iPhone Takes Screenshots of Everything You Do 225
The_AV8R writes "Jonathan Zdziarski showed that every time you press the Home button on your iPhone, a screen capture is taken in order to produce a visual effect. This image is then cached and later deleted. Zdziarski says that there have been cases of law enforcement looking up sex offenders' old data and checking recovered screenshots." This revelation occurred in the midst of a webcast on iPhone forensics, demonstrating how to bypass the iPhone's password security (not trivial, but doable). Video from the talk is not online yet but is promised soon over at O'Reilly.
FUD (Score:4, Funny)
Therefore, forensics experts have used this security flaw to successfully nab criminals who have been accused of rape, murder or drug deals, Zdziarski said.
iPhone: the tool of choice for rapists, murders, and drug dealers!
Joking aside, the article is puzzling and it reeks of FUD: if the iCrooks were bad enough to get the authorities to actively track and sieze their data then they deserve to be caught for being too stoopid to buy disposable phones in cash from 7-11. Even Johnny dormroom pot- dealer knows that!
Malfeasance handbook (Score:5, Insightful)
Smart crooks use dumb (disposable) phones.
Dumb crooks use smart phones.
Re:FUD (Score:5, Funny)
Joking aside, the article is puzzling and it reeks of FUD:
Apple FUD on slashdot? Maybe the LHC is gearing up for armageddon after all.
Re: (Score:2, Insightful)
Apple FUD on slashdot? Maybe the LHC is gearing up for armageddon after all.
Are you kidding? Ever since that line of people mysteriously turned up at an Apple Store, iPhone stories have become hate-fests on Slashdot. I'm not kidding. Somebody says they like the iPhone's web-browser and they're a 'fanboy'. But if somebody says the iPhone is 'useless', they're objective and rational.
It has gotten rather obnoxious lately.
Re:FUD (Score:5, Funny)
Alls I heard was "I love apple" and "I'm a huge fanboy"..
Re: (Score:2)
Re: (Score:3, Insightful)
From TFA:
Therefore, forensics experts have used this security flaw to successfully
nab criminals who have been accused of rape, murder or drug deals, Zdziarski said.
iPhone: the tool of choice for rapists, murders, and drug dealers!
Joking aside, the article is puzzling and it reeks of FUD: if the iCrooks were bad enough to
get the authorities to actively track and sieze their data then they deserve to be caught
for being too stoopid to buy disposable phones in cash from 7-11. Even Johnny dormroom pot-
dealer knows that!
FUD doesn't mean what you think it means.
Re: (Score:2)
Re: (Score:2)
"failing to rat out on you" is actually a damned good feature that consumer electronics should all have... FTROOY ? Failing To Rat You Out ? Either one is better then WYSIWYG.
I think that gadget pundits should be including this feature in their reviews and comparisons. ZDNET? Are you listening? That should put F/OSS (and hardware) closer to the top of the class listing.
We might even call it a 5th Ammendment feature? I think I like that even better. Kind of makes it sound official and like it's a iGoodThing!
Re: (Score:2)
Re:FUD (Score:5, Funny)
Yes, maybe take some time off? (Score:2, Insightful)
It really is no surprise that someone with the screename "lysergic acid" takes issue with being a crook because of illegal drug possession, but how the fuck did this get modded up?
YES possessing illegal drugs makes one a crook. Deal with it, because it's reality. I really don't see how an intelligent person could openly wonder how doing the very thing that makes one a crook could cause one to be called a crook.
Now, you can argue over whether you should be a crook, but that's not what was done here.
Second,
Re: (Score:2)
I really don't see how an intelligent person could openly wonder how doing the very thing that makes one a crook could cause one to be called a crook.
Because they're high? Just a guess ya know?
Re: (Score:2)
Hate to break it to you guys, but the druggie is right. Crook means "one who makes a living by dishonest methods". Therefore: drug dealer==crook, drug purchaser!=crook.
Re: (Score:2)
Well, I don't see any definition in your post that is applicable to drug possession, but we can agree on arguing over slang. I imagine we both have more productive things we could be doing.
Re: (Score:2)
perhaps you should look up the word "crook" in the dictionary before making an ass of yourself.
i brought up alcohol because people who claim all drug users are crooks also seem to share the delusion that alcohol somehow isn't a drug because it's a socially condoned substance. so if you agree with the OP's statement, then you must also agree that 90% of all law-abiding citizens are also dishonest swindlers, a.k.a crooks.
Re: (Score:2, Insightful)
More trivial than walking down to the store? (Score:2, Insightful)
No. Not more trivial than walking down to the store.
In fact, it would take a particularly ignorant, intentionally disingenuous person to argue that getting pot is anywhere near as easy as getting booze.
Next, the reason people think pot is a gateway drug is the same reason people think running around in the cold causes the flu (I SAID FLU THERE PEDANTS, SO FUCK OFF). they're ignorant and are repeating bullshit they've had drilled into them.
It of course never occurs to you people that it may in fact have no
Re: (Score:3, Insightful)
And since by that reasoning the only reason cannabis acts as a gateway is because it's illegal. Legalize it and there goes your supposed gateway drug effect.
Re: (Score:2)
90% of the population of what? A crack den?
Re: (Score:2, Offtopic)
Fine - alcohol is a drug. Happy? A drug that you can have one portion of without strong intoxication. People drink booze for a variety of reasons. Some, but not all of these reasons, involve intoxication. People take illegal drugs for a variety of reasons as well. But all of these reasons include, in some way, intoxication. The whole point of taking drugs is to get high. If you want to drop just a little bit of your namesake, but not enough to have any noticeable effect on you, fine, have at it. But
Re:FUD (Score:5, Funny)
Or a pharmacist.
Re: (Score:2)
Off-topic but yes, possessing drugs does make you a crook
Or a pharmacist.
Or a ghost.
Re: (Score:3, Insightful)
And BTW the dictionary.com definition of "crook" says nothing about simple law breakers. The closest it comes is "a dishonest person, esp. a sharper, swindler, or thief."
Re: (Score:3, Interesting)
Re: (Score:3, Informative)
Just out of curiosity... (Score:5, Funny)
Comment removed (Score:5, Funny)
Re: (Score:2, Funny)
Particularly with new hardware...
Re: (Score:2)
Disclaimer - This comment is utterly disgusting and should not be viewed at work or by people without a twisted sense of humor. I yet again apologise for bring down the tone of
Anybody know if he was hacking 2.1? (Score:3, Interesting)
Sorry to diverge from the screenshot topic but does anyone know if Mr. Zdziarski will demonstrating how to hack the just released 2.1 firmware? Or is a previous version that (may have) been patched? This seems much more significant than being able to see (via a screenshot) what the last user action was.
As for the screenshot, hmm... well at least it doesn't seem to be a deliberate attempt by Apple to get more info on the user. Also, it seems pretty difficult to get these screenshots (since they are automatically deleted according to the article you have to find and undelete them). Doesn't sound like a trivial or reliable way to snoop on people. Still I guess a security flaw is a flaw so be aware!
Re: (Score:2)
No I am pretty sure it is used during the visual effect of switching in and out of an application, for example when having to deal with a phone call while in another application or hitting the home button. It is just a temporary cache used to optimize that effect without having to involve the applications rendering at the time they are doing the affect.
Re: (Score:2)
Pragmatic (Score:4, Funny)
It's pragmatic to not press the home button when doing home invasions or killing people, I guess.
Re:Pragmatic (Score:4, Informative)
It's pragmatic to not press the home button when doing home invasions or killing people, I guess.
Although you are probably technically right, unless you are killing them with a scathing email, or nasty AC troll post - it is not likely that the home button will matter. It captures the screenshot of what is on your screen - not from the camera. (unless you happend to have the camera app on at the moment of course)
-Em
Oblig Simpson's Quote (Score:2)
"Videoaping this crime spree was the best idea we ever had!"
Re: (Score:2)
Do we really have to get into this whole cache=copying=recording debate, though? It's a reasonably simple thing to have any cache clearing functions do so securely, and unlike with magnetic platters there's no need to worry about paranoid 35-pass overwrites with the flash memory in the iPhone and every other handheld on the planet.
I'd say that "recording" is REALLY pushing the limit of what one could call caching, especially as they're not sent anywhere. I'm much more a felon in Illinois for putting Googl
Re: (Score:2)
Suppose the criminal is e-mailing or messaging someone. Some incriminating words are on the message. Now suppose he presses Home to switch to other application. The device would make a screen capture of the incriminating message, and store it for seconds to create the shrinking effect. Forensics are then used on the phone's storage to recover this deleted screenshot. Evidence has just been produced.
No photo taking was needed.
simple fix for Apple (Score:3, Insightful)
Re: (Score:3, Interesting)
Re: (Score:2)
It is a convenient way to ensure that space is always available on the flash.
Re: (Score:2)
Why bother with such a useless thing? It's never saved to Flash; it's created in RAM. Law enforcement must be damn good if they can recover such an image from RAM, so damn good they must be making shit up.
TFA says you are wrong. Maybe you should read it.
-Em
What's the problem (Score:5, Interesting)
And what did you expect from Apple? That every bit of data that was discarded is overwritten ten times? Jeez, I enjoy bashing big companies as much as the other guy but now they're looking too far. Remember, it also saves your web history, every picture you took, every file you opened everything you did somewhere...
Re: (Score:2, Interesting)
Those files are hidden away. This image should live in /tmp/, it doesn't. Apple decided you'd like it to appear in your photos list, which is clearly ridiculous. It does it on the ipod touch too.
2.1 is a mess, apple's forums are full of bugs already, stupidly obvious ones that are found as soon as you use an updated device. Some seem to be problems with what itunes is doing to your files, others are bugs on the device itself. Clearly they didn't do enough testing, and the beta testers should be fired from t
Re: (Score:2)
You're thinking of Power+Home, not just Home.
Power+Home takes screenshots explicitly, and is very useful. Home takes a screenshot to scale in/out on program open and close
Re: (Score:2, Insightful)
The reason it's bad is because it's another way for someone to harvest personal information off your phone for apparently no real reason at all. It's crap like this that makes me feel just fine having my little fugly Palm Centro. I don't have to have yet another security hole because Apple felt taking a screenshot would make
Re: (Score:3, Insightful)
It's crap like this that makes me feel just fine having my little fugly Palm Centro. I don't have to have yet another security hole because Apple felt taking a screenshot would make for a cool bit of eye-candy.
Admit it. You're letting envy cloud your judgement.
Think about what you're saying. "Yeah, my device is ugly and stupid, but YOURS HAS YOUR PERSONAL INFORMATION ON IT".
Seriously. Someone gets my phone, my *LAST* concern is potentially recoverable screenshots of what I was doing on it when I closed an application. What about all the personal data it stores through the very nature of its function?!
lame
Re: (Score:2)
"..harvest personal information off your phone for apparently no real reason at all."
how?
Re:What's the problem (Score:4, Insightful)
In this case, a potential security issue has been introduced for the purpose of look and feel. While the headline is sensational and seems to be written by a person with no technical background or understanding fo the iPhone, the point remains. Pictures of what you are doing prior to pressing the home button are taken, and stored for some indeterminate amount of time. This is like the browser issue, likely not a big problem. OTOH, there does not seem to be an option under the general/home button menu to turn off this effect, so there is no way for persons worried about the issue to turn it off. It is an interesting problem.
And this just in! (Score:5, Funny)
It turns out that you browser will store all the information needed to recreate the web pages you visit! Not just a screenshot! This critical flaw appears to have present for years in all known browsers! The end is near!
Seriously? Come on. I know ./ likes to post anything related to the iPhone, especially if it involves "spying", but this is pretty uninteresting. Security is traded for speed and features on a daily basis, including places where do so presents a major risk (*cough*Outlook). This is really not too surprising since it trades at most a little privacy in exchange for a neat effect; what would you expect Apple's iCandy to do?
Re:And this just in! (Score:5, Funny)
Re: (Score:2)
That explains a lot about recent events around here...
fud (Score:4, Insightful)
Re: (Score:2)
We've had plenty of real reasons to bash the iphone. Look up Apple logo of death on google :) The entire iphone thing has been a huge buggy disaster.
2.1 just came out... we'll see how well it does but... it better be a fucking miracle.
Re: (Score:2)
I've had slight issues after the version 2 software but apparently less than 3g owners. Download 2.1 today and well yes we'll see. There are real problems with phones (3g mainly) but this isn't one of them
Only the guilty have something to hide! (Score:2, Funny)
Re: (Score:2)
The predator obviously WAS thinking of the children....
oops?
Unclear whether this is recoverable... (Score:2)
The iPhone takes a screenshot, but they never said in the FA whether its actually written to flash or not!
Given the limited write cycles of Flash, I would hope that Apple just keeps it in RAM.
Re: (Score:2)
Forensics on RAM are much harder, because it would probably be a single cached screenshot, so you don't HAVE history, only the current ones.
Even the Author Doesn't Think It's News (Score:5, Informative)
This was a side note I mentioned the other day, and has been something I've been grousing about for over a year. It's unnecessary, and a bit of a privacy leak that can be exploited by forensic examiners, but hardly news for the reasons already stated in the comments.
Re:Even the Author Doesn't Think It's News (Score:5, Funny)
I _am_ Jonathan Zdziarski
No, I'm Jonathan Zdziarski!
Re: (Score:2)
In Soviet Russia, Jonathan Zdiarski's you!
Re: (Score:2)
Re: (Score:2)
Only Jonathan Zdiarski pores hot grits on a petrified Natalie Portman.
Will the real Slim Shady please (Score:2)
Re:Even the Author Doesn't Think It's News (Score:5, Funny)
Re: (Score:2)
I know how to settle this: Will the real Jonathan Zdziarski please spell his name?
Re:Even the Author Doesn't Think It's News (Score:5, Informative)
Re: (Score:2)
Re:Even the Author Doesn't Think It's News (Score:4, Funny)
Welcome to Slashdot. Here's your oversized novelty foam finger.
Advertising Opportunity? (Score:2)
iPhone: it watches you masturbate.
I've seen this... (Score:3, Interesting)
I had a glitch occur that put one of these screen shots in my photos collection. I was wondering what kind of glitch would have generated a screenshot. Now that is partially explained.
Re: (Score:2, Informative)
Old attack vector (Score:2)
I can't watch the video, however are the screenshots just left in RAM? Or are there actual files saved somewhere?
I'll show them... (Score:4, Funny)
I wrote a little app to fill the cache with screenshots of the IRS web pages. Anyone tries to investigate me, they'll have to carefully examine Publication 936, the instructions for Schedule F1, the guidelines for reporting "nanny" wages, and the like. Even if they aren't literally bored to death, they definitely won't want to look any further.
New idea for a patent ... (Score:2)
iPhone protector/cover thingy ... with a lens cap!
wait a minute (Score:2, Insightful)
OSX also does that little shrinking animation when you minimize a window. I wonder if the same flaw is in OSX?
So what? (Score:4, Informative)
no foundation (Score:4, Interesting)
This fool doesn't even present any evidence that this 'screenshot' is -ever- even written to storage. Sure, it has to be in RAM to be shown zooming away, but the same thing applies to showing anything on the screen at all. Just because it saves processing power to capture an image instead of zooming the live app like OS X does, doesn't imply that the image ever leaves volatile RAM.
- written from my iphone.
Re:It's nice to know (Score:5, Interesting)
Errr, it's not phoning these screenshots home. You must have a problem with .bash_history too, right? Caching your keystrokes! OMG!
Re:It's nice to know (Score:4, Interesting)
Re: (Score:3, Insightful)
Errr, it's not phoning these screenshots home. You must have a problem with .bash_history too, right? Caching your keystrokes! OMG!
In all fairness, if his account password "alpine" is posted all over the internet, looking into his .bash_history IS a pretty damn good way of spying on him. (Granted, there are bigger issues in this scenario.)
-Em
Re:It's nice to know (Score:5, Insightful)
Sure, if you overwrite your firmware (jailbreak), enable SSH access to the phone, and then NOT change your root password. Quite frankly, you deserve it at that point.
Sounds like yet another sensationalist (and completely inaccurate) headline pointing to a non-story. Unless some pervert is hits the home button while trying to take a (crappy, borderline-useless unless it's being done in full daylight) picture of himself raping a kid, AND law enforcement not only knows to look for this cached file, I don't really see this being an issue. I suppose it could possibly be used as supplemental evidence when a case is being built up, but the actual AIM chat logs, sent emails, phone call history (all of which are far more accessible) and such would be far more potentially incriminating.
Re: (Score:2)
Sounds like yet another sensationalist (and completely inaccurate) headline pointing to a
non-story. Unless some pervert is hits the home button while trying to take a (crappy, borderline-useless unless it's being done in full daylight) picture of himself raping a kid, AND law enforcement not only knows to look for this cached file, I don't really see this being an issue. I suppose it could possibly be used as supplemental evidence when a case is being built up, but the actual AIM chat logs, sent emails, phone call history (all of which are far more accessible) and such would be far more potentially incriminating.
While sensationalist and somewhat misleading, it is not entirely inaccurate. Truth is that while it is not a screenshot of everything, there are some things that anyone with physical access to your iPhone MAY be able to recover.
As a not so far-fetched example, if you happend to hit Home while viewing your encrypted data in an encrypted password/data storage app (like 1passwd), your encrypted data - which may be passwords to other locations - is now stored unencrypted on your hard drive without your knowledg
Re:It's nice to know (Score:4, Interesting)
You'll no doubt be shocked to learn that even though you might empty your Recycle Bin there are some thing that anyone with physical access to your computer MAY be able to recover.
Thank you, that's the point. I DO know that about files *I* create and *I* delete and I can delete them securely if I choose to. What I did NOT know is that something is capturing screenshots of what I am doing and saving them without my knowledge. Generally this sort of a behavior is reserved for spyware, rootkits and other malware. I realize it is not intended as such, but neither was the Sony DRM rootkit a while back.
I would guess most people would have an issue to have a keylogger installed on their computers. This is no different..
(the word may is in all caps for the imbeciles reading, and because some of us are unable to detect when we are being patronizing)
Ok, but there MAY be something vaguely self-referential about that....
-Em
Re:It's nice to know (Score:5, Funny)
Re: (Score:2, Funny)
You must have a problem with .bash_history too, right? Caching your keystrokes! OMG!
I don't much like .bash_history, so I usually do this:
$ rm .bash_history /dev/null .bash_history
$ ln -s
Can I do something similar with the iPhone? Better not to have to think about it, even if it isn't incriminating.
Benjamin Franklin was talking about exactly this when he said:
"They who can give up essential privacy to obtain a little temporary eye-candy, deserve neither privacy nor eye-candy."
That man was way ahead of his time.
Re:Makes you wonder.... (Score:5, Insightful)
it makes me wonder why there is no 'badtitle' tag.
It doesn't take a screenshot of everything you do, just when you hit the home button.
Re:Makes you wonder.... (Score:4, Funny)
(sorry, I tried to find the link)
Re: (Score:3, Funny)
Or iPint which is a free app
Re: (Score:3, Insightful)
It makes me wonder what parental unit is stupid enough to give their kid an iPhone
Re: (Score:2)
Re: (Score:3, Insightful)
Jealous of what, exactly? Kids sending SMS text at 100s the cost of an email, or simple IM? People paying hundreds of bucks to set themselves up for locked-in contracts?
I've been an Apple client since 1979. You want to know what pisses me off? Apple turning into a fucking toy company, and incrementally destroying NeXTSTEP. Apple spending time on bullshit iPhone screenshot shit, and hanging on to the HFS+ file system, which is actually incompatible with their lousy OS. Leopard is nothing but a r
Re: (Score:3, Interesting)
Just curious...why would you think it stupid for a parent to get a kid an iPhone? That way they'd be giving them an iPod and phone in one fell swoop.
Hell, when I was a teen.....I was working, and if they had them in my day...I'd have bought my own.
But really....are you saying buying a phone in general for a kid is stupid or just if it is an iPhone that is stupid?
Re:Makes you wonder.... (Score:4, Insightful)
I can see a situation in which a phone *might* make sense (kid works a late shift, has an unreliable car, etc... But I cant see the wisdom in getting a kid the iPhone or any other upper level phone. If a kid works and uses their own money thats all well and good but its way to much to give a kid because 'they need one'.
Re: (Score:3, Funny)
If I lived in a house with all of that screaming, I'd probably be violent, too.....
Layne
Re: (Score:2)
How many people really use video chat? (Score:2)
I for one would prefer to not have a camera on my Macbook and to have the iSight as a separate product. the only time I've used he actual camera I've actually picked the whole laptop up and waved it at the object I was needed to take a picture of.
Do many people really use the cameras in their Macbooks and iMacs? It seems like a supremely useless (and narcissistic) design to have a camera that you can only use part of the time and only to take a picture of yourself.
Re: (Score:2)
Video chat.
Video blogging (including those idiotic Youtube "response" videos).
Personal grooming without a mirror.
Quick photos (for example, showing your friends a funny wine label without having to find a digital camera, sync it, and then resize the giant 5-8MP image to send via the web).
Barcode scanning (for Delicious Library, etc.).
Profile photos for social networking and the like.
There are plenty of uses. Not all of them apply to everyone, and certainly not all of them are listed here.
Seems most popular at opposite extremes of age (Score:3, Insightful)
Young kids tend to love the built in camera, especially using it with the Photobooth application. The Grandparents love video-chat with the grandkids. Everybody in-between in age thinks it's a waste of money.
I've used the built-in camera in my Macbook exactly once so far.