::Trend Micro Threat Resource Center::

05 November 2011

Siri - Can She Spill Your Secrets?

By Default, Yes.
An IT/infosec expert Ben Schorr points out in an article, the feature of the iPhone 4S that everyone is excited about is Siri, the voice-enabled personal assistant. Siri can do some cool things - she can direct you to the nearest gas station, read you your e-mails and help you remember the coffee shop you liked in Seattle the last time you visited - ah, the wonders of GPS.

Unfortunately, Siri has no loyalty - if someone else gets possession of your phone, Siri will obligingly read them your texts or e-mails - or send text and e-mails that appear to come from you. This is true EVEN if you have your phone locked with a PIN.

This recently discovered security flaw can be corrected, but you must take the affirmative step of disabling Siri when the phone is locked - and how many users are going to do that? Unless you take that step, be wary of what you share with the faithless Siri!