المساعد الشخصي الرقمي

مشاهدة النسخة كاملة : iOS 10 Beta Features Unencrypted Kernel Making it Easier to Discover Vulnerabilities


ahlam1399
06-22-2016, 02:26 PM
Apple's iOS 10 (http://www.macrumors.com/roundup/ios-10/) preview, seeded to developers last week, does **t feature an encrypted kernel and thus gives users access to the inner workings of the operating system and potential security flaws, reports MIT Tech**logy Review (https://www.tech**logyreview.com/s/601748/apple-opens-up-iphone-code-in-what-could-be-savvy-strategy-or-security-screwup/). It is **t k**wn if this was an unintentional mistake or done deliberately to encourage more bug reports.

http://cdn.macrumors.com/article-new/2016/04/ios10-800x585.jpgSecurity experts say the famously secretive company may have adopted a bold new strategy intended to encourage more people to report bugs in its software--or perhaps made an embarrassing mistake.In past versions of iOS, Apple has encrypted the kernel, aka the core of the operating system, which dictates how software uses the iPhone's hardware and keeps it secure. According to experts who spoke to the MIT Tech**logy Review, leaving iOS unencrypted doesn't leave the security of iOS 10 compromised, but it makes it easier to find flaws in the operating system. Security flaws in iOS can be used to create jailbreaks or create malware.The goodies exposed publicly for the first time include a security measure designed to protect the kernel from being modified, says security researcher Mathew Solnik. "**w that it is public, people will be able to study it [and] potentially find ways around it," he says.Apple has declined to comment on whether the lack of encryption was intentional or a mistake, but security expert Jonathan Zdziarski believes it was done by choice because it's **t a mistake Apple is likely to have made. "This would have been an incredibly glaring oversight, like forgetting to put doors on an elevator," he told MIT Tech**logy Review.

He further suggests Apple may have chosen this route to prevent the hoarding of vulnerabilities like the one that was ultimately used by the FBI (http://www.macrumors.com/roundup/apple-fbi/) to break into the iPhone 5c of San Bernardi** shooter Syed Farook and to have more people looking at the code to discover latent security flaws.

Related Roundup: iOS 10 (http://www.macrumors.com/roundup/ios-10/)

Discuss this article (http://forums.macrumors.com/threads/ios-10-beta-unencrypted-kernel.1979069/) in our forums

http://feeds.feedburner.com/~ff/MacRumors-All?d=6W8y8wAjSf4 (http://feeds.macrumors.com/~ff/MacRumors-All?a=F13j2HSd0ME:H5h36P5bGAA:6W8y8wAjSf4) http://feeds.feedburner.com/~ff/MacRumors-All?d=qj6IDK7rITs (http://feeds.macrumors.com/~ff/MacRumors-All?a=F13j2HSd0ME:H5h36P5bGAA:qj6IDK7rITs)
http://feeds.feedburner.com/~r/MacRumors-All/~4/F13j2HSd0ME

أكثر... (http://www.macrumors.com/2016/06/21/ios-10-beta-unencrypted-kernel/)