iMessage flaw lets hackers see your photos and videos

Threat of iPhone backdoor "scares" researcher, who says Apple must get basic encryption right

Researchers at Johns Hopkins University have discovered an encryption flaw in Apple's iMessage platform that could allow an attacker to view photos and videos sent via the service.

The group was led by Matthew Green, an expert in cryptography and professor at the university's department of computer science, who had suspected a bug may exist after reading an Apple security guide in 2015, which described the encryption process.

Green alerted Apple's engineers to the potential vulnerability, according toThe Washington Post. However, after a few months passed with no patch being issued, he and his research team decided to investigate it themselves.

Green told the Post he and his graduate students wrote software to mimic an Apple server in order to target a message being sent between iPhones that contained a link to a photo stored in Apple's iCloud server and a 64-digit key to decrypt it.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

While the key's digits were hidden, the students were able to effectively use a process of trial and error to guess them by repeatedly changing a letter or number in the string. When it was correctly guessed, the phone would accept it, giving them incrementally more of the key until they had the full 64-bit string.

Referring to the ongoing court case between Apple and the FBI, Green told the Post: "Even Apple, with all their skills - and they have terrific cryptographers - wasn't able to quite get this right. So it scares me that we're having this conversation about adding backdoors to encryption when we can't even get basic encryption right."

All devices not running Apple's latest mobile OS, iOS 9.3, are vulnerable to the attack and, the researchers claimed, a modified version of the attack would work even on this operating system, although it would require the resources of a nation state.

Full details of the exploit will be revealed in a research paper to be published by Green and his graduate researchers once Apple has rolled out a patch for the bug.

Image credit: Kelvinsong (Own work) [CC BY 3.0], via Wikimedia Commons

Featured Resources

Digitally perfecting the supply chain

How new technologies are being leveraged to transform the manufacturing supply chain

Download now

Three keys to maximise application migration and modernisation success

Harness the benefits that modernised applications can offer

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

The 3 approaches of Breach and Attack Simulation technologies

A guide to the nuances of BAS, helping you stay one step ahead of cyber criminals

Download now
Advertisement

Recommended

Visit/security/internet-security/354417/avast-and-avg-extensions-pulled-from-chrome
internet security

Avast and AVG extensions pulled from Chrome

19 Dec 2019
Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Most Popular

Visit/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them
operating systems

17 Windows 10 problems - and how to fix them

13 Jan 2020
Visit/hardware/354584/windows-10-and-the-tools-for-agile-working
Sponsored

Windows 10 and the tools for agile working

20 Jan 2020
Visit/microsoft-windows/32066/what-to-do-if-youre-still-running-windows-7
Microsoft Windows

What to do if you're still running Windows 7

14 Jan 2020
Visit/business-strategy/public-sector/354608/uk-gov-launches-ps300000-sen-edtech-initiative
public sector

UK gov launches £300,000 SEN EdTech initiative

22 Jan 2020