|
|
||
|
Source : http://timesofindia.indiatimes.com
Activity:
0 comments
67 views
last activity : 02 14 2011 09:41:49 +0000
|
||
|
|
Companies that let staff use iPhone and iPad for business have been warned that hackers could steal passwords from the device in just six minutes even if its lock is enabled.

The hack, which could seriously compromise a corporation's critical infrastructure, was uncovered by experts in Germany and allows attackers to break into a lost or stolen phone simply by removing its SIM card and following a brief procedure, the Sydney Morning Herald reported.
Experts at Germany's state-sponsored research institute Fraunhofer SIT said in a statement, "Within six minutes the institute's staff was able to render void the iPhone's encryption and decipher the passwords stored on it.
"If the iPhone is used for business purposes then the company's network security may be at risk as well. Only companies prepared for such an attack will be able to reduce their risk."
The attack targets Apple's password management system, known as a "keychain", which scrambles all passwords and login information on the iPhone.
It can compromise iPhone and iPad with the latest software version installed even if they have the software "screen lock" turned on.
Once an attacker has access to the phone, the first step is to install "jailbreaking" software, which a small number of iPhone owners do voluntarily so they can download apps unauthorised by Apple.
From here, the attacker downloads a programme on to the phone that is able to decrypt passwords held on it, most notably for Google Mail accounts and for private company networks.
"As soon as attackers are in the possession of an iPhone or iPad and have removed the device's SIM card, they can get hold of email passwords and access codes to corporate VPNs (virtual private networks) and WLANs (wireless local area networks) as well," the researchers said in a statement.
"Control of an email account allows the attacker to acquire even more additional passwords: for many web services, such as social networks, the attacker only has to request a password reset."
Jens Heider, the technical manager of the Fraunhofer SIT security test lab, said many companies have a false belief that the high-security phones lent to employees are impenetrable to such attacks.
"This opinion we encountered even in companies' security departments," Heider said. "Our demonstration proves that this is a false assumption. We were able to crack devices with high-security settings within a very short time."
Graham Cluley, a security expert at Sophos, said the vulnerability could turn serious if hackers choose to put the attack method in the public domain.
"Others may well try to do this and publish the tools to do it, so it is quite serious," he said. In its latest earnings call last month, Apple said that a large number of Fortune 500 and FTSE 100 companies were "testing or deploying" the iPhone and iPad.
Cluley said companies using Apple's popular smartphone need to put pressure on the technology firm to fix the issue as soon as possible. "This is embarrassing for Apple, because they want people to believe they have a trusted enterprise device. What's important is how quickly they can patch this," the newspaper said citing Cluley.
After all this do you feel like owning an iPhone??
|
|
|
|
|
|
|
|
Thanks for sharing important information. Internet has completely changed the way we look at things.. |
The new models, the E6 and the X7, will go on sale for 340 euros ($491.6) and 380 euros respectively excluding subisidies and taxes, later this quarter. In February, Nokia's new chief executive Stephen Elop dumped Symbian software -- which lost... |
No ways there is a lot more than just video games but yes excessive use of video games can harm in other ways like it reduces physical activities, interaction time, eating habits and harms eyes. |
