Security researcher reveals iPhone design flaws

By Jeremy Kirk, IDG News Service |  Security, Apple, iphones 1 comment

Apple's iPhone has two design flaws that could pose potential security problems, according to a researcher.

The first one concerns the iPhone's e-mail application, which automatically downloads images within an e-mail, said Aviv Raff, a security researcher, on Thursday.

That's problematic because the image will refer back to a server-side script when it is downloaded, indicating to the sender that the e-mail has been opened and the e-mail address is valid. The address can then be spammed.

E-mail applications usually are configured to block images from untrusted sources to prevent the problem, Raff said. He suggests that users avoid using the e-mail application or be careful when clicking on links in an e-mail that comes from an untrusted source.

The second design flaw is how the iPhone's e-mail application displays URLs (Uniform Resource Locators). Messages can be shown in plain text or HTML (Hypertext Markup Language). When in HTML mode, a user can get an e-mail where the text of the link is different than the actual link. The true link can be displayed by hovering over the text, and a pop-up window reveals the URL. But the problem is the pop-up window truncates the URL since there isn't enough space on the screen.

An attacker could create a Web site with a long subdomain in order to fool a user into thinking it's a legitimate site. In fact, a Web site designed to trick a person into revealing personal information, known as a phishing site, Raff said.

After the bad link is served up in the Safari Web browser, the user may still only see a fraction of the URL. If the address bar is clicked in mobile Safari, the cursor jumps to the end of the URL, so a person must scroll back to see the URL in its entirety, Raff wrote on his blog.

Neither Apple's mobile Safari nor the desktop version of the browser have a phishing filter.

Raff said he notified Apple more than two months ago about the design flaws. The company told Raff they were working on fixes but hadn't said when those fixes would be released.

Raff said he decided to go public with the information since Apple has since released at least three iPhone updates but hasn't addressed the issues.

"I think they put their own users at much more risk by not fixing this," Raff said in an interview. "At least now the users who read this will know to be careful. It's only a matter of time until the bad guys will find this anyway."

Apple couldn't immediately be reached for comment.

1 comment

    Anonymous 3 years ago
    Thanks for the warning and the clear explanation. It's been 60 days since he warned Apple and I am confident that Apple now has people working on solutions. Perhaps in the "new" Safari already announced for this month.I don't have an iPhone, and am no computer expert. But, like many business and personal users of the web have already been educated not to click on any link or attachment unless from a trusted source. In this 21st century, unfortunately, the sophistication of our technology and the sophistication of hackers, thieves and other predators is something we all need to be aware. So be prudent and careful, because the wolves are out there.

      Add a comment

      Post a comment using one of these accounts
      Or join now
      At least 6 characters

      Note: Comment will appear soon after you have activated your account.
      Obscene/spam comments will be removed and accounts suspended.
      The information you submit is subject to our Privacy Policy and Terms of Service.

      ITworld LIVE

      SecurityWhite Papers & Webcasts

      White Paper

      Overcome Top 7 Admin Challenges of Active Directory

      As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.

      White Paper

      Insiders Can Ruin Your Company. Take Action.

      Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.

      White Paper

      Top Solutions and Tools to Prevent Devastating Malware

      Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.

      White Paper

      Streamline Compliance and Increase ROI

      Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.

      White Paper

      X-Ray of the PCI Process-4 Proactive Steps

      This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.

      See more White Papers | Webcasts

      Ask a question

      Ask a Question