-
08-12-2010, 12:03 PM #1MMi Staff Writer
- Join Date
- Aug 2009
- Location
- Union Square, Somerville, Mass.
- Posts
- 919
- Thanks
- 6
- Thanked 996 Times in 401 Posts
Panic as @comex Releases JailbreakMe Source

In a move that is sparking hysterical reactions from mainstream journalists and tech bloggers, the Dev-Team's @comex has released the source code of his JailbreakMe "star" exploit, which made use of vulnerabilities recently patched by Apple in iOS versions 4.0.2 and 3.2.2. With pundits calling the public release of @comex's work 'dangerous' and making dire predictions of imminent "attacks," one could wonder why Apple, Inc., which left second generation iPhones and first-generation iPod touches vulnerable in the new release, is being spared from criticism. The only recourse for users of older devices - of course - is to jailbreak.
JailbreakMe relies on a hole in Mobile Safari that lets @comex's code break out of the "sandbox" and get root on an iOS device. What 4.0.2/3.3.2 did was to patch the CFF hole and block @comex's IOSurface root escalation exploit... for any device that can run those versions of firmware, that is. Any device older than an iPhone 3G or a second-gen iPod touch is still out in the cold. In response, @saurik is working on a patch that will protect jailbroken devices. Until that Cydia package is ready, the tweak that @cdevwill created will pop up an alert if any other code attempts to use a similar exploit.
Which brings us to @comex's release. Mainstream tech news sites have reacted with shock and dismay, with Computerworld warning of the "evil uses" the now-useless exploit could be put to, darkly claiming that "It may not be long before comex's work is turned into a weapon for attacks that gain "root" access, or complete control, of iPhones and iPads." The article further cluelessly states that "Apple's desktop operating system includes the FreeType font engine." (It doesn't.) PCWorld puts the FUD right up front, in the title of an article posted at 5:40 am: "Malicious Attacks Coming Soon." PCWorld's Tony Bradley also somehow decrees that it's "ironic" that another Dev-Team member is working on a patch for the users that Apple ignored. Is that like rain on your wedding day, or a free ride when you've already paid, Bradley?
The benefit of open systems to improving security has been clear for some time, at least to experts who don't work at One Infinite Loop. Whitfield Diffie, one of the inventors of of public-key cryptography and the former head of security at Sun Microsystems, calls BS on software makers' claim their code is more secure because it's secret. As Diffie wrote in Risky Business: Keeping Security a Secret, "it's simply unrealistic to depend on secrecy for security in computer software." Until Apple opens its system, the only way to find and fix the vulnerabilities is through the efforts of people like @comex and Charlie Miller. All the hysteria is just a case of blaming the messenger, rather than focusing on the real security problem in iOS: secrecy.Last edited by Paul Daniel Ash; 08-12-2010 at 12:06 PM.
-
The Following 10 Users Say Thank You to Paul Daniel Ash For This Useful Post:
-
08-12-2010, 12:05 PM #2
I support comex's decision. Open is better
-
The Following 5 Users Say Thank You to ambo For This Useful Post:
coolguy742 (08-12-2010), Dash-2 (08-12-2010), milesneptune (08-13-2010), ProZack27 (08-12-2010), rkisling (08-12-2010)
-
08-12-2010, 12:06 PM #3
Scariesssss
-
The Following User Says Thank You to zoomspeed05 For This Useful Post:
SirTimothy1 (08-12-2010)
-
08-12-2010, 12:09 PM #4
I'm sure he has his reasons for releasing it.
-
08-12-2010, 12:12 PM #5Green Apple
- Join Date
- Dec 2009
- Location
- Bathroom stall
- Posts
- 95
- Thanks
- 4
- Thanked 20 Times in 15 Posts
Isn't this what it has been from the beginning?! Exposing the weaknesses and creating freedom! I admit the bad (or should I say wrong) press is still press nonetheless and definitely should put another kink into the chain that is Apple. Oddly enough with the news of no longer "illegal" jailbreaking and unlocking Apple continues to proceed against it and forgetting the more important issues that seem to be common around threads: the "death grip" and proximity sensors. I think for such a big company it's time to face the reality and embrace what is going on and use this a gain/gain opportunity.
Last edited by tremerone; 08-12-2010 at 12:17 PM.
-
08-12-2010, 12:14 PM #6
So are we safe to jailbreak in Any danger?
-
08-12-2010, 12:14 PM #7Formerly Known As rpgpromaster
- Join Date
- Jun 2008
- Location
- UK
- Posts
- 1,794
- Thanks
- 490
- Thanked 672 Times in 358 Posts
what i cant see if it apple have patched it safari wouldnt emailing the pdf and opening it work and also syncing the pdf to ibooks????
Follow me on Twitter: EddieLeonard - - - - - - - -If i have helped in anyway at all, Please click the "Thanks!" button
Stalk me on FaceBook: Eddie Leonard
-
08-12-2010, 12:15 PM #8
Apple left an open hole,@comex screwed the hole and is telling/letting people how....Kinda saying "let's all screw Apple"
-
The Following User Says Thank You to gafu For This Useful Post:
Chere613 (08-13-2010)
-
08-12-2010, 12:17 PM #9
Locking my front door as we speak.
-
08-12-2010, 12:19 PM #10
Jailbreak users are safe as long as they install saurik's PDF Patch.
-
08-12-2010, 12:21 PM #11
Saurik has release the PDF-Patch it's up on Cydia
-
The Following User Says Thank You to dsg For This Useful Post:
s1l3nt (08-12-2010)
-
08-12-2010, 12:21 PM #12
OMFG we're ALL going to MF'n DIE!
lol
-
The Following 4 Users Say Thank You to Dizi For This Useful Post:
jwilky (08-12-2010), oOo ANDR3W oOo (08-19-2010), ProZack27 (08-12-2010), redwolf (08-12-2010)
-
08-12-2010, 12:22 PM #13
PDF patch is already out.
Pic: http://dl.dropbox.com/u/6747848/pdf.png
Why have Modmyi not reported this yet so more people know about it.
-
08-12-2010, 12:25 PM #14MMI's Official Devil Dog
- Join Date
- Mar 2009
- Location
- SC California
- Posts
- 561
- Thanks
- 5
- Thanked 44 Times in 36 Posts
Put the women and children to bed and lets go looking for dinner !!! I support his decision ..

-
08-12-2010, 12:27 PM #15Livin the iPhone Life
- Join Date
- Dec 2007
- Location
- England
- Posts
- 1,564
- Thanks
- 48
- Thanked 166 Times in 136 Posts
Everytime a jailbreak is released, it is achieved through a flaw in iOS which let's the user/hacker obtain root access, which would be described as a security flaw in iOS.
-
08-12-2010, 12:29 PM #16
Open is Def better!!!
-
08-12-2010, 12:36 PM #17
-
08-12-2010, 12:39 PM #18Livin the iPhone Life
- Join Date
- Sep 2008
- Location
- In a van down by ther river
- Posts
- 4,812
- Thanks
- 548
- Thanked 508 Times in 420 Posts
This is what Apple gets for being lazy.
-
08-12-2010, 12:44 PM #19
@chpwn
Hey, security/antivirus companies: JailbreakMe exploits the browser, but it's /not/ malicious. Block actual bad sites, kthx.
-
08-12-2010, 12:44 PM #20
Why are we calling him @comex? This isn't Twitter
Name? whereswaldo
iDevice + Firmware? 32GB Black iPhone 4 iOS 5.0
Computer + OS? Dell Inspiron 15R 2nd Gen i5, 2.3 Ghz, 750GB HDD, 8GB RAM Windows 7 HP
Location? Toronto
Found yet? No
-
The Following User Says Thank You to whereswaldo For This Useful Post:
ggab (08-12-2010)



LinkBack URL
About LinkBacks
Reply With Quote

