(Not so) Smart Cover

By

Apps exposed.

New technologies are taking the workplace by storm, and none more so than Apple’s iPad, which is particularly popular with managers and executives.

(Not so) Smart Cover

As a result, an increasing amount of sensitive data is being carried around, and while the iPad’s security features help to keep your data secure, a recent bug discovered in iOS 5 allows anyone to bypass your passcode to lock and unlock the device.

Interestingly, the vulnerability itself comes in an unexpected form: the functionality required for Apple’s Smart Covers.

It’s worth noting that this is a limited bypass, and by that I mean that the attacker will only gain access to the last app that was open (or the home screen if that’s where you were). They won’t be able to switch apps, and if on the home screen, they’ll be able to see all your apps but won’t be able to start them.

If, like me, you spend a lot of time reading and sending emails, then chances are the mail application was the last one open when your iPad was locked. This would allow an attacker to read your emails, send emails from you, and view your contacts!

If you have a Smart Cover, you can try it for yourself. Wait until your iPad is locked and make
sure it prompts you for your passcode. Hold the power button to bring up the ‘power off’ slider.

When it appears, close the Smart Cover, then re-open it and touch ‘cancel’. If you’ve done everything right, it should drop you into your home screen or the last app you had open.

Apple has released a security update for this in iOS 5.0.1. You can also protect yourself by disabling Smart Covers in your iPad settings
(Settings ›› General ›› iPad Cover lock/unlock ›› Off). 

Don’t forget to patch!

Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:

Most Read Articles

India's alarm over Chinese spying rocks CCTV makers

India's alarm over Chinese spying rocks CCTV makers

Hackers abuse modified Salesforce app to steal data, extort companies

Hackers abuse modified Salesforce app to steal data, extort companies

Cyber companies hope to untangle weird hacker codenames

Cyber companies hope to untangle weird hacker codenames

Woolworths' CSO is Optus-bound

Woolworths' CSO is Optus-bound

Log In

  |  Forgot your password?