Saturday, March 9, 2013

Apple fixes App Store flaw by turning on encryption



Wi-Fi is one of the biggest source of data insecurity and data loss. Although, the iOS had for long been suffering from privacy attacks over Wi-Fi, Apple has been rather slow in providing security to its iOS customers.

Now news is that Apple has 'finally' fixed a security flaw in its application store that for years has allowed attackers to steal passwords and install unwanted or extremely expensive applications.

The flaw arose because Apple neglected to use encryption when an iPhone or other mobile device tries to connect to the App Store, meaning an attacker can hijack the connection. In addition to a security flaw, the unencrypted connections also created a privacy vulnerability because the complete list of applications installed on the device are disclosed over Wi-Fi, says Declan McCullagh at C|net.



Security researcher Elie Bursztein discovered the vulnerability and reported it to Apple last July. Apple fixed the problem in a recent update that said "content is now served over HTTPS by default." Apple also thanked Bernhard Brehm of Recurity Labs and Rahul Iyer of Bejoi.

Bursztein's blog post comes a day after Apple's marketing chief, Phil Schiller, took a security-related swipe at Google on Twitter by pointing to a report on the rise of Android malware.

Read more about it at: C|net

0 comments:

Post a Comment

Twitter Delicious Facebook Digg Stumbleupon Favorites More