Your favorite Apple, iPhone, iPad, iOS, Jailbreak, and Cydia site.
08-12-2010, 12:03 PM #1
Panic as @comex Releases JailbreakMe Source
In a move that is sparking hysterical reactions from mainstream journalists and tech bloggers, the Dev-Team's @comex has released the source code of his JailbreakMe "star" exploit, which made use of vulnerabilities recently patched by Apple in iOS versions 4.0.2 and 3.2.2. With pundits calling the public release of @comex's work 'dangerous' and making dire predictions of imminent "attacks," one could wonder why Apple, Inc., which left second generation iPhones and first-generation iPod touches vulnerable in the new release, is being spared from criticism. The only recourse for users of older devices - of course - is to jailbreak.
JailbreakMe relies on a hole in Mobile Safari that lets @comex's code break out of the "sandbox" and get root on an iOS device. What 4.0.2/3.3.2 did was to patch the CFF hole and block @comex's IOSurface root escalation exploit... for any device that can run those versions of firmware, that is. Any device older than an iPhone 3G or a second-gen iPod touch is still out in the cold. In response, @saurik is working on a patch that will protect jailbroken devices. Until that Cydia package is ready, the tweak that @cdevwill created will pop up an alert if any other code attempts to use a similar exploit.
Which brings us to @comex's release. Mainstream tech news sites have reacted with shock and dismay, with Computerworld warning of the "evil uses" the now-useless exploit could be put to, darkly claiming that "It may not be long before comex's work is turned into a weapon for attacks that gain "root" access, or complete control, of iPhones and iPads." The article further cluelessly states that "Apple's desktop operating system includes the FreeType font engine." (It doesn't.) PCWorld puts the FUD right up front, in the title of an article posted at 5:40 am: "Malicious Attacks Coming Soon." PCWorld's Tony Bradley also somehow decrees that it's "ironic" that another Dev-Team member is working on a patch for the users that Apple ignored. Is that like rain on your wedding day, or a free ride when you've already paid, Bradley?
The benefit of open systems to improving security has been clear for some time, at least to experts who don't work at One Infinite Loop. Whitfield Diffie, one of the inventors of of public-key cryptography and the former head of security at Sun Microsystems, calls BS on software makers' claim their code is more secure because it's secret. As Diffie wrote in Risky Business: Keeping Security a Secret, "it's simply unrealistic to depend on secrecy for security in computer software." Until Apple opens its system, the only way to find and fix the vulnerabilities is through the efforts of people like @comex and Charlie Miller. All the hysteria is just a case of blaming the messenger, rather than focusing on the real security problem in iOS: secrecy.
Last edited by Paul Daniel Ash; 08-12-2010 at 12:06 PM.
The Following 10 Users Say Thank You to Paul Daniel Ash For This Useful Post:
08-12-2010, 12:05 PM #2
I support comex's decision. Open is better
08-12-2010, 12:06 PM #3
The Following User Says Thank You to zoomspeed05 For This Useful Post:
08-12-2010, 12:09 PM #4
I'm sure he has his reasons for releasing it.
08-12-2010, 12:12 PM #5
Isn't this what it has been from the beginning?! Exposing the weaknesses and creating freedom! I admit the bad (or should I say wrong) press is still press nonetheless and definitely should put another kink into the chain that is Apple. Oddly enough with the news of no longer "illegal" jailbreaking and unlocking Apple continues to proceed against it and forgetting the more important issues that seem to be common around threads: the "death grip" and proximity sensors. I think for such a big company it's time to face the reality and embrace what is going on and use this a gain/gain opportunity.
Last edited by tremerone; 08-12-2010 at 12:17 PM.
08-12-2010, 12:14 PM #6
So are we safe to jailbreak in Any danger?
08-12-2010, 12:14 PM #7
08-12-2010, 12:15 PM #8
Apple left an open hole,@comex screwed the hole and is telling/letting people how....Kinda saying "let's all screw Apple"
The Following User Says Thank You to gafu For This Useful Post:
08-12-2010, 12:17 PM #9
Locking my front door as we speak.
08-12-2010, 12:19 PM #10
Jailbreak users are safe as long as they install saurik's PDF Patch.
08-12-2010, 12:21 PM #11
Saurik has release the PDF-Patch it's up on Cydia
The Following User Says Thank You to dsg For This Useful Post:
08-12-2010, 12:21 PM #12
OMFG we're ALL going to MF'n DIE!
08-12-2010, 12:22 PM #13
- Join Date
- Mar 2010
- Thanked 2 Times in 1 Post
08-12-2010, 12:25 PM #14
Put the women and children to bed and lets go looking for dinner !!! I support his decision ..
08-12-2010, 12:27 PM #15
Everytime a jailbreak is released, it is achieved through a flaw in iOS which let's the user/hacker obtain root access, which would be described as a security flaw in iOS.
08-12-2010, 12:29 PM #16
08-12-2010, 12:36 PM #17
08-12-2010, 12:39 PM #18
This is what Apple gets for being lazy.
08-12-2010, 12:44 PM #19
08-12-2010, 12:44 PM #20
Why are we calling him @comex? This isn't TwitterName? whereswaldo
iDevice + Firmware? 32GB Black iPhone 4 iOS 5.0
Computer + OS? Dell Inspiron 15R 2nd Gen i5, 2.3 Ghz, 750GB HDD, 8GB RAM Windows 7 HP
Found yet? No
The Following User Says Thank You to whereswaldo For This Useful Post: