Firms warn staff of iPhone, iPad hacking
February 11th, 2011 - 4:34 pm ICT by IANSSydney, Feb 11 (IANS) Companies that let staff use iPhones and iPads for business have been warned that hackers could steal passwords from the device in just six minutes even if its lock is enabled.The hack, which could seriously compromise a corporation’s critical infrastructure, was uncovered by experts in Germany and allows attackers to break into a lost or stolen phone simply by removing its SIM card and following a brief procedure, the Sydney Morning Herald reported Friday.
Experts at Germany’s state-sponsored research institute Fraunhofer SIT said in a statement: “Within six minutes the institute’s staff were able to render void the iPhone’s encryption and decipher the passwords stored on it.
“If the iPhone is used for business purposes then the company’s network security may be at risk as well. Only companies prepared for such an attack will be able to reduce their risk.”
The attack targets Apple’s password management system, known as a “keychain”, which scrambles all passwords and login information on the iPhone.
It can compromise iPhones and iPads with the latest software version installed even if they have the software “screen lock” turned on.
Once an attacker has access to the phone, the first step is to install “jailbreaking” software, which a small number of iPhone owners do voluntarily so they can download apps unauthorised by Apple.
From here, the attacker downloads a programme on to the phone that is able to decrypt passwords held on it, most notably for Google Mail accounts and for private company networks.
“As soon as attackers are in the possession of an iPhone or iPad and have removed the device’s SIM card, they can get hold of email passwords and access codes to corporate VPNs (virtual private networks) and WLANs (wireless local area networks) as well,” the researchers said in a statement.
“Control of an email account allows the attacker to acquire even more additional passwords: for many web services, such as social networks, the attacker only has to request a password reset.”
Jens Heider, the technical manager of the Fraunhofer SIT security test lab, said many companies have a false belief that the high-security phones lent to employees are impenetrable to such attacks.
“This opinion we encountered even in companies’ security departments,” Heider said. “Our demonstration proves that this is a false assumption. We were able to crack devices with high-security settings within a very short time.”
Graham Cluley, a security expert at Sophos, said the vulnerability could turn serious if hackers choose to put the attack method in the public domain.
“Others may well try to do this and publish the tools to do it, so it is quite serious,” he said.
In its latest earnings call last month, Apple said that a large number of Fortune 500 and FTSE 100 companies were “testing or deploying” the iPhone and iPad.
Cluley said companies using Apple’s popular smartphone need to put pressure on the technology firm to fix the issue as soon as possible.
“This is embarrassing for Apple, because they want people to believe they have a trusted enterprise device. What’s important is how quickly they can patch this,” the newspaper said citing Cluley.
- Chinese downloads 25 billionth app - Mar 06, 2012
- Apple releases preview of new Mac operating system - Feb 17, 2012
- Experts warn against iPhone security flaw - Aug 05, 2010
- Limera1n Jailbreak Is Now Out! - Oct 10, 2010
- China's iPad users get free TV broadcast - Oct 25, 2010
- Facebook Used By 100 Million Apple Users! - Aug 24, 2010
- Mexican-made game world's most downloaded iPad app - Aug 26, 2011
- Apple Gets Trademark For 'There's An App For That' Catchphrase - Oct 12, 2010
- iPhone 5 release date rumors abound - Apr 21, 2011
- Apple's iPhone 4S sales top four mn in three days - Oct 18, 2011
- Apple's app store crosses 15 billion downloads - Jul 08, 2011
- Samsung unveils Galaxy to challenge Apple's iPad - Sep 03, 2010
- Greenpois0n RC5 Goes Out To Web, Users Excited - Feb 04, 2011
- Apple gets setback in patent war - Dec 10, 2011
- Jobs turns loser Apple into a big winner - Oct 06, 2011
Tags: access codes, company networks, critical infrastructure, email passwords, google, ipads, iphone, iphones, latest software, local area networks, mail accounts, password management, sim card, six minutes, software screen, sponsored research, sydney morning herald, virtual private networks, wireless local area networks, wlans