Feeds

iPhone security cracked, smacked and broken

3GS cheerfully decrypts itself, says researcher

Security for virtualized datacentres

A researcher has delved into the encryption used to protect content on the iPhone 3GS, only to claim it is "entirely useless" and that he had "[never] seen encryption implemented so poorly before".

Jonathan Zdziarski spent a couple of minutes demonstrating to Wired that he could copy and decrypt secured information from an iPhone. He removed the SIM to disable any remote-wipe procedures - demonstrating a security risk and concluding that "Apple may be technically correct that [the iPhone 3GS] has an encryption piece in it, but it’s entirely useless toward[s] security".

Earlier iPhone models don't use encrypted storage, but from the demonstrations performed for Wired, it seems that the iPhone 3GS will happily, and automatically, decrypt information as it's copied from the device using a remotely-installed shell - rendering the encryption pointless at best.

Apple might have demonstrated their inability to implement decent cryptographic protection of the content, but few phone systems even bother to make the attempt. With the notable exception of RIM's BlackBerry devices, it's best to assume that once an attacker has physical possession of the phone he'll gain access to the contents pretty quickly. Legally-used forensic software spends most of its time maintaining a legally-verifiable audit trail, rather than using clever techniques to extract the data.

There is an argument that implementing such weak security is worse than not bothering at all. Apple appears to be lending users a false confidence while allowing miscreants free access. But it seems unlikely that many enterprise customers were relying on Apple's encryption to protect their corporate secrets, and if they were, then they should think again. ®

Intelligent flash storage arrays

More from The Register

next story
FCC, Google cast eye over millimetre wireless
The smaller the wave, the bigger 5G's chances of success
It's even GRIMMER up North after MEGA SKY BROADBAND OUTAGE
By 'eck! Eccles cake production thrown into jeopardy
Mobile coverage on trains really is pants
You thought it was just *insert your provider here*, but now we have numbers
Don't mess with Texas ('cos it's getting Google Fiber and you're not)
A bit late, but company says 1Gbps Austin network almost ready to compete with AT&T
HBO shocks US pay TV world: We're down with OTT. Netflix says, 'Gee'
This affects every broadcaster, every cable guy
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why and how to choose the right cloud vendor
The benefits of cloud-based storage in your processes. Eliminate onsite, disk-based backup and archiving in favor of cloud-based data protection.
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.