Security Review: iPhone

By duschang at 1:45 pm on March 16, 2008Comments Off on Security Review: iPhone

iPhone offers lots of convenient functionality, such as phone, internet, music play and etc., making it a communication power house. However, it also opens up lots of new security risks. Since there is already an security review on iPhone 3rd party apps, I will focus on iPhone it self.

Assets:

  • Personal information
  • Contact lists of friends, family or customer
  • Financial information
  • Credibility of the user
  • Credibility of Apple

Adversary:

  • Competitor/Enemy of apple
  • Apple itself?
  • Ex-employees from Apple
  • Identity theft
  • Anyone with bad intention

Potential Weakness:

  • Connection could be sniffed, especially if connect through unsecure wireless network
  • iPhone could be lost/stolen physically. Phones are easier to loose then computer
  • User activities are collected by Apple.(says in the contract that Apple will collect user data to “better” server them) So lots of personal information will be leaked, if adversary get access to Apple’s database.

Potential Defense:

  • Make sure only connect to reliable connection
  • Prevent accessing any private/important information from iPhone
  • Make back up of all information from iPhone
  • Don’t use iPhone?
Filed under: Security ReviewsComments Off on Security Review: iPhone

Comments are closed.