Posterous
chris is using Posterous to post everything online. Shouldn't you?
Me_thumb
 

the runoff

an eclectic collection of life and geekery

iPhones Vulnerable to New Remote Attack

There are several flaws in the way that the iPhone handles digital certificates which could lead to an attacker being able to create his own trusted certificate and entice users into downloading malicious files onto their iPhones. The [vulnerability] is the end result of a number of different problems with the way that the iPhone handles over-the-air provisioning, trusted root certificates and configuration files. [This potentially means] a remote hacker may be able to change some settings on the iPhone and force all of the user's Web traffic to run through any server he chose and also to change the root certificate on the phone, enabling him to man-in-the-middle SSL traffic from the iPhone.

While advances in technology have made mobile access to the internet easy to use and readily available, it's easy to forget the security risks that exist. This write up at threat post brings to light a potentially serious risk in the iPhone.

Security risks exist on all platforms; the best thing we can do to protect ourselves is be aware of what we're doing. Pay attention to what we're clicking on. It may be the provider's responsibility to offer as secure a platform as possible, but we are ultimately responsible for how we use that platform.

Loading mentions Retweet
Filed under  //   Apple   geek   iPhone   security   SSL  
Posted February 3, 2010
// 0 Comments