Another iPhone worm - and this time it's malicious
I had guessed we would see a dangerous incarnation of worm for the iPhone within a week of the 5 Euro scam that Graham blogged about on November 3rd. Fortunately my predictions were wrong, and we made it almost 3 weeks before someone succumbed …
Context & Ripple Effects
iPhone security concerns had moved beyond demonstrations and vulnerability hunting: earlier coverage tracked researchers probing iPhone vulnerabilities and malware being sold around the device. In November 2009, a tool reported to copy personal information from iPhones and guidance on securing jailbroken iPhones made device compromise an immediate user-security issue.
The confirmed discovery of a malicious iPhone worm turns that risk from isolated access or proof-of-concept activity into an active malware threat, raising the stakes for users who alter their devices' default security posture.
First-order effects
- iPhone owners, particularly those running jailbroken devices, face an active malware risk rather than only the risk of unauthorized access or data-copying tools.
- Apple's iPhone ecosystem acquires a visible security incident that makes device-hardening guidance more urgent for users and support providers.
Second-order effects
- Security vendors and iPhone-support communities must shift from explaining how to jailbreak securely to identifying and containing infections on already-modified phones.
- The incident makes the security trade-off of jailbreaking more salient for prospective users, putting pressure on unofficial software and modification practices that depend on weakened device controls.
Third-order effects
- Repeated iPhone malware episodes would establish smartphones as endpoints requiring ongoing patching, access control, and malware response rather than as comparatively self-contained consumer devices.
- As high-use mobile platforms become more valuable targets, security differentiation is likely to become part of competition between device ecosystems, not merely an after-market concern.
The trend: Mobile computing is inheriting the malware and endpoint-security problems previously associated with PCs as smartphones become high-value, always-connected targets.