Security researchers warn Apple that “AirTag” could be a “good Samaritan attack”

The loss prevention tag “AirTag” announced by Apple in April could be used for phishing scams. “Krebs on Security,” run by security journalist Brian Krebs, warned on September 28 (local time).

 airtag 1 AirTag is 3800 yen per piece

If AirTag is set to “lost mode”, a unique URL for https://found.apple.com will be generated and you own the AirTag there. Allows a person to enter a contact’s phone number or email address.

Krebs warns that this feature could be used to redirect “Good Samaritan” to iCloud phishing pages or other malicious websites. bottom. (A good Samaritan is the Samaritan who helped a lost traveler in the Gospel of Luke 10: 25-37.)

) For example, if a person who finds an AirTag of a lost item scans the AirTag, it will be automatically transferred to the URL.

However, since it is possible to enter any code other than the phone number and email address in the lost mode, for example, the person who scanned the AirTag You may be redirected to a fake iCloud login page or another malicious site.

It’s possible that something other than your phone number or email address is entered on found.apple.com

Security consultant Bobby Rauff explained the issue to Krebs on Security. Rauff reported the issue to Apple on June 20, but Apple hasn’t addressed the issue yet. He told Krebs on Security that he had given him 90 days to open the issue to the public.

“I can’t remember other cases where these low-cost small tracking devices could be weaponized” (Rauf)

The price of one AirTag is $ 29 (3800 yen in Japan).

Mr. Krebs introduced a scenario that actually happened in the past and abused an inexpensive USB drive. An attacker drops a malware-laden USB in the parking lot of a company he wants to hack, and employees think it’s a lost item and connect it to an office PC to break into the network. This actually happened in 2008 in a parking lot at a US Department of Defense facility.

Rauff said the issue may not be the most important issue for Apple, but it should be easy to fix. Apple hasn’t responded to Krebs on Security’s request for comment.

Copyright © ITmedia, Inc. All Rights Reserved.

Note: This article have been indexed to our site. We do not claim ownership or copyright of any of the content above. To see the article at original source

Click Here

Related Posts
St. Vincent Announces All Born Screaming Tour thumbnail

St. Vincent Announces All Born Screaming Tour

One of the most innovative and fascinating presences in modern music, GRAMMY award-winning artist St. Vincent is thrilled to announce her long-awaited return to Australia this November with the All Born Screaming Tour. Her first live appearances down under since 2018, St. Vincent (Annie Clark) will perform at two of the state’s most exquisite venues
Read More
Park Seo Joon Details His Busy Schedule in London thumbnail

Park Seo Joon Details His Busy Schedule in London

South Korean actor Park Seo Joon is spending his time in London where he is in the midst of filming major blockbuster The Marvels. Hoping to stay in touch with his fans, the actor released a vlog to share his filming experience and life in the city. Starting the day before sunrise, the actor gave…
Read More
Boredom drew me to acting, says Glenda Jackson thumbnail

Boredom drew me to acting, says Glenda Jackson

Glenda Jackson has said “boredom” is what drew her to acting after she grew up learning that “if you didn’t work, you didn’t eat”.The 86-year-old former politician has won the Oscar for best actress twice, although opted not to attend the ceremony on either occasion.Speaking to The Times Magazine, Jackson said she only started acting
Read More
Index Of News
Total
0
Share