Apple iPhone
Experts have raised doubts about the Skyhook positioning system used in Apple's iPhone
R E L A T E D   C O N T E N T
ADVERTISEMENT

iPhone Wi-Fi positioning 'open to spoofing'

Flaw discovered in WPS used by iPhone and iPod Touch

Robert Jaques, vnunet.com 15 Apr 2008
ADVERTISEMENT

The Wi-Fi positioning system used in Apple's iPhone is vulnerable to " relatively simple" location spoofing attacks, computer experts warned today.

The flaw is alleged to centre on the use of Skyhook's Wi-Fi positioning system, which contains information on access points throughout the world, for Apple's popular Map applications.

Skyhook provides most of the information in the database, but users contribute via direct entries to the database and requests for localisation.

However, a team led by Professor Srdjan Capkun, of the Department of Computer Science at ETH Zurich, questioned the security of Skyhook's positioning system.

The team claimed that its results demonstrate the vulnerability of Skyhook's and similar public wireless local area network positioning systems to location spoofing attacks.

The scientists explained that, when an Apple iPod or iPhone wants to find its position, it detects its neighbouring access points and sends this information to Skyhook's servers.

The servers then return the access point locations to the device. Based on this data, the device computes its location.

To attack this localisation process, Professor Capkun's team used a dual approach. First, access points from a known remote location were impersonated. Second, signals sent by access points in the vicinity were eliminated by jamming.

These actions created the illusion in localised devices that their locations were different from their actual physical locations.

"Skyhook's Wi-Fi positioning system works by requiring a device to report the Media Access Control addresses that it detects," said Professor Capkun.

"However, since Media Access Control addresses can be forged by rogue access points, they can be easily impersonated."

Access point signals can also be jammed and signals from access points in the vicinity of the device can thus be eliminated. These two actions make location spoofing attacks possible, according to the team.

"Given the relative simplicity of the performed attacks, it is clear that the use of wireless Lan-based public localisation systems, such as Skyhook's, should be restricted in security and safety-critical applications," said Professor Capkun.

See also:

Mobile browser1.5 billion smartphone browsers to ship by 2013  15 Apr 2008
Is it or isn’t it coming in two months?  09 Apr 2008
But high price helps cheaper copycats  10 Apr 2008
Touch-screen handset likely to offer Wi-Fi or HSDPA  08 Apr 2008

All Mobile Communications
Tags: IPhone, Apple, Communications

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Berkshire, Reading, United Kingdom | Foster Wheeler
Sharepoint Administrator - Competitive Salary - Reading Foster Wheeler is a leading international project management, engineering and construction organisation with global construction capabilities working on major projects within upstream oil & gas, midstream & LNG, ... more >
London, United Kingdom | BP
Business Analyst - £ Competitive - London About BP Our business is the exploration, production, refining, trading and distribution of energy. This is what we do, and we do it on a truly global scale. ... more >
Welwyn Garden City, Hertfordshire, United Kingdom | Tesco.com
Infrastructure Delivery Project Manager - Welwyn Garden City Who's behind the world's most successful online retailer? Just over 10 years ago we started Tesco.com (aka Dotcom). Today, we've an incredible 750,000 active customers and sales ... more >
Central London, United Kingdom | MI5 Security Services
UNIX Technology Administrator - Competitive + excellent benefits - Central LondonGetting the best out of technology is critical to helping us protect the UK. Join MI5 and use your skills and experience to help us meet the ... more >
More job opportunities