Site icon The Mac Security Blog

Response from Apple Regarding iPhone Anti-Phishing Problem

We reported last week that Apple had added an anti-phishing feature to the iPhone OS, but that this feature did not work consistently. It turns out that the feature, while in the operating system, was not “primed”. Apple has responded to this issue in an article on The Loop, saying that users needed to perform an operation to get it to work. An Apple representative is quoted saying the following:

After updating to iPhone OS 3.1 the user should launch Safari, connect to a Wi-Fi network and charge their iPhone with the screen off. For most users this process should happen automatically when they charge their phone.

Now, this is interesting. How are users to know that they have to do this? Nothing on the iPhone tells them to do so, and it is likely that many users never turn on wifi on their iPhones. Apple should have provided an initial database with the iPhone OS update, or should have given clear instructions to users. This is a very lax way of providing a security feature.

We see a number of problems:

All in all, this is a valiant effort, but one which provides no way for users to know if they are really secure.

Share this: