iPhone 3.0 Update Delivers Prodigious Patch Batch
CWmike writes "Apple patched 46 security vulnerabilities in the iPhone and iPod Touch, half of them in the Safari browser and its WebKit rendering engine, as it released iPhone OS 3.0 on Wednesday. One of the patched WebKit vulnerabilities stands out because of the attention it received in March, when a German college student, Nils, walked away with a $5,000 cash prize for hacking Safari at the Pwn2Own challenge. Nils used a bug in WebKit's handling of SVGList objects to crack Safari."
Frankly I don't know what all the hoopla about iPhone OS 3.0 is about. I was hoping to use compass with google map after the update on my iPhone 3G, but all I got was a lousy voice-memo software.
And before anyone points out that iPhone 3G didn't have compass built into the hardware - It is supposed to be apple! I expect nothing sort of miracles from Steve Jobs!!
On a serious note, tethering was supposed to be there without the need to jailbreak your phone, but it is not available in US, and it is not available in Germany. Could someone tell me where it is available? Phone companies are the scum that are only slightly worse than the music industry.
But when are they going to patch these security flaws on my 2.1 ipod? Paying for an update is ridiculous, especially when it fixes critical security flaws. I sure hope apple does the right thing.
Every hack in the competition was created early, and it was allowed within the rules to do so.
This made all the sensationalist "MAC CRACKED IN SECONDS" news/blogspam all the more annoying, and the _real_ news all the more painful. The real news was that the Safari exploit that the one dude used to win the Macbook Air had been around since the competition the year prior, and that he chose to save his exploit for the next years competition, and it wasn't fixed before he was able to use it for the CanSecWest 12 months later.