22 ms·
About the security content of iOS 14.7.1 and iPadOS 14.7.1
- drexlspivey 5y agoCould this be patching the Pegasus exploit?
- arkadiyt 5y agoPossibly. If anyone would like to check if their iPhone was infected by Pegasus I wrote up some step-by-step instructions here: https://arkadiyt.com/2021/07/25/scanning-your-iphone-for-nso-group-pegasus-malware/ https://arkadiyt.com/2021/07/25/scanning-your-iphone-for-nso...
- m0dest 5y agoThanks for the write-up. One issue, though: >You might have also noticed the “Encrypt local backup” checkbox. MVT only operates on decrypted backups, so there’s no point in encrypting your backup here and immediately decrypting it to scan it - just create an unencrypted backup and delete it after you’re done. You should still do an encrypted backup even if you're going to immediately decrypt it for MVT. An encrypted backup contains more complete data; it's closer to a filesystem dump. The MVT docs actually explicitly recommend this, too: >If you want to have a more accurate detection, ensure that the encrypted backup option is activated and choose a secure password for the backup.
- arkadiyt 5y agoThanks so much for calling this out - I've updated the post
- xvector 5y agoIt's my understanding that Pegasus is a collection of zero days, not a single exploit
- fortuna86 5y agoIs there a way to enable instant over the air updates for 0-day fixes, etc? I see my phone has "automatic updates" on but it still requires me to download and install manually.
- wil421 5y agoUsually the automatic updates run at night when it’s plugged in and on WiFi. I’ve never seen my phone ask to do it during the day unless I ignored the update for a few days. I also believe Apple is doing some kind of rate limiting. Whenever I’ve upgraded iOS or MacOS on day one the download is painfully slow on my gigabit connection.
- infofarmer 5y agoNo extra rate limiting required. With ~1.7 billion active iOS devices, the infra must be under a bit of a strain to deliver even a relatively tiny 50 Mb delta. For this particular update, my iPhone downloaded over 100 Mb and MacBook over 1 Gb.
- rudian 5y agoMy iPhone 11 Pro downloaded over 900 Mb and it was up to date until now.
- slownews45 5y agoThe scale of data involved in this crazy. 1GB/update * 1B devices potentially? We are in exabyte range. I've also noticed somewhat slower downloads on new updates on my 1GB connection. Ideally their caching network really is everywhere. I wish they'd do the Microsoft thing of letting you update based on others local downloads. For campus networks some of these updates can really load things up. I'm also at 900MB+
- marcellus23 5y ago> letting you update based on others local downloads They do, you can set up a Mac as a content cache for system updates for other Macs on the same network.
- praseodym 5y agoIOMobileFrameBuffer has seen a lot of vulnerabilities over the years: https://nvd.nist.gov/vuln/detail/CVE-2011-0227 https://nvd.nist.gov/vuln/detail/CVE-2011-0227 https://nvd.nist.gov/vuln/detail/CVE-2015-1097 https://nvd.nist.gov/vuln/detail/CVE-2015-1097 https://nvd.nist.gov/vuln/detail/CVE-2015-5843 https://nvd.nist.gov/vuln/detail/CVE-2015-5843 https://nvd.nist.gov/vuln/detail/CVE-2016-4654 https://nvd.nist.gov/vuln/detail/CVE-2016-4654 https://nvd.nist.gov/vuln/detail/CVE-2017-13879 https://nvd.nist.gov/vuln/detail/CVE-2017-13879 https://nvd.nist.gov/vuln/detail/CVE-2018-4335 https://nvd.nist.gov/vuln/detail/CVE-2018-4335
- laumars 5y agoCounting the number of CVEs to measure the security of a piece of software makes as much sense as counting lines of code to measure a developer’s performance.
- okwubodu 5y agoSomeone breaking into my house 10 times by jiggling the same doorknob a contractor told me they “fixed” would be very concerning.
- CharlesW 5y agoA door would need thousands of doorknobs for that analogy to make sense.
- okwubodu 5y agoNo, you would need to admit your current approach is ineffective and replace the door and/or the repairman.
- laumars 5y agoThe GPs point is that writing software is a thousand times more complicated than installing a door knob. And frankly I think they’re being generous to you; writing a frame buffer is even more complicated than their estimation.
- jonplackett 5y agoIs there any reverse-engineered write up of how it was done anywhere?
- yellow_lead 5y agoProbably not yet. If we're lucky, someone will provide a write-up soon.
- mzs 5y ago>CVE-2021-30807 POC: int main(){ io_service_t s = IOServiceGetMatchingService(0, IOServiceMatching("AppleCLCD")); io_connect_t c; IOServiceOpen(s,mach_task_self(),0,&c); uint64_t a[1] = {0xFFFFFFFF}; uint64_t b[1] = {0}; uint32_t o = 1; IOConnectCallScalarMethod(c,83,a,1,b,&o); } >Make sure you have "http://com.apple.private.allow-explicit-graphics-priority http://com.apple.private.allow-explicit-graphics-priority" entitlement and IOKit headers imported. >Patch for this bug was released with iOS 14.7.1 less than 2 hours ago. Might be useful for a jailbreak but not sure due to the entitlement check. https://twitter.com/b1n4r1b01/status/1419734844909637642 https://twitter.com/b1n4r1b01/status/1419734844909637642
- yellow_lead 5y agoThanks!
- muricula 5y agoSaar Amar, who works at MSRC, wrote a writeup & POC for what he says is the same bug: https://saaramar.github.io/IOMobileFrameBuffer_LPE_POC/ https://saaramar.github.io/IOMobileFrameBuffer_LPE_POC/ He says he found it independently.
- xoa 5y agoAs always with patches to something of this level (if it is indeed Pegasus related say) it's important to note that if this was a rarified targeted-use exploit before it won't stay that way for long. Now that Apple has released a patch for it widespread reverse engineering will begin immediately and it'll only be a matter of time until packaged exploits become part of standard mass-use toolkits. Having a patch ready to deploy is great, but simultaneously means it's all the more important to get it deployed fairly promptly if it's something that could have serious root/remote execution potential. Though I suppose if this bug can be used for a jailbreak there may be some people who'd actively want to stay on 14.7 as well. It's too bad on iOS Apple forces people to choose between security and control of their own systems and doesn't at least allow a purchase-time option to have the ability to load ones own root signing certificate.
- throwaway4good 5y agoA lot of people don't update or don't update immediately.
- eruleman 5y agothat's what the emoji's are for.
- colejohnson66 5y agoBy default, iOS automatically installs updates after a few days
- useragent86 5y agoThe link says that iPad Air 2 and later are supported. Does this mean that the original iPad Air is vulnerable? There must be many of them still in use for Web browsing, video, games, etc.
- nicebill8 5y agoIf this is really critical, it would not be unprecedented if we were to see another iOS 12.x.x release.
- slownews45 5y agoFor sure - I've been impressed here on older device support. I've seen 7 year old devices getting updates - 5s etc?
- dogsgobork 5y agoFor anyone curious, Apple has release a few updates for iOS 12 since support for some devices was dropped with iOS 13, with 12.5.4 being released in June. The iPad Air mentioned above being a nearly 8 year old device. Are any Android devices of that vintage still receiving any updates?
- richardwhiuk 5y agoI don't think you can conclusively say either way. iPad Air 1st gen only supports iOS 12, which was patched 40 days ago. So either they haven't released a fix yet, or it's not vulnerable.
- SV_BubbleTime 5y agoIt goes both ways. If something is too old to get the fix, there is just as good a chance it’s too old to have the bug. Can’t say for sure that the exploitable code ever existed on that device. Like Win10 0-days not being an issue for Windows 7. But… Yea, I wouldn’t bet on it either way.
- hindsightbias 5y agoOnly 952.5 MB?
- nonninz 5y agoAccording to my phone is 139.8 MB
- signal11 5y ago126 MB for me.
- thekrendal 5y agoI think it depends on which version you're updating from. I'm still on 14.5.1 and it shows as a 922.4MB download.
- fsflover 5y agoSee also: https://news.ycombinator.com/item?id=27946945 https://news.ycombinator.com/item?id=27946945.
- Eriks 5y agoAlso macOS Big Sur 11.5.1 https://support.apple.com/en-us/HT212622 https://support.apple.com/en-us/HT212622
- Rolcol 5y agoI don't like the update system introduced in Big Sur. An update that is only around 124MB on iOS is 2.20 GB on Big Sur.
- eurasiantiger 5y agoFortunately, Apple Coal is rumoured to be just around the corner, to be launched with Apple iSteam product family.
- dangus 5y agoIf you think about the amount of TV in hours people watch on a daily basis via streaming services, it’s weird to me that a 2 GB OS patch could be considered a problem. Data transfer isn’t a finite resource like oil or gas.
- andrewzah 5y agoThat doesn't mean that we should just ignore efficiency. Smaller downloads means less bandwidth required on apple's side as well. This also ignores that not everyone has stellar connection speeds, and that some people -do- have bandwidth caps (also, let's ignore that people are often mobile). Developers really need to stop making assumptions about people's hardware or internet speeds... and just do their jobs and make efficient designs. Maybe one day everyone will have super beefy machines on fiber optic networks with 10gb nics, but that's not the reality as of now. If a patch needs to be 2gb, then so be it. But if it could be 100mb, then that's certainly better and something to strive for.
- deleted 5y ago[deleted]
- 5y ago
- PostThisTooFast 5y agoWhatever "0-day" is...
- 2OEH8eoCRo0 5y agoI thought the walled garden provided impenetrable security?
- ThePowerOfFuet 5y agoNothing provides "impenetrable security". Don't be a dick.
- mrunseen 5y agoRelated tweet (POC): https://twitter.com/b1n4r1b01/status/1419734027565617165 https://twitter.com/b1n4r1b01/status/1419734027565617165 Also (writeup): https://twitter.com/AmarSaar/status/1419770084780875779?s=20 https://twitter.com/AmarSaar/status/1419770084780875779?s=20
- sillysaurusx 5y ago> Thanks a lot Maddie! Sure, I wanted to write a full exploit and achieve tfp0 before submitting because it affects the submission quality. I'm pretty busy right now, so I planned to work on it after August. I did plan to submit it, but I wanted to get an exploit first :) As a former pentester, that's precisely the opposite of the correct thing to do. tptacek could phrase this more eloquently, but pentesters do not try to weaponize exploits. The whole point of exploiting is to demonstrate that a vuln exists. Once that demonstration is complete, weaponization serves no purpose. (No purpose for protecting users, anyway, which is the whole point of pentesting.) I'm surprised no one seems to care. Maybe times are changing.
- saagarjha 5y agoApple will generally not award you a bounty unless you send them a full chain.
- sillysaurusx 5y agoOh. Then it's totally justified. My mistake. I didn't realize that there might be a difference in the awarded bounty level. That's... unfortunate for them. As you can see here, he was sitting on this for some time.
- _kbh_ 5y agoThe only 'correct' thing to do is whatever the person who discovered the bug wants to do. Responsible disclosure is a nicety that most people in the industry follow, it is not a requirement.
- aj3 5y ago
- solarkraft 5y agoWonderful! This means there’s a chance iOS users will be able to get root access on their devices.
- ummonk 5y agoThis isn't remote-exploitable, right? I.e. the exploit happens if you have a trojanware app installed, correct? If it's a remote exploit I'm going to be telling everyone I know to update ASAP, but otherwise seems alright to let the regular auto-update schedule do it for them.
- shitloadofbooks 5y agoIf it is the NOS Group/Pegasus exploit, then it was a "zero-click" exploit which could be exploited by sending someone an iMessage. I'm updating right now just to be sure.
- mtoddsmith 5y agoAn exploit like Pegasus could just fill up the storage on the device which would prevent updates from working. Why does this 14.7.1 fix require almost 2gb of storage?
- AlphaWeaver 5y agoI heard something about updates for the new M1 Macs requiring users to download the entire updated image due to some signing issue? Maybe something similar is happening here.
- swiley 5y agowhat a crap OS. These problems were solved decades ago on Debian.
- crossroadsguy 5y agoYes, crap. That’s what iOS and OSX has been for last 3-4 years. At one point I had wondered whether Apple laid off most of engineering and complete QA team.
- aaomidi 5y agoHmm, is this not a bug in iOS 15? I understand it's in beta but it seems irresponsible for not having the fix out there.
- SigmundA 5y agoAnother day another 2 gig MacOS update to fix unsafe language memory corruption...
- Gigachad 5y agoAt least Google and Linux are making plans and first moves to a safer language that helps avoid these major security flaws.
- danieldk 5y agoAnd Apple has been (re)writing more and more applications and frameworks in a safe language (Swift) for years now. You just don't rewrite hundreds of millions of lines of code overnight.
- SigmundA 5y agoI wish they would at least be able to do smaller faster updates for this stuff on Mac OS.
- allenrb 5y agoHow hard is it to understand that Apple is offering a closed ecosystem, with all of the pluses and minuses that implies? If that isn’t what you want, just don’t buy it. Vote with your $CURRENCY. Personally, the last thing I’ve got time to worry about is what’s going on in my phone. So I’ve got an iPhone and use basic common sense when choosing what to run on it. Yes, this is HN but it sure does get old seeing the inevitable complaints about Apple. I’ve been around long enough to know what happens to Apple when they aren’t selling what people want. That isn’t the case today. Maybe get over it?
- p1necone 5y agoThis seems reasonable on the surface but it's really not. You're basically arguing that nobody should criticize anything that costs money - that is not a world I want to live in as a consumer.
- d110af5ccf 5y agoIt also ignores the tragedy of the commons aspect; real world evidence of it is abundant at this point. At the end of the day we need legislation similar to right-to-repair that covers device ownership and control.
- ralusek 5y agoWhen you try to be currency-neutral by using a variable, but the variable naming forces you to use $.
- fouc 5y ago> Available for: iPhone 6s and later, iPad Pro (all models), iPad Air 2 and later, iPad 5th generation and later, iPad mini 4 and later, and iPod touch (7th generation) They seem to have forgotten to mention iPhone SE which also gets iOS 14
- fortran77 5y agoApple's security is full of holes, yet people want to blame everyone but Apple.
- iJohnDoe 5y agoI would have to agree. There was a time the iPhone was considered the most secure phone. It turns out that people can keep a secret and were simply keeping the vulnerabilities quiet. Some of them years old. https://news.ycombinator.com/item?id=27956435 https://news.ycombinator.com/item?id=27956435
- Gigachad 5y agoYou have two options currently: iOS: Never ending zero days but you get an update for every device in the last 7-10 years to fix it. Android: A more secure OS especially as they integrate more components using rust. But if your device is older than 2 years, you won't receive any security fixes. So depending on your security model it changes what you should pick. If you are a high target individual or someone who upgrades their phone every year, Android is the more secure option. If you are the average person who is not being hit with state level attacks, iOS is the most secure option.
- quenix 5y agoThat’s the first I’ve heard someone call Android an inherently more secure OS than iOS. Could you substantiate that?
- Gigachad 5y agoIt's based on the linux kernel and many of the core components have been rewritten in rust which the google security team seems to be suggesting is the solution to these problems. I don't have any actual proof but my gut feeling is the linux kernel is better tested and has better security hardening than the ios internals.
- _kbh_ 5y ago
- hsbauauvhabzb 5y agoAs someone who needs a jailbreak device, will this 0day allow it? if I need to become an ‘Apple developer’ to exploit that’s not an issue.
- starefossen 5y agoI don’t get why this is almost a 1 GB download on my iPhone. Defiantly a no go for me as long as I am on vacation without Wi-Fi.
- tempodox 5y agoThe delta from 14.7 is ~ 100 MB. Are you updating from before 14.7? That would explain the download size. And iOS wants a Wi-Fi connection to download an OS update. Without Wi-Fi you couldn't update, even if you wanted to.
- starefossen 5y agoYou are right. My iPhone was still on 14.6 - that explains it then!
- kif 5y agoIt feels weird to be locked out of updating my iPhone, only because some smart guy at Apple HQ decided I shouldn't be able to use my unlimited data towards downloading updates.