news-record.com

NEWS

Advertisement | Advertise with Us

Security holes discovered in iPhones, iPads

Friday, July 8, 2011
(Updated 4:24 pm)

SAN FRANCISCO (AP) — A new security hole has opened up in Apple Inc.'s iPhone, iPad and iPod Touch devices, raising alarms about the susceptibility of some of the world's hottest tech gadgets to hacker attacks.

Flaws in the software running those devices came to light after a German security agency warned that criminals could use them to steal confidential data off the devices. Apple, the world's largest technology company by market value, said Thursday that it is working on a fix that will be distributed in an upcoming software upgrade.

With the security hole, an attacker can get malicious software onto a device by tricking its owner into clicking an infected PDF file. Germany's Federal Office for Information Security called the flaws "critical weaknesses" in Apple's iOS operating system.

Internet-connected mobile devices are still subject to fewer attacks than personal computer, but they could eventually prove a juicy target for hackers because they are warehouses of confidential banking, e-mail, calendar, contact and other data.

Software vulnerabilities are discovered all the time. What makes the latest discovery alarming is that the weaknesses are already being actively exploited - albeit in a consensual way.

The latest concerns were prompted by the emergence of a new version of a program to allow Apple devices to run any software and circumvent the restrictions that Apple notoriously retains over software distributed through its online store. There are security risks of doing so, but many people find it liberating to install their own software.

Although this program is something people would seek out, the weaknesses that its authors discovered could easily be used for malice, security experts say.

There is an irony in the controversy: The site distributing the program offers a fix for the problem, but to get the fix, a user has to first install the program in question. So a user must defy Apple's restrictions to get the protection until Apple comes up with a fix of its own.

Charlie Miller, a prominent hacker of Apple products, said it likely took months to develop the program to break Apple's restrictions, but a criminal might need only a day or two to modify it for nefarious purposes.

Apple Inc. spokeswoman Bethan Lloyd said Thursday the company is "aware of this reported issue and developing a fix." She would not say when the update will be available.

One reason for gadget owners to take heart: Attacks on smartphones and other Internet gadgets are still relatively rare. One reason is PC-based attacks are still highly lucrative. Still, vulnerabilities such as the ones Apple is confronting show that consumers should take care of securing their mobile devices as they would their home computer.

"These things are computers - they're just small, portable computers that happen to have a phone tacked onto them," said Marc Fossi, manager of research and development for Symantec Security Response. "You've got to treat them more like a computer than a phone. You have to be aware of what's going on with these devices."

Comments

Confirmed myNR members may comment on this article. Memberships are free, and it only takes a few minutes to create your profile. Click "Submit Comment" to sign in or register for a new account. New members must validate their email addresses in order to comment.

House Rules

User comments can add a valuable and constructive dimension to community dialogue. We encourage respectful debate. But commenting is a privilege that will be revoked for violations of our Terms of Use. In addition, please follow these "House Rules" when commenting on news articles, letters or editorials.

  • Be relevant. Discuss the story or letter opened for comments. Stay on topic.
  • Be respectful. It’s fine to disagree but not to be disagreeable. Avoid abusive or offensive language. Threats, hate speech and libelous statements will be deleted. Name-calling, threats and insults are not welcome.
  • Be substantive. Facts add weight and credibility to your views.
  • Be honest. Don't make up facts or pretend to be someone else.
  • Be discreet. Don't publish telephone numbers, addresses or other personal information about yourself or others.
  • Respect copyrights. Don't publish material that belongs to someone else.
  • Inappropriate comments will be deleted. Users who repeatedly violate these rules will be banned from commenting on this website.
  • Commenters are solely responsible for what they post and can be held responsible for violations of the law. Please report comments that violate these rules by clicking on the "Report Abuse" link.

Inappropriate content? Please report abuse.

Submit Comment

NoiseNatzi

July 9, 2011 - 10:33 am EDT

These wireless devices have low security but not low prices. The apple marketing machine continues to make people believe they can’t live without this stuff and it seems to be working. At some point when enough easy to hack purchasing applications are running on these devices the bad guys will be looking at your checking account.

Submit Comment

eMail Updates

Advertisement | Advertise with Us

Featured Ads

Search

Advertisement | Advertise with Us
Advertisement | Advertise with Us
Advertisement | Advertise with Us

News & Record Network Sites

Triad Weather

  • Current Condition: MOSTLY CLOUDY
  • Current Temperature: 82°
  • UV Idx: 3
  • Forecast High/Low: H: 92° L: 73°

User Tools

  • Social Networking
  • RSS
  • Share
  • Sign in to MyNR

Search