Apple leaking private customer information over insecure HTTP

By William Entriken

3 minutes

EMBARGO: This article was written 2015-10-26 and immediately reported to Apple. Actually published 2017-09-06.

UPDATE 2017-09-06: Added timeline. Also I want to clarify that “leaking” means “accidentally lose” according to Google Dictionary. Some modern use of this word seems to imply “intentional disclosure”, that is not the meaning I intend.

On the Apple Store website, customer details are leaked over insecure HTTP. Following is a screenshot showing that the customer’s complete address is displayed on the page. A ZIP+4 is usually enough to translate to a full address.

Leak example

Here is the same page loaded without cookies, the address is not shown.

No cookies example

Please compare this to Apple’s account login page which also provides account addresses. However this page is delivered over HTTPS.

HTTP example

The attack: a potential way that this vulnerability could be abused would be a free Wi-Fi connection that redirects to the apple.com product page on your device. This rogue Wi-Fi network would then learn your personal shipping address.

Timeline (excluding automated replies)

This is a simple problem reported here but you can be sure that the solution is not always so simple. Also, in addition to the simple solution, verification is a long process. It took much longer than I expected and I needed to stay very involved to see through to the resolution here. I am sharing this timeline so that it may be helpful for other security analysts. Your takeaways should be that A) Apple does follow on their promise to take your report seriously B) Apple does provide credit, it’s not money like other vendors, but hey take what you can get C) be persistent.

Here is the credit citation:

2017-05-31 store.apple.com

A server configuration issue was addressed. We would like to acknowledge William Entriken (@fulldecent) of phor.net for reporting this issue.

https://support.apple.com/en-us/HT201536

Comments

There are no comments yet.

Please discuss this topic anywhere and let me know any great comments or media coverage I should link here.