imessage and facetime have been a constant source of exploits.
imessage and facetime have been a constant source of exploits.
This seems to be functionally much like Python’s pickle, Boost.Serialization, Java’s object serialization, etc. These techniques seem clever, and they are genuinely useful for prototyping and for certain applications that inherently have no security concerns, but they are not at all suitable for network use. Fundamentally, for network use, one should define a data format, an API, etc and implement it. Using object serialization is backwards — it’s writing the code and then asking a framework to magically network it, and the result is that it networks it too much.
(There are a few systems for writing code and a network protocol simultaneously that treat security as a first-class consideration. The E language comes to mind. I still wouldn’t use E objects to represent data for interoperability reasons if nothing else. But ObjC is not E, and Apple’s design is inexcusable in 2020.)
Will be interesting to read a write-up.
I think Apple could address this for real is one of two ways. They could replace the protocol entirely, or they could treat the existing baroque protocol like any other network protocol and write a grammar and parser for it.
As an analogy, suppose you had a wire format like XML, and you had the clever idea to process it in a dynamic language like Python or ObjC by looking up each tag in a list of all known types and trying to instantiate it. Sure, it would work, and you would be exploited all the time. NSSecureCoding limits the available types to a large and apparently still open ended list instead of literally every type that the deserializer can make sense of.
For an attack like this you need to chain an iMessage exploit with an LPE, and the LPE can be launched from any other app.
They’ve also never devoted enough care, resources, or money to network architecture and how important availability is (with fairness, they have improved in this area in the last couple of years due to the major iCloud outages they had).
Apple doesn’t hire mainstream IT people and cybersecurity people from the enterprise realms. There is a vast amount of talented people and knowledge they simply ignore because the Apple culture is too hip and cool for that.
Steve Jobs is primarily the blame for all the above. He treated the departments and any person that cared about enterprise like dirt. Steve Jobs always said Apple is a consumer company. This philosophy has obviously carried on.
I always figured the industry never really rewarded those things over aspects (e.g. time to market).
Which tech companies devote enough care and have competent personnel working on embedded consumer device security?
Answer: Apple and Microsoft (Xbox group).
(Google is nowhere close because they don't design their own silicon, and the OEMs they rely on are incompetent in this field, so their efforts can only go so far, no amount of hiring competent sec folks will fix that problem).
They are, indeed, not "IT people and cybersecurity people from the enterprise realms", because those would be wholly unqualified to work on iOS security. The people actually working on iOS security are hackers and embedded security experts. As they should be. The enterprise cybersecurity world has approximately nothing to do with something like security of a mobile device (e.g. the people in that field wouldn't know the slightest thing about cutting edge exploit mitigations or hardware assisted countermeasures like pointer authentication, memory protection and IOMMUs, etc).