Security Alert: iCracked

Oct 29, 2010   //   by Kevin's Security Scrapbook   //   Blog, News & Updates  //  1 Comment
A security flaw in the iPhone allows strangers to bypass the handset’s lock screen with a few button presses.

…the quick method to circumvent an iPhone’s passcode-protected lock screen:
• tap the “Emergency Call” button,
• then enter three pound signs,
• hit the green Call button
• and immediately press the Lock button.
That simple procedure gives a snoop full access to the Phone app on the iPhone, which contains the address book, voicemail and call history. (more)

Apple:

“We’re aware of this issue and we will deliver a fix to customers as part of the iOS 4.2 software update in November.” 

“Why is this important?”
Not having password protection on a smart phone leaves you open to information theft, jail-breaking and injection of spyware.

“Why does this trick exist?”
• It is a software loophole.
• It is a programmer’s shortcut they forgot to patch.
• It is a programmer’s Easter egg.
• It is a law enforcement backdoor never meant to become public knowledge.
Interesting question. You decide.

FutureWatch: The ability to create passwords longer than four measly digits… which is only a pool of only 10,000 passwords. ~Kevin

1 Comment

  • Let’s hope that Apple fixes this problem sooner than later. I can’t believe they are so exposed to spy software and the theft of information???

Leave a comment

 

Contact Information

Jayde Consulting's team are experienced practitioners of technical surveillance countermeasures (TSCM) bug sweeps and counter-espionage consulting. We work within Australia and regularly internationally. We also maintain close associates in Europe and the USA.

Please telephone us on our Sydney number for a confidential discussion:

(02) 8006-0635

Posts By Month

Keep it Confidential

Julian Claxton and his team are the preeminent providers of TSCM services within Australia and the preferred choice for a significant number of global corporations. Discretion is assured.

Don't risk your most sensitive corporate information to fly-by-nighters or inexperienced operators.