "Join audio by computer" setting is enabled, then it'll do so automatically. While in a call, if you want to disconnect the microphone rather than mute it, hit the dropdown menu to the right of the Mute button and choose "Leave computer audio" at the bottom.
Javascript is a security nightmare responsible for the overhelming majority of web-based CVEs .
Javscript's contributes mostly fluff to the vast majority of webpages.
What's worse, some pages check for it and deliver a totally blank page if it's not enabled, just to punish the non-compliant.
Even worse than all of the above is the fact that Javscript is the vehicle through which users are IDed and tracked. It's the reason why telling your browser to dump-cookie at the end of a session is ineffective.
Javascript is popular because people who own websites demand it be enabled. They demand that so they can fingerprint you- no other REAL reason for Javascript's popularity.
Every single person on this particular forum eithers knows or can clearly see what I am saying is true, but their jobs depend on them selling their Javascript skills and that's the reason this post, as you read it, is fading to gray as its downvoted.
Javscript is the instrumentality of the surveillence state. That's 98% of its utility.
All webpages should have a non-Javascript, "here's the info" version available and the fact they don't is a scandal and we are the culprits.
Also, you can definitely be fingerprinted without javascript. The web is a huge stack of technologies, and most of them can be fingerprinted, all the way down to at least layer 4. (...and layer 2 if you're not on a network you control)
...I never use.
Take all the JS on all the webpages and throw away every page to which it's not essential. Call the remainder set A.
From set A, throw away every application whose functionality could be essentially be replaced by something like an ASP or JSP/Servlet round-trip hit without it much bothering anyone, as in the olden days. Call the remainder Set B.
Take everything in set B and task yourself with creating a secure methodology of obtaining the same or similar level of utility not involving Javascript or anything less secure.
Compare the effort to do that with the sum total cost of what Javascript has inflicted on the world.
Include in your calculations direct financial losses, expenditures in counter-measures, all the manhours spent in ameliorating all the breaches in security caused by Javascript, all the human toll of being tracked - by Javascript- online...
In fact, let's just keep this simple, forget all that.
Every time any human being in any security agency in all nations the world over is engaged in any activity, offensive or defensive, which has as its ultimate root cause Javascript, just make that the bill you have to pay.
Now look at the net gain (Google Docs!) and the net cost and tell me Javascript is a great idea.
I got some time ago that not everyone shares my hierarchy of values and concerns. You use Twitter and Facebook and Google etc. etc ad naseum... all forks where each time I chose the other path.
But by saying "no" to that steaming pile of shit I don't find I've said no to modernity and I don't find myself disavantaged in any way. Those things are not modernity or even the web- they're gadgets. Gadgets you love and can't imagine living without, that's all, like the smartphone you have, and I don't.
J'accuse our world of the following. We have cost everyone incalcuable wealth, time, opportunity and frankly the attention of some of the best minds of the past two generations all to buy ourselves a very particular, circumscribed and unnecessary kind of interactivity on our computer screens.
We have recklessly trodden very far down a dangerous and even deadly path, step by step, merely because at each point along the way we counted our own sunk efforts and extant artefacts as the measure of all things. This, and we have effectively coerced the world into following us.