Security flaw discovered iOS 4.1
A new security flaw was discovered in iOS 4.1, this flaw allows access to the directory of an iPhone protected by a password.
Handling is fairly simple, just to have an iPhone on iOS 4.1 Protecting a password and :
- Click "Emergency Call"
- Type a number at random, ex: 1234
- Tap on "Call" followed immediately:
- Pressing the power button on the top right.
If you were fast enough, you should find yourself in the application "Phone" of the iPhone and can see the different contacts and even call them!
Namely, this flaw does not appear to be present in the beta iOS 4.2 but there is no fix to date for version 4.1, either by Apple or Cydia.
Apple FaceTime “security flaw” fixed
Apple has fixed the security flaw on the server-side.
But you can fix the flaw for your already logged account like this :
Go to your User Folder / Library / Preferences and delete com.apple.FaceTime.plist
FaceTime for Mac opens the door to a big security flaw in the Apple ID
At the same time as the new MacBook Air and Mac OS "Lion", Steve Jobs introduced FaceTime for Macintosh.
Unfortunately, it seems that the software is equipped with a security rather consistent.
Indeed, it seems that once identified with his Apple ID with the application, a user can change the password directly, without having to enter first the old password.
Suddenly, any person sitting behind the computer can compromise the account associated with an open session. This is for the entire Apple ID. Thus, if the rightful owner of the account as stolen at the same time is connected to iTunes, then it will deny access and the new password will be requested.
The attacker, he may at leisure offer music of your choice on your money.
In short, a flaw which is not critical but may, under certain conditions, cause many problems.

