Pages: [1]   Go Down
  Print  
Author Topic: Uber Removing Apple-Granted API That Could Have Let it Record a User’s iPhone Screen [Updated]  (Read 352 times)
HCK
Global Moderator
Hero Member
*****
Posts: 79425



« on: October 10, 2017, 04:05:09 pm »

Uber Removing Apple-Granted API That Could Have Let it Record a User’s iPhone Screen [Updated]

" width="250" height="250" class="alignright size-medium wp-image-590912When the Apple Watch was first released, Apple gave Uber what's known as an "entitlement" to run a special API to improve performance of the Uber app on the wrist worn device.





That entitlement made headlines today when security researchers told Gizmodo that Uber could have used it to record a user's iPhone screen even with the Uber app just running in the background.





In a statement, Uber said the entitlement was used for an old version of the Apple Watch app and was provided to Uber because the original Apple Watch couldn't render maps.
"It was used for an old version of the Apple Watch app, specifically to run the heavy lifting of rendering maps on your phone & then send the rendering to the Watch app," an Uber spokesperson told Gizmodo, saying that early Apple Watches couldn't handle this process alone. "This dependency was removed with previous improvements to Apple's OS & our app. Therefore, we're removing this API from our iOS codebase."
The entitlement is no longer necessary and Uber is planning to remove it from the iOS codebase, according to both the statement given to Gizmodo and a tweet from Uber head of security and privacy communications Melanie Ensign.





According to security researcher Will Strafach, who first brought attention to the issue, Apple does not often give out entitlements. Strafach said he could find no other apps on the App Store that have the permissions that the Uber app has.





<center><blockquote class="twitter-tweet" data-lang="en"><p lang="en" dir="ltr">API was used to render Uber maps on iphone &amp; send to Apple Watch before Watch apps could handle it. It's not in use &amp; being removed. Thx!</p>&mdash; Melanie Ensign (@iMeluny) October 5, 2017 <script async src="//platform.twitter.com/widgets.js" charset="utf-8"></script></center>Strafach says there is no evidence that Uber ever misused the entitlement, but it could have been utilized to monitor activity on an iPhone, recording passwords and other personal information. "Essentially it gives you full control over the framebuffer, which contains the colors of each pixel of your screen. So they can potentially draw or record the screen," another security researcher, Luca Todesco, told Gizmodo.





Uber says the app is no longer connected to anything in the company's current codebase, but users will likely be wary anyway as there have been other privacy concerns with the Uber app. There was a feature that allowed riders to be tracked for up to five minutes after a trip, and Apple CEO Tim Cook even went so far as to threaten to remove the app from the App Store after it was found to be secretly recording the UDID of iPhones to identify them even after the Uber app had been deleted.





Update: An Uber spokesperson said that an update released on Friday removed the API.

<div class="linkback">Tag: Uber</div>
Discuss this article in our forums

<div class="feedflare">
<img src="[url]http://feeds.feedburner.com/~ff/MacRumors-Front?d=yIl2AUoC8zA" border="0"></img>[/url] <img src="[url]http://feeds.feedburner.com/~ff/MacRumors-Front?d=6W8y8wAjSf4" border="0"></img>[/url] <img src="[url]http://feeds.feedburner.com/~ff/MacRumors-Front?d=qj6IDK7rITs" border="0"></img>[/url]
</div><img src="http://feeds.feedburner.com/~r/MacRumors-Front/~4/BN0EsXsvbrI" height="1" width="1" alt=""/>

Source: Uber Removing Apple-Granted API That Could Have Let it Record a User’s iPhone Screen [Updated]
Logged
Pages: [1]   Go Up
  Print  
 
Jump to: