Feeds

Sweet murmuring Siri opens stalker vulnerability hole in iOS 7

'Siri, hand over my contacts and history now…'

Next gen security for virtualised datacentres

It has not been a good week for Apple on the security front, and there's no relief in sight after an Israeli researcher found a way to access a locked iPhone's contacts and messages database using Siri.

In a YouTube video, Dany Lisiansky showed how a locked phone running iOS 7.0.2 can be opened by using Siri's voice control to make a call to an attacker's system. This "feature" then allows an attacker to access the target handset's Phone application, giving access to call history, voicemail, and entire list of contacts by following seven steps:

1. Make a phone call (with Siri / Voice Control).

2. Click the FaceTime button.

3. When the FaceTime App appears, click the Sleep button.

4. Unlock the iPhone.

5. Answer and End the FaceTime call at the other end.

6. Wait a few seconds.

7. Done. You are now in the phone app.

"It's easy to imagine how this vulnerability could be exploited by a business rival or a jealous romantic partner," commented security watcher Graham Cluley.

Cupertino has made security a big selling point for its latest mobes, even going as far as recruiting the New York Police Department to hand out leaflets urging Apple users to upgrade to iOS 7. But the handset has also been targeted by researchers and found wanting, not to mention unsettling to the stomach.

It took the Chaos Computer Club only three days to defeat the new iPhone's fingerprint scanner, using a fingerprint printout and some latex wood glue. Chinese Apple users showed one possible way around this – using their nipples instead – but that's unlikely to take off for most users.

Shortly afterwards, attackers found a way to bypass the lock screen using Apple's Control Center, albeit with some nifty fingerwork. That led to Tim Cook's security engineers spending a few sleepless nights, and they pushed out an update on Thursday – but a day later Lisiansky found a way to crack the update.

With over 200 million Apple users now using iOS 7, with no way to remove the upgrade, it looks like there could be another update in the pipes soon if iPhone users are going to have their privacy protected.

In the meantime, users are advised to turn off Siri's ability to work while the handset is locked by going launching the Settings app, tapping General > Passcode Lock, turning Passcode on if it isn't already, then toggling Siri off under Allow Access When Locked. ®

The essential guide to IT transformation

More from The Register

next story
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
prev story

Whitepapers

Top 10 endpoint backup mistakes
Avoid the ten endpoint backup mistakes to ensure that your critical corporate data is protected and end user productivity is improved.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Backing up distributed data
Eliminating the redundant use of bandwidth and storage capacity and application consolidation in the modern data center.
The essential guide to IT transformation
ServiceNow discusses three IT transformations that can help CIOs automate IT services to transform IT and the enterprise
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.