10 ms·
If You Can’t Break Crypto, Break the Client: Recovery of Plaintext iMessage Data
- yalooze 10y agoI had a similar thought with WhatsApp's Signal announcement. I believe that on iOS, by default all WhatsApp messages are backed up to iCloud Drive. So that would seem to be an easier attack vector.
- ikeboy 10y agohttp://blog.elcomsoft.com/2015/11/a-new-tool-for-whatsapp-acquisition/ http://blog.elcomsoft.com/2015/11/a-new-tool-for-whatsapp-ac...
- endymi0n 10y agoNot just the messages - the key too. Just imagine the outcry from someone breaking his iPhone not being able to restore his messages because of the introduction of end-to-end. That way, you don't even have to attack WhatsApp itself and they have all the plausible deniability they needed.
- mtgx 10y agoWhy would the key be backed up to iCloud? Do you have a source for this?
- sneak 10y agoThe cryptosystem in use by Signal and now WhatsApp does not work this way. It offers forward secrecy, where recovery of the long-term keys will not allow decryption of past intercepted encrypyed messages.
- eeeeeeeeeeeee 10y agoWould love to see a source on this. Every time I restore an iOS device, I need to manually re-enter anything secret like passwords.
- biokoda 10y agoThe only text/voip app that securely stores its data is Biocoded (https://biocoded.com/home https://biocoded.com/home). Even if the local on-device database gets copied elsewhere, it will be undecryptable outside of that device.
- tetrep 10y agoWhat's wrong with Signal's encrypted storage? AFAIK if you set a password it will be used to encrypt local storage of your messages.
- biokoda 10y agoIt's not that difficult to break. Anything encrypted with a password is not all that secure. Someone can clone your device or by using a security hole in the device can get to that storage blob and eventually crack it in reasonable time.
- caf 10y agoThat entirely depends on how much entropy is in your passphrase. It's entirely possible to use one that cannot be cracked in reasonable time.
- Natanael_L 10y agoSignal on Android offers password protected encryption for chat logs
- haddr 10y agoIn case of Android what you only need is that your application can read notifications (and has notifications/accessibility permissions). E.g. all whatsapp messages go through it...
- sgarman 10y agoThis means a user would have to installed the app. Once your local machine is owned it's over.
- Mafana0 10y agoA typical fanboyism argument when one's favorite company screws up. Just mention the other rivals and add zero insight into the original idea being discussed. > In case of Android what you only need is that your application can read notifications This "only" is much harder to do than sending a Javascript URL.
- dmh2000 10y agothat's pretty much the approach on all crypto. crack the implementation, not the algorithm.
- haddr 10y agoIt's rather "steal the message after decrypted" scenario, rather than cracking the implementation.
- CiPHPerCoder 10y agoI think they were referencing, "Most crypto is bypassed rather than broken."
- haddr 10y agoexactly
- exabrial 10y agoUse a wrench: https://xkcd.com/538/ https://xkcd.com/538/
- TazeTSchnitzel 10y agoApple use a web view for messages? I would've thought they'd use native UI. I guess it's easier to handle text properly with HTML.
- moloch 10y agoYes it surprised us too, we didn't even think about looking into Messages until Shubs jokingly started sending payloads to me using it.
- atomwaffel 10y agoYes, surprisingly the OS X Messages app doesn't seem to share a lot of UI code with the iOS version. You can easily tell that it's a simple WebView from the way text selections behave.
- 91bananas 10y agoMeaning how you can select text across messages?
- atomwaffel 10y agoYes, that and how some of the whitespace between the messages gets selected as well.
- TazeTSchnitzel 10y agoStrangely Apple seem to build everything twice, once for iOS, once for OS X, even if they have the same appearance. It'll bite them some day.
- tibbon 10y agoIt looks like the code was pulled from Github https://github.com/BishopFox/cve-2016-1764 https://github.com/BishopFox/cve-2016-1764
- deleted 10y ago[deleted]
- moloch 10y agoSorry about the mix up, the code available here: https://github.com/moloch--/cve-2016-1764 https://github.com/moloch--/cve-2016-1764 and here: https://github.com/BishopFox/cve-2016-1764 https://github.com/BishopFox/cve-2016-1764
- endymi0n 10y agoFor the depressing truth on the crypto wars: https://news.ycombinator.com/item?id=7757978 https://news.ycombinator.com/item?id=7757978 (Crypto won't save you either [PDF]) ...or to paraphrase Jeff Atwood: "I love crypto, it tells me what part of the system not to bother attacking"
- egyptiankarim 10y agoThat's my favorite quote from Atwood! People are so prone to forget that while cryptographic algorithms are provably secure (under practical constraints) in a mathematically rigorous way, their implementations are subject to all of the shortcomings of any engineering practice. Makes quick work for an attacker trying to figure out where to start.
- eutectic 10y agoEven cryptography relies on unproven assumptions; we just consider them trustworthy enough to rely on.
- adenadel 10y agoIt's my understanding that most (all?) public key cryptographic algorithms aren't provably secure, but are conjectured to be. They are reliant on some problem being hard to solve (factoring of large integers, discrete log, etc.). Something like a one time pad is provably secure, however.
- egyptiankarim 10y agoTrue and fair. I overstated my point. More appropriate to say "provably secure (under practical constraints)", and that's a rather significant caveat.
- swordswinger12 10y agoThis is a common misconception. The algorithm itself is provably secure, in the sense that violating the stated security guarantees of the algorithm is equivalent to solving a problem that's considered to be computationally intractable. The only part that isn't 'provable' is the basic assumption that the problem is intractable in the first place.
- Capira 10y agoSimplified POC: javascript://%0aprompt()
- kuschku 10y agoWe’ll see a lot more of this soon, considering more and more software is moving to webkit UIs, often with similar flaws.
- dmix 10y agoImplementing CSP and other mitigations for these types of same origin bypass attacks is relatively easy. I'm shocked that Apple didn't check this. I couldn't imagine Google ever making this mistake, their web security teams are solid. Apple really needs to invest heavily in bug bounties and internal security audits. This is 101 type of stuff when implementing any user-controllable embedded web content. The bar should never be this low for critical OS apps like iMessage.
- kuschku 10y ago> I couldn't imagine Google ever making this mistake, their web security teams are solid. You haven’t seen their XML bugs in Google Toolbar’s web gallery in 2013, have you? Full access to the whole file system of their servers via XML includes. A bunch of security researchers managed to dump /etc/passwd as a sample to get the bug bounty. Google’s security isn’t that much better either...
- bengotow 10y agoMan, that's depressing. It's fairly easy to prevent this particular kind of injection—you just have to add a Content Security Policy to the HTML page. The appropriate value for web pages running from file://, with no expectation of downloading and executing remote JavaScript is: `script-src 'self';` Really sad to see that Apple is using embedded web views without these sort of basic protections. I bet worse exploits than this are possible, given that they probably expose parts of the ObjectiveC layer through the JavaScriptCore bridge.
- moloch 10y agoIt gets even scarier with frameworks like nw.js where you can just execute native code directly from the DOM.
- lukashed 10y agoDoes anyone know how they managed to open the console / inspector inside iMessage.app?
- deleted 10y ago[deleted]
- moloch 10y agoWe used JSConsole and Weinre JSConsole -http://jsconsole.com/ http://jsconsole.com/ Weinre - https://people.apache.org/~pmuellr/weinre/docs/1.x/1.5.0/ https://people.apache.org/~pmuellr/weinre/docs/1.x/1.5.0/
- theseatoms 10y agoThis is the article that years ago convinced me it's not worth obsessing about my own technological privacy: http://www.gaudior.net/alma/johnny.pdf http://www.gaudior.net/alma/johnny.pdf I despise the "if you have nothing to hide..." argument for the surveillance state. And I argue against it every chance I get. But, practically speaking, I don't have much to hide. I also realized that one can draw more attention to oneself by taking drastic measures to preserve one's own privacy. I know, citation needed... I believe FB (or a related party) released some research about detecting "holes in the social network". Browser fingerprinting is another front on which I've probably made myself more unique to trackers.
- hockley 10y agoDon't we all want to hide our payment information when we buy stuff online? Modern commerce is built on identity assertion and securing payments between two parties over the wire.
- theseatoms 10y agoNo doubt. I'd prefer my information stay private. But that liability lies with the party that loses my data.
- Joof 10y agoOn the other hand, if encryption is the default then there is no obscurity in not using it.
- tlrobinson 10y agoThe fake URL in a JavaScript comment in the the JavaScript URI is a hilarious and neat trick. javascript://bishopfox.com/research?%0d%0aalert(1) gets interpreted as: //bishopfox.com/research? alert(1) Fortunately most browsers prevent you from pasting JavaScript URIs in the URL bar these days. It's a little surprising Apple overlooked not one but two fairly obvious major holes: allowing JavaScript URIs, and the lack of same-origin policy. I wonder how many other applications are similarly vulnerable.
- moloch 10y agoWell the lack of SOP is by design, since it's not a browser visiting multiple sites the idea of an "origin" doesn't always make sense. This is part of a larger body of work we've been researching, we found much more than this one (all known bugs have been patched, that's why we've been waiting to release this). We'll be submitting the full body of work to DEFCON/Blackhat, and a few other cons, hopefully we'll get accepted, be on the lookout if we do!
- deleted 10y ago[deleted]
- gravypod 10y agoThis isn't the only thing you can do without breaking crypto. If exploits are too hard because you are lazy like me: check out CreepyDOL.
- known 10y ago"Never do anything against conscience even if the state demands it." --Einstein