Stories
Slash Boxes
Comments
typodupeerror delete not in

+-   a little .mac security flaw on Saturday December 15 2007, @04:59PM deleuth

Submitted by deleuth on Saturday December 15 2007, @04:59PM
security
deleuth writes "The de facto online connectivity software sold along with many Apple computers, .Mac, has a web interface through which users can check their "iDisk" whilst away from their own computer. However, there is no Log-Out button in this web interface, so most users just close the browser and walk away...not realizing that their iDisk has been cached by the browser and that anyone who wants to can open up the browser, go back to the link in History, and get into their iDisk completely logged in. From here, files can be downloaded and/or deleted. This seems like a minor security flaw via bad interface design, and podcaster Klaatu (of thebadapples.info) posted this on the discussion.apple.com site, only to have his post removed by Apple. Furthermore, feedback at apple.com/feedback has gone unanswered. The problem remains: there is NO way for the average computer user to log-out of their iDisk on public computers! The format of the link that will get you into an iDisk is this: http://idisk.mac.com/USERNAME?view=web So a quick review of any public terminal's browser history could bring up all kinds of interesting things."
submission

This discussion was created for logged-in users only, but now has been archived. No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More
Loading... please wait.
The clash of ideas is the sound of freedom.