Websites have been quietly hacking iPhones for years, says Google
technologyreview.com
technologyreview.com
> Apple patched the bugs quickly in February 2019 so everyone who has updated their iPhone since then is protected. Rebooting the iPhone wiped the malware but the data had already been taken.
Why in the world did they silently fix the issue and remove the malware? I'm fine with all of this, but shouldn't they disclose to the user "hey, some very sensitive data from your device has been taken. It is passwords, messages, etc." so that users could at least try to mitigate the impact somewhat (contact their contacts, change passwords, maybe change numbers, etc.)?
Please read the original source at https://news.ycombinator.com/item?id=20835223
So if you don’t tell me I need to reboot my iPhone, I won’t.
I can't see how any software provider (ie Microsoft, Linux, Google... ) will say "install this patch to fix this and you may or may not been hacked, good luck"... They just provide the patch.
Consider a lock manufacturer that has a key copy of each client. If someone enters in the building and steals all the keys, clearly the manufacturer should inform all their clients. But, if a vulnerability has been found in a lock model, the manufacturer can tell you about the vulnerability, but definitely they can't tell you if your house has been robbed that way (or if it has been robbed at all).
Anyway, with this story alone and without knowing if you have visited these webpages that allegedly hacked your iPhone (why aren't they listed?) the only thing you can do is renewing passwords in your most critical accounts.
It’s not big news when it happens all the time.
What is big news, that’s gotten lost in all the noise, is that Google (through it’s crawling of the web) has been able to identify that some websites were (are) indiscriminately jailbreaking iPhones for the purposes of stealing user data.
This is the kind of thing that is routine on Windows, is likely to be routine on Android (given how many unpatchable devices are in use) but wasn’t considered to be routine on iOS.
The takeaway from all this is simple: if you’re not fully patched, you’re at significant risk. It doesn’t matter which platform you use.
This is part of the reason CVEs and security bulletins exist. We're being notified about potential issues all the time by many vendors.
But CVEs are intended for specialists. "Users" don't know about CVE.
It's not bad for the phone, and whether it's bad for the battery depends on the battery technology. In fact previous battery technologies were recommending the occasional full drain!
For lithium-ion batteries the kind used in the iPhone draining to 0% can indeed strain them (though less than you think, as shown by research), but the iPhone doesn't let them go to 0% anyway. It switches off way before that (even if it shows it as 0%). Mind you that regular use cycles (defined by Apple as using 100% of a full charge, even if it's broken down as going from 100% to 80% for five days and recharging) also strains the battery. You cannot not strain it, all current technology batteries degrade over time.
Also note that getting lithium-ion batteries to 100% and keeping them charging can also harm them (although modern devices have mechanisms to prevent that). In general it's advisable to keep going from 80%-20% and back, than to go all the way to charged (or down to 0). Same, one should not store long term fully charged.
But most of this is irrelevant micromanagement unless you plan to keep your phone for years and don't ever consider replacing the battery. Even so, the battery lifespan vendors like Apple give is around 3 years of cycles.
All in all, you can fully drain your lithium-ion iPhone battery as often as the average person does (e.g. just avoid doing it all the time), and you'll see no special degradation. It will run its cycles and will degrade by regular use after a few years even if you never let it drain (and you can trivially replace it with a new one).
Why should we trust your statements over ones like these which seemingly are backed by more data and and explanations of the underlying physics?
[1] https://batteryuniversity.com/learn/article/how_to_prolong_l...
More importantly, that such tracking is marginally useful micromanagement (and, Apple's artificial throttling for degraded batteries aside, has nothing to do with affecting a device's speed. A 90% charged device is not magically faster than a 20% charged one). Apple itself, in their document about battery technology and care ignores the "fully drain" issue completely.
Sometimes I wonder if the windows 10 auto-update fiasco was really about people who rarely recharge; and finally charging their laptop the one time they needed to be prepared, only to get owned by Windows Update at the worst time.
I wish there was a good way to report it, neither apple or twitter seem interested.
If Im just browsing I use the mobile web interface since it's just better anyways.
Seems people are going out of their way to let Apple off the hook for not disclosing to the user a major risk and silently fixing it.
1) the GP quoted the part about rebooting wipes the malware. But that doesn't matter if the info was taken before the user rebooted. So this comment is really off topic.
2) the GP comment is about letting users be aware so they can help mitigate the problem and assess the threat level. For example, users need to change their passwords. If you've ever worked with any government agency their number one concern is not leak of data, but knowing what leaked (obviously they want to minimize that). Knowing what leaked is extremely important. This is what the comment is about. I don't understand how your comment addresses this.
"This is the angriest $1500 I've ever spent on a brand new iPhone, but I will probably do this again next year," says one iPhone user.
Apple is not intentionally removing malware themselves, and AFAIK they don’t have the ability to tell if a device has been compromised.
I’m not yet ready to crucify Apple for not issuing a press release listing sites and services affected. Same with the Google “deep dive” with it’s vague insinuations.
I suspect this is a big international incident like - “China bought hacks from Mossad to target Hong Kong” kind of big. For all we know there are gag orders in place and an ongoing investigation.
I will still use iOS devices too. They are still the most secure consumer available/friendly computing devices available imo. That said, I want to know more.
Also, from a broader point of view - is there any way to perform static code analysis and enumerate all code paths that access sensitive resources? For example, create a graph of functions and search for edges to and from the keychain. If one path ends up in a WebGL content renderer, that’s a vulnerability. I feel like this especially would help you enumerate most exploits and zero-days.
> is there any way to perform static code analysis and enumerate all code paths that access sensitive resources
This starts to get towards something akin to the halting problem. Not exactly, but you can sort of intuit why this doesn't work in practice. The combinatorial explosion kills you.
Current static analyses are imprecise, while dynamic analyses require actual execution which can be difficult.
Modern research is looking to combine the two. Rather than brute force fuzzing (dynamic analysis), static analyze the source to better mutate the input to a few potentially interesting cases.
I would go so far as to say in any non-trivial codebase it's virtually impossible to avoid introducing a bug of this nature. SQLite is probably the codebase that has the highest chance of being safe from this, due to its extremely thorough test suite and amount of fuzzing that's been done, but even that codebase was found to have a significant bug (I forget the details) in one of the optional first-party extensions, as that extension did not have the same rigorous test suite that the SQLite core did.
To be clear, when I say thorough test suite, IIRC SQLite's test suite has 3x as many lines of code as the code being tested. And I think there's some sort of instrumentation to ensure the test suite covers every single code path.
It’s kind of testing every possible valid, invalid and malicious input the program can take in.
Gets even crazier with race conditions and such.
Testing is really hard. And given how many companies skip on testing I am led to believe security is a myth. There’s gonna be someone somewhere with an exploit getting your info.
Actually it has a shocking 662x as many lines of tests as it has code[1].
I agree though, SQLite is an amazing piece of software.
C++? In C++ that means take C, make it better but use the original.
Give me a strongly typed language and check for overflows and the like!
Also, sometimes your design make it difficult to keep track of your memory because you share pointers to different processes and classes and you usually make this interactions to be efficient and fast.
Basically, if you are a beginner, building easy things in C/C++, you can stick to the basic rules so you never fall in this kind of traps, but if you are an expert focusing in optimization (or time sensible applications) sometimes you make assumptions or rulesets so "you can't use this class like this", "you can't never pass a pointer with less than 64 bytes allocated", and after a couple of months and some people and hat changing they end up making mistakes...
This might sound somewhat irrelevant, but are you a native Spanish speaker (or typing on a Spanish keyboard)?
And apparently this one works until iOS10 : https://www.theiphonewiki.com/wiki/TotallyNotSpyware
People do “deep dives” of exploits all the time, the amazing thing about this particular one is that it gets to the keychain and is via a website.
Aren’t there tools that can analyze existing code and enforce memory safety?
Not perfectly.
Should have used a link previewer. It went to a porn site that looked....odd. Like one big static image mimicking a porn site, nothing clickable.
This was a couple years back. Always wondered about it. Does it seem remotely likely it was some kind of exploit that may still be running on my phone. Have upgraded since and am fully updated.
Note: THIS exploit is removed by the patch. Am wondering if this is a reasonable worry in general that would warrant wiping the device and restoring photos, messages etc via icloud sync rather than a backup.
If it was indeed this exploit, they had your data at that point already though. No action will undo that, but changing secrets might help.
Does this include 1password passwords? As far as I understand 1password encrypts the passwords and they can only be accessed either by supplying the master password or the fingerprint.
But 1password is not in the default list of apps to steal (https://googleprojectzero.blogspot.com/2019/08/implant-teard...), so you'd have to know what commands their server sent to get a definitive answer. Most likely they didn't bother, as it seems more like a surveillance / monitoring operation than for financial gain, but then again attackers are getting more sophisticated all the time.
It's definitely stored for Touch ID/fingerprint 1password access though (https://support.1password.com/touch-id-security-ios/).
One of their employees wrote about it here: https://discussions.agilebits.com/discussion/106629/ios-secu.... His response is basically that OS-level 0days aren't in their threat model, so they're continuing their usual bug-fixing routine. And it's true, nothing can really stop a rootkit from sniffing passwords as they're being used, besides winning the anti-rootkit race. Perhaps 1password could have a little more explanation of the insecurity of using Touch ID / Face ID though rather than simply saying it's as secure as possible.
https://stackoverflow.com/questions/11259152/chrome-ios-is-i...
I haven’t seen other browsers mentioned anywhere.
https://support.google.com/mail/forum/AAAAK7un8RUqYupi59QYXM...
https://web.archive.org/web/20190322185231/http://edition.cn...
Well then if you use Linux, it's pretty secure. But most money goes into headless servers.
Do you trust the GNOME project, is it well funded? Or KDE or whatever.
Actually fundamentally. Do you trust the X Server?
More relevant: Do I trust SSH? My browser?
The discussion was on phones, there the issues are mostly core Android's lack of updates from manufacturers (but quite good record of Google releasing patches) vs iOS's closed-source buggy OS.
IDK, security is hard. The easiest solution is to get a nice clay brick and smash whatever phone you have to pieces.
How about nVidia with their 5 security issues: https://www.bleepingcomputer.com/news/security/nvidia-patche...
Checkpoint Endpoint AV that allows escalation to admin because of failing to verifying their DLL files: https://safebreach.com/Post/Check-Point-Endpoint-Security-In...
How about Intel with Spectre issues which are still ongoing? Speaking of Intel, their SGX isn't as secure as it could be: https://www.zdnet.com/article/researchers-hide-malware-in-in...