{"id":762954,"date":"2020-06-01T07:34:00","date_gmt":"2020-06-01T11:34:00","guid":{"rendered":"https:\/\/www.prime-wow.com\/?p=762954"},"modified":"2020-06-01T07:34:00","modified_gmt":"2020-06-01T11:34:00","slug":"finding-serious-sign-in-with-apple-hole-earns-security-researcher-a-100000-bug-bounty","status":"publish","type":"post","link":"https:\/\/www.prime-wow.com\/?p=762954","title":{"rendered":"Finding Serious &#039;Sign In with Apple&#039; Hole Earns Security Researcher a $100,000 Bug Bounty"},"content":{"rendered":"<p>An anonymous reader quotes Forbes:<\/p>\n<p>When Apple announced Sign in with Apple at the June 2019 worldwide developers conference, it called it a &#8220;more private way to simply and quickly sign into apps and websites.&#8221; The idea was, and still is, a good one: replace social logins that can be used to collect personal data with a secure authentication system backed by Apple&#8217;s promise not to profile users or their app activity&#8230; Unsurprisingly, it has been pushed as being a more privacy-oriented option than using your Facebook or Google account. <\/p>\n<p>Fast forward to April 2020, and a security researcher from Delhi uncovered a critical Sign in with Apple vulnerability that could allow an attacker to potentially take over an account with just an email ID. A critical vulnerability that was deemed important enough that Apple paid him $100,000 through its bug bounty program by way of a reward.<br \/>\nWith the vulnerability already now patched by Apple on the server-side, Bhavuk Jain published his disclosure of the security shocker on May 30. <\/p>\n<p>It applied &#8220;only to third-party apps which used Sign in with Apple without taking any further security measures,&#8221; the article points out , adding that the researcher who found it &#8220;said Apple carried out an internal investigation and determined that no account compromises or misuse had occurred before the vulnerability was fixed.&#8221; <\/p>\n<p>But they also quote an SME application security lead at ImmersiveLabs who said he &#8220;would have expected better testing around this from a company such as Apple, especially when it is trying to set itself a reputation as privacy-focused.&#8221;<\/p>\n<p \/>\n<div class=\"share_submission\">\n<a class=\"slashpop\" href=\"http:\/\/twitter.com\/home?status=Finding+Serious+'Sign+In+with+Apple'+Hole+Earns+Security+Researcher+a+%24100%2C000+Bug+Bounty%3A+https%3A%2F%2Fbit.ly%2F3chEu2N\"><img decoding=\"async\" src=\"https:\/\/www.prime-wow.com\/wp-content\/uploads\/2020\/06\/twitter_icon_large-4.png\" \/><\/a><br \/>\n<a class=\"slashpop\" href=\"http:\/\/www.facebook.com\/sharer.php?u=https%3A%2F%2Fapple.slashdot.org%2Fstory%2F20%2F06%2F01%2F0421240%2Ffinding-serious-sign-in-with-apple-hole-earns-security-researcher-a-100000-bug-bounty%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook\"><img decoding=\"async\" src=\"https:\/\/www.prime-wow.com\/wp-content\/uploads\/2020\/06\/facebook_icon_large-2.png\" \/><\/a><\/p>\n<\/div>\n<p><a href=\"https:\/\/apple.slashdot.org\/story\/20\/06\/01\/0421240\/finding-serious-sign-in-with-apple-hole-earns-security-researcher-a-100000-bug-bounty?utm_source=rss1.0moreanon&amp;utm_medium=feed\">Read more of this story<\/a> at Slashdot.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"\" height=\"1\" width=\"1\" alt=\"\" \/>&#013;<br \/>\n&#013;<br \/>\nSource: Slashdot &#8211; <a href=\"http:\/\/feedproxy.google.com\/~r\/Slashdot\/~3\/vexg5KszlHQ\/finding-serious-sign-in-with-apple-hole-earns-security-researcher-a-100000-bug-bounty\" target=\"_blank\" rel=\"noopener noreferrer\">Finding Serious &#8216;Sign In with Apple&#8217; Hole Earns Security Researcher a 0,000 Bug Bounty<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>An anonymous reader quotes Forbes: When Apple announced Sign in with Apple at the June 2019 worldwide developers conference, it called it a &#8220;more private way to simply and quickly sign into apps and websites.&#8221; The idea was, and still &hellip; <a href=\"https:\/\/www.prime-wow.com\/?p=762954\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":762955,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[101,110],"tags":[100],"class_list":["post-762954","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-slashdot","category-unfiltered-rss","tag-slashdot"],"_links":{"self":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/762954","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=762954"}],"version-history":[{"count":0,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/posts\/762954\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=\/wp\/v2\/media\/762955"}],"wp:attachment":[{"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=762954"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=762954"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.prime-wow.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=762954"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}