4 ms·
I wonder how much people are able to publish about the device. I'd expect not much, but it'd be nice to be able to compare a iPhone that was completely unlocked
by jedieaston 6y ago
I wonder how much people are able to publish about the device. I'd expect not much, but it'd be nice to be able to compare a iPhone that was completely unlocked (at least, to whatever that means for Apple) with whatever security they put on the ARM Macs which are supposed to be "open for hobbyists". I'd expect that the ARM Macs have much of the same security stack (by default) that iOS devices have given what they said in the WWDC talks, but maybe that's not the case.
Also, if you found an exploit on a research iPhone because you made use of entitlements that were Apple-only, I wonder if that'd be worth anything bounty wise. Nobody can/should be able to write an that'll get through App Store checks if they asked for PLZ_NO_SANDBOX_ILL_BE_GOOD or something (at least, that's what I thought before the whole Snapchat system call thing happened). But hypothetically the App Store review process is vulnerable to a bad actor inside Apple pushing an update to a big app that included malware, so I'd think that private entitlements shouldn't be available at all to binaries that didn't ship with the device/in a system update (unless some kind of hobbyist flag was flipped by the consumer). So I'd say that would be worth something, even if smaller than a more interesting exploit.
- saagarjha 6y agoWe’ll see how the shipping ARM Macs are “fused” when they come out, but my guess is that they will be more locked down than these devices: their OS will be more permissive but you will not have meaningful kernel debugging. > Nobody can/should be able to write an that'll get through App Store checks if they asked for PLZ_NO_SANDBOX_ILL_BE_GOOD or something (at least, that's what I thought before the whole Snapchat system call thing happened). Snapchat (on iOS at least) is still subject to the app sandbox, no app has on iOS has been granted an exception there to my knowledge. On macOS there are apps that are “grandfathered in” to not require the sandbox on the App Store, but new apps are supposed to have it. Due to the way the dynamic linker works, until recently it was possible to upload an app that could bypass the sandbox, but Apple has said they have fixed this. Some apps do have an exception to this as well, as the broad way they fixed one of the issues broke legitimate functionality in library loading. You can find those hardcoded in AMFI.kext, theoretically they could turn off the sandbox for themselves if they wanted.
- mrpippy 6y ago> you will not have meaningful kernel debugging Given that kext development is still supported (although highly discouraged), won’t they have to support the same level of kernel debugging as usual? > On macOS there are apps that are “grandfathered in” to not require the sandbox on the App Store Can you name any of these apps? Apple’s own apps don’t have to be sandboxed (like Xcode or macOS installers), but I don’t know of anything else that gets an exception. Some apps like Office get special “holes” out of the sandbox (in the form of additional SBPL), but fundamentally they’re still sandboxed.
- saagarjha 6y ago> Given that kext development is still supported (although highly discouraged), won’t they have to support the same level of kernel debugging as usual? They just need to support loading kernel extensions. As watchOS has shown, developers will figure out a way to get their thing working on your device even if your make debugging extremely painful. (Apple's current silicon prevents debugging entirely because the kernel is prevented from being patched in hardware.) > Can you name any of these apps? Sure. If your app's bundle ID matches one of com.aspyr.civ6.appstore com.aspyr.civ6.appstore.Civ6MetalExe com.aspyr.civ6.appstore.Civ6Exe com.tencent.WeWorkMac com.tencent.WeWork-Helper com.igeekinc.DriveGenius3LEJ com.igeekinc.DriveGenius3LEJ.DriveGenius com.igeekinc.DriveGenius3LEJ.dgdefrag com.igeekinc.DriveGenius3LEJ.dgse com.igeekinc.DriveGenius3LEJ.dgprobe com.prosofteng.DGLEAgent com.prosofteng.DriveGeniusLE com.prosofteng.DriveGenius.Locum com.prosofteng.DriveGenius.Duplicate com.prosofteng.DriveGenius.Benchtest com.prosofteng.DriveGenius.FSTools com.prosofteng.DriveGenius.Scan com.prosofteng.DriveGenius.Probe com.prosofteng.DriveGenius.SecureErase com.prosofteng.DriveGenius.Defrag dyld interposing is enabled for your app even if it comes from the App Store, opening the door for subverting the mechanism for applying the sandbox.
- Wowfunhappy 6y agoHuh, I wonder why those got exceptions. You said they were "Grandfathered in", but Civ 6 at least is recent.
- bluesign 6y ago> But hypothetically the App Store review process is vulnerable to a bad actor inside Apple pushing an update to a big app that included malware. I don’t think this is technically possible.