Top stories

Apple Devotes Entire Home Page To Jerome York Obituary

20100318-york.jpg

If ever you needed a sign that Apple was a different kind of technology company, this is it.
What other computer manufacturer would remove its top-selling, hype-inducing, industry-altering new product from the prime spot on its website home page, and replace it with an obituary to an investor?
This is one of those “Here’s to the [...]

Coming Soon: Steve Jobs, the Sitcom

Fake Steve creator Dan Lyons just signed a deal to bring Steve Jobs to another small screen near you.
The half-hour series called “iCon” is billed by the presser as “a savage satire centering on a fictional Silicon Valley CEO whose ego is a study in power and greed.”
Making sure the barbs prick will be the [...]

What’s Next For the iPad? A Tabletop iPad, According to Xerox PARC Circa 1991

Way back in 1991, just as Apple was transitioning from 68k to PowerPC chips, the braniacs at Xerox PARC were predicting it’s entire iPod, iPhone and iPad strategy. And next up for the iPad is a blackboard-sized device.
Nearly 20 years ago, just as personal desktop computers were taking off, researchers at Xerox started thinking about [...]

iPhone App Arms Users With Silent Panic Button

A new app called Silent Bodyguard features a panic button that sends an SOS distress signal with GPS coordinates to potential rescuers without alerting onlookers.
While the $3.99 app, available on iTunes, isn’t the first ICE (in case of emergency) app, this one is backed by Dr. Clint Van Zandt, former FBI chief hostage negotiator and criminal [...]

Warning: iPhone Bug Allows Deleted Email To Be Retrieved With Simple Search

Never use your iPhone for incriminating or embarrassing emails you might not want others to see.

CoM reader Matt Janssen has just found a bug in the iPhone’s 3.x software that allows deleted email to be retrieved.

In other words, the iPhone and iPod Touch’s Mail app doesn’t properly delete email. Erased email messages can be easily retrieved using a simple search with the iPhone’s built-in search tool.

“Obviously this is could be a major security issue if you think you deleted something from your iPod but it’s not really deleted,” says Janssen. “You can still search through messages that are deleted. And this isn’t messages that are just recent. I found some messages that are over three or four months old.”

The bug could reveal embarrassing email sent or received by cheating spouses, or messages that kids don’t want their parents to see. It’s present in the software for both the iPhone and iPod Touch.

Janssen has made a video to demonstrate the bug. In the video, Janssen creates an email in a standard POP account, sends it to himself and then deletes it. The message appears to be gone from his inbox, but he’s able to retrieve it using the iPhone’s Search function. Janssen has to search for the deleted message twice. On first try, the Mail app crashes and sends him back to the Home screen. But on the second try, the message is retrieved and displayed. It even retrieves messages that are deleted from the server.

“Hopefully Apple will fix it in some later releases,” says Janssen.

Link to Jannsen’s YouTube video.

If you enjoyed this article:
Subscribe via RSS or email, or follow us on Facebook and Twitter

About the author

Leander Kahney

Leander Kahney is the editor of Cult of Mac, and author of three books about technology culture: Inside Steve’s Brain, the New York Times bestseller about Steve Jobs; Cult of Mac; and Cult of iPod. Leander has written for Wired, MacWeek, Scientific American, and The Guardian in London. Follow Leander on Twitter @lkahney and Facebook.

Email the author | Read more posts by Leander Kahney.

132 comments

    Ahhh , any moron know that your messages go into the “Deleted” mailbox until you empty it.

    Well the reason the search displays this is because the email is still in the Trash Folder. Since it is still in the Trash Folder it is still on the server. Delete from Trash you have fixed your problem.

    So remember kids, don’t use POP, go for IMAP.

    I should have tested this before posting. Matt may have jumped the gun. As you guys noted, he may simply be finding ‘deleted’ email in the iPhone’s Trash folder, where it is stored until the folder is emptied.
    I just deleted a message on my iPhone, cleared the Trash folder on my Mac, and lo-and-behold, the message is gone for good: it doesn’t appear in a simple search. I’ve asked Matt to double check.

    As always, if you lose physical control of your device, you should have zero expectation of security.

    You shouldn’t use email at all for anything incriminating or embarrassing since the other participant will have a copy of the email even if you delete it!!

    Hi guys,

    Thanks for the comments (except maybe the person who called me a “moron”). If you would kindly watch the video starting at 59 seconds – you can see that I open the Trash folder on my iPod and delete the message. Please take a look at the video again – and if you didn’t even watch it before posting: shame on you.

    Matt Janssen

    BTW Leander, you spelled my last name 3 different ways within the post.

    [...] 3.0, ela ainda pode ser obtida através do Spotlight, conforme prova uma falha de segurança descoberta por um leitor do Cult of Mac. Isso pode expor informações confidenciais de certos usuários a [...]

    [...] if you can find any clues as to what’s going on here: I’m as alarmed as I am stumped. [CultOfMac] [...]

    [...] Try this yourselves and see if you can find any clues as to what’s going on here: I’m as alarmed as I am stumped. [CultOfMac] [...]

    [...] Try &#116&#104is yourselves and see if you can find any clues as &#116o w&#104a&#116’s going on &#104ere: I’&#109 as alar&#109ed as I a&#109 s&#116u&#109ped. [Cul&#116&#79fMac] [...]

    [...] a mensagem ainda pode ser obtida através do Spotlight, conforme prova uma falha de segurança descoberta por um leitor do Cult of [...]

    [...] Try this yourselves and see if you can find any clues as to what’s going on here: I’m as alarmed as I am stumped. [CultOfMac] [...]

    [...] Read | Permalink | Email this | CommentsRandom Posts06/26/2009 — Engadget Podcast 152 – 06.26.2009: The Day the Music Died 207/29/2009 — Greenpeace takes a break from issuing reports to vandalize HP corporate HQ07/28/2009 — The Daily Roundup: here’s what you might’ve missed07/02/2009 — FireFox has multi-touch support08/07/2009 — Sony Ericsson ‘Jalou’ next in company’s Symbian lineup?   [...]

    [...] Read | Permalink | Email this | Comments Share and Enjoy: [...]

    [...] Read | Permalink | Email this | Comments Loading… @import url("http://www.google.com/uds/css/gsearch.css"); window._uds_vbw_donotrepair = true; @import url("http://www.google.com/uds/solutions/videobar/gsvideobar.css"); .playerInnerBox_gsvb .player_gsvb { width : 320px; height : 260px; } function LoadVideoBar() { var videoBar; var options = { largeResultSet : !true, horizontal : true, autoExecuteList : { cycleTime : GSvideoBar.CYCLE_TIME_MEDIUM, cycleMode : GSvideoBar.CYCLE_MODE_LINEAR, executeList : ["ytchannel:theworacle","ytchannel:luckymauro","ytchannel:mttdx"] } } videoBar = new GSvideoBar(document.getElementById("videoBar-bar"), GSvideoBar.PLAYER_ROOT_FLOATING, options); } // arrange for this function to be called during body.onload // event processing GSearch.setOnLoadCallback(LoadVideoBar); Filed under: Engadget No Comments Comments (0) Trackbacks (0) ( subscribe to comments on this post ) [...]

    [...] UPDATED: An internal tipster has provided us with proof that Apple is fully aware of this issue and will probably be including a fix in iPhone OS 3.1. [CultOfMac] [...]

    [...] UPDATED: An internal tipster has provided us with proof that Apple is fully aware of this issue and will probably be including a fix in iPhone OS 3.1. [CultOfMac] [...]

    [...] appeared on Engadget on Mon, 17 Aug 2009 17:31:00 EST. Please see our terms for use of feeds.Read | Permalink | Email [...]

    [...] appeared on Engadget on Mon, 17 Aug 2009 17:31:00 EST. Please see our terms for use of feeds.Read | Permalink | Email [...]

    [...] Read | Permalink | Email this | Comments Categories: Techno Freak, iPhone Tags: Apple, bug, deleting email, DeletingEmail, email, iphone os, iphone os 3.0, IphoneOs, IphoneOs3.0, matt janssen, MattJanssen, security, spotlight Comments (0) Leave a comment [...]

    [...] appeared on Engadget on Mon, 17 Aug 2009 17:31:00 EST. Please see our terms for use of feeds.Read | Permalink | Email [...]

    [...] appeared on Engadget on Mon, 17 Aug 2009 17:31:00 EST. Please see our terms for use of feeds.Read | Permalink | Email this | Comments Categories: Uncategorized [...]

    [...] Read | Permalink | Email this | Comments Filed under: Cell Phone Comparison, Cell Phone Packages, Cell Phone Retail, Cell Phone Wholesaler, Cheap Mobile Phones, Mobile Phone Radiation, Mobile Phones, Mobile Phones New Releases, Prepaid Cell Phone [...]

    [...] appeared on Engadget on Mon, 17 Aug 2009 17:31:00 EST. Please see our terms for use of feeds.Read | Permalink | Email [...]

    [...] appeared on Engadget on Mon, 17 Aug 2009 17:31:00 EST. Please see our terms for use of feeds.Read | Permalink | Email [...]

    [...] appeared on Engadget on Mon, 17 Aug 2009 17:31:00 EST. Please see our terms for use of feeds.Read | Permalink | Email [...]

    [...] UPDATED: An internal tipster has provided us with proof that Apple is fully aware of this issue and will probably be including a fix in iPhone OS 3.1. [CultOfMac] [...]

    [...] appeared on Engadget on Mon, 17 Aug 2009 17:31:00 EST. Please see our terms for use of feeds.Read | Permalink | Email [...]

    [...] appeared on Engadget on Mon, 17 Aug 2009 17:31:00 EST. Please see our terms for use of feeds.Read | Permalink | Email this | Comments Categories: Apple, [...]

    [...] Read | Permalink | Email this | Comments [...]

    [...] appeared on Engadget on Mon, 17 Aug 2009 17:31:00 EST. Please see our terms for use of feeds.Read | Permalink | Email this | Comments Posted on August 17, 2009 at [...]

    [...] Read | Permalink | Email this | Comments [Translate] English العربية български català česky dansk Deutsch ελληνική español eesti فارسی suomi français galego עברית [...]

    [...] UPDATED: An internal tipster has provided us with proof that Apple is fully aware of this issue and will probably be including a fix in iPhone OS 3.1. [CultOfMac] [...]

    [...] Read | Permalink | Email this | Comments Leave a comment Loading… @import url("http://www.google.com/uds/css/gsearch.css"); window._uds_vbw_donotrepair = true; @import url("http://www.google.com/uds/solutions/videobar/gsvideobar.css"); .playerInnerBox_gsvb .player_gsvb { width : 320px; height : 260px; } function LoadVideoBar() { var videoBar; var options = { largeResultSet : !true, horizontal : true, autoExecuteList : { cycleTime : GSvideoBar.CYCLE_TIME_MEDIUM, cycleMode : GSvideoBar.CYCLE_MODE_LINEAR, executeList : ["ytchannel:gamevideostrailers","ytchannel:SheepSqueal","ytchannel:SMGTUK","ytchannel:cobracody"] } } videoBar = new GSvideoBar(document.getElementById("videoBar-bar"), GSvideoBar.PLAYER_ROOT_FLOATING, options); } // arrange for this function to be called during body.onload // event processing GSearch.setOnLoadCallback(LoadVideoBar); Related Posts and VideosNo Related Post No comments yet. [...]

    [...] Read | Permalink | Email this | Comments Read the whole story… [...]

    So… if it’s not displaying the email within the Trash folder, the logical explanation is that Spotlight actually makes a COPY of all our emails when it indexes them? And then it lags behind when an event such as delete happens, not indexing the change for a little while?
    I can’t help but wonder how serious this really is — try the whole thing again, but leave a few minutes between the time you delete and the time you search. Doing the search immediately is not really “fair” and I can’t believe that a few moments delay in removing something from the search index is that big of a security issue on an inherently insecure device such as a mobile phone.

    Also – I wonder if the first search crash was because the index was in the midst of being updated; after the crash it reverted back to the previous index and waited to update it again?

    [...] CultOfMac. Entradas relacionadas con la que acabas de leer:Problemas de seguridad del iPhone En el último [...]

    Gene, he said some of them were as old as month’s prior. Read the damn article and watch the damn video! Ok, Gene!

    [...] Read | Permalink | Email this | Comments Filed under: Another Mobile Phone, Mobile New Phone, Mobile Phone Advertising, Mobile Phone Deals, Mobile Phone Handset, Mobile Phone Prices, Mobile Phone Reviews, Mobile Phone Sales, Mobile Phone Shop, Mobile Phones Online, Pay-as-you-go Mobile Phone [...]

    [...] Cult of Mac] Tweet ThisTipSHARETHIS.addEntry({ title: "Be careful what you write: iPhone OS 3.0 doesn’t [...]

    [...] appeared on Engadget on Mon, 17 Aug 2009 17:31:00 EST. Please gaming our terms for ingest of feeds.Read | Permalink | Email [...]

    This problem doesn’t appear in B3 of 3.1

    [...] appeared on Engadget on Mon, 17 Aug 2009 17:31:00 EST. Please see our terms for use of feeds.Read | Permalink | Email [...]

    [...] UPDATED: An internal tipster has provided us with proof that Apple is fully aware of this issue and will probably be including a fix in iPhone OS 3.1. [CultOfMac] [...]

    [...] UPDATED: An internal tipster has provided us with proof that Apple is fully aware of this issue and will probably be including a fix in iPhone OS 3.1. Additionally, there are a number of ways to delete the messages from the index—for some, waiting works; for me, even restarting didn’t—but the fact remains that deleted emails are left, for some time, fully accessible. [CultOfMac] [...]

    [...] appeared on Engadget on Mon, 17 Aug 2009 17:31:00 EST. Please see our terms for use of feeds.Read | Permalink | Email [...]

    Is there a clear cache option? Perhaps that is where the message is coming from.

    Also, perhaps a complete shutdown and restart of the iPhone will clear this? Has that been tried?

    [...] Read Leave a comment Loading… @import url("http://www.google.com/uds/css/gsearch.css"); window._uds_vbw_donotrepair = true; @import url("http://www.google.com/uds/solutions/videobar/gsvideobar.css"); .playerInnerBox_gsvb .player_gsvb { width : 320px; height : 260px; } function LoadVideoBar() { var videoBar; var options = { largeResultSet : !true, horizontal : true, autoExecuteList : { cycleTime : GSvideoBar.CYCLE_TIME_MEDIUM, cycleMode : GSvideoBar.CYCLE_MODE_LINEAR, executeList : ["ytchannel:SprintPalmPre","ytchannel:phonescoop","ytchannel:phonedog","ytchannel:SlashGear"] } } videoBar = new GSvideoBar(document.getElementById("videoBar-bar"), GSvideoBar.PLAYER_ROOT_FLOATING, options); } // arrange for this function to be called during body.onload // event processing GSearch.setOnLoadCallback(LoadVideoBar); Related Posts and VideosNo Related Post No comments yet. [...]

    [...] CultofMac Stuur naar Twitter, mail e.d. Tags:  bug, e-mail, gewiste, iPhone, [...]

    This may or may not be a security issue but there definitely are a couple of bugs here. 1, the search crashing instead of a graceful failure and 2, the email showing up in the search even though its been deleted (searching immediately might not be “fair” but someone might do it for some reason and crashing could leave the index in a bad state for all future searches ?). The post mentions that the user has seen emails, deleted a few months ago, showing up on search, but I agree it would be nice to test/share a video, if it actually shows up an email older than say a month.

    Good catch whoever found it!

    On my phone it disappears after a few minutes. Of course the copy in the sent box is still there unless I delete that, then everything goes. No record remains. I’m surprised CoM even bothered posting this story, although the crash is perhaps newsworthy.

    [...] Leser von cultofmac scheint ein Bug, eine Sicherheitslücke in Apple iPhone und iPod Touch E-Mail App gefunden zu [...]

    [...] CultofMac] Categories: 1 Tags: Apple, bug, iphone, ipod, mail, security, touch Comments (0) [...]

    [...] erst haben wir die SMS-Sicherheitslücke überstanden, schon wurde eine neue entdeckt. Cult of Mac berichtet, dass das iPhone keine E-Mails löscht, wenn man dazu den Befehl gibt. Das Problem [...]

    [...] (via CultofMac) has heard that bug might be fixed in iPhone 3.1, now on Beta 3, and perhaps to be released as soon [...]

    [...] Read | Permalink | Email this | CommentsBy Nilay Patel Yaab Leave a comment | Trackback No comments yet. [...]

    [...] (via CultofMac) has heard this bug might be fixed in iPhone 3.1, now on Beta 3, and perhaps to be released as soon [...]

    [...] (via CultofMac) has heard this bug might be fixed in iPhone 3.1, now on Beta 3, and perhaps to be released as soon [...]

    [...] (via CultofMac) has heard this bug might be fixed in iPhone 3.1, now on Beta 3, and perhaps to be released as soon [...]

    [...] reading Un bug en el iPhone OS 3.0 permite a los e-mails borrados regresar del inframundoRead | Permalink | Email [...]

    [...] friends over at Engadget have highlighted a Cult of Mac post that, at first glance, appears to have found a bug in Spotlight’s caching of email search results [...]

    [...] friends over at Engadget have highlighted a Cult of Mac post that, at first glance, appears to have found a bug in Spotlight’s caching of email search results [...]

    [...] friends over at Engadget have highlighted a Cult of Mac post that, at first glance, appears to have found a bug in Spotlight’s caching of email search results [...]

    [...] friends over at Engadget have highlighted a Cult of Mac post that, at first glance, appears to have found a bug in Spotlight’s caching of email search results [...]

    [...] (via CultofMac) has heard this bug might be fixed in iPhone 3.1, now on Beta 3, and perhaps to be released as soon [...]

    [...] friends over at Engadget have highlighted a Cult of Mac post that, at first glance, appears to have found a bug in Spotlight’s caching of email search results [...]

    [...] (via CultofMac) has heard that bug might be fixed in iPhone 3.1, now on Beta 3, and perhaps to be released as soon [...]

    [...] Cult of Mac has reported that on iPhone 3.0, the email you have deleted is not actually removed but keep somewhere inside iPhone. When you search for keywords of the deleted email via Spotlight search, the search result displays that deleted email and you can even open it. [...]

    [...] friends over at Engadget impact highlighted a Cult of Mac locate that, at prototypal glance, appears to impact institute a bug in Spotlight’s caching of [...]

    [...] delete an e-mail. Even after emptying the Mail application’s trash, the message — and all of its contents — are still accessible through the phone’s Spotlight search [...]

    [...] friends over at Engadget have highlighted a Cult of Mac post that, at first glance, appears to have found a bug in Spotlight’s caching of email search results [...]

    [...] (via CultofMac) has heard this bug might be fixed in iPhone 3.1, now on Beta 3, and perhaps to be released as soon [...]

    [...] โดยเว็บไซต์ Cult of Mac ซึ่งทำได้ง่ายมาก [...]

    [...] (via CultofMac) has heard this bug might be fixed in iPhone 3.1, now on Beta 3, and perhaps to be released as soon [...]

    [...] Please see this post for updated information. Our friends over at Engadget have highlighted a Cult of Mac post that, at first glance, appears to have found a bug in Spotlight’s caching of email search results [...]

    [...] of Mac reader Matt Janssen revealed the bug yesterday morning after he discovered that an e-mail he remembered deleting showed up in a Spotlight search. [...]

    [...] to delete an e-mail. Even after emptying the Mail application’s trash, the message — and all of its contents — are still accessible through the phone’s Spotlight search [...]

    [...] of Mac reader Matt Janssen revealed the bug yesterday morning after he discovered that an e-mail he remembered deleting showed up in a Spotlight search. [...]

    [...] of Mac reader Matt Janssen revealed the bug yesterday morning after he discovered that an e-mail he remembered deleting showed up in a Spotlight search. [...]

    [...] of Mac reader Matt Janssen revealed the bug yesterday morning after he discovered that an e-mail he remembered deleting showed up in a Spotlight search. [...]

    [...] of Mac reader Matt Janssen revealed the bug yesterday morning after he discovered that an e-mail he remembered deleting showed up in a Spotlight search. [...]

    [...] of Mac reader Matt Janssen revealed the bug yesterday morning after he discovered that an e-mail he remembered deleting showed up in a Spotlight search. [...]

    [...] 分类: 移动电话 有什么比变心的女友、长不回来的头发更可怕的呢?答案是删不掉的电子邮件!(来乱的!?)简单说就是有人发现 iPhone OS 3.0(iPhone、iPod touch 皆然,所以是 OS 的问题)有个跟 Spotlight 搜寻、邮件相关,不大不小刚刚好的漏洞。这漏洞大概是这样的情况;一位朋友在删除(收件匣)兼清除(垃圾桶)的信件(POP / IMAP)后,发现居然还可以用 Spotlight 挖出来并且读取,不过邮件的内容则是显示 1 / 0,正在读一封邮件,但是收件匣 / 垃圾桶里面却都是空的,同时即使是连服务器端的档案都删除,Spotlight 还是找得到,只要还记得邮件的主题是啥,就可以挖回。目前怀疑是这些信件的快取档案,可能没有在信件被删除兼清除后一并杀光,甚至拖了一、两个月都还留(这位朋友有示范找出六月份的信件)在 iPhone / iPod touch 的某处,反而让啥都可以找的 Spotlight 有机会把他们给揪出来;表面上看起来不是啥太大的问题,至少也不是说随便打打就会被找到,真有啥不能说得秘密,还得知道这秘密的『标题』里头有啥关键词。(好像也不太困难的样子…)不过他总是一个很明显不该发生的事情,现在也只能祈祷苹果会在下一版的 iPhone OS(3.1?)更新中把该问题解决才是。[原文连接]继续阅读全文 iPhone Spotlight 搜寻:『翻开一张覆盖的卡!删除信件苏醒!』引用来源 | 此文章网址 | 转寄此文章 | 回应 [...]

    [...] โดยเว็บไซต์ Cult of Mac ซึ่ง ทำได้ง่ายมาก [...]

    [...] pelo Cult of Mac, a falha fica evidente ao utilizarmos a  ferramenta de busca Spotlight (incluída na mais recente [...]

    [...] friends over at Engadget have highlighted a Cult of Mac post that, at first glance, appears to have found a bug in Spotlight’s caching of email search results [...]

    [...] friends over at Engadget have highlighted a Cult of Mac post that, at first glance, appears to have found a bug in Spotlight’s caching of email search results [...]

    [...] Read | Permalink | Email this | Comments Share and Enjoy: These icons link to social bookmarking sites where readers can share and discover new web pages. [...]

    I had a much worse bug on my iPhone – you can read about it here :
    http://blog.typemock.com/2009/08/why-do-software-development-companies.html

    [...] UPDATED: An internal tipster has provided us with proof that Apple is fully aware of this issue and will probably be including a fix in iPhone OS 3.1. Additionally, there are a number of ways to delete the messages from the index—for some, waiting works; for me, even restarting didn’t—but the fact remains that deleted emails are left, for some time, fully accessible. [CultOfMac] [...]

    [...] Janssen, who first exposed the bug at the Web site Cult of Mac, created a video to demonstrate the security flaw. In it, he said that he has been able to use [...]

    [...] friends over at Engadget have highlighted a Cult of Mac post that, at first glance, appears to have found a bug in Spotlight’s caching of email search results [...]

    [...] Read | Permalink | Email this | Comments Go to Source [...]

    I LOVE U MARK JANSEN!!! that tottally worked u are amazin!

    Wow,what a lifesaver I’d deleted an email I needed and got it back using this technique..AWESOME, thankyou.

Add your comment

Name(Required)

Mail (required, but not published)

Website

Comment

Buy Inside Steve's Brain Buy from Amazon.com Buy from Barnes & Noble