• On BNET: Look like you're working
advertisement
October 8, 2008 12:00 AM PDT

iPhone SMS Privacy Flaw Discovered

by Ben Wilson
  • Font size
  • Print
  • 3 comments

Setting the iPhone to emergency call mode allows someone to see incoming text messages even if the passcode lock is turned on. A 12-year-old who uses his iPhone mostly for texting with his girlfriend has discovered what looks like a new vulnerability with the device.

The unnamed boy, son of blogger Karl Kraft, turns on the passcode lock and disables SMS Preview in order to prevent his parents from seeing any messages, Kraft wrote on his blog.

Those settings block the display of incoming text messages and show an alert saying "New Text Message" if an SMS comes through while the phone is locked. However, if the phone is set to emergency call mode the incoming text messages are previewed.

"Thus all I need to do to intercept the messages from his girlfriend is to place the phone in emergency mode and wait 30 seconds for the next sickly sweet message," Kraft writes.

Apple representatives did not return e-mails seeking comment. A different security hole related to password-protected iPhones was discovered in August, and last month a researcher disclosed that the iPhone captures all the activities of a user in order to enable the cool fading applications effect.

[Originally posted by Elinor Mills to our sister site, News.com[

Recent posts from iPhone Atlas
Motorola, RIM leading, with Apple on the rise
Tales2Go: Get on-demand audiobooks for children
iCatchall: 27 apps for free--Monday only
Caps lock--David's iPhone tip of the week
HouseKeeper app reminds you to do forgotten chores
App Genie: 27 apps for 99 cents
Apple extends iTunes Web previews to apps
Possible proof surfaces that iPad supports a camera
Add a Comment (Log in or register) (3 Comments)
  • prev
  • next
by flo_schi October 8, 2008 7:29 AM PDT
I just tried it and can tell you that this bug is already fixed in iPhone OS 2.2 Beta 1.
Reply to this comment
by jzdziarski October 9, 2008 6:30 AM PDT
Given that you can crack the passcode in about 60 seconds (see: iPhone Forensics, ISBN 978-0596153588), I fail to see why this is a big deal.
Reply to this comment
by vaughnsc October 14, 2008 8:46 AM PDT
@Jon: the nerve! (see ISBN 978-0071462020 LOL ) ;-)

@Article:

"iPhone captures ALL the activities of a user in order to enable the cool fading applications effect" (emphasis mine)

Let's not blow THAT out of proportion: the phone doesn't record EVERYTHING: upon returning to the Springboard, the OS just takes a screenshot of the application's 'last known state' to produce the zoom-in when it is relaunched.

If you're really that 'security-conscious,' just leave the screen in some innocuous state before closing it.
Reply to this comment
(3 Comments)
  • prev
  • next

Search iPhone Atlas

advertisement

About iPhone Atlas

iPhone Atlas helps you navigate the ins and outs of Apple iPhone ownership with how-tos, troubleshooting information, news, reviews, and more. Got a tip? Want to contact us? E-mail iphoneatlas@cnet.com.

Add this feed to your online news reader

iPhone Atlas topics