Apple's 'incredibly private' Safari is not so private in Europe
- Reference: 1714461846
- News link: https://www.theregister.co.uk/2024/04/30/apple_safari_europe_tracking/
- Source link:
Developers Talal Haj Bakry and Tommy Mysk looked into the way Apple implemented the installation process for third-party software marketplaces on iOS with Safari, and concluded Cupertino's approach is particularly shoddy.
tl;dr: The way Apple has added support for third-party app stores lets any website, when visited by Safari on iOS at least, to ping a chosen approved software marketplace with a unique per-user identifier. That means as users move from website to website, or use a website, these sites can quietly disclose that activity to a non-Apple app store – revealing the sort of things individual netizens find interesting. That info can be used for targeted app promotions, ads, and so on. This appears to apply to iOS 17.4 users in the EU. Whether anyone will exploit this in the wild remains to be seen – but the potential is there.
"Our testing shows that Apple delivered this feature with catastrophic security and privacy flaws," wrote Bakry and Mysk in an [1]advisory published over the weekend.
Apple – which advertises Safari as " [2]incredibly private " – evidently has undermined privacy among European Union Safari users through a [3]marketplace-kit: URI scheme that potentially allows approved third-party app stores to follow those users around the web.
A URI scheme is a way of determining how a particular network request gets handled. A website offering an alternative software marketplace can include a button that, when tapped in Safari, launches a marketplace-kit: request that is handled by a [4]MarketplaceKit process on the EU user's iPhone. This process, built into iOS 17.4 by Apple, then reaches out to the back-end servers of the approved marketplace to complete the installation of that store's app on the phone.
[5]
The trouble is, any site can trigger a marketplace-kit: request. On EU iOS 17.4 devices, that will cause a unique per-user identifier to be fired off by Safari to an approved marketplace's servers, leaking the fact that the user was just visiting that site. This happens even if Safari is in private browsing mode. The marketplace's servers can reject the request, which can also include a custom payload, passing more info about the user to the alternative store. This is all illustrated in the video below.
[6]
[7]
[8]Youtube Video
In addition to Apple's Safari, two other iOS browsers currently support third-party app stores in Europe: Brave and Ecosia.
[9]
Apple doesn't allow third-party app stores in most parts of the world, citing purported privacy and security concerns – and presumably interest in sustaining its ability to collect commissions for software sales.
But Apple has been designated as a "gatekeeper" under Europe's Digital Markets Act (DMA) for iOS, the App Store, Safari, and just recently [10]iPadOS .
That designation means the iBiz has been ordered to open its gated community so that European customers can choose third-party app stores and web-based app distribution – also known as [11]side-loading .
But wait, there's more
According to Bakry and Mysk, Apple's URI scheme has three significant failings. First, they say, it fails to check the origin of the website, meaning the aforementioned cross-site tracking is possible.
Second, Apple's MarketplaceKit – its API for third-party stores – doesn't validate the JSON Web Tokens (JWT) passed as input parameters via incoming requests. "Worse, it blindly relayed the invalid JWT token when calling the /oauth/token endpoint," observed Bakry and Mysk. "This opens the door to various injection attacks to target either the MarketplaceKit process or the marketplace back-end."
[12]
And third, Apple isn't using [13]certificate pinning , which leaves the door open for meddling by an intermediary ( [14]MITM ) during the MarketplaceKit communication exchange. Bakry and Mysk claim they were able to overwrite the servers involved in this process with their own endpoints.
The limiting factor of this attack is that a marketplace must first be approved by Apple before it can undertake this sort of tracking. At present, not many marketplaces have won approval. We're aware of the B2B [15]Mobivention App marketplace , [16]AltStore , and [17]Setapp . Epic Games has also [18]planned an iOS store . A few other marketplaces will work after an iThing jailbreak, but they’re unlikely to attract many consumers.
The two security researchers argue that scam apps regularly find their way through Apple's review process, meaning rogue app stores could be allowed through. And they claim the privacy problems arise from Apple wanting to track third-party store usage.
"The flaw of exposing users in the EU to tracking is the result of Apple insisting on inserting itself between marketplaces and their users," asserted Bakry and Mysk. "This is why Apple needs to pass an identifier to the marketplaces so they can identify installs and perhaps better calculate the due [19]Core Technology Fee (CTF) ."
They urge iOS users in Europe to use Brave rather than Safari because Brave's implementation [20]checks the origin of the website against the URL to prevent cross-site tracking.
[21]Academics probe Apple's privacy settings and get lost and confused
[22]In quest to defeat Euro red-tape, Apple said it had three Safari browsers – not one
[23]Apple demands app makers explain use of sensitive APIs
[24]Apple Private Wi-Fi hasn't worked for the past three years
Back when Apple planned not to support Home Screen web apps in Europe – a gambit later abandoned after developer complaints and regulatory pressure – the iGiant justified its position by [25]arguing the amount of work required "was not practical to undertake given the other demands of the DMA." By not making the extra effort to implement third-party app stores securely, Apple has arguably turned its security and privacy concerns into a self-fulfilling prophecy.
In its [26]remarks [PDF] on complying with the DMA, Apple declared, "In the EU, every user's security, privacy, and safety will depend in part on two questions. First, are alternative marketplaces and payment processors capable of protecting users? And, second, are they interested in doing so?"
There's also the question of whether Apple is capable of protecting users – and whether it's interested in doing so.
Apple did not respond to a request for comment. ®
Get our [27]Tech Resources
[1] https://www.mysk.blog/2024/04/28/safari-tracking/
[2] https://www.apple.com/safari/
[3] https://developer.apple.com/documentation/marketplacekit/marketplacekiturischeme
[4] https://developer.apple.com/documentation/marketplacekit
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZjDBRetn1MSZuumYkyxePgAAANA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZjDBRetn1MSZuumYkyxePgAAANA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZjDBRetn1MSZuumYkyxePgAAANA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://www.youtube.com/watch?v=aISz4ITI710
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZjDBRetn1MSZuumYkyxePgAAANA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://www.theregister.com/2024/04/29/apple_ipados_dma_gatekeeper/
[11] https://www.theregister.com/2024/03/12/apple_update_eu_devs_can_distribute_from_websites/
[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZjDBRetn1MSZuumYkyxePgAAANA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[13] https://learn.microsoft.com/en-us/azure/security/fundamentals/certificate-pinning
[14] https://csrc.nist.gov/glossary/term/man_in_the_middle_attack
[15] https://app-marketplace.eu/
[16] https://altstore.io/
[17] https://setapp.com/
[18] https://www.epicgames.com/site/en-US/epicgamessweden
[19] https://developer.apple.com/support/core-technology-fee/
[20] https://github.com/brave/brave-core/blob/e5491ddf02847173f1d1d2ab6622a7944b862c79/ios/brave-ios/Sources/Brave/Frontend/Browser/BrowserViewController/BVC%2BWKNavigationDelegate.swift#L211
[21] https://www.theregister.com/2024/04/05/apple_apps_privacy_study/
[22] https://www.theregister.com/2023/11/02/apple_safari_browser/
[23] https://www.theregister.com/2023/07/29/apple_developer_api/
[24] https://www.theregister.com/2023/10/27/apple_private_wifi_fixed/
[25] https://www.theregister.com/2024/02/16/apple_web_apps/
[26] https://developer.apple.com/security/complying-with-the-dma.pdf
[27] https://whitepapers.theregister.com/
Meh
This is a smaller than average storm in a teacup. I don't know what the barrier to getting an alternative App store is, but considering that - unlke Apps - Apple actively don't want them to exist, I would expect the barrier is very, very high. Certificate pinning? Well, OK, but if your DNS has been hacked then you've got bigger issues. As for validation of JWT tokens, please, that's just silly. It's a public webserver, it's already getting thousands of malformed queries a day.
They say you have to click, so even if we imagine the worst case - you're in an environment where the DNS redirects an app-store URL to a malicious IP - you still need users to a) visit a site with this malicious app store link designed to track you, b) interact with it by clicking a button, and c) visit some other malicious site later and do the same so they can correlate. Could a rogue state do much with this? I don't think they could. I also don't understand the claim that Apple are able to track anything with this - there's no network connection to any Apple server in this chain. The only party that could track anything is the one hosting the App store.
Quite Interesting score: 3/10, because it's a new area to research for attacks. Threat score: 1/100.
Re: Meh
More importantly is there a "disable this scheme" option for those who don't care about a third party store?
Re: Meh
I would like to amend my original post.
Despite watching the presentation, noting the network traffic it displayed and concluding the research was almost completely impractical as a method of tracking individuals, I realise this analysis forgot to add any pointed observations about the evils of large tech firms in general and Apple in particular. My knee made no jerking movements during this process, and I also neglected to use the phrase "holding it wrong". I now realise this was unacceptable and I promise to do better on any future comments.
Ah Apple
Between jailbreaking and locked ecosystem and now this, the iNazi has amply demonstrated its thirst for control of everything.
And, as usual, when you're addicted, you don't think straight. Apple is addicted to control, and it has now undermined the security and privacy of its users.
Congratulations for giving me yet another reason to never buy your products.