{"id":3932,"date":"2015-06-18T06:31:11","date_gmt":"2015-06-17T22:31:11","guid":{"rendered":"https:\/\/www.darknet.org.uk\/?p=3932"},"modified":"2015-09-09T19:36:36","modified_gmt":"2015-09-09T11:36:36","slug":"apples-password-storing-keychain-cracked-on-ios-os-x","status":"publish","type":"post","link":"https:\/\/www.darknet.org.uk\/2015\/06\/apples-password-storing-keychain-cracked-on-ios-os-x\/","title":{"rendered":"Apple’s Password Storing Keychain Cracked on iOS & OS X"},"content":{"rendered":"

And another password shocker, a few days after ‘cloud’ password service LastPass was pretty seriously hacked<\/a> (yah if you’re using it, change your master password) critical 0-day flaws in Apple’s password storing keychain have been exposed.<\/p>\n

\"Apple's<\/p>\n

Which is kinda funny, as after the LastPass hack I saw some people espousing the usage of Apple’s keychain as much more secure. And now, Apple’s keychain cracked – and in a really serious way.<\/p>\n

Six university researchers have revealed deadly zero-day flaws in Apple’s iOS and OS X, claiming it is possible to crack Apple’s password-storing keychain, break app sandboxes, and bypass its App Store security checks.<\/p>\n

Attackers can steal passwords from installed apps, including the native email client, without being detected, by exploiting these bugs.<\/p>\n

The team was able to upload malware to the Apple app store, passing the vetting process without triggering alerts. That malware, when installed on a victim’s device, raided the keychain to steal passwords for services including iCloud and the Mail app, and all those stored within Google Chrome.<\/p>\n

Lead researcher Luyi Xing told El Reg he and his team complied with Apple’s request to withhold publication of the research for six months, but had not heard back as of the time of writing.<\/p>\n

They say the holes are still present in Apple’s software, meaning their work will likely be consumed by attackers looking to weaponize the work.<\/p>\n

Apple was not available for immediate comment.<\/p><\/blockquote>\n