3 ms·
I don't think there any additional security issues regarding Apple altering the binaries. iOS devices are already running a closed source proprietary OS, which
by devit 11y ago
I don't think there any additional security issues regarding Apple altering the binaries.
iOS devices are already running a closed source proprietary OS, which can easily set an hardware breakpoint in a binary and then do anything that could be done by modifying the binary itself without leaving traces anywhere (other than timing and cache effects).
Apple even designs and manufactures the CPU so they could even modify the CPU to detect instruction patterns and siphon off private keys without any detectable timing or cache effects at all.
Of course, that doesn't mean that it's all fine, but rather that the system is already completely broken to begin with in this respect.
- sneak 11y agoYeah, this is important. As much as I'd like to be upset about the lack of binary verifiability throughout the chain, as the article even points out, without jailbreaking it is already impossible. We have no idea what code Apple is telling our devices to run, regardless of the form in which it is submitted to the App Store. It's a bummer, but rms was right all along.