ClioSport.net

Register a free account today to become a member!
Once signed in, you'll be able to participate on this site by adding your own topics and posts, as well as connect with other members through your own private inbox!

  • When you purchase through links on our site, we may earn an affiliate commission. Read more here.

Bug found in iOS 4.1, access contacts on a pass coded device



Tom

ClioSport Club Member
  EV (s)
No idea why people use passcodes anyway, if you dont want someone on your phone dont leave it unattended.

(Fixed in 4.2 beta3, just checked)
 

sn00p

ClioSport Club Member
  A blue one.
No idea why people use passcodes anyway, if you dont want someone on your phone dont leave it unattended.

(Fixed in 4.2 beta3, just checked)

Because if it gets lost/misplaced/stolen you can potentially mitigate the potential for losing personal/confidential information, especially with email in corporate environments.
 

AK

  M240i
No idea why people use passcodes anyway, if you dont want someone on your phone dont leave it unattended.

(Fixed in 4.2 beta3, just checked)

There's been a few comments that it still happens in the beta, just more intermittent that every time.
 

Tom

ClioSport Club Member
  EV (s)
Because if it gets lost/misplaced/stolen you can potentially mitigate the potential for losing personal/confidential information, especially with email in corporate environments.

You'd remote wipe via exchange in a business envio?
 

The Boosh!

ClioSport Admin
  Elise, Duster
can someone copy and paste the text from the website as the link won't open on works machine
 

sn00p

ClioSport Club Member
  A blue one.
You'd remote wipe via exchange in a business envio?

Sure...but in the time it's taken you to realise the phone has gone somebody could have already taken advantage if the phone was not pass-coded (and set to pass-code every time rather than after x minutes).
 
can someone copy and paste the text from the website as the link won't open on works machine

Luke;

A pretty major security hole has been found in iOS 4 for iPhone. This flaw lets you access the contacts of a password protected iPhone. No hack or technical skills needed.
On a password protected iPhone, tap the “Emergency Call” button then enter ###. Tap the Call button and immediately hit the Lock button. It will open your iPhone Contacts app from which you’ll be able to browse, edit, email, any contact.
Watch this Brazilian dude demonstrating the security flaw in action…
 

The Boosh!

ClioSport Admin
  Elise, Duster
LOL! Did it on about the 10th Time but didn't work straight away.

Not that bad anyway so I don't know how it's a major security flaw
 
  Bus w**ker
From a data security perspective it is major as it gives access to all contact details, voicemail blah blah blah.

But every other function of the phone is still, as far as I'm aware, secure. It's not really the end of the world, but it's something that shouldn't have been allowed to slip through security validation.

Tom how do you get beta/developer info?
 
  SLK 350
No idea why people use passcodes anyway, if you dont want someone on your phone dont leave it unattended.

(Fixed in 4.2 beta3, just checked)

Dumbest comment of the week goes to you Tom.

Settings>Airplane Mode, there goes your chances of remote wipe. From there, you're free to do as you please. Having a device password is essential with smartphones today, there's a whole world of information contained on them.
 

dk

  911 GTS Cab
I was told 4.2 is imminent while at apple hq the other day, for both iPhone and iPad.

Can't wait for the iPad update.
 

Tom

ClioSport Club Member
  EV (s)
Dumbest comment of the week goes to you Tom.

Settings>Airplane Mode, there goes your chances of remote wipe. From there, you're free to do as you please. Having a device password is essential with smartphones today, there's a whole world of information contained on them.

Yeah, my bad. What i said was so dumb.
 


Top