NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Technology

Is your iPhone safe? Kiwi researcher finds flaw

Herald online
26 Sep, 2011 11:50 PM7 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

Opinion

Apple software may not be as secure as we like to think. A security researcher based in Dunedin, of all places, has recently published some interesting Apple-related information about the security of Unique Device Identifiers in iDevices, and this has been picked up in the international press.

Aldo Cortesi is a security consultant for www.nullcube.com but the UDID work was not specifically commissioned by anyone but done in his personal capacity as a side-project, "motivated by mostly by curiosity".

The first set of UDID work he did has resulted in a class-action lawsuit against OpenFeint in the states.:

Cortesi feels a bit ambivalent about this: "on the one hand, the US legal system is clearly crazy, on the other hand, this kind of action might actually force the companies in question to change their ways."

In his latest article on his own blog, Cortesi describes a systemic failure in the way gaming/social networks use Apple UDIDs for single-sign-on. This problem affects more than 100 million users, all told.

Advertisement
Advertise with NZME.
Advertisement
Advertise with NZME.

Cortesi's previous research focused on OpenFeint and was covered in The Wall Street Journal, Der Spiegel, CNN Online, Wired and the Huffington Post.

The UDID is like an individual serial number permanently in every iPhone, iPad and iPod Touch. Any installed app can access the UDID without requiring your knowledge or consent. UDIDs are very widely used: in a sample of 94 apps Cortesi tested, 74 per cent silently sent the UDID to one or more servers on the internet, often without encryption.

Phone identifiers don't make very secure keys, so sites are using these phone identifiers as keys to the other information. In other words, UDIDs are not secret values.

Cortesi has so far confined his tests to Apple devices, studying seven major game networks, including Crystal, the game network of Chillingo (Angry Birds) and Zynga, maker of FarmVille.

If you use an Apple iDevice regularly, it's certain your UDID has found its way into scores of databases you're not aware of. Many developers seem to assume UDIDs are anonymous values, says Cortesi, and routinely use them to aggregate detailed and sensitive user behavioural information.

Discover more

Technology

Facebook promises to fix tracking 'bug'

27 Sep 06:27 PM
Technology

Use two gadgets at once? Not well, you can't

27 Sep 09:58 PM
Opinion

iPhone 5, or 4GS, or something else, is coming

28 Sep 10:15 PM

Cortesi gives an example: Flurry, a mobile analytics firm used by 15 per cent of apps he tested, can monitor application startup, shutdown, scores achieved and a host of other application-specific events, all linked to the users UDIDs.

Cortesi finds this a real concern: "I recently showed that it was possible to use OpenFeint, a large mobile social gaming network, to de-anonymise UDIDs, linking them to usernames, email addresses, GPS locations, and even Facebook profiles."

Advertisement
Advertise with NZME.

In experiments, Cortesi found that social gaming networks systematically misuse UDIDs, resulting in serious privacy breaches for their users. "All the networks I tested allowed UDIDs to be linked to potentially identifying user information, ranging from usernames to email addresses, friends lists and private messages."

There's a lot more nitty-gritty on Cortesi's blog.

There is hope for your security, though: "A few days after I notified the companies involved, it was revealed that Apple was quietly killing the UDID API. It will still be present in IOS5, but is marked deprecated, and will probably be removed in future."
He recommends developers shift away from using UDIDs now, rather than wait for formal removal of the API. Cortesi also cautions that replacement ID systems developers might add to their apps in place of Apple's UDID could have the same problems if developers don't use them in a secure way. "The challenge will be to make sure that the cure isn't as bad as the disease."

There are other problems with Apple devices, actually. FaceTime calls, which are like Skype with video iDevice/Mac to iDevices/Macs over WiFi networks, are encrypted, but only as long as you use the right type of connection. If your thought cell hone calls could be a source of trouble when taped, imagine the trouble CafeTime could get some couples into.

Apple issued the following response to those who questioned how secure FaceTime is:

"iPad supports WPA2 Enterprise to provide authenticated access to your enterprise wireless network. WPA2 Enterprise uses 128-bit AES encryption, giving users the highest level of assurance that their data will remain protected when they send and receive communications over a Wi-Fi network connection." So WEP connections aren't so safe - WEP and WPA2 are forms of encryption common to wireless networks.

Advertisement
Advertise with NZME.

Read Cult of Mac's take on this here.

And Macs may not get any viruses, but they're not invulnerable either. Mac users can pass on PC viruses to PC users even if they don't affect their Macs in transit, so Mac users in mixed environments should seriously consider installing prophylactic software to stop that happening. It's good neighbourly. (Hopefully, your attitude isn't 'serves 'em right!')

There's the Target Disc Mode vulnerability, too. Apple computers have a unique boot option called Target Disk Mode which allows access to another system's hard drives via a Firewire cable in older Macs and a Thunderbolt cable in newer ones. This is fantastic for literally turning another Mac into a hard drive and copying large files across fast to your own ... however, anyone can do it to anyone.

You access Target Disk Mode by pressing and holding the T key while the system starts. Either the Firewire or Thunderbolt symbol appears on its screen - it doesn't boot up properly into OS X. Cult of Mac has more about this potential vulnerability, including advice about how to stop people doing it to you (of course, they have to have access to your Mac and the right cable, plus some time).

Probably more risky is a Lion vulnerability discovered by a security research firm. A flaw allows attackers to change your system password without any knowledge of its existing password. Ouch. Apparently a change to Lion's authentication system has somehow allowed non-root users to view password hash data.

Chester Wisnieski revealed in a post on the company's Naked Security blog it was Apple's decision to use a local directory service in OS X Lion has left permissions insecure.

Advertisement
Advertise with NZME.

It takes some knowledge - but hackers are hardly ignoramuses. An attacker who has access to a logged-in Mac (locally, over VNC/RDC or SSH protocols etc) is able to change the currently logged in user's password without knowing the existing password as would normally be required via the local directory service. Then they can lock you out - only they have access.

It's not that hard to prevent, and this goes for anyone who uses any connected device: use a secure password. For example, not '1234', '4321' and not 'admin' - mix up letters and numbers. Random is best.

Enable the screensaver and set it to prompt you for your password to use your Mac again after waking it from sleep (System Preferences>Security & Privacy under the General tab).

Disable automatic logon, so you have to put in your password every time you start up your Mac (System Preferences>Users & Groups under Login Options).

And finally, although it's kind of in the 'duh! category: never leave your Mac logged in and unattended - use a Hot Corner to lock your screen.

So yes, people, do take some elementary precautions and keep safe.

Advertisement
Advertise with NZME.

- Mark Webster mac-nz.com

Save

    Share this article

Latest from Technology

Premium
BusinessUpdated

Fringe Benefit Tax: Should you be paying it if your business owns a ute?

18 Jun 06:00 AM
World

What you need to know about Trump Mobile's ambitious phone plans

17 Jun 02:04 AM
Premium
Business|companies

Mighty Ape boss fronts over glitch that saw some users logged into other users’ accounts

15 Jun 11:27 PM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Technology

Premium
Fringe Benefit Tax: Should you be paying it if your business owns a ute?

Fringe Benefit Tax: Should you be paying it if your business owns a ute?

18 Jun 06:00 AM

The IRD says changes should be revenue-neutral – but many have never paid FBT.

What you need to know about Trump Mobile's ambitious phone plans

What you need to know about Trump Mobile's ambitious phone plans

17 Jun 02:04 AM
Premium
Mighty Ape boss fronts over glitch that saw some users logged into other users’ accounts

Mighty Ape boss fronts over glitch that saw some users logged into other users’ accounts

15 Jun 11:27 PM
One NZ expands Starlink partnership to Internet of Things

One NZ expands Starlink partnership to Internet of Things

15 Jun 09:34 PM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP