12 ms·
Stealing your SMS messages with iOS 0day
- gok 6y ago"reading the SMS database of an iOS device to which you have full unlocked physical access"
- shakna 6y agoThere's nothing technical about this that couldn't be exploited by any published app, so far as I can see. It doesn't look like you need physical access.
- AdamJacobMuller 6y agoI cannot be done by an app published via the app store.
- oxguy3 6y agoThe point is that someone could slip this code into an innocuous-looking app and trick an unsuspecting user into installing it.
- formercoder 6y agoBut not a security conscious user who knows once the USB cable is plugged in the device is compromised.
- radicaldreamer 6y agoThere are probably apps out there exploiting this already since this seems to have been known about for a long time and only recently patched.
- verandaguy 6y agoMost security-conscious users do not assume this. Newer iOS versions ask for credentials (and all recent smartphones that I've used ask for credential-less permission) before transferring data over USB.
- deleted 6y ago[deleted]
- saagarjha 6y agoInstalling an app even through a cable requires clicking through permissions.
- AdamJacobMuller 6y agoIt doesn't work via the App store, apps which require you to bypass the app store are not innocuous.
- swiley 6y agoish requires bypassing the App Store and is one of the only ways to run quite a lot of pretty basic everyday software on iOS.
- trevyn 6y agoFWIW, I believe that all TestFlight app releases also undergo the automated portion of the App Store approval process, which would be able to catch entitlements. If you're installing from source, that's another thing.
- saagarjha 6y agoCorrect. This is why iSH cannot dynamically generate code like say UTM can and must use software emulation via a threaded interpreter.
- bzb3 6y agoYeah, a Linux shell is not what I would call "basic everyday software" that I need to run in my phone.
- swiley 6y agoI need ssh and git for a lot of everyday stuff personally. Also a decent text editor shouldn’t be considered unusual software.
- jackjeff 6y agoIt would have worked and passed through the App checks. It’s not like the App is using private APIs. Now that Apple is aware of this class of bug, they may add automated checks to the plist files containing a super strict XML parser.
- tinus_hn 6y agoLike the ‘zeroday vulnerability’ of users pasting commands into a prompt.
- jtchang 6y agoOf course it would be XML. XML is hell to parse. In fact I bet hell is trying to write XSLT for the rest of eternity.
- plasma 6y agoLooks like its actually just a plist/entitlements request in the app asking for access to do something and being allowed. I'm suspicious if this works in App Store apps though, from memory Apple checks what permissions the app is requesting as part of the submission process.
- kennywinker 6y agoDefinitely wouldn't pass the first validation step when you upload a binary to app store connect
- klodolph 6y agoWhat? XML is super easy to parse. If you think XML is hard to parse, maybe you're trying to do it with a DOM interface, or wasting a bunch of time manually shuffling data around. The XML 1.0 spec is super short, once you ignore DTD stuff and things like entity references. In this case it's just a plist, which makes things even easier.
- saagarjha 6y agoAnd yet Apple has a handful of parsers which all parse it differently…
- klodolph 6y agoCan you elaborate on that? I know it's really in fashion to hate on XML here, I just want to understand what people's complaints are. Having written parsers for JSON, YAML, and XML at various points, I can tell you that XML was not much more complicated than JSON. It's got a good, clean spec and not too many rules.
- TedDoesntTalk 6y agoAll it's doing is POSTing the contents of /private/var/mobile/Library/SMS/sms.db to a server. You can't get an app into the app store that haz the required permissions to access that file. Solution: Dont install apps outside the app store.
- aeternum 6y agoThe permission is within a XML comment so how sure are you that this would be caught as part of app store review? Since apps now auto-update each night any one of your apps could theoretically add this code tonight couldn't they?
- mike_d 6y agoApple knows how entitlements work and scan every release you try to upload for distribution. The app bundle is signed with an Apple signing key when it goes live, so you can't just randomly change the file once it is on the device.
- neximo64 6y agoApple tracks every time you change it and manually reviews it. In even more sophisticated means after what Uber did.
- saagarjha 6y agoNote that Uber was given that entitlement by Apple. It was explicitly granted an exception to use a private entitlement (which is in of itself unusual) and then submit such an app to the App Store.
- kennywinker 6y agoit pains me that there is no way to legitimately export your message history for archival. I know it's backed up with icloud and local backups, but I would love the ability to view message history, run analysis of my convos, and "archive" convos to date (i.e. I want to be able to go back and read the convo, but I don't want to have the 13.4TB of gifs on my phone anymore) So, I may just replicate this "0day" and run it on myself... will be fixed soon, but at least I'd have a single snapshot
- kalleboo 6y agoYou can use third-party software like iMazing or PhoneView to extract the message history
- joshspankit 6y agoI personally use iMazing for this, it’s pretty great
- deleted 6y ago[deleted]
- asadhaider 6y agoLooks pretty cool, didn't know about iMazing. The new iPhone/Music app in Catalina is a pain to use and has lost functionality. Thanks for the recommendation!
- AdamJacobMuller 6y agoif you enable iCloud sync you can just copy the database (SQLite) off your mac. ~/Library/Messages/
- dodobirdlord 6y agoIt's actually just SQLite? No weird proprietary format or anything? That's both surprising and awesome to hear.
- captn3m0 6y agoThe exploit author's blog post on why the extra entitlements work (and how Apple fixed it) makes for a more interesting reading: https://siguza.github.io/psychicpaper/ https://siguza.github.io/psychicpaper/
- sinuhe69 6y agoAn interesting read. If the problem is apps entitlements, I wonder why Apple didn’t develop an AI to flag apps with suspicious entitlements? For a parser, it might be a problem with complex nested tags, but for human reviewers I argue it’s much easier to spot constructed entitlements. And Apple can always require the developers to rewrite the entitlements falls needed. Automatic sanitizing entitlements would be helpful, too because they are not designed for being complex.
- ksml 6y agoI think a much simpler solution would be to just use one consistent XML parser. Throwing AI at things is not a good general solution. Black-box AI models may work in the common case, but they have edge cases with bizarre behaviors that are poorly understood. You'd end up with a result likely worse than this.
- madeofpalk 6y ago> Apple didn’t develop an AI to flag apps with suspicious entitlements I think just a simple if statement would work better than an "AI".
- willstrafach 6y agoThey would be caught if this was submitted to the App Store. This applies to self-signed apps by those with a developer certificate.
- sinuhe69 6y agoI understand the attitude of some saying Apple "should implement the absolute correct parser". But such way of thinking is not practical. The question is not whether there is an "absolute correct parser" but much more when can we have a relative correct and safe parser. The way Apple had to wrestle with 4 different implementations of the same parser function shows that the issue is not trivial. Other XML parsers may have the same problem, too, albeit uncovered yet. Using AI to flag down unusual entitlements and other potential hacks in the future is much more practical and future-proof than race for the absolute correct guard. The AI should not replace a correct implementation but rather augment it as an additionl security tool. I'm certain many organization would go this way in the near future (if they not already did!)
- xvector 6y agoDoesn't iOS ask you for permissions when granting data to an app? This seems completely bizarre to me. The App Store verification process does not seem like a reasonable single line of defense. If applications can just get data from the rest of your phone without prompting the user then something is seriously broken here.
- saagarjha 6y agoNo, this is based on the Psychic Paper “exploit” that was described a few days ago that allowed developers to sign their apps with extra entitlements, including ones that would allow for accessing files outside of the normal application sandbox. (To be clear: there is no app, other than Messages, that should ever be able to access your messages. Such an app is not allowed on the App Store.)
- xvector 6y agoAh, thanks.
- tandav 6y agoGood example of using `http.server` in python
- rock_artist 6y agoI'm actually eager to use this and write an app to finally migrate all my messages from Android stuck in an xml since I didn't use Apple's migration tool initially.
- mkchoi212 6y agoAnother reason why you shouldn’t make custom parsers, even if you are a multi-billion dollar company like Apple. Trust in the power of open source!