{"id":16397,"date":"2015-10-23T00:00:00","date_gmt":"2015-10-22T22:00:00","guid":{"rendered":"https:\/\/www.soundpr.it\/post_news\/siri-porta-daccesso-per-gli-hacker-sophos-spiega-come-contrastare-il-bug-che-spaventa-gli-utenti-apple\/"},"modified":"2015-10-23T00:00:00","modified_gmt":"2015-10-22T22:00:00","slug":"siri-porta-daccesso-per-gli-hacker-sophos-spiega-come-contrastare-il-bug-che-spaventa-gli-utenti-apple","status":"publish","type":"news","link":"https:\/\/www.soundpr.it\/en\/news\/siri-porta-daccesso-per-gli-hacker-sophos-spiega-come-contrastare-il-bug-che-spaventa-gli-utenti-apple\/","title":{"rendered":"Siri way of access for hackers,  Sophos explains how to oppose to the bug that is scaring Apple users"},"content":{"rendered":"<p>Watch out, iDevice owners!<\/p>\n<p>Siri has opened the <a href=\"https:\/\/nakedsecurity.sophos.com\/2012\/07\/30\/apple-to-mountain-lion-users-tell-us-who-your-friends-are-if-you-want-to-talk-to-us\/\">pod bay door<\/a> to let snoopers\u00a0in.<\/p>\n<p>Barely a week after the release of <a title=\"Naked Security: Apple iOS 9 is out with a LOT of security holes patched\" href=\"https:\/\/nakedsecurity.sophos.com\/2015\/09\/17\/apple-ios-9-is-out-with-a-lot-of-security-holes-patched\/\">iOS 9<\/a>, a hacker has found a way for\u00a0snoops to access your contacts and photos and send messages without your passcode.<\/p>\n<p>The bug affects iOS 9 and iOS 9.0.1 on iPhones, iPads and iPods.<\/p>\n<p>The security flaw allows a malcontent with physical access to your\u00a0iDevice to use Siri to bypass\u00a0Apple&#8217;s Lock screen\u00a0\u2013\u00a0even if you have set up Touch ID with your fingerprint.<\/p>\n<p>\u2192 Touch ID doesn&#8217;t help here. When you set up Touch ID, iOS requires you to have a passcode too, and you can always tell the Touch ID login process that you want skip trying your fingerprint and use your passcode instead. From that point, you can use this hack.<\/p>\n<p>We&#8217;re not going to explain exactly\u00a0how you can get around the lock screen,\u00a0because Apple hasn&#8217;t fixed the bug yet\u00a0\u2013 we&#8217;re sure you can see\u00a0it demonstrated elsewhere if you really need to know.<\/p>\n<p>In general terms, the bug allows you\u00a0to bypass the lock screen by entering an incorrect passcode several times and then asking Siri to open\u00a0the clock app.<\/p>\n<p>Popping up the clock app at the lock screen sounds like a low-risk feature, not least because the lock screen displays the time and date anyway.<\/p>\n<p>But from the clock, a snoop can use some trickery to access iMessage, and that opens the door to contacts\u00a0and photos.<\/p>\n<p>An intrepid member of our Naked Security team tried this Siri-enabled hack, and managed to get it to work on an iPhone 6 running iOS 9.0.1. (He tried with both a 6-digit numeric and an 8-character alphanumeric code.)<\/p>\n<p>What are the risks?<\/p>\n<p>One of the more worrying consequences, aside from the fact that hackers can access all your selfies, screenshots, family photos and so on, is that a crook can get into iMessage and send text messages in your name to your contacts.<\/p>\n<p>We can imagine a bunch of ways this could be dangerous, from &#8220;<a href=\"https:\/\/nakedsecurity.sophos.com\/2009\/06\/22\/trap-facebook-fraudster\/\">mugged abroad<\/a>&#8221; scams that could cost you $800, all the way to the sort of password phishing and social engineering that recently cost a Bitcoin exchange called BitPay <a href=\"https:\/\/nakedsecurity.sophos.com\/2015\/09\/18\/bitpay-spearphished-and-loses-1-8-million-insurer-refuses-to-pay\/\">$1.8 million<\/a>.<\/p>\n<p>When I contacted the\u00a0bug finder Jose Rodriguez on Twitter, he told me that he posted his video demonstrating the hack because he was &#8220;upset with Apple product security.&#8221;<\/p>\n<p>Rodriguez messaged me screenshots of emails he sent to Apple product security (and one to Apple CEO Tim Cook) about the bug\u00a0\u2013 he\u00a0told me he alerted Apple\u00a0two days before iOS 9 came out on 16 September.<\/p>\n<p>Yet Rodriguez posted his video to YouTube on 19 September\u00a0\u2013 five days\u00a0after telling Apple about the security hole\u00a0\u2013 which wasn&#8217;t much time at all for Apple to fix the bug.<\/p>\n<p>Regardless, this &#8220;zero-day&#8221; lock screen hack is now widely known.<\/p>\n<p>Why the flaw?<\/p>\n<p>Beyond the questions this raises about\u00a0<a title=\"Naked Security: Google's Project Zero backs off a bit - will now give up to 14 days' grace\" href=\"https:\/\/nakedsecurity.sophos.com\/2015\/02\/16\/googles-project-zero-backs-off-a-bit-will-now-give-up-to-14-days-grace\/\">responsible disclosure<\/a> of vulnerabilities, we should ask\u00a0why this serious security flaw exists in the first place.<\/p>\n<p>Part of the problem is having <a title=\"Naked Security: Does Siri have a secret signal to summon 911?\" href=\"https:\/\/nakedsecurity.sophos.com\/2015\/07\/17\/does-siri-have-a-secret-signal-to-summon-911\/\">Siri<\/a> accessible from the lock screen\u00a0\u2013 indeed, we&#8217;ve seen\u00a0quite a few\u00a0security holes\u00a0in earlier versions of iOS where\u00a0Siri\u00a0gave up\u00a0access to the device\u00a0<a title=\"Naked Security: Open the iPhone door Siri! Apple's digital helper coughs up another lockscreen hole\" href=\"https:\/\/nakedsecurity.sophos.com\/2014\/05\/12\/open-the-iphone-door-siri-apples-digital-helper\/\">without the passcode<\/a>.<\/p>\n<p>This iOS 9 lock screen bug isn&#8217;t quite as bad as the recently fixed <a title=\"Naked Security: Google fixes an Android Lollipop lockscreen bypass bug - how bad was it?\" href=\"https:\/\/nakedsecurity.sophos.com\/2015\/09\/18\/google-fixes-an-android-lollipop-lockscreen-bypass-bug-how-bad-was-it\/\">lock screen bypass in Android Lollipop<\/a>, which could give a hacker access to everything on your device.<\/p>\n<p>But the two bugs are similar: on iOS 9, accessing Siri from the lockscreen opens the door; on Android 5.x, the camera app on the lockscreen is the problem.<\/p>\n<p>As my colleague <a title=\"Paul Ducklin bio and articles\" href=\"https:\/\/nakedsecurity.sophos.com\/author\/pducklin\/\">Paul Ducklin<\/a> observed, having a lock screen really ought to mean that your device is <i>locked<\/i>, not sitting there with the front door closed but the cat flap open.<\/p>\n<p>What to do?<\/p>\n<p>Our\u00a0advice: reduce your attack surface right away.<\/p>\n<p>Apple and Google don&#8217;t want to let you turn off the camera on your lock screen, so you&#8217;re stuck with a &#8220;cat flap&#8221; for the camera on both platforms, but we strongly recommend that iDevice owners at least turn off Siri on the lock screen.<\/p>\n<p>How to disable Siri on the lock screen<\/p>\n<p>Go to<tt> Settings <\/tt>|<tt> Touch ID &amp; Passcode<\/tt>, and under<tt> Allow Access When Locked<\/tt>, toggle<tt> Siri <\/tt>off:<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-301156\" src=\"https:\/\/www.soundpr.it\/wp-content\/uploads\/2019\/07\/siri-off-lock-screen-1000.jpg\" alt=\"\" \/><\/p>\n<p>Some other settings you may want to consider while you&#8217;re about it, as configured in the screenshot above (yes, that&#8217;s a Naked Security iPhone):<\/p>\n<ul>\n<li>Set<tt> Require Passcode <\/tt>to<tt> Immediately<\/tt>.<\/li>\n<li>Turn off everything you can under<tt> Allow Access When Locked<\/tt>.<\/li>\n<li>Enable<tt> Erase Data <\/tt>after 10 failed passcode attempts.<\/li>\n<\/ul>\n<p>How to turn Siri off altogether<\/p>\n<p>You may want to go all the way, and turn Siri off altogether.<\/p>\n<p>Go to<tt> Settings <\/tt>|<tt> General <\/tt>|<tt> Siri <\/tt>and toggle to off:<\/p>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-301164\" src=\"https:\/\/www.soundpr.it\/wp-content\/uploads\/2019\/07\/siri-off-altogether-1000.jpg\" alt=\"\" \/><\/p>\n<p>Learn more<\/p>\n<p>For more advice on what to do when you review your phone&#8217;s security settings, please take a look at our popular article, <a title=\"Naked Security: Why you shouldn't worry about privacy and security on your phone\" href=\"https:\/\/nakedsecurity.sophos.com\/2015\/06\/02\/why-you-shouldnt-worry-about-privacy-and-security-on-your-phone\/\"><b>Privacy and Security on Your Phone<\/b><\/a>.<\/p>","protected":false},"featured_media":16400,"template":"","news_categories":[147],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v21.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Siri way of access for hackers, Sophos explains how to oppose to the bug that is scaring Apple users - soundPR<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.soundpr.it\/news\/siri-porta-daccesso-per-gli-hacker-sophos-spiega-come-contrastare-il-bug-che-spaventa-gli-utenti-apple\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"[:it]Siri porta d\u2019accesso per gli hacker, Sophos spiega come contrastare il bug che spaventa gli utenti Apple[:en]Siri way of access for hackers, Sophos explains how to oppose to the bug that is scaring Apple users[:] - soundPR\" \/>\n<meta property=\"og:description\" content=\"Watch out, iDevice owners! Siri has opened the pod bay door to let snoopers\u00a0in. Barely a week after the release of iOS 9, a hacker has found a way for\u00a0snoops to access your contacts and photos and send messages without your passcode. The bug affects iOS 9 and iOS 9.0.1 on iPhones, iPads and iPods. [...]Read More...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.soundpr.it\/news\/siri-porta-daccesso-per-gli-hacker-sophos-spiega-come-contrastare-il-bug-che-spaventa-gli-utenti-apple\/\" \/>\n<meta property=\"og:site_name\" content=\"soundPR\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.soundpr.it\/wp-content\/uploads\/2019\/07\/CS-SIRI.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"624\" \/>\n\t<meta property=\"og:image:height\" content=\"295\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.soundpr.it\/news\/siri-porta-daccesso-per-gli-hacker-sophos-spiega-come-contrastare-il-bug-che-spaventa-gli-utenti-apple\/\",\"url\":\"https:\/\/www.soundpr.it\/news\/siri-porta-daccesso-per-gli-hacker-sophos-spiega-come-contrastare-il-bug-che-spaventa-gli-utenti-apple\/\",\"name\":\"[:it]Siri porta d\u2019accesso per gli hacker, Sophos spiega come contrastare il bug che spaventa gli utenti Apple[:en]Siri way of access for hackers, Sophos explains how to oppose to the bug that is scaring Apple users[:] - soundPR\",\"isPartOf\":{\"@id\":\"https:\/\/www.soundpr.it\/#website\"},\"datePublished\":\"2015-10-22T22:00:00+00:00\",\"dateModified\":\"2015-10-22T22:00:00+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.soundpr.it\/news\/siri-porta-daccesso-per-gli-hacker-sophos-spiega-come-contrastare-il-bug-che-spaventa-gli-utenti-apple\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.soundpr.it\/news\/siri-porta-daccesso-per-gli-hacker-sophos-spiega-come-contrastare-il-bug-che-spaventa-gli-utenti-apple\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.soundpr.it\/news\/siri-porta-daccesso-per-gli-hacker-sophos-spiega-come-contrastare-il-bug-che-spaventa-gli-utenti-apple\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.soundpr.it\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Siri porta d\u2019accesso per gli hacker, Sophos spiega come contrastare il bug che spaventa gli utenti Apple\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.soundpr.it\/#website\",\"url\":\"https:\/\/www.soundpr.it\/\",\"name\":\"soundPR\",\"description\":\"Sound Public Relations\",\"publisher\":{\"@id\":\"https:\/\/www.soundpr.it\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.soundpr.it\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.soundpr.it\/#organization\",\"name\":\"soundPR\",\"url\":\"https:\/\/www.soundpr.it\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.soundpr.it\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.soundpr.it\/wp-content\/uploads\/2019\/07\/Logo-hd-wht.png\",\"contentUrl\":\"https:\/\/www.soundpr.it\/wp-content\/uploads\/2019\/07\/Logo-hd-wht.png\",\"width\":168,\"height\":69,\"caption\":\"soundPR\"},\"image\":{\"@id\":\"https:\/\/www.soundpr.it\/#\/schema\/logo\/image\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"[:it]Siri porta d\u2019accesso per gli hacker, Sophos spiega come contrastare il bug che spaventa gli utenti Apple[:en]Siri way of access for hackers, Sophos explains how to oppose to the bug that is scaring Apple users[:] - soundPR","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.soundpr.it\/news\/siri-porta-daccesso-per-gli-hacker-sophos-spiega-come-contrastare-il-bug-che-spaventa-gli-utenti-apple\/","og_locale":"en_US","og_type":"article","og_title":"[:it]Siri porta d\u2019accesso per gli hacker, Sophos spiega come contrastare il bug che spaventa gli utenti Apple[:en]Siri way of access for hackers, Sophos explains how to oppose to the bug that is scaring Apple users[:] - soundPR","og_description":"Watch out, iDevice owners! Siri has opened the pod bay door to let snoopers\u00a0in. Barely a week after the release of iOS 9, a hacker has found a way for\u00a0snoops to access your contacts and photos and send messages without your passcode. The bug affects iOS 9 and iOS 9.0.1 on iPhones, iPads and iPods. [...]Read More...","og_url":"https:\/\/www.soundpr.it\/news\/siri-porta-daccesso-per-gli-hacker-sophos-spiega-come-contrastare-il-bug-che-spaventa-gli-utenti-apple\/","og_site_name":"soundPR","og_image":[{"width":624,"height":295,"url":"https:\/\/www.soundpr.it\/wp-content\/uploads\/2019\/07\/CS-SIRI.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.soundpr.it\/news\/siri-porta-daccesso-per-gli-hacker-sophos-spiega-come-contrastare-il-bug-che-spaventa-gli-utenti-apple\/","url":"https:\/\/www.soundpr.it\/news\/siri-porta-daccesso-per-gli-hacker-sophos-spiega-come-contrastare-il-bug-che-spaventa-gli-utenti-apple\/","name":"[:it]Siri porta d\u2019accesso per gli hacker, Sophos spiega come contrastare il bug che spaventa gli utenti Apple[:en]Siri way of access for hackers, Sophos explains how to oppose to the bug that is scaring Apple users[:] - soundPR","isPartOf":{"@id":"https:\/\/www.soundpr.it\/#website"},"datePublished":"2015-10-22T22:00:00+00:00","dateModified":"2015-10-22T22:00:00+00:00","breadcrumb":{"@id":"https:\/\/www.soundpr.it\/news\/siri-porta-daccesso-per-gli-hacker-sophos-spiega-come-contrastare-il-bug-che-spaventa-gli-utenti-apple\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.soundpr.it\/news\/siri-porta-daccesso-per-gli-hacker-sophos-spiega-come-contrastare-il-bug-che-spaventa-gli-utenti-apple\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.soundpr.it\/news\/siri-porta-daccesso-per-gli-hacker-sophos-spiega-come-contrastare-il-bug-che-spaventa-gli-utenti-apple\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.soundpr.it\/"},{"@type":"ListItem","position":2,"name":"Siri porta d\u2019accesso per gli hacker, Sophos spiega come contrastare il bug che spaventa gli utenti Apple"}]},{"@type":"WebSite","@id":"https:\/\/www.soundpr.it\/#website","url":"https:\/\/www.soundpr.it\/","name":"soundPR","description":"Sound Public Relations","publisher":{"@id":"https:\/\/www.soundpr.it\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.soundpr.it\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.soundpr.it\/#organization","name":"soundPR","url":"https:\/\/www.soundpr.it\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.soundpr.it\/#\/schema\/logo\/image\/","url":"https:\/\/www.soundpr.it\/wp-content\/uploads\/2019\/07\/Logo-hd-wht.png","contentUrl":"https:\/\/www.soundpr.it\/wp-content\/uploads\/2019\/07\/Logo-hd-wht.png","width":168,"height":69,"caption":"soundPR"},"image":{"@id":"https:\/\/www.soundpr.it\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/www.soundpr.it\/en\/wp-json\/wp\/v2\/news\/16397"}],"collection":[{"href":"https:\/\/www.soundpr.it\/en\/wp-json\/wp\/v2\/news"}],"about":[{"href":"https:\/\/www.soundpr.it\/en\/wp-json\/wp\/v2\/types\/news"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.soundpr.it\/en\/wp-json\/wp\/v2\/media\/16400"}],"wp:attachment":[{"href":"https:\/\/www.soundpr.it\/en\/wp-json\/wp\/v2\/media?parent=16397"}],"wp:term":[{"taxonomy":"news_categories","embeddable":true,"href":"https:\/\/www.soundpr.it\/en\/wp-json\/wp\/v2\/news_categories?post=16397"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}