UPDATED 15:47 EST / NOVEMBER 08 2011

NEWS

Charlie Miller’s Latest Security Revelation Rocks the Apple App Store

Charlie Miller, a former NSA analyst that now works for security firm Accuvant, has taken it as a personal challenge to find exploits in Apple’s products since 2007. After his latest discovery however this dedication backlashed, and Apple went as far as terminating his developer license.

Apple’s fairly criticized approach of controlling its ecosystem by closely monitoring the apps available on the App Store, the only source of third party applications available to iOS users, has a history of stirring some debate. But it’s highly effective when it comes to keeping users’ devices safe. Applications that may run un-approved commands on an iProduct have no way of getting to a user’s device; or at least that’ was we thought until Miller’s latest discovery.

Miller will reveal a bug in Apple’s system at the SysCan conference in Taiwan next week that will demonstrate how it is possible to bypass these security measures. Before going public with it though, he already uploaded an app to the App Store called Instastock which effectively exploits this vulnerability. Needless to say Apple pulled the app from its storefront.

According to the security expert, the vulnerability has to do with excess permission given to javascript code running on iOS 4.3’s browser designed to boost performance.

“In fact, he realized, the browser’s speed increase had forced Apple to create an exception for the browser to run unapproved code in a region of the device’s memory, which until then had been impossible.

As noted above, Millar already has a portfolio of bugs and exploits he single-handedly discovered in Apple products. In July, he uncovered a security flaw in the Mac’s battery firmware that can enable hackers to inject malware that can’t be removed by simply formatting the machine.

iOS is far from being immune to malware. A Skype exploit was discovered not to long enough that provided hackers access to a victim’s contact list, and it’s only one of many. One of the best indicator of that is Lookout Security’s recent launch on iOS.


A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.