Malwarebytes Analysis of Checkm8 iOS Bootrom Exploit
blog.malwarebytes.com
blog.malwarebytes.com
The 8 and 8+ are still available on Apple.com, I wonder if we'll see a hardware revision or if they'll prematurely take it off the store.
This is often overlooked in discussions about iOS exploits. Although 64-bit exploits gets the limelight for obvious reasons such as the possibility of being valid for current series of Apple devices, older 32-bit devices still being used in non-US countries shouldn't be discounted.
Apple devices often cost much higher than US in some of these countries, the difference was even much higher several years back when Apple didn't have dedicated stores in these countries.
Case in point : iPhone 5C was supposedly discounted ($550) when compared to iPhone 5S at the time of launch in US. In India, it was around ~$700 at minimum. To put that in perspective, that was a cost for a decent motorcycle in India which a family can use for at-least 20-30 years.
iPhone 5C can still perform basic smartphone tasks at ease, although it could be very vulnerable to exploits even for basic browsing[1]. But an average consumer in India, doesn't care much about the updates when their phone gets basic tasks done.
Even in first-world countries this is an issue. My employer continues to support iOS 9 in their app because the balance of the cost of continuing to support it versus the cost of losing those customers on an iPhone 4s or iPad 2 is justified. Even if we bump it up, it probably won’t surpass iOS 12 (to continue supporting the iPhone 5s and 6) for several years.
I wonder if this means they’ll continue supporting the 6s for longer than other phones, like the 5s which enjoyed 6 years and 6 major iOS releases of support. It feels irresponsible to know there are still millions of instances of a smartphone in active use around the world, that stopped getting security patches. When Apple released GPS fixes for older phones, as well as new updates for the old thin Apple TVs with UI that still looks like iOS 6, and recent iTunes Windows updates (which bundle WebKit and other Apple core frameworks), they didn’t backport any patches for vulnerabilities that are well-known in these older releases. The cost/benefit almost definitely doesn’t add up favorably when their business primarily relies on hardware profit margins, I know, but it still seems like a responsible thing to do.
https://9to5mac.com/2018/06/26/iphone-6s-production-india/ https://support.apple.com/en-us/HT201222
Especially, when advertising privacy & security as a premium selling point.
So Apple is knowingly selling a device with a publicly known hardware vulnerability. Apple is very much aware of the vulnerability because them fixing it is what caused the vulnerability to become exploited.
The issue is probably that the security team doesn't have much pull (if at all) when product lineup changes are made.
Why wouldn't you?
To each to their own I guess.
IMHO the hardware is quite capable. Meaning that it would be a very convenient headless server with its own UPS.
Similarly to custom ROMs for Android breath new life in non supported devices, I believe running Linux on an old iDevice would be simple way to get perfectly good hardware doing something again.
"I'm a Mac."
"And I'm a PC. Achoo!"
"What's wrong PC?"
"I have a cold."
"Huh, too bad. Macs don't get viruses."
"You never have any security vulnerabilities that get exploited?"
"Nope. Macs just work."
The End
(TBH, Chromebooks _are_ the most secure computers normal people can buy today. But ads like these cannot be recalled if shit hits the fan).
If you are waiting for devices completely free of any security bugs in the software and hardware, well, I hope you plan on living exceptionally long.
I'd say that this qualifies it as "secure by design" for anybody who understands what this is about.