Jonathan Zdziarski Says The iPhone 3GS Encryption Is Useless

Jonathan Zdziarski, a member of the iPhone Dev-Team, says that Apple’s encryption on the iPhone 3GS for business users is not as good as it should be and could put company data at risk. He said that the encryption is so weak, that it could be cracked in two minutes using nothing more than some easily available freeware.

He said after making this discovery: “I don’t think any of us developers have ever seen encryption implemented so Securitypoorly before, which is why it’s hard to describe why it’s such a big threat to security.”

The iPhone 3GS is the first device to officially feature encryption, but Zdziarski says sensitive information like credit card numbers and social security digits on a 3GS are just as easy to access as they were on the 3G and first generation iPhone.

He used Redsn0w and PurpleRa1n to install a custom kernel on the device, then he installed used an SSH client to port the raw disk image onto his computer.

Push Notifications Being Sent To The Wrong iPhone

Some iPhone users have been experiencing strange problems with their iPhone receiving AIM messages which were not Apple iPhone 3G WWDC 2009sent to them, but Apple’s push notification system sent it to the wrong people. However it’s not Apple’s fault as some believed it to be.

The iPhone generates unique private/public keys upon activation that identity each handset, so that they correct messages can be sent to the correct device. However using unlocking tools breaks this as they use duplicated keys to facilitate illicit use. Now that single identifiers have been registered to multiple phones instant messages, messages can be sent to any of those devices.

More New iPod Touch & iPod Nano Cases Leaked

Over the last few weeks a lot of case designs have been leaking out to the internet, appearing to be for a new iPod Touch and iPod Nano with camera.

iPod Cases

The new cases seem to look quite similar in hole positions as the previously leaked ones but these still may not be authentic. However if they are then we should see the announcement of a new iPod Touch and iPod Nano with photo/video recording, sometime around September per Apple’s usual release pattern.

Lawsuit Alleges Apple Conspired With Mafia

iPod Nano

Gregory McKenna has filed a suit against Apple, he alleges that Apple is conspiring with the mafia in an effort to coerce him to return to a New York based modeling agency he quit in 2000. As he explained in the 124 page complaint, an iPod Shuffle he brought in 2005 on eBay and an iPod Mini he got from an Apple store in 2006, possibly a Nano as iPod Mini’s were discontinued a year before. Both contain receivers that have allowed the mafia to send audio death threats that play with his music.
The suit seeks $14.3 million and lists ten defendants in all, including a local mechanic, a private investigator, the St. Louis Police Department, the FBI and the US Department of Justice.

Ultrasn0w Version 0.9 Released

The Dev-Team have released ultrasn0w version 0.9 today. Its features include:

  • Works on both 3G and 3GS
  • Works on hacktivated devices
  • Works regardless of how you jailbroke your device
  • Doesn’t patch any mach-o binary whatsoever.  (Doesn’t require a separate patch as each new firmware comes out).
  • Doesn’t install any additional daemon
  • Has no race conditions, no popups about “Missing SIM”, no network issues
  • Is almost 7000 times smaller than its nearest competition
  • Is available now via Cydia.  Source repo is http://repo666.ultrasn0w.com (that last “0” in ultrasn0w is a zero!)

Read More

Apple Released iTunes 8.2.1

Apple have just released iTunes 8.2.1 earlier today. Apple’s website says the update was to provide “a number of iTunesimportant bug fixes and addresses an issue with verification of Apple devices.” Apparently it also brakes the Palm Pre syncing with iTunes.

You can download it through the software update manager or download it here.

App Reviews Coming Soon

Although I’m probably going to be returning my laptop soon to get it repaired I will soon be starting doing App reviews as Apple iPhone 3G WWDC 2009a separate section of the blog. I will go over some old apps as well as new apps and will begin posting them when I get my laptop back.

Also just a note that once my laptop is sent back I may not be able to update the blog properly for a week or maybe up to 4 weeks so there might be a gap in posts but I will try my hardest to update the blog.

Reports Suggest iPhone 3G Could Be Coming To T-Mobile UK

Register Hardware and guardian.co.uk both suggest that the iPhone 3G, last years model, could be on the British Apple iPhone 3G WWDC 2009carrier T-Mobile within the next few months. However O2 would still keep the 3GS exclusivity.

“This represents a major shift in how Apple markets the iPhone,” The Register said, “which currently relies on network exclusives to get a decent subsidy; giving that up shows either greater confidence or reflected disappointment in how O2 has priced up the latest offering.”

The report from guardian.co.uk talks about how both Orange & Vodafone are interested in providing the iPhone on their networks as well. If that were to come to pass, all of the U.K.’s major cell phone carriers would provide some version of the iPhone, but would this mean it would need to become unlocked or multiple carrier restrictions made?

Though exclusivity for the iPhone with one carrier is the most common arrangement, non-exclusive deals are not unheard of. Since 2008, Apple has signed a number of non-exclusive carrier contracts in various countries.

IPCC Tethering No Longer Works in iPhone OS 3.1 Beta 2

The IPCC tethering hack used to allow use of tethering even if your carrier did not support it has now been stopped in TetheringiPhone OS 3.1 Beta 2. It’s not a surprise that Apple would fix this as not all carries have sorted out price plans for tethering.

If your still on iPhone OS 3.0 and don’t upgrade to 3.1 when it is officially released then the loophole will still be there and you can still use it at your own risk as if your carrier releases your using tethering without paying for it then can charge you at full data rates.

Apple Seeds iPhone OS 3.1 Beta 2 To Developers

Yesterday Apple provided iPhone developers with Beta 2 of the OS 3.1 firwamre. This release didn’t mention any changes, although the first beta included minor feature adjustments without Apples mentioning. Beta 2 will most likely contain bug fixes which address issues in Beta 1. Along with this a updated version of the iPhone SDK for both Leopard and Snow Leopard have been also released.

3.1 Beta 2

If your using Beta 2 and notice any changes feel free to leave a comment.

Update: I’ve just found that beta 2 also introduces a public API for manipulating live video. Developers are still testing the capabilities but it could open the door for many interesting apps in the near future.