Researchers Find iOS Malware That Infects Non-Jailbroken Devices (paloaltonetworks.com)
An anonymous reader writes: Researchers at Palo Alto Networks are reporting about a new iOS malware that could infect non-jailbroken devices without a user's consent. Dubbed "AceDeceiver," the iOS malware exploits a flaw in Apple's DRM software. The researchers claim that the iOS malware could technically infect any type of iOS device, provided a user downloads a third-party app. From the blog post on Palo Alto Networks' website, "AceDeceiver is the first iOS malware we've seen that abuses certain design flaws in Apple's DRM protection mechanism -- namely FairPlay -- to install malicious apps on iOS devices regardless of whether they are jailbroken. This technique is called "FairPlay Man-In-The-Middle (MITM)" and has been used since 2013 to spread pirated iOS apps, but this is the first time we've seen it used to spread malware." The aforementioned malware required users to download a compromised Windows application. Apple has removed three offending apps from the App Store, and it appears that only users in China were targetted.
we'll ride them someday
they now have their backdoor into the system courtesy of the Chinese.
Wheel of Time: Book by Book and Sumview (summary review) Bigdady92 style: http://bigdady92.blogspot.com/
Well that's what happens when you have software that ignores the user's actions and overrides them. You want to do it "for protecting copyrights", but the software isn't coded to obey copyrights (it wouldn't be DRM if it did, since the copyright owners don't want their copyrights managed to the extent of the law, they want extrajudicial rights you cannot get returned by a court case), so it doesn't give a shit what you want to use it for, it just avoids letting the user use their device for what they want and insists on overriding it.
It's ALL malware.
It's merely legally protected and "normalised" malware for people with official money and power, rather than unofficial money and power.
Modern app appers know that ONLY apps can app apps, and Apple's AppPhone is so appy, that it's impossible for LUDDITE malware to infect it!
Apps!
"...the iOS malware exploits a flaw in Apple's DRM software"
O The Irony.
Trying to protect their profits creates a situation that will almost certainly cost them money.
Just cruising through this digital world at 33 1/3 rpm...
For those interested in how the attack works, it relies on having a specific piece of malware (something akin to a rogue version of iTunes that runs in the background) installed first on your PC. After that, from what I understand, the attack roughly goes like this:
1) Attacker submits a piece of iOS malware to the official App Store and has it accepted.
2) Attacker purchases their own iOS malware from the App Store, receiving an authorization code for the purchase.
3) The PC malware gets the authorization code from the attacker.
4) The PC malware masquerades as iTunes to tell your iOS device that a new purchase is ready to install.
5) The PC malware provides the authorization code it received from the attacker.
6) Your iOS device downloads the iOS malware from the App Store.
Strangely, even though the offending apps have been pulled from the App Store, they're still available to people who have previously purchased them...including people who are getting infected via this attack, since that authorization code acts as proof of a previous purchase. Your device just thinks it's a previous purchase you made in iTunes but hadn't yet synchronized over to your device.
As for how the iOS malware was able to get into the App Store in the first place, apparently they were using geolocation to make the app display benign content in the App Store reviewer's location (in this case, they were acting like useless wallpaper apps) while serving up malicious content in China.
It's a gooder form of targeting.
The ability of reusing authorization codes is pretty bad. I am surprised it's not locked to the iTunes/Apple ID. I guess that would be the next step by Apple.... unless there is some reason that doing that would be a problem?? I can't really see why. Maybe it would effect free app give-away codes? Honesty don't know.
They really need better support. My BlackBerry is over 3 years old now, yet I just got an OS update last week. I wonder why a larger manufacturer like Samsung can't be bothered to push updates for at least as long as the average contract length!
Required reading for internet skeptics
"a new iOS malware that could infect non-jailbroken devices .. provided a user downloads a third-party app"
What would make a real story is if this 'iOS malware' infected the device without the user visiting a malicious website, downloading and explicitly installing the malware.
--
Lately, we've been seeing a lot of free adverts for Palo Alto Networks?
In this case, "targetted" is the past tense of the verb "target". For historical reasons, the accepted spelling is "targeted" with just 2 t's in total, whereas the intuitive spelling, with 3 t's in total, is conventially regarded as a misspelling.
Sounds just like cancelled vs canceled. Both are acceptable, though double-L is the more common usage (although that's changing).
Make sure everyone's vote counts: Verified Voting