Apple: Beware Dangerous iPhone Messages
Apple has warned iPhone users to take care when replying to SMS (Short Message Service) text messages, after a hacker released details about a fundamental security flaw in the iPhone operating system.
The flaw could allow pranksters to send bogus messages that appear to come from someone else. It could also trick users into following dangerous links or handing personal information to criminals.
The revelations come from a "white hat" hacker -- someone who looks for security flaws to pressure companies to improve, rather than to exploit them for personal gain -- who goes by the name "Pod2g".
Pod2g says the problem is in the way the iPhone turns message data into computer files in the Protocol Description Unit (PDU) format.
It's possible to manipulate an iPhone so the sender creates a PDU file. The phone then assumes there's no need to make any changes to the file, and transmits it.
This allows a hacker to create a PDU file that displays a false phone number in the "reply to" field. iPhone software uses this information to identify the sender to the person receiving the message. (Source: tgdaily.com)
SMS Sender Identity Could Be Bogus
If hackers send messages that, for example, appear to be from a financial institution asking the recipient to follow a link, the message could lead to a fake website designed to capture the unsuspecting phone user's online banking details.
Or a message purporting to come from a major website could ask the user to provide personal information. Despite the iPhone's on-screen appearance of legitimacy, the reply could go straight to a fraudster.
Pod2g says Apple must force its iPhone software to compare the phone number in the "reply to" field with the actual phone number of the sender, and to flag any disparity.
Apple Concedes Text Message Security Flaw
Apple isn't commenting on whether it will make these changes. Instead, it has warned iPhone users to take greater care when responding to an SMS text message, and to be wary about providing personal information or following unsolicited links, even when the message appears to be from a known sender.
Apple suggests that iPhone users can use the iMessage instead of the SMS text service, because iMessage verifies addresses, making such scams impossible.
However, iMessage works only between iPhone users. (Source: pcworld.com)
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.