Chinese government launches man-in-middle attack against iCloud

Chinese government launches man-in-middle attack against iCloud Targeting new iPhone users to capture user credentials, monitors find.

by Sean Gallagher Oct 20 2014 Ars Technica

GreatFire.org, a group that monitors censorship by the Chinese government's national firewall system (often referred to as the "Great Firewall"), reports that China is using the system as part of a man-in-the-middle (MITM) attack on users of Apple's iCloud service within the country. The attacks come as Apple begins the official rollout of the iPhone 6 and 6 Plus on the Chinese mainland.

The attack, which uses a fake certificate and Domain Name Service address for the iCloud service, is affecting users nationwide in China. The GreatFire.org team speculates that the attack is an effort to help the government circumvent the improved security features of the new phones by compromising their iCloud credentials and allowing the government to gain access to cloud-stored content such as phone backups.

...

formatting link

***** Moderator's Note *****

The article contains a screenshot of the warning users see when they are asked to accept the forged "iCloud" certificate. Unfortunately, users don't understand digital certificates or what the warning means.

Bill Horne Moderator

Reply to
Monty Solomon
Loading thread data ...

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.