Here’s a scary statistic: If your iPhone is lost or stolen and the thief knows what they’re doing, they can get the handset to cough up passwords stored in its keychain in only six minutes -- without ever having to crack through your passcode.
MacStories is reporting that German researches have shown that the iPhone is vulnerable to having the keychain exploited, even with Apple’s current passcode system in place. Like Mac OS X, the keychain is where iOS stores all of your passwords and other key data, which is easily hacked using an existing jailbreak exploit.
“Once jailbroken, the researchers installed an SSH server on the iPhone and install a keychain access script,” MacStories reveals. “This keychain access script utilizes functions that are built within the phone to access passwords and other data stored in keychain which is then outputted to the attacker.”
The discovery was made by researchers at the Fraunhofer Institute of Secure Information Technology, who explain “the attack works because current iOS devices have a cryptographic key that is based on data within the device and not based on the passcode,” MacStories says. “As a result, an attacker can gain access to the internal iPhone data through a jailbreak and then access all the information required to get into the keychain.”
In case you’re thinking that this attack will only give up website passwords that can be easily changed, think again -- it also includes “data such as the passwords for Google Mail, Microsoft Exchange accounts, voicemail, Wi-Fi passwords and some app passwords are fully compromised and accessible to an attacker with physical access to someone’s iPhone.”
Hopefully the jailbreak exploit isn’t one currently in use by the Dev Team, since Apple will likely plug this hole rather quickly. Have a look at just how easy it is with the embedded video below -- and in the meantime, hang onto those iPhones, folks!
MacLife: As if rumors of a budget iPhone weren't enough, now we're hearing whispers of multiple colors, too. http://t.co/Rk5cbxamj47 hours 5 min ago
MacLife: If you've put off grabbing Angry Birds Space for some reason, now's your chance--it's free for the next 7 days. http://t.co/rWFbO7M4QC7 hours 8 min ago
MacLife: Review: HeroClix TabApp Elite for iPad uses real-world figurines to bring DC Comics heroes into a mediocre brawler. http://t.co/4xIV2xlCtE9 hours 14 min ago
MacLife: Review: Sky Guide lights up stargazing sessions with a beautiful interface and meticulously researched data. http://t.co/DCUfcPU79W10 hours 18 min ago
MacLife: Who says you can't tell a good story in an iOS game? Not us—in fact, we've got 8 games that disprove that very idea. http://t.co/8dLa2rhfl010 hours 21 min ago