Meet Comex, The 19-Year-Old iPhone Uber-Hacker Who Keeps Outsmarting Apple
blogs.forbes.com
blogs.forbes.com
"After Allegra released JailbreakMe 2 last year, Apple upped its game another notch, randomizing the location of code in memory so that hackers can’t even locate commands to hijack them." Another security method, and one that some people ripped on Apple for not including for so long. Now they put it in and it's a paranoid response to stop jailbreakers?
Listen, there's no legal issue with jailbreaking. That issue has been settled, as much as it can be without a lawsuit and a court ruling. But Apple is under no obligation to make it easy, or to leave gaping security holes for jailbreak tools to waltz through. We need to stop acting like Apple is persecuting jailbreakers, when what they're really doing is fixing security holes.
I thought that was pretty clear.
If you jailbreak but continue to make phonecalls, use the AppStore, etc. are you in breach of any of the contracts you signed or licenses you agreed to?
Plus, if he jailbreaks devices because he believes people should be free to do with their hardware as they please why on earth would he effectively join the dark side?
Money.
> "How would comex rid Apple's entire development process of error?"
It wouldn't - but finding exploits and security holes isn't a matter of course. There aren't altogether that many people who have the talents for it, much less the ability to package it into a coherent tool that normal joes can actually download and use.
I have a feeling that there are few enough people who fit this description that Apple can effectively buy them all out.
That's why I hedged with "temporarily". If he's the best that's working on jailbreaking now, just taking him off that project would already help. And asking him to work to secure phones would be a great help, too - he could spot potential vulnerabilities before they're shipped.
This won't make the iPhone into a space-shuttle, but it will make jailbreaking harder, perhaps significantly so.
> Plus, if he jailbreaks devices because he believes people should be free to do with their hardware as they please why on earth would he effectively join the dark side?
They'll drive a dump-truck full of money up to his house. Or maybe there's something else he values more than the belief in free hardware.
Also, even if JailbreakMe was malicious (or somebody used the same code or exploits in a malicious way), it could not "spread itself": it was a browser exploit (although it would be possible to run without the user knowing).
It could certainly spread. Maybe it could SMS a link to a malicious download to your most frequently contacted contacts? Being able to run arbitrary code on a device that knows how to contact all your friends certainly introduces some vectors for attack.
See the first of the 10 Immutable Laws of Security: http://technet.microsoft.com/en-us/library/cc722487.aspx
It probably wouldn't be an easy decision for Comex either... I recall that hacker that turned down Sony's offer. What could happen to your hacker freedom once you're at your employer's mercy? And if you leave Apple someday, forget about jailbreaking any other Apple device for as long as you live due NDA's and all the legal stuff he would have sign.
He designed none of the interface.
> '... his obvious coding skills ...'
A lot of the time, a person's coding skills are judged by how readable their code is, and how well they utilize SCM. Also, to be an Apple engineer you want extensive experience with Objective-C. https://github.com/comex/star_
Now I don't mean to say comex is a bad programmer at all, the stuff he writes is amazing, I just feel like he wouldn't make a good Apple engineer.
Comex may not fit the profile of an Apple engineer, but I think he'd still do a damn good job as one.
Once the attacker (again, the owner of the phone who wants to jailbreak) has possession of the phone, he has complete control over it. I wonder if Apple has this internal posture that they should make appearances of caring about jailbreaking (for the benefit of the carriers and their contracts) but actually it's not such a big deal.
Hell, their AT&T contract was probably the only reason they got super up in arms about it anyhow.
The reason Apple closes the security loopholes is that they are security loopholes. It's not some sort of arms race. It's securing their platform.
Notice they have a pretty effective iBooks test for Jailbroken devices, but they don't deploy it widely, etc. I think they're at peace with the JB community as sort of a free research lab for them (hell, on device 3rd party apps came from the JB community first!) and use them to fix security holes in their platform as they are revealed.
Well, it's not that effective; it was worked around within days of showing up. Interestingly, to my knowledge, Google's similar check to prevent rooted devices playing movie rentals hasn't been worked around yet.
Defending against physical access-based exploits is likely always going to be ultimately futile, though.
1. They patch the bugs that, e.g., allow jailbreaking through a webpage or pdf (since those are genuine bugs could be used maliciously).
2. A device comes locked "out of the box", and can only run signed code (so that the vast majority of people need to use the App store).
3. They don't have to support jailbroken devices (so if you install an app on your jailbroken phone that doesn't play nice, it's not their problem).
Looking at sales figures for the app store and iTunes, would you honestly say that Apple's code-signing and other DRM techniques have "failed"?
If you can, then Apple explicitly working to close security holes, not providing a sponsored jailbreak solution, and letting people work on exploiting security holes, seems pretty damn absurd.
No, you're right I can't list names. Apple does not approve of the OSx86 project.
I hate when bullshit business rags ascribe a quality like “obsession” (with the connotation of OCD or some sort of mental imbalance) to a booming business like Apple. As if they know better in this matter, despite the way Apple’s competitors in the market are making crazy little money in comparison…
Before I saw this article, I honestly had no idea he was Comex. I could tell he was brilliant, but that's pretty awesome.
JailbreakMe’s sophistication is on par with that of Stuxnet
No kidding…Edit: Forgot to add the link to the source code https://github.com/comex/star_
this is the most important part of the story
He plays it up in that quote from his article, but it turns out getting the name was /trivial/: comex had a public Facebook account, in his real name, using one of his standard usernames. It is actually likely that he got the name before he even realized it was supposed to be "secret".
In fact, I even joked "fair enough; you know, I've never actually looked, but for all I know his personal domain name is registered to his home address by his mother or something": it turns out it literally is.
(It should also be noted that comex has agreed to talk to reporters before, such as for an article published by Reuters.)
Forbes shouldn't be chastised over releasing his name, and anyone who thinks that blackmail or anything of the sort played a role is just being silly.