Apple's Captive Portal Test

ET is not the only one dialing home. It appears your Apple devices do, too.

Whenever an Apple iOS device, whether it’s an iPhone, iPad, or iPod Touch, connects to a Wi-Fi network, it makes a request to an Apple URL (http://www.apple.com/library/test/success.html). The URL looks harmless, and no personal identifying information is sent to this site. It’s not exactly a privacy issue, but it opens the door for potentially scary scenarios.

We have a name for software that calls the mothership without our being aware of it: spyware.

Security expert Robert Graham of Errata Security downplayed concerns, pointing out that the URL request actually served a useful function. The Apple devices hit the test site to determine if there is a “captive portal” on the Wi-Fi network. This refers to networks that require users to login or accept the Terms of Service before allowing the user to get online, such as free Wi-Fi at the library or a paid hotspot service.

Users using a Web browser on these networks are forced to a login or ToS page, before being redirected to the page they were trying to access. Users trying to get online by other means, such as syncing e-mail, can’t get online and don’t see a prompt indicating they need to open the browser first.

When the mobile device gets on the network for the first time, it tries to access the test site. If it can’t get a response from Apple’s servers confirming the connection is up, the operating system launches a dialog box. The user can log in without opening up the Web browser, and when it’s time to access the e-mail sync, everything works fine.

However, since this is just a simple HTTP request, it can easily be redirected to somewhere less wholesome, and potentially damaging. Even if it’s trying to be helpful, we have some issues with something we bought accessing sites without our say-so.

Showing 2 comments

  1. TheBigSchtroumpf at 7:44pm 10th September 2010 Microsoft do the same thing with Windows 7, no? And how is it possible to detect if we are connected or not to the net without trying to reach an external server? Anyway, I think that there should be a protocol allowing the OS to connect automatically to theses hotspots after saving the login/pwd at the first connection. It works like that in my uni and it is so annoying to have to relogin each time I want to go to the net.
  2. ioman at 10:42am 10th September 2010 I am really surprised to see Apple do this. It's sad too. It's like the company has to go through all the same mistakes Microsoft did to realize what potential threats are out there. They have been so sheltered from hackers up until now.
Close Suggestion Apple iTunes 10: What’s new
View Article