Version: 2008

Comments on: Security hole opens up password-protected iPhones

Users report serious security flaw in iPhone 2.0.2 that exposes mail, texts, voice messages, and browser to strangers despite the device being password-protected.

Add a Comment (Log in or register) (15 Comments)
  • prev
  • 1
  • next
by ralfthedog August 27, 2008 3:28 PM PDT
This is a big flaw. It should be easy to fix.

Honestly, it does not matter what phone or PDA you use, don't put anything on it that you don't want others to find out. Short of hard encryption, nothing will protect you from a Dremel and a flash reader.
Reply to this comment
by Perry_Clease August 27, 2008 3:40 PM PDT
See this story: http://www.ipodobserver.com/story/37028
Reply to this comment
by corporatejet August 27, 2008 4:37 PM PDT
Big deal. Someone can call your favorites list. Simple way around is to set the option to either bring up the Home screen or the iPod player.

My iPhone is set to launch iPod player when double click is pressed. If I loose my phone the worst someone can do is listen to my poor taste in music.
Reply to this comment
by NewsReader_ August 27, 2008 4:49 PM PDT
This is a big deal for corporate users who use ActiveSync to get email to their phones.

Shame on you Apple!
Reply to this comment
by corporatejet August 27, 2008 6:42 PM PDT
If it's such an issue then your company should be using BlackBerry. I've been using the iPhone since day 1 and would not recommend it for a corporate device. Great for web browsing if that's all your users do with their phone.

As 'intuitive' as the interface is, a button push, a slide gesture, enter a pin code, click contacts, wait for contact list to appear (software bug still not fixed), scroll through list to locate contact, select contact, select phone number to dial.... seems a long process to make a phone call. The main purpose of a "phone".
by professionaladventurer August 27, 2008 5:54 PM PDT
We are talking about a phone right? My high security solution? I don't lose my phone or let it get stolen. I keep track of my expensive hand held hardware (don't leave it on the milk deck at Starbucks). I use my phone all the time and it is not really reasonable to put it in password mode. I am also not a geek or 15 year old girl, but rather look like how nature says "don't touch" so muggers generally give me a pass if they see me on the subway at 2 am.
Reply to this comment
by whiterabbit--2008 August 27, 2008 8:24 PM PDT
That key lock should not be considered serious protection in the first place. I've never used mine because it's not only an inconvenience to others, but to myself as well. Also, I do not send private information like SSNs and credit card numbers by email, that's stupid; if you do then you deserve to have your identity stolen.

I actually did lose my iPhone once; my email was the least of my concerns upon realization. In fact I'm glad that I wasn't using the key lock, some kind soul picked it up and dialed one of my favorites (one which I'd entered as a relationship with just this case in mind) and it was then returned to me.
Reply to this comment
by gggg sssss August 27, 2008 8:53 PM PDT
Crapple has a security flaw? I was told that was impossible. Oh well, back to issuing Windows Mobile devices to the sales guys. But the iPhones look SO cool.
Reply to this comment
by Perry_Clease August 28, 2008 4:24 AM PDT
"Oh well, back to issuing Windows Mobile devices to the sales guys."

Good idea! Dump the junk devices on the yacktards so you can give the iPhones to the real workers.
Reply to this comment
by joetesta70 August 28, 2008 6:17 AM PDT
Funny my Blackberry seems secure. Typical Crapple.
Reply to this comment
by Kreuzer33 August 28, 2008 8:41 AM PDT
Another iPhone issue. Guess it's still not time to buy an iPhone.

http://kreuzer33.wordpress.com/2008/08/28/iphone-security-issue-exposes-consumer-data/
Reply to this comment
by Vegaman_Dan August 28, 2008 9:28 AM PDT
This appears to be an oversite on Apple's part. There is only so much testing you can do in labs. The ultimate test is to give it to uninfomred customers who will quite likely come up with key combos and situations that you simply cannot test for.


How quickly this is addressed will be the next question.


This is a serious security issue for any corporate email use, which already has issues with the unit in general, so this may cause more problems for it to be adopted seriously as a business class device.


Give it time. It's still in the testing phase at this point. It will only get better over the years.

Reply to this comment
by Seaspray0 August 28, 2008 10:05 AM PDT
I have always said no operating system is secure, and that includes phone OS's. Perhaps you macfans are willing to listen now?
Reply to this comment
by tech_crazy August 28, 2008 1:36 PM PDT
You don't go about not testing it enough and then positioning it against entrenched competitors like RIM. There is a reason why companies do thorough testing - alpha, beta, etc and evals/quals.
Reply to this comment
by t26l October 7, 2008 9:51 PM PDT
nearly all tech is gonna have <i> some</i> sorta security hole...what are patches for? :D
Reply to this comment
(15 Comments)
  • prev
  • 1
  • next
advertisement

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement