iPhone app iPad app Android phone app Android tablet app More

iPhone Hack Reveals Password In Just 6 Minutes (VIDEO)

The Huffington Post   First Posted: 02/10/11 12:16 PM ET Updated: 05/25/11 07:30 PM ET

Iphone

Lost your iPhone? Got it password protected? It may not be enough to stop hackers.

Researchers in Germany have discovered a way to get inside the iPhone in just six minutes--without using a password, PCWorld reports. Basically, after jailbreaking the phone, they simply targeted Apple's password management system, keychain, to get a huge cache of sensitive information.

Jailbreaking is more commonly performed by iPhone users who want to bypass Apple's restrictions on outside software. In this hack, the researchers were then able to install software that rendered passwords in the keychain vulnerable.

PC World explains,

The attack works because the cryptographic key on current iOS devices is based on material available within the device and is independent of the passcode, the researchers said. This means attackers with access to the phone can create the key from the phone in their possession without having to hack the encrypted and secret passcode.

Using the attack, researchers were able to access and decrypt passwords in the keychain, but not passwords in other protection classes.

"As soon as attackers are in the possession of an iPhone or iPad and have removed the device's SIM card, they can get a hold of e-mail passwords and access codes to corporate VPNs and WLANs as well," the researchers said in a statement. "Control of an e-mail account allows the attacker to acquire even more additional passwords: For many web services such as social networks the attacker only has to request a password reset. Once the respective service returns the new password to the user's e-mail account, the attacker has it as well."

Their recommendation? Change all of your stored passwords should your phone be lost, or stolen.

Watch the video explaining the hack below:

FOLLOW HUFFPOST TECH

 
 
  • Comments
  • 47
  • Pending Comments
  • 0
  • View FAQ
Comments are closed for this entry
View All
Favorites
Recency  | 
Popularity
ThinkCreeps
Seriously, it's time.
05:05 AM on 02/14/2011
But the passcode is just a 4-digit number. After you've tried 1234, 4321 and 0000 you're probably in.
photo
Morgantheaxe
Eisenhower Republicans don't drink tea!!
03:02 PM on 02/13/2011
Why am I being accused of having a "religous devotion" to apple when Im correcting garbage information? I corrected information about the new HP pad as well. Speak very highly of that also. So do I now have two religions? Hp AND Apple? I mean come on ihaters. You say so much thats just patently false about Iphones because you don't own them so you are either repeating what you read somewhere or making it up as you go. Both of which are painfully obvious to people that own Iphones. When we do correct the garbage out there and hand people some truth we get accused of being in a cult, Steve Jobs secret lovers, and or both. I tell ya I used to like droids, but after hearing the rediculous ihate that comes outta people that own em Im starting to think droids have trashy people magnets in them. It seems to attract very small liars quite a bit.
photo
HUFFPOST SUPER USER
Skaterx999
04:02 PM on 02/13/2011
You need not make up lies to hate apple. What a lot of people don't realize is that you can recognize the good things about Apple and the I-ecosystem and still not like it.
photo
hypnotoad72
Real democracy = living wages.
10:14 AM on 02/13/2011
"alpine"?
photo
HUFFPOST SUPER USER
Scott Stevenson
Bless your heart.
06:34 PM on 02/11/2011
Here's a real easy fix. Don't loose your phone.
photo
hypnotoad72
Real democracy = living wages.
10:15 AM on 02/13/2011
Wait until hackers do it remotely... no need to lose it. :(
photo
Morgantheaxe
Eisenhower Republicans don't drink tea!!
02:55 PM on 02/13/2011
Doesn't work remotely. Gotta have their hands on it to remove the card. But keep praying for the Iphone hack so you can hate on it a little more. Sad little person you are.
05:23 PM on 02/11/2011
just don't keep sensitive info in Keychain.
next!
12:25 AM on 02/12/2011
Search the app store for "Keeper". Keeper does not store passwords in the keychain so it's safe to use!
photo
Morgantheaxe
Eisenhower Republicans don't drink tea!!
01:04 AM on 02/11/2011
Love the blurbed over part about they have to have your phone. I can brick my phone in seconds online. My phone turns up missing and thats the first thing Im doing. Good luck jailbreaking a brick.
photo
HUFFPOST SUPER USER
CynicalAgnostic
03:39 AM on 02/11/2011
They did mention removing the sim card before performing the hack. The intention is clearly to restrict its network access so i'd assume they would take care to also be in a place where there were no available wifi connections that you would have previously also placed on the iphone's keychain. In which case good luck in bricking your phone online when it has no connection to the internet.
07:24 PM on 02/11/2011
perhaps he's hot glued the sim card, so he can brick at ease.
photo
Morgantheaxe
Eisenhower Republicans don't drink tea!!
10:47 PM on 02/12/2011
You hear the theme music to twilight zone in your head a LOT dont ya.
photo
HUFFPOST SUPER USER
Skaterx999
04:03 PM on 02/13/2011
"This means attackers with access to the phone can create the key from the phone in their possession without having to hack the encrypted and secret passcode. "
06:55 PM on 02/10/2011
I'm having trouble with the basic premise of having sensitive information stored in a phone. And that someone else is just dying to see it.
10:44 AM on 02/11/2011
I know of several spouses who have found texts and pics to and from extra-marital playmates once they learned their partners password.
HUFFPOST SUPER USER
Vic Tor
05:51 PM on 02/10/2011
Jailbreaking an iphone is not a 6 minute process. The rest probably is. But that's like saying it only takes 30 second to rob a bank because that's how long it takes to open the locked cash drawer. Additionally, are thieves just going to steal your phone and roll the dice hoping something is good in there? There are 10,000 more lucrative ways for a clever person to steal someone's personal info.
photo
Pectin
Lie to me...
04:06 PM on 02/10/2011
The article is good link bait but in the end it basically is just a caution to use a remote wipe from an Exchange server or Find My iPhone as soon as the phone is lost.
photo
Morgantheaxe
Eisenhower Republicans don't drink tea!!
01:06 AM on 02/11/2011
Bingo. Amazing how much incorrect info gets put out there about Iphones. It's like everyone that doesn't own one wants to talk about them even though they have no clue what it is they are talking about.
photo
HUFFPOST SUPER USER
ResearchtheFacts
Alert, awake & paying attention to the details.
03:28 PM on 02/10/2011
They just work. How many times has apple been hacked recently? Still patching those flaws. And those propriety screws they use in their cases have been hacked too. WELCOME to the real world were nothing is 100% full proof or perfect.
02:41 PM on 02/10/2011
I have an iPhone. Hopefully there will be a way to increase security soon.
photo
Morgantheaxe
Eisenhower Republicans don't drink tea!!
01:08 AM on 02/11/2011
If you have one that you didn't jailbreak yourself and load up with a bunch of garbage apps from sources you know nothing about you are using the safest phone on the market period. You can brick your phone in under 2 mins by logging on to....well as an Iphone owner you know. Besides the premise of this is they have your phone in their hands. Now really how many times have you lost your Iphone?
12:39 AM on 02/12/2011
I have never lost my iPhone and I haven't decided to jailbreak it and never will. I learned it is possible to "un brick" an iPhone.
photo
Sacchinftw
Isn't it sad...?
01:20 PM on 02/10/2011
But Apple products can't get hacked, aren't susceptible to viruses, and don't come with faulty alarm clocks! Steve Jobs said so!

I don't know what to believe anymore!!
photo
Morgantheaxe
Eisenhower Republicans don't drink tea!!
01:10 AM on 02/11/2011
Well since you are an Ihater you will believe the article the actual owners of Iphones are scoffing at as being full of it. See we can lock up our phones online in a couple mins and there is no way to jailbreak it from there.
photo
HUFFPOST SUPER USER
PhillyKing
10:47 AM on 02/11/2011
i can lock up my Android from online as well, that doesn't mean that there's no way to get into it... and the same can be said for the iphone... stop being a delusional fanboy and get real... every device has it's flaws but you fanboys go all out to defend urs whenever they're pointed out... these articles are to educate people from the false sense of security and to warn them about putting too much personal info on their devices... you, however, serve no purpose but to encourage that false sense, and work PR for Apple.
photo
Sacchinftw
Isn't it sad...?
11:22 AM on 02/11/2011
I don't hate the product, I hate the religious devotion the iSheep have for the product.
photo
hypnotoad72
Real democracy = living wages.
01:12 PM on 02/10/2011
And isn't the root password for the iphone still (omitted despite the obvious)? (a 0.002 second web search will reveal the password...) Even a firewall app is going to make it not "just work". When I hear "just works", I read "least path of resistance, with zero safety precautions". Ironically I'd rather jailbreak and install a firewall app and end up feeling more secure... :-S
photo
Morgantheaxe
Eisenhower Republicans don't drink tea!!
01:10 AM on 02/11/2011
And yet its the jailbroken phones that get hacked.
04:49 PM on 02/11/2011
The implication was that the hackers would do the "jailbreaking," after removing the SIM card, so you wouldn't be able to "brick" the phone.
photo
hypnotoad72
Real democracy = living wages.
10:19 AM on 02/13/2011
Not jailbroken (to my knowledge): http://www.engadget.com/2010/03/25/iphone-sms-database-hacked-in-20-seconds-news-at-11/
photo
HUFFPOST SUPER USER
JohnSawyer
arglebargy
03:07 AM on 02/11/2011
Well, it's certainly not "alpine", if that's what you're implying...
photo
HUFFPOST SUPER USER
jsgaetano
Legum servi sumus ut liberi esse possimus
01:08 PM on 02/10/2011
It always amuses me when Apple cultists try refuting my claim that the iOS has only a token amount of security.
photo
hypnotoad72
Real democracy = living wages.
01:14 PM on 02/10/2011
I've posted links to a number of sources; PWN2OWN being a favored choice. Unjailbroken phones can have their SMS databases swiped in 20 seconds (though Apple likely patched that by now, but given how each new minor revision of iOS gets jailbroken in only days or a couple weeks max, Apple doesn't seem to take security seriously and I suspect a workaround might have been found. And while big companies say "Tell us the bug and get $20,000" via crowdsourcing since hiring real staff costs more, more hackers are going to silently share the info to other hackers rather than to be good little children and inform Net Nanny, Net Mommy, or even iDaddy of the problems... I pity users of smartphones in general. There IS a big security issue afoot that's just waiting to go *boom*.)
photo
HUFFPOST SUPER USER
jsgaetano
Legum servi sumus ut liberi esse possimus
01:49 PM on 02/10/2011
It's kind of a shame, because I'd have really liked to get an iPhone (I'm a bit of a smartphone geek)... but the security on the device is so bad, an attacker would have a trivially easy time getting access to everything on the device.
 
I don't have multi-million dollar secrets, but I'd still like to have at least a bit of confidence that an attacker won't be looking through my camera and listening through my speaker.
photo
Morgantheaxe
Eisenhower Republicans don't drink tea!!
01:13 AM on 02/11/2011
And yet its only the people stupid enough to jailbreak their own phones and download garbage apps that get hacked. Im laughing at all the chest puffery about being uber hackers.
photo
HUFFPOST SUPER USER
jsgaetano
Legum servi sumus ut liberi esse possimus
10:14 AM on 02/11/2011
They aren't the only ones getting hacked, they're just the low hanging fruit (as it were).
 
Apple's iOS only has a token amount of security.  The fact that the device can be jailbroken at all is proof of that.  The only difference between what jailbreak does and what a virus does is the intent of the program.  Jailbreaking delivers a useful payload, whereas viruses deliver a malicious payload.