iPhone, Safari, IE 8, Firefox hacked in CanSecWest contest
Updated 5:17 p.m. PDT with successful Firefox hack. — VANCOUVER, B.C.—Researchers on Wednesday demonstrated that they could hack a non-jailbroken iPhone, Safari running on Snow Leopard and Internet Explorer 8 and Firefox …
Context & Ripple Effects
CanSecWest had already exposed Apple desktop and browser defenses through a MacBook compromise at a security contest in 2007 and a Safari win at Pwn2Own in 2009. The 2010 results widen that recurring public test from browser software to a non-jailbroken phone, overturning the earlier “Smartphones 1, Hackers 0” framing.
First-order effects
- Apple, Microsoft and Mozilla face immediate pressure to investigate and patch the vulnerabilities demonstrated against their iPhone, Safari, Internet Explorer 8 and Firefox products.
- The iPhone compromise puts mobile-device data protection alongside browser security as a demonstrated target for contest researchers.
Second-order effects
- Browser vendors must treat exploit resistance as a visible competitive issue when several leading products fall in the same event.
- Security researchers and buyers gain public evidence that a handset’s restrictions do not eliminate the value of browser and operating-system attack research.
Third-order effects
- If contests continue to expose flaws across PCs, browsers and phones, they will become a more important disclosure and patch-prioritization mechanism for platform vendors rather than a niche test of desktop software alone.
The trend: Public exploit contests are broadening from isolated browser and computer demonstrations into cross-platform tests that include mainstream mobile devices.