Subscribe to EDN

iPhone Hacks And Security Risks: Whaddya Know, Apple Was Serious

November 11, 2009

Back in September 2007, Apple warned iPhone owners not to jailbreak and carrier-unlock their handsets, citing the potential for permanent inoperability that might result and noting that such damage would not be covered by warranty protection. Since then, the company has regularly repeated such statements, expanding them to include the potential for security breaches to networks on which the jailbroken iPhone (or iPod touch, for that matter) was operating. And as regular readers already know, I chose to ignore those warnings a few months ago.

In retrospect, my nonchalance wasn’t wise (particularly since it’s reminiscent of past situations). My T-Mobile-enabled iPhone 3G is still running iPhone firmware v3.01, since jailbreak software for the latest-generation v3.12 firmware only recently became available. And I haven’t enabled the jailbroken operating system’s SSH server capabilities via the OpenSSH software available from Cydia. Nonetheless, I was very concerned when I learned the other day that a worm had been developed which exploits the ‘alpine’ default mobile (user) and root passwords used by the iPhone’s variant of Mac OS X.

The technique used by the worm developer is pretty clever. A compromised iPhone randomly polls IP addresses on its network; when it finds other jailbroken handsets with SSH enabled and the default password still in place, it installs itself on them (and ironically then helpfully disables inbound SSH capabilities); the worm subsequently spreads. This initial variant of the malware is fairly innocuous; all that it does is change the handset’s screen wallpaper to an image of a particularly annoying 80’s musician. But since the source code has been published, I think you can imagine how it could be adapted for far more nefarious purposes.

As I said above, I don’t have SSH enabled. Nonetheless, I went ahead and changed the mobile and root accounts’ common password, since SSH is conceivably not the only way that someone might attempt to gain control of my handset going forward. I followed these instructions, installing the MobileTerminal application in the process. Another set of instructions I subsequently found gives more detailed information on installing MobileTerminal.

Again, this particular issue only applies to jailbroken iPhones. Nonetheless, the open source nature of both the code that was circumvented and the code used to do the circumvention reminds me of a diatribe I wrote 2.5 years back. To be fair, users are encouraged to change the default operating system passwords as part of the OpenSSH installation, but I’d lean towards the even stronger step of making password update a flat-out requirement. More generally, this situation is a reminder of the inherent weakness of open source software; it’s open to inspection by both friendly and unfriendly coders. Therefore, if you employ open-source software in your designs, you’re responsible for keeping it up-to-date as a response to any vulnerabilities discovered in it, even after the system is purchased by an end customer.

Posted by Brian Dipert on November 11, 2009 | Comments (7)

February 5, 2010
In response to: iPhone Hacks And Security Risks: Whaddya Know, Apple Was Serious
Install Software commented:

Another great post. Thanks for the tips and help. Everyone, bookmark this site.


November 18, 2009
In response to: iPhone Hacks And Security Risks: Whaddya Know, Apple Was Serious
Brendan commented:

As others have already stated. The security issue that was exposed had _nothing_ to do with the fact that it was open source. Open source software is, in general, quite secure. Security through obscurity is, in my opinion, a _much_ larger risk than open source software.


November 12, 2009
In response to: iPhone Hacks And Security Risks: Whaddya Know, Apple Was Serious
Jason Vargas commented:

I have been using open source for over 18 years now and can say the only virus I ever got was from a commercial copy of Novell Netware (Michelangelo if you care to know). Also, care of Microsoft, I got a worm, but mostly because I didn't have my firewall enabled. Well maintained systems are really the best bet regardless of open/closed source. One could argue that if iPhone's OS was open source there would not be a problem maintaining the software in any case.


November 11, 2009
In response to: iPhone Hacks And Security Risks: Whaddya Know, Apple Was Serious
simple solution commented:

execute all hackers and virus authors. draconian? So what.


November 11, 2009
In response to: iPhone Hacks And Security Risks: Whaddya Know, Apple Was Serious
Bubbax12 commented:

"Inherent weakness" is undoubtedly wise terminology in the eyes of your advertisers but unnecessarily slants an interesting debate. Greed exists with vendors and consumers alike.


November 11, 2009
In response to: iPhone Hacks And Security Risks: Whaddya Know, Apple Was Serious
agreed... commented:

I don't consider this an inherent weakness of Open source. Security through obscurity ....isn't secure. It just has the poor illusion of additional security. In this case .. what is the point of a password default? Answer: to allow the changing of the password.. first time. If it isn't changed .. it effectively doesn't have any security. No change = no security Open source has no impact on this equation.


November 11, 2009
In response to: iPhone Hacks And Security Risks: Whaddya Know, Apple Was Serious
Jonno commented:

If the software was closed-source it would be much harder to even find out that this weakness existed.

POST A COMMENT
Display Name
captcha

Before submitting this form, please type the characters displayed above. Note the letters are case sensitive:

Advertisement
Advertisement
Advertisement
About EDN   |   Site Map   |   Contact Us   |   Subscription   |   RSS
© 2012 UBM Electronics. All rights reserved.
Use of this Web site is subject to its Terms of Use | Privacy Policy

Please visit these other UBM Canon sites

UBM Canon | Design News | Test & Measurement World | Packaging Digest | EDN | Qmed | Pharmalive | Appliance Magazine | Plastics Today | Powder Bulk Solids | Canon Trade Shows