Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Apple promises to fix iOS 7 lock screen hack (huge security hole in apple ios7).
CNET ^ | 19 Sep 2013 | Seth Rosenblatt

Posted on 09/20/2013 8:23:44 AM PDT by for-q-clinton

The passcode lock screen on iOS 7 suffers from a bug that allows anyone with direct access to the iPhone or iPad to bypass the lock screen and open apps.

The bug, discovered by 36-year-old soldier Jose Rodriguez, who lives on the Canary Islands off the coast of Spain, is remarkably simple to exploit, reports Forbes. Swipe up from the lock screen to access the new Control Center, then open the alarm clock app.

Hold the phone's sleep button, but instead of swiping to power down the phone, tap cancel and double-tap the home button to access the multitasking screen. From there, you can jump to the camera and share stored photos, which gives you access to the user's communication accounts such as e-mail, Flickr, Facebook, Twitter, and others.

The exploit has been tested successfully on iOS 7 when running on the iPhone 4S, 5, 5C, and 5S, and the most recent iPad model.

Apple did not immediately respond to CNET's request for comment. However, an Apple spokesperson told Forbes and others that the company "takes security very seriously" and that it's "aware of this issue. We'll deliver a fix in a future software update."


TOPICS: Crime/Corruption; News/Current Events; Technical
KEYWORDS: apple; buggy; ios; pos
Navigation: use the links below to view more comments.
first previous 1-2021-26 last
To: Swordmaker

“...As I said, it’s bogus.”
******************************************************
Yes, it is indeed a bogus “security flaw”. But at least it gives another opportunity for Apple haters, like moths drawn to the light, to come and take shots at Apple products.


21 posted on 09/21/2013 3:54:31 PM PDT by House Atreides ( D)
[ Post Reply | Private Reply | To 16 | View Replies]

To: Swordmaker

This exploit revolves around the access to Control Center from the lockscreen. My brand new iPhone 5S came out of the box with the toggle set to allow control center in lock screen. While it is handy to have access there, it should come default set to NOT allow control center in lockscreen. Problem solved.

Oh- ans last night I was notified of an update for my iPhone 5S (iOS 7.0.1). It is primarily for a bug some experienced with using fingerprint scanning to authenticate app store and itunes purchases.


22 posted on 09/21/2013 5:05:08 PM PDT by TheBattman (Isn't the lesser evil... still evil?)
[ Post Reply | Private Reply | To 16 | View Replies]

To: Swordmaker

http://arstechnica.com/apple/2013/09/new-ios-7-bug-lets-you-make-non-emergency-calls-from-the-lock-screen/

This second bug doesn’t require any user to downgrade security first. It’s on video at the link.

Why is it so hard for you to admit that Apple (like every other software company anywhere) ships with bugs? It’s not like anyone here has accused Apple of being bad (or even worse that its competitors) when it comes to bugs? The only statement anyone made on this thread (that I saw) is that other companies would have faced (unwarranted) media attention for these bugs. You seem very defensive about a very normal occurrence in the tech industry...


23 posted on 09/22/2013 6:19:16 AM PDT by Charles H. (The_r0nin) (Hwaet! Lar bith maest hord, sothlice!)
[ Post Reply | Private Reply | To 16 | View Replies]

To: Swordmaker
In other words, it REALLY isn't secure to begin with if you allow bypassing screen locking!. That's exactly what this is describing: unlocked, bypassed screens! What do they expect if they TURN OFF SOME OF THE SECURITY???? Default is screen locking on.

That's not quite correct - the default is to require a screen lock passcode, yes. And obviously, if you choose not to use a passcode, then why would you complain about lock screen security?

However, the default setting for Control Center is "Access on Lock Screen" to be enabled. (Notification Center similarly defaults to being available from the lock screen.) In that respect, the default behavior is to use a passcode for the lock screen, but to bypass it for some functions. An exploit that allows access to the full phone or even partial data that uses that would indeed be a security bug that needs addressed.

That said, the more secure option in the first place is to disable Notification Center and Control Center from the lock screen in Settings.

24 posted on 09/23/2013 6:15:44 AM PDT by kevkrom (It's not "immigration reform", it's an "amnesty bill". Take back the language!)
[ Post Reply | Private Reply | To 16 | View Replies]

To: dfwgator

Always wait for the second service pack, regardless of the OS.

Don’t use this one, (snicker) http://www.telegraph.co.uk/technology/apple/10330414/iOS-7-users-destroy-iPhones-after-fake-waterproof-advert.html


25 posted on 09/27/2013 6:34:55 AM PDT by READINABLUESTATE ("If guns cause crime, there must be something wrong with mine." -Ted Nugent)
[ Post Reply | Private Reply | To 2 | View Replies]

To: papertyger

Barney Frank is on the user interface?? Eeew!


26 posted on 09/27/2013 6:40:04 AM PDT by COBOL2Java (I'm a Christian, pro-life, pro-gun, Reaganite. The GOP hates me. Why should I vote for them?)
[ Post Reply | Private Reply | To 7 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-26 last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson