Slashdot Mirror


Sniffer Hijacks SSL Traffic From Unpatched IPhones

CWmike writes "Almost anyone can snoop the secure data traffic of unpatched iPhones and iPads using a recently-revised nine-year-old tool, a researcher said as he urged owners to apply Apple's latest iOS fix. If iOS devices aren't patched, attackers can easily intercept and decrypt secure traffic — the kind guarded by SSL, which is used by banks, e-tailers and other sites — at a public Wi-Fi hotspot, said Chet Wisniewski, a security researcher with Sophos. 'This is a nine-year-old bug that Moxie Marlinspike disclosed in 2002,' Wisniewski told Computerworld on Wednesday. On Monday, Marlinspike released an easier-to-use revision of his long-available 'sslsniff' traffic sniffing tool. 'My mother could actually use this,' he said."

1 of 94 comments (clear)

  1. Re:3G Owners are SCREWED by spinkham · · Score: 4, Insightful

    iPod touch 2g also.

    It was still being sold as the 8 gig version less than 3 months before the announced last software update.

    The 3g 8gig was being sold around 6 months before the last announced software update.

    I understand not getting feature updates, but why can't we get security updates for a device apple was still selling a year ago?

    --
    Blessed are the pessimists, for they have made backups.