HomeStoreForumsWikiiPhone Native AppsiPhone Apps modmyifone Downloadsmodmyifone Links








Cell Phone Reception

Go Back   iPhone Forums at ModMyiFone.com - iPhone | iPod Touch, news, apps, themes. > ModMyiFone > News
Register FAQ Members List READ THIS Today's Posts Mark Forums Read

News What's the latest news? Check it out here. Grab Our News RSS Feed


Discuss AppStore Apps! | MMi Cydia Repo Download Stats

Get more out of ModMyiFone by joining our free community. By registering you get privileges to download files from our downloads section and you may also post your questions in our forums! It's fast, free, and easy!

2.0 Unlock|Jailbreak OS X / Windows | iPhone 3G Detailed Review w/Pics! | Developers - Port Your Apps to 2.0
Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 08-27-2008, 12:15 PM
Super Moderator
 
Join Date: Jul 2007
Posts: 1,197
Thanks: 46
Thanked 213 Times in 112 Posts
Huge Secuirty Flaw in firmware 2.0.1 and 2.0.2

Fortunately, there's a way to avoid this obvious security breach until Apple fixes it.

First, password protect your phone and lock it. Then slide to unlock and do this:

1. Tap emergency call.
2. Double tap the home button.

Done. You are now in your favorites. This seems like a feature, because you may want to have emergency number in your favorites for quick dial. The security problem here is double. The first: anyone picking up your phone can make a call to anyone in your favorites. On top of that, this also opens access to your full Address Book, the dial keypad, and your voice mail.

If that wasn't bad enough, the second one is even worse: if you tap on the blue arrows next to the names, it will give you full access to the private information in a favorite entry. And it goes downhill from there:

• If you click in a mail address, it will give you full access to the Mail application. All your mail will be exposed.
• If there's a URL in your contact (or in a mail message) you can click on it and have full access to Safari.
• If you click on send text message in a contact, it will give you full access to all your SMS.

Hopefully, this major security break that fully exposes your most private information will be solved as soon as possible. Until then, you can avoid any potential breach doing the following:

1. In the iPhone home, go to Settings.
2. Click on General.
3. Click on Home Button.
4. Click on either "Home" or "iPod".

This way, the double-click on the home button will take the user back to the unlock screen (if you use "Home") or the iPod screen. I recommend using Home. You will lose the ability to quickly access your favorites for a quick call—which is one of my favorite features—but that's better than having all your private mails, contacts, and SMS database compromised. UPDATE: Evidently Apple has a fix coming in their next firmware update, but we've got no word on when that release is planned


Source: Major Security Flaw in 2.0.2 - Mac Forums and every other iphone news site and our own member RaMod and One1
__________________
Click the image to open in full size.

Last edited by .:MirrorminD:.; Yesterday at 07:26 AM.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
The Following 4 Users Say Thank You to .:MirrorminD:. For This Useful Post:
dkaye (Yesterday), flexa (08-27-2008), hjmk (Today), mazen662 (08-27-2008)
  #2 (permalink)  
Old 08-27-2008, 12:21 PM
iPhone? More like MyPhone
 
Join Date: Sep 2007
Posts: 103
Thanks: 5
Thanked 6 Times in 6 Posts

Wow, now Apple will have to think of ways to fix this.
__________________
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #3 (permalink)  
Old 08-27-2008, 12:25 PM
iPhone? More like MyPhone
 
Join Date: Aug 2007
Device + Firmware: 3G-16GB/Black iPhone
Operating System: Vista
Posts: 124
Thanks: 14
Thanked 67 Times in 36 Posts

LOL!

I posted this in the "Chat" section since I don't have the rights to post it as news and also sent the news to "cash" by private message

I am glad you posted it as NEWS so people can see it. We all here to help!

You can remove my post from the "Chat" section if you want!

Thanks!

RaMod
__________________
RaMod!
If I helped you out, please press Click the image to open in full size.... thanks!

New 3G - 16GB/Black iPhone
(On 2.0.1 FW!! AT&T Customer - Jailbreaked and Activated, Cydia and Installer 4! )

=The iPhone?!...wait!...what happened!?=

Last edited by RaMod; 08-27-2008 at 01:09 PM. Reason: edit
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
The Following 9 Users Say Thank You to RaMod For This Useful Post:
.:MirrorminD:. (08-27-2008), 96hondaex (08-27-2008), DoerrFan (08-27-2008), flexa (08-27-2008), hawaiipoolman (08-27-2008), MacBam (08-27-2008), natekyla (08-27-2008), tahazahoor@hotmail.com (08-27-2008), wingy (Yesterday)
  #4 (permalink)  
Old 08-27-2008, 12:27 PM
Green Apple
 
Join Date: Jan 2008
Posts: 67
Thanks: 11
Thanked 0 Times in 0 Posts

That sucks, I guess Apple better fix this ASAP....
__________________
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #5 (permalink)  
Old 08-27-2008, 12:32 PM
iPhone? More like MyPhone
 
Join Date: Nov 2007
Device + Firmware: iphone 16gb 2.0.1 firmware
Operating System: XP (vista is booboo)
Location: The big apple
Posts: 188
Thanks: 10
Thanked 11 Times in 8 Posts

i have my home button to bring up my ipod when i double tap. but still that is pretty bad...
__________________
T-mobile 16gb 1st gen unlock'd and jailbroken on 2.0.1
I'm a NY GIANT!!! don't forget to say "thank you"
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #6 (permalink)  
Old 08-27-2008, 12:35 PM
What's Jailbreak?
 
Join Date: Jul 2007
Posts: 18
Thanks: 0
Thanked 1 Time in 1 Post

at least there is a working around until they can get it fixed. still sucks tho.
__________________
White 16GB 3G iPhone
Pwn'd!
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #7 (permalink)  
Old 08-27-2008, 12:36 PM
billchase2's Avatar
My iPhone is a Part of Me
 
Join Date: Jul 2007
Device + Firmware: 2.0.1 8GB iPhone
Operating System: OS X 10.5.1
Location: Bowling Green, OH
Posts: 768
Thanks: 26
Thanked 23 Times in 22 Posts
Send a message via AIM to billchase2

wow, that doesn't seem good.

oh well, doesn't affect me. i don't use any of that security stuff. i just keep my iphone in my pocket at all times and don't leave it laying around for someone to steal.....
__________________
17" PowerBook l 1.67GHz l 2GB DDR2 l 120GB 5400RPM l OS X 10.5.1
Logitech V270 l 160GB/500GB Maxtor Externals l Pwned 2.0.1 8GB iPhone
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #8 (permalink)  
Old 08-27-2008, 12:41 PM
Green Apple
 
Join Date: Apr 2008
Operating System: Windows XP
Posts: 79
Thanks: 3
Thanked 5 Times in 5 Posts

Wow, things like this delay me from firmware 2.0 add in reception rpoblems, lack of jailbroken apps, and a sluggish OS, I wonder how long it will be before I'm desperate to switch.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
The Following User Says Thank You to thestrangestick For This Useful Post:
solarstar101 (08-27-2008)
  #9 (permalink)  
Old 08-27-2008, 12:44 PM
What's Jailbreak?
 
Join Date: Jul 2008
Device + Firmware: iphone 3g 2.0.1 - xpwn
Operating System: xp sp2
Posts: 8
Thanks: 2
Thanked 1 Time in 1 Post

Uff - I sent you to the BossPrefs on double click - hm I don't like it!
Changed it to Home - that's way better!
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
The Following User Says Thank You to iThinkpad For This Useful Post:
solarstar101 (08-27-2008)
  #10 (permalink)  
Old 08-27-2008, 12:45 PM
iPhone? More like MyPhone
 
Join Date: Jun 2008
Posts: 128
Thanks: 2
Thanked 3 Times in 3 Posts

Just enable home button to be double clicked to go to home and maybe it brings you back to slide to unlock screen. iuno .. this I think we could fix as third party applications can enable theirselves to work when double clicking on the home button.

somebody could try and create a pointless application that would respring&lock their iphones when somebody double clicks on it.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
The Following User Says Thank You to mrtonyyx For This Useful Post:
solarstar101 (08-27-2008)
  #11 (permalink)  
Old 08-27-2008, 12:47 PM
oo3 oo3 is offline
Green Apple
 
Join Date: May 2008
Device + Firmware: White iPhone 3G 01.45.00
Operating System: Mac OSX Leopard & Vista 64-bit
Location: Beaverton, OR
Posts: 94
Thanks: 17
Thanked 12 Times in 10 Posts

This is a big issue...

In the other thread, some people were suggesting to have Boss Prefs become your double tap home, but I found a work around if you choose Boss Prefs.

If you do the security hack, then double tap to pull up Boss Prefs, you can simply go to More, then Dock Icons. From there just add any icon to your Boss Prefs dock and select Done. Now press your Home button and it will reload your springboard. The thing is that once it's done loading, it will take you straight to your home screen, BYPASSING the emergency call. This will give you access to ALL of your apps, which seems worse than the original security hack.

Your best bet to avoid this is to set your double tap as your iPod like what nycdiplomat said.
__________________
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #12 (permalink)  
Old 08-27-2008, 12:49 PM
iPhone? More like MyPhone
 
Join Date: Sep 2007
Device + Firmware: iPhone 3G 16gb + 2.0.2 Jailbroken
Operating System: OSX Leopard 10.5.4
Posts: 163
Thanks: 2
Thanked 23 Times in 17 Posts

Great, now we get to pwn our phones all over again!
__________________
___________________________________________

Press the "Thanks" button if I helped you...or you are the guy in the red shirt
Click the image to open in full size.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
The Following User Says Thank You to mtwiford For This Useful Post:
solarstar101 (08-27-2008)
  #13 (permalink)  
Old 08-27-2008, 12:50 PM
iPhone? More like MyPhone
 
Join Date: Jul 2008
Posts: 108
Thanks: 2
Thanked 5 Times in 5 Posts

It hurts me to say but the iPhone itself is a huge security flaw. Security and email encryption isn't a strong point for the iPhone.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #14 (permalink)  
Old 08-27-2008, 12:56 PM
What's Jailbreak?
 
Join Date: Jul 2008
Device + Firmware: pwn'd iPhone 2.0
Operating System: Windows Vista Home Premium
Posts: 4
Thanks: 1
Thanked 0 Times in 0 Posts

am i the only one that likes this? i don't have to enter my code to call my home phone or my job. LOVE IT!
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
  #15 (permalink)  
Old 08-27-2008, 01:16 PM
A.T A.T is offline
Green Apple
 
Join Date: Apr 2008
Device + Firmware: iPhone 2.0.2 QuickPwned
Operating System: XP and Vista
Location: Manchester, England
Posts: 85
Thanks: 4
Thanked 17 Times in 16 Posts

The person or people who found this out should have kept it to themselves and told Apple.

Now everyone knows it
__________________
The person with the most thanks gets ...... If there's a prize at the end please thank me if I helped you.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks Reply With Quote
The Following User Says Thank You to A.T For This Useful Post:
solarstar101 (08-27-2008)
Reply

  iPhone Forums at ModMyiFone.com - iPhone | iPod Touch, news, apps, themes. > ModMyiFone > News

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump

ModMyMoto.com - ModMyGPhone.com - ModMyiFone.com - Dedicated Server Hosting by SingleHop - iPhone Wallpapers - iPhone forums | iPod touch forums, news, themes, apps, games, unlock, jailbreak community - ModMyiFone.com RSS Feeds - Contact Us - Link to us - Archive - Privacy Statement - - Top
Copyright © 2007-08 by ModMy, LLC. All rights reserved. You may not copy anything on this site unless you link to the original.
All times are GMT -6. The time now is 11:14 PM. Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
ModMyiFone.com is an independent publication and has not been authorized, sponsored, or otherwise approved by Apple, Inc or Cisco Systems, Inc. The information contained on this site is for educational purposes only.
Forum skin by poetic_folly