Feeds

Teen hacker re-unlocks Apple's iPhone

Gets firm with firmware

Securing Web Applications Made Simple and Scalable

A teen hacker known for his deftness with iPhones has figured out how to unlock models running the latest firmware versions by cracking a protection that has frustrated hackers for weeks.

The breakthrough by George Hotz, aka Geohot, means people who have bought a recent iPhone will once again be able to use it on the phone network of their choice. Apple makes as much as $400 for every handset that's activated on an approved network, so its developers have worked hard to prevent the so-called unlocking of iPhones.

Last year, 17-year-old Geohot was among the first group of hackers to break Apple's iron-fisted grasp on the iPhone, a coup that won him a Nissan 350Z and 3 8GB iPhones. Apple promptly responded by issuing updated firmware that stymied such efforts. Not only did the updates disable modified phones, effectively turning them into $400 bricks, they also prevented unlocking software from working in many cases. The arms race has persisted ever since.

The latest salvo was fired late last week, following a 24-hour hacking spree by Geohot that was broken up by only three hours of sleep. It turns out the latest firmware contained modifications to the device's memory registers to prevent unlocking. Geohot worked around those changes by finding another, much higher register that was vulnerable.

"I guess Apple thought big numbers were harder to guess," he wrote.

He then found a way to install his custom-built code by exploiting a flaw that allowed him to erase a range of memory addresses where security software is stored.

"The technique was not one that I was familiar with at all," said Kevin Finisterre, a researcher who has spent a fair amount of time dissecting Apple devices. "From the read it sounds as though the gentleman has made some significant progress. More importantly he is sharing."

This latest unlocking is no small accomplishment because iPhones are programmed to accept only approved SIM cards. Geohot's technique appears to work around this limitation by writing to certain sections of the firmware.

The hack is highly technical and by no means for the faint of heart. Those iPhone owners in need of more hand-holding should check out step-by-step instructions here from iClarified. ModMyiPhone also offers a tutorial here.

Several weeks ago, analysts at Bernstein Research estimated that 1 million iPhones, or a full 27 per cent of the handsets sold to date, are running on unauthorized networks. At that rate, Apple could lose $1bn in revenue over the next two years. Rest assured that developer drones in Cupertino are already laboring to circumvent this latest workaround. ®

Mobile application security vulnerability report

More from The Register

next story
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
NUDE SNAPS AGENCY: NSA bods love 'showing off your saucy selfies'
Swapping other people's sexts is a fringe benefit, says Snowden
Own a Cisco modem or wireless gateway? It might be owned by someone else, too
Remote code exec in HTTP server hands kit to bad guys
British data cops: We need greater powers and more money
You want data butt kicking, we need bigger boots - ICO
Crooks fling banking Trojan at Japanese smut site fans
Wait - they're doing online banking with an unpatched Windows PC?
NIST told to grow a pair and kick NSA to the curb
Lrn2crypto, oversight panel tells US govt's algorithm bods
prev story

Whitepapers

Reducing security risks from open source software
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.