Feeds

iPhone push hack shoves IMs to complete strangers

You talkin' to me?

Application security programs and practises

A German developer has discovered that sending an AIM message to someone who has both jailbroken their iPhone and installed a hack that enables it to receive push notifications may result in your message being read by anyone else who has installed the push-enabling hack.

Till Schadde, founder of equinux, tells The Reg that he sent a message over AIM using iChat on his Mac - with all relevant security settings enabled, such as SSL - to a friend's iPhone. He did know that this iPhone, which was running iPhone Software 3.0, had been jailbroken and that its owner had installed two hacks to enable push notifications: this one and this one.

Schadde was surprised to hear back not from his friend, but from a total stranger in the US - a person who had also installed the offending hacks. He sent Schadde a screenshot proving that he had, indeed, received the same message that Schadde had sent to his European friend.

Apparently, the hacks - or one of them, at least - install the same iPhone ID on any phone that has been so hacked, resulting in any messages being sent to them by Apple's push services to be also received by other similarly hacked iPhones.

Schadde speculates that the problem is not the fault of AOL (AIM's creator) - representatives of which, in fact, contacted him after a report of the problem first surfaced in CrunchGear.

And although the problem appears only on hacked iPhones, it appears to be rooted in a security flaw in the Apple implementation of the Push notification system, according to Schadde. "There appears to be something hackable in the notification," he said.

Schadde hasn't contacted Apple about the problem - even though, as he says, "I think it's kind of major." After all, he told us, in these days of instant worldwide communication, his discovery is sure to have already been noticed in Cupertino. ®

HP ProLiant Gen8: Integrated lifecycle automation

More from The Register

next story
Google Nest, ARM, Samsung pull out Thread to strangle ZigBee
But there's a flaw in Google's IP-based IoT system
Want to beat Verizon's slow Netflix? Get a VPN
Exec finds stream speed climbs when smuggled out
US freemium mobile network eyes up Europe
FreedomPop touts 'free' calls, texts and data
'Two-speed internet' storm turns FCC.gov into zero-speed website
Deadline for comments on net neutrality shake-up extended to Friday
NBN Co execs: No FTTN product until 2015
Faster? Not yet. Cheaper? No data
Oh girl, you jus' didn't: Level 3 slaps Verizon in Netflix throttle blowup
Just hook us up to more 10Gbps ports, backbone biz yells in tit-for-tat spat
UN to Five Eyes nations: Your mass surveillance is breaking the law
And Navi Pillay calls for Snowden to be protected
prev story

Whitepapers

Top three mobile application threats
Prevent sensitive data leakage over insecure channels or stolen mobile devices.
The Essential Guide to IT Transformation
ServiceNow discusses three IT transformations that can help CIO's automate IT services to transform IT and the enterprise.
Mobile application security vulnerability report
The alarming realities regarding the sheer number of applications vulnerable to attack, and the most common and easily addressable vulnerability errors.
How modern custom applications can spur business growth
Learn how to create, deploy and manage custom applications without consuming or expanding the need for scarce, expensive IT resources.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.