On TechRepublic: Five super-secret features in Windows 7
BNET Business Network:
BNET
TechRepublic
ZDNet

June 26th, 2007

The iPhone security non-story

Posted by Ryan Naraine @ 12:17 pm

Categories: Apple, Botnets, Browsers, Data theft, Digital rights management, Exploit code, Hackers, Metasploit, Open source, Passwords, Patch Watch, Pen testing, Punditocracy, Responsible disclosure, Spam and Phishing, Spyware and Adware, Viruses and Worms, Vulnerability research, Zero-day attacks

Tags: Apple iPhone, Security, David Maynor, Ryan Naraine

In Focus » See more posts on: iPhone

David Maynor is hoarding his Safari browser flaws with his eyes on the iPhone.

As far back as January, hackers were asking questions about the iPhone CPU and preparing for attack scenarios.

The first hacker that breaks into the iPhone will generate lots of headlines/publicity but that’s right about where this story ends.

According to this NetworkWorld piece, Gartner will add to the ridiculous hypefest next Monday with a warning to enterprises:

We’re telling IT executives to not support it because Apple has no intentions of supporting (iPhone use in) the enterprise,” Gartner analyst Ken Dulaney says. “This is basically a cellular iPod with some other capabilities and it’s important that it be recognized as such.”

Do we really need a Gartner report to tell us that a storage device presents a data theft risk?

Dave Goldsmith from Matasano says it best:

Every device that walks into your organization is just another way for data to leave. Laptops, iPods, cell phones, PDAs and even the dreaded Furby have all gone through this same set of concerns.

Yes, somewhere deep inside of every enterprise is a small team of people that have to worry about data management. And yes, everytime something like this comes out, they have to write a bunch of policy blocking it. And then they have to start relaxing that policy as the devices become commonplace.

If you are responsible for keeping data inside of your organization, for the love of everything that is holy, please don’t spend too much time on the iPhone. Allow us to remind you about all of the data breaches that are happening thanks to insecure wireless access points, tape backups disappearing, wrapping your newspapers in customers’ personal financial information, and stolen laptops.

Space Rogue, a former L0pht member and editor of the Hacker News Network, agrees this is a non-story and argues that iPhone will be much more locked down and secure than your existing cell phone, thanks to the firmware auto-updating mechanism built into iTunes.

iPhone will run a modified version of OSX. That will likely include some form of FileVault, Apple’s encryption technology for user files. Thats right, encryption built right in. This hasn’t been announced and it might not be in there, but if the technology and the code already exist why not put it in?

iPhone looks to be just about as secure or even more so (no proprietary and closed backend) than a Blackberry, Treo, or Blackjack. Everyone saying otherwise is either a paid MS schill, astroturfing, or just plain idiots.

Bingo.

And the 25+ PR folks pitching me on iPhone security stories to hitch your clients’ wagon to the iPhone gravy train, you can stop now.

This is my last iPhone blog entry. Until Maynor or Halvar Flake breaks in.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 14 Talkback(s)
I Agree, Apple does a much better security job
and will with the iPhone too. I trust Safari much more than any other browser out there. Its secure not counting Java, but Java is not on the iPhone and not an Apple product anyway. So give me an OSX ... (Read the rest)
Posted by: ralphrides Posted on: 07/17/07 You are currently: a Guest | | Terms of Use
Surprising candor  YinToYourYang-22527499 | 06/26/07
Surprising candor indeed!  Mikael_z | 06/27/07
i agree  jjarman | 06/27/07
The moment  frgough | 06/27/07
C'mon, be fair  Ryan NaraineZDNet Moderator | 06/27/07
No matter how old he is, I peg Maynor as a kid.  JoshNorton | 06/27/07
puhleeeze  pcguy777 | 06/27/07
hah...  Stuka | 06/27/07
I have a rule  frgough | 07/17/07
French Like Blackberry FUD!!!  jjarman | 06/27/07
The iPhone is *TOO* enterprise-oriented for me  Resuna | 06/27/07
huh?  jjarman | 06/28/07
Gartner is right about 1% ...  bjbrock | 07/17/07
I Agree, Apple does a much better security job  ralphrides | 07/17/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here