Live data from Hacker News

Mailbox iOS app is a security fail

subhb.org

51–60 of 60 posts

Re: Mailbox iOS app is a security fail

#51
post #30

I'm less concerned about physical access to the device, but more concerned about third-party services like Mailbox increasing the number of attack vectors on your inbox. Mailbox has total access to your email account. Now somebody can either attempt to hack Google's servers, or Mailbox's servers. It's enough to convince me not to sign-up for their service since email provides the gateway to virtually everything else.

This. Why is no one talking about this massive elephant in the room? Mailbox wants you to trust it (and its employees) with (reversibly-encrypted? I haven't used the app but I don't know how it could provide all its features without this) access to and storage of your Gmail account and all your emails?! I barely trust Google with that.

This article just helps compound the idea that that trust might be a little misplaced....

Re: Mailbox iOS app is a security fail

#52
post #31

Earlier quoted context omitted.

How about making it more secure! Won't it solve the problem? It's just not about Mailbox app it's about all the apps that should protect user's data. Should they care about their user's data or leave it up to the device to protect it?

No. Sorry but encryption doesn't really solve the problem. If you lose the device with valuable info on it, the info will be recovered even if it's encrypted.

Encryption absolutely solves the problem. Otherwise any kind of online security would be impossible.

You might need to use an actual strong password though and not the 4 digit passcode.

Re: Mailbox iOS app is a security fail

#53

“if anyone else can get hold of your phone, he can access to files of those apps where data is not protected.” As always, if someone has physical access and unlimited time, no device or computer is safe. Also, Mailbox.app only supports GMail. Security minded people are obviously not the target market.

You are confusing access to the computer itself with access to the data it contains.

Given physical access and "unlimited" time (i.e. no more than a million human lifetimes, say), then certainly an attacker can gain access to the device and make it do what he wants.

However, if the data on the device is securely encrypted, then physical access and (reasonable) time doesn't matter. He won't be able to get at the data.

Re: Mailbox iOS app is a security fail

#54
Can someone verify this with an iOS5 device. On iOS 6.1.3 this doesn't work anymore though. But someone just claimed this on the blog: "I ran a test using my iPhone 5 and a computer I’ve never synced with before. I didn’t need to unlock the phone before getting access to it I don’t believe. I did manage to browse all my mailbox files."

Re: Mailbox iOS app is a security fail

#55
Mailbox.app is a security concern because it copies all of your Gmail to it's own cloud server, and delivers the email to the app from there. Sure, it's exposing your emails on the device. I'm more concerned about them exposing _everyone's_ emails when their cloud platform is exploited.

Re: Mailbox iOS app is a security fail

#56
post #30

I'm less concerned about physical access to the device, but more concerned about third-party services like Mailbox increasing the number of attack vectors on your inbox. Mailbox has total access to your email account. Now somebody can either attempt to hack Google's servers, or Mailbox's servers. It's enough to convince me not to sign-up for their service since email provides the gateway to virtually everything else.

Mailbox was nice, but I dropped it after a week when your point occurred to me. As far as I could tell, the only reason it needed full access was for push notifications. There was no discussion at all of account security, and I just couldn't bring myself to trust them. There's no way one of the usual cutesy startup apologies would cut it here if they compromised my email.

I'm back to Sparrow now (which doesn't do push) and quite happy: Mail.app tells me I have a new message, then I process my emails in Sparrow.

Re: Mailbox iOS app is a security fail

#57
post #54

Can someone verify this with an iOS5 device. On iOS 6.1.3 this doesn't work anymore though. But someone just claimed this on the blog: "I ran a test using my iPhone 5 and a computer I’ve never synced with before. I didn’t need to unlock the phone before getting access to it I don’t believe. I did manage to browse all my mailbox files."

You don't need to sync your device to pair it. This someone may have connected his unlocked device to the computer, which is enough to pair the device. Once a device is paired, the file system can be browsed regardless of lock status.

I have not tested with a new 6.1.3 device yet, but if true, this would be a very serious security regression.

Re: Mailbox iOS app is a security fail

#58
post #47

Earlier quoted context omitted.

Sure, but that's also like saying "car accidents are inevitable, so let's not put on our seat belts". A basic bit of security, especially one that doesn't put any more load on the user (to have to maintain or set up) is a pretty big no-brainer. Raising the bar for a successful hack is also worth doing when the cost is a single line of code and no effort on the user's part.

If we're using analogy it's more like telling bicycle riders to use anti-puncture tape. Sure, it'll reduce the chance of getting a puncture but does nothing when they go under a truck. What's on offer here? 10 minutes extra tamper resistance? For a protocol which is inherently insecure?

Email in may not be generally secure but it is still easier to plug a phone into a computer than to access someone's email account without knowing their credentials. 10 minutes could be the difference between someone copying your emails from your lost iPhone and said person being unable to copy anything because you remote wiped your phone.

Re: Mailbox iOS app is a security fail

#59
post #5

Earlier quoted context omitted.

Does that mean that basic security should not be in a company's mind, especially when it comes to the kind of data emails can contain? Mailbox is BIG. We are not talking of an average app here!

“Does that mean that basic security should not be in a company's mind” I wasn’t suggesting it shouldn’t be. My point is that the article’s headline is overly dramatic: Mailbox.app is not a complete security failure because of one hack that requires physical access. Given that Mailbox only supports GMail, I’d be more worried to put my email in Google’s hands than worrying over someone grabbing my phone out of mine. “M…

> Mailbox.app is not a complete security failure because of one hack that requires physical access

The problem is that we take mobile devices with us every place we go. So physical access is not difficult to obtain.

This really is a big deal primarily because the developers of Mailbox.app did not take steps to even obfuscate the stored data...which would deter all but the most determined of attackers.

Re: Mailbox iOS app is a security fail

#60

“if anyone else can get hold of your phone, he can access to files of those apps where data is not protected.” As always, if someone has physical access and unlimited time, no device or computer is safe. Also, Mailbox.app only supports GMail. Security minded people are obviously not the target market.

[deleted]
Post reply on HN