The Register® — Biting the hand that feeds IT

Comments on: Apple drags its heels on iPhone security patches

Huh? 

Posted Friday 4th July 2008 14:49 GMT

"Security watchers speculate that Apple has been focused on developing software for the next generation of the iPhone rather than addressing problems with version 1.x of the iPhone software."

Well... Seeing as 2.0 is a free upgrade, then surely working on that *is* addressing problems with version 1.x...?

Having known vulnerabilities unfixed sucks, but then at least there are regular upgrades with fixes included. Can't say that about most smartphones.

I'm shocked... 

Posted Friday 4th July 2008 15:08 GMT

...oh, hang on. No I'm not.

a little late for this news? 

Posted Friday 4th July 2008 15:10 GMT

Jobs Halo

surely the next version of this software will be version 2.0

that will be available for the original iPhone and the iPhone 3G

and it's rumoured to be released in 6days 14hours 52minutes and 25seconds

or are you just writing this article now so that in almost a week's time you can feel smug that Apple obviously listened to you?

Difference is.. 

Posted Friday 4th July 2008 15:25 GMT

Other handset manufacturers get around this by releasing phones with very crippled browsers that are secure by being next to useless.

Windows Mobile phones aren't updated that regularly either, in fact it is up to the handset OEM to produce a firmware upgrade. Often they don't as they want you to buy another handset.

Not saying Apple is right, but slow updates are fairly normal in the mobile arena.

@Huh? 

Posted Friday 4th July 2008 15:33 GMT

Paris Hilton

You can get the latest firmwares for almost any smartphone at service centres. Nokia now allow users to download new firmware and flash their phones from their PC at home. These all contain bugfixes and new features.

Paris flashes in public.

Service centre updates?! LOL 

Posted Friday 4th July 2008 16:20 GMT

Black Helicopters

Alas, getting service centre updates can be nigh on impossible if the carrier hasn't approved/added their own branded junk to (delete as appl.) it. Try asking Orange N95 owners about that one. For once, I think that Apple have done the right thing with this - Perhaps slower than a desktop security update, but a hell of a lot quicker than any S60/WM6 update...hell, do we really know what flaws are on those platforms.

That's all obviously assuming this flaw IS corrected in the new v.2.0! ;)

Apple Doesn't Know How Too Patch Wholes and Bugs .... 

Posted Friday 4th July 2008 16:43 GMT

Jobs Horns

But Apple SURE IS Good at creating them on everything from OS X, the iPhony to their own iApps. It's HISTORY and it's DOCUMENTED ... all you have to do is read any Apple Self-help site like macfixit and their archives.

Apple is 20 Times Worse than MS!

Pfft 

Posted Friday 4th July 2008 18:24 GMT

I'm more worried about the fact a guy at work can SSH into an iphone connected onto the same WIFI network as his PC, login as Root (using a username and password that is apparently the same on every single iPhone), and then, well, when you have root access, what can't you do?

Somebody... 

Posted Friday 4th July 2008 19:07 GMT

... hand Webster a towel. Uh, no, I see I'm late... somebody hand Webster a scraper.

iPhone? 

Posted Friday 4th July 2008 21:12 GMT

Stop

I thought the standard label was "JesusPhone"? Or has that become problematic since the second coming/ update?

@Pfft 

Posted Friday 4th July 2008 21:55 GMT

I could be wrong, but I believe you need to have jailbroken the iphone for that, and installed SSH - which, quite frankly, if you are doing all of that you need to reset the root password. It's more of a flaw with the application that is being installed, and less with the phone.

@Andy 

Posted Friday 4th July 2008 22:00 GMT

But the software is available for public release now. When the new phone goes on sale on the 11th, it will have 2.0 on it. Those units are in boxes sitting in a warehouse. So why hasn't Apple released the update to fix the issue?

Phew 

Posted Friday 4th July 2008 22:27 GMT

Happy

Phreaky is still around, I was getting worried.

Oh ok, im bored...

But Microsoft SURE IS Good at creating them on everything from Windows, the WinMobile to their own Office apps. It's HISTORY and it's DOCUMENTED ... all you have to do is read any Microsoft Self-help site like google and their archives.

Microsoft is 20 Times Worse than Apple!

I know you aren't supposed to feed the trolls 

Posted Friday 4th July 2008 22:29 GMT

But Webster, are you sure Apple are 20 times worse than MS?

That sounds like a suspiciously round number, and as such, it could be made up?

Are you sure that they aren't only 18.42x worse than MS?

@ Webster Phreaky 

Posted Saturday 5th July 2008 01:29 GMT

I wont bother to actually respond to your rant, but I would like to know why it would be necessary to patch a "whole".

I can only presume you meant to write:

" Apel dusn't no how 2 pach hols an bugs"

@Chad H. .... mmmm FUD for breakfast 

Posted Saturday 5th July 2008 04:15 GMT

Alien

..but don't forget a couple of oh so minor steps prior to logging in as root...

- Turn on OpenSSH on the iPhone

- Oh, but then you would mean you have to have OpenSSH installed first

- dang! that would mean you need to install the BSD Subsystem beforehand

- ahhhh and that would require to have a community repository on the iPhone too such as installer.app

- ding! to install installer.app the iPhone would have to be jailbroken right?

I mean, unless I missed Apples iPhone 'Hacker Edition' shipping with all this enabled, I cannot see how actively going through the (reverse) steps above is a security issue.

Any IT person who has gone through the above steps and requires OpenSSH on at all times, would actively set their root password, while a dumbass blindly following someones ego-driven blog online would also follow the instruction (that most tutorials post) to *change your root password* if using this feature. Either that or they will brick the fucken thing and create the most secure phone ever, one that doesn't work.

Finally, given a couple of days leaving OpenSSH on 24/7, any sane person would turn it off when not in use as it burns through batteries like a flaming leper doused in kerosene.

Cheers

SSH 

Posted Saturday 5th July 2008 06:24 GMT

Boffin

Chad, you can only SSH into an iPhone if you jailbreak it and install the ssh daemon. If you've done all that and not changed your password, you deserve what you get...

re: Pfft 

Posted Saturday 5th July 2008 07:41 GMT

but you can't just "SSH into an iphone connected onto the same WIFI network"

you have to have installed a cracked version of the firmware first to enable SSH

you can't complain that the guys iphone allows people root access because he's the one that's given it to them

iTwats 

Posted Saturday 5th July 2008 08:52 GMT

Paris Hilton

iTwats usually bleat about MicroShaft always having to release patches. So "The Jobbie" has to keep them happy by not releasing patches for his iCrappy software so often, maybe, for example, only when they release a brand new iPosingMirror. Well done for being security driven.

Paris, she knows how to drive securely.

Yawn 

Posted Saturday 5th July 2008 18:46 GMT

Funny how everyone is so eager to bash Apple and Apple products - yet there's no instance of a zombie iPhone or Mac yet. Why is a theoretical possibility that someday there just might possibly be some harm worth getting worked over?

And if you get worked up over that remote possibility, how can you help but go into cardiac arrest over the tens of millions of zombie Windows computers out there?

Knt pwn me 

Posted Saturday 5th July 2008 19:58 GMT

Thumb Down

When one of these actually causes some damage I might get interested. Frankly, having had Windows since 'MS-DOS Executive' I've NEVER been hit by anything on my Windows machines. I strongly doubt my sole OS X machine is going to be hit by these either, the sky is not falling : D

Second Grade Webster 

Posted Saturday 5th July 2008 20:12 GMT

Stop

Webster Phreaky blatthered: Apple Doesn't Know How Too Patch Wholes and Bugs

That's because they know how TO patch HOLES and bugs. Come on Webster, To, Two and Too are second grade lessons! When you learn that then MAYBE you might be justified in ragging on Apple. : D

<http://www.wisegeek.com/what-is-the-difference-between-to-two-and-too.htm>

@Chad 

Posted Sunday 6th July 2008 21:06 GMT

Just because you've got root access to an iPhone on a network doesn't mean you've got root access to the network.

RE: J Welek, and the assorted iBone fanbois 

Posted Monday 7th July 2008 10:02 GMT

Pirate

Actually, anyone, not just service personnel, can access Nokia firmware downloads. To check if there is a new firmware download fo rthe mentioned N95 then go to; http://www.nokia.co.uk/A4226014?N95_8GB.

But, to be honest, all Nokias I have used have had such a rubbish, over-compicated, menu-driven interface I would think anyone determined enough to hack it to have uber qualities of perseverence.

Windoze device users such as the many badged HTC devices, iPaqs and Axims, have the "pleasure" of multiple Windoze updates right from the earliest Windows CE (very aptly nicknamed "WinCE"). This is one reason that Windows Mobile devices are assessed at higher business security rating than the iBone.

Of course, business users (which are the people that actually need and value security) have had a fully-tested and automated solution that can automatically push out updates as required from long before the appearance of the iBone or Windoze Mobile, and carries the top business security rating. Please put your hands together for the business market leader (yes, that's the market that Jobs wants to get into), RIM's Blackberrys with Blackberry Enterprise Server.

Version 2 - Free? 

Posted Monday 7th July 2008 12:09 GMT

> Well... Seeing as 2.0 is a free upgrade, then surely working on that *is* addressing problems with version 1.x...?

It might be free for iPhone users, but going by past updates us iPod touch users (who are still vulnerable to the published exploit) will have to stump for the v2 upgrade.

I've got no compelling reason to update my firmware based on the features of v2 and I don't want to have to pay to get a security fix.

@ By Anonymous Coward and the other AppleTard 

Posted Tuesday 8th July 2008 16:57 GMT

Jobs Horns

See, the BEST the AppleTards can do is criticize a slip of the keyboard entry like the little juvenile punks they are, INSTEAD of offering any substance in a rebuttal. Reason being, THEY CAN'T!

Apple HAS BEEN branded by security experts and even some of their slightly brave whore media, as being TOO slow at patching; far worse than MS. That's Microsoft, not the Multiple Sclerosis you Apple Tards exhibit every time you open your saliva dripping pie holes. Of course you high and mighty never make a typo, do you perfect wonders of fantasy land?