The ModMyTM Family of Sites:
ModMyMotoModMyiModMyGphone




 
 
Register or Connect with Facebook

Discuss AppStore Apps | Browse / Search Cydia | MMi Cydia Stats




  Apple Forums & iPhone Forums, Mods, Hacks, News, Themes, Downloads, and more! | ModMyi.com > 3rd Party Apps For iPhone | iPod Touch > Native iPhone / iPod Touch App Discussion
Closed Thread
 
LinkBack Thread Tools Display Modes
  #1  
Old 09-24-2008, 01:26 AM
Imahottguy's Avatar
Livin the iPhone Life
 
Join Date: Jul 2007
Device + Firmware: 3G[s] JB redsn0w 0.8
Operating System: Win XP
Location: Lansing, MI, USA
Posts: 1,192
Thanks: 42
Thanked 77 Times in 62 Posts
Send a message via MSN to Imahottguy
MAJOR SECURITY ISSUE - BossPrefs on f/w 2.0+

NOTE: I didn't see this topic posted anywhere...

We all know about the security issue at the emergency screen; An app set to double-tap will launch if one double taps at the emergency call screen (while the phone is locked). Ones' contacts, emails, etc are at risk. That's nothing compared to this 'hole'.

Under 'More' in BossPrefs, one can set the app to double tap, thus making it easier to access. It's very useful if you toggle your connections/hacks frequently. But by doing so, you are opening up your iphone completely.

Once set to double tap, lock the screen such that it requires your passcode to get back in (you may want to use the power menu on bossprefs to accomplish this if you have the phone set to require passcode after a specific interval). Now go to the emergency screen and double tap. What happens? BossPrefs launches. No big deal right? WRONG! Click the power button, and select fast respring, you are now back at the springboard, with complete, unrestricted access to the iPhone.

Setting bossprefs to double-tap compromises the iPhones security completely, for those who have your phone in hand.

Here's the deal: It's not just bossprefs- It's any app that does the 'fast respring' ie 'setting language' to get back to the springboard.

This is huge, spread the word.

HERE'S THE FIX: Install the five-icon dock from Saurik, add bossprefs to it, though you won't have such quick access, it will keep your phone secure.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks
  #2  
Old 09-24-2008, 02:20 AM
redcard's Avatar
Livin the iPhone Life
 
Join Date: Oct 2007
Device + Firmware: 3G 2.2
Operating System: Vista Ultimate
Location: Scotchland
Posts: 1,898
Thanks: 7
Thanked 175 Times in 158 Posts

Get a pocket. Keep phone in. Security issue averted.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks
The Following User Says Thank You to redcard For This Useful Post:
461am (09-24-2008)
  #3  
Old 09-24-2008, 02:26 AM
461am's Avatar
Livin the iPhone Life
 
Join Date: Aug 2008
Operating System: Windows XP | Mac OSX | Ubuntu
Location: Houston, TX
Posts: 1,241
Thanks: 28
Thanked 171 Times in 155 Posts

I concur.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks
  #4  
Old 09-24-2008, 03:23 AM
Imahottguy's Avatar
Livin the iPhone Life
 
Join Date: Jul 2007
Device + Firmware: 3G[s] JB redsn0w 0.8
Operating System: Win XP
Location: Lansing, MI, USA
Posts: 1,192
Thanks: 42
Thanked 77 Times in 62 Posts
Send a message via MSN to Imahottguy

Yes, and no. The point of the passcode is to keep prying eyes out. What if you lose your phone? Wouldn't you want it so the one who finds it doesn't get at your personal info? I would- but I guess I'm crazy. This is more of a forewarning than anything.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks
  #5  
Old 09-24-2008, 03:30 AM
461am's Avatar
Livin the iPhone Life
 
Join Date: Aug 2008
Operating System: Windows XP | Mac OSX | Ubuntu
Location: Houston, TX
Posts: 1,241
Thanks: 28
Thanked 171 Times in 155 Posts

well if I was that worried, I'd update to 2.1,and voila, no more need to set up elaborate safety mechanisms.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks
  #6  
Old 09-24-2008, 04:32 AM
My iPhone is a Part of Me
 
Join Date: Jun 2007
Posts: 745
Thanks: 16
Thanked 112 Times in 89 Posts

All of these ridiculous security "threats" have been beaten to death. Only about 3% of the iphone population gives a damn about them (Yes, that is a completely made up statistic that I just pulled out of my ***). Most people don't even passcode their phone, which would make all of the nonsense you just posted irrelevant because the "prying eyes" could just use the slide to unlock feature.

Quote:
This is huge, spread the word.
No.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks
  #7  
Old 09-24-2008, 05:58 AM
iPhoneaholic
 
Join Date: Dec 2007
Device + Firmware: Iphone 8gb Died :( Now have a Ipod Touch
Operating System: Windows xp +64, Vista +64 & Osx Leopard Dual booting
Location: West Yorkshire UK
Posts: 459
Thanks: 28
Thanked 26 Times in 25 Posts

If you was a smilie what would you be????

Please choose from the below contendents


Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks
  #8  
Old 09-24-2008, 07:27 AM
Imahottguy's Avatar
Livin the iPhone Life
 
Join Date: Jul 2007
Device + Firmware: 3G[s] JB redsn0w 0.8
Operating System: Win XP
Location: Lansing, MI, USA
Posts: 1,192
Thanks: 42
Thanked 77 Times in 62 Posts
Send a message via MSN to Imahottguy

Quote:
Originally Posted by Jasper44 View Post
All of these ridiculous security "threats" have been beaten to death. Only about 3% of the iphone population gives a damn about them (Yes, that is a completely made up statistic that I just pulled out of my ***). Most people don't even passcode their phone, which would make all of the nonsense you just posted irrelevant because the "prying eyes" could just use the slide to unlock feature.


No.
I'm sorry, for a second there, I thought that your reply was going to actually go somewhere other than the 'I don't use it so everyone else does not too' tool approach. And instead of coming in to this thread with sand in your man-vagina, you could could wash a little better. At least then you wouldn't sound like the idiot that you are. By the way, you don't sound like that much of an aficionado of the iphone, so hows about you do us all a favor and buy a zune (and castrate yourself)
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks
  #9  
Old 09-24-2008, 08:14 AM
Cocchiararo's Avatar
iPhone? More like MyPhone
 
Join Date: Dec 2007
Posts: 273
Thanks: 2
Thanked 14 Times in 14 Posts

but the guy has a point, its NOT a security threat if you dont even use paslock or whatever is called :P

thread title should be changed, cause it makes people enter thinking they might have they iphone explode or something with bossprefs :P
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks
  #10  
Old 09-24-2008, 08:33 AM
bhz1's Avatar
Moderator
 
Join Date: Sep 2007
Device + Firmware: iPhone 3G, 3G[S]- 3.1.2 JB
Operating System: Windows XP,Vista, OS X 10.5.8
Location: Pennsylvania
Posts: 2,397
Thanks: 82
Thanked 318 Times in 248 Posts

Thread closed, point made, discussion not going anywhere but downhill.
Digg StumbleUpon Delicious Reddit Newsvine Google Yahoo Thanks
Closed Thread

  Apple Forums & iPhone Forums, Mods, Hacks, News, Themes, Downloads, and more! | ModMyi.com > 3rd Party Apps For iPhone | iPod Touch > Native iPhone / iPod Touch App Discussion

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



Go to Top
ModMyI

All times are GMT -6. The time now is 06:20 AM. Powered by vBulletin® Version 3.8.4
If you need Dedicated Server Hosting, you should check out SingleHop. | Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.0 Copyright © 2007-09 by ModMy, LLC. All rights reserved.

iPhone News / iPhone Forums / Apple News / Apple Forums / RSS / Contact Us / / Privacy Statement / Top