Most Popular Stories
- One on One with Arpan Shah of Microsoft Sharepoint
- IBM will snag half of India's outsoucing work by 2010
- Vendors prepare for Obama's electronic medical records change
- Teen sends 14,528 text messages in a single month
- Coke uses RFID for drink dispensers
- Forrester report predicts web content management will grow in spite of economy
Events
Sponsored Links
Free Newsletter
Latest News
Popular Topics
Whitepapers
- Business Value of Performance IDC Whitepaper
- IM and Presence: Achieving Mission Critical Status in the Enterprise
- Enterprise VTLs: Strategic for Large Scale Datacenters
- White paper: Managing your company's wireless expense is not enough. Be BudgetCorrectâ„¢
- Gartner Magic Quadrant for Content Monitoring and Filtering and Data Loss Prevention
- Consumption-Based Fundamental Asset Allocation Redefines Investing -- Relevant Investing in a Post-Collapse Era
First iPhone bugs discovered
Thanks to months of iPhone hype and the vindication of huge sales, by anyone's estimate Apple is certainly riding high this week. Leave it to the hackers, however, to try to cut the company down to size. Mere minutes after the iPhone's release, Robert Graham of the Errata Security blog discovered the first official iPhone bug: an outstanding Safari vulnerability that was previously discovered in a desktop version of the browser. What's more, it was found that the iPhone is just as vulnerable to caller ID spoofing--which can allow others to access your voicemail--as any other AT&T/Cingular handset. With as many as 525,000 iPhones now in the wild, these vulnerabilities could pose a major threat to iPhone users--not to mention the employers of those iPhone users.
However, there is a silver lining. Unlike the traditional handset security model, which finds carriers addressing (or more often that not, not addressing) security vulnerabilities via the network, Apple has reserved the right to deliver software and firmware updates directly to the iPhone via iTunes. And as we have seen, Apple has been pretty vigilant in addressing Safari exploits, thus far. "While Apple is slightly behind Windows on the desktop/server (that Samba bug still appears to be unfixed), it's still light years ahead of the mobile vendors," Graham writes on the Errata Security blog. "The mobile market is completely screwed up right now: while carriers know about the widespread vulnerabilities in their phones, the carriers are unwilling to patch them."
For more on the bugs:
- see this ZDnet article
For more on caller ID spoofing on AT&T's network:
- see this blog post from Nitesh Dhanjani
Related Stories
- Apple rolls out 17 patches via security update
- Apple issues Quicktime security update
- Apple patches three Safari flaws in Windows
- Apple cleans a few more Safari bugs off Windows
- List of 68 iPhone bugs released
- iPhone/Safari dialer could pose security risks
- iPhone: Almost unlocked by hackers
- Researcher claims to have developed OS X worm
- iPhone 1.0.1 Update fixes Safari vulnerabilities
- iPhone exploit allows control of voice, data functions
Comments
Post new comment
Home
| Subscribe | Advertise | RSS |
Privacy
| Site MapTHE FIERCEMARKETS NETWORKFierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceVoIP | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe© 2009 FierceMarkets, Inc. All rights reserved. |
![]() |







Click here to get the FierceCIO:TechWatch email newsletter for FREE!
Be the first to comment