13 ms·
Remotely Compromising Android and iOS via a bug in Broadcom's WI-FI Chipsets
- shock 9y agoThis is kind of scary :(. How does one ensure that they aren't vulnerable to this bug?
- pedro84 9y agoApple released fixes for both macOS and iOS last week: https://support.apple.com/en-us/HT207923 https://support.apple.com/en-us/HT207923 https://support.apple.com/en-us/HT207922 https://support.apple.com/en-us/HT207922
- excalibur 9y agoDon't use any devices with a Broadcom Wi-Fi chipset.
- merb 9y agowhich basically means don't use any wifi. I think at least 60% of all wi-fi chipsets are broadcom ones.
- cpncrunch 9y agoAnd who's to say another chipset won't have a similar issue?
- gruez 9y agothat seems pretty doable. on phones there's qualcomm chipsets, and on desktops/laptops there's atheros, intel, and realtek (of the vendors i know of).
- simonh 9y agoSo your considered recommendation is for 60% of recently bought device owners globally to all replace their phones, tablets and laptops with devices containing Qualcomm chips, immediately. And this is preferable to a software fix.
- merb 9y agowell on servers/laptops i was always happy to have a intel chip. I once bought a usb stick with intel, which was a complete chunk of garbadge. Well the BCM chips were "mostly" stable, so I didn't had too much problems with them, some chips had problems under linux, but besides that they were ok.
- spudlyo 9y agoIf you have an iPhone make sure you're on iOS 10.3.3. For Macs, you want macOS 10.12.6.
- yborg 9y agoWhy is El Capitan not getting an update? It's still on support.
- culturestate 9y agoThis is the relevant security update for El Cap: https://support.apple.com/kb/DL1932?viewlocale=en_US&locale=en_US https://support.apple.com/kb/DL1932?viewlocale=en_US&locale=...
- ben1040 9y agoIf your Android OEM has pushed the July 2017 security update to your device, you're patched. https://source.android.com/security/bulletin/2017-07-01#broadcom-components https://source.android.com/security/bulletin/2017-07-01#broa...
- yodon 9y agoOut of curiosity, what fraction of Android OEMs push these security updates promptly (or equivalently what fraction of Android phones receive these kind of updates regularly)?
- ben1040 9y agoThis page has a table of OEMs/devices that, as of the end of May, were fewer than 60 days behind on patches. https://android-developers.googleblog.com/2017/06/2017-android-security-rewards.html https://android-developers.googleblog.com/2017/06/2017-andro... To me, the takeaway from this is that unless you are using a "flagship" device, or one sold directly by Google, you're probably not getting updates in a timely manner.
- thrownblown 9y agoManufacturer: Device(S) BlackBerry: PRIV Fujitsu: F-01J General Mobile: GM5 Plus d, GM5 Plus, General Mobile 4G Dual, General Mobile 4G Gionee A1 Google: Pixel XL, Pixel, Nexus 6P, Nexus 6, Nexus 5X, Nexus 9 LGE: LG G6, V20, Stylo 2 V, GPAD 7.0 LTE Motorola: Moto Z, Moto Z Droid Oppo: CPH1613, CPH1605 Samsung: Galaxy S8+, Galaxy S8, Galaxy S7, Galaxy S7 Edge, Galaxy S7 Active, Galaxy S6 Active, Galaxy S5 Dual SIM, Galaxy C9 Pro, Galaxy C7, Galaxy J7, Galaxy On7 Pro, Galaxy J2, Galaxy A8, Galaxy Tab S2 9.7 Sharp: Android One S1, 507SH Sony: Xperia XA1, Xperia X Vivo: Vivo 1609, Vivo 1601, Vivo Y55
- feikname 9y agoJust a disclaimer, this isn't the complete list of devices that received the July 2017 update. I, for one, received it for my Moto G4 Play in Brazil. This list shows the models with a MAJORITY OF DEPLOYED DEVICES running a security update from the last two months.
- deleted 9y ago[deleted]
- 0xdeadbeefbabe 9y agoIt is pretty hard to ensure you are vulnerable.
- cududa 9y agoTurn off your wifi
- yifanlu 9y agoThe article mentions > Broadpwn is a fully remote attack against Broadcom’s BCM43xx family of WiFi chipsets, which allows for code execution on the main application processor in both Android and iOS. But it doesn't go into any details on this privilege escalation actually works for iOS and more specifically that it doesn't require additional exploits. Can anyone explain this in more detail? If this actually allows code execution on iOS application processor, that means we have a jailbreak right?
- revelation 9y agoThe block diagram shows a PCIE connection to the application processor, which enables DMA. Most modern systems have a MMU to prevent the peripheral from DMAing to memory areas not specifically reserved for it, but given (certainly Android) systems run oldschool kernels hacked together by the last kind of crowd you want working on them it's probably not enabled or setup correctly. The other more obvious privilege escalation is that there is still a kernel driver on the application processor talking to the chipset. There is per se no reason to distrust data coming from the chipset, so these often aren't written as defensive as they should be and could contain trivially exploitable assumptions on what the chipset will send and do.
- yifanlu 9y ago> Most modern systems have a MMU to prevent the peripheral from DMAing to memory areas not specifically reserved for it, but given (certainly Android) systems run oldschool kernels hacked together by the last kind of crowd you want working on them it's probably not enabled or setup correctly. I'm not sure it's fair to assume iOS IOMMU isn't set up properly just because that's the case on many (most?) android phones. According to the author, most android phones don't even have KASLR which iOS had since iOS6. I would assume IOMMU exists and is working properly unless someone has evidence otherwise (quick google shows very little information on iOS + IOMMU). If a DMA attack is indeed successful on iOS devices, I think that would be substantial enough to write about. > The other more obvious privilege escalation is that there is still a kernel driver on the application processor talking to the chipset. I would consider that a separate exploit--but even then you still need a KASLR bypass (another exploit?) at the very least to gain control. > so these often aren't written as defensive as they should be On the contrary, the market rate for a iOS jailbreak chain is upwards $1 million USD so I'd be surprised if a single exploit gives you full system control.
- Animats 9y agoC's lack of array size info strikes again: memcpy(current_wmm_ie, ie->data, ie->len); where "ie" points to data obtained from the net.
- revelation 9y agoC's lack of arrays strikes again. They are essentially syntactic sugar.
- frlnBorg 9y agoWhat do you mean by C not having arrays?
- JustSomeNobody 9y agoProbably referring to the fact that they are simply pointers into contiguous memory.
- astrange 9y agoC doesn't have "memory" in the standard. They're pointers into a contiguous object, but anything before a[-1] or after a[sizeof(a)-1] is undefined aka it actually doesn't exist.
- DiThi 9y ago`sizeof(a)` only gives the size of the array when the size is specified at compile time. Either you accept e.g. `int[16]` as a type, or you pass a pointer (for which `sizeof` just returns `sizeof(intptr_t)`)
- nemetroid 9y agoThat's not quite right. Arrays always have a knowable length, and sizeof will give a correct result for variable length arrays as well. However, arrays that are passed as arguments to functions decay into raw pointers, at which point you lose information about its length.
- mangix 9y agoI do wonder why most mobile chips are broadcom. There's decent competition from Qualcomm atheros and mediatek.
- mmagin 9y agoDunno if it's still true, but Qualcomm/atheros was more expensive and mediatek was cheap crap.
- thomastjeffery 9y agoWhy does Broadcom insist on proprietary drivers? How could it possibly be detrimental for Broadcom to have free software drivers? This article is a poignant example that it is detrimental for them to continue to keep their drivers proprietary.
- whowouldathunk 9y agoThe drivers are probably pretty complicated and thus valuable IP.
- thomastjeffery 9y agoI don't buy that. Every wifi chipset has working drivers; therefore there is little to no value in Broadcom's driver as "IP". Contrast that to the value of having a free driver that can receive security patches from anyone at any time.
- johncolanduoni 9y agoEvery GPU has working drivers, but optimizations within them can make huge differences in performance on the same hardware.
- thomastjeffery 9y agoComparing a Wifi chipset to a video card is like comparing a bicycle to a sports car.
- monocasa 9y agoThe driver 'optimizations' in GPUs tend to boil down to hand written replacements for unoptimal/broken shaders and API call sequences on a per application basis. I expect a network card to not 'interpret' my traffic in a similar way.
- vvanders 9y ago
- amazingman 9y agoI already updated my phone. Is the iOS update that patches this available over a cell network? If not, as is usually the case, isn't that Not Good?
- emptybits 9y ago10.3.3? "This update requires a Wi-Fi network connection to download." Frustrating. I read this update may be 80-100 MB. Apple, please let me use my mobile data as I see fit. (And a security patch is certainly a worthy use!)
- eisa01 9y agoAgree, this is irresponsible to not let us update over cellular I'm currently on vacation, which means that most of the wifi hotspots I'm connecting to are public. That's a big security risk in itself
- thesmok 9y agoiOS security update files are crypto signed, so it's safe to download them on public WiFi.
- fragmede 9y agoNot in this case. If your wifi chipset is known to be compromised, and there is a remote exploit available, as in this case, then merely connecting with wifi to an evil hotspot is enough to compromise a device. Once a device's been compromised, crypto signatures on update files won't protect you, as the signature checking itself can no longer be trusted.
- nyolfen 9y agoi've been hearing people complain about the seriousness of this attack vector for years. i'd be surprised if there weren't intelligence agencies that have utilized it already.
- anon4728 9y agoProprietary drivers, firmware blobs and ASICs are a national security threat. Without open code reviews, auditing and functional verification it's impossible to trust there are both a minimum of exploitable bugs and/or backdoors in a given software-hardware stack. This may require some sort of confidentiality rubric but there's no shortcut to getting around this vital need.
- cpach 9y agoIf anyone wonders, this was patched in iOS 10.3.3 https://threatpost.com/apple-patches-broadpwn-bug-in-ios-10-3-3/126955/ https://threatpost.com/apple-patches-broadpwn-bug-in-ios-10-...
- rca 9y agohttp://boosterok.com/blog/broadpwn/ http://boosterok.com/blog/broadpwn/ shows a simple check using hostapd to see if a device is vulnerable
- samat 9y agoCould please someone explain, 1) if firmware is stored on a Wifi chip or rather loaded during the boot process? 2) Do apple/google have binary image from Broadcom or rather source code? It is quite interesting how this patch production/delivery process works.
- dewyatt 9y ago> 1) if firmware is stored on a Wifi chip or rather loaded during the boot process? Typically it's loaded during the boot process. On Linux, see the binary blobs in /usr/lib/firmware or: https://git.kernel.org/pub/scm/linux/kernel/git/firmware/linux-firmware.git https://git.kernel.org/pub/scm/linux/kernel/git/firmware/lin... Source: I did some work with some broadcom (wired) firmware years ago and found it to be pretty unpleasant. http://ipxe.org/gsoc/bnx2 http://ipxe.org/gsoc/bnx2 and https://github.com/dewyatt/bnx2-fw-utils https://github.com/dewyatt/bnx2-fw-utils
- azernik 9y agoI worked with both QCA and Broadcom wireless, and can confirm. Generally a version of the driver is compatible with only a specific version of the firmware; the system manufacturer gets the driver source and a firmware binary as a package.
- swerner 9y agoFortunately, this is being addressed in software updates. Unfortunately, people who own older devices are left with the vulnerability forever. The iPhone 4S alone sold ~60 million units (according to Wikipedia) and did not (and most likely will not) receive any updates.
- yojex 9y agoWhere can you learn if your device has been patched? I have an iPhone 5S. EDIT: From another comment [0], unfortunately if you've been holding out on updates like I have you'll have to upgrade to 10.3.3. [0] https://support.apple.com/en-us/HT207923 https://support.apple.com/en-us/HT207923
- IshKebab 9y agoHow long until someone unleashes this? There are going to be millions of vulnerable Android phones for at least a couple of years to come. Surely it will happen.
- ManyEthers 9y agoApple pushed out an update to ALL affected iOS devices last week. Google provided patch for nexus and pixel devices. Vast majority of android devices (think close to 99%) are still vulnerable. Given how limited pixel availability is and how quickly support is dropped compared to Apple, the logical recommendation is to drop android and switch to iPhones immediately. Bring the downvotes but at least provide logical discussion.