<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>VentureBeat &#187; lockscreen</title>
	<atom:link href="http://venturebeat.com/tag/lockscreen/feed/" rel="self" type="application/rss+xml" />
	<link>http://venturebeat.com</link>
	<description>News About Tech, Money and Innovation</description>
	<lastBuildDate>Wed, 19 Jun 2013 10:41:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='venturebeat.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/c6d8c27ffa1c5a7f106f97e434437baf?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>VentureBeat &#187; lockscreen</title>
		<link>http://venturebeat.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://venturebeat.com/osd.xml" title="VentureBeat" />
	<atom:link rel='hub' href='http://venturebeat.com/?pushpress=hub'/>
<copyright>Copyright 2013, VentureBeat</copyright>		<item>
		<title>Researchers dig up another iOS 6.1 lockscreen exploit</title>
		<link>http://venturebeat.com/2013/02/25/ios-6-1-lockscreen-exploit/</link>
		<comments>http://venturebeat.com/2013/02/25/ios-6-1-lockscreen-exploit/#comments</comments>
		<pubDate>Mon, 25 Feb 2013 20:50:21 +0000</pubDate>
		<dc:creator>Devindra Hardawar</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Mobile]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[bugs]]></category>
		<category><![CDATA[exploits]]></category>
		<category><![CDATA[hacks]]></category>
		<category><![CDATA[iOS]]></category>
		<category><![CDATA[iOS 6.1]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[lockscreen]]></category>

		<guid isPermaLink="false">http://venturebeat.com/?p=628043</guid>
		<description><![CDATA[<p>The iOS 6.1 lockscreen hack from earlier this month isn't the only security vulnerability in Apple's latest mobile&#160;OS.</p>
<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=venturebeat.com&#038;blog=342986&#038;post=628043&#038;subd=venturebeat&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<div class="post-boilerplate boilerplate-before"><div class="event-boilerplate-mobilebeat">
<div class="logo-date-wrap">

<a href="http://mobilebeat2013.com" data-vb-ga-outbound="MB2013boilerplateTOP"><img alt="MobileBeat 2013" src="http://venturebeat.files.wordpress.com/2013/02/mobilebeat-boilerplate.png" /></a>
<div class="date-location"><strong>July 9-10, 2013</strong><br />
San Francisco, CA</div>
</div>
<a class="cta" href="http://mobilebeat2013-MB2013boilerplateTOP.eventbrite.com/" data-vb-ga-outbound="MB2013boilerplateTOP">Tickets On Sale Now</a>

</div></div><p><img class="size-full wp-image-351086 aligncenter" alt="iOS update" src="http://venturebeat.files.wordpress.com/2011/11/screen-shot-2011-11-10-at-12-50-21-pm.png?w=634&#038;h=526" width="634" height="526" /></p>
<p>The <a href="http://venturebeat.com/2013/02/14/ios-6-1-lockscreen-bug/">iOS 6.1 lockscreen hack </a>from earlier this month isn&#8217;t the only security vulnerability in Apple&#8217;s latest mobile OS.</p>
<p>Benjamin Kunz Mejri, the chief executive of the security firm <a href="http://www.vulnerability-lab.com/" target="_blank">Vulnerability Lab</a>, detailed yet another iOS 6.1 hack last week in <a href="http://seclists.org/fulldisclosure/2013/Feb/90" target="_blank">the Full Disclosure mailing list</a>. The hack enables attackers bypass your iPhone&#8217;s lockscreen password, giving them access to your phone&#8217;s contacts, photos, voicemails, and more.</p>
<p>Judging from Mejri&#8217;s description, the new hack seems related to the earlier iOS 6.1 lockscreen exploit. Both involve using the iPhone&#8217;s emergency call function, cancelling it immediately, and then trying to make a screenshot. But the newer attack takes advantage of a slightly different method to make the iPhone vulnerable (basically, pressing the power, home, and emergency call buttons all at once).</p>
<p>Apple acknowledged the previous iOS 6.1 security flaw and <a href="http://9to5mac.com/2013/02/21/apple-releases-ios-6-1-3-beta-2-to-developers-for-ipad-iphone-and-ipod-touch/" target="_blank">quickly issued a fix to developers </a>with the second iOS 6.1.3 beta. That update hasn&#8217;t yet trickled down to iPhone owners, and it&#8217;s unclear if it also fixes Mejri&#8217;s exploit.</p>
<p>Here&#8217;s how Mejri describes the exploit in his e-mail to Full Disclosure:</p>
<blockquote><p>The vulnerability is located in the main login module of the mobile iOS device (iphone or ipad) when processing to use the screenshot function in combination with the emegerncy call and power (standby) button. The vulnerability allows the local attacker to bypass the code lock in iTunes and via USB when a black screen bug occurs.</p>
<p>The vulnerability can be exploited by local attackers with physical device access without privileged iOS account or required user interaction. Successful exploitation of the vulnerability results in unauthorized device access and information disclosure.</p></blockquote>
<p>Check out a video of the exploit below:</p>
<p><span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='560' height='345' src='http://www.youtube.com/embed/oKOj0GMf810?version=3&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;wmode=transparent' frameborder='0'></iframe></span></p>
<p><em>via <a href="http://arstechnica.com/apple/2013/02/researchers-find-yet-another-way-to-get-around-ios-6-1-passcode/" target="_blank">Wired</a>, <a href="https://threatpost.com/en_us/blogs/another-iphone-passcode-bypass-vulnerability-discovered-022513" target="_blank">ThreatPost</a>; Photo: Devindra Hardawar/VentureBeat</em></p>
<br />Filed under: <a href='http://venturebeat.com/category/business/'>Business</a>, <a href='http://venturebeat.com/category/mobile/'>Mobile</a>, <a href='http://venturebeat.com/category/security/'>Security</a>  <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=venturebeat.com&#038;blog=342986&#038;post=628043&#038;subd=venturebeat&#038;ref=&#038;feed=1" width="1" height="1" /><style type="text/css">.boilerplate-before .event-boilerplate-mobilebeat {
width:278px;
margin:0px 0px 10px 20px;
padding:10px;
float:right;
border:1px solid #e4e4e4;
font-family: 'Open Sans', sans-serif;
color:#000;
}
.boilerplate-before .event-boilerplate-mobilebeat .logo-date-wrap {
width:100%;
display:block;
float:left;
margin-bottom:8px;
}
.boilerplate-before .event-boilerplate-mobilebeat img {
float:left;
}
.boilerplate-before .event-boilerplate-mobilebeat .date-location {
float:right;
font-size:12px;
line-height:14px;
text-align:center;
padding-left:7px;
padding-top:5px;
padding-bottom:3px;
border-left:1px solid #e6e6e6;
color:#585a5b;
}
.boilerplate-before .event-boilerplate-mobilebeat .cta {
display:block;
clear:both;
width:100%;
border-radius:5px;
border:1px solid #1864b1;
color:#fff;
text-shadow: 0px -1px 0px rgba(0,0,0,0.3);
text-align:center;
text-decoration:none;
font-weight:600;
font-size:18px;
line-height:17px;
padding:4px 0px 6px 0px;
background: #1f80e4;
background: -moz-linear-gradient(top,  #1f80e4 0%, #1862ae 100%);
background: -webkit-gradient(linear, left top, left bottom, color-stop(0%,#1f80e4), color-stop(100%,#1862ae));
background: -webkit-linear-gradient(top,  #1f80e4 0%,#1862ae 100%);
background: -o-linear-gradient(top,  #1f80e4 0%,#1862ae 100%);
background: -ms-linear-gradient(top,  #1f80e4 0%,#1862ae 100%);
background: linear-gradient(to bottom,  #1f80e4 0%,#1862ae 100%);
filter: progid:DXImageTransform.Microsoft.gradient( startColorstr='#1f80e4', endColorstr='#1862ae',GradientType=0 );
}</style>]]></content:encoded>
			<wfw:commentRss>http://venturebeat.com/2013/02/25/ios-6-1-lockscreen-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	<enclosure url="http://venturebeat.files.wordpress.com/2011/11/screen-shot-2011-11-10-at-12-50-21-pm.png" /><source url="http://venturebeat.com/2013/02/25/ios-6-1-lockscreen-exploit/">Researchers dig up another iOS 6.1 lockscreen exploit</source>
		<media:content url="http://0.gravatar.com/avatar/9045353f22a9cfd0a89654b5de70aa65?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">devindrahardawar</media:title>
		</media:content>

		<media:content url="http://venturebeat.files.wordpress.com/2011/11/screen-shot-2011-11-10-at-12-50-21-pm.png" medium="image">
			<media:title type="html">iOS update</media:title>
		</media:content>
	</item>
	</channel>
</rss>
