3 ms·
Would compiling image parsers with ASLR and bounds checking prevent these zero-click hacks? I haven’t researched the exploits in detail but it seems to me Appl
by DethNinja 5y ago
Would compiling image parsers with ASLR and bounds checking prevent these zero-click hacks?
I haven’t researched the exploits in detail but it seems to me Apple can develop better protection against such zero-click exploits.
At the very least, iMessages shouldn’t preview images from unknown contacts.
- jazzyjackson 5y agoI'm convinced that a bad image parser is apple's backdoor, but I only have my paranoia as proof.
- viktorcode 5y agoWhat Apple stands to gain from a backdoor? It's clear what the cost of risk is, but what is the gain?
- PickledHotdog 5y agoJust spitballing, but market access to China and the like?
- user_7832 5y agoWhy use a backdoor if you have the frontdoor, the walls, the roof.. and the entire server? Censorship, Surveillance and Profits: A Hard Bargain for Apple in China - https://nyti.ms/3oAvIVH https://nyti.ms/3oAvIVH > Apple has largely ceded control to the Chinese government. Chinese state employees physically manage the computers. Apple abandoned the encryption technology it used elsewhere after China would not allow it. And the digital keys that unlock information on those computers are stored in the data centers they’re meant to secure.
- a1a106ed5 5y agoThe image parser uses ASLR. The turing complete NAND computing device they describe in the article was used to do computations on the pointers leaked with the infoleak, resulting in an ASLR bypass. Brilliant.
- oolonthegreat 5y agoIKR, sad to see such ingenuity used to hack activists.