Trend Micro Facebook TrendLabs Twitter Malware Blog RSS Feed You Tube - Trend Micro
Search our blog:

  • Recent Posts

  • Calendar

    February 2012
    S M T W T F S
    « Jan    
     1234
    567891011
    12131415161718
    19202122232425
    26272829  
  • About Us
    Malware Blog > Siri, Don’t Lie To Me

    Nov21
    3:11 pm (UTC-7)   |    by

    Researchers at Applidium have published some interesting findings about the protocol used by Siri. For every request the user makes to Siri, the iPhone 4S sends the compressed audio of the request to servers at Apple to first be converted to text. Then, it is mapped into commands that the iPhone can understand, and then sent back to the device.

    This protocol sits on top of HTTPS, and intercepting or spoofing it requires either a valid SSL certificate for guzzoni.apple.com or a way to convince the device to accept your certificate as valid. One must also hijack DNS so that the phone would think guzzoni.apple.com is at an IP address that you control. The post from Applidium covers the details pretty well, so let’s talk about what one could do with this.

    I’ll start with the positive and creative things that can be done. In theory, it should be easy to port Siri to any device if you have a valid iPhone 4S ID. Any device capable of recording audio and running an “app” with Internet connectivity should work. This includes laptops, tablets, smartphones, even refrigerators and washing machines.

    You can even build your own Siri server for existing Siri capable devices to talk to. This can be utilized for home use for commands like “turn on the light”, or “close the garage door.” This can also be done within a business: imagine integrating such a system with your everyday tools to make workflow voice interactive. Anything you can script, you can ask Siri about.

    Unfortunately, there also some not-so-friendly possibilities. For these scenarios, we’ll assume that the attacker has successfully loaded a self-signed certificate into the device and somehow has control of the local DNS, as both are required to successfully intercept Siri communications.

    The most obvious attack is to play man-in-the-middle and capture all Siri requests and responses. This alone may be useful, but the questions you ask Siri might betray what you are working on. Soon, we can easily start changing answers like altering stock quotes, or replacing a request to call a colleague from your contact list. This can be replaced with a request to call a different number that will forward the call to the original person you intended to call, and record the conversation. This would certainly require inside knowledge of the victim’s address book, but appears possible to a determined attacker.

    There are a number of ways Apple can fix this. The most comprehensive way would be to move to a challenge-response authentication system. Requiring that the server SSL key matches a given key ID, or more practically is signed by a key with a set ID would add broad coverage. Either way, only Apple has the capability to fix this if it is truly broken.





    Share this article
    Get the latest on malware protection from TrendLabs
    Email this story to a friend   Technorati   NewsVine   MySpace   Google   Live   del.icio.us   StumbleUpon




    6 Responses to “Siri, Don’t Lie To Me”

    1. Sorcerer13 Says:

      “For these scenarios, we’ll assume that the attacker has successfully loaded a self-signed certificate into the device and somehow has control of the local DNS..”

      In other words, the assumption is that the device has been totally compromised already, for someone to exploit Siri. If an attacker has a root certificate installed on the device, he can masquerade as anyone or MITM any connection he wants – including connections to your bank, email, or really any app that accesses the internet using that device. How does Siri make you more vulnerable? It’s just another app on your phone, with a nice interface.

    2. GTi Says:

      Looks like Applidium has removed the content you’re referring to.

    Trackbacks

    1. Siri hackable using self signed certificate and DNS control | Julian, I am
    2. Does Siri Allow Hackers Access to iPhone 4S? | Siri iPhone4s
    3. Does Siri Allow Hackers Access to iPhone 4S? | Siri iOS 5
    4. 不要騙我,SIRI | 雲端防毒是趨勢


     

    © Copyright 2011 Trend Micro Inc. All rights reserved. Legal Notice