Business Wire
http://www.sit.fraunhofer.de
February 09, 2011 08:53 PM Eastern Daylight Time 

According to Fraunhofer Institute SIT, iPhone Weakness Demonstrated That Encryption by Itself Does Not Provide Protection - Companies Have to React Quickly When iPhone is Lost

DARMSTADT, Germany--(BUSINESS WIRE)--Passwords are not secure on iPhones that are lost. This is the result of tests carried out at Fraunhofer Institute SIT in Darmstadt, Germany. Within six minutes the institute’s staff was able to render the iPhone’s encryption void and decipher the passwords stored on it. If the iPhone is used for business purposes then the company’s network security may be at risk as well. The flawed security design affects all iPhone and iPad devices containing the latest firmware. Written documentation and a video about the attack are available at http://www.sit.fraunhofer.de/en/forschungsbereiche/projekte/Lost_iPhone.jsp. Only companies prepared for such an attack will be able to reduce their risk.

“This opinion we encountered even in companies’ security departments”

Many people think that the Smartphone device encryption will provide sufficient security. “This opinion we encountered even in companies’ security departments," says Jens Heider, technical manager of the Fraunhofer SIT security test lab. “Our demonstration proves that this is a false assumption. We were able to crack devices with high security settings within a very short time.” The testers did not even have to break the 256 bit encryption to get to the passwords stored in the devices’ keychain. A weakness in the security design was used: The underlying secret the attacked password’s encryption is based on is stored in the device’s operating system. This means that the encryption is independent from the personal password, which is actually supposed to protect the access to the device.

Any device using the iOS operating system can be attacked in such a way, irrespective of the user’s password. As soon as attackers are in the possession of an iPhone or iPad and have removed the device’s SIM card, they can get a hold of e-mail passwords and access codes to VPNs, WLANs and company network accesses as well. Control of an e-mail account allows the attacker to acquire even more passwords: For many web services such as social networks the attacker only has to request a password reset. Once the respective service returns the new password to the user’s e-mail account the attacker has it as well.

Companies wanting to protect themselves against the consequences of such attacks should educate their staff accordingly and introduce appropriate emergency procedures. Employees who have lost their iPhone should change all their passwords, and companies should change the respective network identifications as quickly as possible. Jens Heider: “This reveals how well the security concept has been adapted to the mobile challenge.”

Contacts

Media:
Fraunhofer Institute SIT
Oliver Küch, +49 6151-869-213
oliver.kuech@sit.fraunhofer.de

Recent Stories

  • View Press Release View Press Release
    Fraunhofer integra las llaves en su smartphone
    October 05, 2012
    Graphic
    Translations Available
    DARMSTADT, Alemania--(BUSINESS WIRE)--En la feria de seguridad it-sa de Nuremberg, el Fraunhofer Institute for Secure Information Technology (SIT) (Instituto Fraunhofer para Tecnología de la Inform... more »
  • View Press Release View Press Release
    Fraunhofer: le chiavi nel tuo smartphone
    October 04, 2012
    Graphic
    Translations Available
    DARMSTADT, Germania--(BUSINESS WIRE)--Alla fiera commerciale sulla sicurezza it-sa di Norimberga, il Fraunhofer Institute per la tecnologia informatica sicura (SIT, Secure Information Technology) i... more »
  • View Press Release View Press Release
    Le Fraunhofer intègre des clés à votre smartphone
    October 04, 2012
    Graphic
    Translations Available
    DARMSTADT, Allemagne--(BUSINESS WIRE)--Lors du salon de la sécurité it-sa de Nuremberg, le Fraunhofer Institute for Secure Information Technology (SIT) présentera ShareKey, une solution smartphone ... more »
More Stories
RSS feed for Fraunhofer Institute SIT
http://www.sit.fraunhofer.de

Release Versions

  • EON: Enhanced Online News

Company Information Center

Fraunhofer Institute SIT RSS feed for Fraunhofer Institute SIT

Share

  • Facebook
  • Twitter
  • LinkedIn
  • Delicious
  • Reddit
  • StumbleUpon
  • Digg
  • MySpace
  • Newsvine
  • Google Bookmark
  • Yahoo! Bookmark
  • EmailEmail
Tweet
  • EmailEmail
All News
Business Wire

Site Navigation

  • Home
    • Home
    • Submit a Press Release
  • Services
    • Overview
    • Targeting
    • Distribution
    • Financial Disclosure
    • Measurement & Analytics
    • Event News Services
    • Media & Journalist Tools
  • News
    • All News
    • News with Multimedia
    • News by Industry
    • News by Subject
    • News by Language
    • Tradeshows & Events
    • Earnings & Conference Calls
  • Education
    • Overview
    • Sample Press Release
    • FAQ
    • Find Your News Online
    • How-to
    • Disclosure Resources
    • White Papers
  • About Us
    • Overview
    • Become a Member
    • Contact Us
    • Follow Us
    • Jobs
    • Business Wire Newsroom

Search

Advanced News Search
  • Log In
  • Sign Up

Follow Us

  • Twitter
  • LinkedIn

More from Business Wire

  • Blog
  • Apps
  • Canada
  • UK/Ireland
  • Deutschland
  • France
  • Italy
  • Japan
  • EON: Enhanced Online News
  • Tradeshownews.com
  • PYMNTS.com

Business Wire Information

  • Contact Us
  • Privacy Statement
  • Terms of Use
  • ©2013 Business Wire