Live data from Hacker News

Mailbox iOS app is a security fail

subhb.org

21–30 of 60 posts

Re: Mailbox iOS app is a security fail

#21
post #11
post #4

An important fact is wrong: You actually need to unlock the device to access the data unless the iPhone and the computer were paired before.

Having said the above, one can copy all the contacts and emails of someone in few seconds. This is different than just browsing an email on UI (one would need time for that). What if someone has got an access to an iDevice just for few seconds. Ohh sir, you dropped your phone. Here you go but thanks to iExplorer I have all your documents and contacts now! Is this an issue? Depends what you use your email for!

Ever tried doing it in "a few seconds"? It takes several minutes in fact.

Re: Mailbox iOS app is a security fail

#22
post #7

Earlier quoted context omitted.

This is correct @nezza. I should have verified this with my friend's iPhone first. But the original issue still remains the same which is the files are not protected!

They aren't protected if you go into the app and look at the files (probably turning data off first). If you can unlock the phone, you've almost certainly already lost here.

There are so many things one can do if he/she has access to your entire mail folder or contacts (by copying it using iExplorer or similar forensic tools) Vs just browsing few emails. Talking about attachments, one can in this case get access to all your local attachments in another case probably he/she needs to forward those emails to an email id to access.

Re: Mailbox iOS app is a security fail

#23
post #17

“if anyone else can get hold of your phone, he can access to files of those apps where data is not protected.” As always, if someone has physical access and unlimited time, no device or computer is safe. Also, Mailbox.app only supports GMail. Security minded people are obviously not the target market.

If you get physical access you can also read all the mails in Apple's Mail.app, or any other app on the device. Maybe not using a tool, but you can easily read them in the app, forward them, and send fake e-mails using the account of the user. (edited to make my point more clear :)

That's not entirely correct. If the app uses the correct APIs to inform the system that particular files need more protection, then those files receive more protection. The details are available to a free dev account on Apple's developer site. As long as the device remains locked, such files remain encrypted.

Whether users pick appropriate passwords is another matter entirely.

Re: Mailbox iOS app is a security fail

#24
post #16
post #12

Earlier quoted context omitted.

So therefore, your article could have been titled "{Mailbox|GMail|iMail|all_other_mail_clients_ever} is a Security Fail!"? Because as far as I am aware, few mail clients either support or (if they do) actively encourage an extra password layer, and your users do not want it . Given an average un-password-protected phone, you will be able to read their email even if they were using the iOS encrypted files framework, j…

@tmpajk How does it make Mailbox more secure. Let's talk about the scenario where you have access to an iPhone for few minutes. In one case, you can go through some contents, in another case you can copy all emails and contacts. My whole point is files or attachments on information on every app that has sensitive information should be protected. There are various ways to do it on iOS! One can use keychain to store so…

[deleted]

Re: Mailbox iOS app is a security fail

#25
post #4

An important fact is wrong: You actually need to unlock the device to access the data unless the iPhone and the computer were paired before.

Don't have any data on this, but I know a bunch of not-so-tech-savy people that don't use lock codes. Their data's then as naked as a greek nude.

The very fact that so many apps (Facebook, Twitter, Mail etc) remain signed in while not in use prompted me to use a lock code (albeit with a 5 min grace period, a trade off for convenience). I can't see why anyone wouldn't want it enabled.

I think most devices paired with an ActiveSync (Exchange, GMail) account are required to use lock codes.

Re: Mailbox iOS app is a security fail

#26
post #20
post #16

Earlier quoted context omitted.

@tmpajk How does it make Mailbox more secure. Let's talk about the scenario where you have access to an iPhone for few minutes. In one case, you can go through some contents, in another case you can copy all emails and contacts. My whole point is files or attachments on information on every app that has sensitive information should be protected. There are various ways to do it on iOS! One can use keychain to store so…

Where is the key kept then? One possibility, the user has to know it, at which point we're back to the fact that users dont seem to want a password for their email app (again, happy to see an interesting post on the generalities of email app security). The other approach is to store it somewhere on the phone, at which point connecting the phone to a computer as you describe is still an attack vector; you just need to…

One can keep a secret key anywhere other than Document or Library directory of such apps. One of the obvious place will be device keychain.

Re: Mailbox iOS app is a security fail

#30
I'm less concerned about physical access to the device, but more concerned about third-party services like Mailbox increasing the number of attack vectors on your inbox. Mailbox has total access to your email account. Now somebody can either attempt to hack Google's servers, or Mailbox's servers. It's enough to convince me not to sign-up for their service since email provides the gateway to virtually everything else.
Post reply on HN