Slashdot Mirror


iPhone Takes Screenshots of Everything You Do

The_AV8R writes "Jonathan Zdziarski showed that every time you press the Home button on your iPhone, a screen capture is taken in order to produce a visual effect. This image is then cached and later deleted. Zdziarski says that there have been cases of law enforcement looking up sex offenders' old data and checking recovered screenshots." This revelation occurred in the midst of a webcast on iPhone forensics, demonstrating how to bypass the iPhone's password security (not trivial, but doable). Video from the talk is not online yet but is promised soon over at O'Reilly.

57 of 225 comments (clear)

  1. FUD by Ethanol-fueled · · Score: 4, Funny
    From TFA:

    Therefore, forensics experts have used this security flaw to successfully nab criminals who have been accused of rape, murder or drug deals, Zdziarski said.

    iPhone: the tool of choice for rapists, murders, and drug dealers!

    Joking aside, the article is puzzling and it reeks of FUD: if the iCrooks were bad enough to get the authorities to actively track and sieze their data then they deserve to be caught for being too stoopid to buy disposable phones in cash from 7-11. Even Johnny dormroom pot- dealer knows that!

    1. Re:FUD by wild_quinine · · Score: 4, Funny

      Joking aside, the article is puzzling and it reeks of FUD:

      Apple FUD on slashdot? Maybe the LHC is gearing up for armageddon after all.

    2. Re:FUD by Colonel+Korn · · Score: 2, Insightful

      From TFA:

      Therefore, forensics experts have used this security flaw to successfully

      nab criminals who have been accused of rape, murder or drug deals, Zdziarski said.

      iPhone: the tool of choice for rapists, murders, and drug dealers!

      Joking aside, the article is puzzling and it reeks of FUD: if the iCrooks were bad enough to

      get the authorities to actively track and sieze their data then they deserve to be caught

      for being too stoopid to buy disposable phones in cash from 7-11. Even Johnny dormroom pot-

      dealer knows that!

      FUD doesn't mean what you think it means.

      --
      "I zero-index my hamsters" - Willtor (147206)
    3. Re:FUD by djh101010 · · Score: 4, Funny

      Sorry, LSD, this is the apple-hating thread, not the rant-about-wasting-jail-space-on-potheads thread.

    4. Re:FUD by MobileTatsu-NJG · · Score: 2, Insightful

      Apple FUD on slashdot? Maybe the LHC is gearing up for armageddon after all.

      Are you kidding? Ever since that line of people mysteriously turned up at an Apple Store, iPhone stories have become hate-fests on Slashdot. I'm not kidding. Somebody says they like the iPhone's web-browser and they're a 'fanboy'. But if somebody says the iPhone is 'useless', they're objective and rational.

      It has gotten rather obnoxious lately.

      --

      "I like to lick butts!" by MobileTatsu-NJG (#32700246) (Score:5, Informative)

    5. Re:FUD by Nathrael · · Score: 3, Informative

      TFA = The f**king article. Comes from "RTFM"; usually, if someone tells you to RTFA, he means that you should read the Slashdot article as well as the off-site articles mentioned in it before posting something that is self-explanatory if you RTFA.

      --
      A good education is a bit like a STD - it makes you unsuitable for a lot of jobs and gives you a desire to spread it.
    6. Re:FUD by Hognoxious · · Score: 4, Funny

      Off-topic but yes, possessing drugs does make you a crook

      Or a pharmacist.

      --
      Confucius say, "Find worm in apple - bad. Find half a worm - worse."
    7. Re:FUD by neoform · · Score: 4, Funny

      Alls I heard was "I love apple" and "I'm a huge fanboy"..

      --
      MABASPLOOM!
    8. Re:FUD by Mister+Whirly · · Score: 2, Insightful

      Not as delusional as "These addictive drugs are legal because johnny law-man says so, but johnny law-man doesn't get money from lobbyists for this drug so therefore it is illegal." and using that as an absolute argument. The fact a law exists doesn't make a discussion about it irrelevant, especially when it is a stupid law proven to fail.

      And BTW the dictionary.com definition of "crook" says nothing about simple law breakers. The closest it comes is "a dishonest person, esp. a sharper, swindler, or thief." so unless the drug dealer is dishonest (some are, some aren't) they are by no means a "crook". Unless they stole their stash from someone else.

      --
      "But this one goes to 11!"
    9. Re:FUD by stewbacca · · Score: 2, Interesting

      Yes, caffeine. The recreation drug of choice. I can't wait for my next caffeine party. Maybe I'll go tailgating at the football game today and get hepped up on coffee!

  2. Malfeasance handbook by ColdWetDog · · Score: 4, Insightful

    Item 1:

    Smart crooks use dumb (disposable) phones.
    Dumb crooks use smart phones.

    --
    Faster! Faster! Faster would be better!
  3. Just out of curiosity... by AndyG314 · · Score: 4, Funny

    What type of incriminating things are sex ofenders doing with their iPhones.

    --
    If it's dead, you killed it.
    1. Re:Just out of curiosity... by Fx.Dr · · Score: 5, Funny

      I believe it has something to do with multi-touch.

    2. Re:Just out of curiosity... by omnipresentbob · · Score: 2, Funny

      Particularly with new hardware...

  4. Re:It's nice to know by mmkkbb · · Score: 5, Interesting

    Errr, it's not phoning these screenshots home. You must have a problem with .bash_history too, right? Caching your keystrokes! OMG!

    --
    -mkb
  5. Anybody know if he was hacking 2.1? by wisebabo · · Score: 2, Interesting

    Sorry to diverge from the screenshot topic but does anyone know if Mr. Zdziarski will demonstrating how to hack the just released 2.1 firmware? Or is a previous version that (may have) been patched? This seems much more significant than being able to see (via a screenshot) what the last user action was.

    As for the screenshot, hmm... well at least it doesn't seem to be a deliberate attempt by Apple to get more info on the user. Also, it seems pretty difficult to get these screenshots (since they are automatically deleted according to the article you have to find and undelete them). Doesn't sound like a trivial or reliable way to snoop on people. Still I guess a security flaw is a flaw so be aware!

  6. Pragmatic by mfh · · Score: 4, Funny

    It's pragmatic to not press the home button when doing home invasions or killing people, I guess.

    --
    The dangers of knowledge trigger emotional distress in human beings.
    1. Re:Pragmatic by Em+Ellel · · Score: 3, Informative

      It's pragmatic to not press the home button when doing home invasions or killing people, I guess.

      Although you are probably technically right, unless you are killing them with a scathing email, or nasty AC troll post - it is not likely that the home button will matter. It captures the screenshot of what is on your screen - not from the camera. (unless you happend to have the camera app on at the moment of course)

      -Em

      --
      RelevantElephants: A Somatic WebComic...
  7. simple fix for Apple by RJBeery · · Score: 3, Insightful

    Give the concerned users an option of turning off the "shrinking screenshot" animation that occurs when the Home button is pressed (which is why the screenshot is cached in the first place).

  8. What's the problem by KasperMeerts · · Score: 5, Interesting

    So it takes a screenshot for some effect? Is there even a way to do this without taking a screenshot? A way that is easy enough to be performed on a smartphone?

    And what did you expect from Apple? That every bit of data that was discarded is overwritten ten times? Jeez, I enjoy bashing big companies as much as the other guy but now they're looking too far. Remember, it also saves your web history, every picture you took, every file you opened everything you did somewhere...

    --
    As long as there are slaughterhouses, there will be battlefields.
    1. Re:What's the problem by Anonymous Coward · · Score: 2, Interesting

      Those files are hidden away. This image should live in /tmp/, it doesn't. Apple decided you'd like it to appear in your photos list, which is clearly ridiculous. It does it on the ipod touch too.

      2.1 is a mess, apple's forums are full of bugs already, stupidly obvious ones that are found as soon as you use an updated device. Some seem to be problems with what itunes is doing to your files, others are bugs on the device itself. Clearly they didn't do enough testing, and the beta testers should be fired from the testing program.

    2. Re:What's the problem by fermion · · Score: 3, Insightful
      Sometimes it is just interesting to think about security, and security choices that are made. Certainly the security incompetence of most manufactures does not reach the level of homeland security, but neither does the security issues. It still is interesting to think about. For instance, the iPhone shows one letter of the password for usability, and this is likely worth the security compromise. Many web browser automatically cache a large number of previous web pages, and a large amount of history, so any minimally competent sleuth can determine everything you have done for the past week. This has security implications, yet when Firefox implemented the very reasonable privacy feature, they get ridiculed with installing a porn filter. In fact such history and cache can be argued to be a unnecessary security risk that should not be turned on by default, but the compromise has been made.

      In this case, a potential security issue has been introduced for the purpose of look and feel. While the headline is sensational and seems to be written by a person with no technical background or understanding fo the iPhone, the point remains. Pictures of what you are doing prior to pressing the home button are taken, and stored for some indeterminate amount of time. This is like the browser issue, likely not a big problem. OTOH, there does not seem to be an option under the general/home button menu to turn off this effect, so there is no way for persons worried about the issue to turn it off. It is an interesting problem.

      --
      "She's a scientist and a lesbian. She's not going to let it slide." Orphan Black
    3. Re:What's the problem by Anonymous Coward · · Score: 3, Insightful

      It's crap like this that makes me feel just fine having my little fugly Palm Centro. I don't have to have yet another security hole because Apple felt taking a screenshot would make for a cool bit of eye-candy.

      Admit it. You're letting envy cloud your judgement.

      Think about what you're saying. "Yeah, my device is ugly and stupid, but YOURS HAS YOUR PERSONAL INFORMATION ON IT".

      Seriously. Someone gets my phone, my *LAST* concern is potentially recoverable screenshots of what I was doing on it when I closed an application. What about all the personal data it stores through the very nature of its function?!

      lame

  9. And this just in! by Artraze · · Score: 5, Funny

    It turns out that you browser will store all the information needed to recreate the web pages you visit! Not just a screenshot! This critical flaw appears to have present for years in all known browsers! The end is near!

    Seriously? Come on. I know ./ likes to post anything related to the iPhone, especially if it involves "spying", but this is pretty uninteresting. Security is traded for speed and features on a daily basis, including places where do so presents a major risk (*cough*Outlook). This is really not too surprising since it trades at most a little privacy in exchange for a neat effect; what would you expect Apple's iCandy to do?

    1. Re:And this just in! by venicebeach · · Score: 5, Funny

      It's even worse than that, the iPhone keeps copies of all your emails, and records phone numbers you have called as well as keeping a database of all your personal contacts!!! The thing is a 5 ounce privacy invasion machine!

  10. Re:Yeah, right. by D'Sphitz · · Score: 2, Interesting

    Well, apparently, from TFA it is cached on disk (flash, whatever). That's my question, hy not just create it directly into RAM and release it after the effect? What purpose is there to saving the screenshot beyond the second or so it takes to show the animation?

  11. Re:It's nice to know by Hyppy · · Score: 3, Interesting

    It's trivial to disable logging to .bash_history. What about for this?

  12. fud by sam_paris · · Score: 3, Insightful

    Tag this article as fud, because that's what it is. Any excuse to bash apple and/or iphone.. Really, if we're going to get upset about this, let's get upset about browser caching, cookies, history.. etc etc

  13. Re:It's nice to know by Em+Ellel · · Score: 2, Insightful

    Errr, it's not phoning these screenshots home. You must have a problem with .bash_history too, right? Caching your keystrokes! OMG!

    In all fairness, if his account password "alpine" is posted all over the internet, looking into his .bash_history IS a pretty damn good way of spying on him. (Granted, there are bigger issues in this scenario.)

    -Em

    --
    RelevantElephants: A Somatic WebComic...
  14. Re:It's nice to know by Subliminalbits · · Score: 5, Funny

    Don't forget the page file. The horror; your computer is constantly taking screen shots of your applications ram and storing them on the hard drive!

  15. Re:Makes you wonder.... by ByOhTek · · Score: 5, Insightful

    it makes me wonder why there is no 'badtitle' tag.

    It doesn't take a screenshot of everything you do, just when you hit the home button.

    --
    Self proclaimed typo king, and inventor of the bear destroying coffee table (patent not pending).
  16. Re:Makes you wonder.... by FireStormZ · · Score: 2, Insightful

    It makes me wonder what parental unit is stupid enough to give their kid an iPhone

    --
    "Ahh! Arrogance and stupidity in the same package, how efficient of you!" --Londo Molari
  17. Re:It's nice to know by Firehed · · Score: 4, Insightful

    Sure, if you overwrite your firmware (jailbreak), enable SSH access to the phone, and then NOT change your root password. Quite frankly, you deserve it at that point.

    Sounds like yet another sensationalist (and completely inaccurate) headline pointing to a non-story. Unless some pervert is hits the home button while trying to take a (crappy, borderline-useless unless it's being done in full daylight) picture of himself raping a kid, AND law enforcement not only knows to look for this cached file, I don't really see this being an issue. I suppose it could possibly be used as supplemental evidence when a case is being built up, but the actual AIM chat logs, sent emails, phone call history (all of which are far more accessible) and such would be far more potentially incriminating.

    --
    How are sites slashdotted when nobody reads TFAs?
  18. Even the Author Doesn't Think It's News by Nuclear+Elephant · · Score: 5, Informative

    I _am_ Jonathan Zdziarski and even I don't understand why this is news.

    This was a side note I mentioned the other day, and has been something I've been grousing about for over a year. It's unnecessary, and a bit of a privacy leak that can be exploited by forensic examiners, but hardly news for the reasons already stated in the comments.

    1. Re:Even the Author Doesn't Think It's News by Rob+T+Firefly · · Score: 4, Funny

      I _am_ Jonathan Zdziarski

      No, I'm Jonathan Zdziarski!

    2. Re:Even the Author Doesn't Think It's News by Inda · · Score: 4, Funny

      No, I am Jonathan Zdziarski.

      --
      This post contains benzene, nitrosamines, formaldehyde and hydrogen cyanide.
    3. Re:Even the Author Doesn't Think It's News by Nuclear+Elephant · · Score: 5, Informative

      To add one more comment to this, though, it's been inaccurately reported that this process takes an hour to complete. Well, the passcode breaking piece of the demonstration technically takes maybe 15-20 minutes for a trained pro to prepare, but once you've prepared the custom firmware payload, you can re-use it over and over again on different iPhones. The actual payload installation takes only 60 seconds, so someone who came along prepared would be able to break your passcode in 60 seconds - not an hour. With that said though, you still need to transmit the raw disk image to a desktop machine to access this data. That transfer can easily take 2-3 hours. This means that you're not going to have your personal data hijacked by simply placing the phone down for a moment, but if it were stolen or seized, it's most certainly easy to recover.

    4. Re:Even the Author Doesn't Think It's News by fo0bar · · Score: 3, Funny

      I _am_ Jonathan Zdziarski and even I don't understand why this is news.

      Welcome to Slashdot. Here's your oversized novelty foam finger.

  19. Re:It's nice to know by Vornzog · · Score: 2, Funny

    You must have a problem with .bash_history too, right? Caching your keystrokes! OMG!

    I don't much like .bash_history, so I usually do this:

    $ rm .bash_history
    $ ln -s /dev/null .bash_history

    Can I do something similar with the iPhone? Better not to have to think about it, even if it isn't incriminating.

    Benjamin Franklin was talking about exactly this when he said:

    "They who can give up essential privacy to obtain a little temporary eye-candy, deserve neither privacy nor eye-candy."

    That man was way ahead of his time.

    --

    -V-

    Who can decide a priori? Nobody.
    -Sartre

  20. I've seen this... by zosa · · Score: 3, Interesting

    I had a glitch occur that put one of these screen shots in my photos collection. I was wondering what kind of glitch would have generated a screenshot. Now that is partially explained.

    1. Re:I've seen this... by brainiac+ghost1991 · · Score: 2, Informative

      no, that's the screenshot function the phone has, press power + home button and it takes a screenshot

  21. Yes, maybe take some time off? by QZTR · · Score: 2, Insightful

    It really is no surprise that someone with the screename "lysergic acid" takes issue with being a crook because of illegal drug possession, but how the fuck did this get modded up?

    YES possessing illegal drugs makes one a crook. Deal with it, because it's reality. I really don't see how an intelligent person could openly wonder how doing the very thing that makes one a crook could cause one to be called a crook.

    Now, you can argue over whether you should be a crook, but that's not what was done here.

    Second, save the vacuous "alcohol" argument. I'll wager anything you want that in a random survey, the majority of respondents will indeed say alcohol is a drug, so I don't know who you think is deluding themselves besides you.

    Next, why are you even bringing up alcohol? If you want to decriminalize drugs, then make the case. Aim for what you want, and save the attempts at drawing equivalence. Saying "a drug that is easily and readily available does more damamge than drugs that are much more rare and difficult to obtain" isn't much of a point outside of a smoke filled dorm room.

    --
    To quote LongNoi "QZTR was right and won't leave me alone because I called him a moron when I was wrong" FYS
    1. Re:Yes, maybe take some time off? by hjrnunes · · Score: 2, Insightful

      I think you're seeing it from the wrong side. While it is true you find harder drugs alongside cannabis, that is because they're all illegal. If you sell cannabis and fancy becoming a major drug dealer then why not sell other drugs too? Anyway crime tends to agglutinate so to speak... To the literal crook interpretation fans I have a question then. Let us picture a country (any country) where criticizing whoever holds the power is illegal (see Turkey and Attaturk, though he's already dead). Now, picture them as crooks. Because that's what they are, are they not? All crooks. Doesn't sound that good now does it? Someones crooks are others freedom fighters then I guess...

    2. Re:Yes, maybe take some time off? by amRadioHed · · Score: 2, Insightful

      And since by that reasoning the only reason cannabis acts as a gateway is because it's illegal. Legalize it and there goes your supposed gateway drug effect.

      --
      We hope your rules and wisdom choke you / Now we are one in everlasting peace
  22. Re:Makes you wonder.... by SQLGuru · · Score: 2, Funny

    If I lived in a house with all of that screaming, I'd probably be violent, too.....

    Layne

  23. I'll show them... by russotto · · Score: 3, Funny

    I wrote a little app to fill the cache with screenshots of the IRS web pages. Anyone tries to investigate me, they'll have to carefully examine Publication 936, the instructions for Schedule F1, the guidelines for reporting "nanny" wages, and the like. Even if they aren't literally bored to death, they definitely won't want to look any further.

  24. Re:Makes you wonder.... by frosty_tsm · · Score: 3, Funny

    You can with the iBeer app.

    (sorry, I tried to find the link)

  25. More trivial than walking down to the store? by QZTR · · Score: 2, Insightful

    No. Not more trivial than walking down to the store.

    In fact, it would take a particularly ignorant, intentionally disingenuous person to argue that getting pot is anywhere near as easy as getting booze.

    Next, the reason people think pot is a gateway drug is the same reason people think running around in the cold causes the flu (I SAID FLU THERE PEDANTS, SO FUCK OFF). they're ignorant and are repeating bullshit they've had drilled into them.

    It of course never occurs to you people that it may in fact have nothing to do with the drug and simply be a consequence of well ingrained patterns of behavior that lead to drug taking.

    No way!

    Last, I don't need to "know where to look" for booze, as they have whole stores devoted to it. I could even ask someone I don't know while I'm passing them on the street.

    In short, everything you said is wrong.

    --
    To quote LongNoi "QZTR was right and won't leave me alone because I called him a moron when I was wrong" FYS
  26. wait a minute by GregNorc · · Score: 2, Insightful

    OSX also does that little shrinking animation when you minimize a window. I wonder if the same flaw is in OSX?

  27. Seems most popular at opposite extremes of age by mbessey · · Score: 2, Insightful

    Young kids tend to love the built in camera, especially using it with the Photobooth application. The Grandparents love video-chat with the grandkids. Everybody in-between in age thinks it's a waste of money.

    I've used the built-in camera in my Macbook exactly once so far.

  28. Re:Makes you wonder.... by BagOBones · · Score: 2, Funny

    Or iPint which is a free app

    --
    EA David Gardner -"... but the consumers have proven that actually what they want is fun."
  29. So what? by jrothwell97 · · Score: 3, Informative

    The phone swaps an image to the disk so it can later be used in compositing. It's nothing new you know. Virtual memory's been around for aeons, and looking through an unencrypted swapfile to find incriminating information isn't exactly new either.

    --
    Those using pirated Tinysoft signatures(TM) are a real threat to society and should all be thrown in jail.
  30. Re:Makes you wonder.... by cayenne8 · · Score: 2, Interesting
    "It makes me wonder what parental unit is stupid enough to give their kid an iPhone"

    Just curious...why would you think it stupid for a parent to get a kid an iPhone? That way they'd be giving them an iPod and phone in one fell swoop.

    Hell, when I was a teen.....I was working, and if they had them in my day...I'd have bought my own.

    But really....are you saying buying a phone in general for a kid is stupid or just if it is an iPhone that is stupid?

    --
    Light travels faster than sound. This is why some people appear bright until you hear them speak.........
  31. Re:It's nice to know by Em+Ellel · · Score: 3, Interesting

    You'll no doubt be shocked to learn that even though you might empty your Recycle Bin there are some thing that anyone with physical access to your computer MAY be able to recover.

    Thank you, that's the point. I DO know that about files *I* create and *I* delete and I can delete them securely if I choose to. What I did NOT know is that something is capturing screenshots of what I am doing and saving them without my knowledge. Generally this sort of a behavior is reserved for spyware, rootkits and other malware. I realize it is not intended as such, but neither was the Sony DRM rootkit a while back.
    I would guess most people would have an issue to have a keylogger installed on their computers. This is no different..

    (the word may is in all caps for the imbeciles reading, and because some of us are unable to detect when we are being patronizing)

    Ok, but there MAY be something vaguely self-referential about that....

    -Em

    --
    RelevantElephants: A Somatic WebComic...
  32. no foundation by dynamo · · Score: 3, Interesting

    This fool doesn't even present any evidence that this 'screenshot' is -ever- even written to storage. Sure, it has to be in RAM to be shown zooming away, but the same thing applies to showing anything on the screen at all. Just because it saves processing power to capture an image instead of zooming the live app like OS X does, doesn't imply that the image ever leaves volatile RAM.

    - written from my iphone.

  33. Re:Makes you wonder.... by FireStormZ · · Score: 3, Insightful

    I can see a situation in which a phone *might* make sense (kid works a late shift, has an unreliable car, etc... But I cant see the wisdom in getting a kid the iPhone or any other upper level phone. If a kid works and uses their own money thats all well and good but its way to much to give a kid because 'they need one'.

    --
    "Ahh! Arrogance and stupidity in the same package, how efficient of you!" --Londo Molari
  34. Re:Makes you wonder.... by Lord+Flipper · · Score: 3, Insightful

    Jealous much?

    Jealous of what, exactly? Kids sending SMS text at 100s the cost of an email, or simple IM? People paying hundreds of bucks to set themselves up for locked-in contracts?

    I've been an Apple client since 1979. You want to know what pisses me off? Apple turning into a fucking toy company, and incrementally destroying NeXTSTEP. Apple spending time on bullshit iPhone screenshot shit, and hanging on to the HFS+ file system, which is actually incompatible with their lousy OS. Leopard is nothing but a resource-hungry POS.

    I ride the bus and Light Rail, here in Minneapolis. I hear the ringtones and sometimes I glance around and every kid and person of color on the whole bus is playing Tetris, or fiddling with their fucking phones. When I see the voting returns, the top 10 TV shows by viewership and the voracious appetite in America for 'subjective' dispute of scientific facts, it's no wonder the country has reached a point where every successive 'decision' brings them closer to their own private armageddon. These people are wasting their fucking time on bullshit. Apple knows this, so yes, they pander to people with more money than brains.

    And just so there's no mistake, my last four PowerBooks, and three Apple desktops, were gifts from my happy clients. Apple hasn't seen a nickel (outside of ONE recently-purchased keyboard), from me, since '94. And if Adobe ever ports to Linux, that's it for me, sayonara toy company, and back to work.

    Trolling much?