Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Security Flaw Puts iPhone Users at Risk of Phishing Attacks

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU
 
jayfish Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Feb-04-10 04:54 PM
Original message
Security Flaw Puts iPhone Users at Risk of Phishing Attacks
Source: Ars Technica

Ars spoke with a mobile security expert who discovered the problem (who asked to remain anonymous because he did not have approval to talk about the issue). He told Ars that the issue is one of trust: "Who would you trust to change your iPhone configuration over the air? Your carrier? Your company? Your IT security admin?" he asked. Apple uses SCEP as a way for the iPhone to check in with a certificate server to verify that a mobileconfig file has been signed by a trusted source, but flaws in the set-up on the iPhone mean that the process doesn't always work as intended.

The problem stems from Apple's implementation of SCEP, which is a protocol to manage public key infrastructure for closed systems. For instance, SCEP can be used to manage security certificates and policies for iPhones deployed by an enterprise IT department. Unfortunately, the iPhone uses Safari's list of certificate authorities instead of a much more narrowly defined set for authorizing OTA mobileconfig files. Furthermore, it only requires that certificates used to sign mobileconfig files be signature only, instead of a more secure type of certificate that specifies how it can be used.

Read more: http://arstechnica.com/apple/news/2010/02/security-flaw-puts-iphone-users-at-risk-of-phishing-attacks.ars



What? Apple fall down on security? It can't be.

Jay
Printer Friendly | Permalink |  | Top
Cronus Protagonist Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Feb-04-10 04:56 PM
Response to Original message
1. they should buy a mac
...wait!!
Printer Friendly | Permalink |  | Top
 
liberal N proud Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Feb-04-10 04:58 PM
Response to Original message
2. If it is a problem with the iPhone
Is the problem exponentially larger with the larger iPad?

:rofl:
Printer Friendly | Permalink |  | Top
 
WriteDown Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Feb-04-10 04:58 PM
Response to Original message
3. These problems are fixed in the new Max cPad . Buy one today. nt
Printer Friendly | Permalink |  | Top
 
onehandle Donating Member (1000+ posts) Send PM | Profile | Ignore Thu Feb-04-10 05:00 PM
Response to Original message
4. You would have to be stupid and go out of your way to fall victim to this 'flaw.'
Same with other operating systems.

Yawn.

Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Wed Apr 24th 2024, 07:37 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (1/22-2007 thru 12/14/2010) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC