PDA

View Full Version : Group FaceTime bug omogucava da sve cujete bez javljanja sagovornika



zabrljanje
31-01-2019, 14:05
Pre nekoliko dana se digla prasina oko propusta u okviru FaceTime servisa.

Ova greska omogucava da kad pozovete nekog u okviru Group FaceTime, i nakon toga dodate vas broj kao jos jednog sagovornika, cujete sve sto dolazi do mikrofona telefona koji ste pozvali iako se sagovornik nije javio na telefon.


Ovo je moguce izvesti nevezano da li pozivate nekog na iPhone ili Mac.


Opis:

Pozovete nekog preko FaceTime, swipe odozdo na vise, dodate vas broj telefona, preko add person, kao jos jednog ucesnika u razgovoru i od tad ste u prilici da cujete sve sto dolazi do mikrofona telefona koji ste pozvali, iako se niko jos nije javio na telefon i prihvatio poziv.
Ako osoba koju ste pozvali, pritisne Power dugme u okviru Lock Screen-a, dobijate i video.



Ovo je prijavljeno Apple-u jos 20. januara ali, ocigledno, niko to nije procitao i prosledio gde treba.

Tema na Reddit sajtu

A person reported the Group FaceTime exploit to Apple, 9 days ago
(https://www.reddit.com/r/apple/comments/akyg5b/a_person_reported_the_group_facetime_exploit_to/)


MGT7
@MGT7500


My teen found a major security flaw in Apple’s new iOS. He can listen in to your iPhone/iPad without your approval. I have video. Submitted bug report to @AppleSupport (https://twitter.com/AppleSupport)...waiting to hear back to provide details. Scary stuff! #apple (https://twitter.com/hashtag/apple?src=hash)#bugreport (https://twitter.com/hashtag/bugreport?src=hash)@foxnews (https://twitter.com/FoxNews)

https://twitter.com/MGT7500/status/1087171594756083713




I reported the bug there after registering as a developer (even though I’m not, I was told I could) and also emailed product-security@apple directly.

https://twitter.com/MGT7500/status/1090163397788745728



Cak je 23. januara, video prosledjen Apple-u



VIDEO: Here is a video, recorded & sent to Apple by a 14 yr old & his mom, on JAN 23rd, alerting them to the dangerous #FaceTime (https://twitter.com/hashtag/FaceTime?src=hash) bug, that has threatened the privacy of millions. I've removed sensitive / private info on behalf of the mother (an attorney), whom I just spoke to.

https://twitter.com/BEASTMODE/status/1090298850764644352


Ovaj bag je prvo objavljen na 9to5Mac (https://9to5mac.com/2019/01/28/facetime-bug-hear-audio/).




Nakon toga, Apple je napokon privremeno onemogucio ovaj servis, sto mozete da vidite i na System status strani


https://media.idownloadblog.com/wp-content/uploads/2019/01/Apple-System-Status-group-FaceTime-disabled.png




https://www.apple.com/support/systemstatus/

zabrljanje
01-02-2019, 16:49
Apple je danas dao izjavu vezano za ovaj bug




We have fixed the Group FaceTime security bug on Apple's servers and we will issue a software update to re-enable the feature for users next week. We thank the Thompson family for reporting the bug. We sincerely apologize to our customers who were affected and all who were concerned about this security issue. We appreciate everyone's patience as we complete this process.

We want to assure our customers that as soon as our engineering team became aware of the details necessary to reproduce the bug, they quickly disabled Group FaceTime and began work on the fix. We are committed to improving the process by which we receive and escalate these reports, in order to get them to the right people as fast as possible. We take the security of our products extremely seriously and we are committed to continuing to earn the trust Apple customers place in us.



Ipak ce update iOS-a da saceka narednu nedelju, uprkos prvobitnim najavama da ce tokom ove nedelje da izadje update sa ispravkama.

Za sad ostaje serverski blokiran Group FaceTime i nikom vise na taj nacin nije ugrozena privatnost.

Ono sto je uocljivo i sustinski sporo: "as soon as our engineering team became aware of the details necessary to reproduce the bug, they quickly disabled Group FaceTime and began work on the fix"


Izgleda da niko nije obratio paznju na mail-ove, sve sa video prikazom, koje je porodica Thompson poslala na vise Apple-ovih adresa. Cak je proslo nekoliko sati od detaljnog prikaza greske, koju je predstavio 9to5mac, do Apple-ovog blokiranja servera.

Izgleda da je update sa ispravkama namerno odlozen zato sto vise nije moguce iskoristiti gresku, koja je serverski blokirana, a samim tim ispravke mogu da ubace u, vec ranije, isplaniran raspored pustanja update-ova.


Deo teksta sa 9to5mac (https://9to5mac.com/2019/02/01/apple-says-ios-fix-for-group-facetime-bug-now-coming-next-week-issues-apology/)



EDIT: Prema ovom, Group FaceTime ce uvek biti onemogucen na iOS 12.1-12.1.3.

Macrumors (https://www.macrumors.com/2019/02/01/group-facetime-perm-disabled-ios-12-1-3-earlier/)

zabrljanje
04-02-2019, 18:58
Decak Grant Thompson, cetrnaestogidisnjak, je kandidat za nagradu u okviru Apple-ovog bug bounty programa.

CNBC je preneo vest da je visoko funkcioner posetio porodicu Thompson


A high-level executive with Apple thanked us in person and also asked for our feedback, asked us how they could improve their reporting process.

They also indicated that Grant would be eligible for the bug bounty program. And we would hear from their security team the following week in terms of what that meant.

https://www.idownloadblog.com/2019/02/04/grant-thompson-group-facetime-bug-apple-bug-bounty/

zabrljanje
07-02-2019, 21:31
Ovaj bug, kao i Live Photos bug, u okviru Group FaceTime, koji je naknadno otkrio Apple, je ispravljen na iOS 12.1.4 i macOS 10.14.3.

Grant Thompson, koji ga je i otkrio, dobija nagradu koja ce biti usmerena ka njegovom daljem obrazovanju.




https://i.imgur.com/pGDSezW.png

camopejb
09-02-2019, 16:04
Pa vi posle koristite FT...
Ko zna od kada taj bug čuči u kodu.

bbrks
09-02-2019, 16:17
Izvini, a sta to imas protiv FTa...... vrhunski gadget :)....jeste zalosno sto su otkrili bug, ali eto opravise ga. Idemo dalje....

zabrljanje
09-02-2019, 16:23
Ovo se odnosi na Group FaceTime i tacno se zna od kad cuci, a to je od iOS 12.1, kad je i omogucen.

Ionako je za njih sad serverski zabranjen a FaceTime je zakon u odnosu na ostale usluge tog tipa. Pogotovo uz vise Apple uredjaja.

technobuba
09-02-2019, 18:41
Zamisli sta tek chuchi kod Viber i slicnih app! Zlo jedno od aplikacije kao i Whatsap, FB Messenger... zivio FT :) svakodnevno ga koristim i za mene nema boljeg!