Selasa, Februari 07, 2012
Text Size

Search

Update Berita

Membangun Suasana Kerja Yang Hangat

Sebagian orang berfikir bahwa kantor merupakan tempat yang paling membuat kita stres dengan...

Inggris dan Argentina Sengketa Pulau Falkland

Angkatan bersenjata Inggris akan mengirimkan kapal perang paling canggih mereka ke perairan pulau...

Komputer Awan akankah membantu?

Pernahkah terbayangkan bila suatu hari Anda tidak sengaja menformat USB karena alasan penuh, namun...

Cinta adalah salah satu energi kesehatan

Jatuh cinta turunkan risiko kecanduan alkohol Anda yang masih jomblo, mungkin akan memilih menikmati...

Upah buru menjadi bumberang politik SBY

Presiden Susilo Bambang Yudhoyono (SBY) menegaskan penetapan upah minimum regional (UMR) bagi para...

Google hapus aplikasi berbahaya

Google tidak akan menghapus 13 aplikasi Android yang dinyatakan berbahaya oleh Symantec. Menurut...

  • Grunt Mars probe stranded in Earth orbit

    Kamis, 10 November 2011 02:40
  • Google drops the axe on its internal renewable energy work

    Kamis, 24 November 2011 02:46
  • Membangun Suasana Kerja Yang Hangat

    Selasa, 17 Januari 2012 02:02
  • Inggris dan Argentina Sengketa Pulau Falkland

    Rabu, 01 Februari 2012 09:04
  • Komputer Awan akankah membantu?

    Rabu, 01 Februari 2012 09:11
  • Cinta adalah salah satu energi kesehatan

    Rabu, 01 Februari 2012 09:15
  • Upah buru menjadi bumberang politik SBY

    Rabu, 01 Februari 2012 09:22
  • Google hapus aplikasi berbahaya

    Rabu, 01 Februari 2012 09:26
Posting Member New research reveals troubling security issues for iPhones
SocialTwist Tell-a-Friend

New research reveals troubling security issues for iPhones

Penilaian Pengunjung: / 0
KurangTerbaik 

Though Apple has added additional data security features to the iPhone with every iteration of the OS—including encrypting files on-device for the iPhone 3GS—vulnerabilities still exist. These issues are of particular concern to enterprise users, since sensitive corporate data may exist on any given employee's mobile device. A new vulnerability revealed by security researcher Bernd Marienfeldt, however, shows that all someone needs to get at that data is the latest version of Ubuntu.

Noted iPhone data forensics expert Jonathan Zdziarski demonstrated last year that common hacking tools could remove the data protection features that Apple added with iPhone OS 3.x and the iPhone 3GS. He told Ars that there are ways to get around both the on-device encryption as well as the encrypted backups that can be saved via iTunes. "The only benefit hardware encryption [as implemented] is that it makes wipes faster, by just dropping the [encryption] key," he said. But even the remote wipe feature can be thwarted by removing a device's SIM card.

Marienfeldt's research revealed that standard hacking or jailbreaking tools aren't even needed to get at the data. The latest version of Ubuntu (10.04) will auto mount the flash storage in an iPhone, allowing access to all of the information contained within. Files can be accessed even if a pin code is set.

Zdziarski warned that the way encryption worked on the iPhone could be exploited in this way if a tool allowed the iPhone's file system to be mounted. "The [iPhone OS] kernel decrypts it for you when you ask for files, so you get the decrypted copy," he told Ars last summer .

Ubuntu screen grab
Here you can see the entire filesystem of an iPhone 3GS with PIN code lock displayed under Ubuntu 10.04.

Marienfeldt verified that only the DCIM folder, where images and videos are stored, is accessible on Mac OS X, Windows, and Linux—even older versions of Ubuntu. However, Lucid Lynx will, when set to auto mount USB-based devices, expose the entire filesystem of any iPhone. "This data protection flaw exposes music, photos, videos, podcasts, voice recordings, Google safe browsing database, game contents," Marienfeldt wrote on his blog.

He has shared his findings with Apple, and engineers were able to verify the problem. "Apple could reproduce the described serious issue and believes [it understands] why this can happen but cannot provide timing or further details on the release of a fix," Marienfeldt said.

Of course, knowing that pretty much anyone with Ubuntu installed can get at all of your data is troubling. Marienfeldt noted that this problem is quite serious for enterprise users, especially since companies "rely on the expectation that their iPhone 3GS’s whole content is protected by encryption with a PIN code based authentication in place to unlock it." This is probably true; Steve Jobs recently noted during the iPhone OS 4.0 preview that 80 percent of Fortune 100 companies have employees using iPhones as a work-related mobile device.

AT&T also said that 40 percent of iPhones are now sold to enterprise users. "When the iPhone came out, what most people heard in the first year from '07 to '08 was oh my God, it's not BlackBerry secure; this is not going to work on the enterprise space," AT&T Business Solutions CEO Ron Spears said recently during the Barclays Capital Communications, Media and Technology Conference. "And by the time the 3G came out in ‘08 they had solved about 80 percent of the security issues. By the time the 3GS came out last summer, most CIOs will tell you today they have very few issues around the security that they need provided."

However, this latest example shows that Apple has some work ahead of it to beef up security for its mobile platform. Apple has promised more robust encryption options for iPhone OS 4.0, including giving developers an API to encrypt their applications' data separately. If these new options rely on the same encryption system as current iPhones, though, that won't be enough. Marienfeldt recommends that Apple employ a more robust full disk encryption method, one that requires the PIN code to be entered before the filesystem will mount on any OS.

Comments
Add New Search
Write comment
Name:
Email:
 
Website:
Title:
 
:angry::0:confused::cheer:B):evil::silly::dry::lol::kiss::D:pinch:
:(:shock::X:side::):P:unsure::woohoo::huh::whistle:;):s
:!::?::idea::arrow:
 
Please input the anti-spam code that you can read in the image.

3.25 Copyright (C) 2007 Alain Georgette / Copyright (C) 2006 Frantisek Hliva. All rights reserved."

Advertisement Site

Berita lain-lainnya

Tips Kelolah Uang Gaji Pertama
03/08/2011 | World Friend Indonesia
article thumbnail

Ketika awal bulan datang, dompet seolah bersorak-sorai, mata terbelalak penuh keceriaan, wajah berseri-seri seakan berkata, "Akhirnya punya uang juga," saat seorang fresh graduate menerima gaji pert [ ... ]


Salah masuk toilet seorang polisi di penjara
07/06/2011 | World Friend Indonesia
article thumbnail

Alois Mabhunu, seorang polisi di Zimbabwe, ditahan di penjara khusus polisi hanya gara-gara kebelet buang air. Pasalnya, dia menuntaskan hajatnya itu di toilet yang diperuntukkan bagi Presiden Zimba [ ... ]