Exploit that Caused iPhones To Repeatedly Dial 911 Reveals Grave Cybersecurity Threat, Say Experts (9to5mac.com)
Ben Lovejoy, writing for 9to5Mac: We reported back in October on an iOS exploit that caused iPhones to repeatedly dial 911 without user intervention. It was said then that the volume of calls meant one 911 center was in 'immediate danger' of losing service, while two other centers had been at risk -- but a full investigation has now concluded that the incident was much more serious than it appeared at the time. It was initially thought that a few hundred calls were generated in a short time, but investigators now believe that one tweeted link that activated the exploit was clicked on 117,502 times, each click triggering a 911 call. The WSJ reports that law-enforcement officials and 911 experts fear that a targeted attack using the same technique could prove devastating. Of the 6,500 911 call centers nationwide, just 420 are believed to have implemented a cybersecurity program designed to protect them from this kind of attack.
Because programming
How does someone "accidentally" release something that will repeatedly call 911 on thousands and thousands of phones? Sounds like the creator is full of bullshit or stupid beyond comprehension.
and since most IOS users are on the latest version how is this still a problem?
One wonders if this was coordinated with a specific crime or if it was just a demonstration and they are selling to the highest bidder?
Build a Man a Fire, and He'll Be Warm for a Day. Set a Man on Fire, and He'll Be Warm for the Rest of His Life.
Don't most/all places charge for obviously-inessential calls to 911? Sure, you were down for a day, but the amount of money that this should make for the 911 center should be immense and ought to be able to fund whatever is needed to handle the load next time.
Pretty much the only way someone can snatch defeat from these jaws of victory, is if they don't charge the callers.
There are other upsides to charging the callers, too. It puts them in the position of demanding their OS be secured, and for insecure OSes to be their own punishment. Users having financial incentive to secure their machines (or hold vendors accountable) is basically THE HOLY GRAIL of mass-market computer security. Usually the users are able to externalize the actual costs, thereby preventing things from ever getting better, but a receiving an invoice from a 911 center ought to do the trick.
I never felt Apple's IOS or Mac OS was any better than any other OS at protecting users. I think Apple has become more away of the issues, but still lacks a ability to immediately address issues fast enough. But the end user must be more aware of the exploits and recognizing a issue.
Innocent? Original "cordless phones" used to dial 9-11 as battery failed (sputtered on/off that could be 9 - pause - 1) nobody foresaw this Any chance that this could be accidental? If not, criminal?
all in WAshington state and Colorado, I assume
This is not an exploit. It is an app that asks for the user to give it permission to make phone calls, which the user grants. Then the app calls 911.
There is nothing about iOS that is "exploited" to make this happen. The only thing that is exploited is user stupidity, which should come as no surprise given that education is the least important priority in the US.
... is what someone says right before they are about to be an alarmist.
because there aren't enough skilled programmers in the US, the country that invented computing and programming. We need people from countries where they walk barefoot.
What if christians or atheists did? After all they do kill more Americans than the muslims.
Imagine a robo-call-DDOS attack on certain lawmakers' phones during a crucial debate, denying those lawmakers input from consituents?
Imagine an attack on a company, either to force them to spend money they wouldn't have to spend, to embarrass them, or to distract them from doing things that would compete with another company in which you ("you" being a corrupt person, company, or government) has an interest in.
Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
Twice in my life I've dialed 911, both times on a weekend night, both times because I witnessed a stranger getting beaten and not in a fun/fair Fight cCub way, but in a "these five people are going to kill that guy" way. And no, I'm no hero...neither mentally nor in any physical way I could have intervened.
So dial 911 and it's busy....BUSY. Redialing, etc, etc. and busy. So either the city I live in is way more dangerous than I think, or 911 already gets DDOS attacks from the sheer volume of what I hope are dumbasses ...my cat is stuck in a tree, sort of calls.
There simply isn't a bigger emergency than a problem with an iDiot's iPhone.
Errr...so you are saying they might coordinate a mass pork barbecue attack? Those bastards!!
It is interesting to see a proof of concept DDOS-style attack using a phone as a vector point.
Probably a matter of time before we see this on android as well.
Good outside the box thinking, I guess.
Typical of Apple.. "We are so secure we do not need antivirus programs.. ( leaving the holes completely open, as there are hundreds of exploits out there for apple Mac and Apple iphone, Apple just does not know about them, and they are to pig headded to admit that their phone is less secure then an Android without a virus protection... The age of "No one writing viruses and exploits for Apple products" was over about 10 years ago, The reason that Apple was "secure" was Kiddie Koders did not bother with the "Apple" stuff, as NO ONE was using them.. As soon as the "iphone" became popular the viruses started coming in. Keep in mind that Viruses are NOT what they used to be, where the virus would destroy the data or lock the phone, OHHHH NOOO,,, the virus builders are smart now, they let their viruses live undetected in the phone/device, waiting for the user to enter something useful to the virus programmer, like a credit card number or password..
Now Apple is going to get burned, as they are so far behind the "security" curve, its laughable,, And everyone with a "name brand" idevice, is going to understand exactly why everyone says "USE DROID"... https://it.slashdot.org/story/17/03/06/1431234/exploit-that-caused-iphones-to-repeatedly-dial-911-reveals-grave-cybersecurity-threat-say-experts?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed%3A+Slashdot%2Fslashdot+%28Slashdot%29#
Apple thought of this from the beginning.
There are no permissions for apps to make phone calls on iOS. There is no API for apps to make phone calls on iOS. All you can do is pass a phone number url to the phone app, and user has control over the call.
I suspect this is only a jail break issue.
Just block all iphone based called from the 911 system permanently. In fact, block all AT&T customers too. They're not worth the resources.
(This post is a joke btw, just in case you're an idiot)
9 11 experts
420 centers
over 9000 calls...
The 6500 nationwide call centers are clearly a distraction.
just 420 are believed to have implemented a cybersecurity program designed to protect them from this kind of attack
How can they protect against a DDoS? I assume the protection must let legitimate call pass through, but how can they be recognized?
Just how exactly are certain call centers "equipped" with measures against phone calls?