Apple looking for someone to defeat iPhone hackers

Security manager sought to deal with jailbreaks

Just as a new hack, blacksn0w, promises to unlock iPhones with the latest Apple software, Apple is looking for a sheriff to lock the smartphones back up again, permanently.

A job posting on Apple's corporate website seeks a security manager for the iPhone platform to lead a team focused on secure booting and installation of the operating system, cryptographic services, partitioning and hardening its internal security domains, and risk analysis of security threats.

The "liberation movement" for iPhone poses special issues for enterprises that are adopting the iPhone in unprecedented numbers, despite the fact that Apple provides virtually no security or management infrastructure for the popular device. With jailbroken phones, enterprise users could load applications that might, even unintentionally, threaten corporate data or backend Exchange servers, for example. Unlocking the phone from the authorised network makes it hard to track, monitor and optimise wireless costs and could open the enterprise to legal problems.

Another vendor offers iPhone authentication for e-banking | Apple reaches 100,000 iPhone apps milestone | Intel, Microsoft and Apple investigate iPhone bug | Apple iPhone hack code updated

It's not clear from the online job post whether this is a brand new position or Apple is seeking a replacement for an existing, or former, employee.

Hardening the iPhone OS can address a whole range of potential issues, but almost surely involves preventing both jailbreaking – freeing the iPhone from dependence on the App Store and thereby allowing users to load their own software programs – and unlocking – cutting the cord to exclusive carriers and letting the iPhone run on other GSM networks.

The liberation movement comes to a peak this week with the release of Blacksn0w, a free program from ace iPhone hacker George Hotz, known as Geohot. It offers a baseband unlock of the latest iPhone OS Version, 3.1.2 and the current standard 05.11.07 cellular modem firmware.

One iPhone owner is even touting the new hacking utility as a value added feature to attract bids for his used 16GB iPhone 3GS model on eBay

According to another hacking site, iPhone Dev Team, Hotz exploits a known crash (manipulating the AT+XEMN command) to create a heap overflow, through which Hotz was able to inject code that results in a software unlock of the iPhone's SIM on the latest versions of the OS and baseband firmware loads.

The Dev Team post notes that users with the older 04.26 baseband firmware have been able to unlock using other programs, such as ultrasn0w and purplesn0w. "Whether or not you choose to update your baseband solely to use the new unlock is a personal choice, but so far there are no advantages to doing so (and remember you can't come back to 04.26 after you've gone to 05.11)," the post cautions.

Twitter feeds show that users worldwide are making use of blacksn0w. Some are reporting a range of problems after jailbreaking and unlocking their iPhones: YouTube videos, Wi-Fi, and GPS are not working. Taimur Asad, at Redmondpie.com, offers resetting the phone's "Network Settings" and installing the "Push Fix" app from Cydia, a replacement packing and installer program along with a catalogue of apps for jailbroken phones.

"I found out that installing this app also fixes all issues caused by blacksn0w related to WiFi, Youtube apps and GPS along with Push Notifications on hacktivated iPhones," Asad writes.

Hotz, on his blog, says he hasn't run into Wi-Fi issues himself, but promises to investigate them if someone figures out a way to replicate the problem.

One unlocker, #Xaliax_19 (Luis Figueroa), told the #blackn0w tweet stream that "wifi/youtube problems are due to bad hacktivation [an un-authorised phone activation], activate with an original sim.. THEN unlock, and you will not get the problems."

Other users are still struggling. Earlier today, #mephisto0666 (Ralf Jelinek), tweeted this plea: "Why can I access the internet on my #blacksn0w 'd #iphone with Data Roaming DISABLED !?!?! I have tried reset settings, doesnt work. HELP!!!"

As mentioned, one enterprising iPhone owner is selling his used but nearly new 16GB 3GS model on eBay and touting Hotz's programs as features: "This phone can be unlocked and jailbroken!" But as always, it pays to read the fine print: "We will not personally unlock or [jailbreak] the iPhone, but will give you the website upon finished auction (free website)."


What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.


Characters remaining: 500

Related Mobile & Wireless news

Chip makers push Google Android devices

ARM and MIPS aim to put mobile OS everywhere

Sony struggles to ship ebook readers before christmas

Reader Daily Edition may miss holiday season

Organisations offered build-your-own iPhone app service

BuildAnApp looks to take grunt work away.

Microsoft updates Windows Mobile Marketplace

Enhances security, releases desktop PC client



Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Database security: Preventing enterprise data leaks at the source

IDC discusses the growing internal threats to business information, the impact of government regulations on the protection of data, and how enterprises must adopt database security best practices...

Download Whitepaper

Service-oriented security

SOA has become an integral part of enterprise software by providing a framework to efficiently develop software as services that is easily sharable, reusable, and integrated. No where is the need more apparent than in the Identity Management space. Welcome to the age of Service-Oriented Security (SOS).

Download Whitepaper

Data protection prospective vendor checklist

Organisations need a way to map business needs against all these challenges in procuring a technical solution. To help, SANS has developed the following Prospective Vendor Checklist.

Download Whitepaper

Unlock the power of the mainframe

This whitepaper presents the notion of CICS as an integration hub based on a component-based, service-oriented architecture supporting Web services. Highlights will review the challenges and contrasted support for Web services natively in CICS.

Download Whitepaper

Techworld UK - Technology - Business

COLT White Paper

Are all VoIP services the same?

Questions to ask your service provider to ensure you get the VoIP service you need
With careful choice of partner, your business can have all the advantages of VoIP access - reduced costs, flexibility and simplicity - without the drawbacks.
This white paper is your guide to ensure you get right the VoIP service and details the pitfalls which businesses would do well to avoid.

Download white paper
BMC

Ride the express lane in the journey to speed ITIL adoption

Explore the challenges in making the journey to ITIL and the criteria for selecting consulting services
By following ITIL practices, your IT organisation will become more closely integrated with the business. We recommend making the journey to ITIL in a sequence of six incremental steps, the phases of which are driven through execution of a strategic transformational roadmap.

Download white paper

Webcast: IT Financial Management: Cost Optimisation for Efficiency and Agility.
On Demand Webcast
Join this webcast to learn about the techniques and technologies that can help you prove the value of IT to the business by understanding the true cost of today's IT services and those that will be necessary to deliver future success.

Register Today

Site Map

IDG Network

* *