Apple plans to update iPhones in-store without opening the boxes
appleinsider.com
appleinsider.com
We have wireless power with Qi/MagSafe, and at least MagSafe can pass a serial number.
You could use a “magic” charger through the box (assuming it’s laid out right) to charge the phone and tell it to go into update mode. It could look for some predefined WiFi/Bluetooth/whatever to get info and do what it needs to.
Apple already has full security on OS updates, so you couldn’t apply rogue updates without having a way to crack that.
This special mode could easily be disabled the moment someone starts setting up the iPhone, so it would only work on factory fresh (or perhaps wiped) devices to prevent funny business.
"Consisting of a "pad-like device," store employees place unopened iPhone boxes onto it to trigger an update. The pad wirelessly turns on the iPhone, runs the software update, then turns it off again."
As in without contact with the device.
Maybe you don't install any updates over the entire device lifetime? Okay but what if the firmware runs a keylogger? You always need to put a ton of trust into the company.
They could enable 24/7 recording, lie to the OS about what is happening and trickle the data back server-side within harmless iCloud requests. It would be pretty much undetectable.
And the point of CSAM client-side is that it is more secure and private than them doing it server-side.
What can be more insecure and not at all private than scanning user files using user's computer resources? Server-side scanning is impossible if E2EE.
You see this as a simple trusting apple because they have complete control over the OS/Hardware. I see this as a culture shift that goes beyond trusting any particular company that fundamentally erodes privacy.
Of course, they could lie and scan everything, but as others pointed out, they could do that already anyway.
As much as I oppose client-side scanning, having a single global hash database makes it much harder for a company to do special favors without anyone knowing.
Would you mind expanding upon that?
The fact that you have a phone in and of itself is traceable, as cell phone towers maintain records of who, when, and where. At this point, usage of such records is so commonplace by LEO that not having your phone with you when you do something is considered suspicious in and of itself.
Advocating against Apple force-updating a phone that you haven't bought seems... silly in comparison? Especially as only with an up to date OS, you can be sort of safe against attackers, be it state level sponsored or regular ones.
As opposed to opening the phone, plugging the cable, doing whatever you want and shrink-wrapping again? (which is easy)
"Oh but it's wireless" It's through the wireless charging mechanism. That makes the whole difference
Wood you be ok if this capability could only be activated at super-closer range (wireless charging range) and only worked on iPhones that have not been activated?
We don’t know if that is how this works, but I would be comfortable with this feature if that’s how it works.
And that's obviously how it works. Maybe it will then enable wifi instead of sending data through wireless charging but that's it. And then it would turn itself off. Still what you can do is what Apple could do before putting it into the box. Again, obviously
I fail to see how this is concerning (to put it politely)
* When an iPhone comes from the factory, it's not really off-off, it's just in standby mode. Probably true to some extent in any case?
* If battery is above 50%, try to connect to a special Apple Store wifi network with a known signature. (Wifi has to have this kind of feature, right?)
* If you're connected, check for updates and apply any that apply.
* Go back to sleep.
Easy peasy. Bonus points if you can wirelessly charge them through the box, but honestly apple stores probably go through enough product it doesn't even matter.
And phones can definitely sit around for many months, at the warehouse and the store.
So what you get is a mechanism that wirelessly, without any confirmation, modifies the software on your device and "only" requires proximity. That seems like a great angle of attack for malware, surveillance, cracking a stolen phone,... . You are free to believe that apple implemented this perfectly bug free, but I would not be surprised if we get a CVE related to this in a few years.
> that wirelessly, without any confirmation, modifies the software on your device and "only" requires proximity
Running an update is different than "modifying the software". It is possible that such an update just wipes everything on the phone as well
Apple clearly take security very seriously. There’s no way this would be left enabled after someone sets up the iPhone.
I don't get it? What do you think does Samsung do when you send over your device for repair? Ever got asked for a passcode by them?
The iPhone is one of the most popular devices on the planet, and Apple is in a very high profile position because of it. The last time they tried doing anything remotely close to sneaky was the slowing down of phones with older batteries which eventually resulted in a class action lawsuit.
Sure Apple could install backdoor software, crapware or whatever else in an update, but their exposure to a class action lawsuit would be insane. Whatever they did would be found out pretty quick by security researchers and....you have class action on your hands that will probably cost the org $100M - $500M.
Apple isn't in the business of being nefarious, their in the business of selling you an iPhone. It's in their best interest to sell you the most secure and best phone possible, because all they want is to sell you an iPhone.
They’re not forcing anything on you.
No. Apple's best interest is to make money. Apple is a business; they care neither about you or me.
The iPhone is side-product, a cash-cow that can be milked over and over.
All it will take is for this mechanism to be cracked, and we have lost.
This is also why jailbreaking an iPhone is so difficult. Nobody else has that key, so the best you can do is find a bug in something Apple approved and try to gain root with it.
There hasn’t been one of those in… years… and as for one that will allow an unsigned persistent update? Not since iOS 9. Almost a decade ago. Nobody has found a persistent jailbreak since.
The last true chip exploit, which Apple cannot patch, was with the A10 Fusion seven years ago. It also required a USB cable, a Mac to inject the payload, and you had (and have) to connect the phone to the Mac every time you reboot it because it can’t persist itself.
Oh, so its okay as long as we trust Apple to tell us when their key is stolen...
Phones have NFC readers so your statement is already true if you take paranoia to delusional levels.
I suppose you could test your patch releases even if it's launch weekend, but having the ability to have a known-good version out of the box is nice.
Sounds like they shipped with 17.0.0, 17.0.1 was a day one patch and determined to be broken, but wasn't pulled before a fixed update was released.
In this situation, instead of being told not to update and you being able to skip the update and run initial setup on 17.0.0 if 17.0.2 hadn't shipped, they may have already updated the device to 17.0.1, and you would have had to wait. Presumably if it was bad enough, they might not sell you the thing until 17.0.2 was available for them to update it before you got it.
That said, in box upgrades are great to avoid huge patches when you open something that may have been sitting on the shelves for a while, and should help with logistics as well. Apple said they wanted to use more ocean freight rather than air freight for environmental reasons, and it will also likely reduce costs, but as another poster was saying, if you can't put the phones in the box until the final OS is ready, you can't ship the phones until the OS is ready, and ocean freight is slow. Being able to ship the phones and update them after they arrive in the destination at the destination store/distribution warehouse eliminates a pipeline bubble.
It seems to me the threat model for consumers is the same either way. The box itself doesn't offer any meaningful tamper-evidence, so a sophisticated attacker would just re-shrinkwrap everything if they couldn't update them this way.
I mean, technically there is an attack vector there, but it's oddly specific, and since the attacker needs physical access anyways, you've got other problems (i.e. someone got into your home).
Of course, having phones be updated before users use them is also super important. So maybe what’s going on here is something that only works when a phone hasn’t been associated to a user yet.
- Trigger update via "special pad"
- Interrupt update process to get access to phone
- Wirelessly transmit spyware onto target's phone
Regular Magsafe can start charging at 40-50mm. Power has to go through a lot of packaging layers. If they make an extra-strong in-store charger cradle to boost that distance, it would be possible to reach the phone, and trigger a power-up session without opening the box.
The power detection chip can take very little energy so everything else (other than maybe power-button-press detector) is in super-dormant mode.
On power bootup, the phones can connect to Apple store wifi (preset in wifi defaults), then use key exchange to authorize wifi. Then they can use mDNS/DNS-SD to scan for an update service running on the store network. If found, they can do a key exchange, then download the update, validate, and install.
The whole time, the custom cradle could also be topping up the phones so when the user opens their box, it's charged and they're happy.
Just a guess. Very clever, if true. Also, eminently doable.
I'm not sure how they would test for update failures in that situation. I suppose they could have a LOM or something that validates the software is installed, reports back to the mothership, then deletes itself. That would imply that it's part of Apple's secure chain.
But sheeshj, one can't build a phone, install software on it, have it sit on a shelf for a bit, and then work as advertised without updating immediately after purchase? Latest iPhones don't sit on shelves that long, do they?
Yeah, I know how it works these days. Like with AAA game releases where people are downloading GB-sized updates a day after release.
But this isn't something to be proud of! If anything, it shows the sorry state of current-day software development & deployment practices.
Fix the problem. Not the symptoms.
If a critical vulnerability is found while the phone is on the shelf, you go home, turn on your phone, boom it's vulnerable.
Seems to me this is a solution to the other side of the problem. Were you buy a “brand new“ phone and then immediately have to spend time while downloads the update and installs it because the box sat around a little while and your phone has a newer OS version and won’t transfer until the new phone is updated.
Apple has started transitioning some products to ship by boat rather than by air, so it could be over a month from when the product leaves the factory to when it hits the shelf. Having this kind of update process is a lot more important in that scenario, to the point that Apple probably views this as a prerequisite to using ocean shipping for the iPhone.
Apple Watch since Series 7 has had a 60GHz wireless USB transmitter in it that replaced the hidden pogo-pins used for OS recovery and diagnostics in the back of house at Apple Stores. They designed a specific sled that has an Apple Watch charger and the 60GHz macguffins, and then carriers that each model watch rides in on top to align to the charger and the 60Ghz connection.
Ironically, it's also USB-C. https://sci.tea-nifty.com/blog/2022/03/post-eb2dde.html
Seems like a very high frequency, although looks like there is now a WiFi band up there?
One of the largest devices that ever used it was the Essential PH-1 and its snap-on camera module (and some other modules as well); the data was transferred over 60GHz USB while power and alignment was delivered by two pogo pins.
There was also Dell and friends' various efforts with WiGig 60GHz docking stations. https://www.wi-fi.org/discover-wi-fi/wi-fi-certified-wigig
Apple already updates iOS over-the-air, no port required.
If not, then does the pad setup a WiFi connection to the store to remotely download it and then install?
Seems like another attack vector for NSO to exploit and add to their arsenal of government oriented spyware.
Apple already covers the entire boot process and all the OS updates with digital signatures. They can be absolutely sure that no one has tampered with the download and that it was produced by Apple.
They don’t really need a special iPad serving the update to make it secure.
(of course none of this applies if someone figured out how to break digital signatures, but if they did we’re all screwed anyway)
if phone_initialized:
require_authentication() if phone_initialized and not forced_by_law:
require_authentication()> How can we be assured this can't be done for a phone that is set up, in my pocket?
In that case the phone would already be initialized.
Staying put, hoping for a jailbreak one day.
The biggest thing I miss in the first 24 hours? The way I could monitor my battery's temperature even though for whatever reason Apple in their infinite wisdom has decided people shouldn't be able to monitor their battery temperature directly. That, and the tweak I had that would colorize my notifications based on the app icon.
And if it does charge wirelessly, does that mean they have to move the phone's position specifically to the bottom of the packaging to be close enough to the charging surface? Or is there some fancy tech that can charge via Qi from a couple inches away?
So all you would need is a very simple jig that would align the box with the charger when the box is placed faced down.
The iPhone may already be close enough for wireless charging to work, and Apple could certainly use an out of spec charger that will work at a slightly larger distance if necessary.
''' Consisting of a "pad-like device," store employees place unopened iPhone boxes onto it to trigger an update. The pad wirelessly turns on the iPhone, runs the software update, then turns it off again. '''
pretty cool !
I have not been impressed by the quality of the service in-store (waiting more than an hour for basic requests, like buying an AirTag, within earshot of salespeople chatting about their weekend), but I’m not sure this is going to improve it much.
They also sell those boxes one by one via relative in depth customer interactions.
Setting a box in an automated update device is nothing.
Regarding the in-store experience, I have had similar challenges. I walked in wanting to buy an iPad, and knowing exactly which model I wanted (and that it was in-stock at that store). The employee asked me "if I had an appointment". Since when does one need an appointment to purchase something off the shelf? Crazy.