Research slams fickle iPhone security tool

New anti fraud measure from Apple "inconsistent"

  • Email to a friend
  • Print this article
  • Bookmark this page
  • RSS feed

The iPhone's new defence meant to prevent users from reaching phishing sites is inconsistent at best, a security researcher said today, with some users getting warnings about dangerous links, while others are allowed to blithely surf to criminal URLs.

Other experts said that the fickle feature is worse than no defence at all.

Apple quietly added an anti-fraud feature to the iPhone's Safari browser with the update to iPhone 3.1, released Wednesday. But according to Michael Sutton, the vice president of security research at Zscaler, the new protection is "clearly having issues".

Skype under attack for iPhone restrictions | Researcher finds iPhone flaw | Skype offered on iPhone... finally | New version of iPhone software next week

At first, said Sutton, the anti-phishing feature was simply not working. "It was blocking nothing," Sutton claimed after testing iPhone 3.1's new tool Wednesday against a list of known fraudulent sites. By Thursday, things had improved, but just barely. "Yesterday, it started blocking some sites, for some users, but it was inconsistent. Some sites are being blocked, others are not."

That led Sutton to believe that the feature's functionality wasn't the issue, but how Apple updates users with a "blacklist" of malicious sites. Apple relies on Google's SafeBrowsing API (application programming interface) for the underlying data used to build anti-phishing and anti-malware blocking lists for the desktop edition of its Safari browser. Other browser makers, including Google and Mozilla, also use SafeBrowsing.

"It appears some iPhones are getting timely updates, but others are not, or are getting different [block list] feeds," Sutton said. "I'm feeling better about the feature than I was Wednesday, but clearly Apple is still having issues. With the coverage of the problem, maybe they're resolving it, or trying to."

On Thursday, researchers at Intego, a Mac-only antivirus vendor, echoed Sutton's findings.

"This feature should warn users that they may be visiting a known malicious Web site and ask if they wish to continue," said Peter James, a spokesman for Intego who writes the company's Mac security blog . "However, we have extensively tested this feature, tossing dozens of phishing URLs at it, and it simply does not seem to work. URLs that are blocked by Safari in Mac OS X open and direct users to malicious pages [on the iPhone]."

Like Sutton, James reported inconsistencies in the anti-fraud feature's effectiveness. "All we've come up with is that sometimes it works and sometimes it doesn't," said James. "This is clearly more dangerous than no protection at all, because if users think they are protected, they are less careful about which links they click."

The new feature is turned on by default in iPhone 3.1. The option to turn it off is in Settings/Safari/Security, and is listed as "Fraud Warning."

Sutton, although willing to concede that Apple overall is improving its security track record, bemoaned the state of mobile security in general, and the iPhone's in particular.

"The greater concern to me is that we're making the same mistakes in mobile that we made on the desktop," he said. "On the desktop, security has gotten slowly better, but [with mobile] we have a fresh start. I would have thought we would have learned from our mistakes, but there's virtually no protection in mobile browsers."

According to research conducted by NSS Labs, which was hired by Microsoft to benchmark different desktop browsers' ability to block malware-laden sites, Safari in Mac OS X and Windows blocked only one-in-five malicious sites. Internet Explorer and Firefox, meanwhile, blocked 80% and 27%, respectively. Google's Chrome blocked a paltry 7% of the sites.

Last month, NSS Labs attributed the disparities between Firefox, Safari and Google, all of which use SafeBrowsing as the basis for their blacklists, to differences in how each browser tweaked, then applied, the lists.


Contact Us

For editorial queries:
Max Cooter max_cooter@techworld.com

For website issues:
Email webmaster@techworld.com

For commercial queries
Russell Kearney russell_kearney@idg.co.uk


For more contact details click here.

What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.


Characters remaining: 500

Related SME news

Freescale to build cheap tablet running Android and Linux

i.MX51 prototype showed off at Mobile World Congress

Salesforce.com down for North American customers

Twitter abuzz with irritated cloud users

Mozilla Jetpack ripped off our design, says MetaLab

Mozilla removes mock-ups of Jetpack editing tool from site

International Space Station partners shine light on science benefit

NASA and ESA claim big step forward in space research



Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Email archiving: Top 10 myths and challenges

This survey looks at a number of challenges and myths around email archiving that may also slow adoption of full archiving.

Download Whitepaper

Strategic mobile deployments

Deploying mobile applications? Supporting multiple devices? See why mobile platforms should be part of your IT strategy.

Download Whitepaper

Creating an AUP: Common myths & mistakes

Avoid the common myths & mistakes when implementing your AUP

Download Whitepaper

Legal risks of uncontrolled email and web use

Exploring the challenges facing IT Mangers today and vital steps to ensure safe internet an email use by employees.

Download Whitepaper

Techworld UK - Technology - Business

COLT White Paper

Virtualisation 2.0
Driving to higher ground beyond the basics

Virtualisation can deliver unparalleled efficiency and cost reductions to your business, allowing direct access to servers and guaranteeing a dependable, rapid response in times of crisis. Read this e-book to learn more about consolidation, discover the latest technologies and find out how to reduce the TCO of virtualisation.

Download E-Book
COLT White Paper

IT Misuse Survey

Complete this survey and you could win a Nexus One

Techworld are running a short survey to discover how UK businesses are managing Internet and email misuse in the Enterprise.

Complete Survey

Webcast: IT Financial Management: Cost Optimisation for Efficiency and Agility.
On Demand Webcast
Join this webcast to learn about the techniques and technologies that can help you prove the value of IT to the business by understanding the true cost of today's IT services and those that will be necessary to deliver future success.

Register Today

Site Map

IDG Network

* *