Mobile Tech Today

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
News & Product Reviews for Mobile Tech Users
Making the case for BYOD:
Powering Productivity.
Managing Mobility.

Download the White Paper
Tuesday, May 21st 
Introducing Simpana® 10 software
Home
Laptops & Tablets
Mobile Phones
Mobile Gadgets
Mobile Apps
BYOD & MDM
iPad
Mobile Industry News
Wireless Connectivity
Wireless Security
GPS & Maps
MTT Press Releases
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Advertisement


Apple/Mac

Apple Responds to SMS Vulnerability on iPhone

Apple Responds to SMS Vulnerability on iPhone
August 20, 2012 12:54PM

Bookmark and Share
The iPhone, in an overuse of elegant minimalism, only shows the SMS sender's name, not the sender's number. This means that a hacker could pretend to be a name in your contacts, or even a generic Mom, and fool an SMS recipient into believing an incoming message. Or, using a bank name, you could be tricked into sending back financial information.

Making the Case for BYOD. BuiIf you’re just beginning to develop your BYOD strategy or already have an established edict in place, this Forrester white paper which includes a list of benefits and costs associated with deploying a BYOD program can serve as a guide or a checkpoint for successful implementation. Click here download now.

There's a vulnerability in how Apple's iPhone handles SMS text messaging that could lead to spoofing or phishing attacks. That's the conclusion of a French security blog, to which Apple responded this weekend.

The technical details were itemized Friday on pod2g's iOS blog. It describes how iOS only displays the phone number of the Reply To field in an SMS text, while most mobile Relevant Products/Services devices show both the Reply To field and the originating number. Devices that process both originating and replying phone numbers can potentially compare them to make sure nothing is amiss.

'Never Trust Any SMS'

Consequently, the iPhone, in an overuse of elegant minimalism, only shows the sender's name, not the sender's number. This means that a hacker could pretend to be a name in your contacts, or even a generic Mom, and fool a recipient into believing an incoming message.

Or, if the sender knew your bank name, you could be tricked into sending back confidential financial information. As pod2g wrote, "never trust any SMS you received on your iPhone at first sight."

In a statement, Apple has suggested that the vulnerability was part and parcel of SMS technology and not particular to the iPhone, and it urged that iPhone users employ its iMessage application instead of SMS.

When using iMessage, the technology giant said, "addresses are verified which protects against these kind of spoofing attacks." The company added that one of SMS' limitations is that "it allows messages to be sent with spoofed addresses to any phone, so we urge customers to be extremely careful if they're directed to an unknown Web site or address over SMS."

Rules of Thumb

However, the iMessage protocol only works between Apple iOS devices, so Apple's fix does not cover the gamut -- unless everyone you know only purchases their mobile devices from the maker in Cupertino.

The possible consequences of such trickery could include not only fooling a user into turning over personal data Relevant Products/Services or playing a less-costly but nonetheless embarrassing prank on an unsuspecting iPhone owner. There could also be legal trickery as well, since SMS messages have been used as evidence in court, even though, as the new flurry makes clear, trickery using the technology is not that difficult.

General rules of thumb -- an appropriate term for this thumb-typed medium -- advise that users be wary of any text that is sent from someone not in your contacts. Additionally, one should be suspicious of texts that appear to come from a contact but which are wildly out of context for anything that contact would send. One example: your Mom suggesting you click a link to an unknown site. In fact, be extra wary of any request in a text message to click a link, regardless of the sender.

Tell Us What You Think
Comment:

Name:

Advertisement

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  Recharge Your Phone in 20 Seconds?
  Samsung Dangles $800,000 App Carrot
  MeeGo-Based Sailfish OS Launches
  Outgoing FCC Chair Reflects on Work
  Texting, Driving Teens Take Risks

 Technology Marketplace

BYOD & MDM
Build a business case for a BYOD program.
 
CRM Systems
Free Download: Understanding the Voice of the Customer
 
Cloud & Virtualization
Brocade technologies help enable the full benefits of virtualization.
Riverbed Stingray Traffic Manager on Amazon Web Services
 
Contact Centers
Unlock the potential in your people with Microsoft Dynamics
 
Customer Data
Free Download: Understanding the Voice of the Customer
 
Customer Service
Unlock the potential in your people with Microsoft Dynamics
 
Data Security
Simpana® 10 software: an exponential leap forward
 
Data Storage
Brocade makes it easier to deploy, manage, and scale networks.
 
Enterprise Software
Simpana® 10 software: an exponential leap forward
 
Mobile Apps
Build great mobile apps that drive engagement.
 
Network Security
Brocade makes it easier to deploy, manage, and scale networks.
 
Enterprise Software Spotlight

Should Enterprises Skip Over Windows 8?
Because of the interface changes and compatibility issues, most businesses will not adopt Windows 8 as their standard, but must be prepared to meet employee BYOD demand for it, Forrester Research says.

HP and SAP Team To Advance HANA Database Technology
The two tech leaders are working on a system that SAP says could fundamentally change the database market. HANA is SAP's technology that keeps data in-memory, for super fast processing.

Revlon Saving Millions with Microsoft Dynamics
The cosmetics giant is reporting millions of dollars in savings thanks to consolidating its enterprise resource planning by using Microsoft Dynamics ERP. Revlon CIO David Giambruno recently shared his story.

Advertisement
Navigation
Mobile Tech Today
Home/Top News | Laptops & Tablets | Mobile Phones | Mobile Gadgets | Mobile Apps | BYOD & MDM | iPad
Mobile Industry News | Wireless Connectivity | Wireless Security | GPS & Maps | MTT Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2013 Mobile Tech Today. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.