Apple: PDF security hole fix is already ready to go
JailbreakMe brought root to the iPhone 4-wielding masses, but also unearthed a nasty exploit in a PDF font. Thankfully for the rooted and those who never intended to root, Cupertino claims it has already patched the hole. "We're aware of the reported issue, we have already developed a fix and it will be available to customers in an upcoming software update," an Apple spokeswoman told CNET. We're not sure exactly when it will arrive, but we'd lay odds on soon -- in the meantime, don't open any PDFs you don't trust, don't do anything illegal or immoral, and hit up Comex's hack ASAP if your heart's still set on that shiny new unlock.
[Image Source: F-Secure]
[Image Source: F-Secure]
























Well that was fast.
@Maxipad I'm still going to jailbreak. WINTERBOARD FTW
@Cainhunpi For some reason Winterboard on my ip4 seems to make all the icons dimmed from the top down getting progressively brighter. I have 0 idea why, and yes I have checked to see if dimm is on, I have reinstalled Winterboard about 10 times now.
That and I am waiting for all theme cool themes to get updated to the Retina display, they all look like garbage.
@Maxipad Oh how quick Apple works putting out software when it comes to fixing a jailbreak issue or blocking an itunes sync from a competitors device ;-).
Now, only if they could work on a better fix than free bumpers. Downrank?
@juanvaldez Except the antenna issue can't be fixed with software.
@Maxipad
Upgrade and lose my jailbreak?? Mmmm that ones gonna have me thinking for about 1.2 seconds
@smcnally No, your wrong, they already came out with that software fix. Oh, the hits just keep on coming.
And, yes, thanks for pointing out the obvious, and still, though I wouldn't support them as a fix-all, having the option for a clear coat (like what's used on cars, on top of paint) to bring the attenuation level down since your skin will no longer being conducted has been proposed. I am not technical enough to know that it works, but it seems people have tried themselves with success with both clear and non-clear paint solutions.
In many ways, it's easier than a software fix, because a caveman can do it. It's just not in Apple's financial priority list? I put a question mark, because that seriously seems like a paradox to me, so I'll give them a benefit of the doubt, they are good when it comes to $$$. So, perhaps something else is at play there, maybe it's as hard as painting a phone white?
@juanvaldez it probably is cheaper to manufacture a piece of rubber that weighs a few grams than apply a clear coat and go through a QC testing, so on 2nd thought, it's probably a cost-benefit decision in their mind that they will never fix before a redesign/new product run (not necessarily a change of the antenna position, just a new phone, either in White or iPhone 5).
@Maxipad That's what she said
@juanvaldez Nah, turn that frown upside--down
@Maxipad "Well that was fast."
You expect any less for a zero-day exploit in the wild that can target 100 million people? Also it's not released yet - I'd guess so they can see if there are any other obvious holes that Comex says he's found and will use once this is patched.
OH GOD!! Say it ain't so!!!! RUN FOR THE HILLS!!
@Juggernaut408 why?
@rmbrown09 The Deathstar has become self aware
@Lord Vader
And how the hell are hills going to save you from a battleship the size of a star?
@Firewave when he force chokes you, I want to hear you beg
Wait, is it "in an PDF font" or "in a PDF font" ?? =o
@D0WN5ID3UP
Now it's been fixed and you look like a silly-Billy because it looks like you're pointing out mistakes that aren't really there.
Silly goose.
@Alex R Quack, quack :p
It's already ready already.
Better get your jailbreakme.com action in soon, kids!
@Error601
That is true. But I'm happy that I finally have the jailbreak for my iPhone 4 w/all the apps/packages that I wanted. I know that I won't be updating to 4.1 anytime soon after they release it.
MORE LIKE SUCKS
@nickyP MROE LKIE SKUCS
@nickyP I'm trying to figure out what Kimora is talking about on E network right now. I mean, who the hell is she and why should I care? Reality TV is the worst. I almost want to bury a time capsule full of reality tv dvd's so in 100 years my great grand children can dig them up and think, "WTF IS THIS CRAP AND WHAT IS THE INTERNET?" Typical for sure. I hope that snakes don't break my iphonez.
@rmbrown09 What's N-X-E-T?
You hear that Comex?
It's kind of ironic that in order to stop the exploit u have to jb and download a cydia. App
@alex2792 Unfortunately updates for most security related issues only come over public pressure from the mainstream media. Its odd, we're likely on a collision course until viruses start killing peoples phones.
@nickyP What makes you say that? It's not like Apple knew about this before.
@mgrochowalski I don't really have a real point I just hate Apple.
Yeah... that's my reason for "pardoning" (it is legal now) my iPhone... to fix a security flaw... that's all.
walled gardens are made to broken.
@LazyKid
made to be broken
I hate this whole cat and mouse game w/Jailbreaking, ugh.
@EagleyeSmith
Hey, at least it's not eFuse, which is ironically highly praised by many.
Does anyone else think of doom when they see that .wad file?
The good old days of DOS and modified doom .wads.....
Not on topic but nostalgia is important nonetheless.
@intrglctcrevfnk
I meant wad. Not .wad. Although on DOOM it was doom.wad
Just go to Cydia and add PDF Loading Warner to you apps. It will warn you when a PDF file is about to be loaded. Apple should be paying these guys for every hack they find. I gave them $20. Thank you Dev Team and Muscle Nerd.I love my jailbroken 3Gs running on 4.0 with less expensive T mobile serrvice.
@shell56xxx
And with less broadband speed :/
@shell56xxx Amen! Still running 3.1.2 tho ...feels like I have 4.0 tho :)
"We're aware of the reported issue, we have already developed a fix and it will be available to customers in an upcoming *hardware* update,"
Be funny if they were talkin' bout the fix for the antenna gap.
Wait, is this going to stop
jailbreak? :[
@guitarkid No, not unless you update to the new firmware. But who would want to? We have all the features we need now.
Hmmm...
I hacked my iPhone using jailbreakme, and all it does is add problems... Things lag now, some apps don't even start... Pfft...
I'd rather have 4.1.
@APV Get an iPhone 4. What did you do jailbreak your 3G?
@asharillc
1.) I sadly am one of the people that think the iPhone 4 is fuckin' ugly.
2.) I am not buying one.
3.) I don't want a droid either, because who knows what phones will support even just the firmware updates... ugh... That stuff isn't something I'd want in a device, fragmentation...
4.) That leaves Blackberry and Windows Phone 7... Oh well... The world can't be perfect. Maybe I'll live with it and see what they concoct with the iPhone 5.
From my understanding this jailbreak already doesn't work on 4.1 as the issue was patched in Safari for OSX last year and so the fix was finally added in 4.1 beta for iOS before the jailbreak was even released.
I'm waiting for 4.1 to jailbreak anyways, first there are very few iP4 designed jailbreak apps atm, plus I don't want to deal with the hassle of upgrading firmwares with a jailbroken phone.
I'm betting they already have at least 1-2 other holes to jailbreak with, ones that are usb based, and that the only reason that they released this now was because the 4.1 patch kills it and they wanted to show off and let people play around with the jailbreak some.
Plus it allows Jailbreak App devs to start working on iP4 apps and lets the Dev Team work out all the bugs with a nice big debug team.
So is jailbreakme.com a bad thing? Does it work smoothly? Just waiting for everything to convert to 4.0 before jailbreaking. I want all the kinks ironed out
Billy Singvosa is gay
The only difference between Apple/Adobe/Microsoft, is that Apple's PR department is ON ITTTTT!