8 ms·
Apple says recent Wikileaks CIA docs detail old, fixed iPhone and Mac exploits
- sohkamyung 10y agoYes, it is an old exploit. This ArsTechnica article [1] has more on the timeline [1] https://arstechnica.com/security/2017/03/new-wikileaks-dump-the-cia-built-thunderbolt-exploit-implants-to-target-macs/ https://arstechnica.com/security/2017/03/new-wikileaks-dump-...
- tptacek 10y agoIf you're not familiar with the iPhone platform and you're interested in just one technical detail to help navigate these stories, let it be this: the iPhone 3G platform bears very little resemblance to the modern, post-touch-ID phone. The platform security system at every level, from boot chain to hardware domains to OS security, evolved more in the last 10 years than any previous platform had in 20 years prior. That doesn't make an iPhone 7 impregnable, but it should inform any analysis you do of stories about phones being tampered with "starting in 2008"; that's a little like talking about SMTP server security "starting in 1993".
- kasey_junk 10y agoThat's exactly what an NSA stooge would want us to think!
- bitexploder 10y agoI still wonder how much it would have cost the FBI to crack the passcode/phrase on a phone with secure enclave. I also wonder if an agency like the NSA has capabilities around these devices and would they be willing to expose such capabilities in another similar scenario. A final musing of mine is if they wouldn't just claim some group or another did it for $X,000,000 dollars to make it all seem plausible (e.g. the cost and attack scenario on the 5c was plausible and probably required desoldering the storage, but that won't help on a device with the enclave system). The encrypted by default iOS 4 and the whole design around passcode handling in that release was the start of a very strong security posture for Apple and their iOS devices.
- miles 10y ago> I still wonder how much it would have cost the FBI to crack the passcode/phrase on a phone with secure enclave. Apparently $1,500[1]: "Cellebrite's CAIS now supports lawful unlocking and evidence extraction of iPhone 4S/5/5C/5S/6/6+ devices (via our in-house service only)."[2] [1] https://www.macrumors.com/2017/02/24/cellebrite-lawful-unlocking-iphone-6/ https://www.macrumors.com/2017/02/24/cellebrite-lawful-unloc... [2] https://twitter.com/jifa/status/834510775158976513 https://twitter.com/jifa/status/834510775158976513
- miles 10y agoSadly, I can no longer update my comment, but please note that the iPhone 5S, 6, and 6+ are equipped with Secure Enclave. As recently as last April, the FBI was claiming they could not access 5S or newer models[1] (at least with the hack they reportedly bought for over $1 million[2]). [1] https://9to5mac.com/2016/04/07/fbi-iphone-hack-method-secure-enclave/ https://9to5mac.com/2016/04/07/fbi-iphone-hack-method-secure... [2] http://www.cnn.com/2016/04/21/politics/san-bernardino-iphone-apple-hacking/ http://www.cnn.com/2016/04/21/politics/san-bernardino-iphone...
- rangibaby 10y agoI wouldn't trust the FBI as an accurate source of information about things like this.
- ValleyOfTheMtns 10y agoThis just made me realise that yes, 2008 was in fact almost 10 years ago...
- konceptz 10y agoI always find it fascinating to read and understand the mistakes or yesteryear. Many of the same architecture flaws can be found in systems today, and likely tomorrow. Bugs, on the other hand, are fun because we tell ourselves we would never make those mistakes, and then proceed to make them.
- frik 10y agoWhat were the big changes? Beside the obvious changes in hardware components like different custom ARM SoC, different modem chip, added fingerprint sensor, etc. what are the software changes? I guess you use now fuzzing, static code analysis, semi-automatic proofing on some import kernel drivers. You mentioned boot chain... bootloader, RAM FS, etc. The iPhone OS started as a fork of OSX, which is based on NextStep with the interesting mix of BSD Unix with Mach. So from the OS perspective I guess it still largely resembles the same architecture that was laid out decades ago.
- rmathew 10y agoCheck out the iOS Security Guide from Apple for such information: https://www.apple.com/business/docs/iOS_Security_Guide.pdf https://www.apple.com/business/docs/iOS_Security_Guide.pdf
- ilogik 10y agoif you want the details: https://www.youtube.com/watch?v=BLGFriOKz6U https://www.youtube.com/watch?v=BLGFriOKz6U
- throwaway7312 10y agoAs an iPhone 3G user who spends a lot of time bouncing between countries, this makes me think I should upgrade to something more recent the next time I'm headed anywhere there's a risk customs may inspect my devices.
- praseodym 10y agoThere haven't been any security updates for the iPhone 3G since 2011, so I'd worry about other types of attacks (web malware) as well.
- nkristoffersen 10y agoyes, time for an updated model. backup and wipe your phone before you travel. there are several stories now of customs compelling you to unlock the phone before allowing you to leave. https://www.theatlantic.com/technology/archive/2017/02/a-nasa-engineer-is-required-to-unlock-his-phone-at-the-border/516489/ https://www.theatlantic.com/technology/archive/2017/02/a-nas...
- mastax 10y agoWill that help? There have been many stories (some posted on HN) of customs saying "unlock your phone or be detained indefinitely".
- daenney 10y agoUnless you have to, leave your fancy device at home and bring a dumb(er) travel phone with you that only contains the information you need for that trip. And there's nothing stopping you from loading more information on it after you've made it through customs.
- schoen 10y agoHave you heard "indefinitely" anywhere? I helped write both versions of the EFF border search guide and I don't think I've ever heard of "indefinitely", either as a threat or a reality.
- jandrese 10y ago
- Laforet 10y agoI have not read the leaked docs, however from the description it sounds like the good old 0x24K bootrom exploit[0] which lasted through the earlier revisions of 3GS until it was patched in hardware. There were a few bootrom exploits but by the time iPhone 5 came out, this vector was mostly gone if not entirely and every jailbreak since then required an initial priviledge escalation in the userland. [0] https://www.theiphonewiki.com/wiki/0x24000_Segment_Overflow https://www.theiphonewiki.com/wiki/0x24000_Segment_Overflow
- deleted 10y ago[deleted]
- mmjaa 10y agoIts one thing to state that the current version of the iOS is 'more resilient to intrusion/usurpation than an other version', and its another thing entirely to understand that Apple, Inc., itself .. may not be as resilient as required in order to validate the position that 'we can stop worrying about the CIA'. We should not 'stop worrying about the CIA' just because Apple came to the rescue and already fixed the bugs. We should, in fact, continue to apply pressure to such vendors of digital enslavement as Apple, and the rest of the sordid gang, to provide real evidence that "Things are Okay™", when asked.
- geofft 10y agoWhat would you interpret as "real evidence"? I have no idea how you would begin to demonstrate that a body of source code as big (in both lines of code and length / size of the development project) as iOS, Android/Replicant/Lineage, or any other modern operating system contains zero backdoors, especially when your threat model involves the software authors helping you over a period of many years to weave those backdoors into the OS and obfuscate them as much as necessary. I also have no idea how to audit a physical phone I have received from an Apple Store to make sure that the hardware and firmware faithfully implement what they are supposed to be implementing.
- chillaxtian 10y agoif you're interested in how iOS security works, apple publishes white papers on the subject. https://www.apple.com/business/docs/iOS_Security_Guide.pdf https://www.apple.com/business/docs/iOS_Security_Guide.pdf
- tyingq 10y agoI wonder how old the leaked CIA docs are though. Are there any contextual clues that it's current? Someone might have sat on a copy for years before leaking. Edit: Quick scan shows there are some docs with dates in 2013, 2014, 2015. So at least some of it is fairly recent. No real way to tell, though, if it was all pulled at once, assembled over time, etc.
- doggydogs94 10y agoThe CIA exploits are important because most people never update anything. It doesn't matter if you have fixed the OS for the exploit if the fix is never installed.
- leadingthenet 10y agoThankfully, Apple is pretty proactive about getting people on the latest version of the OS. IIRC, iOS 10 runs on over 80% of devices now.
- doggydogs94 10y agoPeople still have to actually run the update. Most non-tech types I know, never ever run software updates.
- notatoad 10y agoaccording to actual data rather than anecdote, iOS 10 is installed on ~80% of devices, and only 5% have something older than iOS 9. https://developer.apple.com/support/app-store/ https://developer.apple.com/support/app-store/
- imron 10y agoI am the 5%!
- nkristoffersen 10y agothe hackable 5% :-)
- rimliu 10y agoEasier to hack 5%. The rest are probably hackable too (no secure software exists) just takes more effort.
- 10y ago
- pfarnsworth 10y agoCIA must have a bunch of embedded workers at Apple, Google, etc all adding subtle bugs that can later be used to hack the devices and services. I imagine other intelligence agencies must have them too. If they don't, then they're not doing their job.
- JumpCrisscross 10y ago> If they don't, then they're not doing their job The CIA, which has limited domestic authority, compromising American companies' products is not only not their job, but also illegal.
- wruza 10y agoIf they have done everything legal, would wikileaks exist?
- jamesmishra 10y agoYes. An intelligence agency can operate lawfully (and with a higher ethical standard than any other intelligence agency), and still have enemies who intend to expose secrets.
- jackvalentine 10y agoYes, because people love readings about secret stuff regardless of legality.
- JumpCrisscross 10y ago> If they have done everything legal [sic] I never said the CIA always conducts itself legally. My point was that "their job" is defined by the law. CIA agents infiltrating American manufacturers to break their products, even if intended for foreign customers, is illegal and thus not "their job". > would wikileaks exist If I understand correctly, you're saying Wikileaks' existence is proof of the CIA's impropriety? That assumes anything secret is illegal. Not true. Classified information is legal [1]. [1] https://en.wikipedia.org/wiki/Classified_information_in_the_United_States https://en.wikipedia.org/wiki/Classified_information_in_the_...
- kevindong 10y ago> Based on our initial analysis, the alleged iPhone vulnerability affected iPhone 3G only and was fixed in 2009 when iPhone 3GS was released. "fixed" probably isn't the right word.
- abiox 10y agowhat is?
- UpDownLeftRight 10y agoThis is the same Apple that has maintained on their website that their OS is "secure by design" and no additional security steps are needed. See http://cc.bingj.com/cache.aspx?q=%22secure+by+design%22+site%3aapple.com&d=5011627184166823&mkt=en-US&setlang=en-US&w=Xmhyb2VI15fnBjltF7miMeCVnoX2utCg http://cc.bingj.com/cache.aspx?q=%22secure+by+design%22+site...
- zepto 10y agoIt is
- freshyill 10y agoIf there were ever any doubt that Wikileaks is a bad actor, let this be the proof. Regardless of the fact that this is a patched, nearly decade-old exploit, they're trying to make a scene rather than go through ethical channels.
- sneak 10y agoYour assertion that full disclosure is unethical will require some substantiation for us to believe it. I am wary of anyone who claims that giving me access to raw source material is not acting in my best interests.
- cookiecaper 10y agoWe're supposed to take Apple's "nuh-uh" as the smoking gun disproving Wikileaks? That's quite a stretch.
- throwmesomeseo 10y agoKeep in mind, not everyone has the newest shiny iPhone7 in the world. The HN crowd probably is not representing the average iPhone user.
- denzil_correa 10y agoSo, who is the average iPhone user? What percentage of iPhone users could the CIA docs exploit be applied to?
- mattcoles 10y agoI think almost none is the answer seeing as this vulnerability only affects iPhone 3G users.
- jrbaldwin 10y agoI know of three people who use iPhone 3G as their alternate phone when the other battery dies and/or international phone when traveling. The phones don't just go away, they're get passed down.
- kyleblarson 10y agoApple fixed those particular exploits, yes.
- revmoo 10y agoBingo