The new Apple iPhone OS 3.1 software comes with a new anti-phishing feature for the Mobile Safari browser, but researchers say the filter doesn't work.
"I've not been able to get it to block anything," says Michael Sutton, vice president of research at Zscaler, who has been testing the mobile browser's security feature against several phishing sites identified on PhishTank. While Apple's Safari for the desktop blocks many of the sites, the iPhone's mobile version didn't block any that he tested.

Sutton says it's either a bug in the OS 3.1 software, or the new iPhone software just runs a pared-down version of the Safari browser's security feature. "OS 3.1 has settings in the Safari browser for turning on and off phishing protection, but it's just not [working]," Sutton says.

Apple had touted the new iPhone OS 3.0's anti-phishing feature, but Sutton says the feature was a no-show once the software was released in June, and he assumed the feature had just landed on the cutting floor.

The link for this article located at Dark Reading is no longer available.