(Not so) Smart Cover

Powered by SC Magazine
 

Apps exposed.

New technologies are taking the workplace by storm, and none more so than Apple’s iPad, which is particularly popular with managers and executives.

As a result, an increasing amount of sensitive data is being carried around, and while the iPad’s security features help to keep your data secure, a recent bug discovered in iOS 5 allows anyone to bypass your passcode to lock and unlock the device.

Interestingly, the vulnerability itself comes in an unexpected form: the functionality required for Apple’s Smart Covers.

It’s worth noting that this is a limited bypass, and by that I mean that the attacker will only gain access to the last app that was open (or the home screen if that’s where you were). They won’t be able to switch apps, and if on the home screen, they’ll be able to see all your apps but won’t be able to start them.

If, like me, you spend a lot of time reading and sending emails, then chances are the mail application was the last one open when your iPad was locked. This would allow an attacker to read your emails, send emails from you, and view your contacts!

If you have a Smart Cover, you can try it for yourself. Wait until your iPad is locked and make
sure it prompts you for your passcode. Hold the power button to bring up the ‘power off’ slider.

When it appears, close the Smart Cover, then re-open it and touch ‘cancel’. If you’ve done everything right, it should drop you into your home screen or the last app you had open.

Apple has released a security update for this in iOS 5.0.1. You can also protect yourself by disabling Smart Covers in your iPad settings
(Settings ›› General ›› iPad Cover lock/unlock ›› Off). 

Don’t forget to patch!

Copyright © SC Magazine, Australia


(Not so) Smart Cover
Tags
 
 
 
Top Stories
Earning the right to innovate
Breaking down the barriers to innovation is a long, but rewarding process, says Bank of Queensland Group CIO, Julie Bale.
 
A call for timely reporting
[Blog post] Businesses need incentives to keep customer data secure.
 
Doubts cast on Queensland's ICT Dashboard
Opposition, former Govt CIO say it can't be trusted.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
What is delaying adoption of public cloud in your organisation?







   |   View results
Lock-in concerns
  26%
 
Application integration concerns
  3%
 
Security and compliance concerns
  29%
 
Unreliable network infrastructure
  9%
 
Data sovereignty concerns
  23%
 
Lack of stakeholder support
  3%
 
Protecting on-premise IT jobs
  5%
 
Difficulty transitioning CapEx budget into OpEx
  3%
TOTAL VOTES: 829

Vote