Advertisement
Promo

Security management Toolkit

Security flaw exposes password-protected iPhones

Elinor Mills CNET News

Published: 28 Aug 2008 08:39 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A serious security hole in the latest iPhone software exposes email, text and voice messages to whoever gets their hands on the device, despite it being password-protected.

Clicking emergency call and double-clicking the 'home' button brings up the favourites on iPhone 2.0.2, which opens up the address book, the dial keypad and voicemail, according to a report on Gizmodo, which got the tip on the hole from the MacRumors Forum.

Then, clicking on the blue arrows next to the names gives access to private information in a favourite entry, clicking in a mail address opens up the mail application, clicking on a URL in the contact information opens up Safari, and clicking on 'send a text message[ in a contact gives full access to the text messages.

The report suggests using the 'home' setting so that double-clicking on the home button will take whoever is holding the phone to the unlock screen page.

Engadget reports that a fix for the hole will be included in the next firmware update, but it's not known when that update will come.

Representatives from Apple did not respond to emails seeking comment.

Credit: Security hole opens up password protected iPhones from CNET News

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
6 out of 6 people found this useful


Full Talkback thread

1 comment

  1. That is really bad!! 1000098864

Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Symantec website breached

Security company Symantec has said that one of its websites was successfully breached. Romanian security researcher 'Unu' posted details of the breach in a blog post on Monday. Unu... More

Post a comment

Featured Talkback

In association with Network Liberation Movement
It seems to me this is a burden being placed on the wrong shoulders. There is not an It system in the world that can stop an individual taking information in their heads and spewing out at the nearest undesirable third party.

By: RonaldWilkins

Read full story:
Deloitte: People are still weakest security link


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters