Live data from Hacker News

Root vulnerability found in iPhone OS, exploitable via SMS

tech.yahoo.com

21–30 of 31 posts

Re: Root vulnerability found in iPhone OS, exploitable via SMS

#21
This won't be a problem, and that prognosis has nothing to do with the fact that it's the iPhone that's affected. The carriers own the networks. Unlike Internet worms, which spread "in the wild", these messages would have to pass through the carriers' networks to get from one iPhone to another. The carriers can just filter them out, whether the phones are patched or not.

Re: Root vulnerability found in iPhone OS, exploitable via SMS

#22
>For starters, the stripped-down version of the OS presents fewer options for attackers, removing applications and features such as support for Adobe Flash and Java, which they might otherwise be able to exploit for vulnerabilities.

What does that even mean? It would be more vulnerable if it had Java installed?

Re: Root vulnerability found in iPhone OS, exploitable via SMS

#23
post #7

This is not a big problem, because the fix can be forsed through its update system, like microsoft doing it. Similiar vulnerability for Symbian OS is a big thing, because almost no one updates their phone's firmware. =)

Nope, the iPhone doesn't support over-the-air updates. Apple can patch it in the next version of the OS, but no one's gonna get the update without a computer.

Re: Root vulnerability found in iPhone OS, exploitable via SMS

#24
post #5

Why do they mention all the security features of the OS when it doesn't help one bit against this rootkit? It sounds almost as an PR how iPhone is secure! On another point, from an AT&T memo: On June 25, the day Michael Jackson died, text messages sent on our network spiked at 65,000 messages per second I wonder how much would it be if somebody made this into an exploit sending it to the whole address book.

I imagine it would be whatever the capacity of the network before melting down is. If it consecutively gets sent to the entire address book, and there are a lot of iPhones out there, that is some fast exponential growth.

Re: Root vulnerability found in iPhone OS, exploitable via SMS

#25
post #15
post #8

Earlier quoted context omitted.

But they would have better infrastructure to deal with it than any other cell provider. (iTunes, retail stores, etc.)

Except that competing smartphones (BlackBerry, Android, Pre, etc) almost all do OTA updates which is more reliable and doesn't require the user to keep up to date on their computer.

Do you know for sure that the iPhone doesn't support OTA updates, or are you just guessing based on the fact that Apple hasn't done one yet?

Re: Root vulnerability found in iPhone OS, exploitable via SMS

#26
post #22

>For starters, the stripped-down version of the OS presents fewer options for attackers, removing applications and features such as support for Adobe Flash and Java, which they might otherwise be able to exploit for vulnerabilities. What does that even mean? It would be more vulnerable if it had Java installed?

More code, more bugs. More bugs, more vulnerabilities.

Re: Root vulnerability found in iPhone OS, exploitable via SMS

#27
post #22

>For starters, the stripped-down version of the OS presents fewer options for attackers, removing applications and features such as support for Adobe Flash and Java, which they might otherwise be able to exploit for vulnerabilities. What does that even mean? It would be more vulnerable if it had Java installed?

Considering the ridiculous number of exploits based on "Quicktime for Java", I wouldn't bet against it...

Re: Root vulnerability found in iPhone OS, exploitable via SMS

#28
post #21

This won't be a problem, and that prognosis has nothing to do with the fact that it's the iPhone that's affected. The carriers own the networks . Unlike Internet worms, which spread "in the wild", these messages would have to pass through the carriers' networks to get from one iPhone to another. The carriers can just filter them out, whether the phones are patched or not.

Filtering them means analyzing the SMS contents, right? Is that legal?

Re: Root vulnerability found in iPhone OS, exploitable via SMS

#29
post #21

This won't be a problem, and that prognosis has nothing to do with the fact that it's the iPhone that's affected. The carriers own the networks . Unlike Internet worms, which spread "in the wild", these messages would have to pass through the carriers' networks to get from one iPhone to another. The carriers can just filter them out, whether the phones are patched or not.

Of course it would be a problem, due to the fact that they can't respond instantaneously. In order to block these messages, AT&T would have to first 1) realize that there is a problem, 2) figure out what to filter, 3) implement the filter. By the time they did all this, the worm would have already spread to most phones which are turned on. It could easily infect 500,000 phones before AT&T were able to respond.

If, for example, someone released a worm which sent an infected SMS to all contacts and proceeded to permanently destroy the device's baseband, ruining 500,000 iPhones before AT&T implemented a filter, how much money do you think Apple is going to have to spend in repair costs and lost future sales from the bad PR?

Re: Root vulnerability found in iPhone OS, exploitable via SMS

#30
post #5

Why do they mention all the security features of the OS when it doesn't help one bit against this rootkit? It sounds almost as an PR how iPhone is secure! On another point, from an AT&T memo: On June 25, the day Michael Jackson died, text messages sent on our network spiked at 65,000 messages per second I wonder how much would it be if somebody made this into an exploit sending it to the whole address book.

I imagine it would be whatever the capacity of the network before melting down is. If it consecutively gets sent to the entire address book, and there are a lot of iPhones out there, that is some fast exponential growth.

Networks in Britain routinely fall over on New Years' Eve...
Post reply on HN