Apple iPhone
Experts have raised doubts about the Skyhook positioning system used in Apple's iPhone

iPhone Wi-Fi positioning 'open to spoofing'

Flaw discovered in WPS used by iPhone and iPod Touch

Written by Robert Jaques

The use of wireless Lan-based public localisation systems should be restricted in security and safety-critical applications

Professor Srdjan Capkun ETH Zurich

The Wi-Fi positioning system used in Apple's iPhone is vulnerable to " relatively simple" location spoofing attacks, computer experts warned today.

The flaw is alleged to centre on the use of Skyhook's Wi-Fi positioning system, which contains information on access points throughout the world, for Apple's popular Map applications.

Skyhook provides most of the information in the database, but users contribute via direct entries to the database and requests for localisation.

However, a team led by Professor Srdjan Capkun, of the Department of Computer Science at ETH Zurich, questioned the security of Skyhook's positioning system.

The team claimed that its results demonstrate the vulnerability of Skyhook's and similar public wireless local area network positioning systems to location spoofing attacks.

The scientists explained that, when an Apple iPod or iPhone wants to find its position, it detects its neighbouring access points and sends this information to Skyhook's servers.

The servers then return the access point locations to the device. Based on this data, the device computes its location.

To attack this localisation process, Professor Capkun's team used a dual approach. First, access points from a known remote location were impersonated. Second, signals sent by access points in the vicinity were eliminated by jamming.

These actions created the illusion in localised devices that their locations were different from their actual physical locations.

"Skyhook's Wi-Fi positioning system works by requiring a device to report the Media Access Control addresses that it detects," said Professor Capkun.

"However, since Media Access Control addresses can be forged by rogue access points, they can be easily impersonated."

Access point signals can also be jammed and signals from access points in the vicinity of the device can thus be eliminated. These two actions make location spoofing attacks possible, according to the team.

"Given the relative simplicity of the performed attacks, it is clear that the use of wireless Lan-based public localisation systems, such as Skyhook's, should be restricted in security and safety-critical applications," said Professor Capkun.

Further reading

Mobile browser market taking off

1.5 billion smartphone browsers to ship by 2013   More...

China consumers switched on to iPhone

But high price helps cheaper copycats   More...

Confusion reigns over 3G iPhone

Is it or isn’t it coming in two months?   More...

Nokia 'Tube' takes on the iPhone

Touch-screen handset likely to offer Wi-Fi or HSDPA   More...

Related articles

Video rentals co-star in Jobs keynote

New storage and TV boxes also introduced   More...

Remote control flaw found in iPhone

Attackers could take complete control of the platform   More...

Wi-Fi safety concerns slammed as melodramatic

Panorama documentary 'misleading' rather than informed   More...

Jobs hints at 3G iPhone

Apple chief admits failings of Edge   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

09 May 2008

2.51 MBWiMax muddle, Google tactics and asteroid bunkum More...

08 May 2008

3.26 MBBroadband Anywhere, phone-free transport and Web 3.0 More...

07 May 2008

3.19 MBUK success, a paucity of IT women and robot wars More...

Poll

DATA ENCRYPTION

DATA ENCRYPTION

Should encryption be mandatory for all personal data held by companies and governments?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Ofcom

Ofcom outlines future wireless vision

Wi-Fi healthcare and intelligent car brakes in the pipeline   More...

HP

HP Labs opens doors to academia

Innovation Research Program invites proposals related to current research   More...

Advertisement

Asteroid

Nasa plans manned mission to asteroid

Bruce Willis thankfully not going   More...

MySpace

MySpace offers opt-in data sharing

Deals signed with Photobucket, Twitter, eBay and Yahoo   More...

Advertisement