Thoughtful, detailed coverage of the Mac, iPhone, and iPad, plus the TidBITS Content Network for Apple consultants.

Security News: Flash Attacked, iPhone Exposed, Spyware Discovered

It's been a rough few weeks for the security of Apple users due to the appearance of a serious zero-day vulnerability in Adobe Flash, Reader, and Acrobat; a major data access vulnerability on iPhones; and a nasty piece of spyware. Let's look at each of these in turn, with a focus on what you can do to protect yourself.

Problem: Major Unpatched Adobe Vulnerability -- On 4 June 2010, Adobe warned of a new, unpatched vulnerability in Flash and Reader that is being actively exploited. Current and older versions of Flash and Reader (including components installed with Acrobat 9) are vulnerable on multiple operating systems, including Windows and Mac OS X.

What you need to know. This is an extremely serious vulnerability that could allow an attacker to take control of your system. It is being actively exploited in the wild by attackers and there is no patch.

What we don't know is if Macs are being targeted. Nearly all of the information about this issue focuses on Windows. Still, since we know Macs are vulnerable, until more information appears it is only prudent to assume we Mac users are equally exploitable.

How to protect yourself. According to Adobe, the Flash 10.1 Release Candidate is not vulnerable and thus all Mac users should immediately install this pre-release software. (In the advisory linked to above, Adobe also includes a workaround for Windows systems).

If you have installed Adobe Reader or Acrobat you should open your PDF files using Apple Preview instead. If you still need to use Reader or Acrobat, be very careful which files you open and stick to trusted sources to the best of your ability. We don't know for certain if this will protect you, but it is highly likely that you need to open a malicious file to be exploited.

We previously covered Adobe's security problems with Acrobat and Reader in "Protect Yourself from Adobe Acrobat and Reader Vulnerabilities" (16 October 2009). The difference in this situation is that there is no patch, and the vulnerability is being actively exploited (at least on Windows).

Problem: iPhone and iPad Data Exposed -- Security blogger Bernd Marienfeldt has determined that if you connect any version of the iPhone to an Ubuntu computer when the phone is turned off, certain data is exposed. (Ubuntu is a Linux-based operating system.) Additional research at Heise Security discovered techniques to expose even more data.

What you need to know. This vulnerability appears related to the techniques I described in "iPhone 3GS Hardware Encryption Easy to Circumvent," 07 August 2009. (In the course of researching that article, I discovered what appears to be another related vulnerability that I've reported to Apple and thus can't discuss until it's patched.)

Bernd discovered that if you connect an unpowered iPhone, even an encrypted iPhone 3GS with a PIN lock, to an Ubuntu system, all of the iTunes data and some third-party app data is exposed. Heise then determined they were able to access even more information by connecting an iPhone to a Windows computer as the iPhone is booting. Heise states they gained "full system access," including SMS messages, plain text passwords, and the capability to make a complete iTunes backup. Additional testing showed that iPads are also vulnerable.

This reveals two issues. First, that an iPhone with a PIN lock can connect to an untrusted system. Second, that the encryption and PIN lock can be circumvented to expose data, at least partially, under the right conditions. In other words, the hardware encryption on the iPhone 3GS is worthless at protecting data against even a moderately informed attacker.

How to protect yourself. With what we know now, it is clear that if you lose physical control of your iPhone, you cannot assume that your data is protected. Realistically, most lost or stolen iPhones won't be subject to an attack or forensic analysis and will be sold or taken by someone who wants a free phone. That said, enterprise users, celebrities, and other high profile targets are at greater risk of data exposure.

To minimize your risk, use a PIN code, lock your phone manually before shutting it down (not that I think I've ever turned my phone completely off), and set your phone to lock itself after a set time period in the General > Auto-Lock preferences. This particular vulnerability seems related to how your phone boots up when you turn it on, which means you aren't vulnerable unless you shut your phone down before locking it.

If you do lose your iPhone or iPad, and you are a MobileMe subscriber or have your phone connected to a Microsoft Exchange server, you can trigger a remote wipe and delete stored data. This works only if the device is connected to the Internet. MobileMe subscribers can trigger remote wipe in the Find My iPhone section of the service, while Exchange users need to contact their Exchange administrators.

The good news is iPhone OS 4.0 may reduce the severity of this vulnerability. Apple announced that users will have the option of better encrypting their email data using the PIN code as the key, and software vendors can integrate more advanced encryption into their apps.

Problem: New Spyware -- On 1 June 2010, Intego, a Mac security software vendor, released details on a new form of Mac spyware found in downloadable screensavers hosted on normally trusted sites like MacUpdate, VersionTracker, and Softpedia.

What you need to know. The malware, called OSX/OpinionSpy, is the Mac version of a spyware program that first appeared on Windows systems in 2008. Interestingly, OpinionSpy isn't included in the actual downloads, but is downloaded during the installation process for the host software. As a result, there is a good chance that antivirus software wouldn't find it by scanning either the application or screensaver installer.

In some cases, the software will warn you at installation that it includes a "market research" program. You will, however, always be prompted to enter your administrative credentials. As with any software, entering your admin password allows the program to do whatever it wants on your Mac.

There is no evidence that OpinionSpy takes advantage of any Mac OS X vulnerabilities. It relies on tricking the user to install it.

Once installed, OpinionSpy scans your system, monitors your activity, and sends the information to its control servers. The traffic is encrypted, so it is uncertain exactly what is shared. It will also occasionally ask you to fill out forms and surveys.

OpinionSpy is spyware - software that spies on your activities and sends the information to the company that runs it. Not all spyware is necessarily malicious, but since OpinionSpy sometimes hides itself during the installation process, injects itself into other programs like Safari and iChat, doesn't disclose what it sends to its control servers, and tries to stay running even after you turn it off, it is reasonable to consider it malicious.

OpinionSpy is not a virus, and doesn't attempt to replicate itself.

How to protect yourself. As always, common sense and a little skepticism are your first layers of defense. Be wary of any application that asks you to participate in market research. Also be careful of any program that requires administrative credentials to install - especially something as simple as a screensaver. While many legitimate programs do need administrative access, it's worth taking a few minutes to research any previously unknown application from a company with which you're not familiar before entering your password.

Throwaway programs like screensavers and casual games are common sources for spyware, back doors, and other kinds of malware. It isn't unusual for these programs to make it onto trusted download sites since the site operators don't have time to perform robust testing before posting them. I always recommend caution before installing software from an unknown or untrusted developer. That's especially true since antivirus software (if you use it, which I don't generally recommend; see "Should Mac Users Run Antivirus Software?," 18 March 2008) won't always pick up these applications since they don't spread via the usual vectors.

I personally also use Objective Development's $29.95 Little Snitch, an outbound firewall that asks for your permission before allowing any program to make a connection out to the Internet. I deny programs I don't recognize (and then research what they are), along with any programs I'm otherwise suspicious of.

If you spend a lot of time downloading software like widgets, screensavers, and small games from lesser-known developers, you might consider antivirus software in addition to Little Snitch. I don't recommend this for most Mac users, but heavy downloaders, gamblers, and those looking at adult content should consider investing in extra protection.


READERS LIKE YOU! Support TidBITS by becoming a member today!
Check out the perks at <>
Special thanks to Robert Hill, Norbert E. Fuchs, Marcia Daly, and
Nancy Hyland for their generous support!

Comments about Security News: Flash Attacked, iPhone Exposed, Spyware Discovered
(Comments are closed.)

Harald Hanche-Olsen  2010-06-07 14:40
“[…] users will have the option of better encrypting their email data using the PIN code as the key […]“
This is a joke, right? Any encryption with only ten thousand possible keys is utterly trivial to break, after all.
Glenn Fleishman  2010-06-07 16:26
The PIN isn't used directly as a key for the data. The PIN is hashed with other data to produce a key. Without knowledge of the PIN and the associated hashing data, you can't cycle through 10,000 possibilities to crack the key.
Harald Hanche-Olsen  2010-06-07 16:54
Okay, that sounds better. Provided, of course, that the “other data” is inaccessible to the attacker. But if it is, how does the iphone software get the other data when it needs to decrypt?
Glenn Fleishman  2010-06-07 18:29
It depends on whether someone can access some (or all) of the info on an iPhone, like imaging the data and cracking parts of it later, or if someone has physical access to the device and can get root and access parameters on it.

You're correct, of course, that if someone can get all the ancillary bits of information used to increase entropy that it simplifies cracking the PIN. But if some of the information is locked away in a particular fashion in hardware that's inaccessible without the PIN, then you have a nifty paired solution.
Harald Hanche-Olsen  2010-06-07 18:44
Ah, but in the latter case, it is so much easier, and just as secure, to simply store the password in the PIN-secured hardware.
Tracy Valleau  2010-06-07 21:18
I'll point out that the latest Virus Barrier includes a firewall as well as AV scanning (all of which can be controlled from "off" thru several levels of "on") and also monitors outgoing connections, ala Lil'Snitch. Point being that if you run VB, you don't also need to run Lil'Snitch.

Further, I vacillate between running and not running VB. Once the full scan is done, the active parsing takes about 1/2 of 1% of one of my four cores, so calling it "resource intensive" is a bit of an overstatement, in my own experience. (Mouseworks takes more system resources.) I did have it catch a trojan a couple of years back, so at the least, I know it works.

I've been programming Apple computers full time 14 hours a day 6 or 7 days a week since 1978, and honestly don't yet have the confidence you express that "nothing is needed" for Macs.

Do you specifically recommend >against< using VB... and if so, why? I just wonder what you know that I don't... :-)
Chris Pepper  An apple icon for a TidBITS Staffer 2010-06-07 21:28
"To minimize your risk, use a PIN code, lock your phone manually before shutting it down (not that I think I've ever turned my phone completely off),"

How? I have yet to find a way to manually lock an iPhone. I shut it down to force it to lock, but the bug is apparently that the auto-lock-on-boot doesn't work right, so that's no good.
Richard  2010-06-08 08:42
Press the sleep/wake button on the top right corner of the iPhone.