Showing posts with label encryption. Show all posts
Showing posts with label encryption. Show all posts
Saturday, December 17, 2011
SIRI PORTING TO iPHONE 4 NOW LEGAL WITH iOS 5.0.1 UPDATE
IPhone 4 owners looking to take advantage of Apple’s Siri software from the iPhone 4S now have one less barrier standing in their way. Sure, plenty of tricks have been available in the past that allow users to hack Siri onto an iPhone 4, but until now they were illegal. Apple’s recent iOS 5.0.1 update, however, has a decrypted ramdisk, which means users can legally port files to the iPhone 4 that were previously encrypted and protected by Apple’s public distribution policies. Apple may re-encrypt the files in iOS 5.1, which is expected to launch in the near future, so move quick if you want to take advantage of this loophole.
Thursday, February 10, 2011
iPHONE PASSWORDS STOLEN IN JUST 6 MINUTES
Research being carried out at the Fraunhofer Institute for Secure Information Technology in Germany has revealed an iPhone password can be recovered in just 6 minutes from a locked device. In other words, if you lose your iPhone, but it has a password lock, anyone can unlock it in just a few minutes without having to figure out the passcode.
The technique requires that the iPhone be jailbroken and an SSH server be installed on the phone, both of which can be done without the handset being unlocked. Keychain scripts can then be used to run system commands and display full details of the user’s account including the password to unlock the phone (as in the image above).
While the password for the device can be revealed, other passwords for the most part remain protected.
It is made clear in their study that using encryption on the iPhone is not a way around this problem as the encryption relies on the user’s secret information (revealed by this method) to gain access. The best advice at the moment is to change passwords as soon as a device is lost or stolen to limit the damage.
Labels:
Apple,
encryption,
iPhone,
jailbreak
Thursday, January 27, 2011
FACEBOOK CLOSING SECURITY HOLE SWITCHING TO HTTPS FOR LOGINS
Facebook has at long last offered an option to use the encrypted "HTTPS" protocol, a feature it will begin rolling out today but won't finish for a "few weeks." You should check now if it's available, and sign up as soon as it is enabled for your account.
By default, Facebook sends your access credentials in the clear, with no encryption whatsoever. HTTPS solves this longstanding problem by encrypting your login cookies and other data.
A blogger using a freely available program called Firesheep was able to steal up to 40 Facebook logins in 30 minutes in a New York Starbucks recently.
You can sign up for Facebook HTTPS by going to Account Settings and then selecting "Account Security," third from the bottom. Then click under "Secure Browsing" — if it's there. Facebook says everyone should have this by the end of the day, but in the meantime you might be missing the relevant option toggle.
Subscribe to:
Posts (Atom)


