Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Cellphones Security

Watered Down Phishing Protection In IPhone OS 3.1? 98

CrazyCanucklehead writes "Security Researcher Michael Sutton discusses his findings when looking at the advertised anti-phishing features in the recently released iPhone OS 3.1. It turns out that the protection is far less than what is provided in OS X and the feature may not provide any protection at all."
This discussion has been archived. No new comments can be posted.

Watered Down Phishing Protection In IPhone OS 3.1?

Comments Filter:
  • by nneonneo ( 911150 ) <spam_hole.shaw@ca> on Thursday September 10, 2009 @01:44PM (#29380679) Homepage
    I followed the same steps as outlined in TFA: download the verified online [phishtank.com] phishing list, pick a few URLs and load each into MobileSafari.

    The very first one on the list, citibanking.ru, was blocked by both Firefox and MobileSafari. Since it was at the top, I thought that perhaps it was too recent (reported Sept 10, 2009), so I went down the list a bit, and got colorear.org/ray/, also blocked on Firefox and MobileSafari (reported Aug 26, 2009). guildoftibia.w.interia.pl was also blocked on both (reported July 28, 2009). I also found a few that were blocked on neither, but none that were blocked only on one and not the other, suggesting that MobileSafari uses Google's list (further reinforced by the fact that the "about" link takes you to a help page on Google [google.com].

    So, I call sloppy research on the part of this security researcher (who writes "In fact, I have yet to identify a single phishing page blocked on the iPhone", emphasis his), since I was quite easily able to find several pages which were blocked.

Say "twenty-three-skiddoo" to logout.

Working...