iPhone 3.0 Update Delivers Prodigious Patch Batch
CWmike writes "Apple patched 46 security vulnerabilities in the iPhone and iPod Touch, half of them in the Safari browser and its WebKit rendering engine, as it released iPhone OS 3.0 on Wednesday. One of the patched WebKit vulnerabilities stands out because of the attention it received in March, when a German college student, Nils, walked away with a $5,000 cash prize for hacking Safari at the Pwn2Own challenge. Nils used a bug in WebKit's handling of SVGList objects to crack Safari."
Had the dev version on the phone which was great, but at one point bricked my phone.
I've never seen a portable device add so much functionality on a regular basis.
Does it support copy & paste?
Frankly I don't know what all the hoopla about iPhone OS 3.0 is about. I was hoping to use compass with google map after the update on my iPhone 3G, but all I got was a lousy voice-memo software.
And before anyone points out that iPhone 3G didn't have compass built into the hardware - It is supposed to be apple! I expect nothing sort of miracles from Steve Jobs!!
On a serious note, tethering was supposed to be there without the need to jailbreak your phone, but it is not available in US, and it is not available in Germany. Could someone tell me where it is available? Phone companies are the scum that are only slightly worse than the music industry.
But when are they going to patch these security flaws on my 2.1 ipod? Paying for an update is ridiculous, especially when it fixes critical security flaws. I sure hope apple does the right thing.
Maybe I am missing something, but the article linked in the summary (about Pwn2Own's prize for hacking Safari) appears to be about someone hacking IE, not Safari.
I judt got a nre Kinesis keybiartf so please excusr ant egregiou typos.
I wonder why the iPhone doesn't see more patches and updates. If the iPhone OS is a branch of Mac OS why isn't the phone patches as much as the desktop OS? Do Windows Mobile machines patch every Tuesday? I never updated my CrackBerry. Perhaps Apple doesn't want the iPhone to appear to need patches more often than it's competitors.
I have an iPod touch, i was wondering if it was worth it to upgrade. I also wonder if these Safari bugs will be fixed in a 2.x update. Sucks to have to pay $10 to be secure.
Although if i don't, it's easier to pWn and run cydia on it I guess.
GoPhone subscribers warned the upgrade will be the end of the service.
AT&T Narrows Prepaid Plan Options
"AT&T currently offers two types of prepaid plans: GoPhone, its "pay as you go" plan, and Pick Your Plan, its "prepay once a month" plan. AT&T's statement says that GoPhone will not be available for either original iPhones or iPhone 3Gs; Pick Your Plan will only continue to work for existing subscribers using the original iPhone, as long as they have an unlimited data plan. Current Pick Your Plan users who don't have an unlimited data plan will be asked to add one. iPhone 3G users are not eligible for Pick Your Plan.
According to Erica Sadun at TUAW, who's been investigating this issue, all pay-as-you-go users are being strongly encouraged to sign up for a postpaid plan, which includes making a new two-year commitment."
Looks like I'll be waiting a year for the Apple/AT&T agreement to time-out. I'll not do a two year agreement again, ever.
A feeling of having made the same mistake before: Deja Foobar
If you have a data plan of 1 gig per month or better, tethering data comes out of your regular monthly allowance - no extra charge. I must say that this was a pleasant surprise. The fine print in the agreement is that Rogers / Fido may rethink the current arrangement in the new year after assessing the actual hit to the network that tethering may or may not incur.
Fingers crossed...
blah, blah, blah...
Boo. Hoo.
My Photography - http://ian-x.com
The Deathlings (comic) - http://thedeathlings.com
who says you *have* to use it? i use itunes elusively for iPhone updates. nothing requires you to use the software for mp3s or anything else.
my iTunes isn't seeing any update from the original 3.0 upgrade yesterday.
More like "should have been in 1.0" in some cases
Seriously, no copy and paste in 2009?
And it's theoretically possible Apple will release a 2.2.2 firmware for the iPod Touch with backported security fixes.
AT&T actually discontinued its unlimited prepaid data plan in general back in November. I still have it, because I'm grandfathered in, but my understanding is that there's no new ones.
Still... half my reason for keeping it around has been in case the iPhone became more appealing to me. If they drop prepaid data for the iPhone, I think I'm done with them. I'd guess you can still make it work by unlocking, but if I'm going to have to unlock, there's nothing so compelling about their service that would keep me from using T-mobile prepaid instead.
Tweet, tweet.
is required to upgrade to 3.0. While its not a big deal for individual computers, in an office environment its not as trivial..another one of Apples (not so) subtle schemes to get you using a particular software version whether you like it or not? And the "new" features are pretty pathetic really, more like they should have been in the 2.0 version of the software.
So... let me get this straight, your office environment somehow includes lots and lots of people with iPhones, and this is a requirement (hence why you are apparently concerned with said phones being upgraded while at work). Meaning that, if I were to go out on a limb, the office at which you work, in some way, shape, or form, most likely specializes in iPhone app programming. Aaaaaand yet it does NOT have any sort of plan in place to upgrade iTunes (an important part of iPhone maintenance, which will update itself and alert you to this fact), not to mention the fact that this office is perfectly willing to stay behind a version of iPhone firmware in what is undeniably a viciously competitive market.
Alternatively, your office does NOT specialize in iPhone app development and you're just whining because you're too stubborn and/or paranoid and/or aimlessly idealistic to upgrade iTunes, and will most likely be bitching in a month or so anyway when some flaw is discovered in said program and it bites you hard because you heroically refused to upgrade iTunes for whatever reason seems right in your head.
Either way, I present a quote from the game Team Fortress 2 which, if I may be so bold to suggest, sums up the opinions of everyone who read your post: "CRY SOME MORE!!!"
another one of Apples (not so) subtle schemes to get you using a particular software version whether you like it or not
Or there's the part where the new functionality in the phone requires a new software version to control it? You know, as in, "we couldn't predict the future with iTunes 8.1 to know what it would need for the third-gen iPhone coming out next year".
I have an iPod touch, i was wondering if it was worth it to upgrade.
Probably for some of the improvements playing media, you should check a number of the lists and see if anything appeals. Also a number of new apps are going to take advantage of 3.0 and you'll quickly find you would like to upgrade.
I also wonder if these Safari bugs will be fixed in a 2.x update. Sucks to have to pay $10 to be secure
But that's the beauty of a system where a large majority (80%+) upgrades to new OS. You may have security exploit that could be used, but the reality is anyone looking to write an exploit would do so against 3.0 now as there will be hardly anyone using 2.x to attack...
A security vulnerability is a combination of the ease of performing the exploit and the desirably of doing so by an attacker. A Touch is already less likely to be exploited because it doesn't make a good zombie client (network shuts down with the screen). Then on top of that you'd have to trick a user to come to your site... in combination the odds against anyone taking advantage of this are astronomical.
"There is more worth loving than we have strength to love." - Brian Jay Stanley
If you think about it, while they don't happen at exactly the same time OS X does see about as many patches issued as the iPhone.
One thing throwing you off is that the newer Leopard has taken longer to come out with newer iPhone OS versions (like 1.x to 2.x).
They do, of course, share the same base OS but tend to sort of leapfrog each other a little as to versions of components used.
"There is more worth loving than we have strength to love." - Brian Jay Stanley
I must not be geeky enough, I'm tired of Iphone stories.
21st Century Renaissance Man
this upgrade is amazingly troublesome for user.i tried it today, and it was painful no end.
first they make you upgrade itunes (it must be that iphoneos3 requires special super-puper method of uploading that only itunes8.2 supports).
then they backup everything on the handset, but upon upgrade it breaks (it said something about device being lost, unexpectedly disconnected or something).
so the device is bricked, well, being restarted it shows "itunes and usb cable". when it's connected, itunes says "oh, the device is dead you need to restore it"... yeah, no shit!
when "restore" is pressed, it says "hey there's a new version, do you want to restore and update?". and there's no escape! there's no button "thanks but no thanks, just return me to yesterday". you either restore+update it or have it bricked. WTF?!!
once i upgraded itunes and started update, i cannot return back! and yeah, restore didn't work, i saw "preparing for restore" for 5 minutes and then bah "unknown error #1604, have a nice day". windows' restart usually heals everything, but not in this case! their web page offers to clean usb socket, re-install windows' usb drivers, yeah, right...
lucky me, i had co-worker with older itunes and iphoneos2.2 so i was able to return it to 2.2. i think it's enough of experience. mms and rotated keyboard... well i hope i'll get it with 3.1, by that time it maybe will update.
Originally I was getting this message as well, which is why I called them in the first place. The techs told me that they were enabling the feature gradually (pushing some sort of update to the phone?) and that it would be available nationwide tomorrow (Friday).
I know... this doesn't change the fact they charge for iPod firmware updates -- and Apple's reasoning is certainly open to well-deserved criticism -- but they lay the blame squarely on the Sarbanes-Oxley act.
From what I understand, SOX is a law that intends to make public companies more accountable to share holders. Apple has interpreted SOX in such a way that it feels as though it *must* charge for updates which unleash new features that substantially increase the potential value of the device. This appears to be applicable to virtually all hardware-enabling features and reasonably 'novel' software features. 3.0 is such an update.
Why doesn't this affect the iPhone? That's because the iPhone is a subscription-based device. As such, it continually generates profit for the company and its shareholders. The iPod Touch has no subscription, meaning that anytime Apple unleashes a new set of big features for free, they supposedly have "cheated" shareholders by not releasing a new product instead. To generate revenue, they charge for the update. The idea is this keeps them in compliance with SOX by generating extra revenue for 'shareholders'. Obviously, Apple is making a profit, but I understand SOX compliance also costs big companies millions of dollars in fees (lawyers, accountants and God knows what else)... Who knows. And remember: Minor updates are supposedly fine; major updates are supposedly not fine -- although I'm not sure who the legally viable arbiter of that decision would be, exactly.
Like it or not... Believe it or not... It's the way Apple has dealth with this. Incidentally, it's the same reason they charged $2.99 for 802.11n support on Macbooks through Software Updater.
Fact: Everything I say is fiction.
.
In other news, for at least 3 months, hackers exploiting Nils technique walked away with a few hundred thousand via identity theft, atm fraud, password access, etc...
Shit, that's reassuring.
who says you *have* to use it? i use itunes elusively for iPhone updates. nothing requires you to use the software for mp3s or anything else.
If you're in a corporate environment and don't have Administrator access, you can't install the newest version of iTunes, which means you can't use iTunes for iPhone updates, regardless of whether you want to use it to play music.
$x='S24;r)>63/* h@<5+oZ)32"5cz';$me='phroggy'x$];
$x=~y+ -xz+\0-Tx+;print$_^chop$me for split'',$x;
Apple: iPhone 3.0 Update Delivers Pompous Patch Batch There, all better now. Continue commenting.
I have a G3 iPhone and I just upgraded to the 3.0 software. Anybody else done this and notice that about 99% of your apps do not work? You select them the phone goes to a dark screen and then back to the app desktop. Is there any way to step back from the 3.0 software?
How is your stupid corporate IT policy Apple's fault again?