7 ms·
Mailbox iOS app is a security fail
Mailbox iOS app is not even using file protection API that iOS SDK provides by default.
- deleted 13y ago[deleted]
- Samuel_Michon 13y ago“if anyone else can get hold of your phone, he can access to files of those apps where data is not protected.” As always, if someone has physical access and unlimited time, no device or computer is safe. Also, Mailbox.app only supports GMail. Security minded people are obviously not the target market.
- erishig 13y agoDoes that mean that basic security should not be in a company's mind, especially when it comes to the kind of data emails can contain? Mailbox is BIG. We are not talking of an average app here!
- Samuel_Michon 13y ago“Does that mean that basic security should not be in a company's mind” I wasn’t suggesting it shouldn’t be. My point is that the article’s headline is overly dramatic: Mailbox.app is not a complete security failure because of one hack that requires physical access. Given that Mailbox only supports GMail, I’d be more worried to put my email in Google’s hands than worrying over someone grabbing my phone out of mine. “Mailbox is BIG. We are not talking of an average app here!” Mailbox.app is a free app that has been downloaded a couple of million times, I wouldn’t call it “BIG” yet. It’s very new, it’s still on version 1, so it’s not expected to be perfect.
- bloblaw 13y ago> Mailbox.app is not a complete security failure because of one hack that requires physical access The problem is that we take mobile devices with us every place we go. So physical access is not difficult to obtain. This really is a big deal primarily because the developers of Mailbox.app did not take steps to even obfuscate the stored data...which would deter all but the most determined of attackers.
- DanBC 13y agoEmail is not secure. Email has never been secure. Nothing you send over email is secure. There's little authentication and no signing. All this stuff can be kludged onto email, but the attitude should be "unless I've taken measures to add security this thing is not secure".
- potatolicious 13y agoSure, but that's also like saying "car accidents are inevitable, so let's not put on our seat belts". A basic bit of security, especially one that doesn't put any more load on the user (to have to maintain or set up) is a pretty big no-brainer. Raising the bar for a successful hack is also worth doing when the cost is a single line of code and no effort on the user's part.
- DanBC 13y agoIf we're using analogy it's more like telling bicycle riders to use anti-puncture tape. Sure, it'll reduce the chance of getting a puncture but does nothing when they go under a truck. What's on offer here? 10 minutes extra tamper resistance? For a protocol which is inherently insecure?
- potatolicious 13y agoWhat's on offer here is the ability to exclude a large class of attackers entirely - script kiddies with a commonly available file explorer tool. Sure, if you're the CEO of some big company and a skilled attacker really wants at your email, this is only a stopgap - but this is also sufficient to stop less proficient attackers entirely. For most people this is all they need. > "it's more like telling bicycle riders to use anti-puncture tape." If anti-puncture tape has literally no downsides whatsoever to the bicycle rider's experience, and costs nothing, then yes. Why wouldn't you have it?
- Blahah 13y agoActually a small class of attackers - script kiddies with a commonly available file explorer tool and physical access to your phone.
- huskyr 13y agoIf you get physical access you can also read all the mails in Apple's Mail.app, or any other app on the device. Maybe not using a tool, but you can easily read them in the app, forward them, and send fake e-mails using the account of the user. (edited to make my point more clear :)
- 0x0 13y agoAre you sure about that? I would think that Mail.app used apprioriate file protection settings, in which case the file contents is encrypted with a key derived from the user's PIN/passcode
- delinka 13y agoThat's not entirely correct. If the app uses the correct APIs to inform the system that particular files need more protection, then those files receive more protection. The details are available to a free dev account on Apple's developer site. As long as the device remains locked, such files remain encrypted. Whether users pick appropriate passwords is another matter entirely.
- andyhmltn 13y agoOr, you could just... open up Mail.app? and read the emails without a tool haha.
- huskyr 13y agoYes, that's my point.
- potatolicious 13y agoNot if the device is locked. The author talks about this in the post - a properly secured file is only decrypted when the device is unlocked (in which case the mail is readable by anyone with fingers, no need for fancy USB cables). When the device is locked the file is encrypted and cannot be easily retrieved with a USB cable and a file explorer. An app that does not properly secure its files is readable even when the device is locked.
- 13y ago
- fruitydrink 13y ago@Samuel_Michon I take issue with the crap you are spreading. >if someone has physical access and unlimited time There is no such thing as unlimited resources. If I had unlimited time I could crack every encrypted message on the planet. Using DPAPI turns a 30 second hack into an online cracking job. The crypto processor in the iPhone can only check one password every ~80ms and you need the chip with you. An attacker cannot do an offline attack.
- mikeash 13y agoYou are confusing access to the computer itself with access to the data it contains. Given physical access and "unlimited" time (i.e. no more than a million human lifetimes, say), then certainly an attacker can gain access to the device and make it do what he wants. However, if the data on the device is securely encrypted, then physical access and (reasonable) time doesn't matter. He won't be able to get at the data.
- deleted 13y ago[deleted]
- nezza-_- 13y agoAn important fact is wrong: You actually need to unlock the device to access the data unless the iPhone and the computer were paired before.
- cvursache 13y agoDon't have any data on this, but I know a bunch of not-so-tech-savy people that don't use lock codes. Their data's then as naked as a greek nude.
- johansch 13y agoIf the device is not locked, how about just launching the Mailbox app and browse the attachments via its fancy UI? :)
- subhb 13y agoOn any app that consists of sensitive information, one should probably implement passcode security on the application itself. Now this might annoy some users, but if you know you are going to use it for something special, you won't mind it!
- tmpajk 13y agoSo therefore, your article could have been titled "{Mailbox|GMail|iMail|all_other_mail_clients_ever} is a Security Fail!"? Because as far as I am aware, few mail clients either support or (if they do) actively encourage an extra password layer, and your users do not want it. Given an average un-password-protected phone, you will be able to read their email even if they were using the iOS encrypted files framework, just by opening the app. I apologize, but it appears that your headline is deliberate sensationalism. If you want to have a discussion about how we need to secure email apps in general, I'm interested. If you want to just pick the latest 'big thing' and take pot shots at it, nah.
- subhb 13y ago
- mariusmg 13y agoIf you lose your phone is already game over. Here's a idea...if you have important data that you want to be secure.....DON"T KEEP IT ON YOUR PHONE. How about that, huh ?
- subhb 13y agoHow about making it more secure! Won't it solve the problem? It's just not about Mailbox app it's about all the apps that should protect user's data. Should they care about their user's data or leave it up to the device to protect it?
- mariusmg 13y agoNo. Sorry but encryption doesn't really solve the problem. If you lose the device with valuable info on it, the info will be recovered even if it's encrypted.
- AlexandrB 13y agoEncryption absolutely solves the problem. Otherwise any kind of online security would be impossible. You might need to use an actual strong password though and not the 4 digit passcode.
- uzyn 13y agoThis is like telling someone you can access his ~/Documents/ and read the content of files within when he leaves his laptop unattended and logged in.
- subhb 13y agoOne need to handle security differently for mobile devices and for laptops. When it comes to the example I gave above in one case a person can read the contents of the files, in another case the same person can copy your entire content. Now if that's not something to worry about, what is!
- andyhmltn 13y agoThat's not worrying at all. Considering you need the passcode of the device to do so. If they have the passcode, or there isn't one, then the attacker can just open the app and look without extracting the files. These aren't passwords stored in plaintext. This is plaintext stored in plaintext.
- cheffe 13y agoThere is a secure store solution available from a company located in germany. They call it "Secure Incremental Store" - an enhancement for Core Data.
- uptown 13y agoI'm less concerned about physical access to the device, but more concerned about third-party services like Mailbox increasing the number of attack vectors on your inbox. Mailbox has total access to your email account. Now somebody can either attempt to hack Google's servers, or Mailbox's servers. It's enough to convince me not to sign-up for their service since email provides the gateway to virtually everything else.
- jalada 13y agoThis. Why is no one talking about this massive elephant in the room? Mailbox wants you to trust it (and its employees) with (reversibly-encrypted? I haven't used the app but I don't know how it could provide all its features without this) access to and storage of your Gmail account and all your emails?! I barely trust Google with that. This article just helps compound the idea that that trust might be a little misplaced....
- scrumper 13y agoMailbox was nice, but I dropped it after a week when your point occurred to me. As far as I could tell, the only reason it needed full access was for push notifications. There was no discussion at all of account security, and I just couldn't bring myself to trust them. There's no way one of the usual cutesy startup apologies would cut it here if they compromised my email. I'm back to Sparrow now (which doesn't do push) and quite happy: Mail.app tells me I have a new message, then I process my emails in Sparrow.
- jder 13y agoThe original article misses the whole point of the NSFileProtection API: the strongest level of protection, NSFileProtectionComplete, prevents access to files while the device is locked. The whole point of the API is to protect things until the user has authenticated. (It's quite possible Mailbox is already using this API, given the evidence presented.) In other words, this is the expected behaviour when your phone is unlocked. See: https://developer.apple.com/library/ios/documentation/Cocoa/Reference/Foundation/Classes/NSFileManager_Class/Reference/Reference.html#//apple_ref/doc/constant_group/File_Protection_Values https://developer.apple.com/library/ios/documentation/Cocoa/...
- danpalmer 13y agoI'd recommend "Hacking and Securing iOS Applications" by O'Reilly. It really explains well the security and permissions model on the phone. The argument that 'once you've lost the phone you've lost the data anyway' isn't really fair. If a passcode is being used, data marked as being a security concern is protected with the passcode. A 4 digit code is trivial to brute force, yes, but the point is that it should be done anyway. Using iExplorer to find files is a lot easier than loading a custom bootloader on to the phone, booting custom firmware, brute forcing the passcode and decrypting the files. If anything, the extra time will raise the chance that you can get to a computer and initiate a remote-wipe.
- subhb 13y agoCan someone verify this with an iOS5 device. On iOS 6.1.3 this doesn't work anymore though. But someone just claimed this on the blog: "I ran a test using my iPhone 5 and a computer I’ve never synced with before. I didn’t need to unlock the phone before getting access to it I don’t believe. I did manage to browse all my mailbox files."
- mikehotel 13y agoYou don't need to sync your device to pair it. This someone may have connected his unlocked device to the computer, which is enough to pair the device. Once a device is paired, the file system can be browsed regardless of lock status. I have not tested with a new 6.1.3 device yet, but if true, this would be a very serious security regression.
- bengotow 13y agoMailbox.app is a security concern because it copies all of your Gmail to it's own cloud server, and delivers the email to the app from there. Sure, it's exposing your emails on the device. I'm more concerned about them exposing _everyone's_ emails when their cloud platform is exploited.