Home
Reviews
Forums
New Games
Podcast
• submit tip •
  #1  
Old 11-28-2010, 10:16 AM
sticktron sticktron is offline
Senior Member
iPhone 4S, iOS 5.x
 
Join Date: Mar 2009
Location: Toronto
Posts: 1,052
Exclamation ** UH-OH! iOS Has Serious Security Flaws **

Source: http://seriot.ch/blog.php?article=20100203


I had no idea things were this bad. Developers with malicious intent can mine tons of personal data WITHOUT using private frameworks or having root access. That means Apps in the App Store can do it.

Context: in it's secretive review process* Apple is rejecting ~10% of submissions due to spyware or malicious intent. (*S5.4 – You may not make any public statements regarding this Agreement.) It's easy to see how out of the 10,000+ submissions they get each week that SOME bad apps are getting or will get through. It's a subjective process, the odds are against the reviewers, and so it's only a matter of time.


MAJOR PRIVACY VULNERABILITIES - *as of 02/2010
- your phone #
- unrestricted access to your address book
- phone and email account details (eg. your mail server and username; phone IMEI)
- Safari and YouTube search history
- keyboard cache (yes, everything you've typed in)
- where and when you took your photos (the hidden geo-tagging data)
- your current location via GPS (or cellular triangulation)
- your WiFi hotspot connection history
- and more...


As you can see, that is basically ALL of your MOST PRIVATE information. And to reiterate: it's all right there for any App in the App Store to see. And we haven't even touched on private frameworks or dangerous things we could do with root access. No. This is all above board, according to the SDK, from a technical standpoint. It's "against the rules" to violate laws with your App, so Apple has the power to unilaterally reject Apps for security violations. But someone has to catch the violation first, hence with the sheer number of apps, the odds are against Apple.


Example cases of violators who were caught too late to prevent damage

Aurora Feint - pulled in July 2008 for transmitting contact emails in clear text. Affected 20 million users. Allowed back in after revising their privacy policies. Today how many of us have Aurora's OpenFeint software on our devices?

Storm8 Software (iMobsters, etc.) - federal lawsuit filed in November 2009 for collecting the phone numbers of it's customers. Affects every Storm8 game; 20 million downloads. Games were not pulled.

MogoRoad - pulled in September 2009 for transmitting phone numbers in clear text. Customers got unsolicited commercial phone calls. Also allowed back in after revising their privacy policy.


There are 10s of millions of iPhones in use... the potential for the largest scale and most disturbing personal security attacks yet in computer history is right here, in our pockets.

I want to repeat one particularly frightening and futuristic attack scenario: using data collecting from your seeminglessly harmless Breakout clone App, you could identify wealthier customers (by their neighborhood, by the products they're searching for, etc.), monitor their current locations via GPS, and then when they go out of town, go to their house and clean them out. Talk about 21st century thievery. You've used Apple technology to identify ideal targets and perfect windows of opportunity.


IMPORTANT NOTES TO TAKE AWAY FROM THIS
1. Go into Settings on your iPhone and remove your phone number RIGHT NOW. Change it to 555-1234 or some other nonsense. Just don't have your real number there.
2. Clear your caches periodically. That means Safari and any other program that maintains a history of your actions.
3. Since only Apple has the ability to protect you from a dangerous app in sheep's clothing, you have to be extra diligent about what you install and who/where you get it from. We just don't know what the author really has in mind, and if something has slipped past review.

Last edited by sticktron; 11-29-2010 at 06:54 AM..
Reply With Quote
  #2  
Old 11-28-2010, 10:48 AM
acrotran acrotran is offline
Senior Member
iPad (3rd Gen)
 
Join Date: Jul 2010
Posts: 740
Default

"keyboard cache (yes, everything you've typed in)" - that doesn't make sense. How big could the keyboard cache be?
Reply With Quote
  #3  
Old 11-28-2010, 11:05 AM
acrotran acrotran is offline
Senior Member
iPad (3rd Gen)
 
Join Date: Jul 2010
Posts: 740
Default

"MAJOR PRIVACY VULNERABILITIES - *as of 02/2010"

As of 02/2010 - this is old news and probably inaccurate.

Your phone number isn't useful without your name, and even then they can't do much with it.

The only thing to be concerned about is if they can get your email username, and that's not exactly a secret.
Reply With Quote
  #4  
Old 11-28-2010, 11:27 AM
fallenashes fallenashes is offline
Senior Member
iPod Touch (3rd Gen), OS 3.x
 
Join Date: Jan 2010
Location: yes
Posts: 307
Default

Quote:
Originally Posted by acrotran View Post
"keyboard cache (yes, everything you've typed in)" - that doesn't make sense. How big could the keyboard cache be?
As big as your dirty habits
Reply With Quote
  #5  
Old 11-28-2010, 11:32 AM
Cilo Cilo is offline
Senior Member
iPhone 5, iOS 6.x
 
Join Date: Feb 2010
Location: Los Angeles
Posts: 1,659
Default

There goes my mobile porn . . .
Reply With Quote
  #6  
Old 11-28-2010, 12:41 PM
MidianGTX MidianGTX is offline
Senior Member
iPad (3rd Gen), iOS 5.x
 
Join Date: Jun 2009
Location: London, UK
Posts: 2,943
Default

The Aurora Feint one sounds like a genuine mistake or misjudgement. It says clear text, which suggests they're supposed to encrypt such things, but merely didn't think to... I'm guessing.
Reply With Quote
  #7  
Old 11-28-2010, 02:29 PM
sticktron sticktron is offline
Senior Member
iPhone 4S, iOS 5.x
 
Join Date: Mar 2009
Location: Toronto
Posts: 1,052
Default

It probably was but the point was that a simple slip up affects millions of users.

Also, this stuff is still much the same today. Its been that way since iOS 1.0.

And if you don't consider having your location tracked, your unlisted cell number being sold to telemarketers, your passwords being stolen, your address book being tampered with, or having a man-in-the-middle intercepting and recording all your web traffic pretty damn serious... I don't know what to say. What else IS there to safeguard?
Reply With Quote
  #8  
Old 11-28-2010, 03:01 PM
sticktron sticktron is offline
Senior Member
iPhone 4S, iOS 5.x
 
Join Date: Mar 2009
Location: Toronto
Posts: 1,052
Default

Quote:
Originally Posted by acrotran View Post
"keyboard cache (yes, everything you've typed in)" - that doesn't make sense. How big could the keyboard cache be?
There arent that many unique words, not enough to be a concern from a storage standpoint.

You retrieve an alphabetized list, eg. daughter donkey midget sex teen, and it doesn't take much imagination to figure out that person's secret perversions.
Reply With Quote
  #9  
Old 11-28-2010, 03:04 PM
sticktron sticktron is offline
Senior Member
iPhone 4S, iOS 5.x
 
Join Date: Mar 2009
Location: Toronto
Posts: 1,052
Default

Quote:
Originally Posted by acrotran View Post
Your phone number isn't useful without your name, and even then they can't do much with it.
You need to reread what I wrote. Not only is your name and number available, so is your address and gps location, your family and friends' names numbers and addresses too.
Reply With Quote
  #10  
Old 11-28-2010, 04:30 PM
eyemh8 eyemh8 is offline
Senior Member
iPhone 4, OS 4.x
 
Join Date: Oct 2008
Location: Estes Park co.
Posts: 451
Default

Doesn't every connected electronic device with this info on it have the same problem? I personally don't care if someone knows if I look at donkey porn who would be the real perv if they really do care. Phone# I still have the deny call button email well I think every scumbag already has that info. The real concerns are not on the list witch would be billing numbers and iTunes account passwords. This feels less risky than using my computer and I look at way more scary shit on that.
Reply With Quote

Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


iPhone Game Reviews | iPhone Apps

All times are GMT -5. The time now is 03:04 PM.