Menu
Apple warns customers to be cautious of SMS after 'flaw' cited

Apple warns customers to be cautious of SMS after 'flaw' cited

While SMS is a relatively mature technology, in recent years it has attracted the interest of security researchers as an attack vector

Apple has a message for texters: Don't trust SMS.

The consumer electronics heavyweight has advised iPhone users concerned about secure messaging to use the company's iMessage service instead of their carrier's SMS network.

While SMS is a relatively mature technology, in recent years it has attracted the interest of security researchers as an attack vector for smartphones.

Apple made its recommendation in a statement Saturday after a well-known iPhone jailbreaking artist explained in a posting on the Internet how a "flaw" in Apple's implementation of SMS in its mobile operating system, iOS, could be used to spoof SMS messages.

The flaw is in all versions of iOS, including the latest beta of the next release of the operating system, version 6.0, beta 4, according to the security researcher known as pod2g.

"Apple takes security very seriously," the company said in its statement. "When using iMessage instead of SMS, addresses are verified which protects against these kinds of spoofing attacks."

"One of the limitations of SMS is that it allows messages to be sent with spoofed addresses to any phone, so we urge customers to be extremely careful if they're directed to an unknown website or address over SMS," it added.

Pod2g explained that the SMS flaw allows the sender of the message to enter an address on its reply line that's different from the address that appears on its "from" line.

Creating such a message doesn't require rocket science, according to Derek Halliday, a senior security product manager with Lookout Mobile Security. "It is relatively trivial to create a message with the header that is described [by pod2g]," he told PCWorld.

Because iOS uses the information from the "Reply To" line to identify the origin of the message, its sender can make it appear as if it came from someone trusted by the recipient of the message. Once the sender gains the recipient's trust, they can divert the recipient, through malicious links in the message, to a website where sensitive information can be pried from the target.

A simple solution to the SMS problem would be for iOS to display both the original and "reply to" addresses for a message. Then, if the two addresses don't match, a recipient could smell something phishy and take appropriate precautions.

There are a number of sites on the Web, like spoofsms.net and spooftexting.com, for sneaky people and pranksters but it seems that spoofing in the United States isn't as easy as it is in other countries, according to a website called smsspoofing.com.

"The United States is probably the most difficult to spoof text messages to from our tests," it said. "We've never seen a spoofed SMS properly go through to a mobile phone in the US or Canada."

"We're not sure of the technical reasons for this, but the carriers seem to have set themselves up in a way to avoid this," it added.

Follow freelance technology writer John P. Mello Jr. and Today@PCWorld on Twitter.


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Featured

Slideshows

Leading female front runners of the Kiwi ICT industry honoured at 2019 WIICTA

Leading female front runners of the Kiwi ICT industry honoured at 2019 WIICTA

Reseller News has honoured the leading female front runners of the New Zealand ICT industry at the 2019 Women in ICT Awards (WIICTA) in Auckland. The awards recognised standout individuals across six categories, spanning Entrepreneur, Rising Star, Shining Star, Community, Technical and Achievement. Photos by Gino Demeer.

Leading female front runners of the Kiwi ICT industry honoured at 2019 WIICTA
Reseller News kicks off awards season in 2019 with Judges' Lunch

Reseller News kicks off awards season in 2019 with Judges' Lunch

The 2019 Reseller News Innovation Awards has kicked off with the Judges Lunch in Auckland with 70 judges in the voting panel. The awards will reflect the changing dynamics of the channel, recognising excellence across customer value and innovation - spanning start-ups, partners, distributors and vendors. Photos by Christine Wong.

Reseller News kicks off awards season in 2019 with Judges' Lunch
Reseller News welcomes industry figures for 2019 Hall of Fame lunch

Reseller News welcomes industry figures for 2019 Hall of Fame lunch

Reseller News welcomed 2018 inductees - Chris Simpson, Kendra Ross and Phill Patton - to the third running of the Reseller News Hall of Fame lunch, held at the French Cafe in Auckland. The inductees discussed the changing landscape of the technology industry in New Zealand, while outlining ways to attract a new breed of players to the ecosystem. Photos by Gino Demeer.

Reseller News welcomes industry figures for 2019 Hall of Fame lunch
Show Comments