Unreleased iPhone 2.0 May Already Be Hacked
The as-yet unreleased second iteration of iPhone hardware may already be compromised, reports Engadget and News.com. Members of the 'iPhone Dev Team' have (supposedly) made use of the recently released SDK to gin up a Beta 2.0 software hack. "Unlike previous hacks, this one isn't specific to the latest firmware version, it exploits the way that Apple designed the iPhone's main bootloader. According to the iPhone Dev Team, the iPhone verifies whether or not firmware code has been signed with an RSA certificate before allowing it to be written to memory. The team has apparently figured out a way to disable that check and allow unsigned code to be written to memory."
WAS...
I'm sure the iPhone 2 will be held back until this is fixed.
Jobs will pounce on this faster than a Leopard. They should have kept their mouths shut.
...allow unsigned code to be written to memory.This doesn't sound that attractive to me.
The Mothership
It's not the first time something is hacked before it's even released, but it's always funny.
What really makes this one a good example is that for once this lock used some kind of real crypto (RSA), not some security-through-obscurity stuff. And yet, of course, that defeated, by not even letting the check occured.
Because crypto scenario were Bob tries to hide something to bob, after giving Bob the key are just a bit to stupid to work.
Don't take my posts literally; it's just code to control my botnet.
From a user's perspective, I would have rather had them wait until the 2.0 update came out to release this info so that there would be a hackable version 2.0 available. As it is, it's pretty likely that Apple will fix the vulnerability that these folks have discovered before releasing the new firmware.
I like my beverages with warning labels!
They hacked firmware 2.0, which will run on current iPhones, there's no mention of new hardware for this stuff...
Shame on the hackers! How dare they! They are evil people for breaking the security of the almighty Jobs! Oh, and shame on Jobs, we expect your products to be secure. Wait, Apple are imperfect? [Head asplodes].
This thread is probably going to be full of sofware security bashing, deservedly or not. Let's get something constructive out of this... Anyone know of any way to make software security function the way business people dream of? Namely, only approved code running approved processes. I think given access to the hardware any machine can be "hacked" given enough interest and manpower. Even putting security features in the chips themselves, as I've heard they are developing, will just be a relatively minor roadblock.
Well, I guess the iPhone will die a slow death, the same as the PSP (wait a minute, people are still developing for the PSP ... maybe the iphone won't die?).
Are you serious?? how dare you write anything against an article about Apple? You are asking for it.. Now go and burn in karma hell.
and another thing - why the fuck waste all this effort on the iphone when there are other devices out there that don't require this hack and patch dick size contest?
If you mod me down, I will become more powerful than you can imagine....
Another article on hacked iPhones? Really? Are we going to have this with every update? We already know every update will be hacked.
If so, let me be the first to announce that Windows 7 activation has been cracked.
May this open the door to be able to install linux on the iPhone?
First person to get windows running on the iphone 2.0 will receive a free copy of Microsoft Vista.
on any other platform... this would be called a security vulnerability
No it bloody wouldn't. It would be called "of course you can install your own firmware on an iPaq, or a Treo, or what have you". It would be called "why shouldn't you be able to install programs on your own handset". It would be called "yes, of course that's the way it works".
Of course it's a good thing. Of course it's also a waste of time. Of course you're better off getting a phone where you don't have to screw around looking for DRM backdoors. What I can't figure is how anybody who knows it's a waste of time could possibly be stupid enough to honestly think "this would be called a security vulnerability". Right?
now even hackers are releasing vaporware?
intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
...allow unsigned code to be written to memory. This doesn't sound that attractive to me. Oh, baby, I can't wait for the first iPhone iVirus!"The fight for freedom has only just begun." - Geert Wilders
Slashdot got the story late, you'd think they'd get it right. The leaked firmare that dev team has hacked is firmware 1.2
The Admin and the Engineer
Except for the fact that it requires hacked firmware to do it. This requires you to first put the phone into emergency restore mode and physically plug it into your PC/Mac and then run a program to alter it. That's not called a virus or a security vulnerability that's called"I have physical access to my own iPhone and I WANT it hacked"
I keep reading they hacked the firmware. So what's to stop Apple from releasing a firmware update that breaks it? They release firmware updates for their computers periodically. Firmware is not impossible to upgrade.
I work for the Department of Redundancy Department.
They could bring out something similar in specs, unlocked, able to run unsigned code, etc, all the capabilities the hacking community wants but sufficiently different in some way to distinguish it from the standard iphone (Bulkier, to add more connections, maybe?). Market it at a huge enough price difference that AT&T doesn't get upset, and everyone would be happy.
Stasis is death. Embrace change.
The way I see it is that for once, His Steveness had lost faith in his ability to sell his product at their actual price. The deals made with the various telcos were mainly cost-cutting measures, to be made up by the profit-sharing model, leading to the locking of phones, and to the current situation. Who knows, if he had tried to sell a $1000 iPhone, and people still bought it up, and installed whatever software they wanted, then maybe the production cost of iPhone 2.0 might have gone down by now, and an iPhone would be in everyone's pocket.
Starbucks, Harbuckle of Breath.
Given that Apple is slow to approve developers, the only way to test your OpenGL ES program is to Jailbreak the iPhone.
You are supposed to test your program with the iPhone Simulator, called Aspen. The Aspen simulator is part of the free download SDK for the iPhone. However, Aspen does not support OpenGL ES, which is hardware acceleration for cool effects & fast 2D or 3D.
To deploy to the iPhone, Apple must give you a certificate, and they only do that to those paid developers whom they select.
In other words, most game developers can not test their programs because they can not deploy their programs to the iPhone.
I want to play around/learn. I have avoided Jailbreak solutions to date, but I see no other way.
The iPhone is a better computing device than it has ever been a phone. It has bad-to-mediocre voice quality. Anything that can BE a general purpose computer IS, in effect, a general purpose computer.
+++ATH0
You don't actually know what's good for you. You don't know what you need. You don't even really know what you want. You're also not capable of protecting yourself from malware threats.
Don't worry, though. Steve will make sure you don't hurt yourself.
+++ATH0
Since when is malware such a big problem on WinMob, Symbian or Linux-based phones? Can't say I've heard of a single case. Symbian also implements app-signing, as of S60v3 and UIQv3, but they still allow open apps - and plugins. Besides, most malware spreads through code exploits, and the iPhone is as vulnerable to those as any other system.
Sorry, but the "Apple just wants to make life easier for you" line is so much BS. MacOS X isn't signed & locked down, why should "OS X in a mobile device" be so different? Are phones so much more mission-critical than computers? Am I too stupid to watch my own battery life? As I said elsewhere, insisting that *no* user is competant to manage his/her own device is just insulting.
What they want is to restrict the user's freedom of use simply in order to protect their (and their carriers') commercial interests, nothing more. There's no other reason to e.g. ban Skype over cell (which is encouraged on other platforms).
Why would anyone engrave "Elbereth"?
Why doesn't Apple simply come up with an UNBREAKABLE system? Instead of building this iPhone like a computer, they should build it out of a positronic brain, which doesn't boot or load software. They would simply teach it, in their lab, how to be an iPhone and how to avoid letting itself be hacked, and then it would go out into the world and do its thing without all these problems that plague typical computers.
Really? Are you THAT stupid?
+++ATH0
Somehow, "Dweeb hacks into own code and circuit design" doesn't really sound like an interesting headline.
Non impediti ratione cogitationus.
Given that Apple seems to have sold a huge number of iPhones to people other than American AT&T customers, I don't think it's a coincidence that Apple has released four firmware revisions now and still haven't managed to lock it down. Once June arrives and it's confirmed that the iPhone can still be unlocked, I'll happily buy one and use it on T-Mobile, as I have no interest in switching to AT&T.
How relevant is hacking the iPhone, now that we have an SDK?
What I would like to see is a hack to get around the $99 fee to run your app on the device itself. The fee annoys me. I can understand it being there for devs that want to release their app, but what about people like me, who just want to see if I can make run on it?
I know, I know, the simulator.... that's no good. I want running on my phone!
I mean, this post is talking about a hack on hardware that only exists internally to the Apple development cycle.
Huh...
Either, they hacked this themselves so as to determine how to protect against it. Or this whole story is hogwash and not worth two grains of salt.
public devices should be open, anything less is simply evil and or incompetence
i'm so fing tired of corporate irresponsibility and unethicalness