<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Tiago&#039;s Tech Blog &#187; iPhone Flaw</title>
	<atom:link href="http://www.tiagoespinha.net/tag/iphone-flaw/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.tiagoespinha.net</link>
	<description>My life, ideas, news and applications</description>
	<lastBuildDate>Mon, 09 Jan 2012 13:56:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<image>
  <link>http://www.tiagoespinha.net</link>
  <url>http://www.tiagoespinha.net/favico.jpg</url>
  <title>Tiago&#039;s Tech Blog</title>
</image>
		<item>
		<title>iPhone OS 3.0 Spam Exploit</title>
		<link>http://www.tiagoespinha.net/2009/07/iphone-os-3-0-spam-exploit/</link>
		<comments>http://www.tiagoespinha.net/2009/07/iphone-os-3-0-spam-exploit/#comments</comments>
		<pubDate>Thu, 23 Jul 2009 12:11:34 +0000</pubDate>
		<dc:creator>tiago</dc:creator>
				<category><![CDATA[iPhone]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Hacktivation]]></category>
		<category><![CDATA[iPhone 3.0]]></category>
		<category><![CDATA[iPhone 3.0 Exploit]]></category>
		<category><![CDATA[iPhone Exploit]]></category>
		<category><![CDATA[iPhone Flaw]]></category>
		<category><![CDATA[iPhone Hacktivation]]></category>
		<category><![CDATA[iPhone OS 3.0]]></category>
		<category><![CDATA[iPhone Push Notification]]></category>
		<category><![CDATA[Push Notification]]></category>

		<guid isPermaLink="false">http://www.tiagoespinha.net/?p=251</guid>
		<description><![CDATA[The good silly folks over at AppleInsider are reporting on a flaw that might open the iPhone OS 3.0 to mass spam. While there is some truth to their claims, they are also being unnecessarily alarmist and making false claims. The specifics of this exploit is that when you hacktivate an iPhone (i.e. activate it [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.tiagoespinha.net%2F2009%2F07%2Fiphone-os-3-0-spam-exploit%2F" onclick="pageTracker._trackPageview('/outgoing/api.tweetmeme.com/share?url=http_3A_2F_2Fwww.tiagoespinha.net_2F2009_2F07_2Fiphone-os-3-0-spam-exploit_2F&amp;referer=');"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.tiagoespinha.net%2F2009%2F07%2Fiphone-os-3-0-spam-exploit%2F&amp;source=etiago&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p style="text-align: justify;">The <span style="text-decoration: line-through;">good</span> silly folks over at AppleInsider are <a href="http://www.appleinsider.com/articles/09/07/22/hackers_break_iphone_push_messaging_blame_apple.html" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.appleinsider.com/articles/09/07/22/hackers_break_iphone_push_messaging_blame_apple.html?referer=');">reporting</a> on a flaw that might open the iPhone OS 3.0 to mass spam. While there is some truth to their claims, they are also being unnecessarily alarmist and making false claims.</p>
<p style="text-align: justify;">The specifics of this exploit is that when you hacktivate an iPhone (i.e. activate it using Jailbreak), your iPhone will be using a private/public key pair to register with Apple's PNS (Push Notification Service) that already exists, in other words, it will be using a key that was not generated to your iPhone but that will be common to everyone who hacktivates their iPhone.</p>
<p style="text-align: justify;">As a result, when a notification comes addressed to that key, all of the iPhones in the world that have been hacktivated would in theory receive that message.</p>
<p style="text-align: justify;">Still, at AppleInsider they claim:</p>
<blockquote style="text-align: justify;"><p>Destroying the application security layer of the iPhone does not itself automatically break PNS, but (<strong>when combined with an "unofficial activation" required to use it with unofficial service providers</strong>) results in the system having no legitimate certificates to use in performing push notifications. Essentially, if the phone is not properly activated as intended through iTunes, the user's credentials for signing into Apple's PNS messaging servers (which are generated by the device itself in normal conditions) are broken along with the application security layer.</p></blockquote>
<p style="text-align: justify;">Whoa, whoa, whoa, little Timmy! Let's debunk this, shall we?</p>
<ol>
<li>An unofficial activation (read, hacktivation) is <strong>NOT</strong> required to use it with unofficial service providers. If an iPhone is already officially activated, the jailbreak will not reactivate it.</li>
<li>Jailbreaking does <strong>NOT</strong> necessarily mean that you want to use your iPhone with unofficial service providers. Jailbreaking simply allows you to install third-party applications, such that aren't installed through the regular AppStore.</li>
<li>You need to jailbreak to use the iPhone with an unofficial service provider, but jailbreaking does not have only that purpose. You can for instance jailbreak to run cracked games. Sure, it doesn't make it any more legitimate or legal, but it is not the same thing.</li>
</ol>
<p style="text-align: justify;">Finally, I must stress the notion: if you have an officially activated iPhone and if you jailbroke it afterwards, YOU ARE SAFE. Actually, I am not sure about the status of redsn0w right now, but when it was first released the push notifications would not even work for hacktivated iPhones! Still, if you would activate your iPhone normally and then jailbreak it, you would get your push notifications working. In a nutshell, if you have it officially activated, jailbreak will not put you at risk of being spammed.</p>
<p style="text-align: justify;">As for hacktivated iPhones... well, tough luck guys. It seems like you are better off turning of the push notifications if you don't want to be spammed in a near future.</p>
<p style="text-align: justify;">[via <a href="http://www.engadget.com/2009/07/23/iphone-3-0s-broken-push-messaging-caused-by-unlockers-dirty/" target="_blank" onclick="pageTracker._trackPageview('/outgoing/www.engadget.com/2009/07/23/iphone-3-0s-broken-push-messaging-caused-by-unlockers-dirty/?referer=');">Engadget</a>]</p>
 <img src="http://www.tiagoespinha.net/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?view=1&post_id=251" width="1" height="1" style="display: none;" />]]></content:encoded>
			<wfw:commentRss>http://www.tiagoespinha.net/2009/07/iphone-os-3-0-spam-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

