Security researcher Timo Longin, working with the SEC Consult Vulnerability Lab, disclosed two email spoofing flaws in Apple’s iCloud mail infrastructure that could have let someone with a free iCloud account send messages that appeared to come from any @icloud.com address. The crafted messages could pass SPF, DKIM, and DMARC checks, the core controls used by mail services to verify sender identity. Apple has since remediated both issues following a lengthy responsible disclosure process. The research shows that email authentication is only as reliable as the systems that prepare and process the email before it leaves a provider’s network. In this case, the issue was not a stolen iCloud account or a weakness in the...
Läs hela artikeln hos källan.
Kommentarer (0)
Inga kommentarer ännu. Bli först med att kommentera!