Read The Times Australia

Daily Bulletin

Jailbreaking iOS frees you from Apple but exposes you to malware

  • Written by: The Conversation
imageApple's 'walled garden' might be frustrating, but it does protect your devices from being hacked.Faris Algosaibi/Flickr, CC BY

While Apple’s Mac OS X reputation for superior security to Windows has little technical basis, iOS (the operating system for iPhones and iPads) is a very different story. As such, when nearly a quarter of a million Apple accounts were compromised by malware recently, it was a big surprise for many people.

So far Apple has been able to keep the iPhone and iPad almost completely free of malware. While iOS malware – some of it apparently created by intelligence agencies – does exist, only a minority of users have been vulnerable to most of it.

And to be vulnerable, an iOS device must first be “jailbroken”.

iOS’s “jail” – or to put it more diplomatically: its “walled garden” – is at the root of its impressive security record. But this comes at a price that some users are not willing to pay, and this places them at greater risk of being hacked.

iOS security: signatures required

Every iOS device contains special hardware and software designed to ensure that only software authorised by Apple can be run on it.

Every piece of software that runs on an iOS device, including iOS itself, must be digitally “signed” by Apple with the private half of a two-part digital “key”. Each iOS device has the “public” half of the key. Before any piece of software is allowed to run, the phone uses the public key to check whether the software signature is authentic and applies to the software actually present on the device. If either the software or the signature have been modified, the software will not run.

This signature is practically impossible to forge without access to Apple’s private key. And, thus far, the mechanisms within iOS for checking signatures have been pretty much watertight, at least without physically connecting the phone to a computer with a USB cable.

Related mechanisms allow Apple to restrict a downloaded app from running on an iOS device or to revoke permission for an app to run at any time. Notably, this means that using illegally copied software is impossible on an unmodified iOS device.

All apps on Apple’s App Store are signed by Apple. These apps are made available on the App Store only after they have undergone an extensive vetting process according to the company’s published guidelines.

While keeping malware and other forms of objectionable software off the App Store is a primary goal, the guidelines also impose commercial restrictions. For example, subscription apps must use Apple’s payment mechanism, on which Apple collects a 30% commission.

This practice has attracted negative comment from US federal Senator Al Franken, who has asked the Federal Trade Commission to investigate what he views as potentially illegal anti-competitive behaviour under US law.

imageJailbreaking can give you – or hackers – access to the guts of your device.MIKI Yoshihito/Flickr, CC BY

Tinkerers, pirates and foreign language speakers

Some iOS users are unwilling to accept the restrictions imposed on them by Apple, or sometimes Apple-authorised apps, for a variety of reasons. To circumvent these restrictions, they take advantage of flaws in iOS’s security regime to install additional non-authorised software by first “jailbreaking” their device.

Jailbreaking an iOS device requires a program such as TaiG, which anonymous programmers have made available at no cost. A user downloads TaiG to their PC or Mac, connects their iOS device and then runs TaiG.

As well as allowing the user unfettered access to the files hidden behind the scenes on their iOS device, TaiG installs a “package manager” called Cydia. Through this they can install new apps unapproved by Apple, which are available from a variety of third-party repositories, as well as “tweaks” to modify existing apps.

Some of the extra functionality downloadable through Cydia includes a tweak to allow easy saving of photos on an Instagram feed, modifying the system fonts and improved Chinese language input. Historically, Apple’s stock iOS Chinese keyboard has been inferior to unauthorised third-party keyboards.

However, it can’t be denied that the ability to install pirated software is also attractive to some iOS users. It appears this was both the downfall of the victims of the recent hack and a goal of the hackers.

The malware was distributed as a “Trojan horse” through repositories of (mainly pirated) software accessible through Cydia in China (although it was not managed by the Cydia creator itself). Once installed, it stole the Apple account credentials of the user who installed the malware.

This allowed the hackers to use those accounts to purchase items from the iOS App Store for somebody else’s use. The malware could also be used to hold a phone to ransom, or steal the information stored in the cloud on the Apple account.

Whom do you trust?

As a user, I find Apple’s attitude that it is the ultimate arbiter of what’s appropriate for me to do with my device somewhat irritating. But this policy has also been very effective at keeping malware out of the iOS ecosystem, all without the need for consumers to invest in additional anti-malware software.

Outside the iOS jail, the burden of keeping malware off one’s phone falls entirely to the user and their judgement. It’s a virtual Wild West, replete with outlaws looking to exploit the unwary.

While I sympathise with Chinese users burdened with inefficient native language input, for most of us it’s hard to see that “cool” animations and other non-authorised apps are worth the risk of malware infection.

Robert Merkel does not work for, consult, own shares in or receive funding from any company or organization that would benefit from this article, and has disclosed no relevant affiliations beyond the academic appointment above.

Authors: The Conversation

Read more http://theconversation.com/jailbreaking-ios-frees-you-from-apple-but-exposes-you-to-malware-47032

Business News

How Telematics Helps Australian Companies Improve Productivity

Operating a commercial fleet in Australia is a uniquely demanding endeavour. Between the sprawling urban sprawl of cities like Sydney and Melbourne and the immense, unforgiving stretches of the Outb...

Daily Bulletin - avatar Daily Bulletin

Inside the Icon: The BridgeMuseum Officially Opens at the Sydney Harbour Bridge

A bold new way to experience one of Australia’s most recognisable landmarks has arrived, with BridgeClimb Sydney officially opening the all-new BridgeMuseum.  Located inside the Sydney Harbour Brid...

Daily Bulletin - avatar Daily Bulletin

Is Your Brand Showing Up in AI Search? Most Melbourne Brands Aren't.

The New Front Door Nobody Told You About Something changed. Quietly. Without a press release. The way buyers find businesses in Australia has been rewired. Not replaced, rewired. Google isn't dead...

Daily Bulletin - avatar Daily Bulletin

How Australian Businesses Can Measure SEO ROI

SEO can feel vague when you are staring at a dashboard full of numbers that do not clearly connect to revenue. The key is to measure the right signals in the right order, then tie them back to outcome...

Daily Bulletin - avatar Daily Bulletin

How Commercial Roller Shutters Improve Site Security Without Slowing Operations

Security upgrades can be frustrating when they make everyday work harder. A door that takes too long to open, creates bottlenecks at shift change, or fails at the worst time can turn “better protectio...

Daily Bulletin - avatar Daily Bulletin

Why a Document Destruction Service Still Matters for Modern Businesses

Businesses generate large volumes of information every day, from staff records and contracts to invoices, reports and customer files. While attention often focuses on how documents are stored, the way...

Daily Bulletin - avatar Daily Bulletin

Bicycle Rack Safety and Space-Smart Storage

Bike storage problems usually show up as small annoyances first: tangled handlebars, scratched frames, and bikes that topple when you pull one out. Over time, those issues become safety risks, especia...

Daily Bulletin - avatar Daily Bulletin

How to Tell if a Childcare Centre Is a Good Fit for Your Child

Choosing childcare can feel like you’re making a huge decision with limited information. Tours are short, centres are often on their best behaviour, and your child might act differently in a new space...

Daily Bulletin - avatar Daily Bulletin

Car Import Timeline: What Usually Happens at Each Stage

Importing a car into Australia can feel confusing because multiple agencies and checkpoints are involved, and the timeline is shaped as much by paperwork quality as it is by shipping speed. The most u...

Daily Bulletin - avatar Daily Bulletin

The Daily Magazine

Gold Migration Lawyers in Liquidation: How the Closure Affects Your ART Appeal

If your appeal was with Gold Migration Lawyers, a recent change to how the Tribunal decides cases ...

The pressure cooker: life in urban Australia in 2026

Australian cities have always been demanding. Long commutes, rising housing costs, busy schedules a...

What Actually Makes a Good Criminal Lawyer in Melbourne

Most people only think about this question once. That is usually too late. Most people charged wi...

Why Working With A Chatswood Tutor Can Improve Academic Performance

Academic expectations continue increasing for students across primary school, high school, and senio...

Is It Worth Getting Solar Panels in Melbourne?

The real question is not whether solar works in Melbourne. It works. The question is what it is co...

How A Diploma Of Project Management Builds Practical Skills For Modern Work Environments

Developing the ability to plan, execute, and deliver outcomes efficiently is a key requirement in to...

How to Choose the Right Football for Every Level

Choosing a football may seem straightforward, but the right option depends on who will be using it a...

What to Ask a Wedding Photographer Before You Book

Booking a wedding photographer can feel deceptively simple: you like the photos, you like the vibe...

Why Stress Relief For Dogs Is Essential For Emotional Balance And Long-Term Wellbeing

Managing emotional health is just as important as physical care when it comes to pets, which is why ...