|
|
| Welcome to the Mac Forums forums. Please read the FAQ if you have questions. Register to participate. |
|
|||||||
| TouchArcade.com - iPhone Game Reviews and News |
![]() |
|
|
Thread Tools | Search this Thread | Display Modes |
|
|
#26 |
|
macrumors 6502a
Join Date: Mar 2007
Location: Canada
|
Holy crap, I don't give a crap because I don't lock my iPhone since I usually keep it on my person.
It's the same thing with you laptop, as soon as someone has physical access to it, you are screwed anyway. |
|
|
|
|
|
#27 |
|
macrumors Demi-God
Join Date: Jul 2008
Location: Okie land
|
You can really dig into the phone with this, I followed the steps above first then did some exploring. I clicked on a contact in favorites, then clicked on the sms button. Once in sms I backed out of their text log and had access to all my text's. I picked a text I knew had a link in it, that got me to my Safari app. I could surf anywhere I wanted. I picked a contact with an address and had access to Maps and GPS. An email address get's you into mail. I'm sure there is more. Damn talk about dropping the ball.
|
|
|
|
| Cynicalone |
| View Public Profile |
| Find More Posts by Cynicalone |
|
|
#28 |
|
macrumors 6502a
Join Date: Jun 2007
|
i had this same issue in 1.1.4... i posted on the boards about it....
|
|
|
|
|
|
#29 |
|
macrumors Demi-God
Join Date: Apr 2006
Location: Telford, UK
|
That's a great find by the OP, and a big hole left there by Apple!
__________________
MacBook Pro 2.93Ghz, 4GB | 24" LED ACD | iPhone 3GS 32GB Black | ATV 160GB |
|
|
|
|
|
#30 |
|
macrumors 601
Join Date: Mar 2006
|
That is a big gaping hole, props to the OP for discovering this. I'm not too sure enterprise customers will be happy about this...even average consumers. Full access to a phone thats meant to be secured?
|
|
|
|
|
|
#31 |
|
macrumors 6502
Join Date: Nov 2007
Location: Cupertino, CA
|
wow... i hope they patch this soon.
|
|
|
|
|
|
#32 |
|
macrumors member
Join Date: Jun 2008
|
This is already in the front page of gizmodo.com good job in finding it... I hope they fix it soon!!!
|
|
|
|
|
|
#33 |
|
macrumors regular
|
Hmmm... A strange game. The only winning move is not to play. How about a nice game of chess?
|
|
|
|
|
|
#34 |
|
macrumors member
Join Date: Jul 2008
Location: Sussex, UK
|
wow! Just tried this in my 2.0 and it does the same thing... Come on apple!?!!
|
|
|
|
| tucker101uk |
| View Public Profile |
| Find More Posts by tucker101uk |
|
|
#35 |
|
macrumors member
Join Date: Jan 2008
|
That's bad news. Hope they fix it soon.
|
|
|
|
|
|
#36 |
|
macrumors 6502a
Join Date: Mar 2008
Location: London, UK.
|
Thermonuclear war sounds a tad more exciting.
|
|
|
|
|
|
#37 |
|
macrumors newbie
Join Date: Aug 2008
|
While we're on the subject of security, has anyone tried accessing the phone data as follows:
- connect phone (while locked) to a new computer and iTunes - backup iPhone If iTunes allows to sync the iPhone with the computer without requiring the passcode to unlock the phone, then ALL the data on the phone is backed up to the computer and can easily be accessed by anyone using the computer. Not in a position to try this out myself, but I think it just might work... iPhone never asks me for the passcode when I connect it to the computer. |
|
|
|
|
|
#38 |
|
Thread Starter
Banned
|
I have sent it off to Apple Feedback, Apple iTunes Support, Apple Mobile Me Support, TUAW, Someone at Apple is bound to see this!
Last edited by Doctor Q : Aug 28, 2008 at 09:32 PM. Reason: remove quote of removed post |
|
|
|
| greenmymac |
| View Public Profile |
| Find More Posts by greenmymac |
|
|
#39 |
|
macrumors 6502a
Join Date: Jun 2008
|
This "Major Security Flaw" has been there since 1.0
And no one detected it until now??? WOW |
|
|
|
|
|
#40 | |
|
Thread Starter
Banned
|
Quote:
1.0 didn't have the double tap home button option Last edited by Doctor Q : Aug 28, 2008 at 09:32 PM. Reason: post merge |
|
|
|
|
| greenmymac |
| View Public Profile |
| Find More Posts by greenmymac |
|
|
#41 |
|
macrumors regular
Join Date: Sep 2007
Location: New York, NY
|
So...
A stranger can have access to the phone app and safari. ... the only two applications that we're all having problems with. yawn |
|
|
|
|
|
#42 |
|
Thread Starter
Banned
|
|
|
|
|
| greenmymac |
| View Public Profile |
| Find More Posts by greenmymac |
|
|
#43 |
|
macrumors Demi-God
Join Date: Jul 2007
Location: Netherlands
|
I have Exchange setup on my iphone which forces you to set a passcode and I can verify that there is no security hole.
__________________
15" Unibody 2.8GHz, 4GB, 500GB HD 13" Blackbook 2.4GHz, 4GB, 250GB HD "My goal is simply to try to make products that really are meaningful to people." Jonathan Ive |
|
|
|
|
|
#44 |
|
macrumors 6502a
Join Date: Jun 2008
|
|
|
|
|
|
|
#45 |
|
macrumors newbie
Join Date: Aug 2008
|
If it is encrypted, then that's a new feature in 2.0 or iTunes 7 since back when I was in 1.1.3, I could easily access my SMS and calendar from the SQLITE databases that are backed up on my computer. Of course, it takes some time trying to guess which file is which database, but once that trivial task is done, it's very easy to see the data.
Don't have time to check this now, but I still doubt it's encrypted in any way. |
|
|
|
|
|
#46 | |
|
Thread Starter
Banned
|
Quote:
Last edited by Doctor Q : Aug 28, 2008 at 09:33 PM. Reason: language |
|
|
|
|
| greenmymac |
| View Public Profile |
| Find More Posts by greenmymac |
|
|
#47 |
|
macrumors 6502
Join Date: Jul 2008
|
|
|
|
|
|
|
#48 |
|
Thread Starter
Banned
|
|
|
|
|
| greenmymac |
| View Public Profile |
| Find More Posts by greenmymac |
|
|
#49 |
|
macrumors 68000
Join Date: Oct 2007
Location: Durham, NH
|
Macworld has an article about this now, referencing this thread as to pointing it out:
Macworld Link And as it states in their article, an Apple spokesperson in London had no knowledge of this flaw, so this very well might be the first that they have heard of it, if so, expect this to be fixed in 2.1, or maybe an unplanned release of 2.0.3 directed only at this problem.
__________________
Current: White MacBook 2.2 GHz (late-2007) ; 8GB iPod touch (1st-gen) : Setup Pics Soon: |
|
|
|
|
|
#50 |
|
macrumors 68020
Join Date: Jul 2007
Location: NYC
|
Wirelessly posted (iPhone: Mozilla/5.0 (iPhone; U; CPU iPhone OS 2_0_2 like Mac OS X; en-us) AppleWebKit/525.18.1 (KHTML, like Gecko) Version/3.1.1 Mobile/5C1 Safari/525.20)
Pretty ironic, considering all the hoops developers have to jump through to stay within Apple's SDK boundaries, insuring nothing they do compromises the phone. Apple obviously doesn't need any help from devs; the iPhone is perfectly capable of compromising itself.
__________________
Check out my crappy t-shirts Last edited by mcdj : Aug 27, 2008 at 09:12 AM. |
|
|
|
![]() |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|