iPhone/iPad UDID Breach – The Beginning of the End?

Posted September 11, 2012 by Stacey S

We all knew it was coming, and today is the day.  No, I’m not talking about the new iPhone launch – I’m talking about the iPhone/iPad app vulnerability that allowed millions of personal device UDIDs to be exposed to the world on a website, allowing hackers around the world to begin “exploring” the endless possibilities of wreaking havoc on a huge chunk of the world’s population.  Why did this happen?  Well.. I guess since there’s no antivirus or security application of any kind on the iPhone or iPad, it was only a matter of time.

http://today.msnbc.msn.com/id/26184891/vp/48984347#48984347

In a previous post, I discussed the potential ramifications of allowing personal devices into a business environment.  Today’s announcement of the UDID breach further solidifies the notion that these devices are a serious risk to your network.  Because UDIDs uniquely identify a device to websites, and many apps allow login without any further authentication on your part, possession of a device’s UDID allows a hacker direct access to anything your device has direct access to.  This includes credit cards, bank accounts, etc.  Yikes!

As if the security implications of this announcement weren’t bad enough, I also have to wonder about the timing.  Apple is set to unveil the new iPhone tomorrow, and supposedly the only surefire way to protect yourself against the UDID breach is to buy a new iPhone/iPad…  Does anyone else smell a rat?  At any rate, BYOD = Bring Your Own Disaster, indeed.

Posted in: Dental Technology,