On TV.com: Is DEXTER a Little Boring This Season?
BNET Business Network:
BNET
TechRepublic
ZDNet

September 10th, 2009

iPhone's anti-phishing protection offers inconsistent results

Posted by Dancho Danchev @ 2:39 pm

Categories: Apple, Browsers, Data theft, Hackers, Malware, Passwords, Phishing, Spam and Phishing, iPhone

Tags: Apple iPhone, Apple Safari, Fraud, Phishing, Cyberthreats, Spam, Smart Phones, Security, Consumer Electronics, Dancho Danchev

Apple’s iPhone OS 3.1 update includes a new fraud warning feature which is at least theoretically, supposed to warn users when visiting fraudulent websites in Safari Mobile.

However, due to a flawed implementation in the update mechanism, the feature — enabled by default — is offering inconsistent results based on the tests performed by security company Intego, and security researcher Michael Sutton from Zscaler, whose posts basically state that “it simply doesn’t work“.

Here’s how they tested the feature:

The tests were conducted by pulling data of valid phishing sites from the Phishtank, and attempting to visit these sites in Safari and Safari Mobile, which resulted in their successful detection in Safari, but didn’t trigger a warning when visiting the same sites on the iPhone’s Safari Mobile.

The cause for these inconsistent results appears to be a flawed update mechanism, lacking any transparent way of communicating when was the last time an update took place, as well as a built-in “valid time” interval indicating that an outdated anti-phishing database is in use.

A few minutes ago, Intego posted an update to the original post in regard to the varying results:

We’ve had a number of people test this, and some people get warnings for sites that others can load just fine. We’ve tried isolating locations, iPhone/iPod touch models, and whether they are connecting over a cell network or via wifi, but all we’ve come up with is that sometimes it works and sometimes it doesn’t. This is clearly more dangerous than no protection at all, because if users think they are protected, they are less careful about which links they click.

The company makes a good point, however, there are several more issues to consider. For instance, in comparison to Safari Mobile’s fraud warning feature and its lack of transparency into the update mechanism, a commercial iPhone app called Site Check is utilizing the SafeBrowsing API in between offering a transparent way of knowing the last time a database update took place, with the option to manually pull one at any particular moment in time. This very same practice should also be implemented in the fraud warning feature.

Moreover, an assessment of the fraud warning feature at Macworld, points out that compared to Google Classic run on Safari Mobile, Google Mobile isn’t showing potentially harmful and fraudulent web sites, once again leaving users with the impression that they’re surfing the web and clicking on links under the umbrella of the SafeBrowsing initiative.

Transparent processes and customerization always translate into improved customer satisfaction, in this particular case, improved security as well.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 8 Talkback(s)
ZDNet = Horrid reporting.
Jeez! One story about someone hacking into a jailbroken iPhone using the SSH installed during the jailbreak and suddenly all this 'made up' nonsense!

To make matters worse ZDNet regurgitates a 2 month old story for more hits! ZDNet - you are a JOKE!... (Read the rest)
Posted by: No More Microsoft Software Ever! Posted on: 11/03/09  (Edited: 11/03/09 @ 07:00) You are currently: a Guest | | Terms of Use
But Apple says just the opposite  NonZealot | 09/10/09
At least they're trying...  UsernameRequired | 09/10/09
silly  Hagbard_Celine | 09/11/09
Fail on all counts  NonZealot | 09/11/09
Please. Don't drag the Macbook PRO and MacPro adverts into iPhone.  No More Microsoft Software Ever! | 09/15/09
RE: iPhone's anti-phishing protection offers inconsistent results  Hagbard_Celine | 09/11/09
Time for retraction  matthew_maurice | 09/12/09
ZDNet = Horrid reporting.  No More Microsoft Software Ever! | 11/03/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline