One of the best new iOS 15 features may also have a serious security flaw
Date:
Thu, 23 Sep 2021 10:21:39 +0000
Description:
Researchers claim a fatal flaw in iOS 15 anonymising tool defeats its whole purpose.
FULL STORY ======================================================================
Cybersecurity researchers have flagged a potential zero-day vulnerability in Apples new iCloud Private Relay service for iOS 15 , through which it can
leak users true IP addresses.
Offered as a free upgrade provided for paying iCloud users in Apples latest mobile operating system update, iCloud Private Relay allows users to hide their IP addresses and DNS requests from websites and network service providers.
However, Sergey Mostsevenko, a researcher and developer at security vendor FingerprintJS, discovered that the service leaks IP addresses through the WebRTC API. TechRadar needs you!
We're looking at how our readers use VPNs with streaming sites like Netflix
so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.
Click here to start the survey in a new window << Shield yourself with these best identity theft protection services We've put together a list of
the best endpoint protection software Heres our list of the best VPN services
In a post detailing the vulnerability, Mostsevenko demonstrates that this
leak enables websites to establish direct communication with their visitors, defeating the anonymizing purpose of the private relay service. Leaky service
The new Apple service is similar to a VPN , in that it encrypts web-browsing traffic and sends it through a relay to obfuscate its contents, including the users location and IP address. When browsing the web through the service, visited websites will only see the proxy IP address assigned by iCloud.
Explaining Mostsevenkos findings, The Daily Swig says that the service relies on WebRTC to set up communications with the help of the ICE (interactive connectivity establishment) framework.
As part of that process it collects what are known as ICE candidates, which include various pieces of information such as the IP address or domain name, port, protocol, and other information, which it then returns to the browser.
However Mostsevenko found that Apples Safari web browser is passing ICE candidates containing the real IP addresses.
To fix this vulnerability, Apple will need to modify Safari so it routes all traffic through iCloud Private Relay, concludes Mostsevenko, who has reported the vulnerability to Apple, but hasnt heard back. Weve also rounded up the best business VPN services
Via The Daily Swig
======================================================================
Link to news story:
https://www.techradar.com/news/one-of-the-best-new-ios-15-features-may-also-ha ve-a-serious-security-flaw/
--- Mystic BBS v1.12 A47 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)