Security researchers warn Apple that “AirTag” could be a “good Samaritan attack”

The loss prevention tag “AirTag” announced by Apple in April could be used for phishing scams. “Krebs on Security,” run by security journalist Brian Krebs, warned on September 28 (local time).

 airtag 1 AirTag is 3800 yen per piece

If AirTag is set to “lost mode”, a unique URL for https://found.apple.com will be generated and you own the AirTag there. Allows a person to enter a contact’s phone number or email address.

Krebs warns that this feature could be used to redirect “Good Samaritan” to iCloud phishing pages or other malicious websites. bottom. (A good Samaritan is the Samaritan who helped a lost traveler in the Gospel of Luke 10: 25-37.)

) For example, if a person who finds an AirTag of a lost item scans the AirTag, it will be automatically transferred to the URL.

However, since it is possible to enter any code other than the phone number and email address in the lost mode, for example, the person who scanned the AirTag You may be redirected to a fake iCloud login page or another malicious site.

It’s possible that something other than your phone number or email address is entered on found.apple.com

Security consultant Bobby Rauff explained the issue to Krebs on Security. Rauff reported the issue to Apple on June 20, but Apple hasn’t addressed the issue yet. He told Krebs on Security that he had given him 90 days to open the issue to the public.

“I can’t remember other cases where these low-cost small tracking devices could be weaponized” (Rauf)

The price of one AirTag is $ 29 (3800 yen in Japan).

Mr. Krebs introduced a scenario that actually happened in the past and abused an inexpensive USB drive. An attacker drops a malware-laden USB in the parking lot of a company he wants to hack, and employees think it’s a lost item and connect it to an office PC to break into the network. This actually happened in 2008 in a parking lot at a US Department of Defense facility.

Rauff said the issue may not be the most important issue for Apple, but it should be easy to fix. Apple hasn’t responded to Krebs on Security’s request for comment.

Copyright © ITmedia, Inc. All Rights Reserved.

Note: This article have been indexed to our site. We do not claim ownership or copyright of any of the content above. To see the article at original source

Click Here

Related Posts
Ladj Ly’s ‘Les Indésirables’ To World Premiere At Toronto; Fest Describes Paris Outer-City Suburb Drama As “Timely Tale Of Revolution” thumbnail

Ladj Ly’s ‘Les Indésirables’ To World Premiere At Toronto; Fest Describes Paris Outer-City Suburb Drama As “Timely Tale Of Revolution”

The fall fest season is revving up. The Toronto Film Festival said Wednesday that French director Ladj Ly’s new feature Les Indésirables will world premiere at its 48th edition, running from September 7-17. It is the first international world premiere title to be unveiled by TIFF ahead of fuller lineup details in the coming weeks.
Read More
Even in subscriptions, Nintendo is playing its own game | Opinion thumbnail

Even in subscriptions, Nintendo is playing its own game | Opinion

There's an argument to be made that the rise of video game subscription services is inevitable. Take a look at any other form of entertainment -- TV, film, music, books -- and you'll see all have been disrupted, sometimes irreversibly, by the monthly fee model.Conventional wisdom across the wider entertainment world is that subscriptions should…
Read More
The Philharmonic is saying goodbye to Ivan Tasovac with a concert thumbnail

The Philharmonic is saying goodbye to Ivan Tasovac with a concert

Foto: TanjugBEOGRAD – Beogradska filharmonija oprašta se večeras koncertom umesto komemoracije od svog dugogodišnjeg direktora Ivana Tasovca u Kolarčevoj zadužbini.Pred sam početak koncerta, šef dirigent Beogradske filharmonije Gabrijel Felc rekao je publici da će se orkestar umesto minutom ćutanja od Tasovca oprostiti muzikom, onim što je on najviše voleo u životu.Potom su filharmoničari odsvirali petominutni…
Read More
Holly Herndon Covers Dolly Parton’s “Jolene” Using AI: Listen thumbnail

Holly Herndon Covers Dolly Parton’s “Jolene” Using AI: Listen

Holly Herndon has released a new cover of Dolly Parton’s classic ballad “Jolene,” recorded with artificial intelligence. The AI cover was created with Herndon’s deepfake “twin” Holly+, which allows other people to sing in the electronic composer’s voice. In this instance, a modified score of “Jolene,” comprised of new harmonies, was fed to Holly+ and
Read More
Index Of News
Total
0
Share