5 ms·
A persistent denial of service vulnerability affecting iOS
- diebeforei485 5y ago> This bug was initially reported on August 10th They had plenty of time. You did the right thing by disclosing.
- perrohunter 5y agoThis looks nasty, I hope they patch this soon.
- curiousgal 5y agoWhat is it with iOS and string parsing bugs? First it was iMessage content then it was SSIDs now it's LAN device names? Oof
- tinus_hn 5y agoThis is not a parsing bug, it is just some component crashing because of a name that is too long. Not very nice, but considering the source of the name any exploitation scenario is very unlikely and this is incomparable to bugs that allow code execution.
- masklinn 5y agoUh. I wonder if this can still be triggered when the Home application has been removed from the device? I expect so as IIRC builtin-in application removal is really just hiding them and all the functions are part of priviledged bundles shipped with the OS.
- Lammy 5y ago> all the functions are part of privileged bundles shipped with the OS Luckily a lot of these can be disabled when jailbroken: https://i.imgur.com/KhGmGrf.png https://i.imgur.com/KhGmGrf.png
- userbinator 5y agoIt's unfortunate that you need to exploit a (different) vulnerability in order to gain full control of your devices.
- rootsudo 5y agoWhat app is that? I tried to get into cydia and such as of late, and it's a confusing ecosystem, you need to find specific marketplace links from github to browse and then alot of stuff is very legacy and not organized. Would love to jb but it is complicated.
- Nextgrid 5y agoBuilt-in apps are merely frontends, the actual functionality is tightly integrated into the OS in the form of daemons running in the background. I very much doubt removing the frontend app disables any of the daemons, especially considering these can be used to provide APIs that apps may rely upon.
- Apocryphon 5y agoWhy didn’t they add a string limit?
- userbinator 5y agoPerhaps the limit was "available memory"? It's not hard to imagine how a programmer who has only ever worked with dynamic languages and basically doesn't know what a fixed-length-buffer is could be completely oblivious to it. Then again, what is an appropriate limit on the length of the name of a HomeKit device? I'm tempted to say 255, but I'm sure someone else would disagree. I've been in design meetings where such things were discussed, with lots of bikeshed, so it's also understandable that, with deadlines and other priorities, they decided not to impose any limit.
- sodality2 5y agoI can't imagine anyone would disagree with 1024 characters.
- userbinator 5y ago"But that doesn't fit in a byte; why not make it 64k instead so it's 2 bytes?" "Why not 1023?" "Even 1023 is too long, I don't think anyone would need that." "What if <long and convoluted use-case>?" "How about 32?" Having been in a few meetings that went in that direction, I am not surprised that they couldn't agree on a limit. "Design by committee" at its worst.
- prox 5y agoAnother team that didn’t read nor adapted practices from About Face : on interaction design. What the team wants is irrelevant, how the user will adopt it is important, and for that you need to actually do tests.
- sebastien_b 5y agoI doubt it even went that far - given the size the story mentions (500,000 characters, but isn't clear if they tried smaller), my thinking is the programmer didn't make any checks whatsoever and just thought "no one will type in crazy-large values here, and even if they do it'll just truncate on display" (if that) without consideration on how it might affect memory.
- sebastien_b 5y agoThere are so many bugs in iOS that are years old and still unfixed. One example is the cellular-data draining bug[1]. The only "solution" for this is to wipe your device, and set it up again, without restoring any backups, at all. Which makes the whole point of backups of the device totally pointless. For a company that spent $6B+ on a (now mostly empty) campus, you'd think they could spare a few $million into proper QA/Testing. [1] https://mjtsai.com/blog/2019/07/26/broken-ios-cellular-data-switch/ https://mjtsai.com/blog/2019/07/26/broken-ios-cellular-data-...
- pxeboot 5y ago> Which makes the whole point of backups of the device totally pointless. Isn't this exactly how backups should work? Do you really want Apple deciding which settings/data are not important to you?
- aaomidi 5y agoIs this how backups work with your personal computers?
- pxeboot 5y agoYes, if I do a full restore, I expect all files and settings to be restored, including bugs present at the time the backup was made.
- yegle 5y agoiOS backup apparently doesn't work like you described. E.g., when restoring a backup from iOS 14, it doesn't revert your system to iOS 14. Clearly there's a separation of restoring the executables and restoring the configs. I do expect "the config/setup that would trigger a battery drain in <iOS X" to be restored, but Apple can always fix iOS so that the same config/setup won't break >=iOS X.
- aaomidi 5y agoIf you do a full restore implies that you don't have to do that. And yeah as the other commenter said, that's not really how the ios one works.