iPhone as (In)secure as Windows95Best Security Tips offers daily news, information, advices and tips about spyware, adware, viruses, trojans, web vulnerabilities, hackers, other threats    | Register now | Login
   
HOME TIPS NEWS TOOLS DOWNLOADS VIRUS & SPYWARE FORUM BOOKS FREE MAGAZINES & PAPERS
GFI LANguard Network Security Scanner - Dld 30-day trial! del.icio.us  digg  Furl  NewsVine  Spurl  Blinklist  Ma.gnolia  Reddit  Tailrank  YahooMyWeb 
Best Tips
Security Scanner
Security Categories
Advertise With Us!
Latest Viruses / Threats
2008/7/3 19:55:40
2008/7/3 19:55:40
2008/7/3 19:55:40
2008/7/3 19:55:40
2008/7/3 19:55:40
Downloads
RSS / Atom Feeds
Web Security : iPhone as (In)secure as Windows95
Posted by Max on 2007/11/4 10:29:10 (467 reads)
Web Security

It wasn't long after Apple released the iPhone in June that researchers discovered that every application on the device -- from the calculator on up -- runs as "root," i.e., with full system privileges. As a result, a serious vulnerability in any of these applications would allow hackers to gain complete control of the device.


With the limited bandwidth of the iPhone, malicious code would be unlikely to slow portions of the internet. But malware could wreak creative havoc of a different kind. It might, for example, cause a phone to call numbers without the user's knowledge, seize text messages and a list of received and sent calls, turn the phone into a listening device, track the user's location through nearby WiFi access points, or instruct the phone to snap photos of the user's surroundings -- including any companions who may be in view of the camera lens.

Microsoft has been roundly criticized for years for releasing early versions of its Windows operating system with administrative privileges automatically enabled. This gave hackers who gained access to Windows machines complete privileges to modify the operating system and take control of the machine.

It took a while for the company to get the message, but Redmond finally closed the hole with its Vista operating system this year, which included a User Account Control feature to control the level of privileges required for various functions on a Vista machine.

" I guess Apple hadn't learned those lessons and is now going to learn them the hard way," says Geer,vice president and chief scientist at security firm Verdasys.

Charlie Miller,principal security analyst for Independent Security Evaluators says that Apple will need to redesign the entire firmware to fix the problem -- which would require owners to install a pretty hefty update.

"If you start from the beginning with security in mind and you design your product thinking about security as you go, it's not really any harder to design a secure product than an insecure product," he says. "Once you've already got it out in everyone's hands, it's a little harder to go back and add security. And that's really what they need to do at this point."




Other articles
2008/7/3 16:38:16 - Major Security Hole in Citibank ATMs
2008/7/2 8:23:19 - Panda Security Launches Beta of Panda Internet Security 2009
2008/6/30 18:47:39 - Endpoint Productivity Gets A Boost With Anti-Executable 3.0
2008/6/30 18:41:27 - NAMESAFE Sues LifeLock for Attempt to Steal NAMESAFE Corporate Identity
2008/6/26 9:48:12 - Phishing targeting Facebook, companies warned

The comments are owned by the poster. We aren't responsible for their content.