Results 1 to 2 of 2
Like Tree2Likes
  • 1 Post By RadioRaiders
  • 1 Post By spidershowl11

Apple Warns Customers of SMS-Spoofing Flaw in iOS

Wow, this is Apple "magic" at it's finest: someone detects a flaw in iOS that exposes a weakness in a way ...

  1. #1
    RF Black-Belt RadioRaiders's Avatar
    Join Date
    Apr 2007
    Location
    Undisclosed
    Posts
    2,668
    Provider(s)
    GSM / WCDMA
    Likes
    284

    News Apple Warns Customers of SMS-Spoofing Flaw in iOS

    Wow, this is Apple "magic" at it's finest: someone detects a flaw in iOS that exposes a weakness in a way that SMS's can be spoofed, so since "Apple takes security very seriously" they advise customers to instead use their own proprietary iMessage service?? Why don't they just correct the SMS flaw in iOS, if they take security "very seriously"?

    Every phone has SMS capability by default, but only Apple products have iMessage, so if an iPhone user wants to send a message to a non-iPhone user, then what? The iPhone user puts himself at risk because of the iOS flaw? I suppose Apple's response would be that "because they take security very seriously" that everyone on the planet should buy an iPhone so everyone can use iMessage in order to compensate for the faulty way that iOS handles SMS

    Apple has a message for texters: Don't trust SMS.

    The consumer electronics heavyweight has advised iPhone users concerned about secure messaging to use the company's iMessage service instead of their carrier's SMS network.

    While SMS is a relatively mature technology, in recent years it has attracted the interest of security researchers as an attack vector for smartphones.

    Apple made its recommendation in a statement Saturday after a well-known iPhone jailbreaking artist explained in a posting on the Internet how a "flaw" in Apple's implementation of SMS in its mobile operating system, iOS, could be used to spoof SMS messages.

    The flaw is in all versions of iOS, including the latest beta of the next release of the operating system, version 6.0, beta 4, according to the security researcher known as pod2g.

    "Apple takes security very seriously," the company says in its statement. "When using iMessage instead of SMS, addresses are verified which protects against these kinds of spoofing attacks."

    "One of the limitations of SMS is that it allows messages to be sent with spoofed addresses to any phone, so we urge customers to be extremely careful if they're directed to an unknown website or address over SMS," it adds.

    Pod2g explains that the SMS flaw allows the sender of the message to enter an address on its reply line that's different from the address that appears on its "from" line.

    Creating such a message doesn't require rocket science, according to Derek Halliday, a senior security product manager with Lookout Mobile Security. "It is relatively trivial to create a message with the header that is described [by pod2g]," he told PCWorld.

    Because iOS uses the information from the "Reply To" line to identify the origin of the message, its sender can make it appear as if it came from someone trusted by the recipient of the message. Once the sender gains the recipient's trust, they can divert the recipient, through malicious links in the message, to a website where sensitive information can be pried from the target.

    A simple solution to the SMS problem would be for iOS to display both the original and "reply to" addresses for a message. Then, if the two addresses don't match, a recipient could smell something phishy and take appropriate precautions.

    There are a number of sites on the Web, like spoofsms.net and spooftexting.com, for sneaky people and pranksters but it seems that spoofing in the United States isn't as easy as it is in other countries, according to a website called smsspoofing.com.

    "The United States is probably the most difficult to spoof text messages to from our tests," it says. "We've never seen a spoofed SMS properly go through to a mobile phone in the US or Canada."

    "We're not sure of the technical reasons for this, but the carriers seem to have set themselves up in a way to avoid this," it added.
    Apple Warns Customers to be Cautious of SMS After 'Flaw' Cited | PCWorld
    Maximum Signal likes this.
    Understand communications. Visit Radio Raiders
    Plot your own cellular coverage maps at Cellumap <--Apps for BlackBerry / Android / Symbian

  2. #2
    Fresh Member
    Join Date
    Jul 2012
    Posts
    15
    Likes
    1

    Default Re: Apple Warns Customers of SMS-Spoofing Flaw in iOS

    Quote Originally Posted by RadioRaiders View Post
    Wow, this is Apple "magic" at it's finest: someone detects a flaw in iOS that exposes a weakness in a way that SMS's can be spoofed, so since "Apple takes security very seriously" they advise customers to instead use their own proprietary iMessage service?? Why don't they just correct the SMS flaw in iOS, if they take security "very seriously"?

    Every phone has SMS capability by default, but only Apple products have iMessage, so if an iPhone user wants to send a message to a non-iPhone user, then what? The iPhone user puts himself at risk because of the iOS flaw? I suppose Apple's response would be that "because they take security very seriously" that everyone on the planet should buy an iPhone so everyone can use iMessage in order to compensate for the faulty way that iOS handles SMS


    Apple Warns Customers to be Cautious of SMS After 'Flaw' Cited | PCWorld
    SMS spoofing looks similar to the email spoofing that we encounter regularly. SMS spoofing only means that you have to be careful with your messaging as you are with your emails. Why is Apple making it look like a very big problem and asking to use their iMessage only? Probably this might be a marketing technique too.
    Jay2TheRescue likes this.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Replies: 14
    Last Post: 08-07-2009, 3:59 PM
  2. Apple looks to fix 'minor' iPhone security flaw
    By SmArTeStChIlD421 in forum Wireless News
    Replies: 0
    Last Post: 08-31-2008, 10:14 PM
  3. Replies: 2
    Last Post: 07-16-2008, 2:15 AM
  4. Replies: 12
    Last Post: 06-19-2008, 12:14 AM
  5. Caller ID Spoofing
    By jones in forum Wireless News
    Replies: 4
    Last Post: 03-01-2006, 8:48 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  

About Us | Advertising | Privacy Statement | Legal | Press | Feedback/Contact


Forum feeds:         Add to Google Reader or Homepage

Copyright 1997-2013 Wireless Advisor, LLC. All rights reserved. All registered and unregistered trademarks are the property of their respective holders.
WirelessAdvisor.com is not associated by ownership or membership with any cellular, PCS or wireless service provider companies and is not meant to be an endorsement of any company or service. Some links on these pages may be paid advertising or paid affiliate programs.


Copyscape Protected  WAP Site for WirelessAdvisor.com  Visit the WirelessAdvisor page on facebook.com