Google Search

Showing posts with label passcode. Show all posts
Showing posts with label passcode. Show all posts

Friday, June 7, 2013

iOS 6.1.3 security flaw allows passcode lock bypass... again [VIDEO]

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Passcode bypassiOS 6.1.3 has only just been released by Apple, and already a security hole has been followed - allowing anyone to bypass the passcode lock on iPhones, and access private data on the device.

Embarrassingly for the Cupertino company, one of the main reasons for installing iOS 6.1.3 was that it promised to fix other security flaws that allowed the lock screen to be bypassed.

The flaw was found by "videosdebarraquito", who seems to be making a hobby of embarrassing Apple by uncovering lock bypass flaws. In a video he demonstrates that it's not particularly complicated to avoid the iOS 6.1.3 passcode lock if you have physical access to the device and a widget for removing the SIM card.

Here is videosdebarraquito's video, where he demonstrates how the passcode can be bypassed:

It appears that circumventing the passcode lock can allow an unauthorised party access to the device's photo gallery and use the phone.

The good news is that this security flaw can be easily prevented. The passcode bypass relies upon use of the "Voice Dial" feature of iPhones, which is disabled on devices using Apple's Siri voice recognition feature.

If you *aren't* using Siri, then the recommendation is to disable "Voice Dial". If you do that, your device shouldn't be prone to this passcode bypass.

Disable the Voice Dial option

You can disable "Voice Dial" on your iPhone by going to Settings / General / Passcode Lock. (Note that if you have Siri enabled you won't see an option for "Voice Dial" there, as it has been automatically disabled).

Easy as it is to avoid this flaw putting your iDevice at risk, it's still embarrassing for Apple as it comes so soon after other passcode lock bypasses were publicised.

Let's hope that Apple fixes this flaw soon, and shuts a permanent door on passcode lock bypasses.

Follow @gcluley

View the original article here

Sunday, April 14, 2013

Unlock an iPhone without the passcode - harmless trick or computer crime?

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

A YouTube video showing you how to unlock an iPhone 5 without the passcode has racked up nearly 300,000 hits over the past two weeks.

There are some caveats, though:

You need physical access to the device.You need manual dexterity or a fair bit of practice.You only get access to some of the data.You have to make a phoney emergency call as part of the process.

I'm not going to repeat the instructions here.

I'll just say that they're reasonably arcane: you almost turn the phone off twice during the process, as well as actually placing an emergency call but cutting it off before it goes through.

For the last reason alone, I invite you never to pull this trick, even on your own phone "to see if it works".

Deliberately dialling the emergency services when you don't need to, or, indeed, when you know your intention is not to complete the call at all, is a pretty poor show.

I'm not sure what the regulations are in your country, but there's every possibility you could get in trouble with the authorities for that part of the trick alone.

In fact, it's not really a trick. It's a crime, even without the bogus emergency call.

Not, perhaps, a terribly serious crime. But mucking around with other people's computers is behaviour we ought to stamp out of our lives.

Interestingly, the last time we wrote about this sort thing was when an MP in the New South Wales parliament live-tweeted joke comments from a colleague's iPad while the latter was giving a speech.

I suggested a zero-tolerance policy, especially from members of a legislative assembly, who ought to be setting standards, not flouting them, but not everyone was so sure.

Commenters Josh and foo suggested otherwise:

? For the record, I would vigorously oppose any attempt to regulate whoopee cushions. Like Dr Sheldon Cooper of the Big Bang Theory, "I still maintain the whoopee cushion has comic validity."

The good news is that this unlock crime trick doesn't give full access to the phone, but apparently only to your contact list, voicemails and photos.

That's still a lot of important stuff, though.

Macworld reports that Apple told the magazine that it was "aware of this issue, and will deliver a fix in a future software update."

That beats Apple's usual tight-lipped (and still apparently official) policy.

For the protection of our customers, Apple does not disclose, discuss or confirm security issues
until a full investigation has occurred and any necessary patches or releases are available.

So, watch out for the update, watch out for your phone, and don't let this bug make you complacent about phone lock codes overall.

It's still worth having a decent password on your iPhone, to protect all the data this bug doesn't give a miscreant access to.

To help you choose wisely, here are the Top Ten iPhone passcodes not to use:

5683, by the way, spells out L-O-V-E.

In conclusion, let the arcane nature of this trick remind you that hackers, in both the good and bad sense of the word, aren't deterred by secrecy, obscurity or complexity.

Indeed, this trick is surely making you wonder, "How did they think of that?"

Bear that in mind if you are ever called upon to design, implement or enforce security software, policies or procedures.

Follow @duckblog

Image of mobile phone courtesy of Shutterstock.


View the original article here