As someone who used to jailbreak back in the day, this news was really exciting. However looking at it in a mature way than I did back then, it’s also slightly worrying that a whole class of iOS devices have a severe and unpatchable security flaw.
As someone who used to jailbreak back in the day, this news was really exciting. However looking at it in a mature way than I did back then, it’s also slightly worrying that a whole class of iOS devices have a severe and unpatchable security flaw.
"Severe" is a bit over-dramatic. To be accurate, from the article:
Checkm8 requires physical access to the phone. It can't be remotely executed, even if combined with other exploits
The exploit allows only tethered jailbreaks, meaning it lacks persistence. The exploit must be run each time an iDevice boots.
Checkm8 doesn't bypass the protections offered by the Secure Enclave and Touch ID.
Agreed. The hyperbole yesterday was millions of iPhones now have no security which does not seem to be the case. For the average user nothing has changed. For the paranoid, reboot the phone if it ever leaves your sight.
If you suspect your device has been tampered with and need a guaranteed reboot, just let the battery run down and don't use it until it has.
Just a (overly paranoid) thought: a sophisticated attacker could simulate a drained battery and subsequent reboot, no?
See: https://support.apple.com/guide/iphone/force-restart-iphone-...
Not going to lie: I do place a significant level of trust in Apple's statements regarding their security architecture / model.
Having a completely 100% untouchable ROM is very valuable. Yes, this kind of exploit being permanent is the downside, but then they don't have to worry about the modification fuses being misused in any way ever.
You don't 'flash' a fake ios; you can use the bootrom exploit to put your modified version of ios into memory, and once you reboot you would get back straight stock ios. They could even make it reboot as soon as the password was harvested, leaving behind no trace. This is scary stuff. You can keep yourself safe by rebooting as soon as you get your phone back from border patrol, but many people would not know to do that.
Ownership is the state of exclusive rights and control over property, which I don't have when I buy an Apple device. Either they shouldn't say they're selling it (they can say they're leasing it to me) or they should give me all rights.
I like to think of “owning” in the developed world simply as a right to collect rent from someone else.
Are any of these restrictions there so a private third party can decide what you do with your property?
At least, that’s true in at least one state in the USA.
Also the developers and architectural controls can make decisions affecting what you build (down to the color you paint outside), before they turn things over to the city.
All subject to local laws of course, so may vary city to city.
I don't know what people aren't getting about this. You bought a computer that can only run code that Apple has explicitly approved. How is this ownership?