Some great work by Google researcher Dr. Elie Bursztein has led to Apple increasing security on its iOS App Store. Last July, Elie reported a number of vulnerabilities in the App Store to Apple. As of January, they have been fixed. It appears that certain areas of the App Store were not using HTTPS, and as a result, it was possible for attackers to execute a number of different exploits on users.
HTTPS is a protocol widely used to secure web traffic. By using HTTPS, companies employ an added layer of security to their users’ web traffic. When properly implemented, HTTPS helps ensure that when a user communicates with a server, that the server is indeed who they say they are (and not a malicious third party) and that the contents of their conversation stays private and unmodified. Without HTTPS, not only is it possible for a third party to view your traffic, but it is also possible for a third party to modify the traffic that you are sending and receiving without your knowledge.
In the case of Elie’s exploits, it was shown that due to the lack of HTTPS in certain areas of the App Store, it was possible for a third party to perform a number of attacks: stealing App Store passwords, installing an app other than the one the user was requesting, installing fake upgrades, preventing users from installing certain apps, and even obtaining a list of all apps a user has installed on their device. This was accomplished with scripts that Elie wrote to intercept the HTTP request and alter the responses sent back to his device. While an iPhone might request an app like Angry Birds, the response could be modified to instead serve up Real Racing to the device.
This isn’t the first time we’ve seen a company forget to secure all of their sensitive URLs with SSL and it certainly won’t be the last. Fortunately there don’t seem to be any reports of these vulnerabilities being exploited in the wild (though that’s not to say no attacks occurred and simply went unnoticed) prior to Apple’s fix. It’s also important to note that such attacks would have required a user to be on an unencrypted network with an attacker; this isn’t something that would be done while connected to an encrypted wifi network at your home, or while using your data plan with your cell provider.
Another reminder for users to remain vigilant in good security practices, and not connect their devices to unknown or unsecured networks.
We may earn a commission for purchases using our links. Learn more.
FAQ: TikTok & WeChat ban — why it’s happening and what it means for you
Are TikTok and WeChat really being banned? When does all of this take effect? Will I still be able to use these apps? All this and more answered in our FAQ regarding the latest U.S. orders.
Here's everything we know about the iPhone 12 so far
With the iPhone 12 reportedly just weeks away, here's everything we currently know about Apple's next flagship lineup!
Here's where to find all 120 Stars in Super Mario 64
There are hundreds of Stars hidden around and throughout Princess Peach's castle in Super Mario 64. Here's where you'll find them all.
All the Nintendo Switch accessories for Animal Crossing fans
Animal Crossing: New Horizons is finally out on Nintendo Switch. Go all out with your Animal Crossing love with these adorable-themed accessories.