Live data from Hacker News

Mailbox iOS app is a security fail

subhb.org

11–20 of 60 posts

Re: Mailbox iOS app is a security fail

#11
post #4

An important fact is wrong: You actually need to unlock the device to access the data unless the iPhone and the computer were paired before.

Having said the above, one can copy all the contacts and emails of someone in few seconds. This is different than just browsing an email on UI (one would need time for that). What if someone has got an access to an iDevice just for few seconds. Ohh sir, you dropped your phone. Here you go but thanks to iExplorer I have all your documents and contacts now! Is this an issue? Depends what you use your email for!

Re: Mailbox iOS app is a security fail

#12
post #9
post #8

Earlier quoted context omitted.

If the device is not locked, how about just launching the Mailbox app and browse the attachments via its fancy UI? :)

On any app that consists of sensitive information, one should probably implement passcode security on the application itself. Now this might annoy some users, but if you know you are going to use it for something special, you won't mind it!

So therefore, your article could have been titled "{Mailbox|GMail|iMail|all_other_mail_clients_ever} is a Security Fail!"?

Because as far as I am aware, few mail clients either support or (if they do) actively encourage an extra password layer, and your users do not want it. Given an average un-password-protected phone, you will be able to read their email even if they were using the iOS encrypted files framework, just by opening the app.

I apologize, but it appears that your headline is deliberate sensationalism. If you want to have a discussion about how we need to secure email apps in general, I'm interested. If you want to just pick the latest 'big thing' and take pot shots at it, nah.

Re: Mailbox iOS app is a security fail

#13
post #5

“if anyone else can get hold of your phone, he can access to files of those apps where data is not protected.” As always, if someone has physical access and unlimited time, no device or computer is safe. Also, Mailbox.app only supports GMail. Security minded people are obviously not the target market.

Does that mean that basic security should not be in a company's mind, especially when it comes to the kind of data emails can contain? Mailbox is BIG. We are not talking of an average app here!

Email is not secure. Email has never been secure. Nothing you send over email is secure. There's little authentication and no signing.

All this stuff can be kludged onto email, but the attitude should be "unless I've taken measures to add security this thing is not secure".

Re: Mailbox iOS app is a security fail

#14
post #7
post #4

An important fact is wrong: You actually need to unlock the device to access the data unless the iPhone and the computer were paired before.

This is correct @nezza. I should have verified this with my friend's iPhone first. But the original issue still remains the same which is the files are not protected!

They aren't protected if you go into the app and look at the files (probably turning data off first).

If you can unlock the phone, you've almost certainly already lost here.

Re: Mailbox iOS app is a security fail

#15
post #9
post #8

Earlier quoted context omitted.

If the device is not locked, how about just launching the Mailbox app and browse the attachments via its fancy UI? :)

On any app that consists of sensitive information, one should probably implement passcode security on the application itself. Now this might annoy some users, but if you know you are going to use it for something special, you won't mind it!

[deleted]

Re: Mailbox iOS app is a security fail

#16
post #12
post #9

Earlier quoted context omitted.

On any app that consists of sensitive information, one should probably implement passcode security on the application itself. Now this might annoy some users, but if you know you are going to use it for something special, you won't mind it!

So therefore, your article could have been titled "{Mailbox|GMail|iMail|all_other_mail_clients_ever} is a Security Fail!"? Because as far as I am aware, few mail clients either support or (if they do) actively encourage an extra password layer, and your users do not want it . Given an average un-password-protected phone, you will be able to read their email even if they were using the iOS encrypted files framework, j…

@tmpajk How does it make Mailbox more secure. Let's talk about the scenario where you have access to an iPhone for few minutes. In one case, you can go through some contents, in another case you can copy all emails and contacts. My whole point is files or attachments on information on every app that has sensitive information should be protected. There are various ways to do it on iOS! One can use keychain to store some secret key and protect these files using that secret key.

Re: Mailbox iOS app is a security fail

#17

“if anyone else can get hold of your phone, he can access to files of those apps where data is not protected.” As always, if someone has physical access and unlimited time, no device or computer is safe. Also, Mailbox.app only supports GMail. Security minded people are obviously not the target market.

If you get physical access you can also read all the mails in Apple's Mail.app, or any other app on the device. Maybe not using a tool, but you can easily read them in the app, forward them, and send fake e-mails using the account of the user.

(edited to make my point more clear :)

Re: Mailbox iOS app is a security fail

#18
post #16
post #12

Earlier quoted context omitted.

So therefore, your article could have been titled "{Mailbox|GMail|iMail|all_other_mail_clients_ever} is a Security Fail!"? Because as far as I am aware, few mail clients either support or (if they do) actively encourage an extra password layer, and your users do not want it . Given an average un-password-protected phone, you will be able to read their email even if they were using the iOS encrypted files framework, j…

@tmpajk How does it make Mailbox more secure. Let's talk about the scenario where you have access to an iPhone for few minutes. In one case, you can go through some contents, in another case you can copy all emails and contacts. My whole point is files or attachments on information on every app that has sensitive information should be protected. There are various ways to do it on iOS! One can use keychain to store so…

The risk is that people assume their email is secure because the email storage on the iPhone is secure.

Re: Mailbox iOS app is a security fail

#19
post #17

“if anyone else can get hold of your phone, he can access to files of those apps where data is not protected.” As always, if someone has physical access and unlimited time, no device or computer is safe. Also, Mailbox.app only supports GMail. Security minded people are obviously not the target market.

If you get physical access you can also read all the mails in Apple's Mail.app, or any other app on the device. Maybe not using a tool, but you can easily read them in the app, forward them, and send fake e-mails using the account of the user. (edited to make my point more clear :)

Are you sure about that? I would think that Mail.app used apprioriate file protection settings, in which case the file contents is encrypted with a key derived from the user's PIN/passcode

Re: Mailbox iOS app is a security fail

#20
post #16
post #12

Earlier quoted context omitted.

So therefore, your article could have been titled "{Mailbox|GMail|iMail|all_other_mail_clients_ever} is a Security Fail!"? Because as far as I am aware, few mail clients either support or (if they do) actively encourage an extra password layer, and your users do not want it . Given an average un-password-protected phone, you will be able to read their email even if they were using the iOS encrypted files framework, j…

@tmpajk How does it make Mailbox more secure. Let's talk about the scenario where you have access to an iPhone for few minutes. In one case, you can go through some contents, in another case you can copy all emails and contacts. My whole point is files or attachments on information on every app that has sensitive information should be protected. There are various ways to do it on iOS! One can use keychain to store so…

Where is the key kept then? One possibility, the user has to know it, at which point we're back to the fact that users dont seem to want a password for their email app (again, happy to see an interesting post on the generalities of email app security). The other approach is to store it somewhere on the phone, at which point connecting the phone to a computer as you describe is still an attack vector; you just need to find the key.

Of course, I am not highly versed in security, so if there's another option I'm interested to hear it.

Post reply on HN