4 ms·
What's really cool is that they released all the code they used to create the attacks. https://github.com/googleprojectzero/iOS-messaging-tools https://github.
by zabuni 7y ago
What's really cool is that they released all the code they used to create the attacks.
https://github.com/googleprojectzero/iOS-messaging-tools https://github.com/googleprojectzero/iOS-messaging-tools
Just went to the talk. TL;DR: iMessage uses old serialization libraries, they are terrible.
- jhatax 7y agoThe final few paragraphs touch upon how expansive the attack surface can be due to this serialization code. So, yes the libraries are terrible. Asking the HN audience: Is there a set of design principles that the iMessage team can follow to make these more resilient to such attacks while retaining their usability? As a non-Apple employee whose globally dispersed family relies on iMessage to stay in touch, I have a vested interest in the security of my family’s iPhones. I know it’s rare for Apple employees to comment, but it would be great if someone from Apple can comment on whether these libraries are being re-architected in some way. This will cut through any FUD that arises from this disclosure / discussion.