6 ms·
For the author, he misses an important point that except sometimes (and rare case) for a few core libs and functionality, majority zero-days and zero-clicks are
by srvmshr 3y ago
For the author, he misses an important point that except sometimes (and rare case) for a few core libs and functionality, majority zero-days and zero-clicks are based on new features and their integration into current OS iteration. Software revisions begets new security events. Patching software bugs/loophoples is not like treating cancer - something that has existed always and keeps popping up. It is new software added to old stack and made to gell with it. That 'gluing' process churns up new security issues.
If the phone is physically okay and you depend on few core functionalities, then it is perfectly okay to keep using it for majority of (non-critical) tasks. Most bugs in the system & features of old iOS are limited to that old OS anyway - and most likely addressed. If some advanced utility are going to be involved e.g. work communications, some security protocols, I'll perhaps work with a device which still gets critical updates at the least.
I have a iPhone 8 which I use just to Facetime my MIL and receive her iMessages (I am on Pixels since 2019). I can't foresee a old patched- often iOS with a older no-frills Facetime version to have a major risks. For these tasks, I don't see it necessary to get a new iphone.
- thathndude 3y agoExcept that iMessage is a perpetual source of security concerns. Once that becomes unsupported, you’ll likely have exploitable code, where the exploit is publicly and widely known (but patched on newer versions).
- deleted 3y ago[deleted]
- dangus 3y agoThe obvious workaround is to just disable iMessage and use an alternative messaging app that stays up to date on the App Store.
- WirelessGigabit 3y agoThat probably wont help. If the vulnerability is in the PNG renderer, then Signal is also vulnerable as they also show you a preview.
- schiffern 3y agoIf the vulnerability is within the PNG renderer, then wouldn't all text messaging (not just iMessage) be effected? As I recall, the disclosures of major vulnerabilities in iMessage don't say that regular SMS messaging is effected.
- olliej 3y agoI think all the reports just say "iMessage" and don't specifically note sms vs iMessage specifically. It's entirely possible that there a carrier side restrictions on allowed image formats, and of course these attackers don't want people to see their exploits and definitionally using sms would allow just that. But also, in answer to the question: yes, every messaging app on Mac or iOS that could display webp was susceptible to this exploit. If they use ImageIO then the OS update fixes them, if they use their own copy of libwebp they are exploitable until they ship an updated version.
- deleted 3y ago[deleted]
- chatmasta 3y agoFor the recent WebP exploit, IIRC no preview render was even required to trigger it; simply receiving the message was sufficient. The exploit was triggered by a code path in Blastdoor that headlessly rendered the malicious WebP that was embedded within a Passkit attachment. (But I can't find a source for this atm. I remember reading it somewhere, but maybe I'm confusing it with a previous Blastdoor exploit.)
- GeekyBear 3y ago> For the recent WebP exploit, IIRC no preview render was even required to trigger it; simply receiving the message was sufficient. It was triggered because the system shows a preview of the image by default. Devices that had Lockdown Mode enabled no longer show preview images, so were not effected. >Lockdown Mode is an extreme protection feature for iPhone. Its protections include safer wireless connectivity defaults, media handling, media sharing defaults, sandboxing, and network security optimizations. https://support.apple.com/guide/iphone/use-lockdown-mode-iph049680987/ios https://support.apple.com/guide/iphone/use-lockdown-mode-iph... > On September 7, 2023, Apple released emergency security updates to fix a buffer overflow vulnerability (CVE-2023-41064) impacting macOS, iOS, iPadOS, and watchOS products that was used in a zero-click exploitation chain by the NSO Group. Shortly after, on September 11, 2023, Google released an update to fix a buffer overflow vulnerability (CVE-2023-4863) in Google Chrome, which was reported by Apple’s Security Engineering and Architecture (SEAR) and Citizen Lab. Both vulnerabilities were nearly identical and listed as actively exploited, leading to confusion across the security community. Note: Citizen Lab urges all at-risk users to enable Lockdown mode as this has been confirmed by Apple’s Security Engineering and Architecture team that Lockdown Mode blocks this particular attack. https://arcticwolf.com/resources/blog/cve-2023-4863/ https://arcticwolf.com/resources/blog/cve-2023-4863/
- olliej 3y agoiMessage is a "perpetual source of security concerns" because it is a remotely triggerable target. That's it. If everyone is using message service X, then we'll start seeing more attacks on X. The exploits we've seen over the last few years haven't been in iMessage the app, they've been in a host of different things. The most recent security brouhaha was apparently in the webp library[1] that also effected chrome, webkit, Firefox, every electron app, and I assume every app on android, iOS, macOS, that uses system image decoders, etc. But if you want a specific target then you aren't going to use something like a random webpage or phishing email if you have something that you can guarantee will go to only one device that you know is exploitable, and you can guarantee how it will be handled - i.e. the builtin system messaging apps. [1] and even here the attack didn't happen from iMessage
- superq 3y agoI don't know if you're specifically referring to X, the artist formerly known as Twitter, but regardless, no; iMessage runs with unique privileges and capabilities that are not available to ordinary messaging services.
- throwaway290 3y agoX is a common variable/placeholder like A, N or foo. Nobody is using it to refer to x.com unless it is a thread about Musk/Twitter
- dhritzkiv 3y agoLike the other comment pointed out, I understood 'X' to mean a stand in for iMessage. It didn't occur to me that we were referring to FKA Twitter
- saagarjha 3y agoNo it doesn’t.
- olliej 3y agoSorry I forgot the most recent musk idiocy. X was a stand in for any other functionally always on and receiving service, messaging platforms are the primary example. I'm actually now curious whether the various awful web notification standards allow images?
- helsinkiandrew 3y ago> I have a iPhone 8 which I use just to Facetime my MIL and receive her iMessages You have an iPhone just to communicate with your MIL? you're surely the DIL or SIL of the year!
- dangus 3y agoI’m not sure if your MIL is technical enough to do this, but you can receive FaceTime calls on the web now: https://support.apple.com/en-us/HT212619 https://support.apple.com/en-us/HT212619
- da_chicken 3y ago> It is new software added to old stack and made to gell with it. That 'gluing' process churns up new security issues. Perhaps I'm misunderstanding you, but this is not really correct. Most vulnerabilities are not regressions. Attention is what makes security issues discoverable, and popularity is what makes exploits valuable serious enough to warrant attention. The more popular software is, the more attention it gets from the security community (both black and white hat). The more popular software is, the higher the impact of an exploit is. The more popular the software is, the more significant the response is. That doesn't mean older software is secure, or that it can't be exploited. It just means nobody is really looking at it. Fairly often, security alerts come up for software that doesn't list older releases because they didn't bother to check their EoL releases not because they're unaffected. Take the Print Spooler vulnerability on Windows, or the ShellShock exploit in bash, or the Apache Log4j 2.x vulnerability. These vulnerabilities are all so old that they essentially work on any version of the affected software, including those that are more than a decade old for which no fix was even planned. Like the ShellShock bug in bash was found to go back to bash 1.03 released in 1989. As long as you have an earlier version of software that was later found to be vulnerable, you should assume that it is unless you've explicitly investigated the vulnerability and found otherwise.
- Apocryphon 3y agoI guess the question then are there any attackers bothering to target that old software. We’re not in the era where there were millions of users living on unpatched out outdated versions of Windows XP anymore. Would malicious actors attack an iPhone 8?
- Atotalnoob 3y agoSweet summer child... The military extensively uses older OS versions, which means they are very much targets. The UK's new HMS Queen Elizabeth aircraft carrier uses windows XP.
- hluska 3y agoIt’s interesting how such a wise comment can be completely ruined by your first sentence.
- duxup 3y agoI’m amazed how well my wife’s old 8 plus has held up. Was one of the reasons I switched.