10 ms·
Exploiting the Wi-Fi Stack on Apple Devices
- pwinnski 9y agoThis post is a thing of beauty. The details of how this works are amazing.
- caf 9y agoYes, I particularly liked the detail of using the KTRR registers to defeat KASLR.
- cee_el1234 9y agoTruly. This. Is. Art.
- js2 9y agoI'd love to know how many hours were needed to develop this exploit from start to finish, and how many dead ends the researcher ran into along the way. Just writing the blog post and generating all the images for it must've taken many days.
- xtacy 9y agoFrom the project-zero bug (https://bugs.chromium.org/p/project-zero/issues/detail?id=1317#c3 https://bugs.chromium.org/p/project-zero/issues/detail?id=13...), it looks like the first discussion on the issue dates back to July 3, with a working exploit posted just yesterday.
- tr1ck5t3r 9y agoLets wait and see if a PC version of this exploit shows up considering the extensive use of PCIe on desktops.
- bitexploder 9y agoI have followed iOS JB for years and keep up with exploit dev and mitigation/defense. The usage of source code and avoiding deep assembly documenting helped a lot. You are still looking at several man days of deep work on understanding the driver and stack. KASLR was the only real mitigation to bypass. That could have been a difficult part worth it's own discussion. Bypassing ASLR typically requires an info leak. I think 3-4 weeks of one person's effort is a good guess. +/- 1wk depending.
- KGIII 9y agoIf others don't know, the K is for kernel. I had guessed that it was, but decided to look it up. I figure this may save others some time. It looks pretty neat, conceptually. It loads the kernel into a random location in memory on boot. I haven't looked into how random it is, but it's a good idea.
- rhexs 9y agoGoodness, it takes only several days to reverse engineer a driver and stack now? Wow. I know the project zero guys are good, but damn.
- PascLeRasc 9y agoIs the source for this code only Apple's open-source publishings?
- mankash666 9y agoWonder if something like this was used to get into the San Bernardino shooter's phone by the FBI
- NegativeLatency 9y agoThe shooter had an iPhone 5C[1], which according to the article uses USB, so the DMA PCIe exploit detailed here wouldn't work for it. Not saying it wasn't something similar, but it could have been pretty different. 1. https://en.wikipedia.org/wiki/FBI–Apple_encryption_dispute https://en.wikipedia.org/wiki/FBI–Apple_encryption_dispute
- DiabloD3 9y agoIt has a Lightning port, so maybe a different at-the-time undisclosed DMA exploit?
- lawnchair_larry 9y agoMost definitely not.
- Moter8 9y agoCellebrite got into that phone. A presenter from the firm told us so. Apparently 300 devs work fulltime on mobile devices in Isreal to develop iOS/Android exploits, mostly for Law Enforcement or despots. He talked quite a bit about what you can get off the devices, but not much on the how to get into there. Apparently Android-encrypted phones are the safest though. They didn't have an exploit for them 2 months ago.
- e12e 9y ago> Apparently Android-encrypted phones are the safest though. That's odd. I guess the implication is that iPhone hsm is broken (or they can get past a short pin via an exploit that allows brute forcing - typically an hsm should (be possible to configure to) permanently destroy the keys after N attempts). I suppose it demonstrates that secure encryption requires the user to memorise something equivalent of 96-128 bits of entropy, that will be used for key derivation. [ed: i suppose it's conceivable that there's an attack against how the iPhone generates symmetric encryption keys, but I would guess that's less likely]
- lukeh 9y agoThis is an incredible combination of both reverse engineering skill and communication ability. So good!
- benzinschleuder 9y agoAmazing. Did they need to jailbreak or physically open the phone to find all this stuff? They talk about reversing binary images and using their "Legilimency" toolkit; I wonder if a vanilla phone was enough to research all this and propagate through Wi-Fi.
- 0x0 9y agoI'm guessing there must be other jailbreaks involved to be able to observe and experiment on the ios kernel side of things while developing the wifi chip exploit; going in all blind from the wifi side only sounds impossible. The question now is, are they sitting on 0day jailbreaks for current iOS versions or did they have to do all the tests on legacy iOS versions?
- xoa 9y agoIt looks like that setup work for their research environment was all covered in part 1 (all the parts are really interesting and worth a read if anyone hasn't already incidentally). Specifically, the reason they mention at the end of part 3 that >The exploit has been tested against the iPhone 7 running iOS 10.2 (14C92). was because iOS 10.2 has a known kernel exploit developed by Ian Beer [1], and they used that as part of the basis of subsequent research. Presumably they either found some iPhones still running 10.2 (which stopped being signed a long while back) or like many well funded researches just keep a set of different iPhones loaded with major iOS versions so they're ready to go for research if an exploit is found after signing stops (dedicated jailbreakers sometimes to the same thing if they can). And of course security patches themselves are handy for reverse engineering old exploits from whatever bugs Apple fixes. In part one read under "Kernel Memory Analysis Framework". ---- 1: https://googleprojectzero.blogspot.co.uk/2017/04/exception-oriented-exploitation-on-ios.html https://googleprojectzero.blogspot.co.uk/2017/04/exception-o...
- rasz 9y agomost likely this research is a result of Project Zero playing with PCIe interception/injection hardware toolset
- israrkhan 9y agoThese guys are amazing. Excellent level of details.
- walterbell 9y agoWhy did Apple make it harder to turn off the WiFi radio in iOS11?
- mikeash 9y agoBecause people would turn off WiFi from Control Center and then forget about it, resulting in expensive cellular overages. (This cost me about $30, for example.) I think the pertinent question is: why didn't they make the change more clear?
- deftturtle 9y agoApple thinks for its users in all the wrong ways.
- givinguflac 9y agoSeveral people in my family have had overage issues by forgetting about WiFi being off. They are certainly not technically inclined.
- KozmoNau7 9y agoGet them a subscription with an adequate data plan, then?
- walterbell 9y agoIf you want to avoid cellular charges, shouldn't you be turning off cellular?
- mikeash 9y agoThe problematic scenario goes like this: 1. You're in a coffee shop. The WiFi sucks today. You turn off WiFi so you can use your cellular connection instead. 2. Many hours later, you go home, having forgotten about #1. 3. You binge-watch the entirety of Doctor Who streaming on your phone, not realizing the phone is still using cellular. 4. Large bill from your provider.
- senatorobama 9y agoWhen will Apple dump Broadcom?
- ksec 9y agoBut Why? Not until Apple make their own WiFi Chip ( Which they are doing with W1 in Airpod and W2 in Apple Watch ) But until then Broadcom still has the best WiFi Chip. Qualcomm Atheros is a big no no.
- e12e 9y ago> Qualcomm Atheros is a big no no Sarcasm? If not, care to elaborate?
- fulafel 9y agoBroadcom already dumped Broadcom wifi chips, Cypress bought them.
- forapurpose 9y agoWhat is the story with Project Zero? What is the strategy here? If you think about it, pointing out flaws in competitors' products is actually unusual for businesses, especially large ones. It raises questions of motives, of trust (are they drumming up business in a negative way? Can I trust what company X says about their chief rival? Are they exaggerating or spinning it?), and it looks unsavory: You don't win in the court of public opinion by insulting the competition, right or wrong; you just look like a jerk. Also, there's a liability risk, which adds legal costs to otherwise free blog posts - 'can't you guys just find Linux bugs?'. On the other hand, it might improve security for everyone if Apple and Google started competing to publicize each other's flaws. :) (But I'd bet the noise of accusations and counter-accusations of errors in analysis, misleading statements, etc. would soon drown out the technical info, and then the lawsuits would begin ...).
- burnte 9y agoQUalcomm and Linux aren't competetitors, and while MS and Apple are, the PZ blog has talked about them all. It's a very technical security blog.
- late2part 9y agoI submit for your consideration that: 1. The Google Project Zero guys are idealists and motivated by increasing security. 2. Google security is taken far more seriously than most other companies 3. If Apple and Google competed in publicizing exploits, Google would win [is winning].
- advisedwang 9y agoIf everyone competed in publicizing exploits and like project zero coordinates disclosure with vendors, then _consumers_ win!
- veeti 9y agoProject Zero doesn't discriminate: https://googleprojectzero.blogspot.fi/2017/07/trust-issues-exploiting-trustzone-tees.html https://googleprojectzero.blogspot.fi/2017/07/trust-issues-e... https://googleprojectzero.blogspot.fi/2015/09/stagefrightened.html https://googleprojectzero.blogspot.fi/2015/09/stagefrightene... https://bugs.chromium.org/p/project-zero/issues/list?can=1&q=android&colspec=ID+Type+Status+Priority+Milestone+Owner+Summary&cells=ids https://bugs.chromium.org/p/project-zero/issues/list?can=1&q...
- conchy 9y agoSkimming through this makes me feel even more comfortable using my iPhone ... look how smart you need to be to exploit it!