Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

The iPhone just lost its perfect security record — now what?
The Verge ^ | 6 Nov 2014 | Russell Brandom

Posted on 11/06/2014 10:14:15 AM PST by for-q-clinton

For most of the iPhone's lifespan, it's been effectively immune to malware. There were theoretical attacks and viruses targeting jailbroken phones, but thanks to the tight controls of the App Store, finding iOS malware in the wild has been nearly impossible. If you didn't jailbreak your phone and you weren’t targeted by the NSA, you simply didn't have to worry about catching a virus.

Yesterday, that changed. A security firm called Palo Alto Networks discovered a malware program they’re calling Wirelurker, which sneaks into computers through unauthorized Chinese apps, then attacks iOS devices when they connect over USB. It’s an obscure line of attack (when’s the last time you actually plugged your iPhone into your computer?), confined to China, and so far the effects have been minimal. The actual payload for non-jailbroken phones was just a test balloon, side-loading a comic book app to prove the attack really worked. Jailbroken phones got a nastier payload, infecting payment apps, but that's to be expected. Last night, Apple blocked the apps, saying "We are aware of malicious software available from a download site aimed at users in China, and we’ve blocked the identified apps to prevent them from launching. As always, we recommend that users download and install software from trusted sources." Less than 24 hours after Palo Alto Networks published its report, Wirelurker appears to be mostly wiped out. Still, that doesn't mean Apple is completely in the clear. The vulnerabilities exploited by Wirelurker will be around for much longer, and could pose a serious threat to Apple's otherwise spotless record. Now that the platform has had its first real virus scare, there's reason to think it won't be the last.

(Excerpt) Read more at theverge.com ...


TOPICS: Business/Economy; Crime/Corruption; News/Current Events; Technical
KEYWORDS: crap; iphone; malware; security
Navigation: use the links below to view more comments.
first previous 1-20 ... 121-140141-160161-180 ... 221-222 next last
To: Swordmaker

Oh? apple is now proprietary there too and soldereds to the motherboard? What IS a ‘Windows HD”. Who makes it? Segate? Western Digital?

Blather indeed.


141 posted on 11/06/2014 2:13:35 PM PST by Norm Lenhart (Feet to the fire folks. YOU PROMISED!)
[ Post Reply | Private Reply | To 135 | View Replies]

To: Swordmaker

I’m not the only person that has trouble getting cut and paste to work with Safari and iOS 8. It’s a known problem. The only fix for now seems to be use a different browser. I’m not an Apple hater, but when a basic function like cut and paste doesn’t work right it’s very annoying to say the least.


142 posted on 11/06/2014 2:18:09 PM PST by smokingfrog ( sleep with one eye open (<o> ---)
[ Post Reply | Private Reply | To 128 | View Replies]

To: Norm Lenhart
Why don't these hardware companies go Wintel then? Why not Linux? They are choosing to partner with Apple in a very proprietary way. Yet you don't seem to hold them to account and blame Apple (and apparently accept their blaming of Apple from your characterization of the issue). As their customer, why don't you demand they earn your money with a cross-platform solution?

This reminds me of the PC gaming industry years ago: for performance reasons, the game developers bypassed as much of the OS graphics hardware abstraction as they could. They would then get bit by every OS release as Microsoft made changes to the underlying graphics APIs. And everyone blamed Microsoft.

Another example: Microsoft and Intel data show that roughly 80%+ of the blue screens of death in Windows were when the hardware hung during a BIOS call. In other words, while you were not running the Windows OS. Again, Microsoft was blamed. Hence why they are a big supporter of EFI.

And as a final note: I bet Apple doesn't tell them "deal with it", I bet Apple suggests they "use the proper abstraction layers and APIs" to help abstract them from under the hood changes in OSX releases.

143 posted on 11/06/2014 2:26:00 PM PST by 5thGenTexan
[ Post Reply | Private Reply | To 137 | View Replies]

To: Norm Lenhart
Not at all. I am saying that Apple leaves you with their approved security choices ONLY and not apple lets you at least try to find your own or code them yourself.

Am I wrong?

Yes, you are abysmally wrong. Why not Google a bit and find out before opening your mouth and proving to everyone how ignorant and deliberately so you are? You might learn something before you spread your hate and bile.

Commercial anti-virus companies publishing for OS X Mac:

There are more, and many of those have apps for iOS, but that should be sufficient to demonstrate your FUD post.

144 posted on 11/06/2014 2:32:34 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 61 | View Replies]

To: 5thGenTexan

Because who are they going to sell to? All their customers are LOCKED into Apple with ALL of the ;other; choices they are forced into by Apple.

Because even Sony Pictures cannot afford to wholesale switch ALL of their massive investment any easier than Dicks corner Studio can with his comparitively modest. Cost scales.

THAT is why its purely Stalinist. It’s a virtual monopoly.


145 posted on 11/06/2014 2:38:20 PM PST by Norm Lenhart (Feet to the fire folks. YOU PROMISED!)
[ Post Reply | Private Reply | To 143 | View Replies]

To: Norm Lenhart
The point I am making is that Apple removes the very choice to do that.

Total ignorance. Apple OS X is a fully featured and open trademarked UNIX operating system. You REALLY ADONT KNOW WHAT YOU ARE TALKING ABOUT. Every Mac user is either a couple of keystrokes or clicks away from a fully functional UNIX Terminal, if they choose to use it.

146 posted on 11/06/2014 2:38:26 PM PST by Swordmaker (This tag line is a Microsoft insult free zone... but if the insults to Mac users continue...)
[ Post Reply | Private Reply | To 78 | View Replies]

To: Swordmaker

All of which are Apple/NSA backdoored correct?


147 posted on 11/06/2014 2:38:56 PM PST by Norm Lenhart (Feet to the fire folks. YOU PROMISED!)
[ Post Reply | Private Reply | To 144 | View Replies]

To: Swordmaker

Write an apple approved app and sell it outside Apple’s domain.See a problem here yet?


148 posted on 11/06/2014 2:41:29 PM PST by Norm Lenhart (Feet to the fire folks. YOU PROMISED!)
[ Post Reply | Private Reply | To 146 | View Replies]

To: 5thGenTexan

“And as a final note: I bet Apple doesn’t tell them “deal with it”, I bet Apple suggests they “use the proper abstraction layers and APIs” to help abstract them from under the hood changes in OSX releases. “

then you really need to talk to some software devs in the music biz. Because “Deal with it” had become a buzzword for them. They hear it often.


149 posted on 11/06/2014 2:44:18 PM PST by Norm Lenhart (Feet to the fire folks. YOU PROMISED!)
[ Post Reply | Private Reply | To 143 | View Replies]

To: Swordmaker

Run Arturia Jupiter 8V through Elisencer controlled by an SSL Matrix console on MaCUnix from a command line or controled by a Slate Raven MTX via command line and get back to me on how that worked out for you.

To save you 50K in cash and I will tell you how that ‘choice’ worked for Swordie in the real world.

Not at all.


150 posted on 11/06/2014 2:48:19 PM PST by Norm Lenhart (Feet to the fire folks. YOU PROMISED!)
[ Post Reply | Private Reply | To 146 | View Replies]

To: Swordmaker

Then I won’t worry about it.

:)


151 posted on 11/06/2014 2:54:07 PM PST by Salamander (People will stare. Make it worth their while.)
[ Post Reply | Private Reply | To 140 | View Replies]

To: Norm Lenhart; Salamander

>Now you did it. You’ll be branded a collaborator ;)<

Nah, she’s with me. I’ve got a Macbook, so I can play around with UNIX. And I have an iPhone, so thanks for the warning to stay off random Chinese App sites. I’ll make a note of it. :P


152 posted on 11/06/2014 2:55:24 PM PST by Darnright (We won!)
[ Post Reply | Private Reply | To 51 | View Replies]

To: Darnright

:)


153 posted on 11/06/2014 3:01:06 PM PST by Salamander (People will stare. Make it worth their while.)
[ Post Reply | Private Reply | To 152 | View Replies]

To: Norm Lenhart
Apple leaves you no prayer at all to even attempt to protect yourself.

To the contrary, the WireLurker victims took knowing and deliberate steps to AVOID Apple's "walled garden" protocols, getting apps from outside the Apple App Store and installing them via means not intended for such [ab]use.

While we may complain occasionally about Apple's app review process, this is a prime example of why it's in place and valuable. NO WireLurker-infected apps come from the Apple App Store. Get apps from there, and you won't have a problem.

154 posted on 11/06/2014 3:07:07 PM PST by ctdonath2 (You know what, just do it.)
[ Post Reply | Private Reply | To 47 | View Replies]

To: Darnright

What, you mean Itunes? ;)


155 posted on 11/06/2014 3:07:15 PM PST by Norm Lenhart (Feet to the fire folks. YOU PROMISED!)
[ Post Reply | Private Reply | To 152 | View Replies]

To: ctdonath2

Oh so Apple has not backdoored the NSA into everything then? What a relief.


156 posted on 11/06/2014 3:08:08 PM PST by Norm Lenhart (Feet to the fire folks. YOU PROMISED!)
[ Post Reply | Private Reply | To 154 | View Replies]

To: Norm Lenhart
nothing is secure.

If you deliberately bring weed-infested soil into a walled garden, don't be surprised by what grows there.

157 posted on 11/06/2014 3:08:25 PM PST by ctdonath2 (You know what, just do it.)
[ Post Reply | Private Reply | To 100 | View Replies]

To: Norm Lenhart

WTF are you talking about? What does NSA have to do with what I wrote?


158 posted on 11/06/2014 3:11:17 PM PST by ctdonath2 (You know what, just do it.)
[ Post Reply | Private Reply | To 156 | View Replies]

To: Salamander

And here I sit posting from mah (GASP) Winderz laptop. Oh, the embarrassment. (c;


159 posted on 11/06/2014 3:12:15 PM PST by Darnright (We won!)
[ Post Reply | Private Reply | To 153 | View Replies]

To: ctdonath2

Maybe you should read the entire series of posts about it where it was all covered above.


160 posted on 11/06/2014 3:18:42 PM PST by Norm Lenhart (Feet to the fire folks. YOU PROMISED!)
[ Post Reply | Private Reply | To 158 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-20 ... 121-140141-160161-180 ... 221-222 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson