Tuesday, October 30, 2007

Batten-Down the iHatches!

Earlier I posted an article relating to the difficult relationship between enterprise and the iPhone. Now as a follow up it is necessary to look into the security related issues regarding Apple’s venture into mobility.

Lately there have been a number of articles and sites dedicated to hacking the underlying operating system of the iPhone. Initial attempts were purely for benign reasons of curiosity and (not so benign) unlocking. Both of these feats have now been accomplished and have provided some unexpected results. It seems that Apple, in their rush to get the iPhone to market, neglected to lock down security at the OS level. Worse still, the operating system on the iPhone is not some proprietary device based system, but actually a more-or-less fully functional version of Apple’s OS X!

On the surface this seems fantastic! OS X embedded on a $300 device is an incredible deal! Problems arise however when it becomes apparent just how easy it is to hack these devices. The most evident exploit available presently is related to the fact that all applications on the iPhone are run as Root processes. Essentially this allows any application full access to the entire device immediately upon being exploited.

There are any number of articles around now related to the iPhone becoming a mobile hacking platform however this is not the real issue (any hacker worth his salt probably has at least one laptop anyway). The real problem for the consumer is the privacy of their information stored on the device. For instance, malicious code injected into a website accessed by the Safari browser could gain access to the core functionality of any iPhone. An experienced hacker could then gain access to confidential information such as phone logs and contacts.

From the point of view of a personal user this is bad enough. Thinking of it from an enterprise perspective, the lack of security becomes potentially disastrous! Imagine the CEO of a Fortune 500 company having his call logs, contacts and even private photographs on display for the entire world to see! With this exploit it may even be possible for a hacker to gain control of the camera, snapping photos at inopportune times with the CEO’s own device!

I have the honor of calling myself an Apple fan, user and even expert. I am constantly amazed by the wonders of industrial design created within their walls. That said, for the second article in a row, I have to conclude that although I love the idea of the iPhone, it does not belong in business; at least not until Apple decides to leverage the legendary UNIX security that the device already contains!

Mark

207 comments:

«Oldest   ‹Older   201 – 207 of 207
Anonymous said...

Have you ever considered about adding a little bit more than just
your articles? I mean, what you say is valuable and everything.

But just imagine if you added some great graphics or video clips
to give your posts more, "pop"! Your content is excellent but
with pics and videos, this site could definitely be one of the most beneficial
in its field. Fantastic blog!

Check out my homepage fake Rolex watches

Anonymous said...

hey there and thank you for your info – I've certainly picked up something new from right here. I did however expertise several technical issues using this website, since I experienced to reload the website many times previous to I could get it to load properly. I had been wondering if your hosting is OK? Not that I am complaining, but slow loading instances times will often affect your placement in google and can damage your high quality score if advertising and marketing with Adwords. Well I am adding this RSS to my email and could look out for a lot more of your respective fascinating content. Make sure you update this again soon.

Feel free to surf to my site :: Rolex watches

Anonymous said...

This blog was... how do I say it? Relevant!! Finally I've found something that helped me. Many thanks!

Look at my web blog :: Replica Rolex watches

Anonymous said...

Woah! I'm really loving the template/theme of this blog. It's simple, yet
effective. A lot of times it's very difficult to get that "perfect balance" between user friendliness and visual appeal. I must say you have done a great job with this. Also, the blog loads extremely quick for me on Safari. Superb Blog!

My site voyance

Anonymous said...

Nice post. I was checking constantly this blog and I am impressed!
Extremely useful information specifically the ultimate part
:) I care for such information a lot. I was seeking this particular
info for a very long time. Thank you and best of luck.



Here is my homepage ... cheap rolex watches

Anonymous said...

Excellent post. I definitely love this site. Keep writing!


My site :: cheap rolex watches

Anonymous said...

Hi Dear, are you actually visiting this web page daily,
if so after that you will absolutely obtain good know-how.


my weblog - Home Web Profits review\Home Web Profits reviews

«Oldest ‹Older   201 – 207 of 207   Newer› Newest»