<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/researcher_claims_iphone_apps_could_spy_on_you.php" />
  <link rel="self" type="application/atom+xml" href="http://www.readwriteweb.com/atom.xml" />
  <id>tag:www.readwriteweb.com,2011:/1/tag:www.readwriteweb.com,2010://1.18109-</id>
  <updated>2011-08-16T15:53:13Z</updated>
  <title>Comments for Researcher Claims iPhone Apps Could Spy on You</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.35-en</generator>
  <entry>
    <id>tag:www.readwriteweb.com,2010://1.18109</id>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/researcher_claims_iphone_apps_could_spy_on_you.php" />
    <link rel="service.edit" type="application/atom+xml" href="http://www.readwriteweb.com/cgi-bin/mt/mt-atom.cgi/weblog/blog_id=1/entry_id=18109" title="Researcher Claims iPhone Apps Could Spy on You" />
    <published>2010-02-04T17:13:23Z</published>
    <updated>2010-02-04T17:42:53Z</updated>
    <title>Researcher Claims iPhone Apps Could Spy on You</title>
    <summary>Swiss researcher Nicolas Seriot claims it&apos;s possible for &quot;rogue&quot; applications to make their way into the iTunes App Store where they could then be used to steal personal data from victims&apos; iPhones. According to Seriot&apos;s research, the problem has to with Apple&apos;s lax approval process for applications as well as a flaw in an iPhone...</summary>
    <author>
      <name>Sarah Perez</name>
      
    </author>
    
    <category term="Apple" />
    
    <category term="Security" />
    
    <content type="html" xml:lang="en" xml:base="http://www.readwriteweb.com/">
      <![CDATA[<p><img src="http://www.readwriteweb.com/images/iphone_logo_aug08.jpg">Swiss researcher <a href="http://docs.google.com/viewer?url=http://seriot.ch/resources/talks_papers/iPhonePrivacy.pdf">Nicolas Seriot claims</a> it's possible for "rogue" applications to make their way into the iTunes App Store where they could then be used to steal personal data from victims' iPhones. According to Seriot's research, the problem has to with Apple's lax approval process for applications as well as a flaw in an iPhone security feature that provides access to more data than is necessary. If a malicious application was installed on someone's iPhone, it could use this loophole to quietly harvest personal data including phone numbers, address book information, the phone's unique identifier and more. Then, using the phone's Internet connection, it could send that data back to remote servers, all unbeknownst to the iPhone's owner. </p>]]>
      <![CDATA[
<p>In his speech at this week's <a href="http://www.blackhat.com/html/bh-dc-10/bh-dc-10-home.html">Blackhat</a> security conference in D.C., Seriot demonstrated how an attack such as this would work. Using a proof-of-concept application he dubbed "SpyPhone," he was able to retrieve the 20 most recent web searches, YouTube viewing history data, keyboard cache, phone number, and email account parameters including the email address, host, and login information (sans password) from an Apple iPhone.</p>

<h2>Introducing "SpyPhone"</h2>

<p><img src="http://www.readwriteweb.com/images/spyphone.png" align="right">The SpyPhone application works because of what Seriot considers a security flaw in one of the iPhone's "sandboxing" mechanisms. On the device, installed applications are prevented from reading each other's data or accessing specific locations, such as the Music Library, for example. However, they are still able to read the data contained in a number of system and application preference files where personal data is contained.</p>

<p>This illegally harvested data could be retrieved by a malicious application and then sold on the black market to identity thieves or could simply be used for spying purposes. Some of Seriot's examples of the possible dangers are a bit far-out though, as they have him imagining the attackers using the data for everything from blackmail to robbery to virtual stalking.</p>

<p>In addition, <a href="http://www.blackhat.com/html/bh-dc-10/bh-dc-10-home.html">as pointed out on the Mac Security Blog</a>, any computer application has access to <em>some</em> information on the system on which it's installed. Besides, allowing iPhone applications access to things like your address book is considered a <em>feature</em>, not a <em>bug</em>. The real problem is that users may or may not be aware of what an application has access to and what the application is doing with that information. </p>

<p><a href="http://news.cnet.com/8301-27080_3-10446402-245.html?part=rss&amp;tag=feed&amp;subj=iPhoneAtlas">According to Elinor Mills at CNET</a>, some developers have already abused their access to this personal data. both intentionally and unintentionally: "A game called Aurora Feint was uploading all the user contacts to the developer's server, and salespeople from Swiss road traffic information app MogoRoad were calling customers who downloaded the app," she says. "Game app Storm8 was sued last fall for allegedly harvesting customer phone numbers without permission, but it later stopped that practice. And users also complained that Pinch Media, an analytics framework used by developers, was collecting data about customer phones." </p>

<p>However, to date, there have been no reports of the collected data actually being used for nefarious purposes. </p>

<h2>What Can Be Done?</h2>

<p>To protect yourself from these sorts of threats, Seriot recommends iPhone owners clear out their browser's search history regularly, clean the keyboard cache in the phone's Settings and remove or change the phone's declared phone number. </p>

<p>He also recommends that Apple introduce security features that would allow users to opt-out of having usage data sent from their iPhone back to developers' servers. Applications could also be further locked down to the point where they would have to ask permission to access your address book. </p>

<p>At the end of the day, though, there's really no way for consumers to know for sure what their applications are doing. Still, the risks of using an iPhone aren't significantly greater than those involved with using a computer. What consumers should take away from all this is that privacy isn't guaranteed when going online - whether that's on a laptop or via a web-connected mobile application. </p>]]>
    </content>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2010://1.18109-comment:220745</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2010://1.18109" type="text/html" href="http://www.readwriteweb.com/archives/researcher_claims_iphone_apps_could_spy_on_you.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/researcher_claims_iphone_apps_could_spy_on_you.php#c220745" />
    <title>Comment from Hidden Video on 2010-06-28</title>
    <author>
        <name>Hidden Video</name>
        <uri>http://www.hiddenvideo.org/</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://www.hiddenvideo.org/">
        <![CDATA[<p>Not surprising that the ipod spys on you. Jeez.</p>]]>
    </content>
    <published>2010-06-29T01:20:22Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2010://1.18109-comment:199021</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2010://1.18109" type="text/html" href="http://www.readwriteweb.com/archives/researcher_claims_iphone_apps_could_spy_on_you.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/researcher_claims_iphone_apps_could_spy_on_you.php#c199021" />
    <title>Comment from Danik on 2010-03-24</title>
    <author>
        <name>Danik</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Tune into other people's conversations with AudioZoom.</p>

<p>AudioZoom turns your iPhone into a spying device that transmits sound over a distance of up to 65 feet in real time. No one will ever know you are spying on them.</p>

<p>Download it here:<br />
<a href="http://itunes.apple.com/app/audiozoom/id359796186" rel="nofollow">http://itunes.apple.com/app/audiozoom/id359796186</a></p>

<p>More info:<br />
<a href="http://www.sourcewizz.com/audiozoom/" rel="nofollow">http://www.sourcewizz.com/audiozoom/</a></p>]]>
    </content>
    <published>2010-03-24T16:53:02Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2010://1.18109-comment:192349</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2010://1.18109" type="text/html" href="http://www.readwriteweb.com/archives/researcher_claims_iphone_apps_could_spy_on_you.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/researcher_claims_iphone_apps_could_spy_on_you.php#c192349" />
    <title>Comment from Slade on 2010-02-23</title>
    <author>
        <name>Slade</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>real simple way to prevent any spying from someone on your iphone. since the spy software has to manually installed by the spy, is to download the "gotcha pro alarm system" application, and if there is another application that uses encryption that could be the 2nd line of defense.  So if someone tries to move your phone, the alarm sounds and they will be locked out.  <a href="http://appshopper.com/productivity/gotcha-locked-security-motion-alarm-system" rel="nofollow">http://appshopper.com/productivity/gotcha-locked-security-motion-alarm-system</a> </p>

<p>So nobody can figure out an way to prevent spying, well I think my plan should work.  since nothing else seems to work. </p>]]>
    </content>
    <published>2010-02-23T17:03:55Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2010://1.18109-comment:186735</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2010://1.18109" type="text/html" href="http://www.readwriteweb.com/archives/researcher_claims_iphone_apps_could_spy_on_you.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/researcher_claims_iphone_apps_could_spy_on_you.php#c186735" />
    <title>Comment from Vehicle tracking on 2010-02-08</title>
    <author>
        <name>Vehicle tracking</name>
        <uri>http://vehicletrackers.org</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://vehicletrackers.org">
        <![CDATA[<p>Horrible, I have already heard about iPhone tracking software.</p>]]>
    </content>
    <published>2010-02-08T08:27:27Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2010://1.18109-comment:186077</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2010://1.18109" type="text/html" href="http://www.readwriteweb.com/archives/researcher_claims_iphone_apps_could_spy_on_you.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/researcher_claims_iphone_apps_could_spy_on_you.php#c186077" />
    <title>Comment from crowdedroad on 2010-02-04</title>
    <author>
        <name>crowdedroad</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Talking of spying... the Security Cam turns your iPhone into a spy camera. <br />
<a href="http://itunes.apple.com/us/app/security-cam/id300220373" rel="nofollow">http://itunes.apple.com/us/app/security-cam/id300220373</a></p>

<p>Disclosure - we built it :)<br />
</p>]]>
    </content>
    <published>2010-02-04T18:44:30Z</published>
  </entry>

  <entry>
    <id>tag:www.readwriteweb.com,2010://1.18109-comment:186066</id>
    <thr:in-reply-to ref="tag:www.readwriteweb.com,2010://1.18109" type="text/html" href="http://www.readwriteweb.com/archives/researcher_claims_iphone_apps_could_spy_on_you.php"/>
    <link rel="alternate" type="text/html" href="http://www.readwriteweb.com/archives/researcher_claims_iphone_apps_could_spy_on_you.php#c186066" />
    <title>Comment from taranfx on 2010-02-04</title>
    <author>
        <name>taranfx</name>
        <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
        <![CDATA[<p>Well, BlackHat people claim that "Tracking apps" may be already there on App Store.. My article on same [2 months old] <a href="http://bit.ly/cl0WN5" rel="nofollow">http://bit.ly/cl0WN5</a></p>]]>
    </content>
    <published>2010-02-04T18:01:54Z</published>
  </entry>

</feed>
