8 ms·
This is one of the most serious and instructive pieces of technical security work we're likely to see this year. In case it hasn't sunk it: - This vulnerabilit
by scarybeast 10y ago
This is one of the most serious and instructive pieces of technical security work we're likely to see this year. In case it hasn't sunk it:
- This vulnerability affects tons of smart phones (iPhone, Nexus, Samsung S*).
- The attack proceeds silently over WiFi -- you wouldn't see any indication you've been nailed.
- Mitigations and protections on WiFi embedded chips are weak.
- The second blog post will show how to fully commandeer the main phone processor by _hopping from the WiFi chip to the host_.
Imagine the havoc you could wreak by walking around a large city downtown, spewing out exploits to anyone who comes into WiFi range :-)
- JumpCrisscross 10y agoDo you know which iPhone versions are affected? Is the problem patchable?
- wolf550e 10y agohttps://support.apple.com/en-us/HT207688 https://support.apple.com/en-us/HT207688
- metricodus 10y agoReleased yesterday. I hadn't gotten any update prompt yet. I'm guessing the (vast?) majority of iOS users haven't upgraded yet.
- JumpCrisscross 10y agoInteresting seeing the Project Zero post mentions Android, not Apple. This deference to Cupertino contrasts with Project Zero's willingness to directly call out Microsoft. (Granted, at the time of this Project Zero post Apple had already released a patch. Microsoft, from my recollection, has a habit of blowing through its 90 days.) [1] https://www.theregister.co.uk/2017/02/27/google_project_zero_reports_flaw_in_ie_edge/ https://www.theregister.co.uk/2017/02/27/google_project_zero...
- kccqzy 10y agoIt does mention that all iPhones since iPhone 4 are vulnerable. Historically, depending on the patch, Apple has also failed to produce a patch within the 90-day deadline.
- devy 10y agoiOS 10.3.1 and above fixed this.
- deleted 10y ago[deleted]
- IshKebab 10y agoI may be reading it wrong, but I think you have to be on the same network as the victim. Still, you're right this is very serious.
- jessaustin 10y agoJust set your SSID to "attwifi" or "xfinitywifi" or similar, and lots of devices will connect automatically.
- icambron 10y agoA worm using this exploit could presumably spread itself as the user hops between networks as part of their routine.
- 24gttghh 10y agoI would agree that TDLS requires a common network over which to broadcast the "Discovery Request" frame.
- kbuck 10y agoThis is the important bit: > However, much more interestingly, we see that the implementation for [vendor-specific] command #4 seems relevant to our current pursuit. First, it does not require the existence of a TDLS connection in order to be processed!
- userbinator 10y agoImagine the havoc you could wreak by walking around a large city downtown, spewing out exploits to anyone who comes into WiFi range :-) An idea that immediately comes to mind is to root everyone's phones, patch the firmware to fix the bugs, and then do nothing more than perhaps leave a short yet profound message: "Thanks to a bug, you now have full control of your device. Was that a bug? You decide. Enjoy responsibly." http://boingboing.net/2012/01/10/lockdown.html http://boingboing.net/2012/01/10/lockdown.html
- overlordalex 10y agoThat reminds me of the worm[1] that would patch the system, and then self-destruct. The problem being that it caused massive load on the servers distributing the patches, as well as restarting users computers without warning. [1]https://en.wikipedia.org/wiki/Welchia https://en.wikipedia.org/wiki/Welchia