Register Guidelines E-Books Today's Posts Search

Go Back   MobileRead Forums > E-Book Readers > Apple Devices

Notices

Reply
 
Thread Tools Search this Thread
Old 08-05-2010, 11:35 AM   #16
Maggie Leung
Wizard
Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.
 
Posts: 1,449
Karma: 58383
Join Date: Jul 2009
Device: Kindle, iPad
Quote:
Originally Posted by toddos View Post
Once you've used this security hole to jailbreak your device, install the PDF Loading Warner tweak from Cydia to prevent other sites from exploiting the hole silently. This will make Safari warn you any time it's about to open a PDF file, so if you didn't just explicitly tell it to open a PDF you would've been hacked without this in place (of course if you say "Yes", you'll be hacked anyway).
Your message seems to say that you will be automatically hacked when you open a PDF. Is that true? Not sure how the hacking works. I was guessing that opening a PDF left you open to hacking because of the two security holes, but that didn't mean you'd be automatically hacked.

Separate questions: If you do open a PDF, how long is the "window" for someone to be able to hack you? How would hackers know when you open a PDF, so that they can time their hacking?

I'm not sure I've ever opened PDFs on my iPad, but I'd like to know this stuff, to judge how much risk there actually is. Some of the news reports said that the weaknesses hadn't been exploited so far, but hacking was expected. How can they tell whether any hacking has happened? Is such a statement credible, or more likely PR spin?
Maggie Leung is offline   Reply With Quote
Old 08-05-2010, 01:54 PM   #17
vaughnmr
Ebook Reader
vaughnmr ought to be getting tired of karma fortunes by now.vaughnmr ought to be getting tired of karma fortunes by now.vaughnmr ought to be getting tired of karma fortunes by now.vaughnmr ought to be getting tired of karma fortunes by now.vaughnmr ought to be getting tired of karma fortunes by now.vaughnmr ought to be getting tired of karma fortunes by now.vaughnmr ought to be getting tired of karma fortunes by now.vaughnmr ought to be getting tired of karma fortunes by now.vaughnmr ought to be getting tired of karma fortunes by now.vaughnmr ought to be getting tired of karma fortunes by now.vaughnmr ought to be getting tired of karma fortunes by now.
 
Posts: 605
Karma: 3205128
Join Date: Nov 2009
Location: Texas
Device: Kindle 3, HTC Evo, HTC View
You will only be at risk from "risky" pdf's, so be careful what you open. And yes, if you open a "bad" pdf, you're done.

A good example might be downloading pdf ebooks from the darknet, I definitely wouldn't try that.
vaughnmr is offline   Reply With Quote
Advert
Old 08-05-2010, 02:04 PM   #18
dwharrison
Info Geek
dwharrison will become famous soon enoughdwharrison will become famous soon enoughdwharrison will become famous soon enoughdwharrison will become famous soon enoughdwharrison will become famous soon enoughdwharrison will become famous soon enough
 
Posts: 44
Karma: 622
Join Date: Jul 2010
Device: iPad, iPhone 3GS, Kindle 2
Quote:
Originally Posted by vaughnmr View Post
A good example might be downloading pdf ebooks from the darknet, I definitely wouldn't try that.
Just to clarify that point: this only applies to the Apple PDF viewer and anything that uses it (email, iBooks, etc). Opening even risky PDFs in Goodreader or any other reader that has its own rendering engine should be safe.

Quote:
Separate questions: If you do open a PDF, how long is the "window" for someone to be able to hack you? How would hackers know when you open a PDF, so that they can time their hacking?
It's not that opening the PDF leaves you open to being attack; the PDF *is* the attack. The severity of the attack depends on what the PDF has been designed to do.

Last edited by dwharrison; 08-05-2010 at 02:06 PM.
dwharrison is offline   Reply With Quote
Old 08-05-2010, 02:25 PM   #19
Maggie Leung
Wizard
Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.
 
Posts: 1,449
Karma: 58383
Join Date: Jul 2009
Device: Kindle, iPad
Thanks, guys. So reviewing to make sure I understand:

As long as you open PDFs from a trusted source, as opposed to one rigged by a hacker, you should be fine, right? (I realize there are no absolute guarantees.)

Hackers basically hafta lure you into opening their rigged PDFs, right? Or is it likely that they also will infiltrate some legit site and mess with existing PDFs? I ask because I don't visit the darknet (checked it out and haven't returned), so no risk there. But should I be worried if I need to open a PDF from my bank or such? If there's reasonable risk in such uses, I guess I'd just not open PDFs on iPad till some kinda patch is offered.
Maggie Leung is offline   Reply With Quote
Old 08-05-2010, 04:52 PM   #20
toddos
Guru
toddos ought to be getting tired of karma fortunes by now.toddos ought to be getting tired of karma fortunes by now.toddos ought to be getting tired of karma fortunes by now.toddos ought to be getting tired of karma fortunes by now.toddos ought to be getting tired of karma fortunes by now.toddos ought to be getting tired of karma fortunes by now.toddos ought to be getting tired of karma fortunes by now.toddos ought to be getting tired of karma fortunes by now.toddos ought to be getting tired of karma fortunes by now.toddos ought to be getting tired of karma fortunes by now.toddos ought to be getting tired of karma fortunes by now.
 
toddos's Avatar
 
Posts: 695
Karma: 822675
Join Date: May 2010
Device: Kobo Aura, Nokia Lumia 920 (Freda)
Almost, but not quite. That's true if you're physically opening PDFs, but the hack is that PDFs can be loaded automatically. You navigate to shady site X, and that site automatically loads a hacked PDF with malicious payload. If done correctly, you'll never even know that the site just hacked you.

That's why you need to install the PDF Loading Warner (which can only be done after jailbreaking), to stop Safari from automatically and silently opening PDFs. You can still be hacked even after that, since the warner doesn't fix the whole. It just lets you know that, "Hey, this site here just tried to open a PDF. That could be dangerous. You sure you want to do that?" and allows you to stop the load before it's dangerous. If you allow it through anyway, you can still be hacked.
toddos is offline   Reply With Quote
Advert
Old 08-05-2010, 05:38 PM   #21
Maggie Leung
Wizard
Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.
 
Posts: 1,449
Karma: 58383
Join Date: Jul 2009
Device: Kindle, iPad
Quote:
Originally Posted by toddos View Post
Almost, but not quite. That's true if you're physically opening PDFs, but the hack is that PDFs can be loaded automatically. You navigate to shady site X, and that site automatically loads a hacked PDF with malicious payload. If done correctly, you'll never even know that the site just hacked you.

That's why you need to install the PDF Loading Warner (which can only be done after jailbreaking), to stop Safari from automatically and silently opening PDFs. You can still be hacked even after that, since the warner doesn't fix the whole. It just lets you know that, "Hey, this site here just tried to open a PDF. That could be dangerous. You sure you want to do that?" and allows you to stop the load before it's dangerous. If you allow it through anyway, you can still be hacked.
Yeesh. So without jailbreaking, you're pretty much stuck hoping that you don't stumble into some creepy site? Because it seems pretty easy to read something online, like on this forum, follow a link and end up somewhere that you don't know is trustworthy.

How long do you think it will take for Apple to patch this?

Let's say take your iPad back to factory settings, and reload all your stuff from iTunes. Would that work to stop whatever unseen hacking might be already at work on your iPad? I ask because someone posted earlier that it's hard to tell whether you've been hacked. Even if you jailbreak now and load the PDF warner, the hackers could already have access, it sounds like. And it doesn't sound as if the jailbreaking and PDF warner could help if that were the case.
Maggie Leung is offline   Reply With Quote
Old 08-05-2010, 05:52 PM   #22
toddos
Guru
toddos ought to be getting tired of karma fortunes by now.toddos ought to be getting tired of karma fortunes by now.toddos ought to be getting tired of karma fortunes by now.toddos ought to be getting tired of karma fortunes by now.toddos ought to be getting tired of karma fortunes by now.toddos ought to be getting tired of karma fortunes by now.toddos ought to be getting tired of karma fortunes by now.toddos ought to be getting tired of karma fortunes by now.toddos ought to be getting tired of karma fortunes by now.toddos ought to be getting tired of karma fortunes by now.toddos ought to be getting tired of karma fortunes by now.
 
toddos's Avatar
 
Posts: 695
Karma: 822675
Join Date: May 2010
Device: Kobo Aura, Nokia Lumia 920 (Freda)
If you want to be sure you're not hacked, resetting to factory and not applying a backup will ensure you're in a good state. Until you browse the web again, because at that point you've introduced the unknown (did you accidentally go to a site that hacked you?). If you want to be completely paranoid, completely wipe and reset your device, immediately go to jailbreakme.com very first thing after the reset, then install PDF Loading Warner before doing any other web browsing.
toddos is offline   Reply With Quote
Old 08-05-2010, 05:56 PM   #23
Maggie Leung
Wizard
Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.
 
Posts: 1,449
Karma: 58383
Join Date: Jul 2009
Device: Kindle, iPad
Quote:
Originally Posted by toddos View Post
If you want to be sure you're not hacked, resetting to factory and not applying a backup will ensure you're in a good state. Until you browse the web again, because at that point you've introduced the unknown (did you accidentally go to a site that hacked you?). If you want to be completely paranoid, completely wipe and reset your device, immediately go to jailbreakme.com very first thing after the reset, then install PDF Loading Warner before doing any other web browsing.
Yup, that's what I was thinking. I figure if you're gonna go through the effort of jailbreaking and loading the PDF warner, you might as well rule out already carrying a hack aboard.
Maggie Leung is offline   Reply With Quote
Old 08-05-2010, 10:38 PM   #24
arcadata
Grand Sorcerer
arcadata ought to be getting tired of karma fortunes by now.arcadata ought to be getting tired of karma fortunes by now.arcadata ought to be getting tired of karma fortunes by now.arcadata ought to be getting tired of karma fortunes by now.arcadata ought to be getting tired of karma fortunes by now.arcadata ought to be getting tired of karma fortunes by now.arcadata ought to be getting tired of karma fortunes by now.arcadata ought to be getting tired of karma fortunes by now.arcadata ought to be getting tired of karma fortunes by now.arcadata ought to be getting tired of karma fortunes by now.arcadata ought to be getting tired of karma fortunes by now.
 
arcadata's Avatar
 
Posts: 11,230
Karma: 4651787
Join Date: Mar 2009
Device: Kindle, Kindle Fire, iPad, iPod Touch, Sony PRS-350
It's ironic isn't it - the way to protect yourself right now is to jailbreak your device and then apply the warning hack. Apple says it already has a patch, but they haven't released an update yet.

And if they do patch it, doubt that the already jailbroken phones will go for the update. Cause then, how do you jailbreak it again? (I was just looking at the 5 Killer Apps for Jailbroken iPhones - really cool especially the ability to sync via WiFi!)
arcadata is offline   Reply With Quote
Old 08-05-2010, 10:44 PM   #25
Maggie Leung
Wizard
Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.
 
Posts: 1,449
Karma: 58383
Join Date: Jul 2009
Device: Kindle, iPad
Quote:
Originally Posted by arcadata View Post
It's ironic isn't it - the way to protect yourself right now is to jailbreak your device and then apply the warning hack. Apple says it already has a patch, but they haven't released an update yet.

And if they do patch it, doubt that the already jailbroken phones will go for the update. Cause then, how do you jailbreak it again? (I was just looking at the 5 Killer Apps for Jailbroken iPhones - really cool especially the ability to sync via WiFi!)
Yes, it's crazy. ... All the same, I would think that Apple would wanna patch this quick, but do it right. It would be even worse PR-wise if they rushed a patch and there was some kinda problem.
Maggie Leung is offline   Reply With Quote
Old 08-06-2010, 12:44 AM   #26
arcadata
Grand Sorcerer
arcadata ought to be getting tired of karma fortunes by now.arcadata ought to be getting tired of karma fortunes by now.arcadata ought to be getting tired of karma fortunes by now.arcadata ought to be getting tired of karma fortunes by now.arcadata ought to be getting tired of karma fortunes by now.arcadata ought to be getting tired of karma fortunes by now.arcadata ought to be getting tired of karma fortunes by now.arcadata ought to be getting tired of karma fortunes by now.arcadata ought to be getting tired of karma fortunes by now.arcadata ought to be getting tired of karma fortunes by now.arcadata ought to be getting tired of karma fortunes by now.
 
arcadata's Avatar
 
Posts: 11,230
Karma: 4651787
Join Date: Mar 2009
Device: Kindle, Kindle Fire, iPad, iPod Touch, Sony PRS-350
The PDF Loading Warner has a bug though, after you install it, every time you check your Clock app, the Warner pops up to warn you that you're opening a PDF file.
arcadata is offline   Reply With Quote
Old 08-06-2010, 01:38 AM   #27
Maggie Leung
Wizard
Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.Maggie Leung beat Jules Verne's record by 5 days.
 
Posts: 1,449
Karma: 58383
Join Date: Jul 2009
Device: Kindle, iPad
Quote:
Originally Posted by arcadata View Post
The PDF Loading Warner has a bug though, after you install it, every time you check your Clock app, the Warner pops up to warn you that you're opening a PDF file.
Good grief.
Maggie Leung is offline   Reply With Quote
Old 08-06-2010, 05:08 AM   #28
Graham
Wizard
Graham ought to be getting tired of karma fortunes by now.Graham ought to be getting tired of karma fortunes by now.Graham ought to be getting tired of karma fortunes by now.Graham ought to be getting tired of karma fortunes by now.Graham ought to be getting tired of karma fortunes by now.Graham ought to be getting tired of karma fortunes by now.Graham ought to be getting tired of karma fortunes by now.Graham ought to be getting tired of karma fortunes by now.Graham ought to be getting tired of karma fortunes by now.Graham ought to be getting tired of karma fortunes by now.Graham ought to be getting tired of karma fortunes by now.
 
Posts: 2,743
Karma: 32912427
Join Date: Feb 2008
Location: North Yorkshire, UK
Device: Kobo H20, Pixel 2, Samsung Chromebook Plus
What's the reason why an app or plug-in that warns if you're about to open a PDF in Safari can't be written to run on an iPad that hasn't been jailbroken?

Graham
Graham is offline   Reply With Quote
Old 08-06-2010, 08:37 AM   #29
dwharrison
Info Geek
dwharrison will become famous soon enoughdwharrison will become famous soon enoughdwharrison will become famous soon enoughdwharrison will become famous soon enoughdwharrison will become famous soon enoughdwharrison will become famous soon enough
 
Posts: 44
Karma: 622
Join Date: Jul 2010
Device: iPad, iPhone 3GS, Kindle 2
Quote:
Originally Posted by Graham View Post
What's the reason why an app or plug-in that warns if you're about to open a PDF in Safari can't be written to run on an iPad that hasn't been jailbroken?
Because Apple doesn't allow plugins to Safari, so when Safari sees a PDF, it is going to open in the internal PDF viewer.

To get around this restriction involves either (not sure which) unsupported APIs (which means Apple wouldn't approve it for the app store) or just plain hacking the files (which requires security escalation). Either requires jailbreaking.
dwharrison is offline   Reply With Quote
Old 08-08-2010, 12:56 PM   #30
kjk
.
kjk ought to be getting tired of karma fortunes by now.kjk ought to be getting tired of karma fortunes by now.kjk ought to be getting tired of karma fortunes by now.kjk ought to be getting tired of karma fortunes by now.kjk ought to be getting tired of karma fortunes by now.kjk ought to be getting tired of karma fortunes by now.kjk ought to be getting tired of karma fortunes by now.kjk ought to be getting tired of karma fortunes by now.kjk ought to be getting tired of karma fortunes by now.kjk ought to be getting tired of karma fortunes by now.kjk ought to be getting tired of karma fortunes by now.
 
Posts: 3,408
Karma: 5647231
Join Date: Oct 2008
Device: never enough
F-secure has a FAQ about the 2 vulnerabilities:
http://www.f-secure.com/weblog/archives/00002004.html

1) It sounds very serious, and affects all iOS devices, including the Touch.
2) There are zero reports of malicious attacks so far.
3) Don't open PDFs, period-not from email, web, or instant messenger until Apple releases a patch. (I've heard possibly this Monday or Tuesday, actually)
kjk is offline   Reply With Quote
Reply


Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
PDF's in kindle app on ipad???? mack 120 Amazon Kindle 5 08-13-2010 07:27 PM
iOS 4.0.2 (iPhone) 3.22(iPad) updates now available kjk Apple Devices 5 08-12-2010 10:21 PM
FBI investigating iPad 3G security breach / FCC also concerned =X= News 35 06-19-2010 01:47 PM
iPad BoingBoing: Report: AT&T security breach exposed 114k iPad users kjk Apple Devices 9 06-14-2010 12:09 AM
Monthly Magazine PDF's - Is The iPad My Only Option?? Rex32 Which one should I buy? 2 05-30-2010 07:01 AM


All times are GMT -4. The time now is 02:19 AM.


MobileRead.com is a privately owned, operated and funded community.