Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Jailbroken Phones: Too Cool for Security
Articles

Jailbroken Phones: Too Cool for Security

Brian A. McHenryBy Brian A. McHenrySeptember 22, 2015Updated:December 30, 20215 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Smartphones are powerful devices, and a constant reminder that we are “living in the future.” We can take high-resolution photos, edit those photos, and upload them to the Internet in less time than it takes to order a cup of coffee. We can track our activity, our calorie intake, and our workouts. We can even get a ton of work done without ever opening a laptop or sitting down at a desk. All with a device that fits in the palm of the hand.

However, as with any complex device or system, vulnerabilities and the potential for bad guys to exploit them emerge. Along with the explosion in smartphone adoption has come new vectors for malware, virus infection, and so-called ransomware. A quick google of the terms “mobile device malware” yields dozens of results related to Android. Owing to various implementations of the Android OS by smartphone manufacturers, and a lot of choices for installing apps (Google Play Store, Amazon Appstore, sideloading Android application package files (APK)s, and more), there are many opportunities for the bad guys to introduce their nasty payloads.

In contrast, Apple iOS—regardless of carrier or device (iPhone, iPad, iPod, etc.)—is largely free of concerns about malware and other malicious payloads. The reason is not some innately better security in the iOS architecture vs. Android’s. It’s the closed ecosystem of iTunes and the App Store. It’s extraordinarily difficult to download any app or even music or movie without first going through one of these two Apple-controlled distribution mechanisms. Difficult, that is, unless an iPhone happens to be jail-broken, making it possible for users to download apps that aren’t available in the App Store.

The fact that almost every release of iOS gets jailbroken (despite the best efforts of Apple’s iOS developers) indicates that iOS is not inherently more secure than Android. However, because Apple vets and controls all apps available in the App Store, other security holes have very limited opportunity for exploit. As a result, the security track record of iOS has been much stronger than other platforms, and Apple users at least have the perception that their devices are relatively secure.

Why jailbreak a perfectly good iPhone, then? Well, especially among the high school set, there is the ever-tempting “cool factor” of having an app or customization that’s only available on a jailbroken iPhone. For others, it can be the desire to “have their cake and eat it, too”—all the polish of iOS without those pesky constraints of the App Store and the rigid default iOS interface. And for the tech-savvy, it can be the desire to tinker and see how things work. I’ve met more than a few folks with jailbroken iPhones, courtesy of a tech-savvy friend doing them a “favor.”

Regardless of the reasons, and despite disclaimers in many jailbreaking tools, many iPhone jailbreakers don’t fully grasp the security and privacy risks posed by leaving the safety of the closed Apple ecosystem. And with BYOD being the new reality, we must educate users to the risks of jailbroken phones. These risks extend beyond the individual to enterprise networks, applications, and the data a smartphone might access.

Various remote access solutions—SSL VPN gateways, virtual applications and desktops, and mobile application management solutions—are able to assess enterprise resources whether a user is running a supported operating system or a jailbroken version. While it may not be the kindest way to teach users about the dangers of jailbreaking their phones, preventing them from accessing sensitive systems and data using these compromised smartphones sends a clear message that these devices are no longer trustworthy. Make sure to update your mobile device policy and put it in writing.

Beyond simply restricting access, security training can help raise awareness about safe mobile device usage. Most training I’ve seen focuses on spotting potential phishing attacks, using good password practices, and logging out of sensitive accounts. Security awareness training can go a step further and educate aggressively about jailbreaking iPhones as well as sideloading apps from untrusted sources. While some organizations are adopting a strategy of segregating corporate and personal data on the device, or creating closed enterprise ecosystems featuring wrapped apps in an enterprise app store, these can be seen as half-measures that assume too much risk for the enterprise.

Whatever strategy we choose to reduce the risk of malicious apps on personal and enterprise-issued devices, the key is to educate ourselves on how the various operating systems provide security, and to make no assumptions about the security posture of any given device. It’s important to assess the security posture of every device that has access to our systems and data—on each and every request for access.[su_box title=”About Brian A. McHenry” style=”noise” box_color=”#336588″]Brian_McHenryAs a Security Solutions Architect at F5 Networks, Brian McHenry focuses on web application and network security. McHenry acts as a liaison between customers, the F5 sales team, and the F5 product teams, providing a hands-on, real-world perspective. Prior to joining F5 in 2008, McHenry, a self-described “IT generalist”, held leadership positions within a variety of technology organizations, ranging from startups to major financial services firms.

Twitter: @bamchenry[/su_box]

Brian_McHenry
Brian A. McHenry

As a Senior Security Solutions Architect at F5 Networks, Brian McHenry focuses on web application and network security. McHenry acts as a liaison between customers and F5 product teams, providing a hands-on, real-world perspective. He is a regular contributor on InformationSecurityBuzz.com, a co-founder of BSidesNYC, and a speaker at AppSecUSA, BC Aware Day, GoSec Montreal, and the Central Ohio Infosec Summit, among others. Prior to joining F5 in 2008, McHenry, a self-described IT generalist, held leadership positions within a variety of technology organizations, ranging from startups to major financial services firms.

  • Brian A. McHenry
    The WAF Is Not Enough
  • Brian A. McHenry
    Access Management, With A Side Order Of Identity
  • Brian A. McHenry
    The Internet of Thingbots
  • Brian A. McHenry
    Black Hat USA 2017: Bigger and Better (?)

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Lazarus Group Turns to Medusa Ransomware in Escalating Global Extortion Campaign

February 26, 20263 Mins Read

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}