IPhone: 2.0 Firmware Jailbroken, 3G Taken Apart


Oh, iPhone Dev Team, you are a hoot. It isn’t that you managed to jailbreak the iPhone 2.0 firmware on the day of its release, although we can’t help but smirk at that. It isn’t even that you revealed your handiwork in a playful way. We simply love that you expertly work us into a frenzy for the new jailbreak installer with few casual images and some aloof words. Now give us the installer before we get too antsy, please.

Not to be outshined, though, iFixit has posted a full iPhone 3G teardown, stripping away the sleek casing to feast on the goodness inside. They found some interesting changes from the last model: the glass screen, for example, is no longer glued to the LCD, which will no doubt make repairs less expensive. The battery is also unsoldered, meaning you won’t have to send the phone in for repair if the only battery needs maintenance.

ARDAgent.app Still Vulnerable


When Apple pushed their most recent security update, the first thing we checked was whether the ARDAgent issue was fixed. It’s not. This vulnerability lets anyone execute code as a privileged user and versions of this attack have already been found in the wild. While several Ruby, SMB, and WebKit issues were addressed it, ARDAgent is still unpatched. [Dino Dai Zovi] has published the method by which ARDAgent actually becomes vulnerable: when it starts, it installs its own Apple Event handlers and calls AESetInteractionAllowed() with kAEInteractWithSelf. This should restrict it only to its own events, but for some reason that’s not the resulting behavior. He also pointed out that SecurityAgent has displayed similar weirdness; it is vulnerable to Apple Events even though it doesn’t calls an Apple Events function. We can see how this unexpected behavior could make patch development take much longer and may end up uncovering an even bigger problem. Check out [Dino]’s post for more information.

Hackit: Network Attached Storage?


With each passing day the rate we acquire digital media increases (we don’t even bother unpacking our CDs when we move anymore). Large publishers have started moving away from DRM, which means we’ll be buying even more digital media in the future. Acquiring all of this nonphysical property puts importance on not just making it easily accessible, but also protecting it from destruction. Slashdot asked for reader suggestions of what NAS to buy; we’ve compiled some of the options below and want to know what you use.

Continue reading “Hackit: Network Attached Storage?”

IPhone 2.0 Adds Secure Wipe


AppleInsider is reporting that iPhone Software v2.0 will add a secure wipe feature. The screenshot above shows the text “This will take about an hour.” added to the normal erase feature. This time is used to overwrite data to the disk multiple times. The need for secure phone erasure came to light after a researcher was able to recover personal information from a refurbished iPhone using forensic tools. Since then, a few people have published techniques for obliterating personal data using either the GUI or the more thorough command line method. Remote wipe has also been added to the new firmware in case the phone is stolen. We’re happy to see security being made easily accessible to nontechnical users and expect that remote wipe will become standard on laptops in the future.

Make A Universal Macbook Air Superdrive


For $99, Apple will happily sell you a slick USB superdrive (aka DVD burner) that only works with the MacBook Air. [tnkgrl] swapped out the USB-IDE interface with a generic $9 unit to make it work with everything else. The generic board required a few mods: relocating the crystal oscillator along with the amputation of its daughter-board that carried an external power connector, usb connector and some caps.

EFiX Dongle Still Not Available


Well, it’s June 23rd, and still no dongle from EFiX. Despite a new product page on the company’s site, the OS X installing dongle is still not available for purchase. The USB dongle is supposed to facilitate the installation of Mac OS X by booting the Leopard install DVD on PCs, but so far no one has been able to verify this claim as no one has one of these in their hands yet. We’ve been covering this story since the beginning, and we’ll be sure to let you know when you can actually buy one of these.

[via Engadget]

Boxee Social Media Center Public Alpha


Boxee is the latest piece of software to enter the home theater PC space. It’s recently become available as a public alpha. The first build is only for OSX 10.5, but Ubuntu is coming. Built on the XBMC code base-they even hosted the XBMC developer con last weekend-it has the same goal of letting you navigate and watch/listen to all of your media from your using just a remote. There’s more than just that though.

Continue reading “Boxee Social Media Center Public Alpha”