iPhone Security Flaw Exposes All Private Data

You're a smart, safety conscious iPhone user, right? You keep the phone set to require a 4-digit passcode every time it wakes up, so if you ever lose your baby, all your personal information is safe. But if you are running v2.0.2 of the iPhone operating system, you might as well not bother. A simple hack will get anybody past your PIN code with free access to all your mail, contacts and bookmarks. Ouch!
Acting on a tip from the Mac Rumors forums, Gizmodo's Jesus Diaz whipped up a video of the exploit in action, a ridiculously easy two step process:
1. Tap emergency call.
2. Double tap the home button.
This drops you into the iPhones "favorites" section. From here you can make calls or send email, and with a few steps you can browse to the Address Book and then on to Mail, Safari or the SMS application. Jesus gives us a workaround (set the home button's double-tap to something else, either "Home" or "iPod" and you're safe) but this is exactly the sort of thing Apple doesn't want to happen. It hardly inspires credibility for the iPhone as a secure business device.
We expect it'll be fixed in v2.1, or maybe Apple will roll out a 2.0.3 update to fix it. Until then, we can add it to the long list of Apple's iPhone 3G embarrasments.
Huge iPhone Security Flaw Puts All Private Information at Risk [Gizmodo]
by Charlie Sorrel for Wired.comAlso on Wired.com:
Apple TV Ad Banned in UK
Facebook Still Has Worms
Relevant Ads Increase Brand Earnings
Subscribe to Wired magazine
- First Bytes: Amazon, YouTube, Facebook
- Dec 5 2008 10:39AM EST
- GannettBlog: Right Place in a Bad Time
- Dec 5 2008 8:10AM EST
- Smartphone Growth Slowing
- Dec 4 2008 3:05PM EST
- iPhone Gets an Amazon App
- Dec 4 2008 2:25PM EST
- Barack Obama Uses a Zune
- Dec 4 2008 1:30PM EST
- DOJ Ace: Google Dodged Monopoly Lawsuit By Three Hours
- Dec 4 2008 12:15PM EST
- First Bytes: AT&T, Obama, Sony, Microsoft, Spam
- Dec 4 2008 10:14AM EST
- Last Bytes: Cyber Monday, iPhone, YouTube, more
- Dec 3 2008 6:00PM EST
- Update: Miller NOT Gunning for Yahoo
- Dec 3 2008 4:42PM EST
- A Look Inside A Facebook for the Filthy Rich
- Dec 3 2008 4:03PM EST
- Yahoo Cedes Music Webcasting to CBS
- Dec 3 2008 3:00PM EST
- Telecoms, Advocacy Groups Unite Over Broadband "Stimulus"
- Dec 3 2008 1:53PM EST
- A Tweet Time with Ev Williams
- Dec 3 2008 12:54PM EST
- First Bytes: RIM, Yahoo, Twitter, Facebook, Apple
- Dec 3 2008 9:54AM EST
- Miller-Time for Yahoo?
- Dec 2 2008 9:06PM EST
Categories
Links
- Mark Cuban's blog

- TechCrunch

- GigaOM

- Engadget

- USA TODAY Tech

- Romenesko

- BuzzTracker Tech

- Roger McGuinn's Folk Den

- Maney's band on MySpace

- Spiedies, mmmm

- Somewhat Frank's tech conference list

- Tom Foremski

- Fred Wilson

- Pandora

- SciTech Daily

- Todd Bishop's Microsoft Blog

- Steven Johnson

- The Long Tail

- paidContent

- John Battelle's SearchBlog

- Marc Andreessen

- Kevin's site

- Kevin Maney & His Briefs on CD Baby










