If you have reason to believe you're targeted by state-backed intelligence agencies, you really oughta be working under the assumption that they can see everything you're doing.
If you have reason to believe you're targeted by state-backed intelligence agencies, you really oughta be working under the assumption that they can see everything you're doing.
From processor, to boards, to OS, to the walled garden of apps.
No other tech has that level of control.
Think of the controversy surrounding the Intel ME and other “secondary processors”.
Not an issue with the IPhone (from Apples perspective).
When Google decided they wanted to control all the computing on their servers, from bare metal up, they ran into the ME.
Apple is the only key civilian entity with that level of control.
Google has this stack control in Android, Google Home, Chromebook, etc trivially if it chooses, if it doesn't have that already.
Microsoft can do this on its Cortana smart speakers and Surface Pro X running their (Qualcomms) ARM cpu.
Also I imagine bulk buyers can get Intel ME disabled if they don't want it on their server. AMD PSP can be disabled in the BIOS I believe.
Comparing a phone to a server doesn't make too much sense. A phone is a consumer product like Android or Home and a server is a business product. Apple runs its cloud on Intel or AMD like everyone else.
Wat?
Apple's icloud is partly their datacenter running a mix of systems/hardware and renting out Amazon and Google cloud units, which are Intel/AMD.
Google populates it's datacenters with their own servers. So does Facebook. So does Amazon. Netflix builds their own CDN appliances. Apple absolutely could if they wanted to.
Buying a beige box to put an intel chip is not "your own" servers in the context of this discussion. I'm not sure why you're so rude and confrontational here. We're discussing how Apple has top to bottom control in its consumer devices, not some weird discussion about datacenter packaging. Servers run on AMD/Intel and as such are stuck with the elements of those platforms AMD and Intel dictate. That's not having the entire stack to themselves.
Using today's MacOS as a server is an exercise in pain, largely because there are a number of routine server administration tasks that fundamentally require the GUI in MacOS.
This is untrue. Textbooks on type theory (Pierce’s TaPL comes immediately to mind) will state early on that well typed terms cannot always eliminate all undesirable states.
In fact, there is a tension in encoding all your constraints into the type system (at which point you become a mathematician proving theorems) and producing programs that are actually useful to other people.
it is the height of ridiculousness to ever think you can use anything with the surface of something like a modern phone and be safe against a state. ridiculous. i’ll say it again. ridiculous.
threat models exist for a reason. if anyone ever implied that an apple phone or an android, or pc were safe against this model, this person is a lightweight and you should run fast and far from their advice.
if you’ve ever told people they were safe against a state actor with a smart phone, you need to immediately reevaluate what you do and what you do not know. immediately.
no serious person—including apple themselves—ever made the claim these devices were safe against state determined actors with an off-the-shelf device you can grab from best buy on your way home from work.
It’s constantly connected to uncontrolled networks, constantly downloading media, possesses microphones, cameras, gps, etc
Basically gathers tons of info, and is connected to the internet always and everywhere.
I’d say strong incentives plus unlimited funding.
What they do have is patience and secrecy.
For state attacker the model breaks. The value of a target can be very high. And the available resources - financial, technical, other - are there to fill the budget.
They way you put it, these people fired up a quantum computer and broke the users password hash. What they actually did is the equivalent of an activex control owning a machine in a drive-by attack.
You have no goddamn clue if this is correct or not. Your keys may be compromised, your computer might have spyware on it, your messaging client might be backdoored.
> when Apple, in fact, explicitly allowed remote code execution by untrusted actors
Can you please elaborate what do you mean by that?
If a hacker wants to scam people out of their savings they have a limit on how much money they can potentially earn. I don’t know what the actual numbers are, but let’s say an attacker can hope to extract 100k USD from one in every 10k prospect. If those are the numbers then the attacker can’t waste more than 10 dollar on any individual targets on average or they would start loosing money. I suspect the real numbers are even worse.
On the other hand if you work for a state and you burn a few billion dollars to research some zero day vulnerabilities which you then use to delay the weapons development of your adversaries by a few months you get a medal. Or maybe you don’t but one thing is for sure the state won’t collapse just because of this.
What does it mean in practice. Imagine a scenairo where you left your smart phone at the side of your bed for the duration of a bathroom trip. You return and you look at your phone. Can you trust that the phone on the side of your table is the same you had earlier?
It is absolutely 100% sure that the would-be-savings-scammer doesn’t have the resources to camp outside of your bedroom, monitor your comings and goings, sneak in when you leave the room, swap your phone and leave unnoticed. An operation like that costs serious money.
But if a state put in their collective head that their national interest is best served by your phone being swapped then the above can and will happen. They have the resources to do it and they don’t care about “ROI” in a traditional sense.
Now will a state actor sneak in to your bedroom? Probably not, because there are lower hanging fruits to achieve the same cheaper. For example by paying a batalion of nerds to find zero day exploits in complicated software.
The thing about states is that they are higly uneven. One can have slow and inneficient burocracy and crumbling infrastructure and failing healthcare yet still pursue some other goal with dodged persistance. And the truth is if someone decides to spend a billion dollar to hurt you you will be hurt, if they decide to spend a billion dollar to know your secrets your secrets will be known. States can be both bumbling idiots and godlike entities at the same time, maybe even in the same building.
My comment was only about explaining what makes a state level adversary formidable.
Its fun looking at the hardware, wondering what else a component can be made to do besides its obvious legit function.
The Apples preinstalled apps, and default behavior meant the attackers could rely on certain behavior once they were in.
Apples standardization is what got them.
Control doesn't guarantee security, it just assesses accountability. Also, control doesn't mean Apple writes all the software. They outside code like everyone else.
Maybe it shows that even Apple doesn't have the resources to do it, and therefore nobody does.
Then at the end of the day, customers are still installing 3rd party applications, so does apple have to walk all of their code too?
Apple rarely has to “just trust” a part of its stack.
https://en.wikipedia.org/wiki/Intel_Management_Engine
From the Wikipedia article:
The Intel Management Engine (ME), also known as the Intel Manageability Engine, is an autonomous subsystem that has been incorporated in virtually all of Intel's processor chipsets since 2008. It is located in the Platform Controller Hub of modern Intel motherboards.
The Intel Management Engine always runs as long as the motherboard is receiving power, even when the computer is turned off. This issue can be mitigated with deployment of a hardware device, which is able to disconnect mains power.
The Intel ME is an attractive target for hackers, since it has top level access to all devices and completely bypasses the operating system. The Electronic Frontier Foundation has voiced concern about Intel ME and some security researchers have voiced concern that it is a backdoor.
Why not go AMD or do they do something equivalent to the intel ME?
The best we can hope for is using the best tools and practices we have available to make it as hard as possible to make mistakes and therefore as hard as possible for attackers to find exploitable bugs.
In reality tho, that's not really what happens. We still use C (and C++) for example (and other footgun-languages) and/or run billions of lines of badly audited "legacy" code (that wasn't written with the threats we face today in mind) in a lot of places for various reasons[0], and then try to use all kinds of tools as work around to detect past and new mistakes or at least mitigate the severity of outcomes when mistakes happen and are uncovered and exploited by adversaries[1].
And that's not even yet considering supply chain attacks, be it software or hardware ones.
That isn't to say that Apple couldn't still do a lot better...
"Beware of bugs in the above code; I have only proved it correct, not tried it."
[0] Such as maintaining legacy code bases, "performance", interoperability, development speed, developer availability, business ("cost") considerations, etc.
[1] Starting with code reviews, code coverage, unit tests, static analysis, fuzz testing, etc, and then later at runtime ASLR, canaries, retpoline, sandboxes, etc.
When people say "state-level hackers", they appeal to authority like "the state" is something one simply can't win against. And those employed by the state are super-level Uber-hackers. But in reality what it means is:
A state is able to waste billions on mistakes and incompetence. The state gets away with most projects failing.
In reality forensics and post-mortems show the adversary's understanding of tradecraft, opsec and technical understanding of the space was so bad, it's _not_ skill but luck why they won.
There is very little "advanced" about an APT other than unlimited pockets. If you have unlimited pockets you're more likely able to brute-force your way to winning.
state-level is such an opaque concept because of the huge numbers of actors in it, that never get credited. People like systems-thinking and the idea of everything being planned and orchestrated like in a Hollywood movie. And they we forget in many "bAd coUntTiEs" it's a collaboration between criminal enterprise and state enterprise. It includes thousands of "criminals" who can be leaned on or are willing to lean on others. There is also the private-public partnership in some of the more functional countries[1] that adds thousands to this group of people.
the term "state level" is almost useless. It is the language of PR and propaganda. If taken serious as a concept it just means an entire different country.
And this is why it's saying "unhackable": When one expects a security guarantee to defend against such a large group of diverse actors (or not even being able to identify the adversary in the first place) then to fulfill that promise it will have to be "unhackable".
[1] Australia has a gag-order where you can't even warn your employer when they force you to implement a backdoor in their products.
That's not really relevant. The American intelligence apparatus controls their entire stack too, ordering and autiting custom versions of professors and such.
Consumer products are in a he unenviable position of trying to combine things that don't combine well.
Rewriting the stack in a safe language would take years (25+ years of code to rewrite).
Saying the vast majority is on ux+flash, is the super common mistake: you don’t see any of the work that is not in the UI portion of an app, that doesn’t mean that’s not getting huge amounts of work.
I am not sure how secure a Nokia 3210 really is, but I could phone and text with it even today I expect. The users are rare, and that is not accidentap
For me, it's fine if they lose some battles, but they should budget to win the war.
It is far less unrealistic than you think.
Scale numbers to make better financial sense.
Now, one would think there are already more non-NSO security researchers than NSO have, who earn money from bounties and report issues to Apple. Yet NSO has a business model. How?
0: https://jobs.apple.com/en-us/search?search=%22red%20team%22&...
Because Apple's security is actually pretty bad, making their job easy.
No they can’t. If Apple could, they would deploy their war chest billions to do so. People often make the mistake of thinking some objective is money-constrained, and a place like Microsoft could’ve just thrown the most money at mobile in 2008 to be the best mobile OS.
The Israeli’s in these national security level positions work like their life depends on it because they literally believe it does. Good luck replicating that with a gazillion teams of cushy big tech Silicon Valley positions.
NSO makes money reselling the same set of productized exploits. Their business model depends on no one else (apple or other researchers) finding it. Selling an exploit gets you a single payday, selling a service lets them both charge market rate for exploits, but keep doing so.
Honestly I wouldn't be surprised if they had a monthly subscription fee.
> This is not how security works.
what do you mean?
ime this is absolutely how security works regardless of your defense strategy.
*Yes, you do everything in VMs, with a transparent interface.
You do though. You can exploit flaws in the hypervisor to escape the VM and then you've bypassed the Qubes security model. Here's one such example: https://www.qubes-os.org/news/2017/08/15/qsb-32/
Extreme compartmentalization through virtualisation is also insufficient, as it just becomes a matter of “is there a bug in the hyper visor”, to which the answer is yes: every major VM system has had multiple escapes, as another commenter pointed out even your example of qubes os has had them.
I know how hard security is. I know how hard writing bug free code is.
Brushing that aside and saying “just do X and bugs don’t matter”, assumes that somehow the people implementing support for X are immune to the same problems faced by other developers.
iOS isn't. The vulnerability in iMessage led to the whole system compromize.
> every major VM system has had multiple escapes
Qubes uses hardware (VT-d) virtualization, which AFAIK was last time broken by the Qubes founder in 2003: https://en.wikipedia.org/wiki/Blue_Pill_(software).
Every other virtualisation system also uses hardware virtualisation. They’ve been popped. I don’t think it’s unreasonable to suspect that qubes has not had the same degree of offensive interest as, say, VMware.
I would be grateful if you could provide some links.
> I don’t think it’s unreasonable to suspect that qubes has not had the same degree of offensive interest as, say, VMware.
Qubes relies on Xen. The latter definitely had a lot of offensive interest. I am not aware of any recent escapes of hardware virtualization though.
Probably only 10 years ago, I knew a lot of people who thought careful and conscientious use of encryption and security features could protect sensitive info from governments. That's not a very long time ago.
It's taken a while to sink in -- and to the full extent of it being more and more widely known. That nearly any government can probably trivially get access to anything, using commodity off-the-shelf surveillance software.
(Postscript: Edward Snowden is a hero).
Apple put it in their TV ads, you know.
As you say, only thing you can do in such case, is to do everything assuming you're being spied upon.
1. Mossad
2. Not Mossad
https://www.usenix.org/system/files/1401_08-12_mickens.pdfhttps://news.ycombinator.com/item?id=27915173
:)
A fun snippet that jumped out at me this time:
> With public key cryptography, there’s a horrible, fundamental challenge of finding somebody, anybody, to establish and maintain the infrastructure. For example, you could enlist a well-known technology company to do it, but this would offend the refined aesthetics of the vaguely Marxist but comfortably bourgeoisie hacker community who wants everything to be decentralized and who non-ironically believes that Tor is used for things besides drug deals and kidnapping plots.
Apple has way more budget than Mossad.
They don't have to compete with apple they just have to find an interesting mistake in their code. On phones with tens of years of legacy firmware/modem/protocol code that's very hard to reliably stop.
(NSO is not Mossad and Mossad doesn't use NSO afaik)
And there are are no commercial off-the-shelf security solutions that can “protect” you. You have to do your own security. This is why Snowden had to painstakingly teach the journalists on how to use GPG to receive his cache. No other way would be trustful enough.
I think you're making excuses. Apple, owning the entire stack, has the least excuse of anyone. Given their market share they also have a lot of responsibility to be better.
Do you even know what you are asking? You are asking perfect code and hardware, no single mistake on any line of the process. Taking account on every possible scenario and sidescenario you can’t or can think about.
https://bughunters.google.com/about/rules/5745167867576320
I think all this is good until an adversary decides to brick every iDevice, Android, Windows, MacOS, and Linux machine in the US. And by "brick", I mean overwrite firmwares, disable fans, and run at maximum load.
Doesn't it matter which state?
Sure, for US, Russia, China this is probably just true without nuance. For someplace like Israel (small but highly motivated and strong in both espionage and tech) apparently also true.
But should I not expect a FAANG-level company to defend itself from state-sponsored hacking if the state is Uzbekistan or Cambodia?
And if every state can get access to top-tier hacking by having an alliance with $MAJOR_PLAYER, why should we expect that doesn't extend to non-state actors? At which point, are we just giving up on security?
I think Apple absolutely can defend itself against state-funded hackers. Whether they choose to do so is a question of priorities I guess.
State can use selective enforcement of different regulations to strongarm companies doing crazy stuffs..
But that isn’t really a question of technology, and the parent comment was, I think, suggesting it’s an unrealistic expectation on the tech level for companies to beat back state actors.
NSO’s elevator pitch is giving top-tier capabilities to states that can’t develop them in house.
> why should we expect that doesn't extend to non-state actors?
Whether or not that's actually the case is an interesting discussion.
To be fair, this is just as true of an Israeli car repair shop or shawarma joint...
So is every Swiss company, from Swatch to Nestle, just a front for the Swiss Government?