6 ms·
I’m wondering about the economics of this release. I don’t know if Apple has any bug bounty program and whether it would apply here, but I’m pretty sure someone
by Ecco 7y ago
I’m wondering about the economics of this release. I don’t know if Apple has any bug bounty program and whether it would apply here, but I’m pretty sure someone would have paid a lot of money for this.
Hence my question: why make it public? What’s the backstory?
- matwood 7y agoSince it’s already fixed in the Xs and newer iPhones, I’m not sure Apple would have considered it a new exploit worthy of a payout.
- bootlooped 7y agoCellebrite might pay for it. Unless they already knew about it.
- tinus_hn 7y agoIt doesn’t really provide anything useful for Cellebrite and it only works on older devices.
- deleted 7y ago[deleted]
- bredren 7y agoiPhone X is barely 2 years old. It works on the vast majority of iPhones in use today. For those it allows complete data extraction except the Secure Enclave, correct? I suspect this would have been valuable.
- varenc 7y agoIf you have a passcode, all of your data is encrypted with keys stored in the Secure Enclave. So this alone won't let you dump the contents of a phone. (But it's a useful 1st step vulnerability to others)
- tptacek 7y agoEvery iPhone since the 5S has had a SEP, meaning, as this researcher points out, that checkm8 doesn't do much for Cellebrite for those phones.
- bredren 7y agoI would guess this was already known to some intelligence communities. However, as an unknown zero day this would probably have been worth a great deal on the open market. It may have already been sold a few times. And if so, perhaps the author was turned down by the usual suspects.
- bonestamp2 7y ago> What’s the backstory? From the person/hacker/security researcher (@axi0mX) who discovered it: During iOS 12 betas in summer 2018, Apple patched a critical use-after-free vulnerability in iBoot USB code. This vulnerability can only be triggered over USB and requires physical access. It cannot be exploited remotely. I am sure many researchers have seen that patch. That's how I discovered it. It is likely at least a couple other researchers were able to exploit this vulnerability after discovering the patch. The patch is easy to find, but the vulnerability is not trivial to exploit on most devices. > why make it public? A bootrom exploit for older devices makes iOS better for everyone. Jailbreakers and tweak developers will be able to jailbreak their phones on latest version, and they will not need to stay on older iOS versions waiting for a jailbreak. They will be safer. It will also be better for security researchers interested in Apple's Bug Bounty. They will not need to keep vulnerabilities on hand so that they have access they need for their research. More vulnerabilities might get reported to Apple right away. Source: https://mobile.twitter.com/axi0mX/status/1177542201670168576?s=20 https://mobile.twitter.com/axi0mX/status/1177542201670168576... I wonder if this is this vulnerability that a private company was exploiting for tools they provided to various law enforcement agencies?
- strstr 7y agoWait, why does this make iOS better? This breaks the security guarantees I expected from the phone.
- unnouinceput 7y agoI believe he meant in the future versions of iOS. Once this is public Apple can take the necessary steps to patch this on future products. If it wasn't published, then Apple would, guessing here, leave it as is for future products. My 2 cents.
- TAForObvReasons 7y agoNintendo Switch suffered from a similar problem (usb bootrom exploit https://github.com/Qyriad/fusee-launcher/blob/master/report/fusee_gelee.md https://github.com/Qyriad/fusee-launcher/blob/master/report/...) and the company has been watching the homebrew and other communities closely to patch the entire exploit chain as people discover exploits. No doubt the OS and platform is a lot more secure thanks to the community
- fragmede 7y agoApple has a bug bounty program, though some moves that Apple has made towards the broader security community has some questioning Apple's actual commitment to security, vs just being a clever marketing ploy.
- ufmace 7y agoIt doesn't seem to provide much value to bad actors, since you can't trigger this exploit without physical access and a reboot, can't get any device data without the passcode even if you've done that, and can't persist anything that requires privileged access even with the exploit and the passcode. That makes it moderately useful for hackers and security researchers trying to experiment with devices they own, and most likely of little to no use for any hostile agents, with or without physical device access.