news.volyx.in

Zero-day in Sign in with Apple (bhavukjain.com)

1076 points by masnick · 2319 days ago · 267 comments on HN

Article summary

A zero-day vulnerability was discovered in Apple's Sign in with Apple feature, which could have allowed an attacker to take over user accounts on third-party applications. The bug allowed an attacker to request JSON Web Tokens (JWTs) for any email ID from Apple, which would be verified as valid using Apple's public key. Apple paid $100,000 under their Security Bounty program to the researcher who discovered the bug. The vulnerability has been fixed and Apple found no evidence of misuse or account compromise.

Main themes

  • Apple Security Vulnerability
  • Sign in with Apple
  • JSON Web Tokens
  • Bug Bounty Program
  • Market Power and Antitrust
  • Security Measures and Documentation
  • Account Takeover and Authentication Risks

What commenters say

  • The bug was Apple's responsibility, as their authentication system was vulnerable to being tricked into confirming false identities.
  • Third-party applications are also responsible for implementing additional security measures to prevent such attacks.
  • The use of JSON Web Tokens (JWTs) is not inherently insecure, and the issue was with Apple's implementation, not the token format itself.
  • Apple's requirement for apps to implement Sign in with Apple is an abuse of their market power and introduces unnecessary complexity and security risks.
  • The bug bounty program is effective in incentivizing researchers to discover and report vulnerabilities, but its overall effectiveness is debated.
  • The lack of transparency and documentation from Apple contributed to the vulnerability and made it harder for developers to implement the feature securely.
  • The issue highlights the need for more robust security measures and better documentation from companies like Apple, especially when they have significant market influence.