Hacking the Apple Webcam (Again)
ryanpickren.com
ryanpickren.com
Writing a secure browser for today's web appears to be a technological challenge comparable to a level 5 self-driving car. It has not been shown to be feasible. So such cars are not permitted to be deployed on the world's roads. Today's web sites and browsers should similarly not be deployed on the world's infobahns.
Unfortunately the only way to find these modes of failure is to have them actually fail. It's impossible to design and release an error free system without real world usage from real people.
It doesn't mean we should just give up and go back to HTML1 though. It just means exploits should be fixed as soon as possible to minimize damage.
The old web I remember had exploits from flash, java applets, active-x, shockwave, other sketchy plugins people willingly downloaded to access sites, and poorly sandboxed javascript that could take control of your browser window to resize, move, and spam as many popups as it wanted among other worse things. And downloaded "toolbars", https being rarely used, etc.
Even ad blockers and other "power user" extensions (if your browser even offered that) were extremely primitive. etc.
There were websites that could execute user land code through exploits just by visiting a website depending on your browser. And that wasn't uncommon.
It would be completely insane if that was still the case today. But we fixed those issues and evolved.
OP's post shows a major issue obviously. But I would absolutely turn off the entire api with a forced update until it was fixed if I had the power to.
But these sorts of exploits happened back in the day to a worse degree with HTML3 + 4 (can't speak for 1 or 2 though, maybe someone can chime in).
Viewing the bigger picture, the web is way more secure now than back then. And exploits like these are much more rare now.
We used to have school kids coming up with highly privileged attacks on systems to it becoming something the top minds spend months on and get paid 6 figures per discovery for.
Even the encryption has to be free of side channels like timing attacks which are left out of what most people think of as a proof.
Most JS features don't even have a formal spec which is part of the problem.
Only when the "constraints" are that the browser must support all "standards" produced by some committee where most if not all memebers are employees of the few browser vendors or other "tech" companies heavily invested in the web. Perhaps that is what is meant by "today's web".
I use a netcat and similar TCP clients and a text-only browser on today's web and this works quite well for mine own purposes. Non-commercial use. Basic tasks like sending GET and POST requests, downloading pages and other resources and reading them. Using the web as an information source. I would be willing to bet these programs are "more secure" than the "modern web browser". They are certainly less complex.
For 99% of what I do I use Firefox + NoScript and I think I'm relatively secure. My solution probably provides more functionality than yours, but it's still a hassle to use some sites. Other sites simply don't exist w/o JavaScript. The situation isn't getting better.
For example much of MSN is totally non-functional w/o Javascript. E.g. this brings up a totally blank page: https://www.msn.com/en-us/news/us/they-had-covid-19-once-the...
And of course Google really really wants JS to make it easier for them to spy on you. Youtube isn't useful w/o JS (but IIRC it used to at least somewhat function): https://www.youtube.com/ Fortunately search still works.
Twitter are twats and broke all functionality w/o JS, but nitter.net is a workaround! Just replace twitter.com with nitter.net to see the tweet.
Fortunately many sites that start out blank are quite functional w/o JS, just need to View -> Page Style -> No Styles. E.g. this one: https://www.politico.com/ ugly but readable.
Hmmm, I got the full text of the article, immediately readable with links(1), no problem using netcat or, e.g., curl.
NB. Unless required, I never send a user-agent header. Here, as is the case with 99% of the sites I visit, it was not required.
To watch the video, I used ffmpeg to save to an MP4 file:
curl -A "" https://www.msn.com/en-us/news/us/they-had-covid-19-once-then-they-got-it-again/ar-AAT65AV?ocid=uxbndlbing \
|ffmpeg -i $(sed -n '/type=application\/x-mpegURL/{s/.*https/https/;s/\".*//p;}') -codec copy -v -8 1.mp4
However when I checked archive.org I noticed their archived page was different. It appeared to require Javascript.YouTube
I use YouTube without any JS.^1 I search from the command line using a tiny shell script. I download from the command line using a tiny shell script. With few exceptions I do not use youtube-dl.^1
1. Only exceptions are videos with a dynamic sig value in their googlevideo.com URL. Most videos I watch have static sig values in their googlevideo.com URL. Alternatively, I can use a "modern browser" to get the googlevideo.com URLs to download these videos, with all the tracking and other non-essential URLs blocked (no ads), instead of youtube-dl.
I read Twitter without any JS. It currently works fine for me using links(1). I have a tiny shell script to download an entire feed if I need to find some historical tweet. Twitter does make changes from time to time. Previously I had to use the GraphQL API. Not anymore.
I agree 100% that the web of gratuitous JS sucks, but even with TCP clients and a text-only browser that do not run Javascript, I encounter few problems reading the textual information and/or downloading the binary files (resources) that websites provide.
You could have gotten basically the same (I would even argue better) level of security with a virtual machine and an otherwise full browsing experience.
I do not use this method for security. I use it for speed, reliability and aesthetics. The complexity fetish of too many software developers has driven me to appreciate minimalism.
Also, the computers I use are often older, underpowered and/or have limited resources. Running VMs is usually not an option. You cannot assume that everyone has the free overhead available to run VMs.
The large, graphical browsers controlled by corporations are slow, unwieldy and overkill for making simple HTTP requests. The "full browsing experience" is highly unsatisfactory for me. I am not "trading off" anything. I like fast, text-only information retrieval.
That said, the statement I made still stands. Using TCP clients and a text-only HTML reader is probably "more secure" than using one of the corporate graphical browsers that allow users to do more dangerous things. A side benefit.
To each their own.
How does the economy of bug bounty programs work for the company? $100,500 is probably not much for Apple but it's still some engineer's salary. Do the responsible engineer get a pay cut for this bug? Or this kind of 0day bugs are not bugs, but secret features left open from the beginning?
Honestly, $100,000 for this is too low.
I kind of shudder to think of how many of these bugs have been out there for years and only ever ended up in the hands of governments and shady groups like NSO.
A bug in Knight Capital's stock trader lost $460M in 45 minutes.
A bug in the Ariane 5 rocket caused it to crash, a loss of $370M.
A bug in the Therac-25 radiation machine killed 3 people.
> secret features left open from the beginning?
Are you saying Apple engineers are inserting backdoors? What's the motivation? Security bugs are very easy to accidentally introduce when you have complex interacting systems (in this case a browser, a complicated URL parsing syntax, some ancient barely-known file types, and a file sharing application). Occam's razor (and Hanlon's) says it's an accident.
They can afford the bounty.
It seems that we need a better story for when code inevitably can escape the sandboxing that browsers provide because right now it's a straight up disaster scenario. That means you are going to have to rethink the OS underlying it and none of today's options were built with that kind of a threat model in mind.
There is Fuchsia on the horizon which sounds like a MAJOR leap forward but that also seems like it is several years away from ever reaching a desktop for example and it's also really unclear what kind of attacks are going to be possible in the real world against it either.
On macOS I spend the first few days disabling several dozen junk processes I didn’t ask for and don’t want. This includes classroom tools (??) and all kinds of syncing/ sharing daemons I have no use for.
This exploit reinforces what we already know — computers are impossible to secure, you should reduce attack surface where possible. If you get a little privacy and performance out of it all the better.
These programs came bundled, I don't use them and disabled what I could from any GUIs. It is always them causing problems, hardly ever the ones I want and use.
Similarly, "ScreenTimeAgent" is there even with the feature disabled. AppleMusic and AppleTV daemons scan for caches throughout the day - never opened either. There's also "gamecontrollerd", "studentd", some iMessage and FaceTime related stuff, etc. etc.
And on a system where you've disabled all analytics/tracking, turned off Siri in all places [1], disabled dictation and all other voice input related options, you even keep your microphone muted when it's not in use, even then, "corespeechd" will send out several MBs of data to Apple on every single boot.
Most of this is nothing more than very unexpected and strange behaviour. The exceptions being those 3 apps that keep tripping over themselves, those actually destroying my battery and fans. A little less unintentional obscurity, maybe some official descriptions for these processes, just some communication, that would go a long way.
[1] Siri settings are scattered throughout, a lists exists though: open Preferences > click button "Siri Suggestions & Privacy" > click button "About Siri & Privacy" button > click bu... eh wait click heading "Siri Suggestions" - yes that black print > then, finally, all the places are listed right under where it says "You have choice and control".
You Have Choice and Control
You can turn off Ask Siri or Dictation at any time. To turn off Ask Siri, go to System Preferences > Siri, then turn off Listen for ‘Hey Siri’ and Enable Ask Siri. To turn off Dictation, open System Preferences > Keyboard > Dictation and turn off Dictation. If you turn off both Ask Siri and Dictation, Apple will delete Siri Data that is associated with the random identifier.
Request history associated with a random identifier and retained for six months or less can be deleted by going to System Preferences > Siri > Siri History and clicking Delete Siri & Dictation History.
You can control which apps can integrate with Use with Siri at any time by going to System Preferences > Siri > Siri Suggestions & Privacy > [app name] > Use with Ask Siri.
You can turn off Location Services for Siri by going to System Preferences > Security & Privacy > Privacy, then selecting Location Services. Click the lock to make changes and enter your password, then deselect Siri & Dictation in the list of apps and services to the right.
If you do not want Siri personalisation to sync across your devices, you can disable Siri by going to System Preferences > Apple ID > iCloud and deselecting Siri in the list of Apps on this Mac using iCloud.
You can also restrict the ability to use Siri & Dictation altogether by going to System Preferences > Screen Time > Content & Privacy > Apps > Siri & Dictation.
You can control which apps use Siri for transcription by going to System Preferences > Security & Privacy > Privacy > Speech Recognition.
And if this really is Apple just looking out for you, they could have added a small warning to the "disable" option about the sort of functionality you'd miss out on. It all comes back down to a lack of communication or trust.
I suppose if it's your own machine, and you know what you're doing, that's OK, but as soon as something breaks you will have no idea whether it's because you turned something critical off, or whether it's actually a bug.
Please don't do this to other people's Macs.
Thanks for the advice and all, but where is this coming from? It seems kind of out of left field, as parent comment did not communicate or convey in any way that they would ever mess with someone else’s machine like that. Is it not obvious that such an act would be just plain rude (and stupid)?
It is not an issue here so not too helpful as a post, but plenty of folk out there telling their grandparents to delete the temp folder every week to optimize the computer and other nonsense they heard is helpful in some forum.
Point is, disabling junk helps until it doesnt, and its much harder to enable one piece of junk after I forget what all I did in the first place. It would be nice if disabling windows search wouldnt make first attempt to open start menu not work after each restart, and enabling search didnt fix it. But everything is so interwoven that disabling "stuff I dont need" is shooting myself in the foot with a really long gun..
That's why I'm so wary of browsers (well, a certain browser) adding more and more APIs that hide behind permission popups. People will blindly click them.
And I fully agree with a sibling comment: "Writing a secure browser for today's web appears to be a technological challenge comparable to a level 5 self-driving car", https://news.ycombinator.com/item?id=30078738
Also Apple: "We have built in a long list of exceptions for Apple services, because it's impossible for an Apple service to have an exploit."
> "We advise users not to store sensitive info and files on their computers, to prevent nefarious actors from being able to steal these sensitive items"
Although I guess one reason they might buy a bug that would lead to financial harm is to prevent a competitor from getting it, which might be an even worse financial harm.
Also it makes me reconsider using Safari, seeing all these "special cases" of iCloud and iPhoto URLs being allowed.