Azimuth unlocked iPhone at center of legal battle between the FBI and Apple
washingtonpost.com
washingtonpost.com
- Apple unwittingly tried to hire David Wang, the creator of the exploit
- Wang instead went on in 2017 to co-found Corellium, a company specializing in providing "virtual" iPhones for security testing.
- Apple sued Corellium in 2019 for copyright violation. The discovery process turned up Wang and his work on the San Bernadino exploit.
This is how the article describes the exploit:
> Azimuth specialized in finding significant vulnerabilities. Dowd, a former IBM X-Force researcher whom one peer called “the Mozart of exploit design,” had found one in open-source code from Mozilla that Apple used to permit accessories to be plugged into an iPhone’s lightning port, according to the person...
> Using the flaw Dowd found, Wang, based in Portland, created an exploit that enabled initial access to the phone — a foot in the door. Then he hitched it to another exploit that permitted greater maneuverability, according to the people. And then he linked that to a final exploit that another Azimuth researcher had already created for iPhones, giving him full control over the phone’s core processor — the brains of the device. From there, he wrote software that rapidly tried all combinations of the passcode, bypassing other features, such as the one that erased data after 10 incorrect tries.
Things I'm for: targeted, investigative police work, for a specific crime, where it's highly likely the warrant issued will find specific evidence, and the crime is of violent nature.
Things I'm against: Warrantless surveillance by the FBI, CIA, NSA, Google, Facebook, your cell carrier, and friends
It's incredibly worrying that Apple is using the legal system to ban virtualization and pentesting software.
I am surprised and saddened that Apple is going down that route.
Does Apple have legal standing here or are they just using their warchest ($) to intimidate others into not following Corellium's example?
themolecularman is specifically asking for their grounds, I think the "copyright violation" claim is just in order to start the suit, not that they actually violated Apple's copyright in any way.
1. You need a license to use software
2. iOS is only licensed for use on bare-metal Apple hardware
3. Therefore, virtualisation is copyright infringement
4. Corellium makes iPhone virtualisation software
Of course, many hacker types would argue if you've got a license to something there's nothing morally wrong with format-shifting it to your heart's content, regardless of what the license or the letter of the law may say. Apple is probably relying on the courts taking a less enlightened view.
i would think that research, including security one, is a fair use with the virtualization being just a research device/tool in this case. Something akin to making an otherwise illegal copy to a different, more lab hardware specific format. Like say you have a copyrighted picture and you make some blow-up or X-ray photo of it for the research.
Meanwhile the PR damage or liability for having a security exploits running wild is massive. Corporate actions have no ethics or moral - it is simple bean counting for Apple. Any people who get part in this cannot lose their jobs no matter what is the outcome.
If Apple wins the case it would be terrible for the infosec community, every business that got pwned due to a 5 year old wordless exploit will be able to sue Rapid7 which would quite likely mean that Metasploit will be too much of a liability to maintain.
On what basis were you viewing nmap as a potential target for lawsuits?
https://abcnews.go.com/Technology/us-government-jailbreaking...
The FBI didn't need to unlock the phone, most likely. All iPhones in their default configuration back up the ~entire contents of the phone to Apple each night, with Apple keys. Apple can decrypt this without the phone, the user, or the passcode at any time, invisible to the user.
Apple preserves this vulnerability for the FBI, at the FBI's request:
https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...
Apple turns over this data without a warrant frequently (over 30,000 users in 2019) according to Apple's own transparency reports. They also turn it over in response to warrants, as they have plainly stated that they did in this case.
You don't need access via the front door if you have it via the back door.
Whether or not they got into the specific phone (or backup data) possessed by the San Bernadino shooter is irrelevant: that prosecution has almost nothing to do with the contents of their telephone(s).
The narrative that is being pushed in the media, as a result of all of this, is that Apple devices are safe and secure from government snooping, even with a warrant. We know this to be false, and more people should know this to be false.
It's even false without a warrant, as all iCloud Backup data is subject to FISA/PRISM at any time, and this comprises the vast majority of the data stored on all iPhones in the world, no probable cause needed.
The whole thing is an explicit manipulation of the media, undertaken Apple and the FBI in concert, to protect Apple's brand image. It appears to be working.
Anyone know what software (library?) that is referring to?
Firefox OS phones didn't have Lightning ports, so it's not clear what code from Mozilla Apple would be using for that. It seems possible there was a mixup with some other MPL licensed software or the "NS" and "NSS" naming that both Mozilla and Apple use.
"Netscape Security Services" (NSS) is one of the Mozilla libraries that's (somewhat) widely used by other software, and would be a candidate, but I've never heard about Apple using it.
Does Mozilla have some sort GLib / Apache utils ?
https://www.businessinsider.com/john-mcafee-ill-decrypt-san-...
https://twitter.com/pandrewhk/status/1381260920635027459?s=2...
It doesn't matter if an exploit has been patched if the phone in question has been maintained offline for a year or two.
That claim by the FBI was obviously made in bad faith to begin with for the San Bernardino shooting. Of course the shooter didn't store some kind of incriminating communications or plans on his work phone, there was never any rational explanation for why he would have done that. They destroyed their personal phones entirely but didn't even bother to reset their work phone. Add to this the fact that a law enforcement screw up is what originally locked them out of a recent iCloud backup to begin with and they already had access to everything else that was in iCloud before they reset the password. It was painfully obvious that they were pushing hard behind "But TERRORISM!!!" to either set a precedent or get a signed build of iOS that bypassed any protection from brute force attacks.
Also, if this is the work of the investigation by WaPo reporters, it would be better to post a link to WaPo than some other news agency reporting on a WaPo report.
Musicians: The Whitlams also give you lots of points.
But "Australians are the best"? Nah... when you invent the next 'pizza' we may promote you to top10.. but not before that! :)