On Friday, Apple announced a significant security flaw affectingliterally hundreds of millions of iPhones, iPads and iPod Touchesrunning iOS 7, the latest version of the company's mobile operatingsystem.

|

Baked into the system was a flaw that allowed an attacker, undercertain circumstances, to intercept and read in plain sight trafficthe users thought was encrypted via Secure Socket Layertechnologies. That would include email, tweets, Web browsing and,potentially, mobile banking sessions that occur within the Webbrowser.

|

Mark Bower, a vice president at Voltage Security, elaborated:“For quite some time, attackers with knowledge of this bug had theability to mount man-in-the middle attacks to users operating Appledevices. This could have allowed interception or modification ofSSL communications which are supposed to be private andencrypted.”

|

Experts appear divided as to whether this flaw also impactedtraffic via apps, such as mobile banking apps.

|

On Friday, Apple issued a patch that it said fixed the problemon iPad, iPhone and iPod Touch.

|

However, the company also indicated that a related flaw existsin its OS 10 operating system for desktop and laptop computers. Nopatch has been issued so far, although Apple has indicated that oneis imminent.

|

Note, too, the SSL attack can occur only when the hacker hascontrol over a WiFi network (typically a public network) or haserected a rogue cellular network (technically doable butsophisticated and rare). This requires significant skill on thepart of the attacker, said experts.

|

Users who never access public WiFi probably have nothing tofear, said most experts.

|

Experts also, unanimously in this reporter's poll, urged Applemobile device owners to download the security patches as soon aspossible.

|

Experts also suggested that financial institutions such ascredit unions alert their members who use Apple devices to the needto download the patch, which is free.

Complete your profile to continue reading and get FREE access to CUTimes.com, part of your ALM digital membership.

  • Critical CUTimes.com information including comprehensive product and service provider listings via the Marketplace Directory, CU Careers, resources from industry leaders, webcasts, and breaking news, analysis and more with our informative Newsletters.
  • Exclusive discounts on ALM and CU Times events.
  • Access to other award-winning ALM websites including Law.com and GlobeSt.com.
NOT FOR REPRINT

© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.