|
|
| Welcome to the Mac Forums forums. Please read the FAQ if you have questions. Register to participate. |
|
|||||||
| TouchArcade.com - iPhone Game Reviews and News |
![]() |
|
|
Thread Tools | Search this Thread |
|
|
#1 |
|
macrumors bot
Join Date: Apr 2001
|
1.1.1 Jailbreak Complete, Security Ramifications
![]() Engadget's Ryan Block has confirmed that a beta test of the latest jailbreak method for the 1.1.1 firmware of the iPhone and iPod touch works. The current method uses a vulnerability in 1.1.1's mobile Safari to gain root access to the device. Currently, this is the only method available to jailbreak an already upgraded iPhone or iPod Touch, as previous methods relied on firmware 1.0.2 still being available. While the developers are using the Safari vulnerability for somewhat benevolent purposes, it does raise a potential security issue for users. The vulnerability lies in mobile Safari's handling of TIFF images, where viewing a malformed TIFF image allows root access to the device. While the jailbreak is now complete from all angles, it still does not mean that the methods are ready for adoption by general users. We will consider it ready when Installer.app (or equivalent) is updated for the latest firmware. Ongoing iPhone coverage at macrumors.com/iPhone Article Link Last edited by longofest : Oct 10, 2007 at 10:31 AM. |
|
|
|
|
|
#2 |
|
macrumors 6502
Join Date: Jul 2007
|
Woot! Sort of. Well, I def. consider this good news
![]() edit: does anybody know what this means for iPhone AT&Tless activation? I've been waiting to buy an iPhone until the thing can be activated without AT&T service....
__________________
My switcher blog, and a source for first time OSX user: http://switch.shoelessone.com |
|
|
|
| shoelessone |
| View Public Profile |
| Find More Posts by shoelessone |
|
|
#3 |
|
macrumors 6502
|
Applications here we come!
__________________
Unibody MacBook Pro, 2.8 GHz, 4GB RAM, 500 GB FreeAgent Desktop 500GB FreeAgent Go 250GB Time Machine, Seagate 320GB |
|
|
|
|
|
#4 |
|
macrumors 65816
Join Date: Nov 2004
Location: Toronto, Ontario
|
The problem is that this is easily "fixable" by Apple AND they can legitimately say it's for security purposes
__________________
Yes I have a bunch of cool stuff, but no I don't feel the need to brag about it |
|
|
|
|
|
#5 |
|
macrumors regular
Join Date: Jan 2005
Location: So. UT
|
I haven't installed jailbreak before, but I'm planning to once Installer.app is available. I can't wait.
__________________
Keeping Apple debt-free since 1983. |
|
|
|
|
|
#6 |
|
macrumors 6502
Join Date: Nov 2005
|
so much for OS X security....
![]() I'd rather have a secure web browser and some decent Apple-approved applications, then install this.
__________________
Macbook Air 1.8 SSD; Powerbook 12" 1Ghz; iPhone 8gb 2.1 (t-mobile); iPod Nano 8gb (red); AEBS, Airport Express; WD Passport 320gb (airdisk) |
|
|
|
|
|
#7 |
|
macrumors member
Join Date: Mar 2002
|
Not really good news
This will certainly be fixed in 1.1.2 and not to frustrate the iPhoneDevTeam but because its an actual security issues. Then what? Without the key to decrypt the frameworks then 1.1.2 will break all of the apps developed here, again, not because Apple wants to frustrate hacker but because they are continuing to change/develop the API.
|
|
|
|
| dscottbuch |
| View Public Profile |
| Find More Posts by dscottbuch |
|
|
#8 | |
|
Demi-God (Editor)
|
Quote:
|
|
|
|
|
|
|
#9 |
|
macrumors 68000
Join Date: May 2003
Location: Saint Augustine, FL
|
Yep, this is certainly a very temporary situation. It would be impossible to imagine Apple won't close this hole, since it is a security issue.
If I had time, I'd explore how a malformed TIFF could gain you root access. Anybody have a 3 sentence summary? Edit: Someone said "Apple Approved" applications. Why does Apple have to approve them? They don't for regular Mac applications, thank god. If all apps have to go through some certification scheme, we'll be limited to what we get. In the end, don't install shady apps from shady people (like always) and you'll be fine! |
|
|
|
|
|
#10 |
|
macrumors regular
Join Date: Feb 2006
|
This is all good and well, but now we KNOW Apple will fix this in their next update as it is a security vulnerability. In fact, now that it has been brought to light I wouldn't be suprised to see a security update in the next couple of days. Sure, you don't have to install it, but all new iPhones and Touches will already not be able to use this method.
Just seems to be like a whole lot of effort and time going into something that is becoming progressively easier to brick wall. |
|
|
|
|
|
#11 |
|
macrumors regular
Join Date: Jul 2007
|
I don't understand how people could install this, knowing full well that the next firmware update will make their device un-useable.
Correct me if I'm wrong but wont your iphones all "brick" once apple fixes this problem and releases the next firmware?
__________________
iMac 20" Core 2 Duo (256mb Graphics Card & 2GB RAM Upgrades) Macbook Core 2 Duo iPod Video 5.5g 80gb (With iPod Linux) iPod Shuffle 1st gen (eww) |
|
|
|
|
|
#12 |
|
macrumors newbie
Join Date: Jul 2007
|
What about unlocked 1.0.2 iPhones?
I unlocked mine, and it is still 1.0.2 (as I fear that upgrading to 1.1.1 will brick it!) --
Is anyone else in this situation? I mean I love having it unlocked and with all the apps, but sure I'd like to have my cake and eat it too (unlocked/apps, AND 1.1.1)... Thanks! |
|
|
|
|
|
#13 |
|
macrumors newbie
Join Date: Mar 2004
|
Because one would imagine that once you jailbreak it, you wouldn't be foolhardy enough to upgrade the firmware to 1.1.2 and re-lock it again.
|
|
|
|
|
|
#14 | |
|
Demi-God (Editor)
|
Quote:
The people who got "bricked" were people who used the 3rd party unlocks. unlocking is a subset of a jailbreak, if you will. Jailbreaking comes first... it allows developers of all sorts to write applications. Then, unlockers (those who want to unlock the phone to run on any network) write specific applications that will unlock the phone. Some of those unlocking applications ended up bricking the iPhone when 1.1.1 was applied. |
|
|
|
|
|
|
#15 |
|
macrumors 6502a
Join Date: Sep 2006
|
From what NerveGas is saying on the dev channel, Niacin is not part of the dev team, and the dev team has their own jailbreak that does NOT rely on the tiff exploit. I'm planning on waiting for the dev team to come out with their solution, even though they aren't doing as good at getting the word out.
|
|
|
|
|
|
#16 | |
|
macrumors 6502a
Join Date: Apr 2004
Location: Heber Springs, AR
|
You have have obviously made a decision to remain in the past. This appears to be be the only way to move forward and it is basically on a course of disaster if you so chose to embark on it. I certainly would not.
Quote:
__________________
Pardon Multimedia - please give MM another chance! |
|
|
|
|
|
|
#17 | |
|
macrumors 6502a
Join Date: Sep 2006
|
Quote:
I hope that the News mods will research this and post an update to this article so we can all avoid confusion. |
|
|
|
|
|
|
#18 | |
|
macrumors 6502a
Join Date: Apr 2004
Location: Heber Springs, AR
|
Looks Like There Is Trouble in Paradise
Looks like there is trouble in paradise, First signs of a schism in the iPhone dev community:
http://www.tuaw.com/2007/10/10/first...dev-community/ Quote:
__________________
Pardon Multimedia - please give MM another chance! |
|
|
|
|
|
|
#19 | |
|
macrumors newbie
Join Date: Oct 2007
|
Quote:
Someone please correct me if I'm wrong. |
|
|
|
|
|
|
#20 |
|
macrumors newbie
|
iPhone Sadness
Is it just me, or is the whole point to and iPhone/Apple Product suppose to be simplicity. I am in Canada, the land of gay marriage and Weed. It is also the land of Rogers and therefore years behind the USA. I expect I will never live to see the day I can get an iPhone here with a fair monthly rate, and at a fair price. The dollar is at par and I want to get one in the USA and bring it up here, but I feel at the end of the day having an iPhone in Canada is more trouble than it is worth. Having an iPhone unlocked seems to be more of a headache than it is worth. I am ready to just give up on the iPhone in Canada, and smoke my pain away. :-(
|
|
|
|
|
|
#21 | |
|
macrumors 68000
Join Date: Jun 2007
|
Quote:
When 1.1.2 comes out and fixes this SECURITY HOLE.... apple is NOT being greedy or evil towards 3rd party apps. Of course I expect few to remember this and complain, but we now see as I and others have said, apple fixes security holes to make the iphpne safer. And as a result, many or most 3rd party hacks based on this security hole will fail. Don't like this? Don't hack your phone. Becase this is going to be an endless cycle for the time being. |
|
|
|
|
| plumbingandtech |
| View Public Profile |
| Find More Posts by plumbingandtech |
|
|
#22 | |
|
macrumors regular
Join Date: Jul 2007
|
Quote:
Thanks for the info
__________________
iMac 20" Core 2 Duo (256mb Graphics Card & 2GB RAM Upgrades) Macbook Core 2 Duo iPod Video 5.5g 80gb (With iPod Linux) iPod Shuffle 1st gen (eww) |
|
|
|
|
|
|
#23 |
|
macrumors 65816
Join Date: Nov 2003
|
So why are threads about running OS X on a PC closed down on this forum when open discussion of hacking is encouraged on the front page of mr.c on a regular basis? "but it's OK, cause it's the iphone and exempt from the rulz!"
Don't get me wrong, I think it is fine to discuss things like this. I just think it stinks that the moderators crack down on "inappropriate" content when someone is talking about violating a software license or getting around copy protection, etc, and then encouraging the exact same things with the iphone. This is MAC rumors, not iPHONE rumors. Maybe start a new site and put a big link at the top of mr.c pointing people towards iphonerumors.com if that's what they want, then relegate iphone conversations to a forum area inside the "Apple hardware" section of the forums list instead of on top of that section in its own section. The iphone is cool. But I use OS X every day and I want to know about that, not about stupid pointless hacking of safari TIFF files on the iphone. It isn't like this hack will last. /rant |
|
|
|
| benpatient |
| View Public Profile |
| Find More Posts by benpatient |
|
|
#24 | |
|
macrumors 6502a
Join Date: Feb 2007
Location: ERIE, PA
|
Quote:
Until Apple puts out an SDK I for one would not want to play this game! Good Luck All!
|
|
|
|
|
|
|
#25 | |
|
macrumors 6502a
Join Date: Sep 2006
|
Quote:
Apple failed to lock the original phone very well, and so people got a taste of what the iPhone was really capable of. Now we're just all hoping to have the best of both worlds, Apple's updates, and the software from 3rd parties. If you ask me, the big concern here is unlockers. While I sympathize, I kind of worry that they increase Apple's incentive to jail the iphone to keep their contract with AT&T. |
|
|
|
|
![]() |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|