News >> Browse Articles >> Apple

News >> Browse Articles >> Gadgets

News >> Browse Articles >> Security

+2

Hacker Says iPhone is Insecure, "Useless" for Businesses

Hacker Says iPhone is Insecure, "Useless" for Businesses

Photo courtesy flickr user "Sroown" under a Creative Commons 2.0 attribution license.

Jason Mick/DailyTech

July 24, 2009

Jonathan Zdziarski, an iPhone developer and a hacker who teaches forensics courses on recovering data from iPhones, hasn’t been very impressed with the iPhone’s security — or lack thereof.  Mr. Zdziarski has indicated that iPhone OS v3.0 is a bit better when it comes to security, but he says with only a few pieces of readily available freeware you can easily crack it in under two minutes.  That news must be concerning for the corporations and government agencies that support the hundreds of thousands of business iPhones Apple says it has sold.

Mr. Zdziarski says the iPhone’s security woes are entirely unnecessary and are the result of incompetence.  He states, “It is kind of like storing all your secret messages right next to the secret decoder ring.  I don’t think any of us [developers] have ever seen encryption implemented so poorly before, which is why it’s hard to describe why it’s such a big threat to security.”

His statements stand in stark contrast with Apple Chief Operating Officer Tim Cook’s cheerful news that 20 percent of Fortune 100 companies have purchased 10,000 or more iPhones apiece and that multiple government organizations had purchased 25,000 iPhones apiece.  Mr. Cook had bragged, “We’re seeing growing interest with the release of iPhone 3.0 and the iPhone 3GS due in part to the new hardware encryption and improved security policies.  The phone is particularly doing well with small businesses and large organizations.”

Mr. Zdziarski says these entities might be in trouble as the encryption on the phone is so poorly implemented a simple software tool makes it as easy to view encrypted files as unencrypted ones.  Thieves could extract live encrypted data from the phone in a mere 2 minutes, and have an entire raw disk image in about 45 minutes.  Interestingly, the iPhone itself helps with these tasks – it begins to decrypt data on its own automatically after the extraction process has started.

Corporate users often edit finance spreadsheets and other corporate documents on their phone, as well as using the phone to make transactions with corporate credit cards.  All of this information is easy pickings for hackers thanks to the phone’s woeful security.  Mr. Zdziarski surmises, “If (companies are) relying on Apple’s security, then their application is going to be terribly insecure.  Apple may be technically correct that [the iPhone 3GS] has an encryption piece in it, but it’s entirely useless toward security.  We’re going to have to go with the old imperative of ‘Trust no one’.  And unfortunately part of that is, don’t trust Apple.”

Still, some companies say that the risks of deployments are worth it.  States Lance Kidd, chief information officer of Halton Company, an industrial equipment provider, which lets its employees use iPhones, “Your organization has to be culturally ready to accept a certain degree of risk.  I can say we’ve secured everything as tight as a button, but that won’t be true…. Our culture is such that our general manager is saying, ‘I’m willing to take the risk for the value of the applications.’  It’s like business continuity.  You prepare for disasters. You prepare for if there’s an earthquake and the building breaks down, and you prepare for if there’s a crack in [information] security.”

© 2009, DailyTech


Share |
+2
  • Photo_user_blank_big

    tkejlboom

    2 months ago

    8 comments

    Be aware, but be not afraid. Our military still thinks that custom ethernet connectors are suitable substitutes for user authentication. Hacking the military, interestingly enough, is morally and technically similar to taking candy from a baby.

  • Capt

    thehammer1

    7 months ago

    46 comments

    Just think, the blackberry sitting next to you while you sleep is brodcasting and recieving signals from somewhere. and if two kids from michigian hacked into the militairy mainframe. Be aware.

  • Electricity_stewie_max50

    cthenkhaus

    7 months ago

    102 comments

    “Your organization has to be culturally ready to accept a certain degree of risk. I can say we’ve secured everything as tight as a button, but that won’t be true…. Our culture is such that our general manager is saying, ‘I’m willing to take the risk for the value of the applications.’ It’s like business continuity. You prepare for disasters. You prepare for if there’s an earthquake and the building breaks down, and you prepare for if there’s a crack in [information] security.”

    Yeah risk comes with everything but to take unnecessary risks is just down right foolish, especially when it comes to owning a business. Why would you use something that you know has flaws in it? Flaws that could mean you losing a lot of revenue. No revenue no "business continuity". And yes you could make sure you have back up plans for not if but when your business iPhone gets hacked but for a business that means increased rates for contingency plans (insurance, credit cards, etc.). That's just another thing that digs into revenue.

  • Photo_user_blank_big

    blacksmithforlife

    7 months ago

    6 comments

    This just goes to show that Apple needs to start thinking more about security then about the "fashion" of the Iphone. If you are running a computer on a phone, you need to make it just as secure as a computer otherwise it is just a high tech piece of junk...

What's the Scoop?

Post a link to something interesting from another site, or submit your own original writing for the InsideTech community to read.

Report News Here

IT Career Advice

Sf-skyline-main_sq32

Top 25 Cities for Tech Jobs

Now more than ever, it’s important to get the best bang for your buck. And there’s no question about ...

Hotcareers-250_sq32

10 Recession-Proof IT Careers

Companies are cutting back spending, shrinking staff sizes, and making tough layoffs at a rate that most of us ...

50books_sq32

50 Books Every Geek Should Read

Ever find out one of your friends hasn't read "Neuromancer" or doesn't know what a Babelfish is or why ...

Recent Activity

Photo_user_blank_big
not2stupid gave a thumbs down to The Article "Gore: I Wish Global Warming Wasn't Real", 13 minutes ago.
2sbqxpt_max30
soloist010 gave a thumbs up to The Article "Former Studio Heads Sue Activision After Firing", 15 minutes ago.
2sbqxpt_max30
soloist010 posted in: "The Official "Funny Pictures" Thread", 17 minutes ago.