7 ms·
Well I would dare to say iMessage isn't the biggest target to convert to Rust. At the end of the day, it is still an app with app level permissions, sandbox et
by CyberRage 5y ago
Well I would dare to say iMessage isn't the biggest target to convert to Rust.
At the end of the day, it is still an app with app level permissions, sandbox etc.
Kernel\Kernel modules are far more likely to be written as they allow for vastly more access than an app.
- dylan604 5y agoUnless someone applies the squeaky wheel rule. The thing causing everyone to look at you gets pushed to the top of the list.
- saagarjha 5y agoIt's a great target considering that a lot of other exploits go through the kernel just to get access to your iMessages.
- CyberRage 5y agoIf you successfully exploit a kernel vulnerability, you don't need an iMessage bug.... you can pretty much access whatever you want.
- saagarjha 5y agoMy point is that the thing you would often do after that is go after people's iMessages anyways.
- CyberRage 5y agoI think you misunderstand how things work on modern mobile OS. You don't need to access the messages app in order to get access to the messages. it's the opposite actually, the messaging app needs permissions for the system level messaging component.
- saagarjha 5y agoI assure you that I know enough to at least hold an intelligent conversation on mobile security. On iOS there is no "system level messaging component". (i)Messages are stored in a SQLite database that is protected via entitlements and sandboxing; the Messages app is given the ability to access it legitimately. Attackers can either exploit the Messages itself and (via code execution in that process) grab a user's messages, or they can exploit something else (such as the web content process) and then escalate privileges from there to bypass the sandbox.
- CyberRage 5y agoAgain, if you get a kernel exploit, you don't need access to the messaging app or to escalate privileges. you're already root. you can access any component without much restriction. How the data is stored has nothing to do with this
- saagarjha 5y agoThis is correct. My point is that you would want to access messages data after doing that.
- CyberRage 5y agoSo let's circle back to the original question. Pwning the app will only provide access to whatever permission it has and we are still sandboxed. Pwning a kernel module\driver will provide access to everything whether its messaging, call logs, pictures etc. we are not sandboxed, we don't need an LPE exploit. I think the priority is clear.
- saagarjha 5y agoExploiting the kernel is obviously always desirable, but it's not always possible.
- robocat 5y agoI would pick the baseband processor as the biggest target. https://www.theiphonewiki.com/wiki/Baseband_Device https://www.theiphonewiki.com/wiki/Baseband_Device Reasons for worry about the baseband code: a) Code is written by a third parties b) Apple is more restricted applying defence-in-depth (customised security CPU changes like PAC, customised compiler changes, etcetera). c) harder to detect intrusion? Versus reasons not to worry so much: z) Baseband has more limited access to information y) harder to make exploit survive a reboot - mainly useful as part of chain of exploit into main CPU? x) Baseband code is device specific - helps to know target device to attack
- thehappypm 5y agoiMessage has the huge bonus that it's exposed to the internet. The kernel is much harder to actually get close to. iMessage? Send them a text.