Feeds

iPhone security cracked, smacked and broken

3GS cheerfully decrypts itself, says researcher

Next gen security for virtualised datacentres

A researcher has delved into the encryption used to protect content on the iPhone 3GS, only to claim it is "entirely useless" and that he had "[never] seen encryption implemented so poorly before".

Jonathan Zdziarski spent a couple of minutes demonstrating to Wired that he could copy and decrypt secured information from an iPhone. He removed the SIM to disable any remote-wipe procedures - demonstrating a security risk and concluding that "Apple may be technically correct that [the iPhone 3GS] has an encryption piece in it, but it’s entirely useless toward[s] security".

Earlier iPhone models don't use encrypted storage, but from the demonstrations performed for Wired, it seems that the iPhone 3GS will happily, and automatically, decrypt information as it's copied from the device using a remotely-installed shell - rendering the encryption pointless at best.

Apple might have demonstrated their inability to implement decent cryptographic protection of the content, but few phone systems even bother to make the attempt. With the notable exception of RIM's BlackBerry devices, it's best to assume that once an attacker has physical possession of the phone he'll gain access to the contents pretty quickly. Legally-used forensic software spends most of its time maintaining a legally-verifiable audit trail, rather than using clever techniques to extract the data.

There is an argument that implementing such weak security is worse than not bothering at all. Apple appears to be lending users a false confidence while allowing miscreants free access. But it seems unlikely that many enterprise customers were relying on Apple's encryption to protect their corporate secrets, and if they were, then they should think again. ®

Next gen security for virtualised datacentres

More from The Register

next story
6 Obvious Reasons Why Facebook Will Ban This Article (Thank God)
Clampdown on clickbait ... and El Reg is OK with this
So, Apple won't sell cheap kit? Prepare the iOS garden wall WRECKING BALL
It can throw the low cost race if it looks to the cloud
EE fails to apologise for HUGE T-Mobile outage that hit Brits on Friday
Customer: 'Please change your name to occasionally somewhere'
Time Warner Cable customers SQUEAL as US network goes offline
A rude awakening: North Americans greeted with outage drama
Shoot-em-up: Sony Online Entertainment hit by 'large scale DDoS attack'
Games disrupted as firm struggles to control network
We need less U.S. in our WWW – Euro digital chief Steelie Neelie
EC moves to shift status quo at Internet Governance Forum
BT customers face broadband and landline price hikes
Poor punters won't be affected, telecoms giant claims
prev story

Whitepapers

5 things you didn’t know about cloud backup
IT departments are embracing cloud backup, but there’s a lot you need to know before choosing a service provider. Learn all the critical things you need to know.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Backing up Big Data
Solving backup challenges and “protect everything from everywhere,” as we move into the era of big data management and the adoption of BYOD.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?