New iOS flaw makes devices susceptible to covert keylogging, researchers say
Proof-of-concept app in Apple's App Store sent keystrokes to remote server. — Researchers said they have identified a flaw in Apple's iOS that makes it possible for attackers to surreptitiously log every touch a user makes …
Context & Ripple Effects
The finding lands during a bruising stretch for Apple's security posture. The company is still working through the "goto fail" SSL vulnerability, confirmed in February 2014 to allow interception of encrypted traffic to the App Store, iCloud, and apps like Twitter, with the fix shipping in OS X Mavericks 10.9.2. On top of that, researchers publishing through FireEye's blog demonstrated that a proof-of-concept app available in the App Store could log every user touch and send the keystrokes to a remote server — meaning Apple's review process cleared an app whose core behavior was surveillance.
The pickup was unusually broad for an academic-style disclosure: ZDNet, Computerworld, AppleInsider, 9to5Mac, MacRumors, and Softpedia all carried the story on or about February 25, 2014, a signal that it struck at the central selling point of Apple's closed ecosystem — that App Store curation keeps hostile software out.
First-order effects
- Apple faces direct questions about how the proof-of-concept passed App Store vetting, since the review process failed to flag an application whose primary function was covert touch logging.
- Anyone who installed a similarly built app would have every keystroke and screen touch silently transmitted to an attacker-controlled server, with no on-device indication of the exfiltration.
Second-order effects
- Enterprise IT buyers evaluating iPhone deployments gain fresh ammunition against Apple's security pitch, arriving in the same window as the goto fail SSL interception flaw rather than as an isolated incident.
- App Store review teams face pressure to move beyond code inspection toward behavioral analysis of running apps, which raises per-app review cost and slows submission turnaround across the developer base.
Third-order effects
- If curated storefronts demonstrably admit behavior-based surveillance apps, the long-standing assumption that mobile platforms need no endpoint security software weakens, opening room for third-party mobile defense vendors and regulatory scrutiny of app-store vetting practices.
The trend: Mobile platform security is shifting from trusting curated app stores as a sufficient control toward assuming malicious apps are already inside, forcing vendors toward runtime defenses and behavioral vetting.