Is Apple iPhone insecure? Forbes asks ‘experts’ – chuckle – Rob Enderle and David Maynor

“With its science fiction features and high-end price tag, Apple’s iPhone may be the ultimate executive toy. All the uber-gadget lacks, according to some security professionals, is executive-level security. And that, they worry, makes the iPhone a hacker’s playground,” Andy Greenberg reports for Forbes.

“‘It seems Apple is releasing a device with no thought to enterprise security,’ says Andrew Storms, director of operations of the computer security firm nCircle. ‘It’s going to be entering enterprise networks whether we like it or not, and it’s a nightmare for security teams.’ Storms, like most everyone else anticipating the iPhone launch, admits that his worries are largely limited to speculation,” Greenberg reports.

MacDailyNews Take: It bears repeating: His worries, like most everyone else’s, are largely limited to speculation. The iPhone runs Mac OS X, by the way. Some “security nightmare.”

Greenberg populates the rest of his speculative piece on quote from the esteemed likes of not only Rob Enderle, who Greenberg laughingly identifies as a “security consultant who heads the Enderle Group” (a “group” which consists of Rob and his wife, by the way), but also from David Maynor. That’s David “If you watch those ‘Get a Mac’ commercials enough, it eventually makes you want to stab one of those users in the eye with a lit cigarette” Maynor. You tried it with Safari, it didn’t work, Dave, still trying to to fulfill your wants? Also of interest, please see the related article: SecureWorks admits falsifying Apple MacBook ‘60-second wireless hijacking?’ – August 18, 2006

In short, this Forbes article is a joke, a hit piece, just one of many pieces of FUD we seem to have to endure for some time to come.

Full article, Think Before You Click™, here.

103 Comments

  1. This should be another great test of the inherent and built-in security of OS X. It should also be great testimony but I won’t hold my breath. There are too many well-paid astroturfers and mindless trolls out there who will never admit that OS X is inherently more secure than any form of Windows. The onslaught of FUD has only barely begun. Battle stations.

  2. Why is everyone always concerned about Apple security when it has such a good track record? Then they defend MS technologies which has such a bad record on security. Yet somehow they bash Applea nd still stick with MS. I don’t comprehend the logic. In their eyes Apple is damned if they do, damned if they don’t. No winning with them unless you see the windows logo somehow.

  3. Last time I talked to his shrink, iPhone had a healthy self-image and self-esteem. Not insecure at all.

    You know the B.S. going around on this product from both sides of the fence is amazing. Why don’t they just issue those laser holographic images for articles that way you know the flavor lies you will find in the text before hand.

    Just my $0.02

  4. war: The comments you refer to are, in fact, not without a logical basis, IF, and only if, you believe that OS X’s security is a result of its “obscurity”.

    OS X is without a fact more secure, but the Doze trollers think now that with the millions and millions of iPhone users out in the near future, that OS X’s security will be exposed as a “fraud”, and will be shown as no better that the dog known as XP/Vista.

    Hey, just my take on the thinking of doofuses like Enderle.

  5. Correct me if I’m wrong, but wasn’t the hole in Safari only in the new Safari 3 BETA for WINDOWS? Since Safari for the iPhone is running on Mac OS X it satands to reason that the exploit won’t have the ability to compromise the iPhone’s security.

  6. iPhone runs OSX.

    SO to answer his question for all the wed idiots out there who see Enderle as an ‘expert’…

    IPHONE IS THE MOST SECURE PHONE ON THE PLANET.

    p.s. – If you want expert advice – DONT BOTHER TALKING TO ENDERLE.

  7. It is an inherent fact of systems and networks that the more complex and user centric something becomes, the more insecure it becomes. It just works that way.

    The iPhone appears to be a highly complex device. No telephone runs an OS as robust as OS X. This makes it not only complex but highly user centric in terms of potential services.

    This means that it is also potentially the most insecure phone on the planet.

    Give the nutcases a week with the phone and the hacks will fly and what really scares me is that they might also inspire hacks to OS X on general purpose computing devices as well.

  8. You people who spout this crap about how secure OS X is, let’s just say you apparently lack any imagination whatsoever and its very clear that system security are just buzzwords to you and you have no real experience in the field.

    There are holes in OS X. LOTS OF THEM. I guarantee, nah PROMISE you that the iPhone will be hacked. Not only will IT be hacked but it will become a choice tool of hackers to use on other networks.

    Mark my words.

  9. Here’s a childish example for you. Imagine than an OS is a house. Someone mentioned the Palm OS. Let’s say the Palm OS is a house with a door and a window. Very limited house. Then there’s OS X, a much more robust house with lots of doors and windows and a garage and a basement, chimney, etc. Looks like a much more robust and user centric house. Which, old naive ones, is more secure? Yes you can try to make sure all the doors and windows in the OS X house are locked, but we all know how well that works.

    By the way, the MOST secure OS is OS 9. No doors, no windows, once you were in you were in.

    Most insecure? Windows of course. All the doors and windows are interconnected.

  10. Andrew Storms is 100% correct.

    His industrial-strength corporate IT security firm nCircle
    understands Apple is a Mickey Mouse company when
    it comes to real world corporate IT security technology.

    Only Microsoft understands the enterprise corporate IT
    securities priorities and has the enterprise IT savvy to
    deliver the security solutions corporate America needs.

    The iPod is a toy. The macintosh is not a corporate
    enterprise platform and corporate IT experts everywhere
    know to keep American businesses free from Apple’s
    un-productive toy-like computers.

    Without access to Microsoft Outlook servers the Mac
    will always be less than a marginal competitor in the
    world of enterprise and corporate PC technology.

    All of the above is true and worse when it comes to
    the iPhone.

    Those who buy an iPhone will regret it when they
    walk into their jobs the following day — and will
    disqualify themselves on their next job interview;
    especially if it’s an interview for an enterprise IT job.

  11. You have to think like an intruder. We’ve been told that the phone is locked down however Web applications will be allowed. Ok… I guarantee within several weeks of the phone’s release there will be sites that exploit previously unexploited problems in Safari.

    I can see it now.

    “…Buffer Overflow in Safari gives website access to iPhone’s memory allowing download of telephone numbers and other information.

    Millions of iPhone users tricked into going to iPhone site to see naked pictures of Jessica Alba using her iPhone unwittingly gave the site access to their phone’s internal data…”

    All I’m saying is, don’t bet your life on the iPhone or ANY COMPUTER, being secure. There will always be those who take advantage of such naiveté and general lack of sophistication.

    MW: thirty as in, “Over thirty years cleaning up after supposedly secure systems.”

  12. thelonius…

    If you were a gambling man, how long would you say it will be before these hacks appear? A week? Three months? A year?

    Surely if Apple get to the 20 million unit mark without a security attack, it denotes that the iPhone is at least as secure as Mac OS X, or will we still need to be worried after that?

  13. @theloniousMac: You’re insane, calling OS 9 more secure then OS X. People hacked OS 9 to bits. It actually had viruses. OS X has never had a real or significant virus or malware problem.

    In what way does OS 9 have no doors or windows? You don’t consider its support for disk drives and web browsers openings?

    You make no sense. Go away, troll.

  14. Even though I believe OS X is more secure, I’m ready for this topic to be resolved. If it is, then maybe the Doze apologists, who don’t seem to understand the difference between theoretical security holes and actual, continual, breaches that you could drive a starship through, will finally STFU.

    If on the other hand they’re right, then we can end the “complacency” and start the process to make OS X better. In any event, I for one am tired of this continuous dumb ass argument.

  15. iPhone security is from OS X

    OS X security is from BSD

    BSD security is from UNIX

    UNIX security has been worked on since the ’60s and BSD since the ’70s.

    UNIX/BSD have been SECURE, MULTI-USER, environments even before DOS, or even the first Macs!!!! Unix/BSD has a long history working on security, stability, and multi-user functionality, Windows will never catch up. Basing a cell phone off of a very secure, very stable, multi-user OS means that it will be a major pain to write even proof-of-concept security exploits, and damn-near imposable to write an actual, self-propagating, destructive virus.

  16. @theoloniousMac

    Love how you practice rhetorical argument! References to “inherent facts”–an oxymoron grounded in a category mistake. Unspecified future threats based on unsupported assurances of superior “experience.” Bad physical analogies to door and windows (why not use a disease metaphor instead?).

    Try this “inherent counterfact” on for size–complex systems allow more opportunities for defense against and repair of hacking attempts before they do anything serious.

  17. Nope, MCCFR, I’m not a gambling man. That’s why I don’t bet on a device just being “secure.” I’m sure it will be hacked.

    And ya know what??

    I hope I am 1000% wrong.

    I hope I eat my words.

    Thing is, you’re talking to a guy that’s dealt with hacked Macs, hacked Mac servers etc.

    I get calls when people are suddenly banned on a network. Typically such calls come in for Windows and we track down what contagion or malware has invated their systems.

    I’ve had it happen with Macs as well. I’ve seen OS X server compromised and turned into a phishing site for Chase bank customers.

    Stuff like this happens, it just doesn’t get reported. It is most often the fault of the user, but the same can be said of Windows as well.

    There are and there will be malicious users looking for ways to exploit the most vulnerable part of any system, the moron with his hands on the keyboard, or touch screen as it were.

  18. Here’s a concept for you. The iPhone is a closed system. You can only get into it from iTunes. Once in you have to compromise a tried and true Unix OS. One without an admin password. One without a user password.

    Just break in to One Infinite Loop and get those passwords and go for it.

    Really don’t know what you’re talking about, do you.

  19. Come on, we all remember “Sputnik” here on MDN! He (it?) may have changed his moniker, but not his real-world IT slobber and drivel.

    NOTE: Poor bastard; his mother just threw him out of her house on his ear, thereby ending his sex life. How very sad.

  20. “…Try this “inherent counterfact” on for size–complex systems allow more opportunities for defense against and repair of hacking attempts before they do anything serious…”

    Is this tongue-n-cheek? ” width=”19″ height=”19″ alt=”grin” style=”border:0;” />

    Paul, I think you know I’m right about complex systems. It’s a fact of nature. The more complex a system is, the more that can go wrong with it. The more complex a system is, the more opportunity for exploits exist.

    This is computer security 101. Each layer of complexity adds an associated layer of possibilities.

  21. “…Here’s a concept for you. The iPhone is a closed system. You can only get into it from iTunes. Once in you have to compromise a tried and true Unix OS. One without an admin password. One without a user password.

    Just break in to One Infinite Loop and get those passwords and go for it.

    Really don’t know what you’re talking about, do you….”

    English please.

    “Closed System?”

    Closed to the average user possibly, but come on, do you people really think that Apple can create security that is unbreakable that no one in the entire world can bypass.

    Do you really?

    I thought I was a fan boy, but yeesh. You’ve got stronger kool aid than I do.

  22. @: theloniousMac

    “The more complex a system is, the more opportunity for exploits exist.”

    Is that why it is so much easier for a burglar to break into the White House then an old woman’s house down the street? Or why it’s easier to rob from Fort Knox then it is to rob your sister’s piggy bank? Once again, you make no sense at all.

    You can’t see beyond your reality distortion field.

  23. Real World of Information Technology = clueless IT douchebag.

    I happen to have my mac connect to my exchange server just fine thank you.

    I also have it in the Active Directory… oh wait, did I mention that I have Windows 2003 Server on 1/2 of my servers?

    The fileserver though… Mac 10.4 Server — always up, never a problem.

    I speak both languages… I’m the kind of IT guy “Real World of Information Technology” fears most.

  24. norton and mcaffe has been using paranoid scare tactics to sell unneeded “security” for years thiese guys see a paycheck protecting their networks from mac osx if nothing happens they get to say thank god look how good we are. put mac servers on your network and stop worrying about all those attacks and then fire those security guys (and as a bonis your computer may just find the printer down the hall with out a 2 week runaround getting through the firewalls)

  25. Even MDN’s take (which I almost always agree with) states: MacDailyNews Take: It bears repeating: His worries, like most everyone else’s, are largely limited to speculation. The iPhone runs Mac OS X, by the way. Some “security nightmare.”

    I agree with this also.

    Speculation is where exploits begin.

    Here’s my first speculation. The first iphone hack will be through Safari accessing a supposed “WEB 2.0” application.

    Now some moron with nothing better to do will speculate about the same thing, only he will sit down and try to make it happen.

    It’s the way of the world. It shouldn’t be offensive to anyone. You WANT security people assuming such devices are insecure and problematic.

    Don’t you? Do you want security people to assume a device as apparently powerful and robust as the iPhone poses no security threat? Would you hire that person?

  26. It’ll be interesting to find out what settings are accessible or not on the iPhone. Will the firewall in Mac OS X be turned on by default or turned on… period… not accessible in the Preferences at all??

    Before these “experts” get an iPhone in their hands, the security reputation of Mac OS X should speak for itself… no further discussion.

    MW: kind
    as in
    Why does Forbes insist on publishing this kind of putrid refuse ??

  27. @ Reality Check

    “Correct me if I’m wrong, but wasn’t the hole in Safari only in the new Safari 3 BETA for WINDOWS? Since Safari for the iPhone is running on Mac OS X it satands to reason that the exploit won’t have the ability to compromise the iPhone’s security.”

    There’s been more than one, but point taken. The guy who found one of them, Thor Larholm, has this to say:

    “On the OS X platform Apple has enjoyed the same luxury and the same curse as Internet Explorer has had on the Windows platform, namely intimate operating system knowledge. The integration with the originally intended operating system is tightly defined, but the breadth of knowledge is crippled when the software is released on other systems and mistakes and mishaps occur.”

    From what I hear Microsoft has, indeed, tightened things up a lot. I’m sure David Maynor would be ready to assure us of that. But back in the day — and really not so long ago — they did pretty much everything you shouldn’t and didn’t give a damn. Not so long ago their email clients would run scripts. Hence, e.g. this:

    http://en.wikipedia.org/wiki/ILOVEYOU

    Until Service Pack 2, the firewall was OFF by default. hence, e.g., this:

    http://en.wikipedia.org/wiki/Sasser_worm

    And far too many daemons (“services” in MS-speak) were running in the background. At one time everyone had to go here —

    http://www.blackviper.com/

    — and find out how to disable them themselves.

    I don’t doubt they’ve tightened up a lot. They had to, as the publicity had got so bad. They may even have leapfrogged OS X in _some_ respects. But it seems to be a case of too little too late:

    http://www.theregister.co.uk/2007/02/20/vista_security_oversold/

    And, frankly, after everything they’ve done in the past, they don’t get to say that people should stop laughing at them and their security record for a very very long time yet.

  28. mfshroom:

    “… Is that why it is so much easier for a burglar to break into the White House then an old woman’s house down the street? Or why it’s easier to rob from Fort Knox then it is to rob your sister’s piggy bank? Once again, you make no sense at all….”

    This nonsense you are expressing is “faith.” Faith is the basis for religion. There is no understanding of computers or operating systems here. Quite frankly, this is the silliest statement in this thread of comments. You even surpassed “Real World Information Technology.”

    This is why those of us that appreciate the Mac get labeled as cultists.

    I still say let’s hope I’m wrong. Let’s hope that Apple has done what no technology company on the face of the planet has been able to do, build a completely secure intelligent device.

    By the way, I’m not saying this means no one should buy an Apple phone. I will be in line on the 29th, and I’m buying as many as I can for clients… people who hire me for security consulting among other things.

    All I’m saying is stop sipping the kool aid and THINK about it. Let your imagination run free.

    How many of you walk around with BlueTooth enabled on your phone when it isn’t necessary? Hmmm?

  29. why are people so stupid?

    Jobs never said this thing ran MAC osx. MAC osx is the operating system we use on our MACS. OSX is the collection of tools that allow MAC osx to run and look so good. Core image, core video, core animation, quartz, spotlight services, all that stuff is just OSX. What runs on the phone will be OSX and the iPhone interface that the user interacts with.

  30. OSX is the most secure operating system on the planet. I would hardly call that a hackers nightmare. Also Rob underware knows nothing about Apple or its products so why even ask him for an opinion about something he knows nothing about!

  31. “I’ve had it happen with Macs as well. I’ve seen OS X server compromised and turned into a phishing site for Chase bank customers. “

    Did you actually SET UP this server? I’ve set up several installations of OS X Server, and I know how to do it properly. If you set it up, and it was complormised, then you failed. If you didn’t set it up, then do you know that ports were properly routed or closed, services were configured correctly, accounts had the proper permissons. etc? OS X Server is not a system that you just pull out of the box and plug in, you have to know what you’re doing to set it up right.

    It sounds like maybe you should take a class.

    -c

  32. Here’s an idea… how about we wait until the phone is actually released and the real experts have had a chance to look at how it (and its security) is put together before spouting a bunch of baseless speculation about how secure or insecure it’s going to be?

    Then again, there was a lot of FUD spread about the iPod when it was released too.

  33. Has anyone yet broken into one user’s account from another user’s account on a Mac? How do you know that Apple hasn’t set Safari in something like a separate user account given that web apps will supposedly have no access to iPhone internals?

    Now there are front-end apps, like Maps, on the iPhone that talk directly to servers on the Internet, just like iTunes does from the Mac. Has anyone broken into a Mac via iTunes? Or via Software Update?

    In any case, today’s talking point from MS is iPhone security. Several articles on this topic have popped up today. Couldn’t just be a coincidence.

  34. @ trollloniousMac

    Faith and religion? Where did that come from?

    I just happen to be a religious scholar, so I would love to debate you about this, but I just don’t see how faith and religion have anything to do with security. Where do you come up your talking points? It’s so absurd. This is turning into a Montey Python sketch.

  35. And what garbage are these so called experts spouting:

    “Only Microsoft understands the enterprise corporate IT
    securities priorities and has the enterprise IT savvy to
    deliver the security solutions corporate America needs.”

    That has to be the joke of the century.

  36. I am not an IT guy. I am a Mac user for 14 or so years. I have never, yes NEVER, had a virus, worm or had my computer hacked. On the other hand my nephew and sister who use Windows have consistently had problems with the above. They now want to switch. As one of my teachers said, ” When you argue with reality, you are wrong only 100% of the time.”

    All the theorys about what will happen are good mental exercise and even a good part of keeping a great system great. Critical thinking seems irritating at times but is actually necessary.

  37. @Vlad,

    I agree. However, the “real experts” will be end users and their experience with how they incorporate these devices into their work and non-work lives. The results (let’s talk in January) will speak for themselves.

    Apple is all about taking the power from the “security experts” (who really only want to sell crapware) and putting that power into the hands of users. Apple’s been around for 30+ years. Their software security speaks for itself.

  38. @ChrissyOne

    I don’t like talking about God that much, I think religions need to focus more on people and what’s happing in people’s lives on Earth. Religions such as Toasism and Buddhism explicitly avoid talking about gods, because they claim it distracts us from things that really matter. Some religions, like Native American traditions, refer to a Great Spirit that exists in everything, but they tend try to preserve it’s awe and mystery, that it is something inherently beyond basic understanding.

    In Abrahiminac religions (Juddhism, Christianity, Islam) they not only insist on the existance of God, but also insist on knowing many of God’s specific attributes (such as God use to talk to Moses and God hates homosexuals.) This seems very flawed to me; whether God exists or not, I don’t think it’s up to humans to tell us what God thinks and what kinds of people God does or doesn’t like.

  39. Spirited thread guys n gals, great after a couple of pints.

    Forbes, cast around for analcysts that would support their cause, ie whichever is the bigger company. Faced with absolutely no takers to dispense the negative waves in Apple’s direction they ended up with Enderle and Maynor.

    It’s not all their fault (well….) you see they think of software in terms of Microsoft as the benchmark. Like security is something separate that you do, good security isn’t like that, is not ‘security’ as such it’s just part of the everyday process of getting things right.

    I’m starting to think the FUD may be good, in helping to prevent rioting credit card holding frustrated citizens on the evening of 29th June.

    Imagine an OS is a house, there’s a house with lots of doors and windows and flues and sewer pipes and thousands of rooms, it’s a converted old castle with a moat, drawbridge and portcullis. There’s another house with one door and a couple of windows and only one room inside (full of junk too), it’s a mobile home. Which one gets burgled first?

    I had all this before Boot Camp took hold, Windows guys (and Cisco guys) saying with Windows on Apples Mac OSX will get hit with malware.

  40. Noone should jump to conclusions. There is no doubt that Mac OS X is one of the most secure OSes. However, saying that iPhone will be the most secure phone may not be justified. There are reports (unconfirmed, more like rumors) that there is no userspace in iPhone. Apps may access the kernel. It is thought to be a reason why iPhone SDK doesn’t exist yet, because Apple needs to protect the kernel while allowing developers to access it.

    As I said, it’s an unconfirmed reports, apply grains of salt as needed. But we need to refrain from praising iPhone security until it is confirmed whether there is or there is not userspace in iPhone OS X.

  41. @ChrissyOne
    You were hoping to get into a fight with a religious nutjob, weren’t you? ;p

    Religion really is a fascinating topic, if you can steer clear of the crackpots. Here are a few books that I highly recommend:

    The Tao Te Ching, possibly my favorite book of all time. It’s filled with the brilliance, poetic grace, and wisdom you can only get from the Chinese philosopher Lao Tzu. A very practical guide for living life with grace and wisdom. I recommend this translation:
    http://www.amazon.com/Tao-Te-Ching-Stephen-Mitchell/dp/0060812451/ref=pd_bbs_2/104-2474056-9992765?ie=UTF8&s=books&qid=1182278443&sr=8-2

    For something a little bit deeper, try The Bhagavad-Gita: Krishna’s Counsel in Time of War. This book is centered around a young man’s existential dilemma between his desire for peace and his duty as a soldier. Through his journey, he of course discovers the answers to this dilemma and all other questions in the universe. This book was one of the only material possessions Mahatma Gandhi carried with him all of the time. I recommend this translation: http://www.amazon.com/Bhagavad-Gita-Krishnas-Counsel-Bantam-Classics/dp/0553213652/ref=pd_bbs_2/104-2474056-9992765?ie=UTF8&s=books&qid=1182279148&sr=8-2

    Finally, I recommend The Soul of the Indian, a fascinating glimpse into the culture and beliefs of the American Indians. Truly are remarkible people with cool beliefs, that were almost lost forever because of the arrogance of the white man. Link: http://www.amazon.com/Indian-Charles-Alexander-Ohiyesa-Eastman/dp/0486430898/ref=sr_1_1/104-2474056-9992765?ie=UTF8&s=books&qid=1182279458&sr=8-1

    These books are very cheap, and you will enjoy them even if you don’t consider yourself religious. Plus 2 out of 3 of them are over a thousand years old, so you could probably find free translations of them somewhere on the Internet.

    So, what were we saying about iPhone Security?

  42. Oops, I walked into some absurd tech argument. No matter how hard I tried I couldn’t make hide nor hair of anything those two had to say.
    And I’m glad.
    –
    Also- I just want you to know that when I come across the word ‘fsck’ or ‘wtf’ or any of the other asinine variations I stop reading immediately and move on.

  43. @ Jay:

    “Even though I believe OS X is more secure, I’m ready for this topic to be resolved. “

    Jay it will never be resolved. These Microsoft trolls are just spreading FUD. Period. Sure MS is secure, 115,000 viruses secure. Just look the other way. Believe Bill and all will be well. !! LOL

    The iPhone is not even released yet and yet idiots like TheIoniousMac would have you believe that there are thousands of viruses and hacks out there RIGHT NOW, just waiting (Oh wait, that is Vista and XP hacks, ooopps) .

    I say, just wait and see. I would like to know how many millions of millions Microsoft is spending on these FUD spitters!

    en

  44. re: You people who spout this crap about how secure OS X is, let’s just say you apparently lack any imagination whatsoever and its very clear that system security are just buzzwords to you and you have no real experience in the field.

    There are holes in OS X. LOTS OF THEM. I guarantee, nah PROMISE you that the iPhone will be hacked. Not only will IT be hacked but it will become a choice tool of hackers to use on other networks.

    —

    OK – prove it smart arse!

    Post a link to any virus for Mac OS X!

  45. re: why are people so stupid?

    Jobs never said this thing ran MAC osx. MAC osx is the operating system we use on our MACS. OSX is the collection of tools that allow MAC osx to run and look so good. Core image, core video, core animation, quartz, spotlight services, all that stuff is just OSX. What runs on the phone will be OSX and the iPhone interface that the user interacts with.

    —

    What and idiotic comment!

    OS X was developed for the mac platform – therefore it is ‘Mac OS X’ on the iphone.

    The iphone is by all contrasts a mac that you make calls on.

  46. Drink Camel’s Milk! it is the only religion you need!

    If every Woman, man & child drunk Camel’s Milk, the ensuing Tsunamic fart would vibrate the entire World creating a level playing field!

    Any Mole hill that tried to emulate a mountian would soon be dealt with in the same way.

    Peace after the storm:-)

    Yes!….Camel’s Milk, the panacea for all man’s ill’s.

  47. Has itunes ever been hacked? I would imagine that all those active accounts would be an internet thugs dream come true.

    Are they trying to hack it, or is there a hackers code that say’s leave itunes alone because it is being used by 80% of the Wolrd’s music, podcast, tv, internet radio lovers?

    Why is there no FUD against it?
    If it had been hacked into even once, would we have heard the end of it?

    eg. TKMaxx?

    Conclusion. iTunes is a free standing part of OS X, just like Safari & Quicktime.

    The only occassions holes have been found have been in relation to a program written by a third party to work on OS X. The paranoid third party has not released the source code to the open community for scrutiny and testing resulting in over looked holes. eg. Java applelets as in the Zero day experiment.

    So is OS X secure? Yes!
    is Safari secure? Yes! apart from the Windows beta that is now in the open for testing and scrutiny.

    Will iphone be secure? In as far as our experience with OS X goes, we are very confident that it is.

    Can the same be said for Vista & the doomed zune today?

  48. If the phone is just a small laptop with great speakers and expanded communication capabilities i just dont see how its any more dangerous to my network than my I book with an airport card.

    guns dont kill people people with laptops do\
    if some hacker crashes my phone a coplete system restore is a snap on a mac. boo hoo for all you command line people

  49. @ mfshroom

    I find religion fascinating myself – more precisely, the sociopolitical motivations behind the consolidation and use of power as it applies to the human desire for knowledge and the pursuit of wisdom within dogmatic belief systems. Personally, I endeavor to exist outside of these systems, but I acknowledge that I live in a world controlled by them and thus am subject to their influence.
    And yes, I did bait you as a nutter. It was nice to learn that you’re not. ” width=”19″ height=”19″ alt=”wink” style=”border:0;” />

  50. “Also- I just want you to know that when I come across the word ‘fsck’ or ‘wtf’ or any of the other asinine variations I stop reading immediately and move on.”

    <h2>WHEW!</h2>

    Thank you so much!
    I wrote that down on a giant stickie and placed it on my monitor just so I don’t screw that up for you. Did everyone get the message? Show of hands please?

  51. > With its science fiction features and high-end price tag, Apple’s iPhone may be the ultimate executive toy.

    Except that article right below this one says that 40% of people inquiring about iPhone are not current mobile phone users. This is another FUD issue (like the lack of “chicklet” keyboard) that will be irrelevant for most new iPhone users. They will not be making their buying decision based on “expert” opinions about iPhone security.

  52. Real World of Information Technology

    The “Real” world of IT security is complete shit: a confusing morass of garbage security options forced on users by Microsoft’s brutally inept security policies. Microsoft’s garbage OS gave us self propagating viruses, worms and armies of DOS and spam bots.

    Any other interpretation is delusional pro-Microsoft horseshit. The investigation of which OS is vulnerable to and host for the aforementioned problems is information in the public domain. To be ignorant of it and yet still hold forth on security issues as if said problems were an emergent property of the internet is to be uniquely stupid.

  53. ‘It’s going to be entering enterprise networks whether we like it or not, and it’s a nightmare for security teams.’

    And there choice of OS wasn’t? What exactly is special about the iPhone that will make security worse than it already is using Microsoft products? These rants are tiring, stupid and hyperbolic.Especially when they are admittedly done with no knowledge whatsoever!

  54. Mac OS X: OS X with the Mac user interface consisting of windows, menus, mouse and keyboard input, etc.

    Therefore, the iPhone does not have Mac OS X. It has OS X with at a minimum, the iPhone user interface on top of it.

    There may be other differences but this much we know already.

  55. ‘It’s going to be entering enterprise networks whether we like it or not, and it’s a nightmare for security teams.’

    Hahaha! Macs and OS X are ALREADY the nightmare for anyone who makes their living in computer “security”.

  56. @ ChrissyOne,

    Have you heard of a skunk? of course you have!

    It leads it’s life whithin other lives, but is avoided religiously by all other creatures except it’s own kind only when mating though!

    In order for you to live your life outside organised religion but still whithin the brotherhood/sisterhood of man……

    Drink Camel’s Milk!!!

    The fart you expel thereafter will send a ripple down organised religion’s back’s so that they all end up looking & smelling like Skunks, they will then lead their lives like Skunks leaving you in peace to lead your own life whithout their influence.

  57. This is just all soo…. ludicrous.

    How the fsck can an iPhone compromise a company IT network?

    Seriously.

    If it’s completely hackable and gets compromised you have compromised… an iPhone. If an IT network can’t protect itself from a PHONE out there at an IP address, how the FSCK does it protect itself from Russian hackers??!!!

    And because it is a “toy” not using all that MS PROFESSIONAL IT shi–uhhh–stuff… it’s just another fricken web client. A device at an IP address. There are MILLIONS of hacked computers on the net. There are vicious criminal gangs trying to break into corporate nets.

    There are hackers who cruise around looking for accessible wifi networks looking for an edge to break in…

    With all that, it’s some flaw in the iPhone that’s going to trash your company server. That sounds like a Hollywood script.

    ====

    Yes, it’s got OSX inside, which has a great security track record. But even that’s not accessible… the only vector for malware is Safari cuz 3rd parties can’t install apps on it.

    But let’s say Apple gets something wrong, and a hacker finds a clever vector and gets malware onto the phone… how does ONE ROGUE DEVICE threaten your network. A network that’s been hosting windows clients ought to be quite robust one would think.

    =====

    I’m waiting to hear that iPhones will cause brain tumors as well.
    And that they’re actually part of a great government conspiracy…. a quid pro quo because the technology actually came from aliens held captive in Area 51.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.