+

Cookies on the Business Insider India website

Business Insider India has updated its Privacy and Cookie policy. We use cookies to ensure that we give you the better experience on our website. If you continue without changing your settings, we\'ll assume that you are happy to receive all cookies on the Business Insider India website. However, you can change your cookie setting at any time by clicking on our Cookie Policy at any time. You can also see our Privacy Policy.

Close
HomeQuizzoneWhatsappShare Flash Reads
 

UPDATED: Mailbox, The Super-Popular Email App, DOES NOT Have A Big Security Flaw

Apr 24, 2013, 19:54 IST

Kevin Smith/Business InsiderUPDATE: Behera has issued an update to his post: "After posting this on HackerNews some developers / users feel my hypothesis is wrong and one can not repeat the steps below without having physical access to an user’s phone or locked devices. I agree to this."

Advertisement

The short version of the story is that this isn't a bug, flaw, or anything of the like. If someone physically possesses your phone, they'd have access to this information anyway.

PREVIOUSLY: According to app developer Subhransu Behera, iOS email app Mailbox is a "security fail."

Complimentary Tech Event
Transform talent with learning that works
Capability development is critical for businesses who want to push the envelope of innovation.Discover how business leaders are strategizing around building talent capabilities and empowering employee transformation.Know More

We caught wind of this from 9to5Mac.

Behera found out that anyone with physical access to the phone can connect it to a computer and use a free program called iExplorer to access the app's files.

Advertisement

This little workaround gives someone access to your attachments, contacts, and the contents of your email.

Behera says it's an easy fix: "It’s all about adding few extra lines of codes to their iOS app to increase the security level. iOS SDK gives a developer a list data protection APIs for protecting documents, database, and other sensitive files that consist of confidential information about your users. I would love to try my hands on a better Mailbox iOS app, that is more secure. Until then I have deleted my accounts from Mailbox."

We have reached out to Mailbox for comment and will update when it replies.

Next Article