V2EX = way to explore
V2EX 是一个关于分享和探索的地方
Sign Up Now
For Existing Member  Sign In
Chingim
V2EX  ›  Apple

High Sierra 安全隐患: 应用程序可以访问钥匙串并收集密码

  •  
  •   Chingim · Sep 26, 2017 · 4461 views
    This topic created in 3135 days ago, the information mentioned may be changed or developed.

    Patrick Wardle, Synack ’ s head of research, posted a video on Monday that shows how code he wrote can be used to get passwords from macOS ’ s Keychain. Keychain is the password manger built into macOS, and it usually requires a master password to access it. But Wardle ’ s code was able to access Keychain and collect passwords.

    source

    13 replies    2017-09-26 17:11:24 +08:00
    0xcb
        1
    0xcb  
       Sep 26, 2017 via Android
    之前版本都可以的啊,只要你授权管理员帐户,dump keychain 简单的很
    Chingim
        2
    Chingim  
    OP
       Sep 26, 2017
    @0xcb 不用授权
    bkmi
        3
    bkmi  
       Sep 26, 2017 via Android
    按理说这应该是个大新闻,但是竟然没人关注的,神奇神奇
    Chingim
        4
    Chingim  
    OP
       Sep 26, 2017
    @bkmi macOS 的关注度是没有 iOS 的高, 大家普遍更加关注升 iOS 11 卡不卡, 耗电有没有增加.
    bkmi
        5
    bkmi  
       Sep 26, 2017 via Android
    @Chingim 首页还一堆讨论升级的呢
    tairan2006
        6
    tairan2006  
       Sep 26, 2017
    …这个很严重啊,还升什么级。。
    usedname
        7
    usedname  
       Sep 26, 2017
    这个 bug 没人关注?
    BearD01001
        8
    BearD01001  
       Sep 26, 2017
    持续关注...
    NVDA
        9
    NVDA  
       Sep 26, 2017
    看到了,原作者说给 Apple 发邮件了但是没有回应,我也好奇这明明就是个大新闻为什么没人发...
    wuhao930301
        10
    wuhao930301  
       Sep 26, 2017
    手动关注。为什么 Beta 版的时候没曝出来,是正式版才有的 bug 么
    Chingim
        11
    Chingim  
    OP
       Sep 26, 2017
    @wuhao930301 小人之心地不负责任地推断, 这漏洞估计早就发现了, 就等苹果发布正式版吧
    onevcat
        12
    onevcat  
       Sep 26, 2017
    https://twitter.com/patrickwardle/status/912254053849079808

    这个吧?看起来是一直就有的吧,作者也说“ other versions of macOS are vulnerable too ”

    只有 unsign app 能干这事儿,没签名或者签名不对的 app 别用就是了..
    warking
        13
    warking  
       Sep 26, 2017
    Correction: The exploit affects other macOS versions too, including the latest High Sierra, but is not specific to the latter only. Apple has actually fixed a number of critical security flaws with macOS 10.13 making it an important update.

    http://wccftech.com/macos-high-sierra-hackers-steal-passwords/
    About   ·   Help   ·   Advertise   ·   Blog   ·   API   ·   FAQ   ·   Solana   ·   6059 Online   Highest 6679   ·     Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 · 87ms · UTC 01:59 · PVG 09:59 · LAX 18:59 · JFK 21:59
    ♥ Do have faith in what you're doing.