Hacker claims Siri bypasses passcode to allow access to iOS 7 contacts

ios-7-logoEgyptian neurosurgeon and part-time iPhone baseband hacker Sherif Hashim appears to demonstrate a privacy failure in iOS 7 that allows a user to access the contact list on an iPhone even when the phone is locked. The trick takes advantage of a glitch in Siri that occurs when the voice assistant is available on the lock screen of the device.
In the video below, Hashim walks us through the trick that requires a user to activate Siri and access the contact list by saying “Contacts.” This will fail when Siri prompts the user to enter their passcode. The user can then hit “Cancel” and ask Siri again to make a call by saying “Call.” Siri then asks the user “With whom would you like to speak?,” allowing the user to enter a letter like “A” and access all the contacts that begin with the letter “A.”

0 Comments:

Post a Comment