Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Locked iPhones can be unlocked without a password

By Peter Sayer , IDG News Service , 08/27/2008
  • Share/Email
  • Comment
  • Print

Private information stored in Apple's iPhone and protected by a lock code can be accessed by anyone with just a few button presses.

The iPhone, like most mobile phones, can be locked with a four-digit code, but where other phones in their locked state only permit calls to emergency service numbers such as 911 (in the U.S.), 999 (in the U.K.) and 112 (throughout Europe), a locked iPhone can be used to make a call to any number.

However, that's not all you can do with a locked iPhone running the latest version of Apple's software, 2.0.2.

Pressing the emergency call button at the unlock screen, followed by two taps on the home button, takes you to the iPhone's private 'favorites' page without the need to enter the unlock code. If the owner of the phone has favorite entries in their address book containing URLs, e-mail addresses or mobile phone numbers, then those entries can be used to launch the browser, mail application or SMS (Short Message Service) software and gain access to private Web favorites, e-mail messages and text messages stored in the phone, again without entering the unlock code.

The security flaw, revealed by a member of the MacRumors.com forum, came as a surprise to an Apple spokeswoman in London, who said she would look into the matter.

One way to avoid such unauthorized access to e-mail messages or Web favorites would be not to add e-mail addresses or URLs to favorite address book entries.

Apple pushed version 2.0 of its iPhone software as being more enterprise-friendly: some businesses had been reluctant to adopt the first version of the iPhone because it did not adequately protect corporate information stored in the device.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comments (6)
Login
Forgot your account info?

Bug ResponsesBy Anonymous on August 28, 2008, 3:09 pmWhile it's true that the response to software flaws by both Microsoft and Apple has been, well, dismal, perhaps we could all agree that they both suck in this regard. Linux...

Reply | Read entire comment

Gotta love half the story...By Anonymous on August 28, 2008, 11:13 amI enjoy it when only half the story gets reported. Other blog sites have already stated both that a quick change in mapping the double-press function eliminates...

Reply | Read entire comment

How is Microsoft's behaviour relevant?By Anonymous on August 28, 2008, 8:40 amI'd still pick the iPhone over any Windows Mobile device.

Reply | Read entire comment

Microsoft admits problems?By Schratboy on August 27, 2008, 6:04 pmMuahahahahahahahahaha! Microsoft admitting problems! Muauauauahahahahahahahahaha. Sure they admit they have problems and then continually issue new patches to correct...

Reply | Read entire comment

The difference between Apple and MicrosoftBy Anonymous on August 27, 2008, 5:14 pmAt least Microsoft admits that there are security problems. Apple refuses to see or take a security problem seriously even after a number have been discovered. As...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed