Here’s a scary statistic: If your iPhone is lost or stolen and the thief knows what they’re doing, they can get the handset to cough up passwords stored in its keychain in only six minutes -- without ever having to crack through your passcode.
MacStories is reporting that German researches have shown that the iPhone is vulnerable to having the keychain exploited, even with Apple’s current passcode system in place. Like Mac OS X, the keychain is where iOS stores all of your passwords and other key data, which is easily hacked using an existing jailbreak exploit.
“Once jailbroken, the researchers installed an SSH server on the iPhone and install a keychain access script,” MacStories reveals. “This keychain access script utilizes functions that are built within the phone to access passwords and other data stored in keychain which is then outputted to the attacker.”
The discovery was made by researchers at the Fraunhofer Institute of Secure Information Technology, who explain “the attack works because current iOS devices have a cryptographic key that is based on data within the device and not based on the passcode,” MacStories says. “As a result, an attacker can gain access to the internal iPhone data through a jailbreak and then access all the information required to get into the keychain.”
In case you’re thinking that this attack will only give up website passwords that can be easily changed, think again -- it also includes “data such as the passwords for Google Mail, Microsoft Exchange accounts, voicemail, Wi-Fi passwords and some app passwords are fully compromised and accessible to an attacker with physical access to someone’s iPhone.”
Hopefully the jailbreak exploit isn’t one currently in use by the Dev Team, since Apple will likely plug this hole rather quickly. Have a look at just how easy it is with the embedded video below -- and in the meantime, hang onto those iPhones, folks!
MacLife: Looking to buy something cool for cheap? Check out our weekly lineup of discounted Macs, apps and iOS accessories. http://t.co/jQGLVSPKgT24 min 1 sec ago
MacLife: RT @alexlimcw: Reading @MacLife magazine on Newsstand while sipping a cup of tea at the local café. Life's real good just like that.25 min 43 sec ago
MacLife: Logitech to roll out wired iPad keyboard, because pairing keyboards with iPads in classrooms full of 'em is a hassle. http://t.co/vsHo0y05qp1 hour 32 min ago
MacLife: Not on enough social networks? The imo messenger app is expanding its focus with a new Broadcasts feed. http://t.co/66pLgxQek51 hour 50 min ago
MacLife: BlackBerry founder confident of BBM's iOS success, MediaFire adds media streaming, and more in our overnight recap. http://t.co/BuXapP3jsG2 hours 9 min ago