Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Interesting bug, but I'd call the title a bit of an exaggeration. The mail app doesn't 'allow' harvesting Apple IDs, it allows unexpected content to be displayed in emails, and the author shows a proof of concept of using that for relatively convincing phishing.


You may not fall for this -- but a good section of non-technical people would. Harvesting is not an exaggeration.


A good section of non-technical people would fall for the same thing if presented from any random website in Safari (especially with iOS's predilection towards random password popups from background processes...). Not trying to downplay the issue, just provide some perspective.


One big difference is that by tying it to the email client, you're already showing the targets email address pre-filled, just like the legit prompt would. Plus, you can specifically target an individual and show the prompt without needing to convince them to visit a webpage first.


We changed the title to that of the page. Submitted title was "iOS Mail App Allows Harvesting Apple IDs".

When submitting, please follow the guidelines and use the original title unless it is misleading or linkbait.

https://news.ycombinator.com/newsguidelines.html




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: