Slashdot Mirror


Unreleased iPhone 2.0 May Already Be Hacked

The as-yet unreleased second iteration of iPhone hardware may already be compromised, reports Engadget and News.com. Members of the 'iPhone Dev Team' have (supposedly) made use of the recently released SDK to gin up a Beta 2.0 software hack. "Unlike previous hacks, this one isn't specific to the latest firmware version, it exploits the way that Apple designed the iPhone's main bootloader. According to the iPhone Dev Team, the iPhone verifies whether or not firmware code has been signed with an RSA certificate before allowing it to be written to memory. The team has apparently figured out a way to disable that check and allow unsigned code to be written to memory."

51 of 183 comments (clear)

  1. Pertinent word... by the_skywise · · Score: 3, Interesting

    WAS...

    I'm sure the iPhone 2 will be held back until this is fixed.

    1. Re:Pertinent word... by hey! · · Score: 5, Insightful

      Well, it's funny that Jobs likes to lecture the music and movie industry about the futility of DRM, but then he tries to lock down the iPhone.

      If he were rational (which is not to say that irrational precludes being brilliant), I don't think he'd really care that much about iPhone hacking, unless people started to look at it as something safe and normal and that Apple should support those hacks.

      When somebody solders a modchip onto a game console motherboard, he knows very well that he's on his own. But when a hacked up iPhone starts to feel normal to users, then Apple loses the ability to control the release cycle. They don't want their new products to compete with hacks for their existing ones, because they've discovered the secret of the software subscription model Microsoft toyed with a few years ago: you don't call it a subscription, you call it spiffy new hardware.

      Of course, he might well be totally ape-shit over iPhone hacking, I don't know. I don't think like him, which is why I'm not rich.

      --
      Post may contain irony: discontinue use if experiencing mood swings, nausea or elevated blood pressure.
    2. Re:Pertinent word... by nehril · · Score: 5, Insightful

      the whole iphone dev system is interesting in that it is an attempt to finally invert the usual "blacklisted software" security system that has so often been the rule. rather than the busted concept of allowing all software to run, and then chasing down 'bad' ones with antivirus programs, rootkit detectors, spyware removers etc, they're moving to a whitelist. default deny, selective approve, with revocation.

      just as any sane firewall is set up. (it would be nuts to set up a firewall to default allow all ports, and then start selectively blocking them only once an exploit that uses it becomes apparent, but then you have today's software security model doing just that.) forcing devs to buy a cert means they have somewhat of a point of authentication and also a hook to revoke all of a dev's apps if they fail to toe the line by releasing a virus, trojan, phish etc. Or "something that reduces apple's revenue" ;)

      I believe leopard has the (currently unused) capability to do this built in as well. looks like the iphone is going to be a bit of a testbed for the concept. this kind of thing is only possible really with a "brand new" os where you can start from day 1 with no backward compatibility problems. it's also the reason you're not allowed to run interpreters like java or javascript... else Sun would get a valid cert to load the java interpreter, which in turn could run anything on the planet bypassing the "run only whitelist code" concept.

      I can't say i agree with such "mandatory*" restrictions on a computing device I purchased, but as a matter of security philosophy it really is quite interesting.

      *well, mandatory if you want to run snazzy new SDK apps. they really should set up an "unsupported, you may be SORRY!!" class of signature that would let you run, at your own risk, anything from that signature.

    3. Re:Pertinent word... by cybereal · · Score: 4, Insightful

      If he were rational (which is not to say that irrational precludes being brilliant), I don't think he'd really care that much about iPhone hacking, unless people started to look at it as something safe and normal and that Apple should support those hacks.

      This is precisely the concern. Have you ever worked in support? I worked technical support for several years. The worst part of the whole ordeal was dealing with all of the unpredictability on the other end. This is the only reason we had no official Linux support. It was the reason we only needed 3 people to handle all Macintosh calls. The more predictable the workspace on the other end of the line, the better a technician can deal with a situation.

      This also applies to software development. This is what makes game consoles attractive, you have a reliable set of expectations to target. You know, when you have a device as sophisticated in software as the iPhone (it's got an entire OS, not just some execution firmware like non-smartphones) it is infinitely helpful to be able to predict what will or will not be going on there.

      So, while I'm sure Apple has no realistic expectation to avoid firmware hacking, I do believe they try to keep the expected cases in place as best as they can without getting ridiculous so the quality of software can remain high. So they can provide what they claim to provide in the device.

      While a more savvy person may realize their phone is running out of battery twice as fast because of some software they put on there themselves, the average consumer is not going to understand any of this reasoning. Apple doesn't want to deal with phone calls and complaints that root from things the user did to themselves unwittingly. The easiest way to avoid that is making it hard for users to do it to themselves. Make it an effort to get hacked firmware and unapproved software and you achieve this goal. You don't have to prevent it 100%, and therefore, there is no logical argument that Apple is being hypocritical about their DRM stance. This isn't DRM, this is the virtual version of that welded bolt on the back of a service-only machine.

      Any geek willing to break the seal is willing to forego support when they inevitably break the machine.

      --
      I read the script, and I think it would help my character's motivation if he was on fire. -Bender
    4. Re:Pertinent word... by arminw · · Score: 2, Interesting

      ....I develop a killer phone app.......

      If you do, so what? You still have to sell it somehow, unless you write it just for your own amusement. Do you think that people will sell your stuff for free, no matter even if it is insanely great? If given the choice of your "killer" app which may be virus infested, or a clean "vetted by Apple" program, directly from Apple's servers, which with most people pay money for?

      --
      All theory is gray
    5. Re:Pertinent word... by Brian+Gordon · · Score: 4, Insightful

      I find it amusing that they even try to lock it down. Unless they seal the thing in adamantium or lock it away in a secure server facility, any system is hackable. Even if it comes down to slicing lines on a PCB or soldering in a modchip between the memory and the northbridge.. it's just absolutely absurd to hand someone a device and tell them they can't hack it.

    6. Re:Pertinent word... by SuperKendall · · Score: 5, Insightful

      Well, it's funny that Jobs likes to lecture the music and movie industry about the futility of DRM, but then he tries to lock down the iPhone.

      Yes, but Apple only does this as a safeguard to help protect more timid users. Apple, unlike the music studios, knows it will be broken and does not really care.

      If he were rational (which is not to say that irrational precludes being brilliant), I don't think he'd really care that much about iPhone hacking

      He doesn't, which is why the last iPhone update did not break jailbroken phones.

      --
      "There is more worth loving than we have strength to love." - Brian Jay Stanley
    7. Re:Pertinent word... by arminw · · Score: 4, Insightful

      ....restrictions on a computing device ....

      The iPhone is a PHONE a wireless PHONE. Repeat this a thousand times. It is NOT a general purpose computer. Most people who bought or will buy this expensive gadget want a phone first of all and want that to work as reliably as any other phone at LEAST. Apple will and must do everything in its power that their phone or ipods don't become another Windows like portal for propagating all sorts of malware aimed at emptying unsuspecting people's bank accounts.

      In that regard, Apple can simply inform iphone users in no uncertain terms that warranties on hacked devices are null and void. They are also within their rights to warn users that any update from Apple may indeed inadvertently brick their hacked devices. Unauthorized customer modifications and use of manufactured goods and machines have always resulted in lost warranties at the very least. Sometimes human lives are at stake.

      --
      All theory is gray
    8. Re:Pertinent word... by voidptr · · Score: 5, Insightful

      The point isn't to make it unbreakable.

      It's to make it enough of a pain in the ass that those who manage it realize they're wading into unsupported waters.

      --
      This .sig for unofficial government use only. Official use subject to $500 fine.
    9. Re:Pertinent word... by MacDork · · Score: 2, Insightful

      If you do, so what? You still have to sell it somehow, unless you write it just for your own amusement. Do you think that people will sell your stuff for free, no matter even if it is insanely great?

      I have my own server, my own credit card merchant account, and my own SSL certificate vouched for by a root certificate authority accepted by all major web browsers. You're assuming I want or even need Apple's assistance in selling and distributing my software.

      If given the choice of your "killer" app which may be virus infested, or a clean "vetted by Apple" program, directly from Apple's servers, which with most people pay money for?

      So you're saying Mac OS X is insecure and riddled with viruses? Even Apple would disagree when they aren't talking out of the other side of their mouth. Are you suggesting that Adobe Photoshop, a Mac stalwart that has been on the platform for nearly two decades, is insecure because it executes interpreted code? Have you any shred of proof whatsoever? No, you don't, because it doesn't exist. Thanks to the restrictions on the SDK, you'll never see anything like it on your iPhone unless Apple produces it themselves.

    10. Re:Pertinent word... by moosesocks · · Score: 2, Interesting

      Well, it's funny that Jobs likes to lecture the music and movie industry about the futility of DRM, but then he tries to lock down the iPhone.


      What is happening on the iPhone is not DRM. DRM is about copy-protection.

      There are many parallels between DRM and closed hardware platforms, but they are two very distinct issues.

      Apple's reasons for clamping down on the iPhone are very likely to be quite numerous, not to mention whatever sort of contractual obligations they have to fulfill with AT&T. It's not pretty, but it's how the mobile phone industry works in the US.

      I can understand people being disappointed that the iPhone is a closed and locked platform, but displaying outright anger over the issue is absurd. Nobody's forcing you to buy an iPhone, nor is anything preventing some bright entrepreneur from making something better.
      --
      -- If you try to fail and succeed, which have you done? - Uli's moose
    11. Re:Pertinent word... by peragrin · · Score: 3, Insightful

      write again when andriod is actually out on a smart phone.

      Not a single manufacture is using it yet. When they release an actual product I will then judge it, until then it is vaporware with source code. As Android is worthless without hardware.

      --
      i thought once I was found, but it was only a dream.
    12. Re:Pertinent word... by Namarrgon · · Score: 4, Insightful

      Yes, allowing the user to modify a device complicates support. But this can be dealt with - look at how e.g. HP and Dell manage user support nowadays? "Reset your system to the factory-shipped state with the included Restore partition - problem solved." This is even easier to do with the iPhone.

      Thing is, users don't have to install any third-party software, if they want a "guaranteed quality experience". Why not simply allow people the choice about how they use their device? Hell, put up a warning on install - "You are now straying from the Apple Way - Abandon All Hope!" - but to assume that *every* customer is incapable of managing their own device is just insulting.

      What bugs me most is how Apple apologists go on about how the iPhone is so great because "it's got an entire OS!" (like this is new) - and then claim that every limit on this OS, every restriction and removal of user choice, is actually somehow for the user's benefit. "No 3G? Might kill battery. No Flash? Might kill performance. No plugins? Might, um, break something." It really gets old.

      Yeah yeah, vote with my wallet, I don't have to buy one. I'd really like to buy one, they've done so much right with it, but these decisions are deal-breakers for me, and the continual excuses don't give me hope that this will change.

      --
      Why would anyone engrave "Elbereth"?
    13. Re:Pertinent word... by jlarocco · · Score: 4, Insightful

      But the other poster's point is that anybody who's willing to open the device and make a modification already knows they're in unsupported waters. Making it difficult just wastes everyone's time.

    14. Re:Pertinent word... by globaljustin · · Score: 4, Interesting

      worked technical support for several years. The worst part of the whole ordeal was dealing with all of the unpredictability on the other end.

      Saving money on doing tech. support has nothing to do with Apple's response to iphone hacks! Anyone who would have the capability to hack an iphone would know that if you hack it, you can't get support for it.

      Apple is concerned with money. More specifically, they got big bucks from AT&T to make it exclusive. AT&T have a vested interest to make sure that their investment is worth it. Apple has to prove to AT&T that all possible measures are being taken to ensure that if someone buys an iphone, they use AT&T service. That's what's in play here. Tech support is irrelevant.

      I bet Jobs personally at least sympathizes with those who want to hack iphones so they can use them with any phone services. The deal with AT&T may not have been his call in the end.

      off-topic, Parent post is a troll in disguise...basically he's ranting about frustrations of doing tech support and somehow managed to loosely connect it to the topic
      --
      Thank you Dave Raggett
    15. Re:Pertinent word... by nine-times · · Score: 3, Interesting

      Any geek willing to break the seal is willing to forego support when they inevitably break the machine.

      Right. As an iPhone owner, I hacked mine a while back. It was really easy. Part of the problem, though, is that the OS has been changing often enough that most apps won't work unless they're written for the specific firmware you're using, so the payoff of hacking your phone is diminished. I think lots of developers stopped keeping up figuring they'd wait for the official SDK.

      Anyway, I don't doubt that the iPhone will keep getting hacked for as long as it's useful to hack it. I'm betting either Apple will be very reasonable about letting people distribute on iTunes, or else people will immediately hack a different distribution method for unauthorized apps. Either way you'll be able to get the apps you want with a minimum of hassle.

      It's going to happen, and the iPhone will be a cool platform. If Apple's smart (which they often show themselves to be) then they won't fight it.

    16. Re:Pertinent word... by thePowerOfGrayskull · · Score: 2, Insightful

      But the other poster's point is that anybody who's willing to open the device and make a modification already knows they're in unsupported waters. Making it difficult just wastes everyone's time.

      Not at all. Of course the people making the hacks know this; but this also means that when people download these things and install them, it's enough of a hassle that they're aware of what they're getting into.
    17. Re:Pertinent word... by Chrononium · · Score: 4, Informative

      I know that you made this comment in jest, but a few years back when I was a hardware engineer at Apple, we literally only had 5 or 6 IT guys for the whole campus, which probably implied 5 or 6 guys for approximately 5000 computers. Sure, a lot of that was because you were more or less trusted to operate a computer (at least in engineering, but I think it applied in other buildings too), but that's still a massive accomplishment. The university lab I'm at now is dedicated to computational electromagnetics and they do fairly well with only two guys for the 200 or so computers here. But that's largely because we can't do much of anything without their say so. I think the Mac, when properly understood and matched up with the proper IT philosophy, can do wonders. And I bet you can't guess how many people ran the iTunes Music store hardware. It was pretty darn awesome.

    18. Re:Pertinent word... by base3 · · Score: 2, Insightful

      "Unsupported" != "Deliberate device disablement via updates for hacked devices"

      --
      One CPU cycle wasted on digital restrictions management is ONE TOO MANY.
    19. Re:Pertinent word... by Telvin_3d · · Score: 3, Insightful

      I never got the impression that Apple has ever intentionally break jailbroken iPhones. I doubt they even test their updates against them before release. The original jailbroken phones changed some stuff the update wasn't expecting and so you ended up with a broken phone. The more recent updates happen to not interfere with jailbreak. I'd think that is as much coincidence as intentional.

    20. Re:Pertinent word... by bnenning · · Score: 4, Insightful

      The iPhone is a PHONE a wireless PHONE.

      It's a device that can make phone calls, amongst other functionality. My Power Mac 7500 was making and receiving phone calls 10 years ago; that didn't transform it into a single-purpose appliance that would crash and burn if I did anything else with it.

      Also, the iPod touch is not a phone.

      It is NOT a general purpose computer.

      Why not? It runs Unix, and its API looks a whole lot like that for Mac OS X. Apple may not want you to think of it as a computer, but objectively speaking it is.

      Most people who bought or will buy this expensive gadget want a phone first of all and want that to work as reliably as any other phone at LEAST.

      And yet if there's any way to run apps not approved by Apple, these same people who insist on reliability above all else will be stampeding to download malware-infested porn apps from the Elbonian mafia?

      --
      How to solve most of our problems: 1.Lots of nuclear plants. 2.Cure aging.
    21. Re:Pertinent word... by MacDork · · Score: 4, Insightful

      Yes, but Apple only does this as a safeguard to help protect more timid users.

      Funny, because I recall Steve Jobs making it clear in September that Apple would fight attempts to unlock the iPhone. He didn't say anything about protecting the timid. I think it went more like this. "It's a cat and mouse game" and "It's our job to keep them from breaking in." I guess I missed his "Protect the timid" speech.

      He doesn't, which is why the last iPhone update did not break jailbroken phones.

      Yeaaaaah... I'm sure you're right SuperKendal. Steve was just feeling generous. I don't imagine that billion dollar class action lawsuit regarding the intentional bricking had anything to do with it.

    22. Re:Pertinent word... by 99BottlesOfBeerInMyF · · Score: 3, Insightful

      Well, it's funny that Jobs likes to lecture the music and movie industry about the futility of DRM, but then he tries to lock down the iPhone.

      While the difference between content and applications (or even between types of content) bear directly on Job's statements, you don't even need to look that far. Jobs said that DRM was a flawed concept and would never work for the long term... but Apple implemented it anyway because the RIAA required it to do business in the music industry and without them the iPod would have never materialized, or at least never gained significant market. The same thing applies here. Apple cannot ever "win" the fight against iPhone modders, nor is that their goal. Their goal is to make it inconvenient enough so that the modding community never makes up significant share of iPhones and so they can meet their contracts with the big players in this industry, particularly AT&T who Apple has to keep happy and who probably has a signed contract (trade secret of course so it will never be public unless the courts make it so) that says Apple has to perform due diligence to lock down applications to prevent VoIP on the cell network as well as other apps that threaten AT&T's money making services.

      If he were rational (which is not to say that irrational precludes being brilliant)...

      I think Jobs has proved himself rational, nor do I think you're understanding his position. He's made Apple a lot of money while still espousing the opinion that DRM is a flawed concept. That is what he believes and even what he pressures others to accept in deals with Apple, but at the same time he is willing to do what it takes to get a start in a new market; be it music downloads, movies, TV, or smart phones. It is a very reasoned person who can state their opinions consistently, yet at the same time be wiling to bend to the big players in the market who hold the keys to successful entry.

      When somebody solders a modchip onto a game console motherboard, he knows very well that he's on his own. But when a hacked up iPhone starts to feel normal to users, then Apple loses the ability to control the release cycle.

      I doubt Apple cares that much about locking down iPhones beyond what it takes to keep AT&T happy. Very few people will modify their iPhones to run other software (compared to how many people buy them in total). Sure, Jobs sees an opportunity for more security and stability with whitelists, but they've implemented the same thing to a lesser extent on Macs as well nd you don't see it being used to try to seriously stop users who want to do something and are willing to hack.

      They don't want their new products to compete with hacks for their existing ones, because they've discovered the secret of the software subscription model Microsoft toyed with a few years ago: you don't call it a subscription, you call it spiffy new hardware.

      I don't really think this is Apple's plan. They've had lots of opportunity in both iPod and Mac markets to artificially break compatibility with older hardware. If a new version of OS X ran more slowly than an old version, pretty much no one would have batted an eye, since MS has them conditioned to think of this as normal. Instead, each revision was faster on old hardware than the previous revision (well maybe 10.4 was break-even in some cases). Apple has always sold their new hardware on new hardware features, not on mandatory upgrades enforced by software (and I have a dual 533 Mhz PPC tower in the corner still running as a media server to prove it). And before you bring up the iPod touch, read about Apple's media codec licenses and Sarbanes-Oxley as interpreted by quite a few (but not all) companies in technology.

    23. Re:Pertinent word... by tlhIngan · · Score: 5, Informative

      "Unsupported" != "Deliberate device disablement via updates for hacked devices"


      Here we go again.

      Has it been proven it was deliberate? Because there was an update later on (1.1.2, I believe) that fixed all the "bricked" phones. Which would mean that whoever unlocked their phone, the software was done poorly enough that the updates were screwed up. Even the iPhone Elite Team says it's due to a messed up unlock patch. A hack

      And Apple said it will brick phones if they unlocked the phone and update. The solution was to avoid updating until later...

      Heck, Nintendo has to start warning too that their updates may brick the Wii, as well, if there were any third-party modifications done to it.
    24. Re:Pertinent word... by Lehk228 · · Score: 2, Informative

      is the apple way anything like the habbo way, cau's i break the habbo way all the time trying to warn people away from the pool.

      --
      Snowden and Manning are heroes.
    25. Re:Pertinent word... by WhatAmIDoingHere · · Score: 2, Informative

      They don't make it easy to refuse the update? "There is an update for your iPhone (version number here) do you want to download and install it, just download it and install it later, or ignore it? Pick one."

      It's VERY easy to refuse an update. Now, if they were forced down over AT&T, that'd be a different story.

      --
      Not a Twitter sockpuppet... but I wish I was.
    26. Re:Pertinent word... by arminw · · Score: 2, Insightful

      ....the iPhone for its phone calling capabilities....

      For those who don't need the phone part, there is the iTouch music player. Apple has to take steps to prevent their devices from becoming another Windows monoculture that attracts crooks who want to rip off as many people as possible. Some of these steps will displease the software freedom advocates, but are unfortunately a needed precaution in our connected world.

      Decent developers should have no problems writing and selling clean software, according to the rules of Apple, made to ensure the reliability of their devices and profit. Apple is also NOT a charity, but a for PROFIT making company. They have a legal obligation to their owners (share holders) to make an honest profit.

      If some malware gets on millions of iPhones, Apple will get the blame for their "insecure" careless programming, just as Microsoft did. Who wants to have to spend resources on after the fact malware protection? I am so glad that I don't have to waste money and my time to have to install some of the resource hogging anti-malware software Windows users need, on my Macs.

      An ounce of prevention is worth a pound of cure.

      --
      All theory is gray
  2. Don't get your hopes up. by Sterrance · · Score: 2, Insightful

    Jobs will pounce on this faster than a Leopard. They should have kept their mouths shut.

    1. Re:Don't get your hopes up. by Anonymous Coward · · Score: 2, Funny

      And a few years ago he would've jumped on it as fast as a Tiger. And before that as fast as a Panther, a Jaguar, a Puma, or a Cheetah, depending on what year the comment was made.

  3. Nice by aleph42 · · Score: 2, Insightful

    It's not the first time something is hacked before it's even released, but it's always funny.

    What really makes this one a good example is that for once this lock used some kind of real crypto (RSA), not some security-through-obscurity stuff. And yet, of course, that defeated, by not even letting the check occured.

    Because crypto scenario were Bob tries to hide something to bob, after giving Bob the key are just a bit to stupid to work.

    --
    Don't take my posts literally; it's just code to control my botnet.
    1. Re:Nice by aleph42 · · Score: 2, Insightful

      The way they "just don't support it anymore" looks a lot like doing everything they can to discourage anyone from tinkering with their device.

      Which, by the way, is coherent with their whole DRM/iTune/exclusive_deals strategy of leveraging their control over their customer to limit competition.

      In France, the best ISP, http://free.fr/ , gives you a modem that actually runs a trimed down version of linux, acts as a tivo, and even uses a custom version of vlc to stream videos (TV or VOD) to your PC or TV! People have tinkered a lot with it, to add youtube support and the like.
      So excuse me for having high standards :)

      --
      Don't take my posts literally; it's just code to control my botnet.
    2. Re:Nice by Pepsiman · · Score: 2, Informative

      Yes, the RSA encryption on the DS is only used when downloading a game from another DS.

      The RSA encryption on the Wii is used for everything, but has an implementation bug.

      This bug is exploited by Datel to create Freeloader and by homebrewers to create Wii channels, fake update partitions, etc.

  4. Firmware 2.0 by the_g_cat · · Score: 4, Informative

    They hacked firmware 2.0, which will run on current iPhones, there's no mention of new hardware for this stuff...

  5. Feasable? by PolarBearFire · · Score: 4, Interesting

    This thread is probably going to be full of sofware security bashing, deservedly or not. Let's get something constructive out of this... Anyone know of any way to make software security function the way business people dream of? Namely, only approved code running approved processes. I think given access to the hardware any machine can be "hacked" given enough interest and manpower. Even putting security features in the chips themselves, as I've heard they are developing, will just be a relatively minor roadblock.

    1. Re:Feasable? by MBCook · · Score: 2, Informative

      The best you could do would be to alter the hardware (the actual CPU, not some external module) to verify cryptographic signatures. That would prevent you from accidently loading software like this, but it has it's own problems. For one, you have to stick your cryptographic key on the CPU. If they get compromised, they can't be updated. If they can be updated, then someone who cracks the device can just update to their own key and they are now in charge.

      You could have a second CPU, acting as a watchdog, monitor the bus and make sure code is signed, nothing weird is going on, etc. That would be very difficult though.

      Your best option that could be implemented now would be sending hashes across the network to verify stuff all the time. Since most people aren't going to have the ability to play man-in-the-middle with the cell phone network, this would be reasonably secure. That said, it would be a pain (especially with 3rd party programs going to be available). It would also tie up the cell network.

      What they've done seems quite reasonable to me, for the amount of time it probably took to implement.

      --
      Comment forecast: Bits of genius surrounded by a sea of mediocrity.
    2. Re:Feasable? by smallfries · · Score: 2, Insightful

      Why not some external module? That was the design that the Palladium group came up with to solve this very problem - whitelisting software.

      --
      Slashdot: where don knuth is an idiot because he cant grasp the awesome power of php
    3. Re:Feasable? by BosstonesOwn · · Score: 2, Insightful

      Microsystems are becoming the end game at the moment , or are being touted as such.

      The newest platforms are actually systems on a chip. Not only a watch dog watching the voltage and clock lines , but watch dogs performing zero knowledge tests on blocks of data before they are passed to the considered safe block of ram. It always comes to the same point , the key is on the chip some where. You can randomize and do as much as you want to make the key random , at some point the key has to be stored to even start the boot process.

      Some of the newer micros are using a main core like the eco2000 in the case of seimen/infineon 8051 systems and having a watchdog watch the lines , a block decoder/encoder sitting in between passing it to and from the core ram and storing the keys in a small block that is read only under certain conditions met by the block de/enc device, bit settings in protected ram and the state of the eco core. The main issue is the key is still on board. When this happens once you have that you have control.

      There really is no way to prevent the system from being hacked when you have to give the secret with the device. The only combat you have is to make it to expensive to hack and therefore take away the reason to do so.

      Security by using security mess and UV detectors on the newer security chips are stop gap measures, an interested person will find a way around it. There is no way to secure anything , what is secure now , won't be secure tommorow , and when people have interests you won't lock them out. The only hope again is to stave off the hack long enough to develop another system to take its place when some one figures out the current system. Cat and mouse till the day we die.

      --
      This package Does Not Contain a Winner
  6. A slow death, like the PSP by PC+and+Sony+Fanboy · · Score: 2, Insightful

    Well, I guess the iPhone will die a slow death, the same as the PSP (wait a minute, people are still developing for the PSP ... maybe the iphone won't die?).

  7. Re:It would have been better to wait by dagamer34 · · Score: 2, Insightful

    The vulnerability affects the bootloader. Apple will NEVER, EVER, EVER replace the bootloader by a user update. Any disruption while replacing the bootloader equals a truly dead iPhone. While we may have come to expect complications with our computers, cell phones are another story. If anything, we'll see an updated bootloader in new phones, but the millions already on the market will still be available to be unlocked. Though, Apple will probably have yet ANOTHER security audit so make sure the 2nd gen iPhone has no cracks for illegal activities.

  8. Bill Gates just announced... by DanWS6 · · Score: 4, Funny

    First person to get windows running on the iphone 2.0 will receive a free copy of Microsoft Vista.

    1. Re:Bill Gates just announced... by Fnord666 · · Score: 3, Funny

      First person to get windows running on the iphone 2.0 will receive a free copy of Microsoft Vista.
      The second person will receive two copies of Microsoft Vista.
      --
      'The tyrant will always find pretext for his tyranny.' - Aesop's Fables
  9. No it bloody wouldn't. As you should know. by argent · · Score: 3, Insightful

    on any other platform... this would be called a security vulnerability

    No it bloody wouldn't. It would be called "of course you can install your own firmware on an iPaq, or a Treo, or what have you". It would be called "why shouldn't you be able to install programs on your own handset". It would be called "yes, of course that's the way it works".

    Of course it's a good thing. Of course it's also a waste of time. Of course you're better off getting a phone where you don't have to screw around looking for DRM backdoors. What I can't figure is how anybody who knows it's a waste of time could possibly be stupid enough to honestly think "this would be called a security vulnerability". Right?

  10. let me get this straight by circletimessquare · · Score: 4, Funny

    now even hackers are releasing vaporware?

    --
    intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
  11. Re:Uh, did this ring a warning bell with anyone el by skingers6894 · · Score: 3, Insightful

    Except for the fact that it requires hacked firmware to do it. This requires you to first put the phone into emergency restore mode and physically plug it into your PC/Mac and then run a program to alter it. That's not called a virus or a security vulnerability that's called"I have physical access to my own iPhone and I WANT it hacked"

  12. unpatchable? by v1 · · Score: 2, Insightful

    I keep reading they hacked the firmware. So what's to stop Apple from releasing a firmware update that breaks it? They release firmware updates for their computers periodically. Firmware is not impossible to upgrade.

    --
    I work for the Department of Redundancy Department.
  13. Why doesn't Apple just release a Dev platform? by SleepyHappyDoc · · Score: 3, Interesting

    They could bring out something similar in specs, unlocked, able to run unsigned code, etc, all the capabilities the hacking community wants but sufficiently different in some way to distinguish it from the standard iphone (Bulkier, to add more connections, maybe?). Market it at a huge enough price difference that AT&T doesn't get upset, and everyone would be happy.

    --
    Stasis is death. Embrace change.
  14. Jailbreak is the only way to test programs by dougwhitehead · · Score: 5, Insightful

    Given that Apple is slow to approve developers, the only way to test your OpenGL ES program is to Jailbreak the iPhone.

    You are supposed to test your program with the iPhone Simulator, called Aspen. The Aspen simulator is part of the free download SDK for the iPhone. However, Aspen does not support OpenGL ES, which is hardware acceleration for cool effects & fast 2D or 3D.

    To deploy to the iPhone, Apple must give you a certificate, and they only do that to those paid developers whom they select.

    In other words, most game developers can not test their programs because they can not deploy their programs to the iPhone.

    I want to play around/learn. I have avoided Jailbreak solutions to date, but I see no other way.

  15. This isn't "informative." by StarKruzr · · Score: 2, Insightful

    The iPhone is a better computing device than it has ever been a phone. It has bad-to-mediocre voice quality. Anything that can BE a general purpose computer IS, in effect, a general purpose computer.

    --

    +++ATH0
  16. Does Apple care? by Ungulate · · Score: 2, Insightful

    Given that Apple seems to have sold a huge number of iPhones to people other than American AT&T customers, I don't think it's a coincidence that Apple has released four firmware revisions now and still haven't managed to lock it down. Once June arrives and it's confirmed that the iPhone can still be unlocked, I'll happily buy one and use it on T-Mobile, as I have no interest in switching to AT&T.

  17. How relevant? by cadeon · · Score: 3, Insightful

    How relevant is hacking the iPhone, now that we have an SDK?

    What I would like to see is a hack to get around the $99 fee to run your app on the device itself. The fee annoys me. I can understand it being there for devs that want to release their app, but what about people like me, who just want to see if I can make run on it?

    I know, I know, the simulator.... that's no good. I want running on my phone!

  18. iPhone 2.0 Hardware...huh..what? VAPORWARE? by PortHaven · · Score: 2, Interesting

    I mean, this post is talking about a hack on hardware that only exists internally to the Apple development cycle.

    Huh...

    Either, they hacked this themselves so as to determine how to protect against it. Or this whole story is hogwash and not worth two grains of salt.