The only exception to this is the checkm8 vulnerability, which can be performed on an A11 and older chips (so iPhone XR/XS/XS+ and 11/11 pro/11 pro max aren't vulnerable) from DFU mode, which doesn't need the device passcode.
The only exception to this is the checkm8 vulnerability, which can be performed on an A11 and older chips (so iPhone XR/XS/XS+ and 11/11 pro/11 pro max aren't vulnerable) from DFU mode, which doesn't need the device passcode.
Is that true?
Could one somehow enable updates through pure TCP/IP?
Maybe same for Android?
Except that you'd arguably want to update it locally with the Copperhead OS.
> If your computer can’t communicate with Apple's software update server, you might see one of these messages.
The carrier setting thing hasn't ever been use for a jailbreak exploit AFAIK so chances are it's not a good attack vector.
From your other comment:
> But it mentions the option of wiping baseband firmware
iOS also has signature verification for its baseband, since trying to load an incompatible one during a downgrade[0] breaks Face ID / Touch ID.
But ya, this is all "trust apple to not do anything". They've made a good stance with refusing the FBI request[1], but the FBI got into the phone anyways[2].
0: https://github.com/tihmstar/futurerestore
1: https://news.ycombinator.com/item?id=11116274
2: https://venturebeat.com/2016/03/28/u-s-government-gains-acce...
And under what circumstances does the phone leave airplane mode, and go back online.
But even if that were solid, you'd still be ~unable to install apps that Apple doesn't provide. Unless you play the developer game, and I gather that's limited in app number, and how long they'll stay functional.
I mean, if Apple says airplane mode turns off the cell radio, that’s a falsifiable claim, so you don’t have to take it entirely on faith. It might be possible to hide it in the UI, but you can’t hide a radio signal.
Say you set airplane mode. And then the phone sleeps. Will it still be in airplane mode after you wake it?
Or say you shut the phone off, and restart it. Is it still in airplane mode?
That's an issue because, as soon as it's not in airplane mode, it knows where it is.
And that reminds me, does airplane mode disable GPS? Because if it doesn't, it's more or less pointless, from a geolocation perspective.
>Or say you shut the phone off, and restart it. Is it still in airplane mode?
Yes.
>And that reminds me, does airplane mode disable GPS? Because if it doesn't, it's more or less pointless, from a geolocation perspective.
Why does that matter? You can turn location services off. Moreover, GPS functions passively. Turning it on doesn't transmit your location to anyone.
> Why does that [GPS] matter?
GPS matters because it's important that the phone doesn't know where it is. I mean, if it doesn't know where it is, there's no need to worry that adversaries will access the information.
> You can turn location services off.
Off entirely? Even for the OS? Or for rogue apps?
> Turning it on doesn't transmit your location to anyone.
No, but it generates location information that could leak. And if the phone uses WiFi to supplement GPS, it necessarily communicates with some remote server.
So your threat model is that you can't trust the device itself? If that's your threat model, you'd probably need a phone with hardware kill switches. Also, if you can't trust the device itself, why would you be carrying the device around? What would you use it for?
>No, but it generates location information that could leak. And if the phone uses WiFi to supplement GPS, it necessarily communicates with some remote server.
On android you can explicitly disable that ("device only" in location settings). There's no such option on ios, although you could still disable wifi/bluetooth and still have working gps.
Yes. I don't trust a phone OS where I lack root privileges. And I entirely don't trust the baseband.
> If that's your threat model, you'd probably need a phone with hardware kill switches.
Yes. Or with disabled GPS, baseband and WiFi. And with Internet connectivity via external WiFi router, or cellular modem/router.
> Also, if you can't trust the device itself, why would you be carrying the device around? What would you use it for?
I'd use it as a phone. Albeit just using VoIP.
And if I had all the iffy stuff in a separate device, connected via USB, I could trust the phone as much as I trust the host machine I'm using now.
I mean, I'm working in a Debian VM that hits the Internet through a nested VPN chain. And the Debian host has no access to GPS or WiFi. So I'd want to replicate that on a phone.