Ce parere aveti de treaba asta?
http://www.youtube.com/watch?v=uVGiNAs-QbY
In 6 minute, ruland un script urcat prin ssh pe iphone, se pot afla toate parolele din keychain. Totul a fost facut de un institut german specializat in securitate IT.
Eu unul am ramas foarte dezamagit sa vad acest lucru.
Explicatia bresei de securitate o vedeti mai jos:
“The researchers jailbreak the device then install SSH. They then copy a keychain access script to the phone. The script uses system functions to access entries in the keychain and outputs the details to the attacker.
The attack works because the cryptographic key on current iOS devices is based on material available within the device and is independent of the passcode, the researchers said. This means attackers with access to the phone can create the key from the phone in their possession without having to hack the encrypted and secret passcode.
“As soon as attackers are in the possession of an iPhone or iPad and have removed the device’s SIM card, they can get a hold of e-mail passwords and access codes to corporate VPNs and WLANs as well,” said the researchers in a statement. “Control of an e-mail account allows the attacker to acquire even more additional passwords: For many web services such as social networks the attacker only has to request a password reset.” - via iClarified