Risk
9/4/2010
01:38 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Apple's Ping Stumble Highlights Systemic Security Problem

Within 48 hours of Ping's launch, Apple's foray into music social networks, more than one million users joined. Too bad, like so many other applications and services on the Internet, security was an afterthought, and those users were plagued with spam comments.

Within 48 hours of Ping's launch, Apple's foray into music social networks, more than one million users joined. Too bad, like so many other applications and services on the Internet, security was an afterthought, and those users were plagued with spam comments.Chester Wisniewski's blog post (anti-virus vendor Sophos), shows users getting inundated with "Get a free iPhone from . . . " spam because Apple failed to adequately authenticate users,or filter bogus URLs, in the new service:

Strangely, Apple seems to have anticipated a certain degree of malfeasance, as profile pictures that you upload will not appear until approved by Apple. They are likely filtering for other offensive content as well, so they probably have means in place they could use to stop the spam. Another problem that is likely to contribute to spam is that it is quite easy to create bogus accounts for the Ping service because no credit card or other positive identification is required to participate.

Coincidentally, the most common spam on Ping at the moment targets Apple itself. The attacks are nearly identical to survey spams we have blogged about on Facebook, Google and Twitter.

If half as many free iPads, iPhones and iPods were being given away as Ping comments might lead you to believe, there would be no reason to bother with going to an Apple store. But if you actually want an Apple device, my advice is to go out and buy one, as filling out surveys will likely only end in tears.

Our Thomas Claburn covered the Apple spam slip-up in some depth in his story Apple iTunes Ping Draws Spam, Complaints.

To its credit, Apple does appear to now be cleaning spam from its systems. However, Apple loses points for not seeing this coming. Spam that hawks gadgets and other wares is a big problem on Twitter, while in the early days of the now defunct Google Wave complaints of spam slowing the system surfaced, and we all know that comment spam is a big scourge on blogging sites.

Which brings us to a broader, much more important question: why is security, when it comes to just about any application or service deployed on the Internet, treated as the red-headed stepchild that is ignored until something bad happens?

Security was ignored when industry moved all of its back-end applications to the Web in the late 1990s and early 2000s - and Web application security is still abysmal, if not worse, today. Same is true with online credit card acceptance. It didn't take a genius of a futurist to predict that credit card thievery and fraud would follow commerce to the Internet in the late 1990s - and yet merchants and the credit card industry didn't do much to secure e-Commerce systems. It wasn't until 2005 when the Payment Card Industry Data Security Standard came into being - about a decade after online commerce started its growth.

It's because designing secure systems is a difficult (much harder than breaking them by comparison) additional step. It requires engineers step back and consider how the system they're building can possibly be infiltrated, abused and misused. And then design must be changed to mitigate those risks. And it also requires incremental layers of quality control - scanning for defects in design and code during development and as the application lives and changes in production.

That's, apparently, still too much to expect. Speaking of design defects, if you haven't yet, you should consider updating to iTunes 10 - the upgrade comes with a fix for a baker's dozen of separate software vulnerabilities.

One of the most recent, similar examples, of such security design fail and social networking site Twitter, which I covered earlier this summer in the post FTC Security Smackdown And Twitter's Hollow Excuses.

Despite its early security lapses, you can find me on Twitter, and follow my security and business observations throughout the day.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6501
Published: 2015-03-30
The default soap.wsdl_cache_dir setting in (1) php.ini-production and (2) php.ini-development in PHP through 5.6.7 specifies the /tmp directory, which makes it easier for local users to conduct WSDL injection attacks by creating a file under /tmp with a predictable filename that is used by the get_s...

CVE-2014-9652
Published: 2015-03-30
The mconvert function in softmagic.c in file before 5.21, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not properly handle a certain string-length field during a copy of a truncated version of a Pascal string, which might allow remote atta...

CVE-2014-9653
Published: 2015-03-30
readelf.c in file before 5.22, as used in the Fileinfo component in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5, does not consider that pread calls sometimes read only a subset of the available data, which allows remote attackers to cause a denial of service (uninitialized memory ...

CVE-2014-9705
Published: 2015-03-30
Heap-based buffer overflow in the enchant_broker_request_dict function in ext/enchant/enchant.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 allows remote attackers to execute arbitrary code via vectors that trigger creation of multiple dictionaries.

CVE-2014-9709
Published: 2015-03-30
The GetCode_ function in gd_gif_in.c in GD 2.1.1 and earlier, as used in PHP before 5.5.21 and 5.6.x before 5.6.5, allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted GIF image that is improperly handled by the gdImageCreateFromGif function.

Dark Reading Radio
Archived Dark Reading Radio
Good hackers--aka security researchers--are worried about the possible legal and professional ramifications of President Obama's new proposed crackdown on cyber criminals.