BrokeBerry

Attack Computer Wiz

A Security & Technology Weblog

There are a number of rumors floating around and early bandwagon jumpers who are claiming that there is a bug that allows users to bypass the passcode, PIN, or password lock on an iPhone that has updated to iOS 5.1. This is untrue, the described bug is not a bug at all. It is a failure on the users part to properly set security timeouts on their device.

The videos and descriptions show how anyone can bypass the passcode on an iPhone by simply activating the new camera feature on a locked device, click on the gallery button, and then click the home button. The videos show that the unauthorized user is now logged in without a passcode. Well the fact is, the device was never locked, the screen was only turned off. If the user in the demonstration would have set this timeout to immediate, rather than 1 minute or more, then the device would have truly been locked and this alleged bypass would not work. Check your settings by tapping “Settings”, “General”, “Passcode Lock”, “Required Passcode”.  The Required Passcode setting should be set to “Immediately” to properly secure your device.

This is not an Apple failure this is a user failure!

9to5Mac
Sophos

user Posted by John "Mike" Wright

| More


Have you noticed the Picture Frame icon to the right of your unlock slider on your iPad device? This icon allows access to your camera roll by default even if the device is locked. While this may be a cool "feature" to allow the device to work like an electronic picture frame, it also, by default, allows access to images stored on your device while it is locked. I for one am not a fan of that.

While I cannot find an easy way to remove the icon completely, I did find a quick way to limit the images that are displayed. By following these quick steps you can select only certain photos to be displayed while the device is locked.

1. Unlock your device and tap "Photos",
2. Tap "Albums", "Edit", "New Album", name the new album, tap "Save",
3. Select photos from your library that you want to display. I have a photo of my business card with my contact information on it, tap "Done",
4. Exit Photos back to the home screen and tap "Settings",
5. Tap "Picture Frame", un-select "All Photos", select "Albums", and choose your new album from the list.

That should be it. Confirm by locking your iPad, tap the picture frame icon, and the only photo(s) displayed are the one(s) you chose.

user Posted by John "Mike" Wright

| More


Here is a podcast that I did leading up to the RSA Conference 2012 in San Francisco. I should be able to post a video of a shortened version of my presentation that I was invited to do along with my full presentation later.


http://365.rsaconference.com/community/connect/blog/2012/02/14/rsac2012-podcast-das-403-garage-sale-forensics-data-discovery-through-discarded-devices

user Posted by John "Mike" Wright

| More


While at the RSA Conference in San Francisco last week I had the need to drop into the Apple Store. I was looking for a stand for my iPad that I could use to view the script of my presentation while on stage. With the help of an Apple Genius I as able to find exactly what I was looking for. Then, to my surprise she whipped out her POS device, Point of Sale device that is, and advised me that if I was done shopping, that she could complete my purchase. On her modified iPod she swiped my credit card and emailed me a receipt. Purchase complete no fuss no hassle.

We put a lot of trust in retailers when we hand over our credit card to them to complete a transaction. In many cases we are standing at a checkout counter, we usually swipe our card ourselves or hand it to the checker to swipe for us, but most of the time that card never leaves our hand, or at worse it never leaves our sight. The major exception to this is restaurants. At most restaurants we order, we eat, we get a check, and we hand over our card. Then our card disappears for a few minutes or on some cases more than a few minutes. What is going on back there? Where is my card? Is it being skimmed, are the numbers being transfered or copied, did it get handed to another customer by mistake? There are so many things that could be going on when that card is out of our sight that we have no control over.

If Apple can create a POS system that uses a presumably secure wifi connection and a presumably secure iPod device to complete a credit card transaction why can't Applebee's, and Denny's, and every other restaurant out there. This technology is available, it may cost a little more then their current POS devices, but it could save them:

Time; the wait staff could use one of the devices to deliver the check and take immediate payment, then have the receipt emailed or printed back at the register. The customer, who often is ready to leave can do so without waiting even longer for the ticket and their card to return.

Security; the customers card never leaves their site and there is no question as to whether or not the card is tampered with or copied. The wifi and devices would be compliant with laws and regulations that regulate such transactions, not only in transit but also in rest.

Cost; the establishment simply needs to purchase and design the system for a handful of devices. The wait staff could share multiple devices between them. After all, in most cases they only have one or two current POS devices to complete these transaction now.

Reputation; when a theft does occur or even a suspected theft, that customer is going to complain. But often that customer is complaining loudest to other customers. They will tell everyone about the theft and how they think that it must have been that waiter that stole his card. If the card does not leave the customers sight the opportunity of skimming or theft would be low.

Satisfaction; the customer will be very pleased that their credit card does not leave their sight, that they don't have to worry about losing a receipt because it has been emailed, and they don't have to wait for the lengthy payment process at the end of their meal.

Good job to Apple on this one. Another great device even if it is just a POS device.

user Posted by John "Mike" Wright

| More


Use the below codes and this link to register (https://ae.rsaconference.com/US12/portal/login.ww)

ProofPoint - EC12PRF
DeviceLock - EC12DVL
IronKey - EC12IRN
Symantec - SC12SYM
SF Bay InfraGrid - 1412RLPXPO
FortiNet - EC12FRT

user Posted by John "Mike" Wright

| More