iOS 7 Lock Screen Vulnerability Discovered
techcrunch.com
techcrunch.com
I love that. It's not a 'security researcher', it's just some guy messing around with his phone.
Reminded me of this Win95 login bypass: http://i.imgur.com/rG0p0b2.gif
And that's exactly how a vulnerability seeker should behave - messing around!
http://www.forbes.com/sites/andygreenberg/2013/09/19/ios-7-b...
No one seemed to think this was a big deal, but there was certainly potential for abuse. Security of incoming texts is more important, but being able to send a fraudulent iMessage is definitely a problem for kids who like messing with each other's emotions...
"Firefox For Android Can Be Tricked Into Automatically Downloading And Executing Malicious Code"
http://www.androidpolice.com/2013/09/11/security-firefox-for...
"U.S. Government Issues Warning About Security on Android Phones"
http://bits.blogs.nytimes.com/2013/08/28/u-s-government-issu...
Biometric identifiers up next in 3...2...
Between that, and having maps auto-unlock if you're in nav-mode -- that'd solve about every dangerous car-phone situation I run into.
Also, using Navigation instead of Maps keeps the screen unlocked, which may be more handy depending on what you are doing.
Not sure whether or not it prevents screen locking.
> Also, using Navigation instead of Maps
then post on victim facebook for great fun
Regardless, I'm sure this'll be fixed shortly and glad this guy found the vulnerability so soon!
Not that it matters to the resolution of the vulnerability - I'm sure Apple will be in a position to repro and fix it - but I wish for the sake of my own curiousity that these things are described in more detail.
As a side note, one can use this bug to access contacts list and send email on behalf of the owner (via share menu in photo stream).
Edit:
Just found out that I can tweet, post to facebook and send email just by using Siri (if that setting is enabled). Although, this might be the correct behavior.
This is the same with your computer. What's your point? Do you have no private information?
(Don't say "everything's encrypted": it's the same with passworded iPhones, and again: same issue with your PC. There are numerous simple hardware compromises like keyloggers, or removing and chilling RAM to get keys unencrypted from memory, etc)
Note that this is distinct from the login password to something remote.
Seriously though, Control Center is probably a good stop-gap, though the bigger question is probably how quickly Apple will try to patch this.