Researchers find vulnerability in Apple's MDM DEP process
Security
Security researchers from Duo Labs have found a vulnerability in an Apple-specific mechanism used to control devices as part of closed enterprise networks.
The mechanism is quite widespread and is known as Mobile Device Management (MDM). It is used by small to large companies to enroll Apple devices under one management server from where system administrators can deliver common certificates, applications, WiFi passwords, VPN configurations, and so on --all specific to that company's network.
In a research paper published today and shared with ZDNet in advance, the Duo Labs team has revealed a vulnerability in DEP, or the Device Enrollment Program, the protocol through which new Apple devices are added to an MDM server.
More specifically, Duo Labs researchers say that the "device authentication" process of the DEP scheme can be exploited by an attacker --step #4 in the image below.
Duo researchers say that flaws in the way DEP was designed allow an attacker to trick the authentication step and enroll a device of the attacker's choosing in an organization's MDM server.
Furthermore, researchers also say the DEP pre-enrollment authentication process can also be abused to leak information about the organization that owns a specific device, information that can be abused for planning future attacks.
Also: The best way to buy a new iPhone, Galaxy, OnePlus phone right now
These remediation steps are described in a 32-page report released today. They include the use of cryptographic signatures generated by modern chips embedded in Apple's latest devices, adding a rate-limit to DEP API requests to prevent mass device data harvesting, or the use of modern authentication support via SAML or Auth 2.0 as part of the DEP enrollment process.
"Regardless of the authentication weaknesses in the current implementation of Apple's Device Enrollment Program, there's no question that it still provides value for organizations with large fleets of Apple devices," researchers said, also suggesting the issue they found could be mitigated via various security best practices applied to internal networks and user devices.
Duo said it notified Apple of the MDM DEP vulnerability in May this year. Apple has not deployed any countermeasures as of yet. Researchers will be presenting their findings tomorrow, September 28, at the ekoparty security conference, held in Buenos Aires, Argentina.
iPhone XS: Here's what it needed, and what we got
Previous and related coverage:
What is malware? Everything you need to know
Cyber attacks and malware are one of the biggest threats on the internet. Learn about the different types of malware - and how to avoid falling victim to attacks.
Security 101: Here's how to keep your data private, step by step
This simple advice will help to protect you against hackers and government surveillance.
VPN services 2018: The ultimate guide to protecting your data on the internet
Whether you're in the office or on the road, a VPN is still one of the best ways to protect yourself on the big, bad internet.
FBI solves mystery surrounding 15-year-old Fruitfly Mac malware
Fruitfly malware author used port scanning with weak or no passwords to identify potential victims.
Meet Torii, a new IoT botnet far more sophisticated than Mirai variants
The evolving IoT botnet is able to compromise an impressive array of architectures.
Teenage Apple hacker avoids jail for 'hacky hack hack' attack
The self-proclaimed Apple fan stole roughly 90GB of confidential data from the iPad and iPhone maker.
Related stories:
- Mozilla releases Firefox Reality, its web browser for VR
- Tor Browser gets a redesign, switches to new Firefox Quantum engine
- Firefox 62 appears as Mozilla ends support for Windows XP
- Mozilla to block ad trackers on Firefox by default
- California governor signs country's first IoT security law CNET
- Cheat sheet: How to become a cybersecurity pro TechRepublic
- iPhone XS, XS Max, and XR tech specs
- Apple's iPhone XS Max price tops out at $1,449 -- and 8 other keynote takeaways
- One less thing: No new Macs
- iPhone XR? What kind of name is that?
- Apple iPhone XS event: By the numbers
- Apple details new immersive AR experiences coming in ARKit 2
- Apple announces iOS 12 will be available September 17
- iPhone XS: I'm definitely buying Apple's new phone and here's why
- iPhone XS: Here's the one reason I won't buy Apple's new phone
- Apple Watch Series 4 launches, doubles down on digital health and wellness