5 ms·
"Advanced Data Protection" is an optional feature you can enable for iCloud that makes that not true. See the table at https://support.apple.com/en-us/HT202303
by altano 3y ago
"Advanced Data Protection" is an optional feature you can enable for iCloud that makes that not true. See the table at https://support.apple.com/en-us/HT202303 https://support.apple.com/en-us/HT202303 and note that iCloud Backup (including device and Messages backup) stores the keys on your trusted devices only when Advanced Data Protection is enabled:
"Advanced Data Protection: iCloud Backup and everything inside it is end-to-end encrypted, including the Messages in iCloud encryption key."
These sorts of laws make Apple not able to support Advanced Data Protection in jurisdictions that pass them.
- lrvick 3y agoExcept Apple can remotely execute any code they want on your phone at any time. That is how proprietary software works. If Apple is ordered to ask a given device to return all keys in plain text, it can. So can any Apple employees also on payroll for state actors.
- sunshinerag 3y agoYep same for Google/android and Microsoft devices
- lapcat 3y ago> Except Apple can remotely execute any code they want on your phone at any time. That is how proprietary software works. No, that's not how any code works, proprietary or open source. I've written proprietary software for 16 years, and none of it could remotely execute any code that I want.
- idle_zealot 3y agoTheir OS may give them that capability, or it may not. There is no way to know.
- lapcat 3y agoThere actually is a way to know. People can and do reverse engineer the code on device. I've done it myself many times. I would also note that unless you compile an open source project yourself, there's no guarantee that the compiled product you download from an open source project actually came from the publicly available source. If you want to get all conspiratorial, I suggest that you're not conspiratorial enough. ;-)
- smoldesu 3y agoIf Apple is somehow dumb enough to leave an unscrubbed/unfuzzed backdoor in their shipping version of iOS, I'd almost be inclined to call it a red herring. It stands a reasonably safe assumption that Apple has been compelled to add obfuscated adversarial code to iOS, just as you can assume BitLocker is about as secure as a Masterlock made out of Swiss Cheese.
- lapcat 3y agoNo, it's not a safe assumption, and it's not clear that you even know what you're talking about, technically. You use terms like "unscrubbed", "unfuzzed", "obfuscated", but what do you think they mean exactly? For example, how does "unfuzzed" relate, if at all, to https://en.wikipedia.org/wiki/Fuzzing https://en.wikipedia.org/wiki/Fuzzing
- smoldesu 3y agoI think the core conclusion is perfectly sound. Apple is a capable company - they would not let the user discover malicious code unless they wanted you to find it. They intend for people to reverse-engineer their systems and run it through IDA, Ghidra and Cutter. Tools exist to mitigate that discoverability, and I think it's foolish to assume they don't use them. The only safe assumption seems to be that they are hiding something. Proving the contrary requires tools we may never have.
- lapcat 3y ago
- sneak 3y agoiOS has automatic updates enabled by default. All Apple has to do is make an update available for the device in question that has whatever backdoor in it they want. They can easily make updates available only to specific devices. Any iPhone in a default configuration will happily download and install it. This is RCE (with a slight delay). Automatic unattended upgrades are on by default in iOS. The configuration wizard flow still has the screen that used to prompt you about them, asking for consent, but now it doesn't give you the choice, it just tells you it's going to update automatically. It's up to you to go into Settings after setup and disable it if you don't want Apple to be able to push new and unknown code to your device arbitrarily.
- lapcat 3y ago> This is RCE (with a slight delay). Eh, that's really a stretch of the definition. Hardly anyone installs software via physical media anymore, so doesn't mean that all code execution is remote code execution? "Software updates are RCE" is not the greatest take. > It's up to you to go into Settings after setup and disable it if you don't want Apple to be able to push new and unknown code to your device arbitrarily. Which you can do very easily. Regardless, every user notices when Apple has shipped an OS update, because your device rebooted. Furthermore, software updates can still be reverse engineered after they're released.
- lrvick 3y agoThey notice there was an update, but they have no clue if that update just decrypted all their messages then reverted itself along with all evidence. If this is just done on select targets, capture and detection is highly unlikely. A court order on whoever controls the Apple signing keys could do this. I would wager that this is already happening in China since the CCP took control of the signing keys. If a system is not open, accountable, with distributed reproducible builds each adding their own signature, then you are in fact granting a central party access to execute any code they wish on your device if you accept updates without reverse engineering every single CPU instruction, driver, firmware bundle, and microcode change in every update bundle and sideloading them by hand somehow... which Apple does not permit.
- lrvick 3y agoSomeone has the signing keys for Apple os/apps, baseband drivers, oma-dm toolkits, etc. Whoever that is can sign whatever they want, send an update notification targeting a single user, and the phone will then execute anything as instructed. A court order could tell whoever holds those signing keys to sign something to decrypt all messages, or install a dummy encryption key, or make the random number generator always return 42. Just because Apple has successfully gaslighted the courts by claiming they cannot decrypt phones, does not make it true. Supply chain attacks on a proprietary system lacking reproducible builds and public accountability is indistinguishable from remote code execution as a service.
- lapcat 3y ago> Whoever that is can sign whatever they want, send an update notification targeting a single user, and the phone will then execute anything as instructed. That wasn't the claim. The claim was "Apple can remotely execute any code they want on your phone at any time." In other words, Apple can do it right now, on your phone, without any software update. And there's zero evidence for this claim. Software updates are not remote code execution. Moreover, users can choose not to install software updates.
- sneak 3y ago> Software updates are not remote code execution. Moreover, users can choose not to install software updates. However, automatic software updates are, as Solarwinds learned, and this is on by default on iOS, meaning that Apple can indeed execute code on all iPhones in the default configuration without user intervention.
- lrvick 3y agoExecuting code remotely via default-enabled automatic updates with some delay, or via an ssh command with less delay, the result is the same. Someone chooses to run code on your client, and it runs. The semantics do not impact the threat model here so who cares?
- lapcat 3y ago
- sneak 3y agoNo, please see my third paragraph. Your conversation partners are still escrowing their endpoint keys, allowing Apple to continue reading your iMessages. Approximately nobody has this on because it's not default, so even if you enable it, ~100% of your iMessages are still readable by Apple (and by extension FBI/DHS without a warrant).