Should we change our paypal passwords? Or worry about getting more spam? etc Why should an end user (eg my mom) care?
I'm not saying there aren't serious repercussions, just having a hard time seeing exactly what they are.
Should we change our paypal passwords? Or worry about getting more spam? etc Why should an end user (eg my mom) care?
I'm not saying there aren't serious repercussions, just having a hard time seeing exactly what they are.
Unfortunately, there's just not much an ordinary user can do. There's no way for a user to tell if an app accesses and broadcasts their UDID (if you're an expert you can use mitmproxy or a similar tool), and certainly no way to tell if the UDID is being used safely. I would recommend de-linking your social media accounts from all apps unless you know they're safe, but that's the kind of drastic advice that people tend not to take.
However, this is of interest:
>and in some cases (which affected millions of users) completely take over Twitter and Facebook accounts
How is that possible? Are we going to see mass defacements/malware links or other bad stuff on Twitter and Facebook as a result?
Also what is meant by 'take over'? Surely it doesn't mean from a UDID alone, a hacker could log into that associated account with full permissions?
I'm assuming any scripted attack would only have the permissions that any other FB/Twitter app has, and could be blocked in App settings if it started doing 'bad stuff'?
http://blogs.wsj.com/digits/2011/09/19/privacy-risk-found-on...
Chillingo is a publisher of 3rd rate knockoffs.
The problem is that the developers do not understand how to engineer secure systems. Take away the UDID and their systems will still be broken, just in a different way.
You're right that these developers would have made something broken regardless of whether this problem existed, but Apple should try not to give them enough rope to hang themselves. What's fascinating is that "globally visible unique identifier" turns out to be just enough rope.