Exploiting the Wi-Fi Stack on Apple Devices
googleprojectzero.blogspot.com
googleprojectzero.blogspot.com
> We’d also like to note that until hardware host isolation mechanisms are implemented across the Android ecosystem, every exploitable Wi-Fi firmware vulnerability directly results in complete host takeover. In our previous research we identified the lack of host isolation mechanisms on two of the most prominent SoC platforms; Qualcomm’s Snapdragon 810 and Samsung’s Exynos 8890. We are not aware of any advances in this regard, as of yet.
1. It should be Apple Watch. 2. I thought the newest Apple Watch uses Apple's own W2 Chip instead of Broadcom.
Trying to zoom on blogspot images always activates this useless feature.
From Apple directly:
"For the best experience on your iOS device, try to keep Wi-Fi and Bluetooth turned on."
The reason is because Apple are using WiFi for purposes other than those of the average user - data harvesting.
Same for my oven, stove top, vacuum cleaner and pretty much every other device I can think of.
WTH should the WiFi or Bluetooth switches on my iPhone operate differently?
This is another one of those crazy decisions by Apple. And apple being apple means you won’t have any other options either.
It should be perfectly acceptable, maybe normal even, to have a problem with that.
Agreed. That’s why you can still turn it off, but now the UI caters to what I’d consider the more common use-case.
It will? I don't see why it would do so, given that auto-join is disabled.
https://arstechnica.com/information-technology/2014/11/where...
https://arstechnica.com/gadgets/2012/03/loose-lipped-iphones...
So what's the workaround? I have to go into Settings and turn it off there? Will that actually turn it off? We've already established that turning off wifi on Android may or may not actually turn it off [2].
1: http://confiance-numerique.clermont-universite.fr/Slides/M-C...
> The vulnerabilities affecting Apple devices have been addressed in iOS 11.
1: https://source.android.com/security/bulletin/2017-07-01#broa...
I own a LG device, bought in January, stuck on Android 6.
There are only 1.6% of people in the world that own an Android device with 7.1.1, consider yourself lucky.
All because Google don't want actually sort it out.
Given that OEMs are expected to push updates themselves on Treble certified devices, I don't have any hopes that the whole update chaos will improve.
But yep, the mid/low end devices are often basically abandoned soon after release, or get 1-2 midlife updates so that December OTA has April's security patch level etc.
Or when you buy a phone buy a phone that supports Lineage OS. My Samsung Galaxy S2 runs an up to date Lineage OS.
Hacking devices is a workaround, not a solution.
It is this type of advices that made GNU/Linux fail at desktop adoption.
Is is really so strange that the advice for older phones would be similar?
Don't get me wrong, Lineage is great, but fully secure it isn't.
Workarounds that regular users don't have to endure with companies that actually care about them.
I also bought a Xiaomi for my partner (cause the FP2 would be an old SoC for the same price it cost 2 years ago) with specs which otherwise would've cost us more than double. I expect the device to last 1,5 years. Hopefully by that time the FP3 is on the horizon.
I should not have to accept anti-features to get security fixes.
ahhh cliffhanger! Looking forward to the next post!
Perhaps this is something users of Apple's WiFi-only/Ethernet-deficient devices might want.
He provides a useful hint on how to construct a router that allows complete control, utilizing a general purpose computer and two AR9271-driven USB WiFi adapters.
AFAIK this driver is available for both Linux and BSD.
"In my own lab setup, the role of the Wi-Fi router is fulfilled by my ThinkPad laptop, running Ubuntu 16.04. I've connected two SoftMAC TL-WN722N dongles, one for each interface (internal and external). The internal network's access-point is broadcast using hostapd, and the external interface connects to the internet using wpa_supplicant."
"Note that it's imperative that the dongle used to broadcast the internal network's access-point is a SoftMAC device (and not FullMAC) -- this will ensure that the MLME and MAC layers are processed by the host's software (i.e., by the Linux Kernel and hostapd), allowing us to easily control the data transmitted over those layers."
The "correct" name for it is Apple Watch, just FYI.
The iOS client has been “Messages” since iPhone OS 3.0; before that it was called “Text” and had “SMS” written inside the chat bubble in the icon. iMessage wasn’t introduced until iOS 5.0.
The macOS client was originally “iChat”, then “iChat AV”, then “iChat” again; in this era it supported multiple protocols including AIM and Jabber. In OS X 10.8, the client was renamed to “Messages” and gained iMessage support in addition to the older protocols. Support for the older protocols was removed in the just-released macOS 10.13.
[1] With a delightful/odd error message: "The targeted service Potato has been discontinued".
It would be less weird to refer the “apple phone”.
> The vulnerabilities presented in this research are present in iOS up to (and including) version 10.3.3 (apart from #1, which was fixed in 10.3.3).
This seems like it's old enough that Apple probably doesn't mind anymore.
It’s not like there is no fix for it.
A properly vetted update requires both compatibility testing and security testing. It would be irresponsible to push an OS update without verifying that it will not damage productivity or bring down defenses.
The previous behavior was turning off the radio, which is often not the intent of the user. They replaced it with turning off joining networks, which is more often user intent.
With the proliferation of personal connected devices like smart watches and cars, and point to point WiFi services like airdrop, users often want or need to have the radio on to utilize those services. At the same time, users may not want to join WiFi networks due to poor performance (ie one-bar WiFi), ineligibility for use (I’m at a Hilton for a conference, but am not eligible for free WiFi because I’m not staying there), or some other reason.
The previous behavior also duplicated the behavior of the “airplane mode” button in some scenarios.
IMO the iOS 11 behavior adds value in most cases and has two easy workarounds (airplane mode or system preferences) for people who want the radio off.
I want them off. That has always been my intent and those I’ve informally asked.
Additionally, increasingly important services like Airdrop and HomeKit use it.
The change referenced is the shortcut found in Control Center, which keeps Wi-Fi on but won't connect to new networks.
But if you read between the lines, I think what happened here is that Apple did some analysis of their support database and figured out that a huge number of support issues came down to WiFi or Bluetooth being turned off. Like, if someone doesn't really understand how AirDrop works (probably most iPhone users, honestly) and they try to use it with WiFi turned off. Or if they turn off Bluetooth because they heard it was a security issue, then their phone doesn't connect to their car the way it should.
The reality is that most iPhone users don't really understand all this stuff, and so don't fully appreciate the tradeoffs of having WiFi and Bluetooth turned off.
It's a bit more inconvenient, but at least we can still use Settings to really actually turn them off.
I'd be a lot happier with the new behavior if the icons indicated it somehow. If they really wanted to go crazy, they could label the damned things!
So how would you turn off WiFi while retaining mobile broadband?
Oh you cant?
This is just crazy bad UX. Apple is completely losing it.
I want to turn Wifi OFF because I want it off - I don't want to use Wifi, and therefore I don't want the Wifi using my batter life, and I also don't want any chance of Wifi broadcasting/receiving anything when I want it off.
This is just Apple treating their users like idiots. They're leaving the Wifi powered on for their own nefarious purposes - such as harvesting more Wifi SSID's when the user doesn't expect it, and using that harvested info to improve Location accuracy - also when the user is unaware that its happening, unless they dig deep, deep into the SysPrefs ..
From Apple: "For the best experience on your iOS device, try to keep Wi-Fi and Bluetooth turned on."
This is newspeak for "we need you to leave Wifi on so we can continue to harvest the SSID's of the networks around you, save the data, and report it later to improve our Location accuracy database" ..
Does it make a whole lot of sense? No. Has Apple removed the ability to "truly" shut these wireless interfaces off? No.
Though perhaps with MAC Address Randomization it’s a non-issue?
But can’t it still be triangulated?
This seems like a major loss.
https://www.bleepingcomputer.com/news/security/researchers-b...
https://googleprojectzero.blogspot.co.uk/2017/04/over-air-ex...
I do wish they would at least put out a 10.3.4 to fix the security issues, but I understand not putting the resources into a phone from 2012; I'm happy to at least have gotten 10.3.3 considering my Nexus 5 stopped getting updates last year and it was release in 2013.
I don't, but I have more sympathy for a company who quit supporting a phone from 2012 than a hypothetic [1] company who quit supporting a phone from 2015.
[1] Tho certainly a plethora examples would fit here.