Security firm claims bug can prevent iPhone remote wipe from working as advertised

Advertisement
By Reuters | Updated: 4 October 2013 10:53 IST
A German security company has uncovered a bug in the new iPhone's software that it said enables hackers to overcome a safeguard allowing users to remotely wipe stolen or lost phones.

Berlin's Security Research Labs, known as SRL, said on Thursday that the vulnerability could potentially give criminals time to break into the Apple Inc phones, gain complete control of data, access email accounts and then potentially take over the user's bank accounts.

The research firm also said it has figured out an easier way to crack the iPhone fingerprint scanner than has been demonstrated thus far.

Advertisement

It published a video demonstrating the newly discovered flaws on its website.

SRL, which this summer disclosed a major security flaw in SIM card technology that affected mobile systems around the globe, said it has shared its research with Apple's security team.

Advertisement

Apple declined to comment. The company sometimes refrains from discussing potential security bugs while it reviews research.

If SRL's findings are verified, this would mark at least the fifth security bug in the iPhone and its iOS operating system uncovered since July. Apple has already fixed some of those flaws, including one disclosed at a summer hacking conference that make the devices vulnerable to snooping.

Advertisement

The company has remained silent since concerns have been raised about the security of its "Touch ID" fingerprint scanner on its top-of-the-line iPhone 5s (Review I Pictures), which went on sale last month.

A German hacker known as Starbug was able to crack Touch ID within two days of its release. Several experts in mobile security and biometrics say they have independently verified his work.

Advertisement

(Also see: iPhone 5s fingerprint scanner Touch ID 'hacked' by German group)

Another way to skin a cat
Apple's "Find My iPhone" feature aims to thwart thieves and hackers. It lets users log into Apple's iCloud and wipe a device, giving victims a chance to disable the phone before criminals can gain access. It also prevents criminals from registering those devices to another account.

Ben Schlabs, an SRL project manager in biometric security, told Reuters he has identified a new method for preventing those features from being initiated.

He was able to put an iPhone 5s on "airplane mode," cutting off iCloud's ability to communicate with the device to initiate the features. That bought him time to create a "fake finger" to fool Touch ID.

He said he created a fingerprint mold using the same basic approach as Starbug, who took a photo of an iPhone user's fingerprint with a high resolution camera, printed it out on a plastic sheet, then etched the mold.

Schlabs used a previous-generation iPhone 4S to take the photo. Once he gained access to the iPhone 5s with the fake finger, he looked up the user's email address. He then went to Apple's website on an ordinary computer and instructed it to send credentials for resetting its password to the account of the phone's owner.

At that point, he turned off airplane mode for several seconds: just enough time to retrieve email, but not enough for the "Find My iPhone" feature to disable the device or initiate a wipe.

Once he reset the password, Schlabs said he was able to completely "own" the iPhone: he could take over accounts from outside email providers, and reset passwords by getting email providers to send SMS messages to the hijacked phone.

"Once you have access to the email, you can engage in total online identity theft. You can get bank credentials or anything else," Schlabs said.

Chris Morales, a hacking expert and research director with NSS Labs of Austin, Texas, said the growing research on Touch ID underscores what members of the security community have long known: biometrics are not as secure as passwords.

He said a facial recognition feature in Google Android operating system has been defeated using photos.

"As bad as passwords are, it's more secure to know something than to be something," Morales said. "Biometrics only extends security for people who are extremely lazy."

IPhone users can take steps to mitigate the potential for attacks using the newly identified approach, Schlabs said. For instance, users can adjust the phone's settings to prevent airplane mode from being activated when devices are locked.

Customers in Australia, Ireland, New Zealand, the United Kingdom and the United States can opt for two-factor authentication, which requires the user to enter a four-digit code that is sent to their iPhone or other device.

© Thomson Reuters 2013

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Apple, Apple iPhone, SRL, iPhone 5s
Advertisement

Related Stories

Popular Mobile Brands
  1. Xiaomi 17 Max Debuts With 8,000mAh Battery, Leica-Tuned Cameras: See Price
  2. HMD Vibe 2 5G Launched in India With 6,000mAh Battery
  3. iQOO Pad 6 Pro, iQOO TWS 5i Debut at These Prices: See Features
  4. Samsung Galaxy S27 Pro Leak Hints at Major Shake-Up for Galaxy S Lineup
  5. Oppo Find X9 Ultra Launches in India With Hasselblad-Tuned Camera Setup
  6. PS Plus Prices Hiked Across All Tiers in India: Check New Pricing
  7. Oppo Enco Air 5 Pro With 12mm Drivers Arrives in India at This Price
  8. Oppo Find X10 Series Tipped to Launch With Notable Battery Upgrades
  9. Vi Expands 5G Footprint in West Bengal, Plans Rollout Across 10 Cities
  1. Google’s Gemini Offers Agentic Design Creation With New Adobe and Canva Connectors
  2. Xiaomi 17 Max Launched With 8,000mAh Battery, Leica-Tuned 200-Megapixel Rear Camera: Price, Specifications
  3. Honor Win Turbo China Launch Date Revealed as Tipster Leaks Key Specifications
  4. Oppo Enco Air 5 Pro Launched in India With Up to 54 Hours of Music Playback, 12mm Drivers: Price, Features
  5. Vi Expands 5G Network in West Bengal, Plans Rollout Across 10 Cities
  6. Sony Hikes PS Plus Prices Across All Tiers in India: Check New Pricing
  7. Vivo Y600 Turbo Launch Date Revealed as Tipster Leaks Handset's Key Specifications
  8. Oppo Reno 16, Reno 16 Pro Rear Camera Details Teased as Details of India Launch Timeline Surface Online
  9. Vivo S60 Colour Options Revealed Days Ahead of Launch in China: Expected Specifications, Features
  10. Google Is Bringing AI Studio to Android Smartphones, Will Let Users Vibe Code Apps
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.