Apple says recent Wikileaks CIA docs detail old, fixed iPhone and Mac exploits
techcrunch.com
techcrunch.com
That doesn't make an iPhone 7 impregnable, but it should inform any analysis you do of stories about phones being tampered with "starting in 2008"; that's a little like talking about SMTP server security "starting in 1993".
The encrypted by default iOS 4 and the whole design around passcode handling in that release was the start of a very strong security posture for Apple and their iOS devices.
Apparently $1,500[1]:
"Cellebrite's CAIS now supports lawful unlocking and evidence extraction of iPhone 4S/5/5C/5S/6/6+ devices (via our in-house service only)."[2]
[1] https://www.macrumors.com/2017/02/24/cellebrite-lawful-unloc...
As recently as last April, the FBI was claiming they could not access 5S or newer models[1] (at least with the hack they reportedly bought for over $1 million[2]).
[1] https://9to5mac.com/2016/04/07/fbi-iphone-hack-method-secure...
[2] http://www.cnn.com/2016/04/21/politics/san-bernardino-iphone...
Btw, these don't mention 6S or later models, or even the iPhoneSE.
Guessing the exploits are dependent on chipset or older version of the OS.
backup and wipe your phone before you travel. there are several stories now of customs compelling you to unlock the phone before allowing you to leave.
https://www.theatlantic.com/technology/archive/2017/02/a-nas...
It's very important to understand the silent-exploit threat model! That's the model used when someone is being investigated as a terrorist (or freedom fighter) and the government doesn't want to make them aware they're being surveilled, because they might change their plans.
In particular, the 3G is going to be highly vulnerable to silent exploits because of the lack of software updates, but that's not your concern at the border. Your concern is the lack of Secure Enclave on the 3G. That means that if they take your phone from you, they can image the contents of it fairly easily, without needing a fingerprint or passcode from you. If you get a newer phone, enable encryption, and use a strong passcode instead of a fingerprint, you can reboot the phone before a border crossing, and then the data is strongly protected unless you choose to give up your passcode.
For the customs threat model, you might also want to bring a different phone with limited data when traveling. It might make sense to have a powered-off phone with a Secure Element somewhere separate from you (e.g., shipped via post), and just use the 3G for contacting folks while in transit, wiping all interesting data from it. In theory, this means your secure phone could get confiscated but you can't be compelled to unlock it (since you're not physically with it). I'm curious if other folks on this forum think this is a reasonable plan.
... Also, the easy vulnerability to silent exploits is probably a huge threat for you for non-government attackers, which are a much more common attack.
[0] https://www.theiphonewiki.com/wiki/0x24000_Segment_Overflow
We should not 'stop worrying about the CIA' just because Apple came to the rescue and already fixed the bugs.
We should, in fact, continue to apply pressure to such vendors of digital enslavement as Apple, and the rest of the sordid gang, to provide real evidence that "Things are Okay™", when asked.
I have no idea how you would begin to demonstrate that a body of source code as big (in both lines of code and length / size of the development project) as iOS, Android/Replicant/Lineage, or any other modern operating system contains zero backdoors, especially when your threat model involves the software authors helping you over a period of many years to weave those backdoors into the OS and obfuscate them as much as necessary.
I also have no idea how to audit a physical phone I have received from an Apple Store to make sure that the hardware and firmware faithfully implement what they are supposed to be implementing.
[1] https://arstechnica.com/security/2017/03/new-wikileaks-dump-...
The phones don't just go away, they're get passed down.
Someone might have sat on a copy for years before leaking.
Edit: Quick scan shows there are some docs with dates in 2013, 2014, 2015. So at least some of it is fairly recent. No real way to tell, though, if it was all pulled at once, assembled over time, etc.
Regardless of the fact that this is a patched, nearly decade-old exploit, they're trying to make a scene rather than go through ethical channels.
I am wary of anyone who claims that giving me access to raw source material is not acting in my best interests.
The CIA, which has limited domestic authority, compromising American companies' products is not only not their job, but also illegal.
I never said the CIA always conducts itself legally. My point was that "their job" is defined by the law. CIA agents infiltrating American manufacturers to break their products, even if intended for foreign customers, is illegal and thus not "their job".
> would wikileaks exist
If I understand correctly, you're saying Wikileaks' existence is proof of the CIA's impropriety? That assumes anything secret is illegal. Not true. Classified information is legal [1].
[1] https://en.wikipedia.org/wiki/Classified_information_in_the_...
Having said that, we do know for a fact that some US companies and research establishments have actually been penetrated by Chinese agents because some of them have been caught. The problem with taking advantage of such agents though is that they not only have to get a job, they also have to get access to whatever the agency is targeting. In a company like Apple with extremely tight internal security that could be pretty challenging.
Getting listening devices installed/activated on every device is a whole 'nother ball park. To the extent that foreign intel services are doing this, my belief would be that it's only by infiltrating so deep that they learn the secrets of how to activate and utilize the monitoring agents installed for American intel services. That's not outside the realm of possibility, but I wouldn't call other nation-states incompetent for not yet having done so.
There is also reverse-engineering, which seems like the more plausible scenario through which foreign intel services would gain access to embedded spy hardware. They just send a device back to their labs for serious reverse-engineering and learn the secrets from that.
It's not that hard really. Anyone who's worked on a large codebase knows how easy it would be for someone to slip in a vulnerability that looks like a simple coding mistake. There's even a contest for producing such code: http://www.underhanded-c.org/
Keep in mind that Western tech companies knowingly hire tons of foreign nations who are presumably loyal to their home nations (as is natural), and a large portion of whom have their entire families still living there too.
(Which is not to say that they shouldn't hire foreigners. There are similarly bad incentives for domestic nationals as well, who can make hundreds of thousands of dollars per exploit on the grey market. The problem is that the engineering processes and standards for software are nowhere near as robust as they need to be considering the ubiquitous access to and control of our society that technology has.)
Edited to take out insult.
"fixed" probably isn't the right word.
See http://cc.bingj.com/cache.aspx?q=%22secure+by+design%22+site...