Blog

Macs Can Be Hacked With Synthetic Dismissal On Warning Boxes

Aug 24, 2018 | Blog

Depending on the lens you view him through, Patrick Wardle (former hacker for the NSA and macOS security expert) is either your best friend or your worst nightmare.

Most people (whether fans of Apple or not) will readily concede that the company works hard to make their products as secure as possible.  Unfortunately, at this year’s Def Con hacker convention in Las Vegas, Wardle made a presentation that is currently sending shockwaves through the Apple user community. He exposed a major security flaw in the company’s products that impacts many of their secondary defensive measures.

Normally, when an Apple device detects an action that is potentially malicious, Apple’s OS will block it, then display an alert box to let the user know.

Unfortunately, as Wardle demonstrated, it is a trivial task for a hacker to generate a “synthetic click” to dismiss the warning box. This could be done in the blink of an eye, or with only slightly more effort, and be made utterly invisible to the end-user.

As Wardle puts it, “The ability to synthetically interact with a myriad of security prompts allows you to perform a lot of malicious actions.  Many of Apple’s privacy and security-in-depth protections can be trivially bypassed.”

This is hardly a new trick.  Over the years, several malware strains have used synthetic clicks to dismiss warning boxes, so Apple is certainly no stranger to the strategy.  In response, they have given their OS some ability to detect and ignore synthetic clicks, but as Wardle demonstrated, it’s far from perfect and even a fully updated High Sierra system was not completely protected.

Wardle concluded his presentation with the following: “I wasn’t trying to find a bypass, but I uncovered a way to fully break a foundational security mechanism.  If a security mechanism falls over so easily, did they not test this?  I’m almost embarrassed to talk about it.”

Apple has not yet responded to Wardle’s presentation.

FBI Program Tasked with Infrastructure Security Compromised

FBI Program Tasked with Infrastructure Security Compromised

The FBI program tasked with ensuring critical infrastructure security has been compromised by hackers, who now offer access to the program's data on the dark web. The breach was initially disclosed by Brian Krebs of Krebs on Security, who claims that the data was for...

Streamline Your Business with the Latest Smart Home Technology

Streamline Your Business with the Latest Smart Home Technology

Are you a business owner looking to get the most out of your Google smart home devices? If so, you're in luck! Google has enabled its Nest products and Android OS with the initial rollout of the Matter smart home standard. This means that businesses now have the...

Data Breach at Sequoia One Exposes Sensitive Customer Information

Data Breach at Sequoia One Exposes Sensitive Customer Information

What do you do when your most personal information has been compromised? This is likely the question that customers of Sequoia One asked themselves earlier this month as they were informed that the company had been hacked. Sequoia One specializes in the management of...

Cisco Reports Critical IP Phone Vulnerability

Cisco Reports Critical IP Phone Vulnerability

As a business owner, it's important to stay informed about potential vulnerabilities that could impact your organization. Recently, Cisco reported a critical vulnerability, tracked as CVE-2022-20968, affecting its IP Phone 7800 and 8800 Series. This new vulnerability...

Google Chrome Releases Two New Features

Google Chrome Releases Two New Features

Google Chrome is one of the more commonly used web browsers. Over the years, though, Chrome has gained a reputation for utilizing a large portion of a computer's memory. This can be a problem if you're running other resource-intensive tasks and don't want to slow...

Get a Free Consultation

 

Fill out the form below to receive a free consultation and learn how we can make your technology worry-free!

 

Contact Information

  • 39301 Badger Street, Suite 500
    Palm Desert, CA 9221
  • (760) 333-8523
  • info@icn.tech