Tired of getting the brush-off from Apple, Israeli researcher Aviv Raff Thursday disclosed technical details about a pair of iPhone security flaws that he first reported more than two months ago.
Raff, best known as a browser vulnerability researcher, told Apple in July that he had uncovered bugs in the iPhone's Mail application as well as in its version of Safari that could be used to trick users into clicking on malicious links and boost the amount of spam they face.
But after Apple continued to defer patching and declined to set a date for fixing the flaws, Raff decided to go public. "Two and a half months later, and still there is no patch for those vulnerabilities," he complained in a post to his blog. "I've asked Apple several times for a schedule, but they have refused to provide the fix date. Three versions (v2.0.1, v2.02, v2.1) have been released since I provided them with the details, and they are still 'working on it.'"
In an interview Thursday, Raff said that while he's used this tactic before to pressure a vendor into patching, he's reserved it for companies that "act irresponsibly, as Apple did this time and other vendors have done other times." Raff said he last contacted Apple a week ago.
Apple last patched the iPhone on September 12, when it issued fixes for eight security vulnerabilities as part of the v2.1 update.
Both Mail and Safari truncate URLs to accommodate the iPhone's small screen, said Raff, a bug that hackers could exploit by feeding malicious links via HTML messages. Because Mail cuts out the middle portion of a long URL, the attacker could spoof a legitimate domain by using a legitimate service such as Facebook to provide the first bits of the address but tuck the malicious part of the URL after the iPhone's cut-off.
Raff demonstrated a possible exploit by creating a link that, at least to an iPhone owner, appeared to be a URL to Facebook's sign-in site, but was actually a link to an image he'd posted on his own domain.
"The user will have to look carefully at all links that he clicks," said Raff when asked for advice on deflecting such attacks. "But this takes a lot of effort as Safari automatically jumps to the end of the URL when clicking on the address bar."
He called the other iPhone bug "a pretty dumb design flaw" that made it easier for spammers to identify valid e-mail accounts, and thus mark them for more spam.
Because the iPhone automatically downloads images attachments, it would be a cinch for spammers to identify a working e-mail account. "The spammer who controls the remote server will know that you have read the message, and will mark your mail account as active, in order to send you more spam," said Raff. Since there is no way to disable auto-image download on the iPhone, he recommended that iPhone users refrain from using Mail until Apple patches the problem.
The same bug has surfaced before in other versions of Apple's Mail software -- the company bundles a much brawnier edition with Mac OS X -- but those versions have long been patched.
Claiming that the flaws were easily fixed, Raff called on Apple to get on the stick. "It's only a matter of time until the bad guys will find these problems," he said.
Raff isn't the first security researcher to knock Apple's patching process. Last month, two other researchers, including Charlie Miller, who is even better known than Raff in the Mac and iPhone vulnerability arena, took Apple to task for dumping several updates on users in a short time, and without warning.
Latest on Apple
- Apple fixes big security bugs in Mac OS X
- Apple exec stashed $150,000 in shoe boxes
- iPhone gets a social news app
- Apple pulls Grooveshark music streaming app from iTunes
- Apple manager arrested over $1 million in kickbacks
- IPad knockoffs now for sale on eBay
- Elcomsoft releases iPhone 4 password cracker
- iPhone 4 a hit despite antenna hype
- Apple needs to respond quicker to issues, analysts say
- Ask Geek Tech: Is iPhone 4 'Death Grip' Recall-Worthy?
Hardware Essentials
- Slideshow -- Tech of Yesteryear: Where Old Computers Find Their Final Resting Place
- Chip shipments could face slow growth
- Gartner to slash 2009 chip forecast by $25 billion
- Researchers find state of matter that may extend Moore's Law
- Forgotten history: the true origins of the PC
- Researchers develop bug-blocking chip monitor
- Intel, AMD multicore chip sales may be slowed by software
- Asustek turns to Celerons amid Atom shortage
- Strong Intel sales push global PC chip market to record Q2
- Via pushing into laptop, desktop markets with 5 new chips
- WebSphere Solution Design (S20) - CBD, contract role3/09/2010
Other
I.T. & T
WebSphere Solution Design (S20) - CBD, contract role - Solution Architect - Web Application Architecture Project!3/09/2010
Other
I.T. & T
Solution Architect to provide strategic and operational consulting for the end-to-end Web Application System project! Experienced with J2EE or .NET?! - Principal Consultant - ITIL2/09/2010
Other
I.T. & T
Excellent opportunity for an experienced ITIL Principal Consultant to join an innovative leading IT Service management consultancy. Attractive packag - Mainframe Developer - COBOL - 12 Month Contract2/09/2010
Other
I.T. & T
Mainframe Developer - COBOL - 12 Month Contract - Business Systems Analyst2/09/2010
Other
I.T. & T
Perm CBD based role for an experienced Business Systems Analyst - Senior SAP Project Manager2/09/2010
Other
I.T. & T
Senior SAP Project Manager - SAP FICO Consultant - 6 week contract - West Sydney2/09/2010
Other
I.T. & T
SAP FICO Consultant - 6 week contract - West Sydney
TechWorld Blogs
Recent blog posts
- Windows Phone 7: how big can it get?
- NBN gets a turn at political football
- Internet filter gets caught up in politics
- TechWorld Forums goes live
- Selective sourcing the hybrid of cloud services
- Social networks catch more business attention
- RIP Kin
- Telstra’s copper and NBN’s fibre: will the two ends meet?
- RIP Windows 2000, XP lives on
- Does the world need another iPhone? Why not
Recent comments
- java development
13 hours 7 min ago - When mine called they
13 hours 51 min ago - 3D TV cannot fall - no way! Why?
17 hours 4 min ago - Thanks for taking the time to
1 day 5 hours ago - Windows scam
1 day 12 hours ago - My only anti fraud method is
2 days 7 hours ago - Private Cloud Taxonomies
2 days 7 hours ago - ...however...
2 days 16 hours ago - This Guy
2 days 16 hours ago - Glasses Free technology
2 days 17 hours ago - FOSS community
3 days 42 min ago - i have dv6000 with nvidia
3 days 2 hours ago - i have dv6000 and suddenly
3 days 2 hours ago - This is an awesome comment.
3 days 5 hours ago - Real Estate
3 days 7 hours ago - Scam - eventvwr scammers
3 days 12 hours ago - Well I never...
5 days 2 hours ago - Too bad Microsoft was mentioned
5 days 4 hours ago - Phone card is a better option to make calls at a lower rate
5 days 9 hours ago - In other words: "Developers,
5 days 14 hours ago










Comments
Post new comment