Page 1 of 2
 1  2  >
Reply
   
 Serious Security flaw in 2.02 
 
 
  #1 (permalink)  
Old 27-08-2008, 09:53 PM
Regular

Group: Regulars
Location: Melbourne


Serious Security flaw in 2.02

While this doesn't affect me given I don't lock my iphone, this is a potentially MAJOR embarrassment for Apple which is desperately trying to push the iPhone into the Enterprise market.

Now any corporate IT person watching that video would be picking their jaw off the floor in horror.

See info at Gizmodo

The equally scary thing is all those users commenting that 'it's no big deal' and that 'you shouldn't store important info on it anyway'..... HELLO??? Enterprise users? For those guys secure data IS everything and being able to snoop around people's emails, contacts, make calls and surf the internet on their supposedly locked handset ISN'T good security...

I love Apple too but when they screw up like that they need the heavy stick treatment....let's not forget if that was Microsoft people would be singing it from the roofs...

Patch away Apple...this 2.0 software has more bugs than an entomologists hive.

Last edited by drzeus; 27-08-2008 at 09:59 PM.
drzeus is offline
Profile CardPM
Go to the top of the page
Reply With Quote
  #2 (permalink)  
Old 27-08-2008, 09:59 PM
☺ ☻ ☼ ♂ † ♪ ♥ 

Group: Regulars
Location: Melbourne Status:Awesome!


I don't passcode my phone, but I agree, it is a serious flaw.
__________________
Time Capsule 1 Tb (Ours) |  AppleTV 160 Gb (Ours)
MacBook Black C2D (His) | MacBook White C2D (Hers) | iBook G4 1.33Ghz (Ours)
iPhone 3G White 16 Gb (His) |  iPhone 3G White 16 Gb (Hers) |  iPod Nano Silver 2 Gb (Hers)
Successful Trades: purana, nez, OziMac, hMc | Support MacTalk by shopping at the Apple Store here!

Online Life.com
Erwin is offline
Profile CardPM
Go to the top of the page
Reply With Quote
mab
  #3 (permalink)  
Old 27-08-2008, 10:04 PM
Regular

Group: Regulars
Location: Darwin


Hum just downloading PwnageTool_2.0.3.1 But after seeing this I might wait as I'm sure Apple will have an update in the next day or so (well I hope so) thus rendering my pwnd phone unpwrd
__________________
 C2D MBP 15.4" 2.53GHz
 iPhone 16GB
٩๏̯͡๏)۶ LINUX: Fedora 9
mab is offline
Profile CardPM
Go to the top of the page
Reply With Quote
  #4 (permalink)  
Old 27-08-2008, 10:08 PM
I Am Hollywood

Group: Regulars
Location: Bendigo, Victoria


This is quite the cockup that Apple didn't need. But I can see this being fixed very soon. Prepare for 2.0.3 peoples.
__________________
mail | twitter | last.fm | flickr
dathnoth is offline
Profile CardPM
Go to the top of the page
Reply With Quote
  #5 (permalink)  
Old 27-08-2008, 10:09 PM
Here's to the crazy ones

Group: Regulars
Location: melbourne


Apple should hang there heads in shame :P
__________________
Redmond has a cat, too A copycat.
gareth is offline
Profile CardPM
Go to the top of the page
Reply With Quote
  #6 (permalink)  
Old 27-08-2008, 10:14 PM
Regular

Group: Regulars
Location: Perth


Easily fixed though, even the article tells you

Quote:
Until then, you can avoid any potential breach doing the following:

1. In the iPhone home, go to Settings.
2. Click on General.
3. Click on Home Button.
4. Click on either "Home" or "iPod".

This way, the double-click on the home button will take the user back to the unlock screen (if you use "Home") or the iPod screen. I recommend using Home. You will lose the ability to quickly access your favorites for a quick call—which is one of my favorite features—but that's better than having all your private mails, contacts, and SMS database compromised.
__________________
You can trust me. I'm not like the others
Mac Ram is offline
Profile CardPM
Go to the top of the page
Reply With Quote
  #7 (permalink)  
Old 27-08-2008, 10:15 PM
Regular

Group: Regulars
Location: Melbourne and Brisbane Australia


megga stuff up and particularly in the corporate world, Apple need to patch this quick. I can live without the quick access to Fav numbers if it means the phone stays locked.
__________________
The Aussie Motor Sport Podcast OzRacingWrap Podcast and Blog
OzPhotoWrap Podcast and Blog
My Flickr
Ozracingwrap is offline
Profile CardPM
Go to the top of the page
Reply With Quote
  #8 (permalink)  
Old 27-08-2008, 10:17 PM
☺ ☻ ☼ ♂ † ♪ ♥ 

Group: Regulars
Location: Melbourne Status:Awesome!


Quote:
Originally Posted by Mac Ram View Post
Easily fixed though, even the article tells you
But that's not a fix, that's a work-around. Most people will set the double click to Favourites.
__________________
Time Capsule 1 Tb (Ours) |  AppleTV 160 Gb (Ours)
MacBook Black C2D (His) | MacBook White C2D (Hers) | iBook G4 1.33Ghz (Ours)
iPhone 3G White 16 Gb (His) |  iPhone 3G White 16 Gb (Hers) |  iPod Nano Silver 2 Gb (Hers)
Successful Trades: purana, nez, OziMac, hMc | Support MacTalk by shopping at the Apple Store here!

Online Life.com
Erwin is offline
Profile CardPM
Go to the top of the page
Reply With Quote
  #9 (permalink)  
Old 27-08-2008, 10:18 PM
Regular

Group: Regulars
Location: Adelaide, SA


comments removed due to slow.
__________________
Mechanised Convulsions - Adelaide Industrial/Rhythmic Noise project on iTunes too!!!
Check out my new blog site | hit me up on Twitter or iChat, oh and Last.FM
mechcon is offline
Profile CardPM
Go to the top of the page
Reply With Quote
  #10 (permalink)  
Old 27-08-2008, 10:19 PM
Regular

Group: Users Awaiting Email Confirmation
Location: Australia


Well atleast i know that if they do push out 2.0.3 that it won't be worth updating to. Rumored that 2.1 is on its way in september sometime (i think early). Mine has always been set to iPod anyways, favourites? I barely touch the thing. Let alone i don't even passcode lock the phone, it becomes a pain in the arse after sometime.

Overall, should be fixed which i agree.
lefty22 is offline
Profile CardPM
Go to the top of the page
Reply With Quote
  #11 (permalink)  
Old 27-08-2008, 10:25 PM
Regular

Group: Regulars
Location: Perth


Quote:
Originally Posted by Erwin View Post
But that's not a fix, that's a work-around.
Very true.

I work for a v large mining company, and nobody there locks their blackberry's. You pick one up and off you go, email, contacts, etc. May not be right, but that's what they do - and I'm also sure it's probably against company policy.

However I do agree that it needs to be fixed.
__________________
You can trust me. I'm not like the others
Mac Ram is offline
Profile CardPM
Go to the top of the page
Reply With Quote
  #12 (permalink)  
Old 28-08-2008, 06:35 AM
Resident Pirate

Group: Regulars
Location: Sydney Metropolitan


Wow. That is a major security flaw.

But don't forget the minor security flaw of the proper way. The numbers to unlock the phone are always in the same places. Fingerprints will mass up over the numbers for unlocking. If you tilt the iPhone to see the fingerprints, you just have to try all the combinations of four or 5 or however many popular regions of the screen (that is, if you can see a small enough number of mass fingerprinted areas) to unlock the phone. That unlock screen should at least have a scramble pad.
__________________
Mac OS X Leopard 10.5.4, Still can't quicklook volume icons of greater than 128*128 when icon was pasted from picture.
iPirate is offline
Profile CardPM
Go to the top of the page
Reply With Quote
  #13 (permalink)  
Old 28-08-2008, 08:26 AM
That TAM guy

Group: Regulars
Location: Melbourne


That's why I'm loving 1.1.4 - no problems here.
__________________
WANTED: VIDEO INPUT CARD FOR 5500/225 TO MAKE TV TUNER WORK
leon is offline
Profile CardPM
Go to the top of the page
Reply With Quote
  #14 (permalink)  
Old 28-08-2008, 08:43 AM
The Angels have the phone box

Group: Regulars
Location: Melbourne
Blog Entries: 10


I don't use passcode lock, very annoying. What is more annoying though is that if you happened to leave your phone unattended and you have some bastard friends there is no way to stop them putting a passcode lock on your phone if they felt like being a**holes. Not that I ever leave it lying around (it's basically within visual range 24/7) but watch out if you have geek friends who have a grudge.
__________________
16GB White Iphone 3G - Unlocked and Jailbroken 2.2 * 8GB Black Nano third Gen * Macbook: 2.1ghz White 4GB RAM 320GB HDD
Twitter.
Successful trades: Fishinthecity.
mitty is offline
Profile CardPM
Go to the top of the page
Reply With Quote
  #15 (permalink)  
Old 28-08-2008, 08:50 AM
☺ ☻ ☼ ♂ † ♪ ♥ 

Group: Regulars
Location: Melbourne Status:Awesome!


Quote:
Originally Posted by mitty View Post
What is more annoying though is that if you happened to leave your phone unattended and you have some bastard friends there is no way to stop them putting a passcode lock on your phone if they felt like being a**holes.
I wouldn't consider such people as friends.
__________________
Time Capsule 1 Tb (Ours) |  AppleTV 160 Gb (Ours)
MacBook Black C2D (His) | MacBook White C2D (Hers) | iBook G4 1.33Ghz (Ours)
iPhone 3G White 16 Gb (His) |  iPhone 3G White 16 Gb (Hers) |  iPod Nano Silver 2 Gb (Hers)
Successful Trades: purana, nez, OziMac, hMc | Support MacTalk by shopping at the Apple Store here!

Online Life.com
Erwin is offline
Profile CardPM
Go to the top of the page
Reply With Quote
 
Page 1 of 2
 1  2  >
Reply

Thread Tools

 
Similar Threads
 
Thread Thread Starter Forum Replies Last Post
Security Update 2007-005 - this morning. asphotos Mac OS X & All Software 13 25-05-2007 05:21 PM
Security update update g5agogo News 10 02-05-2007 08:04 PM
Mac OS-X Security Update 2006-007 Galumay News 9 30-11-2006 11:28 AM
Serious security hole in OSX Safari + Mail Danamania News 41 23-02-2006 05:44 PM
One big fat OS X security flaw. Danamania Mac OS X & All Software 9 01-03-2005 08:24 PM