The truth behind that 20 second iPhone hack

happygeek 0 Tallied Votes 256 Views Share

The annual CanSecWest PWN2OWN hacking contest has done it again and provided us news types with the perfect headline writing opportunity as the Apple iPhone falls to the hackers in just 20 seconds. The hackers in question, Vincenzo Iozzo and Ralf Weinmann, picked up the prize of $15,000 and an iPhone for being the first to launch a successful attack on the smartphone in Vancouver.

Of course, if you look behind the headlines (including mine) then you will discover that actually it took a little longer than 20 seconds to run that previously unknown hack attack using the Safari browser on the iPhone which allowed the SMS messages on the device, including those which had been previously deleted, to be sent to a remote server.

How much longer? How does a couple of weeks of preparation sound? Well 'The 1,209,600 second iPhone hack' has a certain ring to it I guess but probably not quite the same wow factor as 20 seconds. This will, no doubt, be picked up upon by both fans of the iPhone who will say that the hack is therefore somehow invalid and fans of other devices who will say it makes no difference and the iPhone is insecure.

The truth, as always in such heated debates, actually sits somewhere between the two. Yes, for this SMS database hacking attack to work you need a user to be stupid at a website beforehand but that's par for the insecurity cause. The worrying thing, I would say, is that the hackers demonstrated it was relatively easy to bypass Apple code-signing routines and exploit non-root user privileges in the first place. Especially as we are not talking about previously Jailbroken devices here as the PWN2OWN contest rules insist that only unmodified iPhones can be used.

Apple has not, as of the time of writing, commented upon the hack.

Dani AI

Generated

A short, practical clarification that builds on what and started: the “20 second” line in headlines describes the visible moment an exploit ran under controlled contest rules — not the full research, testing and stabilization that goes into a reliable proof‑of‑concept. Contests deliberately compress disclosure (and competitors commonly withhold fuller exploit details for vendor reporting or commercial reasons), so the takeaway is a signal, not a full incident timeline.

How to interpret risk: treat web‑delivered browser exploits as targeted but real threats. They usually need a specific combination of OS/build/browser and some user action (visit a page, tap a link). An exploit that can be reproduced and pushed at scale is what turns a proof‑of‑concept into a real campaign; that distinction is what matters for day‑to‑day defensive choices (as hinted) and why the original contest matters even if the headline is clicky.

Immediate, practical mitigations:

  • Keep iOS and apps updated; install security patches promptly.
  • Use a strong device passcode and set Require Passcode to “Immediately.”
  • Enable Find My / remote‑wipe and keep automatic backups (use encrypted backups where available).
  • Reduce browser attack surface: Settings > Safari > Advanced > JavaScript (toggle off if high risk), enable Block Pop‑ups, and use reputable content blockers.
  • Avoid jailbreaking and don’t install software from unknown sources.
  • Don’t click unexpected links or attachments in messages from unknown senders.

PWN2OWN-style demos are valuable because they force vendors to fix problems. The best reading of this thread (and a good response to ’s ask for a point) is: don’t confuse a sensational runtime stat with the full engineering story — instead, apply the simple, repeatable hygiene above to lower real risk.

GeekNews 0 Newbie Poster

My first go around on reading this and I was going to say what BS, thankfully I re-read it in a clearer light. Yeah they had weeks to develop the hack, heck they likely spent months, but that's what hackers do.

The fact is they are only showing you the quickest easiest exploits they know, this doesn't mean that is all they know. In fact these guys get paid "x" times more money than they can actually win at Pwn@Own for showing companies some of the real hard core exploits they now.

The way Pwn@ Own was originally setup the goal was to hack your target machine as quickly and effectively as possible. Now with individual pairings they could've taken their time, but why when they could show the world just how easy it is to do.

happygeek 2,411 Most Valuable Poster Team Colleague Featured Poster

I'm actually not knocking PWN2OWN here, it has a place in the security world IMHO. Not least as it manages to focus attention on vulnerabilities, such as with the Firefox 3.6 remote exploit thing this week for example.

What I was trying to point out was that too many headlines will exclaim iPhone hacked in 20 seconds, and too many publications will proclaim that iPhone users are at risk of near instant data loss as a result when the truth is perhaps a little duller :)

spamjim 0 Newbie Poster

Sorry - but you're still not pointing anything out. Your comparison of the time to run the exploit vs. the time to develop the exploit is meaningless. The iPhone took years to develop. Does that mean I need years to place a phone call?

We're all at risk of instant data loss, especially with an item that can be easily lifted from our pockets or bags. :)

blah blubb 0 Newbie Poster

so what's your point? care to tell us something new? did you really think they started working on a hack the day the contest started?

happygeek 2,411 Most Valuable Poster Team Colleague Featured Poster

Funnily enough I didn't, but guess wha,t many people reading 'iphone hacked in 20 seconds' do.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.