Apple Responds to iPhone SMS Spoofing Threat, Suggests You Use iMessage Instead

Apple has responded to pod2g's discovery of a vulnerability in iOS that allows for spoofing of SMS messages, reports Engadget.

Here is Apple's official statement:

Apple takes security very seriously. When using iMessage instead of SMS, addresses are verified which protects against these kinds of spoofing attacks. One of the limitations of SMS is that it allows messages to be sent with spoofed addresses to any phone, so we urge customers to be extremely careful if they're directed to an unknown website or address over SMS.

While Apple is correct in noting that SMS does allow messages to be sent with a different reply-to address, it neglects to comment on why iOS does not let you see who you actually getting the message from.

Pod2g notes, "In a good implementation of this feature, the receiver would see the original phone number and the reply-to one. On iPhone, when you see the message, it seems to come from the reply-to number, and you loose track of the origin."

Definitively - August 19, 2012 at 6:06pm
I am moving to WP8, Tim Cook will destroy Apple :(
Thatcher - August 20, 2012 at 9:55am
I fail to see how this message is relevant, the bug which Pod2G found has been present since iOS 1.0.0. You can't blame Tim Cook for this.
Gbone - August 19, 2012 at 1:56am
Why even bing it up ? You can ready my messages not that important As matter of fact all the messages R stupid .. Unless ur a wife or husband cheaters!!!
Bonehead - August 19, 2012 at 5:36pm
Because it's a serious security flaw that should not have been there in the first place, given that Apple has had 5 major iterations of the iPhone firmware released. I won't read your messages because your spelling sucks as much as your duh logic.
Jayzee - August 18, 2012 at 11:29pm
SMS is a bit old school when having iMessage and other messaging options like Whatsapp which not only comes cheaper since it's an internet feature which does not per message, but it also overcomes many limitations SMS has. But Apple should not take this lightly, it is a security flaw no matter what they say, and a very stupid one to fix, as a developer, I don't see any complications in fixing something like this so there is no excuse.
