AfterDawn: Tech news

iPhones can be tricked into connecting to malicious Wi-Fi networks

Written by James Delahunty @ 13 Jun 2013 11:46 User comments (2)

iPhones can be tricked into connecting to malicious Wi-Fi networks

Researchers have detailed a weakness effecting some iPhone that can be exploited to force devices to connect to malicious Wi-Fi networks.
Even if the iPhone had never connected to a Wi-Fi network before, this attack method could still work, Skycure researchers found. The problem actually lies with the configuration settings installed by wireless carriers.

In order to provide customers with more reliable data connections on the move, Wi-Fi hotspots are setup in public places targeted at just their customers. For example, AT&T pre-sets iPhones to connect to networks with an SSID of "attwifi". The problem is simple, this connection can happen automatically with no user interaction.

"Setting up such Wi-Fi networks would initiate an automatic attack on nearby customers of the carrier, even if they are using an out-of-the-box iOS device that never connected to any Wi-Fi network," the researchers wrote.



A test carried out in a restaurant in Tel Aviv resulted in 60 connections to an imposter network within a minute. At the International Cyber Security Conference, Skycure did the same thing and recorded 448 connections within a two and half hour period.

Connecting to a rogue wireness network could put an iPhone user at risk of man in the middle attacks, where data can be stolen in transit, or links and content could be forged.

Tags: Apple iPhone
Previous Next  

2 user comments

114.6.2013 04:46

turn on "Ask to Join Networks"... Job Done.

I am sure researches could get in my house without a key if I didn't lock the door, same thing.

218.6.2013 08:37

Originally posted by bloke2000:
turn on "Ask to Join Networks"... Job Done.

I am sure researches could get in my house without a key if I didn't lock the door, same thing.
I agree with you, but since most users are dumb and lazy, having a locked door should be the default, shouldn't it?

Comments have been disabled for this article.

Latest news

Sony suspends memory card sales because memory chips are simply not available Sony suspends memory card sales because memory chips are simply not available (28 Mar 2026 6:49)
Sony has announced that it is temporarily suspending the sale of memory cards used in mobile phones and digital cameras, among other things. The company states that the reason is problems with the availability of memory chips.
Austria plans to ban social media for under 14 year olds Austria plans to ban social media for under 14 year olds (28 Mar 2026 6:17)
Austria is planning to ban social media for children under 14. The reform aims to protect children from harmful effects and addictions, but at the same time, it is problematic from a privacy perspective.
TP-Link urges users to update their routers - several vulnerabilities patched TP-Link urges users to update their routers - several vulnerabilities patched (26 Mar 2026 1:56)
Serious security vulnerabilities have been discovered in several TP-Link router models, for which patches were released at the end of March 2026. The company urges users to update their router software immediately.
Google: The feared Q-Day is now expected to happen in 2029 Google: The feared Q-Day is now expected to happen in 2029 (25 Mar 2026 4:32)
Google has advanced its estimate of when current forms of encryption will become insecure. The moment is called Q-Day, or Quantum Day, when the computational power of quantum computers will be sufficient to break currently used encryptions.
OpenAI shuts down its AI video service Sora OpenAI shuts down its AI video service Sora (24 Mar 2026 6:28)
OpenAI has decided to shut down Sora, its AI video creator, just months after its release. The decision is due to issues such as copyright problems and the deepfake phenomenon.

News archive