- Nokia's new N97 vs. the iPhone
- Talk-powered cell phones?
- FBI: Copper thieves jeopardize U.S. infrastructure
- 10 Microsoft research projects
- Smartphone smackdown: Storm vs. iPhone
Apple's iPhone has two design flaws that could pose potential security problems, according to a researcher.
The first one concerns the iPhone's e-mail application, which automatically downloads images within an e-mail, security researcher Aviv Raff said on Thursday. (Watch a slideshow of 20 cool third-party iPhone apps.)
That's problematic because the image will refer back to a server-side script when it is downloaded, indicating to the sender that the e-mail has been opened and the e-mail address is valid. The address can then be spammed.
E-mail applications usually are configured to block images from untrusted sources to prevent the problem, Raff said. He suggests that users avoid using the e-mail application or be careful when clicking on links in an e-mail that comes from an untrusted source.
The second design flaw is how the iPhone's e-mail application displays URLs. Messages can be shown in plain text or HTML. When in HTML mode, a user can get an e-mail where the text of the link is different than the actual link. The true link can be displayed by hovering over the text, and a pop-up window reveals the URL. But the problem is the pop-up window truncates the URL because there isn't enough space on the screen.
An attacker could create a Web site with a long subdomain to fool a user into thinking it's a legitimate site. In fact, it's a Web site designed to trick a person into revealing personal information, known as a phishing site, Raff said.
After the bad link is served up in the Safari Web browser, the user may still see only a fraction of the URL. If the address bar is clicked in mobile Safari, the cursor jumps to the end of the URL, so a person must scroll back to see the URL in its entirety, Raff wrote on his blog.
Neither Apple's mobile Safari nor the desktop version of the browser have a phishing filter.
Raff said he notified Apple more than two months ago about the design flaws. The company told Raff it was working on fixes but hadn't said when those fixes would be released.
Raff said he decided to go public with the information because Apple has since released at least three iPhone updates but hasn't addressed the issues.
"I think they put their own users at much more risk by not fixing this," Raff said in an interview. "At least now the users who read this will know to be careful. It's only a matter of time until the bad guys will find this anyway."
Apple couldn't immediately be reached for comment.
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comments (1)
picturesBy Anonymous on October 3, 2008, 2:43 amWell, my iPhone doesn't download pictures automatically. I have to tap them in order to begin the download.
Reply | Read entire comment
View all comments