HomeinetApple's iCloud Cracked.... Do you still trust it?

Apple's iCloud Cracked... Do You Still Trust It?

Kuala Lumpur, Malaysia– Russian security researcher Vladimir Katalov analyzed Apple’s iCloud and discovered that his phone was not protected by two-factor authentication. But there are worse things. iCloud can be downloaded to the computer of anyone with the skills, without the data owner ever knowing.

iCloud1

In “Cracking and Analyzing Apple's iCloud Protocols,” which was held to a packed room at the Hack In The Box last Thursday in Kuala Lumpur, Malaysia, Vladimir Katalov revealed that Apple's iCloud user data is not as secure as the company claims.
A malicious attacker only needs an Apple ID and password to get iCloud backups — without having to log in to the victim's device. The researcher explained that there is no way for a user to encrypt their data in iCloud.

The data is already encrypted, he explained, but the keys are stored with the data. Katalov added that Apple holds the encryption keys.

The security researcher told  ZDNet that when he was faced with the huge security gap, he was shocked, after discovering that in addition to all this, Apple's iCloud data is stored on Microsoft and Amazon servers.

During his presentation, Katalov pointed out that because Apple places its users' data with third-party storage providers (Amazon and Microsoft), it could well hand over this data to the authorities.

In July, Apple announced (after the revelations about the NSA's PRISM surveillance program) that there are no backdoors in its systems and that it does not give access to government agencies.
When a user downloads their data from iCloud, they will receive an email informing them that the process has been completed.
Katalov discovered that if someone downloads their data bypassing Apple directly from the servers where the owner stores it, they will not receive any notification via email.

Katalov's research is the first publicly presented analysis of Apple's iCloud service.

The researcher analyzed Apple's iCloud and Find My Phone services by sniffing http traffic from jailbroken devices — although they don't have to be jailbroken to exploit the vulnerabilities. Analyzing the traffic, he told the packed room, wasn't difficult.
In his analysis, Katalov discovered that the files stored in iCloud were in the way Apple usually stores them, which is as a plistand the content.

But he found that Apple's two-factor authentication, which is used in conjunction with an Apple ID and a password, was not required for iCloud backups and Find My Phone.
Katalov demonstrated to his Hack In The Box audience that it is very simple to gain access to iCloud, get the data, backup IDs, and encryption keys. One can then download the files stored in Windows Azure or Amazon AWS.

When asked if he had presented his findings to Apple, he explained that his findings were the results of protocol analysis – and not a vulnerability. In other words, the iCloud security hole is a feature, not a bug!

Read the last line again “it's a feature, not a bug” and think about who such a feature might serve.

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS