|
|
| Welcome to the Mac Forums forums. Please read the FAQ if you have questions. Register to participate. |
|
|||||||
| TouchArcade.com - iPhone Game Reviews and News |
![]() |
|
|
Thread Tools | Search this Thread |
|
|
#1 |
|
Banned
|
Admin Edit: User hdm42 appears to be the original source for this flaw discovery.
----------------- 2.0.2 gives almost full access to the iPhone even while under password protection... Steps to Reproduce Set iPhone to use passcode lock, have contacts marked as Favorites with links, phone numbers, addresses, etc in address book entry. Tap "Emergency Call" keypad from passcode entry screen. Double-tap home button. Tap blue arrow next to contact's name. You now have full access to applications such as Safari, complete Contacts list, SMS, Maps, "full" Phone access, and Mail by accessing various entries on the Favorite's page, i.e. tapping their home page brings up a full, unrestricted Safari. Last edited by arn : Aug 29, 2008 at 10:05 PM. |
|
|
|
| greenmymac |
| View Public Profile |
| Find More Posts by greenmymac |
|
|
#2 |
|
macrumors member
Join Date: Aug 2008
|
WOW! I cant believe Apple would release an update with a security flaw like this. I cant wait for 2.1...
|
|
|
|
|
|
#3 |
|
macrumors Demi-Goddess
Join Date: Feb 2005
Location: NC
|
I refuse to move to 2.02 so I cannot try, but holy ****! I tried it on 2.01 and guess what? It works the same way!
How in the world did you find this? And it is a huge flaw. Did you report it to Apple? I think I'm going to (or at least toss it on Digg so people know), it may be all in vain, but at least it's a start.
__________________
persona non grata
Last edited by jessica. : Aug 26, 2008 at 10:51 PM. |
|
|
|
|
|
#4 |
|
macrumors Demi-God
|
Wow! Wow! And Wow!
__________________
MBP 2.5GHz 250GB Mac Pro 3G S⃣ iPhone 32GB Black
|
|
|
|
| SFStateStudent |
| View Public Profile |
| Find More Posts by SFStateStudent |
|
|
#5 |
|
macrumors 6502a
Join Date: Aug 2006
|
yeah, that's messed up.
__________________
Mac Pro 2.8 dual quad Macbook Core Duo 16 gig 3G |
|
|
|
| rockinrocker |
| View Public Profile |
| Find More Posts by rockinrocker |
|
|
#6 |
|
macrumors 68000
|
Oh, DANG! That's so...wow...
See you on the front page .
|
|
|
|
|
|
#7 |
|
macrumors 68020
Join Date: Jul 2007
Location: NYC
|
you *did* send feedback to apple on this, yes?
__________________
Check out my crappy t-shirts |
|
|
|
|
|
#8 |
|
macrumors regular
|
It doesn't work for me, double tapping just takes me to the iPod screen.
__________________
iMac G3, 233 Mhz, 96 MB RAM, 4 GB HD eMac G4, 700 Mhz, 768 MB RAM, 40 GB HD Powerbook G4, 1.67 Ghz, 2 GB RAM, 120 GB HD Mac Pro, 2.66 Octocore, 6 GB RAM, 4870, 1 TB HDD |
|
|
|
|
|
#9 |
|
macrumors 6502
Join Date: Mar 2008
Location: Queens, NY
|
This is awesome! SEcret doors!
Can't wait till this is on gizmodo/engadget...etc. |
|
|
|
|
|
#10 | |
|
macrumors newbie
Join Date: Jul 2008
|
Quote:
|
|
|
|
|
| AndroidSUCKS |
| View Public Profile |
| Find More Posts by AndroidSUCKS |
|
|
#11 |
|
macrumors 65816
Join Date: Jun 2007
|
I tried this and all my iPhone did is say:
"Would you like to play a game?" |
|
|
|
|
|
#12 |
|
macrumors 6502a
|
lmfao wth
__________________
MacBook pro (Mid-2009): 13.3" 2.53GHZ 4GB RAM 250HD iPhone 3GS 16GB Black (3.0) ![]() www.techinfoteam.com |
|
|
|
|
|
#13 | |
|
macrumors 68000
|
Quote:
I just tried it and it works with the iPod setting. Good thing that if you set double tap to Home that it simply brings you back to the passcode screen. So it only works if you have it set to Favorites or iPod. |
|
|
|
|
|
|
#14 |
|
macrumors Demi-God
Join Date: Jul 2008
Location: Okie land
|
How did that slip threw
![]() ![]()
|
|
|
|
| Cynicalone |
| View Public Profile |
| Find More Posts by Cynicalone |
|
|
#15 | |
|
macrumors regular
Join Date: Mar 2008
|
Quote:
edit: And tree'd. |
|
|
|
|
|
|
#16 |
|
macrumors 68020
Join Date: Jul 2007
Location: NYC
|
Same way you typed "threw" when you meant "through".
__________________
Check out my crappy t-shirts |
|
|
|
|
|
#17 | |
|
macrumors 6502a
Join Date: Jun 2007
Location: KC
|
Quote:
The fix FTW: disable double tapping of home button in Settings > General > Home Button > Checkmark Home and it will kick it back out of the emergency call screen when they double tap. If you don't care about someone listening to your iTunes library, then just select iPod instead or you can leave this setting alone if it's already set, which it was on my iPhone originally.
__________________
MBP 2.4ghz 4gb ram 500gb hd / 32gb iPhone 3g S⃣ www.duke-design.com - Graphic design, photography, and more! |
|
|
|
|
|
|
#18 |
|
macrumors 6502
Join Date: Feb 2007
Location: earth, long beach to be exact
|
That was funny.
__________________
17" hi-res 2.4 macbook pro c2d 4gb 160gb 13" MBP 2.53ghz 17" imac g4 1.25 ghz 1.25gb 80gb |
|
|
|
|
|
#19 | |
|
macrumors regular
Join Date: Mar 2008
|
Quote:
|
|
|
|
|
|
|
#20 |
|
macrumors 65816
Join Date: May 2007
Location: Northern NJ
|
Wow, this deserves to be on the front page! Good find.
|
|
|
|
|
|
#21 |
|
macrumors Demi-God
Join Date: Jul 2008
Location: Okie land
|
|
|
|
|
| Cynicalone |
| View Public Profile |
| Find More Posts by Cynicalone |
|
|
#22 |
|
macrumors 65816
Join Date: May 2007
Location: Northern NJ
|
Wow, just tried this on my iPhone and can't believe that it actually works. Can't get into Safari since none of my favorite contacts have any webpages associated with them, but it's still scary that anyone would be able to call, email or text message my closest friends and family without having any clue as to what my passcode is.
|
|
|
|
|
|
#23 |
|
macrumors 6502a
Join Date: Sep 2007
|
Holy crap! I too just tried this and replicated it just as you said. This is crazy! Apple needs to fix this and fast. I too am going to send a report to Apple regarding this. Very nice catch!
__________________
32 GB iPhone 3G S (Black)
20" Alum iMac 2.4GHz 4GB RAM 320GB HD 13" MacBook Pro 2.26GHz 4GB RAM Canon HV30 | Nikon D90 Scott Ramsden's Photography! |
|
|
|
|
|
#24 |
|
macrumors regular
Join Date: Apr 2007
|
Wow, sounds like someone at Apple is about to be yelled at or get fired...
Nothing is perfect, but this is quite unacceptable. It's not a major problem for me since I don't really use that feature, but I'm sure that shows the unreliability the iPhone has especially for high-level agents that need to secure their information. |
|
|
|
|
|
#25 |
|
macrumors 68000
|
I see 2.0.3 in the horizon.
|
|
|
|
![]() |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|