Slashdot Mirror


Safari Privacy Bug May Be Leaking Your Data

richi writes "If you use Safari, your browser may be leaking your private information to any website you visit. Jeremiah Grossman, the CTO of WhiteHat Security, has discovered some Very Bad News. I have some analysis and other reactions over at my Computerworld blog. The potential for spam and phishing is huge. A determined attacker might even be able to steal previously-entered customer data." In short, autofill for Web forms is enabled by default in Safari 4 / 5 (and remotely exploitable), and the data that this feature has access to includes the user's local address book — even if the information has never been entered into a Web form.

4 of 152 comments (clear)

  1. I know all about you if you're a Safari user. by Anonymous Coward · · Score: -1, Troll

    When a Safari user comes to my site, I automatically know:

    1) They make poor purchasing decisions. They'll waste many thousands of dollars on hardware that's four or five years out of date, but sports the "correct" logo.
    2) They are homosexuals, or have strong homosexual tendencies. They are Apple users, after all.
    3) They don't have a real job, but rather a sugardaddy or a trust fund.
    4) They like fancy coffee blends.
    5) They're likely hipsters (or rarely, an old fat neckbeard who's trying to relive his NeXT glory days).

    1. Re:I know all about you if you're a Safari user. by Anonymous Coward · · Score: -1, Troll

      When a Linux user comes to my site, I automatically know:

      1) They have no money because their mom cut back their allowance.
      2) Their sexual orientation is indeterminate because they never had nor will ever have sex.
      3) They don't have a job.
      4) They don't like anything including themselves.
      5) They are loser and likely smell bad.

    2. Re:I know all about you if you're a Safari user. by pandrijeczko · · Score: -1, Troll

      In response:

      1) Please refer to my response in 3) for full details as to why I have no need of an allowance from my mother. However, since I am not compelled to queue outside of electronics stores overnight on a twice-yearly basis in order to buy little white boxes with pictures of fruit on them, I do not spend the money I have on said boxes, thermal underwear (if queuing outside during the Winter period), or overpriced mocha-frappa-choca-rama-langa-ding-dong-chinos while posing with said white boxes in fashionable coffee houses.

      2) Hmmm, interesting. I will have to ask my wife of 17 years if she is sexually frustrated through lack of attention from me.

      3) Hmmm, interesting. I will have to ask my boss why he has been approving my project time bookings for the past five years which causes money that I never use to buy little white boxes with pictures of fruit on them (see 1) above) to mysteriously appear in my bank account at the end of every month.

      4) The lack of a compulsion to buy little white boxes with pictures of fruit on them (see 1) above) stems from not having a requirement that everything I possess looks like a fashion accessory. From this it might be construed that not having a need to hide a personality disorder behind a corporate logo means that I probably do not have a personality disorder in the first place - in other words, I am a happy, well-adjusted Linux-using individual.

      5) You are clearly telepathic, well done. Not only was I a temporary "loser" of my car keys today for about 20 minutes (until I found them in my trouser pocket in the washing basket) but I also have a particularly nasty cold at the moment which impairs the functionality my olefactory senses currently - indeed, my smelling capability is really bad at the moment. You really must tell me how you managed to work this out - was it with the assistance of an app from the store of the manufacturer of the little white boxes with pictures of fruit on them? (See 1) above.)

      --
      Gentoo Linux - another day, another USE flag.
  2. Not a bug... by AnonGCB · · Score: -1, Troll

    It's not a bug, it's a feature!

    --
    http://CryoLANparty.com/ A lan I'm staff on!