nCircle.com >> nCircle Blog >> Sync

« Many Microsoft Bulletins Replaced; Bigger Set of Kill Bits Issued | Main | Time For Apple To Embrace A Security Development Lifecycle »

No surprise - we have more Apple iPhone security flaws

No surprise - we have more Apple iPhone security flaws

This time there is a security hole that bypasses access restrictions and it highlights again that Apple favors functionality over security. In this case, even when a user chooses to physically secure the device with a four digit passcode, the user still has access to some functionality. If someone selects "emergency call", that user can then gain access to other options that eventually provide almost complete access to the phone, without ever having to enter a passcode.

This highlights a fundamental design deficiency with the iPhone, and flies in the face of Steve Jobs' declarations about iPhone security. Even with some of the recent improvements in security, Apple internal decision making process always chooses functionality and aesthetics over security. The most recent demonstration of this internal bias is the quick release of updates to fix 3G connectivity issues this year, but security updates generally take several months.

I don't think this is an acceptable level of risk for most enterprises, and it's probably too much risk for many consumers. Until Apple begins to publicly address the fundamental design, development and process issues that move security to the back burner, enterprises will be forced to remain skeptical about the iPhone and will have to worry about the protection of confidential data on the device.

TrackBack

TrackBack URL for this entry:
http://blog.ncircle.com/cgi-bin/mt-tb.cgi/303

Comments (1)

Ben:

There is a quick fix for this. You can set the double tap to take you somewhere else, a calculator for instance, as opposed to more dangerous menu it defaults to.

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

Verification (needed to reduce spam):

Bio

Blog: Sync
Author: Andrew Storms

As nCircle's Director of Security Operations, Andrew Storms is responsible for setting and enforcing the company's security compliance programs as well as overseeing day-to-day operations for the Information Technology department. He is a Certified Information Systems Security Professional (CISSP).

About

This page contains a single entry from the blog posted on August 29, 2008 2:15 PM.

The previous post in this blog was Many Microsoft Bulletins Replaced; Bigger Set of Kill Bits Issued.

The next post in this blog is Time For Apple To Embrace A Security Development Lifecycle.

Many more can be found on the main index page or by looking through the archives.