リーディングビュー

Apple's 'Private Relay' Is Exposing Users' Real IP Addresses

✇Slashdot
著者: BeauHD

🤖 AI Summary

Appleの「プライバシーリレ」がユーザーの実際のIPアドレスを露出している可能性に関するセキュリティ研究者の報告について説明します。研究者Tommy MyskとTalal Haj Bakryは、iCloud Private Relayを使用していても、一部のパスキー関連のリクエストがSafariやそのプロキシ保護機能を绕過していることを発見しました。これにより、ユーザーの実際のIPアドレスが露出される可能性があります。

この問題は、パスキーがWebAuthn標準に基づく安全な代替手段であるにもかかわらず、デバイスからブラウザ外でリクエストを行うため、プライバシーリレの保護を逃れる可能性があるという特異性により引き起こされます。研究者たちは、ユーザーの実際のIPアドレスが漏洩するかどうか確認できるサイトを作成しました。

Appleはこの問題を「重大」と評価し、研究者に公開することを許可しましたが、具体的な解決時期は明かしていません。
Security researchers found that Apple's iCloud Private Relay can expose users' real IP addresses because some passkey-related requests bypass Safari and its proxy protections at the operating-system level. "In short: any website that supports, or pretends to support, passkeys can see the user's real IP address despite having iCloud Private Relay on," security researcher Tommy Mysk, who discovered the issue along with Talal Haj Bakry, told 404 Media. The flaws also affect OnionBrowser, an iOS app for browsing the web through the Tor anonymity network. It does not, however, impact the official Tor Browser itself. From the report: The researchers developed a site that lets Private Relay users check if the issues impact them. In 404 Media's tests, the site did return the real IP address of a user that was supposed to be protected by Private Relay. [...] In a quirk of how passkeys work -- a broadly secure alternative to usernames and passwords which use the WebAuthn standard -- a user's device makes a web request outside of the browser itself. Meaning, that request essentially bypasses Private Relay and exposes a user's real IP address, even though to them it may look like they are simply interacting with a website as normal. "Because the fetch is issued by the operating system's credential service rather than by Safari, it never enters Private Relay's proxied path. The destination server sees the device's real IP address either way," the researchers write in their research. [...] "We have already informed them. They said the issue was âdire,' but they let us disclose the issue. They didn't provide any time when they will address this," Mysk said.

Read more of this story at Slashdot.

  •  

Russia-Linked 'Midnight Blizzard' Group Hijacks Hotel Wi-Fi With CaptiveCrunch

✇Slashdot
著者: BeauHD
A Russia-linked group tracked as Midnight Blizzard has compromised hotel and conference Wi-Fi portals worldwide, redirecting guests to phishing pages and fake software updates that steal credentials, session tokens, and other sensitive data. Microsoft says the campaign, dubbed CaptiveCrunch, "targets traveling employees generally rather than a particular sector," reports iTNews. From the report: Midnight Blizzard, tracked internally by Microsoft under its earlier codename NOBELIUM, is attributed by the US and UK governments to Russia's SVR (Sluzhba Vneshney Razvedki) foreign intelligence service. Microsoft's technical analysis said compromises occurred in "several countries" without naming them, and it did not give a total number of affected venues, organisations or individuals. A related investigation published earlier in July by security firm ReliaQuest, and which Microsoft cited in its report, found compromised captive portal gateways across multiple United States cities as well as in India and Saudi Arabia, mostly at hotels. ReliaQuest said the traffic it observed came from organizations across financial services, professional services, legal, health care, energy and retail, suggesting the campaign targets traveling employees generally rather than a particular sector. [...] Where attackers gained a foothold, Microsoft said they deployed two main tools: CornFlake, a Windows remote access trojan (RAT) written in Go capable of keylogging, screenshot and webcam capture, audio surveillance and credential and session token theft. They would also drop ChocoShell, an in-memory PowerShell infostealer targeting browser cookies, saved passwords, Microsoft 365 single sign-on (SSO) tokens and wi-fi credentials. Microsoft also said it has seen indications the attackers might be targeting Android devices with similar prompts urging victims to download and install an APK file.

Read more of this story at Slashdot.

  •  

Rogue Police Officers Have Turned Flock's Nationwide Camera Network Into a Stalking Tool

A woman found her police officer ex-boyfriend had used Flock's camera system 600 times to look up the location of her and her daughter, reports the Washington Post (Alternate URL here). (She found out through Have I Been Flocked, described as "a website that aggregates police search logs made available through public records.") But it turns out dozens more police officers have also misused Flock... Authorities have charged or accused at least 50 law-enforcement officers of using license-plate readers for unauthorized purposes, including to stalk women without their knowledge or consent, a Post analysis of police and court records found. In 26 of these cases, police investigators and prosecutors said the officers used the technology to spy on their wives, their girlfriends, their exes, their exes' new partners or women they wanted to meet. In other cases, police or prosecutors have not specified the alleged surveillance targets. Flock's system was used in 46 of the cases analyzed by The Post, while the other cases involved competing products... After The Post relayed its findings to Flock, the company said in a statement it "will soon be announcing better filters and tools to stop abuse before it happens...." In April, the company rolled out a new voluntary "audit assistance" feature, which agencies can choose to enable, that automatically scans officers' searches for suspicious activity, such as queries repeatedly targeting the same vehicle or run by officers off the clock. In an interview with The Post, Flock chief executive Garrett Langley said misuse of its systems is inevitable and that the company is focused on providing tools to catch perpetrators after the fact... "We're not going to change humans, and humans make bad decisions," Langley said. "What we can do is make sure that they know if you use this tool, you will be held accountable...." Through automated license-plate reader systems, or ALPRs, officers could trace the rhythms and travels of their subjects' daily lives, leading in some instances to violent confrontations, moments of psychological manipulation, and threats of coercion and control, the analysis found. - In Wisconsin, a police officer allegedly used Flock to check whether his ex-girlfriend had gone to an abortion clinic, according to a police affidavit for a case set for trial this month. - In Kansas, a police chief who tracked his ex through Flock sneaked up on her while she was intimate with another man, a state police certification body alleged, leading to his firing. - In Florida, a deputy speeding to stop a young actress he'd added to a watch list for a license-plate tool called Guardian nearly caused a head-on crash, according to a police report and video from his dashboard camera. The deputy was arrested in March, and his attorney declined to comment. - And in California, prosecutors said a former deputy, Alexander Vanny, used Flock as part of a months-long campaign of "stalking" and "humiliating" his former fiancée that also involved following her around town and installing a hidden camera in her roommate's bathroom, according to a sentencing brief... While some of the searches resulted in officers' firings, prosecutions and prison sentences, police departments in other cases allowed officers to continue using the systems even after receiving warnings that they were being misused... An array of privacy advocates has argued that Flock could deter bad actors by making simple changes to its product, such as requiring officers to label every search with a criminal case number. Some policing experts also warned that agencies' inconsistencies in developing and enforcing standard procedures for license-plate readers could lead to further misconduct. With no federal laws governing use and only a patchwork of state laws, many of the country's roughly 18,000 police agencies are left to decide their rules on their own... Langley, Flock's chief, has dismissed pushes by activists for the company to further limit how officers use its product. "No one elected me the police chief of America," he told Forbes last year, adding, "I don't think it's our job to police the police." The Post also got this quote from an officer was fired and sentenced to probation after pleading no contest to charges of computer-system misuse, stalking and battery. "Pretty much everybody uses that computer system" improperly in the department, he said, and "they don't audit it [nearly] as much as they should." Flock told The Post it now has over 120,000 cameras in more than 6,000 communities, recording 20 billion license plate scans every month.

Read more of this story at Slashdot.

  •  
❌