<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Cryptopath</title>
	<atom:link href="http://cryptopath.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://cryptopath.wordpress.com</link>
	<description>Zeroing in where security hinges</description>
	<lastBuildDate>Tue, 13 Apr 2010 09:53:51 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='cryptopath.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Cryptopath</title>
		<link>http://cryptopath.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://cryptopath.wordpress.com/osd.xml" title="Cryptopath" />
	<atom:link rel='hub' href='http://cryptopath.wordpress.com/?pushpress=hub'/>
		<item>
		<title>iPhone vulnerability HOWTO</title>
		<link>http://cryptopath.wordpress.com/2010/04/13/iphone-vulnerability-howto/</link>
		<comments>http://cryptopath.wordpress.com/2010/04/13/iphone-vulnerability-howto/#comments</comments>
		<pubDate>Tue, 13 Apr 2010 09:53:51 +0000</pubDate>
		<dc:creator>cryptopath</dc:creator>
				<category><![CDATA[iphone]]></category>
		<category><![CDATA[security flaw]]></category>

		<guid isPermaLink="false">http://cryptopath.wordpress.com/?p=50</guid>
		<description><![CDATA[XMCO Partners is a security company publishing an online magazine about recent security topics. Their latest issue (#25) provides a HOWTO dedicated to creating signed mobileconfig files that are shown as valid from any iPhone/iPod Touch. The most interesting point is that they succeed in re-directing all web traffic from the victim&#8217;s device to their [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptopath.wordpress.com&amp;blog=11717926&amp;post=50&amp;subd=cryptopath&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>XMCO Partners is a security company publishing an online magazine about recent security topics. Their latest issue (#25) provides a HOWTO dedicated to creating signed mobileconfig files that are shown as valid from any iPhone/iPod Touch. The most interesting point is that they succeed in re-directing all web traffic from the victim&#8217;s device to their own server by configuring the operator access point proxy.</p>
<p>This issue (in French) can be found here:<br />
<a href="http://www.xmcopartners.com/actualite-securite-vulnerabilite-fr.html">ActuSecu at XMCO Partners</a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cryptopath.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cryptopath.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cryptopath.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cryptopath.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cryptopath.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cryptopath.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cryptopath.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cryptopath.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cryptopath.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cryptopath.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cryptopath.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cryptopath.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cryptopath.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cryptopath.wordpress.com/50/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptopath.wordpress.com&amp;blog=11717926&amp;post=50&amp;subd=cryptopath&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cryptopath.wordpress.com/2010/04/13/iphone-vulnerability-howto/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/99d04243a087bfde73a34355fb72f601?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cryptopath</media:title>
		</media:content>
	</item>
		<item>
		<title>iPhone OS 3.1.3 vulnerable</title>
		<link>http://cryptopath.wordpress.com/2010/02/10/iphone-os-3-1-3-vulnerable/</link>
		<comments>http://cryptopath.wordpress.com/2010/02/10/iphone-os-3-1-3-vulnerable/#comments</comments>
		<pubDate>Wed, 10 Feb 2010 12:28:12 +0000</pubDate>
		<dc:creator>cryptopath</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://cryptopath.wordpress.com/?p=46</guid>
		<description><![CDATA[Just checked: a mobileconfig profile presenting itself as a Security Update from Apple Computer passes all checks on an iPhone OS 3.1.3, as opposed to what is claimed in this article on gulli.com (German). Screenshot below taken on an iPhone registered on a French carrier.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptopath.wordpress.com&amp;blog=11717926&amp;post=46&amp;subd=cryptopath&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Just checked: a mobileconfig profile presenting itself as a <em>Security Update</em> from <em>Apple Computer</em> passes all checks on an iPhone OS 3.1.3, as opposed to what is claimed in <a href="http://www.gulli.com/news/iphone-ssl-schwachstelle-entdeckt-aber-schon-behoben-2010-02-03">this article on gulli.com (German)</a>. Screenshot below taken on an iPhone registered on a French carrier.</p>
<div id="attachment_47" class="wp-caption alignnone" style="width: 330px"><a href="http://cryptopath.files.wordpress.com/2010/02/screenshot.png"><img class="size-full wp-image-47" title="OS 3.1.3 screenshot" src="http://cryptopath.files.wordpress.com/2010/02/screenshot.png?w=320&#038;h=480" alt="OS 3.1.3 screenshot" width="320" height="480" /></a><p class="wp-caption-text">OS 3.1.3 screenshot</p></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cryptopath.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cryptopath.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cryptopath.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cryptopath.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cryptopath.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cryptopath.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cryptopath.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cryptopath.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cryptopath.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cryptopath.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cryptopath.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cryptopath.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cryptopath.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cryptopath.wordpress.com/46/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptopath.wordpress.com&amp;blog=11717926&amp;post=46&amp;subd=cryptopath&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cryptopath.wordpress.com/2010/02/10/iphone-os-3-1-3-vulnerable/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/99d04243a087bfde73a34355fb72f601?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cryptopath</media:title>
		</media:content>

		<media:content url="http://cryptopath.files.wordpress.com/2010/02/screenshot.png" medium="image">
			<media:title type="html">OS 3.1.3 screenshot</media:title>
		</media:content>
	</item>
		<item>
		<title>Leave Verisign out of it!</title>
		<link>http://cryptopath.wordpress.com/2010/02/04/leave-verisign-out-of-it/</link>
		<comments>http://cryptopath.wordpress.com/2010/02/04/leave-verisign-out-of-it/#comments</comments>
		<pubDate>Thu, 04 Feb 2010 13:10:15 +0000</pubDate>
		<dc:creator>cryptopath</dc:creator>
				<category><![CDATA[crypto]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[verisign]]></category>

		<guid isPermaLink="false">http://cryptopath.wordpress.com/?p=34</guid>
		<description><![CDATA[I keep reading misinterpretations about the previous blog entry and see Verisign buried under a ton of drivel. Just to make things clear: Verisign distributes test certificates for people to try out their service. These certificates are limited to 60 days, delivered without any kind of verification, and clearly labeled as such. People use them [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptopath.wordpress.com&amp;blog=11717926&amp;post=34&amp;subd=cryptopath&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>I keep reading misinterpretations about the previous blog entry and see Verisign buried under a ton of drivel. Just to make things clear:</p>
<ul>
<li>Verisign distributes test certificates for people to try out their service. These certificates are limited to 60 days, delivered without any kind of verification, and <strong>clearly labeled as such</strong>. People use them mostly to validate that PKI-enabled software like browsers or mail clients can handle them fine.</li>
<li>These certificates come with all bells and whistles. If you read the fine print, it is clearly indicated that these are intended for test purposes only.</li>
<li>Many other certificate authorities offer the same kind of service for users to test. The same proof-of-concept could have been realized with <em>any other certificate provider offering test tools</em>, as long as they relate to a root CA trusted by iPhones.</li>
</ul>
<p>You do not have to believe me: browse any certificate provider web site and look for test certificate generation.</p>
<p>The WTF lies in the fact that an iPhone would accept this kind of toy certificate as a token of proof to authenticate a remote configuration received over the air.</p>
<p>Hope that clarifies things a bit.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cryptopath.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cryptopath.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cryptopath.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cryptopath.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cryptopath.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cryptopath.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cryptopath.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cryptopath.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cryptopath.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cryptopath.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cryptopath.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cryptopath.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cryptopath.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cryptopath.wordpress.com/34/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptopath.wordpress.com&amp;blog=11717926&amp;post=34&amp;subd=cryptopath&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cryptopath.wordpress.com/2010/02/04/leave-verisign-out-of-it/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/99d04243a087bfde73a34355fb72f601?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cryptopath</media:title>
		</media:content>
	</item>
		<item>
		<title>iPhone certificate flaws</title>
		<link>http://cryptopath.wordpress.com/2010/01/29/iphone-certificate-flaws/</link>
		<comments>http://cryptopath.wordpress.com/2010/01/29/iphone-certificate-flaws/#comments</comments>
		<pubDate>Fri, 29 Jan 2010 12:41:21 +0000</pubDate>
		<dc:creator>cryptopath</dc:creator>
				<category><![CDATA[iphone]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[mobileconfig]]></category>

		<guid isPermaLink="false">http://cryptopath.wordpress.com/?p=9</guid>
		<description><![CDATA[iPhone certificates are badly handled, creating potential security issues with downloaded mobileconfig files.<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptopath.wordpress.com&amp;blog=11717926&amp;post=9&amp;subd=cryptopath&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h1>iPhone PKI handling flaws</h1>
<h2>Introduction</h2>
<p>The iPhone is obviously a consumer market product which was later enhanced to become an enterprise device. Unfortunately, it seems Apple messed up their corporate-oriented functionalities, ending up with something that proves to be hard to integrate in a public-key infrastucture in any secure way.</p>
<p>The following page summarizes our findings in terms of chain-of-trust management on iPhones, describes a major security flaw and how we could cope with the current situation (Jan 2010).</p>
<h2>iPhone provisioning protocols</h2>
<p>iPhones currently provide two provisioning protocols allowing to install certificates on a device. <em>v2</em> was the version released with iPhone OS v2.0 and <em>v3</em> released with iPhone OS v3.0.</p>
<h3>iPhone OS v2</h3>
<p>This protocol is quite straightforward: put an XML config file named something.mobileconfig served with filetype <tt>application/x-apple-aspen-config</tt> somewhere on a web server seen by the iPhone, point Safari to the corresponding URL and let it download the file.</p>
<p>XML configuration files are created with an Apple utility called the<a onclick="return mugicPopWin(this,event);" oncontextmenu="mugicRightClick(this);" href="http://www.apple.com/support/iphone/enterprise/"> iPhone Configuration Utility (iPCU)</a>, which is a desktop-based program running on Windows or Mac OSX. Apple has not released specs for the XML config files it produces.</p>
<h3>iPhone v3</h3>
<p>This protocol is an attempt from Apple to streamline over-the-air provisioning to large numbers of iPhones. It is described in: <a href="http://manuals.info.apple.com/en_US/Enterprise_Deployment_Guide.pdf">Enterprise Deployment Guide</a></p>
<p>Provisioning an iPhone in v3 is done through several network exchanges:</p>
<ol>
<li> iPhone accesses URL of provisioning server (hereafter: PS)</li>
<li> PS responds with a minimal mobileconfig file requesting credentials</li>
<li> iPhone POSTs a request to PS containing its signed credentials</li>
<li> PS responds with key specifications and the address of a SCEP server</li>
<li> iPhone performs SCEP request to SCEP server</li>
<li> SCEP server delivers a certificate</li>
</ol>
<h3>Shortcomings</h3>
<p>There are several shortcomings to that process:</p>
<h4>Certificate fail</h4>
<p>In step 3, the iPhone signs its own credentials (including its IMEI or device serial number) using an Apple-signed certificate. To validate this certificate, the chain of trust must be established up to Apple&#8217;s root CA. Unfortunately, Apple does not provide access to this chain except by jailbreaking an iPhone and extracting it directly.</p>
<p>The following chain of trust was manually extracted from a jailbroken iPhone:</p>
<pre>Signed requests from this iPhone use this key:
    CN=Apple iPhone Device CA
        keyid=xxxx
    issued by CN=Apple iPhone Device CA
        keyid=B2:FE:21:23:44:86:95:6A:79:D5:81:26:8E:73:10:D8:A7:4C:8E:74

The certificate for 'Apple iPhone Device CA' is:
    CN=Apple iPhone Device CA
        keyid=B2:FE:21:23:44:86:95:6A:79:D5:81:26:8E:73:10:D8:A7:4C:8E:74
    issued by CN=Apple iPhone Certification Authority
        keyid=E7:34:2A:2E:22:DE:39:60:6B:B4:94:CE:77:83:61:2F:31:A0:7C:35

The certificate for 'Apple iPhone Certification Authority' is:
    CN=Apple iPhone Certification Authority
        keyid=E7:34:2A:2E:22:DE:39:60:6B:B4:94:CE:77:83:61:2F:31:A0:7C:35
    issued by CN=Apple Root CA
        keyid=2B:D0:69:47:94:76:09:FE:F4:6B:8D:2E:40:A6:F7:47:4D:7F:08:5E

The certificate for 'Apple Root Certificate Authority' is:
AppleComputerRootCertificate.pem
    Serial Number: <strong>1 (0x1)</strong>
    <strong>CN=Apple Root Certificate Authority</strong>
        <strong>keyid=2B:D0:69:47:94:76:09:FE:F4:6B:8D:2E:40:A6:F7:47:4D:7F:08:5E</strong>
    issued by CN=Apple Root Certificate Authority
        <strong>keyid=2B:D0:69:47:94:76:09:FE:F4:6B:8D:2E:40:A6:F7:47:4D:7F:08:5E</strong></pre>
<p>The last certificate in the chain is a self-signed root CA for <em>Apple Root Certificate Authority</em>.</p>
<p>Interestingly, the Apple root CA on top of the iPhone chain is not the same as the one published on the Apple web site. Fetching the <a onclick="return mugicPopWin(this,event);" oncontextmenu="mugicRightClick(this);" href="http://www.apple.com/certificateauthority/index.html">root certificate published on Apple&#8217;s web site</a> shows:</p>
<pre>    Serial Number: <strong>2 (0x2)</strong>
    <strong>CN=Apple Root CA</strong>
       <strong>keyid=2B:D0:69:47:94:76:09:FE:F4:6B:8D:2E:40:A6:F7:47:4D:7F:08:5E</strong></pre>
<p>Different name (CN), different serial numbers (1 vs 2) but the <em>same key id</em>. It looks like somebody reused the same keyset to generate a second certificate. Hard to tell whether this is an oversight or intentional, but the fact is: you <em>cannot</em> technically relate an iPhone signature to the Apple root CA certificate published on their web site. Even with the same keyset, verification will fail because Subject and Serial are different.</p>
<h4>SCEP fail</h4>
<p>It looks like the iPhone SCEP client implements an old (draft) version of the <a href="http://en.wikipedia.org/wiki/Simple_Certificate_Enrollment_Protocol">SCEP protocol</a>. As an example: sending back a chain of trust containing several certificates will lead to an error, the iPhone only accepts one certificate upon request of the CA chain. If you need to talk to a SCEP server, make sure it will accept old-fashioned requests.</p>
<h4>mobileconfig fail</h4>
<p>As seen above, installing mobileconfig files can happen over the air through v2 or v3 protocol. It is also possible to connect the iPhone to a desktop running iPCU and use it to transfer mobileconfig files through cable.</p>
<p>An interesting difference is that profiles downloaded over the air are not trusted by default, whereas profiles downloaded through iPCU over a cable are trusted. This translates into a red icon for non-trusted profiles and a happy green flag for trusted ones. As demonstrated below, trust does not depend on the medium being a cable or over-the-air download.</p>
<p>A close study of iPCU revealed that:</p>
<ul>
<li> iPCU generates its own set of keys upon install, and self-signs its own certificate</li>
<li> Whenever a new iPhone is connected to that iPCU instance, iPCU inserts its own certificate into the iPhone trusted keystore.</li>
<li> Further exchanges between this iPCU instance and a known iPhone are always trusted, as long as the iPCU certificate is present in the iPhone. This is also valid for mobileconfig files sent over the air: as long as they are signed by a trusted iPCU, they are trusted upon download.</li>
</ul>
<p>An even closer study of the certificate used by iPCU revealed that it only contains Signature in key usage. This lead us to discover a serious security flaw as described below.</p>
<h2>Security flaw</h2>
<h3>What was found</h3>
<p>We observed that iPhones will trust mobileconfig files they receive over the air or through wire if they are signed by a trusted entity. However:</p>
<ul>
<li> The keystore used to lookup trusted CAs includes the default Safari keystore</li>
<li> A signature-only certificate is enough to sign mobileconfig files</li>
</ul>
<p>There are 224 trusted root Certificates in the iPhone keystore (v3.1). See: <a onclick="return mugicPopWin(this,event);" oncontextmenu="mugicRightClick(this);" href="http://support.apple.com/kb/HT3580">http://support.apple.com/kb/HT3580</a> for a complete list published by Apple.</p>
<p>It is relatively easy to obtain a signature certificate from many of them without any sort of verification. A demo (test) signature certificate can be obtained from Verisign without need for anything other than a valid e-mail address (throwaway addresses work, too) for sixty days at no price and without providing any credit card details.</p>
<p><em>NB: Verisign is not to blame for this in any way. They distribute un-verified temporary certificates that you are not supposed to trust for anything, like most other certificate providers.</em></p>
<p>What was tried</p>
<ul>
<li> Create a throwaway e-mail address</li>
<li> Use it to request a demo certificate from Verisign Level 1 for a person named <em>Apple Computer</em>, valid for sixty days</li>
<li> Create a mobileconfig file on iPCU: name it <em>Security Update</em>, declare it as issued by <em>Apple Computer</em>. Export it to disk without signature as a plain XML file.</li>
<li> Using <tt>openssl smime</tt> and the P12 you got from Verisign, sign the mobileconfig file including the complete CA chain and put it onto a public HTTP server</li>
<li> Open the link from Safari on iPhone and observe that the configuration is trusted by the iPhone.</li>
</ul>
<p><em>Edit 2010-02-04: Demonstration file taken away. Point was made</em></p>
<p>On an iPod Touch, the installation screen looks like this:</p>
<div id="attachment_14" class="wp-caption alignnone" style="width: 330px"><a href="http://cryptopath.files.wordpress.com/2010/01/green1.png"><img class="size-full wp-image-14" title="Apple security update" src="http://cryptopath.files.wordpress.com/2010/01/green1.png?w=320&#038;h=480" alt="Apple security update" width="320" height="480" /></a><p class="wp-caption-text">Downloaded mobileconfig file</p></div>
<p>To be successful, profile installation needs to be validated by the end-user. Unless they know about this flaw it is quite likely that a default end-user would trust an update that claims to be issued by Apple and indicated as trusted by the device. A bit of social engineering is needed to both get the user to click on the link and accept the profile installation.</p>
<h3>Exploiting the flaw</h3>
<p>Parameters that can be set through mobileconfig on an iPhone include root certificates. Modifying root certificates makes it possible to act as man-in-the-middle to hijack SSL (HTTPS) connections.</p>
<p>Obnoxious modifications can be brought to the phone like prohibiting the use of Safari, mail and other apps, or adding extra VPN, WiFi or e-mail settings. It is also possible to set up the profile as being non-removable by the end-user, which would force the iPhone owner to wipe it clean to remove the profile.</p>
<h3>What could be done</h3>
<p>There is absolutely no reason for an iPhone/iPod to trust root CAs for over-the-air mobileconfig downloads. Apple needs to define who should be able to download mobileconfig files onto a device, be it an end-user or a company, and devise a correct way to share keys between the device and its associated provisioning server.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cryptopath.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cryptopath.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cryptopath.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cryptopath.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cryptopath.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cryptopath.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cryptopath.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cryptopath.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cryptopath.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cryptopath.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cryptopath.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cryptopath.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cryptopath.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cryptopath.wordpress.com/9/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=cryptopath.wordpress.com&amp;blog=11717926&amp;post=9&amp;subd=cryptopath&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://cryptopath.wordpress.com/2010/01/29/iphone-certificate-flaws/feed/</wfw:commentRss>
		<slash:comments>22</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/99d04243a087bfde73a34355fb72f601?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">cryptopath</media:title>
		</media:content>

		<media:content url="http://cryptopath.files.wordpress.com/2010/01/green1.png" medium="image">
			<media:title type="html">Apple security update</media:title>
		</media:content>
	</item>
	</channel>
</rss>
