Register FAQ/Rules Forum Spy Search Today's Posts Mark Forums Read

Welcome to the Mac Forums forums. Please read the FAQ if you have questions. Register to participate.

 
Go Back   Mac Forums > News and Article Discussion > MacRumors.com News Discussion
TouchArcade.com - iPhone Game Reviews and News

Reply
 
Thread Tools Search this Thread  
Old Aug 27, 2008, 12:19 PM   #1
MacRumors
macrumors bot
 
Join Date: Apr 2001
iPhone Passcode Flaw Already Addressed for Future Firmware Update?



Gizmodo publicizes a security flaw that was publicly posted last night to MacRumors' Discussion Forum. The vulnerability allows individuals to easily bypass the built-in passcode protection offered by Apple to lock your iPhone.

The workaround allows unauthorized individuals access to the iPhone's Safari, Contacts list, SMS, Maps, and Mail.

MacRumors has been told that this security flaw was already reported to Apple earlier this month and has been acknowledged as an issue. A fix will presumably be included in a future firmware update.

Update: A simple fix is available in the meanwhile. Users should set their "Home Button" double-click preference to "Home" or "iPod" rather than the default "iPhone Favorites".

Article Link

Last edited by arn : Aug 27, 2008 at 12:54 PM.
MacRumors is offline   Reply With Quote
Old Aug 27, 2008, 12:21 PM   #2
thecartoonguy
macrumors 6502
 
Join Date: Jun 2008
Let's hope sooner than later
__________________
Windows users laugh at my Apple but I continue to use MY APPLE while you're removing viruses, spyware or reformatting your drive.... Oh and there's this too- http://tinyurl.com/lunlf7
thecartoonguy is offline   Reply With Quote
Old Aug 27, 2008, 12:22 PM   #3
Mindflux
Banned
 
Join Date: Oct 2007
Location: Austin
Quote:
Originally Posted by thecartoonguy View Post
Let's hope sooner than later
Why? For all those 'h4x0rs' you let use your phone?
Mindflux is offline   Reply With Quote
Old Aug 27, 2008, 12:22 PM   #4
arian19
macrumors member
 
Join Date: Jul 2008
who hacked my iphone?
arian19 is offline   Reply With Quote
Old Aug 27, 2008, 12:23 PM   #5
mogzieee
macrumors 6502a
 
mogzieee's Avatar
 
Join Date: Feb 2008
Location: Oxford, UK.
Sounds like someone at Apple reads Mac Rumors Discussions and Gizmodo...
__________________
15" MacBook Pro 2.4GHz, 8GB iPod touch, 1GB iPod shuffle, MobileMe.
website. blog. twitter.
mogzieee is offline   Reply With Quote
Old Aug 27, 2008, 12:24 PM   #6
Mykbibby
macrumors 6502
 
Join Date: Jun 2007
Location: Palm Springs, CA
Send a message via AIM to Mykbibby
Not a big deal in my eyes... If some hacker gets your phone, believe me, a passcode isn't stopping them.
__________________
Mac Soda: Quenching Your Thirst for Everything Apple
Mykbibby is offline   Reply With Quote
Old Aug 27, 2008, 12:25 PM   #7
Beric
macrumors 68000
 
Beric's Avatar
 
Join Date: Jan 2008
Quote:
Originally Posted by mogzieee View Post
Sounds like someone at Apple reads Mac Rumors Discussions...
I believe a ton of Apple employees do. We get heard, believe it or not. That's why Arn gets all of the CAD letters on removing leaked photos.
Beric is offline   Reply With Quote
Old Aug 27, 2008, 12:26 PM   #8
twoodcc
macrumors 603
 
twoodcc's Avatar
 
Join Date: Feb 2005
Location: Right side of wrong
Send a message via AIM to twoodcc Send a message via MSN to twoodcc
well i'm glad to see that Apple is already working on this. hopefully they'll fix it soon
__________________
tville pump
Smarter than the average bear
twoodcc is offline   Reply With Quote
Old Aug 27, 2008, 12:27 PM   #9
Masquerade
macrumors 6502a
 
Join Date: May 2007
OMG and these guys are working in server-OSses :X
Masquerade is offline   Reply With Quote
Old Aug 27, 2008, 12:27 PM   #10
dvkid
macrumors regular
 
Join Date: Feb 2006
Sensationalism much?

Huge iPhone Security Flaw Puts All Private Information at Risk

Really? Because I don't have a pass-code on my iPhone at the moment. Just don't let random folks use your phone?

Gotta love the AOL bloggers and their TimeWarner craziness.
dvkid is offline   Reply With Quote
Old Aug 27, 2008, 12:28 PM   #11
Niiro13
macrumors 68000
 
Join Date: Feb 2008
Location: Illinois
Send a message via AIM to Niiro13 Send a message via MSN to Niiro13 Send a message via Yahoo to Niiro13
Quote:
Originally Posted by mogzieee View Post
Sounds like someone at Apple reads Mac Rumors Discussions and Gizmodo...
Quote:
Originally Posted by Beric View Post
I believe a ton of Apple employees do. We get heard, believe it or not. That's why Arn gets all of the CAD letters on removing leaked photos.
Yup...they're just not allowed to post, right? I thought I read that somewhere on this forum.


Anyway, if this passcode was already being addressed, wouldn't it have come out? Is it not a simple override of the double tapping of the home button when on the passcode screen?
Niiro13 is offline   Reply With Quote
Old Aug 27, 2008, 12:31 PM   #12
aardwolf
macrumors member
 
Join Date: May 2007
Doesn't affect me.

I don't even lock my phone... And if I did, I've read that setting your double-click home action to actually go to the home page will prevent this exploit from working.
aardwolf is offline   Reply With Quote
Old Aug 27, 2008, 12:31 PM   #13
Clayne
macrumors 6502
 
Join Date: Jul 2008
Quote:
Originally Posted by Niiro13 View Post
Yup...they're just not allowed to post, right?
Probably. I bet they're reading this right now, laughing.

And I bet they get a lot of laughs watching us try and guess what's coming out, including all the bizarre things we think of.
__________________
"The society that abolishes all adventure makes the abolition of that society the only real adventure."
Clayne is offline   Reply With Quote
Old Aug 27, 2008, 12:34 PM   #14
gcmexico
macrumors 6502a
 
gcmexico's Avatar
 
Join Date: Dec 2007
Location: New York City
I just tried it...yep security flaw...thanks macrumors
__________________
PB G3, Imac G4, Imac G5, MacMini Media Center, MBA, TV, 3gS Iphone, 4th gen Nano, Drobo
gcmexico is offline   Reply With Quote
Old Aug 27, 2008, 12:37 PM   #15
m4c1nt05h
macrumors newbie
 
Join Date: Jun 2007
here's the work-around

"iPhone users who want to guard against this flaw have a really simple solution - in (Settings) General access the Home Button Settings, and switch double-clicking from 'Phone Favorites' (default) to iPod. " - taken from 9to5mac.com

why didn't macrumors post this?
m4c1nt05h is offline   Reply With Quote
Old Aug 27, 2008, 12:38 PM   #16
pavvento
macrumors 6502
 
Join Date: Jun 2007
Quote:
Originally Posted by dvkid View Post
Huge iPhone Security Flaw Puts All Private Information at Risk

Really? Because I don't have a pass-code on my iPhone at the moment. Just don't let random folks use your phone?

Gotta love the AOL bloggers and their TimeWarner craziness.
I don't think the security concern is having random people use your phone. I think its for the very realistic scenario where your phone might be lost or stolen. Your company (for people on exchange) would most probably want to do a remote wipe immediately, but if someone has the phone and open access they can get to your information before it's cleared out.

For a company hoping to get its phone into the corporate world this is a HUGE oversight.
pavvento is offline   Reply With Quote
Old Aug 27, 2008, 12:40 PM   #17
thejadedmonkey
macrumors 68040
 
thejadedmonkey's Avatar
 
Join Date: May 2005
Location: Pa
Send a message via AIM to thejadedmonkey
Quote:
Originally Posted by MacRumors View Post
MacRumors has been told that this security flaw was already reported to Apple earlier this month and has been acknowledged as an issue. A fix will presumably be included in a future firmware update.
Doesn't mean anything. I've submitted bugs to Apple before, and they've been acknowledged, but then thrown out as "intended behavior". I would assume they'd fix it, but still.... don't count your chickens before they hatch!
__________________
Mac Mini G4 • MacBook Pro • iPod Nano
"Good judgement comes from experience,
experience comes from bad judgement.
- Mark Twain
thejadedmonkey is offline   Reply With Quote
Old Aug 27, 2008, 12:40 PM   #18
Snowcat001
macrumors regular
 
Join Date: Jan 2008
Location: Belgium
Quote:
Originally Posted by Beric View Post
I believe a ton of Apple employees do. We get heard, believe it or not. That's why Arn gets all of the CAD letters on removing leaked photos.
The real question is... who on MacRumors is an Apple employe???
We should have a poll about this
: Who do you think, on this forum, is an apple employe?

Snowcat001 is offline   Reply With Quote
Old Aug 27, 2008, 12:41 PM   #19
mBox
macrumors 6502
 
Join Date: Jun 2002
Quote:
Originally Posted by m4c1nt05h View Post
"iPhone users who want to guard against this flaw have a really simple solution - in (Settings) General access the Home Button Settings, and switch double-clicking from 'Phone Favorites' (default) to iPod. " - taken from 9to5mac.com

why didn't macrumors post this?
Funny thing is I did this weeks ago not knowing about the flaw
mBox is offline   Reply With Quote
Old Aug 27, 2008, 12:47 PM   #20
AnthonyKinyon
macrumors regular
 
Join Date: Apr 2006
Does this affect iPod Touch at all? I wouldn't think so given that it's not a phone.
AnthonyKinyon is offline   Reply With Quote
Old Aug 27, 2008, 12:50 PM   #21
towlieban
macrumors newbie
 
Join Date: Sep 2007
passcode lock

I've got news for you guys. Last week, I set a passcode and forgot it. Since my phone is jailbroken (I'm on 2.0.1) and has ssh installed, I did some research and found 2 things that need to be changed to completely disable the passcode and it's surprisingly easy. If anyone wants these instructions then let me know
towlieban is offline   Reply With Quote
Old Aug 27, 2008, 12:51 PM   #22
jtshaw
macrumors newbie
 
Join Date: Jan 2008
Quote:
Originally Posted by pavvento View Post
I don't think the security concern is having random people use your phone. I think its for the very realistic scenario where your phone might be lost or stolen. Your company (for people on exchange) would most probably want to do a remote wipe immediately, but if someone has the phone and open access they can get to your information before it's cleared out.

For a company hoping to get its phone into the corporate world this is a HUGE oversight.
For what its worth... if you connect to exchange with your iPhone and you lose it you should probably go ahead and change your exchange password asap...

Of course, then you might have to deal with the annoyance of some guy locking your corp. account because he keeps trying to mess with your work e-mail but fails password auth, but it is better then having sensitive data leaked.
jtshaw is offline   Reply With Quote
Old Aug 27, 2008, 12:51 PM   #23
Matthew Yohe
macrumors Demi-God
 
Join Date: Oct 2006
Location: Iowa City, IA
Send a message via AIM to Matthew Yohe
Quote:
Originally Posted by towlieban View Post
I've got news for you guys. Last week, I set a passcode and forgot it. Since my phone is jailbroken (I'm on 2.0.1) and has ssh installed, I did some research and found 2 things that need to be changed to completely disable the passcode and it's surprisingly easy. If anyone wants these instructions then let me know
product-security@apple.com
Matthew Yohe is offline   Reply With Quote
Old Aug 27, 2008, 12:52 PM   #24
dagamer34
macrumors regular
 
Join Date: May 2007
It's not a security flaw if it depends on a user's stupidity, FYI
dagamer34 is offline   Reply With Quote
Old Aug 27, 2008, 01:03 PM   #25
Sijmen
macrumors 6502a
 
Join Date: Sep 2005
Quote:
Originally Posted by dagamer34 View Post
It's not a security flaw if it depends on a user's stupidity, FYI
Uh, what? What's so stupid about setting a passcode and leaving the other settings at their defaults?
Sijmen is offline   Reply With Quote

Reply

Mac Forums > News and Article Discussion > MacRumors.com News Discussion

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 01:08 AM.

Mac News | Mac Rumors | iPhone Game Reviews | iPhone Apps

Powered by vBulletin® Version 3.6.10
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright 2002-2009, MacRumors.com, LLC