9 ms·
Any iPhone can be hacked with a modified charger in under a minute
- Centigonal 13y agoIt's interesting how the progress of iPhone hacks is mirroring that of the PSP homebrew scene 5 or 6 years ago. First there were a bunch of easy to use vulnerabilities or hidden features in apps (like the hidden browser in WipeOut)that provided functions that were offered natively in future versions of the OS. Then the hacking scene moved to OS vulnerabilities. As Sony locked down the platform tighter and tighter, people moved to hardware, using modded batteries to boot the PSP in some kind of troubleshooting mode. Eventually, both Sony and the hackers kind of lost interest, I think -- I haven't kept up with things, TBH. That said, Sony had the PS Vita to move to, but I don't see the iPhone changing significantly in the next few years (risky words, I know, but I'll be happy if proven wrong).
- jamesaguilar 13y agoUnfortunately, since it is a university research group, they probably disclosed responsibly and whatever defect allowed this form of jailbreaking will soon be fixed. That means that it's unlikely that people will have a perennial, easy jailbreak going forward from this source.
- nhm 13y ago>Unfortunately, since it is a university research group, they probably disclosed responsibly and whatever defect allowed this form of jailbreaking will soon be fixed. I wouldn't consider that unfortunate. Responsible disclosure should be praised!
- jamesaguilar 13y agoIn almost all circumstances, I agree. However, the one circumstance I don't agree is when systems are being kept secure mainly against their own users. In this case, insecure systems are preferable (as a user), especially when the attack vector is likely to only be triggered intentionally. Since I don't plug my iphone into random USB cables pretty much ever, the only likely case where this vulnerability could be exploited against my phone is if I chose to jailbreak it.
- eridius 13y agoPlease stop speaking in generics. I assure you that, for the vast majority of iPhone users, insecure systems are not preferable.
- jamesaguilar 13y agoFor the vast majority of them, they'll never plug their phone into a non-Apple connector, so the security status of this subsystem will not have any practical importance either way.
- eridius 13y agoI think you underestimate how willing people are to share chargers. If you make one of these malicious chargers, and mock it up to look similar enough to an Apple one, I bet you could compromise a decent number of phones just by hanging out in a popular place (e.g. a coffee shop, or an airport) and making your charger available to folks.
- jamesaguilar 13y agoI guess I didn't consider that aspect. I have to concede this point.
- dlhavema 13y agoThe airport is a perfect example, offering USB ports for iPhone, Android, etc and there would actually be a computer behind the scenes skimming whatever it wanted, or adding whatever it could to the devices connected... A lot of people are eager to plugin to charging stations while waiting for their flights.
- uxp 13y agoNon-apple connectors are still just USB cables, which have to be plugged into somewhere. That somewhere could be malicious.
- bigiain 13y ago
- kyrias 13y agoWith hardware access all bets are off.
- ef4 13y agoYeah, but I think this is a bit worse than that. If a faulty ethernet driver lets you compromise a laptop just by plugging it into a malicious network, that's a legitimate vulnerability, not really a case of "well, they had physical access". USB may be customarily treated as more trusted than ethernet, but there are clearly still scenarios where untrusted people may be able to send you USB messages.
- bigiain 13y ago"Here, mind if I plug my video camera into your Firewire port to charge (and trawl through your ram and swapspace looking for any usernames and passwords)?"
- cheald 13y agoI dunno - with USB debugging turned off, you can't do much to an Android device even if you can plug an arbitrary device into its USB port. There's a reason I make sure it's turned off every time I leave the house!
- ephemient 13y agoOn stock JB, even with USB debugging turned on, it's been tightened down. http://android-developers.blogspot.com/2013/02/security-enhancements-in-jelly-bean.html#secure-debugging http://android-developers.blogspot.com/2013/02/security-enha...
- randyrand 13y agoTo some extent, sure, but we don't have to make it easy to get root access. Encryption on hard drives, removing the USB auto-play feature from windows, having to enter the PIN on a WP7 device before being able to deploy a developer app over USB, ect, are such examples that can make it considerably harder to get root access despite having the physical machine.
- djbender 13y agoHardware access is root access.
- cookingrobot 13y agoThat rule of thumb usually refers to having unfettered access to the hardware - to be able to crack it open, snoop on internal signals etc. In this case the problem is that the dock is expected to be a safe interface (untrusted), when it actually isn't. For ex, people would be surprised if their computer could be hacked by plugging it into a malicious power socket. And likewise they'll be surprised if they find out their phone can be hacked by putting it on an alarm-clock ipod dock in their hotel room.