Home About Contact Advertise Our Sites: Billions of Bytes | Mobile Device Now | Apple Info Center | iPad Info Center
Apple Info Center
Home > Apple Info

Apple Responds to SMS Vulnerability on iPhone
By Barry Levine
Posted: August 20, 2012 12:54pm PDT

The iPhone, in an overuse of elegant minimalism, only shows the SMS sender's name, not the sender's number. This means that a hacker could pretend to be a name in your contacts, or even a generic Mom, and fool an SMS recipient into believing an incoming message. Or, using a bank name, you could be tricked into sending back financial information.

There's a vulnerability in how Apple's iPhone handles SMS text messaging that could lead to spoofing or phishing attacks. That's the conclusion of a French security blog, to which Apple responded this weekend.

The technical details were itemized Friday on pod2g's iOS blog. It describes how iOS only displays the phone number of the Reply To field in an SMS text, while most mobile devices show both the Reply To field and the originating number. Devices that process both originating and replying phone numbers can potentially compare them to make sure nothing is amiss.

'Never Trust Any SMS'

Consequently, the iPhone, in an overuse of elegant minimalism, only shows the sender's name, not the sender's number. This means that a hacker could pretend to be a name in your contacts, or even a generic Mom, and fool a recipient into believing an incoming message.

Or, if the sender knew your bank name, you could be tricked into sending back confidential financial information. As pod2g wrote, "never trust any SMS you received on your iPhone at first sight."

In a statement, Apple has suggested that the vulnerability was part and parcel of SMS technology and not particular to the iPhone, and it urged that iPhone users employ its iMessage application instead of SMS.

When using iMessage, the technology giant said, "addresses are verified which protects against these kind of spoofing attacks." The company added that one of SMS' limitations is that "it allows messages to be sent with spoofed addresses to any phone, so we urge customers to be extremely careful if they're directed to an unknown Web site or address over SMS."

Rules of Thumb

However, the iMessage protocol only works between Apple iOS devices, so Apple's fix does not cover the gamut -- unless everyone you know only purchases their mobile devices from the maker in Cupertino.

The possible consequences of such trickery could include not only fooling a user into turning over personal data or playing a less-costly but nonetheless embarrassing prank on an unsuspecting iPhone owner. There could also be legal trickery as well, since SMS messages have been used as evidence in court, even though, as the new flurry makes clear, trickery using the technology is not that difficult.

General rules of thumb -- an appropriate term for this thumb-typed medium -- advise that users be wary of any text that is sent from someone not in your contacts. Additionally, one should be suspicious of texts that appear to come from a contact but which are wildly out of context for anything that contact would send. One example: your Mom suggesting you click a link to an unknown site. In fact, be extra wary of any request in a text message to click a link, regardless of the sender.

Tell Us What You Think
Comment:

Name:


Advertisement
CommVault is a data and information management software company dedicated to providing organizations worldwide with a radically better way to manage data and information. Their unique Solving Forward philosophy allows them to deliver complete solutions with infinite scalability and unprecedented control over data and costs. Be among the first to experience Simpana 10 software. Click here now.


Information: About Us | Contact Us | How to Advertise
Services: Services for PR Pros (In partnership with NewsFactor)
Sunshine Policy Network Sites: Billions of Bytes | Mobile Device Now | Apple Info Center | iPad Info Center | Top Tech Wire
Apple Info Center
© Copyright 2013 Apple Info Center and Accuserve Tech Network. All rights reserved.