Will Apple Soon be Forced to Unbrick All iPhones?

Thu, 10/11/2007 - 05:17 — Quincy Pince-Nez

As the current iPhone 1.1.1 locking proves, there is a VERY dangerous flaw in the current iPhone and iPod touch software. A malformed TIF file can be used to get root access to the device. Obviously that is good if you want to install some useful applications on your iPhone/iPod, however that is extremely bad if you are worried about someone taking over your iPhone. Ironically, this might be a good thing for those who accidentally let Apple Brick their iPhones - try to stay with us here...

Theoretically, the malformed TIF file could be used for more nefarious tasks than updating than installing useful apps or updating the modems firmware...stuff like making a 900-number dialer($$ cha - ching $$), a bot installer (iPhone Spam-bot?), a baseband modem crippler or just good old-fashioned bricking the iPhone....

Hypothetically, one of these malformed tif files could even have the same effect as the "bricker" 1.1.1 update. However, this time Apple's Safari security will be to blame, not the users who are trying to assert their legal right to move the phone to other carriers. The only recourse Apple will legally have is to unBrick all of the iPhones that their update has caused and reset the baseband modem to factor settings.

One has to wonder if the malformed tif file vulnerability would have been discovered and applied to the iPhone had Apple not closed the Intaller.app development community out of the iPhone originally. Perhaps it is better to have these incredibly intelligent people on your side?

Comments

Question: DOES this

Question: DOES this vulnerability exist in 1.0.2 iPhones?
Question: Is it that in the way apple bricked their own iPhones the REASON this vulnerability now exists, or just that it was discovered because more cleaver ways were needed in order to reopen the iPhone.
Question (sorry): Why do YOU think that in order for apple to patch this up they would have to un-brick and re-welcome their formerly excommunicated iPhanz?

Pray tell.

1. Yes it does exist in

1. Yes it does exist in 1.0.2 phones
2. No - Apple updated the Baseband Modem firmware, but if it had been tampered with originally, it would break.
3. Because if there is a Bricker tiff in the wild, and a customer happens upon it and breaks his/her phone, it is Apple's responsibility to fix it as it is Apple's fault that it did not fix the tif exploit.

Taking #3 a little further

Taking #3 a little further for the people who don't want to have to think about it for 30 seconds; They won't be able to tell the difference between a phone bricked by the 1.1.1 update, and a phone bricked by Evildoers Unknown taking advantage of their security flaw with nefarious TIFs.

So they'll have to fix the lot.

"Perhaps it is better to

"Perhaps it is better to have these incredibly intelligent people on your side? "

Yeah, it's better to reward the guy that breaks into your house with free room and board.

"Theoretically, the malformed TIF file could be used for more nefarious tasks than updating than installing useful apps or updating the modems firmware...stuff like making a 900-number dialer($$ cha - ching $$), a bot installer (iPhone Spam-bot?), a baseband modem crippler or just good old-fashioned bricking the iPhone...."

Who would even think about this crap!

Stockholm syndrome strikes

Stockholm syndrome strikes again.
go back to http://www.apple.com/hotnews where you are safe from all of the evil bad guys who want to hurt your precious apple

It's not breaking into a

It's not breaking into a house and getting room and board for free. It's flying into a camp where hostages have been taken by evil-doers, disarming the bad guys, providing food and nourishment for the hostages and opening the door so they can leave if they want.

I think you should head home

I think you should head home during your lunch hour and watch Star Wars again.

Have we met?

Have we met?

bravo! Unfortunately the

bravo! Unfortunately the hostages mostly have Stockholm Syndrome as you can see by these comments.

to all of the people who feel they need to defend poor Apple in her time of need, read this:

http://www.extremetech.com/print_article2/0,1217,a=216895,00.asp

[quote=admin]bravo!

[quote=admin]bravo! Unfortunately the hostages mostly have Stockholm Syndrome as you can see by these comments.

to all of the people who feel they need to defend poor Apple in her time of need, read this:

http://www.extremetech.com/print_article2/0,1217,a=216895,00.asp[/quote]

This isn't life and death. It's a dumb ass phone. I happen to think it's a great phone, but it's a phone. If only people would put as much effort in to doing something really worthwhile. What a waste of intelligence. Such smart people wasting so much energy on useless and trivial matters.

"Perhaps it is better to

"Perhaps it is better to have these incredibly intelligent people on your side? " Run that by me again pls cos i thought it was the incredibly intelligent people in Apple that actually came up with the iPhone and all that is Apple in the 1st place. Imagine a world without Apple.
Bah humbug!

I don't think the incredibly

I don't think the incredibly intelligent people at Apple who developed the phone would be adverse to people tinkering with it. I think its the incredibly greedy, talentless, short sighted people at Apple who keep the iPhone locked and keep the 2 groups separated.

"assert their legal right?"

"assert their legal right?" You bumped your head too many times when you were a kid. Anything YOU want to do---whether the patent holder agrees or not---ends up being YOUR legal right! This is incerdible! Take your 6 friends with you and go buy a different phone, and stop bitching!

Quincy, let's be a little

Quincy, let's be a little more adept than this. Do you honestly believe that Apple's only recourse will be to unbrick all those iPhones? I'm not sure how much experience you've had with actual Apple employees but they are not the daft bunch you take them to be. Jobs & Co. know exactly what they're doing and if you'll un-bunch your panties for about five minutes you'll be well satisfied to know that very soon some much better applications will be available on the iPhone--apps that have actually been sanctioned by Apple and will be higher quaility; much better than the soggy crap that was on them before. So, sorry that you're upset Apple took away glitchy NES emulators and anime screen savers, but, in case you forgot, you wouldn't have any of that crap in the first place if Apple hadn't made the phone that you're soo staunch to talk about your rights to screw up to kingdom come.

remember the first hacker

remember the first hacker tools used an exploit that Apple patched in the 1.1.1 update and you all complained. Now your saying Apple better patch this new exploit of watch out out all us non-hackers.

Question. If Apple closes this Tif exploit will you praise Apple for being security concious or harp on them for yet another hacker block?

You can't have it both ways.

"The only recourse Apple

"The only recourse Apple will legally have is to unBrick all of the iPhones that their update has caused and reset the baseband modem to factor settings"

OR, they could patch Safari.....????

An acquaintence of mine made

An acquaintence of mine made 4 different hacks to facebook to have people friend him automatically. Facebook hired him. He's apparently helping them out real well.

As well, I can't find the official post of this (I swear I've seen it on Engadget or Kotaku), but one of the people who hacked guitar hero 2 to play custom games is working on GH3:
http://www.gamersquarter.com/forums/viewtopic.php?p=55457

While this post has an interesting idea, it is actually stated so poorly that many won't get it. What they're trying to say is if the tif exploit is used to brick your phone in a manner similar enough to make the IMEI say 004999010640000 (which will show up in a variety of situations), and there's proof, Apple will have no choice but to unbrick your phone due to the fact that there's no way to prove you unlocked it vs you accidentally visited a malicious website in MobileSafari.

Good idea, 9to5Mac!

To Frosty: Do you really

To Frosty:

Do you really believe there are people out there waiting to sneak into your Iphone and steal... what... your mother's telephone number?
Don't you think you're blowing this just a little bit out of proportion??? A little paranoïd maybe? People must have nothing better to do than go fishing into our iphones...
Come on, man, grow up!

Marc, Valparaíso, Chile

What are you talking

What are you talking about?

It's Apples house. I suppose you interpret the everything you read so literally. Who needs to grow up?

OMG... Apple did NOT brick

OMG... Apple did NOT brick your phone!!!!!!! Hackers bricked your phone!!!!!!!! Even the hackers admit that!

dude, get your head out of

dude, get your head out of your ass.

Yes. Apple bricked the phone. It was working. You apple apple update. You get brick.

Post new comment

The content of this field is kept private and will not be shown publicly.
CAPTCHA
This question is used to make sure you are a human visitor and to prevent spam submissions.
Image CAPTCHA
Copy the characters (respecting upper/lower case) from the image.