Home
BYTE Newsletter
Keep up with all the BYTE News and Reviews

Subscribe

Android And BlackBerry Safer Than iOS For SMS

Comments | Eric Zeman, InformationWeek | August 23, 2012 12:50 PM


11 Security Sights Seen Only At Black Hat
11 Security Sights Seen Only At Black Hat
(click image for larger view and for slideshow)
A flaw discovered recently in Apple's iPhone could allow nefarious people to hack SMS messages. According to AdaptiveMobile, the iPhone stands alone with this security hole. AdaptiveMobile tested the exploit in the iPhone and compared it to Android, BlackBery, Symbian, and Windows Mobile. All the other platforms remained secure in their treatment of SMS messages.

The bug, unearthed by researcher pod2g, essentially allows hackers to spoof the reply-to number in a text message. Doing this could let unsavory types send messages that appear to come from one entity (such as your bank), but that direct the responses elsewhere. The security researcher warned that such spoofing could be used to trick iPhone users into revealing personal information via text message that could then be used to gain access to personal accounts.

More Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

"Historically, the 'reply-address' field was introduced to allow users to reply to texts which were 'broadcast' from information agencies or marketing firms," said Cathal McDaid, security consultant at AdaptiveMobile. "These broadcast systems may not be capable of receiving messages, so this system allows for more interaction."

[ Should Apple be focusing more on security? Read Apple Security Talk Suggests iOS Limits. ]

AdaptiveMobile says that most handsets now ignore this quirk in the system and treat the reply-address field correctly. Its research confirms this to be true with Google's Android, RIM's BlackBerry, Nokia's Symbian, and Microsoft's Windows Mobile platforms.

"Apple has left a significant vulnerability in its handsets [that] could allow consumers to be fooled and hand over personal details to hackers and criminals," noted McDaid. "This reinforces the importance of handset manufacturers, operators, and security providers collaborating and helping to keep SMS as a secure, reliable, and trusted channel."

Apple responded to the issue, but didn't offer much of a fix.

"Apple takes security very seriously," said Apple in a statement. "When using iMessage instead of SMS, addresses are verified which protects against these kinds of spoofing attacks. One of the limitations of SMS is that it allows messages to be sent with spoofed addresses to any phone, so we urge customers to be extremely careful if they're directed to an unknown website or address over SMS."

In other words, Apple suggests that users concerned with the security of their smartphone should trust iMessage instead of SMS. iMessage is available only on the iPhone, iPad, iPod Touch, and Apple computers.

Apple has not indicated if it plans to fix the security hole.

Android and Apple devices make backup a challenge for IT. Look to smart policy, cloud services, and MDM for answers. Also in the new, all-digital Mobile Device Backup issue of InformationWeek: Take advantage of advances that simplify the process of backing up virtual machines. (Free with registration.)



Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

COMMENTS

Tune In to BYTE
Facebook Twitter LinkedIn Newsletter RSS
Whitepapers
whitepaper
In this paper you will learn the five trends shaping the future of enterprise mobility. Learn how the rise of social media as a business application, the lurring between work and home, the emergence of new mobile devices, the demand for tech savvy employees and changing expectations of corporate IT will fundamentally change the workplace.
whitepaper
In a survey of more than 1,700 information workers (iWorkers) in North America, notebooks, desktops, and smartphones were found to be “must-have” devices, while tablets, slates, and netbooks were relegated to “nice-to-have” status, according to a commissioned study conducted by Forrester Consulting on behalf of Dell and Intel.
Sponsored by: Dell
Upcoming Events