Newsletter:

Skip Navigation LinksHome > News > Security > Users can bypass iPhone security

Users can bypass iPhone security

By Shaun Nichols
28 August 2008 04:01PM
Tags: bypass | iphone | security

iPhone users have uncovered a simple procedure to bypass the handset's passcode protections.

A group of users on Apple news site MacRumors.com first pointed out the hole, which involves just a few taps on the touch screen.

The tactic was later tested and verified by Gizmodo, which posted a video of the process.

The issue occurs when the user hits the "emergency call button" on the iPhone's passcode entry screen. This then brings up a dial pad for placing a call in an emergency situation. Unfortunately, it also enables the use of the iPhone's "home" button as normal.

By default, the home button is set to bring up the user's "favorites" list. It also enables an unauthorized user to access a number of other features on the phone.

From within the favorites list, an unauthorized user could view the contact details of those within the iPhone owner's address book. Furthermore, the user could access the owner's voicemail from the list, and could click on a contact's email address to open up the mail application or Safari browser.

From within the Safari or Mail, the intruder would then have access to all of the user's email messages or stored bookmarks, raising obvious privacy and information disclosure concerns.

According to Gizmodo, a fix for the issue is in the works from Apple. Worried iPhone owners will not, however, need to wait that long to fix the hole.

The site notes that simply opening the iPhone's general settings fixes the problem. Users can simply the destination of the "home" button to either the actual Home screen, which requires the passcode to access, or the iPod function, which does not access the phone features.

Copyright © 2008 vnunet.com

   


Ads by Google


Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 


Tripwire - Click here to win an iTouch





Product Reviews

Star Rating
The AdventNet Manage-Engine Password Manager Pro provides a complete system for password management in one...
Star Rating
The Cyber-Ark Enterprise Password Vault, or EPV, is a high-end password management powerhouse.
Star Rating
The Hitachi ID-Archive sets its focus on password randomisation.
Star Rating
The Lieberman Software Enterprise Random Pass­word Manager is a full-on password manager and randomiser for...
Star Rating
Proginet SecurForce is a little bit of a horse of a different color for this month's Group Test.
Unified Communications Podcast Centre

TopTopics
(5714) -  broadband
(5602) -  telstra
(5559) -  nbn
(4357) -  internet
(4013) -  iinet
(3983) -  copyright
(3983) -  afact
(3678) -  servers
(3678) -  mipi
(3088) -  network
(2891) -  internode
(2260) -  microsoft
(2121) -  linux
(1636) -  data
(1529) -  software