NSO developed 3 new ways to hack iPhones, Citizen Lab says
washingtonpost.com
washingtonpost.com
Android being open source makes it easier for more parties to audit the software they run, and not just groups that are paid handsomely to exploit iOS for state sponsored hacking.
[1] https://www.theregister.com/2020/05/14/zerodium_ios_flaws/
Apple has decided that iOS should only accept downloading OS updates over wifi. In my country, for example, people don't really set up wifi at home anymore because basically everyone has unlimited cellular data. So they don't need to connect to any wifi at all. All the iOS update statistics seem to come from the US, where everyone relies on wifi.
It seems that on some level, iOS suffers from the same update problem as Android, but only because Apple decided to do so for no reason. Not everyone lives in the US.
[0] https://osxdaily.com/2022/08/05/how-to-update-your-iphone-ov...
Moreover, the reasons given in [1] don't include "Android being open-source make it easier to audit".
Is this still true today?
And that is the way news works. It was news 3 years ago when iOS exploits became cheaper, now it's just how the market is.
> Moreover, the reasons given in [1] don't include "Android being open-source make it easier to audit".
From Wired[4]:
> Shwartz credits Android's increased security partly to its open-source strategy finally paying off. While Apple has kept its operating system so locked down that even benevolent security researchers have difficulty sussing out its bugs—a problem it's tried to solve with a recent expansion and opening up of its bug bounty program—Android's open-source approach has meant more eyes on its code. While that broadness initially led to more bugs, those vulnerabilities have been patched over time, slowly hardening the operating system. "So many vulnerabilities have been patched that the attack surface is decreased dramatically," says Shwartz.
[3] https://web.archive.org/web/20201108190905/https://zerodium.....
[4] https://www.wired.com/story/android-zero-day-more-than-ios-z...
Is there anywhere that tracks more current prices?
Zerodium pays out based on the maturity of the exploit, how many versions it covers and what are its dependencies and ease of exploit.
Apple's security model clearly excludes their own apps and that shows on the issues publicly released.
Secondly, on Android, very few system components are actually tied to the OS version, and it's getting thinner after every version. On iOS it's the norm.
I'm a huge fan of the idea of Lockdown Mode and have it enabled on my iPhone and MacBook, but I don't think it has mass adoption or appeal. It certainly needs some tuning before the masses will adopt it. Specifically, people in your Contacts should have the option to be trusted. Right now, FaceTime calls are blocked from them if they are not in your recent calls (an issue for me as I regularly purge my call history) and iMessage content is blocked (Live Photos, documents, etc).
1. Device connections - To connect your iPhone or iPad to an accessory or another computer, the device needs to be unlocked.
2. Configuration profiles - Configuration profiles can’t be installed, and the device can’t be enrolled in Mobile Device Management or device supervision while in Lockdown Mode.
> Lockdown Mode Blocked: redacted@gmail.com attempted to access a Home.
[0] (ctrl+f for "Lockdown Mode Highlights Attack") https://citizenlab.ca/2023/04/nso-groups-pegasus-spyware-ret...
How crippled does the device feel? Is it usable? The two things you mentioned wouldn't be a problem for me. I've been considering enabling it for a while but wondered how restrictive it will realistically feel.
1.) FaceTime calls from people not in your recent calls will be blocked with a silent notification. Sometimes I don't see it for hours
2.) Incoming iMessages will be stripped of Live Photos and document attachments
3.) Using Starbucks in a browser did not work until I disabled Lockdown Mode in Safari for the domain. Fortunately these exceptions are easy to make and persist
I'm not a target for state-sponsored attacks but will generally trade usability for security when reasonable.
(3) is weird. Conceivably it’s using wasm (I recall many years ago wasm had no interpreter mode, no idea of current state), or webgl (which seems plausibly like something that would be blocked)
Not. And yes.
I did some analysis of it when it came out to figure out what all is blocked and such: https://www.sevarg.net/2022/07/20/ios16-lockdown-mode-browse...
Animated gifs in text threads don't animate - which, personally, I consider a feature.
And webfonts aren't loaded, which means a lot of forums that load icons as a webfont have a lot of squares instead of arrows for reply and such.
You can disable it on a per-website basis, and I don't do much in the way of facetime and such, so I've not really noticed it. It does remove a LOT of complex attack surfaces, though, which is worth a lot.
The only smart thing to do if you are such a individual is to not have a smartphone at all otherwise you are 100% going to be successfully attacked because every commercial smartphone is trivial to hack for a dedicated threat actor. In addition, you should never purchase a smartphone from any existing smartphone vendor for the foreseeable future regardless of what dangerous lies their marketing spins because all of their security organizations are structurally incompetent with respect to protecting against sophisticated digital threats. It would require a wholesale replacement of their security leadership, technology, and ideology for it to even be possible to actually protect against sophisticated digital threats.
The idea that Apple is playing ball with the IDF is frankly ludicrous.
Apple regularly gives up users' private data when the government simply asks them to[1], despite spending billions of dollars on "privacy" marketing.
Thing 1: Apple complies with US law. How do you think it would work if Apple said “Fuck you” to US law enforcement requests? Can you provide examples of other companies that have done this, or are doing this now, and had it work at all? I can’t think of a single US-based tech company that doesn’t cooperate with law enforcement. At least Apple is transparent about it.
Thing 2: Apple markets privacy — https://www.apple.com/privacy/ They make a bunch of concrete statements, most of which are empirically verifiable. What is wrong with this? Again, can you point to any at-all-similar company that does it better, or more explicitly?
That's to say that Apple regularly hands over users' private data when simply asked, even if there is no legal obligation to do so, as there is with warrants.
I'm having trouble finding this part specifically.
Can you point to where that is described, and what some examples are?
https://en.m.wikipedia.org/wiki/FBI–Apple_encryption_dispute
Jeez, I if I had one wish from a genie some day, it would be to absolutely get rid of the curse that is whattaboutism.
Whilst, yes, you can wonder why it isn’t all rewritten in swift (if it isn’t already), exploits will continue to be found and exploited, forever.
I'm not saying that it's impossible to check in buggy code, but it's possible to have processes to prevent this type of bug nowadays and Apple should have had these 10 years ago.
Apple have as usual decided that nope, some of their features are a must have and if safety has to be sacrificed to get features well, sucks to be you getting exploited.
Something like Swift isn't up to it. It's less easy to blow your foot off than if you wrote C++ but necessarily (as a general purpose language) you can do it. But what if we give up generality? Languages like WUFFS give up general purpose programming, solving only a narrow problem but doing so with cast iron safety because they're able to prove the system always has valid state. This is entirely appropriate when (as so often) we didn't really need generality, which means having it is a gift for bad guys.
"Lockdown mode" should have begun with stuff that's definitely safe, rather than just arbitrarily picking a smaller set of features in the hope that the smaller surface can be more easily defended.
So you’re rewriting practically an entire OS stack from scratch, in a different language (one that is ill-suited for low-level operations needed in many parts of an OS)
I’d say that’s not trivial?
* https://citizenlab.ca/2023/03/manager-information-system-sec...
Ouch. Toronto is one of the most expensive cities in North America. If they really want "expert" level skills across a number of infosec areas, they are going to have a lot of trouble finding a candidate that meets their requirements.
* https://jobs.utoronto.ca/job/Toronto-Manager%2C-Information-...
And so uses the same wage schedule as them:
* https://people.utoronto.ca/wp-content/uploads/2022/06/PM-Sal...
* https://people.utoronto.ca/careers/salary-ranges/
> […] they are going to have a lot of trouble finding a candidate that meets their requirements.
Depends on whether they're trying to bring in someone international, or just in the local talent pool. You do get some good benefits: supplemental health stuff and a DB pension.
I started a new position not too long ago where I got a decent salary bump, but if I was still at my old position I would be semi-tempted to at least would apply to see what the environment is about.
I've read the in-dept writeups on some of the previous ones and they are insane. Combining 5+ seperate problems to finally achieve the goal.
I can't imagine what that interview is like.
Not that I condone any of this stuff, quite the opposite. But from a programming perspective, it's pretty incredible.
https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
These have to be ex-employees of national security groups like the NSA, etc. who are already familiar with this type of stuff. The Stuxnet-type employees who understand everything at the deepest levels and can (and will) do anything to make it happen.
Top-tier engineering. Just used for nerfarious purposes, despite the PR spin.
I'm actually surprised they have a PR person. "Um, nothing to see here!" would be my standard response.
I'd not heard about Apple's "Lockdown Mode" (which applies to both computers and phones). Per a support page[1], there's a lot of small tweaks that reduce convenience of the devices, but it sounds like they will fundamentally still _mostly work_.
Is "Lockdown Mode" a well-known thing that I just missed? It feels like Apple has put a target on things like URL previews for malicious actors, while also labeling the defense mechanism as an expert-only tool.
https://www.google.com/search?q=apple+lockdown+mode+ios
It's very new. August 2022 is the earliest I see anything, iOS 16 (the current release)
It struck me as something designed for people like Jeff Bezos basically lol
[1] https://www.corellium.com/ [2] https://security.apple.com/research-device/