3 ms·
Imagine being in China and finding this out after an update. I used an iPhone a few years ago and when setting it up, I made sure to turn off all iCloud stuff.
by tholdem 3y ago
Imagine being in China and finding this out after an update.
I used an iPhone a few years ago and when setting it up, I made sure to turn off all iCloud stuff. When it was time to get a new phone, I noticed all my pictures were in iCloud.
I also did not like how hard it was to try and keep Bluetooth and Wifi turned off. Regularly it would nag me to connect to an open Wifi when I was sure I switched Wifi off completely. Turns out iOS re-enables both Wifi and Bluetooth after OS updates and you can't completely switch them off from the quick settings. If users privacy was so important, wouldn't you want to make sure all that stuff would not happen?
Also, it's good practice to reboot your phone one in a while, so why isn't there a reboot option in iOS?
- chrisandchris 3y ago> Also, it's good practice to reboot your phone one in a while, so why isn't there a reboot option in iOS? Out of curiosity, what is the advantage of rebooting your phone? I disn't do it for a couple of months and I don't see what gets "better". Besides, turning it off and on again will reboot it too. Just slighty more inconvienent :)
- tholdem 3y agoModern smartphone security relies on verified boot which cryptographically verifies various components in the boot process all the way to the kernel and beyond to make sure they have not been tampered with. This not only protects against physical attack vectors, but also remote as it can detect and prevent malicious modifications to the firmware and OS. For example, this makes malware persistence much more difficult, as verified boot checks for integrity at every boot and reverses any unsigned changes. Persistence on iOS and Android is very difficult. As an example, at least on iOS, threat actors have sometimes failed to achieve persistence, so they hijack the shutdown process and simply fake shutdown by animating the shutdown flow. The user thinks they've shut down the phone, but in reality the device was never shut down and never went through the verified boot process. However, since Steve Jobs decided iOS never needs a manual reboot, gaining persistence may not even be necessary, because people don't reboot their iPhones.
- chrisandchris 3y agoDoesn't that contradict itself? If the attacker fakes the shutdown process (and/or the reboot process), how does a shutdown or reboot help if the process never actually happens?
- tholdem 3y agoSorry my reply was poorly written. Like with anything, there will be vulnerabilities and techniques that allow for verified boot bypass, which most are not trivial and which need to be fixed, but that does not mean verified boot isn't valuable and working. It means extra cost and work for threat actors and the example was just how it was once done, by not attacking verified boot, but the process before it. Maybe because true persistence was too hard to achieve at the moment, thanks to properly implemented verified boot. Once the battery runs out completely, then you can be sure verified boot is helping you out. I'm sure there are now other mechanisms that fixed the example of faking the boot process I wrote about earlier.
- hulitu 3y ago> Imagine being in China and finding this out after an update. Or in the US. Apple and Uncle Sam wants your passwords.
- tholdem 3y agoI mentioned China because there Apple's e2e encryption does not apply.