Welcome!

Open Source Cloud Authors: Pat Romanski, Elizabeth White, Shelly Palmer, Karthick Viswanathan, Stackify Blog

News Feed Item

Stroz Friedberg Whitepaper Confirms Pairing Records Security Risk in Apple iOS Devices

Firm releases open source tool and offers free recommendations to safeguard personal data

NEW YORK, Aug. 11, 2014 /PRNewswire/ -- A reported security vulnerability in Apple iOS devices by which outsiders could potentially access users' personal data through pairing records has been validated in a whitepaper released by the incident response team at Stroz Friedberg, a global investigations, intelligence and risk management company.

In response, Stroz Friedberg has developed an open source tool, "unTRUST," to allow enterprise and personal users to protect their data on iOS devices such as the iPhone and iPad. The whitepaper also lists recommendations to mitigate the security risk.

"We are proactively sharing the unTRUST tool and free recommendations with corporate America," said Erin Nealy Cox, Executive Managing Director and lead of the incident response practice at Stroz Friedberg. "Enterprises today rely heavily on mobile devices for day-to-day business operations. The breach of even one employee's iPhone has the potential to expose a company's valuable information to their competitors or the public at-large."

The vulnerability can occur when a user connects his or her device to a computer via USB cable and selects "Trust" when the "Trust This Computer?" dialog box pops up. Users have the ability to elect to trust multiple computers and the potential for exploit increases as the number of trust relationships increase.

A pairing record is then created on both the device and the computer in order for them to facilitate a variety of services. An unauthorized person with access to a "trusted" computer or a modified USB charger can exploit these services's USB, remotely or over Wi-Fi and gain access to sensitive personal data. This includes user, application, diagnostic, file and system data. Stroz Friedberg developed its unTRUST tool to remove the pairing records at the heart of the issue.

The security hole was first reported during the Hackers on Planet Earth (HOPE) conference in July by digital forensic scientist Jonathan Zdziarski. He revealed several services present on iOS devices that can possibly provide unannounced packet-sniffing and data-dumping capabilities that bypass device settings and back-up encryption.

Stroz Friedberg undertook an effort to independently test and validate Zdziarski's research and was able to reproduce many of his findings on iOS devices running iOS versions 7 and 8. Details about the process and the unTRUST tool are outlined in the whitepaper, entitled "Mitigating Potential Pairing Record Risks in Apple iOS Devices" and authored by Stroz Friedberg digital forensic experts Cheri Carr and Daniel Blank.

"Stroz Friedberg is committed to protecting businesses from potential security risks," Cox said. "IT departments are increasingly adopting Apple products for use by the workforce because they are already extremely popular with employees. By taking a few proactive measures, they can be assured of the security of these devices."

Stroz Friedberg's unTRUST tool is publicly accessible through its GitHub repository. The firm also recommends general mitigation strategies, among them:

  • Delete all pairing records that currently exist on the iOS device.
  • Trust only one computer (a computer necessary for syncing and updates) and implement security controls on the iOS device and the "trusted" computer.
  • Do not allow other untrusted connections, including connections to other unnecessary computers, and other Internet-connected devices (e.g. kiosk computers).
  • Because the trusted relationship can be exploited through Wi-Fi, disable Wi-Fi when not needed.
  • For trusted computers, implement the following, where possible:
    • Encrypt data-at-rest.
    • Ensure operating system and application patching is kept up-to-date.
  • For iOS devices, implement the following, where possible:
    • Enable complex passwords.
    • Do not store account credentials in clear text on the device.
    • Ensure iOS and apps are kept up-to-date.
  • Corporations should use mobile device management apps such as MobileIron or Good Technology for protection of sensitive documents and emails.

"Mitigating Potential Pairing Record Risks in Apple iOS Devices" is available at www.strozfriedberg.com. The source code and installation files for unTRUST can be accessed at https://github.com/strozfriedberg/unTRUST.

About Stroz Friedberg, LLC
Founded in 2000, Stroz Friedberg is a global leader in investigations, intelligence, and risk services. It provides expertise in digital forensics, cybercrime and incident response, security science, forensic accounting, compliance, due diligence, data disclosure and analytics. Working at the intersection of technology, investigations, regulatory governance and behavioral science, the company is driven by a core purpose—seeking truth so clients can find the assurance and answers they need to move forward with certainty. With twelve offices across nine U.S. cities, London, Zurich and Hong Kong, Stroz Friedberg assists in managing critical risk for Fortune 100 companies as well as 80% of the AmLaw 100 and the Top 20 UK law firms. Learn more at www.strozfriedberg.com.

Media Contacts
Karen Guterl 
212-542-3167 
[email protected]

Ben Tanner 
212-445-8245 
[email protected]

SOURCE Stroz Friedberg

More Stories By PR Newswire

Copyright © 2007 PR Newswire. All rights reserved. Republication or redistribution of PRNewswire content is expressly prohibited without the prior written consent of PRNewswire. PRNewswire shall not be liable for any errors or delays in the content, or for any actions taken in reliance thereon.

@ThingsExpo Stories
SYS-CON Events announced today that Keisoku Research Consultant Co. will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Keisoku Research Consultant, Co. offers research and consulting in a wide range of civil engineering-related fields from information construction to preservation of cultural properties. For more information, vi...
SYS-CON Events announced today that MIRAI Inc. will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. MIRAI Inc. are IT consultants from the public sector whose mission is to solve social issues by technology and innovation and to create a meaningful future for people.
SYS-CON Events announced today that Daiya Industry will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Daiya Industry specializes in orthotic support systems and assistive devices with pneumatic artificial muscles in order to contribute to an extended healthy life expectancy. For more information, please visit https://www.daiyak...
SYS-CON Events announced today that Fusic will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Fusic Co. provides mocks as virtual IoT devices. You can customize mocks, and get any amount of data at any time in your test. For more information, visit https://fusic.co.jp/english/.
SYS-CON Events announced today that Interface Corporation will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Interface Corporation is a company developing, manufacturing and marketing high quality and wide variety of industrial computers and interface modules such as PCIs and PCI express. For more information, visit http://www.i...
SYS-CON Events announced today that Ryobi Systems will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Ryobi Systems Co., Ltd., as an information service company, specialized in business support for local governments and medical industry. We are challenging to achive the precision farming with AI. For more information, visit http:...
Elon Musk is among the notable industry figures who worries about the power of AI to destroy rather than help society. Mark Zuckerberg, on the other hand, embraces all that is going on. AI is most powerful when deployed across the vast networks being built for Internets of Things in the manufacturing, transportation and logistics, retail, healthcare, government and other sectors. Is AI transforming IoT for the good or the bad? Do we need to worry about its potential destructive power? Or will we...
SYS-CON Events announced today that Enroute Lab will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Enroute Lab is an industrial design, research and development company of unmanned robotic vehicle system. For more information, please visit http://elab.co.jp/.
SYS-CON Events announced today that Nihon Micron will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Nihon Micron Co., Ltd. strives for technological innovation to establish high-density, high-precision processing technology for providing printed circuit board and metal mount RFID tags used for communication devices. For more inf...
SYS-CON Events announced today that mruby Forum will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. mruby is the lightweight implementation of the Ruby language. We introduce mruby and the mruby IoT framework that enhances development productivity. For more information, visit http://forum.mruby.org/.
In his session at @ThingsExpo, Greg Gorman is the Director, IoT Developer Ecosystem, Watson IoT, will provide a short tutorial on Node-RED, a Node.js-based programming tool for wiring together hardware devices, APIs and online services in new and interesting ways. It provides a browser-based editor that makes it easy to wire together flows using a wide range of nodes in the palette that can be deployed to its runtime in a single-click. There is a large library of contributed nodes that help so...
DevOps at Cloud Expo – being held October 31 - November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA – announces that its Call for Papers is open. Born out of proven success in agile development, cloud computing, and process automation, DevOps is a macro trend you cannot afford to miss. From showcase success stories from early adopters and web-scale businesses, DevOps is expanding to organizations of all sizes, including the world's largest enterprises – and delivering real r...
While some developers care passionately about how data centers and clouds are architected, for most, it is only the end result that matters. To the majority of companies, technology exists to solve a business problem, and only delivers value when it is solving that problem. 2017 brings the mainstream adoption of containers for production workloads. In his session at 21st Cloud Expo, Ben McCormack, VP of Operations at Evernote, will discuss how data centers of the future will be managed, how th...
SYS-CON Events announced today that Massive Networks, that helps your business operate seamlessly with fast, reliable, and secure internet and network solutions, has been named "Exhibitor" of SYS-CON's 21st International Cloud Expo ®, which will take place on Oct 31 - Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. As a premier telecommunications provider, Massive Networks is headquartered out of Louisville, Colorado. With years of experience under their belt, their team of...
SYS-CON Events announced today that Mobile Create USA will exhibit at the Japan External Trade Organization (JETRO) Pavilion at SYS-CON's 21st International Cloud Expo®, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Mobile Create USA Inc. is an MVNO-based business model that uses portable communication devices and cellular-based infrastructure in the development, sales, operation and mobile communications systems incorporating GPS capabi...
SYS-CON Events announced today that TMC has been named “Media Sponsor” of SYS-CON's 21st International Cloud Expo and Big Data at Cloud Expo, which will take place on Oct 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. Global buyers rely on TMC’s content-driven marketplaces to make purchase decisions and navigate markets. Learn how we can help you reach your marketing goals.
There is huge complexity in implementing a successful digital business that requires efficient on-premise and cloud back-end infrastructure, IT and Internet of Things (IoT) data, analytics, Machine Learning, Artificial Intelligence (AI) and Digital Applications. In the data center alone, there are physical and virtual infrastructures, multiple operating systems, multiple applications and new and emerging business and technological paradigms such as cloud computing and XaaS. And then there are pe...
Real IoT production deployments running at scale are collecting sensor data from hundreds / thousands / millions of devices. The goal is to take business-critical actions on the real-time data and find insights from stored datasets. In his session at @ThingsExpo, John Walicki, Watson IoT Developer Advocate at IBM Cloud, will provide a fast-paced developer journey that follows the IoT sensor data from generation, to edge gateway, to edge analytics, to encryption, to the IBM Bluemix cloud, to Wa...
With major technology companies and startups seriously embracing Cloud strategies, now is the perfect time to attend 21st Cloud Expo October 31 - November 2, 2017, at the Santa Clara Convention Center, CA, and June 12-14, 2018, at the Javits Center in New York City, NY, and learn what is going on, contribute to the discussions, and ensure that your enterprise is on the right path to Digital Transformation.
SYS-CON Events announced today that App2Cloud will exhibit at SYS-CON's 21st International Cloud Expo®, which will take place on Oct. 31 – Nov 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. App2Cloud is an online Platform, specializing in migrating legacy applications to any Cloud Providers (AWS, Azure, Google Cloud).