Apple iPhone v1.0.1 Update Now Available 279
The Webguy writes "Apple has released the first update for the iPhone. Updated components in the v1.0.1 update include Safari, the WebCore, and the WebKit. Quoting from the Apple Knowledge Base, the 'update is only available through iTunes, and will not appear in your computer's Software Update application, or on the Apple Support Downloads site.'" One source speculated that Apple wanted to get fixes in users' hands ahead of the Black Hat conference where details of early iPhone vulnerabilities could be revealed.
Sure wish... (Score:4, Funny)
Re: (Score:3, Informative)
Re: (Score:3, Funny)
Here's a way (Score:3, Informative)
If you use a major road name, the location chosen might be in the middle of the stretch of roadway, so try to use smaller streets if you can.
Re: (Score:2)
Would it have killed them to allow connection to a Bluetooth GPS?
Re: (Score:2)
Regardless, the software is top class and allows the use of a GPS with maps from other providers...
Cheers!
Re: (Score:2)
It is also a J2ME app, which makes it useless for iPhone users.
Re: (Score:2)
Re: (Score:3, Insightful)
A Description of the Patches from Apple: (Score:5, Informative)
iPhone v1.0.1 Update
Safari
CVE-ID: CVE-2007-2400
Available for: iPhone v1.0
Impact: Visiting a malicious website may allow cross-site scripting
Description: Safari's security model prevents JavaScript in remote web pages from modifying pages outside of their domain. A race condition in page updating combined with HTTP redirection may allow JavaScript from one page to modify a redirected page. This could allow cookies and pages to be read or arbitrarily modified. This update addresses the issue by correcting access control to window properties. Credit to Lawrence Lai, Stan Switzer, and Ed Rowe of Adobe Systems, Inc. for reporting this issue.
Safari
CVE-ID: CVE-2007-3944
Available for: iPhone v1.0
Impact: Viewing a maliciously crafted web page may lead to arbitrary code execution
Description: Heap buffer overflows exist in the Perl Compatible Regular Expressions (PCRE) library used by the JavaScript engine in Safari. By enticing a user to visit a maliciously crafted web page, an attacker may trigger the issue, which may lead to arbitrary code execution. This update addresses the issue by performing additional validation of JavaScript regular expressions. Credit to Charlie Miller and Jake Honoroff of Independent Security Evaluators for reporting these issues.
WebCore
CVE-ID: CVE-2007-2401
Available for: iPhone v1.0
Impact: Visiting a malicious website may allow cross-site requests
Description: An HTTP injection issue exists in XMLHttpRequest when serializing headers into an HTTP request. By enticing a user to visit a maliciously crafted web page, an attacker could trigger a cross-site scripting issue. This update addresses the issue by performing additional validation of header parameters. Credit to Richard Moore of Westpoint Ltd. for reporting this issue.
WebKit
CVE-ID: CVE-2007-3742
Available for: iPhone v1.0
Impact: Look-alike characters in a URL could be used to masquerade a website
Description: The International Domain Name (IDN) support and Unicode fonts embedded in Safari could be used to create a URL which contains look-alike characters. These could be used in a malicious web site to direct the user to a spoofed site that visually appears to be a legitimate domain. This update addresses the issue by through an improved domain name validity check.
WebKit
CVE-ID: CVE-2007-2399
Available for: iPhone v1.0
Impact: Visiting a maliciously crafted website may lead to an unexpected application termination or arbitrary code execution
Description: An invalid type conversion when rendering frame sets could lead to memory corruption. Visiting a maliciously crafted web page may lead to an unexpected application termination or arbitrary code execution. Credit to Rhys Kidd of Westnet for reporting this issue.
Re: (Score:2, Insightful)
Re: (Score:2)
Re:A Description of the Patches from Apple: (Score:5, Funny)
Arbitrary code execution? But isn't that what every iPhone user has been clamoring for?
Re:Copy and Paste from linked article - karma whor (Score:2)
Yes, but you can't argue with success ;)
It's nice just to have it on the page to look at. Besides, how many people are going to actually read it anyways?
Re: (Score:2)
Copy/paste (Score:5, Funny)
Re:Copy/paste (and take the "Phone" out of iPhone) (Score:2, Troll)
You know how Steve mentioned three things when he introduced the iPhone? Well, two out of three ain't bad--mine wasn't a phone for about 24 hours (and didn't bother to tell me):
My iPhone seems fine... (Score:5, Funny)
Re: (Score:2)
One Source? (Score:3, Insightful)
Slashdot has sources now?
updated (Score:4, Funny)
Re: (Score:2, Funny)
giving you teh snappy
Re: (Score:2)
Clarification on my speculation. (Score:3, Insightful)
Interesting... (Score:5, Interesting)
Anyone with a hacked iPhone try this yet, and if so, any problems? I expect any hacks will have to be re-applied (or even re-discovered, if the hole that allowed them was patched.)
(I haven't hacked my iPhone yet, but I would like to make sure Apple doesn't lock hacked ones out of updates.)
Re:Interesting... (Score:5, Informative)
Re: (Score:2, Informative)
Re:Interesting... (Score:5, Funny)
Funny? (Score:2)
Re: (Score:2)
Re: (Score:3, Informative)
Now that I'm thinking about it... (Score:4, Funny)
Nope, Palm 10.0 (Score:2)
Also, it's what Palm should have developed about two years ago, if they hadn't lost focus on making great small device OSe's
Re: (Score:2)
And Palm? It seems to me that about the only chance Palm has for continued existence is to go back to their roots and release Graffiti (v1, not v2, now that the lawsuit is settled) for the iPhone. You *do* know that Palm's original product was Graffiti, right? And that one of the platforms it ran on was the Newton MessagePad?
Honestly, I hope Pal
Re: (Score:3, Informative)
I don't think they are, because the finger is a terrible writing implement - that would be far more suited to a stylus I think.
And Palm? It seems to me that about the only chance Palm has for continued existence is to go back to their roots and release Graffiti (v1, not v2, now that the lawsuit is settled) for the iPhone. You *do* know that Palm
Re: (Score:2)
WebTV Next Generation. Royal Vista on steroids. (Score:2)
It's basically a canned email/browser device like WebTV in a pocket form factor, with a handful of common organizer applications baked into the image, like Royal's old line of organizers.
One fix that I found (Score:4, Informative)
The update took around 7-8 minutes altogether. Left a ".ipsw" file in my ~/Library/iTunes/iPhone Software Updates folder which presumably contains the image.
Sooooo.... (Score:5, Funny)
Yes Dorthy (Score:2)
I personally don't mind sending it to Apple in three years or so, when it's at 80% capacity... or I may not, as it is the battery is plenty enough for me.
If you enjoy having to replace batteries more often just because you can, and having shorter battery life - more power to you (so to speak).
Re: (Score:2)
i suppose, if i had an iphone, i'd try to find a way of wiping the memory bigtime before sending the device in to have its battery replaced. then i could be sure that apple wasn't gathering personal information about me.
Re: (Score:2)
Don't Fool Yourself (Score:2)
Re: (Score:2)
That'd be funny if it was posted two weeks ago. As is... just lame.
iPhone doesn't charge after update? (Score:3, Interesting)
Re: (Score:2, Informative)
iTunes.... really? (Score:2)
Dear Apple,
Please stop selling out. You're on a slippery slope, and we won't forgive you another time after you slipped up in the 90s.
Sincerely,
Your customers.
Re: (Score:3, Insightful)
Just because data and an installer can be delivered doesn't mean it's a brilliant plan.
But I just have to ask: to whom has Apple sold out by requiring you to sit down at your computer to update a mobile device?
Re: (Score:2)
Likewise, I don't think all that many people tend to make a regular habit of plugging their phones into their computers.
It's perfectly technically feasible, and in all likelihood would be easier for the user to update wirelessly. Requiring iTunes was a business decision plain and simple.
Re: (Score:2)
Mac users were screwed until someone created a hack that would let them work. Early Vista adopters (myself included) were screwed until after the retail release because Sync Center, which replaced ActiveSync, didn't actually do anything like, you know, syncing.
Re: (Score:2)
The iPhone is a flash-based iPod video with a piss-poor phone and some rudimentary web and e-mail clients. Nothing more, nothing less. People with Blackberries and Palm smartphones are thoroughly unimpressed.... when's the last time you saw a story of a non-Mac-fanboi ditching their Blackberry for an iPhone with nowhere near the capabilities of their old device?
Re: (Score:3, Insightful)
Re: (Score:2)
Firmware Updates are done tethered for good reasons. Typically modern cell phones support limited over the air (OTA) updates, but firmware updates fall outside those bounds.
The reasons? If anything goes wrong, the phone is effectively dead. The firmware[1] is the first thing that a phone loads when it is booted. If anything goes wrong during a firmware update and the firmware becomes corrupte
In Your Face "Enterprise" iPhone Bashers (Score:5, Interesting)
There is this meme that the iPhone is not ready for the enterprise because it doesn't have MAPI and special I-T management tools. Yet here we have the first vulnerability in the iPhone and it is promptly patched through a system that will distribute the patches very quickly and easily. A stark contrast to other mobiles. There are multiple holes in Symbian and of course Windows Mobile that remain completely unpatched. Nobody knows when that is going to change. For all the enterprise bluster around those systems they are not patching zero-day exploits.
There are many reasons that the Mac is more secure than Windows, but a big reason is that OS X is such a moving target. Every quarter for 5 years there has been a new version which updates itself automatically. Exploits are made less valuable not just because of the smaller user base than Windows, but also because of the short shelf life of each OS version. The vast majority of Mac users are using the very latest OS and have all the patches applied even though the vast majority of Mac users have no I-T staff and no I-T skills.
When the iPhone first shipped and people started hacking it, there was a lot of talk then that every hack may be temporary, a software update could come down through iTunes at any time and reset the game. There is nothing like that protecting any other mobile.
Re: (Score:2)
And smartphones have been running Windows for 7 years now... no vulnerabilities. I fail to see how that is anything but a huge win for Microsoft.
Re: (Score:2)
Anyone who has done the smallest amount of investigation into the smartphone platforms will know that OTA updates are a standard part of Windows Mobile 6. So somebody does know when it is going to change.
Spin it, baby! (Score:2)
Did they patch that flaw?
(And please provide links to these ZOMG 0-day SPLOITZ! I have a great need to take over phones and bring down the network. HACK THE PLANET!)
Re:In Your Face "Enterprise" iPhone Bashers (Score:5, Insightful)
It is, if you have a PC or mac??? I found it quick and easy. OTA might be a little nicer, but given that I sync once a day or so for calendar updates and other refreshes, it's easy enough.
Tell me, how is IT is going to push patches to the device?
The whole point was they don't need to, because it's easily handled by the user. Less IT work is a good thing, if you can just release your claws a little from grasping everything that comes within reach.
How are users going to know to apply the patch?
Software automatically prompts them to do so within seven days of the last check, so worst case in six days or so the last people should be updating the phones (unless they sync less frequently). Just like OS X updates, with 99% of the user population apply just fine with no IT involvement. I know the concept is just blowing your mind, but updates don't have to involve "support staff".
What if they have disabled patching?
You can't, though you could decline the update. But why would you? Remember, most users just hit "yes".
How do we ensure compliance? What's to stop iPhone 1.0 users/devices from connecting and downloading sensitive data?
Within a week there will be no iPhone 1.0 devices. You aren't getting the Big Picture here.
Here's a pop quiz - the CFO's iPhone is lost/stolen. What do you do?
What you can. Here's the kicker - this is true of your CFO right now, regardless of your feelings! So what are YOU doing other than putting your head in the sand? When have CFO's ever really been "managed" anyway?
Bullshit. Mac OS X is fundamentally unchanged from when Tiger came out two years ago.
Illusion! All those security updates, with patches to sshd and the like - they were all figments!
You have no idea how patching works in IT. We don't necessarily WANT users to have "all the patches applied", at least not right away. IT needs to control patch delivery to limit compatibility issues. Or do you believe that patches never break anything?
More sand-holing. How sad. Learn to deal, you have seven days before everyone is patched, figure it out if something doesn't work - but then again, since you can't install your own software anyway what exactly would break again?? Since you aren't doing the updates why are you taking support calls for the thing? Point them to Apple.
Presumably when third party software arrives, it will keep in step with iPhone updates just as software does with OS X updates.
Windows Mobile 6 devices can be patched over the air, and patch delivery can be managed with a variety of third-party tools.
Oh, you're one of THOSE people. No wonder the big picture is so elusive to you. You've forgotten who you serve.
I'd like to add... (Score:2)
Quickly and easily? That's crap, and you know it. Quickly and easily would be for the iPhone to update over the air, like the T-Mobile Sidekick does. Having to connect the device to a PC running iTunes isn't "quick" or "easy".
It is, if you have a PC or mac??? I found it quick and easy. OTA might be a little nicer, but given that I sync once a day or so for calendar updates and other refreshes, it's easy enough.
Moreover, AT&T can't reliably deliver weather updates and barely gets web pages over it's network. A 7+ MB (or more in the case of Windows Mobile phones) is just not a workable method. Never mind the updates which require nuking all of the data on the phone (typical for WM patches). God help you if your battery goes dead in the process. Sure it would be nice, but when you've been eating shit sandwiches all of your life and someone hands you white bread with cheese and mayonnaise you don't hassle them f
Re: (Score:2)
Mod parent up! (Score:2)
Re: (Score:3, Insightful)
People have complained about how the iPhone is tethered to a desktop computer
Re: (Score:2)
When a user has a problem, WE'RE the support. Not Dell, not Apple, etc. Us. When an executive can't print, we don't tell them to call HP. When the CEO wrecks his home machine downloading spyware, we drive to his house and fix it. I wish this wasn't the case sometimes, but this is how IT support works in large environm
Re:In Your Face "Enterprise" iPhone Bashers (Score:5, Interesting)
Once upon a time, in the distant '80s, there was a large research lab. This lab did a lot of work with computers. The computers of the day were giant VAXen which filled a basement room, with tentacles reaching out to terminals in users' offices throughout the building. The computers was complicated and confusing, and an army of highly trained, very smart support people worked on them. These high priests and acolytes lurked in the basement, worshipping the VAX god and interpreting its prophecies to the users. They did this job well.
But the users looked at the sacrifices they were making to the VAX god and its acolytes, and realized, "I can get much more done with far less money if I buy a small workstation for my office." The priests in the basement said, "but we won't be able to control and service the machine. What will you do when it breaks?" The users replied, "I'll buy a new one. They cost as much as two days of your salary." Lo, the priests in their basement temple feared for their jobs, feared that their great god, the source of their power, would be lost forever.
The priests were right, up to a point. The workstation users discovered viruses, and hackers, and spam, and the rest of the ten plagues of the Internet. They learned to do some of the work the priests once did on the VAX. But the new workstations were so much cheaper, and so much easier to use and maintain, that they found it a fair trade. The great VAX was cast out of the basement, and died the sad death of all forgotten gods, but the priests met a happier ending. The eldest took a generous early retirement; the neophytes re-trained, and learned to serve the new pantheon of desktop workstations. By letting go, by giving up their ability to control and manage and dominate, the priests made their users happier and more productive, and saved the lab a hell of a lot of money.
Then, one day, in the empty, dusty temple where the VAX god was once worshipped, the first Beowulf clusters sprouted. And as they grew and spread their tentacles, a new breed of priests arose to serve them...
Re: (Score:2)
Re: (Score:2)
Hmm so you have to be near another computer to sync your information as well ? I am trying to think far back enough to when I had a "smart" phone that required that. What if I am away from my PC for a week, or 3 days..how erm 2001
The rest of us have moved on from that desktop sync model years ago.
uh...maybe this is a stupid question, but what device are you syncing information on your phone with?
When it comes to phones, i'm not really a "power user". I make calls and store contact information in mine, but i
Who is more ignorant (Score:3, Insightful)
What I am is a security REALIST. What I realize is that people are "in UR Enterprize iPhoneinating UR Network". So who is more ignorant, the one who thinks about how this device can fit in as-is because it's going to anyway even if you don't want it, or someone who whines about lack of IT controlled updates and pretends like it's not already affecting you.
Welcome to real
Do it when you're not expecting a phone call! (Score:2)
Me? I'm bitter and lonely, I could update the phone on my birthday with no concerns.
But normal people will probably want to do it later at night to prevent a painful experience.
Re: (Score:2)
Re: (Score:2)
In other news (Score:2, Insightful)
Seriously, are we going to make a story out of every point release of iPhone's firmware?
iPhone update (Score:2)
It's obvious when you use the iPhone for a while that there are unfinished feat
Re:hmmm or not (Score:5, Informative)
Re: (Score:2)
You could theoretically mod your phone and iTunes wouldn't stop working because of pending updates?
Re: (Score:2)
Re: (Score:2)
Re:hmmm or not (Score:5, Informative)
oops (Score:2, Interesting)
Re: (Score:3, Insightful)
Re: (Score:3, Insightful)
(my update worked without issue, it did "stall" for about 2 minutes during the updating firmware stage)
Re: (Score:3, Informative)
Am I the only one who thinks it's really silly that the only channel through which to update your phone (or, put in another way, your slightly-locked-down, general purpose hand-held computer and communications device) is... is... your MUSIC PLAYER!?
(it is called itunes, no?)
Am I the only one who finds it amusing that people are so desperate to find something, anything, negative to say about the iPhone that they pick something like this to complain about? That, and if you're on a PC and going to sync an iPhone, which includes an iPod (needs iTunes), why would you want _another_ app to do the syncing of the stuff on the iPhone that isn't music? It's the most logical place for that functionality.
Re: (Score:2)
Due to the Slashdot length-between-posts time limit, I have had time to let it finish, and it looks like it worked just fine. Although I currently have no cell phone signal, even though it's in the exact same location that it had a full signal before the update..... Ah, there we go. Signal is back. Sync failed, though. It's losing the connection to the iPhone..
Re:oops (Score:5, Funny)
Re: (Score:2, Insightful)
What web site are you on?
Re: (Score:2, Insightful)
Re: (Score:2)
riiiight (Score:2)
Re: (Score:2)
Slashdot keeps everyone from reposting too often by checking IP-addresses, I think. So in order to accomplish this, the troll has to have control of a number of machines (not behind the same NAT, either!) equal to the number of posts in the sequence.
Re: (Score:2)
Slashdot keeps everyone from reposting too often by checking IP-addresses, I think. So in order to accomplish this, the troll has to have control of a number of machines (not behind the same NAT, either!) equal to the number of posts in the sequence.
Re: (Score:3, Funny)
Remind me not to borrow your iPhone.
Re: (Score:3, Funny)
Yes, waiter, another glass of kool-aid please.
(captcha: ravening)
Re:My iPhone got me laid (Score:5, Funny)
Re: (Score:2)
You still have to pull it off. And somehow I think that someone who posts on Slashdot that an iPhone "got him laid" is not the kind of person who _can_ pull it off.
That's nothing (Score:2, Insightful)
Anybody can get laid with an iPhone.
Re:Uh... (Score:4, Insightful)
Of what use is your comment, exactly?
Re: (Score:3, Informative)
Re: (Score:2)
If they don't patch security holes, what are they then? evil, incompetent, both?
Is Linus evil? Every new kernel he throws out there potentially breaks my custom super secret kernel module!!
Re: (Score:2)
Re: (Score:2)
Reject iTunes, reject iPhone, buy what instead? (Score:2)