3 ms·
So, if they're there for diagnostics why aren't they disabled by default, requiring user intervention to enable them?
by X-Cubed 12y ago
So, if they're there for diagnostics why aren't they disabled by default, requiring user intervention to enable them?
- X-Istence 12y agoUnless you plug the device in, unlock it using your pin code/touch ID sensor, and say "yes, trust the computer I am connected to" these won't be accessible.
- robszumski 12y agoThis is covered on slide 46 of the original researchers presentation. "Oh, and… there’s a bypass switch for pairing anyway" --- Next Slide --- "An electronic alternative to interdiction could be deployed by spoofing Apple’s certificates and configuring / pairing the device out of the box." "OR by penetrating a targeted organization, supervisor records can be used to pair with and access any device they’re supervising."
- lyinsteve 12y agoAll that's saying is that they can use whatever mechanism is available to unlock the device. In an enterprise environment, the supervisor has the credentials to unlock the device. > "Oh, and… there’s a bypass switch for pairing anyway" Nice conjecture. Please show us actual evidence of that.
- X-Cubed 12y agoAccording to the security researchers, these services are available over TCP and existing pairing requests & responses can be replayed to access them.