4 ms·
Exploit Market ‘Flooded’ with iOS Vulnerabilities
- mlacks 7y agoDoes this mean that iOS is more or less just as secure/insecure as Android? I’m not much of a security expert but I continue using iOS under the assumption it was ‘safer’ than android
- verroq 7y agoIf ios is more secure, then there are less exploits. However higher payouts incentivise more researchers to find bugs, leading to more exploits. The free market in action.
- cjbprime 7y agoI'm not expert, but my sense is that Android is open source (easier to find bugs) but memory safe (Java), whereas iOS is closed source but memory unsafe, and tooling is recently at the point where it's feasible to find many exploits despite not having source access, so the lack of memory safety is becoming more and more untenable over time.
- dev_dull 7y agoAccording to the article the flood of exploits has more to do with iMessage and safari attack surface and not necessarily the OS.
- cjbprime 7y agoThat's what I was talking about too. The kernels of both have source available, Linux vs xnu. But the userland of Android is mostly memory-safe Java, and the userland of iOS (e.g. iMessage) is mostly memory-unsafe ObjC. The kind of marshalling and memory management exploits described in the p0 posts are very unlikely to happen on the Android side.
- 0x0 7y agoLots of android system/userland libraries are written in C or C++. Stagefright is but one example of a high impact vulnerability reachable from SMS/MMS on Android.
- 693471 7y agoAndroid is a Linux kernel written in C, so it's memory unsafe there. The apps are in a Java-derivative, so they're memory safe. Chrome browser is not written in this language, so it's memory unsafe. iOS is a Mach+XNU kernel written in C, so it's memory unsafe there. The apps are in Swift, so they're memory safe. Safari/Webkit is not written in this language, so it's memory unsafe. The only real difference in security here is that Apple has had better sandboxing and security (hardware) implementations.
- panpanna 7y agoAndroid has better sandboxing for apps (Java virtual machine + process isolation + user isolation + se-linux + containers & virtualization in some cases). But the permission system is so badly designed it's almost wide open. The hardware you are thinking of is mainly used for secure storage and crypto.
- on_and_off 7y agoWhat's wrong with the permission system design ? (agree otherwise on the refutal of GP, but curious about that point)
- panpanna 7y agoOld permissions were too broad. Need a file? Here is a permission to look at ALL files! More restrictive permissions (and a new model where you don't need a permission but user decides what file to access) were added later but it takes time to get developers to change.
- 693471 7y agoAndroid's hardware is extremely fractured with the majority of the devices sold being cheap and missing the good features, including hardware security. Apple's phones are more homogeneous. Certainly a larger percentage of Apple users have a Secure Enclave than Android users do.
- garren 7y agoThe article indicates that it's pretty much six of one and half a dozen of the other. iOS is more of a monoculture compared to Android, so a successful exploit chain against the current version of iOS has the potential to affect quite a few more users. On the other hand, the article states that Android is more fragmented, so a successful chain of exploits will likely affect fewer users. The article hints that "one-click" Android exploit chains are harder than iOS, and so are worth more at the moment. It's interesting to me that a one-click compromise is so valuable given the supply-chain vulnerabilities [0] and ongoing "dodgy-app" issues [1]. Google just dropped a boatload of iOS issues, but they also just took care of nearly 200 issues, some long-standing and some critical in severity, within Android themselves [2]. It seems like declaring one as more secure than the other is more a game of hot-potato than anything. [0] https://krebsonsecurity.com/2019/06/tracing-the-supply-chain-attack-on-android-2/ https://krebsonsecurity.com/2019/06/tracing-the-supply-chain... [1] https://nakedsecurity.sophos.com/2012/07/31/almost-every-android-device-is-compromise/ https://nakedsecurity.sophos.com/2012/07/31/almost-every-and... [2] https://www.forbes.com/sites/daveywinder/2019/08/23/android-10-google-confirms-193-security-vulnerabilities-need-fixing/#d6a94fc616ba https://www.forbes.com/sites/daveywinder/2019/08/23/android-...
- andrewflnr 7y agoExecuting a supply chain attack requires you to be in a pretty privileged position to start with. Most people can't just decide to do one, whereas most anyone can put up a malicious website or app.
- JoachimSchipper 7y agoYou’ve already received sensible answers, but let me add that “Android” pretty much means a Google device here; an Android device that doesn’t get updates, or only after a long delay, is decidedly less secure.
- kerng 7y agoInterestingly, no one has done a deep dive on what Android exploits were hosted on the site that Google discovered and talked about last week with the iOS exploits. Google has been utterly quiet about it, and kept only talking about iOS exploits. Certainly lots of security PR happening and this article is interestingly timed also.
- arkadiyt 7y ago> Interestingly, no one has done a deep dive on what Android exploits were hosted on the site that Google discovered Volexity did [1], although it's not clear if the android exploits were hosted on the same sites that google was referencing. [1]: https://www.volexity.com/blog/2019/09/02/digital-crackdown-large-scale-surveillance-and-exploitation-of-uyghurs/ https://www.volexity.com/blog/2019/09/02/digital-crackdown-l...
- kerng 7y agoThanks for sharing, that's a great resource! This at the grand scheme of things hasn't gotten much attention I think.
- lawnchair_larry 7y agoGoogle did not find any Android exploits.
- kerng 7y agoIt seems very unlikely that the majority system used (especially outside the US), would not be exploited - maybe they try to separate and say not the exact same webpage hosted Android exploits. But I havent seen any official statement from Project Zero that they have not found Android exploits as part of this campaign. Not even one that says, not the same page hosted Android exploits. If you have a link, please share. All I saw was this below. It says Google did not comment on the question officially: https://www.forbes.com/sites/thomasbrewster/2019/09/01/iphone-hackers-caught-by-google-also-targeted-android-and-microsoft-windows-say-sources/#540aff8b4adf https://www.forbes.com/sites/thomasbrewster/2019/09/01/iphon...
- berbec 7y agoOriginal source article: https://www.vice.com/en_ca/article/mbmgqp/this-is-worst-year-for-iphone-security-yet-2019 https://www.vice.com/en_ca/article/mbmgqp/this-is-worst-year...