Most Popular Stories
Events
- CIO Healthcare Summit
March 11-14 — Scottsdale, AZ - CIO Summit
March 18- 21 — Miami, FL - COMPTEL PLUS Spring 2012
April 15-18 — San Francisco, CA - The AIIM Conference 2012
March 20-22, 2012 — San Francisco, CA
Sponsored Links
Free Newsletter
HOT TOPICS >> The tech world's top flops and fiascos of 2011 | Top 8 features in Windows 8 | Paul's Q&As
INDUSTRY >> Healthcare IT | Government IT | Financial Services IT | Biotech IT | Compliance IT
Free Newsletter
Latest News
Popular Topics
Whitepapers
First iPhone bugs discovered
Thanks to months of iPhone hype and the vindication of huge sales, by anyone's estimate Apple is certainly riding high this week. Leave it to the hackers, however, to try to cut the company down to size. Mere minutes after the iPhone's release, Robert Graham of the Errata Security blog discovered the first official iPhone bug: an outstanding Safari vulnerability that was previously discovered in a desktop version of the browser. What's more, it was found that the iPhone is just as vulnerable to caller ID spoofing--which can allow others to access your voicemail--as any other AT&T/Cingular handset. With as many as 525,000 iPhones now in the wild, these vulnerabilities could pose a major threat to iPhone users--not to mention the employers of those iPhone users.
However, there is a silver lining. Unlike the traditional handset security model, which finds carriers addressing (or more often that not, not addressing) security vulnerabilities via the network, Apple has reserved the right to deliver software and firmware updates directly to the iPhone via iTunes. And as we have seen, Apple has been pretty vigilant in addressing Safari exploits, thus far. "While Apple is slightly behind Windows on the desktop/server (that Samba bug still appears to be unfixed), it's still light years ahead of the mobile vendors," Graham writes on the Errata Security blog. "The mobile market is completely screwed up right now: while carriers know about the widespread vulnerabilities in their phones, the carriers are unwilling to patch them."
For more on the bugs:
- see this ZDnet article
For more on caller ID spoofing on AT&T's network:
- see this blog post from Nitesh Dhanjani
Related Stories
- Apple releases bumper security update for 58 errors
- iPhone 1.0.1 Update fixes Safari vulnerabilities
- iPhone exploit allows control of voice, data functions
- Researcher claims to have developed OS X worm
- iPhone: Almost unlocked by hackers
- iPhone/Safari dialer could pose security risks
- List of 68 iPhone bugs released
- Apple cleans a few more Safari bugs off Windows
- Apple patches three Safari flaws in Windows
- Apple rolls out 17 patches via security update
Home
| Subscribe | Advertise | RSS |
Privacy
| Site Map
| EditorsTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2011 FierceMarkets. All rights reserved. |
![]() |




