apple
Report a problem

iPhone password revealing bug

Andrew Lyle   on 14 September 2009 - 04:21 · 25 comments & 8088 views

Advertisement (Why?)
A user on Twitter has posted a message about a potentially nasty bug found on the iPhone and iPod touch firmware. This user, rpetrich, discovered the exploit, which can reveal users' passwords on the devices, according to ModMyi.com.

The bug only works in certain scenarios and doesn't pose a risk to users everywhere, unless somebody nearby gets a hold of your iPhone or iPod touch. The bug can be exploited in almost every available application that stores passwords; this includes your saved email account passwords.

The bug can reveal all characters, except the very first character in the password field. That is unless a user places a random character at the beginning of the password, then all characters can be revealed. The trick works when a password field is present with a saved password in it, a user can delete one character at a time, starting from right to left and shake the phone, press "undo typing" to reveal the hidden character.

This trick seems to only be present in firmware 2.0 and 3.0, but is apparently patched in the recently released 3.1 firmware.

This video demonstrates how the trick is possible:


Post a comment · Send to friend Comments · There are 25 additional comments
(6 replies) #1 RAID 0 on 14 Sep 2009 - 04:43
From what I've seen, people are quick to hand over their iPhone to show them off. This might be easy.
#1.1 Andrew Lyle on 14 Sep 2009 - 04:45
RAID 0 said,
From what I've seen, people are quick to hand over their iPhone to show them off. This might be easy.

Stolen iPhones are also at high risk, if you store any passwords at all, running firmware 2.x or 3.0
#1.2 PsykX on 14 Sep 2009 - 04:50
What's different in 3.1 ?
#1.3 Andrew Lyle on 14 Sep 2009 - 04:54
PsykX said,
What's different in 3.1 ?

Still unsure what they changed, maybe they have figured it out before the users discovered it
#1.4 QuarterSwede on 14 Sep 2009 - 05:47
What's different in 3.1 ?

When you tap Undo Typing it clears the field instead of revealing the last thing you typed.
#1.5 PsykX on 14 Sep 2009 - 11:55
LOl... I now, I saw the video. I meant... what's better in 3.1 than 3.0 about security?
#1.6 offroadaaron on 15 Sep 2009 - 04:34
PsykX said,
LOl... I now, I saw the video. I meant... what's better in 3.1 than 3.0 about security?


?? QuarterSwede just stated it clears the password rather than revealing the character
#2 DO_A_BARREL_ROLL on 14 Sep 2009 - 06:01
Remember, there's an app for pretty much everything.
(3 replies) #3 JonathanMarston on 14 Sep 2009 - 06:41
Do you really have to shake it as hard as the guy in the video?
#3.1 Andrew Lyle on 14 Sep 2009 - 12:35
No you don't.
#3.2 +dead.cell on 14 Sep 2009 - 15:32
But it's fun to.
#3.3 Jaxkesa on 14 Sep 2009 - 17:21
I didn't realise you could shake it to get that menu to appear...I've only had it 14 months lol
(1 reply) #4 neo1988 on 14 Sep 2009 - 07:10
Firmware 2.0 did not have shake to undo, so it's not possible to uncover a password using this method.
#4.1 Tom W on 14 Sep 2009 - 08:09
Good point, struck through that.
(3 replies) #5 liamwolf on 14 Sep 2009 - 07:23
And you can do it all in under 31 seconds.
#5.1 Chris4 on 14 Sep 2009 - 07:27
I see what you did there.
#5.2 kikumbob on 14 Sep 2009 - 08:46
What did you do there?
#5.3 Liam Wolf on 14 Sep 2009 - 08:59
#6 JDonner on 14 Sep 2009 - 08:21
And yet Apple fails again...
#7 hotdog963al on 14 Sep 2009 - 12:45
Hahaha, so much for testing!
#8 Klownicle on 14 Sep 2009 - 13:29
I love it, eat your heart out apple.

Your macs aren't infected with viruses and spy ware etc because there not widely used enough.

The iPhone on the other hand is, SMS Exploit, and now this. I'm not entirely dissing mac here, but it is a perfect example on how virus creators and malware etc focus on products that are widely used.
#9 +techbeck on 14 Sep 2009 - 14:35
This must be the total security Apple has been talking a bout...no wait, this is a feature...n/m

(1 reply) #10 blachole on 14 Sep 2009 - 19:50
well when I see someone shaking my iPhone non-stop I will know what they are up to..
#10.1 M_Lyons10 on 14 Sep 2009 - 22:11
blachole said,
well when I see someone shaking my iPhone non-stop I will know what they are up to..


LOL!
#11 M_Lyons10 on 14 Sep 2009 - 22:10
Wow... Well, it's good to see Apple fixing this before others noticed it... It's definitely a bad bug...

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)