Why has Apple not fixed well known iPhone security problems?

Mobility

Nearly three months ago a security researcher did the right thing and informed Apple that he had found some serious vulnerabilities that impacted upon the security of the iPhone. Isn't it about time that Apple responded in kind by releasing a fix already?

Although Apple has just released a security fix for Apple TV it has yet to address vulnerabilities regarding the security of the iPhone that it was made aware of back in July.

Indeed, Apple was treated to full disclosure regarding the problems a few weeks before the public was informed they existed. Now the security researcher who originally uncovered those two vulnerabilities, Aviv Raff, has had enough of being Mr Nice Guy.

The Israeli researcher, best known for his work in the area of browser vulnerability, writes that it is custom to eat an apple and honey for a sweet Jewish new year, yet "this year starts a little sour for Apple."

Fed up with the lack of any meaningful response from Apple to his reported security vulnerabilities, and Raff insists that despite his requests Apple has refused to provide any fix schedule, he has now published the technical details for all to see.

One can understand his frustration as he watches iPhone firmware v2.0.1, then v2.02 and now v2.1 come and go but still no sign of what is actually quite a serious security flaw being any the nearer to a fix.

The iPhone v2.1 update did fix a total of 8 security vulnerabilities when it was released on September 12th, but the ones detailed by Raff were not amongst them. Which he finds rather surprising.

"Both issues are pretty trivial" Raff insists, adding that they can be "easily fixed by Apple."

Now Raff has adopted a tactic of full public disclosure that he has used in the past to apply pressure to vendors, but which he views as very much the strategy of last resort reserved only for companies that act irresponsibly as he accuses Apple of doing on this occasion.

How do the vulnerabilities that Raff has revealed impact upon the security of iPhone users? More on page 2...

CONTINUES



SPONSORED PRESS RELEASES

Websense Security Labs Reports ‘User Trust’ Targeted Attacks; Over 1 in 10 ‘Top Search’ Results Categorised as Malware; Increased Focus on Web 2.0
Websense, Inc. today revealed the findings from its bi-annual research report: Websense Security Labs, State of Internet Security, Q3-Q4 2009.

Featured IT jobs

A varied DBA role that involves multitasking in a dynamic software development environment dealing with challenging customer needs on a daily basis.
Skills Tags:   Linux  Oracle  UAT
A position has just become available for experienced Program/Project Manager to join a large organisation on a major Data Centre upgrade....
Skills Tags:   SAP
URGENT! Experienced BDM needed for senior sales role in Melbourne - must have ITSM consultancy sales experience.
Skills Tags:   C  Development  EDI  IT
CRITICAL INCIDENT COORDINATOR - 24 x 7 shifts - 3 month CONTRACT ONLY...
Skills Tags:   Excel  IT  ITIL  Management  Reporting

Editors Picks

Stories you may have missed 

What iTWire offers for free

E - mail News SMS Headlines Desktop Alerts News Feeds Job Alerts Technology Events Press-Releases