toggle

AAPL Stock: 501.18 ( + 7.76 )

Sec. expert: Apple's iPhone security claims 'exaggerated'

updated 11:55 am EST, Fri February 5, 2010

Decries iPhone sandboxing


The iPhone is not as secure as Apple would like people to believe, claims a software engineer and security specialist, Nicolas Seriot. Speaking at this week's Black Hat Conference in Arlington, Virginia, Seriot commented that while the iPhone OS theoretically sandboxes apps in order to restrict data access, the rules in place are "way too loose." Apple should not be claiming that one app cannot access data from another, he emphasized.

Proof of the vulnerability is said to lie with several apps, such as Aurora Feint and mogoRoad, which were initially approved by Apple yet quietly stole phone and e-mail contacts before eventually being blocked from the App Store. Apple's review process can and does miss security problems, Seriot pointed out, and vulnerabilities may only get worse given the increasing appeal of the iPhone as a target for hackers and criminals. Devices can become still more exposed when jailbroken.

A demonstration app created by Seriot, SpyPhone, is said to reveal e-mail addresses, user accounts, Safari and YouTube searches and server information, although not the password. When an iPhone connects to Wi-Fi the app can also learn which networks a device connects to, a person's phone number, and the last call made. Most severe may be location info, which can be pulled from the cache of Maps.

The best solution is claimed to be a firewall, which would notify people whenever potentially dangerous app actions are occurring.


by MacNN Staff

toggle

Comments

  1. Gazoobee

    Fresh-Faced Recruit

    Joined: Feb 2009

    +20

    pop-overs and ads

    Please stop with the pop-over inks and especially the pop-over ads. It's just a disgusting, invasive practice. This site is better than that (or it always used to be).

  1. lkrupp

    Fresh-Faced Recruit

    Joined: May 2001

    +1

    The only thing we have to fear is...

    If we took these bozo's words for it we would all be hiding under our beds cowering in fear.

  1. Geoduck

    Fresh-Faced Recruit

    Joined: Jan 2010

    +3

    I keep thinking...

    that there have been claims of this kind at BlackHat for a decade. Technically they may be true. For me the proof is in the malware attacks on Macs (or the lack thereof).

  1. rexray

    Fresh-Faced Recruit

    Joined: Jul 2002

    +5

    He's trying to make a name

    If all this guy has is that a vulnerable app MAY get through the App Store, or you have to be jailbroken, then he doesn't really have anything significant to say. He's just trying to draw attention to himself (at which he has succeeded).

  1. slapppy

    Fresh-Faced Recruit

    Joined: Mar 2008

    +3

    Windows

    He's right. Just use Windows for everything. Thats the best alternative ever!

  1. godrifle

    Fresh-Faced Recruit

    Joined: Jan 2006

    +3

    What product is...

    ...as secure as its supplier wants us to believe? Hello.

  1. aristotles

    Grizzled Veteran

    Joined: Jul 2004

    +3

    This data is available through the API

    All of this data is available through the API and could have both legitimate and nefarious uses. Without an app approval process, there would be a lot of spyware on the iPhone. Just because missed a few cases, it does not invalidate the whole process or mean that this is a vulnerability.

Login Here

Not a member of the MacNN forums? Register now for free.

 
close
Photo
toggle

Network Headlines

toggle

Most Popular

10 Most Read

Recent Reviews

Logitech Cube

The world of mice could often be described charitably as stagnant: it's an endless sea of ergonomic shapes that assume you're sitting ...

NewerTech and Targus USB Hubs For Gifts

A useful holiday present to resolve an ongoing frustration is a multi-port hub. Whether as a stocking stuffer, Chanukah present, or an ...

X-Rite ColorMunki Photo

Color calibration is the art of tweaking your monitor so that the colors represented on screen better match real life and your printer ...

toggle

Most Commented

10 Most Discussed