Exploiting IndexedDB API information leaks in Safari 15
fingerprintjs.com
fingerprintjs.com
Last IDB shitstorm was discussed at https://news.ycombinator.com/item?id=27509206.
Apple just doesn't care about IDB or the web.
Super frustrating, makes me glad I’m not currently building anything that relies on significant local storage.
The web could fill so many needs instead of using apps, but with crap like this it’s no surprise that it still doesn’t.
This can in cases where the names follow a known pattern be used to infer domains of other websites in the session and, in the case of YouTube, your Google id which can be used to identify your Google account.
The vulnerability doesn't leak all your browsing history. It leaks a small part of it
edit: title is changed now
On the other hand they report (and help close) some gnarly exploits like this via sketchy web apis.
What do you all make of this? It's hard to not see it as some weird "were not doing a bad thing" gaslighting (perhaps even internally to their team).
What if clients use it for tracking and other shady purposes, would they do something about it?
Btw I tried with Tor Browser and it did not accurately fingerprint it between sessions which makes me wonder how effective it really is. Especially for fraudsters; intentional bad actors, I think it would be quite easy to bypass.
Or ones they are not planning to use anyway, but are possible to be used by competition?
Or for marketing purposes to be not known as 100% clearly evil?
Or for marketing purposes to be better known?
I hope regulators will eventually force support for other browsers (that can install apps) in iOS, I don't understand how Apple is allowed to have such a tight control on the market.
The default should be always to delete everything after a website/tab is closed. Want to store a login? Set up a button next to the url bar to enable persistant storage for that specific webpage, and you're done.
I guess I'm curious as to what the norms are around disclosure of such discovered vulnerabilities are in general.
[1] https://news.ycombinator.com/item?id=12308246
[2] https://googleprojectzero.blogspot.com/2021/04/policy-and-di...
Still though:
> Moreover, we observed that in some cases, websites use unique user-specific identifiers in database names. This means that authenticated users can be uniquely and precisely identified. Some popular examples would be YouTube, Google Calendar, or Google Keep. All of these websites create databases that include the authenticated Google User ID and in case the user is logged into multiple accounts, databases are created for all these accounts.
It pretty clear that Apple isn’t giving Safari/WebKit the focus it needs, but it’s also clear that developers just continue to push for more and more features in the browser. I’d much prefer that browsers started to cut back. While Google is excellent about updates, remember that critical bugs are found in Chrome constantly.
Already on chrome we can go to a URL, click the 'install' button, and have an app on our desktop/homepage. No app store, no massive download. I sincerely hope this is the future and not brilliant dead-end HN will be nostalgic about in 10 years.
Is Apple’s culture of secrecy that strong? Is it a sense of superiority? Is it embarrassment? Are they just not here?
As a mid-career engineer with highly marketable skills and an inbox stuffed with job offers the only two companies I would never entertain an offer from are Facebook and Apple.
Facebook because their fundamental purpose for existence is harmful to society and Apple for their perceived (or actual?) engineering incompetence.
I don’t really have a sense for the kind of engineer that works for Apple. With other big tech orgs I have some sense, even if informed almost entirely by tech forums.
This might be different if I had some perception of what was happening internally or how problems are approached. But from what I see nobody at Apple cares. So the silence contributes to the perception of incompetence by not counter-acting it.
Agree. I'm just curious what it is at Apple. Their hardware seems fine, even excellent. But the software is really not at the same level. So I wonder how that happens.
There isn’t silence though. The world doesn’t begin and end at Hacker News. Head over to Twitter, for instance, and you’ll see plenty of Apple developers talking about their work. Or join the WebKit mailing lists or Slack. Or join the Swift forums.
You mean on HN? Oh they do, From JSC to Webkit Engineers. Mostly on technical discussions.
It’s a shame really, because otherwise I think I’d quite like working at Apple. Their laser focus on product is right up my street.
And this kind of an issue is exactly why Apple needs to stop screwing around and do the following things ASAP:
1. Decouple Safari from the OS so that it can be updated independently to fix critical issues like this and deploy to all customers quickly
2. Let other browser engines on the platform for fuck's sake!
Wow. I wonder what Brave thinks of this?
I tend to doubt that's true, mainly because, by far, the most likely alternative is Chrome, and Chrome is specifically designed to leak its users' personal information to Google's customers (the ones that generate the bulk of their revenue, that is).
This is well-tread, mistaken path.
Chromium > all, for security.
But for privacy, sacrificed by all of them out of the box (yes, Firefox is a noisy SOB too, no I won't dig up the articles people have written on the traffic captured for you).
Your settings are very, very important to your browser privacy, regardless of which.
I do not trust it not to report back that I use GrapheneOS, or which internet communities I visit, back to Google for use in who knows what data correlation research — that's privacy.
I think a security issue is one that allows another party to take information or property you have without your consent, and use it for their gain without regard for the harm it may do to you or others.
It's arguable, but I believe that's at the core of Google's business model with regard to Chrome users.
have security without privacy,
but no privacy without first having security!
At my last web dev gig, we had to go and get Apple hardware because our visual tests kept failing on Safari. They need to get their shit together or let people port good browser engines.
Apple's iOS browser monopoly is literally the only thing preventing Google from having a near total monopoly on web standards.
Really, at this point I think Chrome/Blink should be spun out as a separate entity. It could be set up as a model similar to that of ARM, or perhaps a non-profit of some kind. Either way, Blink needs to be separated from overwhelming corporate influence.
Dear god, no, please.
The Chrome team is a treasure of immense value to the world. They are the only major software team in the world where my bug reports have been triaged and fixed. Again and again and again, and usually very quickly too. Ocassionally I would find some hellish obscure corner case of a bug, ignore it, and it would still get fixed even without my reporting it: the team is just unbelievably effective! I wished Google were not selling advertising, but the downsides for Chrome have been fairly limited. The fact that they have given the source code to Chromium away for free is just plain astonishing. I am blown away by how good Google has been as a custodian of something that is used by so many in the world: it has been a fair gift to us all with surprisingly few caveats.
If you don’t like Google’s guardianship then use a derivative browser, even Microsoft Edge!
Split off Chromium and it would likely turn to shit. How many times have I seen browser vendors go down the path of evil? How many times have I seen important software get sold, and the product focus shift to something execrable?
On browsers: the Safari team is a black hole for bug reports, with a browser full of broken or non-compliant functionality… IndexedDB is just one of many similar symptoms. Firefox has the right social goals, but it hasn’t been delivering guru level engineering, but instead Firefox is continually chasing useless queer features (similar to many other now dead products in the world). The Microsoft Edge team did fix one bug report for me once, but I just happened to report it while they were developing the feature, and I had test cases showing the feature working in Firefox and Chrome. I still have trauma from Microsoft IE6+ (although it was a competitive edge for my business that I could usually make it work, albeit at the cost of years of my life devoted to creating IE workarounds).
that (theoretically) any org can adopt and strap additional modules onto.
if the other chromium wrappers have a seat at the table, that isn’t the table that makes the decisions.
I genuinely can’t name a native application released for macOS built with AppKit or SwiftUI or whatever that didn’t come from Apple.
Just named five I use daily...
Inertia is the most powerful force in the universe, and gravity is up there as well. Adobe & Microsoft dynastyware dating back to 1990, and two also rans devoured by the web (Figma/Postman). And TablePlus which genuinely looks cool and gives just enough hope to mourn again.
You're basically right, but at least we have much more cross-compatibility now. Not something we could say about Macs of yore. Pros and cons.
I will say as a former Mac developer who came of age and experience during the Carbon Y2K transition days, the fact you can just expect some form of availability regardless of Linux or iOS or macOS or Chrome or Safari is a genuine fucking achievement for the human race, how far and low we’ve come.
It's certainly true that the center of gravity is tilting toward web apps, but not every kind of app makes a good web app, at least yet.
I can recall a dozen of XSLT implementation bugs which were in Chrome from day 1.
XSLT is not going anywhere from browsers, but they also cannot be fixed, because there is so few people using XSLT today to raise above the noise floor for WebKit devs.