iPhone OS 3.0.1 update released, fixes SMS vulnerability (updated with statement from Apple)
Looks like Apple pulled the trigger on patching that nasty iPhone SMS vulnerability a little earlier than we expected -- the iPhone OS 3.0.1 update just hit iTunes. It's not some lightweight, either: you're looking at 280MB of love here, so get downloading, friends.
Update: Here's what Apple rep Tom Neumayr had to say about this little episode.
[Thanks to everyone who sent this in]
Update: Here's what Apple rep Tom Neumayr had to say about this little episode.
Well... what do you know about that?We appreciate the information provided to us about SMS vulnerabilities which affect several mobile phone platforms. This morning, less than 24 hours after a demonstration of this exploit, we've issued a free software update that eliminates the vulnerability from the iPhone. Contrary to what's been reported, no one has been able to take control of the iPhone to gain access to personal information using this exploit.
[Thanks to everyone who sent this in]





















hmm think ill just wait until 3.1 before I have to re-jailbreak
I concur. Not loosin' slingbox over 3G for this ;)
Also nice going Apple making people download the whole 300mb iPhone OS again for a .01 upgrade instead of a 50kb patch.
But what if someone sends you an SMS that makes your jailbroken iphone take down the entire cellular network?
AT&T Customers would probably cheer!
...and itunes/pre syncing? :)
@ OneLove
This is an iPhone update, not an iTunes update.
How on earth can an update patch to a newly released massive update to the O/S be 280mb?!?!?
That's some pretty shocking bloat.
It's because Apple makes you download the whole firmware image instead of just a simple patch.
@Ernesttechuser - And people make fun of Microsoft bloat. Holy crap, Apple
@Ernest: That's how Apple does it. Every other company has figured out how to do incremental updates, but Apple still can't seem to, and instead they make you download the entire software/OS (they do the same for iTunes updates as well)
^ Not developers ^
My bad, Reading fail, etc. (...and it's Friday)
Apple used to do delta updates for the iPhone 2 years ago. The only reason I can think that they stopped doing them is due to the problems they had when applied to a jailbroken device.
Why does file size matter? Are you guys downloading the update over dial-up?
@ Jeff
they can't find anything else to complain about.
lol you gotta love that statement ... apple just had to stress that its a "free" update ... lol good thing the ipod cant text message or you would have to pay $5 to get a security patch.
Beside the benefit of not needing to install 10 little patches to update your whatever if it goes splat I find it pretty freakin tedious that a patch needs the whole mushy mess just to tweak a line if code.
How's about a half way option where it downloads the patch into the image stashed in iTunes and then reloads the updated image.
Mine was only 230.1 MB
mine 228mb
@ Cy:
Because there's nothing tedious about a 5-minute download. I'd imagine just about everyone who can afford a monthly iPhone data plan can afford (and has) broadband web access.
does anybody see any issues? my iPhone behaves kinda funny after the patch. Basically when I turn it on nothing happens, I have to click the big button 2x
it's really weird and really really annoying
@d889 - Apple don't make you pay for point upgrades on the Touch, only major revisions. So any security patch for the iPod Touch would be free.
Why don't all you complainers just go to apple and give back the phone and shut the he'll up . You sound stupid. You complain about an update that takes a few mins. no matter how apple wants to do it why do you care. Yet here you are using the iPhone. You guys are probably the same ones still living in moms basement and using her phone service.
lol at the jailbreakers
LOL at the tools like you!
Jailbreaking is great for Apple... that means more iPhones in the wild. Plus "LOL AT&T USERS" is required here.
Why LOL at Jailbreakers, they are the ones inovating for the IPhone, Apple has fallen behind someone has to pick up the slack. Not to mention their horrible App store policies preventing perfectly good apps on there like the original slingbox app over 3G, google voice app, those types of things! Maybe if Apple and AT&T didn't suck so much in that respect people wouldn't have to jailbreak. It's more like LOL at you for not fully utilizing your iPhone.
@ Kanos :: He probably doesn't even have one.
My Tron theme laughs at your un-jailbroken phone: http://www.modmyi.com/forums/new-skins-themes-launches/678618-tron-v1-1-release.html
The problem with themes is that you'll always have an app that sticks out like a sore thumb.
@TREX6662k5: you can always just make your own icon to match the skin, most skins also provide a psd for the basic icon stucture/design so that you can make your own
That's why I just get my page 1 set with all the "themed" icons, and leave the other pages with their defaults. Keeps it simple (so I don't go crazy finding icons for every app) and leaves things like games with their original artwork.
@Jahooba - haha that is some ugly ass shit
@TREX6662k5: this is quite true.. it annoyed me as well but i used a theme i found at http://iphonethemes.net that skins the icons it self.. something to do with overlay.. idk but it was cool.. have to put it again after jailbreaking this new update
- Yunus
3.0.1 can be jailbroken, just FYI. You're an idiot for laughing out of ignorance..
Breaking news for a 0.0.1 update! This must be Engadget!
Yeah, it's not like the SMS vulnerability was a hot topic or anything.
It was a "top story" on BBC's website yesterday :P
Awesome! Hello thar panic reaction!
Tell me, Mr. Anderson... what good is a phone call... if you're unable to speak?
Let's not make fun of the verbally challenged.
@ professorDex
matrix reference.
@ mike - he probably knew that. Sarcasm++
wow at "Mr Anderson",, you so reminded me of the Matrix hehe
MSM: I believe -that- was the point?
There is no spoon.
There is however a month of non activity then a frantic rush to get a patch out the door.
"There is however a month of non activity then a frantic rush to get a patch out the door."
I don't think so. I'm sure it was being addressed the moment they were notified, "Months ago," as Charlie Miller stated. I theorize that Apple waited until after yesterday's announcements at Black Hat to make the patch available, in case there was some new angle that Miller added in late in the game yesterday that might have to be patched again, days later.
Either way, it's been addressed, to the dismay of Apple haters everywhere!
Does it break teathering?
except for the fact that engadget is covering this due to the controversy surrounding Apple initially choosing to ignore the huge security flaw while its competitors have already addressed and fixed the issue, who only bit the bullet because it was publicly demonstrated. Apple doesn't want any more negative press than they are already getting these past couple of weeks. Get off of Engadget's nuts.