Apple Won't Fix iPhone Passcode Hole Until September
August 30 12:05:01 PM, Yahoo News
NewsFactor - The latest iPhone embarrassment is a security hole that makes it simple to access stored data on supposedly locked iPhones. Apple said Thursday that a software patch to solve the problem is in the works.
An unauthorized user can exploit the security hole simply by double-pressing the button to make an emergency call. That behavior brings up the owner's preferred contacts and clicking on a number provides full access to the phone's features. Clicking on an e-mail provides access to all e-mail. And clicking on a contact name provides full access to all contacts data.
Apple spokesperson Jennifer Bowcock said, "The minor iPhone security issue which surfaced this week is fixed in a software update which will be released in September."
There is a simple workaround, Bowcock said: iPhone owners can simply change the settings so double-clicking the emergency button returns a user to the home screen, which will present a password login field if password protection is turned on.
'Design Deficiency'
While an attacker must be in physical possession of the iPhone to exploit the security bug, it "highlights a fundamental design deficiency with the iPhone," said Andrew Storms, director of security operations with nCircle Network Security.
"Despite Steve Jobs from day one saying the iPhone was secure, functionality and aesthetics of the device seem to always win out over security," Storms said. A case in point, Storms said, "Apple quickly released updates to fix 3G connectivity issues this year, but consistently takes many months to release security updates."
This particular security hole -- a simple bypass of access restrictions -- was created by Apple's preference for functionality over security, he added. "Even when a user chooses to physically secure the device with a four-digit passcode, Apple has chosen to still permit the user to use some functionality," Storms said. "By selecting to perform an emergency call, the user can then gain access to other options, which eventually leads them to near-full access on the phone --never having had to enter that passcode."
Open Door for Espionage
While this security hole will not allow remote hacking into the device, executives carrying iPhones with sensitive information in e-mail or the contacts list could easily find their information compromised. In May, U.S. Commerce Department officials left a laptop unattended during a visit to China and discovered that their hosts had copied the contents of the hard drive and used the information to attempt to hack into U.S. government systems.
In April, a Mexican press official was arrested after nabbing several BlackBerries left outside a hotel meeting room by White House staffers.
Stories like that underscore the security dangers of a device that makes false security promises. "Enterprises need to maintain their vigilance with Apple," Storms said. "This is an exceptionable security flaw that is not an acceptable risk for many enterprises and consumers alike."
"Until Apple begins to publicly address these fundamental design, development and process issues, enterprises will remain skeptical of the iPhone being an acceptable mobile device," Storms said.
Related articles
- Google to shut down virtual world website
Reuters - Google Inc said it would shut down its three-dimensional virtual experience website by year end to focus more on its core search, advertisements and applications business. - Report: Obama's cell records improperly accessed
CNET - President-elect Barack Obama's cell phone billing records were improperly accessed by employees of Verizon Wireless, CNN reported late on Thursday. - Google empowers users to edit search results
AP - If Google delivers useless search results, just erase them and you won't see them again. - Verizon staff did not listen to Obama voicemails
Reuters - The contents of U.S. President-elect Barack Obama's voicemail messages and emails were not breached by the Verizon employees who gained unauthorized access to his cell phone account, an Obama… - Verizon staff had unauthorized access to Obama's cell
Reuters - Verizon Wireless said Thursday some employees had gained unauthorized access and viewed a personal cell phone account held by President-elect Barack Obama that is now inactive. - Fewer Than 1% Arrested From TSA's "Behavior Detection"
An anonymous reader writes "Fewer than 1% of airline passengers singled out at airports using the much vaunted 'suspicious behavior detection' techniques are arrested, Transportation Security Administration… - Google's virtual world Lively to die next month
AP - Lively, a virtual reality service from Google Inc., is dying. - Google picks Austria village for new European server farm
AFP - Google has bought a 75 hectare (185 acre) property in the north of Austria to erect a new European server farm within two years, the US Internet search engine giant said Thursday. - Certification credited with boosting online confidence
CNET - Extended certificate validation for Web sites has boosted online confidence in 2008, according to a statement released Thursday by the Authentication and Online Trust Alliance (AOTA). - Emerging markets to drive mobile growth: British watchdog
AFP - The top emerging economies of Brazil, Russia, India and China will drive mobile services growth in the coming years, a new report by Britain's telecoms regulator Ofcom said Thursday. - Sun receives complaint about Java vetting process
InfoWorld - Sun Microsystems has heard from a company concerned about the vetting process of Java and open source, a Sun official said on Wednesday. - A future without programming
InfoWorld - A few years ago, self-proclaimed nondeveloper Kevin Smith worked for a software company that tried to build a project tracking tool using Microsoft .Net. Some 15 developers spent a year with… - Virgin Media sees mobile broadband as complementary
Reuters - British cable operator Virgin Media said it did not believe mobile broadband had mass appeal in the short term, but it entered the market to offer the service in its high-end mobile, broadband… - Towards a World Wide Grid?
Roland Piquepaille writes "In recent months, the concept of 'cloud computing' was all the buzz. European researchers think about another name, the World Wide Grid, which could run on top of the Internet.… - When Agile Projects Go Bad
blackbearnh writes "CIO Magazine has an article up looking at some of the ways that Agile projects can fail, or Agile can be misapplied in organizations. Some of the issues raised may not be new, but folks… - Guns N' Roses album to debut on MySpace
CNET - Updated at 8:55 p.m. PST to reflect that NPR Music had the streaming debut of Paul McCartney's album. - U.S. woman posed as teen online, teased girl: attorney
Reuters - A Missouri woman established a fake identity online to torment a vulnerable teenage girl who later committed suicide, federal prosecutors said on Wednesday in a trial that is being closely watched… - Review: New BlackBerrys cool but can't beat iPhone
AP - With the recent releases of three new BlackBerrys across three different wireless providers, Research In Motion Ltd. has fired back at Apple Inc. in the Great Smart Phone Skirmish of 2008. - Physicist Admits Sending Space-Related Military Secrets To China
piemcfly writes "Chinese-born physicist Shu Quan-Sheng Monday pleaded guilty before a US court to violating the Arms Export Control Act by illegally exporting American military space know-how to China.… - Review: New BlackBerrys cool but can't beat iPhone
AP - With the recent releases of three new BlackBerrys across three different wireless providers, Research In Motion Ltd. has fired back at Apple Inc. in the Great Smart Phone Skirmish of 2008. - Microsoft lets Zune music subscribers keep tunes
AP - Microsoft Corp. is giving an early holiday gift to people who pay for all-you-can-listen access to the Zune digital music store: 10 songs to keep each month, included in the $14.99 monthly subscription… - Interviewing Experienced IT People?
thricenightly writes "After more than 20 years in IT I've learned that the most valuable people in a team are frequently the old timers. Young pups straight out of college might (think they) know all the… - New Xbox Experience Launched To Battle Sony's Offering
NewsFactor - Microsoft launched its New Xbox Experience on Wednesday, expanding the existing service to compete with Sony in turning the video-game console into an entertainment hub. - China's Baidu.com fights to rescue reputation
AP - Baidu.com has been the star of China's Internet world. But now the search engine dubbed "China's Google" is scrambling to rescue its reputation after state TV accused it of letting unlicensed suppliers…