Jailbroken iPhones leave users more vulnerable

By Sumner Lemon, IDG News Service |  Mobile & Wireless, iphone jailbreak Add a new comment

Jailbreaking an iPhone leaves users vulnerable to attack by stripping away most of the handset's security protections, a security researcher warned Thursday.

"If you care about security, don't use a jailbroken iPhone," said security researcher Charlie Miller, speaking at the SyScan security conference in Singapore on Thursday.

Jailbreaking is a term used to describe the process of stripping away the protections that prevent a user from installing applications on an iPhone that have not been digitally signed by Apple. Jailbreaking tools have been popular among users in the U.S. and elsewhere who do not want to be tied to a specific operator, or who want to add software or capabilities to the phone that Apple doesn't offer.

The process removes around 80 percent of the security protections built into the phone's software, making it more vulnerable, Miller said.

Overall, the stripped-down version of Mac OS X used in the iPhone makes it more secure than computers running the full version of the operating system, Miller said.

Many capabilities contained in the full version of the operating system, like support for Java and Adobe Flash, are not available on the iPhone. In addition, the iPhone doesn't support many of the features contained in PDF files, which have proved to be a fertile source of Mac OS X vulnerabilities. This gives attackers fewer options when looking for vulnerabilities to exploit, he said.

In addition, iPhones are limited to running applications that have been digitally signed by Apple, which means that an attacker cannot simply install and run their own software on the handset. The iPhone also has hardware protections for data stored in memory.

Jailbreaking an iPhone disables these two security functions, making the phone more vulnerable to an attack, Miller said.

    Add a comment

    Post a comment using one of these accounts
    Or join now
    At least 6 characters

    Note: Comment will appear soon after you have activated your account.
    Obscene/spam comments will be removed and accounts suspended.
    The information you submit is subject to our Privacy Policy and Terms of Service.

    ITworld LIVE

    Mobile & WirelessWhite Papers & Webcasts

    White Paper

    Ten Steps to an Enterprise Mobility Strategy

    Enterprise employees are more mobile, relishing the ability to work productively anywhere, at any time. They may use any means to get connected, often creating financial and security risks for your company. Discover how to get control of your enterprise mobility strategy and ensure mobile worker productivity with these ten steps.

    White Paper

    What You Need to Know About the Costs of Mobility

    Mobile workers want to get connected anywhere, at any time, often at any cost. Enterprise mobility is often a hidden "black" budget in your company. Ensure that your traveling employees are productive everywhere, even while you control cost and security, through an enterprise mobility strategy.

    White Paper

    The 2011 iPass Mobile Enterprise Report

    This industry survey covers trends, recommendations and a policy guide on managing Enterprise Mobility for IT management and CIOs. Get data on employee device liability, as well as smartphone/tablet penetration, budget control and provisioning. Find out how your organization compares, how to ensure mobile worker productivity, and control costs.

    Webcast On Demand

    Managing Enterprise Mobility Costs

    Mobile employees, especially those traveling internationally, were spending time and resources finding and making connections. Roaming costs were out of control. The IT Administrator at The Hay Group tells you how he got more control over these costs, providing management with predictable budgets and insights while ensuring employee productivity.

    Sponsor: iPass

    White Paper

    Digital Transformation: Creating New Business Models Where Digital Meets Physical

    Individuals and businesses alike are embracing the digital revolution. Social networks and digital devices are being used to engage government, businesses and civil society, as well as friends and family.

    See more White Papers | Webcasts

    Ask a question

    Ask a Question