All Things Digital

Skip to main content.

Digital Daily

iPhone to Support Third-Party Security Exploit Applications

header.jpgHere’s an unintended, but perhaps inevitable, corollary to the iPhone’s success: the proof-of-concept security exploit. Researchers at Independent Security Evaluators have discovered a vulnerability that could give an attacker unfettered access to an iPhone, with administrator privileges, and they have written a bit of code to demonstrate it. “In our proof of concept, this code reads the log of SMS messages, the address book, the call history and the voice-mail data,” the ISE team explains. “However, this code could be replaced with code that does anything that the iPhone can do. It could send the user’s mail passwords to the attacker, send text messages that sign the user up for pay services, or record audio that could be relayed to the attacker.”

The vulnerability, which can be exploited by an attacker-controlled WiFi point or Web page, hasn’t yet been reported in the wild. And Apple’s working on a fix for it. That said, we’re certain to see others in the months ahead now that the iPhone has been proved vulnerable.

“Anything as complex as a computer–which is what this phone is–is going to have vulnerabilities,” Johns Hopkins professor Avi Rubin told the New York Times. “The irony is that the more popular something is, the more insecure it becomes, because popularity paints a large target on its back.”

Added Steven M. Bellovin, a professor of computer science at Columbia University, “It’s not the end of the world; it’s not the end of the iPhone. It is a sign that you cannot let down your guard. It is a sign that we need to build software and systems better.”

Comments

  1. GoTrusted just launched a new iPhone Security Service that encrypts your internet communications over WiFi networks. The best part is, it’s FREE!

    http://www.gotrusted.com

    Posted by John Volheizen at August 2nd, 2007 at 10:28 am

Add a Comment

You must be logged in to post a comment. Sign up here or log in below.

Comments posted on this site must be signed with your full, real name. Please see our Comments policy for details.

Latest Digital Daily Videos

More Videos »

About John

John Paczkowski has been poking fun at the tech industry and the personalities that drive it since 1997. From 1999 to 2007, he wrote the award-winning tech news Web log Good Morning Silicon Valley for the San Jose Mercury News, Silicon Valley's daily newspaper.

Read more »

Ethics Statement

Here is a statement of my ethics and coverage policies. It is more than most of you want to know, but, in the age of suspicion of the media, I am laying it all out.

Read more »

alt.misc

Older at alt.misc »