apple news/media reports

08/03/2007, 8:00pm, EDT

Friday, August 3rd

iPhone security slammed at Black Hat

Charles Miller, who first discovered an iPhone vulnerability that was patched by Apple in the iPhone 1.0.1 update, slammed the iPhone's general platform security during a presentation at the Black Hat conference in Las Vegas this week. Saying that his hack was not an isolated incident, Miller labeled Apple's security practices as poor, claiming that they have left the entire OS X platform (both the Mac and the iPhone) vulnerable.

A report in ChannelWeb quotes Miller: "Before they released the patch, I couldn't really say that much because I didn't want to give anyone enough to replicate the exploit. It was really frustrating, because a lot of people leapt to Apple's defense without really knowing the details. Everyone said, 'Oh, everyone gets bugs,' and 'Apple's good on security,' and 'They're better than Microsoft.' When you look at the details of this bug, though, the reality is that Apple's been negligent, I think."

He said that the most problematic Apple practice, from a security standpoint, is the regular inclusion in the OS X platform of older, outdated versions of open source code. Hackers can look at what flaws have been patched in newer releases, then write exploits based on the pre-existing vulnerabilities. Other security experts defended Apple's track record, however, noting that the company has patched serious flaws in a matter of days where Microsoft took several weeks for similar vulnerabilities.

Specifically, the vulnerability reported by Miller was one where viewing a maliciously crafted web page may lead to arbitrary code execution. Apple's description of the flaw is as follows: "Heap buffer overflows exist in the Perl Compatible Regular Expressions (PCRE) library used by the JavaScript engine in Safari. By enticing a user to visit a maliciously crafted web page, an attacker may trigger the issue, which may lead to arbitrary code execution. This update addresses the issue by performing additional validation of JavaScript regular expressions."

Via the exploit, attackers could gain access to the iPhone in one of three ways: any iPhone that automatically connects to an attacker-controlled wireless access point with the same name and encryption type as a trusted network would be compromised; an improperly configured forum on any website could allow insertion of the exploit; and iPhone users opening a link delivered via email or an SMS message could unknowingly open a hostile website.

Apple was under pressure to fix the security problem with the iPhone in a matter of days before briefings begin at the Black Hat 2007 conference


Filed under: Apple

, , 22comments, del.icio.us, slashdot, digg, buzz


22 comments
Reader Reactions (Please use <i></i> for italic text)

subscribe to comments
for this article




Expand All   Global Settings
CM can suckit!
0
08/03, 8:22pm, EDT
Somebody just wants their name in the news...
Fresh-Faced Recruit
Joined Apr 2005
User is offline
Uhh, yeah right
0
08/03, 8:25pm, EDT
Yeah, OS X has terrible security, which explains why in the 6 years I've been running it, I've never had a virus, I've never been exploited, I've never had arbitrary code executed, never had my credentials stolen, and never had antivirus program running. You call me a naive but until some can actually wreck the platform, than I don't have sh!t to worry about, do I? I get so tired of hearing about the lack of security of OS X when it's the most secure environment. Why? THERE ARE NO THREATS!!!! If it's so bad, put something out in the wild and prove it. My windows machine is under constant attack, bots, spyware, and whatever the hell else is out there.
Fresh-Faced Recruit
Joined Nov 1999
User is offline
RE: uhh, yeah right
0
08/03, 8:46pm, EDT
amen loert, amen.
Fresh-Faced Recruit
Joined Dec 2004
User is offline
The list of if's..
0
08/03, 8:57pm, EDT
..in this exploit are long. While it may be possible, what is the motivation to go through all this to control an iphone temporarily? Just because I could buy a new Ferrari and crash it into a brick wall - does not mean I will, what is the motivation? Sitting in Starbbucks trying to create a botnet out of one or two iphones is an idiotic idea.
Fresh-Faced Recruit
Joined Jul 2004
User is offline
OS X is so bad
0
08/03, 9:46pm, EDT
at security that I have yet to catch a bug. That OS X may have vulnerabilities I don't deny. I'm sure it does. But the over dramatic characterization is simply mind boggling, and is, frankly, getting old. When something is let loose in the wild, I'll pay these media whores some creedence. Until then, keep your yap shut.
Fresh-Faced Recruit
Joined Mar 2006
User is offline
macnn slammed on macnn
0
08/03, 10:30pm, EDT
...yet gain a total dog of a story biting the hand that feeds! Should read Apple promptly plugs potential threat to one month old new technology platform!
Forum Regular
Joined Oct 1999
User is offline
the headline is retarded
0
08/04, 12:00am, EDT
i read that headline and was expecting some big panel discussion or ANYTHING involving the conference. Instead its just one man's opinion, albeit a hacker at black hat, but i mean that is some seriously sensationalizing there.

I know all these sites are fighting for page views, but shouldnt you earn then my having quality legitimate stories over a long period of time, instead of trying to grab page views with bullshit like this
Fresh-Faced Recruit
Joined Apr 2007
User is offline
heh
0
08/04, 1:19am, EDT
Look, I don't want to be alarmist, but please put this into context.

1) " what is the motivation to go through all this to control an iphone temporarily?" Same as it would be for zombie nets. Your phone is a computer with a web browser. It can be directed to automatically open an ad site, it can be directed to go to a page that looks like AT&T asking you to enter your credit card info for revalidation, it can be directed to send every email address in your contact list to a spammer's database, or it can just be crashed beyond repair because some kid hates iphones.

2) "Until then, keep your yap shut" - speak fer yourself, bub. I'd rather know about potential issues on a mission-critical piece of kit like my iPhone *before* they become an issue. MacNN could have been more levelheaded and responsible about the posting, but this is MacNN and not some responsible news site.

3) "Instead its just one man's opinion" - You're right that it's only one man's opinion, but it's the opinion of a responsible security analyst with a doctorate who found a hugely serious issue on the iPhone and who by the way used to work for the NSA. I think if you don't take what he says seriously with his credentials, then you're just dangerously close-minded about Apple security and therefore irrelevant to any worthwhile discussion about security.
Mac Enthusiast
Joined Sep 1999
User is offline
heh heh
0
08/04, 1:44am, EDT
NSA? Is that them people who found out about those guys that took over the airliners with intent to meet their 70 virgins each? Or maybe they didn't find those guys out.
Fresh-Faced Recruit
Joined Nov 2001
User is offline
Tired of this shit...
0
08/04, 3:20am, EDT
Does this guy have nothing better to do than slam an OS just because it's made by Apple? If you ask me, he is just shooting his lame ass mouth off because he is a Microsoft crony. I have nothing against Microsoft... I use their software when deemed fit, but if you are going to bad mouth an OS, how about choosing your own?! I can't tell you how many flaws are in VISTA!
Fresh-Faced Recruit
Joined Dec 2001
User is offline
additional comments:..1..2..3..Next
Your Comments

In order to post comments: If you are a registered member, please login with your MacNN Forums username and password otherwise please uncheck the checkbox below.


Registered Member?
macnn forums login:

macnn forums password:

Not a member of the MacNN forums? Register now for free.

RSS Feeds

Have the latest content delivered to your desktop via RSS. Use the links below to get access to a specific blog, news, or reviews feed.



  MacNN -all

  MacNN Reviews

  MacNN Podcasts

  iPodNN

  Electronista

  Left Lane News

Check Out the VIERA from Panasonic!: Enter a New Visual Era with Panasonic VIERA HDTVs. An Enhanced Experience.

Get an IT Degree Online: Get solid credentials. Take your hobby to the next level. Adult Programs. Affordable.

Join The MyView IT Research Panel: Members will receive opportunities to take part in surveys from today's leading businesses.

Check Out the VIERA from Panasonic!: Enter a New Visual Era with Panasonic VIERA HDTVs. An Enhanced Experience.

Join The MyView IT Research Panel: Members will receive opportunities to take part in surveys from today's leading businesses.

Buy from The Apple Store, iTunes.com, Amazon.com, TechDepot, OfficeDepot, Computers4Sure, or donate.