ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Mobile devices Toolkit

The pros and cons of iPhone security

Robert Vamosi CNET News.com

Published: 29 Jun 2007 14:23 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment
The pros and cons of iPhone security

Few people standing in line to buy an iPhone when it is launched in the US will be focusing on the security of Apple's new phone. But some influential security researchers already have given the matter lots of thought.

Take Neel Mehta, a security expert at IBM's Internet Security Systems, which typically focuses on perimeter security for large corporations.

Overall, Mehta thinks the iPhone's security will be better than other smartphones on the market, and he credits the lack of a software developer kit (SDK) from Apple as a definite positive. The absence of an SDK will make writing malware much more challenging, he said, and inexperienced criminals will be scared off. "It doesn't make it impossible," Mehta said, "just harder".

Mehta thinks the iPhone will attract a more sophisticated criminal who's attracted to the challenge of hacking a complex system. Also, with Symbian OS-enabled phones currently occupying 40 to 50 percent of the world market, most petty thieves will still be drawn to the lower-hanging fruit.

The iPhone is likely to be one of the most complex smartphones that we've seen to date. As such, it will be challenging to have to a completely secure code base

Q: What is the biggest security threat to the iPhone?
A: The number of eyes that will be drawn to the iPhone platform itself and all the applications that run on it, that's probably the biggest security risk for the iPhone itself in that it will be undergoing a tremendous amount of scrutiny, probably more so than any of these applications have seen before. In the end, we'll get a better understanding of how secure the entire code base is and how these applications withstand thousands of eyes looking at them. Do you think some early adopters will be targeted by criminals online? Early iPhone users by definition are going to be wealthier than the average person. And for a criminal, there's bound to be payoff in stealing the personal data of someone like that.
The people who are going to buy (the iPhone) are the people who have $500 (£250) to spend on a smartphone and are fairly technology savvy as well. Again, it's a phone and its also, from my understanding, being marketed in a consumer space, and has features that are much more attractive to consumers instead of businesses in terms of the ability to download and play media of all different types on it, and so on.

So businesses are likely to have employees that use it, but in terms of sanctioned IT use within an enterprise environment it's probably not going to be that common. It's always possible that there will be attackers who will launch sophisticated attacks against someone with an iPhone, but there are a lot of other mobile devices that are much more common within an enterprise environment, such as the BlackBerry for example, that are more interesting targets — at least in the short term.

You mentioned that the iPhone's being marketed as a consumer phone. That means there will be a lot of media-rich applications preinstalled. How will that affect the overall security of the device?
You can look at it as a portable computing device, more so than any other mobile phone, in its traditional sense, so it is going to have to understand many different types of multimedia formats. It will be able to play audio, video, pull that content off the wireless network, or off a PC that it's connected to. It will also understand email. It will contain, possibly, a full-featured version of Mac OS X, and so the complexity of the device makes it more challenging to secure.

Read this

iPhone roundup
iPhone: What you need to know

As Apple unveils the mobile to end all mobiles, ZDNet.co.uk looks at what all the fuss is about

Read more +

We're seeing this with all the different smartphone platforms — as they become more complex, have more features built into them, they also have more opportunities for hackers to break into them. The iPhone is likely to be one of the most complex smartphones that we've seen to date. As such, it will be challenging to have a completely secure code base… And so we're likely to see the need for updates for the iPhone as flaws are discovered. >

Speaking of flaws, there have been a few exploits developed recently for Mac OS X vulnerabilities. Mac OS X is based on Unix. Isn't it likely, with the increased interest in Mac OS, that someone will start porting over existing Unix exploits and trying them against the Mac?
Mac is based off or derived from BSD Unix. The OS X that's running on iPhone will most likely be derived from the same original code base. But, the one thing that will probably be a huge factor in how easy it is to port exploits over is the processor that's in the phone. At the moment we don't know for sure what that processor will be. If it's an Intel-based processor, then it will be very similar to the current generation of Mac computers. There probably won't be that much difficulty for attackers to port exploits from existing Mac platforms over to the iPhone.

But if it turns out to be an ARM processor, for example, that's different. ARM has the biggest share of the processor market for mobile devices. That may be something a little bit new for the people who have been writing exploits for the Unix environment or for the Mac computing devices. If there's a change in processor architecture, it may take them a little bit of time. It's something that…

Next

Previous

1 2


  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
6 out of 10 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

C# / ASP.Net / AJAX / Javascript / Warrington 3-6 Months

C# / ASP.Net / AJAX / Javascript / Warrington 3-6 Months I have an E-Commerce client in Warrington which is looking for 2 C#, ASP.Net, SQL Server ...

JavaScript / AJAX / Web 2.0 development role

So to gain this role you will need TECHNICAL skills in Object Orientated JavaScrip and JavaScript libraries such as Yui, Ext, JQuery, Gears etc ...

Front End Developer - AJAX, YUI, GWT, JSP

Front End User Interface Developer - AJAX, JSP, XHTML, CSS, HTML. The project is leading the way in mobile internet and is a great project to work ...

Featured Talkback

Put simply, what is the compelling reason to pay ~$200 extra for an Eee with Windows XP? A Windows Eee won't come with any useful applications and you'll have to buy anti-virus software to boot. The truth about low cost computing is that nobody really cares whether the machine is running Windows or Linux as long as its cheap, its easy to use and it works.

By: dogStar

Read full story:
Asus to ship 60 percent of Eee PCs with Windows XP

On The Road Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Eee 1000 + iPhone 3G = the ultimate mo...

Having left the comforting bosom of ZDNet.co.uk to strike out on my own as a freelance journalist recently, I found myself contemplating a shocking truth – I was going to have to shell... More

Post a comment

Think Your Skype Call is Secure? Read...

There is growing, and credible, speculation that Skype has built in a back door to allow monitoring of SKype calls. Heise Online has a good article about it. So, what we have now... More

Post a comment

Discussions

harpless harpless

SAP goes big business

Friday 25 July 2008, 6:17 PM

1 comment
pjc158 pjc158

Will Drizzle rain on Sun's MySql

Friday 25 July 2008, 5:30 PM

1 comment
pjc158 pjc158

Show me the money!

Friday 25 July 2008, 5:18 PM

5 comments