20 ms·
An iOS zero-click radio proximity exploit odyssey
- free2OSS 6y agoAre Androids without crapware as insecure as iPhones? I wonder if the daily HN article about Apple failing to be secure is a result of 1 OS, 1 phone. Where as no one is going to put the effort to find an exploit on a phone with 1% market share. Similar question for desktops.
- SulfurHexaFluri 6y agoAndroid has has several critical flaws recently. The ones I can remember are stagefright and dirtyCoW. Stagefright was easily remotely triggerable since it was in a media library that runs when getting sent media. The main difference between the two I have seen is ios users get an update that fixes the issue often after their device has stopped getting feature updates while many android users are on kernels that haven't received an update in the last few years.
- meekrohprocess 6y agoStagefright was ~5 years ago now, though. I remember it, because the company I worked for at the time flipped out and banned all Android phones from their network for over a year. It was fantastic; I got a whole year of not being able to see work emails after I went home, and then they let us opt out of the invasive MDM software that they wanted to put on Android phones to let them access corporate email. All for a bug that my phone wasn't even vulnerable to. By the time I left, I had gone 4 years without ever responding to unexpected evening emails. And now that I know it's possible, I'm never going back! :)
- free2OSS 6y agoWow that dirty cow exploit affects Linux too? My server was at risk... Although none of those are recent like daily security flaws we see on HN.
- SulfurHexaFluri 6y agodirtyCoW was a linux kernel bug. The reason the news and drama was all in the android scene was every desktop/server linux installation would be patched long before a malicious binary would be run on the machine (I think it was patched before the news even broke). Android would be left with the exploit until all of the older devices made it to e-waste. It also meant the rooting efforts would be helped somewhat.
- albntomat0 6y agoHere's a recent walkthrough of a Android messenger exploit, by the same organization as the main link: https://googleprojectzero.blogspot.com/2020/08/exploiting-android-messengers-part-1.html https://googleprojectzero.blogspot.com/2020/08/exploiting-an... And a second: https://googleprojectzero.blogspot.com/2020/09/attacking-qualcomm-adreno-gpu.html https://googleprojectzero.blogspot.com/2020/09/attacking-qua...
- swiley 6y agoThe problem with android is that there is a lot of software in the end OS that's not open source and is delivered as binaries from component manufacturers (the GPU drivers tend to be the worst, they almost universally come from Qualcomm since most phones now use the same series of SoCs.) Once the hardware is released these are rarely updated if ever which means the vulnerabilities aren't patched. The phone manufacturers are just helpless as the community is in this situation. Project treble mitigates this to some degree but the individual software components still can't be updated.
- SulfurHexaFluri 6y agoThe scary thing is that even though this sounds like a monstrous effort to pull off this hack, its not out of reach for large governments. Its basically known as a fact they have loads of these exploits sitting in their toolbox ready to use when they have a enticing enough target. Short of rewriting the whole of iOS in a memory safe language I'm not sure how they could even solve this problem. Assigning a researcher to search for 6 months only to find one bug is financially prohibitive.
- q3k 6y agoThe research would've been much shorter if Apple would actually provide researchers with debug symbols. Or you know, if Apple open sourced their security-critical software. > One of the most time-consuming tasks of this whole project was the painstaking process of reverse engineering the types and meanings of a huge number of the fields in these objects. Each IO80211AWDLPeer object is almost 6KB; that's a lot of potential fields. Having structure layout information would probably have saved months. > Six years ago I had hoped Project Zero would be able to get legitimate access to data sources like this. Six years later and I am still spending months reversing structure layouts and naming variables.
- CharlesW 6y ago> The research would've been much shorter if Apple would actually provide researchers with debug symbols. I believe they're about to do this: https://www.theverge.com/2019/8/8/20756629/apple-iphone-security-research-device-program-vulnerabilities https://www.theverge.com/2019/8/8/20756629/apple-iphone-secu...
- q3k 6y agoThese are just phones that you are officially permitted to attach a root shell and kernel debugger to, like to any other device that's not an iPhone. Researchers have been working around that for years by using private jailbreaks / exploits to get similar levels access, and with checkm8/ktrw you yourself can get similar access to any vulnerable iPhone 7/8/X. No sources or structure layout or symbols, so you're still stuck waddling through megabytes of compiled code to reverse-engineer everything from scratch. It's Apple drumming up absolutely nothing, and from my point of view it's mostly a PR stunt.
- q3k 6y ago> After a day or so of analysis and reversing I realize that yes, this is in fact another exploitable zero-day in AWDL. This is the third, also reachable in the default configuration of iOS. Holy shit.
- martin-adams 6y agoI'd be really curious to know whether the phone can be exploited while on flight mode.
- snazz 6y agoI'm pretty sure that AirDrop works when you turn on Wi-Fi and Bluetooth while using airplane mode.
- SulfurHexaFluri 6y agoI checked and airplane mode seems to disable wifi and 4g but not bluetooth. Airdrop refuses to work without wifi. Not sure to what extent wireless is actually turned off for airplane mode now though.
- snazz 6y agoBoth Wi-Fi and Bluetooth are usually turned off by default when you turn on airplane mode, but you can turn on both without turning off airplane mode, at least in my experience.
- SulfurHexaFluri 6y agoI had the apple pencil connected which may affect that decision.
- cstejerean 6y agoIt does, if you have Bluetooth accessories connected then airplane mode won’t disconnect then, like an Apple Watch or AirPods or a pencil for the iPad
- alexnewman 6y agoThis is a disaster
- brandmeyer 6y ago> What's more, with directional antennas, higher transmission powers and sensitive receivers the range of such attacks can be considerable. I'm reminded of ye olde Gumstix BlueSniper rifle. Back in the early 2000's there were a series of exploits against bluetooth stacks. The standard response by the industry was that they attacks weren't practically exploitable due to the low power of typical bluetooth devices. The BlueSniper was a cantenna + gumstix SBC specifically constructed for the purpose of demonstrating the low cost of the threat.
- Animats 6y agoUnfortunately, it's the same old story. A fairly trivial buffer overflow programming error in C++ code in the kernel parsing untrusted data, exposed to remote attackers. In fact, this entire exploit uses just a single memory corruption vulnerability to compromise the flagship iPhone 11 Pro device. With just this one issue I was able to defeat all the mitigations in order to remotely gain native code execution and kernel memory read and write. Yes, same old buffer C/C++ overflow problem. We have mainstream alternatives now. C#. Go. Rust. It's time to move on.
- colesantiago 6y agoIMO this is huge. Thankfully, Apple is starting to hire Rust developers as well as AWS. The tide is changing, one day we will see some Rust code in iOS/macOS so that these issues are a thing of the past.
- zepto 6y agoIt seems unlikely that they’ll solve the problems in iOS with Rust. It seems much more likely that they will use Swift in some form.
- KMag 6y agoSwift seems an unlikely choice for incrementally replacing portions of kernel code.
- zepto 6y agoIn its current form perhaps this is true. However Chris Lattner and others have expressed the desire to have it be suitable for systems programming. There is reason to believe they will adapt it.
- KMag 6y agoHas Chris specifically mentioned OS kernel programming? As the Golang team have pointed out, there's lots of systems programming going on in userspace, which is what they refer to when they call Golang a systems programming language. That being said, ARC is probably easier to get to work well in-kernel vs. tracing garbage collection. There's a performance cost to all of those reference count updates, but at least the variance is extremely low.
- 0x70run 6y agoA bit OT - how do I work on developing the skill set necessary to find vulnerabilities like these? Should I take some particular courses, or some other “track” of sorts? At the moment, I have an undergraduate in Computer Sciences, and I’d say I’m a fairly OK programmer.
- q3k 6y agoCheck out LiveOverflow on YT. Maybe play some CTFs, but don't do that super seriously, just enough to get you hooked on binary exploitation. They're fun, especially if you find some teammates to cooperate with. And then just, well, practice. A lot of practice. Mostly driven by curiosity about how things work - bugs will then just start to pop up and you are free to investigate whatever piques your interest. The more likely you are to just open up a debugger when a piece of software annoys you and try to binary patch it, the closer you are to being a security researcher :). There's not much books/courses on this, low-level hacking is something that you kind of just learn as you go. But, for instance, if you never touched gdb/lldb, or never looked at assembly code, or never wrote C - you should investigate that first as base skills.
- snazz 6y agoAs for books, The Art of Software Security Assessment is frequently recommended, including by members of Project Zero.
- albntomat0 6y agoI'd recommend CTF'ing a bit stronger than the other commenter. While there can be a distinct gap between the vulnerabilities in ctfs and real world applications, CTFs provide a great means of deliberate practice (work on a problem, potentially figure it out, and then read other peoples' write-ups after the competition ends). Checkout https://ctftime.org/ https://ctftime.org/ for a list of ctfs. There are also intro ctfs like https://picoctf.org/ https://picoctf.org/
- q3k 6y agoI didn't meant to discourage from playing CTFs, I just became jaded by seeing the same kind of heap feng shui tasks over and over and over again :). You know, the note-management linked list task with a simple CLI menu. Not to mention the proliferation of 0/1day tasks, which are IMO just lazy. Do play CTFs. Just pick the fun challenges. pwnable.kr used to have some good stuff if you want to level up.
- blkhp19 6y agoPerhaps a dumb question, but why don't things like signed pointers prevent this? Are they just not that good of a security measure?
- q3k 6y agoThe article explains bypassing exactly this (PA/PAC). > Vulnerability discovery remains a fairly linear function of time invested. Defeating mitigations remains a matter of building a sufficiently powerful weird machine. Concretely, Pointer Authentication Codes (PAC) meant I could no longer take the popular direct shortcut to a very powerful weird machine via trivial program counter control and ROP or JOP. Instead I built a remote arbitrary memory read and write primitive which in practise is just as powerful and something which the current implementation of PAC, which focuses almost exclusively on restricting control-flow, wasn't designed to mitigate. Signed pointers are just a mitigation. With enough time to find other primitives/constructs (from less severe but more common bugs) you will work around them.
- exabrial 6y agoWow. No helium required either
- insta_anon 6y agoWhat I don’t understand is: Apple sits on this giant stack of unused money [1]. Why don’t they get the best security researchers in the world, pay each of them north of $1M / year in salary and create the ultimate red team where their only task is to try to hack Apple devices. If they get a team of 1000(!) people, each with $1M(!) in salary that would be less than 0.5%(!) of their revenue in 2019 [2]. Wouldn’t that be worth it? [1] https://fortune.com/2018/01/18/apple-overseas-cash-repatriation-gop-tax-plan/ https://fortune.com/2018/01/18/apple-overseas-cash-repatriat... [2] https://www.statista.com/statistics/265125/total-net-sales-of-apple-since-2004/ https://www.statista.com/statistics/265125/total-net-sales-o...
- tptacek 6y agoThere are dozens, perhaps hundreds of people working at the level we're talking here --- vulnerability research is highly specialized. So the better question is perhaps why Apple doesn't build a program to train 1000 researchers to compete.
- AceJohnny2 6y agoI get the impression that while Apple is world-class at HW ops, they are very mediocre at people ops. (and I get the impression that Google is the opposite)
- tptacek 6y agoI guess. Project Zero has a sort of unique history; as I understand it, it's less a reflection of Google's distinctive culture as it is Google's savvy in acquiring and nurturing a pre-existing research culture, and that might not be replicable. But you can also ask the question: how much of an impact has P0 had on shielding Google and its partners from similar vulnerabilities? If your impression is that, because of people like Ian Beer, Android phones are basically impregnable, I'll submit without a lot of insider knowledge that you're probably mistaken. What an Apple P0 buys Apple might just be a bunch of favorable nerd press cycles. But that's not a problem Apple really has. I am, however, convinced that with the right resource commitment, you could scale up a world-class research capability --- to potentially arbitrary levels --- without headhunting existing researchers, which is where I see the bottleneck right now. Or, I mean, Apple could just rewrite their OS infrastructure in a memory-safe language. If I had the two options, I would put all my chips on the language change. (I think P0 is extremely cool and valuable to Google in a bunch of ways and would be thrilled to see more major vendors try to replicate it, even I doubt they'll be successful).
- hnburnsy 6y ago'AWDL is an Apple-proprietary mesh networking protocol designed to allow Apple devices like iPhones, iPads, Macs and Apple Watches to form ad-hoc peer-to-peer mesh networks. ... And even if you haven't been using those features, if people nearby have been then it's quite possible your device joined the AWDL mesh network they were using anyway.' Wow, so Apple was ahead of Amazon's Sidewalk with AWDL. Can you disable this?
- megablast 6y agoThis is not for sharing data connectons. It if for finding lots iphones, etc...
- philsnow 6y agoIt looks like disabling airdrop doesn't do anything: > All iOS devices are constantly receiving and processing BLE advertisement frames like this. In the case of these AirDrop advertisements, when the device is in the default "Contacts Only" mode, sharingd (which parses BLE advertisements) checks whether this unsalted, truncated hash matches the truncated hashes of any emails or phone numbers in the device's address book. Then follows the section on brute-forcing 2 bytes (only) of a SHA256 hash. Spray noise on channels 6 and 44?
- richardwhiuk 6y agoI don't think that proves what you think it does - that's with AirDrop on, but in a limited mode. If you turn AirDrop/Bluetooth off, you may well disable this. On my phone: - If you disable Bluetooth in the notification tray, then it goes to Bluetooth "Not Connected", but not Off. - If you disable Bluetooth in settings, AirDrop automatically goes into "Receiving Off". - If you then enable AirDrop, it'll automatically turn Bluetooth on. So I don't think it's true that you can't disable it - unless the UI is misleading about Off.
- neilalexander 6y ago> Wow, so Apple was ahead of Amazon's Sidewalk with AWDL. Not exactly. The wording in the article implies that AWDL forms some kind of multi-hop network topology, but it doesn’t - it just enables nearby devices to communicate with each other directly at Wi-Fi speeds without the burden of pairing (like Wi-Fi Direct) or being associated with the same Wi-Fi network. This is used not just in AirDrop but also in the Multipeer Connectivity Framework, AirPlay 2 and the Continuity framework. The standard discovery mechanism for these services is mDNS over AWDL, so for a device to browse for or advertise these services, it needs to be aware of other nearby AWDL neighbours first. (For example, you can browse for and discover other nearby AirDrop devices even if you don’t allow incoming AirDrop enabled yourself.) It’s also worth noting that Apple devices very strictly do not send or receive AWDL traffic when they are locked/asleep, and will often even stop listening on the AWDL social channels when there are no services being advertised or in use.
- dshep 6y agoExcellent video and nice write-up!
- dvt 6y agoI read the entire thing, and honestly the heap grooming is very interesting, but really that's the boring part -- lots of trial and error, padding memory, etc. Also interesting that linked-lists aren't used by Apple† (and Ian Beer's suggestion that they ought to use them), but that's neither here nor there. Getting kernel memory read/write is also very interesting, albeit (again) a bit tedious. At the end of the day, it all started with this: > Using two MacOS laptops and enabling AirDrop on both of them I used a kernel debugger to edit the SyncTree TLV sent by one of the laptops, which caused the other one to kernel panic due to an out-of-bounds memmove. How did this even pass the _smell_ test? How did it get through code reviews and auditing? You're allocating from an untrusted source. It's like memory management 101. I mean, my goodness, it's from a wireless source, at that. † In this specific scenario, namely the list of `IO80211AWDLPeer`s.
- ashleyn 6y agoI suspect linked lists are not used because they are notorious for wrecking cache performance.
- pfundstein 6y agoNever head of that, though I don't use C much. Are you referring to the CPU cache?
- saagarjha 6y agoYeah, linked lists are bad for the data cache since each element is in some totally random area of memory and thus less likely to be in a cache. Whereas for a linear array the data is next to each other and can be cached effectively and accesses can be easily predicted.
- philsnow 6y agoYou can also force-align (with padding if necessary) your structures to be along whatever boundaries make sense for your processor's cache lines. Ensuring an oft-loaded structure always fits inside a single cache line (instead of splaying across ~1.9 cache lines on average) is good not only for fitting lots of those structures into your L1 but for not blowing out cache bandwidth (read _and_ write, if you're modifying them).
- rmac 6y agomasterwork.
- rvr_ 6y agoHow many people on earth can find and exploit something like this? Less than 100, maybe less than 1000?
- saagarjha 6y agoProbably more than a hundred; there are teams of dozens at the good corporate security groups and an unknown number working for governments and other organizations that don’t appear as publicly.
- summerlight 6y agoMore than thousands should be able to find this kind of security bugs, potentially many of them from state-backed hackers from China and Russia.
- randyrand 6y agoCan someone summarize the expoit?
- saagarjha 6y agoAWDL is a wireless protocol that Apple used for things like AirDrop. In the AWDL handling code in the kernel there is a 60-byte buffer that gets copied over by an up-to 1024 byte buffer supplied by an attacker. Using other bugs and poor address randomization Ian Beer from Google Project Zero discloses kernel memory, then constructs a kernel read and write primitive. Then he demonstrates how this can be used to gain privileged code execution in userspace by launching the calculator and making a program to extract user photos.
- pjmlp 6y ago> A fairly trivial buffer overflow programming error in C++ code in the kernel parsing untrusted data, exposed to remote attackers. Apparently Apple failed in their hiring process to get those mythical developers that never write such kind of errors in production C or C++ code. /s
- zionic 6y agoPeople need to accept that the problem is the language. We will never solve the developer problem, but we will/can/have produced languages that make these types of errors impossible/extremely unlikely.
- mensetmanusman 6y agoIt would be amazing to plot the 2.4 GHz amplitude vs. time series plot of this exploit. Think about it, an ocean of electrons in the copper WiFi antenna bump along with a certain guiding EM wave and in so doing, they inadvertently cause the information moving electrons in the silicon crystal to disconnect from the electrons being pushed out of the Li-ion battery. This amplitude fluctuation in principal could have been broadcast by motions of stars in the universe, as astronomy does peer into the deep with these frequencies [0]. In the future, one could imagine a bad actor with control over a global network of low orbit satellites spewing out this code for decades preventing the such devices from being turned on long enough to receive updates, deactivating billions of dollars of human capital. [0]: http://www.astrosurf.com/luxorion/radioastro-frequencieslist.htm http://www.astrosurf.com/luxorion/radioastro-frequencieslist...
- the_only_law 6y agoDespite the rather explicitly explanation I still have absolutely no idea how people go about deciding how and wear to start on such insane exploits.
- wyldfire 6y agoThe link to the clang pointer auth doc is broken, Apple changed their default branch name to 'main' instead of 'master'. A (more?) permanent link is [1]. [1] https://github.com/apple/llvm-project/blob/73ea7cb9eba3196ae0a4ff882ba5aff3a928aecb/clang/docs/PointerAuthentication.rst https://github.com/apple/llvm-project/blob/73ea7cb9eba3196ae...