Headlines >>›› Moto X Review: Say Hello to the Best Android Phone in the WorldHere’s One Important Area Where Some People Think the iPhone 6 Plus Falls Short$44 Worth of Awesome Paid iPhone Apps you Can Download for Free Right NowMissed Out on Preordering the iPhone 6? Here Are the Best Ways to Get One on FridayApple vs. the World: A Brief History of Failed Apple BashingToo Big, Too Small, or Just Right? Sizing up the iPhone 6 PlusThe Top 14 Hidden Features in Windows, iOS, and AndroidiPhone 6 Plus Shipping Now At 3-4 WeeksThe iPhone 6 Might be Low-Res, but Apple’s Highest-Resolution Device Ever is Coming SoonThis is What it Was Like to Preorder the iPhone 6

Gmail Users on iOS at Risk of Data Interception

Apple users accessing Gmail on mobile devices could be at risk of having their data intercepted, a mobile security company said Thursday.

The reason is Google has not yet implemented a security technology that would prevent attackers from viewing and modifying encrypted communications exchanged with the Web giant, wrote Avi Bashan, chief information security officer for Lacoon Mobile Security, based in Israel and the United States.

[ It's time to rethink security. Two former CIOs show you how to rethink your security strategy for today's world. Bonus: Available in PDF and e-book versions. | Stay up to date on the latest security developments with InfoWorld's Security Central newsletter. ]

Websites use digital certificates to encrypt data traffic using the SSL/TLS (Secure Sockets Layer/Transport Layer Security) protocols. But in some instances, those certificates can be spoofed by attackers, allowing them to observe and decrypt the traffic.

That threat can be eliminated through certificate “pinning,” which involves hard coding the details for the legitimate digital certificate into an application.

Unlike for Android, Google doesn’t do this for iOS, which means an attacker could execute a man-in-the-middle attack and read encrypted communications, Bashan wrote. Google acknowledged the problem after being notified by Lacoon on Feb. 24, but the problem has not been fixed, he wrote.

Google officials did not have an immediate comment.

It isn’t clear why certificate pinning isn’t used by Google on iOS. But three years ago, a Google security engineer that works on such security issues described a scenario where the handling of digital certificates becomes complicated.

Occasionally, proxy servers used by companies will intercept HTTPS connections using local, ephemeral certificates, wrote Adam Langley on his personal blog. Some security applications and parental control programs will also do this, he wrote.

Those certificates have the authority to override “pins” that have been set to check for a specific certificate, he wrote.

Lacoon described an attack scenario that involved tricking a user into installing an iOS device management configuration file that contains a malicious root digital certificate. That would validate a spoofed certificate, allowing the person to navigate to a fraudulent Gmail site.

“We were quite surprised by this finding because Google had implemented certificate pinning for their Android Gmail app,” Bashan wrote. “Clearly, not implementing this for iOS was an oversight by Google.”

Source: http://www.infoworld.com/d/security/gmail-users-ios-risk-of-data-interception-246018?source=rss_mobile_technology

VN:F [1.9.13_1145]
Rating: 0.0/10 (0 votes cast)
VN:F [1.9.13_1145]
Rating: 0 (from 0 votes)