Tuesday, July 17, 2007

More Random Thoughs on iPhone Security

The good news is that hackers have been unable to unlock the iPhone. And, oh, are they trying. But it's the bootloader signed with a 1,024-bit RSA private key that's stopping them.

But then, there's the web dialer on its Safari web browser. A bug uncovered by SPI Dynamics could allow someone to track phone calls made through the browser. The issue was reported in SPI's blog, Errata Security and in The Register. There's also a Wiki devoted to the subject.

Apparently, there's also ways to get a user's e-mail and track other web activity.

And this is just the beginning. How many weeks has the iPhone been out already?


