<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: iHacker Charlie Discloses iPhone SMS Security Vulnerability</title>
	<atom:link href="http://www.imore.com/2009/07/03/ihacker-charlie-discloses-iphone-sms-security-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.imore.com/2009/07/03/ihacker-charlie-discloses-iphone-sms-security-vulnerability/</link>
	<description>More of everything iPhone and iPad</description>
	<lastBuildDate>Fri, 10 Feb 2012 15:56:26 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Phil P</title>
		<link>http://www.imore.com/2009/07/03/ihacker-charlie-discloses-iphone-sms-security-vulnerability/comment-page-1/#comment-62336</link>
		<dc:creator>Phil P</dc:creator>
		<pubDate>Mon, 13 Jul 2009 21:28:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=9713#comment-62336</guid>
		<description>&lt;p&gt;@Dev&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;I hope it does require user interaction&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Not likely. Consider what two parts do: GPS location, turn microphone on.  Law Enforcement snooping, anyone?&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>@Dev</p>

<blockquote>
  <p>I hope it does require user interaction</p>
</blockquote>

<p>Not likely. Consider what two parts do: GPS location, turn microphone on.  Law Enforcement snooping, anyone?</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Dev</title>
		<link>http://www.imore.com/2009/07/03/ihacker-charlie-discloses-iphone-sms-security-vulnerability/comment-page-1/#comment-60560</link>
		<dc:creator>Dev</dc:creator>
		<pubDate>Sat, 04 Jul 2009 00:32:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=9713#comment-60560</guid>
		<description>&lt;p&gt;@icebike&lt;/p&gt;

&lt;p&gt;I hope it does require user interaction, but, if it was a some type of protocol exploit in Safari you would think Miller would have framed it as such, or at least indicated it was exploitable through Safari, rather than single out SMS. Or maybe it was a sensationalist hook - we will find out soon enough.  Or better yet, we won&#039;t until after it has been patched :)&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>@icebike</p>

<p>I hope it does require user interaction, but, if it was a some type of protocol exploit in Safari you would think Miller would have framed it as such, or at least indicated it was exploitable through Safari, rather than single out SMS. Or maybe it was a sensationalist hook &#8211; we will find out soon enough.  Or better yet, we won&#8217;t until after it has been patched <img src='http://www.imore.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>]]></content:encoded>
	</item>
	<item>
		<title>By: icebike</title>
		<link>http://www.imore.com/2009/07/03/ihacker-charlie-discloses-iphone-sms-security-vulnerability/comment-page-1/#comment-60482</link>
		<dc:creator>icebike</dc:creator>
		<pubDate>Fri, 03 Jul 2009 17:48:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=9713#comment-60482</guid>
		<description>&lt;p&gt;The likelihood that simply receiving a text message could compromise the phone seems infantessimily small to me.&lt;/p&gt;

&lt;p&gt;After all, the message is simply TEXT, its DATA, and a good operating system never EXECUTES data.&lt;/p&gt;

&lt;p&gt;To do so would be a monumental blunder, and I just don&#039;t think Apple programmers are that stupid.  &lt;/p&gt;

&lt;p&gt;So my bet is that the SMS has to launch something else (probably Safari) by a physical action of the user, like when you get a URL in a SMS and you launch it.&lt;/p&gt;

&lt;p&gt;This seems far more likely to be a bug in Safari, and sms is simply a way to get lots of people to click a link.&lt;/p&gt;

&lt;p&gt;That being said, I agree with @Dev re:&lt;/p&gt;

&lt;blockquote&gt;
  &lt;p&gt;&quot;Apple’s only known motivational button&quot;.  &lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;All too often, the only way you can get Apple to do the right thing is embarrass them in the mainstream press.&lt;/p&gt;

&lt;p&gt;If I were wearing my TinFoil hat, AND if we were talking about Microsoft, I would speculate on a back door access method based on specific SMS message structure having been intentionally built into the software.&lt;/p&gt;

&lt;p&gt;But my tinfoil hat is at the cleaners, and Apple &quot;would never be evil&quot;....  http://mooseyard.com/Jens/?p=163&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>The likelihood that simply receiving a text message could compromise the phone seems infantessimily small to me.</p>

<p>After all, the message is simply TEXT, its DATA, and a good operating system never EXECUTES data.</p>

<p>To do so would be a monumental blunder, and I just don&#8217;t think Apple programmers are that stupid.  </p>

<p>So my bet is that the SMS has to launch something else (probably Safari) by a physical action of the user, like when you get a URL in a SMS and you launch it.</p>

<p>This seems far more likely to be a bug in Safari, and sms is simply a way to get lots of people to click a link.</p>

<p>That being said, I agree with @Dev re:</p>

<blockquote>
  <p>&#8220;Apple’s only known motivational button&#8221;.  </p>
</blockquote>

<p>All too often, the only way you can get Apple to do the right thing is embarrass them in the mainstream press.</p>

<p>If I were wearing my TinFoil hat, AND if we were talking about Microsoft, I would speculate on a back door access method based on specific SMS message structure having been intentionally built into the software.</p>

<p>But my tinfoil hat is at the cleaners, and Apple &#8220;would never be evil&#8221;&#8230;.  <a href="http://mooseyard.com/Jens/?p=163" rel="nofollow">http://mooseyard.com/Jens/?p=163</a></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Travis</title>
		<link>http://www.imore.com/2009/07/03/ihacker-charlie-discloses-iphone-sms-security-vulnerability/comment-page-1/#comment-60452</link>
		<dc:creator>Travis</dc:creator>
		<pubDate>Fri, 03 Jul 2009 15:39:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=9713#comment-60452</guid>
		<description>&lt;p&gt;Thanks for the mention Rene... And yea get a life seriously&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Thanks for the mention Rene&#8230; And yea get a life seriously</p>]]></content:encoded>
	</item>
	<item>
		<title>By: dev</title>
		<link>http://www.imore.com/2009/07/03/ihacker-charlie-discloses-iphone-sms-security-vulnerability/comment-page-1/#comment-60440</link>
		<dc:creator>dev</dc:creator>
		<pubDate>Fri, 03 Jul 2009 14:44:53 +0000</pubDate>
		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=9713#comment-60440</guid>
		<description>&lt;p&gt;The &quot;good of the many&quot; is never served by pretending a problem does not exist.  Good security auditors that if an exploit is discovered, you must assume is present in the wild, and act accordingly.  Rene&#039;s entire premise is based on the assumption that Miller is the first and only person to discover this vulnerability.  That assumption is a fool&#039;s approach to security, a comforting illusion only.&lt;/p&gt;

&lt;p&gt;This vulnerability -- a process that runs at root (!) executing arbitrary code in response to an unsolicited message from the outside -- is far too severe to pretend Miller is the only one who noticed, and wait until Apple gets around to patching it.&lt;/p&gt;

&lt;p&gt;Apple has demonstrated time and time again their willingness to use NDAs and gag orders to stifle everything from software discussion to contract issues, rather than fix the issue at hand promptly.  If anything, Miller has done our community the best possible favor -- by announcing it publicly, he pushes Apple&#039;s only known motivational button to fix the issue promptly, and by not announcing implementation details, he does not give script kiddies a head start.  Kudos to Miller.&lt;/p&gt;

&lt;p&gt;Apple -- the ball is in your court.  You have a severe vulnerability in your most popular platform.  Prove that this time you will not plug your ears and blame others.  Fix your problem.  Now.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>The &#8220;good of the many&#8221; is never served by pretending a problem does not exist.  Good security auditors that if an exploit is discovered, you must assume is present in the wild, and act accordingly.  Rene&#8217;s entire premise is based on the assumption that Miller is the first and only person to discover this vulnerability.  That assumption is a fool&#8217;s approach to security, a comforting illusion only.</p>

<p>This vulnerability &#8212; a process that runs at root (!) executing arbitrary code in response to an unsolicited message from the outside &#8212; is far too severe to pretend Miller is the only one who noticed, and wait until Apple gets around to patching it.</p>

<p>Apple has demonstrated time and time again their willingness to use NDAs and gag orders to stifle everything from software discussion to contract issues, rather than fix the issue at hand promptly.  If anything, Miller has done our community the best possible favor &#8212; by announcing it publicly, he pushes Apple&#8217;s only known motivational button to fix the issue promptly, and by not announcing implementation details, he does not give script kiddies a head start.  Kudos to Miller.</p>

<p>Apple &#8212; the ball is in your court.  You have a severe vulnerability in your most popular platform.  Prove that this time you will not plug your ears and blame others.  Fix your problem.  Now.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: AnteL0pe</title>
		<link>http://www.imore.com/2009/07/03/ihacker-charlie-discloses-iphone-sms-security-vulnerability/comment-page-1/#comment-60435</link>
		<dc:creator>AnteL0pe</dc:creator>
		<pubDate>Fri, 03 Jul 2009 14:29:00 +0000</pubDate>
		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=9713#comment-60435</guid>
		<description>&lt;p&gt;@Joe. Yeah he sure is an idiot finding these holes that apples entire sec team couldn&#039;t, and letting them know so they can be patched.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>@Joe. Yeah he sure is an idiot finding these holes that apples entire sec team couldn&#8217;t, and letting them know so they can be patched.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Brad Zimmerman</title>
		<link>http://www.imore.com/2009/07/03/ihacker-charlie-discloses-iphone-sms-security-vulnerability/comment-page-1/#comment-60421</link>
		<dc:creator>Brad Zimmerman</dc:creator>
		<pubDate>Fri, 03 Jul 2009 13:16:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=9713#comment-60421</guid>
		<description>&lt;p&gt;Considering Apple&#039;s ham-fisted and heavy-handed approach with developers I suspect that they wanted a six month period during which they could, at their own pace, fix this problem and maybe figure out how to sue someone for messing with their baby.&lt;/p&gt;

&lt;p&gt;Now, Miller hasn&#039;t fully published this exploit.  He HAS informed Apple of it.  He is supposed to fully publish it at the upcoming Black Hat/DEF CON conference.  &lt;/p&gt;

&lt;p&gt;Apple has plenty of time to push a fix out.  And since Miller isn&#039;t necessarily the world&#039;s foremost code-explorer you can probably safely bet that there are others who have independently discovered this vulnerability.  &lt;/p&gt;

&lt;p&gt;So, do you want Apple to take their sweet time or would you prefer that the &quot;black hats&quot; put a fire under Apple so we all get patched sooner rather than later?&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Considering Apple&#8217;s ham-fisted and heavy-handed approach with developers I suspect that they wanted a six month period during which they could, at their own pace, fix this problem and maybe figure out how to sue someone for messing with their baby.</p>

<p>Now, Miller hasn&#8217;t fully published this exploit.  He HAS informed Apple of it.  He is supposed to fully publish it at the upcoming Black Hat/DEF CON conference.  </p>

<p>Apple has plenty of time to push a fix out.  And since Miller isn&#8217;t necessarily the world&#8217;s foremost code-explorer you can probably safely bet that there are others who have independently discovered this vulnerability.  </p>

<p>So, do you want Apple to take their sweet time or would you prefer that the &#8220;black hats&#8221; put a fire under Apple so we all get patched sooner rather than later?</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Joe</title>
		<link>http://www.imore.com/2009/07/03/ihacker-charlie-discloses-iphone-sms-security-vulnerability/comment-page-1/#comment-60405</link>
		<dc:creator>Joe</dc:creator>
		<pubDate>Fri, 03 Jul 2009 11:49:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.theiphoneblog.com/?p=9713#comment-60405</guid>
		<description>&lt;p&gt;That hacker is an idiot. Get a life and a real job.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>That hacker is an idiot. Get a life and a real job.</p>]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached

Served from: imore.com @ 2012-02-10 11:01:52 -->
