Apple’s .Mac iDisk insecure via Web browser

“While I was a fan of .Mac back when it was iTools, these days, I am less allured by its now pay-for services,” Jeff Smykil writes for Ars Technica.

“You are now hard-pressed to use Apple’s operating system without seeing some mention of the service. I dare say that the rise in popularity is most likely due to the presence of Apple retail stores and sales people asking just about anyone who makes a purchase if they would like .Mac with that,” Smykil writes.

“One of the more useful features of .Mac is the ability to access an iDisk from a browser [but] your iDisk might not be as secure as you’d like to think, and for a pretty stupid reason,” Smykil writes.

“According to one Slashdot reader, there is no way to log out of an iDisk in a browser, meaning that another user can access everything on your iDisk using the browser’s history feature. The individual is then apparently free to view and or delete your files. Not good. Not good at all,” Smykil writes.

More info in the full article here.

40 Comments

  1. What’s this MDN?
    No reassuring ‘this is only FUD’ comment from MDN?
    Is this an admission that Macs and OSX and .Mac and Safari and other Apple things are now subject to invasion, attacks, horses, worms, other bad things JUST LIKE WINDOWS?
    Huh?

  2. Is this an admission that Macs and OSX and .Mac and Safari and other Apple things are now subject to invasion, attacks, horses, worms, other bad things JUST LIKE WINDOWS?

    Subject to them, yes; but not nearly as vulnerable to them and definitely not JUST LIKE WINDOWS.

  3. “Is this an admission that Macs and OSX and .Mac and Safari and other Apple things are now subject to invasion, attacks, horses, worms, other bad things JUST LIKE WINDOWS?”

    i dont really think this is any of those things, its a problem with the service not the mac or os. Though the issue should be delt with, those who now know can delete there history, or reset safari which is advisable anyway if you do anything secure on a mac other than your own.

  4. IDK if .Mac sucks or not b/c I’ve never used it. I’ve just always thought it was silly to pay for services you can get for free, or near-free anyway. Never really saw any reason to try it, personally.

    @S. J. Sydney
    I think the whole “…JUST LIKE WINDOWS” part mighta been a little over the top. (I hope that was sarcasm). At risk of sounding ‘fanboy-ish’, I don’t think that one instance of insecurity every now and then will ever justify anything as being ‘just like windows’ when it comes to security.

    Just my 2¢

  5. Note that the reporter is only reporting what he read elsewhere and hasn’t actually tried accessing iDisk via web. I tried it and had to both log in to .Mac, then log in again for iDisk access. I quit the web browser and went back later. Yup, my iDisk showed up in the History menu, but when I tried to access it, it required log in.

    Either the Slashdot reader was using some method to circumvent the login request, or was actually accessing only the Shared Folder on iDisk, which is, unless to change the settings, open to anyone to access. Or perhaps Apple quietly fixed the issue.

    Nonetheless, another reporter parroting hearsay with no research.

  6. @ S.J.

    So you hate the MDN comments, but bitch if they aren’t there? Nice. How about, this is a potential security threat, so they posted it to alert Mac users. They could have not posted it, in which case you would probably be bitching that they were hiding it. If you don’t like the commentary, you can troll elsewhere.

  7. I just tied this on a PC with Firefox, IE and Safari and each time after I had quit out of the app I was prompted for my password when I tried to get back into my iDisk. Not sure if I’m missing something but it seems okay to me.

  8. @S. J. Sydney

    Why be so negative? Did MDN have a choice of whether or not to post this article to their site? If they were only interested in “reassuring ‘this is only FUD'”, why would they have posted this article in the first place?

    Remember, this is “MacDailyNews”. By its nature it is Mac-centric. Just read the news and move on. Spend more time outside.

  9. I have .Mac.

    I’ve tried it using Windows PC’s, Linux PC’s, and Macintoshes.

    On all three, if you quit the browser, you have to re-enter the username and password (though the username is pretty easy to guess).

    That being said – if you are using Safari on a Mac – and have put your .Mac information into the system keychain, then it can give the appearance of allowing “full access” from the history.

    This is because Safari will automatically fill in a form using keychain data and move on to the next page without user input.

    FireFox or IE will simply fill in the form from their password managers.

    So yes, if you are dumb enough to put your .Mac username and password into the password manager of a PUBLIC COMPUTER, then yes, your iDisk can be accessed by anybody.

  10. @jeff

    That may be what’s happening but when you X out of a windows browser you automatically quit the app (as long as you don’t have any other browser windows open). Given that most shared computers are PCs that would probably be enough but yes, I agree, on a Mac you’d need to quit out.

    Any yes, if someone clicked ‘remember password’ on a public computer well, there’s probably not much hope for them

  11. @ROB

    “I would start fixing .Mac by lowering the price to $29.95.”

    I would start by offering .Mac for FREE!

    There still is no compelling reason for me to pay for the services of .Mac.

    Keep trying Apple.

  12. If one is dumb enough to just close the idisk window and not also quit the browser, then … yeah … one stays logged in. But if you quit the browser you have to re-log in. You just can’t select it from the history and get in after having quit the browser.

    As usual, most problems like this are dependent upon people being STUPID. Essentially, if one hasn’t quit the browser, one might as well have left the window open to make it easy for he next guy.

  13. yeah… I’m with the first poster. Dot Mac Sucks.

    Nice feature set, but it just doesn’t work half the time. Can’t log in, Syncing gets stuck.. all kinds of issues.. and now since the outage yesterday, the “Back to My Mac” isn’t working either.

    MDW Word = face like face it, Dot Mac hasn’t really lived up to it’s potential.

  14. Just like walking away from MSN messenger or Face book or whatever after logging in and the next person that comes along can post as you or access your personal goodies and change the parameters.

    I once used a public computer in a hotel lobby and found that some young girl had left her account name and password in Outlook Express’ incoming mail account. I suddenly had access to all of her e-mail. Yes, I read it and yes, I fixed her mistake.

    Now, was this user stupidity or a flaw in Outlook Express?

    Outlook Express has many flaws, but those of you who said user stupidity, win.

  15. Well, like other readers above, I quit my Firefox application, and then started Firefox again, and was prompted for my userid and password once again. When the author of this article quotes someone from slashdot as saying,

    “According to one Slashdot reader, there is no way to log out of an iDisk in a browser, meaning that another user can access everything on your iDisk using the browser’s history feature. The individual is then apparently free to view and or delete your files. Not good. Not good at all,”

    They should at least try before writing a whole article from a false pre-supposition. Shame on the author for not doing some simple homework.

    P.S. I Use 256-Bit AES encryption with anything I put on my iDisk that I don’t want anyone to pry into. Indeed, I double encrypt my files so that they cannot even get a directory of my encrypted zip file. Who knows what sys admin what security holes exist out there, so it really all boils down to taking care up front.

  16. @ Bill Mac,

    “P.S. I Use 256-Bit AES encryption with anything I put on my iDisk that I don’t want anyone to pry into. Indeed, I double encrypt my files so that they cannot even get a directory of my encrypted zip file. Who knows what sys admin what security holes exist out there, so it really all boils down to taking care up front.”

    I think there is a job for you at the UK Government, judging by the complete lack of encryption that goes on with our personal data.

  17. Like everything else in the world, iDisk security is vulnerable to good, old-fashioned stupidity. Any .Mac user who is the least bit concerned about the protection of their iDisk files can clear the History and delete the cookies. Should users have to go through this exercise? Certainly not! Does it represent a dire threat to the security of your data? Hardly!

  18. For those who like to blame the victim, I’d like to remind you that every dotMac page/service has a logout button EXCEPT on your iDisk.

    I can’t defend Apple in this situation. It is a dumb oversight which Apple needs to correct… yesterday!

    That doesn’t relieve anyone from observing safe computing practices. However, time-outs and login/logout procedures should be consistent throughout all the dotMac services.

    Yes, I am a subscriber.

  19. I have not seen this behavior and I just tested it. It still prompts me to log in if I close the browser. Tried this in IE7 for Windows with no problems. Maybe it has something to do with my security settings, but I don’t believe this is correct.

    If you are on a public or work computer, you should be deleting history and cookies when you log out anyway. But if this guy is right, it’s a big Apple blunder. Wouldn’t be the first time, but remember, how many blunders have their been on Apple’s side of the street vs. Microsoft?

    fm

  20. @wannabe
    Apple seriously needs to do something with .Mac. They are getting killed in the online service department by Google especially.

    That may be true, but I’m not posting any of my pictures on Picasa anymore. I haven’t checked Google’s other services, but I will.

    From Picasa’s “Terms of Service”:

    11. Content licence from you

    11.1 You retain copyright and any other rights you already hold in Content which you submit, post or display on or through, the Services. By submitting, posting or displaying the content you give Google a perpetual, irrevocable, worldwide, royalty-free, and non-exclusive licence to reproduce, adapt, modify, translate, publish, publicly perform, publicly display and distribute any Content which you submit, post or display on or through, the Services. This licence is for the sole purpose of enabling Google to display, distribute and promote the Services and may be revoked for certain Services as defined in the Additional Terms of those Services.

    11.2 You agree that this licence includes a right for Google to make such Content available to other companies, organizations or individuals with whom Google has relationships for the provision of syndicated services, and to use such Content in connection with the provision of those services.

    11.3 You understand that Google, in performing the required technical steps to provide the Services to our users, may (a) transmit or distribute your Content over various public networks and in various media; and (b) make such changes to your Content as are necessary to conform and adapt that Content to the technical requirements of connecting networks, devices, services or media. You agree that this licence shall permit Google to take these actions.

    11.4 You confirm and warrant to Google that you have all the rights, power and authority necessary to grant the above licence.

  21. If you are using Safari on a different computer, public or borrowed, then you can use private browsing to prevent an entry to the history file from being created in the first place. Or, if you forget, you can delete entries from the history, or wipe it completely.

    Apple still has some work to do to pull all of the MacOS X and application functionality together into a neat package that ‘just works.’ Even more mature apps, like iTunes and iPhoto need some help. You should be able to easily share those databases with other users/accounts on your computer without jumping through hoops. And you should be able to do so while still being able to protect the contents of the library to anyone without admin access.

  22. Hey, Jamie.

    “I think there is a job for you at the UK Government, judging by the complete lack of encryption that goes on with our personal data.”

    Sorry to hear that the UK Government has a problem along these regards. A government should never have these problems. But, I read about information losses everyday. We all need to stay informed, and do our part. A system is only as secure as it’s subsystems. ” width=”19″ height=”19″ alt=”grin” style=”border:0;” />

  23. Browser-based iDisk access uses HTTP authentication rather than the more common login screen that other .Mac services use. This difference is why this flaw is a concern. The browser does remember the login credentials, even after closing all open windows. Quitting the app (at least for Safari) solves the problem.

  24. One other thing I forgot to mention…

    Because webdav allows access control over your iDisk, .Mac allows an iDisk user to set the iDisk as write only i.e. you don’t have to worry about someone erasing your files via a web-browser, not even you can do it. I have to go home and access my iDisk from my Mac to delete stuff off my iDisk ’cause I set webdav up through the iDisk administration (Settings on the Mac as I recall) to be write only.

    As we admin’s usually say: RTFM. Go out and read about webdav on, say, wikipedia before touting off miss-information.

    Ok. Back to normal. iDisk isn’t as bad as some would portray – above.

  25. Oh, yeah – the only thing I’m ever concerned with is using up my 300GByte per month transfer limit to/from my web pages, iDisk (the same thing, actually), etc. I allow my friends to utilize my Public iDisk space to transfer data to/from work (with the usual speech that I give them about double-encryption – see above) – so I monitor my monthly data-transfer amount to make sure I’m not getting hosed. Fortunately, even with sharing a bunch of mpeg4’s with friends, etc., the most I’ve used in 1 month has been slightly over 3.0GBytes of transfer quota. Not even close to my 300GByte per month allocation. Wish Apple would adopt a roll-over policy. Not likely, but it’s nice to dream… ” width=”19″ height=”19″ alt=”grin” style=”border:0;” />

  26. Bream Rockmetteller has it right.

    You can’t access your iDisk thru a web browser in dotMac without logging in. When you close the iDisk window, you’re logged out of your iDisk.

    This is a non-issue… unless you are stupid enough to have non-trustworthy people using your Mac and allow them access to your user account.

    Show of hands on that one.

    Anybody?

    Didn’t think so.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.