iPad2 not too secure!
2011 October 26 – 4:20 pmTablet devices have become popular business tools in the last few years, they offer many of the benefits of laptops without some of the drawbacks. The iPad is currently the most popular tablet device and as such it’s prevalence in the business world cannot be underestimated.
One would assume that Apple, who are surely aware of the business application of their product, would ensure that its default settings are the most secure, with the option to lower the security for convinience sake if the owner should wish.
Alas this is not the case. In iOS5 at least (this is the only OS we’ve tested on) the setting which allows the new Smart Cover to unlock the iPad 2, which is enabled by default, can be exploited to enable access to the last app left open without entering the password!
The exploit is incredibly simple too:
- Lock the iPad 2 (make sure it’s passcode protected);
- Hold down the power button for 2 seconds until the “turn off” slider appears;
- Close the Smart Cover;
- Open the Smart Cover;
- Press Cancel.
This will open the app that was open when the device was locked! You are unable to use the home button to access the home screen and switch to other apps but this is quite a big security issue none the less. If you were to lock the device with the Mail app open then someone using this exploit could access all your emails,send emails as you etc.
We’ve done a bit of testing, if you lock when on the home screen and then use the exploit you are presented with the home screen and are able to scroll between pages of apps, and use the search function, but are unable to open any apps.
Disabling the Smart Cover unlocking setting (under General Settings) will prevent this exploit, at the cost of a small amount of convenience (adds another step to unlocking the device after opening the Smart Cover). This is not a stand alone incident however; the iPhone 4S, by default, has a setting enabled which allows access to Siri without unlocking the device. This in turn allows access to many security sensitive apps (Mail, Calendar, even sending texts and making calls)!





