Researcher says iCloud backups have security shortfalls

By

Lacks 2FA, user alerts.

A Russian security researcher has analysed Apple's iCloud backups and says Cupertino has failed to adequately protect user data.

Researcher says iCloud backups have security shortfalls

Vladimir Katalov earlier this year conducted the first public analysis of Apple's iCloud by sniffing HTTP traffic on jailbroken iOS devices.

The Elcomsoft chief executive found that Apple did not extend its two-factor authentication to protect the online backups which were stored on Microsoft and Amazon servers.

An attacker would still require a victim's username and password to steal iCloud backups but not their linked Apple devices. Cupertino did not send any alerts when user data was downloaded by third parties. 

"In its current implementation, Apple’s two-factor authentication does not prevent anyone from restoring an iOS backup onto a new (not trusted) device," Katalov said in a blog.

"In addition, and this is much more of an issue, Apple’s implementation does not apply to iCloud backups, allowing anyone and everyone knowing the user’s Apple ID and password to download and access information stored in the iCloud.

"This is easy to verify; simply log in to your iCloud account, and you’ll have full information to everything stored there without being requested any additional logon information."

Katalov will present the findings at the Ruxcon security conference in Melbourne today.

Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:

Most Read Articles

India's alarm over Chinese spying rocks CCTV makers

India's alarm over Chinese spying rocks CCTV makers

Hackers abuse modified Salesforce app to steal data, extort companies

Hackers abuse modified Salesforce app to steal data, extort companies

Cyber companies hope to untangle weird hacker codenames

Cyber companies hope to untangle weird hacker codenames

Victoria's Secret pulls down website amid security incident

Victoria's Secret pulls down website amid security incident

Log In

  |  Forgot your password?