Steer Clear of iOS 8's Infinite Loop

Technology

A flaw in iOS 8 allows hackers essentially to crash apps that perform SSLcommunications whenever they like. Skycure reported the bug at the RSA security conference held last week, advising owners of iOS devices to upgrade to iOS 8.3.

Apple this week confirmed that iOS 8.3 addresses the vulnerability, according to Skycure.

An attack would involve specially crafting an SSL certificate to regenerate a bug. SSL is used in almost all apps in the iTunes App Store, which means pretty much every device user running iOS 8 could be at risk.

The flaw is an SSL parsing vulnerability that affects iOS itself, and heavy use of affected devices will crash the OS, Skycure said.

Further, under certain conditions, affected devices can be put into a reboot loop, which locks them up. If the attack's coming through a WiFi network, victims can't disable the WiFi interface to stop it. They're stuck in what Skycure has dubbed a "No iOS Zone."

 

 

However, "we have not seen any instances [of exploits based on this vulnerability] in the wild," Skycure CEO Adi Sharabani told TechNewsWorld.
 

The No iOS Zone

Combining the iOS 8 SSL vulnerability with WiFiGate, which Skycure disclosed in 2013, or with the Karma tool, would let attackers form a No iOS Zone.

Attackers could automatically recruit any iOS device in range into what essentially would be a mobile botnet that could launch denial of service attacks on target iOS devices.

The possibility of such an attack is real, according to Simone Margaritelli, a developer and security researcher at Zimperium.

"I recently used a Karma attack against my updated iOS device, and it worked like a charm," he told TechNewsWorld.

Victims can't do anything about the No iOS Zone, Skycure said.

Follow the Money

"Mobile malware and WiFi hacks like the No iOS Zone are on the rise, driving a multibillion-dollar market opportunity for mobile security companies," said Steve Morgan, CEO of Cybersecurity Ventures.

"This is like the early days of antivirus, when the vendors were leapfrogging each other in the media as they each scurried to be the first one to report a bug," he told TechNewsWorld. "Companies ... who report a bug initially are poised for growth."
 

Nothing to Fear but Fear Itself?

Attacks exploiting the iOS 8 SSL vulnerability "will happen, but I would be much more worried about the prevalence of bugs in iOS that allow malicious apps or malicious websites to run code on the devices," said Marble SecurityCEO Dave Jevans.

"In the one month between the release of iOS 8.2 and iOS 8.3, Apple fixed 37 iOS security bugs, one of which also allowed denial of service attacks over the air," he told TechNewsWorld.

"There were also nine security bugs fixed that were related to malicious apps or websites taking over devices or running unauthorized code on them. The myth that iOS is secure is just that -- a myth," Jevans added.

The iOS 8 SSL vulnerability Skycure found is "similar to the Darwin Nuke flaw discovered by Kaspersky," said Jimmy Shah, senior director of research at Zimperium.

The current threat level for the vulnerability is low, he told TechNewsWorld, because "DoS is not persistent, and no code execution is involved."

Staying Safe

Users whose iOS devices keep on crashing or rebooting should disconnect from a troublesome WiFi network or change their location, Skycure recommended, and they should upgrade to version 8.3 post haste.

Users of iOS devices can enable the OS's "Ask to join networks" feature to protect themselves, Zimperium's Shah suggested.

"Android and iOS are constantly improving their security mechanisms," he remarked. Although iOS is generally believed to be the more secure of the two, "in reality [they] are equally secured, with pluses and minuses for each."

Taguri: Infinite Loop, of iOS 8's, Steer Clear

Technology
Related Content

7 Ways to Promote Your YouTube Channel

If you have decided to create a YouTube channel, you need to find the best ways to promote it. After all, if it is not being promoted, people aren’t going to know about it, and you will be simply wasting your time because you won’t be making any money.

The real reason why teenagers smoke is not addiction, it’s weight loss

Shunning popular beliefs that people smoke cigarettes because they’re addicted to the nicotine, a recent study shows that among teens who are frequent smokers, 46% of girls and 30%of boys smoke to control their weight.

HOW TO BUILD MUSCLE AND STRENGTH WITHOUT LIFTING WEIGHTS

Give yourself a break from all the heavy lifting and reap the muscle-building benefits of bodyweight exercise.

Who lives longest: meat eaters or vegetarians?

Our ability to live a long life is influenced by a combination of our genes and our environment. In studies that involve identical twins, scientists have estimated that no more than 30% of this influence comes from our genes, meaning that the largest group of factors that control how long a person lives is their environment.

How to Relieve Stress Through Music

Did you know there are simple, easy ways to tackle your stress – without spending a fortune? One of the best ways to relieve stress is through music; and we’ve got the science to back it up.


583