NEWS / SMARTPHONES

iPhone's SMS security flaw doesn't exist in other OSes

| by Shunal Doke | Smartphones

There was a report earlier this month about a security flaw in iPhones where one could easily make the iPhone vulnerable to text message cheating. The flaw has existed since the iPhone was first launched back in 2007, and the flaw still hasn’t been fixed as of the beta for iOS 6. According to a report by CNET, the flaw doesn’t exist in smartphones that run on other operating systems.

"We have tested this issue on Android, Windows Mobile, BlackBerry, and Symbian phones and most of them simply ignore the 'reply address' field or display both the 'real' originating address and the reply address as per the specification recommendations," Cathal McDaid, security consultant at AdaptiveMobile, said in a statement to CNET. "The iPhone, so far, is the only device which does not comply with these security recommendations."

According to McDaid, the "reply to" field was there to provide a way to respond to texts from marketing firms or other agencies that may not be capable of receiving messages. These days, most handsets ignore the field. "Apple has left a significant vulnerability in its handsets which could allow consumers to be fooled and hand over personal details to hackers and criminals," says McDaid.

It's no iPhone 5, but it is a fresh new iPhone 4

The only phone with the SMS security flaw

 


Under the protocols handling the exchange of SMS (Short Message Service) text between mobile phones, the sender of a message can technically change the reply-to phone number to something different from the original number, the hacker who found the flaw, who goes by the alias Pod2g, explained. In a good implementation, the receiver of the message would see both the original phone number and the reply-to one. But using iPhone's SMS feature, when receivers see the message, it seems to come from the reply-to number, while the original phone number of the sender is hidden. The loophole means that someone could send iPhone users messages pretending to be from the receivers' banks or other trusted sources, asking for some private information, or cheating them to go to a dedicated website to obtain users' information.

Pod2g called the security flaw "severe" and urged Apple to fix it before the final release of the iOS 6 software. "Now you are alerted. Never trust any SMS you received on your iPhone at first sight," Pod2g wrote in the blog post .Apple Inc. could not be reached for comments.

Engadget had received this response from apple on the matter: “Apple takes security very seriously. When using iMessage instead of SMS, addresses are verified which protects against these kinds of spoofing attacks. One of the limitations of SMS is that it allows messages to be sent with spoofed addresses to any phone, so we urge customers to be extremely careful if they're directed to an unknown Web site or address over SMS.

Tags: iPhone SMS flaw , iPhone , , iPhone Security , iPhone Security Flaw , Apple , Apple iPhone

iPhone SMS Flaw Lets Hackers Control It

30 Jul, 2009, 03:20 pm IST

iPhone SMS Flaw Lets Hackers Control It

Apple Addresses SMS Security Hole

19 Aug, 2012, 09:08 pm IST

Apple Addresses SMS Security Hole

 


Micromax A110Q Canvas 2 Plus: A Specifications Review

Micromax A110Q Canvas 2 Plus: A Specifications Review

Apart from having a long name, there are some other interesting features...

By Shunal Doke

6 Things to look for when buying a 'future-proof' smartphone

6 Things to look for when buying a 'future-proof' smartphone

If you’re out looking for a new smartphone, then there are a couple of...

By Roydon Cerejo

Smartphone launches this week: May 13-17

Smartphone launches this week: May 13-17

In the hustle-bustle of everyday life, you might have missed the launch of

By Nikhil Subramaniam

MORE FEATURES

Nokia Lumia 720 Review

Nokia Lumia 720 Review

21 May, 2013, 01:00 PM IST

 7.0

We’ve already established that the Lumia 720 is Nokia’s best effort as far as Windows Phone 8 handsets go. This could soon change once the Lumia 925 hits markets, but as it stands now, the Lumia 720 offers the best blend of features and performance, wrapped in a beautiful package that’s quite affordable.

Samsung Galaxy S4 Review

LAVA iris 455 Review

Lenovo S890 Review

Nokia Lumia 520 Review

Sony Xperia E Dual Review

MORE REVIEWS