October 31, 2008

Intel's Moorestown would make iPhone less secure

Intel is widely believed to be hopeful that Apple will adopt the chip package, but a security researcher warns that x86 processors are familiar territory for hackers

Putting Intel's Moorestown chip package inside a future version of the iPhone would make the smartphone less secure, according to an independent security researcher.

"That will make the iPhone x86 and that will make a lot of attacks easier," said Dino Dai Zovi, an independent security researcher, in an interview at the Hack In The Box security conference in Kuala Lumpur, Malaysia.

[ For a look at other enterprise-worthy smartphones on the market, check out "Supersmart phones for extreme mobility." For more on bringing the iPhone into the office, read "How to make the new iPhone work at work." ]

Due for release in 2009 or 2010, Moorestown is a chip package designed for smartphones and other handheld computers. The heart of the package is an upcoming version of Intel's Atom's processor, an inexpensive low-power x86 processor. Apple has never said it intends to use Moorestown in future products, but Intel is widely believed to be hopeful that Apple will adopt the chip package.

"The iPhone uses the Arm processor and most people are not familiar with it," Dai Zovi said, noting that x86 processors are familiar territory for malware writers and hackers looking for vulnerabilities.

"If you're doing exploits and vulnerability research, you need to know the specifics of the processor that's running," he said.

Dai Zovi is a well-recognized figure in computer security circles and is widely known for winning a 2007 hacking contest  that involved hacking into a MacBook Pro laptop. The feat by Dai Zovi and partner Shane Macaulay won them the MacBook Pro as well as a $10,000 prize, and laid to rest popular misconceptions that Mac OS X was somehow immune from the type of security vulnerabilities that affect Windows-based computers.

Intel executives declined to comment on Dai Zovi's remarks, saying any discussion of a Moorestown-based iPhone is purely hypothetical. In addition, they said Intel's policy is to decline comment on other companies' products.

Mac OS X is seen as generally safer than Windows, because the small market share of Mac OS X means most malware writers and hackers choose to focus their efforts on Windows instead. But that could change as iPhone sales boost the number of Mac OS X users.

"The iPhone is another OS X platform and whereas now the market share for OS X is definitely under 10 percent on desktops, on smartphones they recently sold more phones than RIM," Dai Zovi said, referring to the maker of the BlackBerry line of handheld devices.

The iPhone runs a slimmed-down version of Mac OS X, the operating system used in Apple's desktop and laptop computers. As a result, some of the security features that are included in the desktop version of Mac OS X are not included in the phone version.

"The iPhone is significantly less secure than the desktop version of OS X," Dai Zovi said.

Close

On Twitter now

Networking

Powered by Twitter

On Twitter now

additional resources
White Paper - How to Improve Delivery of Advanced Web Applications

White Paper

Virtual Workforce: The Key to Expanding The Business While Cutting Costs

Get the independent advice and expertise you need to support a virtual workforce.

Go inside:
The three-step approach to making a virtual workforce a reality.
The four flavors of client virtualization technologies.
The three key initiatives that solve IT challenges.
Download now »
White Paper: Successfully Secure Your Wireless LAN With Wi-Fi firewalls.

White Paper

Addressing Linux Threats Leveraging Fewer Resources

The increase in Linux popularity has increased the frequency and sophistication of malware attacks. Read this 2 page white paper now to learn how you can protect your Linux environment with real-time protection that is certified by all major Linux vendors.

Download now »
White Paper - The 2009 Handbook of Application Delivery

White Paper

The 2009 Handbook of Application Delivery

Ensuring acceptable application delivery will become even more difficult over the next few years. As a result, IT organizations need to ensure that the approach that they take to resolving the current application delivery challenges can scale to support the emerging challenges. This handbook elaborates on the key tasks associated with planning, optimization, management and control and provides decision criteria to help IT organizations choose appropriate solutions.

Download now »
White Paper - Is Your Backup System Outdated?

White Paper

Mid-range Storage Considerations

A common misconception is that mid-range storage requirements are dramatically different than that of a larger enterprise. Mid-range storage users may require less capacity, but they have similar functionality and management requirements. This ESG paper examines mid-range storage needs and reviews a new solution that adjusts size while retaining value, performance and functionality.

Download now »

Sign up to receive Networking Resource Alerts

Subscribe to the Today's Headlines: First Look Newsletter

Find out what will be news for the day, with our first-thing-in-the-morning briefing.

©1994-2010 Infoworld, Inc.