01:09 PM

Apple Ups Security For App Store

Apple begins using secure Web pages -- HTTPS -- for all App Store communications, to protect against password theft and other potential problems.

Apple has begun using secure Web pages -- HTTPS -- for all App Store communications. The move mitigated a number of vulnerabilities that attackers could have exploited to steal App Store passwords, force users to pay for unwanted apps or intercept user data.

Apple announced the security change earlier this year, noting that "active content is now served over HTTPS by default" for App Store via its iTunes applications. Apple's security notice credited multiple researchers for alerting it to the vulnerability, including Google researcher Elie Bursztein.

Bursztein said Friday in a blog post that Apple's previous failure to use HTTPS for App Store communications -- except on purchase pages – along with its failure to confirm certain activities and the dynamic manner in which App Store pages get generated left users open to "an active network attack that is able to read, intercept and manipulate non-encrypted (HTTP) network traffic," for example, via unencrypted public Wi-Fi hotspots.

[ What lessons can we learn from the Evernote security breach? Read Evernote Breach: 7 Security Lessons. ]

"Being on the same networks as the victims is all it takes [to facilitate man-in-the-middle (MITM) attacks]," he said.

For example, an attacker could have stolen passwords by inserting a fake password-notification prompt into the App Store application update mechanism and swapping a paid app for a free app that a user tried to obtain, thus charging them. Users could also have been tricked into paying for fake app upgrades and been blocked from installing an app either by hiding it from view in the App Store or tricking the user into thinking it was already installed. Finally, Bursztein said the vulnerabilities posed a privacy-leak problem, because "the App Store application update mechanism discloses in the clear the list of the applications installed on the device."

Apple's adoption of HTTPS for all App Store communications follows -- and arguably lags -- similar moves made by Google, which began exploring the use of HTTPS for encrypted search in 2010 and made it the default for all communications with Google services, including Gmail, in 2011. Similarly, Facebook adopted HTTPS by default late last year, as did Twitter.

Last year, Mozilla announced that Firefox would default to the HTTPS version of any website, taking a cue from the HTTPS Everywhere campaign and related plug-in advanced by Electronic Frontier Foundation, which seeks to get more sites to adopt the security offered by HTTPS pages.

Calls for websites to adopt HTTPS increased in the wake of Firesheep, a Firefox plug-in that was released in late 2010 that focused attention on the ease with which traffic being sent across unsecured hotspots -- for example, in many cafes and airports -- could be intercepted. The fix for such attacks was easy: websites needed to enable HTTPS by default, thus adding an encryption layer to all HTTP communications between browser and website.

"Apple, it seems, didn't bother with HTTPS Everywhere, even for its own App Store, until 2013," said Paul Ducklin, head of technology for Sophos in the Asia Pacific region, in a blog post. "Since there's no other place to shop when you're buying or selling iDevice software, and since Apple likes it that way, you might think that Cupertino would have set the bar a bit higher."

How long has Apple's use of HTTP for its App Store put users at risk of being exploited? "I am unsure," Google researcher Bursztein said via Twitter. "I reported it in July [2012], but likely they have been susceptible to MITM for years."

But Bursztein hopes that Apple's adoption of HTTPS for its App Store will lead more developers -- "in particular mobile ones" -- to likewise adopt HTTPS. "Enabling HTTPS and ensuring certificates validity is the most important thing you can do to secure your app communication."

"Please don't let your users down," he said. "Do the right thing: use HTTPS."

Attend Interop Las Vegas May 6-10 and learn the emerging trends in information risk management and security. Use Priority Code MPIWK by March 22 to save an additional $200 off the early bird discount on All Access and Conference Passes. Join us in Las Vegas for access to 125+ workshops and conference classes, 300+ exhibiting companies, and the latest technology. Register today!

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
User Rank: Ninja
3/14/2013 | 11:23:47 AM
re: Apple Ups Security For App Store
I think it is more a sign as to how arrogant and ignorant Apple is. It wasn't even an afterthought, it took externals to point that out to Apple. This is the cost of doing business with Apple.
User Rank: Apprentice
3/13/2013 | 3:09:12 AM
re: Apple Ups Security For App Store
Enterprise adoption of Apple devices will be impacted with this revelation, that Apple has taken so long to meet a basic security criteria.
User Rank: Strategist
3/12/2013 | 2:46:45 AM
re: Apple Ups Security For App Store
I would have thought the App Store was all HTTPS, too. But then again, Macs never get hacked. ;-)

Kelly Jackson Higgins, Senior Editor, Dark Reading
Drew Conry-Murray
Drew Conry-Murray,
User Rank: Ninja
3/11/2013 | 11:28:41 PM
re: Apple Ups Security For App Store
I'm really surprised it took Apple this long. Another example of security as an afterthought.

Drew Conry-Murray
Editor, Network Computing
Who Does What in Cybersecurity at the C-Level
Steve Zurier, Freelance Writer,  3/16/2018
New 'Mac-A-Mal' Tool Automates Mac Malware Hunting & Analysis
Kelly Jackson Higgins, Executive Editor at Dark Reading,  3/14/2018
IoT Product Safety: If It Appears Too Good to Be True, It Probably Is
Pat Osborne, Principal - Executive Consultant at Outhaul Consulting, LLC, & Cybersecurity Advisor for the Security Innovation Center,  3/12/2018
Register for Dark Reading Newsletters
White Papers
Current Issue
How to Cope with the IT Security Skills Shortage
Most enterprises don't have all the in-house skills they need to meet the rising threat from online attackers. Here are some tips on ways to beat the shortage.
Flash Poll
[Strategic Security Report] Navigating the Threat Intelligence Maze
[Strategic Security Report] Navigating the Threat Intelligence Maze
Most enterprises are using threat intel services, but many are still figuring out how to use the data they're collecting. In this Dark Reading survey we give you a look at what they're doing today - and where they hope to go.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.