Gmail users on iOS at risk of data interception

Lacoon Security found Google hasn't yet implemented a security technology that could prevent data loss

Apple users accessing Gmail on mobile devices could be at risk of having their data intercepted, a mobile security company said Thursday.

The reason is Google has not yet implemented a security technology that would prevent attackers from viewing and modifying encrypted communications exchanged with the Web giant, wrote Avi Bashan, chief information security officer for Lacoon Mobile Security, based in Israel and the U.S.

Websites use digital certificates to encrypt data traffic using the SSL/TLS (Secure Sockets Layer/Transport Layer Security) protocols. But in some instances, those certificates can be spoofed by attackers, allowing them to observe and decrypt the traffic.

That threat can be eliminated through certificate "pinning," which involves hard coding the details for the legitimate digital certificate into an application.

Unlike for Android, Google doesn't do this for iOS, which means an attacker could execute a man-in-the-middle attack and read encrypted communications, Bashan wrote. Google acknowledged the problem after being notified by Lacoon on Feb. 24, but the problem has not been fixed, he wrote.

Google officials did not have an immediate comment.

It isn't clear why certificate pinning isn't used by Google on iOS. But three years ago, a Google security engineer that works on such security issues described a scenario where the handling of digital certificates becomes complicated.

Occasionally, proxy servers used by companies will intercept HTTPS connections using local, ephemeral certificates, wrote Adam Langley on his personal blog. Some security applications and parental control programs will also do this, he wrote.

Those certificates have the authority to override "pins" that have been set to check for a specific certificate, he wrote.

Lacoon described an attack scenario that involved tricking a user into installing an iOS device management configuration file that contains a malicious root digital certificate. That would validate a spoofed certificate, allowing the person to navigate to a fraudulent Gmail site.

"We were quite surprised by this finding because Google had implemented certificate pinning for their Android Gmail app," Bashan wrote. "Clearly, not implementing this for iOS was an oversight by Google."

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags telecommunicationLacoon Mobile SecurityapplicationsGoogleiossecurityMobile OSesmobile

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Kurt Hegetschweiler

Brother PocketJet PJ-773 A4 Portable Thermal Printer

It’s perfect for mobile workers. Just take it out — it’s small enough to sit anywhere — turn it on, load a sheet of paper, and start printing.

Matthew Stivala

HP OfficeJet 250 Mobile Printer

The HP OfficeJet 250 Mobile Printer is a great device that fits perfectly into my fast paced and mobile lifestyle. My first impression of the printer itself was how incredibly compact and sleek the device was.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?