Older Apple iOS devices must jailbreak to be secure -- oh the irony
Remember that nasty PDF bug that allowed potentially malicious code to be executed on your iOS device? Right, the one that Apple recently patched with the iOS 4.0.2 software update, slamming the door on jailbreakme.com. Well, if you own the original iPhone or iPod touch you're still at risk since Apple's update isn't compatible with those devices. Hell, many iPhone 3G owners are also at risk after rolling back their handsets to iOS 3.1.3 due to sluggish (to put it mildly) performance running iOS 4. So what can you do to protect yourselves? Jailbreak. As counterintuitive as that sounds, Jay Freeman (aka @saurik) just released a patch onto Cydia (search for "PDF Patch") for all iOS devices, no need to update to 4.0.2. Of course, jailbreaking presents its own set of risks, so be careful -- and for crissake be sure to change the root password if you install SSH.























apple just got pwned
This really is a huge security threat, and should be more widespread among mainstream media. How can Apple so faithlessly abandon older users?
Take a look at Microsoft, they even provide security patches for Windows NT right now. Not fair, Apple.
@FrmrPSPCoderTOPAppStoreDev
Hang on, are we sure older users have been abandoned, or is it just not fixed yet.
@Cupid Stunts
We all know Apple (a long with most companys) make it so you will WANT a new phone and get rid of your current one. And Windows only does security fixes for XP and up now. They tried to get people off XP, but there are simply to many corp. computers still running it.
Don't get me wrong, I am not defending Apple, I honestly do hate them as a corporation, but its simply business like to stop maintaining older devices once they are a few years old (like the 3G), however, they have no excuse to not maintain the 3GS since its still a highly used Apple product.
3G is acceptable to stop maintaining tho. It's pretty dated now.
@corylulu
Well, it's really hard when they spit a new device out every year at the same time, literally... And it also hurts when each new device has 1 or 2 not REALLY needed features that just aren't worth the extra 100$.
@corylulu
Company = singular
Companies = plural
Did you graduare the 5th grade?
@corylulu The 3G isn't that dated yet. Compared to Win XP it is still almost brand new!
And yeah, MS tried to stop support for XP - because it IS pretty old now, and it costs them lots of money to keep the patches coming. (And of course to get people/corps. to buy their new OS.)
A corporation that is still running NT (2K).... does that even exist? That OS is 10 years old now...
If XP was only 2-3 years old (like the iphone 3G) it would be a different situation.
If Apple doesn't release the patch they seriously suck donkey tits.
@corylulu really? you could have bought an iPhone 3g NEW from apple as little as 3 1/2 months ago. Why should stop supporting it? NOT TO MENTION its 95% identical to the the 3gs. there is no excuse for this. PERIOD!
@HighestRanked1 graduare?
@HighestRanked1
graduare?!
If you gotta jailbreak your phone to secure it... you blew it!
Sorry, could not resist!
@HighestRanked1
"Graduare"! You must be feeling pretty stupid about now.
@FrmrPSPCoderTOPAppStoreDev
Original iPhone owner & USER checking in... class action, anyone?
Frankly, this is one more reason for me to upgrade to an Android phone when the time comes.
@sullivan504 don't buy one, install FroYo on your iPhone =D www.idroidproject.org I believe. I agree: i'm still using my original iPhone, and may be for the next year too, if the phone works, I don't want to be like a Android or iPhone fanboy getting each good new phone that comes out from each side.
@Nehebkau Windows XP will only be obsolete until Microsoft and software companies finally axe support for the operating system. Until then, it's just as good as it's successors.
Just my two cents.
While I don't expect full feature upgrades on my iPhone2G 3 years out, I do expect companies to keep us updated if such a serious security flaw as this is found. I am certain Google, RIM, or MSoft would have. Stupid Apple.
@timriley The iPhone 2G does not run iOS 4. This is not a concern.
@mutelight Please read the article. The exploit exists on all iPhones running at the very least any version of iOS3 or 4, except 4.0.2. The whole point is that the 2G is unsecure BECAUSE it is not running iOS4.
@mutelight you suck. that is all
@clarinetJWD I skimmed the article, I apologize, I didn't realize that it affected 3.1.3 as well.
@androidfan1 Keep it real, pimp. After you are done maintaining your womens, read the post directly below yours, I am not hesitant to call them out on their BS.
@timriley Not to mention that a lot of iPhone 3G owners do not want to upgrade their devices to iOS 4 because it doesn't offer any compelling features and, by most accounts, degrades phone performance.
Are they even trying to support their older devices anymore? I have an iPhone 4 and I won't touch this update with a 10 foot pole because I like being able to use my device as I wish (volume button shutter, emulation, etc.) but stop worrying about this PDF exploit and start fixing the horrid battery usage and performance of the 3G! OK, so this person has a 3G iPhone, which is now two generations old, now make them want to buy the next one by showing your product support! Apple, you built such a great phone that was "revolutionary" back then, show the end user that. The incremental upgrade every year will only last so long.
I do like Apple's man-to-machine UI design and fluidity but it is starting to end at that. They rely on the faithful, don't lose them.
It seems they [apple] are trying to kick the faithful in the balls.
@Avaviel No joke.
@Avaviel Naw, Apple is just breakin you off some. Little fragments.
I think the word Jobs used to describe developers not fixing bugs was "lazy".
Apple business model has always been release and then upgrade, What once was powerful 2 years ago now isnt even supported, I mean come on Apple, honestly? Not everyone has money to just "upgrade" every year
@AlienSix
Piles of older generation Android phones are also not compatible with 2.2 and receive significantly far less upgrade support from the csrrier, much less Google. And the same went in the days of WinMo. It's not an issue particular of Apple only.
@AlienSix Unfortunately they expect that now. They do have it figured out regarding customer demand and polish but they are a little to forward with the "throw-away" tactics in making people want to upgrade every year. It has worked pretty well for them thus far but with competition constantly evolving, they will hopefully be forced to better their legacy products.
@HighestRanked1 Winmo and Google dont just have one handset. I dont deny that Winmo and Android have issues with Manufacturers following thorough with updates but the iPhone is on a 12 month cycle and the 3G is all of a sudden not good enough for adequate security updates?
@HighestRanked1
"Piles" of Android phones did not come with the Adobe Reader installed and are not effected by the issue. Plus, this would not be a OS upgrade for Android.
@HighestRanked1
No, if you look at the Android OS version numbers published by Google you will see "piles" of phones are being upgraded nicely.
Vendor support is inherently a bigger issue with the Android platform because it is up to the manufacturer to support the phone. This also allows for consumer choices.
Apple claims having one vendor is their advantage, but this article, and the comments, show they are not providing the support, or unification they claim to have.
So the iPhone platform is running on different OS versions with different levels of support.
You can still buy the iPhone 3G on the AT&T web site!
FIRST
@androidfan1 Give it a rest and fail...
@androidfan1
First as in 7th?
@androidfan1
Oh look its someone unfit to be a human being.
@androidfan1 'First to fail' is what I think he meant...
Terminal crashes on 3GS with 4.0.1. Can't change password.
@Unfwithable 99% sure you're infected by that SSH worm. Wipe and restore is only fix if so.
@Thomas Ricker Can't be. Only network I've used is mine, and it's pretty secure.
@Unfwithable try to SSH in with password "ohshit" If that works then you're part of the botnet.
I was infected once and my device had exactly the same symptoms as yours. Hopefully, you're ok.
@Unfwithable Do you have MobileTerm version 426? If it's older or the one in Cydia, it's not compatible with iOS4.
You can always SSH via OSX Terminal or Putty and change password that way. (Faster anyway)
@illutionz I would recommend getting MobileTerminal 364.3 from http://bit.ly/aFaFmX instead, as 426 is missing most of the features, like gestures and even scrolling.
Actually everyone not running 4.0.2 running should get the patch, newer phones on 4.0.1 and lower are still at risk
Since when has Apple gone all sloppy on us? I find that quite odd. Although I am seeing some pretty good comments that suggest otherwise! }:-)
Not releasing security updates for a device that's still very commonly used is really a bad move. If I was a corporate IT department, it would worry me a lot to know that security updates would be unavailable for a device well within its expected lifespan.
@Tired Agreed. Apple is and has been, making their devices to disposable.
@Tired Corporate IT departments are filled with bozos who move like snails. That's why they still use windows xp and IE6. apple does not want to deal with orfices called IT managers.
Steve Jobs=Adolf Hitler
Lol. Fragmentation at it's finest. Raise that bar apple.
Wow. So much for testing. They had 3 phones to test this patch for and they failed. This is why people should have more respect for companies like Nokia and HTC. When they test, they have to test a LOT. awaiting for a press conference where Jobs shows us the impressive room for testing full with PhD testers.