iOS 7 Bug Lets Anyone Bypass iPhone’s Lockscreen To Hijack Photos, Email, Or Twitter
By Andy Greenberg
Forbes Staff
9/19/2013
Forget the debate around the security or insecurity of the iPhone 5s’s
fingerprint reader. The latest version of the iPhone’s operating system
currently offers a gaping hole in its old-fashioned passcode lockscreen.
Jose Rodriguez, a 36-year-old soldier living in Spain’s Canary Islands,
has found a security vulnerability in iOS 7 that allows anyone to bypass
its lockscreen in seconds to access photos, email, Twitter, and more. He
shared the technique with me, along with the video above.
As the video shows, anyone can exploit the bug by swiping up on the
lockscreen to access the phone’s “control center,” and then opening the
alarm clock. Holding the phone’s sleep button brings up the option to
power it off with a swipe. Instead, the intruder can tap “cancel” and
double click the home button to enter the phone’s multitasking screen.
That offers access to its camera and stored photos, along with the ability
to share those photos from the user’s accounts, essentially allowing
anyone who grabs the phone to hijack the user’s email, Twitter, Facebook
or Flickr account.
I tested the technique on an iPhone 5 running iOS 7, and it worked.
Rodriguez’s video shows it working on an iPad, too. It’s not yet clear if
the same exploit can bypass the lockscreen of an iPhone 5s or 5c, but
Rodriguez tells me he believes it will. I’ve reached out to Apple for
comment and I’ll update this post if I hear from the company. Update: A
spokesperson from Apple tells me that the company “takes security very
seriously and we’re aware of this issue. We’ll deliver a fix in a future
software update.”
[…]
http://www.forbes.com/sites/andygreenberg/2013/09/19/ios-7-bug-lets-anyone-bypass-iphones-lockscreen-to-hijack-photos-email-or-twitter/
Tag: technology
Twitter posts inaccurately high metrics about its ads, changes them after questions
THEY LIED and got called out for it.
The blog posted bad metrics Wednesday, then posted new metrics after those numbers were questioned, then explained the changes today.
Twitter claimed that an advertiser received 25 times the number of tweets it actually received and it inflated another metric by 680 million until the San Francisco Chronicle double checked the company’s figures. Jeff Elder at the “The Tech Chronicles” on SFGate.com reported: Twitter posts inaccurately high metrics about its ads, changes them after questions.
It’s not clear what caused the changes from the earlier inaccurately high figures, only that the figures changed after SFGate asked about London Fashion Week metrics. A Topsy rep said she didn’t know if the company discussed the figures with Twitter after questions from SFGate.
A Twitter rep said the company is looking into it.
article
Jeff Elder is the social media lead for SFGate and The San Francisco Chronicle. Connect with him on Twitter here: @jeffelder.
Stop using NSA-influenced code in our products, RSA tells customers
Firm “strongly recommends” customers stop using RNG reported to contain NSA backdoor.
by Dan Goodin – Sept 19 2013, 7:43pm EDT
Officials from RSA Security are advising customers of the company’s BSAFE toolkit and Data Protection Manager to stop using a crucial cryptography component in the products that was recently revealed to contain a backdoor engineered by the National Security Agency.
An advisory sent to select RSA customers on Thursday confirms that both products by default use something known as Dual EC_DRBG when creating cryptographic keys. The specification, which was approved in 2006 by the National Institute of Standards and Technology (NIST) and later by the International Organization for Standardization, contains a backdoor that was inserted by the NSA, the New York Times reported last week. RSA’s advisory came 24 hours after Ars asked the company if it intended to warn BSAFE customers about the deliberately crippled pseudo random number generator (PRNG), which is so weak that it undermines the security of most or all cryptography systems that use it.
“To ensure a high level of assurance in their application, RSA strongly recommends that customers discontinue use of Dual EC DRBG and move to a different PRNG,” the RSA advisory stated. “Technical guidance, including how to change the default PRNG in most libraries, is available in the most current product documentation” on RSA’s websites.
The BSAFE library is used to implement cryptographic functions into products, including at least some versions of the McAfee Firewall Enterprise Control Center, according to NIST certifications. The RSA Data Protection Manager is used to manage cryptographic keys. Confirmation that both use the backdoored RNG means that an untold number of third-party products may be bypassed not only by advanced intelligence agencies, but possibly by other adversaries who have the resources to carry out attacks that use specially designed hardware to quickly cycle though possible keys until the correct one is guessed.
McAfee representatives issued a statement that confirmed the McAfee Firewall Enterprise Control Center 5.3.1 supported the Dual_EC_DRBG, but only when deployed in federal government or government contractor customer environments, where this FIPS certification has recommended it. The product uses the newer SHA1 PRNG random number generator in all other settings.
The NIST certification page lists dozens of other products that also use the weak RNG. Most of those appear to be one-off products. More significant is the embrace of BSAFE as the default RNG, because the tool has the ability to spawn a large number of derivative crypto systems that are highly susceptible to being broken.
< – >
http://arstechnica.com/security/2013/09/stop-using-nsa-influence-code-in-our-product-rsa-tells-customers/
The U.S.'s crap infrastructure threatens the cloud
The U.S.’s crap infrastructure threatens the cloud
Thanks to state-sponsored cable/phone duopolies, U.S. broadband stays slow and expensive — and will probably impede cloud adoption
By Andrew C. Oliver
Sep 19 2013
<http://www.infoworld.com/d/application-development/the-uss-crap-infrastructure-threatens-the-cloud-226917>
According to the broadband testing firm NetIndex, U.S. consumer broadband speeds rank 33rd in the world, right behind the Ukraine. Personally, I pay more than $1,500 per month for 30/30MB fiber for our office. This is ridiculously expensive and slower than the average household Internet in many other countries. It’s a serious impediment to the United States maintaining its economic competitiveness — and to enabling all of us to take full advantage of the cloud, which is clearly the next phase of computing.
As a patriotic American, I find the current political atmosphere where telecom lobbyists set the agenda to be a nightmare. All over the world, high-end fiber is being deployed while powerful monopolies in the United States work to prevent it from coming here. Some of those monopolies are even drafting “model legislation” to protect themselves from both community broadband and commercial competition.
Poor laws and regulations have protected a duopoly in most areas of the country. You can buy Internet from the local cable monopoly or the local phone monopoly, period. Neither have much motivation to make it much faster nor any cheaper.
Lobbying for lock-in
In my state, North Carolina, Time Warner Cable’s lobbying group managed to get our rather technology-unfriendly legislature to pass a horrible law to “protect private enterprise” by making it nearly impossible for local communities to build out their own municipal fiber without the burden of onerous regulations. Apparently, what’s good for Time Warner isn’t good for the rest of us. (Forgive me, but I don’t consider state-sponsored monopolies to be “private enterprise.”)
On its face, such mischief appears to be a local problem in the United States, with at least 20 states having passed legislation to protect Ma Bell and Pa Cable. But clearly, it’s a coordinated national effort. Multiple national lobbying organizations pretend to protect private business from unwarranted government competition, but are actually shielding large, state-sponsored, franchise monopolies.
For many small businesses, $1,500 per month is out of reach. In the case of my business, we expect to have to upgrade this connection pretty rapidly as we expand — and, sadly, pay even more. This kind of a cost, plus the speed disadvantage, puts us on an uneven playing field with similar companies in other countries. Plus, in some rural areas of my state and the rest of the country, there is no broadband at all.
[snip]